Data protection regulation should not stifle innovation. Instead, it should focus on empowering users through information.
This brainstorm on data protection asks some fundamental questions. How does a data protection law impact individuals? How does it impact entities managing the data? How can the law be framed in terms of principles to remain relevant in the face of ever-changing technologies? I will leave the last part to the more seasoned lawyers in this brainstorming group. Also, I would add another important actor that we need protection from – the government.
The previous two pieces in this brainstorm highlight important points. Malavika Raghavan reminds us not to limit our thinking to the top-tier of data consuming audience but also think of “the 67 percent of Indian households that earn less than Rs 10,000 a month, share a phone among family members, and be first-time users of data-driven services and the internet.” For example, if law enforcement gets a warrant to tap a phone that belongs to a person then should they be bound to redact conversations that happen when another family members uses the same phone? I would say, yes. The new scenarios that come up by considering many different user profiles eventually benefit all of us.
Rahul Matthan goes beyond consent with a key assumption that a user mostly doesn’t know what he has consented to. He presents a strong focus on protecting users from any harm. The onus of the harm, as he points out, should be on the providers.

