--- layout: default title: "Open Letter to \"Not\" Recognize India as Data Secure Nation till Enactment of Privacy Legislation" description: "A June 2013 CIS open letter by Elonnai Hickok urging European Data Protection Commissioners not to recognise India as a data secure nation until it enacts comprehensive privacy legislation, prepared under the SAFEGUARDS project." authors: ["Elonnai Hickok"] categories: [Centre for Internet and Society, Elonnai Hickok] date: 2013-06-19 source: "Centre for Internet and Society" permalink: /elonnai/open-letter-to-not-recognize-india-as-data-secure-nation/ created: 2026-08-23 homepage_featured: true --- **"Open Letter to \"Not\" Recognize India as Data Secure Nation till Enactment of Privacy Legislation"** is an open letter by [Elonnai Hickok](/elonnai/) published by the [Centre for Internet and Society](/cis/) on 19 June 2013. It argues that India should not be granted "data secure nation" status by the European Union until it enacts comprehensive privacy legislation, and was sent to Data Protection Commissioners across Europe as part of the SAFEGUARDS project. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
📰 Published by:
Centre for Internet and Society
📅 Date:
19 June 2013
✍️ Author:
Elonnai Hickok
📄 Type:
Open letter
🔗 Original Link:
Read the original post
## Full Text

India shouldn't be granted the status of "data secure nation" by Europe until it enacts a suitable privacy legislation, points out the Centre for Internet and Society in this open letter.


This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC.


This letter is with regards to both the request from the Confederation of Indian Industry that the EU recognize India as a data secure nation made on April 29th 2013,1 and the threat from India to stall negotiations on the Free Trade Agreement with the EU unless recognized as data secure nation made on May 9th 2013.2

On behalf of the Centre for Internet and Society, we request that you urge the European Parliament and the EU ambassador to India to reject the request, and to not recognize India as a data secure nation until a privacy legislation has been enacted.

The Centre for Internet and Society believes that if Europe were to grant India status as a data secure nation based only on the protections found in the "Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011", not only will India be protected through inadequate standards, but the government will not have an incentive to enact a legislation that recognizes privacy as a comprehensive and fundamental human right. Since 2010 India has been in the process of realizing a privacy legislation. In 2011 the "Draft Privacy Bill 2011" was leaked.3 In 2012 the "Report of the Group of Experts on Privacy" was released. The Report recommends a comprehensive right to privacy for India, nine national privacy principles, and a privacy framework of co-regulation for India to adopt.4 In 2013 the need for a stand alone privacy legislation was highlighted by the Law Minister.5 The Centre for Internet and Society has recently drafted the "Privacy Protection Bill 2013" - a citizen's version of a possible privacy legislation for India.6 Currently, we are hosting a series of six "Privacy Roundtables" across India in collaboration with FICCI and DSCI from April 2013 - August 2013.7 The purpose of the roundtables is to gain public feedback to the text of the "Privacy Protection Bill 2013", and other possible frameworks for privacy in India. The discussions and recommendations from the meeting will be published into a compilation and presented at the Internet Governance meeting in October 2013.

The Center for Internet and Society will also be submitting the "Privacy Protection Bill 2013" and the public feedback to the Department of Personnel and Training (DoPT) with the hope of contributing to and informing a privacy legislation in India.

The Centre for Internet and Society has been researching privacy since 2010 and was a member of the committee which compiled the "Report of the Group of Experts on Privacy". We have also submitted comments on the "Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011" to the Committee on Subordinate Legislation of the 15th Lok Sabha.8

We hope that you will consider our request and urge the European Parliament and the EU ambassador to India to not recognize India as a data secure nation until a privacy legislation has been enacted.

Footnotes

  1. CII asks EU to accept India as 'Data Secure' nation: bit.ly/15Z77dH
  2. India threatens to stall trade talks with EU: bit.ly/1716aF1
  3. New privacy Bill: Data Protection Authority, jail term for offence: bit.ly/emqkkH
  4. The Report of the Group of Experts on Privacy: bit.ly/VqzKtr
  5. Law Minister Seeks stand along privacy legislation, writes PM: bit.ly/16hewWs
  6. The Privacy Protection Bill 2013 drafted by CIS: bit.ly/10eum5d
  7. Privacy Roundtable: bit.ly/12HYoj5
  8. Comments on the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data Information) Rules, 2011: bit.ly/Z2FjX6

Note: CIS sent the letters to Data Protection Commissioners across Europe.

{% include back-to-top.html %} ## Context and Background In June 2013, the Centre for Internet and Society (CIS) published an open letter by Elonnai Hickok addressed to Data Protection Commissioners across Europe, urging them not to grant India "data secure nation" status until the country enacted comprehensive privacy legislation. The letter was prepared under the SAFEGUARDS project undertaken jointly by CIS, Privacy International and IDRC, and was prompted directly by two developments in the preceding weeks: a request from the Confederation of Indian Industry on 29 April 2013 asking the European Union to recognise India as data secure, and a subsequent threat on 9 May 2013 that India would stall Free Trade Agreement negotiations with the EU unless that recognition was granted. The letter's central argument was that granting data secure status on the strength of India's existing "Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011" would be premature and counterproductive. Hickok argued that doing so would lock India into an inadequate data protection standard while removing the government's incentive to pass a more comprehensive privacy law recognising privacy as a fundamental human right. To support this argument, the letter traced the development of India's privacy law-making process since 2010, including the leaked Draft Privacy Bill of 2011, the 2012 Report of the Group of Experts on Privacy (which recommended nine national privacy principles and a co-regulatory framework), and a 2013 public call by the Law Minister for standalone privacy legislation. It also referenced CIS's own contribution to that process, a citizen-drafted "Privacy Protection Bill 2013," along with a concurrent series of six Privacy Roundtables being held across India between April and August 2013 in partnership with FICCI and DSCI to gather public feedback on the bill. The letter also noted CIS's involvement in privacy research since 2010, its membership on the committee that compiled the Report of the Group of Experts on Privacy, and its prior formal comments to the Committee on Subordinate Legislation of the 15th Lok Sabha on the 2011 IT Rules. A closing note on the original page records that CIS sent this letter to Data Protection Commissioners across Europe, rather than to a single recipient. ## External Link - [Open Letter to "Not" Recognize India as Data Secure Nation till Enactment of Privacy Legislation](https://cis-india.org/internet-governance/blog/open-letter-to-not-recognize-india-as-data-secure-nation) on CIS website {% include navbox-elonnai.html %}