INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates
3.2 Interaction of Data Regulation and Data Protection Since there is no dedicated statute on data regu - lation for IoT services and data processing ser - vices, the data protection requirement will flow from data protection laws in India, since such services handle both personal and non-person - al data sets. Accordingly, entities offering such services would have to comply with consent, notice, disclosure, transfer and reasonable secu - rity-related requirements under the data protec - tion law of India. Furthermore, IoT systems and data processing services will also be subject to various cybersecurity rules. 3.3 Rights and Obligations Under Applicable Data Regulation The general obligations and rights stipulated in the SPDI Rules and the DPDP Act would apply to the processing of personal data by IoT service providers. Current Data Protection Law The SPDI Rules provide the right to review the information, and ensure that any information found to be inaccurate or deficient is corrected or amended. These rules also provide the right to withdraw consent and the right to grievance redressal to the provider of information. The obli - gations for body corporates include: • providing a privacy policy on the website; • collecting SPDI only with written/electronic consent; • not retaining SPDI for longer than is required for the purposes for which the information may lawfully be used; • compliance with disclosure and transfer-relat - ed requirements; and • implementing reasonable security standards.
Upcoming Data Protection Law Under the DPDP Act, a Data Principal has the right to access (on request) a summary of per - sonal data and processing activities, the identi - ties of all Data Fiduciaries and Data Processors, and any other information that may be prescribed through rules. The right to the correction, com - pletion, updating and erasure of personal data, and the right to withdraw consent, have also been provided for consent-based processing of personal data. The right to grievance redres - sal and the right to nominate another person in the event of death or incapacity are available irrespective of the bases for the processing of personal data. As far as obligations under the DPDP Act are concerned, a Data Fiduciary is required to pro - cess personal data only for a lawful purpose. Furthermore, a notice needs to be provided for consent-based processing of personal data. The DPDP Act also stipulates general obligations for a Data Fiduciary, including but not limited to: • general compliance with the provisions of the DPDP Act, including for processing under - taken by a Data Processor (engaged through a valid contract); • implementing appropriate technical and organisational measures; • taking reasonable security safeguards to pre - vent personal data breaches; • notifying the affected Data Principal and the DPB regarding any personal data breach; and • establishing grievance redressal mechanisms. The Draft DPDP Rules further elaborate on some of these obligations, including, for instance, stip - ulating minimum baseline security measures that must be adopted by a Data Fiduciary.
198 CHAMBERS.COM
Powered by FlippingBook