Information Technology Act & Data Protection. Vakul Sharma. Vakul Sharma. All Rights Reserved, 2010



Similar documents
DATA PROTECTION LAWS OF THE WORLD. India

Vijay Pal Dalmia, Advocate Delhi High Court & Supreme Court of India

THE PERSONAL DATA PROTECTION BILL, 2014

Data protection and outsourcing industry - A study. By Kumar Mihir

Data Compliance. And. Your Obligations

Crimes (Computer Hacking)

South East Asia: Data Protection Update

Sample Business Associate Agreement Provisions

BUSINESS ASSOCIATE AGREEMENT

The board of directors of a company is primarily responsible for:

June 10, Legislative Amendments to the Indiana Code Relating to First Lien Mortgage Act (the Act )

By Directors, Officers and Employees of Hellaby Holdings Limited and its Subsidiaries ( The Company )

BUSINESS ASSOCIATE AGREEMENT

Appendix : Business Associate Agreement

Legislative Language

1 L.R.O Electronic Transactions CAP. 308B ELECTRONIC TRANSACTIONS

ABM Resources NL Security Trading Policy

STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM

Information Management and Security Policy

BUSINESS ASSOCIATE AGREEMENT ( BAA )

The Credit Information Companies (Regulation) Act,

(4) THAMES VALLEY POLICE of Oxford Road, Kidlington, OX5 2NX ("Police Force"),

Policy on Public and School Bus Closed Circuit Television Systems (CCTV)

Council Policy. Records & Information Management

Sample Business Associate Agreement (4. Other Bus. Assoc., Version )

Letter of appointment of Director. Hearty welcome to HINDUSTAN OIL EXPLORATION COMPANY LIMITED as a Director of the Board of our Company.

Additional Tax, Penalty and Prosecution

CORK INSTITUTE OF TECHNOLOGY

VICTIMS RESTITUTION AND COMPENSATION PAYMENT ACT

STATES OF JERSEY DRAFT EU LEGISLATION (CIVIL AVIATION INSURANCE) (JERSEY) REGULATIONS 201-

PLEASE NOTE. For more information concerning the history of this Act, please see the Table of Public Acts.

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

THE WHITE ASBESTOS (BAN ON USE AND IMPORT) BILL, 2009

PLEASE NOTE. For more information concerning the history of this Act, please see the Table of Public Acts.

HIPAA PRIVACY AND SECURITY AWARENESS

Merchants and Trade - Act No 28/2001 on electronic signatures

In this policy: AASB124 means the Australian Accounting Standards Board 124 December 2012 including its subsequent replacements.

Computer Forensics US-CERT

University Healthcare Physicians Compliance and Privacy Policy

Terms of Business for Registered Support Providers

CHAPTER 2: IT ENABLED SERVICES AND EMERGING TECHNOLOGIES... 2 PART 1: IT ASSURANCE SERVICES AND ROLE OF CAs IN BPO-KPO... 2 Learning Objectives...

Comment [1]: BDERIV. Comment [2]: EDERIV

CABLE TELEVISION NETWORKS (REGULATION) ACT, 1995 [Act No. 7 of Year 1995, dated ] (as amended upto )

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1

CHAPTER 124B COMPUTER MISUSE

SEMGROUP CORPORATION. Anti-Corruption Compliance Policy August, 2011

TOOLBOX. ABA Financial Privacy

BUSINESS ASSOCIATE CONTRACTUAL ADDENDUM

SHARE TRADING POLICY November 2013

GUIDE TO ACHIEVING COMPLIANCE a South African perspective

Corporate ICT & Data Management. Data Protection Policy

HIPAA BUSINESS ASSOCIATE AGREEMENT

St. Peter s C.E. Primary School Farnworth , Internet Security and Facsimile Policy

Securities trading policy

HSHS BUSINESS ASSOCIATE AGREEMENT BACKGROUND AND RECITALS

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Mesothelioma Act 2014

Designated Officer means a director or person engaged in the management of the Company, whether as an employee or consultant.

BUSINESS ASSOCIATE AGREEMENT

Share Trading Policy

FINAL May Guideline on Security Systems for Safeguarding Customer Information

Electronic Commerce ELECTRONIC COMMERCE ACT Act. No Commencement LN. 2001/ Assent

Share trading policy. Mortgage Choice Limited ABN ME_ _10 (W2003)

INFORMATION SECURITY MANAGEMENT POLICY

Securities Trading Policy

EXHIBIT C BUSINESS ASSOCIATE AGREEMENT

The Criminal Procedure Rules Part 5 as in force on 7 April 2014 PART 5 FORMS AND COURT RECORDS

Md. FAMILY LAW Code Ann (2014) (a) In general. -- In this Part VI of this subtitle the following words have the meanings indicated.

Professional Solutions Insurance Company. Business Associate Agreement re HIPAA Rules

SUTLEJ TEXTILES AND INDUSTRIES LIMITED DOCUMENT PRESERVATION AND RETENTION POLICY

BUSINESS ASSOCIATE AGREEMENT

RECORDS MANAGEMENT POLICY

THE PUBLIC LIABILITY INSURANCE ACT, 1991

BUSINESS ASSOCIATE AGREEMENT

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

NOTICE OF PRIVACY PRACTICES OF THE GROUP HEALTH PLANS SPONSORED BY ACT, INC.

BUSINESS ASSOCIATE AGREEMENT First Choice Community Healthcare, Inc.

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI

Business Associate Agreement

Texas House Bill 300 & HIPAA. A MainNerve Whitepaper

FORMAL LETTER OF APPOINTMENT FOR INDEPENDENT DIRECTORS

Mandatory Reporting A process

MISLEADING ADVERTISING GUIDE

FACTORING REGULATION ACT, 2011

Legislative Language

BUSINESS ASSOCIATE AGREEMENT

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011

H. R SEC DIRECTORATE FOR INFORMATION ANALYSIS AND INFRA STRUCTURE PROTECTION.

APPENDIX I: STANDARD FORM BUSINESS ASSOCIATE CONTRACT AND DATA USE AGREEMENT (2012 Version)

MD Code, Family Law, T. 5, Subt. 5, Pt. VI, Refs & Annos. MD Code, Family Law, Definitions. Effective: January 1, 2012

DATA PROTECTION POLICY

BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS:

Data Protection Act. Privacy & Security in the Information Age. April 26, Ministry of Communications, Ghana

Data Protection Good Practice Note

Mexico. Rodolfo Trampe, Jorge Díaz, José Palomar and Carlos López. Von Wobeser y Sierra, S.C.

MMA SAMPLE FORM *REVIEW CAREFULLY & ADAPT TO YOUR PRACTICE*

Preferred Professional Insurance Company Subcontractor Business Associate Agreement

THE FACTORING REGULATION BILL, 2011

POLICY ON SECURITIES TRADING BY DIRECTORS, OFFICERS, SENIOR EXECUTIVES AND OTHER EMPLOYEES 2. WHOM DOES THE SECURITIES TRADING POLICY APPLY TO?

Title 9-A: MAINE CONSUMER CREDIT CODE

Transcription:

Information Technology Act & Data Protection Vakul Sharma Vakul Sharma. All Rights Reserved, 2010

When the Information Technology Act, 2000 was introduced it was the first technology legislation introduced in India! And when the Information Technology (Amendment)Act, 2008 came into existence* it is to be seen as a GameChanger! * Effective from October 27, 2009

What the Information Technology (Amendment)Act, 2008 promises to do?

It will bring a paradigm shift in data protection and privacy regime in India: Establishing a self regulation framework Maintenance of reasonable security practices and procedures Articulating sensitive personal data or information Adjudication related to data protection and privacy [civil liabilities] Providing criminal prosecution vis-à-vis data protection and privacy

Banks & The Information Technology Act

Banks providing Internet Banking and other support services can be classified as intermediaries Defined as any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record..[section 2(1)(w)]

Banks as Intermediaries Section 43A: Compensation for failure to protect data. Section 67C: Preservation and retention of information by intermediaries. Section 69B to comply with the directions to monitor and collect traffic data or information through any computer resource for cyber security.

Section 70B to comply with the direction of the Indian Computer Emergency Response Team (CERT-IN) in the area of cyber security. Section 72A disclosure of information in breach of lawful contract. Section 85 offences committed by companies.

Sections Penalties 43A Body corporate liable to pay damages by way of compensation to the person so affected. 67 C Imprisonment for a term, which may extend to 3 years and shall also be liable to fine.

Sections Penalties 69B 70B Imprisonment for a term, which may extend to 3 years and shall also be liable to fine. Imprisonment for a term, which may extend to 1 year or with fine, which may extend to one lakh rupees, or with both.

Sections Penalties 72A Imprisonment for a term, which may extend to 3 years or with fine, which may extend to five lakh rupees, or with both. 85 No express provision vis-à-vis penalties and compensation. However, the onus is on the company and its Directors, Secretary and Officers to prove their innocence.

Banks & Due Diligence Framework

Section 43 A (a) Have you defined the various components of sensitive personal data or information vis-à-vis users/customers? (b) Do you have a security policy? Is it documented?

Section 67C Do you have the electronic record preservation and retention policy?

Section 69B Have you adopted/established any procedure and safeguard for monitoring and collecting traffic data or information? Is it documented?

Section 70B Do you have the documented procedure to comply with the requests of CERT-IN regarding cyber security incidents?

Section 72A (a)do you have an adequate privacy policy? (b) Whether you have provided opt-in/optout clause in your privacy policy?

Quo Vadis Have you appointed designated officer/nodal officer/computer-incharge to comply with the directions of competent authority/agency under various provisions of the Act?

Quo Vadis Whether details of such designated officer/nodal officer readily available online (at your website)?

Yet to see any Indian banking website mentioning that it is IT Act compliant! Yes, sites do mention that they have US Patriot Act Certification!!

Banks and Data Protection Illustrations

Illustration 1 RBI s Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by Banks. These Guidelines came into effect from November 3, 2006. When Banks enter into such Off-shore outsourcing of Financial Services agreements whether banks perform due diligence vis-à-vis data protection regime existing in the host country?

Illustration 2 Master Circular on Credit Card operations (as amended upto July1, 2009): Protection of customer rights - Right to privacy - customer confidentiality Card issuing bank to maintain to maintain a Do Not Call Registry (DNCR) of customers as well as non-customers

The bank would be held responsible if a DNCN is called by its DSAs/DMAs or call centres Liability under section 66A(c): any electronic mail or electronic mail message* for the purpose of causing annoyance or inconvenience.punishable with imprisonment for a term, extend to 3 years and with fine *message or information created or transmitted or received on a computer resource/communication device

The bank should not engage telemarketers, DSAs/DMAs, who do not have a valid registration certificate from DoT as telemarketers. On July 31, 2008 the Hon ble Supreme Court in the case of Harsh Pathak vs. Union of India & Ors passed directions in a PIL. It directed that any telemarketer who is not registered with Department of Telecommunication (DoT) should not be permitted to operate the telemarketing services.

The question is whether banks can be held liable - (a) under section 66A(c) of the Information Technology Act, 2000, and (a) for violating the Supreme Court Directions

Illustration 3 Section 70 Protected system, wherein the appropriate Government is being empowered to declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure (CII) *Critical Information Infrastructure..means the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety

It s time that RBI/IBA should initiate the process of including banking networks, data centres, INFINET, National Financial Switch (NFS) etc. as CII under section 70 of the Act.

Illustration 4 In Umashankar Sivasubramaniam case decided by the Adjudicating Officer [Sh.P.W.C.Davidar], Chennai*, it was held: The Respondent bank has failed to put in place a foolproof Internet Banking system with adequate levels of authentication and validation which would have prevented unauthorised access.found guilty of the offences made out under section 85 r/w section 43 of the Act.. * 12.04.2010

Data Protection under the Act Civil liabilities under section 43, 43A Criminal liabilities section 66, 66A, 66B, 66C, 66D, 67C,69B,70B, 72A and 85

Thanks vakulsharma@gmail.com Vakul Sharma. All Rights Reserved, 2010