India scraps privacy bill following big tech outcry
However, the government is developing a new bill which it hopes to bring into law early next year
India has withdrawn its controversial data protection and privacy bill that caused alarm among big tech companies, with the aim of developing a new law instead.
The Personal Data Protection Bill, first proposed in 2019, contained rules on cross-border data flows, and considered allocating the Indian government powers to obtain user data from companies, as reported by Reuters.
A government notice declared yesterday the decision was due to a parliamentary panel review of the proposed law, which suggested making a number of amendments. Because of the changes involved, the notice said there was a need for a new comprehensive legal framework, sparking the government into plans to present fresh legislation.
The government had already begun drafting the new bill, which is in its advanced stages. The finer details of the bill and how it differs will be published very soon, the IT minister Ashwini Vaishnaw told Reuters.
He added the government is aiming to get the bill approved and made into law by early 2023 during the parliament’s budget session, which usually runs between January and February.
Originally, the 2019 privacy bill aimed to protect Indian citizens and create a data protection authority, but caused concern among big tech companies, as they were worried it could increase their data storage and compliance burden requirements.
When asked whether stakeholders will be consulted on the new bill that's in development, Vaishnaw said the process won’t be that long as the parliamentary panel that reviewed the previous bill had already completed the process of gathering industry feedback.
The Indian government’s approach to privacy forced WhatsApp to file a lawsuit in May 2021 in a bid to block regulations that would compel the Facebook-owned company to break privacy requirements for its users. The case declared that the country’s new internet laws violate privacy rights in the country’s constitution as it requires social media companies to identify the "first originator of information" when authorities demand it.
Additionally, India’s cyber security rules were criticised by the Internet and Mobile Association of India (IAMAI) in June 2022, with the critics saying it would create an environment of fear rather than trust. The technology industry body, which represents organisations such as Google and Facebook, called for a one-year delay before the rules were set to take effect.
The COO's pocket guide to enterprise-wide intelligent automation
Automating more cross-enterprise and expert work for a better value stream for customersFree Download
Introducing IBM Security QRadar XDR
A comprehensive open solution in a crowded and confusing spaceFree Download
2021 Gartner critical capabilities for data integration tools
How to identify the right tool in support of your data management solutionsFree Download
Unified endpoint management solutions 2021-22
Analysing the UEM landscapeFree Download