India Releases Draft Non-Personal Data Governance Framework
Time 3 Minute Read
Categories: International

On July 13, 2020, a Committee of Experts within India’s Ministry of Electronics and Information Technology (“the Committee”) published the first draft of a Non-Personal Data Governance Framework for India for public consultation.

In drafting the framework, the Committee studied various issues relating to non-personal data and has put forward recommendations for consideration by the Indian Government on the regulation of non-personal data.

The Committee believes that regulating the data ecosystem is necessary to:

  • create a modern framework to unlock the economic, social and public value from using data;
  • create certainty and incentives for innovation and to encourage startups in India;
  • create a data sharing framework to enable the availability of data for social, public and economic good; and
  • address privacy concerns, including from re-identification of anonymized personal data.

Key takeaways of the Committee Report include:

  • Definition of Non-Personal Data: The Committee provides new definitions for different types of non-personal data (public, community and private) and defines the concept of “sensitive” non-personal data.
  • Consent for Anonymized Data: The Committee recommends that individuals who provide consent for the collection of their personal information must provide a separate consent for the anonymization and usage of anonymized data.
  • Key Non-Personal Data Roles: The Committee defines key roles that are to be governed by non-personal data rules and regulations—this includes data principal, data custodian and data trustee. The Committee also includes, in the framework, an institutional form of data infrastructure—a data trust.
  • Ownership of Non-Personal Data: The Committee recommends adopting the notion of “beneficial ownership/interest” in articulating a legal basis for establishing rights over non-personal data.
  • New Category of “Data Business”: The Committee recommends creating a new category of business called a “Data Business” that meets certain data threshold criteria. Such businesses will have to formally register and declare what they do and what data they collect, process and use, and in which manner and for what purposes they use the data. Metadata about data being collected by these businesses will be open-access within India, and data requests may be made for the detailed underlying data by other companies and the government.
  • Data Sharing Mechanisms: The Committee sets out a mechanism for mandatory data sharing for some forms of non-personal data. The Committee specifically notes that, with respect to private non-personal data, algorithms and proprietary knowledge may not be considered for data sharing.
  • Data Sharing Checks and Balances: The Committee recommends establishing several checks and balances to ensure appropriate implementation of the rules and regulations with respect to data sharing, including mimicking rules on data transfers that are applicable to personal data in the Personal Data Protection Bill 2019 (the “PDPB”).
  • Non-Personal Data Authority: The Committee recommends the creation of a separate non-personal data authority. This authority would be independent from the data protection authority proposed by India’s PDPB. In cases of mandated sharing, if an organization refuses to share requested data, the non-personal data authority will adjudicate the data sharing dispute.

Comments are due on the draft framework by September 13, 2020.

You May Also Be Interested In

Time 7 Minute Read

As we ring in the New Year, one thing remains the same: understanding the definitions and conditions in your insurance policy is critical. In a recent decision, a Florida federal court in Ohio Security Insurance Co. v. E Kelly Enterprises Inc. et al., No. 3:22-cv-24754, held that an insurer had no duty to defend or indemnify a general contractor and no duty to indemnify a subcontractor for damages from defective work on a naval base, based on the policy’s definition of “suit,” “property damage,” and allocation requirements. The decision highlights the importance of numerous issues in the context of commercial general liability policies, including the nuances of policy definitions, obtaining insurer consent when necessary, and allocation between covered and uncovered claims.

Time 1 Minute Read

On December 15, 2025, the Federal Trade Commission announced that it, along with 21 states and the District of Columbia, filed an amended complaint in the U.S. District for the Northern District of California alleging that Uber used unfair and deceptive billing and cancellation practices. 

Time 2 Minute Read

Nishith Desai Associates reports that on November 13, 2025, India’s Ministry of Electronics and Information Technology enacted India’s Digital Personal Data Protection Rules, 2025, which operationalize India’s Digital Personal Data Protection Act, 2023.

Time 2 Minute Read

On October 8, 2025, California Governor Newsom signed into law the Opt Me Out Act, which amends the CCPA to require web browsers to provide California consumers with the ability to send a single opt-out preference signal to all businesses with which the consumer interacts through the browser.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page