PDPB (Digital Personal Data Protection Bill)
Rohit Chowdary
Data Analytics | Gen AI | AI | ML | LLM | Data Engineering | International Business |
What is PDPB ? What will the data protection bill do?
The Bill establishes requirements for businesses handling and processing data and individual rights. Its purpose is to prohibit cross-border data transfers, penalize firms for data breaches, and provide a framework for the establishment of a data protection body to ensure compliance.
The PDPB states that it applies to “the processing of digital personal data within India where such data is collected online, or collected offline and is digitized” as well as “such processing outside India if it is for offering goods or services or profiling individuals in India.”?
Noncompliance and failure can result in penalties for businesses and institutions. The companies or organizations will also be compelled to discontinue retaining user data if it no longer serves the intended business purpose.
Similar to the EU's General Data Protection Regulation (GDPR), the bill is designed to protect the individuals within its purview, even when their data is processed by companies or other data fiduciaries outside of India.?
What is Personal Data ?
Personal data is defined under the PDPB as “any data about an individual who is identifiable by or in relation to such data.”
Any information that can be used to identify a specific individual. This can include but is not limited to, names, addresses, phone numbers, email addresses, and demographic information.
"There is no mention of Sensitive Personal information explicitly in the bill"
Some Key Terminology
Data Fiduciary - who collects data on behalf of others
Data Principal - the individual whose data is being collected)
Data Processor - an organization that processes data on behalf of a data fiduciary
Data Protection Officer - individual & ensuring compliance with data protection laws
领英推荐
Data Principles: Rights for Citizens
The bill outlines certain obligations for Data Principals, including refraining from providing false information and filing false complaints.
Responsibilities of Data holding companies
Penalties for Non-compliance
Violations of the requirements for data principals may result in fines of up to 10,000 rupees.
Noncompliance for violations by data fiduciaries and significant data fiduciaries may result in fines of up to 250 crore rupees and a minimum of Rs 50 crore. The amount of the penalty imposed depends on the violation, its impact or potential impact, the type of personal data affected, and other factors.?
India's Personal Data Protection Bill is about to become the latest international law that helps protect the individual's privacy rights. The enactment of this bill will make India a safe country in which to handle and process personal information. The bill's current version reflects how much effort and debate went into it, and its passing would mean India has a comprehensive data privacy law in place to protect the more than 760 million active internet users in the country.
P.S : Sharing my understanding of this topic. Feel free to overlook any errors or omissions. Open to enriching discussions!
Marketing Manager at ICode Breakers
1 年The India DPDP Bill 2023 holds immense potential for transforming the data protection landscape for businesses. Explore the following blog to delve into essential factors, spotlighting the changing hurdles and prospects that lie ahead for enterprises. Read more at https://bit.ly/47yQxXr
Head of IT Infra and Security | Digital Transformation | Cyber security
1 年A crucial step towards data privacy! Looking forward to seeing how this bill shapes the landscape of digital personal data protection in India. Rohit Chowdary