Friday, July 3, 2020

PERSONAL DATA PROTECTION ACT: NEED OF THE HOUR


Apex Courts 9 Bench unanimous judgement in Justice Puttaswamy case pronouncing that, “The right of privacy is a fundamental right; It is a right which protects the inner sphere of the individual from interference from both State and non-State actors and allows the individuals to make autonomous life choices” had attracted various reactions from all the sections of society when pronounced in 2017.
The then Union finance minister Shri Arun Jaitley, a legal acumen in himself, reacted that “Privacy issue went to Supreme Court because previous UPA government brought Aadhaar without legal framework. We framed Aadhaar law ensuring privacy as fundamental right will be protected. Supreme Court accepted privacy is a fundamental right but not an absolute right; judgment is a positive development."
The past and present Law minister, Shri Ravi Shankar Prasad said “The government welcomes the Supreme Court order on right to privacy. SC has affirmed what government had said in Parliament while moving Aadhar Bill. Privacy should be a fundamental right subject to reasonable restrictions."
 “Welcome the SC verdict upholding Right to Privacy as an intrinsic part of individual’s liberty, freedom and dignity. The SC decision marks a major blow to fascist forces," the Congress vice-president Rahul Gandhi tweeted. It was a “sound rejection" of the BJP’s ideology of “suppression through surveillance", Gandhi said.
R. Chandrashekhar, President, Nasscom in 2017 said, “This landmark judgment will ensure that protection of citizen’s privacy is a cardinal principle in our growing digital economy. Besides, it will enhance citizens’ trust in digital services, a prerequisite for widespread digital adoption. The ruling also significantly boosts India’s attractiveness as a safe destination for global sourcing."
Soli Sorabjee, India’s most respected legal luminary commented that “It is a very progressive judgment and protects the fundamental rights of the people. Privacy is a basic right which is inherent in every individual. The unanimity of the bench in giving this decision shows a very good approach of the Supreme Court. Any judgment which enlarges the fundamental rights of the people should be welcome."
These reactions were of 2017 and many expected government to come out with a law soon for protection of Privacy of the individual as a committee was set up under stewardship of Retired Justice Srikrishna to draft the act for Data Protection in 2017 itself.
Much water has been passed between pronouncement of judgement, setting up the committee and today. An Act for protection of Fundamental Rights of People is still a distant dream. It was in July 2018 that the Justice BN Srikrishna-led committee timely submitted its draft bill to the Ministry of Electronics and Information Technology (MEITY) to create a powerful data protection law in India. The draft was finalized after a year of consultations with various stakeholders and came just after the European Union General Data Protection Regulation (GDPR) came into force in May 2018. The Personal Data Protection Bill, 2019 is more important because of the urgent need to regulate data protection and data privacy, be it for online platforms, apps, social networks or even online services including by the government. It was expected when the Winter Session of the Parliament began in November 2019, that key bill, the Personal Data Protection Bill, 2019, will be passed. But it did not happen and presently the bill is before the Committee of Parliament for deliberations and consultations.
The 25% growth from 437.4 million in 2017 to 564.5 million currently in digital users should come as some sort of eye-opener. In a country where digital education, digital security or digital awareness is not priority of any of the digital service providers, the digital users are left on mercy of cyber criminals. These cyber criminals are carrying out innovative cyber attacks which are beyond imagination of the digital users. The most favoured white collared cyber crime is DATA THEFT. It is committed before open eyes of the digital users and digital users are not able to recognise the crime of data theft being committed. There are many high end cyber crimes which cannot be even noticed or detected by 90% of the digital users. Present digital era’s description as Golden Era of Cyber Crimes is not misconceived or ill-founded.
Recently, in view of information available with government of India that 59 Apps are engaged in activities which is prejudicial to sovereignty and integrity of India, defence of India, security of state and public order, the government of India has banned these apps , all of which are originated from China. The government said that the Ministry of Information Technology has received "many representations raising concerns from citizens regarding security of data and risk to privacy relating to operation of certain apps". As per government press release, The Computer Emergency Response Team (CERT-IN) has also received many representations from citizens regarding security of data and breach of privacy impacting upon public order issues”.  So, on this backdrop with the relevant provisions of the Information Technology (Procedure and Safeguards for Blocking of Access of Information by Public) Rules 2009 and in view of the emergent nature of threats these apps were banned.
The measure reason as stated by government is the Risk to Privacy as well as risk to data of the citizen. It is open secret that most of the apps are designed to collect huge personal data from the users. The terms and conditions of each of the app very categorically mention the permissions to be provided by gadget owner prior to installing that specific app. With our permission only, these apps are installed in our devices and hence there are very few who regret this decision of providing permission to camera, messages, contacts, GPRS Location, enabling calls and many more such activities by the apps. This is true for all the apps whether having origin in China or from any other part of world. You will rarely find any app/program which is not interested and designed for collection/storage of personal data. In short we need to have a permanent solution for Protection of the Personal Data of the individual as banning any app is short term solution.
Data is the lifeline of today’s business activities in digitalised world and on backdrop COVID 19 where most the world is opting for Work from Home and making maximum use of online platforms, the data theft threat is looming large in cyberspace. Yes , the incidents on Chinese Border has added fuel and security dimension to this Data Theft and Data security of the citizen and banning the 59 apps of Chinese origin by government can be justified. But bigger issue of Data Security and Protection of Privacy by other apps remains to be resolved. What can be said about big social media giants like Facebook, Whatsapp, Instagram or online meeting platforms like Zoom? Are these companies not involved in compromising Security of individual citizen and thereby invading constitutional guaranteed Privacy Right of the Indian citizen?
The most recent incident of trolling of Hon. Chief Justice of India for just sitting on a high-end mobike without headgear and mask and subsequent clarification/warning about not invading Privacy of Hon Chief Justice of India justifies the need of passage of Personal Data Protection Act by the parliament. When Hon Chief Justice’s privacy is vulnerable, what could be said about Privacy of we individual citizen? Are all citizens so powerful like Hon. CJI? What remedies are available to individual citizen for protection of their Right to Privacy? Under which law the reliefs can be sought?
Putting of Personal Data Protection Act in place is the only solution. The preamble of act itself describes the objects of the act as the act to provide for protection of the privacy of individuals relating to their personal data, specify the flow and usage of personal data, create a relationship of trust between persons and entities processing the personal data, protect the rights of individuals whose personal data are processed, to create a framework for organisational and technical measures in processing of data, laying down norms for social media intermediary, cross-border transfer, accountability of entities processing personal data, remedies for unauthorised and harmful processing, and to establish a Data Protection Authority of India for the said purposes and for matters connected therewith or incidental thereto.

The preamble states that the right to privacy is a fundamental right and it is necessary to protect personal data as an essential facet of informational privacy and whereas the growth of the digital economy has expanded the use of data as a critical means of communication between persons and which needs to be protected.

So the significance of Personal Data Protection Act can be found in its preamble only and various rights available, after passage of this Act, to Data Principal like correction of Information, Erasure of information, discontinuing the use of information after the purpose of consent is over and deletion of information etc. highlights how personal data of the individual can be protected.

As most of the apps are exploiting our sensitive personal information without our explicit consent and this can be verified by huge spike in cyber crimes recently, the best way to deter/ control these apps and make citizen more powerful is by passage of Personal Data Protection Act. This act will give much needed tools to the citizen as well as government to check culprits involved in theft of personal data or invasion of Data privacy.

  
To allow the individuals to make autonomous life choices including choice about his Data sharing, the Hon Apex Court mandated a need of law which can give an individual, right about his personal data protection. This object can only be achieved by passage of The Personal Data Protection Act and its effective implementation. Hence in my view, passing and enforcing The Personal Data Protection Act is need of hour and should be top priority of the government.

Thursday, May 21, 2020

Session with Adv. Mahendra Limaye on Cyber Laws and Cyber Safety

Session with Adv. Mahendra Limaye on Cyber Laws and Cyber Safety

Tuesday, May 12, 2020

Who has legal liability if Aarogya Setu Data is compromised?



The Aarogya Setu Data Access and Knowledge Sharing Protocol, 2020 was notified by Ministry of Electronics and Information Technology on 11 May 2020. This has again led to new debate regarding whether after this notification Aarogya Setu app Data is safe? Adv Dr Mahendra Limaye, a cyber legal consultant, analyzed the notification and his reading of the notification is as below.
Functioning of Aarogya Setu app as per notification relates to technology and data management and certain necessary steps required to be taken to ensure its effective operation to detect and mitigate the spread of Covid 19 pandemic and enhance government preparedness at all levels. So the aim and object of the Aarogya Setu App was never a question and it is much applauded move by the government.
In order to ensure secure collection of data, protection of personal data of individuals and efficient use and sharing of personal or non-personal data for mitigation and redress this notification was specially issued. So we must understand that this notification was fall out of many objections raised towards security of the personal data collected through this app and about accountability of the data collected through this app and specially when some hacker claimed about vulnerability of this huge database. This response also shows government’s responsive approach to security concerns raised about the app and this is welcome move.
The notifications says that in order to formulate appropriate health responses for addressing the COVID-19 pandemic, data pertaining to persons who are infected, at high risk of being infected or who have come in contact with infected individuals is urgently required. This data includes demographic data, contact data, self assessment data and location data, collectively called ‘response. The demographic data includes the name, mobile number, age, gender, profession and travel history of an individual. Contact data covers data about any other individual that a given individual has come in close proximity with, including the duration of the contact, the proximate distance between the individuals and the geographical location at which the contact occurred. Self assessment data means the responses provided by that individual to the self assessment test administered within the Aarogya Setu mobile application. Finally Location data means data about the geographical position of an individual in latitude and longitude. So the broad categories of data collected through this app by government is once again made public by this notification.

The notification also states that the Ministry of Electronics and Information Technology, Government of India (“MeitY”) is designated as the agency responsible for the implementation of this Protocol and its developer, the National Informatics Center shall, under this Protocol be responsible for collection, processing and managing response data collected by the Aarogya Setu mobile application.

So it is highlighted that MeitY will be only supervising authority. So the government has brought NIC in picture for protection of entire data in the capacity of developer and made its role minimal in capacity of implementer.



Highlights of Principles for collection and processing of response data:
a. Any response data and the purpose for which it is collected by NIC shall be clearly specified in the Privacy Policy of the Aarogya Setu mobile application.
b. NIC shall collect only such response data as is necessary and proportionate to formulate or implement appropriate health responses. Further, such data shall be used strictly for the purpose of formulating or implementing appropriate health responses and constantly improving such responses.
c. NIC shall process any data collected by it in a fair, transparent and non-discriminatory manner.
d. Contact and location data shall by default, remain on the device on which the Aarogya
Setu mobile application has been installed after such data has been collected. It may be uploaded to the server only for the purpose of formulating or implementing appropriate health responses.
e. Contact, location and self assessment data of an individual that has been collected by NIC shall not be retained beyond the period necessary to satisfy the purpose for which it is obtained which, unless a specific recommendation to this effect is made in the review under Para 10 of this Protocol, shall not ordinarily extend beyond 180 days from the date on which it is collected, after which such data shall be permanently deleted. Demographic data of an individual that has been collected by NIC shall be retained for as long as this Protocol remains in force or if the individual requests that it be deleted, for a maximum of 30 days from such request, whichever is earlier.
f. The response data shall be securely stored by NIC and shall only be shared in accordance with this Protocol.

Principles for sharing of response data have also been stated which highlights that 1) Response data containing personal data may be shared with various government agencies/bodies where such sharing is strictly necessary to directly formulate or implement an appropriate health response.2) Response data in de-identified form may be shared with various bodies with whom such sharing is necessary to assist in the formulation or implementation of a critical health response.3) NIC shall, to the extent reasonable, document the sharing of any data and maintain a list of the agencies with whom such data has been shared.

Obligations of entities with which response data is shared are like use of such data strictly for the purpose for which it is shared, the data accessed and used by such entities should not be retained beyond the period necessary to satisfy the purpose for which it is shared, in any circumstance; such data shall not ordinarily be retained beyond
180 days from the date on which it was accessed, after which such data shall be permanently deleted etc.

The main concern is who is liable for any privacy violations committed through security breach of Aarogya Setu App? This notification does not provide any clarity to said concern. It was clarified that any violation of these directions may lead to penalties as per section 51 to 60 of the Disaster Management Act, 2005 and other legal provisions as may be applicable. Legal position for the protection of sensitive personal information under section 43A of Information Technology Act 2000 is that state cannot be made responsible in case of breach of data or lapse in protection of sensitive personal data. Through this Notification State has clarified that it is acting only in supervisory capacity and National Informatics Center, which is developer of the Aarogya Setu app will own entire responsibility as far as security and sharing of Response Data is concerned.
As regards section 51 to 60 of the Disaster Management Act they have one important protection as related to breach of data and the protection is “ unless he proves that the offense was committed without his knowledge or that he exercised all due diligence to prevent the commission of such offense”.

In case of any data breach through Aarogya Setu app defense will be always available that all due diligence was observed to prevent the commission of offense like Data Theft etc. So in my view this notification clearly fails to provide any specific measures which government has suggested for protection of Data of millions of Aarogya Setu app users. Also the other question remains is whether the provisions of the Disaster management Act can be enforced after Disaster is over? If data breach is reported after present pandemic is over then whether these provisions can be enforced, remains a question in my mind.     


Advocate Dr. Mahendra Limaye

About the author- Advocate Dr Mahendra Limaye is Cyber Legal Consultant and Cyber Law practitioner in India. He specifically practices in Information Technology Act based litigation's before Civil as well as Criminal Courts in India. He has obtained his doctorate on topic Fundamental Rights and Cyberspace. He can be contacted on mahendralimaye@yahoo.com or + 919422109619.

Thursday, May 7, 2020

"Bois Locker Room" and what next we are waiting for?


Its only when such episodes get national publicity suddenly the whole digital world becomes awake, all so called human right activists become active and start hue and cry about regularisation of social media etc. These are the same people who were at forefront in matter of Palghar incident and came down heavily of Information Technology Act section 66A which ultimately led to abolition of the same.
What we sow we reap is old saying. Our society consists of the same people who had seen section 66A of I T Act as draconian and don’t wanted social media to be regulated. They saw regulating social media, which according to them is the biggest tool of freedom of speech and expression, as curtailment of Fundamental Rights and ultimately our Apex Court also viewed in similar perspective.
The underlying object of regulating social media with reasonable restrictions was never debated seriously and nobody has taken a futuristic view about the same. With many similar incidents gradually happening every passing day and when it comes to flash point in Bois Locker Room issue, people again started debating the need to regulate social media. So is this completion of the circle?
We stared with section 66A which regulated online posts on various grounds in 2008, then came 2015 Apex Court Judgement striking down section 66A of I T Act and now with the incident of Bois Locker Room there will be again enactment of some provisions for regulating social media. Unfortunately all this is happening when most awaited regulation regarding Personal Data Privacy is being studied by Indian Parliament. When in Puttuswamy case in July 2017, a need was felt to have a regulation to protect privacy of the individuals and the panel was formed under chairmanship of Justice Shrikrishna (Retd.) to draft new regulation. The Shrikrishna commission has submitted draft bill in July 2018 and it was before parliament since then and recently a high powered committee is again set up to finalise the same.
If this is the level of priority for Privacy regulation in India and in absence of section 66A of I T Act there in no deterrence to perpetrators of such heinous acts through Social Media and Bois Locker Room incidents will happen regularly.
What was the incident?
An 18 year, Class 12 student resident of Noida, started an Instagram group named "Bois Locker Room", on which obscene messages and morphed photos of underage girls were shared. 27 more students of prominent Delhi schools have been members of the group, some were underage and some 18 and older. The chatroom, conversation was exposed by a girl, who was targeted in the group chats and this has drawn massive anger, shock and disgust on social media. The manner in which Class 11 and 12 students casually discussed "gang-raping" girls, sexualized and slut-shamed those in screenshots of chats have gone viral on Twitter and other social media.
"We absolutely do not allow behaviour that promotes sexual violence or exploits anyone, especially women and young people, and have taken action on content violating our Community Standards as we were made aware of it," was the Facebook spokesperson’s response on the episode. The official age of joining Instagram is 13 or above in India as per their policy.
In India 13 year old person is not capable of entering into contract but these social media giants are making mockery of Indian regulation by allowing these young kids by providing them such platforms.
There are basically few questions which need serious debate according to me.
1)    Should social media be regulated? If yes by whom?
2)    Should social media obey right to be forgotten or right to modify one’s personal information?
3)    Do we have Personal Date Privacy Act as a national priority?
4)    Could porn contents be specifically moved to different domains like .xxx?
5)    Is this encroachment of digitalisation in every walk of life is must?
6)    Are people really aware about threats posed by AI and other activities?
7)    When Cyber Awareness Education will be taught to digital netizens?
Unless we collectively provide answers to these questions such incidents are bound to happen. For that instance even if you go through confession pages of schools you will find many such indecent acts by students, who I am sure are not teens.
If we investigate this scam, the first question comes to my mind is from where the teen got hold of the photographs? All of us know the answer is simple. The victims themselves might have uploaded these photographs without thinking that these photographs could be grabbed by anyone and used on any place on the earth. At the time of uploading picks they were never told what the consequences of such acts are. I can go one step further and caution the readers that there are syndicates which are trapping many persons carrying out indecent act on camera and blackmailing them.
Second question is regarding how teens of age group13/14 were given such liberty by their parents to use social media without proper supervision. Are those parents liable for punishment for acts of their minor wards? Yes they must be definitely penalised similar to new provisions in Motor Vehicle Act, where parents are liable for fine/jail term in case they handover vehicle to their under aged ward. Without parents supervision digital education will prove to be a disaster in country of digital illiterates.
Third question is under which provisions of law action will be taken and against whom?
This is very tricky situation because as per reports few are teens and will be protected being Juvenile. Those who are above 18 might not have passed any comments which could be strictly punishable under provisions of I T Act. If IPC is applied then act being committed in Cyber Space must be covered under provisions of I T Act and which provisions of I T Act are applicable? It’s not Identity Theft nor Personating nor Violation of Privacy as per various provisions of section 66 of I T Act. Can section 67 or 67A of I T Act be imposed?
What next is real question and answer for same is lies in answers of Seven questions posed by me earlier.
The power of collective will by self restraint, to make social media a better place can only make it possible. All the stake holders like we netizens, government of all the nations, social media giants along with search engines should come forward and extend best possible solution which will decide the course of future. From my side CYBER AWARENESS IS THE ONLY MANTRA which we are relentlessly carrying out since last decade.

Advocate Dr. Mahendra Limaye

About the author- Advocate Dr Mahendra Limaye is Cyber Legal Consultant and Cyber Law practitioner in India. He specifically practises in Information Technology Act based litigations before Civil as well as Criminal Courts in India. He has obtained his doctorate on topic Fundamental Rights and Cyberspace. He can be contacted on mahendralimaye@yahoo.com or + 919422109619.

Tuesday, April 28, 2020

Adv Dr. Mahendra Limaye’s reply on “don’t stifle our digital economy with overbearing regulations” published in LiveMint.


Adv. Sidhant Kumar has written an article titled “don’t stifle our digital economy with overbearing regulations”, which was published in Live Mint. The article is about Personal Data Protection Bill 2019 and if passed what would be its effect on Indian Digital Economy.
The author believes that our leading digital economy received resounding validation through Facebook’s $5.7 billion investment in Jio Platforms. This according to me may not be entirely appropriate view. It could be at the most seen as marriage of convenience or compulsion. The debt trap in which Reliance Industries is passing through after huge investments in Jio and sharp fall in oil prices world over is well-known and its deal with Saudi company Armaco has already ran into trouble. On the other side Facebook wants to have some influential partner in India which will influence Indian government policies and more particularly on crypto currency and digital money by companies not having their offices in India. So this deal should not be treated as validation of India as investment destination by companies based in US.
The author also has raised five major objections in proposed PDPB 2019, which are baseless and without application of legal mind and needs to be countered. So let’s go by the objections raised by learned author.
Firstly the author feels that pivot of the framework appears to be a domineering mandate to be given to a data regulator, structurally geared to intervene rather than facilitate.
The functions and duties of Data regulator as per proposed bill are 1) It shall be the duty of the Authority to protect the interests of data principals, prevent any misuse of personal data, ensure compliance with the provisions of this Act, and promote awareness about data protection. 2) monitoring and enforcing application of the provisions of this Act; 3) taking prompt and appropriate action in response to personal data breach in accordance with the provisions of this Act; 4) maintaining a database on its website containing names of significant data fiduciaries along with a rating in the form of a data trust score indicating compliance with the obligations of this Act by such fiduciaries; 5) examination of any data audit reports and taking any action pursuant thereto; 6)  monitoring cross-border transfer of personal data etc.
These duties and functions are mostly regulatory and appellate authority is prescribed if any arbitrariness is observed by the authority or anyone is aggrieved by the order of regulator’s mechanism. So it’s totally wrong to state that mandate of only intervening is wasted in hands of regulator. Rather prompting awareness programs and ensuring compliance from various fiduciaries shows its responsibilities as facilitator.

 Second, the Bill has broad-based restrictions on the transfer of data overseas from India, which could hive our market off from the global digital economy.
This is totally misconceived and misleading statement since the bill at section 33 makes it clear that subject to the conditions in sub-section (1) of section 34, the sensitive personal data may be transferred outside India, but such sensitive personal data shall continue to be stored in India.  Section 34 (1) says the sensitive personal data may only be transferred outside India for the purpose of processing, when explicit consent is given by the data principal for such transfer, and where—
(a) The transfer is made pursuant to a contract or intra-group scheme approved by the Authority and (b) the Central Government, after consultation with the Authority, has allowed the transfer to a country or, such entity or class of entity in a country or, an international organisation. This makes it amply clear that permissions can be sought for transfer of data overseas in exceptional circumstances’.  So this itself explains the concerns of the author are false and if he is advocating that data be transferred cross border without any government restrictions then I think he should show any example across the world where any country has allowed free flow of data trans-border without any restrictions.

Third objection of the author regarding  the Bill seeking to protect privacy by way of what looks like a regulatory sledgehammer that imposes extensive compliance requirements with little aid to data protection needs explanation from author himself. If he thinks some provisions of Data protection are arbitrary or impractical he should point out those specific provisions rather than painting entire provisions alike. When stakes involved are high the degree of care and protection needs to be the utmost and same principle seems to be followed in framing the law. Data Protection is core and the worldwide examples of social media giants flaunting these norms are in open domain. The level of security needs to be balanced taking into considerations millions of digital illiterates exposed to digitalisation and author seems to be concerned about these digital sharks which are ever eager  to latch on the private sensitive personal data on the users.
Fourth objection is that the Bill sets forth an inflexible framework that is bereft of any formal consultative rule-making process, which is likely to stifle innovation in the sector. The author seems to be unaware about how much deliberations and discussions and public debates took place prior to introduction of this bill and shows his lack of knowledge. He is more concerned about what will happen to innovations in this sector as they all will be regulated in some or the other law in future. Lawlessness has prevailed in digital world for long and we are paying price for the same.
Lastly his objection is about substantial portions of the Bill being out of sync with international data protection practices, which could blunt India’s competitive advantage as a digital market. Again these are hollow statements without any proof to back the same. The author seems to be fond of most loved one keys known as Ctrl C and Ctrl V and used them to throw baseless allegations without coming up with any concrete evidence.
Being an Advocate it was expected of him to put forward some evidence/logic backing his allegations but he seems to have leveled the allegations without making any preparations and with some ulterior and oblique motive. What it is, presently not known to me, but at least after this rebuttal it is expected from the author to come up with more studied document which will enlighten illiterates like me, more about the topic.
Some counters to his specific statements:
1) Each Facebook user in Asia (except China) generates only $11 of advertising revenue a year. But who is beneficiary of this revenue, the author has not explained. Does our government get any tax on the same?
2) In its present form, the Personal Data Protection Bill could result in the largest expansion of the regulatory state in India since economic liberalization in 1991. The author has forgotten that The Personal Data protection bill’s objective is to “ensure growth of the digital economy while keeping personal data of citizens secure and protected.” It was also mentioned in preface of Personal Data protection bill that the issue of data protection is important both intrinsically and instrumentally. Intrinsically, a regime for data protection is synonymous with protection of informational privacy. As the Supreme Court observed in Puttaswamy’s, “Informational privacy is a facet of the right to privacy. The dangers to privacy in an age of information can originate not only from the state but from non-state actors as well. We commend to the Union Government the need to examine and put into place a robust regime for data protection. The creation of such a regime requires a careful and sensitive balance between individual interests and legitimate concerns of the state.”
Instrumentally, a firm legal framework for data protection is the foundation on which data driven innovation and entrepreneurship can flourish in India. Fostering such innovation and entrepreneurship is essential if India is to lead its citizens and the world into a digital future committed to empowerment, experiment and equal access, observed by Apex court in India and thereafter Justice Shrikrishna committee was formed and which recommended the draft Personal Data Protection Bill after due deliberations and consultations with the experts.

3) He criticizes the creation of a Data Protection Authority with the power to impose penalties to the tune of 4% of a company’s global turnover but forgot that Competition Commission of India has also imposed in Feb 2018 a penalty amounting to 5% of the average revenue generated from India over the three years to FY15, an amount of 135.85 crore and a maximum penalty of 10% can be imposed under the Act.
4) The author criticizes that the Bill contains substantial restrictions on the transfer of sensitive personal data (including financial and health data) outside India and authority’s prior approval would be needed for any such transfer. Has the author gone through provisions of Personal Data protection and more specific to Health data prevailing across globe and more particularly in US? The US healthcare act HIPPA and HITECH mandates even non US companies to be HIPPA compliant if they are handling any health data related to citizen of US.
5) According to the author, Bill also requires large players to have data protection officers physically located within India. These proposals could have an adverse impact on our digital economy, the basic characteristic of which is connectivity beyond barriers. When Indian companies handling any data related to health parameters of US citizen, they have to be compliant with US laws but when Indian law mandates Data Protection Officer to be located in India the author dislikes the same. The present provision does not say he should be Indian Citizen and the physical presence of Data Protection officer in India will rather ease the burden on many foreign companies as DPO will be in better position to understand the situation on ground while performing his duties. This in turn will create more job opportunities to Indian people and will have positive impact on Indian economy.
6) The outside world is likely to see these measures as less about protection and more about protectionism. It needs to be mentioned that most of the provisions of PDPB 2019 are inspired or influenced by GDPR which is already operative in European Union and GDPR is never seen as protectionism of data of European citizen etc. And when our Apex Court has been vocal that Right to Privacy is integral part of our Fundamental Rights and there can be always reasonable restrictions (as contended by author) on exercise of Fundamental Rights in exceptional circumstances.
7) The Bill contains extensive compliance requirements, including the conduct of audits and impact assessments to be filed with the Authority. It would have been better if the author has been kind enough to make few suggestions to make compliance requirement simpler. The normal accounting audits by tax authorities were also seen as stringent initially. The personal data in today’s world of digitalisation is equivalent to free and fresh air required for one’s physical survival. It’s fundamental responsibility of state to see that all its citizen get free and unpolluted air for which there are many environment friendly regulations related to Pollution, Plastic usage etc. passed by parliament. Similarly the Personal Data being part of fundamental rights, its protection becomes responsibility of our government and if stringent provisions are needed to safeguard interest of Indian Citizen, the parliament has every right to do so.
8) The author has shamelessly conceded that the fulcrum of the Reliance-Facebook deal would be the transformation of WhatsApp, a messaging platform, into a one-stop platform for a large number of everyday transactions. Facebook’s bet on India underscores India’s enormous potential as a market. But author has not taken any pain to study what is revenue model of Facebook or Whatsapp? How the only messaging platform, Whatsapp, without any commercial or revenue generating model could survive this long? It has been proved time and again that most social media companies trade in data and make enormous amount of money by such trade alone and still there are few who want that trade should remain unregulated forever. The PDPB only intends to have some safeguards in place where the privacy or confidentiality of the information should be maintained by social media companies or for that matter all data fiduciaries.
The author should have used his knowledge to point out the specific lacunas, if any, in the PDPB2019. Lot of time is already wasted in passage of this crucial act which is concerning Fundamental Right of, practically every citizen of this country.

I hope that to my best abilities I have tried to advocate need for passage of Personal Data Protection Bill 2019 at the earliest. The amendments are always possible once the law is implemented and enforced and tested on various fronts.


Advocate Dr. Mahendra Limaye

About the author- Advocate Dr Mahendra Limaye is Cyber Legal Consultant and Cyber Law practitioner in India. He specifically practises in Information Technology Act based litigation's before Civil as well as Criminal Courts in India. He has obtained his doctorate on topic Fundamental Rights and Cyberspace. He can be contacted on mahendralimaye@yahoo.com or + 919422109619.