Ensuring you have the right technology, processes and people in place to handle the quality of the data that you hold was a key part of thriving under the DPA and now the GDPR.
Important activities you should consider include:. All rights reserved. Experian Ltd is authorised and regulated by the Financial Conduct Authority firm reference number Experian Ltd is registered in England and Wales no. Experian Global Sites. The paper argues that while the protection of privacy is an important objective, privacy also serves as a means to protecting other ends, such as free speech and sexual autonomy. A framework for protecting personal data has to be designed on a more precise understanding of the role of privacy in society and of the harms that emanate from violations of individual privacy.
The notion of informational privacy has become salient in the past decade but, as this paper illustrates, India has privacy jurisprudence going back several decades. Most of it focuses on privacy in the context of harms caused due to a violation of privacy.
This jurisprudence changed in , when the Supreme Court in Justice K. Puttaswamy v. Union of India held that the Indian Constitution included a fundamental right to privacy.
The jurisprudence on privacy therefore changed—from being valued as a right that protected other ends to being an end in itself. Along with holding that privacy is a fundamental right, the judgment also declared informational privacy to be a subset of the right to privacy. The bill aims to protect the informational privacy of individuals by creating a preventive framework that regulates how businesses collect and use personal data, as opposed to protecting informational privacy with a view to the consequent harms caused by the violation of such privacy.
In doing so, it focuses primarily on regulating practices related to the use of data. This is likely to have deleterious consequences for innovation in the economy while leaving unfulfilled the stated objective of protecting informational privacy. The first part of this paper provides a summary of the major developments that have led to the demand for a data protection law.
This paper argues that the bill follows this new conception of privacy and that in doing so it fails to create a precisely designed regulatory framework that adequately addresses market failures in the digital economy. The second, third, and fourth parts highlight three key reasons why the bill should be significantly modified. The first is that its reliance on strengthening consent-based mechanisms for protecting personal data is not likely to be effective.
A large body of academic work highlights that increased disclosure requirements to users about the use of their data is becoming ineffective in light of modern technological developments. A reliance on such mechanisms could be counterproductive and lead to individuals taking less responsibility while sharing their data. Second, the preventive framework proposed in the bill could lead to significant compliance costs for private businesses. The bill will regulate data use in all sectors of economic activity and establishes significant new compliance requirements for the vast majority of affected businesses.
The costs of compliance will be borne across small and big businesses except those that are specifically exempt. This is problematic since most businesses in India are small.
Such compliance requirements would be especially onerous for them. This bill also allows the government to compel businesses to share nonpersonal data with it. This, as the paper argues, could have deleterious consequences for innovation and economic growth in the long run.
This body will be tasked with regulating the provisions of the bill to frame regulations on issues such as mechanisms for taking consent, limitations on the use of data, and cross-border transfer of data. The supervisory mandate of the DPA is sweeping, given the fact that it has to regulate a wide array of preventive obligations, such as security safeguards and transparency requirements, that have to be implemented by businesses.
It is likely that the DPA, therefore, may not be able to either effectively implement the bill or effectively protect informational privacy. This paper argues that, given its cross-sectoral mandate, the DPA may struggle to build internal capacity, leading to either underregulation or overregulation.
The former would defeat the intent of the bill while the latter would add unnecessary burdens for compliant businesses. Additionally, the bill does not provide adequate checks and balances to ensure that the central government and the DPA exercise their vast supervisory powers in a reasonable manner. Lastly, the bill allows the government to exempt any of its agencies from the requirements of this legislation and also allows it to decide what safeguards would apply to their use of data.
This, as the paper argues, potentially constitutes a new source of power for national security agencies to conduct surveillance—and, paradoxically, could dilute privacy instead of strengthening it.
The analysis set forth in this paper has been supported by inputs from structured consultations with stakeholders and an empirical analysis of regulatory frameworks in data protection, as well as academic literature on the subject.
Participants in roundtables organized by Carnegie India included academics working on privacy, representatives from technology companies and start-ups, and scientific experts. Most participants highlighted specific provisions of the bill that could lead to ineffective regulation or substantial compliance burdens due to the obligations proposed in it. These inputs were corroborated by secondary research, survey reports, and academic literature that highlighted similar issues with data protection regulations in other jurisdictions.
This paper concludes by proposing a framework for modifying the bill and addressing the issues highlighted.
In doing so, it argues that there are structural limits to what problems regulation can solve in the data sharing and data processing markets. This is especially true in India, given the extremely low capacity of regulators across sectors. Therefore, data protection legislation must be narrowly focused and designed toward protecting individuals and society against any injury resulting from data processing.
A framework designed with this end in mind would achieve a better balance between privacy and innovation. Though the constitution does not explicitly mention a right to privacy, Indian courts have held that a right to privacy exists under the right to life guaranteed under Article State of Uttar Pradesh , where the court held that a right to privacy did not exist under the constitution.
The growth of the Indian information technology industry and the telecom revolution, which started in the late s, led to the proliferation of digital services in India. This has had two significant consequences. First, the country is increasingly interconnected due to the growth of digital services and platforms.
The second objective has been facilitated largely by the implementation of Aadhaar. However, the growing ubiquity of Aadhaar came under sustained criticism from various quarters.
One criticism was that Aadhaar was being used for purposes other than social-welfare delivery, such as customer onboarding by private firms. It was alleged that the storage of Aadhaar-related customer information, such as metadata about the place of authentication, constituted a serious breach of privacy.
This effort to create a comprehensive data protection regulation in the EU influenced the debate in India. The debate on the privacy concerns over Aadhaar resulted in a clutch of petitions before the Supreme Court that challenged the validity of the legislation that enabled the system: the Aadhaar Targeted Delivery of Financial and Other Subsidies, Benefits and Services Act, The five-judge bench of the Supreme Court that heard the petitions stated that, since the petitions claimed infringement of the right to privacy, it was first important to determine whether this right existed under the constitution.
It referred this issue to a bench of nine judges of the Supreme Court, which held in August that a right to privacy did exist under Article 21, that the Supreme Court had decided the question incorrectly in Kharak Singh , and that informational privacy was a part of this right to privacy. First, it clearly and unambiguously stated that there was a fundamental right to privacy under the constitution.
In the context of this paper, however, the more significant ground was that the right to privacy was conceptualized as a right in itself, irrespective of what privacy it helped protect in turn. In a long line of past cases, privacy was used to protect specific interests, such as privacy from nighttime police visits in the Kharak Singh case or privacy from telephone tapping in PUCL v. Union of India. This arguably led to a focus away from the actual harm individuals would suffer from a violation of privacy.
Importantly, as explained below, this conception of privacy also aligned with already existing regulatory frameworks in data protection in other jurisdictions. Meanwhile, in July , in response to demands for a comprehensive data protection legislation, the government formed a committee to study issues related to data protection and to propose legislation for it.
The committee, chaired by Justice B. Srikrishna, published a report laying out the rationale for a legal framework for data protection, as well as a Draft Personal Data Protection Bill, In , a report of the U. As early as , an academic, Kenneth C. Laudon, highlighted the limitations of the existing framework. He wrote:. The FIP [Fair Information Practices] doctrine was based on the technological reality of the s, where a small number of very large-scale mainframe databases operated by the Federal and State governments, or by large financial institutions, were the primary threats to privacy.
In this period it was conceivable that an individual could know all the databases in which he or she appeared. Large scale databases have become so ubiquitous that individuals have no possibility of knowing about all the database systems in which they appear.
If the technological developments of the early s placed the basic principles of data regulation out of sync with market realities, this gap is arguably wider now.
The bill is, however, based on the same basic principles first set out in The bill provides a legal framework for the collection and use of personal information. In addition to creating a set of rights and responsibilities for the processing of personal data, the bill proposes to create a DPA for making regulations and enforcing the legal framework. The bill also vests substantive standard-setting powers with the central government and tasks the DPA with enforcing the same.
An important feature of the bill is the wide scope of its applicability. If implemented, it will apply to all enterprises across India other than those specifically exempted. This would include any enterprise that uses automated means to collect data. The DPA will have the power to define small entities based on turnover, volume of data handled, and the purposes of data collection.
The bill makes consent a centerpiece of the proposed data protection framework. It proposes that personal data should only be processed on the basis of free, informed, and specific consent, with provisions that allow such consent to be withdrawn. Any data processing without such consent would be a violation and could result in penalties. The data fiduciary will be required to ensure the data are accurate and stored only for the period necessary for satisfying the purposes of data collection.
It also will be accountable for all compliance requirements under the bill. Data fiduciaries have additional obligations, including to implement privacy by design which requires them to implement business practices that can anticipate, identify, and avoid harms to consumers ; 34 to comply with transparency requirements; 35 to create security safeguards—including methods for de-identifying personal data and encryption and steps for preventing misuse of data; and to create grievance-redress systems.
The bill exempts certain kinds of data collection and processing from specific requirements. The bill requires data fiduciaries to store certain data in India data localization and provides an escalating framework for the storage and processing of data based on its sensitivity. Personal data may be transferred freely. The bill does not allow critical personal data as may be defined by the central government to be transferred outside the country, except on limited grounds and after meeting certain specified conditions.
Monetary penalties are proposed if data fiduciaries fail to comply with certain provisions. This offense is cognizable—that is, an offense in which an arrest can be made without a warrant—and nonbailable. The proposed legislation, therefore, adopts a comprehensive preventive framework that applies to varied data collection and usage practices. It creates a number of obligations for businesses that collect and use consumer data and introduces data-related rights for consumers. Since the bill prevents the collection of any personal data without meeting these obligations, it will cover small grocery stores that have fairly uncomplicated data collection practices as well as businesses using sophisticated machine-learning algorithms and large datasets.
The bill will therefore have a significant impact on the economy. India currently has a small number of diversified conglomerates, national and global IT companies, and e-commerce and fintech giants vying for consumers. However, the vast majority of businesses are small businesses.
It is therefore important that this bill protects personal data in a manner that protects privacy while allowing for innovation and economic growth. In India, a large majority of the population has become connected to the internet only recently. In a country with poor road, electricity, and communication infrastructure, digital connectivity for this segment of the population is empowering in a manner that is very different than it is for those who are already accustomed to existing in a digital ecosystem.
The following sections seek to consider the design and likely impact of the bill in this economic context.
The key regulatory approach adopted in the Personal Data Protection Bill seeks to protect consumers from uses of data that could be harmful to them. The bill does not, however, identify specific harmful practices. Instead, it makes user consent an important part of the data protection framework. In order to do so, it mandates that personal data can only be collected after providing notice and taking consent.
The bill therefore focuses on adequate disclosure to individuals as a mechanism for preventing harm to them. In addition, the bill aims to reduce the gap in information about the use of personal data between consumers and data fiduciaries.
It aims to do so by limiting the purposes of data processing as well as by giving users the right to access their personal data and the right to know how it will be used. Users can also correct their personal data stored with data fiduciaries. The bill requires that data fiduciaries give notice of these rights to consumers before collecting their data. The proposed DPA will oversee whether data fiduciaries are complying with these obligations.
It is based on the philosophically significant act of an individual providing consent for certain actions pertaining to her data. The report and the bill acknowledge that users are not capable of providing meaningful consent, and yet—somewhat paradoxically—they build on the premise that stronger consent mechanisms can lead to better outcomes.
If they read the agreements, they cannot understand them, and even if the agreements are comprehensible, these agreements cannot be negotiated. As stated earlier, since the s, legal frameworks have predominantly been aimed at ensuring consent-based data protection.
This legal regime shaped the data collection practices of tech firms that collect personal data. But securing consent has become meaningless as a basis for data protection, not just because of the problems with the idea of meaningful consent but also because sweeping technological changes have rendered the idea even more redundant.
It is important, therefore, to ask whether doubling down on a consent-based framework is likely to protect personal data in India. A preponderance of evidence points to the fact that the operation of notice and consent on the internet today is broken. Our practice is to make the following items of data freely available unless individuals have objected:. Similarly, as part of its regular business activities, the University may process personal information about third parties which is already in the public domain where such processing is carried out in accordance with the Data Protection Act principles set out below and is unlikely to cause any damage or distress to the data subject.
Anyone using personal data must comply with the 6 Data Protection Principles contained in the Data Protection Act as they define how personal data can be legally processed: In summary these state that personal data shall:. Keeping personal data properly secure is key in complying with the Data Protection Act. All staff are therefore responsible for ensuring that if they keep personal data, it is kept securely and is not disclosed either orally or in writing or accidentally to any unauthorised party.
Please see the guidance on Disclosing Data for further information on this point. Please see the section on data security and the University's IT Security Policy for further information and rules on security. Individuals have the right to access any personal data that relates to them which the University holds. Any person who wishes to exercise this right should see the Subject Access Rights Page for details on how to do so.
Before commencing any research which will involve obtaining or using personal data, the researcher whether a student or member of staff and their academic supervisor or Head of Group must give proper consideration to this policy and the guidance contained on our Data Protection webpages and our Research Data Policy and how these will be properly complied with.
In particular, they will need to consider the type of personal data which may be collected, the applicable lawful basis for the processing, whether any special category data is to be processed and if so what additional condition for special category data will be relied on and what additional safeguards required, how ethical consent is to be recorded, the extent to which such data may legitimately be required for the academic objective, how the data will be securely stored, and the duration for which it will be retained.
Personal data obtained or used for research should be limited to the minimum amount of data which is reasonably required to achieve the desired academic objectives and wherever possible any such personal data should be made anonymous so that the data subjects cannot be identified.
For more information refer to the Research Data Policy. It is a condition of employment in the case of staff and enrolment in the case of students that staff and students will abide by the policies and rules of the University. Any breach of this policy will be considered to be a disciplinary offence and may lead to disciplinary action. Compliance with the Data Protection Act is the responsibility of all members of the University. Any questions about this policy or any queries concerning data protection matters should be raised with the Data Protection team.
The Information Commissioner maintains a public register of organisations that use personal data. The University has an entry on this register which specifies the main types of data we hold for example, personal details, education and training info , the main purposes for which we use the data for example, HR administration, student and staff support services, education and research, and so on and those to whom it may be disclosed for example, funding councils, central government.
The University's Registration Number is Z Our registration is renewable annually, although we can make additions or changes to it at any time, for example, if we start to process a new type of data. In practice, most routine uses of personal data by staff will be covered by our Registration. However, if you are processing any data for example, maintaining a database or running a research project involving the use of personal data and think it may involve us handling new personal data for the first time or using personal data for a new purpose, please email the Data Protection team for advice, and so that our Registration can be amended if necessary.
0コメント