Information Technology Law
Subjects / Information Technology Law / Violation of Privacy and Data Protection
Unit 5 · Unit 5

Violation of Privacy and Data Protection

Privacy on the internet encompasses the right of individuals to control their personal information in the digital environment.

Privacy on the internet encompasses the right of individuals to control their personal information in the digital environment. Data protection is the legal framework governing how personal data is collected, processed, stored, and shared. The right to privacy is a fundamental right under Art.21 (post-Puttaswamy, 2017).

Legal Framework

Provision Subject
Art.21 Constitution Right to life and personal liberty (includes privacy: Puttaswamy)
IT Act S.43A Body corporate: reasonable security practices for sensitive personal data
IT Act S.66E Violation of privacy (publishing private images)
IT Act S.69 Government power: interception/monitoring/decryption
IT Act S.69A Power to block websites (privacy vs. state interest)
IT Act S.72 Breach of confidentiality (information obtained under IT Act)
IT Act S.72A Disclosure of personal information in breach of contract
DPDP Act 2023 Comprehensive data protection framework
IT (SPDI) Rules 2011 Sensitive personal data: body corporate obligations (still operative until DPDP rules notified)

Right to Privacy as Fundamental Right

Puttaswamy Framework (2017)

Principle Content
Status Privacy is intrinsic part of Art.21 (life, liberty, dignity)
Components (1) Bodily privacy, (2) Informational privacy, (3) Privacy of choice
Not absolute Subject to reasonable restrictions
Triple test Any interference must satisfy: (a) Legality (prescribed by law), (b) Legitimate aim (state interest), (c) Proportionality (means proportionate to aim)
Overrules MP Sharma (1954) and Kharak Singh (1963) minority view: privacy IS a fundamental right

Why: In the digital age, informational privacy (control over personal data) is the most threatened dimension. Every online transaction generates data that can be aggregated, profiled, and misused. Constitutional protection ensures state and private actors cannot violate data privacy without legal basis, legitimate purpose, and proportionate means.

Illustration: DPDP Act in Everyday Life

Scenario: You download a food delivery app. During signup, it asks for: name, phone, address, location access.

| What App Does | DPDP Act Position | |:--|:--|:--| | Uses your address to deliver food | Lawful (purpose you consented to) | | Uses your location to show nearby restaurants | Lawful (necessary for stated purpose) | | Shares your phone number with insurance companies for cold-calling | Unlawful purpose limitation violated (S.5); you consented for food delivery, not insurance marketing | | Stores your data for 5 years after you delete your account | Unlawful storage limitation violated; data must be erased when purpose no longer served | | You request deletion of your account + all data | Your right to erasure (S.12); app must comply unless retention is required by law (e.g., tax records) | | App suffers a data breach exposing 1 lakh users' details | App must notify Data Protection Board + affected users (S.8(6)); failure → up to Rs.250 crore penalty |

Key takeaway: Every time you share data with an app/website, ask: "What did I consent to?" If the entity uses data beyond that purpose → DPDP violation.

Digital Personal Data Protection Act, 2023

Key Concepts

Term Meaning
Data Principal Individual whose data is collected (equivalent to "data subject" in GDPR)
Data Fiduciary Entity that determines purpose and means of processing (equivalent to "data controller")
Significant Data Fiduciary (SDF) High-risk fiduciary designated by government (additional obligations)
Consent Manager Registered entity facilitating consent management for Data Principals
Data Processor Entity processing data on behalf of Data Fiduciary
Personal Data Any data about an individual identifiable by or in relation to such data
Data Protection Board of India Adjudicatory body for complaints and breaches

Principles

Principle Content
Consent-based processing Data processed only with free, specific, informed, clear consent (S.6)
Purpose limitation Data collected only for specified, lawful purpose (S.5)
Data minimization Only data necessary for stated purpose collected
Storage limitation Data retained only as long as necessary for purpose
Accuracy Data Fiduciary must ensure data is accurate and complete
Security Reasonable security safeguards to prevent breach (S.8)
Accountability Fiduciary responsible for compliance; must demonstrate compliance

Rights of Data Principal (S.11-14)

Right Content
Right to access Know what data is being processed and how
Right to correction and erasure Correct inaccurate data; erase data no longer necessary
Right to grievance redressal Complain to Data Fiduciary and Data Protection Board
Right to nominate Nominate person to exercise rights in case of death/incapacity

Obligations of Data Fiduciary (S.8-10)

Obligation Content
Obtain valid consent (S.6) Before or at time of collection
Give notice (S.5) Inform Data Principal of: data collected, purpose, rights, grievance mechanism
Implement security safeguards (S.8) Reasonable security to prevent breach
Report breaches (S.8(6)) Notify Data Protection Board and affected Data Principals
Erase on request (S.12) Unless retention required by law
Additional for SDF (S.10) Data Protection Impact Assessment, DPO appointment, independent audit

Penalties

Contravention Maximum Penalty
Failure to take security safeguards leading to breach Rs.250 crores
Failure to notify breach Rs.200 crores
Non-compliance with children's data provisions Rs.200 crores
Non-compliance with additional SDF obligations Rs.150 crores
Non-compliance by Data Principal (false complaints, etc.) Rs.10,000
Any other contravention Rs.50 crores

Violations of Privacy on Internet

Type of Violation Description Provision
Unauthorized surveillance Monitoring online activity without consent or legal authority Art.21 (Puttaswamy triple test) + S.69 IT Act (lawful interception)
Data breach Unauthorized access to personal data stored by organizations S.43A IT Act + DPDP Act S.8
Voyeurism Capturing/publishing intimate images without consent S.66E IT Act (3 years + Rs.2 lakhs)
Doxing Publishing personal information (address, phone) online without consent S.72A IT Act + tort of invasion of privacy
Profiling Automated processing to evaluate personal aspects (behavior, preferences) DPDP Act: requires consent + purpose limitation
Dark patterns Deceptive UI design to trick users into sharing more data DPDP Act + Consumer Protection Act
Cookie tracking Monitoring browsing behavior through persistent cookies DPDP Act consent requirements

Recall Check

  1. What is the triple test for interference with privacy under Puttaswamy?
  2. What is the maximum penalty under DPDP Act for failure to prevent a data breach?
  3. What is the difference between Data Fiduciary and Data Processor?

Key Cases

KS Puttaswamy v. Union of India (2017) KS-Puttaswamy-v-Union-of-India-2017 Issue: Whether the right to privacy is a fundamental right under the Constitution of India. Rule: Privacy is an intrinsic part of the right to life and personal liberty under Art.21; includes informational privacy, bodily privacy, and privacy of choice; subject to proportionality test. Held: 9-judge bench unanimously declared privacy a fundamental right. Triple test established: legality, legitimate aim, proportionality. Foundation for all subsequent data protection legislation.

KS Puttaswamy v. Union of India (Aadhaar) (2018) KS-Puttaswamy-v-Union-of-India-Aadhaar-2018 Issue: Whether the Aadhaar scheme (biometric identification linked to services) violates the right to privacy. Rule: State surveillance/data collection must pass proportionality test; purpose limitation and data minimization are constitutional requirements; linking Aadhaar to bank accounts/PAN is proportionate but linking to school admission/mobile numbers is disproportionate. Held: Supreme Court (4:1) upheld Aadhaar's constitutional validity but struck down: S.57 (use by private entities), mandatory linking to bank accounts for non-welfare purposes, and mandatory mobile linking. Proportionality applied section by section.

Distinctions

Aspect IT Act S.43A (Pre-DPDP) DPDP Act, 2023
Scope Only body corporates handling sensitive personal data All Data Fiduciaries processing digital personal data
Trigger Negligence in security practices causing wrongful loss Any non-compliance with data protection principles
Penalty Compensation (determined by Adjudicating Officer) Up to Rs.250 crores per breach
Rights No explicit data principal rights Comprehensive rights (access, correction, erasure, grievance)
Consent framework Reasonable security practices + privacy policy Specific, informed, free consent; consent managers
Regulator Adjudicating Officer (IT Act) Data Protection Board of India
Applicability Sensitive personal data only All personal data (digital)
Extra-territorial Not explicit Applies to processing outside India if offering goods/services to Indians

Flashcards

Q: What are the three components of the right to privacy (Puttaswamy)? A: (1) Bodily privacy (physical integrity), (2) Informational privacy (control over personal data), (3) Privacy of choice (autonomy in personal decisions).

Q: What is the maximum penalty under DPDP Act for security breach? A: Rs.250 crores.

Q: What is a Data Fiduciary under DPDP Act? A: Any person who alone or in conjunction with other persons determines the purpose and means of processing personal data.

Q: What is the triple test for privacy interference (Puttaswamy)? A: (1) Legality: interference prescribed by law, (2) Legitimate aim: serves a state interest, (3) Proportionality: means used are proportionate to the aim pursued.

Q: What is S.66E IT Act? A: Violation of privacy: intentionally capturing, publishing, or transmitting the image of a private area of any person without consent. Punishment: 3 years + Rs.2 lakhs.

Q: What did the Aadhaar judgment (2018) strike down? A: S.57 Aadhaar Act (use by private entities), mandatory linking to bank accounts for non-welfare schemes, and mandatory mobile number linking. Found disproportionate.

Q: What are the rights of a Data Principal under DPDP Act 2023? A: Right to access information about processing, right to correction and erasure, right to grievance redressal, right to nominate (in case of death/incapacity).

Q: What is a Significant Data Fiduciary (SDF)? A: A Data Fiduciary designated by government based on volume/sensitivity of data processed; subject to additional obligations: Data Protection Impact Assessment, Data Protection Officer appointment, independent audit.

Exam Scenario

A social media company collects detailed user data (location, browsing history, contacts) and shares it with advertisers without explicit user consent. A user discovers this and files a complaint. Advise on rights and remedies under the DPDP Act 2023.

Under DPDP Act 2023: (1) The social media company is a Data Fiduciary (determines purpose/means of processing). (2) Sharing data with advertisers without consent violates S.6 (consent-based processing) and S.5 (purpose limitation: data collected for social media use, not advertising). (3) User's rights: Right to access (S.11): demand disclosure of what data is shared and with whom. Right to erasure (S.12): demand deletion of data shared with advertisers. Right to grievance redressal (S.13): complain to the company's grievance officer; if unresolved, escalate to Data Protection Board. (4) Penalty: Up to Rs.250 crores if security safeguards inadequate; up to Rs.50 crores for general non-compliance with consent/purpose requirements. (5) Additionally: if the sharing caused wrongful loss, S.43A IT Act (compensation for negligent security practices). (6) Constitutional claim: violation of Art.21 right to informational privacy (Puttaswamy): collection beyond stated purpose fails proportionality test. The user has strong grounds for both regulatory complaint and civil action.