Privacy & Data Protection
Privacy & Data Protection
‘Privacy’, a noun:
“A state in which one is not
observed or disturbed by other
people”
or
“The state of being free from
public attention”
Privacy & DataProtection
‘Privacy’ of a natural living
person is the state of not
Privacy being observed or
disturbed without their
explicit consent to do so.
Data/
Information
Legal
Security
Compliance
Privacy is control over information or
activities relating to oneself; Privacy can be
considered as a “derivative” right i.e. privacy
right is derived from other related rights;
In India majority understand Privacy only in
context of Sex and Wealth. Sometimes with
password too
The Supreme Court in the case of R. Rajagopal v. State of Tamil Nadu , for the
first time directly linked the right to privacy to Article 21 of the Constitution
and laid down:
Personal data
o US Privacy Laws
Information that can be used on its own or with other information to
identify, contact, or locate a person, or to identify an individual in
context
PERSONAL DATA AND SENSITIVE PERSONAL DATA
any proceedings for any offence committed or alleged to have been committed by him, the disposal of
such proceedings or the sentence of any court in such proceedings.
KEY ISSUES
they had
knowledge
of the
Top contraventio
Company managemen n or they
itself, being t including If it is have not
Sec. 85 directors used due
a legal proved that
person and diligence or
Managers that it was
caused due
to their
negligence
ISSUES
SPDI
Biometrics
Health
Sexual records
orientation
Rule 3 - IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011
REASONABLE SECURITY PRACTICES
Rule 8 - IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011
AUDITING
Need to specify –
Fact that SPDI is being collected
What type of SPDI is collected?
How long SPDI will be held?
Rule 5 - IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011
COLLECTION OF INFORMATION
Provider should know –
Purpose of collection
Intended recipients
Details of the agency collecting the information and agency retaining
the information
Rule 4 - IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011
DISCLOSURE OF INFORMATION
Disclosure –
Prior permission of provider necessary before disclosure to third party
OR
Rule 6 - IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011
TRANSFER OF INFORMATION
Rule 7 - IT (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011
SEC 72(A) (CRIMINAL OFFENCE)
Punishment for Disclosure of information in breach of
lawful contract -