Understanding Legal Liabilities in DPDP Execution

thelawmonitor
5 Min Read
Understanding Legal Liabilities in DPDP Execution

Introduction to DPDP Execution

In this insightful segment of ‘Leading Questions,’ legal experts Sidhant Dhingra and Shikher Upadhyay delve into the intricacies of executing the Digital Personal Data Protection (DPDP) Act. They outline the responsibilities of Data Fiduciaries, duties of Significant Data Fiduciaries, the stringent protections for children’s data, and the regulations surrounding data erasure and retention.

Reasonable Security Safeguards Under DPDP

One of the critical responsibilities under the DPDP Act is ensuring ‘Reasonable Security Safeguards’ as per Section 8(5) of the Act and Rule 6 of the DPDP Rules. At a fundamental level, Data Fiduciaries are required to implement the following measures:

  • Technical protections such as encryption, obfuscation, masking, or tokenization.
  • Access control systems and continuous monitoring of systems.
  • Mandatory retention of logs for a minimum period of one year to facilitate breach detection and investigation.
  • Business continuity plans to maintain processing stability during security incidents.
  • Binding contractual clauses ensuring Data Processors adhere to equivalent security measures.

Given that the ‘reasonableness’ of these measures is often assessed during regulatory inspections, it is imperative for organizations to maintain comprehensive security documentation.

Reconciling Breach-Reporting Mandates

Under the provisions of Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules, Data Fiduciaries are mandated to notify both the Data Protection Board of India and the affected Data Principals ‘without delay’ when a personal data breach occurs. A thorough report, detailing the cause, extent, and remedial measures, must be filed with the Board within 72 hours.

Additionally, certain cybersecurity incidents must be reported to the Indian Computer Emergency Response Team (CERT-In) within six hours as per the 2022 IT Directions. This requires a coordinated incident awareness strategy:

  • Notify CERT-In within 6 hours for cyber incidents.
  • Inform the Data Protection Board and Data Principals immediately for data breaches.
  • Submit a comprehensive forensic report to the Data Protection Board within 72 hours.

Statutory Liability Allocation

The DPDP Act, specifically Section 8, places full statutory responsibility on the Data Fiduciary. Even when data operations are delegated to third-party vendors, cloud services, or platforms, the legal liability remains with the Fiduciary. This necessitates updating Data Processing Agreements (DPAs) to ensure that Processors:

  • Implement security controls equivalent to those required by Rule 6.
  • Provide immediate notifications of any security incidents.
  • Assist the Fiduciary with data erasure requests, enforcement of rights, and compliance audits.

Significant Data Fiduciary Designation

The Central Government holds the authority to designate any Data Fiduciary as a Significant Data Fiduciary (SDF) under Section 10(1) of the DPDP Act. This is based on factors such as the volume of data processed, data sensitivity, public order, electoral integrity, or national security risks. An SDF designation imposes additional statutory obligations under Section 10 and Rule 13 of the DPDP Rules, including:

  • Appointing a Data Protection Officer (DPO) who resides in India.
  • Engaging an independent auditor for annual data protection audits.
  • Conducting annual Data Protection Impact Assessments (DPIAs).
  • Performing regular evaluations of automated profiling and recommendation algorithms.

Children’s Data Protections

Section 9 of the DPDP Act stipulates that a child is any individual under 18 years of age, requiring verifiable parental consent before processing their personal data. The Act enforces strict statutory prohibitions, regardless of parental consent, including:

  • A complete prohibition on tracking or behavioral monitoring.
  • A complete ban on targeted advertising directed at children.
  • Restrictions on processing that could adversely affect a child’s well-being.

Violations can result in statutory penalties up to ₹200 crore.

Data Erasure Mechanics

Section 8(7) of the DPDP Act and Rule 8 of the DPDP Rules require the erasure of personal data when consent is withdrawn by the Data Principal or when the intended purpose of data processing expires. For specific platform categories, the Third Schedule establishes fixed retention limits, such as mandatory erasure after three years of user inactivity. Fiduciaries are required to provide formal notice to the Data Principal at least 48 hours before executing time-based erasures. The erasure process must encompass active systems, backups, and downstream processor environments, unless longer retention is legally mandated.

Sidhant Dhingra serves as a Senior Partner and Shikher Upadhyay as a Senior Associate at Foresight Law Offices India.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *