Buch 
Negotiating digitalised workplaces : rights and obligations, India
Entstehung
Einzelbild herunterladen
 

cessible. It must specify the type of personal data be­ing collected, purpose of collection and usage, disclo­sure to third parties(if any) and the security practices undertaken by the employer(Rule 4). f. Your employer must allow you to access your infor­mation to review, amend and correct it(Rule 5(6)). g. Your employer must provide you with an option to not provide the data or information sought to be col­lected. You may also have an option to withdraw con­sent given earlier to your employer(Rule 5(7)). h. Your employer must designate aGrievance Redressal Officer(GRO) to address your information con­cerns. The GRO must redress your grievance within one month of receipt of the grievance(Rule 5(9)). i. Your employer may transfer information to third par­ties only after ensuring that such third party main­tains the same level of data protection as itself, and as required under the SPDI rules. Such transfer is per­mitted only through a lawful contract between your employer and a third party or through consent from you for such transfer(Rule 7). j. Your employer must implement reasonable security practices and procedures to protect your SPDI. The SPDI rules require compliance with the International Standard IS/ISO/ IEC 27001 onInformation Technol ­ogy Security Techniques Information Security Management Systems Requirements and any oth­er applicable standards as per prevailing laws or sec­tor specific associations. Your employer must also undertake an audit of your security practices from time to time, by appointing an independent auditor. (Rule 8) k. Where an employer is negligent in implementing and maintaining reasonable security practices and proce­dures resulting in wrongful loss or wrongful gain to any person, such employer is required to compensate the employee for wrongful loss that you may accrue due to such non-compliance(Section 43A of IT Act). Digital Data Protection Act, 2023(DPDP Act) 29 The DPDP Act was enacted by the Indian Parliament in Au­gust 2023. The DPDP Act, 2023 provides for the processing of digital personal data in a manner that recognises the right of individuals to protect their personal data and the need to process such personal data for lawful purposes. The DPDP Act, 2023 regulates a class of entities known asdata fiduciaries, which process personal data of individuals. Data fiduciaries means any person who alone or in con­junction with other persons determines the purpose and means of processing of personal data. As per the DPDP Rules, 2025 which have been notified under the DPDP Act, 2023, the provisions on consent, notice requirements, rights of data principals, and security procedures come into force from May 14, 2027, until then the IT Act, 2000 and the SPDI Rules, 2011 will govern the aforementioned issues. The DPDP Act applies to government and private employ­ers collecting or processing personal data. However, pro­cessing of employment data for certain purposes has been classified as a legitimate use under Section 7(i) the DPDP Act. Where an activity is classified as alegitimate use, consent is not required for processing personal data for such purposes. This means that employers may process personal data of employees for the purposes of employ­ment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by the employee without the consent of the employee. Considering that the DPDP Act has been notified only on 13th November 2025, the interpretation of the provisions of the Act by the Courts and industry players is undetermined as on date of this report. However, Unions must push to­wards a very narrow interpretation of Section 7(i) of the DPDP Act and argue foremployee performance not to fall within the ambit of legitimate uses. Unions can argue that any surveillance which assesses the efficiency or work of the employee will not be a legitimate use under the DPDP Act and requires consent of the employee or worker. For instance, while a cab aggregator may collect a gig workers location data since it relates to the purpose of em­ployment, collecting real-time personal health data of the gig worker in the name of efficiency without consent would not be legitimate use. 29  https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf What Are Your Rights And What Are Managements Obligations? 11