You are on page 1of 2

Report Summary

A Free and Fair Digital Economy


 The Committee of Experts on a Data Protection and exposure to risks online. Further, sensitive
Framework for India (Chair: Justice B. N. personal information should require explicit
Srikrishna) submitted its report and draft Bill to consent of the individual.
the Ministry of Electronics and Information
 Non-consensual processing: The Committee
Technology on July 27, 2018. The Committee
noted that it is not possible to obtain consent of
was constituted in August, 2017 to examine
the individual in all circumstances. Therefore,
issues related to data protection, recommend
separate grounds may be established for
methods to address them, and draft a data
processing data without consent. The Committee
protection Bill.
identified four bases for non-consensual
 Fiduciary relationship: The Committee processing: (i) where processing is relevant for
observed that the regulatory framework has to the state to discharge its welfare functions, (ii) to
balance the interests of the individual with regard comply with the law or with court orders in India,
to his personal data and the interests of the entity (iii) when necessitated by the requirement to act
such as a service provider who has access to this promptly (to save a life, for instance), and (iv) in
data. It noted that the relationship between the employment contracts, in limited situations (such,
individual and the service provider must be as where giving the consent requires an
viewed as a fiduciary relationship. This is due to unreasonable effort for the employer).
the dependence of the individual on the service
 Participation rights: The rights of the
provider to obtain a service. Therefore, the
individual are based on the principles of
service provider processing the data is under an
autonomy, self-determination, transparency and
obligation to deal fairly with the individual’s
accountability to give individuals control over
personal data, and use it for the authorised
their data. The Committee categorised these
purposes only.
rights in three categories: (i) the right to access,
 Obligations of fiduciaries: To prevent abuse of confirmation and correction of data, (ii) the right
power by service providers, the law should to object to data processing, automated decision-
establish their basic obligations, including: (i) the making, direct marketing and the right to data
obligation to process data fairly and reasonably, portability, and (iii) the right to be forgotten.
and (ii) the obligation to give notice to the
 Enforcement models: The Committee also
individual at the time of collecting data to various
recommended setting up a regulator to enforce
points in the interim.
the regulatory framework. The Authority will
 Definition of personal data: The Committee have the power to inquire into any violations of
noted that it is important to define what the data protection regime, and can take action
constitutes personal information. It defined against any data fiduciary responsible for the
personal data to include data from which an same. The Authority may also categorise certain
individual may be identified or identifiable, either fiduciaries as significant data fiduciaries based on
directly or indirectly. The Committee sought to their ability to cause greater harm to individuals.
distinguish personal data protection from the Such fiduciaries will be required to undertake
protection of sensitive personal data, since its additional obligations.
processing could result in greater harm to the
 Amendments to Other Laws: The Committee
individual. Sensitive data is related to intimate
noted that various allied laws are relevant in the
matters where there is a higher expectation of
context of data protection because they either
privacy (e.g., caste, religion, and sexual
require or authorise the processing of personal
orientation of the individual).
data. These laws include the Information
 Consent-based processing: The Committee Technology Act, 2000, and the Census Act, 1948.
noted that consent must be treated as a pre- It stated that the Bill provides minimum data
condition for processing personal data. Such protection standards for all data processing in the
consent should be informed or meaningful. country. In the event of inconsistency, the
Further, for certain vulnerable groups, such as standards set in the data privacy law will apply to
children, and for sensitive personal data, a data the processing of data. The Committee also
protection law must sufficiently protect their recommended amendments to the Aadhaar Act,
interests, while considering their vulnerability, 2016 to bolster its data protection framework.

Roshni Sinha August 1, 2018


roshni@prsindia.org
PRS Legislative Research  Institute for Policy Research Studies
3rd Floor, Gandharva Mahavidyalaya  212, Deen Dayal Upadhyaya Marg  New Delhi – 110002
Tel: (011) 43434035-36, 23234801-02  www.prsindia.org
A Free and Fair Digital Economy PRS Legislative Research

Bill Summary
The Draft Personal Data Protection Bill, 2018
 Rights of the individual: The Bill sets out allowed on certain grounds, including: (i) based
certain rights of the individual. These include: on explicit consent of the individual, (ii) if
(i) right to obtain confirmation from the necessary for any function of Parliament or
fiduciary on whether its personal data has been state legislature, or, if required by the state for
processed, (ii) right to seek correction of providing benefits to the individual, or (iii) if
inaccurate, incomplete, or out-of-date personal required under law or for the compliance of any
data, and (iii) right to have personal data court judgement.
transferred to any other data fiduciary in certain
 Sensitive personal data includes passwords,
circumstances.
financial data, biometric data, genetic data,
 Obligations of the data fiduciary: The Bill caste, religious or political beliefs, or any other
sets out obligations of the entity who has access category of data specified by the Authority.
to the personal data (data fiduciary). These Additionally, fiduciaries are required to institute
include: (i) implementation of policies with appropriate mechanisms for age verification and
regard to processing of data, (ii) maintaining parental consent when processing sensitive
transparency with regard to its practices on personal data of children.
processing data, (iii) implementing security
 Transfer of data outside India: Personal data
safeguards (such, as encryption of data), and
(except sensitive personal data) may be
(iv) instituting grievance redressal mechanisms
transferred outside India under certain
to address complaints of individuals.
conditions. These include: (i) where the central
 Data Protection Authority: The Bill provides government has prescribed that transfers to a
for the establishment of a Data Protection particular country are permissible, or (ii) where
Authority. The Authority is empowered to: (i) the Authority approves the transfer in a
take steps to protect interests of individuals, (ii) situation of necessity.
prevent misuse of personal data, and (iii) ensure
 Exemptions: The Bill provides exemptions
compliance with the Bill. It will consist of a
from compliance with its provisions, for certain
chairperson and six members, with knowledge
reasons including: (i) state security, (ii)
of at least 10 years in the field of data protection
prevention, investigation, or prosecution of any
and information technology. Orders of the
offence, or (iii) personal, domestic, or
Authority can be appealed to an Appellate
journalistic purposes.
Tribunal established by the central government
and appeals from the Tribunal will go to the  Offences and Penalties: Under the Bill, the
Supreme Court. Authority may levy penalties for various
offences by the fiduciary including (i) failure to
 Grounds for processing personal data: The
perform its duties, (ii) data processing in
Bill allows processing of data by fiduciaries if
violation of the Bill, and (iii) failure to comply
consent is provided. However, in certain
with directions issued by the Authority. For
circumstances, processing of data may be
example, under the Bill, the fiduciary is
permitted without consent of the individual.
required to notify the Authority of any personal
These grounds include: (ii) if necessary for any
data breach which is likely to cause harm to the
function of Parliament or state legislature, or if
individual. Failure to promptly notify the
required by the state for providing benefits to
Authority can attract a penalty of the higher of
the individual, (iii) if required under law or for
Rs 5 crore or 2% of the worldwide turnover of
the compliance of any court judgement, (iv) to
the fiduciary.
respond to a medical emergency, threat to
public health or breakdown of public order, or,  Amendments to other laws: The Bill makes
(v) for reasonable purposes specified by the consequential amendments to the Information
Authority, related to activities such as fraud Technology Act, 2000. It also amends the Right
detection, debt recovery, and whistle blowing. to Information Act, 2005, and to permit non-
disclosure of personal information where harm to
 Grounds for processing sensitive personal
the individual outweighs public good.
data: Processing of sensitive personal data is
DISCLAIMER: This document is being furnished to you for your information. You may choose to reproduce or redistribute this report for
non-commercial purposes in part or in full to any other person with due acknowledgement of PRS Legislative Research (“PRS”). The
opinions expressed herein are entirely those of the author(s). PRS makes every effort to use reliable and comprehensive information, but
PRS does not represent that the contents of the report are accurate or complete. PRS is an independent, not-for-profit group. This document
has been prepared without regard to the objectives or opinions of those who may receive it.

-2-

You might also like