On Friday, a committee in the Ministry of Information and Electronics Technology submitted the draft of a Bill on protection of personal and sensitive data, along with a report of analysis. Both introduce some key terms to the data protection debate:
DATA PRINCIPAL: It is the person, company, or entity whose information is being collected. “Data” means information that is represented in a form that is more appropriate for processing. “Processing” refers to the operations done to the data, often forms of organisation, searching, combining, and more to glean further information.
DATA FIDUCIARY: This can be a person, state, company, or any entity that decides why data should be processed and how it should be processed. Unlike the Ministry committee, others sometimes refer to this as the “data controller”.
SIGNIFICANT DATA FIDUCIARIES: This classification is based on the volume and sensitivity of the data as well as the fiduciary’s revenue, risk of “harm” (see below) to the principal, and type of technology use. Some regulations of the draft apply only to these significant fiduciaries, such as assessments, audits, record keeping, and hiring a data protection officer.
DATA PROCESSOR: While the fiduciary controls how and why data is processed, the processing itself may be conducted by a third-party, the “data processor”. This distinction is important to delineate responsibility as data moves from group to group. For example, in the United States, Facebook (the data controller) was hit by controversy over the actions of a third-party data processor, Cambridge Analytica.
HARM: The draft aims to protect against “harm” to the individual caused by data processing. It relates harm to mental injury, identity theft, finances, reputation, employment, discrimination, and service denial. Harm also includes any restrictions to individual action because of the fear of surveillance and any surveillance that is not “reasonably expected” by the individual.
AUTOMATED MEANS: Data processors work with data either manually or by automated means. While this definitional distinction may blur, in today’s technological landscape “automated means” colloquially connotes processes such as machine-learning algorithms. In these procedures, algorithms sift through vast amounts of data, find patterns, and apply those patterns on new information to get results.
PERSONAL, SENSITIVE DATA: “Personal data” can identify the person associated with the data while “sensitive personal data” covers a list of categories such as passwords, finances, health, biometrics, caste, and more. Personal data can be processed if there is consent, if it is for the functions of the state, if it is in compliance with the law, for prompt action such as medical and safety emergencies, for employment, or for reasonable purposes.
LIMITATIONS: Two key pillars of the Bill are “purpose limitation” and “collection limitation”. The draft limits the collection of data to what is needed for “clear, specific, and lawful” purposes or for reasons that the data principal would “reasonably expect.”
DATA PROTECTION AUTHORITY: The draft calls for the creation of an independent regulatory body, called the “data protection authority” (DPA). It has four groups of tasks. In adjudication, the DPA receives grievances and handles enforcement. In monitoring, it oversees internal assessments and external audits of the fiduciaries, as well as tracks data security breaches. In policy, the DPA defines sensitive personal data, “reasonable purposes” (see below) for processing, forms of consent, and the lawful transfer of data outside of India. Finally, the DPA conducts research and awareness building about data protection.
REASONABLE PURPOSES: The DPA can determine these by taking into account the interests of the fiduciary, public interest, individual rights, and the reasonable expectations of the individual.
DATA TRUST SCORE: The DPA can assign, register, and manage data auditors, who then may give fiduciaries a “data trust score” after a “data audit”.
ADJUDICATING OFFICERS: A wing in the DPA, they will have the power to call people forward for inquiry into fiduciaries, assess compliance, and determine penalties on the fiduciary or compensation to the principal. Adjudication decisions can be appealed against in the appellate tribunal.
RIGHT TO BE FORGOTTEN: Among the tasks of an adjudicating officer is to decide on cases of “the right to be forgotten”, a concept born out of the Internet’s so-called extended memory. With historical roots in European Union law, this right allows an individual to remove consent for data collection and disclosure. While in the EU the task for assessing requests for removal falls on the fiduciary, India’s draft asks the adjudicating officer to decide by balancing individual rights with the right to free speech and the right to information.
DATA PROTECTION OFFICER. The DPO will be appointed in “significant fiduciaries”, and the DPA will liaise with the officer to facilitate data protection and compliance. The officer is tasked with internal “data protection impact assessments”, grievance redress, record maintenance, and more. For foreign fiduciaries, the DPO must be based in India to represent the fiduciary.
DATA LOCALISATION: One of the highly debated topics in the draft, this relates to regulation about the transfer of data outside national borders. The draft Bill suggests mandating every fiduciary to store at least one copy of personal data in India, with exceptions determined by the central government. If the data is “critical personal data” (determined by the central government), then that data can only be stored and processed in India.
Personal data can be transferred out of the country in the case of contracts, with central government and DPA approval, based on adequate level of protection in destination country, or individual consent. Sensitive personal data can be transferred abroad in cases of health emergency and central government approval.
DE-IDENTIFICATION: Often the markers of data that make an individual identifiable can be removed, or masked, in a process of “de-identification.” The committee report admits a definitional grey area, weighing terms such as “anonymisation” and “pseudonymisation”. The draft deems “re-identification” — the reverse of the former — an offence.
PRIVACY BY DESIGN: This is a concept in which the de-identification process plays a role. The report conveys this to mean organisational practices that avoid harm to individuals and that process data in a transparent manner, including the assurance that business interests are achieved without harming privacy rights.
DATA PORTABILITY: The draft grants individuals this right, or the ability to access and transfer one’s own data. It specifies that the data should be received in a “structured, commonly used and machine readable format”. The committee report tempers this right with the issue of trade secrets and technical feasibility. Fiduciaries may charge fees for this process.