Data protection law needs clarity on risk threshold for breaches: Group

BSA, which represents the global software industry, wants that rules in India’s data protection law give companies 72 hours for reporting breaches and have better clarity on “risk threshold”.

The Digital Personal Data Protection Act (DPDPA) became law in August and its rules are expected to be put up for public consultation after Lok Sabha elections. It asks companies to report breaches to a Data Protection Board.

“Cyber incidents are different from personal data breach incidents. There should be classification of risk thresholds based on factors such as the type of system affected – whether it’s linked to critical infrastructure like government identity databases – and the severity of the breach,” said Venkatesh Krishnamoorthy, country manager for India at BSA.

Read more

You may also like

Comments are closed.