The IT industry has welcomed the government?s statement that personal data sent to India by outsourcing companies will not be covered under the Information Technology Rules, 2011, introduced in April this year.

The rules, which require companies to take written consent from individuals about the use of sensitive personal information they collect, were a potential problem-point for outsourcing firms.

The government clarified on Wednesday that it was not the outsourcer but the companies collecting and sending the data that were responsible for protecting privacy.

On Thursday, IT lobby Nasscom and Data Security Council of India (DSCI) welcomed the statement issued by the Ministry of Communications & Information Technology (MCIT) in this regard.

Som Mittal, president, Nasscom said, ?Data security and privacy are key enablers for the growth of the global sourcing sector. However, the rules issued recently had created possible interpretation issues for outsourcing companies and we thank the government for their support in issuing the necessary clarifications.?

Body corporate (customers for the IT-BPO industry) located outside India will continue to be governed by the data protection legislations in their respective countries and the service providers in India, in turn, would be governed by the contracts signed between them and the outsourcing organisations. However, the service providers in India must follow ?reasonable security practices? for protecting sensitive personal information processed by them.

MCIT has said a body corporate providing services related to collection, storage, dealing or handling of sensitive personal data or information under contractual obligation with any legal entity located within or outside India is not subject to the requirement of the new rules.

The government has also clarified that the body corporate referred to under the new rules are Indian companies, removing the interpretation that the US and European companies sending data for processing to Indian outsourcers would have to follow Indian rules while collecting data in their countries.

?Providers of information? are natural persons (individuals) who provide their sensitive personal information to body corporates (customers) and not the outsourcing organisations in the context of outsourcing as was being interpreted by some of the law firms and attorneys, the ministry clarified.