Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

Cybersecurity Law The CERT-IN Directions require cloud service providers to register accurate information per - taining to the following and to maintain it for five years or a longer period as may be required under law after the cancellation or withdrawal of registration: • validated names of subscribers or customers who are hiring the services; • the period of hiring such services, including dates; • IP addresses allotted to/being used by the members; • email address, IP address and time stamp used at the time of registration/onboarding; • the purpose for hiring services; • validated address and contact numbers; and • the ownership pattern of the subscribers/cus - tomers hiring services. Sectoral Law Obligations under sectoral laws will also apply. For instance, the M2MSP Guidelines provide technical and security conditions that must be adhered to for providing M2M services in India, including: • adhering to KYC-related guidelines; • ensuring quality of service; • providing details of the authorised telecom licensee from which connectivity has been sourced; • ensuring protection of privacy of communica - tion and data as per applicable law; and • providing a decryption facility for the content riding on its network as and when required by the authorities. The UL also stipulates certain conditions, such as maintaining log-in/log-out details of all sub - scribers for a minimum period of two years. Fur -

thermore, the Framework for Adoption of Cloud Services by SEBI Regulated Entities (the “Cloud Service Framework”) provides guidelines on the cloud framework that must be adopted by enti - ties regulated by SEBI for maintaining data pri - vacy, security and regulatory compliance. 3.4 Regulators and Enforcement Please see 1.2 Regulators . 4. Sectoral Issues 4.1 Use of Cookies There are no laws that specifically regulate the use of cookies in India. Both current (SPDI Rules) and upcoming (DPDP Act) data protection laws apply to identifiable personal information. Accordingly, cookies would only be governed by the SPDI Rules and later by the DPDP Act if such cookies qualify as personal identifiable data or information. Accordingly, all corresponding obligations relat - ing to the processing of personal data will also apply to the use of cookies if they qualify as identifiable personal data or information. 4.2 Personalised Advertising and Other Given the rudimentary framework of the SPDI Rules, marketing and personalised advertise - ments have largely remained unregulated in India. Having said that, when the DPDP Act comes into force, the general principles rec - ognised therein – such as data minimisation, consent-based processing, etc – would apply to such advertisements and marketing practices, and would require entities to revisit the policies and practices concerning programmatic adver - tising and reliance on third parties for data. Online Marketing Practices Current Data Protection Law

199 CHAMBERS.COM

Powered by