25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

a <strong>data</strong> c<strong>on</strong>troller must be <strong>in</strong> a positi<strong>on</strong> to dem<strong>on</strong>strate, when asked by a supervisory authority,<br />

that such measures have been adopted. 672<br />

The pr<strong>in</strong>ciple of accountability emphasises that standards prescribed externally either by the<br />

law or by the <strong>in</strong>dustry must be implemented <strong>in</strong>ternally by organisati<strong>on</strong>s. 673 The <strong>on</strong>us of<br />

prov<strong>in</strong>g that such measures have been complied with is placed <strong>on</strong> the organisati<strong>on</strong>. This <strong>in</strong><br />

many ways paves the way for effective implementati<strong>on</strong> of <strong>data</strong> protecti<strong>on</strong> pr<strong>in</strong>ciples.<br />

A more expansive use of accountability may hold the <strong>data</strong> c<strong>on</strong>troller strictly liable for any<br />

harm caused as a c<strong>on</strong>sequence of process<strong>in</strong>g by it, irrespective of whether appropriate<br />

measures to implement <strong>data</strong> protecti<strong>on</strong> pr<strong>in</strong>ciples are put <strong>in</strong> place and implemented. This<br />

pr<strong>in</strong>ciple may be c<strong>on</strong>sidered for process<strong>in</strong>g that is <strong>in</strong>herently risky, <strong>in</strong> c<strong>on</strong>s<strong>on</strong>ance with the<br />

strict liability pr<strong>in</strong>ciple as developed <strong>in</strong> traditi<strong>on</strong>al tort law. 674<br />

To illustrate the work<strong>in</strong>g of the general pr<strong>in</strong>ciple of accountability, c<strong>on</strong>sider a <strong>data</strong> c<strong>on</strong>troller<br />

embark<strong>in</strong>g <strong>on</strong> a new process that <strong>in</strong>volves pers<strong>on</strong>al <strong>data</strong> process<strong>in</strong>g. The <strong>data</strong> c<strong>on</strong>troller,<br />

before commenc<strong>in</strong>g such process<strong>in</strong>g, must c<strong>on</strong>sider the relevant standards <strong>in</strong> the law which<br />

apply to the process<strong>in</strong>g. The standards may <strong>in</strong>clude requirements relat<strong>in</strong>g to grounds of<br />

process<strong>in</strong>g, notice, c<strong>on</strong>sent, <strong>data</strong> quality, security of collected <strong>data</strong>, questi<strong>on</strong>s of access to <strong>data</strong><br />

when <strong>data</strong> is to be handled by a <strong>data</strong> processor, etc. The <strong>data</strong> c<strong>on</strong>troller must draw up a<br />

procedure or policy as to how it <strong>in</strong>tends to meet these standards. In draw<strong>in</strong>g up this policy or<br />

procedure, it must have regard to any b<strong>in</strong>d<strong>in</strong>g code of practice, <strong>in</strong>dustry practices and any<br />

other external b<strong>in</strong>d<strong>in</strong>g standard. The <strong>data</strong> c<strong>on</strong>troller may also take <strong>in</strong>to account any voluntary<br />

standard bey<strong>on</strong>d the basel<strong>in</strong>e norm which it abides by. If harm is caused to an <strong>in</strong>dividual<br />

ow<strong>in</strong>g to such process<strong>in</strong>g, the <strong>data</strong> c<strong>on</strong>troller will bear the burden of proof to dem<strong>on</strong>strate that<br />

it had a policy to prevent such harm and implemented such policy. If such a policy does not<br />

exist, or was not implemented strictly, the <strong>data</strong> c<strong>on</strong>troller would be liable for damages. If<br />

however it does exist and it has been implemented, there is still a str<strong>on</strong>g case that the <strong>data</strong><br />

subject should not be left without recourse. One way <strong>in</strong> which a situati<strong>on</strong> like this can be met<br />

is for <strong>data</strong> c<strong>on</strong>trollers to <strong>in</strong>sure aga<strong>in</strong>st such c<strong>on</strong>t<strong>in</strong>gency to adequately compensate the <strong>data</strong><br />

subject.<br />

In additi<strong>on</strong>, or as an alternative, if the nature of <strong>data</strong> process<strong>in</strong>g is <strong>in</strong>herently risky, then any<br />

harm caused to an <strong>in</strong>dividual that can be traced back to the process<strong>in</strong>g, would result <strong>in</strong><br />

liability of the <strong>data</strong> c<strong>on</strong>troller. 675 Simply dem<strong>on</strong>strat<strong>in</strong>g that certa<strong>in</strong> organisati<strong>on</strong>al measures<br />

672 Article 29 Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 3/2010 <strong>on</strong> the pr<strong>in</strong>ciple of accountability‘, European Commissi<strong>on</strong> (13<br />

July 2010), 9, available at: http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2010/wp173_en.pdf,<br />

(last accessed 2 November 2017).<br />

673 Centre for Informati<strong>on</strong> Policy Leadership, ‗Data Protecti<strong>on</strong> Accountability: The Essential Elements A<br />

Document for Discussi<strong>on</strong>‘, Hunt<strong>on</strong> & Williams LLP (October 2009), available at:<br />

https://www.hunt<strong>on</strong>.com/files/webupload/CIPL_Galway_Accountability_Paper.pdf, (last accessed 21 November<br />

2017).<br />

674 Rylands v. Fletcher, 1868 UKHL 1.<br />

675<br />

See Baker Mckenzie, ‗Accountability Obligati<strong>on</strong>s under the GDPR‘, available at:<br />

http://globalitc.bakermckenzie.com/files/Uploads/Documents/Global%20ITC/13%20Game%20Changers/BM-<br />

Accountability%20Obligati<strong>on</strong>s%20under%20the%20GDPR.pdf, (last accessed 23 November 2017).<br />

148

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!