India scraps privacy bill following big tech outcry
However, the government is developing a new bill which it hopes to bring into law early next year
India has withdrawn its controversial data protection and privacy bill that caused alarm among big tech companies, with the aim of developing a new law instead.
The Personal Data Protection Bill, first proposed in 2019, contained rules on cross-border data flows, and considered allocating the Indian government powers to obtain user data from companies, as reported by Reuters.
A government notice declared yesterday the decision was due to a parliamentary panel review of the proposed law, which suggested making a number of amendments. Because of the changes involved, the notice said there was a need for a new comprehensive legal framework, sparking the government into plans to present fresh legislation.
The government had already begun drafting the new bill, which is in its advanced stages. The finer details of the bill and how it differs will be published very soon, the IT minister Ashwini Vaishnaw told Reuters.
He added the government is aiming to get the bill approved and made into law by early 2023 during the parliament’s budget session, which usually runs between January and February.
Originally, the 2019 privacy bill aimed to protect Indian citizens and create a data protection authority, but caused concern among big tech companies, as they were worried it could increase their data storage and compliance burden requirements.
When asked whether stakeholders will be consulted on the new bill that's in development, Vaishnaw said the process won’t be that long as the parliamentary panel that reviewed the previous bill had already completed the process of gathering industry feedback.
The Indian government’s approach to privacy forced WhatsApp to file a lawsuit in May 2021 in a bid to block regulations that would compel the Facebook-owned company to break privacy requirements for its users. The case declared that the country’s new internet laws violate privacy rights in the country’s constitution as it requires social media companies to identify the "first originator of information" when authorities demand it.
Additionally, India’s cyber security rules were criticised by the Internet and Mobile Association of India (IAMAI) in June 2022, with the critics saying it would create an environment of fear rather than trust. The technology industry body, which represents organisations such as Google and Facebook, called for a one-year delay before the rules were set to take effect.
IT best practices for accelerating the journey to carbon neutrality
Considerations and pragmatic solutions for IT executives driving sustainable IT

The Total Economic Impact™ of IBM Spectrum Virtualize
Cost savings and business benefits enabled by storage built with IBMSpectrum Virtualize

Using application migration and modernisation to supercharge business agility and resiliency
Modernisation can propel your digital transformation to the next generation
