What are the guidelines for the retention of electronic records as per Section 66E of the Information Technology Act, 2000, and how long must they be kept?
LE Asked by Legal Expert from India
Legal Information
Below is a comprehensive legal analysis based on Indian law for your question.
Section 66E of the Information Technology Act, 2000, addresses the violation of privacy through the unauthorized capture, publication, or transmission of images of a person's private area without their consent. While Section 66E itself does not directly provide guidelines for the retention of electronic records, it is essential to understand how this provision interacts with other sections of the Act and related laws concerning data retention.
For retaining electronic records, you should look to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as well as the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These rules guide how digital platforms and service providers manage and retain data, including personal information and sensitive data. Typically, personal data must not be retained for longer than necessary to achieve the purpose for which it was collected (as stipulated in Rule 5 of the 2011 Rules). This means that if the data is no longer useful or relevant, it should be deleted.
From a practical standpoint, organizations should establish a clear data retention policy that outlines how long different types of records will be retained. Generally, records related to business transactions may be kept for a period ranging from 5 to 7 years, based on business needs and legal requirements. For sensitive personal data, it is advisable to evaluate the necessity of retention regularly and ensure compliance with applicable data protection laws, including the upcoming Personal Data Protection Bill, which may further refine these requirements.
To implement these guidelines effectively, organizations should perform regular audits of their data retention practices, ensure that all employees are trained on compliance with privacy laws, and keep records of how and when decisions regarding data retention are made. In case of any incidents or breaches related to data retention, it is crucial to consult with legal experts to navigate the complexities of the law and ensure that the organization is compliant with all relevant regulations.
Disclaimer: AI-generated for educational purposes only. Does not constitute legal advice. Consult a qualified practitioner.