25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

(CALOPPA) 466 and the GLB Act require that websites and f<strong>in</strong>ancial <strong>in</strong>stituti<strong>on</strong> post ―clear<br />

and c<strong>on</strong>spicuous‖ privacy notices. In order to ensure their visibility, and to draw user<br />

attenti<strong>on</strong>, the hyperl<strong>in</strong>ks to the notices must be <strong>in</strong> a c<strong>on</strong>trast<strong>in</strong>g colour and f<strong>on</strong>t. To ensure that<br />

users understand the organisati<strong>on</strong>s‘ <strong>data</strong> use practices, these legislati<strong>on</strong>s make it mandatory<br />

for the notice to c<strong>on</strong>ta<strong>in</strong> certa<strong>in</strong> types of <strong>in</strong>formati<strong>on</strong>, such as the identity of the <strong>data</strong><br />

c<strong>on</strong>troller, the categories of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> collected, whether this <strong>in</strong>formati<strong>on</strong> will be<br />

shared with third parties, and so <strong>on</strong>. The GLB Act goes <strong>on</strong>e step further, through its Privacy<br />

Rule, provides samples of model notices, which organisati<strong>on</strong>s can rely while creat<strong>in</strong>g their<br />

own notices. The Privacy Rule further specifies the language, which must be used while<br />

prepar<strong>in</strong>g a notice, and warns aga<strong>in</strong>st the use of unnecessarily complicated legal jarg<strong>on</strong>.<br />

From the above, it is clear that despite its flaws, notice and choice c<strong>on</strong>t<strong>in</strong>ue to play a central<br />

role <strong>in</strong> many <strong>data</strong> protecti<strong>on</strong> laws. Some jurisdicti<strong>on</strong>s have attempted to address issues<br />

relat<strong>in</strong>g to notice complexity and <strong>in</strong>comprehensibility by requir<strong>in</strong>g that unnecessarily<br />

complicated language not be used. The <strong>data</strong> protecti<strong>on</strong> laws of some jurisdicti<strong>on</strong>s also<br />

prescribe requirements regard<strong>in</strong>g the form and substance of a notice. Despite these measures,<br />

countries are still struggl<strong>in</strong>g with issues relat<strong>in</strong>g to flaws <strong>in</strong> notice design and notice fatigue.<br />

Codes of practice and guidel<strong>in</strong>es issued by a <strong>data</strong> protecti<strong>on</strong> authority provide some clarity <strong>on</strong><br />

how notice can be made more effective.<br />

3.4 Provisi<strong>on</strong>al Views<br />

1. Mandatory notice is a popular form of privacy self-management, which plays a role <strong>in</strong><br />

most <strong>data</strong> protecti<strong>on</strong> laws. Notice is important as it operati<strong>on</strong>alises c<strong>on</strong>sent.<br />

2. The law may c<strong>on</strong>ta<strong>in</strong> requirements regard<strong>in</strong>g the form and substance of the notice.<br />

3. The <strong>data</strong> protecti<strong>on</strong> authority could play an important role by issu<strong>in</strong>g guidel<strong>in</strong>es and<br />

codes of practice that could provide guidance to organisati<strong>on</strong>s <strong>on</strong> the best way to design<br />

notices, so that it c<strong>on</strong>veys relevant <strong>in</strong>formati<strong>on</strong> <strong>in</strong> the most effective manner to<br />

<strong>in</strong>dividuals. This may <strong>in</strong>clude giv<strong>in</strong>g advice <strong>on</strong> how to redesign notices, mak<strong>in</strong>g them<br />

multi-layered and c<strong>on</strong>text specific, <strong>in</strong>form<strong>in</strong>g them of the importance that tim<strong>in</strong>g plays<br />

while provid<strong>in</strong>g notices, etc. This may be further bolstered by sectoral regulators as<br />

well.<br />

4. Privacy Impact Assessment or other enforcement tools may take <strong>in</strong>to account the<br />

effectiveness of notices issued by organisati<strong>on</strong>s.<br />

5. In order to address issues relat<strong>in</strong>g to notice fatigue, assign<strong>in</strong>g every organisati<strong>on</strong> may be<br />

assigned a ―<strong>data</strong> trust score‖ (similar to a credit score), based <strong>on</strong> their <strong>data</strong> use policy.<br />

466 California Onl<strong>in</strong>e Privacy Protecti<strong>on</strong> Act, Educati<strong>on</strong> Foundati<strong>on</strong>: C<strong>on</strong>sumer Federati<strong>on</strong> of California,<br />

available at: https://c<strong>on</strong>sumercal.org/about-cfc/cfc-educati<strong>on</strong>-foundati<strong>on</strong>/california-<strong>on</strong>l<strong>in</strong>e-privacy-protecti<strong>on</strong>act-caloppa-3/,<br />

(last accessed 26 October 2017).<br />

97

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!