Today's Headlines - 06 September 2023
Your personal data online
GS Paper - 3 (ITC)
Recently, India notified its personal data protection framework as a law, signalling the beginning of a new era of privacy legislation in the country. Provisions of the Digital Personal Data Protection Act, 2023 will come in force in a few months, after the Centre has allowed enough transition time to the industry, with users of these platforms — you — experiencing several new notices and rights, as prescribed in the law.
When can an entity process your personal data?
There are broadly two circumstances under which entities — both government and private — can process an individual’s personal data: (i) There has to be clear consent for such processing; and (ii) for certain “legitimate uses”.
When an entity is processing your personal data for which you have consented, it has to be accompanied by a notice, which is to be made available in all 22 languages of Schedule 8 of the Constitution.
You can directly consent to businesses, and the government can process your personal data, or alternatively use a consent manager.
What happens to your personal data that was collected before this law came into existence?
Any entity that has collected a person’s personal data before the Act came into being should give her a notice about the personal data in its possession “as soon as it is reasonably practicable”.
The notice should include:
The personal data an entity is processing and the purpose for such processing;
The way in which a user can withdraw their consent;
The means of grievance redressal
However, the contents of this notice have been significantly diluted from previous iterations of the many data protection Bill drafts in the last five years.
For instance, the Act doesn’t require companies to state the duration for which they will store personal data, if it will be shared with third-parties, and if it will be sent to a foreign jurisdiction.
There are exemptions to consent requirements as well:
The Act says that the government can exempt itself and its instrumentalities from adhering to any and all provisions of the law that relate to processing of personal data.
Will your rights be restricted in any way?
Broadly, there are three major roadblocks that impose restrictions, or limit the rights prescribed in the provisions of the law from applying to individuals. These are as follows:
Government exemptions: In the interest of national security, friendly relations with other governments and public order among others, many of the provisions of the Act, including rights afforded to citizens will no longer be applicable.
The way we have prepared the law, it has adequate safeguards for citizens. A lot of the fear against the government’s power comes from citizens’ experience with previous governments. But that is not the case today. People have a lot of trust in our government, IT Minister Ashwini Vaishnaw said.
Processing of data for legitimate uses: Neither the government nor private companies need to seek informed consent from citizens for certain legitimate uses.
For the government, this includes processing personal data for offering subsidies and certificates, responding to a medical emergency, for national security, and during natural disasters.
Private entities can assume consent when an individual has not expressly denied her consent.
#upsc #news #headline #personaldata #online #ITC #protection #industry #rights #legitimateuses #Constitution #grievance #redressal #duration #instrumentalities #roadblocks #ITMinister #AshwiniVaishnaw #subsidies #medicalemergency #disasters #safeguards #online
Your personal data online
GS Paper - 3 (ITC)
Recently, India notified its personal data protection framework as a law, signalling the beginning of a new era of privacy legislation in the country. Provisions of the Digital Personal Data Protection Act, 2023 will come in force in a few months, after the Centre has allowed enough transition time to the industry, with users of these platforms — you — experiencing several new notices and rights, as prescribed in the law.
When can an entity process your personal data?
There are broadly two circumstances under which entities — both government and private — can process an individual’s personal data: (i) There has to be clear consent for such processing; and (ii) for certain “legitimate uses”.
When an entity is processing your personal data for which you have consented, it has to be accompanied by a notice, which is to be made available in all 22 languages of Schedule 8 of the Constitution.
You can directly consent to businesses, and the government can process your personal data, or alternatively use a consent manager.
What happens to your personal data that was collected before this law came into existence?
Any entity that has collected a person’s personal data before the Act came into being should give her a notice about the personal data in its possession “as soon as it is reasonably practicable”.
The notice should include:
The personal data an entity is processing and the purpose for such processing;
The way in which a user can withdraw their consent;
The means of grievance redressal
However, the contents of this notice have been significantly diluted from previous iterations of the many data protection Bill drafts in the last five years.
For instance, the Act doesn’t require companies to state the duration for which they will store personal data, if it will be shared with third-parties, and if it will be sent to a foreign jurisdiction.
There are exemptions to consent requirements as well:
The Act says that the government can exempt itself and its instrumentalities from adhering to any and all provisions of the law that relate to processing of personal data.
Will your rights be restricted in any way?
Broadly, there are three major roadblocks that impose restrictions, or limit the rights prescribed in the provisions of the law from applying to individuals. These are as follows:
Government exemptions: In the interest of national security, friendly relations with other governments and public order among others, many of the provisions of the Act, including rights afforded to citizens will no longer be applicable.
The way we have prepared the law, it has adequate safeguards for citizens. A lot of the fear against the government’s power comes from citizens’ experience with previous governments. But that is not the case today. People have a lot of trust in our government, IT Minister Ashwini Vaishnaw said.
Processing of data for legitimate uses: Neither the government nor private companies need to seek informed consent from citizens for certain legitimate uses.
For the government, this includes processing personal data for offering subsidies and certificates, responding to a medical emergency, for national security, and during natural disasters.
Private entities can assume consent when an individual has not expressly denied her consent.
#upsc #news #headline #personaldata #online #ITC #protection #industry #rights #legitimateuses #Constitution #grievance #redressal #duration #instrumentalities #roadblocks #ITMinister #AshwiniVaishnaw #subsidies #medicalemergency #disasters #safeguards #online