ADVERTISEMENT
Trai: people have right over data, not firmsSays consumers be given the right to choice, consent and to be forgotten.
PTI
Last Updated IST
"The Right to Choice, Notice, Consent, Data Portability, and Right to be Forgotten should be conferred upon the telecommunication consumers," Trai recommended to the Department of Telecom. (File Photo)
"The Right to Choice, Notice, Consent, Data Portability, and Right to be Forgotten should be conferred upon the telecommunication consumers," Trai recommended to the Department of Telecom. (File Photo)

Directives

  • Transparently
  • disclose information about privacy breaches on websites
  • Mention actions taken for mitigation, and preventing such breaches in future
  • Data controllers should be prohibited from using pre-ticked boxes to gain users’ consent
  • Devices should disclose the terms and conditions of the use in advance

Amid rising concerns over privacy and safety of users’ data, the Telecom Regulatory Authority of India (Trai) on Monday said people should have a right over their data and not companies.

Trai, in its recommendation to the Department of Telecom on “Privacy, Security and Ownership of Data in the Telecom Sector”, said that consumers are owners of their data and firms controlling or processing such data are just custodians and do not have primacy rights on it.

“The Right to Choice, Notice, Consent, Data Portability, and Right to be Forgotten should be conferred upon the telecommunication consumers,” Trai recommended to DoT.

ADVERTISEMENT

Terming that the existing framework for the protection of personal information or data of telecom consumers was not sufficient, the regulator said that to prevent misuse of consumers’ personal data, all entities in the digital ecosystem, which control or process their personal data, should be brought under a data protection framework.

“Privacy by design principle coupled with data minimisation should be made applicable to all the entities in the digital ecosystem including service providers, devices, browsers, operating systems and applications,” the regulator said.

It said that in order to ensure sufficient choices to the users of digital services, granularities in the consent mechanism should be built in by the service providers.

The regulator also suggested that all entities in the digital ecosystem including telecom operators should transparently disclose the information about the privacy breaches on their websites along with the actions taken for mitigation, and preventing such breaches in future.

“The data controllers should be prohibited from using pre-ticked boxes to gain users’ consent. Devices should disclose the terms and conditions of the use in advance before the sale of device,” it said

The department of telecom should re-examine the encryption standards, stipulated in the licence conditions for the telecom service providers to align them with the requirements of other sector regulators, the Trai said.

Deccan Herald is on WhatsApp Channels| Join now for Breaking News & Editor's Picks

ADVERTISEMENT
Read more
(Published 16 July 2018, 19:00 IST)