INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates
certain personal data sets and traffic data that cannot be transferred outside India, based on the recommendations of a committee consti - tuted by the government; in effect, this is a data localisation requirement for an SDF. Consent managers The DPDP Act allows a Data Principal to give, manage, review or withdraw consent through a Consent Manager. The Draft DPDP Rules stipu - late the registration requirements and obliga - tions of such Consent Managers, including that they must be incorporated in India and have suf - ficient capacity to fulfil their obligations, includ - ing technical, operational and financial capacity. These Consent Managers are also required to onboard Data Fiduciaries onto their platform to send requests to users and avoid any conflict of interest with Data Fiduciaries in respect of mana - gerial personnel having directorship or financial interests. Onboarding with a Consent Manager is not mandatory. Timelines for erasure of data The Draft DPDP Rules mandate that e-com - merce platforms with at least 20 million regis - tered users in India, online gaming intermedi - aries with at least 5 million registered users in India, and social media intermediaries with at least 20 million registered users in India must erase a Data Principal’s personal data if the Data Principal has not engaged with the Data Fiduci - ary for the performance of the specified purpose, or exercised their rights regarding the process - ing, for a period of three years, whichever is the latest. A Data Fiduciary is also required to notify the Data Principal at least 48 hours in advance about the scheduled erasure. No clarity is avail - able on timelines for other types of Data Fidu - ciaries.
The DPDP Act allows the government to imple - ment the provisions in a phased manner by appointing different dates for the coming into force of different provisions of the DPDP Act. The Draft DPDP Rules also propose that the pro - visions pertaining to the functioning of the DPB will come into effect immediately upon notifica - tion of the rules. However, the more critical provi - sions for Data Fiduciaries – such as the manner of providing notice, treatment of children’s data, designation of Significant Data Fiduciaries, etc – will come into effect later. According to unofficial reports, the government has indicated that it will provide a period of two years to transition to the The IT Act imposes a cybersecurity reporting requirement. The IT Act read with the Informa - tion Technology (the Indian Computer Emergen - cy Response Team and Manner of Performing Functions and Duties) Rules, 2013 (the “CERT-IN Rules”) and the Directions relating to informa - tion security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet (the “CERT-IN Direc - tions”) comprise the cybersecurity regulations in India. The cybersecurity reporting require - ments get triggered in case of a “cybersecurity incident” and are in addition to the reporting requirements in the DPDP Act, once that comes into force. The CERT-IN Rules and the CERT- IN Directions apply to cybersecurity incidents including but not limited to data breaches, data leaks, unauthorised access of IT systems, ran - somware attacks, identity thefts, etc. requirements under the DPDP Act. Cybersecurity and Sectoral Laws In addition, sectors such as finance, telecom - munications, securities, insurance, etc, are gov - erned by specific regulations that impose data protection requirements on regulated entities.
189 CHAMBERS.COM
Powered by FlippingBook