Minimalist IAS
2018 GS Paper III

UPSC CSE (Main) 2018 · GS Paper III · Question 19

Data security has assumed significant importance in the digitized world due to rising cyber crimes. The…

Syllabus line: Cyber security, media & money-laundering — “Challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security; money-laundering and its prevention.”

GS Paper III 2018 · Q19

15 marks · 250 words Cyber security, media & money-laundering

Data security has assumed significant importance in the digitized world due to rising cyber crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space?

Approach · directive: “what are the strengths and weaknesses”

What it asks · Assess the Committee's report and draft Personal Data Protection Bill: its strengths (rights-based, consent, regulator, penalties) and weaknesses (State exemptions, localisation, oversight, autonomy).

The question has 3 parts — answer each

  1. Strengths of the Report in protecting personal data: coverage, rights, enforcement
  2. Weaknesses of the Report: State exemptions, localisation, oversight and other gaps
  3. Your view: a verdict and what should change before enactment

Open with · Set up in July 2017 and reporting in July 2018 with a draft Bill, the Srikrishna Committee followed the Supreme Court's 2017 ruling that privacy is a fundamental right, and aimed at a 'free and fair digital economy'.

Cover

  • Strength, coverage: one law for government and private data fiduciaries, with principles of consent, purpose and collection limitation, data minimisation and transparency, and reach over processing linked to business in India.
  • Strength, rights: individuals get access, correction, portability and a limited right to be forgotten; fiduciaries owe a duty of fair and reasonable processing, with privacy by design.
  • Strength, enforcement: an independent Data Protection Authority, breach reporting, impact assessments for significant fiduciaries, and penalties of up to ₹15 crore or 4 per cent of global turnover.
  • Weakness, State exemptions: wide grounds such as security of the State and public order, without prior judicial approval, weaken protection against the State itself, the largest data holder.
  • Weakness, localisation: a mandatory local copy of all personal data and local-only storage of 'critical' data raise costs for firms, and may not improve security; the Centre defines what is critical.
  • Weakness, gaps: the proposed change to the RTI Act's personal-information exemption may weaken transparency, and the regulator's independence from the executive was questioned.
  • Way forward: tighter checks on State access (necessity, proportionality, oversight), a truly independent regulator, workable localisation rules, and public consultation before the Bill is enacted.

Close with · The report is a solid base for a rights-based regime; its credibility will depend on tighter checks on State access, a truly independent regulator and workable localisation rules.

Add value (verified)

Question: UPSC's CS (Main) 2018, GS Paper III — paper ↗. Approach: Minimalist IAS, checked 30 Sept 2026 (how we verify) — UPSC publishes no model answers. ·

Model answer · 313 words (UPSC limit 250) · Minimalist IAS

Set up in July 2017 and reporting in July 2018 with a draft Personal Data Protection Bill, the Srikrishna Committee followed the Supreme Court's 2017 ruling that privacy is a fundamental right, and aimed at a 'free and fair digital economy'.

Strengths

  • Coverage: one law binds government and private data fiduciaries alike, built on consent, purpose and collection limitation, data minimisation and transparency, and reaching processing linked to business in India.
  • Rights: individuals get access, correction, portability and a limited right to be forgotten; fiduciaries owe a duty of fair and reasonable processing, with privacy by design.
  • Enforcement: an independent Data Protection Authority, breach reporting, impact assessments for significant fiduciaries, and penalties of up to ₹15 crore or 4 per cent of global turnover give the law teeth.
  • Constitutional footing: it answers the Court's call, repeated in the Aadhaar judgment of September 2018, for a robust data protection regime that balances individual interests with legitimate State concerns.

Weaknesses

  • State exemptions: wide grounds such as security of the State and public order, without prior judicial approval, leave the largest data holder least constrained.
  • Localisation: a mandatory local copy of all personal data and local-only storage of 'critical' data raise costs for firms without clearly improving security, and the Centre alone defines what is critical.
  • Oversight and transparency: the regulator's independence from the executive was questioned, and the proposed change to the RTI Act's personal-information exemption could weaken transparency.
  • Process: the draft was framed without wide public consultation on its final text.

My view

  • The report is a sound, rights-based foundation, but its credibility rests on tighter checks on State access (necessity, proportionality, oversight), a truly independent regulator, workable localisation rules and open consultation before enactment.

A data protection law is only as strong as its limits on the State; with those limits fixed, the Committee's framework can turn the privacy right into everyday protection.

Written by Minimalist IAS from facts checked at source (how we verify) — a little fuller than exam length, so every part of the question is covered; in the hall, keep the structure and trim the detail. UPSC publishes no model answers: compare your structure and coverage with this, then write your own.

Also asked on this syllabus line

All questions on Cyber security, media & money-laundering →

Build the base: Prelims PYQs on this