What is the Personal Data Protection Bill of 2019?
On December 11, 2019, India’s Minister of Electronics and Information Technology, Mr Ravi Shankar Prasad, introduced the Personal Data Protection Bill in the Lok Sabha, aiming to protect the personal and sensitive data of Indian citizens. The bill seeks to govern the processing of personal data by the Indian government, Indian companies, any citizen of India, and foreign companies that handle the personal data of Indian citizens.
Terminology of the PDPB

Personal Data
Personal data is any information related to a natural person that enables their identity. The bill defines it as:
“personal data” means data about or relating to a natural person who is directly or indirectly identifiable, having regard to any characteristic, trait, attribute or any other feature of the identity of such natural person, whether online or offline, or any combination of such features with any other information, and shall include any inference drawn from such data for the purpose of profiling
Examples of personal information include full name, home address, email address, date of birth, and place of birth.
Sensitive Data
Sensitive data is personal data protected against unauthorised access: examples include financial information, health information, caste, biometric data, religious beliefs, and genetic data.
Data Fiduciary
The bill defines a data fiduciary as:
any person, including the State, a company, any juristic entity or any individual who alone or in conjunction with others determines the purpose and means of processing of personal data.
Data Principal
The data principal is the natural person the data relates to.

Who Does the Bill Apply To?
The PDPB applies to entities processing personal data of individuals in India, including the Indian government, companies incorporated in India, and foreign companies that deal with the personal data of individuals in India.

Exemptions for Small Business
There are a few exceptions for small entities, where all of the following apply:
- Turnover under twenty lakh rupees (roughly USD $28,000)
- The entity doesn’t share personal information with any other business
- The entity didn’t process the personal data of more than 100 data principals on a single day in the past 12 months

The Main Features of India’s Personal Data Protection Bill
- Protection of the individual’s privacy in relation to personal data
- Obligations of the data fiduciary
- Rights of the individual
- Grounds for data processing
- A data protection authority
- Transfer of personal data outside of India
- Exemptions
- Offences
- Transparency and accountability

Protecting the Individual’s Privacy
Privacy is a fundamental human right: the right to “freedom from unauthorised intrusion.” In relation to personal information, it means individuals should have some say over how their data is handled. With so much personal information now collected online, many countries have introduced data regulations to protect residents’ data and privacy, the GDPR, CCPA, and Australia’s Privacy Act 1988 among them. India’s Personal Data Protection Bill is an important addition to this landscape, with consequences for any company doing business in or with India.

Obligations of the Data Fiduciary
The data fiduciary decides the means and purpose of processing personal data. Processing is subject to conditions including: it must be for a specific, clear, and lawful purpose; done fairly and reasonably, protecting the data principal’s privacy; limited to what’s necessary for that purpose; and the data principal must be given notice at the time of collection, covering the company’s identity and contact details, the purpose of processing, what data is collected, the right to withdraw consent, the basis for processing, how long data is retained, how rights can be exercised, and the complaints process. The data fiduciary must also keep the data accurate and up to date, not retain it longer than necessary, and be able to demonstrate consent was given before processing began.

Rights of the Individual
Data principals have several rights under the PDPB:
- The right to confirmation and access: confirmation that their data is being processed, what data has been processed, a summary of processing activities, and who the data has been shared with.
- The right to correction and erasure: to have inaccurate or incomplete data corrected or completed, outdated information updated, and data no longer needed for its original purpose erased.
- The right to data portability: where data has been processed by automated means, the right to a copy in a structured, commonly used, machine-readable format.
- The right to be forgotten: the right to restrict or prevent continued disclosure of personal information once it’s no longer needed, consent has been withdrawn, or it was disclosed unlawfully.

Grounds for Data Processing
Personal data may generally only be processed with consent, but there are exceptions: to perform a function of the State, for legal compliance, in response to a medical emergency, for employment-related purposes, or for other reasonable purposes (weighing the data fiduciary’s interests, whether consent could reasonably be obtained, public interest, the effect on the individual, and whether the individual would reasonably expect the processing). Reasonable purposes can include preventing and detecting unlawful activity or fraud, whistleblowing, mergers and acquisitions, network and information security, credit scoring, debt recovery, processing publicly available data, and operating search engines.

Data Protection Authority
The Indian government will establish a Data Protection Authority responsible for protecting individuals’ interests, monitoring and enforcing the Act, acting promptly on data breaches, maintaining a public database of significant data fiduciaries with trust scores, examining data audit reports, certifying data auditors, promoting awareness of data protection rights, monitoring technology and commercial practices affecting personal data, advising government on protective measures, and handling complaints.

Transferring Personal Data Outside of India
Sensitive personal data can be transferred outside India, but must still be stored in India, and requires the data principal’s consent, plus one of: a contract or Authority-approved scheme, government approval of the transfer, or Authority approval for a specific purpose.

Exemptions
The government can exempt agencies where necessary for the sovereignty and integrity of India, foreign relations, public order, or preventing incitement to a cognizable offence. Processing is also exempt for law enforcement investigation and prosecution, legal proceedings, judicial functions, personal or domestic purposes, and journalistic purposes, all still subject to being for a specific, clear, and lawful purpose.

Offences
Violations are punishable by fines, and in some cases imprisonment. Processing or transferring data in violation of the PDPB can incur a penalty of up to 15 crore rupees (roughly USD $2.7 million) or 4% of worldwide turnover, whichever is higher. Selling personal data that harms an individual, or re-identifying anonymised data, can carry a prison sentence of up to 3 years.

Transparency and Accountability
Like most privacy laws, the PDPB requires a privacy policy. To comply, it needs to cover: the types of personal data collected and how, the purposes of processing, categories of data collected in exceptional circumstances, data principal rights and how to access them, the right to file a complaint, a data trust score where applicable, and details of any cross-border data transfers. If you already have a GDPR, CCPA, and Australian Privacy Act compliant privacy policy, much of this will already be covered.
To safeguard the personal data you collect and store, you’ll need de-identification and encryption methods, protection of data integrity, and steps to prevent misuse, unauthorised access, modification, disclosure, or destruction.
If there’s a breach of personal data likely to cause harm, the Authority must be notified, with details of the nature of the breach, how many data principals are affected, the possible consequences, and the remedial action being taken.
A Data Protection Officer is required if the Authority classifies the entity as a “significant data fiduciary,” based on the volume and sensitivity of data processed, turnover, risk of harm, use of new technologies, and any other relevant risk factors.

Conclusion
India’s Personal Data Protection Bill is set to become the latest major international data protection law, making India a safer place to handle and process personal information. To prepare for it becoming law, consider:
- Reviewing and updating your data protection policies
- Reviewing how you notify users that you collect their data
- Reviewing how you obtain user consent
- Reviewing how you keep personal data safe
- Considering how you’ll meet data principal rights requests
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.