Explained: Why Digital Personal Data Protection Bill Matters
The Digital Personal Data Protection Bill of 2023 aims to regulate the processing of digital personal data, balancing individual data protection rights with lawful data usage. The bill outlines principles, rights, and obligations for Data Fiduciaries and Data Principals, promoting a secure and accountable data ecosystem
The Narendra Modi government's Personal Data Protection Bill received the approval of Parliament on Wednesday. This legislation outlines mandates for private companies engaged in online data collection while making allowances for government entities and law enforcement agencies. The Bill's enactment comes after six years since the Supreme Court established the 'Right to Privacy' as a fundamental right. It encompasses measures aimed at preventing the improper utilization of users' personal data by online platforms.
The Digital Personal Data Protection Bill of 2023 aims to regulate the processing of digital personal data while upholding individuals' data protection rights and the legitimate need to use such data for lawful purposes. The bill safeguards data that can identify individuals and outlines the responsibilities of entities (Data Fiduciaries) processing such data, the rights of the individuals (Data Principals) to whom the data pertains and penalties for breaches.
The bill also strives to achieve the following objectives:
- Introduce data protection measures with minimal disruption, ensuring Data Fiduciaries bring necessary changes in data processing.
- Improve the quality of life and business processes.
- Foster India's digital economy and innovation ecosystem.
The bill is founded upon seven principles:
- Consent-based, lawful, and transparent use of personal data.
- Limiting data use to the purpose specified during consent.
- Collecting only essential personal data for the specified purpose.
- Ensuring data accuracy and currency.
- Storing data only as long as required for the designated purpose.
- Implementing reasonable security measures.
- Holding entities accountable through penalties for breaches and violations.
Noteworthy features of the bill include its concise and straightforward nature, with clear language and minimal cross-referencing. Additionally, it employs gender-neutral language by using "she" alongside "he" for the first time in parliamentary law-making, acknowledging women's participation.
The bill grants individuals several rights, including:
- Access to information about processed personal data.
- The right to correct and erase data.
- Redressal of grievances.
- The right to nominate someone to act on their behalf in cases of incapacity or death.
Data Principals can initially approach the Data Fiduciary to enforce their rights. If unsatisfied, they can escalate their complaints to the Data Protection Board.
The bill outlines various obligations for Data Fiduciaries, such as:
- Implementing security measures to prevent data breaches.
- Notifying Data Principals and the Data Protection Board of breaches.
- Erasing data when no longer needed or upon withdrawal of consent.
- Establishing a grievance redressal system and appointing a designated officer.
- Additional responsibilities for Significant Data Fiduciaries, including data audits and periodic assessments.
Children's personal data is protected under the bill. Processing their data requires parental consent and is prohibited if it harms their well-being or involves tracking, monitoring, or targeted advertising.
Exemptions under the bill cover areas such as:
- National security and public order.
- Research, statistics, and archiving.
- Specific categories of Data Fiduciaries like startups.
- Legal rights enforcement.
- Judicial or regulatory functions.
- Offence prevention, detection, investigation, or prosecution.
- Processing non-resident data under foreign contracts.
- Approved mergers or demergers.
The primary functions of the Data Protection Board include:
- Directing remedies for data breaches.
- Investigating breaches and complaints, imposing fines.
- Referring to disputes for resolution and accepting voluntary commitments.
- Advising government action against repeat violators.