HomeLatest NewsGovTechJCP recommendations on PDP Bill to negatively impact Digital India: IAMAI

JCP recommendations on PDP Bill to negatively impact Digital India: IAMAI

JCP suggestions substantially altered the bill's composition, transforming it from a personal data protection measure to a general data protection bill, says IAMAI.

Preferred Source of Google

The Joint Committee of Parliament’s (JCP) report on the Personal Bill, 2019 is not aligned with India’s technology objectives for the next decade, industry body Internet and Mobile Association of India (IAMAI) said in a statement on Thursday. The JCP report was presented to Parliament in December, and among its suggestions are stricter data localization standards, an expansion of the scope to non-personal data, and new frameworks for software and hardware testing.

According to the IAMAI, the JCP suggestions substantially altered the bill’s composition, transforming it from a personal data protection measure to a general data protection bill. This necessitates additional stakeholder discussions and impacts assessment reports prior to these suggestions being enshrined in law.

IAMAI believes that the proposals will have a detrimental effect on a cross-section of the technology industry, including large technology enterprises, technology services companies, and digital start-ups, which constitute the backbone of India’s aspirations for leadership.

Advertisement
Saksham Bharat 2026
Saksham Bharat 2026
A multi-stakeholder dialogue on skilling gap in Cybersecurity, Data Resilience and AI — and the roadmap to a Saksham Bharat.
Register Now →
VeeamON 2026 Tour India - Mumbai
VeeamON 2026 Tour India - Mumbai
A VeeamON 2026 India Leadership Series Mumbai for senior public sector and government technology leaders.
Register Now →
Cyber Surakshit Uttar Pradesh
Cyber Surakshit Uttar Pradesh
Find out strategies, frameworks and solutions for building a resilient and secure digital ecosystem across Uttar Pradesh.
Register Now →
VeeamON 2026 Tour India - Bengaluru
VeeamON 2026 Tour India - Bengaluru
A VeeamON 2026 India Leadership Series Bengaluru for senior public sector and government technology leaders.
Register Now →
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

Additionally, IAMAI stated that the JCP’s planned onerous data localization rules will increase business failure rates, create impediments to start-up growth, increase compliance expenses for businesses, and impede the social benefits of the digital economy. “It would also inevitably have a detrimental effect on Indian customers’ capacity to access a truly global internet,” IAMAI stated.

The JCP’s proposed additional requirement that the Data Protection Authority (DPA) consult with the Government of India (GOI) on all cross-border sensitive personal data transfers not only contradicts established global practises and undercuts the DPA’s role but also subjects data flows to a cumbersome and inefficient process, the statement said.

Also, the industry body said that the proposed retrospective need to bring back data collected overseas creates major organisational and technical hurdles, all the more so because relevant organisations would be subject to laws that were not in effect at the time data was collected.

Advertisement

It stated that while JCP broadens the bill’s reach to encompass non-personal data, it fails to account for the two bills’ distinct value propositions. “This advice is also premature, given the report of the Expert Committee on non-personal data has not yet been approved.”

Additionally, the JCP proposes that the DPA establish a system for monitoring, testing, and certifying computing device hardware and software. “IAMAI asks the government to avoid from developing new standards in light of the well-established regulation that applies to devices marketed in India. Additionally, such a mandate would jeopardise India’s capacity to attract international enterprises and investment,” it stated.

It also stated that existing laws and regulations adequately handle the requirements for hardware and software certifications, which should not be imposed under the PDP Bill.

Advertisement

IAMAI argued that the Government should reconsider its advice that intermediaries be treated as publishers under some cases. Social media intermediaries continue to be protected by safe harbour laws and are not regulated as publishers, despite the fact that their “capacity” to control content is based on a legal requirement. Such a clause might have a significant impact on social media platforms are used, on free expression, and on . Additionally, it poses a risk to the digital ecosystem, especially given that it is unrelated to data protection.

IAMAI also expressed reservations about the proposed introduction of an 18-year-old age restriction on certain services. “Such a prohibition would remove a sizable demographic from the digital ecosystem and would contravene the majority of data regimes, which include enabling provisions for adolescents aged 13 to 18. The government should implement a risk-based strategy for children’s consent age that is graded and commensurate to the type and nature of services offered,” the report stated.

Setting a blanket consent age of 18 years will violate the notion of ‘the kid’s best interest’ in a digital world, as it will create hurdles for a youngster to access educational and recreational opportunities available on the internet.

The group requested the government to reconsider the JCP’s ‘transparency’ mandate. “It is very broad and may encroach upon the data fiduciaries’ intellectual property rights. It may be harmful to data fiduciaries if they are mandated to publicly disclose their algorithms and other proprietary information, without adequate safeguards.”

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Sanjay Singh
Sanjay Singh
Sanjay Singh covers startups, consumer electronics and telecom for TechObserver.in
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

India to Lead Global IT Security Standards Body for Two Years

India will chair the Common Criteria Development Board from April 2026, gaining influence over international IT security certification standards recognised by 38 countries.

RELATED ARTICLES