May 02,2022 | 5 min read

Data Privacy vis a vis Legal Developments

Introduction

“Right to Privacy” was declared a fundamental right in India in a landmark judgment by the Hon'ble Supreme Court of India on August 24, 2017, in the case of Justice K.S. Puttaswamy (Retd.) and Anr. v. Union of India And Ors. The judgment brought a change in the privacy regime in India, i.e. the need to protect the personal data and the privacy of the individuals through a proper codification of the law. Accordingly, a progressive step was adopted by the Central Government by appointing a data protection committee chaired by the retired judge of the Supreme Court, i.e. Justice Srikrishna, who released an extensive white paper on the protection of the data privacy and subsequently, in July 2018, the committee came up with the draft bill on Personal Data Protection Bill, 2018. Thereafter, with the stakeholders’ recommendation and some modifications, the bill was laid before the lower house of the parliament in the year 2019 and is pending before the house currently.

Since 2021, the government has been active in protecting the data and privacy of individuals. The coordination between legislation and the executive has paved the way for privacy laws development. Therefore, with this background, the Indian government has brought significant changes such as liberalising the archaic geospatial data regime, introducing industry standards for privacy assurance, and introducing tighter security measures in the digital payments sector.

While on the other hand, the judiciary has been active enough to pronounce the judgments related to the issues of anonymity, the right to be forgotten, and state surveillance.

The Legal Developments related to Privacy and Data Protection law from 2021:

1. Data Protection Law:

The proposed data protection law, along with the revised version, was presented by the Joint Parliamentary Committee in the parliament in 2021. The Data Protection Bill, 2021, is yet to be considered and will be passed by the parliament. The stakeholders are calling for a fresh consultation and bringing the new changes as compared to the earlier iterations of the proposed law, such as expanding the scope of the law to cover not only personal data but also non-personal data. The stakeholders are asking for the phased implementation of the enactments under the act.

2. Geospatial Data and Map Services:

The Department of Science and Technology has issued the guidelines regarding “Acquiring and producing geospatial data and geospatial data services including Maps”. Prior to such notification, there were several guidelines and notifications published from various ministries/ departments of the Government of India, inclusive of the Ministry of Defence, Survey of India, Ministry of Finance and Ministry of External Affairs regulating mapping data etc., which were mostly unclear and archaic in form. With the new regulation in place, the requirement of any approval, clearance, license, etc. on the collection, generation, preparation, dissemination, storage, publication, updating and digitisation of geospatial data and maps within the territory of India, is subject to a negative list of attributes for which there are restrictions has been dispensed with.

Further, regulation restricts foreign entities from creating and owning or hosting geospatial data finer than specific prescribed threshold values. The new notification bans the foreign entities from conducting the terrestrial mobile mapping surveys, street view surveys and surveys in Indian territorial waters.

3. Banking Regulation in Card Data Storage:

The Reserve Bank of India (RBI) has laid down the guidelines regarding the regulation of the payment aggregator or payment gateways in order to create a license and regulate the payment intermediaries thereby facilitating and handling the payment between both the parties i.e. users and the merchants via electronic modes. With the strict guidelines in place, the RBI has put restrictions on the intermediaries and the merchants regarding the storing of card and card-related data. A circular was issued on behalf of the RBI regarding this on September 7, 2021, mandating that from January 1, 2022, (a) no entity other than card issuers or card networks is allowed to store card data, and (b) all such data previously-stored should be purged. As an exemption, the last 4 digits of the card number and the card issuer’s name could be stored for transaction tracking and reconciliation purposes.

4. The Data Privacy Standard:

The Bureau of Indian Standards has declared to the public the new standards regarding data privacy protection. As per the latest standards laid they seek to provide a privacy issue framework for all the institutions in order to establish, implement, maintain and continually improve their data privacy management system. Under the new law regime, the processors and data fiduciaries are required to implement the security safeguards and use any or all methods like de-identification, encryption, steps to protect personal data integrity and to prevent misuse, unauthorized access, modification, disclosure or destruction of personal data.

5. Whatsapp privacy Policy:

WhatsApp LLC has updated its privacy policy and terms of service in January 2021. As per the new update in the policy, the user needs to share the data with Facebook in order to continue using the services of WhatsApp. This, as an issue, was taken up by the competition commission of India and an investigation was initiated against WhatsApp, Inc. and Facebook, Inc. accessing the impact on the competitive market in the Indian market. The matter went into appeal before the Delhi High Court, wherein it was upheld that “the impleadment of Facebook, Inc. deeming it to be an integral part of the investigation”.

Conclusion:

With such amendments, notifications, and rules in place, India may emerge as a country that is bent on protecting the data and the privacy of the individuals the priority. The year 2022 may become a landmark year in which the country may see its first comprehensive, general data protection law introduced. The bill can be tabled any sooner in the parliament's upcoming sessions. It may also happen that fresh consultations could happen, which would lead to significant changes/modifications in the draft bill. It would be noteworthy to watch how the government would propose the bill and protect and balance the national interest and security.

 

Reference:

1. https://www.mondaq.com/india/privacy-protection/1146570/update-on-data-protection-law

2. https://www.natlawreview.com/article/privacy-data-protection-capsule-india-s-turn-world-stage

3. https://digitalindia.gov.in/writereaddata/files/6.Data%20Protection%20in%20India.pdf

4. https://iapp.org/news/a/a-look-at-proposed-changes-to-indias-personal-data-protection-bill/


Need Free Legal Advice or Assistance Online?


For any Cyber Laws related matter, please Post Your Requirement anonymously and get free proposals OR find the Best Cyber Laws Lawyers and book a free appointment directly.


POPULAR READS

Employee Handbook | Download Free Template


IP Assignment Agreement | Dowload Free Template


MEDICAL NEGLIGENCE | CONSUMER PROTECTION ACT, 2019 | Guest Series by Lawyered


Trademark: Law for Globalizing Trade


MEDICAL NEGLIGENCE IN INDIA | CONSUMER PROTECTION ACT, 2019 | Guest Series by Lawyered


Recovery | Summary Suits | Commercial Courts Act


Rules and Regulations for Driver's Welfare


Article 35A | Indian Constitution | Property ownership of J&K Citizens


Application u/s 11 of Arbitration Act


ABOUT THE AUTHOR



Team Lawyered

Lawyered is a legal tech initiative designed to change the way people interact with and within the legal industry. We believe that access to critical services like legal should be just a click away. Our team is working to bring legal online, making it cost effective, high quality and accessible for all.

MORE IN BUSINESS

DATA PRIVACY LAWS

Mar 12,2022 | 5 min read

How to Invest in Blockhchain in India?

Sep 25,2021 | 5 min read