{"id":199330,"date":"2022-08-09T19:00:13","date_gmt":"2022-08-09T13:30:13","guid":{"rendered":"https:\/\/blog.forumias.com\/?p=199330"},"modified":"2022-08-09T17:34:03","modified_gmt":"2022-08-09T12:04:03","slug":"data-protection-framework-in-india","status":"publish","type":"post","link":"https:\/\/forumias.com\/blog\/data-protection-framework-in-india\/","title":{"rendered":"Data Protection Framework in India &#8211; Explained, pointwise"},"content":{"rendered":"\n<table style=\"width: 100%; border-collapse: collapse; background-color: #f7f2f2;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\">For\u00a0<strong>7PM Editorial<\/strong>\u00a0Archives click<strong>\u00a0<a href=\"https:\/\/forumias.com\/blog\/7-pm-editorials\/\" target=\"_blank\" rel=\"noopener\">HERE <\/a>\u2192<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h5>Introduction<\/h5>\n<p><span style=\"font-weight: 400;\">The Union Government has withdrawn the Personal Data Protection Bill, 2019 from the Parliament. The Government has said that it is considering a &#8216;comprehensive legal framework&#8217; to regulate the online space. This includes bringing separate laws on data privacy, the overall Internet ecosystem, cybersecurity, telecom regulations, and harnessing non-personal data to boost innovation in the country. <\/span><span style=\"font-weight: 400;\">The Government has withdrawn the Bill after nearly 4 years of the Bill being in the works. It had gone through multiple iterations, including a review by a Joint Parliamentary Committee (JPC). The Bill had faced major pushback from a range of stakeholders including big tech companies (like Facebook and Google), privacy and civil society activists.<\/span><\/p>\n<p>The <span style=\"font-weight: 400;\">Joint Committee of Parliament had proposed 81 amendments to the Bill and gave 12 recommendations on creating a comprehensive legal framework for the digital ecosystem in India. The Government will consider the report of the JPC and work on the new framework.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-199396 aligncenter\" src=\"https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?resize=750%2C404&#038;ssl=1\" alt=\"Timeline of the Personal Data Protection Bill 2019 UPSC\" width=\"750\" height=\"404\" srcset=\"https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?resize=1024%2C552&amp;ssl=1 1024w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?resize=300%2C162&amp;ssl=1 300w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?resize=768%2C414&amp;ssl=1 768w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?resize=1536%2C829&amp;ssl=1 1536w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?resize=1568%2C846&amp;ssl=1 1568w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Time-of-Personal-Data-Protection-Bill.jpeg?w=1822&amp;ssl=1 1822w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<h5>What were the key provisions of the Personal Data Protection Bill, 2019?<\/h5>\n<p><b>Personal data definition: <\/b><span style=\"font-weight: 400;\">The Bill defined \u2018personal data\u2019 as any information which renders an individual identifiable. Also, it defined data \u2018processing\u2019 as collection, manipulation, sharing or storage of data.<\/span><\/p>\n<p><b>Territorial applicability<\/b><span style=\"font-weight: 400;\">: The Bill included the processing of personal data by both government and private entities incorporated in India. It also covered the entities incorporated overseas if they systematically deal with data principals within the territory of India.<\/span><\/p>\n<p><b>Grounds for data processing:<\/b><span style=\"font-weight: 400;\"> The Bill allowed data processing by fiduciaries if consent was provided by the individual.<\/span><\/p>\n<p><b>Sensitive personal data: <\/b><span style=\"font-weight: 400;\">It included passwords, financial data, biometric and genetic data, caste, religious or political beliefs. The Bill specifies more stringent grounds for the processing of sensitive personal data, such as seeking explicit consent of an individual prior to processing.<\/span><\/p>\n<p><b>Data Protection Authority:<\/b><span style=\"font-weight: 400;\"> The Bill provided for the establishment of a Data Protection Authority (DPA). The DPA would have been empowered to: <strong>(a)<\/strong>\u00a0<\/span><span style=\"font-weight: 400;\">Draft specific regulations for all data fiduciaries across different sectors; <strong>(b) <\/strong><\/span><span style=\"font-weight: 400;\">Supervise and monitor data fiduciaries.<\/span><\/p>\n<p><b>Cross-border storage of data<\/b><span style=\"font-weight: 400;\">: The Bill stated that every fiduciary shall keep a \u2018serving copy\u2019 of all personal data in a server or data centre located in India.<\/span><\/p>\n<p><b>Transfer of data outside the country<\/b><span style=\"font-weight: 400;\">: Personal data (except sensitive personal data which is \u2018critical\u2019) may be transferred outside India under certain circumstances.<\/span><\/p>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><strong>Read More<\/strong>: <a href=\"https:\/\/forumias.com\/blog\/draft-personal-data-protection-bill\/\" target=\"_blank\" rel=\"noopener\">Draft Personal Data Protection Bill \u2013 Explained, pointwise<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h5>What was the criticism of the Bill?<\/h5>\n<p><b>First<\/b><span style=\"font-weight: 400;\">, the technology companies had questioned a proposed provision in the Bill called<\/span><b> data localisation<\/b><span style=\"font-weight: 400;\">. Under this, it would have been mandatory for companies to store a copy of certain sensitive personal data within India, and the export of undefined \u201ccritical\u201d personal data from the country would be prohibited.\u00a0<\/span><\/p>\n<p><b>Second<\/b><span style=\"font-weight: 400;\">, the activists had criticized the provisions that allowed the Union government and its agencies<\/span><b> blanket exemptions<\/b><span style=\"font-weight: 400;\"> from adhering to any and all provisions of the Bill.<\/span><\/p>\n<h5>What were the recommendations of the Joint Parliamentary Committee?<\/h5>\n<p><span style=\"font-weight: 400;\">The JPC had called for expanding the scope of the proposed law to <\/span><b>cover discussions on non-personal data<\/b><span style=\"font-weight: 400;\">. It had thus changed the mandate of the Bill from personal data protection to broader data protection. Non-personal data are any set of data that does not contain personally identifiable information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It had recommended changes on issues such as regulation of social media companies, and on <\/span><b>using only \u201ctrusted hardware\u201d in smartphones,<\/b><span style=\"font-weight: 400;\"> etc.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It proposed that <\/span><b>social media companies that do not act as intermediaries<\/b><span style=\"font-weight: 400;\"> should be treated as content publishers \u2014 making them liable for the content they host.<\/span><\/p>\n<h5>What is the need for Data Protection Law in India?<\/h5>\n<p><b>First<\/b><span style=\"font-weight: 400;\">, India has one of the<\/span><b> highest numbers of data breaches<\/b><span style=\"font-weight: 400;\"> each year and many sites, both government and private, suffer from data losses and leaks. Recently, data of almost 28 crore Indian citizens registered in the Employees\u2019 Provident Fund Organization (EPFO) were leaked online. This included sensitive information like full name, nominee details, Aadhaar details, bank account details, etc.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><b>Second<\/b>, With a billion population, India has the second highest internet user base in the world. India has 450 million internet users and is expected to increase up to 730 million by 2020. Therefore, a strong data protection law is needed to protect their personal data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><b>Third<\/b>, for efficient management of data in the age of digitisation, a data protection law is needed. One of the major challenges to big data is information privacy which necessitates a robust data protection. <\/span><span style=\"font-weight: 400;\">Further, the Supreme Court (SC) in <\/span><b><em>K.S Puttaswamy vs Union of India<\/em> case, <\/b><span style=\"font-weight: 400;\">maintained the<\/span><b> right to privacy<\/b><span style=\"font-weight: 400;\"> as an inherent part of the fundamental right under Article 21 of the constitution.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><b>Fourth<\/b>, the delay will result in an <\/span><b>unnecessary vacuum for many of the laws <\/b><span style=\"font-weight: 400;\">already taking shape, like the Criminal Procedure Identification Act used for police surveillance and digital policing.\u00a0<\/span><\/p>\n<p><b>Fifth<\/b><span style=\"font-weight: 400;\">, To curtail the perils of unregulated and arbitrary use of personal data. As most of the servers like Google and Facebook are outside India.<\/span><\/p>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><strong>Read More<\/strong>: <a href=\"https:\/\/forumias.com\/blog\/data-protection-privacy-core-tenets\/\" target=\"_blank\" rel=\"noopener\">Data protection and privacy core tenets<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h5>What is the status of Data Protection in other Nations?<\/h5>\n<p><b>The EU<\/b><span style=\"font-weight: 400;\">: The most important data protection legislation enacted to date is the\u00a0<\/span><span style=\"font-weight: 400;\">General Data Protection Regulation (GDPR). It governs the collection, use, transmission, and security of data collected from residents of any of the 28 member countries of the European Union.\u00a0<\/span><span style=\"font-weight: 400;\">The law applies to all EU residents, regardless of the entity&#8217;s location that collects the personal data. Fines of up to \u20ac 20 million or 4% of total global turnover may be imposed on organizations that fail to comply with the GDPR. Some important requirements of the GDPR include: <strong>(a)<\/strong> <strong>Consent<\/strong>: <\/span><span style=\"font-weight: 400;\">Data subjects must be allowed to give explicit, unambiguous consent before the collection of personal data; <strong>(b)<\/strong> <strong>Data Breach<\/strong>:\u00a0<\/span><span style=\"font-weight: 400;\">Organizations are required to notify supervisory authorities and data subjects within 72 hours in the event of a data breach affecting users&#8217; personal information in most cases; <strong>(c)<\/strong> <strong>Rights of the Users<\/strong>: <\/span><span style=\"font-weight: 400;\">Data subjects (people whose data is collected and processed) have certain rights regarding their personal information.\u00a0<\/span><\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-199401 aligncenter\" src=\"https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?resize=750%2C385&#038;ssl=1\" alt=\"Rights of the Users under the GDPR UPSC\" width=\"750\" height=\"385\" srcset=\"https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?resize=1024%2C526&amp;ssl=1 1024w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?resize=300%2C154&amp;ssl=1 300w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?resize=768%2C395&amp;ssl=1 768w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?resize=1536%2C789&amp;ssl=1 1536w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?resize=1568%2C806&amp;ssl=1 1568w, https:\/\/i0.wp.com\/forumias.com\/blog\/wp-content\/uploads\/2022\/08\/Rights-of-Users-under-the-GDPR.jpeg?w=1810&amp;ssl=1 1810w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<p><span data-preserver-spaces=\"true\">The <strong>e-Privacy Regulation (ePR)<\/strong> was supposed come into force alongside the EU\u2019s General Data Protection Regulation in 2018 but has been stalled for years. It is now expected to come to force in 2023. <\/span><span data-preserver-spaces=\"true\">The e-Privacy Regulation, if passed, would create privacy rules for traditional electronic communications services and entities such as WhatsApp, Facebook Messenger, and Skype. <\/span><span data-preserver-spaces=\"true\">It would create <strong>stronger rules on electronic <\/strong><\/span><span data-preserver-spaces=\"true\"><strong>communication\u2019s privacy<\/strong>. It would cover content of the communications as well as metadata.<\/span><span data-preserver-spaces=\"true\"> Service providers and electronic communications networks have to get prior consent from the user before processing their electronic communications metadata.\u00a0<\/span><\/p>\n<p><b>The US:<\/b><span style=\"font-weight: 400;\"> There is no one comprehensive federal law that governs data privacy in the U.S. There&#8217;s a complex patchwork of sector-specific and medium-specific laws like: <\/span><span style=\"font-weight: 400;\"><strong>(a)<\/strong>The Children&#8217;s Online Privacy Protection Act (COPPA), which governs the collection of information about minors; <strong>(b)<\/strong>\u00a0<\/span><span style=\"font-weight: 400;\">The Health Insurance Portability and Accounting Act (HIPAA), which governs the collection of health information. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, many States in the US have their own data protection and privacy acts like <\/span>California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Virginia&#8217;s Consumer Data Protection Act (CDPA), Colorado Privacy Act (CPA), New York SHIELD Act etc.<\/p>\n<h5>What should be done going ahead?<\/h5>\n<p>Legal and Privacy Experts have proposed that:<\/p>\n<p><b>First<\/b><span style=\"font-weight: 400;\">, the new Law should focus on personal data and <strong>exclude non-personal data<\/strong>. Personal data protection falls in domain of privacy and allows an individual to control how information about her is used. Non-personal data regulation more related to economic aims. The mandate of BN Srikrishna Committee was to suggest framework for protection of personal data. Brining in non-personal data, the Government had diluted the proposed law.<\/span><\/p>\n<p><strong>Second<\/strong>, there must be <strong>checks on the use of the data by the Government<\/strong> and its Agencies. Privacy advocates have been calling for reform of Indian surveillance laws. The new law must<span id=\"articlecardpara\" class=\"mt-2 mb-5\"> minimize the amount of data collected by security agencies, limiting how long it can be stored, requiring agencies to adopt security measures to safeguard the data.<\/span><\/p>\n<p><strong>Third<\/strong>, there is a <strong>need for a strong data regulator<\/strong>. The new regulator should work closely with other regulators and stakeholders like the RBI, TRAI etc. for sector specific regulations e.g., RBI has already issued some data related regulations like\u00a0mandating local storage of payments data, barring merchants and payment aggregators from storing card data.<\/p>\n<p><strong>Fourth<\/strong>, the Government should also <strong>allow cross-border flow of data<\/strong>. Data localisation should be limited only to clearly and narrowly defined critical data. Cross-border data flows add to the economy growth. A McKinsey Global Institute paper from 2016 estimates that global data flows contributed US$ 2. 8 trillion to the global GDP.<\/p>\n<p><b>Fifth<\/b><span style=\"font-weight: 400;\">, the new legal framework should be finalized only after <strong>extensive public consultation<\/strong>. <\/span><span style=\"font-weight: 400;\">This will ensure that the protection of the rights of Indian citizens is the cornerstone on which this new legal framework is built.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It has been close to 10 years since the (Justice) A P Shah Committee Report on privacy, 5 years since the Puttaswamy Judgment and 4 years since the Justice B N Srikrishna Committee\u2019s Report. All of this signals an urgency for a data protection law and surveillance reforms.<\/span><\/p>\n<p><strong>Syllabus<\/strong>: GS II, Government policies and interventions for development in various sectors and issues arising out of their design and implementation; GS III, Awareness in the field of IT.<\/p>\n<p><strong>Source<\/strong>: <a href=\"https:\/\/indianexpress.com\/article\/explained\/explained-sci-tech\/personal-data-protection-bill-withdrawal-reason-impact-explained-8070495\/\" target=\"_blank\" rel=\"noopener\">Indian Express<\/a>, <a href=\"https:\/\/www.thehindu.com\/opinion\/editorial\/a-fresh-opportunity-the-hindu-editorial-on-governments-withdrawal-of-the-personal-data-protection-bill-2019-and-after\/article65733197.ece\" target=\"_blank\" rel=\"noopener\">The Hindu<\/a>, <a href=\"https:\/\/timesofindia.indiatimes.com\/blogs\/toi-edit-page\/what-a-new-data-law-must-have-here-are-the-five-key-points-goi-should-remember-while-re-drafting-the-bill\/\" target=\"_blank\" rel=\"noopener\">The Times of India<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For\u00a07PM Editorial\u00a0Archives click\u00a0HERE \u2192 Introduction The Union Government has withdrawn the Personal Data Protection Bill, 2019 from the Parliament. The Government has said that it is considering a &#8216;comprehensive legal framework&#8217; to regulate the online space. This includes bringing separate laws on data privacy, the overall Internet ecosystem, cybersecurity, telecom regulations, and harnessing non-personal data&hellip; <a class=\"more-link\" href=\"https:\/\/forumias.com\/blog\/data-protection-framework-in-india\/\">Continue reading <span class=\"screen-reader-text\">Data Protection Framework in India &#8211; Explained, pointwise<\/span><\/a><\/p>\n","protected":false},"author":10322,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[130,9],"tags":[],"class_list":["post-199330","post","type-post","status-publish","format-standard","hentry","category-7-pm","category-public","entry"],"jetpack_featured_media_url":"","views":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/posts\/199330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/users\/10322"}],"replies":[{"embeddable":true,"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/comments?post=199330"}],"version-history":[{"count":0,"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/posts\/199330\/revisions"}],"wp:attachment":[{"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/media?parent=199330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/categories?post=199330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forumias.com\/blog\/wp-json\/wp\/v2\/tags?post=199330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}