Centre proposes penalty of up to Rs 500 cr for each data breach
   Date :19-Nov-2022

Centre proposes penalty 
THE Government has raised the penalty amount to up to Rs 500 crore for violating provisions under the proposed draft Digital Personal Protection Bill 2022 issued on Friday. The draft personal data protection bill, issued in 2019, had proposed a penalty of Rs 15 crore or 4 per cent of the global turnover of an entity.
“The purpose of this Bill is to provide for the processing of digital personal data in a manner that recognises the right of individuals to protect their personal data, the need to process personal data for lawful purposes and for other incidental purposes,” an explanatory note of the draft bill said. The proposed bill comes in place of the Data Protection Bill, which was withdrawn by the Government in August this year.
The draft proposes to set up a Data Protection Board of India, which will carry on functions as per the provisions of the bill. “If the Board determines at the conclusion of an inquiry that non-compliance by a person is significant, it may, after giving the person a reasonable opportunity of being heard, impose such a financial penalty as specified in Schedule 1, not exceeding rupees five hundred crore in each instance,” the draft said.
It has proposed a graded penalty system for data fiduciaries that will process the personal data of data owners only in accordance with the provisions of the Act. The same set of penalties will be applicable to the Data processor -- which will be an entity that will process data on behalf of the Data Fiduciary. The draft has proposed a penalty of up to Rs 250 crore in case the Data Fiduciary or Data Processor fails to protect against personal data breaches in its possession or under its control. The draft has also proposed a penalty of Rs 200 crore in case the Data Fiduciary or Data Processor fails to inform the Board and data owner about the data breach.
The law allows the transfer and storage of personal data in some countries while raising the penalty for violations.
It will be a great relief for Google, Amazon, Facebook and other global firms as it replaces an earlier version that had alarmed big tech companies over its stringent restrictions on cross-border data flows.
The Government will “notify such countries or territories outside India to which a data fiduciary may transfer personal data”, according to the draft unveiled on Friday for public feedback.
The bill has a provision to allow entities to transfer the personal data of a citizen outside the country in cases where the processing of personal data is necessary for enforcing any legal right or claim, the performance of any judicial or quasi-judicial function, investigation or prosecution of any offence or data owner is not within the territory of India and has entered into any contract with any person outside the country.