QuestionQ14

Common Themes

Which action should the CEO take?

  • A Assess the business risk of further processing in the absence of any regulations on anonymised data.
  • B Refer to India's Information Technology Act and the 2011 rules 3-8 for guidance on handling anonymised data.
  • C Obtain the consent of the data subjects because anonymous data must be treated as personal data at all times.
  • D Adhere to the Singapore guidelines on anonymization and the Hong Kong Guidance on Personal Data Erasure and Anonymization.
Explanation

India’s data-protection framework applies to data about an identifiable individual; properly anonymised data is therefore not automatically treated as personal data. Because re-identification can create privacy, security, and commercial risk, further use of an anonymised dataset should be preceded by a business-risk assessment rather than assuming consent is always required or applying non-Indian guidance as binding law.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!