Regulations in E Commerce
Regulations in E Commerce
Regulations in E Commerce
Overview: Regulations
• EU
• General Data Protection
• Digital market Act
• Digital services Act
• AI Act
• India
• Digital personal data protection
• E-commerce rules
• Other related rules
General Data Protection Regulation
• Drafted and passed by the European Union (EU); put into effect from May ,2018
• It imposes obligations onto organizations anywhere, so long as they target or collect data related to
people in the EU
• Right to privacy: “Everyone has the right to respect for his private and family life, his home and his
correspondence.”
• Personal data
• Names and email addresses; Location information, ethnicity, gender, biometric data, religious beliefs
• Data subject
• The person whose data is processed
• Data processing
• Any action performed on data; collecting, recording, organizing, structuring, storing, using, erasing
• Data controller
• Owner or employee in your organization who handles data
• Levy harsh fines against those who violate its privacy and security standards
GDPR: Obligation for Companies
• Accountability
• Maintain detailed documentation of the data you’re collecting, how it’s used, where
it’s stored, which employee is responsible for it, etc
• Data security
• Limiting access to personal data to only those employees in your organization who
need it
• Data protection by design and by default
• Minimize the amount of data and how you will secure it with the latest technology
• Processing data
• Allowed to process data only if there is unambiguous consent from the data subject
• Consent
• Freely given, specific, informed and unambiguous
Source: What is GDPR, the EU’s new data protection law? - GDPR.eu
GDPR: People’s privacy rights
• The right to be informed
• The right of access
• The right to rectification
• The right to erasure
• The right to restrict processing
• The right to data portability
• The right to object
• Rights in relation to automated decision making and profiling
Digital Markets Act: Regulating
Big
• A levelTech
playing field for all digital companies, regardless of their size
• Stop them from imposing unfair conditions on businesses and consumers
• Ranking services and products offered by the gatekeeper itself higher than
similar services or products offered by third parties on the gatekeeper's
platform or not giving users the possibility of uninstalling any preinstalled
software or app.
• Interoperability between messaging platforms
• Set out the criteria for identifying large online platforms as gatekeepers
• European Commission will have the power to carry out market investigations
Digital Services Act: Safer
digital space
• Will give people more control over what they see online
• Users will have better information over why specific content is
recommended to them and will be able to choose an option that does
not include profiling
• Targeted advertising will be banned for minors and the use of sensitive
data, such as sexual orientation, religion or ethnicity, won’t be allowed
• Help tackle harmful content
EU AI Act
• Better conditions for the development and use of this
innovative technology
• Unacceptable risk
• Cognitive behavioral manipulation of people or specific vulnerable
groups
• Social scoring: classifying people based on behavior, socio-economic
status or personal characteristics
• High risk
• Toys, aviation, cars, medical devices and lifts
• AI systems falling into specific areas that will have to be registered
in an EU database
• All high-risk AI systems will be assessed before being put on the
market and also throughout their lifecycle.
• Transparency requirements
• Disclosing that the content was generated by AI
Indian Digital Personal Data Protection Bill, 2023
• Data Fiduciaries
• Persons, companies and government entities who
process data) for data processing (that is,
collection, storage or any other operation on
personal data);
• Data Principals
• The person to whom the data relates
• Data Protection Board
• Oversee the implementation
• Financial penalties for breach of rights,
duties and obligations
Digital Personal Data Protection Bill: Principle
• Consented, lawful and transparent use of personal data
• Purpose limitation
• Data minimisation
• Data accuracy
• Storage limitation
• Reasonable security safeguards
• Accountability
Digital Personal Data Protection Bill: Right to individual