Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

address concerns relating to their interface with telecom service providers, security, encryption, etc. These guidelines require entities to regis - ter themselves with the DoT and comply with, among other things, the Know-Your-Customer (KYC) and related guidelines and maintenance of customer data requirements. The guidelines also mandate technical and security measures to ensure the protection of communication and data privacy. Information Technology Law Although the IT Act does not specifically mention the term “internet of things”, its provisions apply to IoT devices and services in several ways. For instance, in respect of data protection, the SPDI Rules (and subsequently the DPDP Act) would apply to processing personal data in providing such services. Furthermore, the CERT-IN Rules and the CERT- IN Directions, as well as the reporting require - ments, apply to such services from a cyberse - curity perspective. Cloud service providers are required to register accurate information, such as the names of subscribers hiring the service, period of hire, IP addresses allotted to them, and validated addresses and contact numbers. IoT platforms that qualify as intermediaries would also be subject to the due diligence requirements under the IT Rules 2021, including: • prominently publishing the privacy policy and user agreements on the website/app; • making reasonable efforts to ensure that pro - hibited or harmful information is not hosted, uploaded or published through such plat - forms; • taking down content upon receiving actual knowledge of the unlawful content/informa -

tion being stored, hosted or published by the intermediary; • retaining user registration information for 180 days; and • securing computer resource and information

contained in it. Sectoral Laws

IoT services would also be subject to the requirements under sectoral laws. For instance, IoT-based payment systems would have to com - ply with the RBI guidelines for secure transac - tions and data storage. In fact, the mandate on tokenisation of card details on devices has also recently been extended to IoT devices. The Guidelines for acquiring and producing Geospatial Data and Geospatial Data Services including Maps (the “Geospatial Guidelines”) regulate the collection, use and acquisition of geospatial data and maps of India in product content and materials being offered to Indian customers. According to these guidelines, enti - ties do not require prior approval, clearance or a licence for the collection, generation, prepa - ration, dissemination, storage, publication, updating and/or digitisation of geospatial data and maps in India, apart from the requirements mandated under the Geospatial Guidelines. These guidelines impose restrictions in the form of indicating a “negative list of attributes” and a “threshold value” for spatial accuracy of geospa - tial data and maps. Foreign entities are prohibited from generating geospatial data or maps at a scale finer than the threshold value specified in the Geospatial Guidelines. However, geospatial data or maps created at a coarser scale, resolution or accu - racy are permitted for foreign companies.

197 CHAMBERS.COM

Powered by