THE GAZETTE OF INDIA : EXTRAORDINARY
[ PART II-SEC. 3(i)]
(3) The body corporate or any person on its behalf shall not publish the
sensitive personal data or information.
(4) The third party receiving the sensitive personal data or information from body
corporate or any person on its behalf under sub-rule (1) shall not disclose it further.
7. Transfer of information.-A body corporate or any person on its behalf may transfer
sensitive personal data or information including any information, to any other body corporate or a
person in India, or located in any other country, that ensures the same level of data protection that
is adhered to by the body corporate as provided for under these Rules. The transfer may be
allowed only if it is necessary for the performance of the lawful contract between the body
corporate or any person on its behalf and provider of information or where such person has
consented to data transfer.
8. Reasonable Security Practices and Procedures.— (1) A body corporate or a person on its
behalf shall be considered to have complied with reasonable security practices and procedures, if
they have implemented such security practices and standards and have a comprehensive
documented information security programme and information security policies that contain
managerial, technical, operational and physical security control measures that are commensurate
with the information assets being protected with the nature of business. In the event of an
information security breach, the body corporate or a person on its behalf shall be required to
demonstrate, as and when called upon to do so by the agency mandated under the law, that
they have implemented security control measures as per their documented information security
programme and information security policies.
(2) The international Standard IS/ISO/IEC 27001 on "Information Technology - Security
Techniques - Information Security Management System - Requirements" is one such standard
referred to in sub-rule (1).
(3) Any industry association or an entity formed by such an association, whose members are selfregulating by following other than IS/ISO/IEC codes of best practices for data protection as per
sub-rule(1), shall get its codes of best practices duly approved and notified by the Central
Government for effective implementation.
(4) The body corporate or a person on its behalf who have implemented either IS/ISO/IEC
27001 standard or the codes of best practices for data protection as approved and notified under
sub-rule (3) shall be deemed to have complied with reasonable security practices and
procedures provided that such standard or the codes of best practices have been certified or
audited on a regular basis by entities through independent auditor, duly approved by the Central
Government. The audit of reasonable security practices and procedures shall be carried cut by an
auditor at least once a year or as and when the body corporate or a person on its behalf undertake
significant upgradation of its process and computer resource.
[F. No. 11(3)/2011-CLFE]
N. RAVI SHANKER, Jt. Secy.
Printed by the Manager, Government of India Press, Ring Road. Mayapuri. New Delhi-110064
and Published by the Controller of Publications, Delhi-1 I0054