Changes to India’s data bill will lead to 'higher business failure rates'
A leading trade association says proposed alterations will make the legislation more generic and create barriers to growth


A parliamentary report recommending changes to India’s personal data bill has been described as being out of sync with the country’s ambitions for the future of its technology sector.
India’s Internet and Mobile Association of India (IAMAI) raised concerns about a Joint Parliamentary Committee (JPC) report on the Personal Data Bill 2019. The report reviewed the country’s first data protection law and was tabled in parliament last December.
The IAMAI said yesterday the recommendations have fundamentally altered the structure of the bill, morphing it from a personal data protection bill into a more generic data protection bill, according to the Economic Times. The organisation added it believes the bill will negatively impact parts of the tech industry, including large tech companies, tech services companies, and startups.
The report recommends introducing strict data localisation requirements, which the IAMAI said will lead to higher business failure rates, create barriers to growth for startups, increase costs of compliance for companies, and slow down the socioeconomic benefits gained from the digital economy. It added the changes will have a drastic negative impact on Indian consumers being able to access a truly global internet.
The JPC also suggested tasking the Data Protection Authority (DPA) with consulting the government on all cross-border sensitive personal data transfers. This not only contradicts established global practices and undermines the role of the DPA, the IAMAI argued, but also subjects data flows to a cumbersome and inefficient process.
It added the suggested retrospectively applicable requirement to bring back data taken abroad poses a number of operational and technical challenges. This is especially true since relevant businesses would be subject to policies which weren’t enforced at the time of data collection.
“This calls for wider stakeholder consultations and impact assessment reports before these recommendations are hardcoded into law,” said the IAMAI in its statement.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The association added that while the JPC expands the scope of the bill to include non-personal data, it fails to account for the different value propositions offered by the two.
The report also recommends the DPA should create a framework to monitor, test, and certify hardware and software for computing devices. The IAMAI urged the government to refrain from developing new standards as there is a time-tested regime which devices sold in the country are subjected to. It underlined this new requirement would hamper India’s ability to attract global businesses and investment, and that the current rules and regulations are sufficient to address hardware and software certification requirements.
The IAMAI also urged the government to review a suggested transparency requirement. This is very broad and may encroach upon data fiduciaries’ intellectual property rights, it said, adding it may be harmful if they're mandated to publicly disclose their algorithms and other proprietary information without adequate safeguards.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles
Analysis A new report released by the DSIT revealed the UK’s cybersecurity sector generated £13.2 billion over the last year
By Solomon Klappholz
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag
By George Fitzmaurice
-
Threat of cyber attacks to national security compared to that of chemical weapons
News The UK government has raised the threat level posed by cyber attacks, deeming it greater on average than an event such as the Salisbury poisoning
By Rory Bathgate
-
2022 Public Sector Identity Index Report
Whitepaper UK Report
By ITPro
-
Latitude Financial's data policies questioned after more than 14 million records stolen
News Some of the data is from at least 2005 and includes customers’ name, address, and date of birth
By Zach Marzouk
-
Latitude hack now under state investigation as customers struggle to protect their accounts
News The cyber attack has affected around 330,000 customers, although the company has said this is likely to increase
By Zach Marzouk
-
IDCARE: Meet the cyber security charity shaping Australia and New Zealand's data breach response
Case Studies IDCARE is recruiting a reserve army to turbocharge the fightback against cyber crime not just in the region, but in the interests of victims all over the world
By Zach Marzouk
-
Australia commits to establishing second national cyber security agency
News The country is still aiming to be the most cyber-secure country in the world by 2030
By Zach Marzouk