INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates
ing any injunction in respect of any action taken or to be taken in pursuance of any power pro - vided under the DPDP Act. However, Indian courts recognise the concept of public interest litigation, which can be filed by a person or group for public good and for the enforcement of their fundamental rights (which includes the right to privacy). 3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation There is no dedicated regulation governing the use of IOT services and the rights and obliga - tions of data holders and data processing servic - es; various laws and regulations across sectors cover data regulation for these services. Telecommunication Law The Telecom Act addresses the development, expansion and operation of telecommunication services and telecommunication networks, and also governs matters connected thereto. The term “telecommunication” is defined broadly in the Telecom Act to include IOT services within the scope of the Telecom Act. However, not all provisions of the Telecom Act have yet come into force. The Department of Telecommunications (DoT) regulates and grants licences for telecommu - nication services in India. These licences have been issued under the erstwhile legislation governing telecommunication in India, which remains in force for a period (specified in the Telecom Act) until it migrates to the new require - ments under the Telecom Act.
Under the licence (ie, Unified Licence, or UL), operational, commercial, financial, security and technical conditions applicable to all service cat - egories have been provided, including: • a requirement for licensees to retain all com - mercial records/Call Detail Records/Exchange Detail Records/IP Detail Records with regard to the communications exchanged on the network; • a prohibition on employing bulk encryption equipment in their network; • taking steps to ensure the confidentiality of customer information; and • being responsible for ensuring the protection of privacy of communication and that unau - thorised interception of messages does not take place. There are also specific requirements for the ser - vices covered within the ambit of the UL, such as access services, internet services and machine- to-machine services. Several rules have been notified under the Tel - ecom Act, such as the Telecommunications (Tel - ecom Cyber Security) Rules, 2024 (the “Telecom Cybersecurity Rules”), which will also have to be complied with while providing IoT services. Even if these obligations do not apply to the IoT service providers directly, the obligations may contractually trickle down to such service pro - viders from the telecom service providers. Sepa - rately, the Telecom Regulatory Authority of India (TRAI) has also deliberated on various issues that impact IoT/M2M services in India. Based on these deliberations, the Guidelines for registration process of “Machine to Machine” service providers & WPAN/WLAN Connectiv - ity Provider for M2M Services (the “M2MSP Guidelines”) regulate M2M services in India and
196 CHAMBERS.COM
Powered by FlippingBook