On October 16, the Group of Experts on Privacy, Chaired by Mr. A. P. Shah, submitted its Report to the Planning Commission.  The Expert Group was appointed to set out the principles that Indian privacy law should abide by.   Even though privacy has been held to be a fundamental right as long back as in 1962, India does not have a law that specifies safeguards to privacy.  Moreover, recent government initiatives, such as the UID, involve collection of personal information and storage in electronic form.  The absence of a law on privacy increases the risk to infringement of the fundamental right. In this blog we list the recommendations made by the expert group, discuss the status of the right to privacy in India, and why there is a need for an enactment. Recommendations of the Expert Group on Privacy

  • The Expert Group recommended that the new legislation on privacy should ensure that safeguards are technology neutral.  This means that the enactment should provide protections that are applicable to information, regardless of the manner in which it is stored: digital or physical form.
  • The new legislation should protect all types of privacy, such as bodily privacy (DNA and physical privacy); privacy against surveillance (unauthorised interception, audio and video surveillance); and data protection.
  • The safeguards under the Bill should apply to both government and private sector entities.
  • There should be an office of a ‘Privacy Commissioner’ at both the central and regional level.
  • There should be Self-Regulating Organisations set up by the industry.  These organisations would develop a baseline legal framework that protects and enforces an individual’s right to privacy.  The standards developed by the organisations would have to be approved by the Commissioner.
  • The legislation should ensure that entities that collect and process data would be accountable for these processes and the use to which the data is put.  This, according to the Group, would ensure that the privacy of the data subject is guaranteed.

Present status of the Right to Privacy While the Supreme Court has held privacy to be a fundamental right, it is restricted to certain aspects of a person’s life.  These aspects include the privacy of one’s home, family, marriage, motherhood, procreation and child-rearing.  Therefore, to claim privacy in any other aspect, individuals have to substantiate these are ‘private’ and should not be subjected to state or private interference.  For instance, in 1996 petitioners had to argue before the Court that the right to speak privately over the telephone was a fundamental right. Risks to privacy Government departments collect data under various legislations.  For instance, under the Passport Act, 1967 and the Motor Vehicles Act, 1988 persons have to give details of their address, date of birth etc.  These enactments do not provide safeguards against access and use of the information by third parties.  Similarly, information regarding ownership of property and taxes paid are publicly available on the MCD website. Furthermore, recent government initiatives may increase the risk to infringement of privacy as personal information, previously only available in physical form, will now be available electronically.  Initiatives such as the National e-Governance Plan, introduced in 2006 and Aadhaar would require maintenance of information in electronic form.  The Aadhaar initiative aims at setting up a system for identifying beneficiaries of government sponsored schemes.  Under the initiative, biometric details of the beneficiaries, such as retina scan and fingerprints, are collected and stored by the government.  The government has also introduced a Bill in Parliament creating a right to electronic service delivery.  As per news reports, a draft DNA Profiling Bill is also in the pipeline.  

Recently, there have been instances of certain collective investment schemes (CISs) attempting to circumvent regulatory oversight.  In addition, some market participants have not complied with Securities and Exchange Board of India's (SEBI) orders of payment of penalty and refund to investors. In August, the Securities Laws (Amendment) Bill, 2013 was introduced in the Lok Sabha to amend the Securities and Exchange Board of India Act, 1992 (the SEBI Act, 1992), the Securities Contract (Regulation) Act, 1956 (SCRA, 1956) and the Depositories Act, 1996. The Bill replaced the Securities Laws (Amendments) Ordinance, 2013. The Bill makes the following key amendments: a) Definition of Collective Investment Schemes The SEBI Act, 1992 defines CISs as schemes in which the funds of investors are pooled, yield profits or income and are managed on behalf of investors.  It also exempts certain types of investments which are regulated by other authorities. The Bill introduces a proviso to the definition of CIS.  This proviso deems any scheme or arrangement to be a CIS if it meets all three of the following conditions: (a) funds are pooled, (b) it is not registered with SEBI, or it is not exempted by SEBI Act, 1992, and (c) it has a corpus of Rs 100 crore or more.  These provisions could potentially lead to some schemes not conventionally defined as CIS to fall under the definition. For instance, partnership firms operating in the investment business or real estate developers accepting customer advances could be termed as CISs. SEBI has been given the power to specify conditions under which any scheme or arrangement can be defined as a CIS. This raises the question of whether this is excessive delegation of legislative powers - usually the parent act defines the entities to be regulated and the details are entrusted to the regulator. b) Disgorgement (repayment) of unfair gains/ averted losses SEBI has in the past issued orders directing market participants to refund i) profits made or ii) losses averted, through unfair actions.  The Bill deems SEBI to have always had the power to direct a market participant to disgorge unfair gains made/losses averted, without approaching a court.  This power to order disgorgement without approaching a court is in contrast with the provisions of the recently passed Companies Bill, 2011 and the draft Indian Financial Code (IFC) which require an order from a court/tribunal for disgorgement of unfair gains. Further, the Bill specifies that the disgorged amount shall be credited to the Investor Education and Protection Fund (IEPF), and shall be used in accordance with SEBI regulations.  The Bill does not explicitly provide the first right on the disgorged funds to those who suffered wrongful losses due to the unfair actions, unlike the draft IFC. c) Investigation and prosecution The Bill empowers the SEBI chairman to authorise search and seizure operations on a suspect’s premises.  This does away with the current requirement of permission from a Judicial Magistrate.  This provision removes the usual safeguards regarding search and seizure as seen in the Code of Criminal Procedure, 1973, the recently passed Companies Bill, 2011 and the draft Indian Financial Code. The Bill also empowers an authorised SEBI officer to, without approaching a court, attach a person’s bank accounts and property and even arrest and detain the person in prison for non-compliance of a disgorgement order or penalty order.  Most regulators and authorities, with the exception of the Department of Income Tax, do not have powers to such an extent. d) Other Provisions of the Bill The Bill retrospectively validates consent guidelines issued by SEBI in 2007 under which SEBI can settle non-criminal cases through consent orders, i.e., parties can make out-of-court settlements through payment of fine/compensation.  The United States Securities and Exchange Commission settles over 90% of non-criminal cases by consent orders. The Bill retrospectively validates the exchange of information between SEBI and foreign securities regulators through MoUs. The Bill sets up special courts to try cases relating to offences under the SEBI Act, 1992. For a PRS summary of the Bill, here.