Data Protection and Privacy 2025

INDIA Law and Practice Contributed by: Suvarna Mandal and Rishikaa, Saikrishna & Associates

subscribers using an Indian operator’s network while roaming) outside India. Corporate The Companies Act 2013 requires every com - pany to maintain books of account and financial statements for every financial year. Under the Companies (Accounts) Rules, 2014, such infor - mation must be accessible in India if maintained in electronic mode. The Consumer Protection (Direct Selling) Rules, 2021 require a direct sell - ing entity to take steps to store sensitive per - sonal data in India. 5.4 Blocking Statutes Section 69A of the IT Act grants the govern - ment power to issue directions to block public access to any information in the interest of the sovereignty and integrity of India, security of state, friendly relations with foreign states, etc, if it deems it necessary. The Information Tech - nology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009 (the “Blocking Rules”) issued pursuant to this provision outline the procedure that must be followed for blocking content. Under the Block - ing Rules, anyone can make a complaint to an intermediary to block content. This complaint will then be shared with a designated officer of the government and will be examined by a gov - ernment committee, which must make reason - able efforts to reach out to the originator of the content/intermediary. The committee will submit its final recommendations to the relevant Minis - try, pursuant to which the designated officer will issue the blocking orders. Confidentiality must be maintained in respect of the complaints and actions taken during the blocking process. The constitutionality of this provision had been challenged in the case of Shreya Singhal v Union of India before the Supreme Court of India, stat -

ing that the originator of the content is not given an opportunity for a pre-decisional hearing, and that the confidentiality requirement was uncon - stitutional. The Court upheld the validity of this provision and clarified that any action taken under Section 69A must be backed by a rea - soned order, such that the order can be chal - lenged. The Court further observed that Section 69A does not require an intermediary to deter - mine the legality of the content and that safe harbour would only be lost if the intermediary failed to take down the content upon a court order or government order. In addition, the DPDP Act grants the govern - ment authority to direct any government agency or intermediary to block access to information generated, transmitted, received, stored or hosted on any computer resource that enables a Data Fiduciary to offer goods or services to Data Principals in India, upon receiving a written reference from the DPB. The government must provide an opportunity for the party concerned to be heard, and must take action only if satisfied that doing so is necessary for the public interest. The government is also required to record its As noted in 1.1 Overview of Data and Privacy- Related Laws , in January 2025 the government published the Draft DPDP Rules for public con - sultation. The Draft DPDP Rules impose restric - tions on cross-border data transfers for: • personal data processed within India; and • personal data processed outside India in con - nection with offering goods/services to Data Principals within India. The Draft DPDP Rules also propose that such cross-border transfers would be subject to reasons for taking such action. 5.5 Recent Developments

203 CHAMBERS.COM

Powered by