25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

tested as per the c<strong>on</strong>temporary Indian or Internati<strong>on</strong>al Security Standards, 164 am<strong>on</strong>gst<br />

others. 165 F<strong>in</strong>ally, customer <strong>in</strong>formati<strong>on</strong> can be disclosed <strong>on</strong>ly if the <strong>in</strong>dividual has c<strong>on</strong>sented<br />

to such disclosure and the disclosure is <strong>in</strong> accordance with the terms of c<strong>on</strong>sent. 166 In<br />

additi<strong>on</strong>, the TSP has to make efforts to comply with the Telegraph Act which imposes an<br />

obligati<strong>on</strong> <strong>on</strong> it to facilitate the Government to carry out ‗<strong>in</strong>tercepti<strong>on</strong>‘ of messages <strong>in</strong> case of<br />

emergencies - a privacy <strong>in</strong>trusi<strong>on</strong> justified largely <strong>in</strong> the name of nati<strong>on</strong>al security. There are<br />

some procedural safeguards built <strong>in</strong>to this process of <strong>in</strong>tercepti<strong>on</strong>. 167<br />

Further, the Telecom Regulatory Authority of India (TRAI) has framed the Telecom<br />

Commercial Communicati<strong>on</strong> Preference Regulati<strong>on</strong>s, 2010 (TRAI Regulati<strong>on</strong>s) to deal with<br />

unsolicited commercial communicati<strong>on</strong>s. 168 The TRAI Regulati<strong>on</strong>s envisage the sett<strong>in</strong>g up of<br />

Customer Preference Registrati<strong>on</strong> Facility 169 by telecom service providers through which<br />

customers could choose to not receive commercial communicati<strong>on</strong>s. However, these<br />

regulati<strong>on</strong>s are limited to messages and other communicati<strong>on</strong> through ph<strong>on</strong>es, and would<br />

would not cover an email applicati<strong>on</strong> or advertisements appear<strong>in</strong>g <strong>on</strong> browsers.<br />

e. Health Sector<br />

Despite the <strong>in</strong>herently sensitive nature of health <strong>in</strong>formati<strong>on</strong>, the legal framework <strong>on</strong> <strong>data</strong><br />

protecti<strong>on</strong> <strong>in</strong> the health sector appears to be <strong>in</strong>adequate. The Cl<strong>in</strong>ical Establishments (Central<br />

Government) Rules, 2012 (Cl<strong>in</strong>ical Establishments Rules) requires cl<strong>in</strong>ical establishments to<br />

ma<strong>in</strong>ta<strong>in</strong> and provide Electr<strong>on</strong>ic Medical Records/Electr<strong>on</strong>ic Health Records, thus mandat<strong>in</strong>g<br />

the storage of health <strong>in</strong>formati<strong>on</strong> <strong>in</strong> an electr<strong>on</strong>ic format. 170 The SPDI Rules recognise health<br />

<strong>in</strong>formati<strong>on</strong> as c<strong>on</strong>stitut<strong>in</strong>g ‗sensitive pers<strong>on</strong>al <strong>data</strong>‘ and thus regulates its collecti<strong>on</strong>, use and<br />

disclosure. However, as already menti<strong>on</strong>ed the SPDI Rules apply <strong>on</strong>ly to the private sector<br />

thus leav<strong>in</strong>g the whole of the public health sector outside its ambit.<br />

The Indian Medical Council (Professi<strong>on</strong>al C<strong>on</strong>duct, Etiquette and Ethics) Regulati<strong>on</strong>s, 2002<br />

(IMC Code) issued under the Indian Medical Council Act, 1956 mandate physician-patient<br />

c<strong>on</strong>fidentiality unless the disclosure of the patient‘s <strong>in</strong>formati<strong>on</strong> is required by law, or if there<br />

is a serious and identified risk to an <strong>in</strong>dividual/community, or the disease is a notifiable<br />

<strong>on</strong>e. 171 Interest<strong>in</strong>gly, at the same time the IMC Code requires that the patient, her relatives<br />

and resp<strong>on</strong>sible friends have knowledge of the patient's c<strong>on</strong>diti<strong>on</strong> so as to serve her best<br />

<strong>in</strong>terests 172 thus allow<strong>in</strong>g for disclosure without the c<strong>on</strong>sent of the patient. Further, physicians<br />

are encouraged to computerise medical records, ma<strong>in</strong>ta<strong>in</strong> them for a period of three years and<br />

provide access to them to the patient up<strong>on</strong> her request. 173 However, the limited privacy<br />

164 Clause 39.7, Unified License Agreement.<br />

165 Clause 39, Unified License Agreement.<br />

166 Clause 37.2, Unified License Agreement.<br />

167 Rule 419-A, Telegraph Act.<br />

168 Regulati<strong>on</strong> 2(i), TRAI Regulati<strong>on</strong>s.<br />

169 Regulati<strong>on</strong> 3, TRAI Regulati<strong>on</strong>s.<br />

170 Rule 9(iv), Cl<strong>in</strong>ical Establishments Rules.<br />

171 Secti<strong>on</strong> 2.2., IMC Code.<br />

172 Secti<strong>on</strong> 2.3. IMC Code.<br />

173 Secti<strong>on</strong> 1.3.2, IMC Code.<br />

21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!