Is India’s Personal Data Protection Bill absolute?

 


Author - Hena Kurian


Introduction :

As per an article by Economist back in 2017 titled, ‘The world’s most valuable resource is no longer oil, but data’ protection and regulation of data is a much sophisticated step needed in Indian legislation. The Personal Data Bill was introduced in India’s parliament on December 11 , 2019 which provides the requisites for protection of data of people and also for processing and storing. The Bill also prescribes the rights of people with respect to their personal information.The main objectives of the Personal Data Protection Bill are to protect the right to privacy, the fundamental right and it is important to protect personal data as it is an essential part of informational privacy[1]. And also, the development in the field of digital economy which made usage of data a censorious means of communication between persons. Along with that it is requisite to make a free and fair digital economy by emphasizing informational privacy of individuals and ensuring progress and innovation. Also, to protect the autonomy of individuals in relation with their personal data, to lay down norms for cross-border transfer of personal data, to provide remedies for unauthorized and harmful processing[2]. This Bill also proposes a new independent regulatory body Data Protection Authority (DPA). As the current generation is completely dependent on the internet and they prefer the internet for each and every matter. As every coin has two sides, the internet may also cause issues while we share all our information on that platform. In the urge of getting our work done, we share all our personal sensible information being shared in the cyber platform. The main unnoticed factor over here is we are not aware of who all the persons or companies who store, access, poses or process our data. So, it is essential to have proper legislation to regulate the information shared in networks.

The suggested bill gives emphasis on data protection of individuals. So that no citizens personal information cannot be stored, processed, collected, shared without their prior consent. The companies which access the data should follow the requisites provided by the bill. The bill also allows the customs to swap their data from one internet service provider to another. Severe penalties have been imposed in failure to comply with the proposed Bill. According to this Bill if any organization shares the customers data without permission, they have incurred the fine of INR 15 Crores or 4% of its turnover. Data breach and delay to report it may incur damage of INR 5 Crores or 2% of Companies turnover. If individuals represent the companies they can be sentenced to prison.

Does the Personal Data Protection Bill really protect the privacy of Individuals?

According to Section 4 of the Data Protection Bill any person who posse’s personal data of any other individual has the responsibility to process that data in a fair and reasonable manner with respect to privacy of data principle. According to Section 8 of the bill, the purpose of data or data principle is limited only for purposes that are clear, specific and lawful.

But the main issue in India’s Personal Data Protection Bill is that as per Section 13 any personal data may be processed if such processing is necessary for the purpose of the Central Government or State Government as well Section 14 allows processing of personal data in compliance with law or any other order of any Court or tribunal. Then Section 15 allows processing of personal data necessary for prompt action.

In all these Sections the right of privacy of an individual mentioned in Article 21 of the Indian Constitution is being violated. It is reiterated in case of K.S Puttuswami v Union of India right to privacy is a fundamental righty and shall not be violated. When the data is being collected, stored, processed without the consent of data principle is the complete violation of his privacy rights[3].

According to Section 19 it allows processing of sensitive personal data for certain functions of state as well Section 21 allows processing of sensitive personal data in compliance with law or any order of any court or tribunal. Through these Sections any personal sensitive data can be processed for the functions of state and it obviously leads to violation of privacy of the data owner. The impugned bill provides autonomy to the Government.

The Data Protection Bill was drafted and it was asked to include people who are independent, representatives of stakeholders and some Government nominees in Data Protection Appellate Authorities[4].  But currently in the Bill it poses only Government nominees and it has apparently become a Government Department. Even with the presence of Data Protection Appellate Authorities, there will be a high chance of our data being misused. If the Government requires it to get information like how much money you have in your bank account, when did you go outside, which is your bank too without consent. It may also proceed in framing of individuals in offences. Like this way if the Government can access the data without our consent, it will be like a 24/7 CCTV camera observing us.

The Data Protection Laws of different Countries don't give much power or absolute power to the Government like India’s Personal Data Protection Bill gives for the Government. No Government should have absolute power, that's the basic rule of democracy. That specific rule is being violated in this Bill. The impugned part is, they can access the personal data also the most sensible data of individuals without their consent and this data can be processed for any purpose by the agencies of Government if the Government states that specific data is requisite for interest of sovereignty of the Country. The Government can act arbitrarily with these powers which are given by the Bill. Data protection Bill mentions data localization, this cannot ensure proper security, that is even if data is stored in this but may be encryption may be done in other countries here also our privacy is violated. And also, Section 25 provides the discretionary power to the Data Protection Authority, for informing an individual for leakage of data. This provision is a harm for privacy rights. Whether the leakage of data be minor or major the owner of the data has the complete right over the data. Necessarily he has to know about what happened to his data while processing it. If this provision exists in the act the DPA may themselves or for Government or Governmental agencies or for private entities may leak the data of the individual and using their discretionary power they will conceal it. As privacy is the main concern for evolving the act these kinds of provisions cannot be allowed and it will be providing ultra virus and arbitrary power to the Government.

Can the economy be ramped up through India’s Personal Data Protection Bill?

Bill also contain provisions related to non-personal data that the Government can require any enterprise or business to share non-personal data to them. The information or data includes which are collected by Google or other browsers. The bill doesn’t emphasize the loss of business through these. This may create a long-term loss for the economy and innovation[5].

If companies get information about the online habits of customers it can easily advertise themselves on that platform. If the companies get this information regarding individuals it can advertise in a convincing way. So, India’s future economy depends on regulation of data.The Bill mandates that fiduciaries who store data should provide it to the government when required. This may be used by the companies to fund their business. This may not lead to a boost to our Country’s economy. Using data localization, the Government will be able to assess the internet giants. By assessing that Government can collect tax accordingly. By providing absolute power to the Government to surveil data without checks and balances it may cause deleterious consequences for innovation in the economy. The absolute power provided to the government will be converted to arbitrary usage and ultra virus as well. The regulatory framework in this bill only concentrates on the date of the business or the enterprise which are the vast majority affected business. Basically, most of the businesses in India majorly small startups, so the bill may not consider them.

Conclusion :

This Data Protection Bill has to be protected from invasion of State Government or Central Government or Governmental Authorities or agencies. There should be stringent provision that when, whom or in which circumstances the powers of state can be exercised and the procedure also what is necessary in accessing the personal information of individuals without consent. The bill is a part of Government’s agenda to access personal data of citizens as similar to Aadhar Act, the data localization mandate by Reserve Bank of India and also coming National Level Block chain Framework [6].

As the Act didn’t mention any of these and should have strict provision regarding these issues which are essential to fulfill the objectives of the Act. There should be compulsory provisions to control the power and there should be provision that data can be accessed by the Government only in necessary conditions. The Personal Data Protection Bill should be amended for its accomplishment. As the bill has been evolving for the purpose of securing privacy of individuals and if the bill itself violates the objective of its own can bring the bill worthless. So bill shall be drafted in a way to accomplish the objective of the bill.

References :

[1] www.cisomag.com- All you need to know about India’s first Data Protection Bill

[2] Personal Data Protection Bill

[3] SSRN- UNSW Law Research paper No-2014-48

[4] Data Protection Bill not in the line-Justice N Srikrishna

[5]Carnegie India- What is in India’s Sweeping Personal Data Protection Bill?

[6] Plug loopholes in Personal Data Protection Bill- Yogesh Pratap Singh