Showing posts with label Privacy Laws In India. Show all posts
Showing posts with label Privacy Laws In India. Show all posts

Saturday, March 10, 2012

Online Sale And Purchase Of Prescribed Drugs and Medicines In India

Online sales and purchase are governed by electronic commerce transactions. We have no dedicated e-commerce laws and regulations in India. However, a basic level legal e-commerce framework has been provided by the Information Technology Act, 2000 (IT Act 2000) that is the cyber law of India.

While we have basic level e-commerce legal framework in India yet e-health related legal framework is missing. For instance, e-health in India is facing legal roadblocks. Till now we do not have any dedicated e-health laws and regulations in India. The legal enablement of e-health in India is urgently required.

When technology is used for medical purposes, it gives rise to medico legal and techno legal issues. In United States, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Health Information Technology for Economic and Clinical Health Act (HITECH Act), etc are some of the laws that take care of medico legal and techno legal issues of e-health and telemedicine.

As far as India is concerned, we have no dedicated e-health and telemedicine laws in India. Even essential attributes of these laws like privacy protection, data protection, data security, cyber security, confidentiality maintenance, etc are not governed by much needed dedicated laws.

Ordinary commodities can be comfortably sold through e-commerce websites. However, health related commodities, especially prescribed medicines and drugs, are not easy to manage in an online environment. This is the reason why we have almost nil online sales of prescribed drugs and medicines in India as on date.

We need a dedicated law regarding e-health in general and online sale and purchase of prescription drugs in particular. The laws that deal with sales of prescribed medicines and drugs were enacted many decades ago when information and communication technology (ICT) driven innovative e-commerce methods were not within the contemplation of the legislature. Naturally, these laws are silent about their applicability to online sale and purchase of prescription drugs and their online trading.

Till now many e-health players are not aware whether the present laws allows or disallows the buying and selling of medicines through websites. Though over-the-counter products are no problem, online trade of prescription medicines is a sensitive issue. There are far too many issues involved regarding safety and authenticity of online drug stores.

Most western countries have allowed online sale of medicines. Even China has recently allowed opening of online medical stores for its pharmaceutical industry when about 20 companies were given licenses in this regard and they are doing well. In India, most players are afraid of engaging in online sales of prescribed medicines because of the uncertainty in the legal framework. Time has come to enact a dedicated law that allows online sales and purchase of prescribed drugs and medicines in India.

Wednesday, December 21, 2011

Intelligence Gathering Is Not Above Right To Privacy In India

Right to privacy in India is a constitutional right. Efforts are in the process to make it a statutory right as well. A dedicated statutory right to privacy in India is in pipeline in the form of right to privacy bill of India 2011. The proposed Bill must protect human rights in cyberspace to be valid and constitutional and it must respect the privacy rights of Indians in the information age. The proposed draft right to privacy bill 2011 of India may confer some form of privacy rights to Indians. However, its true scope is yet to be made public.

Privacy laws in India and privacy rights in India have always been ignored. We have no national privacy policy in India as well. Data protection laws in India are missing and so are data privacy laws in India. Privacy, data protection and India seems to be separable and unrelated concepts.

Indian government launched projects like Aadhar, National Intelligence Grid (Natgrid), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under parliamentary scrutiny.

Further, there are some very crucial issues that are posing constitutional problems for the intelligence and security agencies of India. For instance, intelligence gathering in India is unconstitutional. Similarly, counter terrorism capabilities of India are not sufficient and Indian counter terrorism capabilities needs rejuvenation. Finally, parliamentary oversight and constitutional safeguards are missing in the functions of these agencies.

India does not have a constitutionally sound lawful interception law. Phone tapping in India is still done in an unconstitutional manner and at times by private individuals as well. Further surveillance of Internet traffic in India is now openly acknowledged by Indian government.

The intelligence infrastructure of India has become synonymous for non accountability and mess. There is neither any parliamentary oversight nor and transparency and accountability of the working of intelligence agencies of India. Intelligence infrastructure of India needs rejuvenation keeping in mind the constitutional obligations.

The draft Intelligence Services (Powers and Regulation) Bill, 2011 has failed to take the shape of a law in India and it has been announced that law on intelligence agencies would be formulated soon. Even the Draft Central Bureau of Investigation Act, 2010 has failed to become an applicable law.

E-surveillance in India, websites blocking in India, Internet censorship in India, etc are also not done a strictly constitutional manner. Till now Indian courts have not tested the acts of intelligence agencies. Recently Indian research and analysis wing (RAW) was granted e-surveillance powers without any legal framework. Now the home ministry of India is demanding that intelligence and law enforcement agencies must be kept out of the purview of the proposed Privacy law, and should be allowed to continue monitoring the activities and carry out electronic surveillance of citizens.

Home ministry is suggesting that the way intelligence and investigation agencies are exempted under schedule 2 of the Right to Information (RTI) Act, they should be kept out of the proposed privacy Bill in view of national security.

Under schedule 2 of the RTI Act, citizens are restricted from seeking information from agencies such as the Intelligence Bureau (IB), the Research and Analysis Wing, the Central Bureau of Investigation, the National Investigation Agency, the National Intelligence Grid and the National Technical Research Organisation.

Home ministry do not wants the privacy Bill to interfere with intelligence gathering activities even if means accommodating more safeguards in line with the sprit of the privacy Bill.

This seems to be an unreasonable demand as we must now stress upon great parliamentary scrutiny of intelligence agencies and law enforcement agencies. On the contrary we are diluting the constitutional freedoms and procedural safeguards. It is high time for parliament of India to interfere and enact constitutionally sound laws in this regard.

Monday, December 5, 2011

Constitutional Phone Tapping Law In India Is Needed

Phone tapping in India is regulated by outdated and ancient law known as Indian Telegraph Act 1885 and corresponding rules there under. As per section 5 of the telegraph act, the central government or state government is empowered to order interception of messages. Rule 419 and 419A sets out the procedure of interception and monitoring of telephone messages.

As per Rule 428 of the India telegraphic rules, no person without the sanction of the telegraph authority, use any telephone or cause or suffer it to be used, purposes other than the establishment of local or trunk calls.

However, in practice whatever little safeguards provided by the act are seldom followed. Phone tapping by private individuals in India is rampant and even governmental phone tapping is unaccountable. We have no constitutionally sound lawful interception law in India. Even the Home Ministry of India is considering enactment of a lawful Interception Law in India.

It is suffice to say that this unconstitutional phone tapping in India and illegal e-surveillance in India is a “constitutional failure of India”. India urgently needs a valid phone tapping law. The central monitoring system project of India (CMS Project of India) is also not supported by any legal framework.

This is the real problem for the CMS Project of India. We have no dedicated privacy laws in India, data security laws in India and data protection laws in India. Further, the CMS Project of India is also beyond the “parliamentary scrutiny”.

Further, we have no e-surveillance policy in India. Even phone tapping in India is done in an “unconstitutional manner” and even by private individuals with or without governmental approval.

Recently even the Supreme Court of India took a serious note of the growing and blatant incidences of privacy violation in India by Indian government and private individuals/companies supported by it. Supreme Court went upto the extent of saying that no person living in India is safe from privacy violations and omnipresent forgeries prevalent in India.

The present practice of Indian government regarding phone tapping, e-surveillance and e-interceptions is far from being legal and constitutional. India urgently needs a constitutionally sound lawful interception law. Let us hope the Supreme Court would bring some order in the otherwise chaosed banana republic of India.

Friday, October 7, 2011

Privacy Rights And Laws In India

Privacy laws in India are virtually missing and Indian government seems to be in no rush to have suitable privacy and data protection laws in India. Even the national privacy policy of India is missing. However, recent developments pertaining to cyberspace and ICT, has forced Indian government to think about privacy issues in India.

Indian government has been launching projects without proper procedural safeguards and parliamentary scrutiny. These projects and authorities are openly violating the human rights in cyberspace but Indian government is not deterred by this issues.

It is only after the United Nations has declared that access to Internet is a human right that Indian government is thinking about civil liberty issues in cyberspace. In order to confer legitimacy to projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc, they must be supported by a techno legal framework. Presently, none of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

While lack of privacy law has already stalled Natgrid yet other projects like unique identification project of India or Aadhar project of India are simply unconstitutional by their very existence and being violative of privacy rights as conferred under Indian constitution.

For some strange reasons, Indian government has been ignoring enactment of good techno legal privacy laws in India. Various governmental ministries have started the exercise of enacting the privacy law for India time to time but ultimately none of them materialised. These exercises proved to be futile and till now we are still waiting for the enactment of sufficient and strong privacy laws in India.

Tuesday, July 5, 2011

Cloud Computing Due Diligence In India

Cloud computing in India is still at the infancy stage. The primary reasons for this situation is absence of legal framework for cloud computing in India, missing privacy laws, absence of data protection laws in India, inadequate data security in India, etc. Even the basic level cloud computing regulations in India are missing.

Many legal experts in India have opined that India must not use software as a service (SaaS), cloud computing, m-governance, etc till proper legal frameworks and procedural safeguards are at place. Even the CEOs of many companies are apprehensive of using cloud computing for their companies businesses.

Even if a company or individual offers cloud computing services in India, it/he has to comply with many legal provisions and cyber due diligence requirements. The information technology act 2000 (IT Act 2000) has prescribed due diligence requirements for various business organisations and stakeholders. These due diligence requirements equally apply to cloud computing service providers in India.

These due diligence requirements are very stringent and cloud computing providers can find themselves in legal hassles if they ignore the same. Managing sensitive and personal data and information in India is no more a causal approach but it has become very stringent.

With the proposal to codify law of torts in India, more and more civil proceeding for violation of privacy rights may be initiated against the cloud computing service providers. It would be a wise option to establish best practices and cloud computing policy by all stakeholders in their own larger interests.

Wednesday, June 29, 2011

Regulatory Framework For Cloud Computing In India

The proposal to use of cloud computing in India has raised many regulatory and security concerns. Without meeting these regulatory and security concerns, software as a service (SaaS) and cloud computing should not be used in India. In fact, cloud computing in India must be techno legal in nature and till it meets the techno legal requirements, it should not be used in India.

Before using cloud computing in India we must ask few questions to ourselves. These include what are the regulatory frameworks required for successful cloud computing, how the security concerns need to be addressed, what are the legal frameworks for multi jurisdictional cooperation, and what are the quality of service (QoS) parameters for effective cloud service.

Besides regulatory framework for cloud computing in India we must also ensure high availability levels, appropriate data erasing mechanisms, data privacy at the service provider’s level, export restrictions upon data, data handling monitoring mechanisms, jurisdictional issues, cloud computing security issues, licensing issues for cloud computing, etc.

Till now we have no cloud computing policy of India. There is no cyber security in India and even cyber security policy of India is missing. There is no privacy law in India. There is no data protection law in India. And there is no data security law in and cyber security law in India. In short, there is no legal framework for cloud computing in India at all.

Fortunately, stakeholders have openly supported the need of regulatory framework for cloud computing in India. With an increasing pressure the Indian government may consider formulating a legal framework for cloud computing in India. The sooner it is done the better it would for all the stakeholders concerned.

Sunday, June 26, 2011

Human Rights Protection In Indian Cyberspace

A few years back talking of human rights in cyberspace was seen with skepticism. Now people around the world are more concerned and aware of their human rights in cyberspace.

Surprisingly, United Nations has still not considered human rights issues of cyberspace though it has recently announced that access to Internet is a human right. United Nations must seriously consider protection of human rights in cyberspace as soon as possible as nations across the world are becoming more and more oppressive and endemic e-surveillance oriented.

While United Nations has declared that access to Internet is Human Rights yet Indian government is well committed to deny not only this human rights but also all other possible human rights in cyberspace.

For instance, projects like national intelligence grid (Natgrid), central monitoring system project of India (CMS), centre for communication security research and monitoring (CCSRM), Aadhar project of India, crime and criminal tracking network and systems (CCTNS), national counter terrorism centre (NCTC), etc have no “procedural safeguards” and they are violating human rights and fundamental rights in their “present form”.

These projects have been launched without any legal framework and parliamentary oversight. Further, even the most “basic laws” like data protection Laws, data security laws, privacy laws, etc are missing in India.

United Nations must urgently step in to formulate an international treaty on protection of human rights in cyberspace. If UN maintains its indifferent attitude, draconian laws like the cyber law of India keep on surfacing.

Saturday, June 25, 2011

Legal Framework For Cloud Computing In India

Cloud computing is a commercial project that most of the IT vendors of the world would love to launch in India. This is so because India has a large market for cloud computing business. However, the crucial question is whether India is ready for cloud computing? In short, we have to check whether cloud computing is viable for India especially when techno legal experts of India have answered in negative.

There are many hurdles for the successful implementation of cloud computing framework in India. The biggest among them is absence of legal framework for cloud computing in India. Further, allied legal frameworks are also missing that makes use of cloud computing in India non feasible and prone to numerous legal challenges.

For instance we have no dedicated privacy laws in India, data security laws in India and data protection laws in India. Further, India is fast becoming an endemic e-surveillance society in the absence of proper laws and constitutional procedural safeguards.

For instance, the central monitoring system project of India (CMS project of India) would have absolute control over telecommunications and Internet communications that also without any legal framework and parliamentary oversight. Further, companies like Research in Motion (RIM) have openly declared their support for e-surveillance activities of Indian intelligence agencies by extending cloud computing based e-surveillance model for its Blackberry messenger services.

Further, India is also the only country of the world where phone tapping and e-surveillance is done without a court warrant and beyond the judicial scrutiny. The executive branch of Indian constitution is neither accountable to the parliament of India nor to the judiciary in this regard.

All a police officer or governmental officer has to do is to approach the concerned cloud computing service provider, and it would hand over all your sensitive data and information to him without your knowledge. Further, even if the data is not physically handed over, access to the same can be given to such officer without anybody knowing of such access.

Privacy violations would definitely arise in cases of use of cloud computing in India. The only fact is that you may not be aware that your privacy rights have been violated and your sensitive and personal data is no more a secret.

Indian government must not use software as a service (SAAS) or cloud computing for governmental and public services delivery till suitable procedural safeguards against violation of civil liberties in general and privacy rights in particular are at place. Even industrial players like Infosys and CII have endorsed this viewpoint. Time has come to enact a constitutionally sound legal framework for cloud computing in India.

Friday, June 24, 2011

Central Monitoring System Project Of India

Central Monitoring System Project of India (CMS Project of India) is a very crucial project to safeguard Information and Communication Technology (ICT) related security and e-surveillance issues in India. It is mooted by the Central Ministry of Communication and Information Technology (MCIT).

The aim of CMS Project of India is to have a “Centralised Mechanism” where Telecommunications and Internet Communications can be analysed by the MCIT, Indian Government and its Agencies. Some have called this mechanism as the Internet Kill Switch of India where Internet Communications all over India can be suspended through this mechanism.

Recently, the United Nations declared “Right to Access” to Internet as Human Right. This would have a positive impact upon many Human Rights in Cyberspace. For instance, Right to Speech and Expression, Right to Privacy, Right to Know, etc cannot be violated by the CMS Project of India. United Nations must expand Human Rights Protection to many more issues.

This is the real problem for the CMS Project of India. We have no dedicated Privacy Laws in India, Data Security Laws in India and Data Protection Laws in India. Further, the CMS Project of India is also beyond the “Parliamentary Scrutiny”. The Cyber Law of India, incorporated in the Information Technology Act 2000 (IT Act 2000), was drastically amended through the Information Technology Amendment Act 2008 (IT Act 2008).

The IT Act 2008 incorporated various “Unconstitutional Provisions” in the Cyber Law of India that clearly violates the Human Rights in Cyberspace. For instance, provisions regarding Internet Censorship, Website Blocking, Encryption and Decryption, etc have no inbuilt “Procedural Safeguards” as mandated by the Constitution of India. This is the reason why the Cyber Law of India needs to be repealed.

Further, we have no E-Surveillance Policy in India. Even Phone Tapping in India is done in an “Unconstitutional Manner” and even by private individuals with or without Governmental approval.

If CMS Project of India has to be “Legal and Constitutional” it must be subject to “Parliamentary Oversight”. Further, the IT Act 2000 must be repealed as soon as possible as it is clearly not in conformity with the Constitution of India and Civil Liberties Protection in Cyberspace.

Of course, if India Government persists in this “Unconstitutional Approach”, taking recourse of “Self Defence Measures” is not a bad option. Rather that remains the “Sole Option” when our Parliament, Executive and Judiciary fail to protect Fundamental Rights enshrined in the Constitution of India and the Human Rights Charter of United Nations.

Monday, June 20, 2011

Indian Government Waking Up To Privacy Laws Requirements

Of late Fundamental Rights and Civil Liberties of Indian Citizens in Cyberspace have been totally neglected by the Executive and Legislative Branches of Indian Constitution. Unfortunately, even Judiciary failed to interfere and we have reached a “Precarious Situation” where the Constitution of India, especially Fundamental Rights, are about to be made “Redundant and Non Existent”.

While United Nations has declared that “Access to Internet” is Human Rights yet Indian Government is well committed to deny not only this Human Rights but also all other possible Human Rights in Cyberspace.

Naturally, there is a need to protect Human Rights in Cyberspace before we fully launch various E-Surveillance and Civil liberties Violating Projects in India. Security and E-Surveillance Projects have been launched by Indian Government without any “Procedural Safeguards” and in active “Violation” of Human Rights in Cyberspace. The only solace is that these Projects are in their infancy stage and they can still be made “Constitutional”.

For instance, Projects like National Intelligence Grid (NATGRID), Central Monitoring System of India (CMS), Centre for Communication Security Research and Monitoring (CCSRM), Aadhar Project of India, Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), etc have no “Procedural Safeguards” and they are violating Human Rights and Fundamental Rights in their “Present Form”. These Projects have been launched without any Legal Framework and Parliamentary Oversight. Further, even the most “Basic Laws” like Data Protection Laws, Data Security Laws, Privacy Laws, etc are missing in India.

Realising the “Gravity of the Situation”, the Planning Commission of India has now decided to call a high-level meeting of experts, civil society representatives and government officials to address these concerns. The Commission admits that initiatives like UID, NATGRID, DNA profiling, brain mapping and tapping communication, etc are “Genuine Concerns” and they need to be addressed properly. The Commission has also suggested using “Inbuilt Technological Safeguards” for all these Projects.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we have been constantly suggesting that privacy is a key concern in all these Projects as people's personal information would be stored in a single database and the possibility of corruption and exploitation could not be ruled out.

The minister, incharge of IT in the plan panel, said it is necessary to have in-depth and threadbare discussion with experts, civil society representatives and government officials to ensure that the objective of national security and efficiency in public service delivery mechanism are effectively reconciled with the privacy concern of citizens.

This is a good step in the right direction and Perry4Law and PTLB welcome this step of Indian Government.

Friday, June 17, 2011

Cell Site Location Based E-Surveillance In India

While it came as a respite for the encryption service providers in India when they received the news that their services may not be banned in India yet local telecom service providers in India may not be that lucky. The new telecom equipment policy of India mandates the telecom service providers of India have to ensure location based services accuracy (LBSA) upto 50 meters.

The constitutionality and feasibility of this directive is yet to be analysed. For instance we have no cell site data location laws in India. In fact, we have no privacy laws, data protection laws, data security laws, anti telemarketing laws, anti spam laws, etc. On the contrary, the cyber law of India, incorporated in the information technology act 2000 (IT Act 2000), facilitates e-surveillance, Internet censorship, etc that also without any sort of procedural safeguards. Thus, neither a constitutional nor a statutory legal framework is at place to justify this action on the part of Indian government.

Even if we do a cost analysis this directive may require a heavy investment that telecom operators of India may not be wiling to invest. Telecom industry of India is seriously concerned with the burden shifting practice of Indian government. They believe that governmental security requirements must be managed by government funds alone and should not be passed upon industry players. The new equipment security agreement of India is not addressing either the legal or cost issues.

Technical problems have also been cited as a reason for non feasibility of the terms of Indian equipment security agreement. Based on, the technical standards for accuracy levels as defined by the Indian government, the scale of implementation, the execution of the project and the complexities involved, there is no solution at present that meets the agreement’s mandate. The costs to implement such a system have been estimated at approximately $5 billion.

The Indian equipment security agreement is also weak on the front of privacy protection and data protection. There are no clear policy guidelines in this regard. This is because the new equipment security agreement of India requires telecom operators to maintain location information up to accuracy of 50 meters for customers specified by security agencies of India commencing 1st June 2012, and on all customers, irrespective of whether they are the subject of legal intercept or not from June 2014.

Of course, LBS have many benefits for mobile consumers as well but these befits are far lesser as compared to privacy losses, telemarketing vices, spam communications and information misuses. We need a good and effective national telecom policy of India 2011 that can incorporate all these issue.

Thursday, June 16, 2011

Cell Site Data Location Laws In India And Privacy Issues

Cell Site Data Location is not a very positive term. It has been in controversies for breaching Privacy Rights of the person whose Cell Site Data was acquired. Cell Site Data tells about the “Location” of a person who is carrying a cell phone, without his consent. This raises many “Privacy Issues” and “Legal issues” as it amounts to E-Surveillance and “Search without a Warrant”.

In the Indian context we have no Cell Site Data Laws. In fact, we have no Privacy Laws, Data Protection Laws, Data Security Laws, Anti Telemarketing Laws, Anti Spam Laws, etc. On the contrary, the Cyber Law of India, incorporated in the Information Technology Act 2000 (IT Act 2000), facilitates E-Surveillance, Internet Censorship, etc “Without any Procedural Safeguards”.

The Constitution of India provides that no Search or Warrant should be conducted without a “Procedure Established by Law”. The Supreme Court of India has given the expression Procedure Established by Law a wider meaning and this has made it a “Due Process of Law”. Now the Indian Government or its Agencies and Instrumentalities cannot “Infringe” upon any Fundamental Right of an Indian Citizen of Person without Due Process of Law.

The Due Process mandates that the Law in question must not be any Law made as a Façade or Formality but must be “Just, Reasonable and Fair”. If we analyse the IT Act 2000, especially after the Information Technology Amendment Act 2008 (IT Act 2008), its “Fails to Satisfy’ the Due Process Clause of Indian Constitution. In short, the Cyber Law of India carries many “Unconstitutional Provisions” and either the Law itself must be Repealed or those Unconstitutional Provisions must be Struck Down by Supreme Court of India.

India needs to formulate separate and dedicated laws for Cyber Law, Cyber Security, Cyber Forensics, Privacy Protection, Data Protection, Data Security, etc. Presently India has no such Laws as even the Cyber Law of India is not good, effective, strong and most importantly “Constitutional”.

As a matter of fact, with the active use of Technology by Indian Government and its Agencies and Instrumentalities, Constitutional Provisions are “Most Frequently Violated” in India. I hope the Supreme Court of India would take note of this “Downsizing” of Indian Constitution that has become a “Regular Feature” these days.

Encryption Service Providers Would Not Be Banned In India

Encryption related issues have always posed problem for our intelligence agencies and law enforcement agencies. Unable to deal with the encrypted services, the intelligence and law enforcement agencies of India tried to adopt the next possible approach. They decided to take the easier route of eavesdropping and e-surveillance instead of developing the cyber skills.

Naturally, the threats to ban encryption service providers like research in motion’s (RIM) Blackberry, Gmail, Skye, etc was the measure of last resort for our central home ministry. However, home ministry of India did not realise the effect of this decision and now this decision seems to be haste one.

A government panel set up to examine security threats regarding 15 forms of communications that cannot be tracked by law enforcement agencies here, has recommended that no service be banned purely on the grounds that it cannot be monitored.

It has recommended that in the short term, India should force operators who offer such services to either locate servers in the country or share encryption keys with security agencies and assist security agencies here in monitoring these services.

As a long-term solution, the committee has recommended that the upcoming Central Monitoring System (CMS) be made capable of intercepting any form of communication service offered within the country.

It has also endorsed the telecom ministry's stance that the ultimate solution should involve intelligence agencies building up capabilities indigenously to monitor and intercept these technologies. The panel has also added that security agencies must avail the help of companies to build such capabilities.

The committee has said that security agencies must first check whether monitoring solutions are available in other counties before threatening to ban any specific communication service.

Before banning or blocking of encrypted communication impact on business and industry, e-commerce, e-governance, e-medicine, e-health, passport services etc should be taken into consideration. Further, banning or blocking services without providing an alternative may have international reactions and could affect other Indian industries such as BPO and IT outsourcing.

The government panel, with members from different ministries, including telecoms and IT, has also recommended that India raise its encryption levels from the present 40 bits to 256 bits, which is the standard in Europe and the US. Most western countries do not allow financial transactions on the internet through computers and mobile handsets, if the encryption level is less than 128 bits. India on the other hand does not legally allow encryptions beyond the 40-bit on the grounds that its security agencies lacked the technological capabilities to monitor data transfers on the internet when the coding is beyond this limit.

However, the Home Ministry and Intelligence Bureau (IB) whose members were part of the panel, have not signed these recommendations and have given their dissent note. The IB has said the recommendations by the panel shift the onus on encryption and decryption from mobile phone companies to the 'designated agency' (CMS) authorised by the home ministry, when 'current experience was that government agencies were unable to track such services'. It has also pointed out that it may be impossible to persuade foreign players to locate servers in India or share encryption keys with security agencies here as recommended by the panel.

India needs to upgrade its intelligence infrastructure that is in real mess. Intelligence agencies need to develop intelligence gathering and analysis skills so that situations like the present one can be taken care of.

Finally, there are no legal frameworks for intelligence agencies, law enforcement agencies, data protection, privacy protection and data security. These legal frameworks must be at place so that legal and constitutional intelligence gathering can be taken place. India has to cover a long gap before all these requirements and capabilities are developed.

Tuesday, June 14, 2011

Fake UID Card Make Aadhar Project More Vulnerable

Unique identification project of India Aadhar project of India is a very controversial project. It has been portrayed as one thing and is actually a totally different thing. The truth is that Aadhar project is a project that deserves immediate repeal.

Aadhar project is devoid of any physical and cyber security. Aadhar project is not supported by any legal framework. Aadhar project is also not supported by any data security and data protection laws. Even the privacy laws in India are missing. Aadhar project is also launched without adequate project study, planning and management. The sole purpose of Aadhar project is to strengthen the e-surveillance capabilities of Indian government and its agencies.

Recently, biometric data of about 200 registrants stored on laptop(s) were stolen. Now it has been reported that the Madhya Pradesh Police have seized from a SIMI activist an Aadhaar card with a 12-digit unique identity number bearing someone else’s name.

During a search at Zakir’s rented place in Ratlam, the police recovered an Aadhaar card, a driving licence and fake marksheets. The UID card made in Nanded town of Maharashtra had Zakir’s photograph but bore a different name, Sadique Khan. Apparently, Zakir had married a local woman under a false name and showed her home as his residential address.

This shows how simple it is to get a fake Aadhar number through various sorts of manipulations. However, this would be acceptable to Indian government as it is not interested in the “identity” of the concerned person but in his “biometric details” that can help in the e-surveillance activities.

Irrespective of what name or identity a person holds, his biometric details would always remain the same and Indian government is targeting this aspect.

Wednesday, June 8, 2011

Proposed Draft Right To Privacy Bill 2011 Of India

Right to Privacy is a very important Human Right. For long India ignored this important Civil Liberty despite demands for the same. Finally, Supreme Court of India interpreted Article 21 of the Constitution of India as a “Constitutional Source” of Right to Privacy in India.

Now Right to Privacy is a Fundamental Right in India. However, exercise of a Fundamental Rights is very difficult in India without a support of a “Statutory Right” in this regard. This is the reason why we need to enact a Statutory Law on Right to Privacy in India.

Privacy Rights have become even more important in this Information Era where Privacy of Netizens is in real danger. Indian Government has launched various Projects like Aadhar, NATGRID, CCTNS, Central Monitoring System (CMS), etc that are openly violating the Civil Liberties, including Privacy Rights, of Indians. This has forced the Law Ministry to consider enacting a Privacy Law of India.

Law Ministry has proposed a Right to Privacy Bill of India 2011. Surprisingly, the draft of Right to Privacy Bill of India 2011 has still not been made public so its analysis is not possible. However, this is a good beginning and I welcome this step of Law Minister Veerappa Moily.

I am not sure whether Human Rights in Cyberspace have been considered by the proposed draft Right to Privacy Bill of India 2011. However, Law Ministry must incorporate Privacy Rights in Cyberspace in the proposed Bill to make it effective and meaningful.

Privacy is very important for having peaceful and confidential phone conversations, e-mail communications and other forms of electronic communications. Indian Government has launched various Projects that can openly indulge in Unconstitutional Phone Tapping and Illegal E-Surveillance that also without any “Judicial Scrutiny”.

In the absence of Judicial Scrutiny and Privacy Laws, Indian Citizens are left with no choice but to use “Technological Self Defence Measures” to protect their Privacy Rights, especially in Cyberspace. Even this is not acceptable to Indian Government as it is harassing service providers like Blackberry, Gmail, Skype, etc that are using Encrypted Measures to protect Privacy Rights and to ensure Security. This is just like committing a wrong and then taking advantage of the same to one’s own benefits.

I hope this time we would finally have a Privacy Law of India as in the past as well many times it has been declared that Privacy Law for India would be enacted.

Tuesday, June 7, 2011

CCS Did Not Approve Natgrid Project Absolutely

National Intelligence Grid (NATGRID) Project of India is still in troubled waters as lack of Privacy Laws and Data Protection Laws has put it in doldrums. Media reports are full of rumours that the Cabinet Committee on Security (CCS) has cleared the NATGRID Project. However, this is not true as CCS has just granted the “in principle approval” to NATGRID Project and nothing more.

In the past as well in principle approval was given to NATGRID Project but it was not able to proceed as it lacks the basic Planning, Management and Legal Framework. Even today and after the in principle approval of CCS, NATGRID Project is still without any Legal Framework and Parliamentary Oversight.

Further, the CCS has granted its approval to NATGRID Project for “Limited Purposes” only. CCS has allowed NATGRID to operate for “Limited Phases” only that also where the same can operate within the limits of present Legal Framework. For subsequent stages, NATGRID has “not been approved” till “Suitable Amendments” are made in the Laws of India.

Experts in India have been saying that NATGRID Project of India must comply with Civil Liberties in order to be Legal and Constitutional. Fortunately, the CCS has also “Endorsed” this view and this is the reason why it did not give permission for subsequent and “Final Phases” of NATGRID Project. The CCS has just cleared first two “non-controversial phases” and it is still holding back nod for later phases that require Legal Alterations

The real problem with India is that it is not respecting Human Rights in Cyberspace. We have no E-Surveillance Policy in India and Lawful Interception Law in India is missing. Phone Tapping in India is not done in a Constitutional manner and Laws like Information Technology Act 2000, Official Secrets Act, Indian Telegraph Act 1885, etc are “no more constitutional” and deserve to be repealed.

It is only now that India has started paying attention towards issues like Privacy Laws but even these efforts lack Protection of Civil Liberties in Cyberspace and Protection of Privacy Rights in the Information Era.

NATGRID Project of India would not be finished before Five Years in these circumstances. This is despite the claims of Home Minister P. Chidambaram. If NATGIRD Project is finished before that time period and within the present Legal Framework it means only two things. Either the CCS has “forsaken” the Civil Liberties of India Citizens or Home Ministry is operating the NATGIRD Project “Illegally and Unconstitutionally” and without the knowledge of CCS.

Saturday, June 4, 2011

Data Protection Law In India Is Needed

Every individual loves his or her personal space and in order to enjoy the same he/she must exercise his/her privacy and data protection rights effectively. But what would happen if there are no privacy laws and data protection laws at all to protect such rights? This not only is scary but is also difficult to accept. But in India we have neither dedicated privacy laws nor dedicated data protection laws.

This makes the sensitive information and personal details of Indian citizens “highly vulnerable” to misuse. The Indian government has been promising enactment of privacy laws and data protection laws for long but till now we have none.

This indifference of Indian government towards privacy laws, data security laws and data protection laws is also becoming a headache for government itself. Controversial issues like illegal phone tapping, imposition of Aadhar project, launch of projects like national intelligence grid (Natgrid) and crime and criminal tracking network and systems (CCTNS) without any procedural safeguards, etc requires not only enactment of a dedicated and constitutionally sound privacy law but also putting in place sufficient data protection mechanisms.

India’s intention to use cloud computing and m-governance has further complicated the issue. With the proposed use of cloud computing, software as a service (SaaS) and m-governance by Indian government, more “privacy violations”, “cyber security” and many more “regulatory issues” would arise in future believes techno legal experts of India. These “initiatives” cannot succeed in India in the absence of adequate and strong laws in this regard.

With the proposed draft electronic services delivery bill 2011 (EDS Bill 2011) things would even become more complicated. When most of the public services would be delivered through mandatory e-governance model, a very strong data protection regime and privacy protection regulatory framework would be required.

Now government of India has once more declared that it is going to enact a privacy law for India. However, this seems to be another declaration alone as there is no sign of any Bill in this regard that can be analysed by public at large. In the absence of privacy Bill this statement of India government has no significance.

Further, even if, by some miracle, privacy law is introduced it is doubtful whether it would cater the privacy issues of information age. Only time would tell how much serious is Indian government regarding privacy rights of Indians.

Friday, June 3, 2011

Privacy Rights In India In The Information Age

We have no Dedicated Privacy Laws in India and Data Protection Laws in India. In fact, when it comes to respecting Privacy of Indian Citizens, Government of India tries its level best to avoid the same.

For instance, India has launched Projects like Aadhar, National Intelligence Grid (NATGRID), Crime and Criminal Tracking Network and Systems (CCTNS), National Counter Terrorism Centre (NCTC), Central Monitoring System (CMS), Centre for Communication Security Research and Monitoring (CCSRM), etc. None of them are governed by any Legal Framework and none of them are under Parliamentary Scrutiny.

Further, India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more.

Phone Tapping in India has been in controversies for long. Whether it is Illegal Phone Tapping by Private Individuals or Unaccountable Phone Tapping by Indian Government and its Agencies, Phone Tapping in India has never been smooth.

There is a blessing in disguise in Ratan Tata’s Petition before Supreme Court of India. This is a golden chance for the Supreme Court of India to analyse the “Implementation” of its decision in the PUCL case (Phone Tapping Case). The Supreme Court must “Widen” the scope of Privacy Rights in India not only in the context of Phone Tapping but in an “Overall Manner”. The Supreme Court must formulate and lay down the widest possible “Guidelines” regarding Privacy Protection in India as it has done in the Vishaka’s Case (Guidelines against Sexual Harassment). The Supreme Court has even said that with the Technological Advancement, Privacy is virtually disappearing.

On the front of Legal Framework as well we have no Dedicated and Constitutionally Sound Lawful Interception Law in India. The Indian Telegraph Act, 1885 and other similar Laws are not in “Conformity” with the Constitution of India, especially Fundamental Rights of Indians. Even the Home Ministry of India is considering enactment of a Lawful Interception Law in India.

However, what is more surprising is the fact that the Law Enforcement Agencies and the Intelligence Agencies that indulge in Unconstitutional E-Surveillance and Phone Tapping are themselves Governed by No Law. It is no surprise that the Central Bureau of India (CBI) is also not governed by any Law and it is operating in India Without any Law. It is only now that the Central Bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the Constitutional Validity of the National Investigation Agency Act 2008 is doubtful. Even the Draft Intelligence Services (Powers and Regulations) Bill, 2011 has been recently circulated in the Parliament of India. India must urgently formulate E-Surveillance Policy so that the E-Surveillance conducted by Intelligence Agencies and Law Enforcement Agencies of India can be regulated.

Surprisingly, India has no E-Surveillance Policy and Legal Framework. This is despite the fact that many Indian Projects are so S-surveillance Oriented that they cannot pass the scrutiny provisions of Indian Constitution. Of all these E-Surveillance Projects Aadhar Project of India or Unique Identification Project of India (UID Project of India) is the most “Dangerous Project” that should not be there at the very first place. It is based upon Deceit and Deception and both Indian Government and Unique Identification Authority of India (UIDAI) are Hiding Truth from Indians. There is no Legal Framework, no defined Policies and Guidelines and most importantly no Procedural and Civil Liberty Safeguards.

If this was not enough the sole Cyber Law of India (Information Technology Act 2000) was amended through the Information Technology Amendment Act 2008. The IT Act 2008 made the Cyber Law of India an “Unregulated and Unaccountable” piece of E-Surveillance Legislation. It is now wide open to misuses by Indian Government and its Agencies. Further, the IT Act 2008 also violated various provisions of Indian Constitution and hence is “Unconstitutional” as well. Ideally Cyber law Of India must be repealed as soon as possible.

If Parliament of India has abdicated its duties and Indian Judiciary is watching as a moot spectator, it becomes of paramount importance for Cabinet Committee on Security (CCS), Union Cabinet and Prime Minister’s Office (PMO) to “Disallow” all such Projects till proper Civil Liberty Safeguards and Legal Frameworks are at place.

Thursday, May 19, 2011

Natgrid Project Of India Is Still In Troubled Waters

National intelligence grid (Natgrid) project of India is in trouble from the very beginning. With absolute secrecy and no regard for the civil liberties of Indians, this was definitely a controversial project. Home Minister of India P Chidambaram also did not bother to do the needful. Instead he tried his level best to get Natgrid project of India cleared from the Cabinet Committee on Security (CCS) of India.

However, it seems CCS does not agree with the idea and implementation mechanism of Natgrid project. Lack of privacy safeguards has stalled Natgrid project for the time being and Home Ministry is trying hard to get it functional. Even the term of Raghu Raman, project coordinator of Natgrid, is expiring no 31st May, 2011. Till now there are no positive developments and signs that CCS would approve Natgrid project of Home Ministry. CCS may consider the feasibility of Natgrid project next month.

Meanwhile, a 900 page Detailed Project Report (DPR) has been sent to the CCS members to study the feasibility, implications and requirements of Natgrid project. The DPR claims that Natgrid project would be finally and fully put in place in four phases extending between 24 to 36 months. Extension of the term of Raghu Raman may also be considered.

Many experts in India have been questioning the way Natgrid project has been ignoring civil liberties in India. Further, experts have also been demanding that a balance must be maintained between civil liberties and national security requirements. Although the Natgrid project has been granted in principle clearance yet it failed to satisfy the CCS regarding the civil liberty protection requirements.

Another factor that is going against the Natgrid project is that intelligence agencies and law enforcement agencies of India are practically governed by no law. There is no Parliamentary oversight over these agencies. Even Natgrid project is also not supported b by any legal framework. To make the matter worst we have no privacy, data security and data protection laws in India. Even the cyber law of India has conferred unregulated and unreasonable e-surveillance, Internet censorship and website blocking powers in the hands of Indian government and its agencies.

These are very serious constitutional issues that cannot be taken lightly by Home Ministry, Prime Minister’s Office (PMO) and CCS. The CCS must consider the inputs and suggestions of various techno legal experts of India before clearing Natgrid project.