25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2. The follow<strong>in</strong>g additi<strong>on</strong>al obligati<strong>on</strong>s menti<strong>on</strong>ed below may f<strong>in</strong>d place with<strong>in</strong> the<br />

mechanism as appropriate:<br />

(i)<br />

Registrati<strong>on</strong><br />

Registrati<strong>on</strong> obligati<strong>on</strong>s may be placed <strong>on</strong>ly for certa<strong>in</strong> k<strong>in</strong>ds of <strong>data</strong> c<strong>on</strong>trollers<br />

categorised <strong>on</strong> the basis of a specified criteria.<br />

(ii)<br />

Data protecti<strong>on</strong> impact assessment<br />

DPIAs may be required for certa<strong>in</strong> categories of <strong>data</strong> c<strong>on</strong>trollers. Such DPIAs may,<br />

however, be undertaken <strong>in</strong> <strong>on</strong>ly specific <strong>in</strong>stances, such as, where process<strong>in</strong>g <strong>in</strong>volves<br />

the use of new technology or likelihood of harm to any <strong>in</strong>dividual whose <strong>data</strong> is be<strong>in</strong>g<br />

processed.<br />

(iii) Data audits<br />

It would be beneficial for <strong>data</strong> protecti<strong>on</strong> law to provide for <strong>data</strong> protecti<strong>on</strong> audits <strong>in</strong> a<br />

regular manner for <strong>data</strong> c<strong>on</strong>trollers whose activities pose higher risks to the protecti<strong>on</strong><br />

of pers<strong>on</strong>al <strong>data</strong>. A useful framework need not require the regulator to always carry out<br />

such audits itself and the law may provide for the registrati<strong>on</strong> of <strong>in</strong>dependent external<br />

audit<strong>in</strong>g agencies. It may also c<strong>on</strong>ta<strong>in</strong> some <strong>in</strong>dicati<strong>on</strong> as to what an audit should cover<br />

<strong>in</strong> light of the technical nature of the compliance with certa<strong>in</strong> obligati<strong>on</strong>s.<br />

(iv) Data protecti<strong>on</strong> officer<br />

There may be a substantial need for designat<strong>in</strong>g <strong>in</strong>dividuals who are made centres of<br />

accountability through their positi<strong>on</strong> <strong>in</strong> the <strong>data</strong> c<strong>on</strong>troller‘s organisati<strong>on</strong>. Such officer<br />

may not <strong>on</strong>ly play an advisory role <strong>in</strong> relati<strong>on</strong> to the <strong>data</strong> c<strong>on</strong>troller but must also be its<br />

external face <strong>in</strong> relati<strong>on</strong> to compla<strong>in</strong>ts, requests and the requirements of a <strong>data</strong><br />

protecti<strong>on</strong> authority.<br />

2.17 Questi<strong>on</strong>s<br />

1. What are your views <strong>on</strong> the manner <strong>in</strong> which <strong>data</strong> c<strong>on</strong>trollers may be categorised?<br />

2. Should a general classificati<strong>on</strong> of <strong>data</strong> c<strong>on</strong>trollers be made for the purposes of certa<strong>in</strong><br />

additi<strong>on</strong>al obligati<strong>on</strong>s facilitat<strong>in</strong>g compliance while mitigat<strong>in</strong>g risk?<br />

3. Should <strong>data</strong> c<strong>on</strong>trollers be classified <strong>on</strong> the basis of the harm that they are likely to<br />

cause <strong>in</strong>dividuals through their <strong>data</strong> process<strong>in</strong>g activities?<br />

4. What are the factors <strong>on</strong> the basis of which such <strong>data</strong> c<strong>on</strong>trollers may be categorised?<br />

172

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!