On October 16, the Group of Experts on Privacy, Chaired by Mr. A. P. Shah, submitted its Report to the Planning Commission.  The Expert Group was appointed to set out the principles that Indian privacy law should abide by.   Even though privacy has been held to be a fundamental right as long back as in 1962, India does not have a law that specifies safeguards to privacy.  Moreover, recent government initiatives, such as the UID, involve collection of personal information and storage in electronic form.  The absence of a law on privacy increases the risk to infringement of the fundamental right. In this blog we list the recommendations made by the expert group, discuss the status of the right to privacy in India, and why there is a need for an enactment. Recommendations of the Expert Group on Privacy

  • The Expert Group recommended that the new legislation on privacy should ensure that safeguards are technology neutral.  This means that the enactment should provide protections that are applicable to information, regardless of the manner in which it is stored: digital or physical form.
  • The new legislation should protect all types of privacy, such as bodily privacy (DNA and physical privacy); privacy against surveillance (unauthorised interception, audio and video surveillance); and data protection.
  • The safeguards under the Bill should apply to both government and private sector entities.
  • There should be an office of a ‘Privacy Commissioner’ at both the central and regional level.
  • There should be Self-Regulating Organisations set up by the industry.  These organisations would develop a baseline legal framework that protects and enforces an individual’s right to privacy.  The standards developed by the organisations would have to be approved by the Commissioner.
  • The legislation should ensure that entities that collect and process data would be accountable for these processes and the use to which the data is put.  This, according to the Group, would ensure that the privacy of the data subject is guaranteed.

Present status of the Right to Privacy While the Supreme Court has held privacy to be a fundamental right, it is restricted to certain aspects of a person’s life.  These aspects include the privacy of one’s home, family, marriage, motherhood, procreation and child-rearing.  Therefore, to claim privacy in any other aspect, individuals have to substantiate these are ‘private’ and should not be subjected to state or private interference.  For instance, in 1996 petitioners had to argue before the Court that the right to speak privately over the telephone was a fundamental right. Risks to privacy Government departments collect data under various legislations.  For instance, under the Passport Act, 1967 and the Motor Vehicles Act, 1988 persons have to give details of their address, date of birth etc.  These enactments do not provide safeguards against access and use of the information by third parties.  Similarly, information regarding ownership of property and taxes paid are publicly available on the MCD website. Furthermore, recent government initiatives may increase the risk to infringement of privacy as personal information, previously only available in physical form, will now be available electronically.  Initiatives such as the National e-Governance Plan, introduced in 2006 and Aadhaar would require maintenance of information in electronic form.  The Aadhaar initiative aims at setting up a system for identifying beneficiaries of government sponsored schemes.  Under the initiative, biometric details of the beneficiaries, such as retina scan and fingerprints, are collected and stored by the government.  The government has also introduced a Bill in Parliament creating a right to electronic service delivery.  As per news reports, a draft DNA Profiling Bill is also in the pipeline.  

A few minutes ago, the Supreme Court delivered a  judgement striking down Section 66 A of the Information Technology Act, 2000.  This was in response to a PIL that challenged the constitutionality of this provision.  In light of this, we present a background to Section 66 A and the recent developments leading up to its challenge before the Court.  What does the Information Technology Act, 2000 provide for? The Information Technology (IT) Act, 2000 provides for legal recognition for transactions through electronic communication, also known as e-commerce.  The Act also penalizes various forms of cyber crime.  The Act was amended in 2009 to insert a new section, Section 66A which was said to address cases of cyber crime with the advent of technology and the internet. What does Section 66(A) of the IT Act say? Section 66(A) of the Act criminalises the sending of offensive messages through a computer or other communication devices.  Under this provision, any person who by means of a computer or communication device sends any information that is:

  1. grossly offensive;
  2. false and meant for the purpose of causing annoyance, inconvenience, danger, obstruction, insult, injury, criminal intimidation, enmity, hatred or ill will;
  3. meant to deceive or mislead the recipient about the origin of such messages, etc, shall be punishable with imprisonment up to three years and with fine

Over the past few years, incidents related to comments,  sharing of information, or thoughts expressed by an individual to a wider audience on the internet have attracted criminal penalties under Section 66(A).  This has led to discussion and debate on the ambit of the Section and its applicability to such actions. What have been the major developments in context of this Section? In the recent past, a few arrests were made under Section 66(A) on the basis of social media posts directed at notable personalities, including politicians.  These  were alleged to be offensive in nature.  In November 2012, there were various reports of alleged misuse of the law, and the penalties imposed were said to be disproportionate to the offence.  Thereafter, a Public Interest Litigation (PIL) was filed in the Supreme Court, challenging this provision on grounds of unconstitutionality.  It was said to impinge upon the freedom of speech and expression guaranteed by Article 19(1)(a) of the Constitution. How has the government responded so far? Subsequently, the central government issued guidelines for the purposes of Section 66(A).  These guidelines clarified that prior approval of the Deputy Commissioner or Inspector General of Police was required before a police officer or police station could register a complaint under Section 66(A).  In May 2013, the Supreme Court (in relation to the above PIL) also passed an order saying that such approval was necessary before any arrest is to be made.  Since matters related to police and public order are dealt with by respective state governments, a Supreme Court order was required for these guidelines to be applicable across the country.  However, no changes have been made to Section 66 A itself.  Has there been any legislative movement with regard to Section 66(A)? A Private Member Bill was introduced in Lok Sabha in 2013 to amend Section 66(A) of the IT Act.  The Statement of Objects and Reasons of the Bill stated that most of the offences that Section 66(A) dealt with were already covered by the Indian Penal Code (IPC), 1860. This had resulted in dual penalties for the same offence.  According to the Bill, there were also inconsistencies between the two laws in relation to the duration of imprisonment for the same offence.  The offence of threatening someone with injury through email attracts imprisonment of two years under the IPC and three years under the IT Act.  The Bill was eventually withdrawn. In the same year, a Private Members resolution was also moved in Parliament.  The resolution proposed to make four changes: (i) bring Section 66(A) in line with the Fundamental Rights of the Constitution; (ii) restrict the application of the provision to communication between two persons; (iii) precisely define the offence covered; and (iv) reduce the penalty and make the offence a non-cognizable one (which means no arrest could be made without a court order).  However, the resolution was also withdrawn. Meanwhile, how has the PIL proceeded? According to news reports, the Supreme Court  in February, 2015 had stated that the constitutional validity of the provision would be tested, in relation to the PIL before it.  The government argued that they were open to amend/change the provision as the intention was not to suppress freedom of speech and expression, but only deal with cyber crime.  The issues being examined by the Court relate to the powers of the police to decide what is abusive, causes annoyance, etc,. instead of the examination of the offence by the judiciary .  This is pertinent because this offence is a cognizable one, attracting a penalty of at least three years imprisonment.  The law is also said to be ambiguous on the issue of what would constitute information that is “grossly offensive,” as no guidelines have been provided for the same.  This lack of clarity could lead to increased litigation. The judgement is not available in the public domain yet. It remains to be seen on what the reasoning of the Supreme Court was, in its decision to strike down Section 66A, today.