Data Protection Law: A Need of the Moment
This paper examines the need of a data protection law in this era of digitization especially after the commencement of the pandemic. Thus, by tracing the importance of privacy and data protection, we have placed the spotlight on the steps taken by the Indian Government in order to achieve the same. The paper emphasizes on the looming proposed Data Protection Bill, its impact on the Indian economy and the challenges regarding its implementation by the Government.
I. Introduction
In Data Protection refers to the set of privacy laws, policies and procedures that aim to minimise intrusion into one's privacy caused by the collection, storage and dissemination of personal data. Personal data generally refers to the information or data which relate to a person who can be identified from that information or data whether collected by any Government or any private organization or an agency. The pandemic was the year in which there was a large transition to digitization. One of the silver linings of the year was the spotlight on the importance of data and data flow. Taking this cue, the Indian Government took significant steps in tech policy and data regulation in 2020.Through this paper, we have analysed the looming proposed privacy law’s impact in the Indian economy.
II. Delineating the importance of privacy and data protection
With the advent of the Information Technological sector in the late 1990s, and the revolutionization of the telecom industry, digital services took prominence in the economy and this led to important consequences. On one hand, due to increasing number of services becoming digitized and a surge in digital platforms, the economy became more interconnected and on the other hand, policy objectives like cash transfers could easily be achieved through the online service delivery. The implementation of the Aadhaar scheme sought to facilitate this objective, but was subject to criticism due to several reasons2. One major criticism was that this scheme was being utilised to benefit private firms for customer onboarding, which went against social welfare. It was alleged that the storage of Aadhaar-related customer information, such as metadata about the place of authentication, constituted a serious breach of privacy3. Another significant point of criticism was that the scheme would vest extensive powers with the state in terms of surveillance due to the proposed ubiquitous nature of the Aadhar. It was this Aadhar debate that highlighted the privacy concerns, which manifested itself before the Supreme Court by way of several petitions challenging the validity of the impugned Act. Upon hearing the case, the five-judge bench of the Supreme Court stated that, before ruling on the infringement of privacy, there was a need to determine if there was a Right to Privacy that is guaranteed by the Constitution in the first place. Thus, the case was referred to a bench of nine judges of the Supreme Court, which resulted in the landmark ruling of Justice K. S. Puttaswamy and Anr. v. Union of India and Ors4 in August 2017 that a right to privacy did exist under Article 21, and overturned the earlier judgement given in Kharak Singh5.
Supreme Court had, on earlier occasions protected facets of privacy in cases such as Kharak Singh (Privacy from Police visits at night) and PUCL v. Union of India6 (Telephone tapping case). However, the Puttaswamy judgement stood out in conceptualizing the concept of Privacy as a right in itself that was fundamental in nature. This perception of privacy was already in line with the principle of privacy existent in other countries, that had a framework which included data protection under its ambit.
The B.N. Srikrishna Committee Report
Around the same time, the Union Government constituted a committee to be headed by retired Supreme Court Judge, Justice BN Srikrishna, in July 2017, to deliberate on a data protection framework. The committee published its report in 2018, Justice Srikrishna said data privacy is a burning issue and there are three parts to the triangle. “The citizen’s rights have to be protected, the responsibilities of the states have to be defined but the data protection can't be at the cost of trade and industry.” In its report, a draft for the Personal Data Protection Bill 2018 was provided which eventually formed the basis for the bill that was tabled in the Lok Sabha7.
III. Features of the proposed data protection bill
The bill provides a legal framework for the collection and use of personal information. It governs the processing of personal data by the Government, Companies in India and Foreign companies dealing with processing of data of individuals in India. The Bill categorises certain personal data as sensitive personal data. This includes financial data, biometric data, caste, religious or political beliefs, or any other category of data specified by the government, in consultation with the Authority and the concerned sectoral regulator.
It imposes certain obligations upon data fiduciaries in the way they process the data available to them, in a transparent and accountable manner. It is ensured through implementing security safeguards, instituting grievance redressal mechanisms to address complaints of individuals. Additionally, mechanisms for parental consent and age verification are mandated when processing personal data of children that are sensitive.
The Bill creates a set of rights and responsibilities for individuals including the right to obtain confirmation from fiduciaries on processing of their data, seek correction of inaccurate, incomplete, or out-of-date personal data; have personal data transferred to any other data fiduciary in certain circumstances, and restrict continuing disclosure of their personal data by a fiduciary, if it is no longer necessary or consent is withdrawn.
- It lays down grounds for processing of personal data, which is possible only if an individual consents to it, except under certain circumstances which include instances where the State requires it for providing benefits to an individual, or for legal proceedings, or to respond to a medical emergency. It allows for Social Media Intermediaries to facilitate online interaction between users and allow for sharing of information. These intermediaries have a notified threshold, and those who would have an impact on electoral democracy or public order also have obligations thrust upon them including making a provision of a voluntary user verification mechanism for users in India.
- The bill proposes to create a Data Protection Authority (DPA) for making regulations and enforcing the legal framework, which may take steps to protect individuals’ interests, prevent the misuse of any personal data and to ensure complying with the Bill.
- The DPA would consist of a chairperson and six members, with at least 10 years’ expertise in the field of data protection and information technology. It also provides appeal provisions for the orders provided by the DPA, which would be directed to the Appellate Tribunal, and appeals upon orders of the Appellate Tribunal would be heard by the Supreme Court.
- The bill also vests substantive standard setting powers with the central government and tasks the DPA with enforcing the same.
- While the Bill allows for transferring of data for processing outside of India, if explicitly consented to by individuals, these are restricted to a certain extent by way of conditions. Such sensitive personal data would, however, continue to be stored in India.
Exemptions from the Bill: The union government can exempt any of its agencies from the provisions of the Act:(i) in interest of security of state, public order, sovereignty and integrity of India and friendly relations with foreign states
(ii) for preventing incitement to commission of any cognisable offence (arrest without warrant) relating to the above matters. Processing of personal data is also exempted from provisions of the Bill for certain other purposes such as: prevention, investigation, or prosecution of any offence, or personal, domestic, journalistic purposes. However, such processing must be for a specific, clear and lawful purpose, with certain security safeguards.
Offences under the Bill would incur monetary penalties, for instance, processing or transferring personal data in violation of the Bill is punishable with a fine of Rs 15 crore or 4% of the annual turnover of the fiduciary, whichever is higher. A failure to conduct a data audit, is punishable with a fine of five crore rupees or 2% of the annual turnover of the fiduciary, whichever is higher. This offense is cognizable, i.e., an offense in which an arrest can be made without a warrant and nonbailable.
- Re-identification and processing of deidentified personal data without consent is punishable with imprisonment of up to three years, or fine, or both.
- The Bill amends the Information Technology Act, 2000 to delete the provisions related to compensation payable by companies for failure to protect personal data.
IV. Effect of the proposed bill on the indian economy
The proposed data protection bill would therefore provide a preventive framework that would apply to existing methods of data collection and the practices of usage currently being followed. It imposes obligations upon businesses that collect and use data of its consumers while providing a higher threshold of consumer-rights in relation to their data that is stored. Since the provisions of the legislation mandates the meeting of the outlined requirements to collect any sort of personal data, it would require even the small grocery stores and mom-and-pop stores that have been following simple data collection methods, and the erstwhile larger business complexes using a more sophisticated range of data collection involving algorithms and datasets to re-evaluate their methodologies.
The legislation would thus have a notable impact on the country’s economy. Although India is home to a myriad of multinational corporations, and houses several national and international companies, the majority of the business sector is comprised of small businesses and entrepreneurial start-ups that are small in scale. As per an annual report of the Ministry of Micro, Small and Medium Enterprises, “of the estimated number of 633.92 lakh [63.39 million] enterprises, only 4000 enterprises were large and thereby out of the MSME [micro, small, and medium enterprise] Sector.”8 Therefore the major impact of the proposed legislation would affect small businesses.
It is therefore pertinent that personal data protection does not negatively influence industrial innovation and growth. Further, the Indian landscape is predominantly rural, in the sense that digital connectivity still a novel concept for a large section of the populace as against the urban metropolitans who have adapted to the digital ecosystem. Rural population (% of total population) in India was reported at 65.53 % in 2019, according to the World Bank collection of development indicators, compiled from officially recognized sources9.
The remotest corners of India still do not have basic infrastructural facilities including proper roads, hospitals or schools, and sanitation facilities. Under such circumstances, a well-laid out plan to implement the existing digitization plans should be closely followed up with bringing awareness and educating the rural population of importance of Data Privacy and protection and the online hazards that could likely occur and in such cases, of the remedies available to them.
As with most legislations, the main problem that could hinder the efficiency of the proposed legislation would arise during the process of implementation. Implementing a uniform legislation protecting the rights of such a diverse and dense population with contrasting economic and social backgrounds would be a challenge in itself. Furthermore, the threat to data privacy of citizens could occur from both state as well as non-state actors. When the State joins with private entities, in the absence of such a protection law, people would fall prey to more serious concerns than mere target advertising.
V. Conclusion
India’s data protection legislation ought to balance the twin requisites of protecting people’s privacy without negatively influencing industrial innovation and growth. The digital economy in India is expected to reach a valuation of $1 trillion dollars by 2023 and this reinforces the need for a legislative framework to be put in place, to regulate and protect the citizens’ rights in the cyberspace. Therefore, while implementing the data protection bill, these factors ought to be kept in mind and the implementation process should consider and evaluate all forms of loopholes and lacunae in the law.
*****
Footnotes
- Author is a Student at Sree Narayana Guru College of Legal Studies, Kerala, India.
- “Users in India to Reach 627 Million in 2019,” Economic Times, https://economictimes.indiatimes.com /tech/internet/internet-users-in-india-to-reach-627-million-in-2019- report/articleshow/68288868.cms?from=mdr. ↩
- Madhav Khosla and Ananth Padmanabhan, “The Aadhaar Challenge: 3 Features That Put Constitutional Rights at Risk,” ThePrint, June 27, 2018, https://theprint.in/opinion/the-aadhaar-challeng e-3-features-that-put-constitutional-rights-at-risk/755 76 ↩
- WRIT PETITION (CIVIL) NO 494 OF 2012 ↩
- AIR 1963 SC 1295 ↩
- (1997) 1 SCC 301 ↩
- Committee of Experts under the Chairmanship of Justice B. N. Srikrishna, “Draft Personal Data Protection Bill, 2018,” https://www.thehinducentre.c om/resources/article245 ↩
- Ministry of Micro, Small and Medium Enterprises, Government of India, “Annual Report 2017-18 -Ministry of Micro, Small and Medium Enterprises,” (New Delhi, India, 2018), https://msme.gov.in/sites/ default/files/MSME-AR-2017-18-Eng.pdf.,%2023. ↩
- Tradingeconomics.com. 2021. India - Rural Population - 1960-2020 Data | 2021 Forecast. [online], https://tradingeconomics.com/india/rural-po pulation-percent-of-total-population-wb-data.html> [Accessed 26 September 2021]. ↩
