Hindustan Times (Jammu)

Handle personal data with care

The new rule on internatio­nal passengers must be rolled out carefully and further checks built in

-

The government on Monday notified the Passenger Name Record (PNR) Informatio­n Regulation­s, 2022, making it mandatory for any operating flight to share details of internatio­nal travellers with a customs agency. Among these are details of a person’s ticket — when it was booked, date of travel and billing informatio­n — and data about their travel, such as origin, destinatio­n, and how many bags they are carrying. Also included will be their seat numbers and copassenge­r data. The government, in the notificati­on, said the objective is to create an advance risk assessment to combat crimes under the excise law and for sharing of intelligen­ce with other law enforcemen­t agencies. As safeguards, the notificati­on says such data will be subject to privacy laws in force, avoid certain types of informatio­n (like race and religion) and be processed only within a secure system.

India isn’t the first country to set up such as system. In 2016, the European Union (EU) adopted the PNR Directive for all its member countries. Even before the directive, the EU and the United States (US) signed a pact in 2011 to share PNR records. A veritable data dragnet, such systems became expedient in the aftermath of the September 11 attacks in 2001 and the terror strikes that followed in parts of Europe later that decade. The US operates an even more sophistica­ted system called the Automated Targeting System. While little is known about the American system, the data sought by India suggests Delhi’s requiremen­ts may lie somewhere in between the European and the American models in terms of scope.

Experts in India rightly point out that the purpose and safeguards of the country’s new model need to be better explicated, at least for two factors. First, the nature of the data sought qualifies as personal informatio­n and at times even as sensitive personal informatio­n. The EU rules require data protection officers to oversee the functionin­g of PNR-sharing systems and have a provision for an independen­t supervisor­y mechanism to mitigate the scope of abuse and harm that such databases can lead to. Second, five years ago, this month, the Supreme Court laid down a broad principle that personal data can be accessed by the State only in manners that are “just, fair and reasonable”. With no statute still in place to codify this, the new rules may need to be implemente­d carefully, and further checks built in.

Newspapers in English

Newspapers from India