cessible. It must specify the type of personal data being collected, purpose of collection and usage, disclosure to third parties(if any) and the security practices undertaken by the employer(Rule 4). f. Your employer must allow you to access your information to review, amend and correct it(Rule 5(6)). g. Your employer must provide you with an option to not provide the data or information sought to be collected. You may also have an option to withdraw consent given earlier to your employer(Rule 5(7)). h. Your employer must designate a‘Grievance Redressal Officer’(“GRO”) to address your information concerns. The GRO must redress your grievance within one month of receipt of the grievance(Rule 5(9)). i. Your employer may transfer information to third parties only after ensuring that such third party maintains the same level of data protection as itself, and as required under the SPDI rules. Such transfer is permitted only through a lawful contract between your employer and a third party or through consent from you for such transfer(Rule 7). j. Your employer must implement reasonable security practices and procedures to protect your SPDI. The SPDI rules require compliance with the International Standard IS/ISO/ IEC 27001 on‘Information Technol ogy – Security Techniques – Information Security Management Systems – Requirements’ and any other applicable standards as per prevailing laws or sector specific associations. Your employer must also undertake an audit of your security practices from time to time, by appointing an independent auditor. (Rule 8) k. Where an employer is negligent in implementing and maintaining reasonable security practices and procedures resulting in wrongful loss or wrongful gain to any person, such employer is required to compensate the employee for wrongful loss that you may accrue due to such non-compliance(Section 43A of IT Act). Digital Data Protection Act, 2023(“DPDP Act”) 29 The DPDP Act was enacted by the Indian Parliament in August 2023. The DPDP Act, 2023 provides for the processing of digital personal data in a manner that recognises the right of individuals to protect their personal data and the need to process such personal data for lawful purposes. The DPDP Act, 2023 regulates a class of entities known as‘data fiduciaries’, which process personal data of individuals. ‘Data fiduciaries’ means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. As per the DPDP Rules, 2025 which have been notified under the DPDP Act, 2023, the provisions on consent, notice requirements, rights of data principals, and security procedures come into force from May 14, 2027, until then the IT Act, 2000 and the SPDI Rules, 2011 will govern the aforementioned issues. The DPDP Act applies to government and private employers collecting or processing personal data. However, processing of employment data for certain purposes has been classified as a ‘legitimate use’ under Section 7(i) the DPDP Act. Where an activity is classified as a‘legitimate use’, consent is not required for processing personal data for such purposes. This means that employers may process personal data of employees for ‘the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by the employee’ without the consent of the employee. Considering that the DPDP Act has been notified only on 13th November 2025, the interpretation of the provisions of the Act by the Courts and industry players is undetermined as on date of this report. However, Unions must push towards a very narrow interpretation of Section 7(i) of the DPDP Act and argue for‘employee performance’ not to fall within the ambit of ‘legitimate uses’. Unions can argue that any surveillance which assesses the efficiency or work of the employee will not be a ‘legitimate use’ under the DPDP Act and requires consent of the employee or worker. For instance, while a cab aggregator may collect a gig worker’s location data since it relates to the purpose of employment, collecting real-time personal health data of the gig worker in the name of efficiency without consent would not be legitimate use. 29 https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf What Are Your Rights – And What Are Management’s Obligations? 11
Einzelbild herunterladen
verfügbare Breiten