Data Protection and Privacy Laws — Unit 5 Notes (Information Technology Law (Cyber Law))

LLB504 · Unit 5

Data Protection and Privacy Laws notes — Unit 5

Free unit-wise study notes on data protection and privacy laws for Information Technology Law (Cyber Law), Semester 5 of Bachelor of Laws (LLB) — key concepts, examples, important questions and a revision checklist for semester exams.

The New Oil and the Fundamental Right. This final unit navigates the complex and rapidly evolving landscape of Data Protection. It covers the monumental Supreme Court judgment in the Puttaswamy case elevating Privacy to a Fundamental Right. It also examines the limitations of the existing IT Rules (SPDI Rules 2011) and the framework of the new Digital Personal Data Protection (DPDP) Act, 2023.

Notebook — 14 pages

Page 1

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

1. Data is the New Oil

In the digital economy, personal data—your location, browsing history, shopping habits, medical records, and financial details—is the most valuable commodity. Tech giants harvest this data to run targeted advertising and train algorithms.

The Legal Vacuum

For a long time, India did not have a dedicated, comprehensive Data Protection Act (unlike Europe's GDPR). The protection of personal data was scattered, weakly enforced through Section 43A of the IT Act and the SPDI Rules, 2011.

Next — The Fundamental Right to Privacy

1 of 14

Page 2

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

2. The Puttaswamy Judgment (2017)

The landscape of data protection changed forever due to the Aadhaar project challenge.

Justice K.S. Puttaswamy v. Union of India

A 9-judge constitutional bench of the Supreme Court unanimously delivered a historic judgment. The Government had argued that the Constitution does not explicitly guarantee a "Right to Privacy."

The Supreme Court rejected this, holding that the Right to Privacy is an intrinsic part of the Right to Life and Personal Liberty under Article 21, and as a part of the freedoms guaranteed by Part III of the Constitution.

Next — Informational Privacy

2 of 14

Page 3

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

3. Informational Privacy (Puttaswamy)

The Puttaswamy judgment specifically recognized "Informational Privacy" as a core facet of the right to privacy.

Control over Data

The Court held that individuals have a right to protect their personal data and control how it is used by the State and private corporations. The State cannot force citizens to surrender their biometric data (Aadhaar) without a valid law satisfying the test of proportionality.

This judgment triggered the urgent need for a standalone Data Protection Act in India.

Next — Existing Protection: SPDI Rules, 2011

3 of 14

Page 4

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

4. SPDI Rules, 2011 (Under Sec 43A)

Until the new DPDP Act is fully operational, data protection is largely governed by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

What is Sensitive Personal Data (SPDI)?

The rules classify certain data as highly sensitive, requiring strict protection:

  • Passwords.
  • Financial information (bank accounts, credit cards).
  • Physical, physiological, and mental health condition.
  • Sexual orientation.
  • Medical records and history.
  • Biometric information.

Next — Obligations under SPDI Rules

4 of 14

Page 5

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

5. Obligations under SPDI Rules

Corporations collecting SPDI must comply with specific rules:

  • Consent: Must obtain written consent (or e-consent) from the provider of the information before collecting SPDI.
  • Purpose Limitation: Data can only be collected for a lawful purpose connected with the function of the corporate body, and must not be retained longer than necessary.
  • Privacy Policy: Must publish a comprehensive privacy policy on their website.
  • Disclosure: SPDI cannot be disclosed to a third party without prior permission from the provider.

(However, these rules were considered weak, lacking a strong regulatory authority to enforce them, leading to the drafting of a new law).

Next — The DPDP Act, 2023

5 of 14

Page 6

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

6. Digital Personal Data Protection Act, 2023

After years of drafts (BN Srikrishna Committee), India finally enacted a comprehensive law: The DPDP Act, 2023.

Core Philosophy

The Act aims to balance the right of individuals to protect their personal data with the need to process such personal data for lawful purposes.

Applicability

It applies to the processing of digital personal data within India. It also applies to processing outside India if it is connected to offering goods/services to data principals in India.

Next — Key Definitions in DPDP Act

6 of 14

Page 7

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

7. Key Entities in the DPDP Act

1. Data Principal

The individual to whom the personal data relates. (e.g., You, the user, whose email and shopping history is collected).

2. Data Fiduciary

Any person/company who determines the purpose and means of processing personal data. (e.g., Facebook, Amazon, or a Bank). They hold the data in 'trust'.

3. Data Processor

Any person who processes personal data on behalf of a Data Fiduciary. (e.g., A cloud storage company hired by the Bank to store files).

Next — Grounds for Processing Data

7 of 14

Page 8

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

8. Grounds for Processing Data

A Data Fiduciary can only process your data on specific legal grounds.

1. Explicit Consent

Consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. The Fiduciary must give a notice explaining exactly what data is collected and why.

2. Certain Legitimate Uses

Consent is not required in some specific scenarios, such as:

  • Medical emergencies (life or death situations).
  • For the State to provide subsidies, benefits, or services.
  • For fulfilling legal obligations or complying with court orders.

Next — Rights of the Data Principal

8 of 14

Page 9

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

9. Rights of the Data Principal

The DPDP Act empowers citizens with specific rights over their digital shadow.

  • Right to Information: The right to obtain a summary of personal data being processed and the identities of all other Data Fiduciaries with whom the data has been shared.
  • Right to Correction & Erasure: The right to demand the correction of inaccurate data, and the right to demand the deletion of data once the purpose is served (Right to be Forgotten).
  • Right of Grievance Redressal: The right to readily available means to register grievances with the Data Fiduciary.
  • Right to Nominate: The right to nominate a person to exercise these rights in the event of death or incapacity.

Next — Obligations of Data Fiduciaries

9 of 14

Page 10

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

10. Obligations of Data Fiduciaries

Companies collecting data face massive compliance burdens.

  • Security: Must implement technical and organizational measures to ensure security and prevent personal data breaches.
  • Breach Notification: In case of a data breach (hack/leak), the Fiduciary must intimately notify the Data Protection Board and every affected Data Principal.
  • Data Minimization & Erasure: Must delete data when the specified purpose is fulfilled and retention is no longer necessary.

Children's Data

Processing data of a child (under 18) requires verifiable consent of the parent. Fiduciaries are banned from undertaking tracking, behavioral monitoring, or targeted advertising directed at children.

Next — Significant Data Fiduciaries (SDF)

10 of 14

Page 11

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

11. Significant Data Fiduciaries (SDF)

Just like SSMI in intermediary rules, the DPDP Act creates a category for massive data controllers (based on volume of data, risk to electoral democracy, or national security).

Extra Obligations for SDFs

  • Appoint a Data Protection Officer (DPO) based in India to represent the SDF.
  • Appoint an independent Data Auditor to evaluate compliance.
  • Undertake periodic Data Protection Impact Assessments (DPIA) before launching new technologies or services.

Next — The Data Protection Board of India

11 of 14

Page 12

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

12. The Data Protection Board of India

The Act creates an independent regulatory body to enforce the law: The Data Protection Board (DPB).

Functions of the Board

  • To inquire into data breaches and non-compliance by Fiduciaries.
  • To direct Fiduciaries to take urgent remedial measures during a breach.
  • To impose massive financial penalties for violations.

Financial Penalties (No Jail)

Unlike the IT Act which relies on criminal imprisonment, the DPDP Act relies on crippling civil fines. Failure to prevent a data breach can result in a penalty up to Rs. 250 Crores. Failure to notify the Board of a breach can result in a penalty up to Rs. 200 Crores.

Next — Conclusion of Unit 5

12 of 14

Page 13

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

13. Summary of Master Concepts

  • Puttaswamy Judgment: Elevated Privacy to a Fundamental Right under Art 21, recognizing Informational Privacy.
  • SPDI Rules (2011): Existing IT Act rules mandating consent and security for sensitive data (health, finance, passwords).
  • DPDP Act (2023): Comprehensive data protection law balancing citizen rights and lawful processing.
  • Data Principal vs Fiduciary: The citizen is the Principal; the company collecting the data is the Fiduciary.
  • Rights: Principals have rights to Information, Correction, and Erasure (Right to be Forgotten).
  • Penalties: Enforced by the Data Protection Board with massive fines up to 250 Crores, but no criminal imprisonment.

Next — Exam Strategy

13 of 14

Page 14

Wink Notes

LLB — 5th Semester

Information Technology Law

Unit - 5

14. University Exam Strategy

Premium Advice for Top Marks

  • The Puttaswamy Case: This is the bedrock of any privacy answer. Always quote that the 9-judge bench overruled older cases (like MP Sharma and Kharak Singh) to firmly anchor Privacy in Article 21. Emphasize the concept of 'Informational Privacy'.
  • Right to be Forgotten: If asked about emerging rights, explain this as the right of a Data Principal to demand the erasure of their past data once the purpose is over. Connect it to the DPDP Act's right to erasure.
  • Terminology Shift: In exams dealing with the new law, DO NOT use terms like 'Data Subject' or 'Data Controller' (which are GDPR terms). Strictly use the Indian terminology: Data Principal and Data Fiduciary. It shows precision.

Next — End of Unit

14 of 14

Continue in this subject