Comprehension
The Supreme Court of India declared that the right to privacy is a fundamental right and that the right to informational privacy is part of this right. Subsequently, the Parliament of India enacted a new law relating to digital personal data protection. The law applies to Indian residents and businesses collecting the data of Indian residents. It also applies to non-citizens living in India whose data processing is "in connection with any activity related to the offering of goods or services" that happens outside India. The law allows personal data to be processed for any lawful purpose. If the personal data is sensitive, then additional safeguards are to be observed. The entity processing data can do so either by taking the concerned individual's consent or for "legitimate uses". which include situations where an individual has voluntarily provided personal data for a specified purpose. The law requires that an individual's consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action" and for a specific purpose. The data collected has to be limited to that necessary for the specified purpose. A clear notice containing these details has to be provided to consumers, including the rights of the concerned individual and the grievance redressal mechanism. Individuals have the right to withdraw consent if consent is the ground on which data is being processed. The law also creates rights and obligations for individuals. These include the right to get a summary of all the collected data and to know the identities of all other entities/organisations with whom the personal data has been shared, along with a description of the data shared. Individuals also have the right to correction. completion, updating, and erasure of their data. Besides, they have a right to obtain redressal for their grievances and a right to nominate persons who will receive their data. [Excerpts from Anirudh Burman, "Understanding India's New Data Protection Law", CARNEGIE INDIA, October 03, 2023]
Question: 1

A startup provides a health-tracking app that collects sensitive health data from users. Under the digital personal data protection law in India, what additional precautions must the startup take compared to regular personal data?

Updated On: Sep 10, 2025
  • No additional measures are needed
  • Ensure explicit consent and adopt higher security standards
  • Store the data only with the government agencies
  • Store the data only with the hospitals and other health care institutions
Hide Solution
collegedunia
Verified By Collegedunia

The Correct Option is B

Solution and Explanation

The digital personal data protection law in India emphasizes additional precautions for handling sensitive health data compared to regular personal data. Here’s a breakdown based on the provided comprehension:
  1. Explicit Consent: The startup must ensure that explicit consent is obtained from users. This consent has to be "free, specific, informed, unconditional, and unambiguous with a clear affirmative action" and must be specific to the purpose of data collection.
  2. Higher Security Standards: Additional security measures need to be implemented to adequately protect sensitive health data. This includes adopting higher security standards than those required for regular personal data.
  3. Notice and Purpose Limitation: A clear notice containing details about data processing, including rights and grievance redressal mechanisms, must be provided. The data collected should be limited to what is necessary for the specified purpose.
  4. Data Subject Rights: Users have the right to withdraw consent, rectify or erase data, and obtain a summary of their data and details of its sharing with third parties.
Therefore, the correct approach for the startup under Indian law is to:
Ensure explicit consent and adopt higher security standards.
Was this answer helpful?
0
0
Question: 2

As per the passage, what are the rights included under the digital data protection law of India?

Updated On: Sep 10, 2025
  • 1, 2, 3, 4, 5 and 6
  • 1, 2, 3, 5 and 6
  • 1, 3, 5 and 6
  • 1, 2, 3, and 6
Hide Solution
collegedunia
Verified By Collegedunia

The Correct Option is D

Solution and Explanation

The digital data protection law of India encompasses several rights for individuals regarding their personal data. The specified rights include:
  • The right to obtain a summary of all collected data and to be informed of the identities of third-party entities with whom their data has been shared, along with a description of the data.
  • The right to correction, completion, updating, and erasure of their personal data.
  • The right to withdraw consent if it forms the basis for data processing, ensuring it is "free, specific, informed, unconditional and unambiguous with a clear affirmative action" for a specified purpose.
  • The right to obtain redressal for grievances related to their personal data.
  • The right to nominate individuals who will receive their data.
The correct answer, indicating the rights mentioned above, corresponds to the option:1, 2, 3, and 6.
Was this answer helpful?
0
0
Question: 3

An Indian company collects personal data from its users to provide personalized services. The company intends to share this data with a third-party vendor for targeted advertisements. Under the digital personal data protection law in India, what must the company do before sharing the data?

Updated On: Sep 10, 2025
  • Obtain explicit consent from the users
  • Share the data by inferring the uses, as it is for business purposes
  • Encrypt the data and share it with the third-party vendor
  • Inform the third-party vendor that the data is sensitive
Hide Solution
collegedunia
Verified By Collegedunia

The Correct Option is A

Solution and Explanation

Under the digital personal data protection law in India, when a company intends to share personal data with a third-party vendor, it must adhere to certain legal protocols to ensure compliance with privacy standards. The steps the Indian company should follow before sharing personal data are:
  1. Obtain Explicit Consent: The company must secure explicit consent from users whose data is to be shared. The law mandates that the consent should be "free, specific, informed, unconditional and unambiguous with a clear affirmative action" and related to a specific purpose.
  2. Provide a Clear Notice: The company must provide consumers with a clear and comprehensive notice about what data will be collected, how it will be used, the identities of third parties involved, and the rights afforded to the individuals.
  3. Inform About Rights and Grievance Mechanism: Users must be informed about their rights concerning data protection, such as the right to withdraw consent and the redressal mechanism available for grievances.
  4. Limit Data Collection: The collected data should be limited to what is necessary for the specified purpose as addressed when obtaining user consent.
In summary, the company must focus primarily on obtaining explicit consent from users before data-sharing activities with the third-party vendor. This approach ensures the company aligns with the legal requirements and respects user privacy.
Was this answer helpful?
0
0
Question: 4

A social media platform processes user data based on the consent given during account creation. A user now wishes to withdraw consent to process their data. Under the digital personal data protection law in India, what must the platform do?

Updated On: Sep 10, 2025
  • Refuse to accept the withdrawal request since consent was already given
  • Comply with the legal requirements and stop processing the data
  • Continue processing the data but notify the user
  • Allow withdrawal only after 30 days
Hide Solution
collegedunia
Verified By Collegedunia

The Correct Option is B

Solution and Explanation

The digital personal data protection law in India provides specific guidelines regarding the handling of user consent. According to this law, individuals have the right to withdraw their consent for data processing. The main aspects of the law relevant to this situation include:

  • Fundamental Right to Privacy: The Indian Supreme Court has established that the right to privacy is a fundamental right, including informational privacy.
  • User Rights: The law grants users the right to withdraw their consent for data processing at any time if their data processing is based on consent.
  • Compliance Obligation: Once withdrawal of consent is requested, the data processor (in this case, the social media platform) must comply with the legal requirements and stop processing the individual's data.
  • Grievance Redressal Mechanism: The platform must also provide a clear notice to the users about their rights and the grievance redressal mechanisms.

Given that the user wishes to withdraw consent, the platform is legally obligated to comply with the legal requirements and stop processing the data. This ensures adherence to user rights under the digital personal data protection law in India.

Was this answer helpful?
0
0
Question: 5

A financial institution collects biometric data from its clients for verification purposes. If the clients wish to know what data has been collected, under the digital personal data protection law in India, what right allows them to request this information?

Updated On: Sep 10, 2025
  • Right to Data Portability
  • Right to Correction
  • Right to Access
  • Right to be Forgotten
Hide Solution
collegedunia
Verified By Collegedunia

The Correct Option is C

Solution and Explanation

According to the digital personal data protection law in India, individuals have been granted several rights concerning their personal data. One of these rights is particularly relevant when a client or individual seeks to know what data has been collected by a financial institution for verification purposes. This right is known as the "Right to Access"

The "Right to Access" enables individuals to request and obtain information concerning their personal data that has been collected by any entity. This includes the capability to receive a summary of all the data collected, as well as insights into who else might have received their data. This right is part of a broader attempt to ensure transparency and control for individuals over their personal data.

RightsDescription
Right to Data PortabilityEnables the transfer of data from one service provider to another.
Right to CorrectionAllows individuals to correct inaccurate personal data.
Right to AccessAllows individuals to request and obtain information about their data collected by entities.
Right to be ForgottenPermits the erasure of personal data when it is no longer necessary.

Hence, when clients wish to know what biometric or other data a financial institution has collected about them, they can exercise their "Right to Access" to request this information.

Was this answer helpful?
0
0

Questions Asked in CLAT exam

View More Questions