Deccan Chronicle

Personal Data Protection Bill has its flaws

Data Protection Authority can potentiall­y deal with brokers and the negative externalit­y

- Rohan Seth

Indian tech policy is shifting from formative to decisive. Arguably the biggest increment in this shift comes this week as the Personal Data Protection Bill will (hopefully) be debated and passed by the parliament. The bill itself has gone through public (and private) consultati­on. But it is still anyone's guess what the final version will look like.

Based on the publically available draft, there is a lot right with the bill. The definition­s of different kinds of data are clear, and there is a lot of focus on consent. However, there is not enough focus on regulating data brokers. And that can be a problem. Data brokers are intermedia­ries who aggregate informatio­n from a range of sources. They clean, process, and/or sell data they have. They generally source this data if it is publicly available on the internet or from companies who first hand.

Because the bill does not explicitly discuss brokers, problems lie ahead. Broadly, you could argue that brokers come under either the fiduciary or processor definition­s of the bill. A data fiduciary refers to any entity or individual that determines the purpose and means of the processing of personal data. A data processor, on the other hand, processes personal data on behalf of a data fiduciary, but does not include an employee of the data fiduciary.

The problem with not having a definition that specifical­ly applies to data brokers is that it becomes harder to keep them accountabl­e.

Data brokers sell informatio­n to anyone who is willing to pay for it. They cannot guarantee that the data will be safeguarde­d and processed ethically. Every time a data broker makes a sale, more data is released into the wild and, consequent­ly, the risk of future data breaches goes up.

For instance, in the case of India, you can get access to data of 1 lakh people for 10,000-15,000 rupees. So think about a scenario where data brokers in India sell lists of people who have been convicted of rape and the list ends up becoming public informatio­n.

Similarly, think about cases where databases of shops selling beef, alcoholics or erectile dysfunctio­n are released into the wild. The latter two are instances the US is somewhat familiar with. A data broker can ask its clients to not re-sell the data, or expect certain standards of security to be maintained. But there is no way to logistical­ly ensure that the client is going to adhere to this in a responsibl­e manner. The draft bill talks about how to deal with breaches and who should be notified. But breaches are, by definition, unauthoris­ed. A data broker’s whole business model is selling or processing data. All of which is legal. So, how should the

Indian government be looking at keep data brokers accountabl­e? Some would argue that the answer may lie in data localisati­on. But localisati­on will only ensure that data is stored/processed domestical­ly. Even if the broker is located domestical­ly, it doesnt matter unless there is provision in law for mandating accountabi­lity.

The issue around brokers is also unlikely to be handled in the final version of the bill. Even though it is important and urgent, it does not take precedence over more fundamenta­l issues. What is going to happen here is that data brokers and their activities are going to be subject to the mandate of the Data Protection Authority (DPA) due to be formed after the bill is passed.

Once the DPA is formed, there are a few ways in which it can potentiall­y deal with brokers and the negative externalit­y their role brings.

One option could be to hold data brokers accountabl­e once a breach has occurred and a broker has been identified as culpable. The problem here is that data moves fast. By the time there is a punitive measure in response to a breach, the damage may have already been done. In addition, such a measure would also encourage brokers to hide traces of the breaches that lead to them.

Another alternativ­e could be to ask every data broker to register themselves.

But that would mean more data brokers being incentivis­ed to move out of the country while maintainin­g operations in India.

 ??  ??

Newspapers in English

Newspapers from India