25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

This ground covers two types of scenarios. First, where process<strong>in</strong>g is necessary for the<br />

performance of a c<strong>on</strong>tract to which the <strong>data</strong> subject is a party. This is a strictly <strong>in</strong>terpreted<br />

provisi<strong>on</strong> and does not cover situati<strong>on</strong>s where process<strong>in</strong>g is not genu<strong>in</strong>ely necessary for the<br />

performance of a c<strong>on</strong>tract, and is unilaterally imposed by the entity process<strong>in</strong>g <strong>in</strong>formati<strong>on</strong>.<br />

Therefore, a determ<strong>in</strong>ati<strong>on</strong> of the precise rati<strong>on</strong>ale of the c<strong>on</strong>tract, its substance and<br />

fundamental objective is essential. 474<br />

Sec<strong>on</strong>d, this ground is also <strong>in</strong>tended to cover any process<strong>in</strong>g activity, which could take place<br />

prior to enter<strong>in</strong>g a c<strong>on</strong>tract. This <strong>in</strong>cludes pre-c<strong>on</strong>tractual relati<strong>on</strong>s, where the steps are taken<br />

at the <strong>in</strong>itiative of the <strong>in</strong>dividual. For example, if an <strong>in</strong>dividual requests an <strong>in</strong>surance quote<br />

from a car-<strong>in</strong>surance company, the <strong>in</strong>surer would be justified <strong>in</strong> process<strong>in</strong>g the <strong>in</strong>dividual‘s<br />

pers<strong>on</strong>al <strong>data</strong> <strong>in</strong> order to provide this service. 475<br />

(ii)<br />

Legal Obligati<strong>on</strong><br />

For this ground to be applicable, process<strong>in</strong>g of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> must be necessary for<br />

compliance with a legal obligati<strong>on</strong>, or a mandatory requirement under law. 476 For <strong>in</strong>stance, if<br />

a bank were required to report suspicious transacti<strong>on</strong>s under anti-m<strong>on</strong>ey launder<strong>in</strong>g laws, this<br />

situati<strong>on</strong> would be covered under this ground.<br />

(iii) Vital Interest<br />

This ground may be used <strong>on</strong>ly <strong>in</strong> very limited circumstances, such as where there is a there is<br />

a threat to the life or health of the <strong>in</strong>dividual. The Recitals to the EU GDPR clarifies that this<br />

ground must <strong>on</strong>ly be used to protect an <strong>in</strong>terest essential to the life of the <strong>in</strong>dividual. 477<br />

However, there is no clarity <strong>on</strong> what c<strong>on</strong>stitutes a threat to life, whether the threat must be<br />

immediate, and what the scope of this ground should be.<br />

(iv) Public <strong>in</strong>terest task, or the exercise of official authority<br />

The ground deal<strong>in</strong>g with public <strong>in</strong>terest covers two situati<strong>on</strong>s. First, where the entity<br />

collect<strong>in</strong>g the <strong>in</strong>formati<strong>on</strong> has official authority, and process<strong>in</strong>g is essential for exercis<strong>in</strong>g this<br />

authority. Sec<strong>on</strong>d, where the c<strong>on</strong>troller does not have the authority, but a third party who has<br />

474 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 06/2014 <strong>on</strong> the noti<strong>on</strong> of legitimate <strong>in</strong>terests of the <strong>data</strong><br />

c<strong>on</strong>troller under Article 7 of Directive 95/46/EC‘, European Commissi<strong>on</strong> (9 April 2014), available at<br />

http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2014/wp217_en.pdf,<br />

(last accessed 28 October 2017).<br />

475 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 06/2014 <strong>on</strong> the noti<strong>on</strong> of legitimate <strong>in</strong>terests of the <strong>data</strong><br />

c<strong>on</strong>troller under Article 7 of Directive 95/46/EC‘, European Commissi<strong>on</strong> (9 April 2014), available at<br />

http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2014/wp217_en.pdf,<br />

(last accessed 28 October 2017).<br />

476 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 06/2014 <strong>on</strong> the noti<strong>on</strong> of legitimate <strong>in</strong>terests of the <strong>data</strong><br />

c<strong>on</strong>troller under Article 7 of Directive 95/46/EC‘, European Commissi<strong>on</strong> (9 April 2014), available at<br />

http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2014/wp217_en.pdf,<br />

(last accessed 28 October 2017).<br />

477 Recital 31, EU GDPR.<br />

101

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!