Understanding data privacy under IT Act
Comprehensive guide to data privacy rights under the Information Technology Act 2000 in India. Learn about privacy provisions, data protection requirements, and
Table of Contents
Legal Framework for Data Privacy in India
Data privacy in India is primarily governed by Section 43A and Section 72A of the Information Technology Act, 2000, along with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These provisions create obligations for entities handling personal data.
Section 43A deals with compensation for failure to protect data. It requires body corporates handling sensitive personal data to implement reasonable security practices. Failure to do so resulting in wrongful loss or gain makes them liable for damages.
Section 72A provides for punishment for disclosure of information in breach of lawful contract. It addresses situations where a person having access to personal information under a contract discloses it without consent, causing wrongful loss. The punishment includes imprisonment up to 3 years and/or fine up to Rs. 5 lakhs.
Sensitive Personal Data Rules 2011
The IT Rules 2011 define 'sensitive personal data or information' (SPDI) to include passwords, financial information, health information, sexual orientation, biometric information, and certain categories of personal data. Body corporates handling SPDI must comply with specific requirements.
Key requirements include obtaining written consent before collecting SPDI, providing a privacy policy, allowing individuals to review and correct their information, maintaining security practices, and not disclosing SPDI without prior permission except as required by law.
Entities must designate a grievance officer and publish their contact information. They must implement reasonable security practices as prescribed by ISO 27001 standards or equivalent. Non-compliance can result in both civil and criminal liability.
Rights of Individuals Under Data Privacy Framework
Individuals have the right to know what personal information is being collected and the purpose of collection. They have the right to review their information and request corrections. They can withdraw consent for the use of their data at any time.
Individuals have the right to expect that their data will be kept secure and confidential. They have the right to seek compensation for damages caused by data breaches or unauthorized disclosure. They can file complaints with the cyber cell or approach civil courts.
The Digital Personal Data Protection Act 2023 has been passed to establish a comprehensive data protection regime in India, though its implementation is being phased in. This new law will strengthen individual rights and create a Data Protection Board.
Remedies for Data Privacy Violations
Victims of data privacy violations can file a complaint with the cyber cell under Section 66E of the IT Act for violation of privacy. They can also file a civil suit for damages under Section 43A for failure to protect data by a body corporate.
Individuals can claim compensation for financial losses, mental anguish, and reputational damage caused by data breaches. Companies found negligent in protecting data can be ordered to pay substantial damages.
Under the new Digital Personal Data Protection Act, individuals will have enhanced rights including the right to access, correction, erasure, and grievance redressal. The Act establishes a Data Protection Board for adjudication. Vidhi Legal Services advises clients on data privacy compliance and litigation.
Frequently Asked Questions
Need Legal Help? Contact Vidhi Legal Services Today
Get expert legal advice from our experienced advocates. We offer free initial consultation and transparent pricing for all our services.