Showing posts with label Perry4Law. Show all posts
Showing posts with label Perry4Law. Show all posts

Saturday, November 24, 2012

Cyber Security Capabilities Of India Must Be Strengthened

 
This Article was originally published on 9th February 2012. However, due to DELIBERATE NEGATIVE TACTICS ADOPTED BY GOOGLE, this article was removed by Google despite clear indications that we are the copyright holders and source of original contribution.

Google is engaging in unethical and illegal behavior simply to favour few and working in derogation of others. For complete list of Google’s censorship and negative tactics, kindly visit Websites, Blogs And News Censorship By Google And India.  

Maintaining cyber security at the international level is a tedious task. This is so because cyberspace does not recognises any boundary and cyber attacks can be launched from any part of the world. While cyber attacks upon various computer systems and computer resources are cause of concern yet cyber attacks upon critical infrastructures is of grave concern.

Cyber security in India is at initial stage. Even the information technology act, 2000 (IT Act 2000), which is the sole cyber law of India, does not address the cyber crimes and cyber security issues effectively. We have no dedicated cyber security laws in India and we urgently need a dedicated cyber security legal framework in India.

Meanwhile, India is increasingly facing cyber attacks and cyber threats from foreign nationals. In fact, the cyber laws and cyber security trends of India 2011 by Perry4Law and Perry4Law Techno Legal Base (PTLB) has clearly showed the cyber security vulnerabilities of India. Cyber terrorism against India, cyber warfare against India, cyber espionage against India and cyber attacks against India have already increased a lot. Even the cyber law trends of India 2012 by PTLB have also projected an increased rate of cyber crimes in India and cyber attacks against India in the year 2012.

The biggest cyber threat against India is originating in the form of cyber attacks upon Indian critical infrastructures. Critical infrastructure protection in India requires a well formulated policy. Presently we have no critical infrastructure protection policy of India. Further, critical ICT infrastructure protection in India is one area that requires special attention of Indian government.

Fortunately, Indian government has decided to streamline cyber security of India. The Indian government is in the process of finalising an elaborate plan to strengthen India's cyber security capabilities. A national critical information infrastructure protection centre (NCIPC) of India has also been proposed by Indian government. It intends to ensure critical infrastructure protection and critical ICT infrastructure protection in India.

There are few prerequisites that can make the NCIPC of India successful. Firstly, there must be a centralised ICT command centre of India that can coordinate various cyber security issues. Secondly, specialised agencies and authorities must be constituted for critical infrastructure areas like power, telecom, defense, aviation, etc. These agencies and authorities must coordinate with the centralised command centre for cyber security related issues.

Ministry of communication and information technology (MCIT) has already taken certain initiatives in this regard. For instance, a central monitoring system (CMS) project of India has been launched by MCIT to monitor and intercept electronic communications, messages and information. Further, a national telecom network security coordination board (NTNSCB) of India has also been proposed to strengthen the national telecom security of India.

Now Indian government is planning to step up cyber security protection levels, putting in place real time command-and-control centers and delineating responsibilities among various agencies.

Among the proposals are establishment of dedicated command-and-control centers in India to monitor critical infrastructure in real time, constituting computer emergency response teams (CERTs) for key sectors such as power, aviations, etc and formulation of elaborate protocols for all stakeholders involved in the process of ensuring cyber security in India.

The Cabinet Committee on Security (CS) may approve in a few weeks the multi-layered security plans to protect India's critical infrastructure. The national security advisor (NSA) and the cabinet secretary are working on the final plan.

There would be a clear demarcation of responsibilities between Computer Emergency Response Team-India (CERT-In), National Technical Research Organisation (NTRO), Intelligence Bureau (IB), Military Intelligence (MI) and other agencies that have a role in fighting cyber intrusions. Protocols would be formulated to ensure that there is no overlap between the functions and obligations of various agencies fighting cyber attacks against India. The proposed protocol will also cover department of telecom, department of information technology, National Informatics Centre etc.

Under the proposal, the government will also regularly and proactively monitor and scan critical networks. Not just that, the levels of security for these networks will also be stepped up. CERT-In may also be creating its own real time monitoring centre to strengthen it cyber security initiatives. The responsibility for monitoring critical infrastructure will be divided between NCIPC and CERT-In. The government will also set up dedicated CERT for critical sectors such as power, aviation etc where no such national monitoring mechanism exists.

This is a good step in the right direction and Perry4law and PTLB welcome this move. We also hope that with this the cyber security capabilities of India would be upgraded to the required levels.

Thursday, April 26, 2012

Statement Of Administration Policy On Cyber Intelligence Sharing and Protection Act (CISPA)

This is the statement issued by the Obama Administration (PDF) regarding proposed Cyber Intelligence Sharing and Protection Act (CISPA). Perry4Law and Perry4Law Techno Legal Base (PTLB) wish to share the same with all the stakeholders.

The Administration is committed to increasing public-private sharing of information about cybersecurity threats as an essential part of comprehensive legislation to protect the Nation's vital information systems and critical infrastructure. The sharing of information must be conducted in a manner that preserves Americans' privacy, data confidentiality, and civil liberties and recognizes the civilian nature of cyberspace. Cybersecurity and privacy are not mutually exclusive. Moreover, information sharing, while an essential component of comprehensive legislation, is not alone enough to protect the Nation's core critical infrastructure from cyber threats. Accordingly, the Administration strongly opposes H.R. 3523, the Cyber Intelligence Sharing and Protection Act, in its current form.

H.R. 3523 fails to provide authorities to ensure that the Nation's core critical infrastructure is protected while repealing important provisions of electronic surveillance law without instituting corresponding privacy, confidentiality, and civil liberties safeguards. For example, the bill would allow broad sharing of information with governmental entities without establishing requirements for both industry and the Government to minimize and protect personally identifiable information. Moreover, such sharing should be accomplished in a way that permits appropriate sharing within the Government without undue restrictions imposed by private sector companies that share information.

The bill also lacks sufficient limitations on the sharing of personally identifiable information between private entities and does not contain adequate oversight or accountability measures necessary to ensure that the data is used only for appropriate purposes. Citizens have a right to know that corporations will be held legally accountable for failing to safeguard personal information adequately. The Government, rather than establishing a new antitrust exemption under this bill, should ensure that information is not shared for anti-competitive purposes.

In addition, H.R. 3523 would inappropriately shield companies from any suits where a company's actions are based on cyber threat information identified, obtained, or shared under this bill, regardless of whether that action otherwise violated Federal criminal law or results in damage or loss of life. This broad liability protection not only removes a strong incentive to improving cybersecurity, it also potentially undermines our Nation's economic, national security, and public safety interests.

H.R. 3523 effectively treats domestic cybersecurity as an intelligence activity and thus, significantly departs from longstanding efforts to treat the Internet and cyberspace as civilian spheres. The Administration believes that a civilian agency – the Department of Homeland Security – must have a central role in domestic cybersecurity, including for conducting and overseeing the exchange of cybersecurity information with the private sector and with sector-specific Federal agencies.

The American people expect their Government to enhance security without undermining their privacy and civil liberties. Without clear legal protections and independent oversight, information sharing legislation will undermine the public's trust in the Government as well as in the Internet by undermining fundamental privacy, confidentiality, civil liberties, and consumer protections. The Administration's draft legislation, submitted last May, provided for information sharing with clear privacy protections and strong oversight by the independent Privacy and Civil Liberties Oversight Board.

The Administration's proposal also provided authority for the Federal Government to ensure that the Nation's critical infrastructure operators are taking the steps necessary to protect the American people. The Congress must also include authorities to ensure our Nation's most vital critical infrastructure assets are properly protected by meeting minimum cybersecurity performance standards. Industry would develop these standards collaboratively with the Department of Homeland Security. Voluntary measures alone are insufficient responses to the growing danger of cyber threats.

Legislation should address core critical infrastructure vulnerabilities without sacrificing the fundamental values of privacy and civil liberties for our citizens, especially at a time our Nation is facing challenges to our economic well-being and national security. The Administration looks forward to continuing to engage with the Congress in a bipartisan, bicameral fashion to enact cybersecurity legislation to address these critical issues. However, for the reasons stated herein, if H.R. 3523 were presented to the President, his senior advisors would recommend that he veto the bill

Sunday, April 22, 2012

Conflict Of Laws, Indian Cyberspace And Google

Cyberspace and Internet has made it possible to access single information from multiple jurisdictions. It is also possible that for a single transaction, multiple countries may exercise jurisdiction. In other words, the conflict of law in cyberspace is most complicated in nature and very difficult to resolve.

The validity of electronic legal notices in India and DMCA notice from India to other jurisdictions through e-mails is now well established. This makes it very easier to engage in legal proceedings from India to multiple jurisdictions. Similarly, Indian citizens and companies may also be involved at multiple jurisdictions in various civil and criminal proceedings.

As on date there is no globally acceptable international cyber law treaty.  In its own interest, India must stress upon an international cyber law treaty.  Till then India is free to apply its own laws even though it may result in conflict of laws.

Further, the position of US companies, India, conflict of laws and criminal liabilities has also become clear these days. Even in the case of cyber laws, US companies and courts are applying US standards and are not following Indian standards. This is a classic situation that is occurring due to conflict of laws. This is also the reason why an international cyber law treaty is required to bring harmonious application of cyber law principles.

Google is one company that can found itself deeply involved world over. Google incorporation’s Indian strategy to counter legal disputes must be formulated to avoid any inconvenience in India. Whether it is copyright violation, trademark violation, cyber law infringements or any similar legal issue, Google has been facing many regulatory and legal hurdles in India and US.

Perry4Law and Perry4Law Techno Legal Base (PTLB) believe that Google has been doing its level best to resolve disputes of various parties though many times disputes are not resolved as per desired expectations. However, Google needs to do something more to avoid future cyber litigations and disputes that are going to increase in India.

Tuesday, March 13, 2012

National Telecom Policy 2012 Of India

The national telecom policy of India 2012 is in pipeline. It is in continuation of its precursor i.e. the national telecom policy of India 2011. It has incorporated many far reaching reforms that if accepted can really streamline the telecom sector of India.

The Telecom Regulatory Authority of India (TRAI) has done a good job by combining the suggestions and recommendations of various stakeholders. In fact, the proposed national telecom policy 2012 of India is an improvement over the policy suggested in 2011.

Perry4Law and Perry4Law Techno Legal Base (PTLB) provided its techno legal public inputs in this regard and many of them have been endorsed by TRAI. TRAI has also accepted many suggestions of Perry4Law on telecom policy of India.

Some of the suggestions of Perry4Law and PTLB that have been accepted by TRAI pertain to issues like establishing servers in India, establishing cloud computing legal framework in India, establishment of telecom security in India, reconciling privacy rights and law enforcement requirements, reconciling privacy rights and national security requirements, adoption of lawful interception methods, telecom dispute resolution reforms in India, crisis management and emergency response services, delivery of e-services in a time bound manner, digitisation of governmental records, establishing cloud computing best practices in India, encryption and privacy issues of cloud computing, establishing a centralised monitoring system in India, etc.

However, these are very broad and important aspects that require suitable modification of the constitution and powers of TRAI so that TRAI can fulfill the commitments and policies that have been suggested in the 2012 policy.

Fortunately, the Telecom Commission has agreed to grant to TRAI the powers to penalise the defaulters. If finally approved by the appropriate authority, TRAI will be able to summon companies and individuals, call for evidence and even seek expert advice while conducting an enquiry, in order to ensure that telecom companies comply with rules, especially those concerning phone users in the country.

This is a much needed power that should be conferred upon TRAI so that it can perform its functions and duties more efficiently. Perry4Law and PTLB welcome this move and wishes TRAI all the best in this regard and hope that TRAI would emerge as a super regulator in the field it is managing.

Wednesday, February 29, 2012

Mobile Cyber Security In India

Mobile phones have become ubiquitous these days. They are used for multiple purposes ranging from personal use to mobile banking. Cyber criminals have also realised the importance of mobile phones for committing cyber crimes and financial frauds. This is also the reason why malware writers are also writing mobile phone specific malware to steal confidential and sensitive information.

Mobile cyber security in India has become a cause of concern these days. Mobile phones are now proposed to be used for mobile banking and mobile governance in India. Naturally, we must ensure robust mobile cyber security in India. An electronic authentication policy of India can help in more active and secure mobile usages in India. Mobile governance and e-authentication in India are also closely related and with the proposed electronic delivery of services in India this is also a must have requirement.

For the time being we have no implementable electronic delivery of services policy of India though it may be in pipeline. Indian government is working in the direction of ensuring electronic delivery of services in India. In fact a legal framework titled electronic delivery of services bill 2011 (EDS Bill 2011) has also been proposed by Indian government.

Once the EDS Bill 2011 becomes an applicable law, governments across the India would provide electronic services through various modes, including mobile phones. This requires putting a robust and reliable mobile security infrastructure in India.

However, using of mobile phones for commercial and personal transactions in India is also risky. For instance, the mobile banking in India is risky as the present banking and other technology related legal frameworks are not conducive for mobile banking in India. Similarly, we do not have a well developed e-governance infrastructure in India. As a result India is still not ready for m-governance.

We at Perry4Law and Perry4Law Techno Legal Base (PTLB) believe that the biggest hurdles before the mobile related uses in India pertain to use of weak encryption standards and non use of mobile cyber security mechanisms in India. Absence of encryption laws in India has further made the mobile security very weak in India.

The ever evolving mobile malware are further increasing the woes of mobile users’ world wide. Recently 50 applications within Google’s official Android Market were found to be contaminated with DroidDream malware. The malware stole sensitive information like phone’s International Mobile Equipment Identity (IMEI) Number and the SIM card’s International Mobile Subscriber Identity (IMSI) number. It then sent it to a command-and-control server. Similarly, other spyware and bugs are also infecting mobile phones worldwide.

It is high time for India to seriously work upon mobile cyber security aspects as soon as possible. The policy decisions in this regard must be taken urgently and must be implemented as soon as possible.

Friday, February 3, 2012

Google, Facebook, Microsoft, Etc Must Appoint Nodal Officers In India

The Information Technology (Intermediaries Guidelines) Rules, 2011 of India prescribe stringent provisions regarding Internet intermediary liability in India. However, till now foreign companies and websites have not followed the Guidelines and Rules issued by Indian government in this regard. In fact, they are avoiding compliance with Indian laws.

Legal liability of foreign websites in India is now well established after the matter has been brought to the attention of Indian judiciary. A criminal complaint has been filed against companies like Google, Facebook, Microsoft, Yahoo, etc before a Trail Court for non observation of cyber due diligence by them. Even the Delhi High Court has not quashed the criminal complaint against these companies so far and in the absence of the same the representatives of these foreign companies would now personally appear before the Trail Court on 13th March 2012.

Another related problem that has to be addressed is that foreign companies and websites have not established a procedure that can deal with complaints and notifications arising out of the Information Technology act, 2000 (IT Act 2000) and Rules made there under. This is so even though companies like Google, Microsoft, Yahoo, etc have subsidiary companies and offices in India.

When these foreign companies and websites and their subsidiaries are deriving financial gains out of Indian operations, non following of Indian laws seems to be a grave disregard to Indian laws and regulations. These foreign companies and websites must follow Indian laws and this is the right time to do so.

We at Perry4Law and Perry4Law Techno Legal Base (PTLB) suggest that the best method to do so is to appoint a nodal officer who is responsible for managing cyber law due diligence issues arising out of Indian transactions. By not doing so, companies like Google, Facebook, Microsoft, etc are heading towards a big trouble. The sooner these nodal officers are appointed the better it would be for the larger interest of Internet intermediaries in India.

Sunday, September 4, 2011

Social Media Laws In India

Social media includes social networking sites, blogs, forums, wikis, etc. Social media is growingly seen as a medium to connect with millions of professionals, friends and like minded individuals and organisations.

India is also witnessing a growing revolution of information and communication technology (ICT) and social media usage. However, till now we have no social media policy in India. Even we do not have dedicated social networking laws in India that can take care of the misuses of social platforms.

However, the framework and guidelines for use of social media for government organisations has been recently suggested by department of information technology. Theses guidelines provide an Indian social media framework for governmental departments and organisations that employees of these organisations must follow.

Perry4Law and Perry4Law Techno Legal Base (PTLB) strongly recommend that Indian government must enact strong and effective social media laws, e-governance laws and e-commerce laws in India. These three fields are going to assume centre stage in the near future and their regulation by Indian government would be required.

Till now India has enacted a single technology law in the form of information technology act 2000 (IT Act 2000). It has tried to cover all the three issues but not with great success. This is so because these three fields are very vast and require a different treatment and separate law. Perry4Law and PTLB strongly recommend enacting suitable laws in this regard.

E-Commerce Laws In India

Electronic commerce in India (E-commerce in India) has slowly and steadily entered the Indian market. Toady from tickets booking to purchasing of good and services, everything happens in an online environment.

Of course, where commercial transactions occur, disputes and differences are bound to occur. To prevent and resolve these disputes we need norms, regulations and laws that are acceptable to all the stakeholders.

The e-commerce law of India is primarily incorporated in the information technology act, 2000 (IT Act 2000) that takes cares of legal obligations of both sellers and buyers of good and services in cyberspace.

The IT Act 2000 prescribes rules and norms for online contract formulation. The traditional concepts of offer, acceptance etc, as applicable under the contractual laws, have also been covered by the IT Act 2000. The only difference is that they have been customised as per the requirements of cyberspace.

However, e-commerce transactions and contracts also attract certain additional legal liabilities that e-commerce players in India are not very much aware. For instance, very few e-commerce players in India are aware that they are “intermediaries” within the meaning of IT Act 2000.

Further, other laws, including intellectual property laws, make these e-commerce players labile for civil and criminal actions. For instance, these e-commerce players can be held liable for online infringement of copyright in India of the copyright owners.

Similarly, if any person posts an offending material at the e-commerce site or otherwise deal with the e-commerce site in an illegal manner, the e-commerce site owner may find himself in trouble.

Cyber law due diligence in India is one aspect that all e-commerce site owners must frequently engage in. The present laws of India are stringent in nature and subsequently claiming ignorance of such laws would not make much difference.

Perry4Law and Perry4Law Techno Legal Base (PTLB) strongly recommend that before opening an e-commerce site or business, the owner of the same must consult a good techno legal law firm that can advice him upon all the possible and applicable aspect of e-commerce laws in India.

Saturday, September 3, 2011

Social Networking Laws In India

Social networking in India has increased tremendously. This has also given rise to many legal issues as well. Most of these legal issues are related to online acts or omissions that are resulting in giving rise to civil and criminal liabilities.

Laws ranging from intellectual property rights (IPRs) to information technology laws are applicable to social networking acts or omissions in India. The growing demands for cyber due diligence in India has further necessitated for adopting of a sound social networking policy in India by various stakeholders.

Social networking media is an “intermediary” within the meaning of Indian information technology act 2000 (IT Act 2000). Thus social networking sites in India are liable for various acts or omissions that are punishable under the laws of India. For instance, social networking sites are liable for online IPRs violations, including online copyright violations in India.

Although we have no law on the lines of online copyright infringement liability limitation Act (OCILLA) of United States yet the “safe harbour” provisions protecting intermediaries are not available under certain conditions as per Indian laws. Social networking sites must be aware of these limitations while operating in India.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been spreading public awareness about social networking issues in general and cyber laws in particular. We hope that social networking sites would be cautious while operating in India.

Social Media Policy Of India

Social media is playing an important role these days. Educated citizens are freely and openly airing their views on social media platforms. Many times such views are critical in nature that point to the shortcomings of governmental polices and functioning.

Obviously, governments cannot afford to take such criticisms casually. This is the reason why many countries have social media policy at place. India has no social media policy for governmental departments and its employees. Still many governmental employees are using various social platforms to express their views.

For the first time, a social media framework and guidelines for Indian government organisations has been suggested. However, keeping in mind the past record of Indian government, this may be another proposal that would not be fulfilled.

However, Indian government cannot take the social media policy casually. Information and communication technology has changed the way we communicate and share information. Social media is disruptive and potentially revolutionary in nature because it can connect large numbers of people with relative ease. Thus, it becomes important for the governments to have a separate social media wing that can communicate with its citizens in a timely and friendly manner.

The aim of any future social media policy of India must be to put citizens firmly at the centre of government service delivery and information distribution. Social media technologies can support this aim because they are intrinsically about dialogue and engagement within and between individuals and communities.

Perry4Law and Perry4Law Techno Legal Base (PTLB) have already started initiatives that can rejuvenate citizen to government (C2G) participation in India. In fact, Perry4Law and PTLB have already started the exclusive C2G LPO and KPO services in India.

We hope that sooner we would have an Indian social media policy that can cater the requirements of Indian citizens in the best possible manner.

Friday, September 2, 2011

CCTNS Project Of India To Be Launched Shortly

Crime and Criminal Tracking Network and Systems (CCTNS) Project Of India (CCTNS Project of India) is a serious effort on the part of Home Ministry of India to modernise the law enforcement functions in India. Although the modernisation efforts are in the pipeline yet they have not still matured fully.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we believe that cyber police reforms in India are urgently required. However, there is a void that has to be filled by Home Ministry before India can have a capable techno legal police force. PTLB has been managing a techno legal ICT training centre for police force that intends to fill this void and make our police force techno legal in nature.

A trained cyber police force of India is also required to effectively manage ambitious projects like CCTNS project of India. Further, if we talk about the national intelligence grid (Natgrid) project of India as well, we would also require intelligence gathering skills development in India.

The Union Home Ministry will launch its ambitious CCTNS project, as a pilot project, from September 1 in Assam, Kerala and Uttar Pradesh. This is only a trial run where they will use the software in the States to connect all the police stations and enable the police to track criminals in real time.

The National Crime Records Bureau (NCRB), the nodal agency for the CCTNS, will launch pilot phase in the three States. As the NCRB does not have requisite capability, other experts would help it in achieving this task. Other checks on safety and quality will also be carried out during the pilot phase.

Once implemented, the CCTNS will facilitate collection, storage, retrieval, analysis, transfer and sharing of data and information between police stations, their state headquarters, central police organisations and other security agencies. Information on any case, right from an offence being registered to its investigation and prosecution will be available on a secure network at the click of a button.

Further, this capability of CCTNS project would also be added to the Natgrid Project thereby making information held by 21 databases available to security agencies. This includes immigration records, airlines, mobile, bank and credit card transactions and travel details creating a maze of rich data that would enable 11 intelligence and investigation agencies to launch hot pursuit of a criminal.

The CCTNS also offers benefits for ordinary citizens. It is expected to simplify the process of registering and tracking petitions and First Information Report (FIR), giving access to general services such as requests for certificates, verifications and permission, registering grievances against police, tracking the progress of a case during trail and access to reports for stolen or recovered vehicles and property through a citizen interface.

Thursday, September 1, 2011

Why E-Courts In India Failed?

Electronic courts in India (e-courts in India) have been discussed in India for long but till now we are still waiting for the establishment of first e-court in India. From time to time it has been reported that e-courts have been established in India but none of these claims are true.

There is no doubt about the proposition that e-courts infrastructure in India needs urgent rejuvenation. The so called e-courts project of India has failed to materialise and Indian government must seriously think in this regard.

To start with, we must stress upon e-courts skills development in India. At Perry4Law and Perry4Law Techno Legal Base (PTLB) we believe that without adequate techno legal e-courts skills, the e-courts project of India would never materialise.

Realising this crucial shortcoming, Perry4Law and PTLB have even established the exclusive techno legal e-courts research, education and training institution of India and the world. The e-courts centre of PTLB provides many techno legal e-courts related services that can help in the successful implementation of e-courts project of India and other jurisdictions.

Indian laws and judiciary can become more user friendly through use of e-courts. Speedier justice through e-courts way is the future of Indian judicial system that has been ignored for long. Time has come to give e-courts a serious consideration, preferably on a public private partnership model.

Friday, August 26, 2011

Cyber Police Reforms In India Are Needed

Police reforms in India are long overdue. Whether it is on the front of legal framework, prison conditions, police accountability and transparency or any other similar aspect, police reforms in India have been stagnant.

Some of these reforms pertain to infrastructure while others pertain to policy formulation and still others regarding brand and image making of police in India. While these reforms can be managed through political will yet one reform area that cannot be achieved through mere political will pertains to training of police force in technology related issues.

For instance, we do not have enough cyber crime investigation capabilities in India till now. Cyber crime investigation in India is still far from satisfactory and there are selective police officials who are aware of technological issues and technological laws like information technology act 2000 (IT Act 2000).

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been working in the direction of removing these obstacles for the law enforcement officials of India. PTLB has been managing a techno legal ICT training centre for police force that intends to fill this void and make our police force techno legal in nature.

Perry4Law and PTLB suggest that police force of India must be well versed in areas like cyber law, cyber security attacks, cyber forensics, digital evidencing and e-discovery, video conferencing evidence, e-courts, etc.

Presently, these issues are not considered by police force of India. To start with police force must be made aware of the cyber law of India and its applicable provisions. Further, police in India also needs to learn how to investigate a cyber crime. Simple issues of cyber forensics like internet protocol address tracking and data recovery must also be learned by police force of India.

Indian government in general and ministry of home affairs in particular must pay special attention to these issues as ambitious projects like national intelligence grid (Natgrid), crime and criminal tracking network and systems (CCTNS), etc cannot be run successfully through an untrained police and intelligence force.

Cyber skill and intelligence gathering skills need to be developed in India as soon as possible. Perry4Law and PTLB hope that our suggestions would be considered by Indian government for the larger interest of all concerned.

Friday, August 19, 2011

Privacy Laws, Lawyers And Law Firms In India

Cyber security laws, lawyers and law firms in India and abroad are scanty to find. This is because fields like cyber security need expertise that legal fraternity is currently not possessing. However, if we see the global cyber security legal practice trend, legal community has started exploring techno legal fields.

Just like cyber law and cyber security legal practices, privacy protection, data protection and data security lawyers and law firms are also limited in nature. As far as India is concerned, we have no dedicated privacy, data protection and data security law. This is a serious limitation that is resulting in poor privacy, data protection and data security legal practice in India.

On the other hand the cyber law of India, incorporated in the information technology act 2000, imposes many cyber laws due diligence obligations upon various stakeholders like banks, companies, internet intermediaries, website owners, etc. This is a serious issue whose seriousness has not been properly appreciated by stakeholders in India.

With the recent formulation of rules under the IT Act 2000 regarding privacy and data protection, the due diligence requirements regarding privacy protection and data protection in India have become very stringent.

It is in the own interest of various stakeholders operating in India to adopt techno legal privacy and data protection strategies so that they may not be violating the cyber law and other laws of India.

Needless to mention such techno legal policies and strategies must be formulated by techno legal law firms alone as it is a delicate issue that requires balancing of both technical and legal issues involved.

The outsourcing industry must pay a special attention to the techno legal requirements of privacy, data protection and data security issues. Perry4Law and Perry4Law Techno Legal Base (PTLB) strongly recommend formulating and adopting best practices by stakeholders in this regard.

Wednesday, August 17, 2011

Draft National Competition Law Policy Of India

Competition Law of India is incorporated in the Competition Act 2002. It intends to regulate unfair business and commercial transactions and bring order in the otherwise disordered and manipulated business environment. The law also deals with anti-competitive agreements, unfair practices and abuse of dominant position.

In order to further strengthen the competition regime in India, the Ministry of Corporate Affairs has decided to formulate the draft National Competition Policy of India. This is a good step in the right direction and we at Perry4Law and Perry4Law Techno Legal Base (PTLB) support this initiative of Indian Government.

The Policy is aimed at laying down an overarching policy framework for infusing competition principles in various policies, statutes and regulations and promoting a competitive market structure in the economy, thereby striving to achieve maximum economy efficiency in various spheres, and public welfare. This Policy also includes some suggestions on the methodology and parameters for undertaking Competition Impact Assessment of concerned policies, regulations and procedures.

Competition refers to a situation in a market place in which firms/ entities or sellers independently strive for the patronage of buyers in order to achieve a particular business objective, such as profits, sales, market share etc. By responding to demand for goods and services with lower prices and higher quality, competing businesses are pressured to reduce costs, innovate in processes and products, invest in technology and better managerial practices and increase productivity. This process leads to achievement of static, dynamic as also resource/allocative efficiencies, sustainable economic growth, development, and poverty alleviation.

Competition is not an end unto itself, rather a means to achieve economic efficiency and welfare objectives. Importantly, competition is not automatic, and requires to be promoted, protected and nurtured through appropriate regulatory frameworks, by minimising market restrictions and distortions, and provision of related productive inputs such as infrastructure services, finance, human capital etc. However, a Competition Policy has to be evolved to imbibe the principles of competition in various endeavours of the Government, of course in alignment with the national strategic objectives, along with social, environmental, public safety, and other considerations.

Competition Policy means government measures, policies, statutes, and regulations including a competition law, aimed at promoting competitive market structure and behavior of entities in an economy. Competition Law is but a sub-set of the Competition Policy. Thus, Competition Policy is a broader term which includes all government policies and laws whereas competition law is specific statute with a predefined mandate to adjudicate on violation(s) of the law. In India, the Competition Act, 2002 deals with anti-competitive agreements such as price fixing, bid rigging, joint boycotts, etc; abusive practices undertaken by dominant entities such as predatory pricing, abusive conditions of supply, etc, and regulation of combinations. It would be seen that a competition law is a regulatory instrument to check the prevalence of anti-competitive practices whereas a competition policy is a proactive and positive effort to build a competition culture in an economy.

The Constitution of India seeks to ensure for its citizens—social, economic and political justice. Article 19(1) (g) of the Indian Constitution provides “freedom to practice any profession, or to carry on any occupation, trade or business”. Articles 301-304 further elucidate the issues. In a judgment3 the Supreme Court held that Article 301 provides freedom not from all laws but freedom from such laws which restrict or affect activities of trade and commerce among and within the States; and that Article 301 refers to freedom from laws which go beyond regulations which burdens, restricts or prevents the trade movements between states and within states.

Competition Policy is widely recognised as a powerful tool to promote freedom of trade, efficient use of scarce resources, enhance productive efficiency, add to the static and dynamic efficiency of the economy, maximise economic growth and contribute to the welfare of the common man. The basic premise of the National Competition Policy (NCP) is to unlock fuller growth potential of Indian economy, which among other things could also help in tapping the opportunities arising from the demographic dividend in our country. It would seek to inculcate a competition culture across various sectors to induct greater efficiency and dynamism, bringing in innovation and technology, delivering goods and services which are competitive, thus contributing to accessibility for consumers and consumption and thereby accelerating economic development, global competitiveness, unleashing entrepreneurial energy, creating more jobs and opportunities to raise the living standards of people, thus ensuring inclusive growth.

National Competition Policy may also help to promote good governance by transparency, accountability through competing responses and avoidance of rent seeking. It would also have a positive co-relation with other strategic national objectives like employment, R&D efforts and environmental objectives. It also respects the sovereign functions of the State like defence and security etc, and would seek to encourage competition related measures only in matters having economic impact on the market.

In this background, the National Competition Policy will endeavour to:

(a) Preserve the competition process, to protect competition, and to encourage competition in the domestic market so as to optimise efficiency and maximise consumer welfare. This would also make domestic firms competitive globally,

(b) Promote, build and sustain a strong competition culture within the country through creating awareness, imparting training and consequently capacity building of stakeholders including public officials, business, trade associations, consumers associations, civil society etc.,

(c) Achieve harmonisation in policies, laws and procedures of the Central Government, State Government and sub-State Authorities in so far as the competition dimensions are concerned with focus on greater reliance on well-functioning markets,

(d) Ensure competition in regulated sectors and to ensure institutional mechanism for synergised relationship between and among the sectoral regulators and/or the CCI and prevent jurisdictional grid locks,

(e) Strive for single national market as fragmented markets are impediments to competition, and

(f) Ensure that consumers enjoy greater benefits in terms of wider choices and better quality of goods and services at competitive prices.

Taking into account the needs of and priorities for promoting a healthy competition culture the principles of the National Competition Policy are:

(a) Fair market process: Market regulation procedures should be rule bound, transparent, fair and non-discriminatory. Public interest tests are to be used to assess the desirability and proportionality of policies and regulations, and these would be subject to regular independent review.

(b) Institutional separation between policy making, operations and regulation i.e. operations in and regulation of a sector should be independent of the government branch which deals with policy formulation in the sector and is accountable to the Legislature.

(c) ‘Competitive neutrality’, such as adoption of policies which establish a ‘level playing field’ where government businesses compete with private sector and vice versa.

(d) Fair pricing and inclusionary behaviour, particularly of public utilities and intellectual property rights holders, which could be imbued with monopolistic characteristics and a large part of the consumers could be excluded.

(e) Third party access to ‘essential facilities’, i.e. requiring dominant infrastructure owners to grant to third parties access (e.g., electricity, communications, gas pipe lines, railway tracks etc) to their infrastructure on agreed terms and conditions and at regulated prices, aligned with competition principles. Such treatment can be given to intellectual property rights as well if the IPR concerned possesses essential infrastructure characteristics.

(f) Public Policies and programmes to work towards promotion of competition in the market place; and

(g) National, regional and international co-operation in the field of competition policy enforcement and advocacy.

The following initiatives are envisaged to effectively generate a culture of competition and to enhance competition in the domestic markets with the involvement of all the stakeholders:

(a) Several existing policies, statutes and regulations of the Government restrict or undermine competition. A review of such policies, statutes and regulations from the competition perspective will be undertaken with a view to removing or minimising their competition restricting effect.

(b) Proposed policies, statutes or regulations that affect competition should be subject to Competition Impact Assessment.

(c) Where a regulatory regime is justified, it should provide that the principles of competition would be taken into account in the regulation. Regulation needs to be diluted progressively as competition becomes effective in the regulated sector.

(d) The competition authorities need to be functionally autonomous and financially independent.

(e) In order to ensure effective competition, third party access to essential facilities in the infrastructure sector owned by dominant enterprise on reasonable and fair terms should be provided.

(f) Incorporate competition clauses in bilateral and regional trade agreements, which will go a long way in preventing anti-competitive behaviour and potential anti-competitive cross-border conduct.

Tuesday, July 5, 2011

Indian Cyber Security And International Cooperation

It has been long felt that we need to strengthen the cyber security of India. As more and more cyber crimes are committed against India and severe cyber attacks launched against India this requirement has become even more demanding.

India needs to intensify its focus on cyber security issues at both national and international level and must promote more international cooperation regarding cyber security.

India must also develop and adopt existing best practices in cyber security area. Similarly, India must develop a more efficient cyber incident response mechanism to tackle cyber attacks.

Public private partnerships (PPP) on cyber security must be given more importance in India. Presently, PPP in India in the field of cyber security is in infancy stage. Similarly, there are very few international cooperations between India and foreign players regarding cyber security.

Perry4Law and Perry4Law Techno Legal Base (PTLB) suggest that to start with, we must urgently formulate a techno legal cyber security policy of India. The cyber security policy of India must cover issues like legal framework for cyber security, PPP model for cyber security, international cooperation for cyber security, cyber crisis management plan of India, human rights protection in cyberspace, etc.

Once the cyber security policy of India is at place, we must work in the direction of implementing the same in true letter and spirit. The growing incidences of cyber crimes, cyber attacks against India, cyber espionage against India, websites defacement and cracking, etc show that India has still not taken cyber security seriously.

While absolute cyber security is next to impossible to achieve yet a basic level cyber security audit of Indian government’s websites, computers and computer systems would show that they are vulnerable to cyber attacks.

Perry4Law and PTLB believe that we must at least start securing our websites, servers and government computers. Further, computers located at sensitive government departments and ministries must have a well defined cyber security policy and usage. We hope these suggestions of Perry4Law and PTLB would be useful for Indian government.

Monday, July 4, 2011

US Cyberspace Policy Review And Cyber Security

US President Barack Obama promised during his election campaign that he would streamline the Cyber Security Infrastructure of America. He did not disappoint America and he initiated the “Most Comprehensive” Cyber Security Initiatives of America.

He has also declared that Cyber Threats are serious Economical and National Security related challenges that US must urgently redress. He also believes that America's economic prosperity in the 21st century will depend on Cyber Security.

To achieve the abovementioned Cyber Security Objectives, Obama has directed a top-to-bottom review of the Federal Government's efforts to defend America’s information and Communications Infrastructure.

This resulted in the finalisation of a report titled the Cyberspace Policy Review. To implement the results of this review, the President has appointed Howard Schmidt to serve at the U.S. Cyber Security Coordinator and created the Cyber Security Office within the National Security Staff. The Office works closely with the Federal Chief Information Officer Vivek Kundra, the Federal Chief Technology Officer Aneesh Chopra and the National Economic Council.

America’s National Cyber Security Strategy intends to improve its resilience to cyber incidents and reduce the cyber threat. Improving the cyber resilience includes hardening the digital infrastructure to be more resistant to penetration and disruption, improving the ability to defend against sophisticated and agile cyber threats and recovering quickly from cyber incidents—whether caused by malicious activity, accident, or natural disaster.

On the front of tackling Cyber Threats, US intends to reduce threats by working with allies on International Cyber Security Cooperation, strengthening Law Enforcement Capabilities against Cyber Crime, and deterring potential adversaries from taking advantage of its remaining vulnerabilities.

Underlying all of these efforts is the need to acquire the best possible information about the State of America’s networks and the capabilities and intentions of its cyber adversaries. US must also make critical Cyber Security information available to and usable by everyone who needs it, including network operators and defenders, law enforcement and intelligence agencies, and emergency management officials in the Federal, State, local, and tribal governments, private industry, and allied Governments.

US has also recognised the importance of Protecting the Civil Liberties and Human Rights in Cyberspace. Similar commitment is also required from United Nations for the Protection of Human Rights in Cyberspace. US maintains that while securing its networks, it will do so in a manner that preserves and enhances our personal privacy and enables the exercise of our civil liberties and fundamental freedoms.

US believes that in the 21st Century, our digital networks are essential to our way of life around the World and are an engine for freedom. The increased security must be accompanied with an enhanced user privacy and keeping the Internet open and innovative.

The President’s Cyberspace Policy Review identifies 10 near term actions to support its Cyber Security strategy:

(1) Appoint a Cyber Security policy official responsible for coordinating the Nation’s Cyber Security policies and activities.

(2) Prepare for the President’s approval an updated national strategy to secure the information and communications infrastructure.

(3) Designate Cyber Security as one of the President’s key management priorities and establish performance metrics.

(4) Designate a Privacy and Civil Liberties official to the NSC Cyber Security directorate.

(5) Conduct interagency-cleared legal analysis of priority Cyber Security-related issues.

(6) Initiate a national awareness and education campaign to promote Cyber Security.

(7) Develop an International Cyber Security Policy Framework and strengthen our International Partnerships.

(8) Prepare a Cyber Security Incident Response Plan and initiate a dialog to enhance public-private partnerships.

(9) Develop a framework for research and development strategies that focus on game-changing technologies that have the potential to enhance the security, reliability, resilience, and trustworthiness of digital infrastructure.

(10) Build a Cyber Security-based identity management vision and strategy, leveraging privacy-enhancing technologies for the Nation.

We at Perry4Law and Perry4Law Techno Legal Base (PTLB) believe that these are far reaching and Reformative Cyber Security Initiatives suggested by US. If implemented in a Timely and Planned manner they can reduce the Cyber Threat against US Cyberspace to a great extent.

Right To Information Act 2005 And Public Records Act 1993

This is another Document of the Series of Research Reports Published by Perry4Law and Perry4Law Techno Legal Base (PTLB) that establishes the relationship of National Archives of India (NAI), Public Records Act 1993 and other Departments, Initiatives and Legislations of India. Perry4Law and PTLB have already provided Research Reports pertaining to Information Technology Act 2000, Electronic Services Delivery Bill 2011, Digital Preservation In India, etc.

The Right to Information Act, 2005 (RTI Act, 2005) has provided for certain obligations that every “Public Authority” is required to fulfill. All Government Departments, including NAI, are Public Authorities within the meaning of Section 2(h) of the RTI Act, 2005.

Section 2(h) of the RTI Act, 2005 provides that "Public Authority" means any authority or body or institution of self-government established or constituted- (a) by or under the Constitution; (b) by any other law made by Parliament; (c) by any other law made by State Legislature; (d) by notification issued or order made by the appropriate Government, and includes any- (i) body owned, controlled or substantially financed or (ii) non-Government organisation substantially financed, directly or indirectly by funds provided by the appropriate Government.

This “Research Report” briefly outlines those responsibilities of NAI vis-à vis RTI Act, 2005.

Section 2 of the RTI Act, 2005 provides that unless the context otherwise requires-

(i) "Information" means any material in any form, including records, documents, memos, e-mails, opinions, advices, press releases, circulars, orders, logbooks, contracts, reports, papers, samples, models, data material held in any electronic form and information relating to any private body which can be accessed by a public authority under any other law for the time being in force.

NAI would be required to provide “Information” to the information seekers who have made an RTI Application.

(ii) "Record" includes-

(a) Any document, manuscript and file;
(b) Any microfilm, microfiche and facsimile copy of a document;
(c) Any reproduction of image or images embodied in such microfilm (whether enlarged or not); and
(d) Any other material produced by a computer or any other device.

The definition of “Public Records” U/S 2(e) of Public Records Act, 1993 (PRA 1993) is almost identical with the definition of Records under the RTI Act 2005. These Records can be sough under the RTI Act, 2005 as “Information” through RTI Application.

(iii) "Right to information" means the right to information accessible under this Act which is held by or under the control of any public authority and includes the right to-

(i) Inspection of work, documents, records;
(ii) Taking notes, extracts or certified copies of documents or records;
(iii) Taking certified samples of material;
(iv) Obtaining information in the form of diskettes, floppies, tapes, video cassettes or in any other electronic mode or through printouts where such information is stored in a computer or in any other device.

(iv) "Third party" means a person other than the citizen making a request for information and includes a public authority.

Section 3 of the RTI Act, 2005 provides that subject to the provisions of this Act, all citizens shall have the right to information.

Section 4(1) of the RTI Act, 2005 provides that every public authority shall-

(a) Maintain all its records duly catalogued and indexed in a manner and the form which facilitates the right to information under this Act and ensure that all records that are appropriate to be computerised are, within a reasonable time and subject to availability of resources, computerised and connected through a network all over the country on different systems so that access to such records is facilitated;

With laws like the proposed Electronic Services Delivery Bill, 2011 the requirements to computerise Records and Public Records of NAI would become almost mandatory. We at Perry4Law and Perry4Law Techno Legal Base (PTLB) strongly recommend initiation of Digitilisation and Digital Preservation Initiatives by NAI as soon as possible.

The provisions of Information Technology Act, 2000 would also apply to the initiatives of NAI. Further, provisions regarding Digitilisation and Digital Preservation must be incorporated in the proposed Amendments in the Public Records Act, 1993 itself.

(b) Publish within one hundred and twenty days from the enactment of this Act,-

(i) The particulars of its organisation, functions and duties;
(ii) The powers and duties of its officers and employees;
(iii) The procedure followed in the decision making process, including channels of supervision and accountability;
(iv) The norms set by it for the discharge of its functions;
(v) The rules, regulations, instructions, manuals and records, held by it or under its control or used by its employees for discharging its functions;
(vi) A statement of the categories of documents that are held by it or under its control;
(vii) The particulars of any arrangement that exists for consultation with, or representation by, the members of the public in relation to the formulation of its policy or implementation thereof;
(viii) A statement of the boards, councils, committees and other bodies consisting of two or more persons constituted as its part or for the purpose of its advice, and as to whether meetings of those boards, councils, committees and other bodies are open to the public, or the minutes of such meetings are accessible for public;
(ix) A directory of its officers and employees;
(x) The monthly remuneration received by each of its officers and employees, including the system of compensation as provided in its regulations;
(xi) The budget allocated to each of its agency, indicating the particulars of all plans, proposed expenditures and reports on disbursements made;
(xii) The manner of execution of subsidy programmes, including the amounts allocated and the details of beneficiaries of such programmes;
(xiii) Particulars of recipients of concessions, permits or authorisations granted by it;
(xiv) Details in respect of the information, available to or held by it, reduced in an electronic form;
(xv) The particulars of facilities available to citizens for obtaining information, including the working hours of a library or reading room, if maintained for public use;
(xvi) The names, designations and other particulars of the Public Information Officers;
(xvii) Such other information as may be prescribed; and thereafter update these publications every year.

These are very wide mandates especially the one created by clause (xiv) that requires NAI to provide details in respect of the information, available to or held by it, and reduced in an electronic form.

(c) Publish all relevant facts while formulating important policies or announcing the decisions which affect public;

(d) Provide reasons for its administrative or quasi-judicial decisions to affected persons. Section 4(2) of the RTI Act, 2005 provides that it shall be a constant endeavour of every public authority to take steps in accordance with the requirements of clause (b) of sub section (1) to provide as much information suo motu to the public at regular intervals through various means of communications, including internet, so that the public have minimum resort to the use of this Act to obtain information.

Again the desirability to adopt Digitilisation of Records and Public records by NAI is clear from Section 4(2) of RTI Act, 2005.

Section 4(3) of the RTI Act, 2005 provides that for the purposes of sub-section (1), every information shall be disseminated widely and in such form and manner which is easily accessible to the public.

Section 4(4) of the RTI Act, 2005 provides that all materials shall be disseminated taking into consideration the cost effectiveness, local language and the most effective method of communication in that local area and the information should be easily accessible, to the extent possible in electronic format with the Central Public Information Officer or State
Public Information Officer, as the case may be, available free or at such cost of the medium or the print cost price as may be prescribed.

The Explanation to Section 4 of RTI Act, 2005 provides that for the purposes of subsections (3) and (4), "disseminated" means making known or communicated the information to the public through notice boards, newspapers, public announcements, media broadcasts, the internet or any other means, including inspection of offices of any public authority.

Section 6 (1) of the RTI Act, 2005 provides that a person, who desires to obtain any information under this Act, shall make a request in writing or through electronic means in
English or Hindi or in the official language of the area in which the application is being made, accompanying such fee as may be prescribed, to the appropriate officer.

An RTI Application can also be made through E-Mail, Fax or any other Electronic means. Thus, NAI must keep in place a “System” and “Procedure” for dealing with Electronic Records and Electronic RTI Applications.

Section 8 (1) of the RTI Act, 2005 provides that notwithstanding anything contained in this Act, there shall be no obligation to give any citizen,-

(a) Information, disclosure of which would prejudicially affect the sovereignty and integrity of India, the security, strategic, scientific or economic interests of the State, relation with foreign State or lead to incitement of an offence;
(b) Information which has been expressly forbidden to be published by any court of law or tribunal or the disclosure of which may constitute contempt of court;
(c) Information, the disclosure of which would cause a breach of privilege of Parliament or the State Legislature;
(d) Information including commercial confidence, trade secrets or intellectual property, the disclosure of which would harm the competitive position of a third party, unless the competent authority is satisfied that larger public interest warrants the disclosure of such information;
(e) Information available to a person in his fiduciary relationship, unless the competent authority is satisfied that the larger public interest warrants the disclosure of such information;
(f) Information received in confidence from foreign Government;
(g) Information, the disclosure of which would endanger the life or physical safety of any person or identify the source of information or assistance given in confidence for law enforcement or security purposes;
(h) Information which would impede the process of investigation or apprehension or prosecution of offenders;
(i) Cabinet papers including records of deliberations of the Council of Ministers, Secretaries and other officers:

Provided that the decisions of Council of Ministers, the reasons thereof, and the material on the basis of which the decisions were taken shall be made public after the decision has been taken, and the matter is complete, or over:

Provided further that those matters which come under the exemptions specified in this section shall not be disclosed;

(j) Information which relates to personal information the disclosure of which has no relationship to any public activity or interest, or which would cause unwarranted invasion of the privacy of the individual unless the Central Public Information Officer or the State
Public Information Officer or the appellate authority, as the case may be, is satisfied that the larger public interest justifies the disclosure of such information:

Provided that the information which cannot be denied to the Parliament or a State Legislature shall not be denied to any person.

Section 8(1) of the RTI Act, 2005 outlines the “Grounds” on which NAI can “Refuse” to give Information about Records and Public Records to an RTI Applicant. By virtue of Section 22 of the RTI Act, 2005, these are the “Only Grounds” subject to which NAI can refuse information to RTI Applicants.

The grounds mentioned in the Public Records Act, 1993 would no more be relevant after the passing of the RTI Act, 2005. The proposed amendments in the Public Records Act, 1993 must add the “Grounds and Exemptions” that NAI wishes to add in addition to the one mentioned by RTI Act, 2005.

Section 8 (2) of the RTI Act, 2005 provides that notwithstanding anything in the Official Secrets Act, 1923 nor any of the exemptions permissible in accordance with sub-section (1), a public authority may allow access to information, if public interest in disclosure outweighs the harm to the protected interests.

Section 8 (3) of the RTI Act, 2005 provides that subject to the provisions of clauses (a), (c) and (i) of sub-section (1), any information relating to any occurrence, event or matter which has taken place, occurred or happened twenty years before the date on which any request is made under Section 6 shall be provided to any person making a request under that section:

Provided that where any question arises as to the date from which the said period of twenty years has to be computed, the decision of the Central Government shall be final, subject to the usual appeals provided for in this Act.

The 20 years period is in conformity with the proposed amendments suggested by the Consultation Committee of NAI formulated to suggest Amendments in the PRA 1993.

Section 9 of the RTI Act, 2005 provides that without prejudice to the provisions of section 8, a Central Public Information Officer or a State Public Information Officer, as the case may be, may reject a request for information where such a request for providing access would involve an infringement of Copyright subsisting in a person other than the State.

Section 10(1) of the RTI Act, 2005 provides that where a request for access to information is rejected on the ground that it is in relation to information which is exempt from disclosure, then, notwithstanding anything contained in this Act, access may be provided to that part of the record which does not contain any information which is exempt from disclosure under this Act and which can reasonably be severed from any part that contains exempt information.

NAI can provide “Partial Access” to its Records and Public Records.

Section 10 (2) of the RTI Act, 2005 provides that where access is granted to a part of the record under sub-section (1), the Central Public Information Officer or State Public Information Officer, as the case may be, shall give a notice to the applicant, informing-

(a) That only part of the record requested, after severance of the record containing information which is exempt from disclosure, is being provided;
(b) The reasons for the decision, including any findings on any material question of fact, referring to the material on which those findings were based;
(c) The name and designation of the person giving the decision;
(d) The details of the fees calculated by him or her and the amount of fee which the applicant is required to deposit; and
(e) His or her rights with respect to review of the decision regarding non-disclosure of part of the information, the amount of fee charged or the form of access provided, including the particulars of the senior officer specified under sub-section (1) of section 19 or the Central Information Commission or the State Information Commission, as the case may be, time limit, process and any other form of access.

Section 11(1) of the RTI Act, 2005 provides that where a Central Public Information Officer or a State Public Information Officer, as the case may be, intends to disclose any information or record, or part thereof on a request made under this Act, which relates to or has been supplied by a third party and has been treated as confidential by that third party, the Central Public Information Officer or State Public Information Officer, as the case may be, shall, within five days from the receipt of the request, give a written notice to such third party of the request and of the fact that the Central Public Information Officer or State Public Information Officer, as the case may be, intends to disclose the information or record, or part thereof, and invite the third party to make a submission in writing or orally, regarding whether the information should be disclosed, and such submission of the third party shall be kept in view while taking a decision about disclosure of information:

Provided that except in the case of trade or commercial secrets protected by law, disclosure may be allowed if the public interest in disclosure outweighs in importance any possible harm or injury to the interests of such third party.

NAI receives many Archives, Records, Books, etc by way of Gifts and otherwise by Third Parties. Such Records, etc must be given subject to the provisions of this Clause or to the Terms and Conditions subject to which they have been given to the NAI by such Third Parties. .

Section 11(2) of the RTI Act, 2005 provides that where a notice is served by the Central Public Information Officer or State Public Information Officer, as the case may be, under sub-section (1) to a third party in respect of any information or record or part thereof, the third party shall, within ten days from the date of receipt of such notice, be given the opportunity to make representation against the proposed disclosure.

Section 11(3) of the RTI Act, 2005 provides that notwithstanding anything contained in Section 7, the Central Public Information Officer or State Public Information Officer, as the case may be, shall, within forty days after receipt of the request under Section 6, if the third party has been given an opportunity to make representation under sub-section (2), make a decision as to whether or not to disclose the information or record or part thereof and give in writing the notice of his decision to the third party.

Section 11(4) of the RTI Act, 2005 provides that a notice given under sub-section (3) shall include a statement that the third party to whom the notice is given is entitled to prefer an appeal under section 19 against the decision.

Third Party Relationships of NAI must be suitably regulated. A sound and practical Procedure or Guidelines in this regard is desirable on the part of NAI.

Section 22 of the RTI Act, 2005 provides that the provisions of this Act shall have effect notwithstanding anything inconsistent therewith contained in the Official Secrets Act, 1923, and any other law for the time being in force or in any instrument having effect by virtue of any law other than this Act.

The RTI Act, 2005 would “Override” the provisions of Public Records Act, 1993 and its Rules by virtue of this section.

Section 24 (1) of the RTI Act, 2005 provides that nothing contained in this Act shall apply to the intelligence and security organisations specified in the Second Schedule, being organisations established by the Central Government or any information furnished by such organisations to that Government:

Provided that the information pertaining to the allegations of corruption and human rights violations shall not be excluded under this sub-section:

Provided further that in the case of information sought for is in respect of allegations of violation of human rights, the information shall only be provided after the approval of the Central Information Commission, and notwithstanding anything contained in section 7, such information shall be provided within forty-five days from the date of the receipt of request.

Section 24 (2) of the RTI Act, 2005 provides that the Central Government may, by notification in the Official Gazette, amend the Schedule by including therein any other intelligence or security organisation established by that Government or omitting therefrom any organisation already specified therein and on the publication of such notification, such organisation shall be deemed to be included in or, as the case may be, omitted from the Schedule.