→ Rule 4 The body corporate must provide policy for privacy and disclosure of information. → Rule 5 The body corporate is required to take consent and provide notice to the Data Principal before collecting sensitive personal data. The body corporate must not retain the personal data for longer than required for the purpose of collection or permitted under law, and such data must be used only for the purpose for which it was collected. Data principals must also be permitted to correct the SPDI that they have provided and to withdraw consent. The SPDI must be kept secure. The body corporate must also appoint a Grievance Redressal Officer to redress concerns of data principals under the SPDI rules, within 1 month of the date of receipt of the grievance. → Rule 6 Disclosure of information by the body corporate to any third parties will require prior consent of the data principal unless disclosure is otherwise required under law. → Rule 7 The body corporate must ensure the same level of data protection as maintained by itself prior to transferring information to any third parties. Such transfer of information is permitted only under a lawful contract. → Rule 8 The body corporate is required to maintain reasonable security practices and procedures The SPDI Rules are applicable to‘body corporates’ which are private entities and to select public entities where such entities are registered as a company or firm engaged in commercial or professional activities. The SPDI Rules will continue to remain in force until May 13, 2027, in the con text of notice and consent requirements, security safeguards, and rights of data principals. These rules, with respect to the aforementioned issues, will be replaced by the DPDP Act, 2023 and the Digital Personal Data Protections Rules, 2025(“the DPDP Rules, 2025”) from May 14, 2027, onwards.‘Sensitive personal data’ under the SPDI Rules includes the following information: → passwords; → financial information such as bank account or credit card or debit card or other payment instrument details; → physical, physiological and mental health condition; → sexual orientation; → medical records and history; → biometric information; → any detail relating to the above clauses as provided to body corporate for providing service; and → any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise. The compliances for an employer collecting SPDI under the IT Act and the SPDI Rules are specified below: a. Your employer must implement security practices and procedures designed to protect SPDI from unauthorised access, damage, use, modification, disclosure or impairment.(Rule 8) b. Your employer may collect SPDI only where collection of information is considered necessary for a lawful purpose in connection with the function or activity of the company of the employer(Rule 5(2)). Such SPDI can be used only for the purpose for which it was collected by the employer and not for any other use case (Rule 5(5)). For instance, an employer cannot ask in formation about an employee’s sexual orientation 28 as it has no nexus with the activity of the company. c. Your employer must not retain the SPDI for longer than necessary for the purpose for which it was collected(Rule 5(4)). d. Your employer must obtain specific written consent from you before collecting your SPDI.(Rule 5(1)) You must be informed as to why such SPDI is being collected, what SPDI is being collected, who will such SPDI be transferred to and the name and address of the entity collecting and storing the SPDI(Rule 5(3)). e. Your employer must have a privacy policy which is made available to you, and it should be available on the website of your employer(Rule 4). The privacy policy of your employer must be clear and easily ac28 Navtej Singh Johar v. Union of India, AIR 2018 SC 4321. 10 Friedrich-Ebert-Stiftung e. V.
Einzelbild herunterladen
verfügbare Breiten