Differences
This shows you the differences between two versions of the page.
| — | courses:dpdp:module-02 [2026/06/03 17:01] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | |||
| + | ====== Module 02 — Data principal rights + Fiduciary obligations ====== | ||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Goal:** Map every right + obligation to a practical action. | ||
| + | </ | ||
| + | |||
| + | ===== Rights of data principals (§11-§14) ===== | ||
| + | |||
| + | - **§11 — Right to information** about processing (similar to GDPR Art. 15) | ||
| + | - **§12 — Right to correction + erasure** (similar to Art. 16-17, but with limits) | ||
| + | - **§13 — Right to grievance redressal** — file with Fiduciary first; escalate to DPB | ||
| + | - **§14 — Right to nominate** — appoint another individual to exercise rights upon death/ | ||
| + | |||
| + | Notably absent: data portability, | ||
| + | |||
| + | ===== Obligations of fiduciaries (§8) ===== | ||
| + | |||
| + | Every Fiduciary must: | ||
| + | - Process for lawful purpose only | ||
| + | - Implement reasonable security safeguards | ||
| + | - Notify the DPB + affected data principals of breaches | ||
| + | - Erase data when purpose is fulfilled (and inform Processors) | ||
| + | - Publish business contact for grievance officer | ||
| + | |||
| + | ===== Significant Data Fiduciary additional obligations ===== | ||
| + | |||
| + | SDFs (notified by Government): | ||
| + | - Appoint **Data Protection Officer** (DPO) based in India | ||
| + | - Conduct **Data Protection Impact Assessment** (DPIA) for high-risk processing | ||
| + | - Conduct **periodic audits** by independent Data Auditors | ||
| + | |||
| + | Likely SDFs: large e-commerce, healthcare aggregators, | ||
| + | |||
| + | ===== Children' | ||
| + | |||
| + | - Verifiable parental consent required for processing children' | ||
| + | - Cannot do **tracking, behavioural monitoring, targeted advertising** at children | ||
| + | - Cannot cause **harm** to children | ||
| + | - DPB can exempt platforms that demonstrate verifiable safe processing | ||
| + | |||
| + | ===== Cross-border transfer (§16) ===== | ||
| + | |||
| + | Default: data can flow to **any country EXCEPT those notified as restricted** by Central Government. | ||
| + | |||
| + | This is more permissive than GDPR's adequacy decisions. The restricted list (when notified) becomes the bottleneck. | ||
| + | |||
| + | ===== ✅ Quiz ===== | ||
| + | |||
| + | Quiz available from your [[: | ||
| + | |||
| + | ===== Next ===== | ||
| + | |||
| + | * [[: | ||
| + | * Next: [[: | ||
| + | |||
| + | //Last reviewed: 24 April 2026.// | ||
| + | |||
| + | {{tag> | ||