madhav.gupta@polytechnique.edu

← All posts

The Personal Data Protection Bill

What it means for the future of privacy.

September 9, 2021

Course project for ACDW101 Academic Writing (2021) at FLAME University, Pune, taught by Professor Michael Burns.

Abstract

After multiple attempts, India may finally have its first data privacy-focused law in the form of the Data Protection Bill, 2019. However, does this Bill really enforce privacy? If yes, then how does it do so? And to what extent does it do the same? These are some of the questions that will be tackled in this paper. With the landmark judgement of the Supreme Court in 2017, when privacy was declared a fundamental right, India started to wake up to the value of data, and why it causes other international parties to be attracted towards India. With a makeshift set of rules and a lack of government accountability, and with the spread of the Fake News Epidemic, the country realised that it was time for a more elaborate judicial defence of the people’s privacy.

Although Anirudh Burman demonstrated why a copy-paste of the European Union’s GDPR is harmful, the government still went ahead with a modified draft modelled on the former, which provides many provisions such as making the data collectors responsible for its processing as well, providing rights to consent, be forgotten, correct and delete a piece of data about you, verification methods to counter trolling and fake news, and digital localisation of storage of some data, while putting other legal restrictions on the other types. However, the Bill also gave the government autocratic power over people’s data. Justice Srikrishna, leader of the first draft, says that the Bill was modified to be completely against what it set out to be, creating a financial, economic, and humanitarian mess in the future.

Introduction

In today’s world, we all live in what is called ‘the Age of Information’. Even though we cannot see it or touch it, our modern life, with all its conveniences, is surrounded by data. It is the running blood inside the structure of a technological society. As we spend over half our time on the Internet or on electronic devices, we carelessly generate data like cookie crumbs. It can be what your name is, what movie you just watched, your SAT score, your medical records – anything and everything that can be recorded as information, is most probably recorded. However, this data is sought after by a lot of people, for a lot of reasons, and none of them are fully in our own interest. Thus, just as we require locks on our doors, we need someone – or something – to protect us and our data from being stolen by someone else for their own benefit.

Since most individuals do not have the required time, knowledge, power or patience to defend their own data, it is generally up to the law and judiciary systems to create legislation that does not let people just steal data and walk away. However, even for the law, it is not always as easy. For e.g., India still obeys the Information Technology (IT) Act, 2000 dictating the rules of today’s digital world – an act that was made seven years before the first ever iPhone was even unveiled, ruling a world dominated by smartphones and the Internet. The Government of India realised the danger of not updating their laws, and hence set out to create India’s first-ever law designed for privacy – the Data Protection Bill. Currently yet to be evaluated in the Parliament, the new law does raise one important question, one that is worth looking into.

How will the DPA protect and enforce our privacy in the future?

Now, there are multiple data protection acts and laws in existence. Almost every modern country tries to make its own, and have had multiple such laws throughout the past few decades. Why is India’s Data Protection Bill – especially one that is still a draft – so noteworthy? Well the fact is that this Act, one that is going to govern the world’s largest digital market open to international businesses, is willing to make a lot of noise and unforeseen demands. Sooner or later it will put multiple businesses into the dilemma of either remodelling themselves to obey the Bill, or risk losing their biggest user base, while gaining international attention and notoriety. The type of future we are heading towards, as a country if not as a world, will depend on the outcomes of this Bill.

In the upcoming few paragraphs, we will talk about how India viewed, protected and enforced privacy prior to this Bill, the gist of the Bill and the provisions it provides to enforce privacy in comparison to other famous similar laws such as the GDPR, the challenges and limitations the Bill may face according to two Indian Statistical Institute Kolkata researchers, and finally how Justice Srikrishna, a retired Supreme Court judge and the person who led the original committee in designing the very first draft of the Bill, feels like it is no longer the Bill he envisioned.

The Present Situation

Currently, India enjoys a newly gained fundamental right to privacy from the landmark judgement of 24th August 2017. In ‘Justice K.S. Puttaswamy (Retired) vs. Union of India And Ors., 2017’, a retired High Court judge challenged the constitutionality of the Aadhaar Act for violating the right to privacy, claiming it as a part of the right to life and personal liberty under Article 21 of the Indian Constitution: “No person shall be deprived of his life or personal liberty except according to procedure established by law”. The nine-judge bench of the Supreme Court of India stated that informational privacy, “the right of an individual to exercise control over his data and to be able to control his/her existence on the internet”, is a fundamental right to privacy protected by the constitution. The right was also declared to not be an absolute right, and any invasion of privacy by state or non-state actor is permissible as long as it has a legitimate aim, is reasonably proportional to the level of risk, and follows legal formalities and procedures.

In the same year, the world had begun to understand more and more the importance of the Big Data industry. A study by The Economist officially revealed data to have surpassed oil as the world’s most valuable resource (“The world’s most valuable resource is no longer oil, but data”). Authoritarian regimes like Russia and China are said to have understood, “the twenty-first century belongs to nations that control communications platforms, suppress independent media, and dominate the development of data-driven technologies such as artificial intelligence” (Rosenbach and Mansted). The primary understanding of private entities is that huge amounts of organised data is needed to train and model artificial intelligence, the stepping-stone to the future market.

The importance of data in India has been duly noted by the Indian Government. With 600 million unique users (more than the number of Indians with access to a toilet) in 2010, Nandan Nilekani, co-founder of Infosys and closely involved with the Aadhaar Act, “India will be data rich before it’ll be economically rich” (Narain). According to Karnika Seth, Section 69 of the IT Act, 2000, and the IT (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009, allow the Secretary in the Home Ministry to authorise agencies to:

“intercept, decrypt or monitor Internet traffic or electronic data whenever there is a threat to national security, national integrity, security of the state, and friendly relations with other countries, or in the interest of public order and decency, or to prevent incitement to commission of an offence” (Seth et al.)

The motive behind the push of such legislation originates from a rise in technological threats, such as the ‘Fake News Epidemic’ of WhatsApp in India, which creates a demand for accountability and traceability.

Furthermore, the judgement paved way for reformations in the Aadhaar Act. In September 2018, the Supreme Court declared Aadhaar as “constitutionally valid”, and only a few parts as unconstitutional and to be taken out (PTI). Lothar Determann and Chetan Gupta talk about the current situation of data protection in India, in a paper in the Berkeley Journal of International Law. According to them, the right to privacy is not yet established enough, and rather, relies on other laws to be enforced. However, the paper explains a few new additions such as the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, now requiring companies “to meet certain criteria when collecting ‘sensitive’ personal data”, provide a privacy policy, and appoint grievance officers (Determann and Gupta). Moreover, it is pointed out in the paper that the Aadhaar Act forbids “the sharing of biometric information and requires other identity information to be shared and used only for specified purposes”, and that in 2018 the Reserve Bank of India required payment system operators to store data locally, although “it does not seem intended or suited to protect individual privacy; rather, it serves to secure access to data for the Indian government” (Determann and Gupta).

With reliance on an outdated act, a set of ill-defined modifications and other more concrete laws, it was only a matter of time for digital privacy to warrant a new Act.

The Personal Data Protection Bill, 2019

To combat the attack on privacy and the negative economic effects of a distrusting lack of the same, the European Union put into effect in 2018 the General Data Protection Regulation (GDPR). The GDPR served as the main basis for the draft of India’s very own Data Protection Bill (Saigal). However, Anirudh Burman, a senior research analyst at Carnegie India – a well-known and recognised research institution – pointed out a few reasons why a reckless duplication of the GDPR in India could be disastrous.

Using the EU’s Impact Assessment (IA) report of the GDPR, he points out that a careful, contextually relevant cost-benefits analysis would be required before drafting such a Bill, that the IA suggests that the key economic benefit of the GDPR is by fixing a broken privacy protection system, while India had next to no such system needing to be fixed and hence no such benefit, and that they need to understand the impact on “employment, job growth, and small businesses” (Burman). For e.g. compliance costs and restrictions on new technologies like artificial intelligence may drive small businesses out of business and reduce jobs, undoing years of economic progress.

Graham Greenleaf in his paper calls the Bill “GDPR-lite with Chinese characteristics”, and a “‘Fourth Way to privacy, autonomy and empowerment’, distinct from the approaches of the US, EU and China, a new model which is relevant to ‘all countries in the global South’” (Greenleaf). The fact that India is not one of the first countries with a data protection law demonstrates exactly this ability to learn from others’ failures. He further explains that while the draft is “clearly modelled” on the GDPR, it has “Chinese-influenced” data localisation provisions (Greenleaf). This arises from India’s socialist nature, as data generated by its citizens is treated as a national asset, and hence ordered to be stored domestically under the new Bill. Such provisions are unlikely to be used by capitalist countries like the US and even the EU, as they believe data to only be the individual’s property.

Multiple provisions under the aim of protection of the individual’s privacy have been made in the Bill, which is yet to be discussed in the Parliament. Section 110 of the Act gives it overriding authority over the previously used IT Act, 2000 (Determann and Gupta). The Bill, dividing data into three categories – critical data (defined by the government from time-to-time), sensitive data (consisting of “passwords, financial data, health data, official identifier, sex life, sexual orientation, biometric and genetic data, and data that reveals transgender status, intersex status, caste, tribe, religious or political beliefs or affiliations of an individual”), and general data (everything else) – makes it mandatory for all critical data to be stored domestically, and sensitive data transferred abroad only for processing and after “explicit consent” of the data owner, called the “data principal” (“Justice Srikrishna committee submits report on data protection”). However, critics point out that storing data locally is not the most efficient method for virtually any objective, even easy access to data (Singh and Ruj).

The penalties for the Internet companies now held accountable for collection as well as handling of the data (referred to as “data fiduciaries” in the Bill), and responsible executives, that fail to comply with the act are strict and high. According to the Harvard Business Review:

“In case of a data breach or inaction by the fiduciary upon data breach or a minor violation, the penalties could reach $ 700,000 or 2% of a company’s global revenues, whichever is higher. For major violations, such as data shared without consent, the penalties would double” (Govindarajan et al.)

The high penalties, combined with the leverage of the world’s largest digital market of estimated 829 million Internet users (59% of the population) in 2021, goes to show the confidence of the Indian Government in the success of this act and the threat it poses for almost every global tech company (VNI Complete Forecast).

The Bill, moreover, provides the data owners/principals the right to be forgotten as well as the right to erase or correct individual aspects of their data. The Bill also makes it mandatory for fiduciaries to carry out a voluntary identity verification, and tag all of its users as one of three groups – verified with real names displayed, verified with anonymous names, and unverified users – so as to counter trolling and spread of fake news on the Internet (Govindarajan et al.). While many social media companies have features such as the ‘verified’ tick mark of Facebook reserved for celebrities, creating such an identification and tagging system for an enormous number of users (many of whom are fake profiles), is certainly a new and ground-shaking move – and a difficult commitment that social media companies will have to make if they want to retain India and its users.

However, the Act also sponsors multiple provisions that give perhaps too much power and access to the state itself. The Bill outright exempts government agencies from following the same rules of data collection and processing as private companies, “in the interest of sovereignty and integrity of India, the security of the state, friendly relations with foreign states, and public order” (Singh). Under the Data Protection Bill, a Data Protection Authority of India (DPAI) will also be set up by the government as an independent body and granted rights and authority related to the Bill and its effective implementation, regulation, and enforcement (“Justice Srikrishna committee submits report on data protection”). Among others, the DPAI has the right to access the locally stored data of its citizens to “protect national interests”, and can even demand “non-personal” or “anonymized” data i.e. data that cannot be used to identify individuals, from the fiduciaries (Govindarajan et al.). This data can be used on behalf of the government for its own research and planning purposes, all without the consent of the citizens.

Limitations of the Personal Data Protection Bill

Ram Govind Singh and Sushmita Ruj, in their paper ‘A Technical Look At The Indian Personal Data Protection Bill’, reveal the main challenges and limitations that the Bill would face in its current draft form. Although the paper claims the Bill to be an ambitious first major step, it further explains that the uncertainty of its success arises out of the “inherent limitations” of the Bill, and “the constraints of practical implementation”, with most if not all of these shortcomings leading to “excessive power to the government” (Singh and Ruj). With the ability to collect any personal or non-personal data and the relief of the privacy concerns as soon as the government gets their hand on the data, the Bill essentially gives it seemingly ultimate and endless power. The DPAI also reserves the right to define various terminology used in the Bill, and by extension, manipulate the Bill itself (Singh and Ruj). For e.g., the definitions of data principal and fiduciary, critical, sensitive and general data, high-risk, and consent are all loosely defined terms left for the DPAI to define fully, or even alter completely, allowing them to implement definitions that suit their own purposes.

Justice B.N. Srikrishna, a retired Supreme Court judge who led the committee that created the first draft of the Data Protection Bill, spoke out in an interview about how the current draft is in complete contrast with the original design. He says the Bill was made with data protection, privacy, and digital empowerment of the people as the main objectives in mind, with inspiration from laws from other countries including the GDPR (Saigal). Calling the Bill to be heading towards an “Orwellian” future (based on the novel 1984 by George Orwell, taking place in a world of complete surveillance), he says that all the safeguards he had mentioned with the Bill are no longer present in it, and that it directly provides the government with all the “autonomy” it can have (Saigal). The need in the current version of the Bill is of more accountability and transparency, so that no party – government or not – can abuse its powers. As it is, getting any data the government representatives desire is as simple as them saying, “I want it for national interests”, and voila.

Srikrishna also speaks about the DPAI, and his discontentment, or disappointment, in them. While he believed any data processing done without consent or a legal warrant “should comply with the three principles — an objective has to be achieved, proportionality and reasonability”, the reason for setting up the Data Protective Agency was because of his distrust in the Parliament, where there is no genuine and legitimate criticising and debating anymore, but only yes-men, who, “don’t realise they are playing with the Fundamental Rights of the citizens” (Saigal). However, he demanded the DPAI to consist of “people who are independent, people who are representatives of stakeholders and may be some government nominee”, but in reality it consists of government officials only, making it indifferent from the government itself, and only furthering their control (Saigal). He strongly believes, “If this [Bill] is passed in its current form, it should be challenged in the Supreme Court” (Saigal). From what the common man can see, Srikrishna’s vision of the Bill seems to be the perfect representation that is celebrated by the people, however all the changes done to it is the exact reason why it shouldn’t be celebrated.

Looking Forward

If the Personal Data Protection Bill does get passed in its current form one can expect not just India but all of Internet to face at least some sort of ripple effect. Data Fiduciaries, now suddenly responsible for collecting as well as processing its users’ data and that too in compliance with the law, will have to rethink their entire business models or wish goodbye to possibly their biggest market – forecasted to be valued at one trillion dollars by 2022 (Govindarajan et al.). As a result, a dramatic shift in the online market sphere will occur, as old businesses fall, new businesses rise, and some businesses completely remodel themselves to survive. Many ‘free’ products may need to look for other sources of income as they no longer get to collect data. There is a huge possibility of start-ups to have to face endless compliance costs, creating unemployment and a barrier to entry in the market. With new introductions of concepts like consent, data and verification, ‘privacy’ will soon become a hot-topic for the average Indian layman.

The Indian Government, depending on the success of the Bill or modifications made to it, will soon enter the territories of informational warfare, using its citizens’ data as a strategic and militaristic asset against others. According to Brookings:

“It is pertinent for India, given the size of its population and economy, to have a strongly enforced data protection law. If it is too lenient and vague, individual rights in a democracy suffer; if it is too restrictive, the ease of doing business and promise of growth suffers” (Somvanshi and Desouza)

According to Udbhav Tiwari, a public policy advisor at Mozilla, the Bill “represent new, significant threats to Indians’ privacy. If Indians are to be truly protected, it is urgent that the Parliament reviews and addresses these dangerous provisions before they become law” (Singh). According to the Belfer Center, data localisation such as that done by India may create “cyber borders”, which could “unwind decades of economic liberalism, fragment the relative openness of current information flows, and give rise to suspicion and animosity” (Rosenbach and Mansted).

As of now, a final Data Protection Bill is expected to be tabled in Parliament in the Budget session, and according to BJP MP Rajeev Chandrasekhar, “the Joint Parliamentary Committee (JPC) examining the Personal Data Protection Bill, 2019 will not approve the current version of the bill”, implying some reforms underway (PTI; Mihindukulasuriya). “What other economic ramifications will the Bill have?” “Will it fulfil the privacy criteria it set out to do” “Will global companies change themselves or leave India” “Will other countries follow our lead of a law specifically designed for privacy?” “What will ‘cyber-borders’ mean for the future of our international relations?” “How will companies adapt and survive through this?” Unfortunately, these are some of the many questions that only time can fully answer.

However the Bill performs, the direction of all our futures are the direction of this Bill itself. It could perhaps be a flawed but bold first step towards better privacy, or it could also be the first movement towards an autocratic ‘surveillance’ or ‘police’ state.

References

  1. Burman, Anirudh. Will a GDPR-Style Data Protection Law Work for India?. Carnegie India, 2019.
  2. Determann, Lothar, and Chetan Gupta. “India’s Personal Data Protection Act, 2018: Comparison with the General Data Protection Regulation and the California Consumer Privacy Act of 2018”. Berkeley Journal of International Law, vol. 37, no. 3, 2019, pp. 483–515.
  3. Govindarajan, Vijay, and others. “How India Plans to Protect Consumer Data”. Harvard Business Review, 18 December 2019, https://hbr.org/2019/12/how-india-plans-to-protect-consumer-data. Accessed 10 December 2020.
  4. Greenleaf, Graham. GDPR-lite and requiring strengthening – submission on the draft Personal Data Protection Bill to the Ministry of Electronics and Information Technology (India). University of New South Wales Law Research Series, 2018.
  5. “Justice Srikrishna committee submits report on data protection. Here’re its top 10 suggestions”. The Economic Times, 28 July 2018, https://economictimes.indiatimes.com/news/politics-and-nation/justice-bn-srikrishna-committee-submits-report-on-data-protection-herere-the-highlights/articleshow/65164663.cms?from=mdr. Accessed 10 December 2020.
  6. Mihindukulasuriya, Regina. “Data Protection Bill won’t get cleared in its current version — BJP MP Rajeev Chandrasekhar”. The Print, 16 December 2020, https://theprint.in/india/data-protection-bill-wont-get-cleared-in-its-current-version-bjp-mp-rajeev-chandrasekhar/568003/. Accessed 10 December 2020.
  7. Narain, Siddharth. Mapping Digital Media: INDIA. Open Society Foundations, 2013.
  8. PTI. “Personal Data Protection Bill likely to be tabled in Parliament in Budget session”. The Hindu, 4 October 2020, https://www.thehindu.com/business/Industry/personal-data-protection-bill-likely-to-be-tabled-in-parliament-in-budget-session/article32765880.ece. Accessed 10 December 2020.
  9. Rosenbach, Eric, and Katherine Mansted. “How to Win the Battle Over Data”. Belfer Center for Science and International Affairs, Harvard Kennedy School, 17 September 2019, https://www.belfercenter.org/publication/how-win-battle-over-data. Accessed 10 December 2020.
  10. Saigal, Sonam. “Data Protection Bill not in line with draft: Justice Srikrishna”. The Hindu, 14 December 2019, https://www.thehindu.com/news/national/data-protection-bill-not-in-line-with-draft/article30307560.ece. Accessed 10 December 2020.
  11. Seth, Karnika, and others. “Are India’s laws on surveillance a threat to privacy?”. The Hindu, 28 December 2018, https://www.thehindu.com/opinion/op-ed/are-indias-laws-on-surveillance-a-threat-to-privacy/article25844250.ece. Accessed 10 December 2020.
  12. Singh, Manish. “India proposes new rules to access its citizens’ data”. TechCrunch.com, 10 December 2019, https://techcrunch.com/2019/12/10/india-personal-data-protection-bill-2019/. Accessed 10 December 2020.
  13. Singh, Ram Govind, and Sushmita Ruj. A Technical Look At The Indian Personal Data Protection Bill. Indian Statistical Institute Kolkata, India, 2020.
  14. Somvanshi, Kiran Kabtta, and Kevin C. Desouza. “India’s data dilemma: How to protect all of it”. Brookings, 23 August 2018, https://www.brookings.edu/blog/techtank/2018/08/23/indias-data-dilemma-how-to-protect-all-of-it/. Accessed 10 December 2020.
  15. “The world’s most valuable resource is no longer oil, but data”. The Economist, 6 May 2017, https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data. Accessed 10 December 2020.
  16. Visual Networking Index Complete Forecast. India – 2021 Forecast Highlights. Cisco, 2016.