INDIA Trends and Developments Contributed by: Vikram Jeet Singh and Kalindhi Bhatia, BTG Advaya
implementation and enforcement of the new DPDPA. The members of the Data Protec - tion Board of India will be appointed for a period of two years, and will be eligible for re-appointment. • Notice and consent: businesses will be required to provide notice to the data prin - cipals whose data they collect. Such notice has to be in clear and plain language, with an itemised description of Personal Data and the specific purposes for collection. On the day the new law comes into force, the “data fiduciary” will need to provide a notice to all legacy data subjects, informing them of their rights under the new law. • Security safeguards: the Draft Privacy Rules spell out seven security safeguards that should be implemented by all data fiduciaries who process Personal Data. These include security measures such as encryption or masking, physical access control restric - tions, data-backups, access logs to detect breaches, etc. The data fiduciary is required to retain such logs for one year, and to insert data security provisions in its contracts with data processors. • “Significant Data Fiduciaries”: some entities will face additional obligations under the new law. The law does not yet specify who quali - fies as a Significant Data Fiduciary; this may be notified after the law comes into force. The obligations include undertaking a Data Protection Impact Assessment once every 12 months, and an audit to demonstrate compli - ance with the privacy law. • Breach reporting: data fiduciaries are required to notify affected data principals of data breaches “without delay”. A time limit of 72 hours is specified for reporting such breaches to the Data Protection Board, which is in line with global standards. The notice to the Data
Protection Board will be in addition to notify - ing other regulators, such as CERT-In. What becomes harder: processing children’s data The DPDPA requires “data fiduciaries” to under - take certain compliances for processing the Per - sonal Data of children (ie, individuals under the age of 18). These include: • obtaining verifiable consent from parents or lawful guardians; • not undertaking processing that is likely to cause any detrimental effect on the well- being of a child; and • not undertaking tracking or behavioural monitoring of children or targeted advertising directed at children. The requirement under the parent act to obtain “verifiable parental consent” for processing children’s data continues in the Draft Privacy Rules, which note that data fiduciaries must adopt “appropriate technical and organisational measures” to ensure that “verifiable” consent is obtained from a parent or lawful guardian of a child prior to processing the latter’s Personal Data. In addition to obtaining verifiable consent, the Draft Rules also require data fiduciaries to undertake due diligence to ensure that the individual identifying themselves as a particular child’s parent/guardian is an adult. The Draft Privacy Rules also provide some exemptions when it comes to obtaining verifia - ble consent for the processing of children’s Per - sonal Data. For one, certain categories of data fiduciaries are exempt from these obligations, such as clinical, mental health and educational establishments, allied healthcare professionals, creches and day care facilities. For this, the pro - cessing of a child’s data is to be strictly limited
207 CHAMBERS.COM
Powered by FlippingBook