SlideShare a Scribd company logo
1 of 12
The Digital Personal Data
Protection Bill, 2023
Character Arc: tracing
past developments
• Unchecked processing of personal data may have adverse implications for the
privacy of persons, which has been recognized as a fundamental right (Justice
K.S. Puttaswamy (Retd) vs. Union of India),
• In 2017, the central government constituted a Committee of Experts on Data
Protection, chaired by Justice B. N. Srikrishna, to examine issues relating to data
protection in the country. The Committee submitted its report in July 2018.
Based on the recommendations of the Committee, the Personal Data Protection
Bill, 2019 was introduced in Lok Sabha in December 2019. The Bill was referred
to a Joint Parliamentary Committee which submitted its report in December 2021
which ultimately took form of Digital Personal Data Protection Bill 2022.
• In August 2022, the Bill was withdrawn from Parliament. In November 2022, a
Draft Bill was released for public consultation. In August 2023, the Digital
Personal Data Protection Bill, 2023 was introduced in Parliament.
Important Definitions
• “Data” means a representation of information, facts, concepts, opinions or instructions in a
manner suitable for communication, interpretation or processing by human beings or by
automated means;
• “personal data” means any data about an individual who is identifiable by or in relation to
such data
• “Data Fiduciary” means any person who alone or in conjunction with other persons
determines the purpose and means of processing of personal data;
• “Data Principal” means the individual to whom the personal data relates and where such
individual is—
• a child, includes the parents or lawful guardian of such a child;
• a person with disability, includes her lawful guardian, acting on her behalf;
• “Data Processor” means any person who processes personal data on behalf of a Data
Fiduciary;
• “Processing” has been defined as wholly or partially automated operation or set of
operations performed on digital personal data, and include operations such as collection,
recording, organisation, structuring, storage, adaptation retrieval, use, alignment or
combination, indexing, sharing, disclosure by transmission, dissemination or otherwise
making available, restriction, erasure or destruction’.
Application of
the Bill
• Applicability: The Bill applies to the
processing of digital personal data within
India where such data is: (i) collected online,
or (ii) collected offline and is digitized. It will
also apply to the processing of personal data
outside India if it is for offering goods or
services in India.
• The Bill does not apply to: not apply to— (i)
personal data processed by an individual for
any personal or domestic purpose; and (ii)
personal data that is made or caused to be
made publicly available by—
(A)the Data Principal
(B)any other person who is under an
obligation under any law for the
time being in force in India to make
such personal data publicly
available.
Consent
• Consent: Personal data may be processed only for a lawful
purpose after obtaining the consent of the individual. A notice
must be given before seeking consent. The notice should contain
details about the personal data to be collected and the purpose of
processing.
• Consent may be withdrawn at any point in time and the details of
the manner for withdrawal shall be provided in the notice itself .
• Consent will not be required for ‘legitimate uses’ including: (i)
specified purpose for which data has been provided by
an individual voluntarily, (ii) provision of benefit or
service by the government, (iii) medical emergency, and
(iv) employment.
• For individuals below 18 years of age, consent will be provided by
the parent or the legal guardian.
Obligations of
data fiduciaries
• The entity determining the purpose and means
of processing, (data fiduciary), must:
• (i) make reasonable efforts to ensure the
accuracy and completeness of data,
• (ii) build reasonable security safeguards to
prevent a data breach,
• (iii) inform the Data Protection Board of
India and affected persons in the event of a
breach, and
• (iv) erase personal data as soon as the
purpose has been met and retention is not
necessary for legal purposes (storage
limitation). In case of government entities,
storage limitation and the right of the data
principal to erasure will not apply.
SDFs and their
obligations
• The government may notify ‘significant data
fiduciaries’ (SDFs) by assessing factors like
volume and sensitivity of the personal data
processed, risk to the rights of the data
principals, potential impact on the
sovereignty and integrity of India, among
other things.
• SDFs must:
(i) appoint a data protection officer (DPO)
based in India – who will be responsible to
the board of directors of the SDF;
(ii) appoint an independent data auditor
to evaluate the SDF’s compliance with the
Bill;
(iii) undertake data protection impact
assessments (DPIA) and periodic audits,
as may be prescribed under rules
Rights and Duties
of Data Principal
• An individual whose data is being processed (data principal), will have the
right to: (i) obtain information about processing, (ii) seek correction and erasure
of personal data, (iii) nominate another person to exercise rights in the event of
death or incapacity, and (iv) grievance redressal.
• Data principals will have certain duties. They must not: (i) register a false or
frivolous complaint, and (ii) furnish any false particulars or impersonate another
person in specified cases. Violation of duties will be punishable with a penalty of
up to Rs 10,000.
Transfer of
Personal Data
Abroad
• Transfer of personal data outside
India: The Bill allows transfer of
personal data outside India, except
to countries restricted by the central
government through notification
Exemptions
• Rights of the data principal and obligations of data fiduciaries (except data security) will not apply in specified cases. These
include:
• (a) Processing of personal data is allowed if it is necessary to enforce a legal right or claim.
• (b) Processing of personal data by a court, tribunal, or other body in India is allowed if it is necessary for the
performance of a judicial, quasi-judicial, regulatory, or supervisory function.
• (c) Processing of personal data is allowed if it is necessary to prevent, detect, investigate, or prosecute an offense or
contravention of any law in India.
• (d) Processing of personal data of Data Principals (DPs) who are not in India is allowed if it is pursuant to a contract
entered into with any person outside India by any person based in India.
• (e) Processing of personal data is allowed if it is necessary for a scheme of compromise or arrangement or merger or
amalgamation of two or more companies, or a reconstruction by way of demerger or otherwise of a company, or
transfer of undertaking of one or more company to another company, or involving division of one or more
companies, approved by a court, tribunal, or other authority competent to do so by any law in force.
• (f) Processing of personal data is allowed for the purpose of ascertaining the financial information and assets and
liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial
institution, subject to such processing being in accordance with the provisions regarding disclosure of information or
data in any other law in force.
• The central government may, by notification, exempt certain activities from the application of the entire Bill.
These include:
• processing by government entities in the interest of the security of the state and public order, and
• research, archiving, or statistical purposes
Data Protection
Board of India
• The central government will establish the
Data Protection Board of India. Key functions
of the Board include:
 monitoring compliance and imposing
penalties,
 directing data fiduciaries to take necessary
measures in the event of a data breach, and
 hearing grievances made by affected
persons.
• Board members will be appointed for two
years and will be eligible for re-appointment.
• The central government will prescribe details
such as the number of members of the Board
and the selection process.
Penalty • The schedule to the Bill specifies penalties for
various offences such as up to: (i) Rs 200 crore
for non-fulfilment of obligations for children,
and (ii) Rs 250 crore for failure to take security
measures to prevent data breaches.
• Penalties will be imposed by the Data
Protection Board after conducting an inquiry.

More Related Content

Similar to Digital Personal Data Protection Bill 2023 PPT.pptx

DIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptx
DIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptxDIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptx
DIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptxVijay Dalmia
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityEmerson Bryan
 
Freedom of Information and Data Protection
Freedom of Information and Data ProtectionFreedom of Information and Data Protection
Freedom of Information and Data ProtectionEquiGov Institute
 
WB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillWB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillTrustArc
 
Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...
Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...
Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...Spice Route Legal
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADr. Oliver Massmann
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillAntaraa Vasudev
 
Right to information act, 2005
Right to information act, 2005Right to information act, 2005
Right to information act, 2005Manish Runthala
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance PreparationLawPlus Ltd.
 
Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Minh Duong
 
Principles and guidelines and approach for the documents
Principles and guidelines and approach for the documentsPrinciples and guidelines and approach for the documents
Principles and guidelines and approach for the documentsvaanila2023
 
Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Nanda Mohan Shenoy
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...Dr. Oliver Massmann
 
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson LLP
 
India’s Digital Personal Data Protection Bill-New.pdf
India’s Digital Personal Data Protection Bill-New.pdfIndia’s Digital Personal Data Protection Bill-New.pdf
India’s Digital Personal Data Protection Bill-New.pdfInfosec train
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawFatmaAkram2
 
An Indian Outline on Database Protection
An Indian Outline on Database ProtectionAn Indian Outline on Database Protection
An Indian Outline on Database ProtectionSinghania2015
 

Similar to Digital Personal Data Protection Bill 2023 PPT.pptx (20)

DIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptx
DIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptxDIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptx
DIGITAL PERSONAL DATA PROTECTION ACT 2023-PPT-VPD.pptx
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
Freedom of Information and Data Protection
Freedom of Information and Data ProtectionFreedom of Information and Data Protection
Freedom of Information and Data Protection
 
WB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillWB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection Bill
 
Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...
Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...
Digital Personal Data Protection Act, 2023: A Guide to the Applicability of t...
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection Bill
 
Right to information act, 2005
Right to information act, 2005Right to information act, 2005
Right to information act, 2005
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance Preparation
 
Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Asia Counsel Insights May 2023
Asia Counsel Insights May 2023
 
Principles and guidelines and approach for the documents
Principles and guidelines and approach for the documentsPrinciples and guidelines and approach for the documents
Principles and guidelines and approach for the documents
 
Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Personal Data Protection Bill 2018
Personal Data Protection Bill 2018
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
India’s Digital Personal Data Protection Bill-New.pdf
India’s Digital Personal Data Protection Bill-New.pdfIndia’s Digital Personal Data Protection Bill-New.pdf
India’s Digital Personal Data Protection Bill-New.pdf
 
China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection Law
 
An Indian Outline on Database Protection
An Indian Outline on Database ProtectionAn Indian Outline on Database Protection
An Indian Outline on Database Protection
 

Recently uploaded

如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionAnuragMishra811030
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书Fir L
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaBridgeWest.eu
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
Ricky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in MidlothianRicky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in MidlothianRicky French
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 

Recently uploaded (20)

如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad Visa
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to Service
 
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
Ricky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in MidlothianRicky French: Championing Truth and Change in Midlothian
Ricky French: Championing Truth and Change in Midlothian
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 

Digital Personal Data Protection Bill 2023 PPT.pptx

  • 1. The Digital Personal Data Protection Bill, 2023
  • 2. Character Arc: tracing past developments • Unchecked processing of personal data may have adverse implications for the privacy of persons, which has been recognized as a fundamental right (Justice K.S. Puttaswamy (Retd) vs. Union of India), • In 2017, the central government constituted a Committee of Experts on Data Protection, chaired by Justice B. N. Srikrishna, to examine issues relating to data protection in the country. The Committee submitted its report in July 2018. Based on the recommendations of the Committee, the Personal Data Protection Bill, 2019 was introduced in Lok Sabha in December 2019. The Bill was referred to a Joint Parliamentary Committee which submitted its report in December 2021 which ultimately took form of Digital Personal Data Protection Bill 2022. • In August 2022, the Bill was withdrawn from Parliament. In November 2022, a Draft Bill was released for public consultation. In August 2023, the Digital Personal Data Protection Bill, 2023 was introduced in Parliament.
  • 3. Important Definitions • “Data” means a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means; • “personal data” means any data about an individual who is identifiable by or in relation to such data • “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data; • “Data Principal” means the individual to whom the personal data relates and where such individual is— • a child, includes the parents or lawful guardian of such a child; • a person with disability, includes her lawful guardian, acting on her behalf; • “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary; • “Processing” has been defined as wholly or partially automated operation or set of operations performed on digital personal data, and include operations such as collection, recording, organisation, structuring, storage, adaptation retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction’.
  • 4. Application of the Bill • Applicability: The Bill applies to the processing of digital personal data within India where such data is: (i) collected online, or (ii) collected offline and is digitized. It will also apply to the processing of personal data outside India if it is for offering goods or services in India. • The Bill does not apply to: not apply to— (i) personal data processed by an individual for any personal or domestic purpose; and (ii) personal data that is made or caused to be made publicly available by— (A)the Data Principal (B)any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available.
  • 5. Consent • Consent: Personal data may be processed only for a lawful purpose after obtaining the consent of the individual. A notice must be given before seeking consent. The notice should contain details about the personal data to be collected and the purpose of processing. • Consent may be withdrawn at any point in time and the details of the manner for withdrawal shall be provided in the notice itself . • Consent will not be required for ‘legitimate uses’ including: (i) specified purpose for which data has been provided by an individual voluntarily, (ii) provision of benefit or service by the government, (iii) medical emergency, and (iv) employment. • For individuals below 18 years of age, consent will be provided by the parent or the legal guardian.
  • 6. Obligations of data fiduciaries • The entity determining the purpose and means of processing, (data fiduciary), must: • (i) make reasonable efforts to ensure the accuracy and completeness of data, • (ii) build reasonable security safeguards to prevent a data breach, • (iii) inform the Data Protection Board of India and affected persons in the event of a breach, and • (iv) erase personal data as soon as the purpose has been met and retention is not necessary for legal purposes (storage limitation). In case of government entities, storage limitation and the right of the data principal to erasure will not apply.
  • 7. SDFs and their obligations • The government may notify ‘significant data fiduciaries’ (SDFs) by assessing factors like volume and sensitivity of the personal data processed, risk to the rights of the data principals, potential impact on the sovereignty and integrity of India, among other things. • SDFs must: (i) appoint a data protection officer (DPO) based in India – who will be responsible to the board of directors of the SDF; (ii) appoint an independent data auditor to evaluate the SDF’s compliance with the Bill; (iii) undertake data protection impact assessments (DPIA) and periodic audits, as may be prescribed under rules
  • 8. Rights and Duties of Data Principal • An individual whose data is being processed (data principal), will have the right to: (i) obtain information about processing, (ii) seek correction and erasure of personal data, (iii) nominate another person to exercise rights in the event of death or incapacity, and (iv) grievance redressal. • Data principals will have certain duties. They must not: (i) register a false or frivolous complaint, and (ii) furnish any false particulars or impersonate another person in specified cases. Violation of duties will be punishable with a penalty of up to Rs 10,000.
  • 9. Transfer of Personal Data Abroad • Transfer of personal data outside India: The Bill allows transfer of personal data outside India, except to countries restricted by the central government through notification
  • 10. Exemptions • Rights of the data principal and obligations of data fiduciaries (except data security) will not apply in specified cases. These include: • (a) Processing of personal data is allowed if it is necessary to enforce a legal right or claim. • (b) Processing of personal data by a court, tribunal, or other body in India is allowed if it is necessary for the performance of a judicial, quasi-judicial, regulatory, or supervisory function. • (c) Processing of personal data is allowed if it is necessary to prevent, detect, investigate, or prosecute an offense or contravention of any law in India. • (d) Processing of personal data of Data Principals (DPs) who are not in India is allowed if it is pursuant to a contract entered into with any person outside India by any person based in India. • (e) Processing of personal data is allowed if it is necessary for a scheme of compromise or arrangement or merger or amalgamation of two or more companies, or a reconstruction by way of demerger or otherwise of a company, or transfer of undertaking of one or more company to another company, or involving division of one or more companies, approved by a court, tribunal, or other authority competent to do so by any law in force. • (f) Processing of personal data is allowed for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law in force. • The central government may, by notification, exempt certain activities from the application of the entire Bill. These include: • processing by government entities in the interest of the security of the state and public order, and • research, archiving, or statistical purposes
  • 11. Data Protection Board of India • The central government will establish the Data Protection Board of India. Key functions of the Board include:  monitoring compliance and imposing penalties,  directing data fiduciaries to take necessary measures in the event of a data breach, and  hearing grievances made by affected persons. • Board members will be appointed for two years and will be eligible for re-appointment. • The central government will prescribe details such as the number of members of the Board and the selection process.
  • 12. Penalty • The schedule to the Bill specifies penalties for various offences such as up to: (i) Rs 200 crore for non-fulfilment of obligations for children, and (ii) Rs 250 crore for failure to take security measures to prevent data breaches. • Penalties will be imposed by the Data Protection Board after conducting an inquiry.