[भाग II- ख ड 3(i)]
भारत का राजप
: असाधारण
(3) The body corporate or any person on its behalf shall not publish the
sensitive personal data or information.
(4) The third party receiving the sensitive personal data or information from
body corporate or any person on its behalf under sub-rule (1) shall not disclose it further.
7. Transfer of information.-A body corporate or any person on its behalf may transfer
sensitive personal data or information including any information, to any other body
corporate or a person in India, or located in any other country, that ensures the same level
of data protection that is adhered to by the body corporate as provided for under these
Rules. The transfer may be allowed only if it is necessary for the performance of the lawful
contract between the body corporate or any person on its behalf and provider of
information or where such person has consented to data transfer.
8. Reasonable Security Practices and Procedures.— (1) A body corporate or a person
on its behalf shall be considered to have complied with reasonable security practices and
procedures, if they have implemented such security practices and standards and have a
comprehensive documented information security programme and information security
policies that contain managerial, technical, operational and physical security control
measures that are commensurate with the information assets being protected with the
nature of business. In the event of an information security breach, the body corporate or a
person on its behalf shall be required to demonstrate, as and when called upon to do so by
the agency mandated under the law, that they have implemented security control
measures as per their documented information security programme and information
security policies.
(2) The international Standard IS/ISO/IEC 27001 on "Information Technology - Security
Techniques - Information Security Management System - Requirements" is one such
standard referred to in sub-rule (1).
(3) Any industry association or an entity formed by such an association, whose members
are self-regulating by following other than IS/ISO/IEC codes of best practices for data
protection as per sub-rule(1), shall get its codes of best practices duly approved and
notified by the Central Government for effective implementation.
(4) The body corporate or a person on its behalf who have implemented either IS/ISO/IEC
27001 standard or the codes of best practices for data protection as approved and notified
under sub-rule (3) shall be deemed to have complied with reasonable security practices
and procedures provided that such standard or the codes of best practices have been
certified or audited on a regular basis by entities through independent auditor, duly
approved by the Central Government. The audit of reasonable security practices and
procedures shall be carried cut by an auditor at least once a year or as and when the body
corporate or a person on its behalf undertake significant upgradation of its process and
computer resource.