Processing of personal data with due consent of the Data Principal under DPDPA 2023
In this article, an attempt has been made to present some of the important provisions of the Digital Personal Data Protection Act (DPDPA), 2023 keeping in mind their relevance in the present environment of digital transactions and transmission of our digital personal data for day-to-day affairs. The Act has beautifully covered the provisions relating to personal data protection aspects. However, this Article explains the provisions broadly related to application of DPDPA, 2023, definitions of Data Fiduciary and Data Principal, grounds for processing personal data, and the notice and consent for use of personal data.
DPDPA, 2023 also provides provisions to establish the Data Protection Board of India, delineating the powers, functions and procedures to be followed by the Board, appeal and alternate dispute resolution, special provisions for processing of personal data outside India, exemptions thereunder, penalties and adjudication, and other miscellaneous provisions, apart from the role and responsibilities of the Data Fiduciary and the Data Principals.
The Digital Personal Data Protection Act, 2023 (DPDPA, 2023) aims to regulate the processing of digital personal data in a manner that recognises both the right of individuals to protect their data and the requirement to process such individual data for legal purposes and for such issues which are connected with data protection or those incidental to data protection, such personal data for the given lawful purposes and matters connected to such objectives or incidental thereto.
The Act in the Context of Data Misuse
As is widely recognized, social media platforms abound with freely accessible applications. The moment we use social media, log in for a mailing list, or access a free app on our laptops or computers, we are required to agree to the supplier’s terms of access to the app. These agreements are unnecessarily confusing and detailed that we missread them. In order to ease the challenging process, we knowingly or unknowingly tend to agree with them, and thus they set the conditions for how a company can access the personal data they obtain from us while using their app.
Typically, that data gets utilized by such companies in one of the three ways:
- Personal data is aggregated and analysed to provide us with more personalized advertisements.
- Personal data is logged and assessed for research and development.
- Personal data is sold to a data brokerage.
Under the aforesaid scenarios, companies handle, store, and distribute our personal data using specific and different parameters. In a situation when you are working from home, this becomes very difficult for companies to enforce precautions and protections against sensitive information and data for the prevention of both internal and external data breaches. The misuse of data often happens when people or companies use individual data for other than the stated intentions. Often, data misuse does not occur as a result of direct company actions but rather due to the improper actions of individuals, and outsiders. Data breach could be explained with an example, such as when a bank employee accesses the bank account of a friend to know a friend’s current balance in his savings bank account and inform others. Similarly, data breaches happen if an advertising company uses one client’s data to inform another client regarding the marketing campaign.
In this context, (DPDPA, 2023) is a significant attempt by the Government to arrest data misuse and regulate the utilization and processing of such personal data for the given lawful purposes and matters connected to such purposes or incidental thereto.
Analysis of Some of the Important Provisions of the Act
Definition of Data Fiduciary and Data Principal
Various terms used in the Act have been defined under Section 2 of the Act. For the sake of easy understanding of the terms ‘Data Fiduciary’ and ‘Data Principal’, the extracts of the provisions of sub-sections (i) and (j) of Section 2 of the Act are given as under:
- Section 2(i) — “Data Fiduciary”: means any person who alone or in conjunction with other person determines the purpose and means of processing of personal data.
- Section 2(j) — “Data Principal”: means the individual to whom the personal data relates and where such individual is:
- a child, includes the parents or lawful guardian of such a child;
- a person with disability, includes her lawful guardian, acting on her/his behalf.
Applicability of the Act
Section 3 of the Act provides for the applicability of the Act and reads as under:
It has been clearly provided in the Act that the application of the Act shall not only be restricted to the domestic territory of India, but the same shall also be applicable to the use of individuals’ personal data in foreign countries. The condition is that the use of such data is in connection with the activity related to the supply of goods or services to the Data Principals within India. Provisions shall apply to all kinds of data whether it is in digital form, or non-digital form which may be digitalized afterwards. If the data is not in digital form today, it can be digitalized and used subsequently. The provisions therefore restrict non-digitalized data also.
Sub-section (c) of Section 3 of the Act further provides:
Illustration: Publicly Available Personal Data
If a girl, while blogging her views, has publicly made available her individual data on social media, the provisions of this Act shall not apply in such a case. We need to be cautious while providing our personal data to the public on social media while submitting our views on any of the public channels as protection is no longer available if you voluntarily provide your personal data on social media tools and apps.
Grounds for Processing Personal Data and Notice Requirements
Sub-section (1) of Section 4 of the Act provides as under:
Here, it is important to note that there must be a consent from the Data Principal before processing his/her personal data, and such processing of the data must be for a lawful purpose and certain legitimate uses only.
Sub-section (2) of Section 4 of the Act provides that for the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by the law.
A Data Fiduciary must seek explicit consent of the Data Principal before processing his/her personal data for which he/she has to make a request in a manner as prescribed in Section 5(1) of the Act, which provides that every request made to a Data Principal under Section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her:
- The personal data and the purpose for which the same is proposed to be processed;
- The manner in which he/she may exercise her rights under Sub-section (4) of Section 6 and Section 13; and
- The manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed.
Illustration: Live Video KYC Verification
If a person opens a bank account via a mobile app/website of a Bank and opts to utilize his personal data by a bank employee in a live, video-based customer identification process to complete the KYC requirements, the bank employee shall accept the request for using the personal data with the notice of the customer. In such situations, this section of the Act does not apply.
Sub-section (3) of Section 4 of the Act provides that the Data Fiduciary shall give the Data Principal the option to access the contents of the notice in English or any language specified in the Eighth Schedule to the Constitution.
Consent to be Free, Specific, Informed, Unconditional and Unambiguous
Section 6(1) of the Act provides as under:
Under the consent, only that personal data which is necessary for such specified purpose can be processed, irrespective of whether the consent is sought for a few other details additionally which are not relevant for the specified purpose.
Illustration: Telemedicine Application
A person downloads a telemedicine app. The App seeks the consent of the person to process his individual data and access his mobile phone contact list to avail telemedicine services, and the person signifies his consent to both. Here, the phone contact list is not necessary for making available telemedicine services, and his consent shall be limited to the processing of his individual data for availing the telemedicine services.
Invalidity of Infringing Consent Conditions
Section 6(2) provides as under:
Illustration: Waiver of Right to Complain
A girl buys an insurance policy using the mobile app/website of an insurer. She gives consent to the insurer to process her personal data for the objective of providing the insurance policy. By doing so, she waives her right to file a complaint to the Data Protection Board of India. Part (ii) of the consent given in the illustration, relating to the waiver of her right to file a complaint, shall be invalid as it infringes the provisions of the Act.
Presentation and Language of Consent Requests
Section 6(3) of the Data Protection Act provides as under:
Withdrawal of Consent and Its Consequences
As per Section 6(4), where consent given by the Data Principal is the very basis of processing of individual data, the Data Principal shall have the right to withdraw his consent at any time, with the ease of doing so being comparable to the ease with which such consent was given.
Section 6(5) specifies that the consequences of withdrawal shall be borne by the Data Principal, and such withdrawal shall not affect the legality of processing of the personal data based on consent before its withdrawal.
Illustration: E-Commerce Supply Order Withdrawal
A girl is a user of an online shopping app/website operated by an e-commerce service provider. The girl consents to the processing of her personal data by the said service provider for the objective of fulfilling her supply order and places an order for supply of goods while making payment for the same. If the girl withdraws her consent, the service provider may stop enabling the girl to use the app/website for placing her orders. However, he may not stop the processing for supply of the goods already ordered and paid for by the girl.
Section 6(6) provides that if a Data Principal withdraws her consent, the Data Fiduciary shall, within a reasonable time, cease and cause its Data Processors to cease processing the personal data unless such processing is required or authorized under any law in force.
Illustration: Telecom Billing and Processor Cessation
A customer of the service provider, who had earlier given his consent to the service provider for the processing of his personal data for emailing of bills, downloads the mobile app of the service provider and opts to receive bills only on the app. The service provider shall itself cease, and shall cause the Data Processor to cease, the processing of personal data of the customer for emailing the bills.
Consent Manager Framework & Burden of Proof
Under Sub-sections (7), (8), (9), and (10) of Section 6:
- The Data Principal may give, manage, review, or withdraw consent to the Data Fiduciary through an interoperable Consent Manager.
- The Consent Manager shall be accountable to the Data Principal and must register with the Data Protection Board of India subject to prescribed technical, operational, and financial standards.
- Burden of Proof: Where consent is the basis of processing and a question arises in any proceeding, the Data Fiduciary is statutorily obliged to prove that notice was given and consent was obtained in accordance with the Act.
Legitimate Uses for Which Personal Data Can Be Processed
The Act provides for legitimate uses where personal data may be processed without separate consent:
- Section 7(a): Processing for a specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated that she does not consent.
- Section 7(b): Processing by the State and any of its instrumentalities to provide or issue subsidies, benefits, services, certificates, licences, or permits, where prior consent was given or the data exists in a notified government database/register.
Reference
Extract of provisions at points 1 to 6 taken from the Bare Act of THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023 (Act no. 01 of 2023), available via the Ministry of Electronics and Information Technology, Government of India (meity.gov.in).