Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Data protection bill should be tougher on enterprises, says parliamentary committee

India’s data protection bill should be modified to cover more than just personal data, and impose strict deadlines on businesses to report data breaches, a parliamentary committee recommended in a long-awaited report published on 16 December, 2021.

The Joint Committee on the Personal Data Protection Bill, 2019, has spent two years examining the proposed legislation first laid before parliament on 11 December, 2019. Given the long delay — and its view that the bill should project more than just personal information —  the committee recommended that resulting legislation be renamed the Data Protection Act, 2021.

The committee’s 542-page report includes 93 recommendations to legislators on the drafting of the bill, which sets out the rights of data principals (those that the data describes) and the obligations of data processors a data fiduciaries (those who hold the data).

If the bill and the committee’s recommendations become law, businesses will have new obligations to fulfil, including putting a detailed privacy notice on their website, adopting a privacy by design policy, keeping various records pertaining to data processing activities, demonstrating the fairness of algorithms deployed, and conducting data protection impact assessments, among other accountability and transparency measures.

Significance

The committee recommended that businesses processing large volumes of personal data, or whose businesses, through their nature, have the potential to affect a large number of people, or that are otherwise considered risky, be labelled “significant data fiduciaries,” requiring them to implement additional controls and procedures.

The consequences for those that don’t respect the proposed rules would be severe, to say the least. Fines for significant offenses or non-compliance would be up to ₹15 crores or 4% of worldwide turnover, while fines for a minor offence or non-compliance would be up to ₹5 crores or 2% of global turnover.

The bill also creates a host of lesser offences that would attract lower fines and penalties.

The committee recommended that the scope of the bill be enlarged beyond protection of personal data to encompass the collection and storage of non-personal data since, it said, it’s impossible to clearly distinguish between the two, and if privacy is a concern then all data must be protected.

To avoid the need for additional legislation, therefore, it proposed that the Data Protection Authority (DPA) charged with defending citizens personal data in the bill also be empowered to oversee non-personal data.

Two years to implement, three days to report

The bill itself provides no timeline for the implementation of its provisions, so the committee recommended that once it becomes law data fiduciaries and data processors be given about two years to make the modifications to their policies, infrastructure, and processes necessary to bring them into compliance.

The committee was less generous in its suggestion for how long businesses should have to report data breaches. It recommended that data fiduciaries should have to report every breach of personal data to the DPA within 72 hours of becoming aware of the breach, and to keep a log of all data breaches, whether personal data or not.

Another deadline proposed by the committee would come into effect when data principals reached majority. Businesses that process the data of minors should, the committee proposed, have to contact them three months before their 18th birthday to seek renewed permission.

As it stands, the bill allows data principals to receive their personal data where it has been processed automatically, but not if doing so would reveal trade secrets or is not technically feasible. The committee said that the revealing of trade secrets should not be grounds for businesses to refuse to provide data principals with their personal data.

Location, location, location

The bill includes provisions for where data may be stored or processed. Sensitive personal data may be sent outside of India for processing if the individual has given their explicit agreement and certain additional conditions have been met, it says.  

Where data is sent abroad, the committee recommended that a copy be kept in India, to facilitate the eventual reshoring of data-processing activities. It also called on the government to ensure that India developed a strong AI software and services ecosystem to support the domestic processing of Indians’ personal data.

It also advocated for a framework to oversee hardware companies that collect data, calling for a certification system for all digital and internet of things (IOT) devices.

Swift retribution

The Committee observed that “data protection in the financial sector is a matter of genuine concern worldwide, particularly when through the SWIFT network, privacy has been compromised widely.” Indian citizens, it noted, are major users of the SWIFT international payment service and so, it said, it could give a boost to the domestic economy if India were to develop its own alternative to SWIFT.

But other bodies would remain exempt from retribution for privacy violations under the committee’s rules. Its report did not recommend removing a contentious clause that  provides the government with authority to exempt any of its agencies from the data protection laws.

It’s worth noting that the committee’s recommendations aren’t legally binding. The bill will next be presented to the Cabinet, which will decide whether to adopt the committee’s recommendations. Only then will the bill be presented to Parliament for approval. It is expected to be introduced to parliament in the 2022 budget session.


Read More from This Article: Data protection bill should be tougher on enterprises, says parliamentary committee
Source: News

Category: NewsDecember 22, 2021
Tags: art

Post navigation

PreviousPrevious post:Indian CIOs’ IT spending priorities in 2022NextNext post:Bringing Open Source to the Mainframe to Modernize in Place

Related posts

Barb Wixom and MIT CISR on managing data like a product
May 30, 2025
Avery Dennison takes culture-first approach to AI transformation
May 30, 2025
The agentic AI assist Stanford University cancer care staff needed
May 30, 2025
Los desafíos de la era de la ‘IA en todas partes’, a fondo en Data & AI Summit 2025
May 30, 2025
“AI 비서가 팀 단위로 지원하는 효과”···퍼플렉시티, AI 프로젝트 10분 완성 도구 ‘랩스’ 출시
May 30, 2025
“ROI는 어디에?” AI 도입을 재고하게 만드는 실패 사례
May 30, 2025
Recent Posts
  • Barb Wixom and MIT CISR on managing data like a product
  • Avery Dennison takes culture-first approach to AI transformation
  • The agentic AI assist Stanford University cancer care staff needed
  • Los desafíos de la era de la ‘IA en todas partes’, a fondo en Data & AI Summit 2025
  • “AI 비서가 팀 단위로 지원하는 효과”···퍼플렉시티, AI 프로젝트 10분 완성 도구 ‘랩스’ 출시
Recent Comments
    Archives
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.