The Blockchain and Crypto Assets Council (‘BACC’) has recently pointed out that India can learn from Singapore on how to regulate cryptocurrencies. This is because Singapore has struck a delicate balance between discouraging illegal activities pursued through cryptocurrency, while simultaneously nourishing innovation. The BACC’s recommendation is astute. Previous efforts to regulate cryptocurrency in India failed to study the Singaporean model carefully, and a course correction may unlock an enabling framework for virtual currencies in India.
The example mentioned above is illustrative of a less than robust engagement with global tech regulation in India. More recently, engagement tends to favour Western jurisdictions and overlook jurisdictions in the East, or elsewhere. The National Digital Health Mission Health Data Management Policy, mimicked the Personal Data Protection Bill, 2019, which in turn had borrowed substantially from the EU GDPR. Such a series creates a ‘selection bias’, unleashing a vicious circle of imitating the West. In this piece, we advocate dismantling this bias and make a case for also looking at the development of law and policy in eastern jurisdictions.
Read More+
Scholars have observed that in developmental states, like jurisdictions in East Asia, regulatory models were shaped by pressures flowing from financial globalisation. Therefore, the rules that were framed for the regulatory frameworks in these jurisdictions, were primarily at the behest of Western nations and international financial institutions. In India, these rules are often at odds with the limited state capacity at hand. Present day scholars have criticised this as a “mismatch between the Indian state’s ambitions and its abilities”, attributing the mismatch to the Indian elite’s urge to mimic policies more appropriate to developed nations. We study this mismatch in the context of recently proposed tech regulations in India, and outline a paradigm to attenuate the concerns surrounding a ‘Look West’ approach to regulation. We term this new paradigm, the ‘Look East’ approach.
The overzealous adaption of Western precedent in Indian lawmaking has resulted in concern and uncertainty for tech regulation in India on two counts. These are capacity, and compliance costs. Often, Indian lawmaking has sought to adapt regulation from jurisdictions that outperform India on state capacity. In trying to ape advanced jurisdictions such as the UK or USA, India sets out to do as much as these countries, with a fraction of the resources. Consequently, well-intentioned regulation becomes difficult to implement.
The capacity critique has shadowed the evolution of tech regulation in India. An article analysing the White Paper of the Committee of Experts on Data Protection noted the stark ‘capacity gap’ prevailing between the countries surveyed under the White Paper, and India. It observed that the initial capacity of a proposed data protection regulator in India will be low. Faced with a broad mandate, the regulator may always bear an undue load, seeking to accomplish several regulatory outcomes in the face of low capacity.
This notion of a broad mandate rings true for the Personal Data Protection Bill, 2019 (‘PDP Bill’). The PDP Bill requires a robust Data Protection Authority (‘DPA’) to set standards for data security and anonymity, certify Privacy by Design policies undertaken by firms, and appoint relevant personnel to enforce the array of rights granted to individuals under the PDP Bill.
The demand for state capacity for regulating data does not stop here. More recently, a Committee of Experts constituted by the Union Government – buoyed by Western precedent – supported the creation of a Non-Personal Data Authority to facilitate data sharing among players. The development indicates India’s willingness to set up two regulators for governing data, which is one more than most countries. Mobilising capital and skilled personnel for both regulators, ensuring robust co-ordination between these and other sectoral regulators, and building capacity to ensure the robust enforcement of possibly several data regulations are challenges that may potentially overwhelm the efficient deployment of data governance norms in India.
The cost of compliance argument is a straightforward one. Previous work has highlighted the potentially onerous costs businesses incur as a consequence of EU-centric data protection models; a firm with 500 employees is expected to spend about $3million to comply with the GDPR. Transplanting significant chunks of tech regulation from the EU is poised to lead to an imposition of similar costs on Indian businesses.
A look at the PDP Bill helps illuminate the possibly costly nature of data protection in India. In order to provide for the vast array of rights guaranteed to individuals under the Bill, each entity processing the personal data of individuals has to bear costs. Further costs are involved in appointing key managerial personnel in accordance with the provisions of the proposed law. Lastly, costs escalate in accordance with the data processed; entities identified as processors of sensitive personal data may be subject to enhanced checks (impact assessments, audits, mandatory domestic storage of personal data, etc.) that drive up their cost of compliance. It is also likely that such costs will disproportionately affect small and medium enterprises.
We understand that it is neither possible, nor desirable, to completely divorce India from tech regulation in the West. Nevertheless, trialling a Look East perspective does have merits. First, tech regulation in the East has actively controlled for costs. For instance, Singapore’s PDPC has permitted organisations to levy reasonable charges for processing requests for accessing personal data, anticipating the ‘incremental costs’ associated with handling such requests. Similarly, Hong Kong’s privacy regulator has released information leaflets providing guidance on data ethics for SMEs. Such targeted data governance policies for SMEs help them to calibrate costs while achieving data protection, and ensure compliance in a manner suitable to the size of the entity.
Second, regulation in the East offers significant insight on building tech-policy capacity for a developmental state. Multilateral mechanisms such as the Asia-Pacific Economic Co-operation’s Privacy Framework, 2015 prioritise data protection related capacity-building for Member States. The Framework may help India balance the rights, and laissez faire approaches to privacy. The Framework also promotes self-regulation as a means to enforce privacy principles, distributing some of the cost of enjoying privacy onto the industry itself. This frees up capacity for the State.
It is clear that looking Eastward could unlock a more holistic approach to tech-regulation in India. For a start, regulators can introduce ‘diversity-audits’ into the pre-legislative process. Prior to publication, a consultation paper may be audited to assess the range of precedents considered to arrive at findings. Upon completing such audits, documents that insufficiently engage with cost-and-capacity-calibration could be flagged for revision.
Furthermore, regulators may expressly call for contributions that study alternative regulatory paradigms. Contributors may explicitly be told to also look Eastwards. Comments received along these lines may be separately tagged and archived. Not only would such measures prompt Indian policymakers to rethink their western bias, it could also substantially enrich the fabric of future tech regulation in India.
This article was originally published in The Times of India on 19 October 2021 Co-written by: Sohini Banerjee, Research Fellow; K.S. Roshan Menon, Research Scholar. Click here for original article
Read Less-
Contributed by: Sohini Banerjee, Research Fellow; K.S. Roshan Menon, Research Scholar
Disclaimer
This is intended for general information purposes only. The views and opinions expressed in this article are those of the author/authors and does not necessarily reflect the views of the firm.
The Bar Council of India does not permit solicitation of work and advertising by legal practitioners and advocates. By accessing the Shardul Amarchand Mangaldas & Co. website (our website), the user acknowledges that:
Click here for important public notice from the Firm.