Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

Saikrishna & Associates 8th Floor, VJ Business Tower Plot No A-6, Sector 125 Noida, Uttar Pradesh 201301 India

Tel: +91 120 4633900 Fax: +91 120 4633999

Email: info@saikrishnaassociates.com Web: www.saikrishnaassociates.com

1. Legal and Regulatory Framework 1.1 Overview of Data and Privacy- Related Laws Current Law At present, the Information Technology Act, 2000 (the “IT Act”) is the parent legislation under which the delegated legislation – the Informa - tion Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 (the “SPDI Rules”) – provides the framework for data protection and privacy. The SPDI Rules are outdated and are due to be overhauled by dedicated legislation on data protection, called the Digital Personal Data Protection Act, 2023 or the DPDP Act (the “upcoming law”), which was introduced in August 2023. For context, the IT Act contains specific pro - visions on privacy and data protection. For instance, Section 72 imposes a penalty for breach of confidentiality and privacy, and Sec - tion 72A imposes a penalty for disclosure of information in breach of a lawful contract.

Section 43A imposes a liability on a “body cor - porate” (ie, a company, firm, sole proprietorship or other association of individuals engaged in commercial or professional activities) to pay damages by way of compensation for any neg - ligence in implementing and maintaining reason - able security practices and procedures that may result in wrongful loss or wrongful gain to any person. Given the requirement of maintaining reasonable security practices and procedures under Section 43A, the government notified the SPDI Rules in 2011, stipulating the requirements for data protection by body corporates in India. The IT Act read with the SPDI Rules forms the current data protection regime in India. The SPDI Rules apply to the collection and pro - cessing of personal information, which means any information that – directly or indirectly, in combination with other information available or likely to be available to a body corporate – is capable of identifying such person. Personal information is further categorised into sensi - tive personal data or information (SPDI), which consists of information relating to passwords, financial information, physical, physiological and mental health conditions, sexual orientation, medical records and history, and biometric infor -

186 CHAMBERS.COM

Powered by