Disclaimer

By clicking, "I Accept" below, you accept and acknowledge the following:

The purpose of this website is to provide general information and insights about TLH, Advocates & Solicitors, and not to advertise or solicit work in any manner whatsoever.

Please note that as per the Bar Council of India Rules, advocates in India are prohibited from advertising or soliciting work in any form or manner. You acknowledge that you are visiting this website at your discretion and that there has been no solicitation, invitation, or inducement of any sort whatsoever from TLH, Advocates & Solicitors or any of its professionals in relation to this website.

The content available on this website does not constitute legal or other professional advice and should not be substituted for advice relevant to particular circumstances.

The access and use of this website does not establish any fiduciary or other relationship between you and TLH, Advocates & Solicitors or any of its advocates.

Please read the ‘Terms of Use’ and our ‘Privacy Policy’ before accessing this website.

Blog default background
Blog
Corporate Law

Compliance with Data Protection during COVID-19

Authors:
Atif Ahmed
January 1, 2021
•
5 min read
Share this post
Copied!

Introduction

The Central Government, on March 24, 2020 issued a nation-wide lockdown to slow down the spread of COVID-19. India has been relaxing the measures of the lockdown with ‘Unlock 1.0’ by allowing private offices and other establishments to operate at full capacity. With increased movement of labour, the government, along with employers including corporates and non-governmental organisations, has been burdened with the task of restricting the spread of COVID-19. Employers have had to undertake certain measures like tracking their employees and collecting their health data.

While it is important to implement protocols like monitoring temperature, collecting travel history, documenting symptoms and contact tracing employees, it is also imperative for the employers to balance such actions with their employees’ right to privacy. In this context, the article seeks to examine the data protection regime in India and address the ‘balance’ that employers are bound to maintain.

Legislative Background

Currently in India, the Information Technology Act, 2000 (“ITA”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) govern the data protection regime. The law is applicable to any company, firm, sole proprietorship, and associations of individuals involved in professional/commercial activities. The definition of SPDI includes “physical, physiological, and mental health condition” and “medical records and history”.[1]

In Justice Puttaswamy (Retd.) and Another V. Union of India and Others[2],the Supreme Court held that that right to privacy is a fundamental right to uphold the right to life and personal liberty enshrined under Article 21 of the Constitution of India. The Supreme Court also stated that this right is not absolute and may be curtailed if certain criteria are met.[3] It is relevant to note that no special exemption for complying with privacy regulations has been granted by the Central Government for the duration of the COVID-19 pandemic.

Application of Law

Collection and processing of SPDI attracts a higher level of regulation and it is compulsory for employers to comply with ITA and SPDI Rules when doing so. Under the existing data protection regime, data collection must be as prescribed under a specific privacy policy,[4] The purpose for such collection of SPDI and its consequent terms of use must be intimated[5] and informed consent of the concerned individual must be taken.[6] Furthermore, it is mandatory for employers to implement ’reasonable security practices and procedures’. The said security practices and procedures must be appropriate with the nature and extent of the activities undertaken by the employer. The most commonly followed standard is  the International Standard IS/ISO/IEC 270001 and ISO/IEC 27035, which is the international standard for information security management. In a case where another standard is being followed, the same needs the approval of the Central Government, after which its implementation has to be certified by independent auditors.[7]

Practical Considerations

The abovementioned protocols must be adhered to by the employers to ensure that the ITA and SPDI Rules are not violated, and the employees’ right to privacy is not infringed. In the absence of the specific guidelines by the Central Government, an employer needs to adhere to basic data protection principles and the provisions of ITA and SPDI Rules. In view of the same, it is recommended that employers:

1. Collect only relevant data with the employee’s written consent and attempt to limit it to confirmed or suspected cases. When the COVID-19 is controlled, all the data collected to control the outbreak must be deleted/erased.

2. With the severity of COVID-19 increasing, employers may collect and store health details (like temperature, pulse rate or oxygen level) of individuals entering their work premises. However, such data should not be used for any other purpose other than for tackling the spread of COVID-19. It is employers’ duty to ensure that the information is well protected from third-party invasion.

3. Have a policy setting out a protocol for collecting and processing personal and SPDI which is line with an internationally recognized standard for data protection..

Imposition of Penalties under the ITA  

Under section 43A of the ITA, an employer is liable to pay compensation if it is found that there is negligence in providing ’reasonable security measures and procedures’, resulting in wrongful loss or wrongful gain to anyone.[8] While there is no upper limit prescribed, the compensation demanded would be commensurate to the damage caused. Under section 72A, the punishment for a service provider may include a jail term extending for three years and/or a fine extending to Rupees Five Lakhs if it is found that personal information has been disclosed without prior consent of the aggrieved individual or in breach of a contract.[9] It is imperative to prove that the intention behind such disclosure was to cause wrongful loss or wrongful gain to any person.[10]

Conclusion

In the fight against COVID-19, data is expected to play a huge role. However, in this pursuit, it is imperative to uphold right to privacy and comply with data protection laws. Utilisation of data will only be deemed successful if it is handled with proper caution and is erased once the crisis in brought under control. It is of utmost importance for employers to evaluate and update their data processing practices and information security management according to the prevailing circumstances.

The views and opinions expressed in this article belong solely to the author and do not reflect the position of TLH, Advocates & Solicitors.

[1] Rule 3 of SPDI Rules

[2] (2018) 1 SCC 809

[3] Ibid.

[4] Rule 5(3) of SPDI Rules

[5] Rule 4(1) of SPDI Rules

[6] Rule 5(1) of SPDI Rules

[7] Rule 8 of SPDI Rules

[8] Section 43A of the ITA

[9] Section 72A of the ITA

[10] Ibid.

No items found.
COVID-19, Data protection

Footnotes

Share this post
Copied!

Latest posts

Dispute Resolution
October 8, 2026
Arbitration Case Comment: Venue is Seat in the absence of contrary indicia ��� Implied Overruling of The Verdict in the Hardy Exploration case
A recent decision of the Supreme Court of India has far reaching ramifications for arbitration law in the country. While the decision in the BGS Soma[1] case has seemingly set out the ���correct law�۝ concerning the venue and seat dichotomy which has been the subject matter of a high volume of contested litigation over the years, its clarity and efficacy may come undone due to issues touching on the law of precedent.
Read more
Arrow Right
Information Technology
October 8, 2026
Privacy Shield Set Aside by CJEU ��� A Guidance for India
The European Union (���EU�۝) is a major source of revenue for the information technology and business process outsourcing industry in India. However, there are several challenges that India faces with respect to transfer of personal data from EU to India. Presently, the data protection regime in India does not provide the same level of protection as the data protection regime in the EU, in particular because the Personal Data Protection Bill, 2019 has not been enacted yet.
Read more
Arrow Right
Corporate Law
October 8, 2026
The Fate of Online Gaming in India: Game of Chance versus Game of Skill
With the advent of technology, there have been a lot of developments and inventions which have blurred the concepts of physical presence and boundaries that were prevalent a couple of decades ago. Today, even traditional games like rummy, flush, poker, ludo, cricket, etc. are played online, some of which include real money as stakes. ��
Read more
Arrow Right
Corporate Law
October 8, 2026
Whether Call / Put Options in FDI Transactions are considered as Assured Returns?
In the context of increased liberalisation of various foreign exchange laws in India, the country has seen a surge in the investment from abroad. Whereas, in case of divestments by foreign investors, the Indian foreign exchange laws have not been as liberalised as the foreign investors would have preferred, especially with regards to an assured exit price.
Read more
Arrow Right
October 8, 2026
Captive Generating Plants in the States of Telangana and Andhra Pradesh
A captive generating plant is a power plant set up by any person to generate electricity primarily for his own use and includes a power plant set up by any co-operative society or association of persons for generating electricity primarily for use of members of such co-operative society or association (���CGP�۝).
Read more
Arrow Right
Employment Law
October 8, 2026
Non-Compete Clauses in Employment Contracts
A very fine line divides the issues that fall within the sphere of: (a) the principle of the freedom to contract, and (b) restraint of trade. A non-compete clause by its very nature falls on the periphery.
Read more
Arrow Right
View All Blogs
Arrow Right