Data protection law.
Data Protection Law
Data protection law is the body of legal rules that regulates how personal information is collected, stored, used, disclosed, transferred, and deleted. Its main purpose is to protect individuals from misuse of their personal data while allowing organisations, businesses, employers, and governments to process information for legitimate purposes.
Personal data may include a person's name, address, telephone number, email address, identification details, financial information, employment records, photographs, online identifiers, location information, and other information that can identify an individual.
1. Objectives of Data Protection Law
The major objectives are:
- Protection of privacy – Individuals should have control over information relating to them.
- Lawful processing – Organisations should have a valid legal basis for collecting and using personal data.
- Transparency – Individuals should know what information is collected and why.
- Purpose limitation – Data should generally be used only for legitimate and specified purposes.
- Data minimisation – Organisations should avoid collecting unnecessary personal information.
- Accuracy – Personal information should be accurate and kept up to date.
- Security – Appropriate technical and organisational safeguards should protect data.
- Accountability – Organisations must be able to demonstrate compliance with data-protection obligations.
2. Important Principles
A. Lawfulness, Fairness and Transparency
Personal data should be processed fairly and on a lawful basis. Individuals should receive understandable information about the processing of their data.
B. Purpose Limitation
Data collected for one legitimate purpose should not ordinarily be used for an unrelated purpose without an appropriate legal justification.
C. Data Minimisation
Only information reasonably necessary for the intended purpose should be collected. For example, an employer should not collect excessive personal information from an employee merely because it might be useful in the future.
D. Accuracy
Organisations should take reasonable steps to ensure that personal information is correct. Incorrect records can cause serious consequences in employment, banking, insurance and public services.
E. Storage Limitation
Personal data should not normally be retained indefinitely. Organisations should establish appropriate retention periods and securely dispose of information when it is no longer required.
F. Security and Confidentiality
Organisations must protect personal data against unauthorised access, loss, destruction, alteration and disclosure. Security measures may include access controls, encryption, authentication, backups and employee training.
G. Accountability
The organisation responsible for processing data should be able to demonstrate that it follows applicable data-protection requirements.
3. Rights of Individuals
Depending on the applicable legal framework, individuals may have rights such as:
- Right to be informed about data processing.
- Right to access personal information.
- Right to correct inaccurate information.
- Right to request deletion in appropriate circumstances.
- Right to restrict certain processing.
- Right to object to certain processing.
- Right to data portability in applicable situations.
- Rights concerning automated decision-making and profiling.
- Right to seek remedies for unlawful processing.
4. Data Protection in Employment
Data protection is particularly important in the employment relationship because employers routinely possess large amounts of employee information, including:
- Recruitment applications.
- Identity and contact details.
- Salary and payroll information.
- Attendance records.
- Performance assessments.
- Disciplinary records.
- Medical or other sensitive information.
- CCTV and access-control records.
- Email and internet-use information.
Employers should have a legitimate reason for collecting such information and should limit access to authorised personnel.
5. Sensitive and Special Categories of Data
Some information receives stronger protection because misuse could seriously affect an individual. Depending on the applicable law, this may include health information, biometric information, genetic information, information concerning racial or ethnic origin, religious beliefs, political opinions and other particularly sensitive categories.
Processing such information may require additional legal conditions and safeguards.
6. Data Breaches
A data breach occurs when personal information is accidentally or unlawfully destroyed, lost, altered, disclosed or accessed without authorisation.
Examples include:
- Hacking of an employee database.
- Sending salary information to the wrong person.
- Losing a laptop containing employee records.
- Unauthorised access to customer information.
- An ex-employee copying confidential data.
- Disclosure of personal information through an unsecured website.
Depending on the applicable law, organisations may have obligations to investigate, contain, document and notify authorities or affected individuals about serious breaches.
Important Case Laws
1. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
The Supreme Court of India recognised privacy as a fundamental right under the Constitution. The judgment established that privacy includes protection of personal autonomy and informational privacy.
Importance: It provides a constitutional foundation for protecting personal data and privacy in India.
2. District Registrar and Collector, Hyderabad v. Canara Bank (2005)
The Supreme Court considered the protection of privacy in relation to access to documents and banking information.
Importance: The case recognised that privacy interests can extend to confidential financial and personal information.
3. People's Union for Civil Liberties v. Union of India (1997)
The Supreme Court dealt with telephone interception and held that interception of communications affects an individual's right to privacy.
Importance: It established safeguards against arbitrary interception and demonstrated the importance of privacy in communications.
4. R. Rajagopal v. State of Tamil Nadu (1994)
The Supreme Court recognised aspects of an individual's right to privacy and considered the publication of private information without consent.
Importance: The case helped establish privacy as an important constitutional and legal interest in India.
5. K.S. Puttaswamy (Retd.) v. Union of India — Aadhaar Case (2018)
The Supreme Court examined the relationship between Aadhaar, personal information and the constitutional right to privacy. The Court applied the principles of legality, legitimate state purpose and proportionality when considering restrictions on privacy.
Importance: The judgment is highly significant for government collection and use of personal data.
6. Selvi v. State of Karnataka (2010)
The Supreme Court considered involuntary techniques such as narco-analysis, polygraph examinations and brain-mapping.
Importance: The judgment emphasised personal autonomy, privacy and protection against compelled intrusion into an individual's mental processes.
7. PUCL v. Union of India — Telephone Tapping Case (1997)
The Court imposed procedural safeguards concerning telephone interception.
Importance: It demonstrates that even when the State has legitimate security interests, interference with privacy must operate within legal safeguards.
8. Google Spain SL, Google Inc. v. Agencia Española de Protección de Datos (2014)
The Court of Justice of the European Union considered whether individuals could request removal of certain search-engine results concerning them.
Importance: The case became a landmark authority concerning data protection, online privacy and the right to be forgotten.
9. Digital Rights Ireland Ltd v. Minister for Communications (2014)
The Court of Justice of the European Union examined legislation requiring retention of telecommunications data.
Importance: The Court stressed that large-scale retention of communications data can seriously interfere with privacy and data-protection rights and must satisfy strict requirements.
10. Schrems v. Data Protection Commissioner (2015)
The European Union Court considered the transfer of personal data from the EU to the United States and the adequacy of privacy protection.
Importance: The case demonstrated the importance of adequate safeguards when personal data is transferred internationally.
Conclusion
Data protection law creates a framework for balancing individual privacy with legitimate organisational and governmental needs. It requires personal information to be collected and processed responsibly, securely and transparently. Modern data protection is especially important because organisations increasingly use cloud computing, artificial intelligence, employee-monitoring systems, biometric technology and large-scale data analytics.
In India, the constitutional right to privacy recognised in Justice K.S. Puttaswamy v. Union of India provides an important foundation for data-protection principles, while statutory data-protection legislation further regulates the processing and protection of personal data.

comments