Showing posts with label Cyber Law In India. Show all posts
Showing posts with label Cyber Law In India. Show all posts

Friday, February 3, 2012

Information Technology (Intermediaries Guidelines) Rules 2011 Of India

Internet intermediary law in India is incorporated in the Information Technology Act 2000 (IT Act 2000) and the Rules made there under. Internet intermediaries’ liability in India is now well established and foreign companies and websites must duly comply with the same to avoid civil, criminal, administrative and financial penalties. In short, these foreign companies and their Indian subsidiaries must ensure that they comply with the cyber law due diligence in India.

The Gazette Notification numbered G.S.R. 314(E), dated 11-04-2011, formulated the Information Technology (Intermediaries Guidelines) Rules, 2011 of India. These rules provide the rights and responsibilities of internet intermediaries in India. If the Internet intermediaries follow these rules and exercise proper cyber due diligence, they are entitled to a “safe harbour protection”. Otherwise, they are liable for various acts or omission occurring at their respective platforms once the matter has been brought to their notice.

The legal actions against foreign websites can be taken in India. Further, cyber litigations against such foreign websites would increase in India in the near future. It is of utmost importance for these foreign companies and websites to follow Indian laws in true letter and spirit.

Perry4Law and Perry4Law Techno Legal Base (PTLB) are providing the legal position regarding Internet intermediary liability in India under the IT Act 2000 in general and Information Technology (Intermediaries Guidelines) Rules, 2011 of India in particular. The salient features of the same are as follows:

(1) The Information Technology (Intermediaries Guidelines) Rules, 2011 of India have been formulated by the Central Government in exercise of its powers conferred by clause (zg) of subsection (2) of section 87 read with sub-section (2) of section 79 of the Information Technology Act, 2000 (21 of 2000).

(2) Definitions — (1) In these rules, unless the context otherwise requires,--

(a) "Act" means the Information Technology Act, 2000 (21 of 2000);

(b) "Communication link” means a connection between a hyperlink or graphical element (button, drawing, image) and one or more such items in the same or different electronic document wherein upon clicking on a hyperlinked item, the user is automatically transferred to the other end of the hyperlink which could be another document website or graphical element.

(c) "Computer resource” means computer resources as defined in clause (k) of sub-section (1) of section 2 of the Act;

(d) "Cyber security incident” means any real or suspected adverse event in relation to cyber security that violates an explicitly or implicitly applicable security policy resulting in unauthotrised access, denial of service or disruption, unauthorised use of a computer resource for processing or storage of information or changes to data, information without authorisation;

(e) "Data" means data as defined in clause (o) of sub-section (1) of section 2 of the Act;

(f) "Electronic Signature" means electronic signature as defined in clause (ta) of sub- section (1) of section 2 of the Act;

(g) "Indian Computer Emergency Response Team” means the Indian Computer Emergency Response Team appointed under sub section (1) section 70 (B) of the Act;

(h) “Information” means information as defined in clause (v) of sub-section (1) of section 2 of the Act;

(i) “Intermediary” means an intermediary as defined in clause (w) of sub-section (1) of section 2 of the Act;

(j) "User" means any person who access or avail any computer resource of intermediary for the purpose of hosting, publishing, sharing, transacting, displaying or uploading information or views and includes other persons jointly participating in using the computer resource of an intermediary.

(2) All other words and expressions used and not defined in these rules but defined in the Act shall have the meanings respectively assigned to them in the Act.

(3) Due diligence to be observed by intermediary — The intermediary shall observe following due diligence while discharging his duties, namely: —

(1) The intermediary shall publish the rules and regulations, privacy policy and user agreement for access-or usage of the intermediary's computer resource by any person.

(2) Such rules and regulations, terms and conditions or user agreement shall inform the users of computer resource not to host, display, upload, modify, publish, transmit, update or share any information that —

(a) Belongs to another person and to which the user does not have any right to;

(b) Is grossly harmful, harassing, blasphemous defamatory, obscene, pornographic, paedophilic, libellous, invasive of another's privacy, hateful, or racially, ethnically objectionable, disparaging, relating or encouraging money laundering or gambling, or otherwise unlawful in any manner whatever;

(c) Harm minors in any way;

(d) Infringes any patent, trademark, copyright or other proprietary rights;

(e) Violates any law for the time being in force;

(f) Deceives or misleads the addressee about the origin of such messages or communicates any information which is grossly offensive or menacing in nature;

(g) Impersonate another person;

(h) Contains software viruses or any other computer code, files or programs designed to interrupt, destroy or limit the functionality of any computer resource;

(i) Threatens the unity, integrity, defence, security or sovereignty of India, friendly relations with foreign states, or public order or causes incitement to the commission of any cognisable offence or prevents investigation of any offence or is insulting any other nation

(3) The intermediary shall not knowingly host or publish any information or shall not initiate the transmission, select the receiver of transmission, and select or modify the information contained in the transmission as specified in sub-rule (2):

Provided that the following actions by an intermediary shall not amount to hosing, publishing, editing or storing of any such information as specified in sub-rule: (2) —

(a) Temporary or transient or intermediate storage of information automatically within the computer resource as an intrinsic feature of such computer resource, involving no exercise of any human editorial control, for onward transmission or communication to another computer resource;

(b) Removal of access to any information, data or communication link by an intermediary after such information, data or communication link comes to the actual knowledge of a person authorised by the intermediary pursuant to any order or direction as per the provisions of the Act;

(4) The intermediary, on whose computer system the information is stored or hosted or published, upon obtaining knowledge by itself or been brought to actual knowledge by an affected person in writing or through email signed with electronic signature about any such information as mentioned in sub-rule (2) above, shall act within thirty six (36) hours and where applicable, work with user or owner of such information to disable such information that is in contravention of sub-rule (2). Further the intermediary shall preserve such information and associated records for at least ninety days for investigation purposes,

(5) The Intermediary shall inform its users that in case of non-compliance with rules and regulations, user agreement and privacy policy for access or usage of intermediary computer resource, the Intermediary has the right to immediately terminate the access or usage rights of the users to the computer resource of Intermediary and remove non-compliant information.

(6) The intermediary shall strictly follow the provisions of the Act or any other laws for the time being in force.

(7) When required by lawful order, the intermediary shall provide information or any such assistance to Government Agencies who are lawfully authorised for investigative, protective, cyber security activity. The information or any such assistance shall be provided for the purpose of verification of identity, or for prevention, detection, investigation, prosecution, cyber security incidents and punishment of offences under any law for the time being in force, on a request in writing staling clearly the purpose of seeking such information or any such assistance.

(8) The intermediary shall take all reasonable measures to secure its computer resource and information contained therein following the reasonable security practices and procedures as prescribed in the Information Technology (Reasonable security practices and procedures and sensitive personal Information) Rules, 2011.

(9) The intermediary shall report cyber security incidents and also share cyber security incidents related information with the Indian Computer Emergency Response Team.

(10) The intermediary shall not knowingly deploy or install or modify the technical configuration of computer resource or become party to any such act which may change or has the potential to change the normal course of operation of the computer resource than what it is supposed to "perform thereby circumventing any law for the time being in force:

Provided that the intermediary may develop, produce, distribute or employ technological means for the sole purpose of performing the acts of securing the computer resource and information contained therein.

(11) The intermediary shall publish on its website the name of the Grievance Officer and his contact details as well as mechanism by which users or any victim who suffers as a result of access or usage of computer resource by any person in violation of rule 3 can notify their complaints against such access or usage of computer resource of the intermediary or other matters pertaining to the computer resources made available by it. The Grievance Officer shall redress the complaints within one month from the date of receipt of complaint.

The cyber laws due diligence requirements for companies in India are strenuous in nature and Internet intermediaries in India need to take care of the same to avoid legal troubles.

Sunday, January 29, 2012

Cyber Litigations Against Foreign Websites Would Increase In India

Foreign companies and websites are increasingly facing civil and criminal litigations in India. The main problem seems to be application of foreign laws and standards to Indian conditions that is not desirable. These foreign companies and websites apply standards and norms that are well beyond Indian laws and norms.

There are mainly two reasons for this increase in civil and criminal litigations against such foreign companies and websites. Firstly, many individuals and companies in India are neither aware of foreign laws like Digital Millennium Copyright Act (DMCA) 1998 or/and Online Copyright Infringement Liability Limitation Act (OCILLA) nor they prefer to apply the same in derogation of Indian laws, though rightly.

Secondly, even if some individuals and companies invoke foreign laws procedures like DMCA notices and complaints, foreign websites may or may not comply with the same. We have filed a DMCA notice with Google Incorporation and a legal notice to Google India regarding copyright, trademark and impersonation issues. We are still waiting Google’s action in this regard and this shows that even DMCA compliances are not followed by foreign companies and websites.

These are the reasons why filing of civil and criminal cases in India against such foreign companies and websites is increasing. For instance, companies like Google, Facebook, etc are facing a criminal trial in India for not removing objectionable contents from their sites. In other cases, it appear that these companies are deliberately ignoring and violating Indian laws like copyright law, trademarks law and cyber law of India.

There is no doubt that companies like Google, Facebook, Wordpress, etc must comply with Indian laws. These companies cannot claim that they would keep on deriving financial and other benefits from India and would not respect India’s laws and legal procedures.

We believe that India must take urgent steps so that companies and websites like Google, Facebook, WordPress, etc comply with legal demands as per Indian laws as well. We suggest the following in this regard:

(1) All subsidiary/Joint ventures companies operating in India that deal in information technology and online environment, must mandatorily establish a server in India. Otherwise, such companies and their websites should not be allowed to operate in India.

(2) A stringent liability for Indian subsidiaries dealing in information technology and online environment must be established by laws of India.

(3) More stringent online advertisement and e-commerce provisions must be formulated for Indian subsidiary companies and their websites.

India must formulate alternatives to DMCA notices to Google, Facebook, WordPress, etc so that these companies and websites comply with Indian laws and legal procedures. These companies and websites should not be allowed to hide behind the façade of being subsidiary company and citing conflict of laws.

Legal action against offending foreign websites can be taken in India if they fail to exercise cyber due diligence. In fact, Google, Facebook, Microsoft, Yahoo, etc have already been summoned to personally appear before a criminal court in New Delhi on March 13, 2012. Further, as a measure of last resort, these foreign websites can be blocked in India for not complying with Indian laws.

We hope the Delhi High Court would consider these suggestions while deciding the fate of companies like Google, Facebook, etc on the forthcoming hearing.

Sunday, January 1, 2012

Cyber Laws And Cyber Security Trends In India 2011

Cyber law in India and cyber security in India was all over the news in the year 2011. However, they were in the news for the wrong reasons. Incidences of increased cyber crimes and cyber attacks were reported from time to time in India. The cyber law trends in India 2011 and cyber security trends in India 2011 were not promising at all but we can expect better results in the year 2012.

Many crucial issues pertaining to cyber law, cyber security, Internet censorship, websites blocking, social media control, cyber law due diligence, social media due diligence, corporate cyber law due diligence, enhanced banking due diligence, Internet intermediaries liability, phone tapping, etc took place in India in 2011. Collectively they pointed towards a negative approach on the part of Indian government.

Similarly, initiative towards strengthening of information and communication technology (ICT) usages in India also proved lack of insight and proper management. For instance, the proposed electronic delivery of services bill 2011 (EDS Bill 2011) failed to address the crucial issues like mandatory e-governance services in India.

Crucial issues like electronic discovery (e-discovery) in India, use of cyber forensics in India, establishment of e-courts in India, use of online disputes resolution (ODR) in India, formulation of critical ICT infrastructure protection policy in India, formulating implementable cyberspace crisis management plan of India, formulating dedicated and suitable e-commerce laws in India, enacting whistleblowers protection laws in India, etc have still to be addressed by Indian government.

On the positive side, the Reserve Bank of India (RBI) tried to streamline the cyber security infrastructure of Indian banks. It made appointment of chief information officers (CIOs) mandatory in banks of India. But all such initiatives of RBI proved futile as cyber security in Indian banking sector is still missing. For instance, online banking systems in India are still insecure. Internet banking cyber security in India is still missing. ATM frauds in India are still in abundance.

An integrated modern banking law of India is in pipeline and that may establish the cyber law and cyber security due diligence for banks in India. In fact, mobile banking transactions in India have already been liberalised. However, mobile governance policy of India is still missing.

On the corporate front, financial frauds and cyber crimes in Indian companies are increasing. However, corporate IT frauds and cyber crimes investigations in India are still maturing. Although attempts to strengthen the corporate laws of India were made in the form of introduction of Indian companies bill 2011 in the Parliament yet the same could not see the light of the day. Also, the bill gave statutory recognition to the Serious Fraud Investigation Office (SFIO) that was expected to give wider powers to investigate corporate frauds and white color crimes. This proposal is also postponed for the time being.

Reports of violation of human rights in cyberspace by Internet intermediaries like Google, Facebook, etc were also made. Concerns regarding Facebook emerging as the worst e-surveillance serving platform also expressed. Reports of Facebook engaging in censorship of its users account were also surfaced.

Incidences of manipulation of Blogspot blogs by negative SEO and competitors were also reported. Similarly, apprehensions regarding manual action penalty and censorship by Google were also raised.

Research in motion’s (RIM) Blackberry messenger services in India have now become an e-surveillance tool. However, this arrangement does not extend to the enterprise Virtual Private Network (VPN) solution, provided through the Blackberry Enterprise Server (BES) product.

Overall the year 2010 saw the cyber law, cyber security and civil liberties protection in Indian cyberspace in bad light. Perry4Law and Perry4Law Techno Legal Base (PTLB) hope the year 2012 would bring positive and reformative changes in this regard.

Monday, December 5, 2011

Internet Intermediaries In India Asked To Pre Screen Contents

When information technology act 2000, the sole cyber law of India, was amended through the information technology amendment act 2008, very few people opposed the same. The provisions of the proposed IT Act 2008 were draconian and without constitutional and procedural safeguards. This is the reason why self defense mechanisms against state were also advocated to counter illegal and unconstitutional e-surveillance and internet censorship.

However, commercial enterprises and internet intermediaries silently accepted the amendments without realising its far reaching consequences. Now e-surveillance in India has become a big nuisance for intermediaries like internet service providers (ISPs), e-commerce sites, search engines, e-mail providers, etc. The liability of Internet intermediaries for copyright violations would also create problem for intermediaries in India.

Intermediaries liability for cyber law due diligence in India has become very stringent after the IT Act 2008. The IT Act 2000 now carries many e-surveillance, websites blocking and Internet censorship provisions and Indian government is openly using these provisions without following the constitutional requirements.

Recently, through a petition, Yahoo has raised questions regarding the right to privacy of a company that stores sensitive data of its customers and users and to what extent authorities can coerce it to part with the information considered necessary to either track terror perpetrators or thwart future attacks.

The matter must also be looked from another angle. Human rights protections in cyberspace in India are not safeguarded at all. Even at the international level United Nations has not shown much interest in protecting civil liberties in cyberspace. The data privacy laws in India are also missing. In short, there is complete negation of human rights in cyberspace in the Indian context.

Now the Indian government has asked Internet companies like Google, Microsoft, Yahoo and social media sites like Facebook to prescreen user content from India and to remove disparaging, inflammatory or defamatory content before it goes online. Top officials from the Indian units of Google, Microsoft, Yahoo and Facebook have met with Kapil Sibal in this regard.

Kapil Sibal has told them that he expected them to use human beings to screen content instead of the automated technology. However, these companies believe that his demand is impossible to fulfill keeping in mind the nature of internet and user generated contents. Let us see how things would take shape in this regard.

Wednesday, June 1, 2011

The Second Worldwide Cyber Security Summit Of London

Tackling Cyber Crimes and maintaining Cyber Security are not “National Problems”. Rather they are International Problems that require International Initiatives. This is the reason why US declared its International Strategy for Cyberspace. However, by and large International efforts regarding Cyber Laws and Cyber Security are “Unilateral” in nature.

At most there can be “Bilateral Agreements” between two or more countries but these agreements seldom bring “Harmonisation” of International Legal Framework for Cyber Law and Cyber Security. The India US Homeland Security Dialogue and signing of India US Cyber Security Agreement are classical examples of this Bilateral Agreements Approach.

There are very few International Organisations that are working in this crucial direction. Although in the recent past, some significant steps have been taken by International Community yet they are not adequate from any angle. The latest initiative in this regard is the Second International Cyber Security Summit that is organised in London. Governments from around the globe have been discussing how to fight the nuisance of Cyber Crimes at National and International level.

Kapil Sibal is the Indian representative in this Summit. I hope after this visit he would be well aware of the requirements to have a Strong Cyber Law and Robust Cyber Security. Presently India has none.

Indian Cyber Law, incorporated in the Information Technology Act, 2000 (IT Act 2000), is the sole Cyber Law of India. It is a weak and ineffective piece of Legislation for meeting growing Cyber Crimes in India. The first step that Kapil Sibal must do is to Repeal the Indian Cyber Law and enact a sensible, robust and effective Cyber Law. Next he must strengthen the Cyber Security of India that is in a bad shape. To achieve that he must formulate the Cyber Security Policy of India.

Kapil Sibal is a learned person with ability to learn quickly. I hope he would do justice to the requirements of having a Strong Cyber Law and Robust Cyber Security.

Sunday, May 22, 2011

Glendora Police Department Is Using Innovative Methods

Law enforcement agencies around the world are increasingly using information technology for efficient law enforcement delivery. In India as well projects like crime and criminal tracking network and systems (CCTNS) has been proposed by Home Ministry of India. Even projects like national intelligence grid (Natgrid) have been suggested by Home Ministry.

Further, a proposal to establish a system where first information reports can be filed online has also been proposed. However, till now all of these are just proposals and not even a single project has been implemented in India.

Law enforcement agencies of India are still afraid of information technology related issues like cyber law and use of computers and other technological instruments. Of course, they are catching up with the new technology but the pace is very slow.

The Glendora Police Department has launched a new feature on the Glendora Police Department's website. Now anyone who has access to a computer can see the calls that come into the police department in almost real time.

A department official said keeping the public informed about police activities serves two purposes. On one hand, he hopes it will reduce the work load for his employees. If people can see why a police helicopter is circling overhead with a few mouse clicks, they'll be less likely to flood police dispatchers with calls asking `why,' so the thinking goes.

On the other hand, it satisfies people's growing appetite for non-stop information. To that end, the department has also created its own online crime-mapping system. The official said there are also some big changes in store for the website, including an online log that shows whom the department has arrested.

And the Glendora Police Department isn't the only agency responding to that need. The Los Angeles County Sheriff's Department has taken a huge leap into the Information Age in the past year and a half.

I hope Indian law enforcement agencies may also take a leaf out of these activities from their foreign counterparts. Although electronic delivery of services in India has been proposed yet it is far from being actual implementation. Let us see how our law enforcement agencies would perform in future.