25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3.3 Internati<strong>on</strong>al Practices<br />

Despite certa<strong>in</strong> flaws, the mechanism of notice and choice c<strong>on</strong>t<strong>in</strong>ue to be widely used across<br />

many jurisdicti<strong>on</strong>s. These jurisdicti<strong>on</strong>s have attempted to address some of these flaws through<br />

the practices described below:<br />

European Uni<strong>on</strong><br />

The EU GDPR does not use the term ―notice‖ per se. 454 It provides that a <strong>data</strong> c<strong>on</strong>troller must<br />

dem<strong>on</strong>strate that the <strong>data</strong> subject has c<strong>on</strong>sented to the process<strong>in</strong>g of her <strong>in</strong>formati<strong>on</strong>. 455 This<br />

is d<strong>on</strong>e by ensur<strong>in</strong>g that a ―request for c<strong>on</strong>sent‖ (which could be understood to mean a<br />

notice), is presented <strong>in</strong> a manner clearly dist<strong>in</strong>guishable from other matters <strong>in</strong> a c<strong>on</strong>cise,<br />

<strong>in</strong>telligible and easily accessible form- us<strong>in</strong>g clear and pla<strong>in</strong> language. 456 These provisi<strong>on</strong>s are<br />

<strong>in</strong>tended to ensure that the notice c<strong>on</strong>veys necessary <strong>in</strong>formati<strong>on</strong> <strong>in</strong> an easily comprehensible<br />

manner, which is clear to the <strong>data</strong> subject. The EU GDPR‘s notice requirements are<br />

prescriptive <strong>in</strong> nature, and c<strong>on</strong>ta<strong>in</strong> details regard<strong>in</strong>g the types of <strong>in</strong>formati<strong>on</strong>, which must be<br />

provided to the <strong>data</strong> subject, <strong>in</strong>clud<strong>in</strong>g the identity of the <strong>data</strong> c<strong>on</strong>troller, purpose of<br />

process<strong>in</strong>g, <strong>in</strong>tended recipients of the <strong>data</strong>, am<strong>on</strong>g others. It attempts to make choice more<br />

mean<strong>in</strong>gful by <strong>in</strong>dicat<strong>in</strong>g when delivery of the notice will be most effective, and additi<strong>on</strong>al<br />

safeguards, which are to be followed when the <strong>in</strong>formati<strong>on</strong> is not collected directly from the<br />

<strong>data</strong> subject. 457<br />

United K<strong>in</strong>gdom<br />

UK DPA, provides that pers<strong>on</strong>al <strong>data</strong> must be processed fairly and lawfully. 458 The ICO has<br />

issued some guidel<strong>in</strong>es as to what this means. Be<strong>in</strong>g transparent and provid<strong>in</strong>g accessible<br />

<strong>in</strong>formati<strong>on</strong> to <strong>in</strong>dividuals about how their <strong>data</strong> will be used is critical. Transparency through<br />

a privacy notice is an important part of fair process<strong>in</strong>g. The ICO recognises that <strong>in</strong>dividuals‘<br />

expectati<strong>on</strong>s of privacy have changed and very often us<strong>in</strong>g a s<strong>in</strong>gle notice to c<strong>on</strong>vey the<br />

necessary <strong>in</strong>formati<strong>on</strong> will not be an effective approach to c<strong>on</strong>vey necessary <strong>in</strong>formati<strong>on</strong>. It<br />

has provided samples of what a good privacy notice and a bad privacy notice would look<br />

like. 459 It recognises that use of <strong>in</strong>novative techniques, such as multi-layered notices are<br />

helpful <strong>in</strong> c<strong>on</strong>vey<strong>in</strong>g relevant <strong>in</strong>formati<strong>on</strong> to users <strong>in</strong> a clear and accessible manner. Where<br />

<strong>in</strong>dividuals have a choice, with respect to decid<strong>in</strong>g whether their <strong>in</strong>formati<strong>on</strong> can be used, the<br />

privacy notice should give <strong>in</strong>dividuals the opportunity to exercise that choice. 460<br />

454 Regulati<strong>on</strong> (EU) 2016/679 of the European Parliament and of the Council <strong>on</strong> the protecti<strong>on</strong> of natural pers<strong>on</strong>s<br />

with regard to the process<strong>in</strong>g of pers<strong>on</strong>al <strong>data</strong> and <strong>on</strong> the free movement of such <strong>data</strong>.<br />

455 Article 7(1), EU GDPR.<br />

456 Article 7(2), EU GDPR.<br />

457 Articles 12, 13 and 14, EU GDPR.<br />

458 Schedule I, Part I, Paragraph 1, UK DPA.<br />

459<br />

ICO, ‗Good and Bad Examples of Privacy Notices‘, available at: https://ico.org.uk/media/fororganisati<strong>on</strong>s/documents/1625136/good-and-bad-examples-of-privacy-notices.pdf,<br />

(last accessed 23 October<br />

2017).<br />

460 ICO, ‗Privacy Notices, Transparency and C<strong>on</strong>trol‘, available at: https://ico.org.uk/for-organisati<strong>on</strong>s/guide-to<strong>data</strong>-protecti<strong>on</strong>/privacy-notices-transparency-and-c<strong>on</strong>trol/,<br />

(last accessed 23 October 2017).<br />

95

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!