INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates
• examining the appropriateness and viability of the technical measures to strengthen compli - ance and enforcement tools across AI eco - systems; and • forming a subgroup to work with MeitY on strengthening the legal framework for digital industries under the DIA. 1.6 Interplay Between AI and Data Protection Regulations AI and data protection are interconnected, since AI relies on datasets to generate output. These datasets often contain personal information or data, and are used during all stages of AI train - ing, development, deployment and use. Accord - ingly, any development and use of AI would have to comply with the data protection laws and cybersecurity laws in the country, particularly for the collection, processing and storage of data. Impact of DPDP Act on AI With the introduction of the DPDP Act, the focus of data protection is set to move to consent- based processing. The term “processing” has been defined broadly in the DPDP Act to mean a “wholly or partly automated operation or set of operations performed on digital personal data”, including operations such as collection, recording, organisation, storage, adaptation, retrieval, use, sharing, dissemination or erasure. Accordingly, consent will have to be obtained for the processing of personal data obtained from users, developers and third parties, and while scraping from private databases. The DPDP Act will not apply if the AI platform uses publicly available personal data and if the processing is done for statistical, research and archival purposes. In addition, the transfer of personal data from India to other countries would be subject to the requirements and restrictions under the data protection laws, which may play
a crucial role in the development of indigenous infrastructure and practices surrounding AI tech - nologies. As noted in 1.5 AI Regulation , the need to com - ply with the data protection laws has also been recognised in the AI Report. Impact of Cybersecurity Laws on AI From a cybersecurity perspective, the develop - ers and deployers of AI technology would have to ensure that they have reasonable security safeguards in place to prevent any cybersecu - rity incidents such as data breaches, data leaks, attacks on IoT devices, attacks or malicious activities affecting systems, servers, software or applications related to AI, and machine learning. The CERT-IN also requires service providers and companies to enable logs of all ICT systems, and to maintain them in India. Any regulatory and legal framework that is being developed to govern and harness the potential of AI technologies would have to be cognisant of these considerations, and would also have to take into account the practical implications at the organisational and user levels. In 2017, in the case of Justice K.S. Puttaswamy (Retd) v Union of India, a nine-judge bench of the Supreme Court declared that the “right to privacy” was a fundamental right under the “right to life” provided in the Indian Constitution. The Court recognised the importance of protecting one’s identity and information, as well as the freedom to share or withhold such information as per an individual’s choice. However, funda - mental rights are subject to restrictions. Accord - 2. Privacy Litigation 2.1 General Overview
193 CHAMBERS.COM
Powered by FlippingBook