25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

or necessary for legal compliance. 127 When it comes to shar<strong>in</strong>g <strong>in</strong>formati<strong>on</strong> with Government<br />

agencies, then the c<strong>on</strong>sent of the provider is not required and such <strong>in</strong>formati<strong>on</strong> can be shared<br />

for purposes such as verificati<strong>on</strong> of identity, preventi<strong>on</strong>, detecti<strong>on</strong> and <strong>in</strong>vestigati<strong>on</strong> <strong>in</strong>clud<strong>in</strong>g<br />

of cyber <strong>in</strong>cidents, prosecuti<strong>on</strong>, and punishment of offences. 128<br />

The SPDI Rules apply <strong>on</strong>ly to corporate entities 129 and leaves the government and<br />

government bodies outside its ambit; the rules are restricted to ‗sensitive pers<strong>on</strong>al <strong>data</strong>‘,<br />

which <strong>in</strong>cludes attributes like sexual orientati<strong>on</strong>, medical records and history, biometric<br />

<strong>in</strong>formati<strong>on</strong> etc., 130 and not to the larger category of pers<strong>on</strong>al <strong>data</strong>. Further, the Cyber<br />

Appellate Tribunal (CyAT) which hears appeals under the IT Act has issued its last order <strong>in</strong><br />

2011. The absence of an effective enforcement mach<strong>in</strong>ery therefore raises c<strong>on</strong>cerns about the<br />

implementati<strong>on</strong> of the SPDI Rules. It is thus necessary to make a comprehensive law to<br />

adequately protect pers<strong>on</strong>al <strong>data</strong> <strong>in</strong> all its dimensi<strong>on</strong>s and to ensure an effective enforcement<br />

mach<strong>in</strong>ery for the same.<br />

b. The Aadhaar (Targeted Delivery of F<strong>in</strong>ancial and other Subsidies, Benefits and<br />

Services) Act, 2016 (Aadhaar Act)<br />

The Aadhaar Act enables the Government to collect identity <strong>in</strong>formati<strong>on</strong> from citizens 131<br />

<strong>in</strong>clud<strong>in</strong>g their biometrics, issue a unique identificati<strong>on</strong> number or an Aadhaar Number <strong>on</strong> the<br />

basis of such biometric <strong>in</strong>formati<strong>on</strong> 132 , and thereafter provide targeted delivery of subsidies,<br />

benefits and services to them. 133 The Aadhaar Act also provides for Aadhaar based<br />

authenticati<strong>on</strong> services where<strong>in</strong> a request<strong>in</strong>g entity (government/public and private<br />

entities/agencies) can request the Unique Identificati<strong>on</strong> Authority of India (UIDAI) to<br />

verify/validate the correctness of the identity <strong>in</strong>formati<strong>on</strong> submitted by <strong>in</strong>dividuals to be able<br />

to extend services to them. 134 The request<strong>in</strong>g entity is required to obta<strong>in</strong> the c<strong>on</strong>sent of the<br />

<strong>in</strong>dividual before obta<strong>in</strong><strong>in</strong>g her identity <strong>in</strong>formati<strong>on</strong> for the purpose of authenticati<strong>on</strong> and<br />

must use her identity <strong>in</strong>formati<strong>on</strong> <strong>on</strong>ly for the purpose of authenticati<strong>on</strong>. 135<br />

The Aadhaar Act establishes an authority, namely, the UIDAI, which is resp<strong>on</strong>sible for the<br />

adm<strong>in</strong>istrati<strong>on</strong> of the said Act. 136 It also establishes a Central Identities Data Repository<br />

(CIDR) 137 which is a <strong>data</strong>base hold<strong>in</strong>g Aadhaar Numbers and corresp<strong>on</strong>d<strong>in</strong>g demographic<br />

and biometric <strong>in</strong>formati<strong>on</strong>. 138 Under the Aadhaar Act, collecti<strong>on</strong>, storage and use of pers<strong>on</strong>al<br />

<strong>data</strong> is a prec<strong>on</strong>diti<strong>on</strong> for the receipt of a subsidy, benefit or service. 139 Though the Aadhaar<br />

127 Rule 6, SPDI Rules.<br />

128 Rule 6(1), SPDI Rules.<br />

129 Secti<strong>on</strong> 43-A, IT Act.<br />

130 Rule 3, SPDI Rules.<br />

131 Secti<strong>on</strong> 30, Aadhaar Act.<br />

132 Secti<strong>on</strong> 3, Aadhaar Act.<br />

133 Secti<strong>on</strong> 7, Aadhaar Act.<br />

134 Secti<strong>on</strong> 8, Aadhaar Act.<br />

135 Secti<strong>on</strong> 8(2), Aadhaar Act.<br />

136 Secti<strong>on</strong> 11, Aadhaar Act.<br />

137 Secti<strong>on</strong> 10, Aadhaar Act.<br />

138 Secti<strong>on</strong> 2(h), Aadhaar Act.<br />

139 Secti<strong>on</strong> 7, Aadhaar Act.<br />

17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!