Showing posts with label Data Protection Bill. Show all posts
Showing posts with label Data Protection Bill. Show all posts

Thursday, December 12, 2019

Data Protection Bill: Raising more concerns than satisfying them

In an era of technological advancement, where the growth of the digital economy has meant the use of data as a critical means of communication, the Personal Data Protection Bill is proposed to ensure the informational privacy of individuals, and ensuring empowerment, progress and innovation

The Personal Data Protection Bill was introduced in the Lok Sabha on Wednesday, and referred to a Joint Select Committee (JSC) following a voice vote.

Well, according to parliamentary procedure, the Bill could also have been referred to the departmental committee, which in this case, would be the parlimentary standing committee on information technology, headed by Congress leader Shashi Tharoor.

However, it didn’t happen that way and Tharoor objected to the proposal of sending the Bill to the JSC and also wrote to Lok Sabha Speaker Om Birla to register "strong concerns" with Prasad's proposal. He said the Committee on IT has a mandate and a parliamentary responsibility to examine all matters related to information technology, electronics, telecommunications, postal services, and allied services.

As a matter of fact, the draft was not circulated well in advance of its presentation in Parliament and comments and submissions made during the drafting process were not made public.

Besides, the government has taken extraordinary measures to reduce public scrutiny, and even Parliamentary examination of the Personal Data Protection Bill. This lack of scrutiny makes it more likely that multiple areas of concern will not be addressed. Some of them include:

The independence of the proposed Data Protection Authority (DPA), which has been weakened as all members must be from the executive arm of government. This contrasts with the Srikrishna Committee’s suggestion that the DPA induct individuals with executive, judicial, and external expertise.

Besides, if social media platforms are forced to provide processes for “voluntary” user-verification, this would chill freedom of expression, and impinge on the privacy of those who chose to be verified.

Any user who does not submit “voluntary” verification and remains anonymous could also be specifically targeted by government agencies. Moreover, it would increase the risk of profiling, and data breaches as more data would flow to social media platforms.

The mandate for enforced transfer of “non-personal” data to government could also lead to abuse and misuse.

This means even anonymised information about e-commerce sales patterns can, for example, be used to infer personal details like caste, religion, medical conditions, sexuality, reading habits and so on.

Tying non-personal data to personal data, such as electoral rolls, income tax records, mobile call and internet-usage patterns and social media usage is possible since government has access to such data and a free hand with surveillance.

Critics argue that it is a pity that India’s first privacy legislation has so many holes.

However, looking at the positive front, the bill ensures...

Wednesday, December 11, 2019

Firms developing new tech can avail of exemption from data privacy rules

The government has proposed that companies developing innovative technologies for public good can avail of exemption from the proposed data privacy rules for a limited period.

As part of the draft Data Protection Bill, 2019, cleared by the Union Cabinet last week, the Centre has proposed the creation of a “regulatory sandbox” to ensure that the privacy law doesn’t curtail the ability of companies, especially start-ups innovating around emerging technologies, in the initial phases.

Sandbox refers to a testing environment that enables isolated execution of new software or programme before its mass roll-out.

“The authority shall, for the purposes of encouraging innovation in artificial intelligence (AI), machine learning (ML) or any other emerging technology in public interest, create a sandbox,” the draft Bill read.

“Any data fiduciary whose privacy by design policy is certified by the Authority under Sub-section (3) of Section 22 shall be eligible to apply, in such manner as may be specified by regulations, for inclusion in the sandbox created under Sub-section (1),” it added.

With the sandbox provision, the government has balanced out promoting innovation while furthering individual privacy and state interest, said Arun Prabhu, partner at law firm Cyril Amarchand Mangaldas.

“Companies developing innovative technology in areas, such as AI/ML and big data may be well placed to avail of this sandbox.”

According to provisions in the Bill, the sandbox will be managed by the data protection authority, which will decide on such requests. Companies can apply for inclusion in the sandbox by furnishing details of their innovative use of technology and its benefits. Upon inclusion, qualified entities will be excluded from collection, storage and purpose limitation under the Bill, thereby significantly expanding the usage of the data that are available with them.

The exemption will be for a period of 12 months, but can be renewed twice, taking the maximum possible exemption period to 36 months.

Wednesday, December 4, 2019

E-commerce, tech firms call for clarity on Personal Data Protection Bill

Uncertain about their future and the ramifications for their businesses, the country’s e-commerce and technology industries want the Personal Data Protection Bill to take into account their fears and business models.

According to several industry insiders, there exists several ambiguities in the current draft of the Bill. Clarity is required on classification of data and consent requirements.

The first draft was released last year and underwent a rigorous consultation process, under which the ministry of electronics and information technology received over 600 responses. However, it did not make them public. The data protection law, once passed, will apply across industries, and not just Internet or technology firms. “We look forward to reviewing the full text of the Bill, and are hopeful that the Centre will support Indian businesses’ ability to collaborate with US partners and reduce e- barriers that would compound investment uncertainty,” said Kumar Deep, country manager, India Information Technology Industry Council.

The biggest fear many of the e-commerce firms have is the possible requirement to change business models overnight, which would drastically increase costs as well as disrupt businesses. E-commerce firms bore the brunt of overnight changes when the government changed the foreign direct investment rules earlier this year. “When the new FDI norms in e-commerce kicked in, we had to change a lot of our processes. We just hope the Centre understands our business models and gives us time to put our point across as well,” said a senior public policy advocate.

According to industry experts, the Bill creates a need for the data fiduciary to repeatedly obtain consent from the data principal for every step of the processing activity.

“The problem gets aggravated when data collection and processing are done by different agencies, in which case, each fiduciary will have to take consent at every step of the operation. Such ambiguities lead to unnecessary compliance burden on companies and hinders the ease of doing business,” said Salman Waris, managing partner at TechLegis Advocates & Solicitors, a law firm.

Another issue that the industry has sought clarity on is the Bill talking of consent and explicit content.

While adverse data localisation norms around storing and more importantly processing data could affect a host of ecommerce firms, some of them believe that strong data protection norms would help in increasing transparency.

Another contentious issue has been the role of the data protection authority. “The Bill also talks about establishment of the Data Protection Authority of India. Organisations would want to understand the clear roles of the authority and how it impacts them,” said Jaspreet Singh, Partner – Cyber Security, EY.