Rediff.com« Back to articlePrint this article

Parliament nod for data protection bill, to come into force in 10 months

Last updated on: August 09, 2023 23:20 IST

Parliament on Wednesday approved the Digital Personal Data Protection Bill that introduces several compliance requirements for the collection and processing of personal data and provisions for up to Rs 250 crore penalty for any data breach.

IMAGE: Kindly note that this image has been posted for representational purposes only. Photograph: Kind courtesy Gerd Altmann/Pixabay.com

The government expects to implement Digital Personal Data Protection Act 2023 within 10 months.

The Lok Sabha approved the Bill on August 7, and with the Rajya Sabha giving its consent on Wednesday, the parliamentary approval process is complete.

The Bill will now go to the President for assent, after which it will become law.

 

Moving the bill for consideration and passage in the Upper House of Parliament, Vaishnaw said, "It would have been good had the opposition discussed the bill today (in the house). But no opposition leader or member is concerned over the rights of the citizens."     

He said the bill has been brought after extensive public consultation.

Underscoring its salient features, the information and technology minister said data collected by any entity will have to be used as per "principle of legality", "principle of purpose limitation'', "principle of data minimisation", "principle of data accuracy", "principle of storage limitation", "principle of reasonable safeguards, and "principle of accountability''.

Elaborating on the principles, he said the data collected by the citizens should be used as per law, only for the purpose for which it has been collected, and the quantum of data should be limited to the requirement.

Vaishnaw said citizens will have the right to correct their data and it should be stored with entities till the time it is required and protected by putting in place reasonable safeguards. 

Referring to certain principles on which the bill is based, he said according to the principle of legality, data of a person has to be taken based on prevailing laws and cannot be used for purposes beyond which it has been collected.

He said citizens have been given four rights under the Act comprising right to access information, right to correction of personal data and eraser, right to grievances redressal, and right to nominate.

The minister said an independent data protection board (DPB) will be created which is "digital by design" and will provide similar access to justice to people across the country in the same way as privileged people in cities like Delhi and Mumbai.

"The board will comprise experts who understand the field of data and the board is independent by law. Above this board, appeal can be made before telecom tribunal TDSAT and further before the Supreme Court," Vaishnaw said.         

Addressing concerns around changes in the Right to Information Act, he said the Puttaswamy judgment has made right to privacy a fundamental right, therefore any personal data can be published only through a legally approved process and in no other form, personal information can be shared in any public forum.

"The contradiction in the Right to Information Act has been done away through this bill," the Union minister said.   

He said Europe's data protection bill has provided for 16 exemptions, while the Digital Personal Data Protection (DPDP) Bill 2023 has provided only four exemptions.

Motion to send the bill to the select committee of Parliament by Rajya Sabha member John Brittas and V Sivadasan was not moved due to their absence in the house when the bill was put for vote. 

During the discussion, YSR Congress Party member V Vijayasai Reddy raised the issue of telephone tapping through software.

"Telephone tapping can be done either by taking control of the speaker that we have in the telephone or even the camera on the reverse side of the telephone. In fact, I have physically seen the demonstration that has been given by a foreign company that any app -- whether it is WhatsApp, Facetime, Telegram or Signal, anything can be tapped," Reddy said.

Without naming the firm, he claimed foreign companies selling such solutions sell these to only government institutions.

"The government departments are using the software for their own personal purposes with ulterior motives. Almost 15-20 software are there and each costs in the range of Rs 50 to Rs 100 crore. Those who could afford to spend Rs 50 to Rs 100 crore and an annual maintenance contract of say 20 per cent, can tap anybody's telephone," Reddy said.

He requested the government to come with a solution to protect personal data from private entities buying such a software.  

BJD member Amar Patnaik said the bill is the most landmark legislation of the country after independence and this is the law of the largest democracy of the world. He, however, said he could not find the word "privacy" in the bill which was there in the Supreme Court judgment.

He said the words "compensation" and "harm" are also missing.

Patnaik said the norms under the bill interpret data breach in financial terms.

"What happens if there is reputational damage because of a data breach? What happens if there is a bodily injury? You may say that you can use criminal procedure and IPC to try that person, but it has to be read with this particular Act to make the provisions more stringent," he said.

He also pleaded that state-level data protection board should be set up under the redressal mechanism.    

YSRCP's S Niranjan Reddy raised concerns on sweeping powers given to the Centre as well as exemption given to start-ups.

Vaishnaw said the exemption to start-ups will be given only after their solution pass the test in regulatory sandbox environment.

TDP member Kanakamedala Ravindra Kumar, Tamil Maanila Congress-M member G K Vasan, and AIADMK's M Thambidurai also participated in the discussion.

© Copyright 2024 PTI. All rights reserved. Republication or redistribution of PTI content, including by framing or similar means, is expressly prohibited without the prior written consent.