INDIA Trends and Developments Contributed by: Vikram Jeet Singh and Kalindhi Bhatia, BTG Advaya
to healthcare, education and safety uses that are essential for the child’s well-being and protec - tion. This may hint at more exemptions being possible in the future, based on purpose. What becomes easier: data retention timelines To date, there has been little to no guidance available on data retention and purging prac - tices, particularly when it comes to Personal Data. In fact, Indian businesses are often unso - phisticated in storing, indexing and accessing discrete sets of data. The DPDPA mandates that Personal Data should not be stored if the con - sent of the data subject has been withdrawn, or if the purpose for which the data was collected no longer subsists. Even so, given the multifari - ous types of data that businesses in India will collect, additional guidance would be welcome. It is good news then, that the Draft Privacy Rules contain a good amount of detail on the permitted data retention timelines for different categories of data fiduciaries. Schedule III to these draft rules prescribes bespoke retention periods for e-commerce companies, online gaming plat - forms and social media companies, and also denotes the purposes for which such data can be retained. In addition, data fiduciaries will need to give 48 hours’ notice to data subjects before erasing their Personal Data that is available to the data fiduciary. The inclusion of different retention periods for different types of data serves as good guidance, and encourages businesses to “map” the data they already hold in terms of how long it will need to be retained. Perhaps most importantly, this will enable Indian businesses to delete or purge data that is no longer relevant or needed with some level of confidence. If the volume of Personal Data stored in various locations decreases, this
will hopefully lead to a more secure ecosystem when it comes to potential breaches of data. What becomes clearer: cross-border data transfers One of the biggest fears among Indian busi - nesses, if not the biggest, was that the new law would prescribe data localisation. Over the past decade, a number of Indian regulators have demanded that data should be stored within India. This includes the Reserve Bank of India’s view on payment data, the companies regula - tor’s view on books of account, and the insur - ance regulator’s mandate to store insurance data within India, among others. This trend pos - es challenges to Indian businesses, particularly those that are owned by overseas companies, in their day-to-day operations. The DPDPA does not mandate data localisa - tion. An earlier draft version of the privacy law suggested a “whitelist” mechanism, pursuant to which the Indian government would prescribe the jurisdictions to which data could be trans - ferred. The final DPDPA goes the other way, and requires the government to specifically bar data transfers to a particular jurisdiction, under a “blacklist” mechanism. In addition, there are no requirements to enter into DPAs or SCCs or similar while transferring data outside of India (although this requirement may change in the future). As was clarified in the parent law, there are no overarching restrictions even in the Draft Privacy Rules on the transfer of Personal Data outside India. That said, the central government retains the power to specify restrictions in cases where such Personal Data is made available to any for - eign state, or to any instrumentality of a foreign state. In addition, Significant Data Fiduciaries will need to adopt measures to ensure that cer -
208 CHAMBERS.COM
Powered by FlippingBook