25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

A research c<strong>on</strong>ducted by P<strong>on</strong>em<strong>on</strong> Institute, sp<strong>on</strong>sored by Arbor Networks and found that the<br />

average security breach (<strong>in</strong> North America and EMEA regi<strong>on</strong>s) <strong>in</strong> the retail services sector<br />

takes 197 days to detect and 98 days <strong>in</strong> the f<strong>in</strong>ancial service sector. 734<br />

Under Secti<strong>on</strong> 6 of the New Mexico Data Breach Notificati<strong>on</strong> Act, 2017 (New Mexico Data<br />

Breach Act), a pers<strong>on</strong> that owns or licenses elements that <strong>in</strong>clude pers<strong>on</strong>al identify<strong>in</strong>g<br />

<strong>in</strong>formati<strong>on</strong> of a New Mexico resident shall provide notificati<strong>on</strong> to each New Mexico resident<br />

whose pers<strong>on</strong>al identify<strong>in</strong>g <strong>in</strong>formati<strong>on</strong> is reas<strong>on</strong>ably believed to have been subject to a<br />

security breach. Notificati<strong>on</strong> shall be made <strong>in</strong> the most expedient time possible, but not later<br />

than 45 calendar days follow<strong>in</strong>g discovery of the security breach.<br />

The New Mexico Data Breach Act uses a time frame for notify<strong>in</strong>g the <strong>in</strong>dividual <strong>in</strong> case of<br />

breach. It provides that the notificati<strong>on</strong> should happen as so<strong>on</strong> as possible but also provides<br />

an upper limit of 45 days for the purpose of notificati<strong>on</strong> to the affected <strong>in</strong>dividual. This<br />

legislati<strong>on</strong> solely provides for <strong>on</strong>e time notificati<strong>on</strong> of the <strong>in</strong>dividual affected by the breach <strong>in</strong><br />

the manner prescribed under Secti<strong>on</strong> 7 of the said legislati<strong>on</strong>.<br />

This time frame allows the organisati<strong>on</strong> to provide the <strong>in</strong>dividual with the <strong>in</strong>formati<strong>on</strong> that<br />

would help her/him understand<strong>in</strong>g how the <strong>in</strong>cident took place, what is be<strong>in</strong>g d<strong>on</strong>e <strong>in</strong> this<br />

regard and the pers<strong>on</strong> or office to c<strong>on</strong>tact <strong>in</strong> case for follow<strong>in</strong>g up. An argument <strong>in</strong> favour of<br />

this manner of notificati<strong>on</strong> would be that it doesn‘t create a situati<strong>on</strong> of panic, which might<br />

happen if the <strong>in</strong>dividual is <strong>in</strong>formed right at the time of <strong>in</strong>itial detecti<strong>on</strong>. At the stage of <strong>in</strong>itial<br />

detecti<strong>on</strong>, the organisati<strong>on</strong> itself is many times <strong>in</strong> the dark and w<strong>on</strong>‘t have enough<br />

<strong>in</strong>formati<strong>on</strong> to answer the <strong>in</strong>dividual‘s queries and may result <strong>in</strong> an atmosphere of panic and<br />

mistrust. This po<strong>in</strong>t needs to be deliberated up<strong>on</strong> further <strong>in</strong> the Indian c<strong>on</strong>text, where the<br />

average <strong>in</strong>dividual‘s privacy awareness is at a very different level from what it is <strong>in</strong> the EU or<br />

the US.<br />

While fix<strong>in</strong>g a time period for breach notificati<strong>on</strong> it is also important to take <strong>in</strong>to<br />

c<strong>on</strong>siderati<strong>on</strong> the magnitude of the leak. If the number of <strong>in</strong>dividuals affected is <strong>in</strong> milli<strong>on</strong>s<br />

then would it be prudent to put <strong>in</strong> a place a notificati<strong>on</strong> requirement like we see <strong>in</strong> the EU<br />

GDPR where the <strong>data</strong> c<strong>on</strong>troller has <strong>on</strong>ly 72 hours to notify the <strong>in</strong>dividuals? It might be<br />

with<strong>in</strong> the ability of a large organisati<strong>on</strong> to put automated report<strong>in</strong>g and breach notificati<strong>on</strong><br />

mechanisms <strong>in</strong> place. But that might not be the case with respect to SME and start-ups across<br />

sectors. Build<strong>in</strong>g a notificati<strong>on</strong> matrix based <strong>on</strong> the size of the organisati<strong>on</strong>s could be a way to<br />

tackle this problem, provid<strong>in</strong>g different time limits for notify<strong>in</strong>g <strong>in</strong>dividuals. This could solve<br />

this particular problem but at the risk of complicat<strong>in</strong>g the notificati<strong>on</strong> mechanism greatly.<br />

734 P<strong>on</strong>em<strong>on</strong> Institute LLC, ‗Advanced Threats <strong>in</strong> Retail – A Study of North America & EMEA‘, ARBOR<br />

Networks, available at:<br />

https://pages.arbornetworks.com/Global_P<strong>on</strong>em<strong>on</strong>_Retail.html?utm_source=P<strong>on</strong>em<strong>on</strong>&utm_medium=blog_pos<br />

t&utm_term=AT&utm_c<strong>on</strong>tent=<str<strong>on</strong>g>white</str<strong>on</strong>g><str<strong>on</strong>g>paper</str<strong>on</strong>g>&utm_campaign=P<strong>on</strong>em<strong>on</strong>_Retail, (last accessed 21 November<br />

2017); P<strong>on</strong>em<strong>on</strong> Institute LLC, ‗Advanced Threats <strong>in</strong> F<strong>in</strong>ancial Services – A Study of North America &<br />

EMEA‘, ARBOR Networks, available at:<br />

https://pages.arbornetworks.com/Global_P<strong>on</strong>em<strong>on</strong>_F<strong>in</strong>ancial_Services.html?utm_source=P<strong>on</strong>em<strong>on</strong>&utm_medi<br />

um=blog_post&utm_term=AT&utm_c<strong>on</strong>tent=<str<strong>on</strong>g>white</str<strong>on</strong>g><str<strong>on</strong>g>paper</str<strong>on</strong>g>&utm_campaign=P<strong>on</strong>em<strong>on</strong>_F<strong>in</strong>Serv, (last accessed 21<br />

November 2017).<br />

164

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!