Articles /Vol. 6 No. 5 (2024) /PP. 63-76

Data Privacy in Contemporary India

Lead author · Corresponding
Shruti Kanherkar
Student at Banasthali Vidyapith, Rajasthan, India
Co-author
Sakshi Parashar
Student at Banasthali Vidyapith, Rajasthan, India
370 views
231 downloads
Abstract

This paper studies and analyses the current data privacy laws. The paper aims to understand the extent to which the data privacy laws in India effective on the ground. It further discusses the problem of data leak and cyber security in the Indian context by looking into the major cyber-attacks that took a toll on Indian consumer base within the last 5 years. The paper provides an understanding regarding the emerging concept of data privacy and provide constructive critical analysis regarding the loopholes and gaps that are being exploited by parties with malicious intent to harm, illegally attain, use, sell the data of Indian customers. We as individuals hold a critical stake in data-privacy laws as the world becomes data-sensitive. The data can be used for multiple illegal activities resulting in direct legal injuries to us. The paper delves into a thorough study regarding the evolution of the concept of data privacy, the emergence of data-privacy laws in India and the current problems that poses threat to the data privacy of Indian citizens.

Keywords
Data Privacy Internet Data Protection Third-Party Apps
Full Text

I. Introduction

If you put a key under the mat for the cops, a burglar can find it too. Criminals are using every technology tool at their disposal to hack people’s accounts. If they know there’s a key hidden somewhere, they won’t stop until they find it”- Tim Cook, CEO, of Apple.

With the advancement of technology, the internet has become the fourth necessity of life. We use the internet in everyday usage for multiple tasks ranging from personal entertainment to academic and office work. Every click, every link, every site and every pop-up that we go through with the innocent impression of data protection from any third undesirable party is not as true as we thought it should be. Any time you click on a link it gives the second party access to your information. The catch in the above statement is that the extent of the information accessed by the second party is not defined. On April, 30th of 1993, when the Internet was first made accessible to the general public, CERN designed it intending to assist scientists at universities and institutions across the globe to share information automatically with increased promptness and accuracy.

In 1993, the concept of data privacy was not a ground of debate, but the last three decades have seen a significant change in the scenario. The Tech Industry has transmuted the concept of the internet. A vision whose seed was just confined in the pot of science and academics has spread its roots into multiple domains. The accessibility of the internet is far easier to find than any other life necessity. The enormous advancement in the internet facility has no doubt created a better present with access to every end of information at our fingertips, and it most definitely is a valuable ally in future advancements of human race, but nothing created by man is only confined to human betterment and this age-old custom remains intact in the present world for the internet.

Privacy is one of the most integral aspects of human life. We expect our privacy to be protected and respected. In the age of the internet where every information is available at either fingertips or price, our privacy has fallen under scrutiny. When we give consent on the pop-up form, “Terms and Conditions”, not many of us bother with the task of reading the terms and conditions that are mentioned in that form, as we fall under the pretext that our personal information remains beyond the reach of undesirable third parties. There are various incidents which have shattered the preconceived notion of data privacy in this modern world, naming a few,

  • Dubsmash Data Breach- December 2018.
  • In April 2019, two data sets from Facebook apps had been exposed to the public internet.
  • Twitter Data Breach, 2018.
  • First American Financial Corp Data Breach, 2019.
  • Adobe Data Breach, 2013
  • Indian Council of Medical Research Data Breach, October 2023
  • Marriott International Data Breach, 2018
  • Myspace Data Breach, June 2013.

The above are a few examples of how personal data ranging from place of residence to bank accounts was leaked, hacked or lost. The matter of concern is that all the above-stated cases come from big trusted tech giants whose data is complex, extensive and private. This brings us to the question of whether the privacy granted as a matter of right under Article 21 of the Constitution of India, is a philosophy on paper guarded by words or it is a right shielded with enforcement.

II. Concept of data privacy

The right to privacy is an integral part of the 1950, European Convention on Human Rights which states “Everyone has the right to respect for his private and family life, his home and his correspondence”. Taking the above as the basis the European Union has sought to ensure the protection of the right of privacy in European Nations by the means of implementation of strong and definitive legislation. General data protection regulations are the toughest and most guarded privacy and security laws in the world. The beauty of the Act lies in the extent of its operations, although drafted and enacted in the European Union, the law extends its operation and implementation across the globe as it imposes a stringent obligation on every organization across the globe, so long as they aim to operate and collect sensitive operation of individuals residing in Europe. The dusk of this regulation happened on May 25th, 2018. The Act isn’t one of its kind, but is special due to its harsh regulations, wide ambit and commitment to the protection of the sensitive individual information of the citizens of Europe. The execution is coupled with the levy of harsh fines against organizations, individuals of any institution that violates its privacy and security standards. The penalties are high and ranging to tens of millions of Euros.

Europe is not a pioneer in data privacy and protection laws, but it has signalled a firm stance on data privacy and security of its people at a time where most of the residents/citizens of Europe are entrusting their personal and sensitive data with the cloud services under the impression of data safety, and yet the data breaches have turned into a daily occurrence. “The data regulation in itself is large, far-reaching and fairly light on specifics, making GDPR compliance, a daunting prospect, particularly for small and medium-sized enterprises”. The data privacy laws under GDPR are stringent, strict and inexhaustible. They provide specific guidelines regarding the collection, handling, use and storage of data sourced from individuals of Europe. It should be taken well into consideration that these laws were formulated keeping in mind the data mishandling on the part of Tech giants which makes GDPR, ‘a not so friendly’ regulation for SMEs as it places a burden and limits the information accessed for small-scale Tech Companies as they are in a stage of business where they require the collection of data from its users to create a user friendly and effective interface for their clients as well as it limits the access of data for further research into the technology. Though this problem was not ignored by the European Union, it formulated a website for SMEs to address any specific challenge that they may face regarding this aspect.

GDPR in Article 5.1- 2 outlines seven protection and accountability principles, which are;

1. Integrity and confidentiality- This principle enumerates provisions to ensure appropriate security, integrity and confidentiality by means possible.

2. Accountability- It is the duty of the data controller to demonstrate GDPR compliance with all the stated principles.

3. Storage Limitation- The regulations’ state about storage of personally identifying data only to the point necessary for specified purpose,

4. Accuracy- Personal data must be kept accurate and up to date.

5. Data minimization- It states about the collection and processing of only the absolutely necessary data for the purpose specified.

6. Purpose Limitation- The processing of the data must be done only for the legitimate purpose explicitly specified on the way to the data subject as when you collect it.

7. Lawfulness, Fairness and Transparency- The processing must lawful, fair and transparent to the data subject.

The GDPR guidelines regardi technical measures to be taken during acquirement of data, it mandates the use of two-factor authentication on accounts where personal data is stores and also deploy the usage of end-to-end encryption. Organizational measures like staff training, adding a data privacy policy to the employee handbook, limiting access to personal data in the organizational structure and have been emphasized.

Article 25 of GDPR speaks about, “By design and by default” in respect of data protection. The above statement connotates that every institution that collects sensitive data from its users must design its interface as well as algorithms in a manner so that data protection is a principle deployed in design and activities.

Article 6 of GDPR gives a list of the instances which an organization can legally process a person's data until and unless the reason stated for processing the personal data is justified by the list stated in Article 6 in the GDPR. One cannot access the data of its users;

1. Unambiguous consent of the subject

2. Data processing is essential to enter into a contract into a subject.

3. To comply with the legal obligation

4. To save somebody’s life

5. To undertake a task in the public interest.

6. Legitimate interest.

III. Data privacy, a growing concept in India

Privacy is the right to be left alone and protection from the misuse or abuse of one’s confidential/personal data. It is a right to be free from unwarranted public attention and to live in seclusion without any interference in matters where public opinion is neither directly nor indirectly warranted. This right has a wide ambit as it also determines that one should be free from any secret surveillance regarding the individual’s personal information. Privacy can be branched in four directions.

1. Physical- This is an imposition whereby another individual is restricted from experiencing an individual or a situation.

2. Decisional- This imposition refers to restriction regarding the exclusivity of an entity.

3. Informational- It refers to the prevention of for searching unknown information.

4. Dispositional- It is a prevention from the attempts made to get to know the state of mind of an individual. In this state, one is not supposed to be observed or disturbed by other people as this refers to be free from public attention.

The right to privacy is not a concept out of the blue nor has it found its root in the 21st century rather right to privacy is a part of a common law concept of England. One of the first cases on the said topic was Semayne’s Case (1604). The case was related to the entry into a property by the sheriff of London in order to execute a writ. Sir Edward Coke, while recognizing a man’s right to privacy said, “The house of everyone is to him as his castle and fortress, as well for his defence against injury and violence, as for his repose”. The concept of privacy went under further development in England in the nineteenth century and took the shape of as it is in today’s world. The case of Campbell v MGN, the court stated if, “There is an intrusion in a situation where a person can reasonably expect his privacy to be respected, that intrusion will be capable of giving rise to liability unless the intrusion can be justified”. The above line though said in the nineteenth century, became the basis of enactment and formulation of laws to protect the individual identity and privacy of a person.

The right to privacy derives its powers and functionality from Article 21 of the Constitution of India, which states that “No one shall be deprived of his life and his personal liberty except according to the procedure established by law”. The right to privacy does not find an explicit mention as a ‘right’ in the Constitution. However, it is a concept developed over a course of time and has been recognized under Article 21 of the Constitution of India. The right to privacy is a concept that emerged from a detailed debate and judgements in various cases where the Apex Court tried to understand the need for privacy laws in the changing world.

The concept as to whether the right to privacy can be considered as a fundamental right first emerged as a point of contention in the case of M.P. Sharma & Ors. v Satish Chandra, District Magistrate, Delhi & Ors., the Supreme Court of India stated, “When the Constitution makers have thought fit not to subject such regulations to constitutional limitations by recognition of the fundamental right to privacy, analogous to the fourth amendment, we have no justifications to import it, into a totally different fundamental right, by some process of strained construction”. In the case of Kharak Singh v State of Uttar Pradesh & Ors., the Hon’ble Supreme Court of India was of the opinion, “…as already pointed out, the right of privacy is not guaranteed under our constitution and therefore the attempt to ascertain the movement of an individual which is nearly a manner in which privacy is invaded is not an infringement of a fundamental right guaranteed by Part III”. The silver lining came as the minority opinion of Hon’ble Mr. Justice Subba Rao as he recognized privacy as an essential facet of personal liberty. In his words, “…further, the right to personal liberty takes in not only a right to be free from restrictions placed on his movements, but also free from encroachments of his private life. ….in the last resort, a person’s house where he lives with his family, is his “castle”; it is his rampart against encroachment of his personal liberty”.

Subsequently, in the case of Gobind v. State of M.P., the concept of right to privacy further came into scrutiny. The Hon’ble Supreme Court of India in this case finally accepted the right to privacy as a fundamental right guaranteed under the Constitution of India, but it favoured the evolution of the right to privacy through case laws and negated it to be absolute in nature.

The Court had a similar opinion in the case of R. Rajagopal & Anr. v. State of Tamil Nadu, where it stated, “The right to privacy is implicit in right to life and liberty guaranteed to the citizen of this country by Article 21, “Right to be let alone”. A citizen has a right to safeguard the privacy of his own, his family, marriage, procreation, motherhood, childbearing and education among other matters”. In the further advancement in the case of PUCL v. Union of India, where the Supreme Court clearly held, “once the facts in a given case constitute a right to privacy, Article 21 is attracted”.

The famous case of K.S. Puttaswamy (Retd.) v. Union of India, which was related to ‘Aadhaar Card Scheme’, it was challenged before the Hon’ble Supreme Court of India that the collection of data according to the Aadhaar card scheme was a breach of the fundamental right to privacy guaranteed under Article 21 to which Hon’ble Dr. Justice D.Y. Chandrachud clearly held that, “Privacy is a constitutionally protected right which emerges primarily from the guarantee of life and personal liberty in Article 21 of the Constitution. Elements of Privacy also arise in varying the context from the other facets of freedom and dignity recognized and guaranteed by the fundamental rights contained in Part III…. Privacy has both positive and negative content. The negative content restraints the state from committing an intrusion upon the life and personal liberty on a citizen. Its positive content poses an obligation on the state to take all the necessary measures to protect the privacy of an individual”. It was the result of this judgement that the right to privacy became a more ‘robust and sacrosanct’ and became more than a mere common law right.

In the case of R. C. Cooper v. Union of India, the Hon’ble Dr Justice D.Y. Chandrachud held that “Informational privacy is a facet of the right to privacy. The dangers to privacy in an age of information can originate not only from the state but from non-state actors as well. The comment to the Union Government the need to examine and put into place a robust regime of data protection. The creation of such of regime requires a careful and sensitive balance between individual interest and legitimate concerns of the state …we are in an information’s age. With the growth and development of technology, more information is now easily available. The information explosion has manifold advantages but also some disadvantages. The access to information, which an individual may not want to give, needs the protection of privacy. ….. The right to privacy is claimed qua the State and non-state actors. Recognition and enforcement of claims qua non-state actors may require legislative intervention by the State.”

IV. Data Privacy and Information Technology Act, 2000

People all across the world are becoming concerned about the protection of the private data in this digital era. The proliferation of social media platforms and other digital platforms had led to assimilation of undetermined and unprecedented data collection. The excessive data collection through these platforms has raised ripples of concern across the globe. The data collected by these platforms is of sensitive nature as it is directly corelated to not just a person’s personal preferences but also to social details like Aadhaar Card, PAN Card, Bank accounts, insurance, residential data, data regarding family members, phone records, contacts, photos, emails and so goes on the list. The government sends in future need of data privacy incorporated as a concept in the Information Technology Act, 2000. However, these laws are not absolute in providing protection to the personal data of users.

“The Information Technology Act, 2000”, is a key piece that protects the private sensitive data of individuals in India. The Act lays down the foundation for legal recognition or the transactions carried out via electronic sources and lays down further provisions regarding the collection, storage, transmission, usage, and third-party dealings of this data that also lays down stringent provisions regarding punishment in the cases of violation of its rules.

“Section 43A of the Information Technology Act, 2000”, includes passwords, information regarding the financial transaction, personal information, and biometric data. This section mandates the businesses that collect and store sensitive information to ensure deployment of reasonable security practices so as to prevent the misuse, mishandling, misappropriation or any other malafied use of this data. Shall an organization and person fail to comply with the provisions of this Act may face a significant fine in addition to possible imprisonment.

“Section 72A of the Information technology Act, 2000”, provides for the punishment for intentionally or knowingly disclosing the personal data related to a person, it was acquired from for providing a lawful contractual service the breach of the data without the consent of the person concerned or in the breach of a lawful contract. Further, as a clarification to the above, the government introduced Information Technology, ‘Reasonable security practices and procedures in sensitive personal data or information Rules, 2011’;

1. Enacted pursuant to Section 43A of the IT Act,2000, defined, “personal information” to mean any information that can relate to a natural person, can be deployed or used either directly or indirectly coupled with some other information for the identification of such person. This is also known by the name of “Personally identifiable information”. Further, “sensitive personal data or information” is defined to be a further sub category of this information. It means all the such items involving individuals’ usernames, passwords, banking information, credentials, information regarding health, Aadhaar information, PAN Card information, sexual orientation, biometrics, etc.

2. IT Act Rules, provide guidelines in respect to the privacy policy that needs to be adhered by body corporates. This policy involves the following key takeaways:

a. There should be clear and easy indication regarding the practices of the body corporate.

b. The rationale behind the collection, analysis, synthesis, processing, usage of such data.

c. The nature of the data collected.

d. The rules lay grounds regarding the procurement of consent stating it should be received in writing or email from the service provider regarding the nature, purpose and collection of sensitive data.

e. The option to opt out is to be given to the customer to withdraw his consent prior to the collection of data. In case the service provider needs to transfer this data to a third party it is mandatory to acquire prior permission from the person/people from whom this data has been acquired.

f. The body corporates are directed to designate a grievance officer and are required to publish his name and contact details on authorized website to deal with any data protection issue.

The judgment of Justice K.S. Puttaswamy & Ors v Union of India & Ors., helped and facilitated the recognition as an informational privacy as a facet of privacy. The judgment identified the grey area and recognised the ever-urgent need of data protection laws and data regulations to protect the autonomy of persons. Some of the key takeaways of this case in respect to data privacy are:

1. Information is non-rivalrous.

2. Information can be invisible.

3. Information is recombinant.

When you open a website pop-up comes on the screen called, “Cookies”. These cookies are technology used to identify and evaluate preferences of a consumer that uses a particular website. It also saves, retains this information and majority of the people click on that pop-up, “Accept the cookies” often. They do not understand the concept behind this pop-up, they are under the assumptions that whatever they browse through that website is available to them only to the point while they are operating that website or when they create, ‘Log in’ on that particular platform. The data collected is used to analyze the consumer’s preferences by businesses and provide a semi-customised experience to them. This is a going marketing technology to understand consumer database better and understanding the preferences of their potential customers to enhance business operations. This technological advancement in the field of business though seems harmless can cause huge havoc in case of data leaks.

On 30th August, 2024, it came to public notice that Durex India exposed sensitive consumer data, which includes the full names of the consumer, order details, bank account numbers/ payment details, address, and other sensitive data. Security researcher Sourajeet Majumder, first discovered the security data leak. While the exact number of affected customers remain unknown, it is suspected that the information of thousands of customers has been exposed due to the lack of proper authentication on the company’s order confirmation stage. The problem that arises out of these data leaks is easy to understand due to the social stigma regarding the products of this company. The customers whose data has been breached might get subjected to online harassment and moral policing. Everything about this incident infringes a person’s right to privacy as the data submitted to the company while placing the order for the product is supposed to remain strictly confidential.

V. Accommodating Data Protection Through Digital Personal Data Protection Act, 2023

Protecting one’s data is of greatest importance in this rapidly digitising world. To make sure of this, the Legislature has passed a Bill, The Digital Personal Data Protection Act, 2023. In this essay, we shall try to understand and learn about different safeguards provided by the Act and draw a critical analysis of it.

Often, we tend to click on ‘Allow all’ when we open an app. We might not notice the atrocities of providing consent to the apps to access our data like our gallery, contacts, location, etc. because we refuse to believe that someone can take benefits from our data. One should know that your data carries it all, your preferences, your favourite food, your favourite brand, your credentials and even your health records. This data can be breached and can lead to harmful repercussions like financial fraud, etc. There have been many instances, say, for example, data leaks from the AIIMS records, which created havoc in society. To combat this, and to ensure the secure processing of data, the Legislature has enacted The Digital Personal Data Protection Act, 2023. Let us take a dig at what the Act aims to cater to the Indian Society.

The Digital Personal Data Protection Act, 2023:

In 2017, for the very first time in India, the right to privacy was considered a fundamental right under Article 21 of The Constitution of India. As a consequence of this, a committee was formed under Mr. Justice B.N. Srikrishna to secure this newly recognised Fundamental Right. This Committee was specifically created to examine the subjects of Data Protection. In 2018, the very first-drafted bill was presented which was named, the Personal Data Protection Bill, 2018, which later in December 2019, was presented to the Joint Parliamentary Committee to review it and suggest changes. Several changes were proposed, which gave birth to a new-drafted bill, Data Protection Bill, 2021. However, this 2021 bill, was taken aback in August 2022. Later, in November 2022, the Ministry of Electronics and Information Technology (MeitY) presented another bill that was passed by both the Parliamentary Houses in August 2023, which we now study as the Digital Personal Data Protection Act, 2023.

The Digital Personal Data Protection Act, 2023, is the first Act to regulate and protect digital Data. It aims to digitize the 120-crore population of India by processing their personal data. Personal Data is information or statistics of an individual. It is a sensitive information which can reveal the identity of an individual. The individual who generates this data is called Data Principal and the entity which stores or processes this data is known as Data Fiduciary in this Act.

This Act applies to all the data in digitised form and in non-digitised form which has to be digitised subsequently. It also pertains to data collected in India as well as data used for goods and services provided outside of India, nonetheless, consent is crucial for processing such data. Consent is a key element under this Act, without which such regulation and process is barred. A major i.e. 18 years of age and above, can give consent on his own but for a minor child, below the age of 18, his consent should be given by his parents or guardian. One can withdraw his consent and the processing of data may stop.

Within its authority, the Central Government can form a Data Protection Board, which will monitor the implementation of this Act and impose penalties upon the Data Principal and Data Fiduciary. In case of a breach relating to children, a penalty of up to 200 crores can be imposed and in case of inadequate security measures by Data Fiduciary, this penalty may extend up to 250 crores. This board will also help Data Fiduciary to take curative actions against the breach.

Rights and Duties of Data Principal:

Rights;

  • Data Principal can demand the processing of his data from Data Fiduciary.
  • Data Principal can make corrections and even erase his data.
  • Data Principal can declare a nominee for his data.
  • There is also a provision regarding the grievance redressal mechanism for the Data Principal.

Duties;

  • A fine may be imposed on any false or frivolous complaint by the Data Principal.
  • The Data Principal is prohibited from providing incorrect data if the consent was granted voluntarily.
  • A penalty of Rs. 10000/- is levied in case of the commission of the above acts.

Powers of Data Fiduciary:

  • This Data can be used for legitimate purposes only.
  • Data Fiduciary has been obligated to inform the Data Protection Board in cases of data breach.
  • Data Fiduciaries will have to erase all the data after the fulfilment of its purpose.

Excessive Powers of the Indian Government:

  • The Indian Government has broad powers to keep this data even after the completion of its purpose.
  • Central Government, through notification in the Official Gazette, ban countries from data transfer.
  • They cannot claim it if the Government of India's investigation into a crime result in a violation of the rights of Data Principal or Data Fiduciary.
  • If Central Government is acting in the interest of Security of the State and maintaining the public order, then any action in furtherance of this can be exempted.

The Internet is both a boon and a bane. While it can popularise someone quickly, it can also be a reason for destruction. Lately, many people have been targets of financial fraud, Deepfake, and whatnot. People have taken drastic steps like suicide as this has somehow affected the mental health of the people. The Digital Personal Data Protection Act, 2023 was enacted to curb situations like these. This Act is one of its kind in a country like India, where a new wave of digitalisation has emerged over the past 10 years. But this is also a big concern that the Government has excessive powers over the data once consent has been given. This Act also provides no provision regarding the safe and secure processing of the data. These drawbacks may play a huge role in the infringement of the rights of the general public. Therefore, this is an alarming situation in which amendments have to be made to secure the rights of individuals.

VI. Present environment

On November 23rd, 2022, ransomware attacked the servers of All India Institute of Medical Science in Delhi led to chaos and wreaked havoc on systems. The entire process of AIIMS Delhi had to go manual. One of India's most advanced medical institutes went back decades due to this cyber-attack. It took over a time of 2 weeks to get the infected system back online. This sent ripples of debate regarding the protection of medical data across India. A medical institute is home to medically sensitive data of a huge number of patients that has been honed over years. Medical data is one of the most sensitive information for any individual and unauthorized circulation of this highly sensitive data on unauthorized and murky waters of the darker side of the internet makes people vulnerable to a larger extent than fathomable. The 2019 report, estimated the value of a single health care record at $250. It is by far one of the most valuable data records. In the AIIMS ransomware attack estimated around 14 million records containing highly sensitive data of not just the citizens but also some of the most powerful people in the country had been under attack. It is impossible to draw a monetary valuation of this data since life of an individual cannot be calculated on a monetary scale. The attackers didn’t wish to release the data in the public domain, but rather encrypted the current existing data and allegedly demanded 200 crores as ransom. K.K. Mookhey, CEO and Founder, of Network Intelligence, stated, “In a ransomware incident the loss to the entity under attack is not tangible. Think of the nightmarish scenario of manual entry process at hospital as busy as AIIMS, which treats over twelve thousand patients in just in its out-patient department”. It is hard to point fingers to determine who is the victim and who shall be held liable. This data privacy breach shook the nation to its core as the medical records of every individual in a country are extremely valuable and integral and this attack on a high-profile institution brings us to the question as to whether our data is actually safe or is it a dream of no cause.

In 2019, India’s largest bank, State Bank of India, faced a significant data breach that exposed the sensitive information of its millions of users in India. This data breach was the result of grave negligence on the part of SBI’s management. This security lapse led to unauthorized access to millions of customer record databases which in turn put the financial wellbeing of millions of Indians at risk. SBI is one of the largest operating banks in India with its offices situated in not only metropolitan cities but also remote villages. SBI holds highly confidential and sensitive data of millions of Indians which was exposed to hackers and organizations with ill intentions to commit fraud. In today’s digital era, we are highly concerned about our data, hence we like to keep everything password-protected. SBIs' failure to secure the password led to the leak of personal financial data of an astonishing 422 million customers. The data leaked consisted of bank account numbers, bank balances, partial account numbers, Aadhaar numbers, KYCs, linked account details and so much more. The irony of the situation lies in the fact that the breach was discovered not by the officials of an organization, but rather an independent researcher who happened to stumble upon the unprotected server while searching for vulnerabilities. He reported the findings to Tech Crunch, online publisher that mainly focuses on technological news. What makes this data breach a landmark is that this one data breach can lead to an n-number of malicious frauds as sensitive financial information like this can lead to social engineering attacks, identity thefts, financial frauds, scams, etc. The data breach has a significant impact on SBI’s reputation being the leading financial institution of India, its responsibility is to make sure that the financial data of its customers is protected, secured and encrypted.

VII. Conclusion

As the world of technology evolves, data will become the cheapest luxury. There is a knock on the door of the authorities to protect the personal data of individuals, as the present scenario poses a warning regarding the horrors of data leaks. The wars are no longer limited to battlegrounds. They extend themselves into the home of every individual, and cyber-attacks on private data are not just a concern for individuals but also for the country. The need for strict and effective data privacy laws is now more than ever. Learning from our counterparts and allies, we need to understand that data is the new currency and there are many who would not stop at anything to get their hands at this currency. Data has a price, but the privacy of an individual is priceless. It is the duty of the government to protect its citizens from falling prey in the hands of individuals or organizations who aim to violate their privacy.

*****

Footnotes

  1. Author is a student at Banasthali Vidyapith, Rajasthan, India.
  2. Author is a student at Banasthali Vidyapith, Rajasthan, India.
How to Cite
Kanherkar, S., Parashar, S. (2024). Data Privacy in Contemporary India. International Journal of Legal Science and Innovation, 6(5), 63-76. https://ijlsi.com/article/view/data-privacy-in-contemporary-india