Showing posts with label Cyber Law Of India. Show all posts
Showing posts with label Cyber Law Of India. Show all posts

Friday, February 3, 2012

Google, Facebook, Microsoft, Etc Must Appoint Nodal Officers In India

The Information Technology (Intermediaries Guidelines) Rules, 2011 of India prescribe stringent provisions regarding Internet intermediary liability in India. However, till now foreign companies and websites have not followed the Guidelines and Rules issued by Indian government in this regard. In fact, they are avoiding compliance with Indian laws.

Legal liability of foreign websites in India is now well established after the matter has been brought to the attention of Indian judiciary. A criminal complaint has been filed against companies like Google, Facebook, Microsoft, Yahoo, etc before a Trail Court for non observation of cyber due diligence by them. Even the Delhi High Court has not quashed the criminal complaint against these companies so far and in the absence of the same the representatives of these foreign companies would now personally appear before the Trail Court on 13th March 2012.

Another related problem that has to be addressed is that foreign companies and websites have not established a procedure that can deal with complaints and notifications arising out of the Information Technology act, 2000 (IT Act 2000) and Rules made there under. This is so even though companies like Google, Microsoft, Yahoo, etc have subsidiary companies and offices in India.

When these foreign companies and websites and their subsidiaries are deriving financial gains out of Indian operations, non following of Indian laws seems to be a grave disregard to Indian laws and regulations. These foreign companies and websites must follow Indian laws and this is the right time to do so.

We at Perry4Law and Perry4Law Techno Legal Base (PTLB) suggest that the best method to do so is to appoint a nodal officer who is responsible for managing cyber law due diligence issues arising out of Indian transactions. By not doing so, companies like Google, Facebook, Microsoft, etc are heading towards a big trouble. The sooner these nodal officers are appointed the better it would be for the larger interest of Internet intermediaries in India.

Wednesday, February 1, 2012

Websites Blocking In India Is Mainly A Judicial Act

Blocking of websites in India is governed by the cyber law of India that is incorporated in the Information Technology Act 2000 (IT Act 2000). The Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009 prescribe the manner of blocking of websites in India.

In exercise of the powers conferred by sub-section (1) of Section 69A of the Information Technology Act, 2000 (21 of 2000) read with rule 3 of the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009, the Central Government has authorised and designated the Group Coordinator (being an officer of the Central Government not below the rank of Joint Secretary), Cyber Law Division in the Department of Information Technology (DIT), Ministry of Communications and Information Technology (MCIT), Government of India, Electronics Niketan,6, Central Government Offices Complex, New Delhi-110003, as the Designated Officer for the purposes of the said rules.

A notification numbered S.0.117 (E), dated 20th January, 2010 has been issued in this regard. Dr. Gulshan Rai is the present Group Coordinator for the Cyber Law and E-Security Division of DIT. He is also the Director General of Indian Computer Emergency Response Team (CERT-In).

In a media interview, Dr. Gulshan Rai has revealed that websites blocking in India has been so far a judicial act and DIT has not blocked a single site without a court order. This is a good attitude that shows that freedom of speech and expression is respected in India. This is also setting a bad precedent as it would encourage websites and foreign websites to violate and defy Indian laws, especially intellectual property laws and cyber law.

In fact, judicial orders for blocking of websites in India are not always very sound. In fact, India judiciary, cyber law and websites blocking in India is still far from perfect. In such situations, the responsibility of Designated Officer Dr. Gulshan Rai becomes even more demanding and pro active.

The way companies like Google are deliberately avoiding compliances with Indian laws, it becomes very important for DIT in general and Dr. Gulshan Rai in particular to safeguard the interests of Indian individuals and companies. There is no doubt that companies like Google and Facebook must comply with Indian laws and Google and Facebook can be blocked in India.

We recently filed a DMCA complaint with Google Incorporation and a legal notice to Google India. However, both Google Incorporation and Google India are openly denying compliance with Indian laws. If DIT/CERT-In does not change its soft attitude towards companies like Google, Facebook, etc, and keep on insisting upon court cases and judicial orders, it would increase an unnecessary pressure upon Indian courts that are already overburdened.

Cyber litigations against foreign websites are going to increase in India. Even Google has anticipated this situation and Google’s blogspot platform has started giving country specific results for blogspot blogs. Clearly, hints of non compliance with Indian laws are visible but India is not doing enough in this regard. The least Indian can do in this regard is to develop alternative mechanisms to filing of DMCA complaints to Google, Facebook, Wordpress, etc each time offending contents appear on their websites.

Companies like Google, Facebook, etc are already facing a criminal trail in India for non removal of objectionable contents. A trial court has also asked the representatives of the parent companies like Google, Facebook, etc to appear before it and face the trial. If these companies continue to flout Indian laws, Indian government can and should block the websites of such companies in India.

While the Indian government is armed with discretionary powers to block any website carrying malicious or offensive content, it has never exercised these powers so far. This is giving a bad signal to Internet intermediaries and something must be done in this regard.

What is more surprising is the revelation of Dr. Gulshan Rai that if the police find a problem, they come to CERT-In/DIT and ask to block some websites; CERT-In/DIT tells them that it/they cannot do this and ask them to go to court and get an order. This is abdication of duties by CERT-In/DIT that they are duty bound to follow. By insisting upon blocking of an offending website with a court order alone, both CERT-In and DIT are violating the provisions of IT Act 2000 and various Rules under the same.

So far CERT-In/DIT has blocked some 20-25 websites after taking orders from the court but CERT-In/DIT have not used their discretionary power to block an offending website in a single case. In fact, they have refused to use their discretionary power. Clearly not exercising the discretionary power even where there is a clear case for the exercise of the same is violating the mandates of IT Act 2000 and corresponding Rules.

It is not the case that a website should be blocked at the drop of a hat. But when a clear case is made out, insisting upon a court order to block the offending website is definitely a bad policy and erroneous exercise of discretion. It is high time to think seriously about this issue.

Saturday, December 31, 2011

Online Education In India: Some Legal Considerations

Online education in India is still passing through a transformation. In India, a major focus is given to traditional institutionalised education system that requires establishment of big infrastructure not necessarily justifying its costs. On the other hand, online education can provide cost effective, timely, qualitative and transparent education system of India.

Another limitation of the traditional educational system of India is that it is largely academic in nature. Very few educational institutions of India are providing practical trainings and skills development courses while imparting education to their students and professionals.

This has resulted in mass unemployment for a large majority of educated masses of India. As per many studies and surveys, only 20-25% educated population is fit for employment purposes in India. We must stress more upon technical education in India and technical education skills development in India.

Skills development in India is an area that has still not got the attention of policy makers of India. This is more so regarding cyber skills development in India. Virtual campuses in India can solve many of educational problems of India. These problems include corruption, lack of transparency, lack of accountability, non qualitative education, monopolistic behaviours, etc. Virtual campuses can eliminate the corruption in higher education of India and bring fairness and competition among various stakeholders.

Higher education in India needs reform especially the higher legal education in India. PhDs in India are suffering due to corruption. Similarly, lack of skills and expertise is also affecting higher education in India.

Another area that has received limited attention of Indian government pertains to lifelong learning in India. For instance, till now Perry4Law Techno Legal Base (PTLB) is the exclusive techno legal lifelong learning institutions and centre of India. Professional continuing legal education in India is also missing.

Although efforts in the direction of conducting bar examinations in India were undertaken in 2011 yet they are not coherent and well designed and managed. Bar examinations in India need to be properly managed and scientifically undertaken. The focus should be to evaluate skills and knowledge of the students rather than introducing another hurdle that is more on the side of formality. A better option is to scrap the bar examination altogether or conduct a very qualitative bar examination in India.

Further issues have been introduced with the proposal to conduct Indian legal services examinations In India and Indian regulatory services examination In India. These examinations require a totally different outlook, orientation and preparation that are presently missing in India.

As online education in India is going to grow, contents creation and its management would be a big problem. For instance, legal research in India is no good and plagiarism in India and other places is widespread. Further, the growing use of online advertisement for online contents has increased the demand and value for educational and non educational contents. In order to earn money through advertisement and e-learning methods, many individuals and companies are violating the intellectual property rights (IPRs) like copyright of others.

Individuals and companies engaging in online business or transactions are required to observe cyber law due diligence in India. Cyber due diligence for companies in India requires that they avoid violating IPRs of others and also prevent the violation of the same at their own online platforms and websites.

Countries like United States have created dedicated laws like online copyright infringement liability limitation act (OCILLA) in this regard. However, in India we have no such dedicated law for dealing with online copyright violations cases. Even the copyright law of India is not expressly dealing with this issue. However, Internet intermediaries’ liability in India, under the information technology act 2000 (IT Act 2000), covers this issue.

The role and responsibility of Internet intermediaries in the field of copyright in India cannot be anymore ignored by various stakeholders. Even technological issues of IPRs in India must be kept in mind by all while dealing with others contents and IPRs. Liability of Internet intermediaries for copyright violations in India is very stringent under the cyber laws of India and contents of others should not be taken without their permissions.

Perry4Law Techno Legal Base (PTLB) has been providing various techno legal e-learning courses in India. These include online legal education in India, online cyber law education in India, online cyber law trainings in India, online cyber law courses in India, etc.

PTLB is providing the exclusive techno legal e-learning courses in India. The exclusive techno legal e-learning centre in India is also managed by PTLB. It is providing e-learning for lawyers in India, public legal awareness training in India, legal e-learning in India, online skills development in India , etc. There is no second opinion that Indian legal workforce needs to be skilled driven.

Similarly, online education in India needs to be developed urgently. However, in order to achieve this task, we must do proper planning and actual implementation. The sooner it is done the better it would for all the stakeholders involved.

Sunday, December 18, 2011

Cyber Crimes And Social Media Websites In India

Social media websites are popular places for building new relationships and contacts. However, social media websites are also becoming a place for cyber criminals to indulge in various cyber crimes. In fact, the share of offences related to social media websites among cyber crimes registered in India is showing an upward trend. Most of these cases are of posting defamatory or obscene matter or images on various social media websites.

For instance, Facebook users are experiencing attacks from hackers and morphed images having pornographic contents are being uploaded on Facebook accounts without the knowledge of actual users. Cases related to account hacking, morphed photographs and data laundering are very common these days.

Many crimes related to social networking sites involving personation, defamation and anti-national activities have been reported recently. Data collected by the National Crime Records Bureau shows that in cities like Bangalore, those between 30 and 45 years of age are involved more in cyber crimes than youngsters. The bureau records suggest that most cyber offences are for illegal gain, eve-teasing and harassment.

We have no dedicated social media laws in India although guidelines for social media contents monitoring in India may be prescribed. Although we have a cyber law in India in the form of information technology act 2000 (IT Act 2000) yet we have no dedicated social networking laws in India. The cyber law for social media in India needs to be strengthened further keeping in mind a balance between civil liberties and law enforcement requirements.

Human rights protection in cyberspace in India is also required to be considered by Indian government. Presently, protecting civil liberties protection in Indian cyberspace is not a priority for India and this is a serious problem.

For instance, till now we have no social media policy in India. Even we do not have dedicated social networking laws in India that can take care of the misuses of social platforms. However, the framework and guidelines for use of social media for government organisations has been recently suggested by department of information technology. Theses guidelines provide an Indian social media framework for governmental departments and organisations that employees of these organisations must follow.

Social media is considered to be an Internet intermediary as per Indian cyber law. The recent controversy of Internet censorship in India has once again reiterated the importance of effective social media laws in India.

Cyber law due diligence in India has become very stringent. This applies to various fields and to multiple stakeholders. For instance, cyber due diligence for banks in India is now a well known requirement for banks in India. However, Internet intermediaries are the most widely covered stakeholders in this regard. Intermediaries liability for cyber law due diligence in India is really tough and they must take it very seriously. Similarly, social media users must have basic level awareness about cyber laws and cyber crimes. Many of these cyber crimes can be prevented if public awareness about the same is spread in India.

Tuesday, August 23, 2011

Indian Encryption Policy Must Be Formulated

Encryption policy of India is long overdue but India has been slow in formulating this much needed policy. At the same time encryption is also a controversial issue in India that requires a balancing of conflicting interests of law enforcement requirements and personal privacy and security.

Provisions pertaining to encryption usage in India are scattered in various laws, rules and regulations of India. We do not have a centralised or dedicated legal framework for encryption related matters and this is hindering proper usage and innovation in the field of encryption in India.

The cyber law of India, as applicable through information technology act 2000 (IT Act 2000) has a single provisions in this regard. Section 84A of IT Act 2000 says that the Central Government may prescribe the modes or methods of encryption. Till now the Central Government has not prescribed any “modes or methods” of encryption usage in India.

We are compromising the cyber security of India, mobile security of India and mobile governance in India by insisting upon a weak encryption infrastructure. Mobile cyber security in India is not up to the mark and unencrypted communication would further increase the risks.

There are many service providers that use encryption for private and secure communications. The ministry of home affairs has been insisting upon surrendering of encryption keys of such services and in the absence of same banning such encrypted services. However, the ministry of communication and information technology has made it clear that it is not possible to do so.

India has taken too much time to resolve encryption issues and the same must be resolved as soon as possible. Encrypted services would bring both benefits and problems for India. On the benefit side, it would bring secure, private and confidential services. The problem with encryption, like any other technological service, is that it can be abused by criminals.

However, the possibility of abuse should not deter Indian government from using encryption in India. Further, Indian government must develop core cyber skills to deal with encryption related crimes rather than downsising the same and making Indian cyber and mobile security vulnerable to threats.

India needs to upgrade its intelligence infrastructure that is in real mess. Intelligence agencies need to develop intelligence gathering and analysis skills so that situations like the present one can be taken care of. E-surveillance is not a substitute for cyber skills and Indian government and its agencies must realise this truth as soon as possible. However, the call is for the Indian government to take that is shying away from taking a well informed decision in this regard.

Wednesday, July 27, 2011

Is Electronic Service Delivery Bill Worth Considering?

The Electronic Service Delivery Bill 2011(ESDB 2011) started at a very positive note but just like other laws of India, it ended up miserably. Electronic services cannot be effective till it is claimed as a matter of right against the government and its departments. If citizens cannot have mandatory e-services delivery there is no sense in doing the entire exercise.

Take the example of the cyber law of India incorporated in the information technology act 2000. Even after more than 10 years of its enactment till now citizens do not have a mandatory right to e-governance in India.

This happened because of a disabling provisions incorporated as section 9 of the IT Act 2000 that make providing of e-governance services in India discretionary. This has failed the entire purpose of e-governance in India.

Now a similar approach has been adopted regarding the ESDB 2011. If States are not bound to provide “compulsory” e-services delivery, there is no sense in making it a law. Even if it is enacted as a law, not much purpose would be served. Instead, it is better if we streamline public services through administrative reforms in India.

Further, ESDB 2011 would also face problems on the fronts of data protection, data security, privacy rights, cyber security, etc. India has not done enough on any of these fronts and legal framework for all above mentioned areas is still a big problem.

Finally, on the front of digital preservation and pubic records management as well India has to cover a long gap. Let us hope that the proposed ESDB 2011 would cover all these aspects.

Thursday, June 30, 2011

Public Records Act 1993 And IT Act 2000 Mandates

Information Technology Act, 2000 (IT Act, 2000) is the sole Cyber Law of India. It deals with E-Commerce, E-Governance, Cyber Crimes, etc. It also provides a “Digital Framework” for ensuring Digitilisation, Electronic Documents Creation and their use in Government Departments. This “Research Report” of Perry4Law and Perry4Law Techno Legal Base (PTLB) is briefly analysing the relationship between IT Act, 2000 and Public Records Act, 1993 (PRA 1993).

Section 2 of IT Act, 200 deals with definitions that are relevant for PRA 1993 purposes. Section 2(1) provides that in this Act, unless the context otherwise requires:

(i) "Access" with its grammatical variations and cognate expressions means gaining entry into, instructing or communicating with the logical, arithmetical, or memory function resources of a computer, computer system or computer network.

(ii) "Affixing Electronic Signature" with its grammatical variations and cognate expressions means adoption of any methodology or procedure by a person for the purpose of authenticating an electronic record by means of Electronic Signature.

If documents are issued by NIA in electronic form, they have to be authenticated by using electronic signatures. Unauthenticated electronic documents would not create any right or liability either under the IT Act, 2000 or under the PRA 1993.

(iii) "Asymmetric Crypto System" means a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature.

Digital Signatures are based upon Asymmetric Crypto System and they can be used for “Authentication Purposes” by NAI.

(iv) "Computer" means any electronic, magnetic, optical or other high-speed data processing device or system which performs logical, arithmetic, and memory functions by manipulations of electronic, magnetic or optical impulses, and includes all input, output, processing, storage, computer software, or communication facilities which are connected or related to the computer in a computer system or computer network.

(v) "Cyber Security" means protecting information, equipment, devices, computer, computer resource, communication device and information stored therein from unauthorised access, use, disclosure, disruption, modification or destruction.

Cyber Security is an issue that is of “Paramount Importance” for the NAI. When Digitilisation and Digital Preservation would be adopted by NAI, Electronic Documents and Digital Resources would be required to be protected from Cyber Attacks. A Techno Legal Strategy must be formulated by NAI in this regard.

(vi) "Data" means a representation of information, knowledge, facts, concepts or instructions which are being prepared or have been prepared in a formalised manner, and is intended to be processed, is being processed or has been processed in a computer system or computer network, and may be in any form (including computer printouts magnetic or optical storage media, punched cards, punched tapes) or stored internally in the memory of the computer.

(vii) "Digital Signature" means authentication of any electronic record by a subscriber by means of an electronic method or procedure in accordance with the provisions of section 3.

(viii) "Electronic Form" with reference to information means any information generated, sent, received or stored in media, magnetic, optical, computer memory, micro film, computer generated micro fiche or similar device.

(ix) "Electronic Record" means data, record or data generated, image or sound stored, received or sent in an electronic form or micro film or computer generated micro fiche.

(x) "Electronic signature" means authentication of any electronic record by a subscriber by means of the electronic technique specified in the second schedule and includes digital signature.

(xi) "Information" includes data, message, text, images, sound, voice, codes, computer programmes, software and databases or micro film or computer generated micro fiche.

(xii) "Intermediary" with respect to any particular electronic records, means any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record and includes telecom service providers, network service providers, internet service providers, web hosting service providers, search engines, online payment sites, online-auction sites, online market places and cyber cafes.

(xiii) "Key Pair", in an asymmetric crypto system, means a private key and its mathematically related public key, which are so related that the public key can verify a digital signature created by the private key.

(xiv) "Private Key" means the key of a key pair used to create a digital signature.

(xv) "Public Key" means the key of a key pair used to verify a digital signature and listed in the Digital Signature Certificate.

(xvi) "Secure System" means computer hardware, software, and procedure that-

(a) Are reasonably secure from unauthorised access and misuse;

(b) Provide a reasonable level of reliability and correct operation;

(c) Are reasonably suited to performing the intended functions; and

(d) Adhere to generally accepted security procedures.

(xvii) "Security Procedure" means the security procedure prescribed under section 16 by the Central Government.

(xviii) "Verify" in relation to a digital signature, electronic record or public key, with its grammatical variations and cognate expressions means to determine whether:

(a) The initial electronic record was affixed with the digital signature by the use of private key corresponding to the public key of the subscriber;

(b) The initial electronic record is retained intact or has been altered since such electronic record was so affixed with the digital signature.

Section 2 (2) of the IT Act, 2000 provides that any reference in this Act to any enactment or any provision thereof shall, in relation to an area in which such enactment or such provision is not in force, be construed as a reference to the corresponding law or the relevant provision of the corresponding law, if any, in force in that area.

Section 4 of the IT Act, 2000 provides Legal Recognition to Electronic Records. It says that where any law provides that information or any other matter shall be in writing or in the typewritten or printed form, then, notwithstanding anything contained in such law, such requirement shall be deemed to have been satisfied if such information or matter is

(a) Rendered or made available in an electronic form; and

(b) Accessible so as to be usable for a subsequent reference

Section 5 of the IT Act, 2000 provides legal recognition to Electronic Signature. It says that where any law provides that information or any other matter shall be authenticated by affixing the signature or any document should be signed or bear the signature of any person then, notwithstanding anything contained in such law, such requirement shall be deemed to have been satisfied, if such information or matter is authenticated by means of digital signature affixed in such manner as may be prescribed by the Central Government.

Explanation to section 5 provides that for the purposes of this section, "Signed", with its grammatical variations and cognate expressions, shall, with reference to a person, mean affixing of his hand written signature or any mark on any document and the expression "Signature" shall be construed accordingly.

Section 6 of the IT Act, 2000 deals with use of Electronic Records and Electronic Signature in Government and its agencies. Section 6(1) of the Act provides that where any law provides for

(a) The filing of any form, application or any other document with any office, authority, body or agency owned or controlled by the appropriate Government in a particular manner;

(b) The issue or grant of any licence, permit, sanction or approval by whatever name called in a particular manner;

(c) The receipt or payment of money in a particular manner, then, notwithstanding anything contained in any other law for the time being in force, such requirement shall be deemed to have been satisfied if such filing, issue, grant, receipt or payment, as the case may be, is effected by means of such electronic form as may be prescribed by the appropriate Government.

Section 6(2) of the Act provides that the appropriate Government may, for the purposes of sub-section (1), by rules, prescribe -

(a) The manner and format in which such electronic records shall be filed, created or issued;

(b) The manner or method of payment of any fee or charges for filing, creation or issue any electronic record under clause (a).

Section 6A (1) of the IT Act, 2000 provides that the appropriate Government may, for the purposes of this Chapter and for efficient delivery of services to the public through electronic means authorise, by order, any service provider to set up, maintain and upgrade the computerised facilities and perform such other services as it may specify, by notification in the Official Gazette.

The Explanation to Section 6A (1) of the IT Act, 2000 provides that for the purposes of this section, service provider so authorised includes any individual, private agency, private company, partnership firm, sole proprietor form or any such other body or agency which has been granted permission by the appropriate Government to offer services through electronic means in accordance with the policy governing such service sector.

Section 6A of the IT Act, 2000 reflects the intention of Indian Government to provide Electronic Services Delivery in India. In fact, Electronic Services Delivery Bill, 2011 has already been proposed and if implemented would ensure many Electronic Services to Indians.

NAI must start working in the direction of providing its Service Online, if not already done. Even the non-service related matters and matters pertaining to the NAI are already required to be provided online in an Electronic Form as per the requirements of Section 4(1) of the RTI Act, 2005.

Section 7 of the IT Act, 2000 deals with retention of electronic records. Section 7(1) of the Act provides that where any law provides that documents, records or information shall be retained for any specific period, then, that requirement shall be deemed to have been satisfied if such documents, records or information are retained in the electronic form, if-

(a) The information contained therein remains accessible so as to be usable for a subsequent reference;

(b) The electronic record is retained in the format in which it was originally generated, sent or received or in a format which can be demonstrated to represent accurately the information originally generated, sent or received;

(c) The details which will facilitate the identification of the origin, destination, date and time of dispatch or receipt of such electronic record are available in the electronic record.

The Proviso to Section 7 (1) provides that this clause does not apply to any information which is automatically generated solely for the purpose of enabling an electronic record to be dispatched or received.

NAI can convert its Records and Public Records into Electronic Form. Digital Preservation of Records or Public Records can also be done by NAI. While current records can be digitilised non current records can be digitilised and made available to public and researchers as the Electronic Services by NAI.

Section 7(2) of the Act provides that nothing in this section shall apply to any law that expressly provides for the retention of documents, records or information in the form of electronic records.

For instance, the RTI Act, 2005 provides for creating of many records in digital form and available to the public in an online environment. Similarly, the proposed Electronic Services Delivery Bill 2011 also requires providing of Services in online environment. This would also require digitilisation of Records and Public Records by NAI.

Section 7A of the IT Act, 2000 provides that where in any law for the time being in force, there is a provision for audit of documents, records or information, that provision shall also be applicable for audit of documents, records or information processed and maintained in electronic form.

Audit of Electronic Documents would also be undertaken in future. Just like NAI has to maintain proper paper based documents, it would be required to main proper Electronic Records as well.

Section 8 of the IT Act, 2000 provides that where any law provides that any rule, regulation, order, bye-law, notification or any other matter shall be published in the Official Gazette, then, such requirement shall be deemed to have been satisfied if such rule, regulation, order, bye-law, notification or any other matter is published in the Official Gazette or Electronic Gazette.

The proviso to section 8 provides that where any rule, regulation, order, bye-law, notification or any other matters published in the Official Gazette or Electronic Gazette, the date of publication shall be deemed to be the date of the Gazette which was first published in any form.

NAI can publish its Rules, Regulations, etc in Electronic Gazette.

Section 9 of the IT Act, 2000 provides that Sections 6, 7 and 8 would not to confer right to insist document should be accepted in electronic form. Section 9 says that nothing contained in sections 6, 7 and 8 shall confer a right upon any person to insist that any Ministry or Department of the Central Government or the State Government or any authority or body established by or under any law or controlled or funded by the Central or State Government should accept, issue, create, retain and preserve any document in the form of electronic records or effect any monetary transaction in the electronic form.

This is a real “Disabling Provision” that is preventing the actual accomplishment of Electronic Services Delivery in India. By making it “Discretionary” India Government has kept at bay for long the Electronic Delivery of Services to Indians. The latest proposed Electronic Services Delivery Bill 2011 addresses a very small and insignificant portion of the Electronic Delivery of Services in India and till now Electronic Services cannot be claimed as a “Matter of Right”.

However, by virtue of RTI Act, 2005 “Providing Information” about Governmental Departments in Electronic Form has been made “Compulsory”. But till now there is no Law or Provision that makes Delivery of Electronic Services Mandatory in India. This is a “Serious Issue” that must be resolved as soon as possible.

Section 11 of the IT Act, 2000 deals with attribution of Electronic Records. Section 11 says that an electronic record shall be attributed to the originator

(a) If it was sent by the originator himself;

(b) By a person who had the authority to act on behalf of the originator in respect of that electronic record; or

(c) By an information system programmed by or on behalf of the originator to operate automatically.

There may be other provisions of IT Act, 2000 that may be relevant for NAI and PRA 1993 purposes. But for the time being, they are not mandatory in nature. We hope this “Research Report” by Perry4Law and PTLB would be useful for Government Departments in general and national archives of India in particular.

Friday, June 24, 2011

Central Monitoring System Project Of India

Central Monitoring System Project of India (CMS Project of India) is a very crucial project to safeguard Information and Communication Technology (ICT) related security and e-surveillance issues in India. It is mooted by the Central Ministry of Communication and Information Technology (MCIT).

The aim of CMS Project of India is to have a “Centralised Mechanism” where Telecommunications and Internet Communications can be analysed by the MCIT, Indian Government and its Agencies. Some have called this mechanism as the Internet Kill Switch of India where Internet Communications all over India can be suspended through this mechanism.

Recently, the United Nations declared “Right to Access” to Internet as Human Right. This would have a positive impact upon many Human Rights in Cyberspace. For instance, Right to Speech and Expression, Right to Privacy, Right to Know, etc cannot be violated by the CMS Project of India. United Nations must expand Human Rights Protection to many more issues.

This is the real problem for the CMS Project of India. We have no dedicated Privacy Laws in India, Data Security Laws in India and Data Protection Laws in India. Further, the CMS Project of India is also beyond the “Parliamentary Scrutiny”. The Cyber Law of India, incorporated in the Information Technology Act 2000 (IT Act 2000), was drastically amended through the Information Technology Amendment Act 2008 (IT Act 2008).

The IT Act 2008 incorporated various “Unconstitutional Provisions” in the Cyber Law of India that clearly violates the Human Rights in Cyberspace. For instance, provisions regarding Internet Censorship, Website Blocking, Encryption and Decryption, etc have no inbuilt “Procedural Safeguards” as mandated by the Constitution of India. This is the reason why the Cyber Law of India needs to be repealed.

Further, we have no E-Surveillance Policy in India. Even Phone Tapping in India is done in an “Unconstitutional Manner” and even by private individuals with or without Governmental approval.

If CMS Project of India has to be “Legal and Constitutional” it must be subject to “Parliamentary Oversight”. Further, the IT Act 2000 must be repealed as soon as possible as it is clearly not in conformity with the Constitution of India and Civil Liberties Protection in Cyberspace.

Of course, if India Government persists in this “Unconstitutional Approach”, taking recourse of “Self Defence Measures” is not a bad option. Rather that remains the “Sole Option” when our Parliament, Executive and Judiciary fail to protect Fundamental Rights enshrined in the Constitution of India and the Human Rights Charter of United Nations.

Friday, June 17, 2011

Cell Site Location Based E-Surveillance In India

While it came as a respite for the encryption service providers in India when they received the news that their services may not be banned in India yet local telecom service providers in India may not be that lucky. The new telecom equipment policy of India mandates the telecom service providers of India have to ensure location based services accuracy (LBSA) upto 50 meters.

The constitutionality and feasibility of this directive is yet to be analysed. For instance we have no cell site data location laws in India. In fact, we have no privacy laws, data protection laws, data security laws, anti telemarketing laws, anti spam laws, etc. On the contrary, the cyber law of India, incorporated in the information technology act 2000 (IT Act 2000), facilitates e-surveillance, Internet censorship, etc that also without any sort of procedural safeguards. Thus, neither a constitutional nor a statutory legal framework is at place to justify this action on the part of Indian government.

Even if we do a cost analysis this directive may require a heavy investment that telecom operators of India may not be wiling to invest. Telecom industry of India is seriously concerned with the burden shifting practice of Indian government. They believe that governmental security requirements must be managed by government funds alone and should not be passed upon industry players. The new equipment security agreement of India is not addressing either the legal or cost issues.

Technical problems have also been cited as a reason for non feasibility of the terms of Indian equipment security agreement. Based on, the technical standards for accuracy levels as defined by the Indian government, the scale of implementation, the execution of the project and the complexities involved, there is no solution at present that meets the agreement’s mandate. The costs to implement such a system have been estimated at approximately $5 billion.

The Indian equipment security agreement is also weak on the front of privacy protection and data protection. There are no clear policy guidelines in this regard. This is because the new equipment security agreement of India requires telecom operators to maintain location information up to accuracy of 50 meters for customers specified by security agencies of India commencing 1st June 2012, and on all customers, irrespective of whether they are the subject of legal intercept or not from June 2014.

Of course, LBS have many benefits for mobile consumers as well but these befits are far lesser as compared to privacy losses, telemarketing vices, spam communications and information misuses. We need a good and effective national telecom policy of India 2011 that can incorporate all these issue.

Cyber Law Due Diligence In India

Cyber Law Due Diligence and Cyber Security Diligence in India are two fields that are not taken seriously by Stakeholders and Intermediaries of India. Under the Information Technology Act 2000 (IT Act 2000) there are many “Due Diligence Requirements” that Banks, Internet Service Providers (ISPs), Search Engines, E-Commerce Portals, etc must fulfill. However, by and large these Due Diligence Requirements are seldom followed till some “Criminal Prosecution” takes place.

This “Mindset” needs to be changed in India. The Cyber Law of India has express provisions that provides for both Civil and Criminal Liabilities for “Non Observance of Due Diligence”. Once these provisions are attracted, the concerned Person or Institutions has to defend himself/itself in a Court of Law.

In India there is a lack of awareness about both Cyber Law of India as well Cyber Law Due Diligence Requirements in India. This is the main reason why Cyber Law Due Diligence has not been upto the requirements and expectations.

Of all stakeholders, Intermediaries must pay special attention to Cyber Law Due Diligence Requirements of India. Intermediaries like ISPs, Cyber Café owners, Web Hosting Service Providers, Blogging Platforms, etc have to take care of issues pertaining to Cyber Law, Cyber Security, Defamation Laws, Intellectual Property Rights (IPRs) Violations, etc.

A special care must be taken of the Online Copyright issues that are increasingly posing problems for Intermediaries. The liability of Internet Intermediaries for Copyright Violations is an issue that should be taken very seriously. With Laws like Digital Millennium Copyright Act (DMCA) and similar Laws, this liability has become very onerous.

“Take Down Notices” for Copyright Violations in the Cyberspace are very common these days. The moment a take Down Notice is communicated to the Intermediary, it becomes imperative on its behalf to take appropriate action. Further, the “Long Arm Jurisdiction” makes the applicability of National Law Extra Territorial. Even the Cyber Law of India has Extra Territorial Applicability.

Perry4Law and Perry4Law Techno Legal Base (PTLB) “Strongly Recommends” that all Stakeholders and Intermediaries must put in place Robust and Effective Due Diligence Mechanisms at their places. This would not only help them in preventing Crimes and Cyber Crimes but would also protect them from various Civil and Criminal Liabilities as well.

Thursday, June 16, 2011

Cell Site Data Location Laws In India And Privacy Issues

Cell Site Data Location is not a very positive term. It has been in controversies for breaching Privacy Rights of the person whose Cell Site Data was acquired. Cell Site Data tells about the “Location” of a person who is carrying a cell phone, without his consent. This raises many “Privacy Issues” and “Legal issues” as it amounts to E-Surveillance and “Search without a Warrant”.

In the Indian context we have no Cell Site Data Laws. In fact, we have no Privacy Laws, Data Protection Laws, Data Security Laws, Anti Telemarketing Laws, Anti Spam Laws, etc. On the contrary, the Cyber Law of India, incorporated in the Information Technology Act 2000 (IT Act 2000), facilitates E-Surveillance, Internet Censorship, etc “Without any Procedural Safeguards”.

The Constitution of India provides that no Search or Warrant should be conducted without a “Procedure Established by Law”. The Supreme Court of India has given the expression Procedure Established by Law a wider meaning and this has made it a “Due Process of Law”. Now the Indian Government or its Agencies and Instrumentalities cannot “Infringe” upon any Fundamental Right of an Indian Citizen of Person without Due Process of Law.

The Due Process mandates that the Law in question must not be any Law made as a Façade or Formality but must be “Just, Reasonable and Fair”. If we analyse the IT Act 2000, especially after the Information Technology Amendment Act 2008 (IT Act 2008), its “Fails to Satisfy’ the Due Process Clause of Indian Constitution. In short, the Cyber Law of India carries many “Unconstitutional Provisions” and either the Law itself must be Repealed or those Unconstitutional Provisions must be Struck Down by Supreme Court of India.

India needs to formulate separate and dedicated laws for Cyber Law, Cyber Security, Cyber Forensics, Privacy Protection, Data Protection, Data Security, etc. Presently India has no such Laws as even the Cyber Law of India is not good, effective, strong and most importantly “Constitutional”.

As a matter of fact, with the active use of Technology by Indian Government and its Agencies and Instrumentalities, Constitutional Provisions are “Most Frequently Violated” in India. I hope the Supreme Court of India would take note of this “Downsizing” of Indian Constitution that has become a “Regular Feature” these days.

Wednesday, June 15, 2011

White House Is Mulling Federal Cyber Security Law

United States (US) is a country that takes its cyber security very seriously. Recently US declared its international cyberspace strategy. US is also entering into bilateral cyber security agreements with various countries including India. Further, US is also advocating international cooperation for cyber security issues, though within the limits of existing international law framework and not through a dedicated international cyber security treaty.

Cyber attacks at the international level are getting worst and more sophisticated. Recently cyber attacks at Gmail, Citicorp, International Monetary Fund, etc have proved the point. Cyber security has become a necessity these days. Since cyber security is techno legal in nature, both laws and technology must be used to tackle cyber attacks.

India has a bad cyber law, missing cyber security and cyber warfare policy and absent cyber security laws. US on the other hand has good cyber laws and is now planning to have a federal cyber security law. The focus seems to be on developing both offensive and defensive cyber warfare capabilities. The department of homeland security may be entrusted with the job to secure US cyberspace.

In the Indian context, expecting cyber security law before a decade would be pre mature and over optimism. India must first make its cyber law potent and strong by repealing the existing one. But given the preference of e-surveillance over cyber security capabilities in India, the information technology act, 2000 may continue on the statute book despite it being a bad law having unconstitutional provisions.

Cyber security is an international concept and so must be the regulations governing the same. We need international harmonisation because a national approach in this regard would not be sufficed.

Entertainment And Media Industry Growth And Challenges In India

Entertainment and media industries are growing at a fast rate. India’s media and entertainment industry is projected to grow by 18 per cent over the next five years and is expected to become a 1.157 trillion industry by 2012. With this growth there are also increasing cases of disputes as well. A majority of these disputes pertain to intellectual property rights (IPRs) issues.

Similarly, online entertainment is the next big thing for studios and broadcasters. The biggest changes are expected in the Internet, television distribution, video games and casinos sectors.

Although this growth and development is happening in many countries yet a majority of this growth is expected from "BRIC" countries, i.e. Brazil, Russia, India and China. Undoubtedly, the huge markets of China and India are leading that growth. However, we need to consider the legal challenges, especially IPRs issues, in order to fully benefit from this growth of entertainment and media industry.

Indian media and entertainment industry may face the legal challenges of IPRs laws and cyber law of India. IPRs laws like copyright, trademark, etc may be frequently violated and occasionally invoked to redress IPRs violations of media and entertainment industry in India. Similarly, online IPRs issues like domain name disputes may also be agitated in the future. Similarly, media and entertainment industry must keep in mind the mandates like “due diligence” and other provisions of Information Technology Act, 2000.

Media and entertainment industry will also face technological challenges in future. For instance, the issues pertaining to digital preservation of entertainment industry products may assume significance in future. This requires a domain specific and techno-legal expertise that India may not currently possess. This situation requires a shift in the academic and professional education in India that needs to be suitably adopted keeping in mind the contemporary needs.

Tuesday, June 14, 2011

Spear Phishing Is A Potential Threat To Financial Institutions

Cyber security of banking and financial institutions has become very important these days. Recently the Citicorp confirmed the occurrence of cyber attack upon its bank’s network. In India as well ATM frauds, credit card frauds, online banking frauds, etc have increased a lot.

However, of all these cyber crimes, phishing is the most dangerous one for banking customers. If it is a case of spear phishing, it becomes deadly as the targeted person is specifically targeted for this purpose. The attack tactics are also specifically designed for the attack purposes.

The spear phishing cases appear so genuine that even tech savvy people are fooled into divulging sensitive information. Recently Reserve Bank of India (RBI) constituted a working group on information security that gave many good cyber security recommendations. However, the implementation of these recommendations has still not been achieved.

This gives lots of space for cyber crimes like spear phishing. Recent break-ins at high-profile targets like the International Monetary Fund (IMF) demonstrate just how proficient hackers have become at spear phishing.

Today's spear phishing is not only more prevalent but also much more technically proficient. They're not going for a password, anymore, they're getting people to install malware on their computers.

According to the reports the IMF suspected that a phishing attack against one of its workers planted malware on a machine, which was then presumably used to scout the network for data to steal. But the IMF incident was only the most recent in a series of specialized attacks this year aimed at targets from the Oak Ridge National Laboratory and the French foreign ministry to Google's Gmail.

Recent cyber attacks on multinational firms and institutions, from Google and Citigroup to the International Monetary Fund, have raised fears that governments and the private sector are ill-prepared to beat off hackers. The latest high-profile target was the U.S. Senate's website, which was hacked over the weekend.

However, as far as India is concerned, it has neither a good cyber security strategy nor a strong cyber law. Even cyber crisis management plan of India is practically missing. Indian banks must urgently revamp their cyber security so that interests of bank customers can be safeguarded.

Sunday, June 12, 2011

Spam Blogs Are Diminishing Quality Of Google

Spam Blogs are undermining the quality and reputation of Google. Take the example of the blog titled federal credit law firm. It has posted our copyrighted articles without our permission and in active violation of various civil, criminal and intellectual property rights of India. They are also breaching the express copyright notice of our Blog.

A quick search about the credentials of the people behind this Blog makes it clear that they are impersonating as a law firm and by posting our posts, without our permission, they are trying to give an impression that they are related to us somehow and somewhere, directly or indirectly.

We have no relation whatsoever with these people and we have lodged a DMCA complaint as well as spam complaint with Google. We are also contemplating taking civil and criminal actions against the offenders.

We have also requested Google to take the necessary administrative and legal action against these imposters. The deletion of the Blog(s) of these imposter is the least Google can do and Google must do backgrounds check of their activities on the search engine.

The cyber law of India prescribes various “due diligence requirements” on the part of Google. Since the matter has been actually brought to the knowledge of Google, the information technology act 2000 applies to it. The law imposes various liabilities upon Google and since we are located in India, Indian courts have jurisdiction over the matter.

We hope Google would do the needful as soon as possible to avoid any actual, constructive and vicarious liability.

Friday, June 10, 2011

EU Sets Up Team Of Cyber Crimes Fighters

European Union has been taking cyber crimes very seriously. EU has recently proposed to enhance the minimum punishment for serious cyber crimes to five years and for non serious crimes to two years.

EU is also aware that besides a stringent law, it must also develop capabilities to fight cyber crimes. This is the reason why EU has set up a team of cyber crimes fighters to tackle growing cyber crimes in Europe.

Cyber attacks in Europe are increasing and recently 30 million euros' worth of carbon credits stolen by one such attack. The 10-strong team of IT security experts will guard against repeats of attacks on sensitive information, for example on the eurozone debt crisis, such as occurred on the eve of the last summit of national leaders in March.

Cyber-attacks are a very real and ever-increasing threat that can paralyse key infrastructure and cause huge long-term damage," said European Union digital agenda commissioner Neelie Kroes.

India on the other hand is soft upon cyber criminals. The information technology act 2000 of India, which is the sole cyber law of India, is not stringent and strong enough. After the information technology amendment act 2008, almost all the cyber crimes have been made bailable.

This has taken the sting and deterrent out of the cyber law of India. Some experts even have suggested repeal of the same and enactment of strong cyber law for India. Even on the front of policy India is not performing well. We have no cyber security policy in India and even the cyber crisis management policy of India is missing.

We urgently need to ensure strong and robust legal enablement of ICT systems in India. This enablement must include enablement of cyber law, cyber security, cyber forensics, etc. Like developed countries, India must also make its cyberspace safe and secure.

Legal Enablement Of ICT Systems In India

Information and communication technology (ICT) is both a boon and bane. It is a boon as it facilitates e-governance, e-commerce and e-delivery of public services. It is a bane as it has a darker side as well. ICT is very frequently used for committing various cyber contraventions and cyber crimes.

This is the reason why we must have a strong and stringent legal framework to regulate ICT dealings. Legal enablement of ICT systems ensures formulation of legal framework for various cyberspace dealings.

Legal enablement covers areas like cyber law, cyber security, cyber forensics, critical ICT infrastructure protection, anti cyber warfare steps, anti cyber espionage steps, anti cyber terrorism steps, etc.

Legal enablement also includes policy issues like cyber law policy, cyber security policy, cyber forensics policy, etc. At the same time legal enablement also ensures a legal framework for all these components. A cyber crisis management plan is also an essential part of the legal enablement initiative of any nation.

In the national context we have no legal enablement of ICT systems in India. We have information technology act 2000 as the cyber law of India that is trying to give some legitimacy to cyberspace dealings in India. However, in the desire to get everything at a single place, the cyber law of India has failed to achieve even a single aspect of legal enablement.

There is no deterrent for cyber criminals in India as almost all the cyber crimes are bailable. Mandatory e-governance services in India are missing and the cyber law of India has imposed a blanket ban upon asking such services by Indiana citizens. The e-commerce environment of India is also not safe and sound. Lack of cyber security and encryption usage makes e-commerce of India highly vulnerable to cyber attacks.

India must repeal the cyber law of India and come up with separate laws on these aspects of legal enablement. As far as cyber security law and cyber forensics law are concerned, India has none.

It would be safe to presume that we have no legal enablement of ICT systems in India. India is not a part of international cyber law treaty and there is also no international cyber security treaty in existence. Thus, India is lax regarding legal frameworks, policy issues and cyber security requirements and the same need to be changed as soon as possible for the larger interest of India.

Thursday, June 9, 2011

Cyberspace Crisis Management Plan Of India

Crisis Management is an important aspect of planning and management of any project or eventuality. If we have a proper Crisis Management Plan, losses of lives and property is minimised to a great extent. We have Crisis Management Plans in India against floods, earthquakes and other natural calamities. However, are we prepared for Cyber Crises in Indian Cyberspace?

India has formulated a Crisis Management Plan for its Cyberspace. However, like other Policies and Strategies in India, it has not been implemented in true letter and spirit. Even the basic level Cyber Security Preparedness in India is not up to the mark.

There are many aspects of a Cyber Crisis Management Plan. For instance, Cyber Security, Cyber Law, Cyber Forensics, Anti Cyber Terrorism Plans, Anti Cyber Espionage Plans, Anti Cyber Warfare Plans, Human Rights Protection in Cyberspace, Critical ICT Infrastructure Protection, etc are some of the “Components” of a Cyber Crisis Management Plan.

Theoretically, India has a Cyber Law in the form of Information Technology Act 2000 (IT Act 2000), Cyber Security in the form of Government Guidelines, Cyber Forensics Practices in Governmental Laboratories alone and so on.

However, practically we have no Cyber Crimes Laws in India as the Cyber Law of India has made almost all the Cyber Crimes “Bailable”. We may have a Cyber Law but India has no Cyber Crimes Law. So Legal Framework for preventing Cyber Crimes is “practically missing” in India.

As far as Cyber Security is concerned, we have no Cyber Security Laws in India and no Cyber Security Policy in India. The Governmental Guidelines are meant for Government Departments alone and even these Government Departments do not follow the same. Government Websites are the most frequently defaced websites in India. Similarly, Government Computers are the “most successfully breached” Computers in India. Computers of Defense Forces, Prime Minister’s Office (PMO), Ministry of External Affairs (MEA), Ministry of Home affairs, etc have been successfully breached without even notice by these Ministries/Offices.

As far as other components of Cyber Crisis Management Plan of India are concerned, even they do not exist in India. We have no Cyber Forensics Laws in India, no Cyber Terrorism Policy in India, no Cyber Warfare Policy in India, no Critical ICT Infrastructure Protection Policy in India and no Human Rights Protection in Cyberspace in India.

In fact, Projects like Aadhar, NATGRID, CCTNS, Central Monitoring System (CMS) of India, etc are openly violating the Human Rights of Indians. These Projects are operating without any Legal Framework, Parliamentary Oversight and Judicial Scrutiny.

Even the basic Privacy Rights in India are missing. It is only now the Law Ministry of India has proposed the Right to Privacy Bill 2011 of India. Further, Data Protection Law in India is urgently required. We also need a Data Security Policy of India so that sensitive information and data of projects like Aadhar, NATGRID, CMS, etc is not “misused” once it falls in the wrong hands.

India cannot have a robust and effective Cyber Crisis Management Plan till it considers these aspects and actually starts working in the direction of achieving these components.

Wednesday, June 8, 2011

Cyber Security Laws In India

The debate between self regulatory environment and a regulatory environment has always been a part of technology related laws. Some believe that issues like cyber law, cyber security, cyber forensics, etc must be regulated by the government whereas others believe that they should be left to individuals and organisations as self regulatory mechanisms.

In this present fragile and dangerous cyberspace it would not be advisable to leave everything upon self regulation mechanism. Issues like cyber law, cyber security, cyber forensics, etc deserve to be regulated at national and international level.

We have no legal framework or laws for cyber security in India. Of course, a few provisions have been incorporated in this regard in the information technology act, 2000 of India that is the sole cyber law of India. However, we need express and dedicated cyber security legislation in India as soon as possible.

Even the cyber law of India needs to be upgraded and strengthened. We need stringent provisions against cyber criminals and not the soft provisions that are presently incorporated in the Indian cyber law. By making the offences and cyber crimes “bailable” India has made its cyberspace a “free zone” and “safe heaven” for cyber criminals and cyber offenders.

It seems the problems of Indian cyber security are multi facet in nature. We do not have sufficient laws, we lack proper strategies and policies, and we do not care much about cyber security.

To start with we must formulate a pro active cyber security policy of India. Then we must proceed towards strengthening our existing cyber law and enacting an effective cyber security law of India. The sooner we consider these issues the better it would be for the cyber security of India.

Monday, June 6, 2011

United Nations And Human Rights In Cyberspace

Human Rights Protection in Cyberspace is urgently needed at National and International level. The call is for the United Nations to take that is “Slow” in this regard. No time in the history of Internet and Cyberspace the need for Protection of Human Rights in Cyberspace is more than the present times.

If the United Nations believes in Human Rights, it must start thinking towards its new form in this Internet Era. There is no reason why Human Rights in Cyberspace must be given any lesser importance than its traditional Human Rights. After all Human Rights like Right to Speech and Expression, Right to Information, Right to Know, Privacy Rights, etc are similar in Cyberspace. Rather violation of Human Rights in Cyberspace is much easier and more frequent.

What is most surprising is why UN has still not considered Cyberspace as an essential part of human life. If we analyse the trends World over, technology has been increasingly used to violate Human Rights in Cyberspace. Thus, UN must urgently protect Human Rights in Cyberspace.

Even the World community on Human Rights, Cyber Law and Cyber Security must start thinking in this direction as issues like Cyber Warfare, Cyber Terrorism, Cyber Espionage, Cyber Crimes, E-Surveillance, Unlawful Interceptions, etc are “Transnational” in nature. If different Countries would have different laws for these issues, it would be very difficult to truly enforce protective provisions against these menaces at National and International levels.

This is the reason why we must a “Harmonised Legal Framework” in this regard, preferably under the regime of United Nation’s Human Rights Organisation. The Governments all over the World are engaging in illegal and unlawful phone tapping and interceptions. This is violating various Human Rights that must be addressed immediately by the International Community.

The present UN Framework for Human Rights can be “Suitably Amended” to accommodate Human Rights in Cyberspace. Almost all the Countries of the World are Member of UN and this would extend Human Rights Protection in Cyberspace to their Citizens automatically. The call is for UN to take and the sooner it is taken by it the better it would for Citizens’ World wide.

Take the example of India. The Cyber Law of India is violating various Human Rights in Cyberspace. This is the main reason why we started the exclusive Cyberspace Human Rights Protection Centre of India. So much offensive is the Cyber Law of India that it deserves to be repealed.

Further, Indian Government launched Projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

If there is no “Internationally Acceptable Standard” for Protection of Human Rights in Cyberspace, Countries like India would keep on enacting and applying the Draconian Laws like Information Technology Act, 2000, Indian Telegraph Act, 1885, Official Secrets Act, etc.

Finally, UN has shown some inclination in this regard. UN now considers Internet access a Human Right and considers disconnecting people from the Internet as a violation of Human Rights and International Law. A Report by the UN Human Rights Council’s 17th Session underscored the “unique and transformative" nature of the Internet allowing individuals to exercise a range of Human Rights, and to promote the progress of society as a whole.

I welcome this initiative of UN as this is a good step in the right direction. However, UN must not stop here and must move towards enacting a “Comprehensive Framework” for Protection of Human Rights in Cyberspace.