By Siddharth Pankaj Tiwari and Swastik Parhi
Introduction
The Personal Data Protection Bill, 2019, (“the bill”) was introduced and passed in the Lok Sabha on December 11th, 2019.[1] The newly passed bill has now been referred to a joint parliamentary committee to be headed by BJP MP Meenakshi Lekhi which is expected to submit its report during the upcoming budget session.[2].The bill is a revised version of the 2018 draft bill submitted to the central government by the Justice BN Srikrishna Committee (“the Committee”) which was formed by the Ministry of Electronics and Information Technology. [3] The Ministry was fleshed out by the need for a robust data protection regime by the Supreme Court in Justice K.S. Puttaswamy (Retd.) & Anr. v Union of India & Ors. [4] (“Privacy Judgment”).
This blog post discusses the various proposals of the bill regarding rights, authority for data processing and its implications on individuals and companies. Further, it discusses various shortcomings of the bill such as dilution of offences and lack of safeguard on right to privacy.
The Bill and its implications.
The bill espouses to protect the personal data of data principals (individuals) against any misuse by data fiduciary (any government. or private entity).[5] It classifies data into three different categories namely general data, personal data and sensitive personal data.[6] Personal data includes those attributes of a data principal through which the data principal itself can be correctly identified.[7] Sensitive personal data includes data pertaining to one’s finances, health, sexual orientation, sexual health, genetics, caste, political or religious affiliations and beliefs.[8] The definition of general data has not been defined in the bill. The bill lays down the provision that before the usage of sensitive personal data, the concerned data principal needs to be informed and his consent is required.[9]
The bill also seeks to form an authority known as “Data Protection Authority ”(DPA) whose duty will be to protect the interests of data principals, prevent any misuse of personal data as well as sensitive personal data of data principals by data fiduciary, ensure compliance with the provisions of this bill and to promote awareness about data protection.[10] The functions of DPA include taking prompt and appropriate action in response to a personal data breach, examination of any data audit reports and taking any action pursuant thereto and receiving and inquiring into complaints .[11]
The bill if strictly enforced in its current state has numerous safeguards. It provides the data principal with several rights such as right to confirmation and access[12], right to correction and erasure[13], right to data portability[14] and right to be forgotten.[15] If the data fiduciaries, without any reasonable justification, fail to uphold the rights of the data principals then they will be penalized under the bill.[16] The bill makes “knowingly” and “intentionally” re-identification and processing of de-identified personal data without consent of the data fiduciary an offence and provides for imprisonment of up to three years, or fine, or both.[17]
The implication for not complying with provisions of the bill would attract penalties for the data fiduciaries. It provides a penalty of Rs. 5 Crores or 2% of the annual total worldwide turnover of the data fiduciary, whichever is higher, on violation of certain provisions of the Bill such as obligation to conduct a data audit, etc.[18] It also provides a fine of Rs.15 crore or 4% of the total worldwide turnover, whichever is higher, for violation of certain other provision of the bill such as processing or transferring personal data in violation of the bill .[19]
Shortcomings of the bill
Privacy compromised
The Supreme Court while laying down the right to privacy in the privacy judgment provided a three-fold test on the basis of which the right to privacy can be restricted.[20] First, the restriction should be brought in by a law. Second, there needs to be legitimate state interest in restricting the right. Third, the restriction should be necessary and proportional to the object sought to be fulfilled by the law.[21] The committee had suggested that the data protection law may enable an exemption to the processing of personal or sensitive personal data if these three-fold requirements are fulfilled.[22] The same was incorporated in the 2018 draft.
However, the bill does not incorporate the proportionality and necessity test. The committee had suggested[23] that government should bring in a law which will authorize for oversight of intelligence gathering activities for getting exemption on basis of security of state[24] and a law to authorize the law enforcement agencies to get exemption on the basis of prevention, detection, investigation and prosecution of contraventions of law.[25]The bill also does not provide for the requirement of such separate laws for claiming the exemptions. It just provides that the government can avail exemption if it is necessary and expedient for the security of the State, friendly relations with foreign States, public order, etc.[26]
In absence of the proportionality and necessity test, and such laws government can exempt any of its agencies and demand any kind of data disproportionately. For instance, in the absence of these tests in the bill, there is no mechanism which limits the Government’s scrutiny of an accused’s call history or internet surfing history, to the period during which the individual committed the crime. This gives the Government, a free leeway to access an accused’s private data for an unspecified period of time, which in turn, is a blatant disregard to the non-derogable privacy rights of the individual.
Thus, by not complying strictly with the third test laid down by the privacy judgment, the bill legitimizes disproportionate restriction to privacy rights. Therefore, it creates a legal vacuum through which the government and its agencies can extract unrestricted information regarding a data principal.
Watering down of offences and lowering the standard of mens rea.
The bill reduces the effectiveness of the proposed data protection framework by narrowing down the list of offences by an individual when compared to the recommendation of the committee. Only re-identification and processing of de-identified personal data without consent of data fiduciary has been made an offence in the bill.[27] Whereas, the Committee also proposed obtaining, transferring or selling of personal data or sensitive personal data as an offence.[28]
The bill provides only “knowingly” or “intentionally” for determining whether the offence was committed[29] Whereas the committee had suggested that the form of mens rea required for committing an offence under the data protection act should be “knowingly” or “intentionally” or “recklessly”.[30] The import of mens rea captured by recklessness has been omitted, which is on lower hierarchy of mens rea as compared to intentionally[31] or knowingly[32].
Both the acts of reducing the list of offence and increasing the standard of mens rea may have a significant impact as individuals will only be said to have committed offence when it is re-identification and processing of de-identified personal data with “intention” or “knowledge”. Thus, an individual may commit these acts recklessly and infringe upon the privacy of people but will not be liable under the bill.
Government controlled DPA
The committee suggested that a system should be created for selecting members of the DPA in an unbiased and transparent manner.[33] Accordingly, the 2018 draft bill provided for a selection committee compromising the CJI or his nominee (a judge from the Supreme Court), the Cabinet Secretary, government of India and one expert (nominated by the CJI or his nominee and cabinet secretary) to handle data protection, internet laws and other related subjects. .[34] This committee would make recommendations regarding appointments to the board of DPA by the central government. However, the bill provides that the selection committee will consist of the Cabinet secretary, the secretary to the Ministry or Department dealing with legal affairs and the secretary to the Ministry or Department dealing with electronics and information technology.[35]
This significantly weakens the credibility of the selection committee as earlier this committee comprised a judicial, an executive and an external expert as a member. However, now the bill allows only members of the executive to be a part of the selection committee This makes the government the deciding authority on appointing people as chairman and members of the DPA. This amply illustrates the power asymmetry which is at play here, inasmuch as, the composition of the DPA has conveniently been amended for the Government’s self-serving interests.
Conclusion
A robust law for protecting data is the need of the hour in India. The bill tries to lay down a data regime that would safeguard the privacy of individuals by providing them with various rights and imposing penalties on the companies for misusing the data. But the bill in its current form fails to fully deliver its promises and raises concerns regarding the right to privacy of an individual as it makes it easy for the government to claim exemptions under the bill. Moreover, the committee’s suggestions regarding the list of offences and the standard of mens rea should also be included in the bill to make it more effective. Furthermore, the selection committee of DPA should be made more inclusive so that members of the judiciary and external experts can also take part in the selection process.
The authors are 2nd Year B.A. LLB. (Hon.) Students at The National University of Juridical Sciences (NUJS), Kolkata.
[1]PRS Legislative Research, The Personal Data Protection Bill 2019, available at http://prsindia.org/billtrack/personal-data-protection-bill-2019(last visited on 24th December 2019).
[2]The Hindu, Unfulfilled promise: On Personal Data Protection Bill, available at https://www.thehindu.com/opinion/editorial/unfulfilled-promise-on-personal-data-protection-bill/article30323338.ece (last visited on 24th December 2019).
[3] Ikgai Law, Protection Regulation, 2016 and the Personal Data Protection Bill, 2018, September 21, 2019, available at https://www.ikigailaw.com/comparative-analysis-general-data-protection-regulation-2016-and-the-personal-data-protection-bill-2018/#acceptLicense (last visited on 24th December 2019).
[4] Justice K.S. Puttaswamy and Ors. vs. Union of India (UOI) and Ors. (24.08.2017 – SC): MANU/SC/1044/2017.
[5] The Hindu, The Data Protection Bill only weakens user rights, available at
(last visited on 28th December 2019).
[6] Supra note 1.
[7] Id.
[8] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.3(36).
[9] The Personal Data Protection Bill ,2019, 373 of 2019, Cl. 11(1).
[10] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.49(1).
[11] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.49(2).
[12] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.17.
[13] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.18.
[14] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.19.
[15] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.20.
[16] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.58.
[17] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.82.
[18] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.57(1).
[19] The Personal Data Protection Bill ,2019, 373 of 2019, Cl.57(2).
[20] Supra note 4.
[21] Supra note 4 at ¶.180.
[22] Justice Bn Srikrishna Committee, A Free and Fair Digital Economy Protecting Privacy, Empowering Indians, 128(July 27, 2018).
[23] Id, at 150 (July 27, 2018).
[24] The Personal Data Protection Bill, 2018, Cl. 42.
[25] The Personal Data Protection Bill, 2018, Cl. 43.
[26] The Personal Data Protection Bill,2019, 373 of 2019, Cl. 35.
[27] The Personal Data Protection Bill,2019, 373 of 2019, Cl. 82
[28] Supra note 22 at p.166.
[29] The Personal Data Protection Bill,2019, 373 of 2019, Cl. 82.
[30] Id.
[31] Janet loveless, Complete Criminal Law: Text, Cases, and Materials 92 (5th edn, 2016), available at https://www.oxfordlawtrove.com/view/10.1093/he/9780198753292.001.0001/he-9780198753292-chapter-3 (last visited on 24th December 2019).
[32] Legal Information institute, Mens rea, available at https://www.law.cornell.edu/wex/mens_rea# (last visited on 23rd December 2019).
[33] Supra note 22, at p. 153.
[34] The Personal Data Protection Bill, 2018, Cl. 50.
[35]The Personal Data Protection Bill,2019, 373 of 2019, Cl. 42(2).
