munotes®

What Data Protection Is, and How It Differs From Confidentiality

Chapter One Hundred Fourteen

Syllabus topic 4.1, "Law relating to Data Protection and Trade Secrets."

Pages 528 to 532 of 683

In one line

Data protection is the regulation of how anyone handles information about an identifiable individual, and it differs from confidentiality in what it protects, whom it protects, and how the obligation arises.

The subject in one paragraph

Data protection law starts from a simple observation. Information about a person is generated by almost everything the person does, is easy to copy, easy to combine, and is held mostly by organisations the person did not choose and cannot see. The law's response is not to make that information secret, which is impossible, but to regulate what those organisations may do with it: they must have a reason, must say what they are doing, must do only that, must keep it safe, must correct it, must delete it, and must answer for it.

Notice that the aim is not secrecy. A person's name and address are not secret; they are still personal data. Data protection is about control and accountability, not confidentiality.

The vocabulary

Every data protection statute in the world uses roughly the same five ideas, and the Indian Act's names for them are worth learning at once.

Personal data. "Any data about an individual who is identifiable by or in relation to such data." Section 2(t) of the Digital Personal Data Protection Act, 2023. Identifiability is the whole test, and it is why an account number, a device identifier and a photograph are all personal data.

Processing. Everything you can do with data. Section 2(x) lists collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission or dissemination, restriction, erasure and destruction.

The individual. Called the Data Principal in India, the data subject in Europe.

The organisation that decides. Called the Data Fiduciary in India, the controller in Europe. Section 2(i): "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data".

The organisation that acts on instructions. Called the Data Processor in India, the processor in Europe. Section 2(k): a person who processes personal data on behalf of a Data Fiduciary.

The word "Fiduciary" is a deliberate Indian choice. Europe says "controller", which describes power. India says "fiduciary", which describes a duty of loyalty owed to the person whose data it is. The Srikrishna Committee, chapter 1190, chose it precisely to say that the relationship is one of trust and not of ownership.

The four principles every regime shares

Purpose limitation. Data collected for one purpose may not be used for another.

Data minimisation. Only what is necessary for that purpose.

Accuracy. The data must be correct, and correctable.

Storage limitation. Kept only as long as the purpose requires, then erased.

munotes.in528

The rest of this chapter

Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

Notes + Solved papers: ₹798 Already bought it? Sign in

Or notes only: ₹499
Or solved papers only: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!