Under the revamped version of the Data Protection Bill, companies that fail to take reasonable safeguards to prevent data breaches could end up facing penalties as high as around Rs 200 crore.
Penalties are expected to vary on the basis of the nature of non-compliance by data entities that handle and process personal data of individuals. In the previous version of the Bill, the penalty proposed on a company for violation of the law was Rs 15 crore or 4 percent of its annual turnover, whichever is higher.
The new Bill will only deal with safeguards around personal data and is learnt to have excluded non-personal data from its ambit. Non-personal data essentially means any data which cannot reveal the identity of an individual.
In August, the government withdrew the earlier Personal Data Protection Bill from Parliament after putting in nearly four years and having gone through multiple iterations. The withdrawal came despite Union IT Minister Ashwini Vaishnaw stating that he hoped to get the Parliament’s nod on the Bill in the monsoon session.
A senior government official, “There will also be a strict or purpose limitation of data collected by companies and the time till which they can store it under the new Bill.” It is learnt data fiduciaries will be required to stop retaining personal data and delete previously collected data after the initial purpose for which it was collected was fulfilled.













































