25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

South Africa<br />

The POPI Act def<strong>in</strong>es process<strong>in</strong>g 252 as any operati<strong>on</strong> or activity or any set of operati<strong>on</strong>s,<br />

whether or not by automatic means, c<strong>on</strong>cern<strong>in</strong>g pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>, <strong>in</strong>clud<strong>in</strong>g; the<br />

collecti<strong>on</strong>, receipt, record<strong>in</strong>g, organisati<strong>on</strong>, collati<strong>on</strong>, storage, updat<strong>in</strong>g or modificati<strong>on</strong>,<br />

retrieval, alterati<strong>on</strong>, c<strong>on</strong>sultati<strong>on</strong>, dissem<strong>in</strong>ati<strong>on</strong> by means of transmissi<strong>on</strong>, distributi<strong>on</strong> or<br />

mak<strong>in</strong>g available <strong>in</strong> any other form, merg<strong>in</strong>g, l<strong>in</strong>k<strong>in</strong>g, restricti<strong>on</strong>, degradati<strong>on</strong>, erasure or<br />

destructi<strong>on</strong> of <strong>in</strong>formati<strong>on</strong>.<br />

In these legislati<strong>on</strong>s, the lawfulness of acti<strong>on</strong>s relat<strong>in</strong>g to <strong>data</strong> is set out with reference to the<br />

term process<strong>in</strong>g. In other words, these statutes do not prescribe separate standards or<br />

limitati<strong>on</strong>s <strong>on</strong> different acti<strong>on</strong>s relat<strong>in</strong>g to <strong>data</strong>, for <strong>in</strong>stance such as collecti<strong>on</strong>, use or<br />

disclosure. Example, the EU GDPR <strong>in</strong> Article 6 lays down the c<strong>on</strong>diti<strong>on</strong>s for lawful<br />

process<strong>in</strong>g. These c<strong>on</strong>diti<strong>on</strong>s apply across the board any acti<strong>on</strong> <strong>in</strong>volv<strong>in</strong>g <strong>data</strong> such as<br />

collecti<strong>on</strong>, use or disclosure.<br />

Canada and Australia<br />

Other jurisdicti<strong>on</strong>s, such as Canada and Australia, adopt a different approach. In Canada, the<br />

PIPEDA def<strong>in</strong>es process<strong>in</strong>g of <strong>data</strong> us<strong>in</strong>g three terms—collecti<strong>on</strong>, use, and disclosure. The<br />

(Australian) Privacy Act, also focuses <strong>on</strong> the collecti<strong>on</strong>, use and disclosure of <strong>data</strong> rather than<br />

an elaborate def<strong>in</strong>iti<strong>on</strong> of <strong>data</strong> process<strong>in</strong>g. In these laws while the term process<strong>in</strong>g is also<br />

used, the c<strong>on</strong>diti<strong>on</strong>s for collecti<strong>on</strong>, use and disclosure are separately identified and isolated.<br />

Thus <strong>in</strong> the PIPEDA, for <strong>in</strong>stance, collecti<strong>on</strong> and use of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> are separately<br />

dealt with. 253 Similarly, under the Privacy Act, APP 3 deals with collecti<strong>on</strong> of Informati<strong>on</strong><br />

while APP 6 deals with use or disclosure of <strong>in</strong>formati<strong>on</strong>.<br />

The dist<strong>in</strong>cti<strong>on</strong> between collecti<strong>on</strong> use and disclosure of <strong>data</strong> is often th<strong>in</strong> and it is perhaps for<br />

this reas<strong>on</strong> that the EU does not dist<strong>in</strong>guish c<strong>on</strong>ceptually between these acti<strong>on</strong>s and uses the<br />

broad term process<strong>in</strong>g. The advantage of the Canadian and Australian approach is that it<br />

appears more precise when c<strong>on</strong>diti<strong>on</strong>s for collecti<strong>on</strong>, use and disclosure are separately listed.<br />

(ii)<br />

Automated means versus manual process<strong>in</strong>g<br />

Data process<strong>in</strong>g activities are carried out through automated means, as well as manual<br />

methods. In this c<strong>on</strong>text, it is necessary to exam<strong>in</strong>e whether a <strong>data</strong> protecti<strong>on</strong> law would apply<br />

to both types of process<strong>in</strong>g.<br />

European Uni<strong>on</strong><br />

The EU GDPR is applicable to pers<strong>on</strong>al <strong>data</strong> that has been processed wholly or partly by<br />

automated means. It also applies to <strong>data</strong> which forms part or is <strong>in</strong>tended to form part of a<br />

252 Secti<strong>on</strong> 1, POPI Act.<br />

253 Paragraph 4.3 of Schedule I and Secti<strong>on</strong> 7, PIPEDA.<br />

45

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!