SlideShare ist ein Scribd-Unternehmen logo
1 von 16
Downloaden Sie, um offline zu lesen
DATA DECODEDDATA DECODED
www.civis.vote
Background of the Draft Bill
● The Ministry of Electronics & Information Technology constituted a Committee
of Experts.
● Chairman – retired SC Judge, Justice B.N. Srikrishna.
● Mandate – study issues relating to data protection in India and suggest measures.
● Committee issued:
○ Data Protection Report - “A Free and Fair Digital Economy Protecting Privacy,
Empowering Indians”; and
○ Draft Personal Data Protection Bill, 2018
● MEITY has sought feedback from public We are here
How Does This Draft Bill Become a Law? (Next Steps):
● MEITY to consider feedback from public
● Draft Bill to be modified, if required
● Union Cabinet to pass the draft Bill
● Bill to be introduced in Parliament
Important Concepts in the Draft Bill
● Data
● Personal data
● Sensitive Personal Data:
○ Passwords
○ Financial data
○ Health data
○ Official identifier
○ Sex life / sexual orientation / Transgender status / intersex status
○ Biometric / genetic data
○ Caste or tribe
○ Religious / political belief or affiliation
○ Anything else specified by Authority
Important Concepts in the Draft Bill (Continued)
● Data principal – natural person to whom data relates
● Data Fiduciary
○ Any person – individual / company / Govt. / entity
○ Determines purpose and means of processing data
● Processing – collection / recording / organizing / storing /
disclosure / use / etc.
SPD
Personal
Data
Data
Obligations of the Data Fiduciary
● Processing in fair and reasonable manner
● Purpose limitation – clear, specific, lawful purposes
● Collection limitation– only necessary data
● Notice - DF to give notice to data principal about factors such as:
o Purpose
o Categories of data being collected
o Identity/contact details of DF
o Withdrawing consent
o Basis for processing and consequences of not providing data
o Identity of other DF or data processors with whom data shared
o Cross-border transfer of data
o Procedure for grievance redressal
o Source of collection etc.
● Quality of data – complete, accurate, not misleading and updated
● Data storage limitation – only as long as necessary
● DF must follow provisions of the Act
When can Personal Data be Processed?
● By consent - free, informed, specific, clear and capable of being withdrawn
● For functions of State
● To comply with law or order of court/tribunal
● For prompt action (medical emergencies, safety, etc.)
● For employment purposes
● For reasonable purposes to be specified by the Authority like:
○ Whistle-blowing
○ M&A
○ Credit scoring
○ Prevention of unlawful activity
○ Recovery of debt
○ Publicly available personal data.
● By explicit consent
● For functions of State
● To comply with law or order of court/tribunal
● For prompt action
● Further categories of SPD may be specified by the Authority
When can personal data and SPD of children be processed?
● Protects / advances best interest of the child
● Age verification & parental consent
● Guardian data fiduciaries (GDFs): websites for children / DF who process large
volumes of personal data of children.
● GDFs cannot profile/track kids or give targeted ads for kids.
● If GDFs are child counselors or child protection services, parental consent is not
required.
When can Sensitive Personal Data be Processed?
Rights of Data Principals
● Right to confirmation and access
○ Confirmation about the fact of processing
○ Summary of the personal data being processed
○ Summary of processing activities undertaken
● Right to correct, complete and update personal data
● Right to data portability - Personal data available with DF can be transferred to
another DF on DP’s request
● Right to be forgotten – Upon application to Authority in following cases:
○ When purpose is served
○ When consent has been withdrawn
○ When disclosure was made contrary to provisions of the Bill or any other
law
How to Exercise These Rights?
● DP to make a request in writing to the DF (except Right to be forgotten)
● If data portability or summary of processing activities sought – DF can charge
fee
● DF to comply within reasonable time.
● If request declined by DF, need to give reasons in writing and inform DP about
her right to complaint to Authority
● DF not bound to comply with anything from S.24 to 27 if it would harm any
other DP.
How Does the Bill Impact Businesses?
● Provide ‘Notice’ before collecting Data that is clear, concise and can be easily
understood by the average person.
○ This Notice may be in multiple languages if required
● Organisations should provision for individual privacy and innovation can’t take
place at the risk of compromising an individual’s privacy.
● Create safeguards like the de-identification of data to prevent misuse.
● Be transparent about data being collected and processed and provide
information at periodic intervals about the data that is being processed.
● Maintain at least one copy of data collected on a server located in India.
Compliances
● Different standards of compliance for ‘significant data fiduciaries’, data
fiduciaries and small entities.
○ Significant data fiduciaries will be classified based on the volumes of data processed, sensitivity
of data, turnover, new technologies used, risk of harm from processing.
○ Small entities are organisations with a turnover under 20 lakh, that manually process data and
haven’t collected personal data of over 100 people in the last calendar year.
● Report data breaches to the authorities along with measures taken to remedy a
breach.
● Conduct annual data audits, through a recognised professional auditor. Conduct
Data Protection Impact assessments before using new technologies.
● Maintain records of data collected and the manner of it’s processing.
● Appoint a data protection officer with whom grievances can be raised and who
can provide advice to ensure data protection under this Bill.
Authorities and Penalties
● The Bill, provides for the creation of a Data Protection Authority and an
Appellate Tribunal.
● Penalties under this Bill are as follows:
● These penalties are separate from compensation.
5 crore or 2% of global
turnover
15 crore or 4% of global
turnover 5,000/- Failure to attend to indvidual's requests
10,000/- Failure to give information to the Authority
20,000/- Failure of significant fiduciaries to comply
with orders.
5,000/- Failure of fiduciaries to comply with orders.
1 crore - For significant fiduciaries where no penalty
is specified.
25 lakh - For fiduciaries where no penalty is
specified.
• Not acting promptly on a
data breach.
• Not undertaking data impact
assesment
• Not appointing a data
protection officer
• Not registering with the
authority
• Unlawful processing of data
• Violates the grounds for
processing
• Processing sensitive personal
data or children's data
incorrectly
• Failure to ensure data security
• Transferring personal data
contrary to the Act's provisions
● All offences under the Act are cognizable and non-bailable. Offences under the
Act are:
○ Transferring data contrary to the Act - 2 lakh fine and/or 3 year
imprisonment.
○ Obtaining or selling personal data - 3 lakh fine and/or 5 years in jail.
○ Re-identifying and processing personal data without consent 2 lakh fine
and/or 3 years in jail.
Offences Under the Bill
www.meity.gov.in www.saveourprivacy.in
www.civis.vote twitter.com/_maadhyam_
What can you do about the Bill and how?

Weitere ähnliche Inhalte

Was ist angesagt?

GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360DataStax
 
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback  on Draft Personal Data Protection Bill 2018 submitted to MEITYFeedback  on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITYNanda Mohan Shenoy
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill Mathew Chacko
 
China's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysChina's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysTrustArc
 
Guernsey Data Protection Legislation
Guernsey Data Protection LegislationGuernsey Data Protection Legislation
Guernsey Data Protection Legislationjonbarclay
 
LGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionLGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionTrustArc
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer UpdateTrustArc
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill Komal Gadia
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Quotient Consulting
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskTrustArc
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Actmrmwood
 
Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Werksmans Attorneys
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacylegalPadmin
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk- Mark - Fullbright
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamBrowne Jacobson LLP
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 

Was ist angesagt? (20)

GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360GDPR: The Catalyst for Customer 360
GDPR: The Catalyst for Customer 360
 
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback  on Draft Personal Data Protection Bill 2018 submitted to MEITYFeedback  on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITY
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill
 
China's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 DaysChina's PIPL: How to Comply in Under 60 Days
China's PIPL: How to Comply in Under 60 Days
 
Guernsey Data Protection Legislation
Guernsey Data Protection LegislationGuernsey Data Protection Legislation
Guernsey Data Protection Legislation
 
LGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionLGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement action
 
International Data Transfer Update
International Data Transfer UpdateInternational Data Transfer Update
International Data Transfer Update
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 

Ähnlich wie Data Decoded: Understanding India's Draft Data Protection Bill

Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Burton Lee
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeIBB Law
 
Data protection compliance for tech startups
Data protection compliance for tech startupsData protection compliance for tech startups
Data protection compliance for tech startupsEkoInnovationCentre
 
Data protection regulations in Nigeria
Data protection regulations in NigeriaData protection regulations in Nigeria
Data protection regulations in NigeriaMercy Akinseinde
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Forums financiers de Wallonie
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowTerry Gorry
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementTrustArc
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 

Ähnlich wie Data Decoded: Understanding India's Draft Data Protection Bill (20)

Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
Data protection compliance for tech startups
Data protection compliance for tech startupsData protection compliance for tech startups
Data protection compliance for tech startups
 
Data protection regulations in Nigeria
Data protection regulations in NigeriaData protection regulations in Nigeria
Data protection regulations in Nigeria
 
GDPR Demystified
GDPR Demystified GDPR Demystified
GDPR Demystified
 
Data Protection and IDEA
Data Protection and IDEAData Protection and IDEA
Data Protection and IDEA
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 

Kürzlich hochgeladen

Embed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopko
Embed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopkoEmbed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopko
Embed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopkobhavenpr
 
Lorenzo D'Emidio_Lavoro sullaNorth Korea .pptx
Lorenzo D'Emidio_Lavoro sullaNorth Korea .pptxLorenzo D'Emidio_Lavoro sullaNorth Korea .pptx
Lorenzo D'Emidio_Lavoro sullaNorth Korea .pptxlorenzodemidio01
 
China's soft power in 21st century .pptx
China's soft power in 21st century   .pptxChina's soft power in 21st century   .pptx
China's soft power in 21st century .pptxYasinAhmad20
 
BDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...
AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...
AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...Axel Bruns
 
TDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s Leadership
TDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s LeadershipTDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s Leadership
TDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s Leadershipanjanibaddipudi1
 
Verified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover Back
Verified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover BackVerified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover Back
Verified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover BackPsychicRuben LoveSpells
 
2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx
2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx
2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docxkfjstone13
 
1971 war india pakistan bangladesh liberation.ppt
1971 war india pakistan bangladesh liberation.ppt1971 war india pakistan bangladesh liberation.ppt
1971 war india pakistan bangladesh liberation.pptsammehtumblr
 
Group_5_US-China Trade War to understand the trade
Group_5_US-China Trade War to understand the tradeGroup_5_US-China Trade War to understand the trade
Group_5_US-China Trade War to understand the tradeRahatulAshafeen
 
Enjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort ServiceDelhi Call girls
 
Kishan Reddy Report To People (2019-24).pdf
Kishan Reddy Report To People (2019-24).pdfKishan Reddy Report To People (2019-24).pdf
Kishan Reddy Report To People (2019-24).pdfKISHAN REDDY OFFICE
 
KAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptx
KAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptxKAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptx
KAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptxjohnandrewcarlos
 
Pakistan PMLN Election Manifesto 2024.pdf
Pakistan PMLN Election Manifesto 2024.pdfPakistan PMLN Election Manifesto 2024.pdf
Pakistan PMLN Election Manifesto 2024.pdfFahimUddin61
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceDelhi Call girls
 
BDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
04052024_First India Newspaper Jaipur.pdf
04052024_First India Newspaper Jaipur.pdf04052024_First India Newspaper Jaipur.pdf
04052024_First India Newspaper Jaipur.pdfFIRST INDIA
 
America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...
America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...
America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...Andy (Avraham) Blumenthal
 
30042024_First India Newspaper Jaipur.pdf
30042024_First India Newspaper Jaipur.pdf30042024_First India Newspaper Jaipur.pdf
30042024_First India Newspaper Jaipur.pdfFIRST INDIA
 
BDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 

Kürzlich hochgeladen (20)

Embed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopko
Embed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopkoEmbed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopko
Embed-2 (1).pdfb[k[k[[k[kkkpkdpokkdpkopko
 
Lorenzo D'Emidio_Lavoro sullaNorth Korea .pptx
Lorenzo D'Emidio_Lavoro sullaNorth Korea .pptxLorenzo D'Emidio_Lavoro sullaNorth Korea .pptx
Lorenzo D'Emidio_Lavoro sullaNorth Korea .pptx
 
China's soft power in 21st century .pptx
China's soft power in 21st century   .pptxChina's soft power in 21st century   .pptx
China's soft power in 21st century .pptx
 
BDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 135 Noida Escorts >༒8448380779 Escort Service
 
AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...
AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...
AI as Research Assistant: Upscaling Content Analysis to Identify Patterns of ...
 
TDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s Leadership
TDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s LeadershipTDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s Leadership
TDP As the Party of Hope For AP Youth Under N Chandrababu Naidu’s Leadership
 
Verified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover Back
Verified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover BackVerified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover Back
Verified Love Spells in Little Rock, AR (310) 882-6330 Get My Ex-Lover Back
 
2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx
2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx
2024 03 13 AZ GOP LD4 Gen Meeting Minutes_FINAL.docx
 
1971 war india pakistan bangladesh liberation.ppt
1971 war india pakistan bangladesh liberation.ppt1971 war india pakistan bangladesh liberation.ppt
1971 war india pakistan bangladesh liberation.ppt
 
Group_5_US-China Trade War to understand the trade
Group_5_US-China Trade War to understand the tradeGroup_5_US-China Trade War to understand the trade
Group_5_US-China Trade War to understand the trade
 
Enjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Rajokri Delhi >༒8448380779 Escort Service
 
Kishan Reddy Report To People (2019-24).pdf
Kishan Reddy Report To People (2019-24).pdfKishan Reddy Report To People (2019-24).pdf
Kishan Reddy Report To People (2019-24).pdf
 
KAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptx
KAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptxKAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptx
KAHULUGAN AT KAHALAGAHAN NG GAWAING PANSIBIKO.pptx
 
Pakistan PMLN Election Manifesto 2024.pdf
Pakistan PMLN Election Manifesto 2024.pdfPakistan PMLN Election Manifesto 2024.pdf
Pakistan PMLN Election Manifesto 2024.pdf
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
BDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Indirapuram Escorts >༒8448380779 Escort Service
 
04052024_First India Newspaper Jaipur.pdf
04052024_First India Newspaper Jaipur.pdf04052024_First India Newspaper Jaipur.pdf
04052024_First India Newspaper Jaipur.pdf
 
America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...
America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...
America Is the Target; Israel Is the Front Line _ Andy Blumenthal _ The Blogs...
 
30042024_First India Newspaper Jaipur.pdf
30042024_First India Newspaper Jaipur.pdf30042024_First India Newspaper Jaipur.pdf
30042024_First India Newspaper Jaipur.pdf
 
BDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Greater Noida Escorts >༒8448380779 Escort Service
 

Data Decoded: Understanding India's Draft Data Protection Bill

  • 2.
  • 3. Background of the Draft Bill ● The Ministry of Electronics & Information Technology constituted a Committee of Experts. ● Chairman – retired SC Judge, Justice B.N. Srikrishna. ● Mandate – study issues relating to data protection in India and suggest measures. ● Committee issued: ○ Data Protection Report - “A Free and Fair Digital Economy Protecting Privacy, Empowering Indians”; and ○ Draft Personal Data Protection Bill, 2018 ● MEITY has sought feedback from public We are here
  • 4. How Does This Draft Bill Become a Law? (Next Steps): ● MEITY to consider feedback from public ● Draft Bill to be modified, if required ● Union Cabinet to pass the draft Bill ● Bill to be introduced in Parliament
  • 5. Important Concepts in the Draft Bill ● Data ● Personal data ● Sensitive Personal Data: ○ Passwords ○ Financial data ○ Health data ○ Official identifier ○ Sex life / sexual orientation / Transgender status / intersex status ○ Biometric / genetic data ○ Caste or tribe ○ Religious / political belief or affiliation ○ Anything else specified by Authority
  • 6. Important Concepts in the Draft Bill (Continued) ● Data principal – natural person to whom data relates ● Data Fiduciary ○ Any person – individual / company / Govt. / entity ○ Determines purpose and means of processing data ● Processing – collection / recording / organizing / storing / disclosure / use / etc. SPD Personal Data Data
  • 7. Obligations of the Data Fiduciary ● Processing in fair and reasonable manner ● Purpose limitation – clear, specific, lawful purposes ● Collection limitation– only necessary data ● Notice - DF to give notice to data principal about factors such as: o Purpose o Categories of data being collected o Identity/contact details of DF o Withdrawing consent o Basis for processing and consequences of not providing data o Identity of other DF or data processors with whom data shared o Cross-border transfer of data o Procedure for grievance redressal o Source of collection etc. ● Quality of data – complete, accurate, not misleading and updated ● Data storage limitation – only as long as necessary ● DF must follow provisions of the Act
  • 8. When can Personal Data be Processed? ● By consent - free, informed, specific, clear and capable of being withdrawn ● For functions of State ● To comply with law or order of court/tribunal ● For prompt action (medical emergencies, safety, etc.) ● For employment purposes ● For reasonable purposes to be specified by the Authority like: ○ Whistle-blowing ○ M&A ○ Credit scoring ○ Prevention of unlawful activity ○ Recovery of debt ○ Publicly available personal data.
  • 9. ● By explicit consent ● For functions of State ● To comply with law or order of court/tribunal ● For prompt action ● Further categories of SPD may be specified by the Authority When can personal data and SPD of children be processed? ● Protects / advances best interest of the child ● Age verification & parental consent ● Guardian data fiduciaries (GDFs): websites for children / DF who process large volumes of personal data of children. ● GDFs cannot profile/track kids or give targeted ads for kids. ● If GDFs are child counselors or child protection services, parental consent is not required. When can Sensitive Personal Data be Processed?
  • 10. Rights of Data Principals ● Right to confirmation and access ○ Confirmation about the fact of processing ○ Summary of the personal data being processed ○ Summary of processing activities undertaken ● Right to correct, complete and update personal data ● Right to data portability - Personal data available with DF can be transferred to another DF on DP’s request ● Right to be forgotten – Upon application to Authority in following cases: ○ When purpose is served ○ When consent has been withdrawn ○ When disclosure was made contrary to provisions of the Bill or any other law
  • 11. How to Exercise These Rights? ● DP to make a request in writing to the DF (except Right to be forgotten) ● If data portability or summary of processing activities sought – DF can charge fee ● DF to comply within reasonable time. ● If request declined by DF, need to give reasons in writing and inform DP about her right to complaint to Authority ● DF not bound to comply with anything from S.24 to 27 if it would harm any other DP.
  • 12. How Does the Bill Impact Businesses? ● Provide ‘Notice’ before collecting Data that is clear, concise and can be easily understood by the average person. ○ This Notice may be in multiple languages if required ● Organisations should provision for individual privacy and innovation can’t take place at the risk of compromising an individual’s privacy. ● Create safeguards like the de-identification of data to prevent misuse. ● Be transparent about data being collected and processed and provide information at periodic intervals about the data that is being processed. ● Maintain at least one copy of data collected on a server located in India.
  • 13. Compliances ● Different standards of compliance for ‘significant data fiduciaries’, data fiduciaries and small entities. ○ Significant data fiduciaries will be classified based on the volumes of data processed, sensitivity of data, turnover, new technologies used, risk of harm from processing. ○ Small entities are organisations with a turnover under 20 lakh, that manually process data and haven’t collected personal data of over 100 people in the last calendar year. ● Report data breaches to the authorities along with measures taken to remedy a breach. ● Conduct annual data audits, through a recognised professional auditor. Conduct Data Protection Impact assessments before using new technologies. ● Maintain records of data collected and the manner of it’s processing. ● Appoint a data protection officer with whom grievances can be raised and who can provide advice to ensure data protection under this Bill.
  • 14. Authorities and Penalties ● The Bill, provides for the creation of a Data Protection Authority and an Appellate Tribunal. ● Penalties under this Bill are as follows: ● These penalties are separate from compensation. 5 crore or 2% of global turnover 15 crore or 4% of global turnover 5,000/- Failure to attend to indvidual's requests 10,000/- Failure to give information to the Authority 20,000/- Failure of significant fiduciaries to comply with orders. 5,000/- Failure of fiduciaries to comply with orders. 1 crore - For significant fiduciaries where no penalty is specified. 25 lakh - For fiduciaries where no penalty is specified. • Not acting promptly on a data breach. • Not undertaking data impact assesment • Not appointing a data protection officer • Not registering with the authority • Unlawful processing of data • Violates the grounds for processing • Processing sensitive personal data or children's data incorrectly • Failure to ensure data security • Transferring personal data contrary to the Act's provisions
  • 15. ● All offences under the Act are cognizable and non-bailable. Offences under the Act are: ○ Transferring data contrary to the Act - 2 lakh fine and/or 3 year imprisonment. ○ Obtaining or selling personal data - 3 lakh fine and/or 5 years in jail. ○ Re-identifying and processing personal data without consent 2 lakh fine and/or 3 years in jail. Offences Under the Bill