Independent Research and Policy Advocacy

India’s proposed data protection regulator needs strong safeguards

By Malavika Raghavan & Srikara PrasadOn August 30, Paytm Mall allegedly suffered a massive data breach after being targeted of a group of hackers. The allegations were made by Cyble, a US cyber-risk intelligence firm. These were immediately denied by Paytm Mall, which, in turn, threatened to take legal action against Cyble. Meanwhile, customers and vendors have no way of verifying whether a breach occurred, or if their data has been compromised,

Initial Comments of Dvara Research dated 16 January 2020 on the Personal Data Protection Bill 2019 introduced in the Lok Sabha on 11 December 2019

In this document, we present our initial comments on the Personal Data Protection Bill 2019 (the Bill), introduced in the Lok Sabha in December 2019. This continues our engagement with the public consultation process on India’s new data protection regime since 2017.2 We welcome the introduction of the Bill in Parliament as an important development to take forward India’s journey towards an overarching data protection framework.

Effective Enforcement of a Data Protection Regime

This paper presents ideas for a new approach to enforcement of a data protection regime, based on risk-based supervision and the use of a range of responsive enforcement tools that could be deployed in advance of a breach to prevent it, or after a breach to mitigate the effects.