What India’s draft digital privacy law says — and how it compares with data protection laws elsewhere https://indianexpress.com/article/explained/explained-economics/india-draft-digital-privacy-law-data-protection-laws-8279199/
The reworked version of the data protection Bill, released three months after the Govt withdrew an earlier draft, eases cross-border data flows and increases penalties for breaches. But it gives the Centre wide-ranging powers and prescribes very few safeguards.
two potentially significant red flags: a near blanket exemption for government agencies from complying with some of the more onerous requirements under the Bill, and a dilution of the remit of the proposed Data Protection Board, which is mandated to oversee the provisions of the proposed legislation.
This larger policy includes a comprehensive digital India Act that would eventually replace the existing IT Act, the new data protection Bill that has just been unveiled, and the new telecom Bill that was put in the public domain last month.
In contrast, the landmark GDPR, in force since May 2018, is clearly focused on privacy and requires individuals to give explicit consent before their data can be processed. A pair of sub-legislation — the Digital Services Act (DSA) and the Digital Markets Act (DMA) — take off from the GDPR’s overarching focus on the individual’s right over her data. The DSA focuses on issues such as regulating hate speech, counterfeit goods etc. while the DMA defines a new category of “dominant gatekeeper” platforms, and is focused on uncompetitive practices and the abuse of dominance by these players.