<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/internet-governance/blog/online-anonymity/search_rss">
  <title>We are anonymous, we are legion</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 2761 to 2775.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/bensonsamuel-an-introduction-to-bitfilm-and-bitcoin-in-bangalore"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/interview-with-suresh-ramasubramanian"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/interview-with-nishant-shah"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/interview-with-anne-cavoukian"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/privacy/privacy_privacyandsexworkers"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/deccan-herald-january-29-2013-an-innovative-concept-comes-to-the-fore"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/vipul-kharbanda-may-8-2019-an-analysis-of-rbi-draft-framework-on-regulatory-sandbox-for-fintech"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/an-analysis-of-the-cloud-act-and-implications-for-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/analysis-of-cases-filed-under-sec-48-it-act-for-adjudication-maharashtra"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/all-night-for-hackers"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/deccan-herald-chetana-divya-vasudev-october-4-2016-an-appening-world"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/events/firstfridayatcis-amutha-arunachalam-stand-shielded-of-digital-rights-may-05"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/business-standard-november-28-2012-nirmalya-behera-amnesty-international-calls-for-review-of-66a-of-it-act"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/amid-unrest-in-the-valley-students-see-a-dark-wall"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/blog/bensonsamuel-an-introduction-to-bitfilm-and-bitcoin-in-bangalore">
    <title>An Introduction to Bitfilm &amp; Bitcoin in Bangalore, India</title>
    <link>https://cis-india.org/internet-governance/blog/bensonsamuel-an-introduction-to-bitfilm-and-bitcoin-in-bangalore</link>
    <description>
        &lt;b&gt;An event at the Centre for Internet &amp; Society (CIS) was organized on January 23, 2013. The all star team at CIS was awesome at organizing this event for Bitcoin. Live streaming, mainstream newspaper coverage and Twitter based Q&amp;A made this the first Bitcoin event in India that leveraged these mediums of information transfer.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;See the &lt;a class="external-link" href="http://www.bensonsamuel.com/?p=108"&gt;blog post published&lt;/a&gt; in Benson's Blog&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Aaron Koenig gave a talk on the creation and use of Bitcoin, and on a  payment system designed for the voting process of the Bitfilm Festival  for Digital Film. Since the year 2000, the Bitfilm Festival has been  showcasing films that use digital technology in a creative and  innovative way. It takes place on the Internet. However, physical  screenings of the films will be held in Bangalore and in Hamburg. Each  of the 59 nominated digital animations has its own Bitcoin account, and  users worldwide may vote by donating Bitcoins to the films they like  anonymously and without any transfer costs. The donated money will be  divided among the most popular films (the films with the most  votes/Bitcoins).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A strong knowledgeable speaker, Aaron brought forward his tremendous knowledge of Bitcoin, Art &amp;amp; Economics.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Twitter based Q&amp;amp;A can be viewed on the Twitter ID's of&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;@pranesh_prakash&lt;/p&gt;
&lt;p&gt;@cis_india&lt;/p&gt;
&lt;p&gt;@bensonsamuel&lt;/p&gt;
&lt;p&gt;&lt;b&gt;The Newspaper Articles where Bitfilm &amp;amp; Bitcoin made their news in India were&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Deccan Herald - &lt;a class="external-link" href="http://bit.ly/U74YsS"&gt;http://bit.ly/U74YsS&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Hindu -&lt;a class="external-link" href="http://goo.gl/YJYni"&gt; http://goo.gl/YJYni&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Bangalore Mirror - &lt;a class="external-link" href="http://bit.ly/XfDRbZ"&gt;http://bit.ly/XfDRbZ&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Bitcoin Resources In India&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Local Exchange - &lt;a class="external-link" href="https://localbitcoins.com/"&gt;LocalBitcoins.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;India Fourms -   &lt;a href="https://bitcointalk.org/index.php?board=89.0"&gt;https://bitcointalk.org/index.php?board=89.0&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a class="external-link" href="http://bit.ly/ZDm4jW"&gt;http://bit.ly/ZDm4jW&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Blogs - &lt;a class="external-link" href="http://www.bensonsamuel.com/"&gt;bensonsamuel.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a class="external-link" href="http://unocoin.com/"&gt;Unocoin.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Services - &lt;a class="external-link" href="http://indiabitcoin.com/"&gt;indiabitcoin.com&lt;/a&gt; - Official Partners of Bitpay USA in India&lt;/p&gt;
&lt;p&gt;Meetup Group - &lt;a class="external-link" href="http://www.meetup.com/Bitcoin-Bangalore-Meetup-Group/"&gt;http://www.meetup.com/Bitcoin-Bangalore-Meetup-Group/&lt;/a&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2 style="text-align: justify; "&gt;Video&lt;/h2&gt;
&lt;p&gt;&lt;iframe frameborder="0" height="315" src="http://www.youtube.com/embed/mOCBjDM6ZiQ" width="400"&gt;&lt;/iframe&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/bensonsamuel-an-introduction-to-bitfilm-and-bitcoin-in-bangalore'&gt;https://cis-india.org/internet-governance/blog/bensonsamuel-an-introduction-to-bitfilm-and-bitcoin-in-bangalore&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>benson</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Video</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2013-03-12T05:58:24Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/interview-with-suresh-ramasubramanian">
    <title>An Interview with Suresh Ramasubramanian </title>
    <link>https://cis-india.org/internet-governance/blog/interview-with-suresh-ramasubramanian</link>
    <description>
        &lt;b&gt;Suresh Ramasubramanian is the ICS Quality Representative - IBM SmartCloud at IBM. We from the Centre for Internet and Society conducted an interview on cybersecurity and issues in the Cloud. &lt;/b&gt;
        &lt;ol&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;You have done a lot of work around cybersecurity and issues in the Cloud. Could you please tell us of your experience in these areas and the challenges facing them?&lt;/b&gt;&lt;br /&gt;a. I have been involved in antispam activism from the late 1990s and have worked in ISP / messaging provider antispam teams since 2001. Since 2005, I expanded my focus to include general cyber security and privacy, having written white papers on spam and botnets for the OECD, ITU and UNDP/APDIP. More recently, have become a M3AAWG special advisor for capacity building and outreach in India.&lt;br /&gt;&lt;br /&gt;In fact capacity building and outreach has been the focus of my career for a long time now. I have been putting relevant stakeholders from ISPs, government and civil society in India in touch with their counterparts around the world, and, at a small level, enabling an international exchange of ideas and information around antispam and security.&lt;br /&gt;&lt;br /&gt;This was a challenge over a decade back when I was a newbie to antispam and it still is. People in India and other emerging economies, with some notable exceptions, are not part of the international communities that have grown in the area of cyber security and privacy.&lt;br /&gt;&lt;br /&gt;There is a prevalent lack of knowledge in this area, which combined with gaps in local law and its enforcement. There is a tendency on the part of online criminals to target emerging and fast growing economies as a rich source of potential victims for various forms of online crime, and sometimes as a safe haven against prosecution.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;In a recent public statement Google said "Cloud users have no legitimate expectation of privacy. Do you agree with this statement?&lt;/b&gt;&lt;br /&gt;a. Let us put it this way. All email received by a cloud or other Internet service provider for its customers is automatically processed and data mined in one form or the other. At one level, this can be done for spam filtering and other security measures that are essential to maintain the security and stability of the service, and to protect users from being targeted by spam, malware and potential account compromises.&lt;br /&gt;&lt;br /&gt;The actual intent of automated data mining and processing should be transparently provided to customers of a service, with a clearly defined privacy policy, and the deployment of such processing, and the “end use” to which data mined from this processing is put, are key to agreeing or disagreeing with such a statement.&lt;br /&gt;&lt;br /&gt;It goes without saying that such processing must stay within the letter, scope and spirit of a company’s privacy policy, and must actually be structured to be respectful of user privacy.&lt;br /&gt;&lt;br /&gt;Especially where mined data is used to provide user advertising or for any other commercial purpose (such as being aggregated and resold), strict adherence to a well written privacy policy and periodic review of this policy and its implementation to examine its compliance to laws in all countries that the company operates in are essential.&lt;br /&gt;&lt;br /&gt;There is way too much noise in the media for me to usefully add any more to this issue and so I will restrict myself to the purely general comments above.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;What ways can be privacy of an individual be compromised on the cloud? What can be done to prevent such instances of compromise?&lt;/b&gt;&lt;br /&gt;a. All the recent headlines about companies mining their own users’ data, and yet more headlines about different countries deploying nationwide or even international lawful intercept and wiretap programs, aside, the single largest threat to individual privacy on the cloud is, and has been for years before the word “cloud” came into general use, the constant targeting of online users by online criminals with a variety of threats including scams, phish campaigns and data / account credential stealing malware.&lt;br /&gt;&lt;br /&gt;Poor device security is another threat – one that becomes even more of a serious problem when the long talked about “internet of things” seems set to become reality, with cars, baby monitors, even Bluetooth enabled toilets, and more dangerously, critical national infrastructure such as power plants and water utilities becoming accessible over the Internet but still running software that is basically insecure and architected with assumptions that date back to an era when there was no conception or need to connect these to the Internet.&lt;br /&gt;&lt;br /&gt;Someone in Bluetooth range with the appropriate android application being able to automatically flush your toilet and even download a list of the dates and times when you last used it is personally embarrassing. Having your bank account broken into because your computer got infected with a virus is even more damaging. Someone able to access a dam’s control panel over the internet and remotely trigger the dam’s gates to open can cause far more catastrophic damage.&lt;br /&gt;&lt;br /&gt;The line between security and privacy, between normal business practice and unacceptable, even illegal behaviour, is sometimes quite thin and in a grey area that may be leveraged to the hilt for commercial and/or national security interests. However, scams, malware, exploits of insecure systems and similar threats are well on the wrong side of the “criminal” spectrum, and are a clear and present danger that cause far more than an embarrassing or personally damaging loss of privacy.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;How is the jurisdiction of the data on the cloud determined?&lt;/b&gt;&lt;br /&gt;This is a surprisingly thorny question. Normally, a company is based in a particular country and has an end user agreement / terms of service that makes its customers / users accept that country’s jurisdiction.&lt;br /&gt;&lt;br /&gt;However, a cloud based provider that does business around the world may, in practice, have to comply to some extent at least, with that country’s local laws – at any rate, in respect to its users who are citizens of that country. And any cloud product sold to a local business or individual by a salesman from the vendor’s branch in the country would possibly fall under a contract executed in the country and therefore, subject to local law.&lt;br /&gt;&lt;br /&gt;The level of compliance for data retention and disclosure in response to legal processes will possibly vary from country to country – ranging from flat refusals to cooperate (especially where any law enforcement request for data are for something that is quite legal in the country the cloud provider is based in) to actual compliance.&lt;br /&gt;&lt;br /&gt;In practice this may also depend on what is at stake for the cloud vendor in complying or refusing to comply with local laws – regardless of what the terms of use policies or contract assert about jurisdiction. The number of users the cloud vendor has in the country, the extent of its local presence in the country, how vulnerable its resident employees and executives are to legal sanctions or punishment.&lt;br /&gt;&lt;br /&gt;In the past, it has been observed that a practical balance [which may be based on business economics as much as it is based on a privacy assessment] may be struck by certain cloud vendors with a global presence, based on the critical mass of users it stands to gain or lose by complying with local law, and the risks it faces if it complies, or conversely, does not comply with local laws – so the decision may be to fight lawsuits or prosecutions on charges of breaking local data privacy laws or not complying with local law enforcement requests for handover of user data in court, or worst case, pulling out of the country altogether.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;Currently, big cloud owners are US corps, yet US courts do not extend the same privacy rights to non US citizens. Is it possible for countries to use the cloud and still protect citizen data from being accessed by foreign governments? Do you think a "National Cloud" is a practical solution?&lt;/b&gt;&lt;br /&gt;a. The “cloud” in this context is just “the internet”, and keeping local data local and within local jurisdiction is possible in theory at any rate. Peering can be used to keep local traffic local instead of having it do a roundtrip through a foreign country and back [where it might or might not be subject to another country’s intercept activities, no comment on that].&lt;br /&gt;&lt;br /&gt;A national cloud demands local infrastructure including bandwidth, datacenters etc. that meet the international standards of most global cloud providers. It then requires cloud based sites that provide an equivalent level of service, functionality and quality to that provided by an international cloud vendor. And then after that, it has to have usable privacy policies and the country needs to have a privacy law and a sizeable amount of practical regulation to bolster the law, a well-defined path for reporting and redress of data breaches. There are a whole lot of other technical and process issues before having a national cloud becomes a reality, and even more before such a reality makes a palpable positive difference to user privacy.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;What audit mechanisms of security and standards exist for Cloud Service Providers and Cloud Data Providers?&lt;/b&gt;&lt;br /&gt;a. Plenty – some specific to the country and the industry sector / kind of data the cloud handles. The Cloud Security Alliance has been working for quite a while on CloudAudit, a framework developed as part of a cross industry effort to unify and automate Assertion, Assessment and Assurance of their infrastructure and service.&lt;br /&gt;&lt;br /&gt;Different standards bodies and government agencies have all come out with their own sets of standards and best practices in this area (this article has a reasonable list - &lt;a class="external-link" href="http://www.esecurityplanet.com/network-security/cloud-security-standards-what-youshould-know.html"&gt;http://www.esecurityplanet.com/network-security/cloud-security-standards-what-youshould-know.html&lt;/a&gt;). Some standards you absolutely have to comply with for legal reasons.&lt;br /&gt;&lt;br /&gt;Compliance reasons aside, a judicious mix of standards, and considerable amounts of adaptation in your process to make those standards work for you and play well together.&lt;br /&gt;&lt;br /&gt;The standards all exist – what varies considerably, and is a major cause of data privacy breaches, are incomplete or ham handed implementations of existing standards, any attempt at “checkbox compliance” to simply implement a set of steps that lead to a required certification, and a lack of continuing initiative to keep the data privacy and securitymomentum going once these standards have been “achieved”, till it is time for the next audit at any rate.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;What do you see as the big challenges for privacy in the cloud in the coming years?&lt;/b&gt;&lt;br /&gt;a. Not very much more than the exact same challenges for privacy in the cloud over the past decade or more. The only difference is that any threat that existed before has always amplified itself because the complexity of systems and the level of technology and computing power available to implement security, and to attempt to breach security, is exponentially higher than ever before – and set to increase as we go further down the line.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;Do you think encryption the answer to the private and public institutions snooping?&lt;/b&gt;&lt;br /&gt;a. Encryption of data at rest and in transit is a key recommendation of any data privacy standard and cloud / enterprise security policy. Companies and users are strongly encouraged to deploy and use strong cryptography for personal protection. But to call it “the answer” is sort of like the tale of the blind men and the elephant.&lt;br /&gt;&lt;br /&gt;There are multiple ways to circumvent encryption – social engineering to trick people into revealing data (which can be mitigated to some extent, or detected if it is tried on a large cross section of your userbase – it is something that security teams do have to watch for), or just plain coercion, which is much tougher to defend against.&lt;br /&gt;&lt;br /&gt;As a very popular &lt;a class="external-link" href="http://xkcd.com/538/"&gt;XKCD&lt;/a&gt; cartoon that has been shared around social media and has been cited in multiple security papers says -&lt;br /&gt;&lt;br /&gt;“A crypto nerd’s imagination”&lt;br /&gt;&lt;br /&gt;“His laptop’s encrypted. Let us build a million dollar cluster to crack it”&lt;br /&gt;“No good! It is 4096 bit RSA”&lt;br /&gt;“Blast, our evil plan is foiled”&lt;br /&gt;&lt;br /&gt;“What would actually happen”&lt;br /&gt;“His laptop’s encrypted. Drug him and hit him with this $5 wrench till he tells us the password”&lt;br /&gt;“Got it”&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;Spam is now consistently used to get people to divulge their personal data or otherwise compromise a persons financial information and perpetuate illegal activity. Can spam be regulated? If so, how?&lt;/b&gt;&lt;br /&gt;a. Spam has been regulated in several countries around the world. The USA has had laws against spam since 2003. So has Australia. Several other countries have laws that specifically target spam or use other statutes in their books to deal with crime (fraud, the sale of counterfeit goods, theft..) that happens to be carried out through the medium of spam.&lt;br /&gt;&lt;br /&gt;The problems here are the usual problems that plague international enforcement of any law at all. Spammers (and worse online criminals including those that actively employ malware) tend to pick jurisdictions to operate in where there are no existing laws on their activities, and generally take the precaution not to target residents of the country that they live in. Others send spam but attempt to, in several cases successfully, skate around loopholes in their country’s antispam laws.&lt;br /&gt;&lt;br /&gt;Still others fully exploit the anonymity that the Internet provides, with privately registered domain names, anonymizing proxy servers (when they are not using botnets of compromised machines), as well as a string of shell companies and complex international routing of revenue from their spam campaigns, to quickly take money offshore to a more permissible jurisdiction.&lt;br /&gt;&lt;br /&gt;Their other advantage is that law enforcement and regulatory bodies are generally short staffed and heavily tasked, so that even a spammer who operates in the open may continue his activities for a very long time before someone manages to prosecute him.&lt;br /&gt;&lt;br /&gt;Some antispam laws allow recipients of spam to sue the spammer in small claims courts – which, like regulatory action, has also previously led to judgements being handed out against spammers and their being fined or possibly imprisoned in case their spam has criminal aspects to it, attracting local computer crime laws rather than being mere violations of civil antispam laws.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;There has been a lot of talk about the use of malware like FinFisher and its ability to compromise national security and individual security. Do you think regulation is needed for this type of malware - and if so what type - export  controls? privacy regulation? Use control?&lt;/b&gt;&lt;br /&gt;a. Malware used by nation states as a part of their surveillance activities is a problem. It is further a problem if such malware is used by nation states that are not even nominally democratic and that have long standing records of human rights violations.&lt;br /&gt;&lt;br /&gt;Regulating or embargoing their sale is not going to help in such cases. One problem is that export controls on such software are not going to be particularly easy and countries that are on software export blacklists routinely manage to find newer and more creative ways to attempt to get around these and try to purchase embargoed software and computing equipment of all kinds.&lt;br /&gt;&lt;br /&gt;Another problem is that such software is not produced just by legitimate vendors of lawful intercept gear. Criminals who write malware that is capable of, say, stealing personal data such as bank account credentials are perfectly capable of writing such software, and there is a thriving underground economy in the sale of malware and of “take” from malware such as personal data, credit cards and bank accounts where any rogue nation state can easily acquire products with an equivalent functionality.&lt;br /&gt;&lt;br /&gt;This is going to apply even if legitimate vendors of such products are subject to strict regulations governing their sale and national laws exist regulating the use of such products. So while there is no reason not to regulate / provide judicial and regulatory oversight of their sale and intended use, it should not be seen as any kind of a solution to this problem.&lt;br /&gt;&lt;br /&gt;User education in privacy and access to secure computing resources is probably going to be the bedrock of any initiative that looks to protect user privacy – a final backstop to any technical / legal or other measure that is taken to protect them.&lt;/li&gt;
&lt;/ol&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/interview-with-suresh-ramasubramanian'&gt;https://cis-india.org/internet-governance/blog/interview-with-suresh-ramasubramanian&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-09-06T09:37:47Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/interview-with-nishant-shah">
    <title>An Interview with Nishant Shah</title>
    <link>https://cis-india.org/news/interview-with-nishant-shah</link>
    <description>
        &lt;b&gt;Jamillah Knowles from BBC Radio interviewed Nishant Shah about Indian Internet issues.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;"I think what we need to do is perhaps say that there is something happening with the internet in India and then maybe we can move on to figuring out what is happening to the anonymous because we had a series of challenges on freedom of speech and expression and online space in the country. Just around the end of 2011, the Information and Broadcasting Minister was summoning social networks like Facebook and MySpace and Google and asking for a regime of pre-censorship so that everything you and I write from what we had to breakfast to which lunch and video we like the most ... that all the info needs to be first reviewed by somebody to make sure that it doesn't commute the larger moral thinkabilities of the nation."&lt;/p&gt;
&lt;p&gt;Listen to the full interview &lt;a href="https://cis-india.org/internet-governance/interview-with-bbc-radio" class="internal-link" title="An Interview with Nishant Shah"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Originally published by &lt;a class="external-link" href="http://www.bbc.co.uk/podcasts/series/pods/all"&gt;Outriders&lt;/a&gt;, a BBC Radio  5 live's programme dedicated to exploring the frontiers of the Web.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/interview-with-nishant-shah'&gt;https://cis-india.org/news/interview-with-nishant-shah&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Interview</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2012-07-06T05:05:36Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm">
    <title>An Interview with Jacob Kohnstamm, Dutch Data Protection Authority and Chairman of the Article 29 Working Party</title>
    <link>https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm</link>
    <description>
        &lt;b&gt;The Centre for Internet and Society interviewed Jacob Kohnstamm, Dutch Data Protection Authority and Chairman of the Article 29 Working Party.&lt;/b&gt;
        &lt;h3 style="text-align: justify; "&gt;What activities and functions does your office undertake?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The activities and functions of the Dutch data protection authority can roughly be divided in 4 different categories: supervisory activities, giving advise on draft legislation, raising awareness and international tasks. &lt;br /&gt;&lt;br /&gt;The Dutch DPA supervises the legislation applicable in the Netherlands with regard to the use of personal data. The most important law is the Dutch Data Protection Act, but the Dutch DPA also supervises for example the Acts governing data processing by police and justice as well as parts of the Telecoms Act. &lt;br /&gt;&lt;br /&gt;The supervisory activities mainly consist of investigating, ex officio, violations of the law, with the focus on violations that are serious, structural and impact a large amount of people. Where necessary, the Dutch DPA can use its sanctioning powers, including imposing a conditional fine, to enforce the law. The Dutch DPA can also decide to examine sector-wide codes of conduct that are submitted to it and provide its views in the form of a formal opinion. &lt;br /&gt;&lt;br /&gt;In addition to investigations, the Dutch DPA advises the government, and sometimes the parliament, on draft legislation related to the processing of personal data. Following the Data Protection Act, the government is obliged to submit both primary and secondary legislation related to data processing to the DPA for advice. &lt;br /&gt;&lt;br /&gt;As regards awareness-raising, next to publishing the results of the investigations, its views on codes of conduct and its advice on legislation, the Dutch DPA also issues guidelines, on its own initiative, explaining legal norms. Via its websites, the Dutch DPA provides more information to both data subjects and controllers on how data can and cannot be processed. Specifically for data subjects, self-empowerment tools – including standard letters to exercise their rights – are made available. Furthermore, they can contact the Dutch DPA daily via a telephone hotline.&lt;br /&gt;&lt;br /&gt;Last but not least, the Dutch DPA participates in several International and European fora, including the Article 29 Working Party of which I am the Chair, the European and the International Conference of data protection and privacy commissioners, of whose Executive Committee I am also the Chair.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What powers does your office have? in your opinion are these sufficient? Which powers have been most useful? If there is a lack, what do you feel is needed?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Dutch DPA has a broad range investigative powers, including the power to order the controller to hand over all relevant information and entering the premises of the controller unannounced. All organisations subjected to the supervision of the Dutch DPA are obligated to cooperate. &lt;br /&gt;&lt;br /&gt;The Dutch DPA also has a considerable range of sanctioning powers, it can for example order the suspension or termination of certain processing operations and can also impose a conditional fine. Currently a bill is before Parliament to provide the Dutch DPA with fining powers as well.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Especially when the bill providing the Dutch DPA with fining powers will be passed, I feel the powers are sufficient, giving us all the necessary enforcement tools to ensure compliance with the law.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;How is your office funded?&lt;/h3&gt;
&lt;p&gt;The Dutch DPA is funded through the government who, together with the parliament, each year determines the budget for the next year. The budget is drafted on the basis of a proposal from the Dutch DPA.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What is the organizational structure of your office and the responsibilities of the key executives?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Dutch DPA consists of a college of commissioners and the supporting Secretariat, itself consisting of 6 departments and headed by the Director. The Dutch DPA has 2 supervision departments, one for the private and one for the public sector, a legal department, a communications department, an international department and a department providing the operational support.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;If India creates a  framework of co-regulation, how would you suggest the overseeing body be structured?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Considering the many differences between India and the Netherlands - and Europe - this is a very hard question to answer. But whatever construction is chosen in India, it is of utmost importance to guarantee the independence of the supervisory authorit(y)(ies), who shall be provided with sufficient and scalable powers to be able to sanction violations.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What legal challenges has your office faced?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The biggest legal challenge we face at the moment is the new European legal framework currently being discussed. It is as yet uncertain whether and when this will enter into force, but it is clear that it will bring new challenges for our office.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What are the main differences between your offices?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Generally, I think that the differences between my office and the UK and Canadian offices mostly stem from our different legal and cultural backgrounds, especially the difference between the common law and codified law systems. &lt;br /&gt;&lt;br /&gt;In addition, the norms and powers differ per supervisory authority. The Dutch DPA for example can enter a building without prior notice, while the ICO, if I understand correctly, can only enter with the consent of the supervised organisation. &lt;br /&gt;&lt;br /&gt;I however prefer to look at the similarities and possibilities to overcome our differences, because I think that we all feel that providing a high level of data protection and ensuring user control are all of our main priorities.&lt;br /&gt;&lt;br /&gt;Naturally, I am very curious to hear from Chrisopher and Chantal as well.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What are the most recent privacy developments for each of your respective offices?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The technological developments of the past decades and the increasing use of smartphones and tablets, have also made privacy developments necessary and have obliged us, as data protection authorities, to consider the rules and norms in this new environment.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What would you broadly recommend for a privacy legislation for India?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In my view the privacy legislation in India should in any case contain the basic principles of the protection of personal data, applicable to both the public and the private sector. Naturally with some exceptions for law enforcement purposes. &lt;br /&gt;&lt;br /&gt;Furthermore, the Indian law should protect the imported data of citizens from other parts of the world as well, including the EU. &lt;br /&gt;&lt;br /&gt;And as mentioned in my answer to question 5, it is of utmost importance that the Indian legislation guarantees the establishment of (a) completely independent supervisory authorit(y)(ies), provided with sufficient sanctioning powers, to supervise compliance with the legislation also of the government, including police and justice.&lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm'&gt;https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-25T04:50:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/interview-with-anne-cavoukian">
    <title>An Interview with Dr. Ann Cavoukian, Information and Privacy Commissioner, Ontario, Canada</title>
    <link>https://cis-india.org/internet-governance/interview-with-anne-cavoukian</link>
    <description>
        &lt;b&gt;Elonnai Hickok interviewed Dr. Ann Cavoukian, Information and Privacy Commissioner, Ontario, Canada. The full interview is reproduced below.&lt;/b&gt;
        
&lt;ol&gt;&lt;li&gt;&lt;strong&gt;When Canada weighed a broad privacy legislation against sectoral legislation, was the decision close?&amp;nbsp; What were the most decisive factors?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Canada’s legislative privacy regime consists of both broad and sectoral privacy legislation.&lt;br /&gt;&lt;br /&gt;Broadly, the use of personal information in Canadian commercial activities is regulated by federal legislation under the &lt;em&gt;&lt;a class="external-link" href="http://www.priv.gc.ca/leg_c/leg_c_p_e.cfm"&gt;Personal Information Protection and Electronic Documents Act (PIPEDA)&lt;/a&gt;&lt;/em&gt;, or by provincial legislation that is “substantially similar” to PIPEDA, or by provincial legislation that is “substantially similar” to &lt;em&gt;PIPEDA&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Sectorally, a prime example is the protection of personal health information under Ontario's &lt;em&gt;&lt;a class="external-link" href="http://www.e-laws.gov.on.ca/html/statutes/english/elaws_statutes_04p03_e.htm"&gt;Personal Health Information Protection Act, 2004 (PHIPA)&lt;/a&gt;&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Regarding the decisive factors surrounding Parliament's passing of a broad private sector privacy statute, you may know that oversight of PIPEDA falls within the jurisdiction of the &lt;a class="external-link" href="http://www.priv.gc.ca/leg_c/leg_c_p_e.cfm"&gt;Office of the Privacy Commissioner of Canada (OPC)&lt;/a&gt;. Accordingly, you may wish to focus your contact with the OPC regarding your question.&amp;nbsp; In addition, &lt;a class="external-link" href="http://www.ic.gc.ca/ic_wp-pa.htm"&gt;Industry Canada&lt;/a&gt; may have some helpful resources regarding the federal government’s decision to enact &lt;em&gt;PIPEDA&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Do you see the different perceptions and cultural understandings of privacy as something to be addressed through legislation?&amp;nbsp; If not, do you think it should be addressed at all?&amp;nbsp; How? &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In an era marked by the widespread use of new information technologies, globalization, and the international flow of personal information, the establishment of global privacy standards is required to effectively protect personal privacy. Fortunately, an international community of data protection commissioners is hard at work contributing to the establishment of a set of global privacy principles. At the annual International Data Protection Commissioners Conference in 2005, Dr. Ann Cavoukian, Information and Privacy Commissioner of Ontario, chaired a Working Group of Data Protection Commissioners that led to the &lt;a class="external-link" href="http://www.ipc.on.ca/images/Resources/gps.pdf"&gt;Creation of a Global Privacy Standard&lt;/a&gt;. Such a principled but flexible approach can also be seen, for example, in the landmark &lt;a class="external-link" href="http://www.privacybydesign.ca/content/uploads/2010/11/pbd-resolution.pdf"&gt;&lt;em&gt;Privacy by Design&lt;/em&gt; (PbD) resolution&lt;/a&gt; adopted unanimously, in 2010, by the international Privacy Authorities and Regulators at the International Conference of Data Protection and Privacy Commissioners in Jerusalem.&lt;a name="fr1" href="#fn1"&gt;[1]&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The resolution recognizes &lt;em&gt;&lt;a class="external-link" href="http://privacybydesign.ca/about/principles/"&gt;PbD&lt;/a&gt;&lt;/em&gt; as an “essential component of fundamental privacy protection” – an International Standard, and urges its adoption in regulations and legislation around the world. Governments that employ this internationally recognized standard will be able to both protect privacy and address local and national priorities.&lt;a name="fr2" href="#fn2"&gt;[2]&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;How does the Canadian model implement self-regulation of privacy standards? How is that balanced against legal enforcement of privacy legislation?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In Canada, as elsewhere, private sector privacy regulation recognizes the dual purposes of protecting the individual's right to privacy, on the one hand, and recognizing the commercial need for access to personal information, on the other.&lt;a name="fr3" href="#fn3"&gt;[3]&lt;/a&gt;&lt;em&gt;&lt;br /&gt;&lt;br /&gt;PIPEDA&lt;/em&gt; furthers these two purposes by tying a set of flexible, technology-neutral privacy principles to a statutory framework of rules governing the collection, use, and disclosure of personal information.&lt;br /&gt;&lt;br /&gt;In particular, Part I of PIPEDA provides the overarching statutory framework, while Schedule I, which was borrowed from the Canadian Standards Association’s Model Code for the Protection of Personal Information, provides flexible, technology-neutral privacy principles.&amp;nbsp; To accomplish the dual purposes that animate PIPEDA and its Schedule, Canada’s Federal Court of Appeal has directed that the interpretation and application of this regulatory framework should be guided by "flexibility, common sense and pragmatism."&lt;a name="fr4" href="#fn4"&gt;[4]&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Such an approach allows organizations to address their own goals and priorities within a privacy protective framework.&amp;nbsp; Moreover, by incorporating the flexible principles of PbD, organizations can "go beyond mere legal compliance with notice, choice, access, security and enforcement requirements."&amp;nbsp; Instead, they can be empowered to design their own responsive approaches to risk management and privacy-related innovation, within the context of the relevant regulatory framework.&amp;nbsp; This approach allows organizations to develop doubly-enabling, positive-sum solutions that are win/win in nature and appropriate given the size and nature of the organization, the personal information it manages, and the range of risks, opportunities, and solutions available.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Does Canada favor private forms of redress or agency/state enforcement to prevent and remedy privacy violations?&amp;nbsp; In what circumstances is one more effective than the other?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Canadian privacy legislation includes both state enforcement and private forms of redress; neither is necessarily favoured.&lt;br /&gt;&lt;br /&gt;For example, under &lt;em&gt;PHIPA&lt;/em&gt;, the Attorney General may impose fines of up to $50,000 for individuals and $250,000 for corporations who are found to be in breach of &lt;em&gt;PHIPA&lt;/em&gt;. Further, our office has broad powers of investigation and can directly order a custodian to comply with its obligations.&amp;nbsp; An individual affected by a Commissioner’s final &lt;em&gt;PHIPA &lt;/em&gt;order may commence a proceeding in the Ontario Superior Court for damages for actual harm suffered.&lt;br /&gt;&lt;br /&gt;Another example is under &lt;em&gt;PIPEDA&lt;/em&gt; where contravention can result in fines of up to $100,000 depending upon the type and severity of the matter. Further, the federal privacy Commissioner has powers to investigate and report findings with respect to privacy complaints.&amp;nbsp; Following the release of the Commissioner’s report, a complainant may apply to the Federal Court to seek remedies that include damages and an order requiring an organization to correct its practices.&lt;br /&gt;&lt;br /&gt;Generally, fines and other penalties imposed on individuals and corporations by the government are effective in deterring certain actions and protecting the public from a variety of harmful practices.&amp;nbsp; On the other hand, a private right of action may be effective when a particular individual is harmed by an individual or corporation and is seeking damages to compensate or redress that particular harm.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;What types of privacy violations are the most common? How have these been addressed?&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;The most common types of privacy violations are inadvertent disclosures or privacy breaches of personal information, including personal health information.&amp;nbsp; In particular, these violations usually stem from the improper retention, transfer and disclosure of personal information.&lt;br /&gt;&lt;br /&gt;Privacy breaches are addressed in a variety of ways, depending on the type and amount of information disclosed.&amp;nbsp; For example, under &lt;em&gt;PHIPA&lt;/em&gt;, if health information is stolen, lost, or accessed by unauthorized persons, the health information custodian must notify the affected individual at the first reasonable opportunity and should take immediate steps to contain the breach.&amp;nbsp; Further, the Commissioner may order the health information custodian to take corrective action such as requiring the custodian to implement a certain procedure when handling personal health information or conduct privacy training.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;What forms of privacy education has Canada pursued?&amp;nbsp; What audiences have been targeted? Which efforts have been the most successful and why?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Canadian institutions and organizations have pursued a wide variety of privacy education initiatives including programs that award professional designations (e.g. &lt;a class="external-link" href="https://www.privacyassociation.org/certification/"&gt;IAPP&lt;/a&gt;, &lt;a class="external-link" href="http://capapa.org/"&gt;CAPAPA&lt;/a&gt;, &lt;a class="external-link" href="http://www.ipsi.utoronto.ca/"&gt;University of Toronto Identity, Privacy and Security Initiative&lt;/a&gt;, &lt;a class="external-link" href="http://www.extension.ualberta.ca/study/government-studies/iapp/"&gt;University of Alberta Program&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Our Office has led a wide variety of educational initiatives to spread the word about privacy protection and freedom of information under our Ontario legislation. We have focused on a variety of audiences from the general public to individuals who deal with privacy and access to information issues as part of their daily professional role.&lt;br /&gt;&lt;br /&gt;Initiatives include frequent contact between our Information Officers and the public, and dozens of marketing materials geared to providing guidance (e.g. “&lt;a class="external-link" href="http://www.ipc.on.ca/images/Resources/circle-care.pdf"&gt;Circle of Care: Sharing of Personal Health Information for Health-Care purposes&lt;/a&gt;”, “&lt;a class="external-link" href="http://www.ipc.on.ca/images/Resources/hprivbreach-e.pdf"&gt;What to do When Faced With a Privacy Breach: Guidelines for the Health Sector&lt;/a&gt;”). Our Office has developed Educational Resource Guides (&lt;a class="external-link" href="http://www.ipc.on.ca/english/Resources/Educational-Material/Educational-Material-Summary/?id=183"&gt;Grade 5&lt;/a&gt;, &lt;a class="external-link" href="http://www.ipc.on.ca/english/Resources/Educational-Material/Educational-Material-Summary/?id=184"&gt;Grade 10&lt;/a&gt;, &lt;a class="external-link" href="http://www.ipc.on.ca/english/Resources/Educational-Material/Educational-Material-Summary/?id=1110"&gt;Grades 11/12&lt;/a&gt;), which have been added to the formal Ontario curriculum to help teachers educate about privacy protection. Commissioner Cavoukian participates in extensive presentations and speeches at numerous conferences and events. As well, representatives from our Office reach out into the community to educate about our offerings and role (hospitals, conference, community events etc.). In addition, to educate Ontarians about privacy protection, the IPC also allots significant resources to many marketing initiatives including a &lt;a class="external-link" href="http://www.ipc.on.ca/english/Resources/Newsletters/Newsletters-Summary/?id=1100"&gt;quarterly e-newsletter&lt;/a&gt;, video production, and social media outreach. Most recently, we circulated an &lt;a class="external-link" href="http://www.ipc.on.ca/english/Resources/IPC-Corporate/IPC-Corporate-Summary/?id=482"&gt;online tool kit &lt;/a&gt;(available via USB as well), to assist new Freedom of Information and Protection of Privacy Co-ordinators in the public sector. Most of our resources are available in English and French.&lt;br /&gt;&lt;br /&gt;Without a doubt, the IPC’s most successful educational effort thus far is in the area of PbD, now an international standard. This Ontario-made solution was created by Commissioner Cavoukian who has led the IPC in partnering with global stalwarts such as IBM, Intel, and Nokia to advance Privacy by Design, and to foster innovation in many fields, including &lt;a class="external-link" href="http://www.privacybydesign.ca/content/uploads/2011/02/pbd-olg-facial-recog.pdf"&gt;biometrics&lt;/a&gt;, the &lt;a class="external-link" href="http://www.privacybydesign.ca/content/uploads/2011/02/pbd-ont-smartgrid-casestudy.pdf"&gt;Smart Grid&lt;/a&gt; and even &lt;a class="external-link" href="http://www.ipc.on.ca/images/Resources/AVAwhite6.pdf"&gt;Targeted Advertising&lt;/a&gt;. &lt;em&gt;Privacy by Design&lt;/em&gt; knows no boundaries and makes sense for everyone — especially businesses. Not only is it cheaper to build in privacy before a breach occurs, it is also a compelling way to win the trust of clients and build a successful brand.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;What [have] proven to be [the main] challenges or obstacles to protecting privacy in Canada?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The most common obstacle to protecting privacy is that key stakeholders hold on to misconceptions about privacy.&amp;nbsp; &lt;br /&gt;Misconception #1 – Privacy is dead or obsolete.&amp;nbsp; &lt;br /&gt;Misconception #2 – Privacy stops us from performing our job.&lt;br /&gt;Misconception #3 – With the massive growth of online social media, you cannot have both widespread connectivity and privacy.&lt;br /&gt;&lt;br /&gt;Not only do these misconceptions contradict each other, they are both dead wrong!&lt;br /&gt;&lt;br /&gt;Privacy is alive and well and more relevant than ever. Consider, for example, that the same technologies that serve to threaten privacy may also be enlisted to support it.&amp;nbsp; Properly understood, privacy is becoming increasingly critical to achieving success in the new economy.&amp;nbsp; In this environment, PbD offers a principled, flexible, and technology-neutral vehicle for engaging with privacy issues, and for resolving them in ways that support multiple outcomes in a full functionality, positive-sum, win-win scenario.&lt;br /&gt;&lt;br /&gt;It does so by ensuring that privacy is built in right up front, directly into the design specifications and architecture of new systems and processes.&amp;nbsp; &lt;em&gt;&lt;br /&gt;&lt;br /&gt;PbD&lt;/em&gt; seeks to accommodate all legitimate interests and objectives in a positive-sum “win-win” manner, not through a dated, zero-sum approach, where unnecessary trade-offs are made. PbD avoids the pretense of false dichotomies or unnecessary trade-offs, such as privacy vs. security, demonstrating that it is possible to have both. For more on PbD, go to &lt;a class="external-link" href="http://www.privacybydesign.ca/"&gt;www.privacybydesign.ca&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;h3&gt;Dr. Ann Cavoukian, Ph.D., Information and Privacy Commissioner, Ontario, Canada&lt;/h3&gt;
&lt;p&gt;Dr. Ann Cavoukian is recognized as one of the leading privacy experts in the world. Noted for her seminal work on Privacy Enhancing Technologies (PETs) in 1995, her concept of Privacy by Design seeks to proactively embed privacy into the design specifications of information technology and accountable business practices, thereby achieving the strongest protection possible. In October, 2010, regulators from around the world gathered at the annual assembly of International Data Protection and Privacy Commissioners in Jerusalem, Israel, and unanimously passed a landmark Resolution recognizing &lt;em&gt;Privacy by Design&lt;/em&gt; as an essential component of fundamental privacy protection. This was followed by the U.S. Federal Trade Commission’s inclusion of &lt;em&gt;Privacy by Design&lt;/em&gt; as one of its three recommended practices for protecting online privacy – a major validation of its significance.&lt;/p&gt;
&lt;p&gt;An avowed believer in the role that technology can play in the protection of privacy, Dr. Cavoukian’s leadership has seen her office develop a number of tools and procedures to ensure that privacy is strongly protected, not only in Canada, but around the world. She has been involved in numerous international committees focused on privacy, security, technology and business, and endeavours to focus on strengthening consumer confidence and trust in emerging technology applications.&lt;/p&gt;
&lt;p&gt;Dr. Cavoukian serves as the Chair of the Identity, Privacy and Security Institute at the University of Toronto, Canada. She is also a member of several Boards including, the European Biometrics Forum, Future of Privacy Forum, RIM Council, and has been conferred a Distinguished Fellow of the Ponemon Institute. Dr. Cavoukian was honoured with the prestigious &lt;em&gt;Kristian Beckman Award&lt;/em&gt; in 2011 for her pioneering work on &lt;em&gt;Privacy by Design&lt;/em&gt; and privacy protection in modern international environments. In the same year, Dr. Cavoukian was also named by&lt;em&gt; Intelligent Utility &lt;/em&gt;Magazine as one of the Top 11 Movers and Shakers for the Global Smart Grid industry, received the SC Canada Privacy Professional of the Year Award and was honoured by the University of Alberta Information Access and Protection of Privacy Program for her positive contribution to the field of privacy. Most recently in November 2011, Dr. Cavoukian was ranked by Women of Influence Inc. as one of the top 25 Women of Influence recognizing her contribution to the Canadian and global economy.&amp;nbsp; This award follows her recognition in 2007 by the Women’s Executive Network as one of the Top 100 Most Powerful Women in Canada.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;strong&gt;Notes&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn1" href="#fr1"&gt;1&lt;/a&gt;].Information and Privacy Commissioner/Ontario, Landmark Resolution passed to preserve the Future of Privacy, &lt;a class="external-link" href="http://www.ipc.on.ca/images/Resources/2010-10-29-Resolution-e_1.pdf"&gt;http://www.ipc.on.ca/images/Resources/2010-10-29-Resolution-e_1.pdf&lt;/a&gt;&lt;br /&gt;[&lt;a name="fn2" href="#fr2"&gt;2&lt;/a&gt;].For a discussion of how governments might employ an PbD approach to privacy regulation, see Commissioner Cavoukian’s White Paper, Privacy by Design in Law, Policy, and Practice available at:&lt;br /&gt;&lt;a class="external-link" href="http://www.ipc.on.ca/english/Resources/Discussion-Papers/Discussion-Papers-Summary/?id=1095"&gt;http://www.ipc.on.ca/english/Resources/Discussion-Papers/Discussion-Papers-Summary/?id=1095&lt;/a&gt;&lt;br /&gt;[&lt;a name="fn3" href="#fr3"&gt;3&lt;/a&gt;].See the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (Can.), &lt;a class="external-link" href="http://www.canlii.org/en/ca/laws/stat/sc-2000-c-5/latest/sc-2000-c-5.html"&gt;http://www.canlii.org/en/ca/laws/stat/sc-2000-c-5/latest/sc-2000-c-5.html&lt;/a&gt;.&lt;br /&gt;[&lt;a name="fn4" href="#fr4"&gt;4&lt;/a&gt;].&lt;em&gt;Englander v. Telus Communications Inc.&lt;/em&gt;, 2004 FCA 387, Locus Para. 38-46.&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/interview-with-anne-cavoukian'&gt;https://cis-india.org/internet-governance/interview-with-anne-cavoukian&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2011-12-03T01:26:04Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/privacy/privacy_privacyandsexworkers">
    <title> An Interview with Activist Shubha Chacko: Privacy and Sex Workers</title>
    <link>https://cis-india.org/internet-governance/blog/privacy/privacy_privacyandsexworkers</link>
    <description>
        &lt;b&gt;On February 20th I had the opportunity to speak with Shubha Chacko on privacy and sex workers. Ms. Chacko is an activist who  works for Aneka, an NGO based in Bangalore, which fights for the human rights of sexual minorities. In my interview with Ms. Chacko I tried to understand how privacy impacts the lives of sex workers in India. The below is an account of our conversation. &lt;/b&gt;
        
&lt;h3&gt;Introduction&lt;br /&gt;&lt;/h3&gt;
&lt;p&gt;In our research we have been exploring where and how privacy is found in different areas of Indian society, law, and culture. As part of our research we have been holding public conferences across the country to raise awareness and gather opinions around privacy. One area that was discussed in the public conference in Bangalore was the privacy of sex workers. Shubha Chacko, who is from&amp;nbsp; Aneka - an NGO located in Bangalore which fights for the human rights of sexual minorities, made a presentation that focused on the privacy challenges that sex workers in India face. In our interview Ms. Chacko pointed out many misconceptions that society holds about sex workers’ lives. She also detailed the challenges of stigma and discrimination that sex workers face, and described the precarious position that sex workers find themselves in as their work is constantly being pushed out of the public sphere by the law and society. I later interviewed Ms. Chacko to follow up on her presentation on privacy and sex workers. During the interview I had the opportunity to speak with both Ms. Chacko and a board member from the Karnataka Sex Workers Union. The following is meant to provide a perspective on how and in what ways society, law, media and tradition invades the privacy of sex workers. Though the piece is focused on the lives of sex workers, many of the issues raised are not limited to only sex workers, but characterize other marginalized communities as well.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;When I began the interview with Ms. Chacko I was hoping to do a piece that looked at the different elements of a sex worker’s life, and identified the points at which their privacy was invaded – such as in contacting a client, going to the doctors, etc. After I began my interview only, I realized how privacy impacts sex workers is much more complicated than a life cycle analysis. Among other things, privacy issues for sex workers prompt questions challenging social definitions of public and private, having the right to an identity and a recognized profession, and having the autonomy to control decisions about oneself.&lt;/p&gt;
&lt;h3&gt;Basic Facts and Background Information:&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;Karnataka has been found to have 85,000 sex workers, and India has an estimated 2 million female sex workers [1] &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Sex work is not against the law in India, but any commercialized aspect of the trade is prohibited – including running a brothel or soliciting a client. &lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;Sex work is a multi-faceted profession with many positive and negative complexities that are rarely known to the public.&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Understanding the Challenge of the Public and the Private&lt;/h3&gt;
&lt;p&gt;My interview with Ms. Chacko began with my seeking an understanding of the challenges that traditional notions of the public sphere and the private sphere pose for sex workers. Ms. Chacko explained that to understand how privacy impacts the life of a sex worker, it is important to first understand that sex workers by profession confront and question traditional conceptions of the public and the private. Sex and everything associated with it is seen as something that is to be kept only in the private sphere. The work of sex workers brings sex into the public sphere, and thus the workers are seen as being public women not entitled to privacy, because they stand on street corners and conduct their work in the public. This notion that sex workers are public women without a right to privacy shows through in the way they are treated by the media, the police, NGOs,&amp;nbsp; and researchers. An example of this tension and society’s response can be seen in the recent elections. On April 6th, a Times of India news article reported that the election commission will be setting up “special booths” for sex workers to vote in because “while the sex workers had been waiting in queues to cast their votes, common people were not comfortable with that”[2]&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;What is the Challenge of the Public and the Private? &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“It starts with a conception of issues around privacy vis-à-vis sex workers. The general perception is that sex workers are considered “public women”, because they are considered available to the public and because they sell sexual services on the streets (and are seen in contrast to the “good” woman who is confined to the private world of the home This then leads people to assume that then sex workers have are not entitled to privacy. Also sex workers are forced to reckon with issues of sex and sexuality, and if you talk about issues of sexuality - issues that are considered private are forced into the public domain, so sex workers by their presence force these issues into the public domain. So notions of privacy become complicated by this challenge of what is public and private, because the sex workers’ presence brings into the public domain what is private.”&lt;/p&gt;
&lt;br /&gt;&lt;strong&gt;How does this tension of the public and the private translate into privacy violations? &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;
&lt;p&gt;"Due to the stigma around sex work all rights of sex workers are seriously compromised; with impunity. Thus, privacy is a threshold issue.&lt;/p&gt;
&lt;p&gt;The violation of privacy happens at various points, for example the way the media deals with them – publishing their photographs, outing them without their consent, talking about them without their consent. There are the police who are often engaged in so called “rescue and rehabilitation” work, but in the process of rescuing the sex workers, disregard the harmful impacts that compromising their right to privacy will do to them. The HIV prevention intervention programs that are in place now that target sex workers (along with other ‘high risk groups”) also erode their right to confidentiality. Besides intimate details of their lives being recorded, their address and other coordinates are noted.&amp;nbsp; This information along with other sensitive information including&amp;nbsp; their HIV status, is often accessible to a host of people and is a potential threat to their privacy and anonymity. Researchers and NGOs too often quiz sex workers about a range of intimate details about their lives with little sensitivity and expect them to be totally candid.&amp;nbsp; These interviews also raise questions that relate to privacy."&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Stigma, Discrimination, and Identity&lt;/h3&gt;
&lt;p&gt;Ms. Chacko also spoke about how the stigma and discrimination that sex workers face invades their privacy. Society views sex workers in one light – as immoral women. This stigma is attached to them permanently and is a source of violence and discrimination in the home, from the state, and from society. The sex workers’ right to anonymity and identity is also restricted because of the stigma attached to their work. Sex workers do not have the ability to control information about themselves, and they face challenges in obtaining official documents like a PAN card or a passport. This stigma and its consequences impedes sex workers from functioning comfortably in society and creates a difficult tension for sex workers to live with. Society denies the presence of sex workers, and police patrol parks and other public areas chasing away individuals whom they believe to be sex workers.&amp;nbsp; The increased passivisation of public spaces – parks, (for example) and the over gentrification of the neighborhoods squeeze them out&lt;/p&gt;
&lt;p&gt;In New York, one way that sex workers have overcome this constant and sometimes violent confrontation with society is through the use of mobile phones. Sex workers will contact clients only through mobile phones. This allows them to find their clients in private and anonymous ways, and it eliminates the need of a pimp or other type of ring leader. When I asked Ms. Chacko if sex workers are using this same technique in India, she recognized that they are, but said that it is not a yet widely practiced - especially among women in rural areas.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;How Restricting is the Stigma? &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“Huge - hardly ever does a person’s entire identity get conflated with her with occupation or livelihood option; the way it does with sex workers. … I mean, for example, if you go to a movie - people would not say; oh, look, there is a researcher come to see a movie - people would call you by name, but if a sex worker goes to a movie they always say: oh, look, there is a sex worker. There is only one side to her identity according to society. And everyone wants to know the same thing - How did they get into sex work. There is an excessive interest in this aspect alone (and generally they are seeking simple answers)&amp;nbsp; - they never ask other questions about them as a person, only about them as a sex worker. Thus, real issues of violence and exploitation are never dealt with”.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;HIV Initiatives, Medical Counseling , and Privacy&lt;/h3&gt;
&lt;p&gt; Medical consultations, especially those related to HIV/AIDS, in many ways violate the privacy of sex workers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;HIV Initiatives&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;HIV initiatives run by the Government are often invasive and function off of privacy-violating techniques. The government runs many HIV initiatives where sex workers are employed to be “peer educators.” A peer educator’s job is to spread awareness about HIV, distribute condoms, and bring sex workers for HIV testing. The privacy and anonymity of peer educators is compromised in the job title itself. Everyone in the community knows that to be a peer educator, one must also be a sex worker. Thus, if a person is a peer educator or with a peer educator, she is immediately outed and identified as a sex worker. Furthermore, HIV testing is compulsory for sex workers, though on paper it looks as though it is a choice. Because there are quotas that must be filled, sex workers often go through HIV testing without full consent.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;How do Government HIV Initiatives Violate Privacy?&lt;/strong&gt; &lt;br /&gt;
&lt;p&gt;“The whole HIV intervention itself violates sex workers’ privacy. Both in the sense that people get jobs as peer educators and they have to carry condoms around and talk to other sex workers, and everyone thinks that if you are a peer educator then you are a sex worker, and there is no protection for these people even though it is sponsored by the state government.”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Line Listing &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The HIV programs and testing centers also violate the privacy of sex workers. The clinics have a system known as line listing, which is meant to ensure that there are no duplications in data. In order to ensure this they collect identifying information from sex workers including address and phone number. The information is not protected and is easily accessible to whoever wishes to see it.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Line Listing and Privacy &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“HIV programs have a process called line listing, which is to ensure that there is no duplication. So they take all your facts from you, and from that a sex workers address and such go out, and it’s put out with no safeguards.”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;HIV Counselors and Doctors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;HIV counselors also violate the privacy of sex workers. Though a patient’s HIV status is only supposed to be known to the counselor at the testing clinic and the lab technician, it often becomes the case that HIV results are widely shared. As per protocol, doctors and counselors must follow up with sex workers every three months if a sex worker is HIV negative. This is to ensure that they are still HIV negative, and to provide them treatment at the soonest if they do contract the disease. To carry out this follow-up work, counselors keep a list of patients whom they have seen. This list is supposed to be confidential, but other personnel in the hospital are assigned to do the follow-up phone calls, and thus the list is in fact easily accessible. If a person’s name disappears from the list, it is obvious that the person is now HIV positive, and that person’s privacy is violated and her status known.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;How does HIV Counseling compromise Privacy? &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“…only the counselor and the lab technician is supposed to know about it, but it turns out a whole number of people know about it, because of follow up. The counselor is supposed to follow up on the list with people every three months for further testing, but if you are positive then you do not need to follow up. Plus, these results are shared with everyone. Because of the stigma attached to HIV there is a need for privacy to be protected, so confidentiality is routinely violated.”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;Media and Research&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Media &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Media was another area of contention that Ms.Chacko pointed out. Though the media plays an important role as being a channel for the voice of sex workers, it can also be intrusive on the sex worker by publishing stories without their consent, or reporting in ways that can be misconstrued. Through their coverage, the media can also deepen the stigma against sex workers and place them under an unwanted social spotlight. For example, a news article in The Hindu spoke about the World Cup bringing an “off day” for sex workers.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“With hoards of supporters glued to their television screens for the World Cup cricket final between India and Sri Lanka on Saturday, sex workers are anticipating a slow day, but they are not disappointed. It is a rare weekend for them with their children. The prospects of fewer clients coming in only buoyed the enthusiasm of the women in Sonagachi, the largest red-light area in the city…”[3]&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The media is also often a part of raids by cover stories of brothels being uncovered, and in doing so expose the lives of sex workers, often printing sensitive information, including addresses, while portraying the sex workers as victims. The media, along with NGOs and the police will conduct raids that severely violate the privacy of sex workers. For example, in an Express India article a raid was described that took place in Pune with NGOs and the police in which sex workers were dragged out, beaten, and molested by the police against their will [4].&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;How does the media violate the privacy of sex workers? &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“The media conducts raids, and so do NGOs in an attempt to rescue them. Once they are rescued and taken back with police escorts to their village, the whole village knows that she was in sex work, and then her privacy is violated because she was publicly returned. My problem is not about them being rescued, but they need to have consent from the person. If a person wants to do sex work – this decision needs to be respected. The media is difficult because you don’t want to ask for a ban, so we don’t ask for banning, but we do put pressure on the media to be more responsible in their reporting.”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Research/Films &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Ms. Chacko also spoke about how research often violates the privacy of sex workers, in ways that range from the words that are used to describe sex workers to the one-sided victim story that is too often used to describe the lives of sex workers, to the methods researchers use to find their facts. Thus, perhaps without meaning to, research can de-legitimatize the work that sex workers do, and can work to increase the amount of violence or abuse that they are exposed to.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Research and Privacy &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“Researchers who are writing a report on sex workers - land up in some village and end up violating their privacy as everyone in the village wants to know why the researchers came. The researchers also ask invasive questions. They want to know details about the sex workers’ lives: what kind of sex they have and with whom? What do they experience with their clients? What is their relationship with their partners? What is the status of their relationship.? They do not have a sense of whether the workers will want to talk about their lives or not…Some people make films and some make them in extremely exploitative ways. Films are also often incorrect and invasive of privacy in that way as well.”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;The Role of a Privacy Legislation&lt;/h3&gt;
&lt;p&gt;In our research, we are looking at how a privacy legislation could help remedy the challenges to privacy that different people face in society; or ,if a privacy legislation cannot offer a solution, if there are other ways in which a legislation or society can offer solutions. When I asked Ms. Chacko if a privacy legislation or the right to privacy could improve the lives of sex workers, she was not certain if a privacy legislation would make a difference directly, and thought it might in fact overlook sex workers because currently they are seen in society as immoral women that are not to be afforded the right to privacy. In fact, it is the law and enforcers of the law itself that is invading their privacy. For example, in a study done by the World Health Organization it was found that in India 70 per cent of sex workers in a survey reported being beaten by the police, and more than 80 per cent had been arrested without evidence [5]. Thus, before a right to privacy can apply to sex workers, sex work itself must be decriminalized and recognized as a legitimate profession worthy of labor rights and other rights. Furthermore the debate around sex work needs to move away from the traditional dialogue of who is having sex and who is not to one that looks at what rights should be protected for every person. At that point perhaps a law which protects dignity and regulates the use of information could be useful. On another note, the UID (the Unique Identification Project) could be a potential benefit for sex workers as it would serve as identity that would give only a yes or no response at the time of a transaction.&amp;nbsp;&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Could a Privacy Legislation help? &lt;/strong&gt;&lt;br /&gt;
&lt;p&gt;“Some of the privacy is violated by the raids that happen by the police. So those raids are problematic. What kind of laws would help? One would be to decriminalize sex work itself and also work with society to gain understanding and perspective. Because now people think: they are immoral women ,so what privacy do they deserve? The sexual debate should not be about who is having sex and who is not, but about who has the power…”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;The Current Law&lt;/h3&gt;
&lt;p&gt;In India, the Immoral Trafficking prevention Act ( ITPA) is the law that governs sex work. The ITPA does not make prostitution illegal, but instead tries to target the commercialized aspects of the trade such as brothel keeping, pimping, and soliciting. Though the law does not attack the sex workers as individuals, and its stated purpose is to prevent the trafficking of sex workers, the law has become a tool of harassment and abuse by law enforcement agencies. Sections 5A, 5B, 5C, which pertain to trafficking are the most troublesome, because the clauses do not distinguish between trafficking and sex work, but instead defines them as the same[6]. Thus, the new definitions of prostitution and trafficking leave room for reading all sex work as within the meaning of trafficking, and thus criminalizing sex work by defacto.[7] In addition, under the new Section 5C, clients visiting or found in a brothel will face imprisonment and/or fines [8]. Penalization of clients is a significant modification to the the ITPA, which formally targeted 'third parties' profiting from prostitution and not sex workers or clients themselves [9]. Sex workers have fought for a long time to overturn the ITPA. In June 2008, sex workers went on a hunger strike in the hopes of forcing the bill to be discarded [10]. In 2010 sex workers demonstrated against the amendment of the ITPA that would hold the clients of sex workers liable. Despite their protests and demands for their occupation to be treated equally, the Indian courts are slow to move forward and recognize sex work as a dignified profession. “A woman is compelled to indulge in prostitution not for pleasure but because of abject poverty,” the court said last month. “If such woman is granted opportunity to avail some technical or vocational training, she would be able to earn her livelihood by such vocational training and skill instead of selling her body.” The court has also promised to initiate a program in May for vocational training of sex workers [11]. Unfortunately, vocational training fails to address the actual issues and violations that sex workers face – a fact that was demonstrated by one sex worker’s saying: “If we can’t solicit clients without getting arrested, we will naturally rely on pimps to carry on our trade…What we need are practical measures that free us from exploitation created by the law itself.”&lt;/p&gt;
&lt;h3&gt;Solutions&lt;/h3&gt;
&lt;p&gt;One of the most impactful source of aid for sex workers currently is the sex workers union. I had the opportunity to speak with a member from the board of the Karnataka Sex Workers &lt;br /&gt;union. She spoke about the challenges that sex workers face and how the Union provides assistance to the sex workers. The union helps them obtain benefits, helps with enrolling their children in schools, and answers questions that they would not be able to seek legal or other assistance on. The union is a confidential and safe space for sex workers to function in society. The person interviewed feels as though the information about herself that should be kept confidential is: her medical information, her clients, where she meets her clients, and information about her family. Ms. Chacko also spoke about the positives that an identity scheme like the UID could have on sex workers, because the transactions would be done through a yes/ no response, and no one will be denied a UID number. Most importantly, Ms. Chacko stressed that it is important to recognize sex work as a legitimate profession,and focus on the actual problems, rather than limiting the debate to stigmas around sex. The interview with Ms. Chacko demonstrated that protection of sex workers’ and sexual minorities’ privacy cannot be addressed simply by a law, but must be embodied by an ethos and a culture before that law is meaningful.&lt;/p&gt;
&lt;h3&gt;Bibliography&amp;nbsp;&lt;/h3&gt;
&lt;ol&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.dnaindia.com/bangalore/report_karnataka-sex-workers-want-right-to-work_1517602"&gt;http://www.dnaindia.com/bangalore/report_karnataka-sex-workers-want-right-to-work_1517602&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://timesofindia.indiatimes.com/home/specials/assembly-elections-2011/west-bengal/Special-booth-for-sex-workers/articleshow/7880039.cms"&gt;http://timesofindia.indiatimes.com/home/specials/assembly-elections-2011/west-bengal/Special-booth-for-sex-workers/articleshow/7880039.cms&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.thehindu.com/news/article1594609.ece"&gt;http://www.thehindu.com/news/article1594609.ece&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.expressindia.com/latest-news/sex-workers-allege-excesses-in-police-raid-to-submit-evidence-to-commissioner/739326/"&gt;http://www.expressindia.com/latest-news/sex-workers-allege-excesses-in-police-raid-to-submit-evidence-to-commissioner/739326/&amp;nbsp;&amp;nbsp;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.who.int/gender/documents/sexworkers.pdfhttp://ncpcr.gov.in/Acts/Immoral_Traffic_Prevention_Act_%28ITPA%29_1956.pdf"&gt;http://www.who.int/gender/documents/sexworkers.pdfhttp://ncpcr.gov.in/Acts/Immoral_Traffic_Prevention_Act_%28ITPA%29_1956.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.who.int/gender/documents/sexworkers.pdfhttp://ncpcr.gov.in/Acts/Immoral_Traffic_Prevention_Act_%28ITPA%29_1956.pdf"&gt;http://ncpcr.gov.i /Acts/Immoral_Traffic_Prevention_Act_%28ITPA%29_1956.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://cflr.org/ITPA%20Amendment%20bill.htm"&gt;http://cflr.org/ITPA%20Amendment%20bill.htm&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.prsindia.org/uploads/media/1167469313/1167469313_immoral_traffic_prevention_amendment_bill2006.pdf"&gt;http://www.prsindia.org/uploads/media/1167469313/1167469313_immoral_traffic_prevention_amendment_bill2006.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://theindiapost.com/2008/07/21/itpa-amendment-has-a-provision-of-jail-term-and-penalties-for-the-clients-of-prostitutes-who-were-so-far-kept-out-of-the-ambit-of-prosecution/"&gt;http://theindiapost.com/2008/07/21/itpa-amendment-has-a-provision-of-jail-term-and-penalties-for-the-clients-of-prostitutes-who-were-so-far-kept-out-of-the-ambit-of-prosecution/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.expressindia.com/latest-news/Sex-workers-to-go-on-hungerstrike-over-ITPA/330250/"&gt;http://www.expressindia.com/latest-news/Sex-workers-to-go-on-hungerstrike-over-ITPA/330250/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="external-link" href="http://www.trust.org/trustlaw/blogs/the-word-on-women/rehabilitation-cuts-no-ice-with-indias-sex-workers"&gt;http://www.trust.org/trustlaw/blogs/the-word-on-women/rehabilitation-cuts-no-ice-with-indias-sex-workers&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/privacy/privacy_privacyandsexworkers'&gt;https://cis-india.org/internet-governance/blog/privacy/privacy_privacyandsexworkers&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-03-28T06:26:03Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/deccan-herald-january-29-2013-an-innovative-concept-comes-to-the-fore">
    <title>An innovative concept comes to the fore</title>
    <link>https://cis-india.org/news/deccan-herald-january-29-2013-an-innovative-concept-comes-to-the-fore</link>
    <description>
        &lt;b&gt;There’s very little awareness about Bitcoin — a new digital currency and payment system, designed for the voting process of ‘Bitfilm 13’  — in the City. Aaron Koenig, the managing director at Bitfilm Networks Hamburg, addressed this issue recently, during a talk held at The Centre for Internet and Society. The talk was based on the creation of Bitcoin and its various uses.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The article was &lt;a class="external-link" href="http://www.deccanherald.com/content/308243/an-innovative-concept-comes-fore.html"&gt;published in the Deccan Herald&lt;/a&gt; on January 29, 2013.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;"The potential of Bitcoin is huge. It’s easy to use and currently, there are about 21 million (units of) Bitcoin in the world and everyone accepts it. It works differently, but it is the same as gold and has an intrinsic value," explains Aaron.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aaron also showed cryptographic diagrams of how a Bitcoin transaction works. "It is a clever way of encryption and it is easy to open an account. You just need to download some software and then, you get a virtual wallet and a user ID and password. The identity of the person is kept anonymous and hence, there have been instances of people misusing Bitcoin," he says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;An animated short film about Bitcoin, which Aaron produced along with an animation team based in Bangalore, was also screened during the talk. "I have paid all the animators in Bitcoin. Initially, they were hesitant and did not want to accept it. But when they got to know about how its value almost doubles itself in the span of a year, they readily accepted it," he explains.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"There is a German restaurant where Bitcoin is accepted. Slowly, more such places are coming up, as people are realising its worth. It is easy to transfer," he adds. There was an interactive session with the audience after the talk, which was equally interesting. Many wanted to know if Bitcoin can be liquidated.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"I am very curious to know if Bitcoin can be liquidated. Also, what is the exact process that one should follow when they want to liquidate Bitcoin?" questions Geane, who was attending the session. These queries, as well as many others, were addressed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Vinod, who also attended the session, says that it was a new concept and interesting for those who wanted to know more. "The concept of a new form of money sounds great and Aaron really helped us get to know more about it. For people like us, who had no clue about Bitcoin, it was an enlightening session," he informs.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/deccan-herald-january-29-2013-an-innovative-concept-comes-to-the-fore'&gt;https://cis-india.org/news/deccan-herald-january-29-2013-an-innovative-concept-comes-to-the-fore&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2013-01-30T06:04:14Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/vipul-kharbanda-may-8-2019-an-analysis-of-rbi-draft-framework-on-regulatory-sandbox-for-fintech">
    <title>An Analysis of the RBI’s Draft Framework on Regulatory Sandbox for Fintech</title>
    <link>https://cis-india.org/internet-governance/blog/vipul-kharbanda-may-8-2019-an-analysis-of-rbi-draft-framework-on-regulatory-sandbox-for-fintech</link>
    <description>
        &lt;b&gt;The term Fintech is generally used to describe innovative technology and technological processes being used in the financial services sector.&lt;/b&gt;
        &lt;p&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/analysis-of-the-rbi2019s-draft-framework-on-regulatory-sandbox-for-fintech"&gt;&lt;b&gt;Click here&lt;/b&gt;&lt;/a&gt; to download the file.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;It originated as a term referring to the back-end technology used by large financial institutions, but has expanded to include technological innovation in the financial sector, including innovations in financial literacy and education, retail banking, investments, etc.&lt;/span&gt;&lt;a name="_ftnref1"&gt;&lt;/a&gt;&lt;span&gt; Entities engaged in FinTech offer an array of services ranging from peer-to-peer lending platforms and mobile payment solutions to online portfolio management tools and international money transfers.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Regulation and supervision of the Fintech industry raises some unique challenges for regulatory authorities as they have to strike a balance between financial inclusion, stability, integrity, consumer protection, and competition.&lt;a name="_ftnref2"&gt;&lt;/a&gt; One of the methods that have been adopted by regulators in certain jurisdictions to tackle the complexities of this sector is to establish a “regulatory sandbox” which could nurture innovative fintech enterprises while at the same time ensuring that the risk associated with any regulatory relaxations is contained within specified boundaries. It was precisely for this reason that establishment of a regulatory sandbox was one of the options put forward by the Working Group on Fintech and Digital Banking established by the Reserve Bank of India in its report of November, 2017 which was released for public comments on February 8, 2018. Acting on this recommendation the Reserve Bank has proposed a Draft Enabling Framework for Regulatory Sandbox, dated April 18, 2019, (“&lt;strong&gt;RBI Framework&lt;/strong&gt;”) which is analysed and discussed below.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Regulatory Sandbox and its benefits&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While the basic concept of a regulatory sandbox is to ensure that there is regulatory encouragement and incentive for fledgling Fintech enterprises in a contained environment to mitigate risks, different regulatory authorities have adopted varied methods of achieving this objective. While the Australian Securities and Exchange Commission (ASIC) uses a method where the eligible enterprises notify the ASIC and commence testing without an individual application process, the Financial Conduct Authority, UK (FCA) uses a cohort approach wherein eligible enterprises have to apply to the FCA which then selects the best options based on criteria laid down in the policy.&lt;a name="_ftnref3"&gt;&lt;/a&gt; The RBI has, not surprisingly, adopted an approach similar to the FCA wherein applicants will be selected by the RBI based on pre-defined eligibility criterion and start the regulatory sandbox in cohorts containing a few entities at a time.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A regulatory sandbox offers the users the opportunity to test the product’s viability without a larger and more expensive roll out involving heavy investment and regulatory authorizations. If the product appears to have the potential to be successful, it might then be authorized and brought to the broader market more quickly.&lt;a name="_ftnref4"&gt;&lt;/a&gt; If there are any problems with the product the limited nature of the sandbox ensures that the consequences of the problems are contained and do not affect the broader market. It also allows regulators to obtain first-hand empirical evidence on the benefits and risks of emerging technologies and business models, and their implications, which allows them to take a considered (and perhaps more nuanced) view on the regulatory requirements that may be needed to support useful innovation, while mitigating the attendant risks. A regulatory sandbox initiative also sends a clear signal to the market that innovation is on the agenda of the regulator.&lt;a name="_ftnref5"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;RBI Draft Framework&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Since the RBI has adopted a cohort approach for its regulatory sandbox process (“&lt;strong&gt;RS&lt;/strong&gt;”), it implies that fintech entities will have to apply to the RBI to be selected in the RS. The eligibility criterion provides that the applicants will have to meet the eligibility conditions prescribed by the government for start-ups as per the Government of India, Department of Industrial Policy and Promotion, Notification GSR 364(E) April 11, 2018.&lt;a name="_ftnref6"&gt;&lt;/a&gt; The RS will focus on areas where (i) there is an absence of regulations, (ii) regulations need to be eased to encourage innovation, and (iii) the innovation/product shows promise of easing/effecting delivery of financial services in a significant way.&lt;a name="_ftnref7"&gt;&lt;/a&gt; The Framework also provides an indicative list of innovative products and technologies which could be considered for RS testing,&lt;a name="_ftnref8"&gt;&lt;/a&gt; and at the same time prohibits certain products and technologies from being considered for this programme such as credit registry, crypto currencies, ICOs, etc.&lt;a name="_ftnref9"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The RBI Framework also lays down specific conditions that the entity has to satisfy in order to be considered for the RS such as satisfaction of the conditions to be considered a start-up, minimum net worth requirements, fit and proper criteria for Directors and Promoters, satisfactory conduct of bank accounts of promoters/directors, satisfactory credit score, technological readiness of the product for deployment in the broader market, ensuring compliance with existing laws and regulations on consumer data and privacy, adequate safeguards in its IT systems for protection against unauthorised access etc. and a robust IT infrastructure and managerial resources. The fit and proper criteria for Directors and Promoters which requires elements of credit history along with the minimum net worth requirements in the RBI Framework are conditions which may be too difficult for some of the smaller and newer start-ups to satisfy even though the technology and products they offer might be sound. The applicants are also required to: (i) highlight an existing gap in the financial ecosystem and how they intend to address that, (ii) show a regulatory barrier or gap that prevents the implementation of the solution on a large scale, (iii) clearly define the test scenarios, expected outcomes, boundary conditions, exit or transition strategy, assessment and mitigation of risks, etc.&lt;a name="_ftnref10"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The RBI Framework specifies that the focus of the RS should be narrow in terms of areas of innovation and limited in terms of intake.&lt;a name="_ftnref11"&gt;&lt;/a&gt; While limits on the number of entities per cohort may be justified based on paucity of resources, limiting the focus of the RS by narrow areas of innovation is a lost opportunity in terms of sharing of ideas and learning from the mistakes of their colleagues who may be employing technologies and principles which could be useful in fields other than those where they are currently being applied.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The RBI Framework specifies that the boundaries of the RS have to be well defined so that any consequences of failure can be contained. These boundary conditions include a specific start and end date, target customer type and limits on number of customers, cash holdings, transaction amounts and customer losses.&lt;a name="_ftnref12"&gt;&lt;/a&gt; The Framework does not put in place any hard numbers on the boundary conditions which ensures that the RS process can be customised to the needs of specific entities since the sample sizes and data needed to determine the viability of fintech entities and products may vary from product to product. However a major dampener is the hard limit of 12 weeks imposed on the testing phase of the RS, which is the most important phase since all the data from the operations is generated during this phase and 12 weeks may not be enough time to generate enough reliable data so as to reach a determination of the viability of the product.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Although the RBI has shown a willingness to relax regulatory requirements for RS participants on a case to case basis, it has specified that there shall be no relaxation on issues of customer privacy and data protection, security of payment data, transaction security, KYC requirements and statutory restrictions.&lt;a name="_ftnref13"&gt;&lt;/a&gt; Since this is only an initiative by the RBI the RS participants dealing with the insurance or securities sector would not be entitled to any relaxations from the IRDA or the SEBI even if they are found eligible for relaxations from RBI regulations. This would severely limit the efficacy of the RS process and is an issue that could have been addressed if all three regulators had collaborated thereby encouraging innovative start-ups offering a broader spectrum of services.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Once the RS is finished, the regulatory relaxations provided by the RBI will expire and the fintech entity will have to either stop operations or comply with the relevant regulations. In case the entity requires an extension of the RS period, it would apply to the RBI atleast one month prior to the expiry of the RS period with reasons for the extension. The RBI also has the option of prematurely terminating the sandbox process in case the entity does not achieve its intended purpose or if it cannot comply with the regulatory requirements and other conditions specified at the relevant stage of the sandbox process. The fintech entity is also entitled to quit the RS process prematurely by giving one week’s notice to the RBI, provided it ensures that all its existing obligations to its customers are fully addressed before such discontinuance.&lt;a name="_ftnref14"&gt;&lt;/a&gt; Infact customer obligations have to be met by the fintech entities irrespective of whether the operations are prematurely ended by the entity or it continues through the entire RS process; no waiver of the legal liability towards consumers is provided by the RS process. In addition, customers are required to be notified upfront about the potential risks and their explicit consent is to be taken in this regard.&lt;a name="_ftnref15"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The RBI Framework itself lists out some of the risks associated with the regulatory sandbox model such as (i) loss of flexibility in going through the RS process, (ii) case by case determinations involve time and discretional judgements, (iii) no legal waivers, (iv) requirement of regulatory approvals after the RS process is over, (iv) legal issues such as consumer complaints, challenges from rejected candidates, etc. While acknowledging the above risks the Framework also mentions that atleast some of them may be mitigated by following a time bound and transparent process thus reducing risks of arbitrary discretion and loss of flexibility.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Conclusions&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While there are some who are sceptical of the entire concept of a regulatory sandbox for the reason that it loosens regulation too much while at the same time putting customers at risk,&lt;a name="_ftnref16"&gt;&lt;/a&gt; the cohort model adopted by the RBI would reduce that risk to an extent since it ensures comprehensive screening and supervision by the RBI with clear exit strategies and an emphasis on consumer interests. On the other hand the eligibility criterion for applicants prescribes minimum net worth requirements as well as credit history, etc. which may impose conditions too onerous for some start ups which may be their infancy. Further the clear emphasis on protection of customer privacy and consumer interests also ensures that the RBI will not put the interests of ordinary citizens at risk in order to promote new and untested technologies. That said, the regulatory sandbox process is a welcome initiative by the RBI which may send a signal to the financial community that it is aware of the potential advantages as well as risks of Fintech and is willing to play a proactive role in encouraging new technologies to improve the financial sector in India.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn1"&gt;&lt;/a&gt; Report of Working Group on Fintech and Digital Banking, Reserve Bank of India, November, 2017, available at &lt;a href="https://www.rbi.org.in/Scripts/PublicationReportDetails.aspx?UrlPage=&amp;amp;ID=892"&gt;https://www.rbi.org.in/Scripts/PublicationReportDetails.aspx?UrlPage=&amp;amp;ID=892&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn2"&gt;&lt;/a&gt; Jenik, Ivo, and Kate Lauer. 2017. “Regulatory Sandboxes and Financial Inclusion.” Working Paper. Washington, D.C.: CGAP, available at &lt;a href="https://www.cgap.org/sites/default/files/Working-Paper-Regulatory-Sandboxes-Oct-2017.pdf"&gt;https://www.cgap.org/sites/default/files/Working-Paper-Regulatory-Sandboxes-Oct-2017.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn3"&gt;&lt;/a&gt; Other countries which have regulatory sandboxes are Netherlands, Bahrain, Abu Dhabi, Saudi Arabia, etc.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn4"&gt;&lt;/a&gt; Report of Working Group on Fintech and Digital Banking, Reserve Bank of India, November, 2017, available at &lt;a href="https://www.rbi.org.in/Scripts/PublicationReportDetails.aspx?UrlPage=&amp;amp;ID=892"&gt;https://www.rbi.org.in/Scripts/PublicationReportDetails.aspx?UrlPage=&amp;amp;ID=892&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn5"&gt;&lt;/a&gt; Jenik, Ivo, and Kate Lauer. 2017. “Regulatory Sandboxes and Financial Inclusion.” Working Paper. Washington, D.C.: CGAP, available at &lt;a href="https://www.cgap.org/sites/default/files/Working-Paper-Regulatory-Sandboxes-Oct-2017.pdf"&gt;https://www.cgap.org/sites/default/files/Working-Paper-Regulatory-Sandboxes-Oct-2017.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn6"&gt;&lt;/a&gt; These conditions are fairly liberal in that they require that the entity should be less than 7 years old; should not have a turnover of more than 25 crores, and should be working for innovation, development or improvement of products or processes or services, or if it is a scalable business model with a high potential of employment generation or wealth creation&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn7"&gt;&lt;/a&gt; Clause 5 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn8"&gt;&lt;/a&gt; Clause 6.1 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn9"&gt;&lt;/a&gt; Clause 6.3 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn10"&gt;&lt;/a&gt; Clause 6.5 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn11"&gt;&lt;/a&gt; Clause 6.4 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn12"&gt;&lt;/a&gt; Clause 6.7 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn13"&gt;&lt;/a&gt; Clauses 6.2 and 8 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn14"&gt;&lt;/a&gt; Clause 6.6 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn15"&gt;&lt;/a&gt; Clause 6.9 of the RBI Framework.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a name="_ftn16"&gt;&lt;/a&gt; Jemima Kelly, A “fintech sandbox” might sound like a harmless idea. It's not, Financial Times, Aplphaville, &lt;a href="https://ftalphaville.ft.com/2018/12/05/1543986004000/A--fintech-sandbox--might-sound-like-a-harmless-idea--It-s-not/"&gt;https://ftalphaville.ft.com/2018/12/05/1543986004000/A--fintech-sandbox--might-sound-like-a-harmless-idea--It-s-not/&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/vipul-kharbanda-may-8-2019-an-analysis-of-rbi-draft-framework-on-regulatory-sandbox-for-fintech'&gt;https://cis-india.org/internet-governance/blog/vipul-kharbanda-may-8-2019-an-analysis-of-rbi-draft-framework-on-regulatory-sandbox-for-fintech&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>vipul</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-05-08T13:57:49Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/an-analysis-of-the-cloud-act-and-implications-for-india">
    <title>An Analysis of the CLOUD Act and Implications for India </title>
    <link>https://cis-india.org/internet-governance/blog/an-analysis-of-the-cloud-act-and-implications-for-india</link>
    <description>
        &lt;b&gt;India houses the second largest population in the world at approximately 1.35 billion individuals. In such a diverse and dense context, law enforcement could be a challenging job.&lt;/b&gt;
        &lt;h3 style="text-align: justify; "&gt;Introduction&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Networked technologies have changed the nature of crime and will continue to do so.&lt;/span&gt;&lt;span&gt; Access to data generated by digital technologies and on digital platforms is important in solving online and offline crimes. Yet, a significant amount of such data is stored predominantly under the control of companies in the United States. Thus, for Indian law enforcement to access metadata (location data or subscriber information), they can send a request directly to the company. However for access to content data, law enforcement must follow the MLAT process as a result of requirements under the Electronic Communications Privacy Act (ECPA).  ECPA allows service providers to share metadata on request of foreign governments, but requires a judicially issued warrant based on a finding of ‘probable cause’ for a service provider to share content data.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The challenges associated with accessing data across borders has been an area of concern for India for many years. From data localization requirements&lt;/span&gt;&lt;span&gt;, legal decryption mandates&lt;/span&gt;&lt;span&gt;, proposed back doors&lt;/span&gt;&lt;span&gt;- law enforcement and the government have consistently been trying to find efficient ways to access data across borders.  &lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Towards finding solutions to the challenges in the MLAT process, Peter Swire and Deven Desai in the article “A Qualified SPOC Approach for India and Mutual Legal Assistance” have noted the importance of finding a solution to the hurdles in the India - US MLAT and have suggested that reforms for the MLAT process in India should not start with law enforcement, and have instead proposed the establishment of a Single Point of Contact designated to handle and process government to government requests with requests emerging from that office receiving special legal treatment.&lt;/span&gt;&lt;span&gt; &lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Frustrations with cross border sharing of data are not unique to India and the framework has been recognized by many stakeholders for being outdated, slow, and inefficient - giving rise to calls from governments, law enforcement, and companies for solutions.&lt;/span&gt;&lt;span&gt; As a note, some research has also highlighted that the identified issues with the MLAT system are broad and more evidence is needed to support each concern and inform policy response.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Towards this, the US and EU have undertaken clear policy steps to address the tensions in the MLAT system by enabling direct access by governments to content data. On April 17 2018, the European Union published the E-Evidence Directive and a Regulation that allows for a law enforcement agency to obtain electronic evidence from service providers within 10 days of receiving a request or 6 hours for emergency requests and request the preservation or production of data. Production orders for content and transactional records can be issued only for certain serious crimes and must be issued by a judge.  No judicial authorisation is required for production orders for subscriber information and access data, and it can be sought to investigate any criminal offense, not just serious offenses. Preservation orders can be issued without judicial authorisation for all four types of data and for the investigation of any crime.&lt;/span&gt;&lt;span&gt; Further, requests originating from the European Union must be handled by a designated legal representative.&lt;/span&gt;&lt;span&gt; Preservation orders can be issued for all four types of data.&lt;/span&gt;&lt;span&gt; Further, requests originating from the European Union must be handled by a designated legal representative.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;On the US side, in 2016, the Department of Justice (DoJ) put out draft legislation that would create a framework allowing the US to enter into executive agreements with countries that have been evaluated as meeting criteria defined in the law.&lt;/span&gt;&lt;span&gt; Our response to the DoJ draft Bill can be found here.&lt;/span&gt;&lt;span&gt; In February 2018, the Microsoft Ireland Case was presented before the U.S Supreme Court. The question central to the case was whether or not a US warrant issued against a company incorporated in the US was valid if the data was stored in servers outside of the US. On March 23, 2018, the United States government enacted the “Clarifying Lawful Overseas Use of Data Act” also known as the CLOUD Act. The passing of the Act solves the dilemma found in the Microsoft Ireland case.&lt;/span&gt;&lt;span&gt; The CLOUD Act amends Title 18 of the United States Code and allows U.S. law enforcement agencies to access data stored abroad by increasing the reach of the U.S. Stored Communication Act&lt;/span&gt;&lt;span&gt;, enabling access without requiring the specific cooperation of foreign governments. Under this law, U.S. law enforcement agencies can seek or issue orders that compel companies to provide data regardless of where the data is located as long as the data is under their “possession, custody or control”. It further allows US communication service providers to intercept or provide the content of communications in response to orders from foreign governments if the foreign government has entered into an executive agreement with the US upon approval by the Attorney General and concurrence with the Secretary of State. The Act also absolves companies from criminal and civil liability when disclosing information in good faith pursuant to an executive agreement between the US and a foreign country. Such access would be reciprocal, with the US government having similar access rights to data stored in the foreign country.   &lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Though the E-Evidence Directive is a significant development, in this article - we focus on the CLOUD Act and its implications for cross border sharing of data between India and the US. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;To read more &lt;b&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/analysis-of-cloud-act-and-implications-for-india"&gt;download the PDF&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/an-analysis-of-the-cloud-act-and-implications-for-india'&gt;https://cis-india.org/internet-governance/blog/an-analysis-of-the-cloud-act-and-implications-for-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Elonnai Hickok and Vipul Kharbanda</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cloud Act</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-08-22T14:55:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/analysis-of-cases-filed-under-sec-48-it-act-for-adjudication-maharashtra">
    <title>An Analysis of the Cases Filed under Section 46 of the Information Technology Act, 2000  for Adjudication in the State of Maharashtra</title>
    <link>https://cis-india.org/internet-governance/blog/analysis-of-cases-filed-under-sec-48-it-act-for-adjudication-maharashtra</link>
    <description>
        &lt;b&gt;This is a brief review of some of the cases related to privacy filed under section 46 of the Information Technology Act, 2000 ("the Act") seeking adjudication for alleged contraventions of the Act in the State of Maharashtra. &lt;/b&gt;
        &lt;h3&gt;Background&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Section 46 of the Act grants the Central Government the power to appoint an adjudicating officer to hold an enquiry to adjudge, upon complaints being filed before that adjudicating officer, contraventions of the Act. The adjudicating officer may be of the Central Government or of the State Government [see section 46(1) of the Act], must have field experience with information technology and law [see section 46(3) of the Act] and exercises jurisdiction over claims for damages up to `5,00,00,000 [see section 46(1A) of the Act]. For the purpose of adjudication, the officer is vested with certain powers of a civil court [see section 46(5) of the Act] and must follow basic principles of natural justice while conducting adjudications [see section 46(2) of the Act]. Hence, the adjudicating officer appointed under section 46 is a quasi-judicial authority.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In addition, the quasi-judicial adjudicating officer may impose penalties, thereby vesting him with some of the powers of a criminal court [see section 46(2) of the Act], and award compensation, the quantum of which is to be determined after taking into account factors including unfair advantage, loss and repeat offences [see section 47 of the Act]. The adjudicating officer may impose penalties for any of the offences described in section 43, section 44 and section 45 of the Act; and, further, may award compensation for losses suffered as a result of contraventions of section 43 and section 43A. The text of these sections is reproduced in the Schedule below. Further law as to the appointment of the adjudicating officer and the procedure attendant on all adjudications was made by Information Technology (Qualification and Experience of Adjudicating Officers and the Manner of Holding Enquiry) Rules, 2003.&lt;a href="#fn1" name="fr1"&gt;[1]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is clear that the adjudicating officer is vested with significant judicial powers, including the power to enforce certain criminal penalties, and is an important quasi-judicial authority.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Excursus&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;At the outset, it is important to understand the distinction between compensation and damages. Compensation is a sum of money awarded by a civil court, before or along with the primary decree, to indemnify a person for injury or loss. It is usually awarded to a person who has a suffered a monetary loss as a result of the acts or omissions of another party. Its quantification is usually guided by principles of equity. [See &lt;i&gt;Shantilal Mangaldas&lt;/i&gt; AIR 1969 SC 634 and &lt;i&gt;Ranbir Kumar Arora&lt;/i&gt; AIR 1983 P&amp;amp;H 431]. On the hand, damages are punitive and, in addition to restoring an indemnitee to wholeness, may be imposed to deter an offender, punish exemplary offences, and recover consequential losses, amongst other objectives. Damages that are punitive, while not judicially popular in India, are usually imposed by a criminal court in common law jurisdictions. They are distinct from civil and equitable actions. [See the seminal case of &lt;i&gt;The Owners of the Steamship Mediana&lt;/i&gt; [1900] AC 113 (HL)].&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Unfortunately, section 46 of the Act uses the terms “damage”, “injury” and “compensation” interchangeably without regard for the long and rich jurisprudence that finds them to be different concepts.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;The Cases related to Privacy&lt;/h3&gt;
&lt;p&gt;In the State of Maharashtra, there have been a total of 47 cases filed under section 46 of the Act. Of these, 33 cases have been disposed of by the Adjudicating Officer and 14 are currently pending disposal. &lt;a href="#fn2" name="fr2"&gt;[2]&lt;/a&gt; At least three of these cases before the Adjudicating Officer deal with issues related to privacy of communications and personal data. They are:&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Case Title&lt;/th&gt;&lt;th&gt;Forum&lt;/th&gt;&lt;th&gt;Date&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;&lt;i&gt;Vinod Kaushik&lt;/i&gt; v. &lt;i&gt;Madhvika Joshi&lt;/i&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;Shri Rajesh Aggarwal&lt;br /&gt;Adjudicating Officer, &lt;i&gt;ex-officio Secretary&lt;/i&gt;, IT&lt;br /&gt;Government of Maharashtra&lt;/td&gt;
&lt;td&gt;10.10.2011&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;i&gt;Amit D. Patwardhan&lt;/i&gt; v. &lt;i&gt;Rud India Chains&lt;/i&gt;&lt;/td&gt;
&lt;td&gt;Shri Rajesh Aggarwal&lt;br /&gt;Adjudicating Officer, &lt;i&gt;ex-officio&lt;/i&gt;&lt;br /&gt;Secretary, IT&lt;br /&gt;Government of Maharashtra&lt;/td&gt;
&lt;td&gt;15.04.2013&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;i&gt;Nirmalkumar Bagherwal&lt;/i&gt; v. &lt;i&gt;Minal Bagherwal&lt;/i&gt;&lt;/td&gt;
&lt;td&gt;Shri Rajesh Aggarwal&lt;br /&gt;Adjudicating Officer, &lt;i&gt;ex-officio Secretary&lt;/i&gt;, IT&lt;br /&gt;Government of Maharashtra&lt;br /&gt;&lt;/td&gt;
&lt;td&gt;26.08.2013&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;In all three cases the Adjudicating Officer was called upon to determine and penalise unauthorised access to personal data of the complainants. In the &lt;i&gt;Vinod Kaushik&lt;/i&gt; case, the complainants’ emails and chat sessions were accessed, copied and made available to the police for legal proceedings without the permission of the complainants. In the &lt;i&gt;Amit Patwardhan&lt;/i&gt; and &lt;i&gt;Nirmalkumar Bagherwal&lt;/i&gt; cases, the complainants’ financial information in the form of bank account statements were obtained from their respective banks without their consent and used against them in legal proceedings.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The &lt;i&gt;Vinod Kaushik&lt;/i&gt; complaint was filed in 2010 for privacy violations committed between 2008 and 2009. The complaint was made against the complainant’s daughter-in-law – the respondent, who was estranged from her husband, the complainant’s son. The respondent had, independent of the proceedings before the Adjudicating Officer, instituted criminal proceedings alleging cruelty and dowry-related harassment against her estranged husband and the complainant. To support some of the claims made in the criminal proceedings, the respondent accessed the email accounts of her estranged husband and the complainant and printed copies of certain communications, both emails and chat transcripts. The complaint to the Adjudicating Officer was made in relation to these emails and chat transcripts that were obtained without the consent and knowledge of the complainant and his son. On 09.08.2010, the then Adjudicating Officer dismissed the complaint after finding that, owing to the marriage between the respondent and the complainant’s son, there was a relation of mutual trust between them that resulted in the complainant and his son consensually sharing their email account passwords with the respondent. This ruling was appealed to the Cyber Appellate Tribunal (&lt;b&gt;"CyAT"&lt;/b&gt;) which, in a decision of 29.06.2011, found irregularities in the complainant’s son’s privity to the proceedings and remanded the complaint to the Adjudicating Officer for re-adjudication. The re-adjudication, which was conducted by Shri Rajesh Aggarwal as Adjudicating Officer, resulted in a final order of 10.10.2011 (&lt;b&gt;"the final order"&lt;/b&gt;) that is the subject of this analysis. The final order found that the respondent had violated the privacy of the complainant and his son by her unauthorised access of their email accounts and sharing of their private communications. However, the Adjudicating Officer found that the intent of the unauthorised access – to obtain evidence to support a criminal proceeding – was mitigatory and hence ordered the respondent to pay only a small token amount in compensation, not to the complainants but instead to the State Treasury. The Delhi High Court, which was moved in appeal because the CyAT was non-functional, upheld the final order in its decision of 27.01.2012.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The &lt;i&gt;Amit Patwardhan&lt;/i&gt; complaint was filed against the complainant’s ex-employer – the respondent, for illegally obtaining copies of the complainant’s bank account statement. The complainant had left the employ of the respondent to work with a competing business company but not before colluding with the competing business company and diverting the respondent’s customers to them. For redress, the respondent filed suit for a decree of compensation and lead the complainant’s bank statements in evidence to prove unlawful gratification. Since the bank statements were obtained electronically by the respondent without the complainant’s consent, the jurisdiction of the Adjudicating Officer was invoked. In his order of 15.04.2013, Shri Rajesh Aggarwal, the Adjudicating Officer, found that the respondent had, by unlawfully obtaining the complainant’s bank account statements which constitute sensitive personal data, violated the complainant’s privacy. The Adjudicating Officer astutely applied the equitable doctrine of clean hands to deny compensation to the complainant; however, because the complainant’s bank was not a party to the complaint, the Adjudicating Officer was unable to make a ruling on the lack of action by the bank to protect the sensitive personal data of its depositors.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The &lt;i&gt;Nirmalkumar Bagherwal&lt;/i&gt; complaint bears a few similarities to the preceding two cases. Like the &lt;i&gt;Vinod Kaushik&lt;/i&gt; matter, the issue concerned the manner in which a wife, estranged but still legally married, accessed electronic records of personal data of the complainants; and, like the &lt;i&gt;Amit Patwardhan&lt;/i&gt; matter, the object of the privacy violation was the bank account statements of the complainants that constitute sensitive personal data. The respondent was the estranged wife of one of the complainants who, along with his complainant father, managed the third complainant company. To support her claim for maintenance from the complainant and his family in an independent legal proceeding, the respondent obtained certain bank account statements of the complainants without their consent and, possibly, with the collusion of the respondent bank. After reviewing relevant law from the European Union and the United States, and observant of relevant sectoral regulations applicable in India including the relevant Master Circular of the Reserve Bank of India, and further noting preceding consumer case law on the subject, the Adjudicating Officer issued an order on 26.08.2013. The order found that the complainant’s right to privacy was violated by both the respondents but, while determining the quantum of compensation, distinguished between the respondents in respect of the degree of liability; the respondent wife was ordered to pay a token compensation amount while the respondent bank was ordered to pay higher compensation to each of the three complainants individually.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The high quality of each of the three orders bears specific mention. Despite the superb quality of the judgments of the Indian higher judiciary in the decades after independence, the overall quality of judgment-writing appears to have declined. &lt;a href="#fn3" name="fr3"&gt;[3]&lt;/a&gt; In the last decade, several Indian judges have called for higher standards of judgment writing from their fellow judges. &lt;a href="#fn4" name="fr4"&gt;[4]&lt;/a&gt; In this background, it is notable that Shri Rajesh Aggarwal, despite not being a member of the judiciary, has delivered well-reasoned, articulate and clear orders that are cognisant of legal issues and also easily understandable to a non-legal reader.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In each of these cases, the Adjudicating Officer has successfully navigated around the fact that none of the primary parties were interacting and transacting at arm’s length. In the &lt;i&gt;Vinod Kaushik&lt;/i&gt; and &lt;i&gt;Nirmalkumar Bagherwal&lt;/i&gt; matters, the primary parties were estranged but still legally married partners and in the &lt;i&gt;Amit Patwardhan&lt;/i&gt; matter the parties were in an employer-employee relationship. The first Adjudicating Officer in the &lt;i&gt;Vinod Kaushik&lt;/i&gt; matter failed, in his order of 09.08.2010, to appreciate that the individual communications of individual persons were privileged by an expectation of privacy, regardless of their relationship. Hence, despite acknowledging that the marital partners in that matter were in conflict with each other, and despite being told by one party that the other party’s access to those private communications was made without consent, the Adjudicating Officer allowed his non-judicial opinion of marriage to influence his order. This mistake was corrected when the matter was remanded for re-adjudication. In the re-adjudication, the new Adjudicating Officer correctly noted that the respondent wife could have chosen to approach the police or a court to follow the proper investigative procedure for accessing emails and other private communications of another person and that her unauthorised use of the complainant’s passwords amounted to a violation of their privacy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Popular conceptions of different types of relationships may affect the (quasi) judicial imagination of privacy. In comparison to the &lt;i&gt;Vinod Kaushik&lt;/i&gt; matter, the &lt;i&gt;Nirmalkumar Bagherwal&lt;/i&gt; and &lt;i&gt;Amit Patwardhan&lt;/i&gt; matters both dealt with unauthorised access to bank account statements, by a wife and by an ex-employer respectively. In any event, the same Adjudicating Officer presided over all three matters and correctly found that the facts in all three matters admitted to contraventions of the privacy of the complainants. The conjecture as to whether the first Adjudicating Officer in the &lt;i&gt;Vinod Kaushik&lt;/i&gt; matter would have applied the same standard of family unity to unauthorised access of bank account statements by an estranged wife who was seeking maintenance remains untested. However, the reliance placed on the decision of the Delhi State Consumer Protection Commission in the matter of &lt;i&gt;Rupa Mahajan Pahwa,&lt;/i&gt; &lt;a href="#fn5" name="fr5"&gt;[5]&lt;/a&gt; where the Commission found that unauthorised access to a bank pass book by an estranged husband violated the privacy of the wife, would suggest that judges clothe financial information with a standard of privacy higher than that given to emails.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Emails are a form of electronic communication. The &lt;i&gt;PUCL&lt;/i&gt; case (Supreme Court of India, 1996)&lt;a href="#fn6" name="fr6"&gt;[6]&lt;/a&gt; while it did not explicitly deal with the standard of protection accorded to emails, held that personal communications were protected by an individual right to privacy that emanated from the protection of personal liberty guaranteed under Article 21 of the Constitution of India. Following the &lt;i&gt;Maneka Gandhi&lt;/i&gt; case (Supreme Court of India, 1978)&lt;a href="#fn7" name="fr7"&gt;[7]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;it is settled that persons may be deprived of their personal liberty only by a just, fair and reasonable procedure established by law. As a result, interceptions of private communications that are protected by Article 21 may only be conducted in pursuance of such a procedure. This procedure exists in the form of the Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009 that came into effect on 27 October 2009 (&lt;b&gt;"the Interception Rules"&lt;/b&gt;). The Interception Rules set out a regime for accessing private emails in certain conditions. The powers and procedure of Section 91 of the Code of Criminal Procedure (&lt;b&gt;"CrPC")&lt;/b&gt; may also apply to obtain data at rest, such as emails stored in an inbox or sent-mail folder.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Finally, the orders of the Adjudicating Officer reveal a well-reasoned and progressive understanding of the law and principles relating to the quantification of compensation. By choosing to impose larger amounts of compensation on the bank that violated the privacy of the complainant in the &lt;i&gt;Nirmalkumar Bagherwal&lt;/i&gt; matter, the Adjudicating Officer has indicated that the institutions that hold sensitive personal data, such as financial information, are subject to a higher duty of care in relation of it. But, most importantly, the act of imposing monetary compensation of privacy violations is a step forward because, for the first time in India, it recognises that privacy violations are civil wrongs or injuries that demand compensation.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr1" name="fn1"&gt;1&lt;/a&gt;]. These Rules were issued &lt;i&gt;vide&lt;/i&gt; GSR 220(E), dated 17 March 2003 and published in the Gazette of India, Extraordinary, Part II, Section 3(i). These Rules can be accessed here – &lt;a href="http://it.maharashtra.gov.in/PDF/Qual_ExpAdjudicatingOfficer_Manner_of_Holding_Enquiry_Rules.PDF"&gt;http://it.maharashtra.gov.in/PDF/Qual_ExpAdjudicatingOfficer_Manner_of_Holding_Enquiry_Rules.PDF&lt;/a&gt; (visited on 30 September 2013).&lt;/p&gt;
&lt;p&gt;[&lt;a href="#fr2" name="fn2"&gt;2&lt;/a&gt;]. These cases and statistics may be viewed here – &lt;a href="http://it.maharashtra.gov.in/1089/IT-Act-Judgements"&gt;http://it.maharashtra.gov.in/1089/IT-Act-Judgements&lt;/a&gt; (visited on 30 September 2013).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr3" name="fn3"&gt;3&lt;/a&gt;]. See generally, Upendra Baxi “"The Fair Name of Justice": The Memorable Voyage of Chief Justice Chandrachud” in &lt;i&gt;A Chandrachud Reader&lt;/i&gt; (Justice V. S. Deshpande ed., Delhi: Documentation Centre &lt;i&gt;etc.&lt;/i&gt;, 1985) and, Rajeev Dhavan, "Judging the Judges" in &lt;i&gt;Judges and the Judicial Power: Essays in Honour of Justice V. R. Krishna Iyer&lt;/i&gt; (Rajeev Dhavan and Salman Khurshid eds., London: Sweet &amp;amp; Maxwell, 1985).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr4" name="fn4"&gt;4&lt;/a&gt;]. See generally, Justice B.G .Harindranath, &lt;i&gt;Art of Writing Judgments&lt;/i&gt; (Bangalore: Karnataka Judicial Academy, 2004); Justice T .S. Sivagnanam, &lt;i&gt;The Salient Features of the Art of Writing Orders and Judgments&lt;/i&gt; (Chennai: Tamil Nadu State Judicial Academy, 2010); and, Justice Sunil Ambwani, “Writing Judgments: Comparative Models” Presentation at the National Judicial Academy, Bhopal (2006) available here – &lt;a href="http://districtcourtallahabad.up.nic.in/articles/writing%20judgment.pdf"&gt;http://districtcourtallahabad.up.nic.in/articles/writing%20judgment.pdf&lt;/a&gt; (visited on 29 Sep 2013).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr5" name="fn5"&gt;5&lt;/a&gt;]. Appeal No. FA-2008/659 of the Delhi State Consumer Protection Commission, decided on 16 October 2008.&lt;/p&gt;
&lt;p&gt;[&lt;a href="#fr6" name="fn6"&gt;6&lt;/a&gt;]. (1997) 1 SCC 301.&lt;/p&gt;
&lt;p&gt;[&lt;a href="#fr7" name="fn7"&gt;7&lt;/a&gt;]. (1978) 1 SCC 248.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/analysis-of-cases-filed-under-sec-48-it-act-for-adjudication-maharashtra'&gt;https://cis-india.org/internet-governance/blog/analysis-of-cases-filed-under-sec-48-it-act-for-adjudication-maharashtra&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>bhairav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-01T15:29:46Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/all-night-for-hackers">
    <title>An all-nighter for hackers</title>
    <link>https://cis-india.org/news/all-night-for-hackers</link>
    <description>
        &lt;b&gt;Tech event management firm HasGeek is back with its Hacknight for hackers and developers willing to burn the proverbial midnight oil writing some competitive code.&lt;/b&gt;
        &lt;p class="body"&gt;&lt;b&gt;An all-nighter for hackers&lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Tech event management firm HasGeek is back with its Hacknight for hackers and developers willing to burn the proverbial midnight oil writing some competitive code.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hacknight will be held between July 14 and 15, from 2 p.m. to 8 a.m. at the Centre for Internet and Society (CIS), in Bangalore, and simultaneously in Pune, at AmiWorks.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Data Hacknight was open to geeks, enthusiasts, designers, mathematicians and statisticians to work with different datasets on projects ranging from discovering unknown patterns in data to representing data in various visual forms. This event was being held in the run-up to a larger conference on big data, analytics and applications called The Fifth Elephant.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hacknight was also open to individuals who want to work with tools such as R, Pig, Excel or even Hadoop to discover the possibilities and challenges of working with data, a release from HasGeek stated.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;To register for the Hacknight, visit http://beta.hacknight.in/fifthelephant/bangalore2012&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Yahoo sets up Grid Computing Lab&lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Yahoo India’s Research and Development wing and the Indian Institute of Technology, Madras announced the launch of a Grid Computing Lab set up by the Internet major on the institute campus.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;This cluster of high-end servers at the lab would allow researchers to access Web-scale data and conduct research on big data and cloud computing systems, a release from Yahoo stated. The lab would focus on this emerging field and encourage more researchers to take up research in the field, as well as process and analyse huge volumes of structured and unstructured data which, to date, has been limited due to significant cost barriers in getting large computing systems operational.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;D. Janakiram, Department of Computer Science, IIT-Madras, said in a release: “This opens up a new arena of exciting opportunities for our students. We are hopeful such partnerships will allow students to conduct truly breakthrough work on cloud computing and data storage systems, ultimately leading to Web innovations coming to the marketplace.”&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;World Class Award for iGate&lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;iGATE, an integrated technology and operations company, announced that it has won the ‘World Class Award’ under the ‘large service organisations’ category at the Global Performance Excellence Awards (GPEA).&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The awards were administered by the Asia Pacific Quality Organisation, a non-profit group, a release from iGate stated. Ravi Mani, senior vice-president, Organisational Excellence Group, iGATE, said the award was a testimony to the persistent effort the teams have put in to achieve the high-quality standards and processes at iGATE.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Cloud and growth: a survey&lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Over the last two years, the public cloud market in India has rapidly evolved with focus on software and payments as a service, a survey by Zinnov, a consulting firm, has found.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;A study titled ‘Public Cloud Opportunity in India’ found that the overall Indian market for cloud (both public and private) grew steadily in 2011. The Software as a Service (SaaS) market, largely dominated by email, collaboration tools and enterprise resource products grew by 46 per cent, a release on the survey stated.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The public cloud market was expected to grow 55 per cent in the near future and become a default choice for new IT investments, especially in the small and medium businesses segment, the study observed.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The article was &lt;a class="external-link" href="http://www.thehindu.com/sci-tech/technology/article3613800.ece"&gt;published&lt;/a&gt; in the Hindu on July 11, 2012&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/all-night-for-hackers'&gt;https://cis-india.org/news/all-night-for-hackers&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2012-08-06T10:59:09Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/deccan-herald-chetana-divya-vasudev-october-4-2016-an-appening-world">
    <title>An 'app'ening world</title>
    <link>https://cis-india.org/internet-governance/news/deccan-herald-chetana-divya-vasudev-october-4-2016-an-appening-world</link>
    <description>
        &lt;b&gt;A ‘forward’ has been doing the rounds on WhatsApp about the privacy concerns relating to that instant messaging app; it’s asking for permission to share user data with Facebook.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Chetana Divya Vasudev was published in &lt;a class="external-link" href="http://www.deccanherald.com/content/573852/an-appening-world.html"&gt;Deccan Herald&lt;/a&gt; on October 4, 2016. Rohini was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;In the WhatsApp notification, asking users to agree to the terms and  conditions again, the option to share these user details to help improve  ads on Facebook is already selected. Those who are uncomfortable  parting with this information have to uncheck it before clicking on the  ‘I agree’ button.&lt;br /&gt;&lt;br /&gt;“Agreeing to this would mean Facebook can see  who you’re chatting with and what you’re talking about,” says tech  expert Chinmayi S K. “So if you’re talking about cat adoption, the ads  displayed on the side could be relevant to that.”&lt;br /&gt;&lt;br /&gt;When it comes  to other smartphone apps, she cites Zomato as an example. “It has been  asking for user history — previous orders and other such details — to  make recommendations,” she says. “This comes with the app update.  Tinder, too, is asking for your location using wifi, which is more  accurate than the GPRS location.”&lt;br /&gt;It’s alright to agree to these  permissions, she says, so long as you’re aware of what you’re signing up  for and how that data is going to be used.&lt;br /&gt;&lt;br /&gt;If you have qualms  about agreeing to this, there are usually alternatives you can find,  adds Rohini Lakshane, program officer, Centre for Internet and Society.  “If not, it’s usually a trade-off: you have to see how much you want the  app,” she points out.&lt;br /&gt;&lt;br /&gt;There are, however, other apps that might be duplicates asking for access to your device or files, cautions Chinmayi. &lt;br /&gt;&lt;br /&gt;“If a cooking app, a simple one that gives you recipes, asks for your call logs or other files, for example,” she says.&lt;br /&gt;&lt;br /&gt;A  discerning user, interjects Rohini, will check for permission to access  files or functions that are not strictly necessary for the features the  app supports. “I don’t want to name anything but some e-commerce and  travel apps ask to access your browsing history and the other apps or  networks you’re connect to. It could be to serve you contextual ads or  content, like Zomato, or to sell it to someone. You never know,” she  says. However, some devices or versions of the Android OS let you  control what permissions you enable, she informs.&lt;br /&gt;&lt;br /&gt;Aeronautical  engineer Pavan Raj P V says he takes care not to compromise on his  safety, whenever possible. “But there are a few apps that I have on my  phone no matter what — Facebook, WhatsApp, LinkedIn, Instagram. Most of  them auto-update and require no extra permissions.”&lt;br /&gt;&lt;br /&gt;However, he  has noticed that LinkedIn asks for access to Gmail contacts that you  could accidentally accept “if you’re logging in mechanically”.&lt;br /&gt;&lt;br /&gt;Varsha  C V, communications specialist at Karnataka State Highways Improvement  Project, says, “Last month, my husband asked me to download a Google app  for free calls that required all sorts of permissions, such as access  to your phone logs. When Skype offers the same features without asking  for all this, why should anyone use this app?”&lt;br /&gt;&lt;br /&gt;She believes  privacy in India is not taken as seriously as it should be. “You should  keep in mind that if you’re giving them access to your contacts, you’re  also compromising on others’ privacy,” she points out.&lt;br /&gt;&lt;br /&gt;Lokanand, a  sound engineer, admits to not paying attention to what he’s giving apps  access to. “I’m no expert but if you ask me, you download apps because  they are useful. So I don’t really bother about what I’m saying yes to.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/deccan-herald-chetana-divya-vasudev-october-4-2016-an-appening-world'&gt;https://cis-india.org/internet-governance/news/deccan-herald-chetana-divya-vasudev-october-4-2016-an-appening-world&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>WhatsApp</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2016-10-05T00:24:19Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/events/firstfridayatcis-amutha-arunachalam-stand-shielded-of-digital-rights-may-05">
    <title>Amutha Arunachalam - Stand Shielded of Digital Rights (Delhi, May 05, 4 pm)</title>
    <link>https://cis-india.org/internet-governance/events/firstfridayatcis-amutha-arunachalam-stand-shielded-of-digital-rights-may-05</link>
    <description>
        &lt;b&gt;We are proud to announce that Amutha Arunachalam will be the speaker at the May #FirstFriday event at the CIS Delhi office. Amutha is Principal Technical Officer in the Council Of Scientific and Industrial Research. The talk will be on digital signatures, traceability of time-stamps, and setting up an Indian Standard (Digital) Time. If you are joining us, please RSVP at the soonest as we have only limited space in our office.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Amutha Arunachalam&lt;/strong&gt;&lt;/h3&gt;
&lt;h4&gt;Principal Technical Officer, Council of Scientific and Industrial Research&lt;/h4&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/internet-governance/files/amutha-arunachalam/image" alt="Amutha Arunachalam" class="image-inline" title="Amutha Arunachalam" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Amutha Arunachalam entered the Indian Government service as an Intelligence Officer in Ministry of Home Affairs in 1988 after working at the Indian Institute of  Technology Madras in Fibre Optic communication Laboratory. She later moved to the Council of Scientific and Industrial Research in the field of Information Technology. She managed the IT infrastructure of the CSIR lab (Central Road Research Institute) till  2006 and moved to CSIR Head Quarters and contributed in the ICT refurbishment drive, mainly in the IT with a major contribution in establishing DATA Centre, implementing network security, linking CSIR HQ to the National Knowledge Network facility extended by National Information Centre(NIC) before joining UIDAI.&lt;/p&gt;
&lt;p&gt;In UIDAI (National Identity Project) she managed the Data Center operations that includes critical CIDR (Central Identification Repository) and was responsible for setting up Infrastructure to roll out Disaster recovery centre, Aadhaar Enrolment Service, Benchmarking  of  UIDAI  Enrolment ,  Authentication Applications and setting up of Backend infrastructure of the Authentication Service for Roll out to citizens. After the five year Deputation at UIDAI (Feb 2016), she is currently posted in the Council of Scientific and Industrial Research working in the Area of Policy in Cyber Security for CSIR, Enhancing Research with collaborative, networking  and Building unified CSIR Ecosystem with Enterprise platform.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;RSVP&lt;/strong&gt;&lt;/h3&gt;
&lt;iframe src="https://docs.google.com/forms/d/e/1FAIpQLSfWGNDezfJOi3UU7GpAWkrKn0uOMlCsV2P_6QEHqPWCb6JSqA/viewform?embedded=true" frameborder="0" marginwidth="0" marginheight="0" height="666" width="600"&gt;Loading...&lt;/iframe&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Location&lt;/strong&gt;&lt;/h3&gt;
&lt;iframe src="https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d876.157470894426!2d77.20553462919722!3d28.550842498903158!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x0%3A0x834072df81ffcb39!2sCentre+for+Internet+and+Society!5e0!3m2!1sen!2sin!4v1493818109951" frameborder="0" height="450" width="600"&gt;&lt;/iframe&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/events/firstfridayatcis-amutha-arunachalam-stand-shielded-of-digital-rights-may-05'&gt;https://cis-india.org/internet-governance/events/firstfridayatcis-amutha-arunachalam-stand-shielded-of-digital-rights-may-05&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>sumandro</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cybersecurity</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Digital India</dc:subject>
    
    
        <dc:subject>#FirstFridayAtCIS</dc:subject>
    
    
        <dc:subject>E-Governance</dc:subject>
    

   <dc:date>2017-05-03T13:30:32Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/business-standard-november-28-2012-nirmalya-behera-amnesty-international-calls-for-review-of-66a-of-it-act">
    <title>Amnesty International calls for review of 66A of IT act</title>
    <link>https://cis-india.org/news/business-standard-november-28-2012-nirmalya-behera-amnesty-international-calls-for-review-of-66a-of-it-act</link>
    <description>
        &lt;b&gt;The review seeks to bring the Act in line with international human rights law standards on freedom of expression.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;This article by Nirmalya Behera was &lt;a class="external-link" href="http://www.business-standard.com/india/news/amnesty-international-calls-for-review66ait-act/197621/on"&gt;published in the Business Standard&lt;/a&gt; on November 28, 2012.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;Joining in the row over arrest of two girls in Maharastra for &lt;a href="http://www.business-standard.com/india/prof_page.php?search=Facebook&amp;amp;select=1" target="_blank"&gt;Facebook&lt;/a&gt; comments, the human rights group, Amnesty International, has called for review of the Section 66A of the Information Technology Act, 2000. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In a letter to Kapil Sibal, Union minister for Communications and  Information Technology, the London based human right watchdog has asked  for reviewing the section and bringing it in line with international  human rights law standards on freedom of expression.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;The human rights group and the Centre for Internet and Society believe that Section 66A, which was amended in 2008, is not in line with the constitution of India and internationally accepted standards on freedom of expression. They termed the section as imprecise and over board.&lt;br /&gt;&lt;br /&gt;Amnesty has also called for laying down clear and comprehensive explanations of the restrictions on free speech either in the IT act or in the rules in order to prevent the abuse of the provision by various state law enforcement officials and frame the explanations after consulting it with the public.&lt;br /&gt;&lt;br /&gt;“The Internet should be a force for political freedom, not repression. People have the right to seek and receive information and to express their peaceful beliefs without fear, or interference. But under Section 66A, even a peaceful posting could lead to a prison sentence of up to three years”, it said in its letter.&lt;br /&gt;&lt;br /&gt;It may be noted that two girls- Shaheen Dhada and her friend Renu Srinivasan were arrested on November 19, after Dhada had lamented in a Facebook post about the shutdown in Mumbai due to Bal Thackeray's funeral and were later released on bail. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/business-standard-november-28-2012-nirmalya-behera-amnesty-international-calls-for-review-of-66a-of-it-act'&gt;https://cis-india.org/news/business-standard-november-28-2012-nirmalya-behera-amnesty-international-calls-for-review-of-66a-of-it-act&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Information Technology</dc:subject>
    

   <dc:date>2012-11-30T06:19:45Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/amid-unrest-in-the-valley-students-see-a-dark-wall">
    <title>Amid Unrest in the Valley, Students See a Dark Wall</title>
    <link>https://cis-india.org/internet-governance/blog/amid-unrest-in-the-valley-students-see-a-dark-wall</link>
    <description>
        &lt;b&gt;Strap: Frequent, prolonged restrictions on internet have kept many from using the learning resource.&lt;/b&gt;
        &lt;p class="normal" style="text-align: justify; "&gt;&lt;b&gt;Srinagar, J&amp;amp;K: &lt;/b&gt;On November 18, Srinagar lost 3G and 4G connectivity after a militant and a sub-inspector of the Jammu &amp;amp; Kashmir police force were killed, and one militant caught alive in a&lt;a href="http://www.uniindia.com/news/states/si-militant-killed-1-ultra-arrested-alive-in-srinagar/1050461.html"&gt; &lt;/a&gt;&lt;a href="http://www.uniindia.com/news/states/si-militant-killed-1-ultra-arrested-alive-in-srinagar/1050461.html"&gt;brief encounter&lt;/a&gt; on the outskirts of the city, near Zakoora crossing. District authorities said data connectivity was snapped to “maintain law and order”.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/JKEducation1.png/@@images/77d075bb-5b8f-4f93-81ad-1f6e9a56f35c.png" alt="JK Education 1" class="image-inline" title="JK Education 1" /&gt;&lt;/th&gt;&lt;th&gt;&lt;img src="https://cis-india.org/home-images/copy_of_JKEducation2.png" alt="JKEducation2" class="image-inline" title="JKEducation2" /&gt;&lt;/th&gt;&lt;th&gt;&lt;img src="https://cis-india.org/home-images/JKEducation3.png" alt="JK Education 3" class="image-inline" title="JK Education 3" /&gt;&lt;/th&gt;&lt;th style="text-align: center; "&gt;&lt;img src="https://cis-india.org/home-images/JKEducation4.png" alt="JK Education 4" class="image-inline" title="JK Education 4" /&gt;&lt;br /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p class="normal" style="text-align: center; "&gt;&lt;span class="discreet"&gt;Students in Srinagar’s SPS Library. Picture Courtesy: Aakash Hassan &lt;/span&gt;&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;But to Jasif Ayoub, an aspiring chartered accountant, it seemed like an obstruction to his exam preparations. Not being able to access lectures and texts online, Ayoub was perturbed. He had moved from Anantnag in south Kashmir, to Srinagar, only to have an easy access to the vast pool of information on the world wide web. “My hometown witnesses internet shutdowns very frequently. That is why I moved to live with relatives in Srinagar to prepare for my exams. But the internet speed here too is getting worse by the day,” says Ayoub.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;The internet is usually the first administrative casualty when any law &amp;amp; order situation arises in the Kashmir Valley, which has been restive and agitated over the last two decades. Despite the frequency of shutdowns, the state still does not issue a prior warning, or offer emergency connectivity measures. Residents know the pattern now: the mobile internet and SMS are the first to go down, and then broadband and other lease-line service providers follow.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;J&amp;amp;K tops the list of Indian states that have witnessed most number of internet shutdowns, with 27 being the count from 2012 to 2017, according to &lt;a href="https://internetshutdowns.in/"&gt;&lt;i&gt;internetshutdowns.in&lt;/i&gt;&lt;/a&gt;, run by Software Freedom Law Centre&lt;i&gt;. &lt;/i&gt;There has been a sharp rise in the curbs on internet imposed this year, with over 30 shutdowns until November 22. Government authorities who issue and implement these bans say it is the only way to undercut the strength of social media in organising movements and resistance. The prime example is&lt;a href="http://kashmirdispatch.com/2016/07/24/11-burhan-funeral-pictures-which-you-missed-due-to-internet-clampdown/144891/"&gt; &lt;/a&gt;&lt;a href="http://kashmirdispatch.com/2016/07/24/11-burhan-funeral-pictures-which-you-missed-due-to-internet-clampdown/144891/"&gt;Burhan Wani&lt;/a&gt;, the 21-year-old Hizb-ul-Mujahideen commander who had used his Facebook account to&lt;a href="http://www.firstpost.com/india/the-virtual-world-hizb-ul-mujahideens-burhan-wani-innovates-to-influence-youth-in-kashmir-2794392.html"&gt; &lt;/a&gt;&lt;a href="http://www.firstpost.com/india/the-virtual-world-hizb-ul-mujahideens-burhan-wani-innovates-to-influence-youth-in-kashmir-2794392.html"&gt;popularise&lt;/a&gt; and justify militant resistance. Wani’s death saw protests erupting across the Valley, which made the state snap internet services for about&lt;a href="https://scroll.in/latest/827906/prepaid-mobile-internet-services-restored-in-kashmir-after-six-months"&gt; &lt;/a&gt;&lt;a href="https://scroll.in/latest/827906/prepaid-mobile-internet-services-restored-in-kashmir-after-six-months"&gt;six months&lt;/a&gt; on prepaid mobile networks. For four months, there was no internet access on postpaid mobile networks too. These have been the longest intervals of ban. However, day-long, hour-long and even week-long periods of non-connectivity are alarmingly common.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;The incessant disruption of internet services prevents students from accessing online education resources. Class IX student Haiba Jaan in Srinagar depends on lectures from Khan Academy,  an online coaching centre, to clarify a lot of concepts. A resident of Hyderpora in Srinagar, Haiba points to the i-Pad in her hand. “This is the best way of learning," she says. "I was not satisfied with my teachers in school or tuition classes. I found studying on the internet quite useful. But, the problem with that is the regular internet shutdowns." Her parents got a postpaid broadband connection the previous year to help Haiba. "But even that gives up many times during total internet shutdowns," says Haiba.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;In May this year, the government suspended the use of 22 social media and messaging platforms in Kashmir for a month. Skype was one of the messaging services banned. This put Mehraj Din through great trouble. Shortlisted for a summer programme at Istanbul, Turkey, this scholar of Islamic Studies at Kashmir University, had to appear for the final interview via Skype. "The ban could have ended all my chances to get selected had the organisers not agreed to an audio interview considering the ground situation here," says Mehraj, who is currently compiling his dissertation for the university. "I have a deadline to meet, but repeated shutdowns have affected my work," he says. "This a punishment from the State."&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;&lt;b&gt;Full libraries, half studies&lt;/b&gt;&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;When home and mobile internet connections are snapped, the state government's e-learning initiative in public libraries provides some respite. Mehrosha Rasool wants to secure an MBBS seat through the NEET competitive exam. She visits the SPS library in Srinagar religiously to access the study material that has been downloaded and made available on computers. The 17-year-old resident of Nishat in Srinagar says libraries are useful since one never knows how long the internet services at home will stay stable. Irshad Ahmad, another student utilising the facilities at SPS library, says he moved to Srinagar from Pattan town of north Kashmir because "this facility of accessing education material is not available at the library in my tehsil."&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;Most prominent libraries in Srinagar have computers and tablets for students’ access, "But the rooms often become overcrowded as hundreds of students have registered at the libraries for internet facilities," says Mehrosha.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;Schools in the Valley, meanwhile, rely on traditional means in the absence of the e-learning systems. Javaid Ahmad Wani, a political science teacher from south Kashmir’s Anantnag, believes that with little time in the year to even complete the basic syllabus thanks to frequent and sudden school closures during periods of unrest, supplementary e-learning is a distant possibility. Even when teachers and students do have access to these resources to stay updated, internet shutdowns make them unreliable. Therefore, teachers and schools stick to conventional means. Javaid admits that he has himself lost opportunities to an internet shutdown. “I could not submit the form for the main exam of the J&amp;amp;K public service last year because there was no Internet,” he says.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;&lt;b&gt;Curbs pinch civil service aspirants&lt;/b&gt;&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;Many among the civil service aspirants are dependent on the internet for preparations. Anees Malik, a resident of Shopian, is preparing for the civil service exams. "I cannot afford coaching, so I rely on the internet," he says, especially for mock exams and previous question papers. "In such a situation, losing connectivity almost every other week is the worst thing to happen.”&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;Sakib Wani, a Kupwara resident who is currently studying chemistry in Uttarakhand, notices a marked indifference in Kashmir to using online resources. "Those applying for scholarships and pursuing higher education may be using it but not to the extent that students in other states of India do it,” Sakib says. He believes that the repeated internet ban could be a possible reason for students to not opt for online educational resources. With colleges and schools shut for weeks during conflict periods, the internet could have been a great way to continue education formally and personally, but the repeated shutdowns have closed that door of opportunity too.&lt;/p&gt;
&lt;p class="normal" style="text-align: justify; "&gt;Aakash Hassan is a Srinagar​-based freelance writer and a member of &lt;a href="http://www.101reporters.com/"&gt;101Reporters.com&lt;/a&gt;, a pan-India network of grassroots reporters. He has reported on conflict, environment, health and other issues for different publications across India.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p class="normal" style="text-align: justify; "&gt;Shutdown stories are the output of a collaboration between 101 Reporters and CIS with support from Facebook.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/amid-unrest-in-the-valley-students-see-a-dark-wall'&gt;https://cis-india.org/internet-governance/blog/amid-unrest-in-the-valley-students-see-a-dark-wall&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Aakash Hassan</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Shutdown</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2017-12-21T14:07:46Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>




</rdf:RDF>
