25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PIPEDA does not specifically deal with sensitive <strong>in</strong>formati<strong>on</strong>. It provides that the form of<br />

c<strong>on</strong>sent sought by organisati<strong>on</strong>s may vary depend<strong>in</strong>g <strong>on</strong> the circumstances of use and the type<br />

of <strong>in</strong>formati<strong>on</strong>. An organisati<strong>on</strong> would have to seek express c<strong>on</strong>sent, when the <strong>in</strong>formati<strong>on</strong> is<br />

likely to be c<strong>on</strong>sidered sensitive. For <strong>in</strong>stance, medical records and <strong>in</strong>come records are almost<br />

always c<strong>on</strong>sidered to be sensitive. Any <strong>in</strong>formati<strong>on</strong> could be c<strong>on</strong>sidered sensitive based <strong>on</strong><br />

the c<strong>on</strong>text <strong>in</strong> which it is used. 526 For <strong>in</strong>stance, collect<strong>in</strong>g names of <strong>in</strong>dividuals for magaz<strong>in</strong>e<br />

subscripti<strong>on</strong>s will not be problematic. However, releas<strong>in</strong>g a list of names of <strong>in</strong>dividuals who<br />

subscribe to a special-<strong>in</strong>terest magaz<strong>in</strong>e may be problematic, as it could lead to identificati<strong>on</strong><br />

and discrim<strong>in</strong>ati<strong>on</strong> aga<strong>in</strong>st those <strong>in</strong>dividuals. This method of handl<strong>in</strong>g sensitive <strong>in</strong>formati<strong>on</strong><br />

could be problematic as it shifts the burden <strong>on</strong> the organisati<strong>on</strong> to determ<strong>in</strong>e whether a<br />

particular use would cause harm, and this analysis would vary <strong>on</strong> a case-to-case basis.<br />

United States<br />

Although there is no broad def<strong>in</strong>iti<strong>on</strong> of what c<strong>on</strong>stitutes ―sensitive <strong>data</strong>‖ <strong>in</strong> the US, several<br />

sector-specific laws and guidel<strong>in</strong>es implement safeguards where it may be c<strong>on</strong>sidered<br />

necessary. For <strong>in</strong>stance the FTC‘s Behavioural Advertis<strong>in</strong>g Pr<strong>in</strong>ciples 527 suggest that website<br />

operators should obta<strong>in</strong> the express affirmative c<strong>on</strong>sent of the c<strong>on</strong>sumer before us<strong>in</strong>g<br />

sensitive c<strong>on</strong>sumer <strong>data</strong>, which may <strong>in</strong>clude f<strong>in</strong>ancial <strong>data</strong>, <strong>data</strong> relat<strong>in</strong>g to children, health<br />

<strong>in</strong>formati<strong>on</strong>, and precise geographic <strong>in</strong>formati<strong>on</strong>. 528 The Fair Credit Report<strong>in</strong>g Act limits how<br />

c<strong>on</strong>sumer reports and credit card account numbers can be used and disclosed, although it does<br />

not term them as ―sensitive‖. 529 HIPAA regulates medical <strong>in</strong>formati<strong>on</strong> and how it may be<br />

collected and disclosed. 530 The Security Standards for the Protecti<strong>on</strong> of Electr<strong>on</strong>ic Health<br />

Informati<strong>on</strong> (HIPAA Security Rule) provides standards for protect<strong>in</strong>g medical <strong>data</strong>. For<br />

<strong>in</strong>stance, there are specific rules, which regulate the disclosure of psychotherapy notes, even<br />

for the purpose of medical treatment. 531<br />

Therefore, largely the approach of most jurisdicti<strong>on</strong>s is to identify and carve out categories<br />

and types of <strong>in</strong>formati<strong>on</strong>, which are c<strong>on</strong>sidered sensitive. These categories of <strong>in</strong>formati<strong>on</strong> are<br />

then protected by certa<strong>in</strong> safeguards, which limit their collecti<strong>on</strong>, use and disclosure, <strong>in</strong> order<br />

to mitigate harm to the <strong>in</strong>dividual.<br />

6.4 Provisi<strong>on</strong>al Views<br />

526 Schedule 1, Secti<strong>on</strong> 4.3.4, Pr<strong>in</strong>ciple 3- C<strong>on</strong>sent, PIPEDA.<br />

527 FTC , ‗FTC Staff Report: Self-Regulatory Pr<strong>in</strong>ciples for Onl<strong>in</strong>e Behavioural Advertis<strong>in</strong>g‘ (February 2009),<br />

available at: https://www.ftc.gov/sites/default/files/documents/reports/federal-trade-commissi<strong>on</strong>-staff-reportself-regulatory-pr<strong>in</strong>ciples-<strong>on</strong>l<strong>in</strong>e-behavioral-advertis<strong>in</strong>g/p085400behavadreport.pdf,<br />

(last accessed 30 October<br />

2017).<br />

528 FTC , ‗FTC Staff Revises Onl<strong>in</strong>e Behavioural Advertis<strong>in</strong>g Pr<strong>in</strong>ciples‘ (12 February 2009), available at:<br />

https://www.ftc.gov/news-events/press-releases/2009/02/ftc-staff-revises-<strong>on</strong>l<strong>in</strong>e-behavioral-advertis<strong>in</strong>gpr<strong>in</strong>ciples,<br />

(last accessed 30 October 2017).<br />

529 15 USC Secti<strong>on</strong> 1681.<br />

530 42 USC Secti<strong>on</strong> 1301.<br />

531 HIPAA Privacy Rule.<br />

115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!