In Search of Adequacy: India's Data Privacy Draft Bills Compared
Graham Greenleaf · SSRN Electronic Journal · 2014
Indian government spokespersons have at various times since 2003 stated that data protection Bills have been drafted, but none have been introduced into the legislature as yet. Since 2011 there have been three significant steps toward such legislation: (i) a draft The Right to Privacy Bill, 2011 drafted by the Department of Personnel and Training and considered (largely favourably) by the Committee of Secretaries (2011); (ii) recommendations for a Bill from a report by a government-appointed ‘Group of Experts’ chaired by former Justice A P Shah (2012) , and (iii) a non-official Bill developed in 2013 by a civil society organisation, the Centre for Internet & Society, Bangalore. While these three Bills have their differences, their many similarities include coverage of both public and private sectors, a data protection authority, a conventional definition of ‘personal information’, and privacy principles generally up to ‘minimum’ OECD standards. They differ somewhat on the range of enforcement methods and whether individuals would have court actions available. Modest improvements could bring any of them to an international standard. None of these draft Bills have yet been adopted as government proposals. By and large, they are all proposing ‘normal’ data privacy laws such as are found in most of the more than 100 countries with such laws. These Bills and proposals would fit somewhere on the spectrum from ‘weak’ to ‘moderate’. The most likely future for data privacy in India is that it will go down this path. This paper compares these three draft Bills.