25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

In the US, pers<strong>on</strong>al <strong>data</strong> breaches are def<strong>in</strong>ed under sector-specific statutes or specific state<br />

laws. Under HIPAA Privacy Rule 726 , a breach is, generally, an impermissible use or<br />

disclosure that compromises the security or privacy of the protected health <strong>in</strong>formati<strong>on</strong>. 727<br />

Privacy Technical Assistance Center (PTAC), established by the US department of educati<strong>on</strong><br />

def<strong>in</strong>es a <strong>data</strong> breach as any <strong>in</strong>stance <strong>in</strong> which there is an unauthorized release or access of<br />

PII or other <strong>in</strong>formati<strong>on</strong> not suitable for public release. 728<br />

Further, the California Security Breach Notificati<strong>on</strong> Act, 2016 def<strong>in</strong>es a security breach as an<br />

unauthorized acquisiti<strong>on</strong> of computerized <strong>data</strong> that compromises the security, c<strong>on</strong>fidentiality,<br />

or <strong>in</strong>tegrity of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> ma<strong>in</strong>ta<strong>in</strong>ed by the entity. Good-faith acquisiti<strong>on</strong> of<br />

pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> by an employee or agent of an entity for the purposes of the entity is not<br />

a breach of the security of the system, provided that the pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> is not used or<br />

subject to further unauthorized disclosure. 729<br />

North Dakota Century Code, Chapter 51-30 Notice of Security Breach for Pers<strong>on</strong>al<br />

Informati<strong>on</strong> def<strong>in</strong>es a security breach as unauthorized acquisiti<strong>on</strong> of computerized <strong>data</strong> when<br />

access to pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> has not been secured by encrypti<strong>on</strong> or by any other method or<br />

technology that renders the electr<strong>on</strong>ic files, media, or <strong>data</strong> bases unreadable or unusable. 730<br />

It is important to note that although worded differently, US sector specific laws and a<br />

comprehensive privacy legislati<strong>on</strong> like the EU GDPR, both recognise the cause and effect<br />

relati<strong>on</strong>ship between a security <strong>in</strong>cident and a breach that may hamper pers<strong>on</strong>al <strong>data</strong>.<br />

(ii)<br />

Data Breach Notificati<strong>on</strong>s<br />

Data breach notificati<strong>on</strong> refers to the practice of alert<strong>in</strong>g and <strong>in</strong>form<strong>in</strong>g stakeholders<br />

<strong>in</strong>clud<strong>in</strong>g <strong>data</strong> subjects that a pers<strong>on</strong>al <strong>data</strong> breach has occurred. The nature of notificati<strong>on</strong><br />

required depends <strong>on</strong> the nature of <strong>data</strong> <strong>in</strong>volved <strong>in</strong> the breach.<br />

A breach can potentially have a range of significant adverse effects <strong>on</strong> <strong>in</strong>dividuals, which can<br />

result <strong>in</strong> physical, material, or n<strong>on</strong>-material damage. The EU GDPR expla<strong>in</strong>s that this can<br />

<strong>in</strong>clude loss of c<strong>on</strong>trol over their pers<strong>on</strong>al <strong>data</strong>, limitati<strong>on</strong> of their rights, discrim<strong>in</strong>ati<strong>on</strong>,<br />

identity theft or fraud, f<strong>in</strong>ancial loss, unauthorised reversal of pseud<strong>on</strong>ymisati<strong>on</strong>, damage to<br />

726 The HIPAA Privacy Rule establishes nati<strong>on</strong>al standards to protect <strong>in</strong>dividuals‘ medical records and other<br />

pers<strong>on</strong>al health <strong>in</strong>formati<strong>on</strong> and applies to health plans, health care clear<strong>in</strong>ghouses, and those health care<br />

providers that c<strong>on</strong>duct certa<strong>in</strong> health care transacti<strong>on</strong>s electr<strong>on</strong>ically. The rule requires appropriate safeguards to<br />

protect the privacy of pers<strong>on</strong>al health <strong>in</strong>formati<strong>on</strong>, and sets limits and c<strong>on</strong>diti<strong>on</strong>s <strong>on</strong> the uses and disclosures that<br />

may be made of such <strong>in</strong>formati<strong>on</strong> without patient authorizati<strong>on</strong>.<br />

727 Office for Civil Rights (OCR), ‗Breach Notificati<strong>on</strong> Rule‘, US Department of Health & Human Services (26<br />

July 2013), available at: https://www.hhs.gov/hipaa/for-professi<strong>on</strong>als/breach-notificati<strong>on</strong>/<strong>in</strong>dex.html, (last<br />

accessed 20 November 2017).<br />

728 Privacy Technical Assistance Center, ‗Data Breach Resp<strong>on</strong>se Checklist‘ (September 2012), available at:<br />

http://ptac.ed.gov/sites/default/files/checklist_<strong>data</strong>_breach_resp<strong>on</strong>se_092012.pdf (last accessed 10 November<br />

2017).<br />

729 Secti<strong>on</strong> 1(d), California Security Breach Notificati<strong>on</strong> Act, 2016.<br />

730 North Dakota Century Code, Chapter 51-30 Notice of Security Breach for Pers<strong>on</strong>al Informati<strong>on</strong>.<br />

162

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!