Key Features of India's Digital Personal Data Protection Bill 2022
The Digital Personal Data Protection Bill 2022 is an important step towards safeguarding the personal data of Indian citizens. Here are some of the key features of the bill:
- Data Localization: The bill requires all data fiduciaries to store personal data of Indian citizens within the country, except for certain categories of data that may be processed outside the country.
- Consent Framework: The bill introduces a new consent framework, which requires data fiduciaries to obtain explicit and informed consent from individuals for processing their personal data.
- Right to be Forgotten: The bill grants individuals the right to request erasure of their personal data, subject to certain conditions.
- Data Protection Authority: The bill establishes a new Data Protection Authority, which will be responsible for enforcing data protection laws, issuing regulations, and imposing penalties for non-compliance.
- Cross-Border Data Transfer: The bill allows for cross-border transfer of personal data, subject to the fulfilment of certain conditions.
- Data Breach Notification: The bill mandates data fiduciaries to notify the Data Protection Authority and affected individuals in case of any data breaches.
- Penalty Provisions: The bill introduces heavy penalties for data fiduciaries found in breach of data protection laws, including fines of up to 4% of their global turnover.
- Personal Data Processing Categories: The bill categorizes personal data into three categories - sensitive personal data, critical personal data, and general personal data. The processing and storage requirements for each category of data vary, with more stringent requirements for sensitive and critical personal data.
Overall, the Digital Personal Data Protection Bill 2022 is a significant step towards ensuring the privacy and security of personal data in India, and aligning the country's data protection laws with global best practices.