Showing posts with label Privacy Law In India. Show all posts
Showing posts with label Privacy Law In India. Show all posts

Monday, June 6, 2011

Right To Privacy Bill Of India 2011

Law minister Veerappa Moily is planning to introduce the privacy law of India in the forthcoming monsoon session of the parliament. Till now we have no dedicated statutory privacy law in India. The Supreme Court of India has interpreted right to privacy as a fundamental right under article 21 of the constitution of India.

The need to have a privacy law in India has arises as Indian government has launched many e-surveillance and national security related projects without proper privacy and civil liberties safeguards. Projects like Aadhar, National Intelligence Grid (Natgrid), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

Now law ministry is trying to give some minimum privacy safeguards from these projects. The right to privacy bill 2011 of India would provide for such a right to citizens of India and to regulate collection, maintenance, use and dissemination of their personal information. The Bill also contains penal provisions for violation of privacy rights.

The Bill says, “every individual shall have a right to his privacy — confidentiality of communication made to, or, by him — including his personal correspondence, telephone conversations, telegraph messages, postal, electronic mail and other modes of communication; confidentiality of his private or his family life; protection of his honour and good name; protection from search, detention or exposure of lawful communication between and among individuals; privacy from surveillance; confidentiality of his banking and financial transactions, medical and legal information and protection of data relating to individual.”

The bill gives protection from a citizen's identity theft, including criminal identity theft (posing as another person when apprehended for a crime), financial identify theft (using another's identity to obtain credit, goods and services), etc.

The bill prohibits interception of communications except in certain cases with approval of Secretary-level officer. It mandates destruction of interception of the material within two months of discontinuance of interception.

The bill provides for constitution of a Central Communication Interception Review Committee to examine and review the interception orders passed and is empowered to render a finding that such interception contravened Section 5 of the Indian Telegraphs Act and that the intercepted material should be destroyed forthwith. It also prohibits surveillance either by following a person or closed circuit television or other electronic or by any other mode, except in certain cases as per the specified procedure.

As per the bill, no person who has a place of business in India but has data using equipment located in India, shall collect or processor use or disclose any data relating to individual to any person without consent of such individual.

The bill mandates the establishment of a Data Protection Authority of India, whose function is to monitor development in data processing and computer technology; to examine law and to evaluate its effect on data protection and to give recommendations and to receive representations from members of the public on any matter generally affecting data protection.

The Authority can investigate any data security breach and issue orders to safeguard the security interests of affected individuals in the personal data that has or is likely to have been compromised by such breach.

The bill makes contravention of the provisions on interception an offence punishable with imprisonment for a term that may extend up to five years or with fine, which may extend to Rs. 1 lakh or with both for each such interception. Similarly, disclosure of such information is a punishable offence with imprisonment up to three years and a fine of up to Rs. 50,000, or both.

Further, it says any persons who obtain any record of information concerning an individual from any officer of the government or agency under false pretext shall be punishable with a fine of up to Rs. 5 lakh.

For some strange reasons, the law ministry has not made the Bill public. By making the Bill public useful public inputs could have been obtained. Without analysing the copy of the Bill, we cannot comment upon the legality and constitutionality of the same. All we can say at this point of time is that the proposed Bill must protect human rights in cyberspace to be valid and constitutional and it must respect the privacy rights of Indian in the information age.

Saturday, June 4, 2011

Cloud Computing Policy Of India

Cloud computing is the buzz word in India these days. However, the crucial question is whether cloud computing is a viable option in India? Cloud computing is based upon essentials like privacy protection, data protection and data security. India has none.

There is no cyber security in India and even cyber security policy of India is missing. There is no privacy law in India. There is no data protection law in India. And there is no data security law in and cyber security law in India. In short, there is no legal framework for cloud computing in India at all. With these negative developments India should not use software as a service (SaaS) and cloud computing for crucial governmental services.

In fact, cloud computing in India is a new landmine for privacy in India. For instance, in order to safeguard its commercial interests in India, Research in Motion’s (RIM) Blackberry has established a framework that would allow Indian intelligence agencies to monitor contents on its messenger service. Interestingly, this e-surveillance arrangement is cloud computing based and this shows how vulnerable cloud based systems can be for violating civil liberties.

India is not ready for cloud computing and in order to effectively use the benefits of cloud computing and saas we must have a cloud computing policy of India. This cloud computing policy must clearly incorporate essential civil liberties safeguards, lawful interception law related principles, e-surveillance policy of India, cyber security policy of India and other similar policies.

Presently, India is giving too much importance to commercial interests and e-surveillance activities and this may hamper the growth of cloud computing in India. It is high time to formulate effective cloud computing policy of India.

Friday, June 3, 2011

Right To Privacy In India In Pipeline

Privacy law in India is the need of the hour. This is more so where privacy rights in India are frequently violated through various e-surveillance projects of Indian government. India has no dedicated privacy law. The Supreme Court of India interpreted it by expanding the scope of Article 21 of the Constitution.

Meanwhile, Indian government launched projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

These projects have also raised serious privacy violations issues as well that have still not been redressed by Indian government.

Realising that this may cause problems in future, the Law Ministry of India is working on a proposal to make right to privacy a fundamental right in the Indian Constitution. This is the right approach as without privacy safeguards all the recently launched projects of Indian government are “unconstitutional”.

We are working on making right to privacy a fundamental right. It is likely to be tabled in the monsoon session of Parliament. However, it's difficult to commit the timeframe, law minister Veerappa Moily said.

The right to privacy would include the right to confidentiality of communication, confidentiality of private or family life, protection of his honour and good name, protection from search, detention or exposure of lawful communication between individuals, privacy from surveillance, confidentiality of banking, financial, medical and legal information, protection from identity theft of various kinds, protection of use of a person's photographs, fingerprints, DNA samples and other samples taken at police stations and other places and protection of data relating to individual.

Many of these are already observed at a practical level. For example, it's a part of professional ethics of a lawyer or a doctor not to reveal details about clients or patients. The same applies for the banking sector. Apart from strengthening norms for interception of communication, the proposed Act will guarantee an individual's right to privacy. It's similar in the way the Constitution guarantees existing fundamental rights like right to equality, right to freedom of expression etc," explained a senior law ministry official.

The proposed legislation must be enacted keeping in mind the techno legal aspects. Technology would create serious challenges before Indian government and necessary provisions must be incorporated to deal with the same in future.