25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The Know Your Customer (KYC) norms limit the categories of <strong>in</strong>formati<strong>on</strong> that banks and<br />

f<strong>in</strong>ancial <strong>in</strong>stituti<strong>on</strong>s can seek from their customers. 156 Once such <strong>in</strong>formati<strong>on</strong> is collected,<br />

there is an obligati<strong>on</strong> <strong>on</strong> banks to keep it c<strong>on</strong>fidential. 157 Further, multiple <strong>in</strong>struments such as<br />

the Master Circular <strong>on</strong> Credit Card, Debit Card and Rupee Denom<strong>in</strong>ated Co-branded Prepaid<br />

Card Operati<strong>on</strong>s of Banks and Credit Card issu<strong>in</strong>g NBFCs, 158 the Master Circular <strong>on</strong><br />

Customer Services, 2009 159 and the Code of Banks Commitment to Customers 160 etc. all<br />

provide for privacy and customer c<strong>on</strong>fidentiality obligati<strong>on</strong>s that have to be adhered to by<br />

various entities <strong>in</strong> the f<strong>in</strong>ancial sector.<br />

d. Telecom Sector<br />

There are multiple laws that operate <strong>in</strong> the telecom sector such as the Indian Telegraph Act,<br />

1885 (Telegraph Act), the Indian Wireless Telegraphy Act, 1933, the Telecom Regulatory<br />

Authority of India Act, 1997 (TRAI Act) and various regulati<strong>on</strong>s issued thereunder. However,<br />

<strong>data</strong> protecti<strong>on</strong> norms <strong>in</strong> the telecom sector are primarily dictated by the Unified License<br />

Agreement (ULA) issued to Telecom Service Providers (TSP) by the Department of<br />

Telecommunicati<strong>on</strong>s (DoT).<br />

The format <strong>in</strong> which, and the types of <strong>in</strong>formati<strong>on</strong> that are to be collected from the <strong>in</strong>dividual<br />

is prescribed by the DoT. 161 A TSP has an obligati<strong>on</strong> to take necessary steps to safeguard the<br />

privacy and c<strong>on</strong>fidentiality of the <strong>in</strong>formati<strong>on</strong> of <strong>in</strong>dividuals to whom it provides a service<br />

and from whom it has acquired such <strong>in</strong>formati<strong>on</strong> by the virtue of the service provided. 162<br />

Further, the TSP is obliged to ma<strong>in</strong>ta<strong>in</strong> all commercial, call detail records, exchange detail<br />

records and IP detail records for at least <strong>on</strong>e year for scrut<strong>in</strong>y by the DoT. 163 As far as security<br />

safeguards are c<strong>on</strong>cerned, there are multiple obligati<strong>on</strong>s prescribed for the TSP which<br />

<strong>in</strong>cludes <strong>in</strong>duct<strong>in</strong>g <strong>on</strong>ly those network elements <strong>in</strong>to its telecom network which have been<br />

156 RBI Master Directi<strong>on</strong> <strong>on</strong> Know Your Customer (KYC) Directi<strong>on</strong>, 2016 dated 25 February 2016, updated as<br />

<strong>on</strong> 8 July 2016, available at: https://www.rbi.org.<strong>in</strong>/Scripts/Notificati<strong>on</strong>User.aspx?Id=10292&Mode=0 (last<br />

accessed 13 November 2017). This Master Directi<strong>on</strong> was amended by RBI Amendment to Master Directi<strong>on</strong><br />

dated 8 December 2016, available at https://rbi.org.<strong>in</strong>/scripts/Notificati<strong>on</strong>User.aspx?Mode=0&Id=10770 (last<br />

accessed 13 November 2017).<br />

157<br />

RBI Master Circular <strong>on</strong> Customer Service <strong>in</strong> UCBs dated 1 July 2015, available at:<br />

https://www.rbi.org.<strong>in</strong>/scripts/BS_ViewMasCirculardetails.aspx?id=9863, (last accessed November 5, 2017).<br />

158 RBI Master Circular <strong>on</strong> Credit Card, Debit Card and Rupee Denom<strong>in</strong>ated Co-branded Prepaid Card<br />

Operati<strong>on</strong>s of Banks and Credit Card issu<strong>in</strong>g NBFCs, available at Master Circular <strong>on</strong> Credit Card, Debit Card<br />

and Rupee Denom<strong>in</strong>ated Cobranded Prepaid Card operati<strong>on</strong>s of banks dated 1 July 2014, available at:<br />

https://rbi.org.<strong>in</strong>/Scripts/BS_ViewMasCirculardetails.aspx?id=8998 , (last accessed 5 November 2017). Some<br />

parts of this Circular were amended by RBI Notificati<strong>on</strong> <strong>on</strong> Customer Protecti<strong>on</strong> <strong>on</strong> Limit<strong>in</strong>g Liability of<br />

Customers <strong>in</strong> Unauthorised Electr<strong>on</strong>ic Bank<strong>in</strong>g Transacti<strong>on</strong>s dated 6 July 2017, available at:<br />

https://www.rbi.org.<strong>in</strong>/scripts/Notificati<strong>on</strong>User.aspx?Id=11040&Mode=0 (last accessed 13 November 2017).<br />

159<br />

RBI Master Circular <strong>on</strong> Customer Service <strong>in</strong> Banks, 2015 dated 1 July 2015, available at:<br />

https://rbi.org.<strong>in</strong>/scripts/BS_ViewMasCirculardetails.aspx?id=9862 (last accessed 14 November 2017).<br />

160 Code of Bank‘s Commitment to Customers, ‗Secti<strong>on</strong> 5- Privacy and C<strong>on</strong>fidentiality‘, Bank<strong>in</strong>g Codes and<br />

Standards Board of India (June 2014), available at: https://www.dbs.com/<strong>in</strong>/iwov-resources/pdf/codeofbanksaug091.pdf<br />

(last accessed 3 November 2017).<br />

161 Clause 39.17, Unified License Agreement.<br />

162 Clause 37.2, Unified License Agreement.<br />

163 Clause 39.20, Unified License Agreement.<br />

20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!