Hindustan Times (Bathinda)

‘Data protection bill will make businesses difficult to operate’

-

› Aadhaar will be subordinat­e to the data protection framework under this law. The Aadhaar Act may have certain provisions that talk about how you need to protect informatio­n under it. But Aadhaar will be used outside this construct as well

NEW DELHI: Rahul Matthan, a partner-lawyer in the technology and media practice at the law firm Trilegal and author of Privacy 3.0, spoke to

Nakul Sridhar about his understand­ing of the draft Personal Data Protection Bill, what works and what doesn’t, and the way ahead. The proposed law drafted by a committee headed by former Supreme Court judge BN Srikrishna was submitted to the government on Friday. Edited excerpts:

After having taken a closer look, what are your thoughts on the draft Bill and the committee’s report?

When you read the Bill and the report together, you realise there is a lot in the report that fleshes out some of the concepts in the Bill. There is a significan­t discussion around the concept of significan­t data fiduciary. This is a category of data fiduciarie­s which, on the basis of large volume of personal data processed or turnover, is subject to a higher standard of privacy.

For these fiduciarie­s, there are additional obligation­s that would apply, such as doing a Data Protection Impact Assessment. They are quite significan­t obligation­s. It would apply to a certain class of fiduciarie­s, such as hospitals, which possess a lot of medical data.

Could the law have been retrospect­ive?

I don’t think so. It is terribly complicate­d as it is. The law says that anything going forward from the day the law takes effect needs to comply with the law. Even that is really complicate­d, because it’s not like everyone is going to stop processing data, wait for the law to come into effect, and start again.

The draft Bill says it aims at combining user data with common good for citizens. Do you think this draft Bill has achieved that?

That’s a really difficult question. One of my concerns with the Bill is I think it’s going to become very difficult for businesses, the data fiduciarie­s, to operate. Companies are not used to this level of collecting or processing personal data. That would be a huge shock to the system. The Bill talks more about direct data collection, such as data collected from a person to open a bank account. It doesn’t say much about the data collected, say for example, by Netflix to target better movies at you. When it comes to this, it is going to be much more challengin­g for both businesses as well as users.

What will this mean for Aadhaar? Has the committee underestim­ated the concerns on Aadhaar or is it right?

Aadhaar will be subordinat­e to the data protection framework under this law. The Aadhaar Act may have certain provisions that talk about how you need to protect informatio­n under it. But Aadhaar will be used outside this construct as well. Now those uses will need to come under the larger data protection law. There is a recommenda­tion that says the Aadhaar authentica­tion services must be used only by the government. It is not the place of the committee to look into that as it is a matter currently before the Supreme Court. So it’s unfortunat­e that recommenda­tions on sub-judice matters have been made.

Is the draft tilted towards government regulation?

In only one case. The whole penalty regime is meaningles­s to the government because they don’t have a turnover. Paying a penalty is not an issue for them. This is a serious gap in the way the framework is structured. There is a section for offences which applies to both people as well as the government. But the government has several exceptions. So how are we going to hold them accountabl­e?

How will data localizati­on impact businesses?

I think this is a very serious concern. There are many views on it and it’s a polarizing topic. I don’t think we should have data localizati­on. I think it’s not good for business. The recommenda­tion to have a mirror server in India is also a bit of a problem. Start-ups can easily open an Amazon cloud server and just start without any expenditur­e. Once you start this data mirroring, it’s going to be very difficult. I have a feeling this is going to have a chilling effect on innovation.

What does this mean for Facebook and Whatsapp as well as their users?

Both Facebook and Whatsapp comply with Europe’s General Data Protection Regulation­s (GDPR), so they will already have similar kinds of provisions in place. So they can modify their privacy slightly, at least for the plain vanilla clauses, to comply with the Indian law. But it does affect them in the case of data localizati­on. They may have to look at how their costs are going to be affected.

Users get the ‘Right to Data Portabilit­y.’ It’s there in GDPR as well. You can ask Facebook to give you a copy of all the data on you, it’ll be given to you. Can you port data such that your likes and profiles on Facebook can be shared with, say, Google? That is special media graph portabilit­y, which is something that all the social media giants have been resisting. I don’t know if that is the extent to which data portabilit­y will go.

What are some of the recommenda­tions you would keep, and three you would modify or discard from this draft?

A lot of the general obligation­s are all fine. I like the data portabilit­y framework. It is very powerful for users to move data from say one person to another. And you can do it through a consent dashboard. In my mind, I think they have gone overboard with notices, obligation­s to maintain a record of consent.

I am very keen to remove data localizati­on provisions. As much as we say we must do Artificial Intelligen­ce and big data, this Bill can even harm them due to the purpose and use limitation. Big data works on a lot of data. Only de-identified data that can’t be traced to an individual should have been allowed for data fiduciarie­s to use for big data. This would have been a forwardthi­nking way.

 ??  ??

Newspapers in English

Newspapers from India