HomePostsDigital RightsShould Consent be the Cornerstone for processing Health Data? Regulatory Perspectives from...

Related Posts

Should Consent be the Cornerstone for processing Health Data? Regulatory Perspectives from India

Introduction

In India, health data, among other personal information, will be governed by the incoming data protection legislation, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) once enforced. Consent, operationalised by the notice and choice framework, continues to be the cornerstone on which data processing, including that of health data, is founded. However, health data is uniquely sensitive, and processing of such data in the same manner as other forms of personal data poses challenges. While concerns regarding efficacy of consent-based models to process personal data have been debated upon in general, including in the Srikrishna Committee Report that gave recommendations for India’s data protection framework, these concerns become exponentially greater for health data. Steep information asymmetry between data principals and health data processors leaves data principals with very little choice even if their consent is taken for data processing. This blog post will explore the limitations of the consent based approach of the DPDP Act towards processing health data, and discuss alternative approaches to consent in safeguarding health data.

Defining health data

In India, the draft Digital Information Security in Healthcare Act, 2018 (“DISHA”) is the only legislative framework that defines digital health data. Unfortunately, it never became law. Under DISHA, digital health data means electronic records of health-related information. It gave separate definitions for digital health data and personally identifiable information, unlike in DPDP Act which only defines personal data and lacks a definition and categorisation of health data. DISHA further defines sensitive health related information to mean health data which would pose significant risks to the individual, if breached.

How the law uses Consent for processing health data

Under the DPDP Act, consent is express, informed and unambiguous. Where consent is the basis of processing personal data, the data principal has the right to withdraw consent. However, the consequences of such withdrawal have to be borne by the data principal.[1] The extent of these consequences remain untethered, and can be huge in terms of health data. For instance, if a person withdraws consent given to a health service provider, they could be denied ancillary health services by the service provider, or find it difficult to access a service in the future. This is because the law does not specify that the consequences of withdrawing consent should be proportionate to the purpose for which the consent was given in the first place. For patients dependent on frequent health services, such as diagnostic lab services, such consent actually makes them part with more autonomy, instead of equipping them with choice.

The DPDP Act’s imposition of virtually untethered consequences on withdrawal of consent is a more broadly-worded continuation of the information collection practices under India’s erstwhile  Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 (“SPDI Rules”). Under the SPDI Rules, not providing or withdrawing consent allowed the body corporate to not provide the goods or services for which the information was sought.[2] While the consequences of withdrawing consent are narrower than the DPDP Act’s provision on withdrawal of consent, the SPDI Rules do not exempt sensitive personal information, which includes health data from such consequences. Thus, under the SPDI Rules, information providers could be denied health services for withholding consent.

Why Consent is a lesser shield for health data

It may be argued that consent is a contractual necessity to avail services and hence the SPDI Rules, and by extension the DPDP Act, are not incorrect in denying goods and services on withdrawal of consent, especially when the SPDI Rules allow sensitive information collection under lawful contract. However, for health data, the concept of consent, as it exists in contract law, changes.

The Indian Contract Act defines consent as when two or more people are in agreement upon the same thing in the same sense.[3] But for a patient availing a health service, her understanding of what she is consenting to, or how the health data shared by her will be processed by the service provider, will never be at par with the knowledge of the data processor due to information asymmetry. The relationship between a seeker of health service and a health service provider is fraught with power imbalance, and is different from a consumer-seller scenario where the consumer has other options if the seller’s terms are not amenable.

The Srikrishna Committee Report addresses the problem of bundling consent with contract, by attaching product liability to the contract that enables information collection. This means that the contract is offered to the data principal as the end product instead of being used as a process, with notice and choice features, the lack of which would make the data fiduciary liable. However, this does not solve the problems with processing health data, where the stakes are higher due to power imbalance, greater information asymmetry, and greater dependence on the service at offer.

Protecting health data beyond Consent

1 – Weaken the enabling power of consent over health data

Health data can be protected by relying more on safeguards than consent. Daniel Solove advocates for “Murky Consent”, which authorises restricted and weak licence to use data. According to Solove, actual consent is missing under the notice and choice approach of the US, since inaction in indicating choice does not mean anything. The express consent approach in the GDPR is not scalable and would lead to consent fatigue. Solove argues that privacy consent is fictitious and bestows unwarranted legitimacy to use data which can be dangerous. Since the law pretends that people are consenting, the law should ensure that what people are consenting to is good. Hence, murky consent takes a middle position between consent and non consent, and comprises the duty to obtain consent appropriately, duty to avoid thwarting reasonable expectations, duty of loyalty and duty to avoid unreasonable risk.

2 – Mandate doctor-patient confidentiality level of trust as standard for health data processing

Traditionally, doctor-patient confidentiality has been the bastion of protecting health data. Various medical laws, like the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 and the Medical Termination of Pregnancy Regulations, 2003 impose secrecy obligations related to patient data. Mass digitisation, generation and resultant oversharing of health data with third parties have eroded the trust that was associated with doctor-patient confidentiality over health data. To protect health data, data fiduciaries and data processors should be held accountable to the same standard of trust as medical practitioners in possession of patient data. For instance, DISHA gave the status of custodian to any entity that collected digital health data, making it duty bound to protect the privacy, confidentiality and security of such data[4].

3 – Differentiating health data from other personal data

For the law to adequately protect health data, it must distinguish health data from other personal data. The DPDP Act may achieve additional safeguards for health data through Section 10, by notifying health data fiduciaries as significant data fiduciaries. These significant data fiduciaries could then be held to higher standards for processing health data, such as being prevented from commercialising data, and facing liability for coercive practices relating to collection and processing of health data.

4 – Data Trust

Data trust is a form of stewardship, wherein one party of stakeholders appoints a second party to look after and make decisions regarding its data, and the second party is held to a fiduciary responsibility in making data-related decisions that benefit the first party of stakeholders. Data trust helps in collective bargaining for data rights of a larger group of individuals and facilitates informed decision making, thus countering the problems of power imbalance and information asymmetry posed by health data processing.

Conclusion

The ideal approach for protecting health data is to look beyond using consent to legitimise data processing, and implement higher safeguards targeted at securing best interests of data principals. By distinguishing health data from other personal data, the law must create space for higher safeguards for processing data and not simply rely on consent to legitimise sharing and processing of health data. Considering the health information asymmetry, the enabling power of consent over health data processing must be weakened to make way for higher safeguards. These safeguards must be rooted in custodianship and stewardship, and must protect the interests of the data principal against exploitation of their health data.


[1] Section 6(5) of the Digital Personal Data Protection Act, 2023.

[2] Rule 5(7) of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011.

[3] Section 13 of the Indian Contract Act, 1872.

[4] Section 30(4) of the Digital Information Security in Healthcare Act, 2018.

Tithi Neogi
Research Analyst at the Centre for Communication Governance, National Law University Delhi (CCG-NLUD) |  + posts

Tithi is a Research Analyst at the Centre for Communication Governance, National Law University Delhi (CCG-NLUD). She is interested in exploring inclusive and intersectional approaches to Internet governance, specifically related to disability and digital health.

[citationic]

Featured Artist