Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

The proposed requirements of providing “item - ised descriptions” and independent presentation of the notice are more onerous than in the EU GDPR. Notification of personal data breach Upon becoming aware of a personal data breach, a Data Fiduciary (an entity who alone or in conjunction with another entity determines the means and purpose of the processing of personal data) must inform, without delay, each affected Data Principal (an individual to whom the personal data relates) and the Data Pro - tection Board of India (DPB – an independent adjudicating body that will enforce the DPDP Act) about the nature and extent of the breach, potential consequences, mitigation measures, safety measures and business contact informa - tion of an individual who can respond to their queries. After this, a detailed report will have to be submitted to the DPB within 72 hours (unless an extension is granted by the DPB upon a writ - ten request) with updated information about the breach, mitigation and remedial measures, findings regarding the person responsible for the breach, and a report about the Data Princi - pal notification. The proposed requirements of notifying affected Data Principals and double reporting to the DPB is onerous. These proposed reporting requirements are also in addition to requirements to report breaches to a separate authority under cybersecurity regulations. Verifiable consent Verifiable consent of a parent/lawful guardian will have to be obtained before processing the per - sonal data of a child or a person with disability. As per the Draft DPDP Rules, appropriate tech - nical and organisational measures would have to be adopted to ensure that verifiable consent of the parent is obtained before the processing of a child’s personal data. The DPDP Rules also

provide mechanisms to verify parental consent through identity details of the parent available to the Data Fiduciary, or through voluntarily pro - vided identity and age details of the parent or a virtual token mapped to the same, issued by an entity authorised by law/government, includ - ing through a digital locker service provider. Due diligence must be undertaken to ensure that the person identifying as the parent is an identifiable adult and that the lawful guardian is appointed by a court or competent authority as per the Indian guardianship law. Reasonable security safeguards It has been proposed that minimum baseline safeguards must be adopted by a Data Fiduci - ary, such as encryption, obfuscation of virtual tokens mapped to that personal data, and vis - ibility on the accessing of personal data. No spe - cific standards have been prescribed. Cross-border transfer The government may direct, by general or spe - cial orders, Data Fiduciaries to meet certain spe - cific requirements (or restrictions) for transferring personal data to foreign states or entities under the control of such states. Additional obligations for Significant Data Fiduciaries (SDF) SDFs are a category of a Data Fiduciary that will be notified by the government based on its assessment of factors listed in the DPDP Act. The Draft DPDP Rules require SDFs to under - take audits and Data Protection Impact Assess - ments (DPIA) annually, and to ensure that a report regarding these activities is submitted to the DPB. Furthermore, due diligence will have to be exercised to verify that the “algorithmic software” deployed by an SDF for personal data processing does not pose risks to the Data Principal’s rights. The government can specify

188 CHAMBERS.COM

Powered by