In India, the use of cookies on websites is governed by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which were issued under the Information Technology Act, 2000.
As per the rules, website operators are required to provide a clear and conspicuous notice to users about the use of cookies on their website and obtain their consent before placing cookies on their device. The notice should provide information about the purpose of using cookies, the type of data collected, and how it will be used.
The rules also require website operators to provide users with the option to withdraw their consent to the use of cookies at any time. Additionally, website operators are required to implement reasonable security practices and procedures to protect the personal data collected through cookies from unauthorized access or disclosure.
The website complies with these rules to ensure the protection of user data and avoid potential legal liability.
The key requirements for cookies policy:
- Provide a clear and conspicuous notice: The website provides a clear and easily understandable notice to users about the use of cookies on their website. This notice informs users about the purpose of using cookies, the type of data collected, and how it will be used.
- Obtain user consent: The website obtains the user's consent before placing cookies on their device. This consent is obtained through a clear and unambiguous affirmative action, such as clicking on an "I Agree" button or similar.
- Provide the option to withdraw consent: The website provides users with the option to withdraw their consent to the use of cookies at any time. Users should be able to easily and freely exercise this right without facing any negative consequences.
- Implement reasonable security practices: The website implements reasonable security practices and procedures to protect the personal data collected through cookies from unauthorized access or disclosure.
- Maintain records: The website maintains records of user consent for at least 3 years from the date of collection.
Additional Points to consider:
- Data Retention: The website retains the SPDI collected through cookies only for as long as it is necessary for the purposes for which it was collected. Once the purpose is fulfilled, the data must be deleted or anonym zed.
- Third-Party Cookies: The website uses third-party cookies, such as those for advertising or analytics purposes must also provide clear and transparent information about these cookies and obtain user consent for their use.
- Children's Data: The website collects data from children under the age of 18, they must obtain parental consent for the data collection and processing.
- Enforcement: The website complies with the IT rules. The penalties can include fines and imprisonment.
- Privacy Policy: The privacy policy includes information about cookies, such as what they are, how they are used, and how users can control or disable them. The policy is easily accessible and prominently displayed on the website.
- Consent Management: The website ensures that the consent obtained from users for the use of cookies is valid and informed. This means that users must be fully aware of what they are consenting to, including the purpose, type, and duration of the cookies.
- Opt-Out Mechanisms: Users have the option to opt-out of the use of cookies at any time. The website provides a clear and easy-to-use mechanism for users to do so.
- Cross-Border Data Transfers: If the website transfers personal data collected through cookies to another country, it must ensures that the receiving country has adequate data protection laws or those adequate safeguards are in place to protect the data.
- Data Subject Rights: Users have the right to access, rectify, or erase their personal data collected through cookies. The website provides an easy and accessible way for users to exercise these rights.
- Awareness and Training: The website ensures that their employees are trained on the importance of data privacy and how to comply with the IT rules. This includes regular awareness campaigns and training sessions.
It's important to keep in mind that India's legal landscape regarding data privacy and cookies is constantly evolving, so it's important to stay up-to-date with any new laws or regulations that may be introduced in the future. Overall, ensuring compliance with data privacy laws and regulations is an ongoing process that requires constant attention and updating.