Showing posts with label NATGRID. Show all posts
Showing posts with label NATGRID. Show all posts

Tuesday, March 13, 2012

National Counter Terrorism Centre Of India: The Problems and Solutions

This is the research analysis of Perry4Law and Perry4Law Techno Legal Base (PTLB) regarding the legality, constitutionality, requirements, etc of establishment of national counter terrorism centre of India. Perry4Law and PTLB have outlined all the legal constitutional and administrative issues at a single place so that parliament of India, home ministry and Indian government can consider the same. Perry4Law and PTLB hope that this analysis would be useful for all concerned.

National counter terrorism centre (NCTC) of India has been facing many ups and downs. This is despite the fact that national counter terrorism centre (NCTC) of India is required to meet the growing national security requirements of India.

However, there are many constitutional, legal and administrative challenges that NCTC is facing. In the past the NCTC of India was downsized in its nature, scope and functions. Now NCTC of India is facing stiff oppositions from various States that consider establishment of NCTC as an encroachment upon their law and enforcement powers and federalism features of Indian constitution.

However, these objections and oppositions are mostly politically motivated and are not truly striking at the real problem from which NCTC has been suffering. The real issue that must be demanded by political parties is that parliamentary oversight of intelligence agencies of India is needed. Till now there is no parliamentary scrutiny of the intelligence agencies in India.

Indian Government is too reluctant to ensure parliamentary oversight for intelligence agencies and law enforcement agencies of India. If this is not enough, Indian government has been launching new projects having serious “constitutional ramifications” and “civil liberties violation” effects.

For instance, the national counter terrorism centre (NCTC) project of India, national intelligence grid (Natgrid) project of India, Aadhar project of India, crime and criminal tracking network and system (CCTNS), etc are not governed by any legal framework and parliamentary oversight. Indian government is not willing to understand and accept that intelligence work is not an excuse for non accountability.

For some strange reasons intelligence infrastructure of India has become synonymous for non accountability and mess. There is neither any parliamentary oversight nor and transparency and accountability of the working of intelligence agencies of India.

Even a basic level effort to enact a legal framework for intelligence agencies of India is missing in India. The first and foremost challenge to such parliamentary oversight mechanism comes from the intelligence agencies themselves that do not wish to be governed by any rules and norms at all. Then we have “bureaucratic hurdles” in India that do not allow such a legal framework to be proceeded with. Finally, the parliament of India itself is not interested in bringing these intelligence agencies within the fold of parliamentary oversight.

Take the example of the recent private bill titled intelligence services (powers and regulation) bill, 2011. It was shelved out by none other than the Indian Prime Minister Dr. Manmohan Singh who announced that law on intelligence agencies would be formulated soon. However, it proved nothing but a “time gaining tactics” and so far intelligence agencies of India are not governed by any legal framework and parliamentary oversight. Interestingly, even the central bureau of investigation (CBI) is riding the same boat. The draft central bureau of investigation act, 2010 is another example where the Indian government is just interested in making “declaration” with no actual “intention” to implement the same.

In these circumstances, can the States trust the Centre regarding the establishment of National Counter Terrorism Centre (NCTC) of India? The answer is definitely negative even if States keep their “political interests” aside. Of course, there are “practical difficulties” and “internal turf war” among various agencies and ministries of Central government a well. It seems the obvious but unsolvable terrorism dilemma in India would continue as national interest of India and fighting terrorism is not a “national priority”.

Till now the constitutionality of the national investigation agency act 2008 (NIAA 2008) has not been accepted by States and now NCTC has been launched through an “executive order”. The practice of clubbing new projects, agencies and institutions with existing laws is a bad approach. So NCTC without a legal framework is definitely unconstitutional and even tagging it with the Unlawful Activities (Prevention) Act, 1967 would not save it from the patent and apparent unconstitutionality with which it is suffering.

The NCTC project of India is also “very significant” for the national security of India. Terrorist attacks against India are on increase and we need a “specilaised institution” like NCTC to provide and analyse valuable intelligence inputs and leads.

The real problem seems to be “lack of coordination and harmonisation” between the Centre and States. The Constitution of India has made a clear demarcation between the legislative, executive and judicial powers of Centre and State. The NIAA 2008 and NCTC are sitting at the “border line” of the legislative and executive powers of Centre that can be challenged by various States.

The intentions of Home Minister Mr. P.Chidambaram are good but the concerns of States are also of equal force. Further, the turf war between multiple intelligence agencies operating under different government ministries is also causing problem for the successful establishment of NCTC. Even there is a lack of proper planning and management on the part of Union Home Ministry that is causing delayed implementation of projects like Natgrid, NCTC, CCTNS, etc.

If Mr. P. Chidambaram really wants his projects to become successful, he has to think well beyond the present “parameters and objectives” set by Indian government in general his own ministry in particular. A good starting point can be formulation of a “constitutionally sound legal framework” that can confer legitimacy and constitutionality to projects like NATGRID, NCTC, CCTNS, etc. Obviously, States must be taken into confidence before starting any such legislative exercise.

This must be supplemented by sound planning and management. The projects of Home Ministry are neither simple nor easy to execute. They required dedicated efforts from all directions. Experts from diverse fields must be on panel of Home Ministry so that these Projects can be successfully implemented. We are sure Home Minister Mr. P. Chidambaram would have already considered these aspects and we wish all the best to him in this regard.

Friday, February 24, 2012

Phone Tapping Laws In India Required

Phone Tapping in India has never been a smooth ride. While Phone Tapping procedures essentially require a “Judicial Order” in most Jurisdictions of the World yet India preferred to keep Phone Tapping Procedure out of the reach of Indian Judiciary. The entire procedure of Phone Tapping is an “Executive Action” devoid of Judicial Interventions and Judicial Reviews.

Big Brother in India is Overstepping the Constitutional Limits. Neither there is a “Constitutionally Sound” Lawful Interception Law in India nor are the existing Laws like Indian Telegraph Act, 1885 strictly in compliance with Indian Constitution. Interestingly, Phone Tapping by “Private Individuals” in India is rampant and the Phone Tapping by Indian Government is “Practically Unaccountable”.

We have no Constitutionally Sound Lawful Interception Law in India. Even the Home Ministry of India has considered enactment of a Lawful Interception Law in India. A Constitutional Phone Tapping Law in India is needed to prevent Unconstitutional Phone Tapping in India.

However, the worst affected area seems to be Parliamentary Oversight of Intelligence Agencies of India and various E-Surveillance Projects of India. We have no E-Surveillance Policy in India as well. Further, the National Counter Terrorism Centre (NCTC) Project of India, National Intelligence Grid (Natgrid) Project of India, Aadhar Project of India, Crime and Criminal Tracking Network and System (CCTNS), etc are not governed by any Legal Framework and Parliamentary Oversight. Indian Government is not willing to understand and accept that Intelligence Work is not an excuse for Non Accountability.

The Central Monitoring System Project of India (CMS Project of India) is also not supported by any Legal Framework. Surveillance of Internet Traffic in India is also another area that requires a sound Legal Framework. The Phone Tapping Law proposed by the Home Ministry is a history now. Intelligence Services (Powers and Regulation) Bill, 2011 and Draft Central Bureau of Investigation Act, 2010 have long suggested and gone. The Constitutionality of the National Investigation Agency Act 2008 (NIAA 2008) is still doubtful. Even we have no dedicated Privacy Laws in India, Data Security Laws in India and Data Protection Laws in India.

In short, the Legal Regime in these crucial areas is in “Real Mess” and without these “Crucial Legislations”, the Projects and Initiatives of Indian Government cannot be considered to be Constitutional. Project s like Aadhar, NATGRID, NCTC, CCTNS, CMS, etc are “Violating Constitutional Safeguards” and are therefore “Unconstitutional”.

It is high time for the Parliament of India to interfere as the “Legislative Function” is about to be transferred to the “Executive Branch” of Indian Constitution and Indian Judiciary is looking at it in a helpless manner. The precious Human Rights in Cyberspace are under grave risks as there is none in India that can presently enforce Fundamental Rights and Human Rights in Indian Cyberspace. Perhaps, Proactive Self Defense in India Cyberspace must be exercised by Indian Citizens to “Safeguard” their Civil Liberties themselves as our own Executive, Legislature and Parliament have failed to do so.

Wednesday, December 21, 2011

Intelligence Gathering Is Not Above Right To Privacy In India

Right to privacy in India is a constitutional right. Efforts are in the process to make it a statutory right as well. A dedicated statutory right to privacy in India is in pipeline in the form of right to privacy bill of India 2011. The proposed Bill must protect human rights in cyberspace to be valid and constitutional and it must respect the privacy rights of Indians in the information age. The proposed draft right to privacy bill 2011 of India may confer some form of privacy rights to Indians. However, its true scope is yet to be made public.

Privacy laws in India and privacy rights in India have always been ignored. We have no national privacy policy in India as well. Data protection laws in India are missing and so are data privacy laws in India. Privacy, data protection and India seems to be separable and unrelated concepts.

Indian government launched projects like Aadhar, National Intelligence Grid (Natgrid), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under parliamentary scrutiny.

Further, there are some very crucial issues that are posing constitutional problems for the intelligence and security agencies of India. For instance, intelligence gathering in India is unconstitutional. Similarly, counter terrorism capabilities of India are not sufficient and Indian counter terrorism capabilities needs rejuvenation. Finally, parliamentary oversight and constitutional safeguards are missing in the functions of these agencies.

India does not have a constitutionally sound lawful interception law. Phone tapping in India is still done in an unconstitutional manner and at times by private individuals as well. Further surveillance of Internet traffic in India is now openly acknowledged by Indian government.

The intelligence infrastructure of India has become synonymous for non accountability and mess. There is neither any parliamentary oversight nor and transparency and accountability of the working of intelligence agencies of India. Intelligence infrastructure of India needs rejuvenation keeping in mind the constitutional obligations.

The draft Intelligence Services (Powers and Regulation) Bill, 2011 has failed to take the shape of a law in India and it has been announced that law on intelligence agencies would be formulated soon. Even the Draft Central Bureau of Investigation Act, 2010 has failed to become an applicable law.

E-surveillance in India, websites blocking in India, Internet censorship in India, etc are also not done a strictly constitutional manner. Till now Indian courts have not tested the acts of intelligence agencies. Recently Indian research and analysis wing (RAW) was granted e-surveillance powers without any legal framework. Now the home ministry of India is demanding that intelligence and law enforcement agencies must be kept out of the purview of the proposed Privacy law, and should be allowed to continue monitoring the activities and carry out electronic surveillance of citizens.

Home ministry is suggesting that the way intelligence and investigation agencies are exempted under schedule 2 of the Right to Information (RTI) Act, they should be kept out of the proposed privacy Bill in view of national security.

Under schedule 2 of the RTI Act, citizens are restricted from seeking information from agencies such as the Intelligence Bureau (IB), the Research and Analysis Wing, the Central Bureau of Investigation, the National Investigation Agency, the National Intelligence Grid and the National Technical Research Organisation.

Home ministry do not wants the privacy Bill to interfere with intelligence gathering activities even if means accommodating more safeguards in line with the sprit of the privacy Bill.

This seems to be an unreasonable demand as we must now stress upon great parliamentary scrutiny of intelligence agencies and law enforcement agencies. On the contrary we are diluting the constitutional freedoms and procedural safeguards. It is high time for parliament of India to interfere and enact constitutionally sound laws in this regard.

Friday, August 26, 2011

Cyber Police Reforms In India Are Needed

Police reforms in India are long overdue. Whether it is on the front of legal framework, prison conditions, police accountability and transparency or any other similar aspect, police reforms in India have been stagnant.

Some of these reforms pertain to infrastructure while others pertain to policy formulation and still others regarding brand and image making of police in India. While these reforms can be managed through political will yet one reform area that cannot be achieved through mere political will pertains to training of police force in technology related issues.

For instance, we do not have enough cyber crime investigation capabilities in India till now. Cyber crime investigation in India is still far from satisfactory and there are selective police officials who are aware of technological issues and technological laws like information technology act 2000 (IT Act 2000).

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been working in the direction of removing these obstacles for the law enforcement officials of India. PTLB has been managing a techno legal ICT training centre for police force that intends to fill this void and make our police force techno legal in nature.

Perry4Law and PTLB suggest that police force of India must be well versed in areas like cyber law, cyber security attacks, cyber forensics, digital evidencing and e-discovery, video conferencing evidence, e-courts, etc.

Presently, these issues are not considered by police force of India. To start with police force must be made aware of the cyber law of India and its applicable provisions. Further, police in India also needs to learn how to investigate a cyber crime. Simple issues of cyber forensics like internet protocol address tracking and data recovery must also be learned by police force of India.

Indian government in general and ministry of home affairs in particular must pay special attention to these issues as ambitious projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), etc cannot be run successfully through an untrained police and intelligence force.

Cyber skill and intelligence gathering skills need to be developed in India as soon as possible. Perry4Law and PTLB hope that our suggestions would be considered by Indian government for the larger interest of all concerned.

Sunday, June 26, 2011

Human Rights Protection In Indian Cyberspace

A few years back talking of human rights in cyberspace was seen with skepticism. Now people around the world are more concerned and aware of their human rights in cyberspace.

Surprisingly, United Nations has still not considered human rights issues of cyberspace though it has recently announced that access to Internet is a human right. United Nations must seriously consider protection of human rights in cyberspace as soon as possible as nations across the world are becoming more and more oppressive and endemic e-surveillance oriented.

While United Nations has declared that access to Internet is Human Rights yet Indian government is well committed to deny not only this human rights but also all other possible human rights in cyberspace.

For instance, projects like national intelligence grid (Natgrid), central monitoring system project of India (CMS), centre for communication security research and monitoring (CCSRM), Aadhar project of India, crime and criminal tracking network and systems (CCTNS), national counter terrorism centre (NCTC), etc have no “procedural safeguards” and they are violating human rights and fundamental rights in their “present form”.

These projects have been launched without any legal framework and parliamentary oversight. Further, even the most “basic laws” like data protection Laws, data security laws, privacy laws, etc are missing in India.

United Nations must urgently step in to formulate an international treaty on protection of human rights in cyberspace. If UN maintains its indifferent attitude, draconian laws like the cyber law of India keep on surfacing.

Wednesday, June 22, 2011

Intelligence Work Is Not An Excuse For Non Accountability

Indian Government has decided to “Exempt” Central Bureau of Investigation (CBI), National Investigation Agency (NIA) of India and National Intelligence Grid (NATGRID) from the applicability of Right to Information Act 2005 (RTI Act 2005). This is a “Policy Decision” and is well within the Powers of the Executive Branch of Indian Constitution.

Generally, Policy Decisions of Executive are not subjected to “Judicial Review”. However, if the Policy Decisions are Malafide, Unconstitutional or violates the Rule of Law, these decisions can be “Challenged” in a Court of Law.

Before we analyse the Policy Decision of Indian Government to exempt CBI, NIA and NATGRID, we must be aware of some background facts. The RTI Act 2005 is the sole “Transparency Law of India” that needs further amendments and strengthening. However, the proposed Right to Information Rules 2010 instead of strengthening the RTI Act, 2005 took steps that are Retrograde in nature.

The Constitutional Validity of National Investigation Agency Act, 2008 (NIA 2008) is still doubtful and CBI and NATGRID are not governed by any law at all. Even the proposed Central Monitoring System (CMS) of India is “Without any Parliamentary Oversight”.

In short, whether it is CBI or Intelligence Agencies of India, none of them are presently Accountable to Parliament of India. Human Rights in Cyberspace in India are regularly targeted by Indian Government and its Agencies without “Constitutional Laws”. Without Parliamentary Scrutiny and Judicial Review these Agencies cannot be considered to be “Constitutional”. If these Agencies are themselves “Unconstitutional” their functioning is also “Unconstitutional”.

Indian Government has already made these Agencies “Non Accountable” and now it is making them “Non Transparent” as well. In my personal opinion, this Policy decision of India Government is “Unconstitutional” and is well within the scope of Judicial Review.

This also casts a doubt about the “Impartiality and Transparency” of these Agencies. Exempting these Agencies without any parallel “Parliamentary Oversight” is against the provisions of Indian Constitution.

But then there seems to be no “Separation of Powers” in India any more and expecting Parliament of India to perform its “Constitutional Duties” can safely be considered to be “Over Ambitious Thinking”.

Monday, June 20, 2011

Indian Government Waking Up To Privacy Laws Requirements

Of late Fundamental Rights and Civil Liberties of Indian Citizens in Cyberspace have been totally neglected by the Executive and Legislative Branches of Indian Constitution. Unfortunately, even Judiciary failed to interfere and we have reached a “Precarious Situation” where the Constitution of India, especially Fundamental Rights, are about to be made “Redundant and Non Existent”.

While United Nations has declared that “Access to Internet” is Human Rights yet Indian Government is well committed to deny not only this Human Rights but also all other possible Human Rights in Cyberspace.

Naturally, there is a need to protect Human Rights in Cyberspace before we fully launch various E-Surveillance and Civil liberties Violating Projects in India. Security and E-Surveillance Projects have been launched by Indian Government without any “Procedural Safeguards” and in active “Violation” of Human Rights in Cyberspace. The only solace is that these Projects are in their infancy stage and they can still be made “Constitutional”.

For instance, Projects like National Intelligence Grid (NATGRID), Central Monitoring System of India (CMS), Centre for Communication Security Research and Monitoring (CCSRM), Aadhar Project of India, Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), etc have no “Procedural Safeguards” and they are violating Human Rights and Fundamental Rights in their “Present Form”. These Projects have been launched without any Legal Framework and Parliamentary Oversight. Further, even the most “Basic Laws” like Data Protection Laws, Data Security Laws, Privacy Laws, etc are missing in India.

Realising the “Gravity of the Situation”, the Planning Commission of India has now decided to call a high-level meeting of experts, civil society representatives and government officials to address these concerns. The Commission admits that initiatives like UID, NATGRID, DNA profiling, brain mapping and tapping communication, etc are “Genuine Concerns” and they need to be addressed properly. The Commission has also suggested using “Inbuilt Technological Safeguards” for all these Projects.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been constantly suggesting that privacy is a key concern in all these Projects as people's personal information would be stored in a single database and the possibility of corruption and exploitation could not be ruled out.

The minister, incharge of IT in the plan panel, said it is necessary to have in-depth and threadbare discussion with experts, civil society representatives and government officials to ensure that the objective of national security and efficiency in public service delivery mechanism are effectively reconciled with the privacy concern of citizens.

This is a good step in the right direction and Perry4Law and PTLB welcome this step of Indian Government.

Thursday, June 9, 2011

Cyberspace Crisis Management Plan Of India

Crisis Management is an important aspect of planning and management of any project or eventuality. If we have a proper Crisis Management Plan, losses of lives and property is minimised to a great extent. We have Crisis Management Plans in India against floods, earthquakes and other natural calamities. However, are we prepared for Cyber Crises in Indian Cyberspace?

India has formulated a Crisis Management Plan for its Cyberspace. However, like other Policies and Strategies in India, it has not been implemented in true letter and spirit. Even the basic level Cyber Security Preparedness in India is not up to the mark.

There are many aspects of a Cyber Crisis Management Plan. For instance, Cyber Security, Cyber Law, Cyber Forensics, Anti Cyber Terrorism Plans, Anti Cyber Espionage Plans, Anti Cyber Warfare Plans, Human Rights Protection in Cyberspace, Critical ICT Infrastructure Protection, etc are some of the “Components” of a Cyber Crisis Management Plan.

Theoretically, India has a Cyber Law in the form of Information Technology Act 2000 (IT Act 2000), Cyber Security in the form of Government Guidelines, Cyber Forensics Practices in Governmental Laboratories alone and so on.

However, practically we have no Cyber Crimes Laws in India as the Cyber Law of India has made almost all the Cyber Crimes “Bailable”. We may have a Cyber Law but India has no Cyber Crimes Law. So Legal Framework for preventing Cyber Crimes is “practically missing” in India.

As far as Cyber Security is concerned, we have no Cyber Security Laws in India and no Cyber Security Policy in India. The Governmental Guidelines are meant for Government Departments alone and even these Government Departments do not follow the same. Government Websites are the most frequently defaced websites in India. Similarly, Government Computers are the “most successfully breached” Computers in India. Computers of Defense Forces, Prime Minister’s Office (PMO), Ministry of External Affairs (MEA), Ministry of Home affairs, etc have been successfully breached without even notice by these Ministries/Offices.

As far as other components of Cyber Crisis Management Plan of India are concerned, even they do not exist in India. We have no Cyber Forensics Laws in India, no Cyber Terrorism Policy in India, no Cyber Warfare Policy in India, no Critical ICT Infrastructure Protection Policy in India and no Human Rights Protection in Cyberspace in India.

In fact, Projects like Aadhar, NATGRID, CCTNS, Central Monitoring System (CMS) of India, etc are openly violating the Human Rights of Indians. These Projects are operating without any Legal Framework, Parliamentary Oversight and Judicial Scrutiny.

Even the basic Privacy Rights in India are missing. It is only now the Law Ministry of India has proposed the Right to Privacy Bill 2011 of India. Further, Data Protection Law in India is urgently required. We also need a Data Security Policy of India so that sensitive information and data of projects like Aadhar, NATGRID, CMS, etc is not “misused” once it falls in the wrong hands.

India cannot have a robust and effective Cyber Crisis Management Plan till it considers these aspects and actually starts working in the direction of achieving these components.

Monday, June 6, 2011

United Nations And Human Rights In Cyberspace

Human Rights Protection in Cyberspace is urgently needed at National and International level. The call is for the United Nations to take that is “Slow” in this regard. No time in the history of Internet and Cyberspace the need for Protection of Human Rights in Cyberspace is more than the present times.

If the United Nations believes in Human Rights, it must start thinking towards its new form in this Internet Era. There is no reason why Human Rights in Cyberspace must be given any lesser importance than its traditional Human Rights. After all Human Rights like Right to Speech and Expression, Right to Information, Right to Know, Privacy Rights, etc are similar in Cyberspace. Rather violation of Human Rights in Cyberspace is much easier and more frequent.

What is most surprising is why UN has still not considered Cyberspace as an essential part of human life. If we analyse the trends World over, technology has been increasingly used to violate Human Rights in Cyberspace. Thus, UN must urgently protect Human Rights in Cyberspace.

Even the World community on Human Rights, Cyber Law and Cyber Security must start thinking in this direction as issues like Cyber Warfare, Cyber Terrorism, Cyber Espionage, Cyber Crimes, E-Surveillance, Unlawful Interceptions, etc are “Transnational” in nature. If different Countries would have different laws for these issues, it would be very difficult to truly enforce protective provisions against these menaces at National and International levels.

This is the reason why we must a “Harmonised Legal Framework” in this regard, preferably under the regime of United Nation’s Human Rights Organisation. The Governments all over the World are engaging in illegal and unlawful phone tapping and interceptions. This is violating various Human Rights that must be addressed immediately by the International Community.

The present UN Framework for Human Rights can be “Suitably Amended” to accommodate Human Rights in Cyberspace. Almost all the Countries of the World are Member of UN and this would extend Human Rights Protection in Cyberspace to their Citizens automatically. The call is for UN to take and the sooner it is taken by it the better it would for Citizens’ World wide.

Take the example of India. The Cyber Law of India is violating various Human Rights in Cyberspace. This is the main reason why we started the exclusive Cyberspace Human Rights Protection Centre of India. So much offensive is the Cyber Law of India that it deserves to be repealed.

Further, Indian Government launched Projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

If there is no “Internationally Acceptable Standard” for Protection of Human Rights in Cyberspace, Countries like India would keep on enacting and applying the Draconian Laws like Information Technology Act, 2000, Indian Telegraph Act, 1885, Official Secrets Act, etc.

Finally, UN has shown some inclination in this regard. UN now considers Internet access a Human Right and considers disconnecting people from the Internet as a violation of Human Rights and International Law. A Report by the UN Human Rights Council’s 17th Session underscored the “unique and transformative" nature of the Internet allowing individuals to exercise a range of Human Rights, and to promote the progress of society as a whole.

I welcome this initiative of UN as this is a good step in the right direction. However, UN must not stop here and must move towards enacting a “Comprehensive Framework” for Protection of Human Rights in Cyberspace.

Saturday, June 4, 2011

Data Protection Law In India Is Needed

Every individual loves his or her personal space and in order to enjoy the same he/she must exercise his/her privacy and data protection rights effectively. But what would happen if there are no privacy laws and data protection laws at all to protect such rights? This not only is scary but is also difficult to accept. But in India we have neither dedicated privacy laws nor dedicated data protection laws.

This makes the sensitive information and personal details of Indian citizens “highly vulnerable” to misuse. The Indian government has been promising enactment of privacy laws and data protection laws for long but till now we have none.

This indifference of Indian government towards privacy laws, data security laws and data protection laws is also becoming a headache for government itself. Controversial issues like illegal phone tapping, imposition of Aadhar project, launch of projects like national intelligence grid (Natgrid) and crime and criminal tracking network and systems (CCTNS) without any procedural safeguards, etc requires not only enactment of a dedicated and constitutionally sound privacy law but also putting in place sufficient data protection mechanisms.

India’s intention to use cloud computing and m-governance has further complicated the issue. With the proposed use of cloud computing, software as a service (SaaS) and m-governance by Indian government, more “privacy violations”, “cyber security” and many more “regulatory issues” would arise in future believes techno legal experts of India. These “initiatives” cannot succeed in India in the absence of adequate and strong laws in this regard.

With the proposed draft electronic services delivery bill 2011 (EDS Bill 2011) things would even become more complicated. When most of the public services would be delivered through mandatory e-governance model, a very strong data protection regime and privacy protection regulatory framework would be required.

Now government of India has once more declared that it is going to enact a privacy law for India. However, this seems to be another declaration alone as there is no sign of any Bill in this regard that can be analysed by public at large. In the absence of privacy Bill this statement of India government has no significance.

Further, even if, by some miracle, privacy law is introduced it is doubtful whether it would cater the privacy issues of information age. Only time would tell how much serious is Indian government regarding privacy rights of Indians.

Friday, June 3, 2011

Privacy Rights In India In The Information Age

We have no Dedicated Privacy Laws in India and Data Protection Laws in India. In fact, when it comes to respecting Privacy of Indian Citizens, Government of India tries its level best to avoid the same.

For instance, India has launched Projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

Further, India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more.

Phone Tapping in India has been in controversies for long. Whether it is Illegal Phone Tapping by Private Individuals or Unaccountable Phone Tapping by Indian Government and its Agencies, Phone Tapping in India has never been smooth.

There is a blessing in disguise in Ratan Tata’s Petition before Supreme Court of India. This is a golden chance for the Supreme Court of India to analyse the “Implementation” of its decision in the PUCL case (Phone Tapping Case). The Supreme Court must “Widen” the scope of Privacy Rights in India not only in the context of Phone Tapping but in an “Overall Manner”. The Supreme Court must formulate and lay down the widest possible “Guidelines” regarding Privacy Protection in India as it has done in the Vishaka’s Case (Guidelines against Sexual Harassment). The Supreme Court has even said that with the Technological Advancement, Privacy is virtually disappearing.

On the front of Legal Framework as well we have no Dedicated and Constitutionally Sound Lawful Interception Law in India. The Indian Telegraph Act, 1885 and other similar Laws are not in “Conformity” with the Constitution of India, especially Fundamental Rights of Indians. Even the Home Ministry of India is considering enactment of a Lawful Interception Law in India.

However, what is more surprising is the fact that the Law Enforcement Agencies and the Intelligence Agencies that indulge in Unconstitutional E-Surveillance and Phone Tapping are themselves Governed by No Law. It is no surprise that the Central Bureau of India (CBI) is also not governed by any Law and it is operating in India Without any Law. It is only now that the Central Bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the Constitutional Validity of the National Investigation Agency Act 2008 is doubtful. Even the Draft Intelligence Services (Powers and Regulations) Bill, 2011 has been recently circulated in the Parliament of India. India must urgently formulate E-Surveillance Policy so that the E-Surveillance conducted by Intelligence Agencies and Law Enforcement Agencies of India can be regulated.

Surprisingly, India has no E-Surveillance Policy and Legal Framework. This is despite the fact that many Indian Projects are so S-surveillance Oriented that they cannot pass the scrutiny provisions of Indian Constitution. Of all these E-Surveillance Projects Aadhar Project of India or Unique Identification Project of India (UID Project of India) is the most “Dangerous Project” that should not be there at the very first place. It is based upon Deceit and Deception and both Indian Government and Unique Identification Authority of India (UIDAI) are Hiding Truth from Indians. There is no Legal Framework, no defined Policies and Guidelines and most importantly no Procedural and Civil Liberty Safeguards.

If this was not enough the sole Cyber Law of India (Information Technology Act 2000) was amended through the Information Technology Amendment Act 2008. The IT Act 2008 made the Cyber Law of India an “Unregulated and Unaccountable” piece of E-Surveillance Legislation. It is now wide open to misuses by Indian Government and its Agencies. Further, the IT Act 2008 also violated various provisions of Indian Constitution and hence is “Unconstitutional” as well. Ideally Cyber law Of India must be repealed as soon as possible.

If Parliament of India has abdicated its duties and Indian Judiciary is watching as a moot spectator, it becomes of paramount importance for Cabinet Committee on Security (CCS), Union Cabinet and Prime Minister’s Office (PMO) to “Disallow” all such Projects till proper Civil Liberty Safeguards and Legal Frameworks are at place.

Monday, May 30, 2011

Call Data Records Storage Policy Of India

India is not very good at law making. This is more so regarding technology related laws. For instance, consider the cyber law of India incorporated in the information technology act 2000 (IT Act 2000). IT Act 2000 is a classical example of bad drafting that has created more problems than solutions. This is the reason why experts have been suggesting that it should be repealed.

Similarly, we have no lawful interception law in India. Even phone tapping in India is not done in a constitutional manner and illegal phone tapping in India is under scrutiny. There is no e-surveillance policy in India. India does not bother to maintain a balance between national security and fundamental rights of Indians.

India has launched projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

In this background, the news that Intelligence Bureau (IB) wants all mobile phone companies to store call data records, or details of all phone calls made by their customers, for a period of five years is really surprising. Indian law enforcement agencies and intelligence agencies are practically governed by no law. In fact, intelligence infrastructure of India is in big mess and India is not at all ready for projects like CCTNS, Natgrid, NCTC, etc.

It is no surprise that the central bureau of India (CBI) is also not governed by any law and it is operating in India without any law. It is only now that the central bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the constitutional validity of the national investigation agency act 2008 is doubtful. The recent circulation of the draft Intelligence Services (Powers and Regulations) Bill, 2011 (Draft Intelligence Bill 2011) in the Lok Sabha shows how our Parliament of India took the matter very casually.

We must start formulating the call data storage policy of India as soon as possible. The one suggested by IB is neither feasible nor desirable. Issues like increased costs to operators, privacy safeguards, legal framework requirements, etc cannot be ignored the way they have been ignored so far. Presently, an inter-ministerial group is looking into monitoring of both internet services and networks in the country. This matter may also be refereed to the same. However, in all probability, this demand would be refused.

Sunday, May 22, 2011

Glendora Police Department Is Using Innovative Methods

Law enforcement agencies around the world are increasingly using information technology for efficient law enforcement delivery. In India as well projects like crime and criminal tracking network and systems (CCTNS) has been proposed by Home Ministry of India. Even projects like national intelligence grid (Natgrid) have been suggested by Home Ministry.

Further, a proposal to establish a system where first information reports can be filed online has also been proposed. However, till now all of these are just proposals and not even a single project has been implemented in India.

Law enforcement agencies of India are still afraid of information technology related issues like cyber law and use of computers and other technological instruments. Of course, they are catching up with the new technology but the pace is very slow.

The Glendora Police Department has launched a new feature on the Glendora Police Department's website. Now anyone who has access to a computer can see the calls that come into the police department in almost real time.

A department official said keeping the public informed about police activities serves two purposes. On one hand, he hopes it will reduce the work load for his employees. If people can see why a police helicopter is circling overhead with a few mouse clicks, they'll be less likely to flood police dispatchers with calls asking `why,' so the thinking goes.

On the other hand, it satisfies people's growing appetite for non-stop information. To that end, the department has also created its own online crime-mapping system. The official said there are also some big changes in store for the website, including an online log that shows whom the department has arrested.

And the Glendora Police Department isn't the only agency responding to that need. The Los Angeles County Sheriff's Department has taken a huge leap into the Information Age in the past year and a half.

I hope Indian law enforcement agencies may also take a leaf out of these activities from their foreign counterparts. Although electronic delivery of services in India has been proposed yet it is far from being actual implementation. Let us see how our law enforcement agencies would perform in future.

Thursday, May 19, 2011

Natgrid Project Of India Is Still In Troubled Waters

National intelligence grid (Natgrid) project of India is in trouble from the very beginning. With absolute secrecy and no regard for the civil liberties of Indians, this was definitely a controversial project. Home Minister of India P Chidambaram also did not bother to do the needful. Instead he tried his level best to get Natgrid project of India cleared from the Cabinet Committee on Security (CCS) of India.

However, it seems CCS does not agree with the idea and implementation mechanism of Natgrid project. Lack of privacy safeguards has stalled Natgrid project for the time being and Home Ministry is trying hard to get it functional. Even the term of Raghu Raman, project coordinator of Natgrid, is expiring no 31st May, 2011. Till now there are no positive developments and signs that CCS would approve Natgrid project of Home Ministry. CCS may consider the feasibility of Natgrid project next month.

Meanwhile, a 900 page Detailed Project Report (DPR) has been sent to the CCS members to study the feasibility, implications and requirements of Natgrid project. The DPR claims that Natgrid project would be finally and fully put in place in four phases extending between 24 to 36 months. Extension of the term of Raghu Raman may also be considered.

Many experts in India have been questioning the way Natgrid project has been ignoring civil liberties in India. Further, experts have also been demanding that a balance must be maintained between civil liberties and national security requirements. Although the Natgrid project has been granted in principle clearance yet it failed to satisfy the CCS regarding the civil liberty protection requirements.

Another factor that is going against the Natgrid project is that intelligence agencies and law enforcement agencies of India are practically governed by no law. There is no Parliamentary oversight over these agencies. Even Natgrid project is also not supported b by any legal framework. To make the matter worst we have no privacy, data security and data protection laws in India. Even the cyber law of India has conferred unregulated and unreasonable e-surveillance, Internet censorship and website blocking powers in the hands of Indian government and its agencies.

These are very serious constitutional issues that cannot be taken lightly by Home Ministry, Prime Minister’s Office (PMO) and CCS. The CCS must consider the inputs and suggestions of various techno legal experts of India before clearing Natgrid project.

Wednesday, May 18, 2011

India-US Homeland Security Dialogue

India and United States (US) have in the past worked in the direction of homeland security. In fact a cyber security forum was started between India and US that faced some troubles and it became obsolete. Now talks are in progress to revive Indo US homeland security dialogue once more.

A special emphasis has been laid upon counter-terrorism co-operation, intelligence sharing, technology transfers and capacity building. Homeland security in India is at the infancy stage. Issues like cyber law, cyber security, cyber espionage, cyber terrorism, cyber warfare, etc are still not considered while formulation national policies of India.

At Perry4Law Techno Legal Base (PTLB) we are managing the exclusive techno legal cyber security research and training centre of India (CSRTCI). The centre is covering areas like cyber law, cyber security, cyber forensics, critical ICT infrastructure protection, cyber warfare, cyber terrorism, cyber espionage, national counter terrorism centre (NCTC), national intelligence grid (Natgrid) of India, crime and criminal tracking networks and systems (CCTNS), etc.

CSRTCI is supported by Cyberspace Human Rights Protection Centre of India that is working in the direction of reconciling the conflicting interests of national security and civil liberties protection.

The proposed Indo US homeland security dialogue must address many crucial issues ranging from cyber law to cyber security. Issues like encryption, technology transfer, international cooperation to fight cyber crimes and terrorism, etc must also be a part of national policies of both US and India.

PTLB believes that besides addressing these issues the proposed India US dialogue must also concentrate upon mutual trainings and skills development issues in the abovementioned fields. India particularly needs skill development trainings for intelligence gathering and their analysis. In all probability, this would be a fruitful and productive dialogue between India and US.

Lack Of Privacy Laws Stalled Natgrid Project

National intelligence grid (Natgrid) has been in news from time to time. Although the intentions behind the Natgrid project are good yet it planning and management is really bad. We have been stressing that Natgrid is an essential project for robust and effective intelligence agencies and law enforcement functions in India. The only requirement is to ensure that Natgrid’s abuses can be anticipated, prevented and remedied.

There are many challenges that Natgrid must successfully meet in order to be finally established. For some strange reasons, the Home Ministry of India failed to consider these challenges. Further, experts have been suggesting that Natgrid project of India must comply with civil liberties in order to be valid and constitutional. Even this aspect has been ignored by Home Ministry. Even Home Ministry has been cautioned that Natgrid project of India may fail if it is not managed properly.

By not acting in a proper manner, Home Ministry of India has created a trouble for itself. Now the Natgrid project has been struck at the last stage of securing final approval by Prime Minister Manmohan Singh, who is, apparently, in a dilemma whether it would be wise to give overarching power to the agencies to infringe upon individual privacy, allowing tracking of all their activities. Raghu Raman is managing the Natgrid project and his term is expiring this month after he sat idle for 18 months.

Natgrid project, if approved, would ask the telecom and internet service providers to compulsorily link up their databases with it. Even the rail and air travel, phone calls, bank accounts, credit card transactions, passport and visa records, PAN cards, land and property records, automobile ownership and driving licences and many more such data would be linked.

What Home Ministry failed to understand is that civil liberties cannot be violated at will in a blatant manner as has been suggested by it. Civil liberties are violated world over through use of technology and Natgrid project seems to be no exception to the same. Now a section of government suspects such a move as a dangerous precursor to an autocratic state having overarching power of keeping an eye on its citizens all the time and eroding their privacy.

They claim that with the National Counter Terrorism Centre (NCTC) would give unbridled powers to the Home Minister which can prove detrimental to freedom and privacy of common man. This has even put in jeopardy the very Natgrid project itself.

In the ultimate analysis the fault lies with the approach of Home Ministry. Natgrid project cannot be taken as casually and in an unplanned manner as has been done by Home Ministry. If at all the Home Ministry wishes this project to see the light of the day. It must immediately start working in a planned and systematic manner.

Tuesday, May 17, 2011

Indian Centre For Communication Security Research and Monitoring (CCSRM)

An Indian centre for communication security research and monitoring (CCSRM) was proposed by the Union Cabinet in the past. The Department of Telecommunication (DOT) was asked to do the needful in this regard. The DOT came up with the proposal of establishment of Central Monitoring System (CMS) that can help security agencies and law enforcement agencies in intercepting mobile phone calls and monitor internet traffic.

None can doubt about the utility of a CMS or CCSRM. However, there are many technical, administrative and legal issues that have to be addressed before implementing either CMS or CCSRM.

On the technical side, intelligence agencies and law enforcement agencies of India need to develop skills for intelligence gathering and their analysis. If we keep in mind the latest development, it can be assumed that services of Blackberry, Gmail, Skype, etc would not be banned in India for some more time. Naturally, their highly encrypted services would continue in India that intelligence agencies and law enforcement agencies of India cannot monitor unless they are skilled enough to do so.

On the legal side, in India intelligence agencies and law enforcement agencies are practically governed by no law. Even the constitutional validity of national investigation agency act, 2008 is still doubtful. Further, India does not have a constitutionally sound lawful interception law. Phone tapping in India is still done in an unconstitutional manner and at times by private individuals as well.

On the administrative side, the intelligence infrastructure of India is in big mess. There seems to be a tussle between various Ministries of Indian government and this is preventing the successful implementation of various projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), national counter terrorism centre (NCTC), central monitoring system (CMS), etc.

However, nothing is more offensive than an absence of Parliamentary oversight of intelligence agencies, law enforcement agencies and projects like Natgrid, CCTNS, NCTC, CMS, etc.

Fortunately, our Prime Minister Dr. Manmohan Singh is taking interest in these projects and he has recently has sought clarifications on the upcoming CCSRM system. I hope the Cabinet Committee on Security (CCS), Union Cabinet and Prime Minister’s Office (PMO) would bring some order in the otherwise chaosed world of intelligence agencies and law enforcement agencies of India.

Is Cloud Computing A Viable Solution In India?

India is a country that is weak privacy, data protection and data security laws. India is also infamous for its e-surveillance and eavesdropping exercises without any constitutional laws backing the same. Phone tapping in India is not done in a strictly constitutional manner and we also lack a lawful interception law in India.

With the information technology amendment act, 2008 (IT Act 2008), the cyber law of India has been amended and this has also made it vulnerable to constitutionality attacks. With projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), central monitoring system (CMS), etc e-surveillance in India has reached its zenith.

In this background we have to analyse the use of cloud computing in India. Cloud computing in India cannot succeed till we have trust in the service provider. We cannot trust a service provider who can be forced to disclose even the most sensitive information and data without a court order.

In India a mere order from the Indian government or its agencies is enough for the service provider to share sensitive information. There is no judicial scrutiny of a warrant that is absolutely required in these circumstances. So you cannot be even sure what government agencies are looking at and what information they are taking from the service provider.

Any business model must essentially balance profit motives and risks associated with the business. Similarly, the users of cloud computing services must ensure that the convenience of software as a service (SASS) and cloud computing is much greater than the risks of data leakages and manipulations.

Till now the legal opinion is weighting against the use of cloud computing and SAAS in governmental departments and for governmental projects. Without a conducive legal framework, user’s data in India is not safe. Let us create a conducive commercial and legal environment before we jump upon cloud computing wagon.