25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

United K<strong>in</strong>gdom<br />

The UK DPA also requires the <strong>data</strong> subject to provide c<strong>on</strong>sent for the process<strong>in</strong>g of her<br />

pers<strong>on</strong>al <strong>data</strong>. 408 The UK DPA follows the EU GDPR approach by mak<strong>in</strong>g c<strong>on</strong>sent <strong>on</strong>ly <strong>on</strong>e<br />

of the six grounds for lawful process<strong>in</strong>g.<br />

South Africa<br />

The POPI Act also recognises that process<strong>in</strong>g of pers<strong>on</strong>al <strong>data</strong> should <strong>on</strong>ly takes place with<br />

the c<strong>on</strong>sent of the <strong>data</strong> subject. It follows the EU GDPR and the UK DPA approach by<br />

mak<strong>in</strong>g c<strong>on</strong>sent <strong>on</strong>e of the other grounds for lawful process<strong>in</strong>g of pers<strong>on</strong>al <strong>data</strong>. 409<br />

Canada<br />

Under Canada‘s PIPEDA, organisati<strong>on</strong>s are required to obta<strong>in</strong> an <strong>in</strong>dividual‘s valid c<strong>on</strong>sent to<br />

lawfully collect, use and disclose pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> <strong>in</strong> the course of commercial<br />

activity. 410 Recognis<strong>in</strong>g the need to have different standards of c<strong>on</strong>sent, the 2015 amendment<br />

to PIPEDA (through the Digital Privacy Act) provides that the form of c<strong>on</strong>sent required<br />

depends <strong>on</strong> the circumstances and the type of <strong>in</strong>formati<strong>on</strong> be<strong>in</strong>g collected. 411 While express<br />

c<strong>on</strong>sent is necessary for sensitive <strong>in</strong>formati<strong>on</strong>, implied c<strong>on</strong>sent is sufficient for n<strong>on</strong>-sensitive<br />

<strong>in</strong>formati<strong>on</strong>. 412 The Digital Privacy Act <strong>in</strong>troduced a ―graduated c<strong>on</strong>sent standard‖ or a<br />

―slid<strong>in</strong>g-scale‖ for obta<strong>in</strong><strong>in</strong>g valid c<strong>on</strong>sent. The Digital Privacy Act stipulates that an<br />

<strong>in</strong>dividual‘s c<strong>on</strong>sent will be valid <strong>on</strong>ly if an <strong>in</strong>dividual could reas<strong>on</strong>ably expect to understand<br />

the nature, purpose and c<strong>on</strong>sequences of the collecti<strong>on</strong>, use or disclosure of the pers<strong>on</strong>al<br />

<strong>in</strong>formati<strong>on</strong> to which she has c<strong>on</strong>sented. 413<br />

Australia<br />

Under the Privacy Act, c<strong>on</strong>sent is not directly a pre-requisite for collect<strong>in</strong>g pers<strong>on</strong>al<br />

<strong>in</strong>formati<strong>on</strong>. The <strong>on</strong>ly requirement prior to collect<strong>in</strong>g pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> is that the<br />

<strong>in</strong>formati<strong>on</strong> should be reas<strong>on</strong>ably necessary for the agency‘s (government body) or the<br />

organisati<strong>on</strong>‘s (private entity) activities. The APPs set out that pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> should be<br />

collected directly from the <strong>in</strong>dividual unless the <strong>in</strong>dividual has c<strong>on</strong>sented to collecti<strong>on</strong> from<br />

other sources, or if it is authorised by law. 414 The bar is significantly higher for the collecti<strong>on</strong><br />

of sensitive <strong>in</strong>formati<strong>on</strong> as the <strong>in</strong>dividual‘s c<strong>on</strong>sent is required <strong>in</strong> additi<strong>on</strong> to the c<strong>on</strong>diti<strong>on</strong><br />

408 Secti<strong>on</strong> 4, read with Schedule 1 (Pr<strong>in</strong>ciple 1), Schedule 2 (C<strong>on</strong>diti<strong>on</strong> 1) and Schedule III (C<strong>on</strong>diti<strong>on</strong> 1) of the<br />

UK DPA.<br />

409 Secti<strong>on</strong> 11(1)(a)-(f), POPI Act.<br />

410 Pr<strong>in</strong>ciple 4.3, Schedule 1, PIPEDA.<br />

411 Pr<strong>in</strong>ciple 4.3.4, Schedule 1, PIPEDA.<br />

412 Pr<strong>in</strong>ciple 4.3.6, Schedule 1, PIPEDA.<br />

413 Dan Cooper, ‗Highlights of the Canada Digital Privacy Act‘, Cov<strong>in</strong>gt<strong>on</strong> & Burl<strong>in</strong>g LLP (24 June 2015),<br />

available at: https://www.<strong>in</strong>sideprivacy.com/<strong>in</strong>ternati<strong>on</strong>al/canada/highlights-of-the-canada-digital-privacy-act-<br />

2015/, (last accessed 24 October 2017).<br />

414 APP 3.6, Privacy Act.<br />

82

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!