We value your privacy & take necessary steps to protect your information.
REQUEST A CALLBACK
Why data protection:
In the landmark judgment of Justice K.S. Puttaswamy vs. Union of India, the Hon’ble Supreme Court of India explicitly recognised and laid down that right to privacy is a fundamental right under Article 21 of the Indian Constitution. Accordingly, every person including an individual, company/firm/association, a Hindu undivided family, state and every artificial juristic person (“Data Principal”), is entitled to the right of privacy which also encompasses the right to protection of personal data.
Personal data refers to any data that helps in identifying a person and breach of the same in any form of unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access may compromise the data’s confidentiality, integrity or availability, which can cause prejudice to such a person in terms of financial losses, reputational damage, legal issues, regulatory fine and breach of consumer trust. Thus, the person collecting personal data (“Data Fiduciary”) is obligated to undertake appropriate measures and avoid such breach. Accordingly, the Companies have been bestowed with additional responsibility as custodians for following proper procedure while collecting data, ensuring proper use within permissible limits and safeguarding such data. This article seeks to give a brief overview of all the requisite data protection compliances that need to be undertaken by Indian companies to fulfil this responsibility.
Legal framework:
The Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (”SPDI”) impose obligations on Data Fiduciaries including a company or a person located in India to implement strong data protection measures and safeguards for protecting the individual’s sensitive personal data i.e. bank account details, present and past health records, passwords, sexual orientation, biometric data, credit/debit card details . However, given the ongoing and probable data breaches/misuse, especially in the digital era, the need for a comprehensive and stricter data protection law was felt by the Indian parliament and hence the Digital Personal Data Protection Act, 2023 (“DPDPA”) was enacted on August 11, 2023, which is soon to come in force. Once it comes into force, the SPDI Rules will no longer be applicable and only DPDPA will regulate the process of data sharing/collection and processing in India. Thus, it is important to analyse the compliances and consequences laid down in DPDPA.
Every Indian company, as a Data Fiduciary must comply with the DPDPA and implement appropriate technical and organisational measures to ensure effective observance of the provisions of the DPDPA and the rules made thereunder. This approach must be adopted for the purpose of ensuring data protection of the company itself, its employees and its clients through contractual arrangements and its internal policies.
No right is absolute:
The DPDPA has adopted a balanced approach by providing for processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes . Thus, few exceptions have been carved out in the DPDPA whereby the data of Data Principals can be processed without obtaining their explicit consent. This is where the DPDPA differs from the European Union’s General Data Protection Regulation (GDPR), which has a higher standard of data protection as the same requires obtaining of explicit consent without exceptions.
DPDPA applies to processing of personal data in digital form or personal data collected physically but digitised subsequently, within the territory of India. It also applies to digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. DPDPA mandates a Data Fiduciary to obtain consent of Data Principals before processing their data. However, this obligation does not apply in the following situations: (1) Personal data processed by the Data Principal for personal or domestic purpose; (2) Publicly available personal data; (3) Processing of personal data for “legitimate uses ” including the following situations, wherein consent is deemed to be given even if not obtained explicitly:
(a) cases where the Data Principals have voluntarily provided personal data to the company and in respect of which they have not indicated that they do not consent to the use of such personal data; and
(b) cases where processing is necessary for: (i) for fulfilling obligations under any law or compliance with orders issued by courts; (ii) for responding to medical emergency involving threat to the life or immediate threat to the health of the Data Principal or any other individual; (iii) for performance of functions by the State or any of its instrumentalities under any law or in the interest of sovereignty and integrity of India or security of the State; (iv) for providing medical treatment or health services during an epidemic, outbreak of disease, or other threat to public health; (v) for ensuring safety/providing assistance/services during any disaster or a breakdown of public order; and (vi) for employment related purposes for safeguarding the employer/company from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.
The DPDPA also provides for duties of the Data Principal (employees/clients) to provide authentic data and not to file frivolous complaints.
Compliance, not a choice but a must:
Every company located in India is required to comply with the DPDPA and fulfil its obligations explained below:
What’s at stake?
Even though the DPDPA does not contain a private right of action, a company may be liable for non-compliance and payment of penalty (which may extend up to Rs. 250 crores) depending on the nature of breach and its gravity. It is pertinent to note that the process of litigation and appellate procedure, as provided under the DPDPA, may take longer and there is a high risk of reputation loss. To avoid heavy penalties and reputation loss or business loss, a company must implement DPDPA for protecting personal data of its employees and customers/clients. The company must also protect its own rights while entering contractual arrangements with other organisations as not incorporating specific clauses pertaining to data protection in the contract, may jeopardise the business interest or reputation of the Company.
Way forward:
The author feels that even though the DPDPA provides a comprehensive framework for data protection, it does not address the following:
The above issues need to be clarified by way of an amendment or notification.