SlideShare a Scribd company logo
1 of 8
Amit Khandelwal Legal Counsel- South East Asia SAS
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Information in public domain and information disclosed under Right to Information Act are excluded from SPDI
[object Object],[object Object],[object Object],[object Object],BPOs, KPOs, LPOs and captive units will have to comply with privacy laws of outsourcing country and (now) of India!
Requirements under the Rules Type of Data Requirements PI and SPDI ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Body Corporate to appoint a Grievance Officer (GO) and publish his name and contact details on its website. Grievance to be resolved within 30 days
Type of Data Requirements SPDI Collection, Withdrawal and Transfer of SPDI:  1.   Usage:  SPDI can be  collected only: a. For lawful business purpose; and b. There is a necessity to collect such information Collected SPDI cannot be used/retained for longer than required period. 2.   Consent:  Body corporate should take prior written consent in the form of a fax, e-mail or letter  from the provider of  SPDI. Provider has a right to decline consent. 3.  Knowledge:  The provider of SPDI should be informed about the purpose, the intended recipients, name and address of agency collecting the  information. 4.  Right of Review and Withdrawal:  The provider of SPDI shall have the right to review the information provided by him/her and will have the discretion to withdraw his/her consent. 5.  Transfer of SPDI:  allowed outside the country provided same level of protection exists. Provider’s consent required
Have  PI? No End yes No Follow slide 5 yes Follow slide 5 & 6 Have  SPDI? End
Disclaimer We acknowledge that this presentation is merely an overview and has been prepared by the presenter for your benefit and should not be construed as a legal opinion. It may not be relied upon by any other person for any other purpose, nor is it to be quoted or referred to in any public document or shown to, or filed with any government authority, agency or other official body without presenter’s prior written consent. © 2011 Amit Khandelwal

More Related Content

What's hot

JSA presentation on corporate crimes_27aug2015_hm
JSA presentation on corporate crimes_27aug2015_hmJSA presentation on corporate crimes_27aug2015_hm
JSA presentation on corporate crimes_27aug2015_hm
Hormuz Mehta
 
Right to information
Right to informationRight to information
Right to information
Nirav Shah
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711
Quotient Consulting
 
Mpc recruitment application form (2016)
Mpc recruitment   application form (2016)Mpc recruitment   application form (2016)
Mpc recruitment application form (2016)
Vhusani Libago
 
Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012
Fuji Xerox Singapore
 
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
Colin Zick
 

What's hot (20)

JSA presentation on corporate crimes_27aug2015_hm
JSA presentation on corporate crimes_27aug2015_hmJSA presentation on corporate crimes_27aug2015_hm
JSA presentation on corporate crimes_27aug2015_hm
 
Right to information
Right to informationRight to information
Right to information
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
Right to privacy on internet and Data Protection
Right to privacy on internet and Data ProtectionRight to privacy on internet and Data Protection
Right to privacy on internet and Data Protection
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711
 
Principles of mobile privacy
Principles of mobile privacyPrinciples of mobile privacy
Principles of mobile privacy
 
Mpc recruitment application form (2016)
Mpc recruitment   application form (2016)Mpc recruitment   application form (2016)
Mpc recruitment application form (2016)
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection Law
 
Basic Data Privacy for Non Lawyers
Basic Data Privacy for Non LawyersBasic Data Privacy for Non Lawyers
Basic Data Privacy for Non Lawyers
 
Data Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-ComplianceData Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-Compliance
 
Data Privacy - Security of Personal Information
Data Privacy - Security of Personal InformationData Privacy - Security of Personal Information
Data Privacy - Security of Personal Information
 
Data Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectData Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data Subject
 
DATA BREACH CHARTS
DATA BREACH CHARTSDATA BREACH CHARTS
DATA BREACH CHARTS
 
RTI ACT 2005 PART-II
RTI ACT 2005 PART-IIRTI ACT 2005 PART-II
RTI ACT 2005 PART-II
 
Data Privacy- Security of Sensitive Personal Information
Data Privacy- Security of Sensitive Personal InformationData Privacy- Security of Sensitive Personal Information
Data Privacy- Security of Sensitive Personal Information
 
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
高谷知佐子講演_PERSONAL DATA AND PRIVACY ISSUES IN CROSS-BORDER M&A PROCESS Japan ca...
 
Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012Highlights of the Singapore Personal Data Protection Act 2012
Highlights of the Singapore Personal Data Protection Act 2012
 
Cyber Tribunal and Cyber Appellate Tribunal in Bangladesh
Cyber Tribunal and Cyber Appellate Tribunal in BangladeshCyber Tribunal and Cyber Appellate Tribunal in Bangladesh
Cyber Tribunal and Cyber Appellate Tribunal in Bangladesh
 
RTI ACT 2005 PART-III
RTI ACT 2005 PART-IIIRTI ACT 2005 PART-III
RTI ACT 2005 PART-III
 
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
MaHIMA_Winter_Meeting___Compliance_Beyond_HIPAA_1_2016
 

Similar to New Data Privacy Rules By Amit Khandelwal

Privacy in India: Legal issues
Privacy in India: Legal issuesPrivacy in India: Legal issues
Privacy in India: Legal issues
Sagar Rahurkar
 

Similar to New Data Privacy Rules By Amit Khandelwal (20)

India's Data Protection Law 2018- Future Road Ahead
India's Data Protection Law 2018- Future Road AheadIndia's Data Protection Law 2018- Future Road Ahead
India's Data Protection Law 2018- Future Road Ahead
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
 
The Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCMThe Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCM
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislation
 
Uchi data local presentation 2020
Uchi data local presentation 2020Uchi data local presentation 2020
Uchi data local presentation 2020
 
The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
Privacy in India: Legal issues
Privacy in India: Legal issuesPrivacy in India: Legal issues
Privacy in India: Legal issues
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdf
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
POPI Seminar FINAL
POPI Seminar FINALPOPI Seminar FINAL
POPI Seminar FINAL
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdfDIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
 
Data Ethics: Legal and ethical obligations to Insurance company
Data Ethics: Legal and ethical obligations to Insurance companyData Ethics: Legal and ethical obligations to Insurance company
Data Ethics: Legal and ethical obligations to Insurance company
 
CHINA PIP LAW ppt.pptx
CHINA PIP LAW ppt.pptxCHINA PIP LAW ppt.pptx
CHINA PIP LAW ppt.pptx
 
Data privacy act of 2012 presentation
Data privacy act of 2012 presentationData privacy act of 2012 presentation
Data privacy act of 2012 presentation
 
HIPAA vs GDPR The How, What, and Why ?
HIPAA vs GDPR The How, What, and Why ? HIPAA vs GDPR The How, What, and Why ?
HIPAA vs GDPR The How, What, and Why ?
 
Startups - data protection
Startups  - data protectionStartups  - data protection
Startups - data protection
 
Privacy Policy
Privacy PolicyPrivacy Policy
Privacy Policy
 

New Data Privacy Rules By Amit Khandelwal

  • 1. Amit Khandelwal Legal Counsel- South East Asia SAS
  • 2.
  • 3.
  • 4.
  • 5.
  • 6. Type of Data Requirements SPDI Collection, Withdrawal and Transfer of SPDI: 1. Usage: SPDI can be collected only: a. For lawful business purpose; and b. There is a necessity to collect such information Collected SPDI cannot be used/retained for longer than required period. 2. Consent: Body corporate should take prior written consent in the form of a fax, e-mail or letter from the provider of SPDI. Provider has a right to decline consent. 3. Knowledge: The provider of SPDI should be informed about the purpose, the intended recipients, name and address of agency collecting the information. 4. Right of Review and Withdrawal: The provider of SPDI shall have the right to review the information provided by him/her and will have the discretion to withdraw his/her consent. 5. Transfer of SPDI: allowed outside the country provided same level of protection exists. Provider’s consent required
  • 7. Have PI? No End yes No Follow slide 5 yes Follow slide 5 & 6 Have SPDI? End
  • 8. Disclaimer We acknowledge that this presentation is merely an overview and has been prepared by the presenter for your benefit and should not be construed as a legal opinion. It may not be relied upon by any other person for any other purpose, nor is it to be quoted or referred to in any public document or shown to, or filed with any government authority, agency or other official body without presenter’s prior written consent. © 2011 Amit Khandelwal

Editor's Notes

  1. India had been criticized by the western world of not having a proper data privacy law in place. Our corporates (esp. outsourcing industry) used to really face difficulties in getting business in India. So with lot of persuasion from Industry forums like NASSCOM, our parliament finally in 2009 was able to include section 43A in the Information Technology Act which partially cater to the need of the hour. But the job was not over, Section 43A did provide the skeleton to the inception of privacy laws in India but the detailed Rules were still to be formed. These Rules were formulated and finally were notified in April 2011.
  2. It is notable that Section 43A defined terms like Body Corporate, Reasonable Security Practices and Procedures, it did not define imp terms like Personal Information and SPDI. These terms were left for CG to define in consultation with Industry forums.8ugub
  3. Again it is noteworthy that section 43A clearly states that when SPDI