Reforms in IT Act needed:
Expansion of the definition of sensitive personal data under Rule 3 of the Sensitive Personal
Data Rules:
– Categories of information such as mobile big data, machine-to-machine (M2M) data, and user behavior should also fall in the ambit of sensitive personal data
Government agencies and departments, non-profits must also be accountable to ensure data protection:
– At present, Section 43A of the Information Technology Act only covers body corporates engaged in “commercial or professional activities”. This excludes from any accountability government agencies such as the Unique Identification Authority of India, which issues Aadhar numbers, and others that are among the biggest gatherers of data in the country