According to Stephen Mathias, partner, Kochhar & Co, though the amount of compensation payable under Section 43A is unlimited, it fails to cover cases involving the government. As a large majority of banking institutions are part of the public sector, the provision seems feeble in protecting the rapidly evolving transactional space.
Section 72A makes the disclosure culpable only when there is an intention to cause wrongful loss or gain. However, such intent is hard to prove, often allowing companies to escape prosecution.
To modernise the regulatory framework in the transactional space, the government introduced the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, laying down guidelines for the collection, possession, storage and dissemination of personal data.
These Rules also promote reasonable security practices and require annual due-diligence and audit exercises to ensure conformity. Additionally, the Banking Codes and Standards Board of India lays down further safeguards on handling of personal data in financial transactions.
However, many of these requirements are optional in nature. One may contractually opt out of these, undermining the effectiveness.
“Till the Reserve Bank of India (RBI) starts penalising banks for non-adherence, its efforts are sure to be lacklustre. Some banks are yet to comply with even the old guidelines and the whole of the cooperative sector is outside the clutches of the regulator,” says Prashant Mali, president, Cyber Law Consulting.
He says RBI should also have separate guidelines for mobile payments. At present, the regulation of these platforms is weak. India’s tryst with encryption standards has further complicated the issue of data security. According to Salman Waris, founder partner, TechLegis, there exists a practical dichotomy between the RBI-mandated minimum standards (128-bit) and the maximum permissible encryption levels (40-bit), allowed by the department of telecommunications (DoT). “This often requires banks to obtain permissions and provide encryption keys to DoT, creating a hurdle in Ease of Doing Business for these entities," he says.
“The government may consider protecting personally identifiable information such as spending patterns, in addition to the current protection awarded to sensitive data. And, an enhanced security framework should always be promoted," says Vaibhav Parikh, partner, Nishith Desai Associates.
Consolidating the multi-layered Know Your Customer (KYC) requirements and proper implementation of the e-KYC system, alongside the development of a secured central digital database, such as Aadhaar, will also give a boost to e-transactions.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)