Analysis: Data Protection in India

3 min read

The government of India recently informed the Supreme Court of India that it expects to put in place a comprehensive data protection framework by October. The Telecom Regulatory Authority of India will be heading up the initiative and has already started consultations for preparing a draft framework.

The government on April 5 acknowledged that there was no proper regulatory framework to deal with privacy concerns of citizens arising out of “over-the-top” popular messaging services such as Whatsapp, Facebook and Skype. Consequently, the Department of Telecommunications is exploring creating a “regulatory framework” through legislation to address data protection and citizens’ privacy concerns.

With the European Union already preparing to enforce its General Data Protection Regulation next year, India may be late to the party. But the need for a data protection and privacy law in India is pressing. And when it’s enacted, it will define provisions for protecting sensitive personally identifiable information and spell out liabilities in the event PII gets breached.

Many security practitioners, however, say the government’s goal of having a law by October seems aggressive (see: Why India is Still Not Ready for Breach, Privacy Laws).

Shivangi Nadkarni, co-founder & CEO at Arrka Consulting, points out that once the government publishes a draft regulation for public comment, it must allow two months for gathering feedback. “It has to align with the schedule of the Monsoon Session of Parliament if it has to meet the October deadline,” Nadkarni says (see: It’s Time to get Serious About Privacy).

India already has some data protection and privacy provisions in the Information Technology Act 2000, amended in 2008 and the subsequent IT rules defined in 2011. But the IT Act 2000/8 doesn’t define sensitive personal information directly and only provides guidance for reasonable security practice and due diligence – the actual implementation standards have not been explicitly prescribed, says Bengaluru-based Na. Vijayashankar, a cyber law expert and information risk consultant.

The current data protection regime is under section 43A of the IT Act 2000/8, and the regulations made thereunder, says Pranesh Prakash, policy director at Bengaluru-based research think tank the Center for Internet and Society. He contends those regulations are weak, do not specify any governmental agency, and do not lay out penalties for violations. Other relevant provisions, such as section 72A, are also far too onerous and aren’t ever applied in practice to such cases, he says (see: Pavan Duggal on Why India‘s Cyberlaw Must Rapidly Evolve).

“Section 43A and the ‘reasonable security rules’ didn’t change much, given the lack of teeth in the regulations, and the onerous job of proving “wrongful gain or wrongful loss” of property due to data breaches,” Prakash says. In addition, as a complement to a strong, yet flexible, data protection/data security regime, the government also needs to put in a privacy regime that covers both the private and public sectors, he adds.

India lacks a clear framework that categorically recognizes the sanctity of privacy, says J. Sai Deepak, an independent cyber law expert and arguing counsel at the Delhi High Court.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at bankinfosecurity.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.