DATA PRIVACY: REPERCUSSIONS AND LEGAL FRAMEWORK IN INDIA
- Details
- Category: ARTICLES
DATA PRIVACY: REPERCUSSIONS AND LEGAL FRAMEWORK IN INDIA
The concept of data privacy has gathered momentum in recent years with end users becoming aware of their private data and how it can be used by other entities for processing. India is a country with 76 crore active internet users and is the largest connected democracy in the world and is amongst the highest consumers and producers of data per capita among the countries [1]. The advancement in technology has made it possible to violate an individual’s privacy without physically entering into his place or property. In India, the legal backing for the digital privacy of the individual has not gained a stronghold due to a lack of constitutional legal backing.
Personal data can now be cached, copied, and archived by third parties, frequently without the user's knowledge, as a result of increased reliance on web services and the adoption of Web 3.0. This captured data is used for profiling the users for targeted ad delivery or marketing of services. Internet users jeopardize themselves by disclosing private information on websites especially social media websites knowingly or unknowingly and lend themselves prey to cyber-attacks. Today visits to websites are tracked secretly, E-mail addresses and other personal information is captured and used for the marketing of products and services without permission, personal information is sold to third parties, and credit card information is stolen by malicious entities.
REPERCUSSIONS OF THE PRIVACY BREACH
Personally Identifiable Information data (PII) is the most critical and sensitive data which can be used to identify someone uniquely. Many businesses in India are marketing their products and services through unsolicited telemarketing calls/emails/sms that have obtained the private information of the individuals in bulk without consent through a third party with whom the individual has dealt in the past. Such wrong practices in the market can only be dealt with through strong law and legal action. Data Privacy breaches can cause massive damage to the individual or organization if the PII data or private information gets leaked online. Today credit card data, bank customer usernames-passwords, and individual data w/ (name, email, mobile no) are available for purchase on the dark web. This data is acquired through hacking, phishing campaign, and data breaches. Malicious entities can attempt to leverage or make use of such breached data to carry on an attack against an individual or organization for personal gain/benefit.
The real loss from the impact of a data breach cannot be estimated beforehand and only it can be roughly estimated. However, the data breach has definitive financial and non-financial consequences for organizations/individuals. The financial consequences for data breaches include theft of money or fines and fees imposed by regulators/authorities on companies/individual entities on account of compromised user data. The non-financial consequence part is loss of reputation and damage for either an individual or organization.
INFORMATION TECHNOLOGY ACT,2000
The Information Technology Act, of 2000 does not directly deal with the issue of privacy however some provisions of the act deal with the issue of data privacy. The captioned act deals with important issues related to unauthorized access to the computer/data processing systems, damage to the computer through computer contaminants, hacking of the computer systems with malicious intent, breach of privacy and confidentiality, and publishing false digital signature certificates for fraudulent purposes [2].
- Section 43 of the IT Act entitled “Penalty for damage to the computer, computer system, etc.” is related to unauthorized access to a computer system.
- Section 72 of the Act entitled ‘penalty for breach of confidentiality and privacy’ is concerned with the ‘confidentiality’ and ‘privacy’ of individuals.
- Section 66 of the Act deals with hacking. It defines hacking as being committed by someone to cause loss or damage to any public entity or person, destroy/deletes/alters any information residing in computer resource.
- Section 79 of the Act deals with 'Exemption from liability of intermediary in certain cases'. It provides for the Internet Service Provider/Network Service Provider’s Liability for violation of privacy.
- Section 43A of the Information Technology Act (ITA) provides that anybody corporate that possesses, deals with, or handles any “sensitive personal data” or information should maintain reasonable security practices and procedures for protecting such data. It will be liable to pay compensation to the affected person in case of any negligence.
- Section 72A provides for the punishment for intentionally or knowingly disclosing personal information relating to a person that was acquired for providing services under a lawful contract, without the consent of the person concerned.
The Right to Privacy as a fundamental right is not expressly recognized in the Indian Constitution. The Supreme Court, however, determined that the right to privacy is a fundamental right that derives from the right to life and personal liberty as well as other fundamental rights guaranteed by the constitution for preserving individual liberty. [3]. But still, there is no clear law like the European Union's - General Data Protection Law(GDPR) which is the toughest privacy and security law in the world. The Government of India has planned to put in place the "Digital Personal Data Protection Bill" which is intended to give a legal framework to data privacy and is pending enactment. To date, the legal provisions contained in the Information Technology Act, of 2000, and some provisions of the Indian Penal Code have provided legal footing for data privacy.
Data privacy wasn’t given much importance during the early stages of ICT. However as ICT matured and the technological landscape advanced, the value of data became clear enough. It came to be understood that by using data sciences techniques, Machine Learning & AI, and through the use of specialized tools data can be gathered/mined/scrapped for personal benefit and can have numerous beneficial use cases. In 2006, British mathematician Clive Humby coined the phrase, “Data is the new oil”.
Page 3 of 4
