Home | MyGov

Accessibility
Accessibility Tools
Color Adjustment
Text Size
Navigation Adjustment
Screen Reader iconScreen Reader

Inviting feedback and inputs on Draft National Data Governance Framework Policy

Start Date :
May 27, 2022
Last Date :
Jun 18, 2022
23:45 PM IST (GMT +5.30 Hrs)
Submission Closed

India is accelerating towards an increasingly digitised and data-driven economy. With increasing digitization and engagement, the volume of data is also increasing exponentially, ...

India is accelerating towards an increasingly digitised and data-driven economy. With increasing digitization and engagement, the volume of data is also increasing exponentially, providing opportunities for better governance, service delivery and innovation in sectors critical for societal transformation.

Against this backdrop, the National Data Governance Framework Policy aims to enhance access, quality, and use of data, in line with the current and emerging technology needs of the decade.

The Ministry of Electronics and Information Technology invites all Indian citizens to bring their best ideas, inputs and suggestions to the table as we move ahead to become the hub for Data-driven innovation and decision making.

Please refer to the policy document: Draft National Data Governance Framework Policy (PDF 509 KB)

Share your inputs on the MyGov platform.
The inputs/suggestions may also be sent to
Ms Kavita Bhatia,
Scientist 'F' at the email kbhatia@gov.in and pmu.etech@meity.gov.in

The last date to submit your entries is 18th June 2022.

Reset
Showing 788 Submission(s)
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
Clause 4.10 (iii): Data trusts Section 4.10 (iii) notes that data custodians may voluntarily share data in these data trusts. However it is unclear if such sharing must be done with the express consent of the relevant data trustee. Clause 4.10 (iv): Mandatory sharing and competition The fundamental premise of a mandatory data sharing regime seems increasingly distant from its practical impacts. The EU which earlier championed the cause now seems reluctant to further it on the face of studies which skews towards counteractive impacts of such steps. Such steps could apply to huge volumes of first-party data companies collect on their own assets, products and services, even though such data are among the least likely to create barriers to entry or contribute to abuses of dominant positions
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
Lack of means for selecting a data trustee: The report makes note of the fact that both private and public entities can be selected to be data trustees but offers no principles on how these data trustees can be selected, i.e. whether they are to be directly selected by the members of a community, and if so how. Any selection criteria or process prescribed has to keep in mind the following point regarding the potential lack of representation for marginalised communities that could arise from a direct selection of a data trustee by a group of people. Issues of having a single data trustee for large scale communities and when dealing with marginalised communities: The report assumes that in instances wherein a community is spread across a geographic region, or consists of multiple sub-communities, then the data trustee will be the closest shared government authority (for example, the Ministry of Health and Family Welfare, Government of India being the data trustee for data regarding diab
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
Clause 4.8 (i), (ii): Function of data custodians The Report does not make it clear who may perform the role of data custodians. The use of data fiduciary indicates the potential import of the definition of ‘data fiduciary’ as specified under Clause 3.13 of the PDP Bill. However, this needs to be further clarified.Clause 4.8 (iii): Data custodians’ “duty of care” As is outlined in the following section on data trustees, it can be difficult for a singular entity to maintain a duty of care and undertake actions with the best interest of a community when that community consists of sub-communities that may be marginalised. Further, ‘duty of care’, ‘best interest’, and ‘absence of harm’ are not sufficient standards for data processing by data custodians. Recommendations to the effect of obligating data custodians to uphold the rights of data principals, including economic and fundamental rights need to be incorporated in the framework. Clause 4.9: Data trusteesThe committee’s suggestion
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
to mean “such irreversible process of transforming or converting personal data to a form in which a data principal cannot be identified”. From a plain reading, it appears that the Report proposes a lower threshold of the anonymization requirements governing non-personal data. It is unclear how non-personal data would then be different from inferred data as described within the definition of personal data under the PDP Bill. This adds regulatory uncertainty making it imperative for the Committee to articulate bright-line, risk-based principles and rules for the test of anonymization. Such rules should also indicate the factors that ought to be taken into account to determine whether anonymization has occurred and the timescale of reference for anonymization outcomes
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
Clause 4.1 (iii) and Recommendation 1: Defining Non-Personal Data The Report proposes the definition of non-personal data to include (i) data that was never related to an identified or identifiable natural person, and (ii) aggregated, anonymised personal data such that individual events are “no longer identifiable”. In doing so, they have attempted to extend protections to categories of data that fall outside the ambit of the Personal Data Protection Bill, 2019 (hereafter “PDP Bill”). The Report is cognizant of the fallible nature of anonymization techniques but fails to indicate how these may be addressed. The test of anonymization in regarding data as non-personal data requires further clarification. Anonymization, in and of itself, is an ambiguous standard. Scholarship has indicated that anonymised data may never be completely anonymous. Despite this, the PDP Bill proposes a high threshold of zero-risk of anonymization in relation to personal data,
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
The Report does not acknowledge that the very technological processes that may have rendered the articulation of collective privacy necessary, also are intended to create ad-hoc and newer sets of individuals or groups with shared attributes. In doing so, the Report furthers an ontology of groups having intuitive, predetermined attributes that exist naturally, or in law, whereas the intervention of data collection and processing technologies can determine shared group attributes afresh. Moreover, the Report also ignores that predetermined attributes are static, and in doing so, ignores a vast existing literature speaking to fluidity of identities and the intersectionality of identities that individuals in groups occupy. We fully appreciate the challenges these pose in the determination of the legal contours of collective privacy. Much of the Report’s recommendations are premised on the idea of a predetermined collective, rendering more granular exploration of these ideas urgent.
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
Clause 3.8 (iv): Introducing collective privacy The introduction of collective privacy has initiated an overdue discussion at the policy level to arrive at privacy formulations that account for limitations in the contemporary dominant social, legal and ethical paradigms of privacy premised on individual interests and personal harm. The notion of collective privacy has garnered contemporary attention with the rise of data processing technologies and business models that thrive on the collection and processing of aggregate information. While the Report acknowledges that collective privacy is an evolving concept, it doesn’t attempt to define either collective or what privacy could entail in the context of a collective. The postulation of collective privacy as a legally binding right is bereft with challenges in both domestic and international legal frameworks.
Adarsh Pandey
Adarsh Pandey 4 years 3 months ago
Clause 3.7 (v): The role of the Indian government in the operation of data markets While highlighting the potential for India to be one of the top consumer and data markets of the world, it also sheds light on the concern about the possibility of data monopolies. The clause envisions the role of the Indian government as a regulator and a catalyst for domestic data markets. In doing so, the clause does not acknowledge that the proactive and dominant roles of the Indian government in generation and reuse of data, based on the existing data collection practices, as well as the provisions that have been given, as under the compulsory sharing provisions in the Report, and would continue to be given by the Personal Data Protection Bill. In reality, the Indian government’s role is not just of a catalyst but also of a key player, potentially with monopolistic market power, in the domestic data market, especially due to the ongoing data marketplace initiatives as detailed in published policy
KELLAMPALLISREEVISHNUTEJA
KELLAMPALLISREEVISHNUTEJA 4 years 3 months ago
it's is very good program. with help of it we can create your own database like maps, and we detect the online criminals who try to hack the official websites. we get security. we can't depends on others for digital frame programs. Thank you
Kumaraswamy HollaV
Kumaraswamy HollaV 4 years 3 months ago
Entry of address, contact number and email address may not be made mandatory while logging some complaints like finding orphans in few locations, finding some mischief, finding some accidents or reporting some medical emergency. Since many people step back rather than stepping forward to report to Government Authority based on their work priority.