[Law & Policy Pod] Shweta
![[Law & Policy Pod] Shweta [Law & Policy Pod] Shweta](https://lawbeat.in/sites/default/files/news_images/LAW&POLICYPOD.jpg)
After Whatsapp recently informed the Delhi High Court that it shall keep the rollout of its controversial Privacy Policy on hold till the Personal Data Protection Bill, 2019 is effectuated, Lawbeat reached out to Shweta Dwivedi, a ________ to unravel the ramifications of this decision on the Social Media giant.
Dwivedi’s perspective in this segment of Law & Policy Pod succinctly sheds light on various aspects of what such a suspension of the policy now means for Whatsapp’s user’s in India, what really is at stake for Whatsapp & whether this decision was a thought-out move for the social media giant.
Lawbeat: So what was the chronology of events like for this issue?
Dwivedi: The chronology of events dictate that after an investigation was ordered by the Competition Commission of India, the social media giant approached Delhi High Court, challenging it. WhatsApp then informed the Delhi High Court that it had voluntarily put the updated Privacy Policy on hold until the proposed privacy law (the Personal Data Protection Bill, 2019 (PDP Bill) in India comes into force.
As on now, Delhi High Court is yet to decide the matter on stay of the investigation ordered by the CCI on the grounds that the matter on WhatsApp’s privacy policies is sub-judice before various courts in India.
Interestingly, CCI in its detailed order observed that the updated Privacy Policy and Terms and Conditions are broad, vague, and non-transparent, since the users are not fully made aware of how their personal data can be shared and for what all purposes can it be used for, which will be subject-matter of the investigation by the Director General.
Lawbeat: Why did this policy come under the scanner in the first place?
Dwivedi: The controversy surrounding WhatsApp’s Privacy Policy began when it was announced around January 2021. Among other updates, the Privacy Policy mentioned that user data may be shared by WhatsApp with Facebook Inc. and its subsidiaries.
The previous updates to the Privacy Policy by WhatsApp in 2016 and 2019 provided users with an option to ‘opt-out’ if they didn’t want to share their data, and the users continued to avail the services in any case. However, this time, WhatsApp’s policy seemed like a ‘take-it or leave-out’ for the users. If users didn’t accept the revised Privacy Policy, they can longer avail the services.
Lawbeat: Right. Now that the updated policy has been suspended, where do the Whatsapp users of India stand?
Dwivedi: At this juncture, this essentially means that while WhatsApp will continue to inform the users of the updates,
“it will not force users to accept the updates nor will it discontinue/ limit the services until PDP Bill is enacted."
Lawbeat: What is the correlation between the PDP bill and WhatsApp’s Privacy Policy? What impact will our proposed Privacy Law have on Whatsapp?
Dwivedi: The PDP Bill was sent for consideration of the Joint Parliamentary Committee, which is to submit its report before the upcoming monsoon session. Going by media reports, several key changes are expected in the PDP Bill, one will have to wait and watch for the actual fine print.
“Once the new law is enacted, WhatsApp will need to assess if it’s Privacy Policy is complying with the new law or not.”
Dwivedi adds,
Some provisions of the PDP Bill may be worth a mention here, and may be considered by WhatsApp if retained in the new law:
The last version of PDP Bill provides that any person may process the personal data for the purposes consented to by the data principal (i.e. the users in this case), or purpose which is incidental to or connected with such purpose, and which the data principal would reasonably expect that such personal data shall be used for, having regard to the purpose, and in the context and circumstances in which the personal data was collected (Clause 5(b) of PDP Bill). This gives ample scope for creative drafting of the privacy policies.
At the time of collection of data, the users need to be given notice of the purpose of collection, right to withdraw the consent and the process for withdrawal, the individuals or entities with whom such personal data may be shared, so on and so forth (Clause 7(1)). The consent for processing needs to be free, informed, specific, clear and capable of being withdrawn (Clause 11(1)). For processing sensitive personal data (such as health data, biometric data, financial data, sexual orientation, etc.), explicit consent must be obtained from data principals.
“Broadly these principles also form part of the current privacy framework under the Information Technology Act, 2000 and the SPDI Rules, 2011. Where consent is taken by users for processing of personal date, they also need to be provided with an option to withdraw consent. This is what essentially what the industry and users have been demanding,” says Dwivedi.
Lawbeat: What’s in it for other stakeholders?
Dwivedi: The PDP Bill also provides grounds for processing of personal data without obtaining consent of the data principals, such as compliance with court orders, medical emergencies, health services, employment, etc.
Clause 14 lists out other reasonable purposes for processing of personal data without consent, which may include whistle blowing, mergers and acquisitions, prevention and detection of unlawful activity, and other grounds as may be provided by the Data Protection Authority. This leaves ample room for companies to creatively design and word their privacy policies as they would want to fall within one of the exceptions.
WhatsApp will either rely on consent approach, or try to fall within one of the exceptions for processing without consent. If the latter is not an option, the consent based approach will require them to provide an opt-out option to the users from sharing their personal data with Facebook and its subsidiaries. Interestingly, WhatsApp has 2 versions of its privacy policies globally.
"Their privacy policy for Europe is far too stringent than rest of the world given the stringent privacy regime there. In Europe, WhatsApp provides an opt-out option to users who do not wish to share their personal data with Facebook and its subsidiaries. WhatsApp will hence wait and watch for the fine print of the new law in India, and assess if the new law is a take-it or leave-it for WhatsApp."
Lawbeat: Do you think this (of suspending the Updated Privacy Policy till the Privacy Law is enforced) decision was well-thought out for the SM giant?
Dwivedi: As a data privacy lawyer, I would agree that this was the best available option to WhatsApp now given the strong resistance from all quarters in India, be the Government, the CCI or the courts. While India is a global technology hub and privacy laws have not been very robust historically, I believe its time that the new privacy law is strong and at par with global standards to inspire confidence of the users and citizens. If WhatsApp can have a separate privacy policy for Europe, there is no reason why India cannot be another exception for them.