SWS Technologies

Aug 23, 2018

Overview of Personal Data Protection Bill, India

Highlights of the 2018 draft bill, user rights, and provider obligations.

Data Protection Regulations

Author: khelender

The Justice B. N. Srikrishna committee submitted a draft Personal Data Protection bill to Parliament on 27-July-2018.

This overview highlights the bill from the perspective of users (data principals) and organizations (data fiduciaries).

Entities involved

  • Data Principal (user)
  • Data Fiduciary (service provider/organization)
  • Data Protection Authority
  • Adjudicating Officer

User rights

  1. Ask whether data is captured and what it contains
  2. Correct or dispute data
  3. Request deletion in select cases
  4. Request portable data
  5. File complaints with the DPA

Provider obligations

  • Provide clear notice and consent mechanisms
  • Ensure data quality and retention controls
  • Maintain accountability across the data lifecycle
  • Run audits and privacy impact assessments
  • Appoint a DPO where required

Breach, offences, and penalties

The act includes strict penalties for non-compliance and breaches, including financial penalties and legal consequences.