(1) The Authority shall ensure the security of data maintained by it.
(2) Subject to the provisions of this Act, the Authority shall ensure confidentiality of data of families maintained by it.
(3) The Authority shall take all necessary measures to ensure that the data in the possession or control of the Authority, including information stored in the Family Information Data Repository is secured and protected against unauthorised access, use or disclosure and against accidental or intentional destruction, loss or damage.
(4) Without prejudice to sub-sections (1) and (2), the Authority shall-
(a) adopt and implement appropriate technical and organisational security measures;
(b) ensure that any person appointed or engaged for performing any function of the Authority under this Act or rules or regulations made thereunder follows appropriate technical and organisational security measures;
(c) ensure that the agreements or arrangements entered into with any person impose obligations equivalent to those imposed on the Authority under this Act and require such person to act only on instructions from the Authority or powers delegated by or on behalf of the Authority.
(5) Notwithstanding anything contained in any other State law for the time being in force and save as otherwise provided by or under this Act, no officer or other employee of the Authority shall, whether during his service or thereafter, reveal any data stored in the Family Information Data Repository or authentication record to anyone except for the purposes of planning or evaluation by the State Government or for the purpose of determining eligibility for or the provision of any subsidy, scheme, service or benefit.
(6) The information collected, verified or authenticated by the Authority in the Family Information Data Repository or created under this Act shall be shared only in such manner, as may be specified by regulations.
(7) No information of a family collected, verified or authenticated by the Authority in the Family Information Data Repository or created under this Act shall be published, displayed or posted publicly, except for the purposes, as may be specified by regulations.
Security and confidentiality of information.
32. Whoever impersonates or attempts to impersonate another person, whether dead or alive, real or imaginary by providing any false information knowingly, shall be punishable with imprisonment for a term which may extend to three years or with a fine which may extend to fifty thousand rupees or with both.
Penalty for impersonation.
33. Whoever, with the intention of causing harm or mischief to a Parivar Pehchan number holder, changes or attempts to change any information of a Parivar Pehchan number holder by impersonating or attempting to impersonate another person, dead or alive, real or imaginary, shall be punishable with imprisonment for a term which may extend to three years and shall also be liable to a fine which may extend to fifty thousand rupees.
Penalty for impersonation of Parivar Pehchan number holder by changing information.
34. Whoever, not being authorised to collect information under the provisions of this Act, by words, conduct or demeanour pretends that he is authorised to do so, shall be punishable with imprisonment for a term which may extend to three years and with a fine which may extend to one lakh rupees or, in the case of a company, every person who at the time the offence was committed was in charge of and was responsible to the company for the conduct of the business of the company, with imprisonment for a term which may extend to three years with a fine which may extend to ten lakh rupees or with both.
Penalty for impersonation claiming authority to collect information.
35. Whoever, not being authorised by the Authority, intentionally,-
(a) accesses or secures access to the Family Information Data Repository;
(b) downloads, copies or extracts any data from the Family Information Data Repository or stored in any removable storage medium;
(c) introduces or causes to be introduced any virus or other computer contaminant in the Family Information Data Repository;
Penalty for unauthorized access.
186 HARYANA GOVT. GAZ. (EXTRA.), SEPT. 6, 2021 (BHDR. 15, 1943 SAKA)
(d) damages or causes to be damaged the data in the Family Information Data Repository;
(e) disrupts or causes disruption of the access to the Family Information Data Repository;
(f) denies or causes a denial of access to any person who is authorised to access the Family Information Data Repository;
(g) reveals any information in contravention of sub-section (5) of section 31, or shares, uses or displays information in contravention of sub-section (7) of section 31 or assists any person in any of the aforementioned acts;
(h) destroys, deletes or alters any information stored in any removable storage media or in the Family Information Data Repository or diminishes its value or utility or affects it injuriously by any means; or
(i) steals, conceals, destroys or alters or causes any person to steal, conceal, destroy or alter any computer source code used by the Authority with an intention to cause damage, shall be punishable with imprisonment for a term which may extend to ten years and shall also be liable to a fine which shall not be less than fifty lakh rupees.
Explanation.— For the purposes of this section, the expressions “computer contaminant”, “computer virus” and “damage” shall have the meanings respectively assigned to them in the Explanation to section 43 of the Information Technology Act, 2000 (Central Act 21 of 2000), and the expression “computer source code” shall have the meaning assigned to it in the Explanation to section 65 of the said Act.
Penalty for tampering data.
36. Whoever, not being authorised by the Authority, uses or tampers the data in the Family Information Data Repository or in any removable storage medium with the intent of modifying information or discovering any information thereof, shall be punishable with imprisonment for a term which may extend to three years and shall also be liable to a fine which may extend to ten thousand rupees.
General penalty. 37. Whoever commits an offence under this Act or any rules or regulations made thereunder for which no specific penalty is provided, shall be punishable with imprisonment for a term which may extend to one year or with a fine which may extend to one lakh rupees or in the case of a company, with a fine which may extend to fifty lakh rupees or with both.
Offences by companies.
38. Where any offence under this Act has been committed by a company and it is proved that the offence has been committed with the consent or connivance of or is attributable to any neglect on the part of any director, manager, secretary or other officer of the company, such director, manager, secretary or other officer shall also be deemed to be guilty of the offence and shall be liable to be proceeded against and punished accordingly:
Provided that nothing contained in this sub-section shall render any such person liable to any punishment provided in this Act if he proves that the offence was committed without his knowledge or that he had exercised all due diligence to prevent the commission of such offence.
Penalties not to interfere with other punishments.
39. No penalty imposed under this Act shall prevent the imposition of any other penalty or punishment under any other law for the time being in force.
Cognizance of offences.
40. No court shall take cognizance of any offence punishable under this Act, save on a complaint made by the Authority or any officer or person authorised by it.
Public servants.
41. The Chairperson, Deputy Chairperson, members, officers and other employees of the Authority, while acting or purporting to act in pursuance of any of the provisions of this Act, shall be deemed to be a public servant within the meaning of section 21 of the Indian Penal Code, 1860 (Central Act 45 of 1860).
HARYANA GOVT. GAZ. (EXTRA.), SEPT. 6, 2021 (BHDR. 15, 1943 SAKA) 187 Power of State Government to issue directions.