Nestle Office in
Cyber City Gurgaon Thank you, Mr. Arora for
allowing RS Pvt. Ltd. to
undertake the plantation
activity ! It is great to
have a partner like
NESTLE.
Mr. Sahay, Now you have to
start the tree plantation
activity. We need regular
reports and data collected.
Don't worry sir!
Everything will be
done as per your
requirements.
After few years...
the trees have
grown in various
locations.
Unkown individual hacks the
systems of RS Pvt. Ltd. and
uploads the stolen data on
Dark Web
What? There has been
a data breach from
one of our business
partners.
Hi Mr. Arora! There has
been a cyber security
incident at RS Pvt. Ltd.
Have they collected any
information on behalf
of NESTLE ?
We had done tree plantation
activity through them. The
activity was done on land of
many farmers. They had
collected details of these
farmers such as name, contact
details, images of farms,
location etc.
Personal details of
farmers! But I couldn't
find any Privacy Impact
Assessment (PIA) for
this project.
I don't think any PIA
was done. This was
only one time activity
and we were short on
time to close this.
Anyway, the
breach was from
RS Pvt. Ltd. and
not at our
facilities
The project was done for
NESTLE and the data was
collected on our behalf. In such
scenarios, we are obligated to
ensure that our partner adopts
reasonable security measures.
PIA would have provided us
an opportunity to assess the
project and the partner.
Accordingly, we could have
included reasonable security
measures in agreement.
In some other
jurisdiction, corporates
have been fined to the
tune of 5% of profits of
last 5 years.
In India, the new
bill provides for
penalty upto 250
crores.
This is huge. What
should we do now?
Now, we can only try to
salvage the situation by
cooperating with the
authorities.
I wish if we would have
taken necessary steps at
the time of execution of
project.
Data Privacy Day 2023
"Data Privacy is everyone's
responsibility"