




版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
DigitalPersonalData
ProtectionRules(2025)
January2025
01
OverviewofdraftDPDPrules2025
KeytenetsoftheDPDPrules
Dataprivacynoticeandconsent:
Noticeshouldincludeanitemisedlistofcollectedpersonaldata,thepurposeforprocessingit,anditemiseddescriptionofgoodsandservicesprovided.Itshould
alsoincludealinktoaccessthewebsiteorapptowithdrawconsentandmakeacomplainttotheDataProtectionBoard.
RightsofDataPrincipals:
01
02
DataFiduciariesandConsentManagersmustclearlyoutlineontheirwebsiteor
apptheprocessforDataPrincipalstoexercisetheirrightsundertheAct,
includingtheDataPrincipal’srighttonominate.
Reasonablesecuritysafeguards:
DataFiduciariesmustprotectthe
personaldataoftheirDataPrincipalsbytakingadequatedatasecuritymeasures.
Verifiableparentalconsent:
03
04
ForaDataPrincipalunder18oranypersonwithadisability,theData
Fiduciarymustobtainverifiableconsentfromtheparentorguardian.
Personaldatadeletion:
Dataprivacybreachnotification:
Incaseofadatabreach,theData
FiduciaryshouldnotifyaffectedData
Principalsandtheboardwithin72hours.
05
06
Forspecificscenarios,thepersonaldataofDataPrincipalswhohavenotinteractedwiththeDataFiduciaryforthreeyears
mustbedeleted,andtheyshouldbenotifiedofthesameatleast48hoursbeforedeletion.
PwC|DigitalPersonalDataProtectionRules(2025)January20252
KeytenetsoftheDPDPrules
Cross-borderdatatransfer:
ObligationsofSignificantDataFiduciaries(SDFs):
SDFsmustconductanannualData
ProtectionImpactAssessment(DPIA)anddataprivacyaudits.
DataFiduciariesprocessingdatainIndiaorprovidinggoodsorservicesfrom
08
07
outsideIndiamustadheretoany
requirementsestablishedbythecentralgovernmentregardingtheavailabilityofsuchpersonaldatatoaforeignstateoritsentities.
Exemptionstotheact:
DataFiduciarieslikehealthcare
professionals,educationalinstitutions
andchildcareprovidersareexemptfromcertainprovisionsregardingchildren’s
data,butcanonlyprocessitforspecificactivities(e.g.safetymonitoringand
transportationtracking).
PublishingthedetailsoftheDPOorrepresentative:
10
09
DataFiduciariesshoulddisplaythe
contactdetailsofanydesignatedpersonsuchasthedataprotectionofficer
(DPO).
ProcessingofpersonaldatabytheState:
ConsentManager:
MustbeanIndian-incorporatedcompanywithanetworthofatleastINR2crore
andacertifiedinteroperableplatformformanagingconsent.
TheStateandinstrumentalitiesmay
11
12
processthepersonaldataofindividualstoprovidevariousbenefits,services,
certificates,licencesorpermits,aspermittedbylawsandpolicies,orthroughpublicfunds.
PwC|DigitalPersonalDataProtectionRules(2025)January20253
Ourperspectiveonkeytenets
Referencetotheact
Requirementintheact
Proposedrules
Ourperspective
ChapterII,Section5-Notice
Thenoticeforconsent-based
processingshouldbeservedto:
?newandexistingData
Principalsassoonasitisreasonablypracticable.
Thenoticeshouldcontaindetailsabout:
?personaldataandthepurposeofprocessing
?themannertoexerciserights
?themannertomakeacomplainttotheboard.
ThenoticeshouldbeaccessibleinEnglish,oranylanguagespecifiedintheEighthScheduleofthe
ConstitutionofIndia.
Rule3
ThenoticefromtheDataFiduciarytotheDataPrincipalshould:
?beindependentlyunderstood
?haveclearandplainlanguage
?provideafairaccountofthedetailssuchas:
a)anitemisedlistofpersonaldata
b)specifiedpurposeof
processinganditemiseddescriptionofgoodsandservicestobeprovided
c)communicationlinkfor
accessingthewebsiteor
apporboth,towithdrawtheconsentorexerciserights
undertheactormakeacomplainttotheboard.
?Noticemustbeclearandeasilyaccessible,withouthiding
importantdetailsinseparatetermsandconditionsor
redirectingtounclearFAQs.ThisensuresthattheData
Principalhasalltherequiredinformationatoneplaceforinformeddecision-makingonconsent.
?Themanagementshouldcreateaconciseitemisedlistof
personaldata.
?Insomecases,businesses
mightdelivernoticesinapaperformat.Thedraftrulesdonot
specifywhatmustbeincludedinsuchnotices,whereaddingawebsiteorapplinkisnot
possible.
ChapterIISection6-Consent,Clause7
and8
TheDataPrincipalcangive,
manage,revieworwithdrawtheirconsentthroughaConsent
Manager.
TheConsentManagerwillbe
accountabletotheDataPrincipalandshallactontheirbehalf.
Rule4
PrerequisiteforConsentManagercompanies:
?incorporatedinIndia
?minimumnetworthofINR2crore
?interoperableplatformsforconsentmanagement
?reputationforfairnessandintegrity
?appropriatetechnicalandorganisationalmeasures
?noconflictofinterestwiththeregisteredDataFiduciaries
?adheretothedefinedobligationssuchas:
?maintainingthewebsiteorappthroughwhichData
Principalsaccessservices/consents
?keeprecordsofconsents,accompanyingnoticesandpersonaldatasharedwithtransfereeDataFiduciariesforatleast7years.
?Anyentitywiththenecessary
infrastructuretoactasa
consentmanagershoulduseitonlyforinternalpurposes
withoutaconflictofinterestwiththedatafiduciary.So,ifan
entitycanmaintainthisintegrity,theycanoffertheirplatformto
otherfirmstoexplorebusinessopportunities.
?Consentmanagershouldstorerecordsforatleastsevenyearsorlongerasagreeduponbythedataprincipal,orasrequiredbythelaw.Butforafewindustries,datashouldbedeletedwithin
threeyears.So,consent
managersmusthavebuilt-in
capabilitiestomeetthesedataretentionrequirements.
PwC|DigitalPersonalDataProtectionRules(2025)January20254
Ourperspectiveonkeytenets
Referencetotheact
Requirementintheact
Proposedrules
Ourperspective
ChapterII,
Section7-
Certain
Legitimate
uses,Clause7(b)
TheStateanditsinstrumentalitiesmayprocesspersonaldatato
providesubsidy,benefit,service,certificate,licenceorpermitas
prescribed,where:
?theDataPrincipalhas
previouslyconsentedtotheprocessingoftheirpersonaldata
?personaldataisavailableinadigitalform,orinanon-digitalformwhichissubsequently
digitisedfromanydatabase,register,bookorother
documentmaintainedbythestateanditsinstrumentalities.
Rule5
TheStateanditsinstrumentalitiesmayprocessthepersonaldata
undercertainlegitimateusessuchasprovidingsubsidies,benefits,
services,certificates,licencesandpermitsandwillhavetoadheretocertaintechnicalandorganisationalmeasureswhileprocessingsuch
data.
?Thedraftrulesclarifyhowthe
Stateanditsinstrumentalities
shouldprocesspersonaldata
forlegitimateuse,while
intimatingthecontact
informationofthepersonwhoisanswerabletothedataprincipalaboutprocessingpersonaldata,specifyingcommunicationlink
toaccessthewebsiteortheapp.
ChapterII,Section8-General
obligationsofdata
fiduciary,Clause5
ADataFiduciaryshallprotect
personaldatainitspossession,orunderitscontrol,includingdata
processedonitsbehalfbyadata
processor,bytakingreasonable
securitysafeguardstopreventdatabreach.
Rule6
ADataFiduciaryshallprotect
personaldatainitspossessionor
underitscontrolbytaking
reasonablesecuritymeasures,suchas:
?encryption,obfuscation,
maskingoruseofvirtualtokens
?accesscontroltocomputerresources
?visibilityondataaccessed
throughlogs,therebyenablingdetection,investigationand
remediationofunauthorisedaccess
?regularbackupofdataensuringcontinuityincaseof
compromise,destructionorlossofaccess
?retainlogsforoneyear,unlessrequiredotherwisebythelaw
?havingappropriatecontractualobligationsonthedata
processorforreasonablesecuritysafeguards
?implementingtechnicalandorganisationalmeasures.
?Thedraftruleslisttheprivacyandsecuritytechniquestobeimplemented,withroomfor
DataFiduciariestoupgradetheirprivacyandsecurity
infrastructure.
?Maintainingtheaudittrailforayearwillassistfiduciariesto
demonstratecomplianceandtakereasonableactionsduringanyincident.
?Implementingthesecontrols
mayincreaseoperationalcostsfortheDataFiduciary,which
canbeachallengeforsmallorganisations.
?Maintaininganefficientdata
backupmechanismwillrequirearobustbusinesscontinuity
program(BCP).
?Thedraftrulesdonotoutline
theaccountabilityand
contractualobligationsofthe
dataprocessorformaintainingreasonablesecuritymeasures.
?ThedraftrulesdonotclarifyifthesecuritymeasuresapplytoallDataFiduciariesirrespectiveoftheirsizeandscale.
PwC|DigitalPersonalDataProtectionRules(2025)January20255
Ourperspectiveonkeytenets
Referencetotheact
Requirementintheact
Proposedrules
Ourperspective
ChapterII,Section8-General
obligationsofdata
fiduciary,Clause6
ThenotificationofpersonaldatabreachshallbegivenbytheDataFiduciaryto:
?theboard
?affectedDataPrincipals.
Rule7
DataFiduciaryshallnotifythebreachto:
?theboard–within72hoursof
becomingawareoralongerperiod
–aspermittedbytheboard
?affectedDataPrincipalsina
concise,clearandplainmanner,
withoutdelaythroughuseraccountoranymodeofcommunication
registeredbythem.
Thenotificationshallinclude:
?adescriptionofthebreach
?consequencesofthebreach
?measuresimplementedtomitigaterisk
?safetymeasuresthatdata
principalmaytaketoprotectthemselves
?businesscontactinformationofarepresentative
?factsrelatedtotheevent,
reasonsleadingtothebreachandanyfindingsregardingthepersonwhocausedthebreach.
?Thedraftruleforthepersonal
databreachnotificationis
detailedandcomprehensible.
Datafiduciariesshallupdate,ordocumentnewpolicy/procedurealignedwiththeactanddraft
rulestoensurecompliance.
?Incaseofadatabreach,thedraftrulesdonotprovidea
mechanismtonotifytheDataProtectionBoardorspecifyiftheymustinformguardiansorparentsofchildrenorpersonswithdisabilitiesaboutthe
incident.
?Thedraftrulesdonotmandateatimeperiodforcommunicatingaboutthebreachtothedata
principal,whichispractical,aseachbreachneedstobe
investigatedbeforenotification.
ChapterII,Section8-General
obligationsofdata
fiduciary,Clause7and8
TheDataFiduciaryshallerasethepersonaldatawhen:
?eitherDataPrincipalswithdrawtheirconsent
?ortheintendedpurposeis
fulfilled–whicheverisearlier
?orifrequiredbythelaw.
ADataFiduciaryshallobligateitsdataprocessortoerasethe
personaldataasperthedefinedperiod,orascommunicated.
ThedataprincipalcanrequesttheDataFiduciarytoexercisetheir
rightsforaspecifictimeperiod.ThismayvarydependingontheclassoftheDataFiduciariesandpurposes.
Rule8
E-commerceentities(with>2crore
usersinIndia),gaming
intermediaries(with>50lakhs
usersinIndia)andsocialmedia
intermediaries(with>2croreusersinIndia)musterasepersonaldataafterthreeyearsfromthedatetheDataPrincipallastapproachedthefiduciary,exceptforenablingthe
DataPrincipaltoaccesstheir
accountoranyvirtualtokens
issuedbyoronbehalfoftheDataFiduciary
IntimatetheDataPrincipalatleast48hoursbeforedeletionoftheir
dataunlesstheylogintotheir
accountorinitiatecontactwiththeDataFiduciary.
?AsperConsumerProtectionAct2019,‘e-commerce’means
buyingorsellingofgoodsor
services,includingdigital
products,overdigitalor
electronicnetwork.Hence,all
organisationswithanonline
presence(websiteand/orapp)foracceptinganddelivering
goodsandservicescomeunderthepurviewofthisrule.
?Thiscompliancemayreduce
storagecostsbutcouldimpactmarketingandanalytics.Itmayalsorequireupdatestodata
managementsystemsforproperidentificationanddeletionofpersonaldata.
PwC|DigitalPersonalDataProtectionRules(2025)January20256
Ourperspectiveonkeytenets
Referencetotheact
Requirementintheact
Proposedrules
Ourperspective
ChapterII,Section8-General
obligationsofdata
fiduciary,Clause9
DataFiduciaryshallpublishthe
businesscontactinformationofaDPOorapersonwhoisableto
answerthequeriesoftheData
Principalabouttheprocessingof
theirpersonaldataonbehalfoftheDataFiduciary.
Rule9
DataFiduciaryshallpublishtheirbusinesscontactortheirDPOonthewebsiteortheapp.The
fiduciarymustalsosharethese
contactsineverycommunicationwiththeDataPrincipalwithregardtoexercisingtheirDPDPrights.
?Thedraftrulesre-emphasise
thatthecontactpersonorDPOappointeeshouldbeaccessiblefordataprincipalsonwebsites,mobileappsandotherrelevantcommunicationplatforms.
ChapterII,Section9-Processingofpersonaldataof
children
TheDataFiduciaryshall:
?obtainverifiableconsentfromtheparentorlawfulguardian
beforeprocessingthepersonaldataofachildorapersonwithdisabilitywhohasalawful
guardian
?refrainfromprocessingany
personaldatathatislikelyto
causeanydetrimentaleffectonthewell-beingofachild
?refrainfromtracking,
behaviouralmonitoringand
targetedadvertisingdirectedatchildren.
Theabove-mentionedprovisionsshallnotbeapplicabletothe
processingofthepersonaldataofachildbytheclassesofData
Fiduciariesorforsuchpurposes,andsubjecttosuchconditions,asmaybeprescribed.
Rule10
ADataFiduciaryshalladopt
appropriatetechnicaland
organisationalmeasurestoensurethatverifiableconsentoftheparentisobtainedbeforeprocessinganypersonaldataofachildandfrom
individualsidentifyingthemselvesasthelawfulguardianofapersonwithdisability.
Fiduciarymustensurethatthe
individualidentifyingastheparentisanadultandisidentifiable
through:
?reliabledetailsofidentityandageavailablewiththeData
Fiduciary
?voluntarilyprovideddetailsofidentityandage
?avirtualtokenmappedtothesame
?theguardianisappointedbyacourtoflaw,adesignated
authorityoralocallevel
committee,underthelawapplicabletoguardianship.
ExceptionsapplytoDataFiduciary
classessuchaseducational
institutions,clinicalestablishments,mentalhealthestablishmentsandhealthcareprofessionals–subjecttonotundertaketrackingor
behaviouralmonitoringortargetedadvertisingforchildren.
?TheDataFiduciarywillrequiretechnologicalandprocess
changestoobtainverifiable
consentfromparentsor
guardians.Thisposes
challengestoverifytheageandidentityoftheindividual
identifyingastheparent,andintegratingsystemswith
externalentitiesentrustedby
lawortheCentralGovernment(UIDAI,DigiLocker,etc.).
PwC|DigitalPersonalDataProtectionRules(2025)January20257
Ourperspectiveonkeytenets
Referencetotheact
Requirementintheact
Proposedrules
Ourperspective
ChapterII,Section10-Additional
obligationsofSDF
TheSDFshall:
?appointaDPO
?appointanindependentdataauditor
?undertaketheperiodicDPIA
?conductperiodicaudits
?implementothermeasures
consistentwiththeprovisionsoftheact,asmaybeprescribed.
Rule12
SDFshall:
?undertakeDPIAanddataprivacyauditsonceayear
?furnishthereporttotheboardcontainingsignificant
observationsintheDPIAandaudit
?observeduediligencetoverifythatalgorithmicsoftware
deployedarenotposingarisktotherightsofDataPrincipals
?ensurethatpersonaldata
specifiedbythecentral
governmentisprocessed
subjecttotherestrictionthatthepersonalandtrafficdata
pertainingtoitsflowisnottransferredoutsideIndia.
?Thedraftrulesclarifythe
additionalobligationsofSDFs,andtheymustmakeadditionaleffortstoensurecompliance.
?ThecriteriaforclassificationofSDFsisunclear.
?Whilethedraftrulesdonot
clarifywhatalgorithmicsoftwareis,SDFsusingpersonaldataforthepurposeoftrainingmodelsneedtoreconsidertheir
processes,incaseaData
Principalwithdrawsconsent.
?Thedraftrulesdonotclarifyhowandwhenthecentral
governmentwilldefinethepersonaldatathatmustbeprocessedwithinIndia’s
borders.Additionally,thesedraftrulesreinforcedatalocalisationrequirementsacrossallindustrysectors,whichwereoriginally
applicableonlytopayment
systemprovidersundera
ReserveBankofIndia(RBI)regulation.
ChapterIII
Section11-14-RightsofData
Principal
TheDataPrincipalhasthefollowingrights:
?righttoaccessinformationaboutpersonaldata
?righttocorrectionanderasureofpersonaldata
?rightofgrievanceredressal
?righttonominate.
Rule13
TheDataFiduciaryandConsentManager(asapplicable)shall
publishontheirwebsiteorapporboth:
?howaDataPrincipalcanraisearequest
?theparticularsoftheidentifierofaDataPrincipal,whichmaybe
requiredtoidentifythem(asapplicable)
?theperiodofresponseunderitsgrievanceredressalsystem.
TheDataPrincipalhastherighttonominateoneormoreindividualstoactontheirbehalfunderthe
righttonominate.
?Theserightsreflecttheact’s
centraltheme,whichisto
empowerindividualstocontroltheirinformationandhow
organisationscollect,process
andshareit.DataFiduciaries
andConsentManagersmust
developprocessesand
technologysolutionstoaddressDataPrincipals’rightsrequests.
?ThedraftrulesdonotdefinethemaximumtimeallowedforDataFiduciariesandConsent
Managerstoaddress
grievances.Withoutaspecifiedtimeframeforgrievance
redressal,therightsgrantedtodataprincipalsundertheDPDPActmaybeweakened.
PwC|DigitalPersonalDataProtectionRules(2025)January20258
Ourperspectiveonkeytenets
Referencetotheact
Requirementintheact
Proposedrules
Ourperspective
ChapterIV,Section16-Processing
ofpersonal
dataoutsideIndia,Clause1and2
Thecentralgovernmentmay
imposerestrictionsonthetransferofpersonaldatabyaData
FiduciarytoanycountryorterritoryoutsideIndia.ThisdoesnotimpactanyexistinglawsinIndiathat
provideprotectionorrestrictionsontransferringpersonaldatabya
DataFiduciaryoutsideIndia.
Rule14
Thetransferofpersonaldata
processedbyaDataFiduciaryto
anycountryorterritoryoutside
IndiaissubjecttotheconditionthattheDataFiduciarymustcomply
withtherequirementssetbythe
centralgovernment.These
requirementsmaybespecified
throughgeneralorspecialorders.
?ThecurrentdraftrulewillhaveanannexurewithmoredetailsregardingthetransferofdataoutsideIndia.
?Iftheprocessingofpersonal
databyDataFiduciariesoutsideIndiaisrestrictedbyafuture
governmentorder,
organisationsthatusecloud
servicesorprocesspersonal
dataabroadwillneedto
reconsidertheirITstrategyandarchitecturetomaintain
compliancewiththeDPDPAct2023.
ChapterIV,Section17-Exemptions,Clause2
Theactdoesnotapplywhen:
?thecentralgovernmentmay
notify,intheinterestsof
sovereigntyandintegrityofIndia,securityofthestate,friendly
relationswithforeignstates,
maintenanceofpublicorderor
preventingincitementtoany
cognisableoffencerelatingtoanyofthese.
?dataisnecessaryforresearch,archivingorstatisticalpurposes,aslongasitisnotgoingtobe
usedtotakeanydecisions
specifictoaDataPrincipalandsuchprocessingiscarriedoutinaccordancewithsuchstandardsasmaybeprescribed.
Rule15
Theprovisionsoftheactshallnotapplytotheprocessingofpersonaldatanecessaryforresearch,
archivingorstatisticalpurposesifitiscarriedoutinaccordancewith
thestandardsspecifiedinthesecondschedule.
?Thedefinitionsof‘research’,
‘a(chǎn)rchival’and‘statistical
purpose’arenotclearlydefinedinthedraftrules.Forinstance,itisnotclearwhetherclinical
trialsandmedicaldevice
researchfallunderthecategoryof‘research’undertheact.
PwC|DigitalPersonalDataProtectionRules(2025)January20259
02
Key
responsibilities
Keyresponsibilitiesofadatafiduciary
Dataprivacynotice
Presentedinanunderstandableandclearlanguage
?Descriptionofpersonaldata
?Purposeofprocessing
?Descriptionofthegoodsorservicestobeprovided
?Descriptionofmeansusingwhichthedataprincipalmaywithdrawhis/herconsent,exercisetheirrightsandmakeacomplainttotheboard
Personaldatasecurity
ProtectthepersonaldataincludinganyprocessingundertakenbytheDataFiduciaryoronitsbehalfbyadataprocessor.
?Securingofpersonaldatathroughencryption,obfuscation,maskingortheuseofvirtualtokensmappedtothepersonaldata
?Accesscontrolforthecomputerresourceused
?Maintaining,monitoringandreviewinglogs
?Retaininglogsandpersonaldatafordetection,investigation,remediationandcontinuousprocessingforoneyear
?Databackupsandanyothermeansforcontinuedprocessing
?AppropriatecontractualclausesbetweenDataFiduciaryanddataprocessorforundertakingreasonablesecuritysafeguards
?Appropriatetechnicalandorganisationalmeasures
PwC|DigitalPersonalDataProtectionRules(2025)January202510
Keyresponsibilitiesofadatafiduciary
Notificationofpersonaldatabreach
SendnotificationstoeachaffectedDataPrincipalinaconcise,clearmannerandwithoutdelay,andtotheboardwithin72hoursofbecomingaware–orwithinalongerspecifiedperiodasallowedbytheboard.
?Descriptionofthebreach,includingitsnature,extentandthetimingandlocationofitsoccurrence
?Consequencesthatarelikelytoarisefromthebreach
?Measuresimplementedandbeingimplementedtomitigaterisk
?SafetymeasuresthattheDataPrincipalsmaytaketoprotecttheirinterests
?Businesscontactinformationofarepresentative
?Anyfindingsregardingthepersonwhocausedthebreach
?Areportregardingtheintimationsgiventoaffecteddataprincipals
Personaldatadeletion
?InformtheDataPrincipalatleast48hoursbeforecompletionofthetimeperiodforerasure.
?IntimatetheDataPrincipalaboutthedeletionunlesstheylogintotheiruseraccountorinitiatecontactwiththefiduciaryforthespecifiedpurposeofdataprivacyrights.
Publishingthecontactinformation
?PublishthebusinesscontactinformationoftheDPOorarepresentative.
?Publishthedetailsonthewebsiteorapp,andineveryresponsetoacommunicationfortheexerciseoftherights.
Verifiableconsentfromparentsand/orguardians
?Adoptnecessarytechnicalandorganisationalmeasurestoensurethatverifiableconsentisobtainedfromtheparent
beforeprocessingthechild’spersonaldataandtoverifythattheguardianisappointedbyacourtoflaworadesignatedauthorityunderappropriatelaw.
?Suchparentorguardianshallbeadultandshallbeidentifiableasrequiredbythefollowingreferences:?reliabledetailsofidentityandageavailablewiththefiduciary
?voluntarilyprovideddetailsofidentityandage?virtualtokenmappedtothedetailsoftheparent
?tokenverifiedandmadeavailablebyadigitallockerserviceprovider.
Dataprivacyrights
?PublishthemeansusingwhichaDataPrincipalcanmakearequestonthewebsiteorapp.
?Additionallypublish:
?theparticularsoridentifiernumber*whichisrequiredtoidentifytheDataPrincipal?theperiodforgrievanceredressalandforrespondingtothegrievances.
*IdentifiermeansanysequenceofcharactersissuedbytheDataFiduciarytoidentifytheDataPrincipalandincludesacustomeridentificationfilenumber,customeracquisitionformnumber,applicationreferencenumber,enrolmentIDorlicencenumberthatenablessuchidentification.
PwC|DigitalPersonalDataProtectionRules(2025)January202511
Keyresponsibilitiesofadatafiduciary
PerformingDPIAsandauditsforSDFs
?PerformperiodicDPIAsanddataprivacyaudits.
?PerformaDPIAonceevery12monthsfromthedateonwhichtheywerenotifiedasanSDF.
?Conductanauditonceevery12monthstoensureeffectiveobservanceoftheactanddraftrules.
?FurnishsignificantobservationsfromtheDPIAandaudittotheboard.
RiskassessmentforSDFs
?Observeduediligencetoverifythatalgorithmicsoftwaredeployedforhosting,display,uploading,modification,publishing,transmission,storage,updatingorsharingofpersonaldataprocessedarenotlikelytoposearisktotherightsofData
Principals.
Cross-borderdatatransferforSDFs
?Aligncross-borderdatatransferwiththecentralgovernment’snotification.
?Undertakemeasurestoensurethatpersonaldataandtrafficdata,specifiedbythecentr
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 汽車吊機(jī)租賃合同
- 房地產(chǎn)經(jīng)紀(jì)行業(yè)客戶信息保密合同
- 貨車運(yùn)輸合同協(xié)議書(shū)
- 戶外運(yùn)動(dòng)安全責(zé)任豁免合同
- 建筑工程大清包合同新
- 智能制造生產(chǎn)線建設(shè)合同
- 金融行業(yè)投資產(chǎn)品風(fēng)險(xiǎn)提示協(xié)議
- 保潔衛(wèi)生承包合同
- 第十二章第三節(jié)《機(jī)械效率》教學(xué)設(shè)計(jì) -2023-2024學(xué)年人教版八年級(jí)物理下冊(cè)
- 第4課 嗅覺(jué)和味覺(jué)(教學(xué)設(shè)計(jì))-2023-2024學(xué)年六年級(jí)科學(xué)下冊(cè)同步備課(青島版)
- 高中主題班會(huì) 悟哪吒精神做英雄少年-下學(xué)期開(kāi)學(xué)第一課主題班會(huì)課件-高中主題班會(huì)課件
- 2025版大學(xué)食堂冷鏈?zhǔn)巢呐渌头?wù)合同模板3篇
- 2024年青島港灣職業(yè)技術(shù)學(xué)院高職單招語(yǔ)文歷年參考題庫(kù)含答案解析
- 廣西壯族自治區(qū)公路發(fā)展中心2025年面向社會(huì)公開(kāi)招聘657名工作人員高頻重點(diǎn)提升(共500題)附帶答案詳解
- 《中國(guó)的宗教》課件
- 2025年山東魯商集團(tuán)有限公司招聘筆試參考題庫(kù)含答案解析
- 大學(xué)轉(zhuǎn)專業(yè)高等數(shù)學(xué)試卷
- 大型活動(dòng)中的風(fēng)險(xiǎn)管理與安全保障
- 公司廠區(qū)保潔培訓(xùn)
- 課題申報(bào)書(shū):個(gè)體衰老差異視角下社區(qū)交往空間特征識(shí)別與優(yōu)化
- 2024年防盜門(mén)銷售合同范本
評(píng)論
0/150
提交評(píng)論