--- layout: default title: "Leaked Privacy Bill: 2014 vs. 2011" description: "A March 2014 CIS post by Elonnai Hickok comparing the leaked draft Privacy Bill 2014, prepared by the Department of Personnel and Training, against the previously leaked September 2011 Privacy Bill, covering changes to scope, definitions, exceptions, privacy principles, and enforcement mechanisms." authors: ["Elonnai Hickok"] categories: [Centre for Internet and Society, Elonnai Hickok] date: 2014-03-31 source: "Centre for Internet and Society" permalink: /elonnai/leaked-privacy-bill-2014-vs-2011/ created: 2026-08-30 --- **"Leaked Privacy Bill: 2014 vs. 2011"** is a policy analysis by [Elonnai Hickok](/elonnai/) published by the [Centre for Internet and Society](/cis/) on 31 March 2014. It compares a leaked draft Privacy Bill 2014, prepared by the Department of Personnel and Training, Government of India, against the previously leaked September 2011 Privacy Bill, marking the third known leak of privacy legislation for India after versions surfaced in April 2011 and September 2011. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
The Centre for Internet and Society has recently received a leaked version of the draft Privacy Bill 2014 that the Department of Personnel and Training, Government of India has drafted.
Note: After obtaining a copy of the leaked Privacy Bill 2014, we have replaced the blog "An Analysis of the New Draft Privacy Bill" which was based off of a report from the Economic Times, with this blog post.
This represents the third leak of potential privacy legislation for India that we know of, with publicly available versions having leaked in April 2011 and September 2011.
When compared to the September 2011 Privacy Bill, the text of the 2014 Bill includes a number of changes, additions, and deletions. Below is an outline of significant changes from the September 2011 Privacy Bill to the 2014 Privacy Bill:
The 2014 Bill extends the right to privacy to all residents of India. This is in contrast to the 2011 Bill, which extended the right to privacy to citizens of India. The 2014 Bill furthermore recognizes the right to privacy as a part of Article 21 of the Indian Constitution and extends to the whole of India, whereas the 2011 Bill did not explicitly recognize the right to privacy as being a part of Article 21, and excluded Jammu and Kashmir from its purview.
The 2014 Bill includes a number of new definitions, redefines existing terms, and deletes others.
According to the 2011 Bill, the exceptions to the right to privacy included:
The 2014 Bill reflects almost all of the exceptions defined in the 2011 Bill, but removes "detection of crime" from the list of exceptions. The 2014 Bill also qualifies that the application of each exception must be adequate, relevant, and not excessive to the objective it aims to achieve and must be imposed in the manner prescribed, whereas the 2011 Bill stated only that the application of exceptions to the right to privacy cannot be disproportionate to the purpose sought to be achieved.
The 2011 Bill lists five instances that will not be considered a deprivation of privacy, namely:
The 2014 Bill limits these instances to:
Unlike the 2011 Bill, the 2014 Bill defines nine specific privacy principles: notice, choice and consent, collection limitation, purposes limitation, access and correction, disclosure of information, security, openness, and accountability. The privacy principles will apply to all existing and evolving practices.
Both the 2011 Bill and the 2014 Bill have provisions that apply to the processing of personal and sensitive personal data. The 2011 Bill includes provisions addressing the:
Of these, the 2014 Bill broadly (though not verbatim) reflects the 2011 Bill provisions relating to the collection of personal data, processing of personal data, access to personal data, updating personal data, retention of personal data, and data quality.
The 2014 Bill further includes provisions addressing openness and accountability, choice, consent, and exceptions for personal identifiers.
The 2014 Bill has made changes to the provisions addressing provisions relating to sensitive personal data, sharing (disclosure) of personal data, notification of breach of security, mandatory processing of data, security of personal data, and trans-border flows of personal data. The changes that have been made have been mapped out below.
The 2011 Bill and 2014 Bill both require authorization by the Authority for the collection and processing of sensitive personal data. At the same time, both Bills include a list of circumstances under which authorization for the collection and processing of sensitive personal data is not required. On the whole, this list is the same between the 2011 Bill and 2014 Bill, but the 2014 Bill adds the following circumstances on which authorization is not needed for the collection and processing of sensitive personal data:
The 2014 Bill also allows the Authority to specify additional regulations for sensitive personal data, and requires that any additional transaction sought to be performed with the sensitive personal information requires fresh consent to first be obtained. The 2014 Bill carves out another exception for Government agencies, allowing disclosure of sensitive personal data without consent to Government agencies mandated under law for the purposes of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution, and punishment of offences.
The provisions relating to the notification of breach of security in the 2014 Bill differ from the 2011 Bill. Specifically, the 2014 Bill removes the requirement that data controllers must publish information about a data breach in two national newspapers. Thus, in the 2014 Bill, data controllers must only inform the data protection authority and affected individuals of the breach.
The 2014 Bill changes the structure of the notice mechanism. In the 2011 Bill, prior to the processing of data, data controllers had to take all reasonable steps to ensure that the data subject was aware of the following:
In contrast, the 2014 Bill provides that before personal data is collected, the data controller must give notice of what data is being collected and the legitimate purpose for the collection. If the purpose for which the data was collected has changed, the data controller will then be obligated to provide the data subject with notice of:
Though titled as "sharing of personal data," both the 2011 Bill and 2014 Bill require consent for the disclosure of personal information, but list exceptional circumstances on which consent is not needed. In the 2011 Bill, the relevant provision permits disclosure of personal data without consent only if (i) the sharing was a part of the documented purpose, (ii) the sharing is for any purpose relating to the exceptions to the right to privacy, or (iii) the Data Protection Authority has authorized the sharing.
In contrast, the 2014 Bill permits disclosure of personal data without consent if (i) such disclosure is part of the legitimate purpose, (ii) such disclosure is for achieving any of the objectives of section 5, (iii) the Authority has by order authorized such disclosure, (iv) the disclosure is required under any law for the time being in force, or (v) the disclosure is made to the Government Intelligence agencies in the interest of the sovereignty, integrity, security or the strategic, scientific or economic interest of India. As a safeguard, the 2014 Bill requires that any person to whom personal information is disclosed, whether a resident or not, must adhere to all provisions of the Act. Furthermore, the disclosure of personal data must be limited to the extent which is necessary to achieve the purpose for which the disclosure is sought, and no person can make public any personal data that is in its control.
Though both the 2011 Bill and the 2014 Bill require any country that data is transferred to must have equivalent or stronger data protection standards in place, the 2014 Bill carves out an exception for law enforcement and intelligence agencies and the transfer of any personal data outside the territory of India, in the interest of the sovereignty, integrity, security or the strategic, scientific or economic interest of India.
Both the 2011 Bill and 2014 Bill have provisions that address the mandatory processing of data. These provisions are similar, but the 2014 Bill includes a requirement that data controllers must anonymize personal data that is collected without prior consent from the data subject within a reasonable time frame after collection.
The provision relating to the security of personal information in the 2014 Bill has been changed from the 2011 Bill by expanding the list and type of breaches that must be prevented, but removing requirements that data controllers must ensure all contractual arrangements with data processors specifically ensure that the data is maintained with the same level of security.
Both the 2011 Bill and 2014 Bill define conditions on which the provisions of updating personal data, access, notification of breach of security, retention of personal data, data quality, consent, choice, notice, and right to privacy will not apply to personal data. Though the 2011 Bill and 2014 Bill reflect the same conditions, the 2014 Bill carves out an exception for Government Intelligence Agencies, stating that the provisions of updating personal data, access to data by the data subject, notification about breach of security, retention of personal data, data quality, processing of personal data, consent, choice, notice, and collection from an individual will not apply to data collected or processed in the interest of the sovereignty, integrity, security or the strategic, scientific or economic interest of India.
Unlike the 2011 Bill, the 2014 Bill defines the role of the privacy officer that must be established by every data controller for the purpose of overseeing the security of personal data and implementation of the provisions of the Act.
Both the 2011 Bill and 2014 Bill contain provisions that enable the Authority to waive the applicability of specific provisions of the Act. The circumstances on which this can be done are based on the exceptions to the right to privacy in both the 2011 and 2014 Bill. To this extent, the 2014 Bill differs slightly from the 2011 Bill, by removing the power of the Authority to exempt for the "detection of crime" and "any other legitimate purpose mentioned in this Act."
The 2011 Bill and 2014 Bill both establish Data Protection Authorities, but the 2014 Bill further clarifies certain aspects of the functioning of the Authority and expands the functions and the powers of the Authority. For example, new functions of the Authority include:
The 2014 Bill also expands the powers of the Data Protection Authority, importantly giving it the power to receive, investigate complaints about alleged violations of privacy, and issue appropriate orders or directions. At the same time, the 2014 Bill carves out an exception for Government Intelligence Agencies and Law Enforcement agencies, preventing the Authority from conducting investigations, issuing appropriate orders or directions, and adjudicating complaints in respect to actions taken by the Government Intelligence Agencies and Law Enforcement, if for the objectives of (a) sovereignty, integrity or security of India, (b) strategic, scientific or economic interest of India, (c) preventing incitement to the commission of any offence, (d) prevention of public disorder, (e) the investigation of any crime, (f) protection of rights and freedoms of others, (g) friendly relations with foreign states, or (h) any other legitimate purpose mentioned in this Act. This power is instead vested with a court of competent jurisdiction.
The 2014 Bill removes the National Data Controller Registry and requirements for data controllers to register themselves and oversight of the Registry by the Data Protection Authority.
Both the 2011 and 2014 Bills contain provisions regulating the use of personal information for direct marketing purposes. Though the provisions are broadly the same, the 2011 Bill envisions that no person will undertake direct marketing unless he or she is registered in the "National Data Registry" and one of the stated purposes is direct marketing. As the 2014 Bill removes the National Data Registry, the 2014 Bill now requires that any person undertaking direct marketing must have on record where he or she has obtained personal data from.
Though maintaining some of the safeguards defined in the 2011 Bill for interception, the 2014 Bill changes the interception regime envisioned in the 2011 Bill by carving out a wide exception for organizations monitoring the electronic mail of employees, removing provisions requiring that interception take place only for the minimum period of time required for achieving the purposes, and removing provisions excluding the use of intercepted communications as evidence in a court of law. Similar to the 2011 Bill, the 2014 Bill specifies that the principles of notice, choice and consent, access and correction, and openness will not apply to the interception of communications.
Unlike the 2011 Bill, which addressed only the use of CCTVs, the 2014 Bill addresses the installation and use of video recording equipment in public places. Though both the 2011 Bill and 2014 Bill prevent the use of recording equipment and CCTVs for the purpose of identifying an individual, monitoring his personal particulars, or revealing personal information, or otherwise adversely affecting his right to privacy, the 2014 Bill requires that the use of recording equipment must be in accordance with procedures, for a legitimate purpose, and proportionate to the objective for which the equipment was installed.
The 2014 Bill makes a broad exception to these safeguards for law enforcement agencies and government intelligence agencies in the interest of the sovereignty, integrity, security or the strategic, scientific, or economic interest of India.
The 2014 Bill establishes a specific mechanism of self-regulation where industry associations will develop privacy standards and adhere to them. For this purpose, an industry ombudsman should be appointed. The standards must be in conformity with the National Privacy Principles and the provisions of the Privacy Bill. The developed standards will be submitted to the Authority, and the Authority may frame regulations based on the standards. If an industry association has not developed privacy standards, the Authority may frame regulations for a specific sector.
The 2014 Bill makes significant changes to the process for settling disputes from the 2011 Bill. In the 2014 Bill, an Alternative Dispute Mechanism is established where disputes between individuals and data controllers are first addressed by the Privacy Officer of each Data Controller or the industry-level Ombudsman. If individuals are not satisfied with the decision of the Ombudsman, they may take the complaint to the Authority. Individuals can also take the complaint directly to the Authority if they wish. If an individual is aggrieved with the decision of the Authority, by a privacy officer or ombudsman through the Alternative Dispute Resolution mechanism, or by the adjudicating officer of the Authority, they may approach the Appellate Tribunal. Any order from the Appellate Tribunal can be appealed at a High Court.
In the 2011 Bill, disputes between the data controller and an individual can be taken directly to the Appellate Tribunal, and orders from the Authority can be appealed at the Tribunal. There is no further path for appeal of an order of the tribunal.
The 2014 Bill changes the structure of the offences and penalties section by breaking the two into separate sections, one addressing offences and one addressing penalties, while the 2011 Bill addressed offences and penalties in the same section.
The 2014 Bill penalizes every offence with imprisonment and a fine, and empowers a police officer not below the rank of Deputy Superintendent of Police to investigate any offence. It limits the courts' ability to take cognizance of an offence to only those brought by the Authority, requires that the court be no lower than a Chief Metropolitan Magistrate or a Chief Judicial Magistrate, and permits courts to compound offences. The 2014 Bill further specifies that any offence that is punishable with three years in prison and above is cognizable, and offences punishable with three years in prison are bailable. Under the 2014 Bill, offences are defined as:
The offences defined under the Act are reflected in the 2011 Bill, but the time in prison and fine is higher in the 2014 Bill.
The 2014 Bill provides a list of penalties including:
These penalties reflect the penalties in the 2011 Bill, but prescribe higher fines.
Unlike the 2011 Bill, which did not have in place an adjudicating officer, the 2014 Bill specifies that the Chairperson of the Authority will appoint a member of the Authority not below the rank of Director of the Government of India to be an adjudicating officer. The adjudicating officer will have the power to impose a penalty and will have the same powers as vested in a civil court under the Code of Civil Procedure. Every proceeding before the adjudicating officer will be considered a judicial proceeding. When adjudicating, the officer must take into consideration the amount of disproportionate gain or unfair advantage, the amount of loss caused, and the respective nature of the default.
Both the 2011 and 2014 Bills contain provisions that permit an individual to pursue a civil remedy, but the 2014 Bill limits these instances to cases where loss or damage has been suffered or an adverse determination is made about an individual due to negligence in complying with the Act, and provides for the possibility that the contravening parties will have to provide a public notice of the offence.
The 2014 Bill removes provisions specifying that individuals who have suffered loss due to a contravention by the data controller of the Act are entitled to compensation.
Unlike the 2011 Bill, the 2014 Bill includes an exception for Government Intelligence Agencies and Law Enforcement Agencies, stating that the Authority will not have the power to conduct investigations, issue appropriate orders and directions, or otherwise adjudicate complaints in respect of action taken by the Government intelligence agencies and law enforcement agencies for achieving any of the objectives that reflect the defined exceptions to privacy.
The Centre for Internet and Society welcomes many of the changes that are reflected in the Privacy Bill 2014, but is cautious about the wide exceptions that have been carved out for law enforcement and intelligence agencies in the Bill.
In 2012, the Report of the Group of Experts on Privacy was developed for the purpose of informing a privacy framework for India. As such, the Centre for Internet and Society will be analysing in upcoming posts the draft Privacy Bill 2014 and the recommendations in the Report of the Group of Experts on Privacy.