IAPP-GDPR Web Banners-300x250-FINAL

Ponnurangam Kumaraguru, Sunil Mehta and Nandkumar Saravade

As India becomes a leader in Business Process Outsourcing (BPO), increasing amounts of personal information from other countries are flowing into the country. India's outsourcing business is expected to grow to $20 billion and employ about 2 million people by 2008. Questions have been raised about the ability of Indian companies to adequately protect this information.

There are legal remedies in India to address issues of privacy violations despite the absence of an all-encompassing privacy law in India. The right to privacy is included in the country's Constitution, and upheld in a Supreme Court judgment as well. In addition, industries such as accountancy and law have Self-Regulatory Organizations (SRO) with a prescribed code of conduct, and recently, the telecom and banking industries have set up SROs, which have codes for handling customer data. The IT and BPO industries also are close to setting up an SRO.

As mentioned by Dr. Amartya Sen in his book, "Argumentative Indian," there is a long history of success for public reasoning in the democratic society in India. Accordingly, the National Association of Software Services Companies (NASSCOM) decided to create a public debate and reasoning on privacy topics in India. One of the first efforts was to plan a research study during summer 2006 to initiate a discussion among different stakeholders in the privacy space in India and to bring the group together to plan for a road map for the privacy discussions.

One-on-One Discussions with the Stakeholders

The group was comprised of attorneys, technologists, journalists, activists, entrepreneurs and government employees. Ponnurangam Kumaraguru met with stakeholders from different parts of India who have written or worked in the area of privacy. This was a one-on-one interview which lasted for about 60 to 90 minutes. Kumaraguru, a representative of NASSCOM, met with two or three participants in each group. The topics that we discussed with the participants of the study were: their understanding of privacy and related topics in the Indian context; privacy laws or frameworks in India; and their views on the Information Technology ACT (IT ACT) 2000. The participants interviewed echoed these themes:

  • There is no common definition of privacy in India. Most participants agreed that there should be a working definition of privacy which is accepted in the court, organizations, public, etc.
  • The general public is not aware of their rights toward its information and data protection.
  • The group should work toward a framework for protection of the personal information of Indian citizens among Indian and foreign organizations. There are legal remedies for privacy breaches in India but they are not codified in one single place. For example remedies can be provided by Indian Contract Act, 1872; Indian Penal code, 1960; Special Relief Act, 1963; Consumer Protection Act, 1986; and the IT ACT 2000.

Most of the study participants interviewed agreed there was a need for a privacy framework for India. The next step was to gather the participants for a roundtable discussion.

Roundtable Discussion Held in Early August

Twenty-two participants from all over India gathered on Aug. 8, 2006 in Mumbai, India. Most of the participants were from organizations which have global presence, such as IBM, Microsoft, eBay, KPMG, TCS, Cognizant, Ernst & Young, WNS and others. Attorneys, journalists, activists and government employees also attended the session. While the group represented a broad array of stakeholders in the privacy community, it was not all-encompassing of the entire privacy community in India.

The summary of the roundtable discussion:

  • While defining privacy, there were many different definitions among the participants. Most of the participants agreed on "Privacy is a right of an individual to restrict the use of the personal information other than the intended purpose by the collecting or the holding party."
  • Participants agreed that the de facto should be "everything is private unless I choose it not to be private" and privacy is contextual and subjective.
  • When asked to list what information comprises PII, participants felt that the list is subjective and contextual and so one cannot derive a list that can be used in all situations. Therefore, the list only can be a working one.
  • Twenty of the 22 participants chose for opt-in against opt-out choice if the information collected for some purpose is then used for purposes other than the reason for which it was initially collected. It was not entirely clear why the two participants favored opt-out.
  • Participants agreed that the government should not be excluded from the purview of any privacy framework. Participants said that the government agencies can share information among other agencies after obtaining necessary permissions.

There never has been an effort in India to bring different stakeholders together for a discussion about privacy. NASSCOM is proud of its role in initiating the discussions about privacy in India. To date, this effort has been an exploratory one, but this early framework has given NASSCOM and other stakeholders the opportunity to launch additional focused discussions in the context of privacy. As there is no single community discussing privacy issues in India, the roundtable provided an opportunity for participants to network with people thinking or working in the same area.

Some of the future steps planned are:

  • To continue the discussion on the privacy framework started in the roundtable, NASSCOM has created a Privacy-India Yahoo! groups. This will help us in exchanging ideas online, and if necessary, members will meet offline.
  • With respect to growing the privacy community and creating the privacy framework, we plan to conduct a future Workshop on "Privacy in India."
  • To network and collaborate with other organizational bodies and stakeholders in India.

For further information on the research and to contribute towards the privacy discussions in India, please contact Ponnurangam Kumaraguru (PK), ponguru@cs.cmu.edu

Ponnurangam Kumaraguru is a PhD. student in the COS (Computation Organization and Society) program with the School of Computer Science at Carnegie Mellon University. His research interests include building system to educate users to make better trust decisions, trust modeling and international privacy issues (specifically in India). He spent the summer 2006 as an intern at National Association for Software Services and Companies (NASSCOM), India. He can be reached at ponguru@cs.cmu.edu

Sunil Mehta holds the position of Vice President at NASSCOM. In his role, Mehta is responsible for spearheading NASSCOM's research initiatives. He also oversees NASSCOM's international public affairs and public relations. Mehta has a Bachelor's in Commerce from Mumbai University and a Master's in Business Administration from IIM, Ahmedabad. He can be reached at sunil@nasscom.org

Nandkumar Saravade is the Director of cyber security and compliance at NASSCOM. Nandkumar is an Indian Police Service (IPS) officer. He specializes in cybercrime issues. He is handling NASSCOM's outreach program on cyber security, focusing on law enforcement capacity building on cybercrime response and enhancing information security awareness for different IT user groups. He holds a post-graduate degree in Environmental Engineering from the IIT, Mumbai. He can be reached at saravade@nasscom.org


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»