Free unit-wise study notes on data protection and privacy laws for Information Technology Law (Cyber Law), Semester 5 of Bachelor of Laws (LLB) — key concepts, examples, important questions and a revision checklist for semester exams.
The New Oil and the Fundamental Right. This final unit navigates the complex and rapidly evolving landscape of Data Protection. It covers the monumental Supreme Court judgment in the Puttaswamy case elevating Privacy to a Fundamental Right. It also examines the limitations of the existing IT Rules (SPDI Rules 2011) and the framework of the new Digital Personal Data Protection (DPDP) Act, 2023.
Notebook — 14 pages
Page 1
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
1. Data is the New Oil
In the digital economy, personal data—your location, browsing history, shopping habits, medical records, and financial details—is the most valuable commodity. Tech giants harvest this data to run targeted advertising and train algorithms.
⇒The Legal Vacuum
For a long time, India did not have a dedicated, comprehensive Data Protection Act (unlike Europe's GDPR). The protection of personal data was scattered, weakly enforced through Section 43A of the IT Act and the SPDI Rules, 2011.
Page 2
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
2. The Puttaswamy Judgment (2017)
The landscape of data protection changed forever due to the Aadhaar project challenge.
⇒Justice K.S. Puttaswamy v. Union of India
A 9-judge constitutional bench of the Supreme Court unanimously delivered a historic judgment. The Government had argued that the Constitution does not explicitly guarantee a "Right to Privacy."
The Supreme Court rejected this, holding that the Right to Privacy is an intrinsic part of the Right to Life and Personal Liberty under Article 21, and as a part of the freedoms guaranteed by Part III of the Constitution.
Page 3
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
3. Informational Privacy (Puttaswamy)
The Puttaswamy judgment specifically recognized "Informational Privacy" as a core facet of the right to privacy.
⇒Control over Data
The Court held that individuals have a right to protect their personal data and control how it is used by the State and private corporations. The State cannot force citizens to surrender their biometric data (Aadhaar) without a valid law satisfying the test of proportionality.
This judgment triggered the urgent need for a standalone Data Protection Act in India.
Page 4
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
4. SPDI Rules, 2011 (Under Sec 43A)
Until the new DPDP Act is fully operational, data protection is largely governed by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
⇒What is Sensitive Personal Data (SPDI)?
The rules classify certain data as highly sensitive, requiring strict protection:
Passwords.
Financial information (bank accounts, credit cards).
Physical, physiological, and mental health condition.
Sexual orientation.
Medical records and history.
Biometric information.
Page 5
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
5. Obligations under SPDI Rules
Corporations collecting SPDI must comply with specific rules:
Consent: Must obtain written consent (or e-consent) from the provider of the information before collecting SPDI.
Purpose Limitation: Data can only be collected for a lawful purpose connected with the function of the corporate body, and must not be retained longer than necessary.
Privacy Policy: Must publish a comprehensive privacy policy on their website.
Disclosure: SPDI cannot be disclosed to a third party without prior permission from the provider.
(However, these rules were considered weak, lacking a strong regulatory authority to enforce them, leading to the drafting of a new law).
Page 6
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
6. Digital Personal Data Protection Act, 2023
After years of drafts (BN Srikrishna Committee), India finally enacted a comprehensive law: The DPDP Act, 2023.
⇒Core Philosophy
The Act aims to balance the right of individuals to protect their personal data with the need to process such personal data for lawful purposes.
⇒Applicability
It applies to the processing of digital personal data within India. It also applies to processing outside India if it is connected to offering goods/services to data principals in India.
Page 7
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
7. Key Entities in the DPDP Act
⇒1. Data Principal
The individual to whom the personal data relates. (e.g., You, the user, whose email and shopping history is collected).
⇒2. Data Fiduciary
Any person/company who determines the purpose and means of processing personal data. (e.g., Facebook, Amazon, or a Bank). They hold the data in 'trust'.
⇒3. Data Processor
Any person who processes personal data on behalf of a Data Fiduciary. (e.g., A cloud storage company hired by the Bank to store files).
Page 8
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
8. Grounds for Processing Data
A Data Fiduciary can only process your data on specific legal grounds.
⇒1. Explicit Consent
Consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. The Fiduciary must give a notice explaining exactly what data is collected and why.
⇒2. Certain Legitimate Uses
Consent is not required in some specific scenarios, such as:
Medical emergencies (life or death situations).
For the State to provide subsidies, benefits, or services.
For fulfilling legal obligations or complying with court orders.
Page 9
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
9. Rights of the Data Principal
The DPDP Act empowers citizens with specific rights over their digital shadow.
Right to Information: The right to obtain a summary of personal data being processed and the identities of all other Data Fiduciaries with whom the data has been shared.
Right to Correction & Erasure: The right to demand the correction of inaccurate data, and the right to demand the deletion of data once the purpose is served (Right to be Forgotten).
Right of Grievance Redressal: The right to readily available means to register grievances with the Data Fiduciary.
Right to Nominate: The right to nominate a person to exercise these rights in the event of death or incapacity.
Page 10
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
10. Obligations of Data Fiduciaries
Companies collecting data face massive compliance burdens.
Security: Must implement technical and organizational measures to ensure security and prevent personal data breaches.
Breach Notification: In case of a data breach (hack/leak), the Fiduciary must intimately notify the Data Protection Board and every affected Data Principal.
Data Minimization & Erasure: Must delete data when the specified purpose is fulfilled and retention is no longer necessary.
⇒Children's Data
Processing data of a child (under 18) requires verifiable consent of the parent. Fiduciaries are banned from undertaking tracking, behavioral monitoring, or targeted advertising directed at children.
Page 11
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
11. Significant Data Fiduciaries (SDF)
Just like SSMI in intermediary rules, the DPDP Act creates a category for massive data controllers (based on volume of data, risk to electoral democracy, or national security).
⇒Extra Obligations for SDFs
Appoint a Data Protection Officer (DPO) based in India to represent the SDF.
Appoint an independent Data Auditor to evaluate compliance.
Undertake periodic Data Protection Impact Assessments (DPIA) before launching new technologies or services.
Page 12
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
12. The Data Protection Board of India
The Act creates an independent regulatory body to enforce the law: The Data Protection Board (DPB).
⇒Functions of the Board
To inquire into data breaches and non-compliance by Fiduciaries.
To direct Fiduciaries to take urgent remedial measures during a breach.
To impose massive financial penalties for violations.
⇒Financial Penalties (No Jail)
Unlike the IT Act which relies on criminal imprisonment, the DPDP Act relies on crippling civil fines. Failure to prevent a data breach can result in a penalty up to Rs. 250 Crores. Failure to notify the Board of a breach can result in a penalty up to Rs. 200 Crores.
Page 13
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
13. Summary of Master Concepts
Puttaswamy Judgment: Elevated Privacy to a Fundamental Right under Art 21, recognizing Informational Privacy.
SPDI Rules (2011): Existing IT Act rules mandating consent and security for sensitive data (health, finance, passwords).
DPDP Act (2023): Comprehensive data protection law balancing citizen rights and lawful processing.
Data Principal vs Fiduciary: The citizen is the Principal; the company collecting the data is the Fiduciary.
Rights: Principals have rights to Information, Correction, and Erasure (Right to be Forgotten).
Penalties: Enforced by the Data Protection Board with massive fines up to 250 Crores, but no criminal imprisonment.
Page 14
Wink Notes
LLB — 5th Semester
Information Technology Law
— Unit - 5 —
14. University Exam Strategy
⇒Premium Advice for Top Marks
The Puttaswamy Case: This is the bedrock of any privacy answer. Always quote that the 9-judge bench overruled older cases (like MP Sharma and Kharak Singh) to firmly anchor Privacy in Article 21. Emphasize the concept of 'Informational Privacy'.
Right to be Forgotten: If asked about emerging rights, explain this as the right of a Data Principal to demand the erasure of their past data once the purpose is over. Connect it to the DPDP Act's right to erasure.
Terminology Shift: In exams dealing with the new law, DO NOT use terms like 'Data Subject' or 'Data Controller' (which are GDPR terms). Strictly use the Indian terminology: Data Principal and Data Fiduciary. It shows precision.