Showing posts with label CCTNS. Show all posts
Showing posts with label CCTNS. Show all posts

Tuesday, March 13, 2012

National Counter Terrorism Centre Of India: The Problems and Solutions

This is the research analysis of Perry4Law and Perry4Law Techno Legal Base (PTLB) regarding the legality, constitutionality, requirements, etc of establishment of national counter terrorism centre of India. Perry4Law and PTLB have outlined all the legal constitutional and administrative issues at a single place so that parliament of India, home ministry and Indian government can consider the same. Perry4Law and PTLB hope that this analysis would be useful for all concerned.

National counter terrorism centre (NCTC) of India has been facing many ups and downs. This is despite the fact that national counter terrorism centre (NCTC) of India is required to meet the growing national security requirements of India.

However, there are many constitutional, legal and administrative challenges that NCTC is facing. In the past the NCTC of India was downsized in its nature, scope and functions. Now NCTC of India is facing stiff oppositions from various States that consider establishment of NCTC as an encroachment upon their law and enforcement powers and federalism features of Indian constitution.

However, these objections and oppositions are mostly politically motivated and are not truly striking at the real problem from which NCTC has been suffering. The real issue that must be demanded by political parties is that parliamentary oversight of intelligence agencies of India is needed. Till now there is no parliamentary scrutiny of the intelligence agencies in India.

Indian Government is too reluctant to ensure parliamentary oversight for intelligence agencies and law enforcement agencies of India. If this is not enough, Indian government has been launching new projects having serious “constitutional ramifications” and “civil liberties violation” effects.

For instance, the national counter terrorism centre (NCTC) project of India, national intelligence grid (Natgrid) project of India, Aadhar project of India, crime and criminal tracking network and system (CCTNS), etc are not governed by any legal framework and parliamentary oversight. Indian government is not willing to understand and accept that intelligence work is not an excuse for non accountability.

For some strange reasons intelligence infrastructure of India has become synonymous for non accountability and mess. There is neither any parliamentary oversight nor and transparency and accountability of the working of intelligence agencies of India.

Even a basic level effort to enact a legal framework for intelligence agencies of India is missing in India. The first and foremost challenge to such parliamentary oversight mechanism comes from the intelligence agencies themselves that do not wish to be governed by any rules and norms at all. Then we have “bureaucratic hurdles” in India that do not allow such a legal framework to be proceeded with. Finally, the parliament of India itself is not interested in bringing these intelligence agencies within the fold of parliamentary oversight.

Take the example of the recent private bill titled intelligence services (powers and regulation) bill, 2011. It was shelved out by none other than the Indian Prime Minister Dr. Manmohan Singh who announced that law on intelligence agencies would be formulated soon. However, it proved nothing but a “time gaining tactics” and so far intelligence agencies of India are not governed by any legal framework and parliamentary oversight. Interestingly, even the central bureau of investigation (CBI) is riding the same boat. The draft central bureau of investigation act, 2010 is another example where the Indian government is just interested in making “declaration” with no actual “intention” to implement the same.

In these circumstances, can the States trust the Centre regarding the establishment of National Counter Terrorism Centre (NCTC) of India? The answer is definitely negative even if States keep their “political interests” aside. Of course, there are “practical difficulties” and “internal turf war” among various agencies and ministries of Central government a well. It seems the obvious but unsolvable terrorism dilemma in India would continue as national interest of India and fighting terrorism is not a “national priority”.

Till now the constitutionality of the national investigation agency act 2008 (NIAA 2008) has not been accepted by States and now NCTC has been launched through an “executive order”. The practice of clubbing new projects, agencies and institutions with existing laws is a bad approach. So NCTC without a legal framework is definitely unconstitutional and even tagging it with the Unlawful Activities (Prevention) Act, 1967 would not save it from the patent and apparent unconstitutionality with which it is suffering.

The NCTC project of India is also “very significant” for the national security of India. Terrorist attacks against India are on increase and we need a “specilaised institution” like NCTC to provide and analyse valuable intelligence inputs and leads.

The real problem seems to be “lack of coordination and harmonisation” between the Centre and States. The Constitution of India has made a clear demarcation between the legislative, executive and judicial powers of Centre and State. The NIAA 2008 and NCTC are sitting at the “border line” of the legislative and executive powers of Centre that can be challenged by various States.

The intentions of Home Minister Mr. P.Chidambaram are good but the concerns of States are also of equal force. Further, the turf war between multiple intelligence agencies operating under different government ministries is also causing problem for the successful establishment of NCTC. Even there is a lack of proper planning and management on the part of Union Home Ministry that is causing delayed implementation of projects like Natgrid, NCTC, CCTNS, etc.

If Mr. P. Chidambaram really wants his projects to become successful, he has to think well beyond the present “parameters and objectives” set by Indian government in general his own ministry in particular. A good starting point can be formulation of a “constitutionally sound legal framework” that can confer legitimacy and constitutionality to projects like NATGRID, NCTC, CCTNS, etc. Obviously, States must be taken into confidence before starting any such legislative exercise.

This must be supplemented by sound planning and management. The projects of Home Ministry are neither simple nor easy to execute. They required dedicated efforts from all directions. Experts from diverse fields must be on panel of Home Ministry so that these Projects can be successfully implemented. We are sure Home Minister Mr. P. Chidambaram would have already considered these aspects and we wish all the best to him in this regard.

Friday, February 24, 2012

Phone Tapping Laws In India Required

Phone Tapping in India has never been a smooth ride. While Phone Tapping procedures essentially require a “Judicial Order” in most Jurisdictions of the World yet India preferred to keep Phone Tapping Procedure out of the reach of Indian Judiciary. The entire procedure of Phone Tapping is an “Executive Action” devoid of Judicial Interventions and Judicial Reviews.

Big Brother in India is Overstepping the Constitutional Limits. Neither there is a “Constitutionally Sound” Lawful Interception Law in India nor are the existing Laws like Indian Telegraph Act, 1885 strictly in compliance with Indian Constitution. Interestingly, Phone Tapping by “Private Individuals” in India is rampant and the Phone Tapping by Indian Government is “Practically Unaccountable”.

We have no Constitutionally Sound Lawful Interception Law in India. Even the Home Ministry of India has considered enactment of a Lawful Interception Law in India. A Constitutional Phone Tapping Law in India is needed to prevent Unconstitutional Phone Tapping in India.

However, the worst affected area seems to be Parliamentary Oversight of Intelligence Agencies of India and various E-Surveillance Projects of India. We have no E-Surveillance Policy in India as well. Further, the National Counter Terrorism Centre (NCTC) Project of India, National Intelligence Grid (Natgrid) Project of India, Aadhar Project of India, Crime and Criminal Tracking Network and System (CCTNS), etc are not governed by any Legal Framework and Parliamentary Oversight. Indian Government is not willing to understand and accept that Intelligence Work is not an excuse for Non Accountability.

The Central Monitoring System Project of India (CMS Project of India) is also not supported by any Legal Framework. Surveillance of Internet Traffic in India is also another area that requires a sound Legal Framework. The Phone Tapping Law proposed by the Home Ministry is a history now. Intelligence Services (Powers and Regulation) Bill, 2011 and Draft Central Bureau of Investigation Act, 2010 have long suggested and gone. The Constitutionality of the National Investigation Agency Act 2008 (NIAA 2008) is still doubtful. Even we have no dedicated Privacy Laws in India, Data Security Laws in India and Data Protection Laws in India.

In short, the Legal Regime in these crucial areas is in “Real Mess” and without these “Crucial Legislations”, the Projects and Initiatives of Indian Government cannot be considered to be Constitutional. Project s like Aadhar, NATGRID, NCTC, CCTNS, CMS, etc are “Violating Constitutional Safeguards” and are therefore “Unconstitutional”.

It is high time for the Parliament of India to interfere as the “Legislative Function” is about to be transferred to the “Executive Branch” of Indian Constitution and Indian Judiciary is looking at it in a helpless manner. The precious Human Rights in Cyberspace are under grave risks as there is none in India that can presently enforce Fundamental Rights and Human Rights in Indian Cyberspace. Perhaps, Proactive Self Defense in India Cyberspace must be exercised by Indian Citizens to “Safeguard” their Civil Liberties themselves as our own Executive, Legislature and Parliament have failed to do so.

Wednesday, December 21, 2011

Intelligence Gathering Is Not Above Right To Privacy In India

Right to privacy in India is a constitutional right. Efforts are in the process to make it a statutory right as well. A dedicated statutory right to privacy in India is in pipeline in the form of right to privacy bill of India 2011. The proposed Bill must protect human rights in cyberspace to be valid and constitutional and it must respect the privacy rights of Indians in the information age. The proposed draft right to privacy bill 2011 of India may confer some form of privacy rights to Indians. However, its true scope is yet to be made public.

Privacy laws in India and privacy rights in India have always been ignored. We have no national privacy policy in India as well. Data protection laws in India are missing and so are data privacy laws in India. Privacy, data protection and India seems to be separable and unrelated concepts.

Indian government launched projects like Aadhar, National Intelligence Grid (Natgrid), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under parliamentary scrutiny.

Further, there are some very crucial issues that are posing constitutional problems for the intelligence and security agencies of India. For instance, intelligence gathering in India is unconstitutional. Similarly, counter terrorism capabilities of India are not sufficient and Indian counter terrorism capabilities needs rejuvenation. Finally, parliamentary oversight and constitutional safeguards are missing in the functions of these agencies.

India does not have a constitutionally sound lawful interception law. Phone tapping in India is still done in an unconstitutional manner and at times by private individuals as well. Further surveillance of Internet traffic in India is now openly acknowledged by Indian government.

The intelligence infrastructure of India has become synonymous for non accountability and mess. There is neither any parliamentary oversight nor and transparency and accountability of the working of intelligence agencies of India. Intelligence infrastructure of India needs rejuvenation keeping in mind the constitutional obligations.

The draft Intelligence Services (Powers and Regulation) Bill, 2011 has failed to take the shape of a law in India and it has been announced that law on intelligence agencies would be formulated soon. Even the Draft Central Bureau of Investigation Act, 2010 has failed to become an applicable law.

E-surveillance in India, websites blocking in India, Internet censorship in India, etc are also not done a strictly constitutional manner. Till now Indian courts have not tested the acts of intelligence agencies. Recently Indian research and analysis wing (RAW) was granted e-surveillance powers without any legal framework. Now the home ministry of India is demanding that intelligence and law enforcement agencies must be kept out of the purview of the proposed Privacy law, and should be allowed to continue monitoring the activities and carry out electronic surveillance of citizens.

Home ministry is suggesting that the way intelligence and investigation agencies are exempted under schedule 2 of the Right to Information (RTI) Act, they should be kept out of the proposed privacy Bill in view of national security.

Under schedule 2 of the RTI Act, citizens are restricted from seeking information from agencies such as the Intelligence Bureau (IB), the Research and Analysis Wing, the Central Bureau of Investigation, the National Investigation Agency, the National Intelligence Grid and the National Technical Research Organisation.

Home ministry do not wants the privacy Bill to interfere with intelligence gathering activities even if means accommodating more safeguards in line with the sprit of the privacy Bill.

This seems to be an unreasonable demand as we must now stress upon great parliamentary scrutiny of intelligence agencies and law enforcement agencies. On the contrary we are diluting the constitutional freedoms and procedural safeguards. It is high time for parliament of India to interfere and enact constitutionally sound laws in this regard.

Friday, August 26, 2011

Cyber Police Reforms In India Are Needed

Police reforms in India are long overdue. Whether it is on the front of legal framework, prison conditions, police accountability and transparency or any other similar aspect, police reforms in India have been stagnant.

Some of these reforms pertain to infrastructure while others pertain to policy formulation and still others regarding brand and image making of police in India. While these reforms can be managed through political will yet one reform area that cannot be achieved through mere political will pertains to training of police force in technology related issues.

For instance, we do not have enough cyber crime investigation capabilities in India till now. Cyber crime investigation in India is still far from satisfactory and there are selective police officials who are aware of technological issues and technological laws like information technology act 2000 (IT Act 2000).

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been working in the direction of removing these obstacles for the law enforcement officials of India. PTLB has been managing a techno legal ICT training centre for police force that intends to fill this void and make our police force techno legal in nature.

Perry4Law and PTLB suggest that police force of India must be well versed in areas like cyber law, cyber security attacks, cyber forensics, digital evidencing and e-discovery, video conferencing evidence, e-courts, etc.

Presently, these issues are not considered by police force of India. To start with police force must be made aware of the cyber law of India and its applicable provisions. Further, police in India also needs to learn how to investigate a cyber crime. Simple issues of cyber forensics like internet protocol address tracking and data recovery must also be learned by police force of India.

Indian government in general and ministry of home affairs in particular must pay special attention to these issues as ambitious projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), etc cannot be run successfully through an untrained police and intelligence force.

Cyber skill and intelligence gathering skills need to be developed in India as soon as possible. Perry4Law and PTLB hope that our suggestions would be considered by Indian government for the larger interest of all concerned.

Monday, June 20, 2011

Indian Government Waking Up To Privacy Laws Requirements

Of late Fundamental Rights and Civil Liberties of Indian Citizens in Cyberspace have been totally neglected by the Executive and Legislative Branches of Indian Constitution. Unfortunately, even Judiciary failed to interfere and we have reached a “Precarious Situation” where the Constitution of India, especially Fundamental Rights, are about to be made “Redundant and Non Existent”.

While United Nations has declared that “Access to Internet” is Human Rights yet Indian Government is well committed to deny not only this Human Rights but also all other possible Human Rights in Cyberspace.

Naturally, there is a need to protect Human Rights in Cyberspace before we fully launch various E-Surveillance and Civil liberties Violating Projects in India. Security and E-Surveillance Projects have been launched by Indian Government without any “Procedural Safeguards” and in active “Violation” of Human Rights in Cyberspace. The only solace is that these Projects are in their infancy stage and they can still be made “Constitutional”.

For instance, Projects like National Intelligence Grid (NATGRID), Central Monitoring System of India (CMS), Centre for Communication Security Research and Monitoring (CCSRM), Aadhar Project of India, Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), etc have no “Procedural Safeguards” and they are violating Human Rights and Fundamental Rights in their “Present Form”. These Projects have been launched without any Legal Framework and Parliamentary Oversight. Further, even the most “Basic Laws” like Data Protection Laws, Data Security Laws, Privacy Laws, etc are missing in India.

Realising the “Gravity of the Situation”, the Planning Commission of India has now decided to call a high-level meeting of experts, civil society representatives and government officials to address these concerns. The Commission admits that initiatives like UID, NATGRID, DNA profiling, brain mapping and tapping communication, etc are “Genuine Concerns” and they need to be addressed properly. The Commission has also suggested using “Inbuilt Technological Safeguards” for all these Projects.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been constantly suggesting that privacy is a key concern in all these Projects as people's personal information would be stored in a single database and the possibility of corruption and exploitation could not be ruled out.

The minister, incharge of IT in the plan panel, said it is necessary to have in-depth and threadbare discussion with experts, civil society representatives and government officials to ensure that the objective of national security and efficiency in public service delivery mechanism are effectively reconciled with the privacy concern of citizens.

This is a good step in the right direction and Perry4Law and PTLB welcome this step of Indian Government.

Saturday, June 18, 2011

National Intelligence Grid (Natgrid) Project Of India

National Intelligence Grid (NATGRID) Project of India is one of the most ambitious Intelligence Gathering Project of India. It has been launched at a time when the Intelligence Infrastructure of India is in a bad shape.

The recent decision of a Government Panel rejecting the proposal to ban Encryption Service Providers like Blackberry, Gmail, Skype, etc has further made the task of Intelligence Agencies of India more tedious. Since the E-Surveillance option has gone now they have to acquire Techno Legal Intelligence Gathering Skills to deal with sophisticated and encrypted communications.

Meanwhile, the Cabinet Committee on Security (CCS) has also given only “Partial In Principle Approval” to NATGRID Project. Since NATGRID Project is not supported by any Legal Framework and Parliamentary Oversight, the “Crucial Stages” of NATGRID Project has not yet been approved by the CCS. Thus, NATGRID Project of India is still in troubled waters as lack of Privacy Laws and Data Protection Laws has put it in doldrums.

Meanwhile similar Security and E-Surveillance Projects have also been launched by Indian Government. These include Projects like Central Monitoring System of India (CMS), Centre for Communication Security Research and Monitoring (CCSRM), Aadhar Project of India, Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), etc. Once again, all these Projects are without any Legal Framework and Parliamentary Oversight.

To make the matter worst, the Law Enforcement Agencies and Intelligence Agencies of India are also practically not governed by any Legal Framework and Parliamentary Oversight. Whether it is Central Bureau of Investigation (CBI) or Intelligence Agencies of India, none of them are presently “Accountable” to Parliament of India.

It is only now that the Draft Central Bureau Of Investigation Act, 2010 and the Intelligence Services (Powers and Regulation) Bill, 2011 have been proposed. They have still to be made “Applicable Laws” in India by Parliament of India. In other words, there is no Legal Framework and Parliamentary Oversight for our Law Enforcement Agencies and Intelligence Agencies as on the date.

In this background, we have to “Proceed With” Projects like NATGRID, CCTNS, CMS, CCSRM, Aadhar Project of India, etc. As far as NATGRID Project is concerned, it is still not within the limits of “Constitutionality”.

NATGRID Project is an essential requirement for robust and effective Intelligence Agencies and Law Enforcement functions in India. The urgent requirement is to ensure that its “Abuses” can be anticipated, prevented and remedied. Further, Natgrid Project of India must also be supported by a Legal Framework and Parliamentary Oversight.

The aim of NATGRID is to ensure a readily available and real time information sharing platform between Intelligence Agencies, Law Enforcement Agencies, etc of India. Information gathering and its timely distribution is also an essential part of Cyber Crisis Management Plan of India. While the NATGRID system is a must for India, yet India has to make it sure that it is not abused for “Political Purposes” and in a manner that goes against the provisions of the Constitution of India.

The scope for misuse is tremendous as NATGRID is planning to link 21 categories of databases maintained by different public and private agencies for ready access by the country’s Intelligence Agencies. There must be “Mechanism” to ensure that this wonderful system may not be abused and nothing is better than Parliamentary Oversight.

Thursday, June 9, 2011

Cyberspace Crisis Management Plan Of India

Crisis Management is an important aspect of planning and management of any project or eventuality. If we have a proper Crisis Management Plan, losses of lives and property is minimised to a great extent. We have Crisis Management Plans in India against floods, earthquakes and other natural calamities. However, are we prepared for Cyber Crises in Indian Cyberspace?

India has formulated a Crisis Management Plan for its Cyberspace. However, like other Policies and Strategies in India, it has not been implemented in true letter and spirit. Even the basic level Cyber Security Preparedness in India is not up to the mark.

There are many aspects of a Cyber Crisis Management Plan. For instance, Cyber Security, Cyber Law, Cyber Forensics, Anti Cyber Terrorism Plans, Anti Cyber Espionage Plans, Anti Cyber Warfare Plans, Human Rights Protection in Cyberspace, Critical ICT Infrastructure Protection, etc are some of the “Components” of a Cyber Crisis Management Plan.

Theoretically, India has a Cyber Law in the form of Information Technology Act 2000 (IT Act 2000), Cyber Security in the form of Government Guidelines, Cyber Forensics Practices in Governmental Laboratories alone and so on.

However, practically we have no Cyber Crimes Laws in India as the Cyber Law of India has made almost all the Cyber Crimes “Bailable”. We may have a Cyber Law but India has no Cyber Crimes Law. So Legal Framework for preventing Cyber Crimes is “practically missing” in India.

As far as Cyber Security is concerned, we have no Cyber Security Laws in India and no Cyber Security Policy in India. The Governmental Guidelines are meant for Government Departments alone and even these Government Departments do not follow the same. Government Websites are the most frequently defaced websites in India. Similarly, Government Computers are the “most successfully breached” Computers in India. Computers of Defense Forces, Prime Minister’s Office (PMO), Ministry of External Affairs (MEA), Ministry of Home affairs, etc have been successfully breached without even notice by these Ministries/Offices.

As far as other components of Cyber Crisis Management Plan of India are concerned, even they do not exist in India. We have no Cyber Forensics Laws in India, no Cyber Terrorism Policy in India, no Cyber Warfare Policy in India, no Critical ICT Infrastructure Protection Policy in India and no Human Rights Protection in Cyberspace in India.

In fact, Projects like Aadhar, NATGRID, CCTNS, Central Monitoring System (CMS) of India, etc are openly violating the Human Rights of Indians. These Projects are operating without any Legal Framework, Parliamentary Oversight and Judicial Scrutiny.

Even the basic Privacy Rights in India are missing. It is only now the Law Ministry of India has proposed the Right to Privacy Bill 2011 of India. Further, Data Protection Law in India is urgently required. We also need a Data Security Policy of India so that sensitive information and data of projects like Aadhar, NATGRID, CMS, etc is not “misused” once it falls in the wrong hands.

India cannot have a robust and effective Cyber Crisis Management Plan till it considers these aspects and actually starts working in the direction of achieving these components.

Monday, June 6, 2011

United Nations And Human Rights In Cyberspace

Human Rights Protection in Cyberspace is urgently needed at National and International level. The call is for the United Nations to take that is “Slow” in this regard. No time in the history of Internet and Cyberspace the need for Protection of Human Rights in Cyberspace is more than the present times.

If the United Nations believes in Human Rights, it must start thinking towards its new form in this Internet Era. There is no reason why Human Rights in Cyberspace must be given any lesser importance than its traditional Human Rights. After all Human Rights like Right to Speech and Expression, Right to Information, Right to Know, Privacy Rights, etc are similar in Cyberspace. Rather violation of Human Rights in Cyberspace is much easier and more frequent.

What is most surprising is why UN has still not considered Cyberspace as an essential part of human life. If we analyse the trends World over, technology has been increasingly used to violate Human Rights in Cyberspace. Thus, UN must urgently protect Human Rights in Cyberspace.

Even the World community on Human Rights, Cyber Law and Cyber Security must start thinking in this direction as issues like Cyber Warfare, Cyber Terrorism, Cyber Espionage, Cyber Crimes, E-Surveillance, Unlawful Interceptions, etc are “Transnational” in nature. If different Countries would have different laws for these issues, it would be very difficult to truly enforce protective provisions against these menaces at National and International levels.

This is the reason why we must a “Harmonised Legal Framework” in this regard, preferably under the regime of United Nation’s Human Rights Organisation. The Governments all over the World are engaging in illegal and unlawful phone tapping and interceptions. This is violating various Human Rights that must be addressed immediately by the International Community.

The present UN Framework for Human Rights can be “Suitably Amended” to accommodate Human Rights in Cyberspace. Almost all the Countries of the World are Member of UN and this would extend Human Rights Protection in Cyberspace to their Citizens automatically. The call is for UN to take and the sooner it is taken by it the better it would for Citizens’ World wide.

Take the example of India. The Cyber Law of India is violating various Human Rights in Cyberspace. This is the main reason why we started the exclusive Cyberspace Human Rights Protection Centre of India. So much offensive is the Cyber Law of India that it deserves to be repealed.

Further, Indian Government launched Projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

If there is no “Internationally Acceptable Standard” for Protection of Human Rights in Cyberspace, Countries like India would keep on enacting and applying the Draconian Laws like Information Technology Act, 2000, Indian Telegraph Act, 1885, Official Secrets Act, etc.

Finally, UN has shown some inclination in this regard. UN now considers Internet access a Human Right and considers disconnecting people from the Internet as a violation of Human Rights and International Law. A Report by the UN Human Rights Council’s 17th Session underscored the “unique and transformative" nature of the Internet allowing individuals to exercise a range of Human Rights, and to promote the progress of society as a whole.

I welcome this initiative of UN as this is a good step in the right direction. However, UN must not stop here and must move towards enacting a “Comprehensive Framework” for Protection of Human Rights in Cyberspace.

Saturday, June 4, 2011

Data Protection Law In India Is Needed

Every individual loves his or her personal space and in order to enjoy the same he/she must exercise his/her privacy and data protection rights effectively. But what would happen if there are no privacy laws and data protection laws at all to protect such rights? This not only is scary but is also difficult to accept. But in India we have neither dedicated privacy laws nor dedicated data protection laws.

This makes the sensitive information and personal details of Indian citizens “highly vulnerable” to misuse. The Indian government has been promising enactment of privacy laws and data protection laws for long but till now we have none.

This indifference of Indian government towards privacy laws, data security laws and data protection laws is also becoming a headache for government itself. Controversial issues like illegal phone tapping, imposition of Aadhar project, launch of projects like national intelligence grid (Natgrid) and crime and criminal tracking network and systems (CCTNS) without any procedural safeguards, etc requires not only enactment of a dedicated and constitutionally sound privacy law but also putting in place sufficient data protection mechanisms.

India’s intention to use cloud computing and m-governance has further complicated the issue. With the proposed use of cloud computing, software as a service (SaaS) and m-governance by Indian government, more “privacy violations”, “cyber security” and many more “regulatory issues” would arise in future believes techno legal experts of India. These “initiatives” cannot succeed in India in the absence of adequate and strong laws in this regard.

With the proposed draft electronic services delivery bill 2011 (EDS Bill 2011) things would even become more complicated. When most of the public services would be delivered through mandatory e-governance model, a very strong data protection regime and privacy protection regulatory framework would be required.

Now government of India has once more declared that it is going to enact a privacy law for India. However, this seems to be another declaration alone as there is no sign of any Bill in this regard that can be analysed by public at large. In the absence of privacy Bill this statement of India government has no significance.

Further, even if, by some miracle, privacy law is introduced it is doubtful whether it would cater the privacy issues of information age. Only time would tell how much serious is Indian government regarding privacy rights of Indians.

Friday, June 3, 2011

Privacy Rights In India In The Information Age

We have no Dedicated Privacy Laws in India and Data Protection Laws in India. In fact, when it comes to respecting Privacy of Indian Citizens, Government of India tries its level best to avoid the same.

For instance, India has launched Projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

Further, India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more.

Phone Tapping in India has been in controversies for long. Whether it is Illegal Phone Tapping by Private Individuals or Unaccountable Phone Tapping by Indian Government and its Agencies, Phone Tapping in India has never been smooth.

There is a blessing in disguise in Ratan Tata’s Petition before Supreme Court of India. This is a golden chance for the Supreme Court of India to analyse the “Implementation” of its decision in the PUCL case (Phone Tapping Case). The Supreme Court must “Widen” the scope of Privacy Rights in India not only in the context of Phone Tapping but in an “Overall Manner”. The Supreme Court must formulate and lay down the widest possible “Guidelines” regarding Privacy Protection in India as it has done in the Vishaka’s Case (Guidelines against Sexual Harassment). The Supreme Court has even said that with the Technological Advancement, Privacy is virtually disappearing.

On the front of Legal Framework as well we have no Dedicated and Constitutionally Sound Lawful Interception Law in India. The Indian Telegraph Act, 1885 and other similar Laws are not in “Conformity” with the Constitution of India, especially Fundamental Rights of Indians. Even the Home Ministry of India is considering enactment of a Lawful Interception Law in India.

However, what is more surprising is the fact that the Law Enforcement Agencies and the Intelligence Agencies that indulge in Unconstitutional E-Surveillance and Phone Tapping are themselves Governed by No Law. It is no surprise that the Central Bureau of India (CBI) is also not governed by any Law and it is operating in India Without any Law. It is only now that the Central Bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the Constitutional Validity of the National Investigation Agency Act 2008 is doubtful. Even the Draft Intelligence Services (Powers and Regulations) Bill, 2011 has been recently circulated in the Parliament of India. India must urgently formulate E-Surveillance Policy so that the E-Surveillance conducted by Intelligence Agencies and Law Enforcement Agencies of India can be regulated.

Surprisingly, India has no E-Surveillance Policy and Legal Framework. This is despite the fact that many Indian Projects are so S-surveillance Oriented that they cannot pass the scrutiny provisions of Indian Constitution. Of all these E-Surveillance Projects Aadhar Project of India or Unique Identification Project of India (UID Project of India) is the most “Dangerous Project” that should not be there at the very first place. It is based upon Deceit and Deception and both Indian Government and Unique Identification Authority of India (UIDAI) are Hiding Truth from Indians. There is no Legal Framework, no defined Policies and Guidelines and most importantly no Procedural and Civil Liberty Safeguards.

If this was not enough the sole Cyber Law of India (Information Technology Act 2000) was amended through the Information Technology Amendment Act 2008. The IT Act 2008 made the Cyber Law of India an “Unregulated and Unaccountable” piece of E-Surveillance Legislation. It is now wide open to misuses by Indian Government and its Agencies. Further, the IT Act 2008 also violated various provisions of Indian Constitution and hence is “Unconstitutional” as well. Ideally Cyber law Of India must be repealed as soon as possible.

If Parliament of India has abdicated its duties and Indian Judiciary is watching as a moot spectator, it becomes of paramount importance for Cabinet Committee on Security (CCS), Union Cabinet and Prime Minister’s Office (PMO) to “Disallow” all such Projects till proper Civil Liberty Safeguards and Legal Frameworks are at place.

Monday, May 30, 2011

Call Data Records Storage Policy Of India

India is not very good at law making. This is more so regarding technology related laws. For instance, consider the cyber law of India incorporated in the information technology act 2000 (IT Act 2000). IT Act 2000 is a classical example of bad drafting that has created more problems than solutions. This is the reason why experts have been suggesting that it should be repealed.

Similarly, we have no lawful interception law in India. Even phone tapping in India is not done in a constitutional manner and illegal phone tapping in India is under scrutiny. There is no e-surveillance policy in India. India does not bother to maintain a balance between national security and fundamental rights of Indians.

India has launched projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

In this background, the news that Intelligence Bureau (IB) wants all mobile phone companies to store call data records, or details of all phone calls made by their customers, for a period of five years is really surprising. Indian law enforcement agencies and intelligence agencies are practically governed by no law. In fact, intelligence infrastructure of India is in big mess and India is not at all ready for projects like CCTNS, Natgrid, NCTC, etc.

It is no surprise that the central bureau of India (CBI) is also not governed by any law and it is operating in India without any law. It is only now that the central bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the constitutional validity of the national investigation agency act 2008 is doubtful. The recent circulation of the draft Intelligence Services (Powers and Regulations) Bill, 2011 (Draft Intelligence Bill 2011) in the Lok Sabha shows how our Parliament of India took the matter very casually.

We must start formulating the call data storage policy of India as soon as possible. The one suggested by IB is neither feasible nor desirable. Issues like increased costs to operators, privacy safeguards, legal framework requirements, etc cannot be ignored the way they have been ignored so far. Presently, an inter-ministerial group is looking into monitoring of both internet services and networks in the country. This matter may also be refereed to the same. However, in all probability, this demand would be refused.

Sunday, May 22, 2011

Glendora Police Department Is Using Innovative Methods

Law enforcement agencies around the world are increasingly using information technology for efficient law enforcement delivery. In India as well projects like crime and criminal tracking network and systems (CCTNS) has been proposed by Home Ministry of India. Even projects like national intelligence grid (Natgrid) have been suggested by Home Ministry.

Further, a proposal to establish a system where first information reports can be filed online has also been proposed. However, till now all of these are just proposals and not even a single project has been implemented in India.

Law enforcement agencies of India are still afraid of information technology related issues like cyber law and use of computers and other technological instruments. Of course, they are catching up with the new technology but the pace is very slow.

The Glendora Police Department has launched a new feature on the Glendora Police Department's website. Now anyone who has access to a computer can see the calls that come into the police department in almost real time.

A department official said keeping the public informed about police activities serves two purposes. On one hand, he hopes it will reduce the work load for his employees. If people can see why a police helicopter is circling overhead with a few mouse clicks, they'll be less likely to flood police dispatchers with calls asking `why,' so the thinking goes.

On the other hand, it satisfies people's growing appetite for non-stop information. To that end, the department has also created its own online crime-mapping system. The official said there are also some big changes in store for the website, including an online log that shows whom the department has arrested.

And the Glendora Police Department isn't the only agency responding to that need. The Los Angeles County Sheriff's Department has taken a huge leap into the Information Age in the past year and a half.

I hope Indian law enforcement agencies may also take a leaf out of these activities from their foreign counterparts. Although electronic delivery of services in India has been proposed yet it is far from being actual implementation. Let us see how our law enforcement agencies would perform in future.

Wednesday, May 18, 2011

India-US Homeland Security Dialogue

India and United States (US) have in the past worked in the direction of homeland security. In fact a cyber security forum was started between India and US that faced some troubles and it became obsolete. Now talks are in progress to revive Indo US homeland security dialogue once more.

A special emphasis has been laid upon counter-terrorism co-operation, intelligence sharing, technology transfers and capacity building. Homeland security in India is at the infancy stage. Issues like cyber law, cyber security, cyber espionage, cyber terrorism, cyber warfare, etc are still not considered while formulation national policies of India.

At Perry4Law Techno Legal Base (PTLB) we are managing the exclusive techno legal cyber security research and training centre of India (CSRTCI). The centre is covering areas like cyber law, cyber security, cyber forensics, critical ICT infrastructure protection, cyber warfare, cyber terrorism, cyber espionage, national counter terrorism centre (NCTC), national intelligence grid (Natgrid) of India, crime and criminal tracking networks and systems (CCTNS), etc.

CSRTCI is supported by Cyberspace Human Rights Protection Centre of India that is working in the direction of reconciling the conflicting interests of national security and civil liberties protection.

The proposed Indo US homeland security dialogue must address many crucial issues ranging from cyber law to cyber security. Issues like encryption, technology transfer, international cooperation to fight cyber crimes and terrorism, etc must also be a part of national policies of both US and India.

PTLB believes that besides addressing these issues the proposed India US dialogue must also concentrate upon mutual trainings and skills development issues in the abovementioned fields. India particularly needs skill development trainings for intelligence gathering and their analysis. In all probability, this would be a fruitful and productive dialogue between India and US.

Tuesday, May 17, 2011

Indian Centre For Communication Security Research and Monitoring (CCSRM)

An Indian centre for communication security research and monitoring (CCSRM) was proposed by the Union Cabinet in the past. The Department of Telecommunication (DOT) was asked to do the needful in this regard. The DOT came up with the proposal of establishment of Central Monitoring System (CMS) that can help security agencies and law enforcement agencies in intercepting mobile phone calls and monitor internet traffic.

None can doubt about the utility of a CMS or CCSRM. However, there are many technical, administrative and legal issues that have to be addressed before implementing either CMS or CCSRM.

On the technical side, intelligence agencies and law enforcement agencies of India need to develop skills for intelligence gathering and their analysis. If we keep in mind the latest development, it can be assumed that services of Blackberry, Gmail, Skype, etc would not be banned in India for some more time. Naturally, their highly encrypted services would continue in India that intelligence agencies and law enforcement agencies of India cannot monitor unless they are skilled enough to do so.

On the legal side, in India intelligence agencies and law enforcement agencies are practically governed by no law. Even the constitutional validity of national investigation agency act, 2008 is still doubtful. Further, India does not have a constitutionally sound lawful interception law. Phone tapping in India is still done in an unconstitutional manner and at times by private individuals as well.

On the administrative side, the intelligence infrastructure of India is in big mess. There seems to be a tussle between various Ministries of Indian government and this is preventing the successful implementation of various projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), national counter terrorism centre (NCTC), central monitoring system (CMS), etc.

However, nothing is more offensive than an absence of Parliamentary oversight of intelligence agencies, law enforcement agencies and projects like Natgrid, CCTNS, NCTC, CMS, etc.

Fortunately, our Prime Minister Dr. Manmohan Singh is taking interest in these projects and he has recently has sought clarifications on the upcoming CCSRM system. I hope the Cabinet Committee on Security (CCS), Union Cabinet and Prime Minister’s Office (PMO) would bring some order in the otherwise chaosed world of intelligence agencies and law enforcement agencies of India.

Is Cloud Computing A Viable Solution In India?

India is a country that is weak privacy, data protection and data security laws. India is also infamous for its e-surveillance and eavesdropping exercises without any constitutional laws backing the same. Phone tapping in India is not done in a strictly constitutional manner and we also lack a lawful interception law in India.

With the information technology amendment act, 2008 (IT Act 2008), the cyber law of India has been amended and this has also made it vulnerable to constitutionality attacks. With projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), central monitoring system (CMS), etc e-surveillance in India has reached its zenith.

In this background we have to analyse the use of cloud computing in India. Cloud computing in India cannot succeed till we have trust in the service provider. We cannot trust a service provider who can be forced to disclose even the most sensitive information and data without a court order.

In India a mere order from the Indian government or its agencies is enough for the service provider to share sensitive information. There is no judicial scrutiny of a warrant that is absolutely required in these circumstances. So you cannot be even sure what government agencies are looking at and what information they are taking from the service provider.

Any business model must essentially balance profit motives and risks associated with the business. Similarly, the users of cloud computing services must ensure that the convenience of software as a service (SASS) and cloud computing is much greater than the risks of data leakages and manipulations.

Till now the legal opinion is weighting against the use of cloud computing and SAAS in governmental departments and for governmental projects. Without a conducive legal framework, user’s data in India is not safe. Let us create a conducive commercial and legal environment before we jump upon cloud computing wagon.