Under the powers conferred by clause (ob) of sub-section (2) of section 87 read with section 43A of the Information Technology Act, 2000, on 11th April 2011 Department of Information Technology notified rules for protection of sensitive personal information.
These rules identifies personal information consisting of information relating to password; financial information such as Bank account or credit card or debit card or other payment instrument details; physical, physiological and mental health condition; sexual orientation; medical records and history;Biometric information as sensitive personal data or information and stipulates the rules for handling such information.
Considering the news items appearing in a section of media which have commented on some aspects of the Rules, today The Department of Information Technology, Ministry of Communications & IT has clarified the position in this regard that these Rules do not provide free access to sensitive personal information. The nature and applicability of these Rules have been clearly specified. The Intent of Rules is to protect sensitive personal information and does not give any undue powers to Government agencies for free access of sensitive personal information. Wide public consultations were held before finalizing the Rules and the Rules have been duly endorsed by the Industry Association.
The Rules under section 43A cast onus on the body corporate to provide policy for privacy and disclosure of information. Any such disclosure of sensitive personal data or information by body corporate to any third party shall require prior permission from the provider of such information. The Rules provide for inherent checks-and-balances in the form: (a) that the Government agencies must have been mandated under the law to obtain such information for the purpose of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution and punishment of offences and (b) that any such agency receiving such information has to give an undertaking that the information so obtained shall not be published or shared with any other person. The Government Agencies are required to the follow lawful process and procedures.