“Let us be DPDPA Compliant”..is our New Year Resolution

As we enter the dawn of 2025, we the data protection professionals in India shall adopt a New Year Resolution….to be DPDPA compliant within the environment in which we work.

As a starting point we request every Corporate professional who observes any breach of DPDPA principles within their organisations to send a request to their DPO to correct.

Such principles include

  1. Define a purpose for every personal data collection.
  2. Ensure only such information as is required for the purpose are collected.
  3. Ensure that there are no uninformed extensions of subscription to services
  4. Ensure that personal data is not retained beyond the purpose requirement.
  5. Ensure that valid consent is in place for every personal data collection and processing.
  6. Ensure that personal data disclosures are as per documented procedures.
  7. Ensure that every grievance from a data principal is promptly attended to.
  8. Ensure that Compliance to DPDPA is not neglected because the organisation is certified compliant already to GDPR or ISO 27001.
  9. Ensure that when in doubt about any aspect of DPDPA, contact FDPPI on email naavi@ fdppi.in or call naavi

Our motto…No Excuses..Just Be Compliant ..

Naavi

Posted in Cyber Law | Leave a comment

C.DPO.DA. course in Mumbai

The three day program for Certified Data protection professionals and Data Auditors will be conducted at Mumbai on January 24/25 and 26.

The program is open for registration now at https://fdppi.iletsolutions.com/c-dpo-da-training-2025/

Those who attend the program will be provided with participation certificate and will be eligible to take the online examination for full certification.

Naavi

Posted in Cyber Law | Leave a comment

Ascension Health Systems Data breach

The reported breach of 6 million data sets of Ascension Health Systems opens up certain discussion points.

The data breach followed a ransomware attack from Black Basta indicates caused by an accidental downloading of a malicious file. It is reported that the breach happened on February 29, 2024 but came to light some time in May 2024 when the systems were disturbed. The Organization seems to be now in the process of notifying the affected data principals/patients.

What is important to note is “What happened after the data breach?”. If we look at the website of Ascension, there is no prominent notice on the website. The notice is available on an inside page.

On the HHS website there is a mention that “HHS is aware of a cyber incident involving Ascension Health and is in communication with Ascension Leadership to understand their efforts to minimize any disruptions to patient care.”

According to this report in hipaajournal.com, the breach has caused significant set back to the Company.

Initially the Company claimed that there was no data exfiltration but has now admitted and reported the data breach with a possibility of data theft.

The breach has affected 142 hospitals, 40 senior living facilities and more than 2600 care sites in 10 different states besides the District of Columbia. An estimated 5, 599,699 patients have been affected as per the report filed by the Company to OCR. There are already a couple of law suits filed against the Company and the full impact of the breach is yet to unfold.

In the meantime, the Company has announced that affected individuals will get 24 months of credit and CyberScan monitoring, as well as $1,000,000 insurance reimbursement policy and fully managed ID theft recovery services. Normally such services may cost nearly $20 per month though this cover could be treated as a group cover under a much lower cost. However, given the quantum of data breach the company which had made a loss of $79 million last year could be in for a huge trouble in the year 2024-25. At present HHS has not imposed any fine of its own and if it finalizes its penalty there could be another $600 million or more as regulatory fine.

In the context of the incident, it would be interesting for Indian Cyber Insurance Companies to come up with appropriate policies that provide for such liability insurance under DPDPA. At present we often look only at the penalty of Rs 250 crores as the liability for data breach.

However the cost of compliance which includes such complimentary credit monitoring and Cyber crime cover, could be much lager. If 6 million people are to be sent a registered letter by post the cost could be about Rs 12 crores. The Credit monitoring and Cyber Crime coverage insurance if available may cost about Rs 3000/- per person or around Rs 1800 crores. (Assuming an average coverage of around Rs 5 lakhs).

Naavi

Posted in Cyber Law | Leave a comment

The Art of Digital Advertising in the Privacy Era

We opened up a discussion yesterday on the challenges before a digital marketing or a digital advertising company after the advent of Data Protection laws such as DPDPA.

Advertising is focussed on the five principles namely creating Awareness, Interest, Desire besides informing about the availability and enhancing the post purchase satisfaction.

The Advertising has the responsibility of converting the marketing strategy through appropriate communication to bring desirable changes in the buying behaviour. The advent of Artificial intelligence (AI) has enabled advertisers to analyse the buying behaviour of a prospective consumer and derive better communication strategies.

On the other hand the approach of Privacy and Data Protection is to provide the consumer a choice of decision making and any attempt to persuade the consumer to change his buying behaviour may be considered as ‘manipulation’ of the consumer’s mind and invoke the complaint of the use of “Dark Pattern” methods which are considered undesirable and a punishable offence under the Consumer Protection Act.

Consumer goods organizations who depend on Advertising need to balance their need for marketing with the risks of their campaigns turning out to be considered as “Manipulations” of the consumer mind.

At the same time, in structuring the appropriate advertising messages, an organization needs to have a good understanding of the current state of mind of a consumer and hence “Profiling” of a Consumer is the starting point for any marketing activity. Understanding the buying behaviour and tailoring the advertising messages to maximize the desire to purchase is the essence of marketing.

Attempting to understand and document the buying behaviour of a consumer is what is referred to as “Profiling”. The DPDPA and other data protection laws consider profiling of visitors on a website as an infringement of Privacy rights. GDPR Compliance therefore considers “Cookie Management” as an important activity of Compliance.

In DPDPA Compliance therefore, we need to strike a balance between the advertising needs and the avoidance of privacy infringement. Many times the Data Fiduciaries entrust their advertising responsibilities to specialized agencies and donot have a clear visibility of what an Advertiser is doing to gather information.

The DGPSI, the golden standard for DPDPA Compliance suggests many effective steps to mitigate the Privacy Risks in Profiling of prospective customers including visitors to a website or Visitors to a retail product store, conducting marketing surveys etc.

a) Manage the Advertisers as Joint Data Fiduciaries

b)Develop an exclusive “Data Monetization Policy” which includes the Profiling and Advertising policies

c) Develop a suitable Pseudonymization/anonymization policy for Personal Data Processing

When we look at the risks of advertising, it is clear that people mind “Friendly Alerts” but are concerned about “Spamming”. When does a “Friendly Alert” become “An Annoying Spam” and how do we recognize it is the art of Digital Advertising in the Privacy Era.

In the years around 2011, Naavi was pursuing a patent on “Adview Certification” and though Privacy was not a concern at that time, had incorporated an element of Consumer Consent and incentivisation. The thought seems to have a value even now with the added aspects of Anonymized processing of information and the use of AI.

Perhaps this new thought requires to be merged with the DGPSI framework into the “Data Monetization Strategy”.

This would however require technology back up where gathering of profiling information is done in a manner that it has the consumer consent and the delivery of advertisements is done in such a manner that it cannot be classified as “Spam”

Watch out for more action in this front as the “Privacy Compliant Digital Advertising” as a concept is unfolded. Probably there is scope for new Privacy Enhancement Technology Products in this area as well.

Naavi

Posted in Cyber Law | Leave a comment

DPDPA Impact on Digital Advertising and Marketing companies

One of the toughest challenges presented by DPDPA is for the Digital Marketing and Advertising Companies.

Marketing to be effective needs market segmentation and Advertising to be effective requires the messages to be tailored for the audience. The movement of media from the Print to TV and now to the Social Media/Internet has necessitated a big change in the approach of the Advertisers and Marketers.

When Internet was first used for business communication, the potential of the internet to have a targeted advertising campaign became extremely attractive to the Advertising & Marketing (A&M) Community. The potential to understand the location of a web site visitor enabled a geographical profiling of the audience. The content and the key word used by the visitor to arrive at the landing page enabled profiling of the immediate interest of the visitor. These factors enabled presentation of target specific messages which are useful to the A&M companies as well as the consumers.

Over a period, excessive advertising, use of content interrupting advertising made advertising a bit annoying. Today, privacy activists consider any form of profiling of a visitor of a website as an intrusion of privacy requiring prior consent of the Consumer.

With the availability of AI, analysing the visitor’s habit including the amount of time spent on each page by a visitor provides a lot of information which can be productively used by the marketing company to make its campaigns sharp and effective.

The challenge for the Website owner and the supporting Advertising and Marketing consultants is to ensure that while the requirements of profiling for advertising needs to be fulfilled, the constraints of DPDPA also need to be managed.

DGPSI the Peerless framework for DPDPA compliance is developing the procedural framework that should make DPDPA compliance for A&M companies feasible.

Await a more detailed discussion of the DGPSI-A&M framework shortly.

Naavi

Posted in Cyber Law | Leave a comment

ZeeTV needs to set aside Rs 250 crores for DPDPA fine

As the data protection community awaits the notification DPDPA rules, there is a speculation that Government is hesitant since Government bodies are not ready.

While it may be true that the Government bodies are not fully ready for DPDPA, private entities are also not ready and are putting pressures on the Government to delay.

It is strange that some of these companies are deliberately flouting the rules even though they are aware that they are wrong.

We have been attending many Privacy seminars all over India and it is clear that the professionals have a fairly good awareness of what needs to be done and what should be avoided. But the companies are going ahead with their bad practices indicating that the business managers donot care about the law.

I recently came across ZeeTV which has a mobile app which can be subscribed only with an “Auto Pay” instruction. There is no clear option to make payment for a monthly or yearly subscription without agreeing to auto renew.

I recently saw “Audible” also imposing mandatory auto renewal for its membership. Does it mean that the DPO of Audible and ZeeTV donot know the basics of Data Protection?. It appears to be so.

Probably the business managers donot know that as soon as the Act is notified, there could be a flood of complaints on such companies and ZeeTV may need to face a penalty situation upto and beyond Rs 250 crores for not complying with DPDPA.

Hope ZeeTV will put an end to this obnoxious practice.

Naavi

P.S: Readers have informed that Netflix and Audible also have a similar policy of forced auto renewal.

Posted in Cyber Law | Leave a comment