25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

protecti<strong>on</strong>, etc.‘ 118 The Court recognised ‗<strong>in</strong>formati<strong>on</strong>al privacy‘ as an important aspect of the<br />

right to privacy that can be claimed aga<strong>in</strong>st state and n<strong>on</strong>-state actors. The right to<br />

<strong>in</strong>formati<strong>on</strong>al privacy allows an <strong>in</strong>dividual to protect <strong>in</strong>formati<strong>on</strong> about herself and prevent it<br />

from be<strong>in</strong>g dissem<strong>in</strong>ated. 119 Further, the Court recognised that the right to privacy is not<br />

absolute and may be subject to reas<strong>on</strong>able restricti<strong>on</strong>s. In order to limit discreti<strong>on</strong> of State <strong>in</strong><br />

such matters, the Court has laid down a test to limit the possibility of the State clamp<strong>in</strong>g<br />

down <strong>on</strong> the right – the acti<strong>on</strong> must be sancti<strong>on</strong>ed by law, it must be necessary to fulfil a<br />

legitimate aim of the State, the extent of the State <strong>in</strong>terference must be ‗proporti<strong>on</strong>ate to the<br />

need for such <strong>in</strong>terference‘, there must be procedural safeguards to prevent the State from<br />

abus<strong>in</strong>g its power. 120 It has expressly recognised ―protect<strong>in</strong>g nati<strong>on</strong>al security, prevent<strong>in</strong>g and<br />

<strong>in</strong>vestigat<strong>in</strong>g crime, encourag<strong>in</strong>g <strong>in</strong>novati<strong>on</strong> and the spread of knowledge, and prevent<strong>in</strong>g the<br />

dissipati<strong>on</strong> of social welfare benefits‖ 121 as certa<strong>in</strong> legitimate aims of the State.<br />

(ii)<br />

Legislative Developments<br />

Though the Puttaswamy judgment is a landmark legal development <strong>in</strong> the discourse <strong>on</strong><br />

privacy, especially <strong>in</strong>formati<strong>on</strong>al privacy; prior legislative attempts have been made to secure<br />

<strong>in</strong>formati<strong>on</strong>al privacy <strong>in</strong> various sectors <strong>in</strong> India. These <strong>in</strong>cludes the general <strong>data</strong> protecti<strong>on</strong><br />

rules under the Informati<strong>on</strong> Technology Act, 2000 (IT Act) as well as various sector specific<br />

laws <strong>on</strong> <strong>data</strong> protecti<strong>on</strong>.<br />

a. The Informati<strong>on</strong> Technology (Reas<strong>on</strong>able Security Practices and Sensitive Pers<strong>on</strong>al<br />

Data or Informati<strong>on</strong>) Rules, 2011 (SPDI Rules)<br />

The SPDI Rules have been issued under Secti<strong>on</strong> 43A of the IT Act. Secti<strong>on</strong> 43A, relates to<br />

―Compensati<strong>on</strong> for Failure to Protect Data‖ and enables the enactment of ―reas<strong>on</strong>able security<br />

practices and procedures‖ for the protecti<strong>on</strong> of sensitive pers<strong>on</strong>al <strong>data</strong>. The SPDI Rules<br />

<strong>in</strong>corporate, to a limited extent, the OECD Guidel<strong>in</strong>es, specifically: collecti<strong>on</strong> limitati<strong>on</strong>,<br />

purpose specificati<strong>on</strong>, use limitati<strong>on</strong> and <strong>in</strong>dividual participati<strong>on</strong>.<br />

The SPDI Rules mandate certa<strong>in</strong> requirements for the collecti<strong>on</strong> of <strong>in</strong>formati<strong>on</strong>, 122 and <strong>in</strong>sist<br />

that it be d<strong>on</strong>e <strong>on</strong>ly for a lawful purpose c<strong>on</strong>nected with the functi<strong>on</strong> of the organisati<strong>on</strong>. 123 In<br />

additi<strong>on</strong>, every organisati<strong>on</strong> is required to have a detailed privacy policy. 124 The SPDI Rules<br />

also set out <strong>in</strong>structi<strong>on</strong>s for the period of time <strong>in</strong>formati<strong>on</strong> can be reta<strong>in</strong>ed, 125 and gives<br />

<strong>in</strong>dividuals the right to correct their <strong>in</strong>formati<strong>on</strong>. 126 Disclosure is not permitted without<br />

c<strong>on</strong>sent of the provider of the <strong>in</strong>dividual, or unless such disclosure is c<strong>on</strong>tractually permitted<br />

118 Per R.F. Nariman, J. at paragraph 42.<br />

119 Per D.Y. Chandrachud, J. at paragraph 142.<br />

120 Per S.K. Kaul, J., paragraph 71.<br />

121<br />

Per D.Y. Chandrachud, at paragraph 185.<br />

122 Rule 5(1), SPDI Rules.<br />

123 Rule 5(2), SPDI Rules.<br />

124 Rule 4, SPDI Rules.<br />

125 Rule 5(4), SPDI Rules.<br />

126 Rule 5(6), SPDI Rules.<br />

16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!