INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates
data do not apply if the processing is necessary for the following: • a scheme of compromise, arrangement, merger or amalgamation of two or more com - panies; • a reconstruction by way of demerger or oth - erwise; • the transfer of undertaking of one or more company to another company; or • the division of one or more companies, approved by a court or tribunal or any other competent authority. 5. International Considerations 5.1 Restrictions on International Data Transfers Current Data Protection Law As per the SPDI Rules, an entity or any person on its behalf can transfer personal information and/or SPDI to any other entity or person locat - ed in India or abroad if such entity or person ensures the same level of data protection as is required to be adhered to under the SPDI Rules. The transfer would only be allowed if consent has been sought or if it is necessary for the per - formance of the lawful contract between the entity and the provider of information. Upcoming Data Protection Law The DPDP Act, on the other hand, gives the government power to, by notification, restrict the transfer of personal data for processing to such country or territory outside India as may be notified – ie, to provide a negative list of coun - tries to which the transfer of personal data will be restricted. Furthermore, if there is a higher degree of restriction/protection on transfers of personal data outside India in any law (or sec - toral regulation) other than the DPDP Act, then
this higher regime must be followed. Accord - ingly, sectoral laws such as those relating to RBI’s payment systems-related data (having data localisation requirements) will continue to be applicable. However, personal data transfers are exempt - ed from the requirements under the DPDP Act under certain conditions, including but not lim - ited to the following: • the processing of personal data necessary for the enforcement of a legal right or claim; • the processing for prevention, detection, investigation or prosecution of any offence or contravention of law in India; • the processing of personal data of Data Principals outside India under contracts with persons outside India by individuals or enti - ties based in India; and • the processing for a merger, amalgamation, demerger or transfer of two or more compa - nies duly approved by competent authorities. 5.2 Government Notifications and Approvals No approvals from the government are required for international data transfers under the SPDI Rules. However, in the past, the government has been critical of access to information by certain coun - tries and has taken steps to block such access. For instance, in 2020 the government blocked certain mobile applications upon receiving reports about “stealing and surreptitiously trans - mitting users’ data in an unauthorised manner to servers which have locations outside India”. Similar concerns had also been raised by the Indian Cyber Crime Coordination Centre of the Ministry of Home Affairs. Accordingly, the gov - ernment decided to block the apps in the inter -
201 CHAMBERS.COM
Powered by FlippingBook