{"id":17493,"date":"2019-12-14T09:08:47","date_gmt":"2019-12-14T03:38:47","guid":{"rendered":"https:\/\/www.technologyforyou.org\/?p=17493"},"modified":"2019-12-14T09:08:47","modified_gmt":"2019-12-14T03:38:47","slug":"nasscom-dsci-statement-on-personal-data-protection-bill-2019","status":"publish","type":"post","link":"https:\/\/www.technologyforyou.org\/nasscom-dsci-statement-on-personal-data-protection-bill-2019\/","title":{"rendered":"NASSCOM &#8211; DSCI Statement on Personal Data Protection Bill 2019"},"content":{"rendered":"<p><strong><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">To deliberate on the recently tabled Personal Data Protection Bill, NASSCOM-DSCI held an industry <\/span><\/strong><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\"><strong>consultation with its members today. Debjani Ghosh, President NASSCOM, said, <\/strong>A robust data <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">protection law is critical for India\u2019s success in the data economy and we are very happy that the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Government is taking the necessary steps to pass the law at the earliest. Am also happy that the voice <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">of the industry has been heard and that this version has incorporated several of the recommendations <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">made. There are a few areas where we still need further clarity and NASSCOM will continue to work <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">with the Government to ensure the bill is a win -win for India and the Industry.<\/span><\/p>\n<p><span style=\"color: #008000;\"><strong><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">The notable positive changes in the draft of the Bill include :<\/span><\/strong><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Removal of Restrictions on Cross-Border Transfer of Personal Data \u2013<\/strong> The earlier draft of the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Bill required one copy of personal data to be stored within the territory of India, for transfers <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">of Personal Data to take place. Further, such transfers could only take place on the basis of<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">standard contractual clauses, intra-group transfer schemes or adequacy decisions. These <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">restrictions have now been removed.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Removal of Passwords from the indicative list of Sensitive Personal Data \u2013<\/strong> Passwords have <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">been removed from the indicative list of Sensitive Personal Data under Clause 2(36) of the Bill.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Certain Offences Removed from the Bill \u2013<\/strong> The earlier draft of the Bill listed the obtaining, <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">transferring or selling of personal and sensitive personal data in a manner contrary to the Act, <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">as an offence. These provisions have now been removed.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Relaxations on Cross-Border Transfer of Critical Data \u2013<\/strong> It has been explicitly clarified in the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Bill, that personal data which is notified by the Central Government as critical data, may be <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">transferred outside the territory of India in certain limited circumstances \u2013 i.e. (i) prompt<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">action for the provision health services or emergency services; and (ii) where the transfer is <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">to a territory where the Central Government allows the transfer of critical data.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Creation of sandbox to encourage innovation \u2013<\/strong> The Data Protection Authority (DPA) shall <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">create a sandbox for encouraging development of artificial intelligence, machine learning or <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">any emerging technology in public interest.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Due Process Requirements for Investigating Offences \u2013<\/strong> The power granted to police officers <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">above the rank of Inspector to investigate offences under the Bill have been removed. Any <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">investigation has to happen on the basis of a complaint by the DPA, and subsequent to a court<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">order issued on the basis of such complaint.\u00a0<\/span><\/p>\n<p><span style=\"color: #008000;\"><strong><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">The key areas of concern for the industry however, are:<\/span><\/strong><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Power to Exempt certain Data Processors \u2013<\/strong> Central Government has the power to exempt <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">data processors, that process personal data of data principals who are outside the territory of <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">India. While this was included in the earlier draft of the Bill as a miscellaneous provision, this<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">has now been included under the Chapter on exemptions under the Bill. However, no material <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">changes have been made to the text. The industry, in particular the IT-BPM and GCC industries <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">will need greater certainty on the scope and issuance of the exemption.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Inclusion of Provisions Dealing with Non-Personal Data \u2013<\/strong> The Bill empowers the Central <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Government to direct data fiduciaries or data processors to share anonymised data or non-<\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">personal data for the purpose of enabling better targeting for delivery of services or for the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">formulation of evidence based policies by the Central Government. The Central Government <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">has to make annual disclosures of the directions issued under this provision. However, no <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">safeguards have been provided for protecting IP rights, or other business sensitive non personal data.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Categories of Sensitive Personal Data-<\/strong> The Bill retains \u201cfinancial data\u201d as a category of <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">sensitive personal data. Further, \u201cfinancial data\u201d continues to be defined broadly under the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Bill. This is an area of concern, especially with reference to employee data processing for<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">operations such as payroll services, that requires processing of financial data. Given that <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">explicit consent is the only ground for processing sensitive personal data, the classification of <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u201cfinancial data\u201d as sensitive personal data poses potential problems for other business<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">operations such as risk management, fraud detection, among others. <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Lastly, there are some areas where we will be seeking further clarity. For instance, while the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">classification of data has been designed in the same manner, personal data now covers inferences <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">drawn for the purposes of profiling, we will be studying this closely to assess its impact. <\/span><\/p>\n<p><span style=\"color: #008000;\"><strong><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Other areas <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">where clarity will be sought includes:<\/span><\/strong><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Classification of Significant Data Fiduciaries \u2013<\/strong> The Bill provides certain factors that need to <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">be considered by the DPA while classifying certain data fiduciaries as \u201csignificant data <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">fiduciaries\u201d. It needs to be made abundantly clear that these factors will be assessed <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">cumulatively, instead of individually, by the DPA.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Classification of certain Personal Data as Critical Data \u2013<\/strong> The Central Government retains the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">power to notify any personal data as critical data. However, the Bill still does not provide any <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">definition for critical data, or provide any guidelines for the determination of what may be<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">notified as critical data. This is an area that needs further clarity to create business <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">predictability from an operational standpoint.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Cross-Border Transfer of Sensitive Personal Data \u2013<\/strong> The Bill requires continued storage of <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">sensitive personal data in India, in instances where a cross-border transfer of sensitive <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">personal data is affected. It is unclear as to what this requirement entails vis-\u00e0-vis manner of <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">storage.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">\u2022 <strong>Removal of Transitional Provisions \u2013<\/strong> The Bill excludes transitional provisions provided in the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">earlier draft. Upon enactment, the industry will need sufficient time to implement changes in <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">their business models. Accordingly, there is a need for further clarity from the Central<\/span><br \/>\n<span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">Government on the manner in which various provisions will be brought into force, so that the <\/span><span style=\"font-family: 'trebuchet ms', geneva, sans-serif;\">industry is able to achieve meaningful compliance.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>To deliberate on the recently tabled Personal Data Protection Bill, NASSCOM-DSCI held an industry consultation with its members today. Debjani Ghosh, President NASSCOM, said, A robust data protection law is critical for India\u2019s success in the data economy and we are very happy that the Government is taking the necessary steps to pass the law [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":17494,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,9231],"tags":[10267,10266],"class_list":{"0":"post-17493","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security","8":"category-top-stories","9":"tag-nasscom-dsci-statement-on-personal-data-protection-bill-2019","10":"tag-personal-data-protection-bill-2019"},"_links":{"self":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/posts\/17493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/comments?post=17493"}],"version-history":[{"count":0,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/posts\/17493\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/media\/17494"}],"wp:attachment":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/media?parent=17493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/categories?post=17493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/tags?post=17493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}