We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

India Exempts Its Outsourcers from New Privacy Rules

Personal data sent to India by customers outsourcing IT work there will not be covered by India's new privacy rules, the government announced in late August. The clarification was a huge relief to India's large outsourcing industry.

The data privacy rules, issued in April, require companies or their intermediaries to get written consent from individuals about the use of the sensitive personal information they collect. But it would have been very difficult for Indian outsourcers to operate if they had to get written consent from every foreign citizen whose personal data moves through India's vast collection of call centers and other outsourcing operations.

India's Ministry of Communications and Information Technology issued a clarification saying the new rules apply only to Indian companies that collect information from individuals. That ended confusion over whether U.S. and European companies sending data for processing to Indian outsourcers would have to follow India's privacy rules while collecting data in their countries.

The rules define "sensitive data" as including passwords, financial information, medical conditions, sexual orientation and biometric information.

It is now clear that it is the companies collecting and sending the data-not outsourcers-that are responsible for protecting the privacy of the data according to the rules of the countries they operate in, says Kamlesh Bajaj, CEO of the Data Security Council of India. The council was set up by India's National Association of Software and Service Companies to set standards for data security and privacy for outsourcers.

However, the preferential treatment given to outsourcers could be struck down in court, says Pavan Duggal, a cyberlaw consultant and advocate in India's Supreme Court. The clarification has not been issued under any provision of the country's IT Act, and in fact violates the spirit of the IT Act, which does not limit the jurisdiction of its laws to companies within India, Duggal says.

The clarification is also vague and could lead to a variety of companies claiming to be exempt from the personal data rules, he adds.

Read more about privacy in CIO's Privacy Drilldown.


IDG UK Sites

Microsoft Band UK release date and price rumours, features and specs: Microsoft smartwatch unveiled

IDG UK Sites

Why Sony's PS4 2.0 update is every gamer's dream (well, mine at least)

IDG UK Sites

This Grolsch ad combines stop-motion & CG for majestic results

IDG UK Sites

Apple rumours and predictions for 2015: What to expect from Apple in 2015