25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

have been taken or that the <strong>data</strong> subject c<strong>on</strong>sented to such use may not, by itself, be sufficient<br />

to disclaim liability.<br />

The operati<strong>on</strong> of this pr<strong>in</strong>ciple would mean that the process<strong>in</strong>g of pers<strong>on</strong>al <strong>data</strong> by a <strong>data</strong><br />

c<strong>on</strong>troller for its bus<strong>in</strong>ess needs commences and c<strong>on</strong>t<strong>in</strong>ues <strong>on</strong>ly <strong>in</strong> a manner which is <strong>in</strong><br />

accord with the <strong>data</strong> protecti<strong>on</strong> pr<strong>in</strong>ciples. This approach, to some extent, shifts the burden<br />

away from the <strong>in</strong>dividual from hav<strong>in</strong>g to c<strong>on</strong>stantly m<strong>on</strong>itor whether his or her <strong>data</strong> is be<strong>in</strong>g<br />

processed as per law and ensures greater accountability for <strong>data</strong> c<strong>on</strong>trollers.<br />

2.2 Issues<br />

(i)<br />

Harm and Liability<br />

The pr<strong>in</strong>ciple of accountability bears a close l<strong>in</strong>k to the liability to be cast <strong>on</strong> the <strong>data</strong><br />

c<strong>on</strong>troller. In order to determ<strong>in</strong>e the c<strong>on</strong>tours of such liability, it may be important to establish<br />

what c<strong>on</strong>stitutes harm. For <strong>in</strong>stance, if as a result of the manner <strong>in</strong> which the <strong>data</strong> is<br />

processed, the reputati<strong>on</strong> of the <strong>in</strong>dividual is impaired so as to result <strong>in</strong> a loss <strong>in</strong> reputati<strong>on</strong> or<br />

social stand<strong>in</strong>g of the <strong>in</strong>dividual, this could could have serious repercussi<strong>on</strong>s for the<br />

<strong>in</strong>dividual. Similarly, as a c<strong>on</strong>sequence of process<strong>in</strong>g the <strong>data</strong>, the <strong>in</strong>dividual suffers any<br />

direct or <strong>in</strong>direct f<strong>in</strong>ancial loss this could be easily identified as a harm that the <strong>data</strong> c<strong>on</strong>troller<br />

should be held accountable for. If the <strong>data</strong> c<strong>on</strong>troller uses the pers<strong>on</strong>al <strong>data</strong> about the<br />

<strong>in</strong>dividual <strong>in</strong> order to limit the choice available to the <strong>in</strong>dividual whether <strong>in</strong> terms of the<br />

<strong>in</strong>formati<strong>on</strong> that she can access or any products or services that she is allowed to avail of, this<br />

too could be a harmful restricti<strong>on</strong> of the opti<strong>on</strong>s available to the <strong>in</strong>dividual. However, this<br />

k<strong>in</strong>d of harm is of a qualitatively different nature as compared to the first two examples,<br />

c<strong>on</strong>stitut<strong>in</strong>g a denial of access or fair treatment, rather than material loss.<br />

From am<strong>on</strong>gst these, the <strong>data</strong> protecti<strong>on</strong> law could identify categories of material and n<strong>on</strong>material<br />

harm. If such harm is occasi<strong>on</strong>ed, it could trigger liability <strong>on</strong>ly <strong>on</strong> proof of failure to<br />

to take appropriate measures. Alternatively, if the nature of process<strong>in</strong>g is <strong>in</strong>herently risky, the<br />

<strong>data</strong> c<strong>on</strong>trollers could become strictly liable, subject to the excepti<strong>on</strong>s that the harm was<br />

caused by an act of God or the <strong>data</strong> subject herself c<strong>on</strong>tributed to the harm. A third alternative<br />

is for <strong>data</strong> c<strong>on</strong>trollers, or a certa<strong>in</strong> class of <strong>data</strong> c<strong>on</strong>trollers to compulsorily take out <strong>in</strong>surance<br />

to cover certa<strong>in</strong> types of harms caused to <strong>data</strong> subjects due to process<strong>in</strong>g activities, even <strong>in</strong> a<br />

situati<strong>on</strong> where the <strong>data</strong> c<strong>on</strong>troller has taken all reas<strong>on</strong>able measures accord<strong>in</strong>g to law and<br />

established practices and standards.<br />

(ii)<br />

Jo<strong>in</strong>t C<strong>on</strong>trollers and Remoteness of Liability<br />

Modern <strong>data</strong> process<strong>in</strong>g is complex and often <strong>in</strong>volves multiple service providers who<br />

process the <strong>in</strong>dividual‘s <strong>data</strong> simultaneously or sequentially. Primary <strong>data</strong> collected directly<br />

from the <strong>in</strong>dividual is often made available through applicati<strong>on</strong> programm<strong>in</strong>g <strong>in</strong>terfaces<br />

(APIs) that can be accessed by various sec<strong>on</strong>dary <strong>data</strong> c<strong>on</strong>trollers who either process this <strong>data</strong><br />

themselves or make the <strong>data</strong> available for further process<strong>in</strong>g down the l<strong>in</strong>e. If any harm<br />

149

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!