The bill defines 'personal data' as any data about an individual who can be identified by such data. Personal data collected online as well as offline which is digitised for processing all fall under this definition. The bill is also applicable to the processing of digital personal data outside the territory of India in certain conditions.
Stakeholders such as ‘Data Principal’, ‘Data Fiduciary’, and ‘Consent Manager’ have been identified. ‘Data Fiduciaries’ are entities involved in the processing of a person’s personal data. ‘Data Principals’ (individuals) have been given certain rights and duties with respect to their personal data and can seek redressal of their grievances against the data fiduciaries. ‘Consent Managers’ are intermediaries who will enable Data Principals to manage their consent for sharing personal data with Data Fiduciaries. These managers are accountable to the Principals and will act on their behalf.
The bill introduces the idea of ‘consent’ wherein a data principal agrees to the processing of his/her personal data for a specific purpose. The consent is not perpetual and the principal can revoke, renew, and extend his/her consent with the help of consent managers.
The bill lays down the rights, duties, and liabilities of all stakeholders. These have been discussed in the sections below:
Obligations of Data Fiduciary
Personal data can only be processed for lawful purposes. Fiduciaries must issue a notice and take consent from the data principals. The notice should be in plain language and contain a description of the data being collected as well as the purpose of the data processing
When processing the personal data of children (users below 18 years of age), fiduciaries are required to obtain verifiable consent from the parents
A fiduciary must cease the processing of personal data after a principal withdraws his/her consent
In the event of a personal data breach, the fiduciary is required to notify the Data Protection Board ("Board") proposed under the bill, and each affected data principal
If a fiduciary is found to have failed in implementing reasonable security safeguards to prevent a personal data breach, it can be penalised with a fine of up to ₹250,00,00,000/-
Rights of Data Principal
Right to be notified when their personal data is being processed as well as the nature of the personal data being processed. Data principals must also be informed about all the data fiduciaries with whom their personal data has been shared
Right to make a request for correction, completion, updation, and erasure of personal data that is no longer needed
Right to nominate a representative who will exercise these rights in the event of death or unavailability
Right of grievance redressal
Duties of Data Principal
The bill has assigned certain duties to data principals in order to ensure that there is no misuse of their rights. Data principals must not register false or frivolous complaints with a data fiduciary or the Board. They are required to furnish the correct information in all circumstances and not suppress any material information or impersonate another person. A penalty of up to ₹10,000/- (Rupees Ten Thousand) can be levied on a data principal for failure to comply with his/her duties.
Data Protection Board
A Data Protection Board is set to be constituted to oversee the enforcement and compliance with the provisions of the bill. The need for a digital-by-design compliance framework was identified and the Data Protection Board has been given the powers to determine instances of non-compliance and impose relevant penalties. In instances of a data breach, the board has the power to direct Data Fiduciaries to provide remedy/mitigate the damage caused to ‘Data Principals’. The bill provides that any appeal against an order of the Board would lie to the High Court. The Board has also been given the power to direct alternative dispute resolution to resolve disputes between concerned parties in certain cases.
The bill provides a comprehensive legal framework for governing digital personal data protection. It recognises the right of the individual to protect his/her personal data as well as the need for processing personal data for lawful purposes. The bill will affect the compliance obligations of businesses across the economy including the finance, healthcare, IT and other service sectors. Every business and service that collects and processes user data will be regulated under this new regulatory framework. In addition, the digital India bill is also set to be introduced which will rein in the social media, e-commerce, OTT, and other digital space companies that operate in the digital world. These 2 legislations together will provide the necessary groundwork for laying down the plumbing required to push India’s digital economy.