News Analysis / The Personal Data Protection Bill
Published on: December 18, 2021
Data Privacy related issues
Context:
The author talks about the Joint Committee on the Personal Data Protection Bill’s report.
Editorial Insights:
After rigorous sittings & deliberations, the Joint Committee of Parliament on the Personal Data Protection Bill recently tabled its report in both houses.
About JCP on Personal Data:
The JCP, which was formed in December 2019 to deliberate on issues surrounding personal data protection, expanded its mandate to include discussions on non-personal data, thereby changing the mandate of the Bill from personal data protection to broader data protection.
In all, the committee has made 99 recommendations, of which 12 are in connection with the provisions made in the Bill, and the rest are in the form of modifications.
The Recommendations:
Inclusion of Non-Personal Data: The key recommendation that changes the nature of the Bill itself is for the inclusion of non-personal data within the larger umbrella.
Because committee believed that it was impossible to distinguish between personal data and non-personal data when mass data is collected or transported”.
This means that all issues under the new legislation will be dealt with by a single Data Protection Authority (DPA) instead of separate ones for personal and non-personal.
Transition Period: As technology has become an inseparable part of everyone’s life.
To ensure that all such data aggregators get ample time to comply with the rules under the new Bill, the JCP suggested that up to 24 months be given from the date of notification of the Act.
All data fiduciaries that deal exclusively with children’s data have to register themselves with the DPA.
Social Media Liability: Another major recommendation is that social media platforms that do not act as intermediaries should be treated as publishers, and therefore be held liable for the content they host.
In other words, this would strip these companies of protections they are accorded under Section 79 of the Information Technology Act.
Penalty: The committee has recommended a fine of up to Rs 15 crore or 4% of the total global turnover of the firm for data breaches, and a jail term of up to 3 years if de-identified data is re-identified.
Timely-Alert: In case of any data breach, the data aggregator or fiduciary must notify the DPA within 72 hours of becoming aware of it.
The DPA shall then decide the quantum of the severity of the data breach and accordingly ask the company to report it and take appropriate remedial measures.
Factors took into consideration by JCP:
With the growth of the Internet, consumers have been generating a lot of data, Companies began to store a lot of these datasets without taking the users’ consent and did not take responsibility when the data leaked.
The committee stressed a need to set up new processes to unify such data present across spectrums and organizations such as public and private sector companies, research organizations, and academic institutions.
Among the major concerns that the JCP recommendations sought to address are :
The rapid commercial use of personal data has resulted in undermining the end-user trust and confidence.
Concerns and tensions about the misuse of sensitive and critical personal data are rising exponentially,
To deal with such situations, it was important to build a legal, cultural, technological, and economic infrastructure for a secure and user-friendly data ecosystem.
Apart from the obvious economic and privacy concerns, the JCP report also discusses the impact on mental health and emotional well-being that a user experiences due to a data breach.
It cites findings that among such individuals, as much as 86% felt worried, angry, and frustrated, while 85% experienced disturbed sleeping habits.
The Extra-Mile:
Though the JCP report reaffirms the core components of the Bill & fine-tunes many aspects. But it has also used the Bill to paint a broader canvas of data regulation for India.
Some of these proposals need greater deliberations:
On many other aspects of the Bill, the JPC has adopted a workman-like approach:
Concerns:
The Bill presented in Parliament gives the central government the power to exempt its agencies from the ambit of the data protection regulation.
The report proposes that any procedure followed by such agencies will have to be a just, fair, reasonable, and proportionate procedure.
While this encapsulates the checks laid down by the Supreme Court in its judgment on the right to privacy, it leaves it to the executive to figure out what just, fair, reasonable, and proportionate ought to mean.
The report takes a similar approach to the provision that enables the central government to require businesses to hand over non-personal data to it.
Way-Ahead:
Though the concern of the state invading the domain of privacy is visible, the need for Data protection against exploitation & breach is also necessary.
Therefore the need of the hour is the state's accountability in data protection to rebuild public confidence & trust in the process.