Andhra Pradesh Core Digital Data Authority (Effective Delivery of e-Services) Act, 2017
Chapter VI PROTECTION AND MAINTENANCE OF CORE DIGITAL DATA
General201741 sections8 chapters
Chapter VI PROTECTION AND MAINTENANCE OF CORE DIGITAL DATA
23. Security and Confidentiality of information
Statutory text
- (1) The Authority shall ensure the security of core digital data and authentication records of the same;
- (2) Subject to the provisions of this Act, the Authority shall ensure confidentiality of core data and authentication records of core entities, unless such information has been declared as public record by the law for the time being in force;
- (3) The Authority shall take all necessary measures to ensure that the information in the possession or control of the Authority, including information stored in the Core Digital Data Repository, is secured and protected against access, use or disclosure not permitted under this Act or regulations made thereunder, and against accidental or intentional destruction, loss or damage;
- (4) Without prejudice to sub-sections (1) and (2), the Authority shall,-
- (a) adopt and implement appropriate technical and organizational security measures;
- (b) ensure that the agencies, consultants, advisors or other persons appointed or engaged for performing any function of the Authority under this Act, have in place appropriate technical and organisational security measures for the information; and
- (c) ensure that the agreements or arrangements entered into with such agencies, consultants, advisors or other persons impose obligations equivalent to those imposed on the Authority under this Act, and require such agencies, consultants, advisors and other persons to act only on instructions from the Authority.
- (5) Notwithstanding anything contained in any other law for the time being in force, and save as otherwise provided in this Act, the Authority or any of its officers or other employees or any agency that maintains the Core Digital Data Repository shall not, whether during his service or thereafter, reveal any information stored in the Core Digital Data Repository or authentication record to anyone:
Chapter VI PROTECTION AND MAINTENANCE OF CORE DIGITAL DATA
24. Restriction on sharing Core Data
Statutory text
The core data, collected or created under this Act may be shared only in accordance with the provisions of this Act and in such manner as may be specified by regulations.
Chapter VI PROTECTION AND MAINTENANCE OF CORE DIGITAL DATA
25. Alteration of Core Data
Statutory text
- (1) In case any core data is found incorrect or changes subsequently, the UNICORE number holder shall request the Authority to alter such data in the Core Digital Data Repository in such manner as may be specified by regulations.
- (2) On receipt of any request under sub-section (1), the Authority may, if it is satisfied, make such alteration as may be required in the record relating to such entity and intimate such alteration to the concerned UNICORE number holder.
- (3) The Authority may, by regulation, permit a change in the core digital data, as a consequence of or incidental to a transaction or event that necessitates or has the effect of changing any element of a core digital data, and in all such cases, the Authority shall ensure that the aforesaid transactions shall be completed only after the aforesaid change has been committed simultaneously and in an automated manner in the databases of the Authority and of the owner of such core digital date, so as to ensure that the core digital maintained by the Authority remains current and always held to be the single source of truth in respect of such data.
- (4) The Authority may prescribe, by regulations, the appropriate procedures, application programming interfaces and standards for the purposes of giving effect to the requirements of sub-section (3).
Chapter VI PROTECTION AND MAINTENANCE OF CORE DIGITAL DATA
26. Disclosure of information in certain cases
Statutory text
- (1) Nothing contained in section 23 or 24 shall apply in respect of any disclosure of information, including identity information or authentication records, made pursuant to an order of a court not inferior to that of a District Judge; Provided that no order by the court under this sub-section shall be made without giving an opportunity of hearing to the Authority.
- (2) Nothing contained in section 23 or section 24 shall apply respect of any disclosure of information, including identity information or authentication records, made in the interest of national security in pursuance of a direction of an officer not below the rank of Joint Secretary to the State Government specially authorised in this behalf by an order of the Government.
PDF: pending for this language.