SlideShare a Scribd company logo
Amit Khandelwal Legal Counsel- South East Asia SAS
The Rules have emerged from Section 43A of the Information Technology Act, 2000 read with Section 87(2)(oo) of the said Act. Section 43A states: Where a body corporate, possessing, dealing or handling any  sensitive personal data or information  in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining  reasonable security practices and procedures  and thereby  causes wrongful loss or wrongful gain  to any person, such body corporate shall be liable to pay damages by way of compensation, not exceeding  Five Crore Rupees , to the person so affected.
Personal Information (PI)  has been defined as: Any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person. Sensitive Personal Data or Information (SPDI)  has been defined as: (i)         password;  (ii)        financial information such as bank account or credit card or debit card or other payment instrument details;  (iii)       physical, physiological and mental health condition;  (iv)       sexual orientation;  (v)        medical records and history;  (vi)       biometric information;  (vii)      any detail relating to the above clauses as provided to body corporate for providing service; and  (viii)    any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise. Information in public domain and information disclosed under Right to Information Act are excluded from SPDI
It applies to data or information stored “in computer resource” It applies to personal information irrespective of the nationality of the provider It will be applicable when information is collected in India and transferred to any computer resource outside India It will be applicable when the information is neither collected in India nor stored in India but is dealt or handled in India i.e. accessed from India.  BPOs, KPOs, LPOs and captive units will have to comply with privacy laws of outsourcing country and (now) of India!
Requirements under the Rules Type of Data Requirements PI and SPDI Create Privacy Policy:  Such policy should be made available to the provider of information and it should clearly state: 1. The practices and procedures followed; 2. Type of PI and SPDI which is being collected; 3. Purpose and Usage of such information; 4. Process relating to disclosure of information to third parties; 5. Kind of reasonable security practices and procedures followed in the organization: a. Agreed by parties under an agreement; or b. As may be specified in any law; or c. In the absence of above, there should be a comprehensive documented information security programme and policies or is IS/ISO/IEC 27001  (IT- Security Techniques- Information Security Management System- Requirements) certified. Body Corporate to appoint a Grievance Officer (GO) and publish his name and contact details on its website. Grievance to be resolved within 30 days
Type of Data Requirements SPDI Collection, Withdrawal and Transfer of SPDI:  1.   Usage:  SPDI can be  collected only: a. For lawful business purpose; and b. There is a necessity to collect such information Collected SPDI cannot be used/retained for longer than required period. 2.   Consent:  Body corporate should take prior written consent in the form of a fax, e-mail or letter  from the provider of  SPDI. Provider has a right to decline consent. 3.  Knowledge:  The provider of SPDI should be informed about the purpose, the intended recipients, name and address of agency collecting the  information. 4.  Right of Review and Withdrawal:  The provider of SPDI shall have the right to review the information provided by him/her and will have the discretion to withdraw his/her consent. 5.  Transfer of SPDI:  allowed outside the country provided same level of protection exists. Provider’s consent required
Have  PI? No End yes No Follow slide 5 yes Follow slide 5 & 6 Have  SPDI? End
Disclaimer We acknowledge that this presentation is merely an overview and has been prepared by the presenter for your benefit and should not be construed as a legal opinion. It may not be relied upon by any other person for any other purpose, nor is it to be quoted or referred to in any public document or shown to, or filed with any government authority, agency or other official body without presenter’s prior written consent. © 2011 Amit Khandelwal

More Related Content

PDF
Reasonable Security Practices And Procedures And Sensitive Personala 24 06 2...
PDF
Reasonable security practices and procedures and sensitive personal data or i...
PPT
Reasonable security practices and procedures and sensitive personal data or i...
PPT
Data protection in_india
PPTX
Privacy Act
PPTX
Powers of Controller in India
PPTX
Update on Laws and Practices 2020
PDF
The 22nd Legal Forum Seminar (Nov 2021)
Reasonable Security Practices And Procedures And Sensitive Personala 24 06 2...
Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...
Data protection in_india
Privacy Act
Powers of Controller in India
Update on Laws and Practices 2020
The 22nd Legal Forum Seminar (Nov 2021)

What's hot (20)

PPTX
JSA presentation on corporate crimes_27aug2015_hm
PPTX
Right to information
PPT
Personal Data Protection in Malaysia
PPTX
Right to privacy on internet and Data Protection
PDF
Half day public-seminar_on_pdpa_2010_-_250711
PPTX
Principles of mobile privacy
PDF
Mpc recruitment application form (2016)
PDF
Overview of the Egyptian Personal Data Protection Law
PDF
Basic Data Privacy for Non Lawyers
PDF
Data Privacy - Penalties for Non-Compliance
PDF
Data Privacy - Security of Personal Information
PDF
Data Privacy - Rights of the Data Subject
PDF
DATA BREACH CHARTS
PPT
RTI ACT 2005 PART-II
PDF
Data Privacy- Security of Sensitive Personal Information
PPTX
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
PDF
Highlights of the Singapore Personal Data Protection Act 2012
PPTX
Cyber Tribunal and Cyber Appellate Tribunal in Bangladesh
PPT
RTI ACT 2005 PART-III
PPT
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
JSA presentation on corporate crimes_27aug2015_hm
Right to information
Personal Data Protection in Malaysia
Right to privacy on internet and Data Protection
Half day public-seminar_on_pdpa_2010_-_250711
Principles of mobile privacy
Mpc recruitment application form (2016)
Overview of the Egyptian Personal Data Protection Law
Basic Data Privacy for Non Lawyers
Data Privacy - Penalties for Non-Compliance
Data Privacy - Security of Personal Information
Data Privacy - Rights of the Data Subject
DATA BREACH CHARTS
RTI ACT 2005 PART-II
Data Privacy- Security of Sensitive Personal Information
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
Highlights of the Singapore Personal Data Protection Act 2012
Cyber Tribunal and Cyber Appellate Tribunal in Bangladesh
RTI ACT 2005 PART-III
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
Ad

Similar to New Data Privacy Rules By Amit Khandelwal (20)

PDF
India's Data Protection Law 2018- Future Road Ahead
PPT
Data Privacy in India and data theft
PPTX
The Popi Act 4 of 2013 - Implications for iSCM
PPTX
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PDF
Examples of international privacy legislation
PDF
Uchi data local presentation 2020
PPTX
The Protection of Personal Information Act 4 of 2013
PDF
An overview of the Indian Data Privacy Bill
PPTX
Privacy in India: Legal issues
PDF
UAE-Personal-Data-Protection-Law.pdf
PPT
Personal Data Protection in Malaysia
PPTX
POPI Seminar FINAL
PDF
GDPR Changing Mindset
PDF
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
PPTX
Data Ethics: Legal and ethical obligations to Insurance company
PPTX
CHINA PIP LAW ppt.pptx
PDF
Data privacy act of 2012 presentation
PPTX
Digital Personal Data Protection-Fin 2.pptx
PPTX
HIPAA vs GDPR The How, What, and Why ?
PDF
Startups - data protection
India's Data Protection Law 2018- Future Road Ahead
Data Privacy in India and data theft
The Popi Act 4 of 2013 - Implications for iSCM
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
Examples of international privacy legislation
Uchi data local presentation 2020
The Protection of Personal Information Act 4 of 2013
An overview of the Indian Data Privacy Bill
Privacy in India: Legal issues
UAE-Personal-Data-Protection-Law.pdf
Personal Data Protection in Malaysia
POPI Seminar FINAL
GDPR Changing Mindset
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
Data Ethics: Legal and ethical obligations to Insurance company
CHINA PIP LAW ppt.pptx
Data privacy act of 2012 presentation
Digital Personal Data Protection-Fin 2.pptx
HIPAA vs GDPR The How, What, and Why ?
Startups - data protection
Ad

New Data Privacy Rules By Amit Khandelwal

  • 1. Amit Khandelwal Legal Counsel- South East Asia SAS
  • 2. The Rules have emerged from Section 43A of the Information Technology Act, 2000 read with Section 87(2)(oo) of the said Act. Section 43A states: Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation, not exceeding Five Crore Rupees , to the person so affected.
  • 3. Personal Information (PI) has been defined as: Any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person. Sensitive Personal Data or Information (SPDI) has been defined as: (i)         password; (ii)        financial information such as bank account or credit card or debit card or other payment instrument details; (iii)       physical, physiological and mental health condition; (iv)       sexual orientation; (v)        medical records and history; (vi)       biometric information; (vii)      any detail relating to the above clauses as provided to body corporate for providing service; and (viii)    any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise. Information in public domain and information disclosed under Right to Information Act are excluded from SPDI
  • 4. It applies to data or information stored “in computer resource” It applies to personal information irrespective of the nationality of the provider It will be applicable when information is collected in India and transferred to any computer resource outside India It will be applicable when the information is neither collected in India nor stored in India but is dealt or handled in India i.e. accessed from India. BPOs, KPOs, LPOs and captive units will have to comply with privacy laws of outsourcing country and (now) of India!
  • 5. Requirements under the Rules Type of Data Requirements PI and SPDI Create Privacy Policy: Such policy should be made available to the provider of information and it should clearly state: 1. The practices and procedures followed; 2. Type of PI and SPDI which is being collected; 3. Purpose and Usage of such information; 4. Process relating to disclosure of information to third parties; 5. Kind of reasonable security practices and procedures followed in the organization: a. Agreed by parties under an agreement; or b. As may be specified in any law; or c. In the absence of above, there should be a comprehensive documented information security programme and policies or is IS/ISO/IEC 27001 (IT- Security Techniques- Information Security Management System- Requirements) certified. Body Corporate to appoint a Grievance Officer (GO) and publish his name and contact details on its website. Grievance to be resolved within 30 days
  • 6. Type of Data Requirements SPDI Collection, Withdrawal and Transfer of SPDI: 1. Usage: SPDI can be collected only: a. For lawful business purpose; and b. There is a necessity to collect such information Collected SPDI cannot be used/retained for longer than required period. 2. Consent: Body corporate should take prior written consent in the form of a fax, e-mail or letter from the provider of SPDI. Provider has a right to decline consent. 3. Knowledge: The provider of SPDI should be informed about the purpose, the intended recipients, name and address of agency collecting the information. 4. Right of Review and Withdrawal: The provider of SPDI shall have the right to review the information provided by him/her and will have the discretion to withdraw his/her consent. 5. Transfer of SPDI: allowed outside the country provided same level of protection exists. Provider’s consent required
  • 7. Have PI? No End yes No Follow slide 5 yes Follow slide 5 & 6 Have SPDI? End
  • 8. Disclaimer We acknowledge that this presentation is merely an overview and has been prepared by the presenter for your benefit and should not be construed as a legal opinion. It may not be relied upon by any other person for any other purpose, nor is it to be quoted or referred to in any public document or shown to, or filed with any government authority, agency or other official body without presenter’s prior written consent. © 2011 Amit Khandelwal

Editor's Notes

  • #2: India had been criticized by the western world of not having a proper data privacy law in place. Our corporates (esp. outsourcing industry) used to really face difficulties in getting business in India. So with lot of persuasion from Industry forums like NASSCOM, our parliament finally in 2009 was able to include section 43A in the Information Technology Act which partially cater to the need of the hour. But the job was not over, Section 43A did provide the skeleton to the inception of privacy laws in India but the detailed Rules were still to be formed. These Rules were formulated and finally were notified in April 2011.
  • #3: It is notable that Section 43A defined terms like Body Corporate, Reasonable Security Practices and Procedures, it did not define imp terms like Personal Information and SPDI. These terms were left for CG to define in consultation with Industry forums.8ugub
  • #5: Again it is noteworthy that section 43A clearly states that when SPDI