<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 21 to 35.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/rti-requests-to-bsnl-mtnl-regarding-security-equipment"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/security-surveillance-and-data-sharing.pdf"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/mlats-and-cross-border-sharing-of-information-in-india.pdf"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/policy-recommendations-for-surveillance-law-in-india-and-analysis-of-legal-provisions-on-surveillance-in-india-and-the-necessary-and-proportionate-principles.pdf"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/surveillance-industry-india.pdf"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/chart_11.png"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/big-democracy-big-surveillance-indias-surveillance-state"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/spy-files-three"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/Brochures.zip"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/report-on-the-third-privacy-round-table-meeting"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/comparison-of-draft-dna-profiling-bills"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/workshop-on-the-uid-and-npr"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/blog/rti-requests-to-bsnl-mtnl-regarding-security-equipment">
    <title>  Right to Information (RTI) Requests to BSNL and MTNL Regarding Security Equipment</title>
    <link>https://cis-india.org/internet-governance/blog/rti-requests-to-bsnl-mtnl-regarding-security-equipment</link>
    <description>
        &lt;b&gt;As part of research, on July 2, 2013, the Centre for Internet and Society (CIS) had sent Right to Information (RTI) requests to two of the largest internet service providers (ISPs) in India: Mahanagar Telephone Nigam Limited (MTNL) and Bharat Sanchar Nigam Limited (BSNL) requesting answers to some questions.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Answers to the following questions were requested:&lt;/p&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;li&gt;Please list the companies from which MTNL/BSNL has bought all its security equipment.&lt;/li&gt;
&lt;li&gt;What type of security equipment does MTNL/BSNL use to assist Indian law enforcement agencies in detecting and preventing crime, terrorism and all other illegal activity? Please provide the certification for all such equipment.&lt;/li&gt;
&lt;li&gt;What malware does MTNL/BSNL test for? What does MTNL/BSNL use for testing malware in its networks?&lt;/li&gt;
&lt;li&gt;Which proxy server does MTNL/BSNL use and is it used for filtering data? If so, what type of data is being filtered and for what purpose? Is authorisation required and if so, by whom?&lt;/li&gt;
&lt;li&gt;Does MTNL/BSNL use FinFly ISP? If so, who authorises its use and under what conditions?&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;M. K. Sheda, the appellate authority of MTNL, responded to the above questions on August 3, 2013 with the following answers:&lt;/p&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;li&gt;MTNL procures all its equipment through an open competitive bidding process and the details of all past tenders are available on the MTNL website. Equipment from multiple vendors are operational in GSM MTNL Packet-Core Network and specific 	names cannot be given due to security reasons.&lt;/li&gt;
&lt;li&gt;MTNL uses the security equipment by the Department of Telecommunications, Government of India, to assist Indian law enforcement agencies. The details 	cannot be disclosed as the information is classified as "secret" as per MTNL IT Policy Revision 2.0 and also comes under Section -8 (1) (a) and (d) of the 	RTI Act 2005.&lt;/li&gt;
&lt;li&gt;MTNL GSM Packet Core equipment for data access uses MTNL ISP as its interface with external entities. Thus information is pertaining to MTNL ISP and hence a reply may please be taken from the GM (Broadband) unit.&lt;/li&gt;
&lt;li&gt;Same answer as "3" above.&lt;/li&gt;
&lt;li&gt;Same answer as "3" above.&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;BSNL has still not responded to the above questions.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Click below to download the respective files:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/bsnl-rti-application-2013.pdf" class="external-link"&gt;RTI Application to BSNL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/reply-from-mtnl-to-rti-application.pdf" class="external-link"&gt;Reply from MTNL&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/rti-requests-to-bsnl-mtnl-regarding-security-equipment'&gt;https://cis-india.org/internet-governance/blog/rti-requests-to-bsnl-mtnl-regarding-security-equipment&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>RTI Application</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2015-02-25T15:04:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/security-surveillance-and-data-sharing.pdf">
    <title>Security, Surveillance and Data Sharing Schemes and Bodies in India</title>
    <link>https://cis-india.org/internet-governance/blog/security-surveillance-and-data-sharing.pdf</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/security-surveillance-and-data-sharing.pdf'&gt;https://cis-india.org/internet-governance/blog/security-surveillance-and-data-sharing.pdf&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>


   <dc:date>2015-03-14T02:35:31Z</dc:date>
   <dc:type>File</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/mlats-and-cross-border-sharing-of-information-in-india.pdf">
    <title>Mutual Legal Assistance Treaties (MLATs) and Cross Border Sharing of Information in India</title>
    <link>https://cis-india.org/internet-governance/blog/mlats-and-cross-border-sharing-of-information-in-india.pdf</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/mlats-and-cross-border-sharing-of-information-in-india.pdf'&gt;https://cis-india.org/internet-governance/blog/mlats-and-cross-border-sharing-of-information-in-india.pdf&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>


   <dc:date>2015-03-14T02:45:24Z</dc:date>
   <dc:type>File</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/policy-recommendations-for-surveillance-law-in-india-and-analysis-of-legal-provisions-on-surveillance-in-india-and-the-necessary-and-proportionate-principles.pdf">
    <title>Policy Recommendations for Surveillance Law in India and an Analysis of Legal Provisions on Surveillance in India and the Necessary &amp; Proportionate Principles</title>
    <link>https://cis-india.org/internet-governance/blog/policy-recommendations-for-surveillance-law-in-india-and-analysis-of-legal-provisions-on-surveillance-in-india-and-the-necessary-and-proportionate-principles.pdf</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/policy-recommendations-for-surveillance-law-in-india-and-analysis-of-legal-provisions-on-surveillance-in-india-and-the-necessary-and-proportionate-principles.pdf'&gt;https://cis-india.org/internet-governance/blog/policy-recommendations-for-surveillance-law-in-india-and-analysis-of-legal-provisions-on-surveillance-in-india-and-the-necessary-and-proportionate-principles.pdf&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>


   <dc:date>2015-03-14T03:08:04Z</dc:date>
   <dc:type>File</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/surveillance-industry-india.pdf">
    <title>The Surveillance Industry in India</title>
    <link>https://cis-india.org/internet-governance/blog/surveillance-industry-india.pdf</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/surveillance-industry-india.pdf'&gt;https://cis-india.org/internet-governance/blog/surveillance-industry-india.pdf&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>


   <dc:date>2015-03-14T03:20:42Z</dc:date>
   <dc:type>File</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/chart_11.png">
    <title>CMS chart</title>
    <link>https://cis-india.org/chart_11.png</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/chart_11.png'&gt;https://cis-india.org/chart_11.png&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>


   <dc:date>2014-02-22T13:47:30Z</dc:date>
   <dc:type>Image</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/big-democracy-big-surveillance-indias-surveillance-state">
    <title>Big Democracy, Big Surveillance: India's Surveillance State</title>
    <link>https://cis-india.org/internet-governance/blog/big-democracy-big-surveillance-indias-surveillance-state</link>
    <description>
        &lt;b&gt;In India, surveillance is on the rise by the state to tackle crime and terrorism, and private companies are eager to meet the demand.&lt;/b&gt;
        &lt;p&gt;This article by Maria Xynou was&lt;a class="external-link" href="http://www.opendemocracy.net/opensecurity/maria-xynou/big-democracy-big-surveillance-indias-surveillance-state"&gt; published by OpenDemocracy&lt;/a&gt; on 10 February 2014.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Worried about the secret, mass surveillance schemes being carried out by the NSA? While we should be, some of the surveillance schemes in the world's largest democracy, India, are arguably&lt;/span&gt;&lt;a href="http://www.thehindu.com/news/national/indias-surveillance-project-may-be-as-lethal-as-prism/article4834619.ece"&gt; in the same league&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;a href="http://www.amazon.com/Globalization-Surveillance-Armand-Mattelart/dp/0745645119"&gt;Surveillance is being globalised&lt;/a&gt; to the extent that even India, a country with huge poverty issues, is investing millions of dollars in creating an &lt;a href="http://www.thehindu.com/news/national/indias-surveillance-project-may-be-as-lethal-as-prism/article4834619.ece"&gt;expansive surveillance regime&lt;/a&gt;. However, why would communications monitoring interest Indian authorities, when the majority of the population lives below the line of poverty and &lt;a href="http://wearesocial.net/tag/india/"&gt;only 17% of the population&lt;/a&gt;&lt;a href="http://wearesocial.net/tag/india/"&gt; has access to the Internet&lt;/a&gt;?&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The official political motivation behind surveillance in India appears to be the government's &lt;a href="http://digitaljournal.com/article/268467"&gt;determination to tackle terrorism&lt;/a&gt; in the country. The &lt;a href="http://edition.cnn.com/2013/09/18/world/asia/mumbai-terror-attacks/"&gt;2008 Mumbai terrorist attacks&lt;/a&gt; were arguably a similar landmark to the 9/11 terrorist attacks in the US, and both governments officially announced their intention to carry out surveillance as a counter-terrorism measure. However, unlike in the west, terrorist attacks in India are much more common, and the National Security Adviser reported in 2008 that 800 terrorist cells were operational in the country. With India’s history of &lt;a href="http://www.thenews.com.pk/Todays-News-2-210676-Major-terror-attacks-in-India-during-last-25-years"&gt;major terror attacks in India over the last 25 years&lt;/a&gt;, it's easy for one to be persuaded that terrorism is actually a major threat to national security.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;India's surveillance schemes&lt;/b&gt;&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;India’s surveillance programs mostly started following the 2008 Mumbai terror attacks. That was when the Ministry of Home Affairs first proposed the creation of a &lt;a href="http://www.pib.nic.in/newsite/erelease.aspx?relid=56395"&gt;National Intelligence Grid (NATGRID)&lt;/a&gt;, which will give &lt;a href="http://articles.economictimes.indiatimes.com/2013-09-10/news/41938113_1_executive-order-national-intelligence-grid-databases"&gt;11 intelligence and investigative agencies real-time access to 21 citizen data sources&lt;/a&gt; to track terror activities. These citizen data sources will be provided by various ministries and departments, otherwise called “provider agencies”, and will include &lt;a href="http://articles.economictimes.indiatimes.com/2013-09-10/news/41938113_1_executive-order-national-intelligence-grid-databases"&gt;bank account details, telephone records, passport data and vehicle registration details&lt;/a&gt;, among other types of data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Ministry of Home Affairs has &lt;a href="http://www.deccanherald.com/content/181065/mha-seeks-over-rs-3400.html"&gt;sought over Rs. 3,400 crore&lt;/a&gt; (around USD 540 million!) for the implementation of NATGRID, which aims to create comprehensive patterns of intelligence by collecting sensitive information from databases of departments like the police, banks, tax and telecoms to supposedly track any terror suspect and incident.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But NATGRID is far from India's only data sharing scheme. In 2009 the Cabinet Committee on Economic Affairs approved the creation and implementation of the &lt;a href="http://pib.nic.in/newsite/erelease.aspx?relid=49261"&gt;Crime and Criminal Tracking Network &amp;amp; &lt;/a&gt;&lt;a href="http://pib.nic.in/newsite/erelease.aspx?relid=49261"&gt;Systems&lt;/a&gt; (CCTNS), which would facilitate the sharing of databases among &lt;a href="http://ncrb.nic.in/AboutCCTNS.htm"&gt;14,000 police stations across all 35 states and Union Territories&lt;/a&gt; of India, excluding 6,000 police offices which are high in the police hierarchy. &lt;a href="http://www.thehindu.com/news/national/govt-launches-crime-tracking-pilot-project/article4272857.ece"&gt;Rs. 2,000 crore&lt;/a&gt; (around USD 320 million) have been allocated for the CCTNS, which is being implemented by the National Crime Records Bureau under the national e-governance scheme. The CCTNS not only increases transparency by automating the function of police stations, but also &lt;a href="http://ncrb.nic.in/AboutCCTNS.htm"&gt;provides the civil police with tools, technology and information&lt;/a&gt; to facilitate the investigation of crime and detection of criminals.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But apparently, sharing data and linking databases is not enough to track criminals and terrorists. As such, in the aftermath of the 2008 Mumbai terror attacks, the Indian government also implemented various interception systems. In September 2013&lt;a href="http://www.thehindu.com/news/national/govt-violates-privacy-safeguards-to-secretly-monitor-internet-traffic/article5107682.ece"&gt; it was reported&lt;/a&gt; that the Indian government has been operating Lawful Intercept &amp;amp; Monitoring (LIM) systems, widely in secret. In particular, &lt;a href="http://www.thehindu.com/news/national/govt-violates-privacy-safeguards-to-secretly-monitor-internet-traffic/article5107682.ece"&gt;mobile operators in India have deployed their own LIM systems&lt;/a&gt; allowing for the so-called “lawful interception” of calls by the government. And possibly to enable this, mobile operators are required to provide &lt;a href="http://telecomtalk.info/dot-tightens-norms-no-mobile-connection-without-physical-verification/102120/"&gt;subscriber verification&lt;/a&gt; to the Telecom Enforcement, Resource and Monitoring (TERM) cells of the Department of Telecommunications.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the case of Internet traffic, the LIM systems are deployed at the &lt;a href="http://www.thehindu.com/news/national/govt-violates-privacy-safeguards-to-secretly-monitor-internet-traffic/article5107682.ece"&gt;international gateways of large Internet Service Providers (ISPs) &lt;/a&gt;and expand to a broad search across all Internet traffic using “keywords” and “key-phrases”. In other words, security agencies using LIM systems are capable of launching a search for suspicious words, resulting in the indiscriminate monitoring of all Internet traffic, possibly without court oversight and without the knowledge of ISPs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India has also automated and centralized the interception of communications through the &lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central Monitoring System (CMS)&lt;/a&gt;. This project was initially envisioned in 2009, following the 2008 Mumbai terror attacks and was approved in 2011.  The CMS intercepts all telecommunications in India and &lt;a href="https://cis-india.org/internet-governance/blog/india-central-monitoring-system-something-to-worry-about"&gt;centrally stores the data in national and regional databases&lt;/a&gt;. The CMS will be connected with the Telephone Call Interception System (TCIS) which will help monitor voice calls, SMS and MMS, fax communications on landlines, CDMA, video calls, GSM and 3G networks. &lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Agencies&lt;/a&gt; which will have access to the CMS include the Intelligence Bureau (IB), the Central Bureau of Investigation (CBI), the Directorate of Revenue Intelligence (DRI), the Research and Analysis Wing (RAW) and the National Investigation Agency (NIA).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Unlike mainstream interception, where service providers are required to intercept communications and provision interception requests to law enforcement agencies, the Central Monitoring System will automate the entire process of interception. This means that the CMS authority will have centralized access to all intercepted data and that the authority can also bypass service providers in gaining such access. Once security agencies have access to this data, they are equipped with &lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Direct Electronic Provisioning, filters and alerts on the target numbers&lt;/a&gt;, as well as with Call Details Records (CDR) analysis and data mining tools to identify the personal information of target numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given that roughly &lt;a href="http://wearesocial.net/tag/india/"&gt;73% of India's population uses mobile phones&lt;/a&gt;, this means that the Central Monitoring System can potentially affect about 893 million people, more than double the population of the United States! However, how is it even possible for Indian authorities to mine the data of literally millions of people? Who supplies Indian authorities with the technology to do this and what type of technology is actually being used?&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;India's surveillance industry&lt;/b&gt;&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;India has the world's second largest population, consisting of more than a billion people and an expanding middle class. Undoubtedly, India is a big market and many international companies aspire in investing in the country. Unfortunately though, along with everything else being imported into India, surveillance technologies are no exception.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Some of the biggest and most notorious surveillance technology companies in the world, such as ZTE, Utimaco and Verint, have offices in India. Even &lt;a href="https://citizenlab.org/2013/04/for-their-eyes-only-2/"&gt;FinFisher command and control servers&lt;/a&gt; have been found in India. However, in addition to allowing foreign surveillance technology companies to create offices and to sell their products and solutions in the country, local companies selling controversial spyware appear to be on the rise too.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kommlabs Dezign is an Indian company which loves to show off its Internet monitoring solutions at&lt;a href="http://www.kommlabs.com/events.asp"&gt; various ISS trade shows&lt;/a&gt;, otherwise known as &lt;a href="http://www.wired.com/beyond_the_beyond/2011/12/at-the-wiretappers-ball/"&gt;“the Wiretapper's Ball”&lt;/a&gt;. In particular, Kommlabs Dezign sells VerbaNET, an Internet Interception Solution, as well as VerbaCENTRE, which is a Unified Monitoring Centre that can even detect cognitive and emotional stress in voice calls and flag them! In other words, Kommlabs Dezign makes a point that not only should we worry about what we text and say over our phones, but that we should also worry about what we sound like when on the phone.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Vehere is another Indian company which sells various surveillance solutions and notably sells vCRIMES, which is a Call Details Records (CDR) analysis system. VCRIMES is used to analyse and gather intelligence and to unveil hidden interconnections and relations through communications. This system also includes a tool for detecting sleeper cells through advanced statistical analysis and &lt;a href="http://www.veheretech.com/products/vcrimes/"&gt;can analyse more than 40 billion records in less than 3 seconds&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="http://www.paladion.net/"&gt;Paladion Networks&lt;/a&gt; is headquartered in Bangalore, India and sells various Internet Monitoring Systems, Telecom Operator Interception Systems, SSL Interception and Decryption Systems and Cyber Cafe Monitoring Systems to law enforcement agencies in India and abroad. In fact, Paladion Networks even states in its website that its &lt;a href="http://www.paladion.net/client_list.html"&gt;customers include India's Ministry of Information Technology and the U.S Department of Justice&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;ClearTrail Technologies is yet another Indian company which not only &lt;a href="http://www.issworldtraining.com/iss_europe/sponsors.html"&gt;sponsors global surveillance trade shows&lt;/a&gt; but also sells a wide range of monitoring solutions to law enforcement agencies in India and abroad. ComTrail is a solution for the &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;centralised mass interception and monitoring of voice and data networks&lt;/a&gt;, including Gmail, Yahoo, Hotmail, BlackBerry, ICQ and GSM voice calls. Furthermore, ComTrail is equipped to handle millions of communications per day, correlating identities across multiple networks, and can instantly analyse data across thousands of terabytes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;ClearTrail also sells xTrail, which is a solution for the &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;targeted interception, decoding and analysis of data traffic over IP networks&lt;/a&gt; and which enables law enforcement agencies to intercept and monitor targeted communications without degrading the service quality of the IP network. Interestingly, xTrail can filter based on a “pure keyword”, a URL/Domain with a keyword, a mobile number or even with just a user identity, such as an email ID, chat ID or VoIP ID.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Apparently, some the biggest challenges that law enforcement agencies face when monitoring communications include cases when targets operate from public Internet networks and/or use encryption. However, it turns out that ClearTrail's QuickTrail solution is designed to &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;gather intelligence from public Internet networks&lt;/a&gt;, when a target is operating from a cyber cafe, a hotel, a university campus or a free Wi-Fi zone. This device can remotely deploy spyware into a target's computer and supports protocol decoding, including HTTP, SMTP, POP3 and HTTPS.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Additionally, QuickTrail can identify a target machine on the basis of metadata, such as an IP address, and can monitor Ethernet LANs in real time, as well as monitor Gmail, Yahoo and all other HTTPS-based communications. ClearTrail's mTrail is designed for the passive &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;'off-the-air' interception of GSM communications&lt;/a&gt;, including the interception of targeted calls from pre-defined suspect lists and the monitoring of SMS and protocol information. MTrail also identifies a target's location by using signal strength, target numbers, such as IMSI, TIMSI, IMEI or MSI SDN, which makes it possible to listen to the conversation of so-called “lawfully intercepted” calls in near real-time.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In short, it looks like India is reaching the top league when it comes to surveillance technologies, especially since many of its companies and their products appear to be just as scary as some of the most sophisticated spying gear sold by the West. India may be the world's largest (by population) democracy, but that means that it has a huge population with way too many opinions...and apparently, the private and public sectors in India appear to be joining forces to do something about it.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;So do Indians have nothing to hide?&lt;/b&gt;&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;A very popular rhetoric in both India and the west is that citizens should &lt;i&gt;not&lt;/i&gt; be concerned about surveillance because, after all, if they are not terrorists, they should have nothing to hide. However, privacy advocate &lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;Caspar Bowden&lt;/a&gt; has rightfully stated that this rhetoric is fundamentally flawed and that we should all indeed “have something to hide”. But is privacy just about “having something to hide”? &lt;a href="http://www.youtube.com/watch?v=GMN2360LM_U"&gt;Jacob Appelbaum&lt;/a&gt; has stated that this rhetoric is merely a psychological copying mechanism when dealing with security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It's probably rather comforting and reassuring to think that we are not special or important enough for surveillance to affect us personally. But is that really up to us to decide? Unfortunately not. The very point of data mining is to match patterns, create profiles of individuals and to unveil hidden interconnections and relations. A data analyst can uncover more information about us than what we are even aware of and it is they who decide if our data is “incriminating” or not. Or even worse: in many cases it's up to &lt;i&gt;data mining software&lt;/i&gt; to decide how “special” or “important” we are. And unfortunately, technology is &lt;i&gt;not&lt;/i&gt; infallible.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The world's largest democracy, which is also &lt;a href="http://www.hindustantimes.com/india-news/india-less-corrupt-than-pakistan-ranks-94th-in-world-survey/article1-1158513.aspx"&gt;one of the most corrupt countries in the world&lt;/a&gt;, is implementing many controversial surveillance schemes which lack transparency, accountability and adequate legal backing, and which are largely being carried out in secret. And to make matters worse, India lacks privacy legislation. Over a billion people in a democratic regime are exposed to inadequately regulated surveillance schemes, while a local surveillance industry is thriving without any checks or balances whatsoever. What will this mean for the global future of democracy?&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/big-democracy-big-surveillance-indias-surveillance-state'&gt;https://cis-india.org/internet-governance/blog/big-democracy-big-surveillance-indias-surveillance-state&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Surveillance</dc:subject>
    

   <dc:date>2014-02-28T10:35:09Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/spy-files-three">
    <title>Spy Files 3: WikiLeaks Sheds More Light On The Global Surveillance Industry</title>
    <link>https://cis-india.org/internet-governance/blog/spy-files-three</link>
    <description>
        &lt;b&gt;In this article, Maria Xynou looks at WikiLeaks' latest Spy Files and examines the legality of India's surveillance technologies, as well as their potential connection with India's Central Monitoring System (CMS) and implications on human rights. &lt;/b&gt;
        
&lt;p align="JUSTIFY"&gt;Last month, WikiLeaks released &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt;“&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt;Spy&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt;Files&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt; 3”&lt;/a&gt;&lt;/span&gt;, a mass exposure of the global surveillance trade and industry. WikiLeaks first released the Spy Files in December 2011, which entail brochures, presentations, marketing videos and technical specifications on the global trade of surveillance technologies. Spy Files 3 supplements this with 294 additional documents from 92 global intelligence contractors.&lt;/p&gt;

&lt;h2&gt;&lt;b&gt;So what do the latest Spy Files reveal about India?&lt;/b&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;When we think about India, the first issues that probably come to mind are poverty and corruption, while surveillance appears to be a more “Western” and elitist issue. However, while many other developing countries are excluded from WikiLeaks’ list of surveillance technology companies, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;India&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;is&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;once&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;again&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;on&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;the&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;list&lt;/a&gt;&lt;/span&gt; with some of the most controversial spyware.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;ISS World Surveillance Trade Shows&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;The latest Spy Files include a &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;brochure&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;the&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; 2013&lt;/a&gt;&lt;/span&gt; -the so-called “wiretapper’s ball”- which is the world’s largest surveillance trade show. &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;This&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;years&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;’ &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;ISS&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;World&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;Asia&lt;/a&gt;&lt;/span&gt; will take place in Malaysia during the first week of December and law enforcement agencies from around the world will have another opportunity to view and purchase the latest surveillance tech. The&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;leaked&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; 2013 &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;brochure&lt;/a&gt;&lt;/span&gt; entails a list of last years’ global attendees. According to the brochure, 53% of the attendees included law enforcement agencies and individuals from the defense, public safety and interior security sectors, 41% of the attendees were ISS vendors and technology integrators, while only 6% of the attendees were telecom operators and from the private enterprise. The brochure boasts that 4,635 individuals from 110 countries attended the ISS World trade shows last year and that the percentage of attendance is increasing.&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;The following table lists the &lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;&lt;i&gt;&lt;span style="text-decoration: underline;"&gt;Indian&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;attendees&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;at&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;last&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;years&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;’ &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;/span&gt;:&lt;/p&gt;
 
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;Law Enforcement, Defense and Interior Security Attendees&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;&lt;th&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;Telecom Operators and Private Enterprises Attendees&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;&lt;th&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;ISS Vendors and Technology Integrators Attendees&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Andhra Pradesh India Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;BT&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;AGC Networks&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;CBI Academy&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Cogence Investment Bank&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Aqsacom India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Government of India, Telecom Department&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Reliance Communications&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;ClearTrail Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Cabinet Secretariat&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Span Telecom Pvt. Ldt. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Foundation Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Centre for Development of Telematics (C-DOT)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;Kommlabs&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Chandigarh Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Paladion Networks&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Defence Agency&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Polaris Wireless&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India General Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Polixel Security Systems&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Intelligence Department&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Pyramid Cyber Security&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India National Institute of Criminology&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Schleicher Group&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India office LOKAYUKTA NCT DELHI&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Span Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Police Department, A.P.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;TATA India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Tamil Nadu Police Department&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Tata Consultancy Services&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Indian Police Service, Vigilance&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Telecommunications India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Indian Telecommunications Authority&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Vehere Interactive&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;NTRO India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;SAIC Indian Tamil Nadu Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt; 17                                                        4                                                      15&lt;br /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p align="JUSTIFY"&gt;According to the above table - which is based on data from the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;WikiLeaks&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;’ &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; 2013 &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;brochure&lt;/a&gt;&lt;/span&gt;- the majority of Indian attendees at last years’ ISS World were from the law enforcement, defense and interior security sectors. 15 Indian companies exhibited and sold their surveillance technologies to law enforcement agencies from around the world and it is notable that India’s popular ISP provider, Reliance Communications, attended the trade show too.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In addition to the ISS World 2013 brochure, the Spy Files 3 entail a detailed brochure of a major Indian surveillance technology company: ClearTrail Technologies.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;ClearTrail Technologies&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.clear-trail.com/"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt; &lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt;Technologies&lt;/a&gt;&lt;/span&gt; is an Indian company based in Indore. The document titled &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Internet&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Suite&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;”&lt;/a&gt;&lt;/span&gt; from ClearTrail Technologies boasts about the company’s mass monitoring, deep packet inspection, COMINT, SIGINT, tactical Internet monitoring, network recording and lawful interception technologies. ClearTrail’s Internet Monitoring Suite includes the following products:&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;1. ComTrail: Mass Monitoring of IP and Voice Networks&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ComTrail&lt;/span&gt;&lt;/a&gt; is an integrated product suite for centralized interception and monitoring of voice and data networks. It is equipped with an advanced analysis engine for pro-active analysis of thousands of connections and is integrated with various tools, such as Link Analysis, Voice Recognition and Target Location.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;ComTrail is deployed within a service provider network and its monitoring function correlates voice and data intercepts across diverse networks to provide a comprehensive intelligence picture. ComTrail supports the capture, record and replay of a variety of Voice and IP communications in pretty much any type of communication, including - but not limited to- Gmail, Yahoo, Hotmail, BlackBerry, ICQ and GSM voice calls.&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;Additionally, ComTrail intercepts data from any type of network -whether Wireless, packet data, Wire line or VoIP networks- and can decode hundreds of protocols and P2P applications, including HTTP, Instant Messengers, Web-mails, VoIP Calls and MMS.&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;In short, ComTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Equipped to handle millions of communications per day intercepted over high speed STM &amp;amp; Ethernet Links&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Doubles up as Targeted Monitoring System&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- On demand data retention, capacity exceeding several years&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Instant Analysis across thousands of Terabytes&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Correlates Identities across multiple networks&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Speaker Recognition and Target Location&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;2. xTrail: Targeted IP Monitoring&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;xTrail&lt;/span&gt;&lt;/a&gt; is a solution for interception, decoding and analysis of high speed data traffic over IP networks and independently monitors ISPs/GPRS and 3G networks. xTrail has been designed in such a way that it can be deployed within minutes and enables law enforcement agencies to intercept and monitor targeted communications without degrading the service quality of the IP network. This product is capable of intercepting all types of networks -including wireline, wireless, cable, VoIP and VSAT networks- and acts as a black box for “record and replay” targeted Internet communications.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Interestingly enough, xTrail can filter based on a “pure keyword”, a URL/Domain with a keyword, an IP address, a mobile number or even with just a user identity, such as an email ID, chat ID or VoIP ID. Furthermore, xTrail can be integrated with link analysis tools and can export data in a digital format which can allegedly be presented in court as evidence.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, xTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Pure passive probe&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Designed for rapid field operations at ISP/GPRS/Wi-Max/VSAT Network Gateways&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Stand-alone solution for interception, decoding and analysis of multi Gigabit IP traffic&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Portable trolley based for simplified logistics, can easily be deployed and removed from any network location&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Huge data retention, rich analysis interface and tamper proof court evidence&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Easily integrates with any existing centralized monitoring system for extended coverage&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;3. QuickTrail: Tactical Wi-Fi Monitoring&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;Some of the biggest IP monitoring challenges that law enforcement agencies face include cases when targets operate from public Internet networks and/or use encryption.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;QuickTrail&lt;/span&gt;&lt;/a&gt; is a device which is designed to gather intelligence from public Internet networks, when a target is operating from a cyber cafe, a hotel, a university campus or a free Wi-Fi zone. In particular, QuickTrail is equipped with multiple monitoring tools and techniques that can help intercept almost any wired, Wi-Fi or hybrid Internet network so that a target communication can be monitored. QuickTrail can be deployed within fractions of seconds to intercept, reconstruct, replay and analyze email, chat, VoIP and other Internet activities of a target. This device supports real time monitoring and wiretapping of Ethernet LANs.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;According to ClearTrail’s brochure, QuickTrail is a “all-in-one” device which can intercept secured communications, know passwords with c-Jack attack, alert on activities of a target, support active and passive interception of Wi-Fi and wired LAN and capture, reconstruct and replay. It is noteworthy that QuickTrail can identify a target machine on the basis of an IP address, MAC ID, machine name, activity status and several other parameters. In addition, QuickTrail supports protocol decoding, including HTTP, SMTP, POP3 and HTTPS. This device also enables the remote and central management of field operations at geographically different locations.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, QuickTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Conveniently housed in a laptop computer&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Intercepts Wi-Fi and wired LANs in five different ways&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Breaks WEP, WPA/WPA2 to rip-off secured Wi-Fi networks&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Deploys spyware into a target’s machine&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Monitor’s Gmail, Yahoo and all other HTTPS-based communications&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Reconstructs webmails, chats, VoIP calls, news groups and social networks&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;4. mTrail: Off-The-Air Interception&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;mTrail&lt;/span&gt;&lt;/a&gt; offers active and passive ‘off-the-air’ interception of GSM 900/1800/1900 Mhz phone calls and data to meet law enforcement surveillance and investigation requirements. The mTrail passive interception system works in the stealth mode so that there is no dependence on the network operator and so that the target is unaware of the interception of its communications.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The mTrail system has the capability to scale from interception of 2 channels (carrier frequencies) to 32 channels. mTrail can be deployed either in a mobile or fixed mode: in the mobile mode the system is able to fit into a briefcase, while in the fixed mode the system fits in a rack-mount industrial grade chassis.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Target location identification is supported by using signal strength, target numbers, such as IMSI, TIMSI, IMEI or MSI SDN, which makes it possible to listen to the conversation on so-called “lawfully intercepted” calls in near real-time, as well as to store all calls. Additionally, mTrail supports the interception of targeted calls from pre-defined suspect lists and the monitoring of SMS and protocol information.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, mTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Designed for passive interception of GSM communications&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Intercepts Voice and SMS “off-the-air”&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Detects the location of the target&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Can be deployed as a fixed unit or mounted in a surveillance van&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- No support required from GSM operator&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;5. Astra: Remote Monitoring and Infection framework&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Astra&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;”&lt;/a&gt;&lt;/span&gt; is a remote monitoring and infection framework which incorporates both conventional and proprietary infection methods to ensure bot delivery to the targeted devices. It also offers a varied choice in handling the behavior of bots and ensuring non-traceable payload delivery to the controller.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The conventional methods of infection include physical access to a targeted device by using exposed interfaces, such as a CD-ROM, DVD and USB ports, as well as the use of social media engineering techniques. However, Astra also supports bot deployment &lt;i&gt;without&lt;/i&gt; requiring any physical access to the target device.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In particular, Astra can push bot to &lt;i&gt;any&lt;/i&gt; targeted machine sharing the &lt;i&gt;same&lt;/i&gt; LAN (wired, wi-fi or hybrid). The SEED is a generic bot which can identify a target’s location, log keystrokes, capture screen-shots, capture Mic, listen to Skype calls, capture webcams and search the target’s browsing history. Additionally, the SEED bot can also be remotely activated, deactivated or terminated, as and when required. Astra allegedly provides an un-traceable reporting mechanism that operates without using any proxies, which overrules the possibility of getting traced by the target.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Astra’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Proactive intelligence gathering&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- End-to-end remote infection and monitoring framework&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Follow the target, beat encryption, listen to in-room conversations, capture keystrokes and screen shots&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Designed for centralized management of thousands of targets&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- A wide range of deployment mechanisms to optimize success ration&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Non-traceable, non-detectable delivery mechanism&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Intrusive yet stealthy&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Easy interface for handling most complex tasks&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Successfully tested over the current top 10 anti-virus available in the market&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- No third party dependencies&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Free from any back-door intervention&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Technologies&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;argue&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;that&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;they&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;meet&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;lawful&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;interception&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;regulatory&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;requirements&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;/span&gt;across the globe. In particular, they claim that their products are compliant with &lt;a href="http://www.etsi.org/technologies-clusters/technologies/regulation-legislation"&gt;&lt;span style="text-decoration: underline;"&gt;ETSI&lt;/span&gt;&lt;/a&gt; and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;CALEA&lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt; &lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;regulations&lt;/a&gt;&lt;/span&gt; and that they are efficient to cater to region specific requirements as well.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The latest Spy Files also include data on foreign  surveillance technology companies operating in India, such as &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Telesoft&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Technologies&lt;/a&gt;&lt;/span&gt;, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/AGTINTERNATIONAL-2011-UrbaManaSolu-fr.pdf"&gt;AGT&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/AGTINTERNATIONAL-2011-UrbaManaSolu-fr.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/AGTINTERNATIONAL-2011-UrbaManaSolu-fr.pdf"&gt;International&lt;/a&gt;&lt;/span&gt; and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Verint&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Systems&lt;/a&gt;&lt;/span&gt;. In particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://verint.com/"&gt;Verint&lt;/a&gt;&lt;a href="http://verint.com/"&gt; &lt;/a&gt;&lt;a href="http://verint.com/"&gt;Systems&lt;/a&gt;&lt;/span&gt; has its headquarters in New York and offices all around the world, including Bangalore in India. Founded in 1994 and run by Dan Bodner, Verint Systems produces a wide range of surveillance technologies, including the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Impact 360 Speech Analytics&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Impact 360 Text Analytics&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Video Management Software (VMS)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Physical Security Information Management (PSIM)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Network Video Recorders (NVRs)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Video Business Intelligence (VBI)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Surveillance Analytics&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva IP cameras&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- CYBERVISION Network Security&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- ENGAGE suite&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- FOCAL-INFO (FOCAL-COLLECT &amp;amp; FOCAL-ANALYTICS)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- RELIANT&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- STAR-GATE&lt;/p&gt;
&lt;p&gt;- VANTAGE&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://verint.com/"&gt;Verint&lt;/a&gt;&lt;a href="http://verint.com/"&gt; &lt;/a&gt;&lt;a href="http://verint.com/"&gt;Systems&lt;/a&gt;&lt;/span&gt; claims to be in compliance with ETSI, CALEA and other worldwide lawful interception and standards and regulations, it remains unclear whether such products successfully help law enforcement agencies in tackling crime and terrorism, without violating individuals’ right to privacy and other human rights. After all, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;Verint&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;Systems&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;has&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;participated&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;in&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;ISS&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;World&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;Trade&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;shows&lt;/a&gt;&lt;/span&gt; which exhibit some of the most controversial spyware in the world, used to target individuals and for mass surveillance.&lt;/p&gt;

&lt;h2&gt;&lt;b&gt;And what do the latest Spy Files mean for India?&lt;/b&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;Why is it even important to look at the latest Spy Files? Well, for starters, they reveal data about which Indian law enforcement agencies are interested in surveillance and which companies are interested in selling and/or buying the latest spy gear. And why is any of this important? I can think of three main reasons:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. The Central Monitoring System (CMS)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. Is any of this surveillance even legal in India?&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. Can such surveillance result in the violation of human rights?&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Spy Files 3...and the Central Monitoring System (CMS)&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;Following the &lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt;Mumbai&lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt; 2008 &lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt;terrorist&lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt; &lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt;attacks&lt;/a&gt;, the Telecom Enforcement, Resource and Monitoring (TREM) cells and the Centre for Development of Telematics (C-DOT) started preparing the &lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Monitoring&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;System&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; (&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;)&lt;/a&gt;. As of April 2013, this project is being manned by the Intelligence Bureau, while agencies which are planned to have access to it include the Research &amp;amp; Analysis Wing (RAW) and the Central Bureau of Investigation (CBI). ISP and Telecom operators are required to&lt;b&gt; &lt;/b&gt;&lt;span&gt;install the gear which enables law enforcement agencies to carry&lt;/span&gt; out the Central Monitoring System under the &lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Unified&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Access&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Services&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; (&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;) &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The Central Monitoring System aims at centrally monitoring all telecommunications and Internet communications in India and its estimated cost is &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ciol.com/ciol/news/184770/governments-central-monitoring-system-operational-soon"&gt;Rs&lt;/a&gt;&lt;a href="http://www.ciol.com/ciol/news/184770/governments-central-monitoring-system-operational-soon"&gt;. 4 &lt;/a&gt;&lt;a href="http://www.ciol.com/ciol/news/184770/governments-central-monitoring-system-operational-soon"&gt;billion&lt;/a&gt;&lt;/span&gt;. In addition to &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;equipping&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;government&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;agencies&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;/span&gt;with Direct Electronic Provisioning, filters and alerts on the target numbers, the CMS will also enable Call Data Records (CDR) analysis and data mining to identify personal information of the target numbers. The CMS supplements&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;regional&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Internet&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Systems&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;, &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;such&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;as&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;that&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Assam&lt;/a&gt;&lt;/span&gt;, by providing a nationwide monitoring of telecommunications and Internet communications, supposedly to assist law enforcement agencies in tackling crime and terrorism.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;However, data monitored and collected through the CMS will be stored in a&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt; &lt;/a&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt;centralised&lt;/a&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt; &lt;/a&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt;database&lt;/a&gt;&lt;/span&gt;, which could potentially increase the probability of centralized cyber attacks and thus increase, rather than reduce, threats to national security. Furthermore, some basic rules of statistics indicate that &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;bigger&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;amount&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;data&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;, &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;bigger&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;probability&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;an&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;error&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;in&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;matching&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;profiles&lt;/a&gt;&lt;/span&gt;, which could potentially result in innocent people being charged with crimes they did not commit. And most importantly: the CMS currently lacks adequate legal oversight, which means that it remains unclear how monitored data will be used. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;regarding&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;the&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;CMS&lt;/a&gt;&lt;/span&gt; mandates mass surveillance by requiring ISPs and Telecom operators to enable the monitoring and interception of communications. However, targeted and mass surveillance through the CMS not only raises serious questions around its legality, but also creates the potential for abuse of the right to privacy and other human rights.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Interestingly enough, Indian law enforcement agencies which attended &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;last&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;years&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;’ &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;trade&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;shows&lt;/a&gt;&lt;/span&gt; are linked to the Central Monitoring System. In particular, last years’ law enforcement, defense and interior security attendees include the Centre for Development of Telematics (C-DOT) and the Department of Telecommunications, both of which prepared the Central Monitoring System. The list of attendees also includes India’s Intelligence Bureau, which is manning the CMS, as well as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;agencies&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;which&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;will&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;have&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;access&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;to&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;/span&gt;: the Central Bureau of Investigation (CBI), the Research and Analysis Wing (RAW), the National Technical Research Organization (NTRO) and various other state police departments and intelligence agencies.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Furthermore, Spy Files 3 entail a &lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;list&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;of&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;last&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;years&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;’ &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;ISS&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;World&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;security&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;company&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;attendees&lt;/a&gt;, which includes several Indian companies. Again, interestingly enough, many of these companies may potentially be aiding law enforcement with the technology to carry out the Central Monitoring System. ClearTrail Technologies, in particular, provides &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;solutions&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;for&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;targeted&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;and&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;mass&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;monitoring&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;IP&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;and&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;voice&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;networks&lt;/a&gt;, as well as remote monitoring and infection frameworks - all of which would potentially be perfect to aid the Central Monitoring System.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In fact, ClearTrail states in its brochure that its &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ComTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;product&lt;/a&gt; is equipped to handle millions of communications per day, while its &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;xTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;product&lt;/a&gt; can easily be integrated with any existing centralised monitoring system for extended coverage. And if that’s not enough, ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Astra&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;” &lt;/a&gt;is designed for the centralized management of thousands of targets. While there may not be any concrete proof that ClearTrail is indeed aiding the Centralized Monitoring System, the facts speak for themselves: ClearTrail is an Indian company which sells target and mass monitoring products to law enforcement agencies. The Centralized Monitoring System is currently being implemented. What are the odds that ClearTrail is &lt;i&gt;not &lt;/i&gt;equipping the CMS? &lt;span&gt;And what are the odds that such technology is &lt;/span&gt;&lt;i&gt;&lt;span&gt;not&lt;/span&gt;&lt;/i&gt;&lt;span&gt; being used for other mass electronic surveillance programmes, such as the Lawful Intercept and Monitoring (LIM)?&lt;/span&gt;&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Spy Files 3...and the legality of India’s surveillance technologies&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;ClearTrail Technologies’ &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;brochure&lt;/span&gt;&lt;/a&gt; -the only leaked document on Indian surveillance technology by the latest Spy Files- states that the company complies with &lt;a href="http://www.etsi.org/technologies-clusters/technologies/regulation-legislation"&gt;&lt;span style="text-decoration: underline;"&gt;ETSI&lt;/span&gt;&lt;/a&gt; and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;CALEA&lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt; &lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;regulations&lt;/a&gt;&lt;/span&gt;. While it’s clear that the company complies with U.S. and European regulations on the interception of communications to attract more customers in the international market, such regulations don’t really apply &lt;i&gt;within&lt;/i&gt; India, which is part of ClearTrail’s market. Notably enough, ClearTrail does not mention any compliance with Indian regulations in its brochure. So let’s have a look at them.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;India has five laws which regulate surveillance:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 1885&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Post&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Office&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 1898&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Wireless&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Telegraphy&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 1933&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;4. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;Code&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; &lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;of&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; &lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;Criminal&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; &lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;Procedure&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; (&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;CrPc&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;)&lt;/a&gt;&lt;/span&gt;, 1973: Section 91&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;5. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 2008&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Post&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Offices&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt; does not cover electronic communications and the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Wireless&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Telegraphy&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;/span&gt;lacks procedures which would determine if surveillance should be targeted or not. Neither the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt; nor the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt; cover mass surveillance, but are both limited to targeted surveillance. Moreover, targeted interception in India according to these laws requires case-by-case authorization by either the home secretary or the secretary department of information technology. In other words, unauthorized, limitless, mass surveillance is not technically permitted by law in India.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The Indian Telegraph Act mandates that the interception of communications can only be carried out on account of &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;a&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;public&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;emergency&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;or&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;for&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;public&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;safety&lt;/a&gt;. However, in 2008, the Information Technology Act copied most of the interception provisions of the Indian Telegraph Act, but removed the preconditions of public emergency or public safety, and instead expanded the power of the government to order interception for the “investigation of any offense”.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The interception of Internet communications is mainly covered by the &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;2009 &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Rules&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;under&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;the&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Information&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Technology&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Act&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; 2008 &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;and&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Sections&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; 69 &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;and&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; 69&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;B&lt;/a&gt; are particularly noteworthy. According to these Sections, an Intelligence Bureau officer who leaked national secrets may be imprisoned for up to three years, while Section 69 not only allows for the interception of any information transmitted through a computer resource, but also requires that users disclose their encryption keys upon request or face a jail sentence of up to seven years.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While these laws allow for the interception of communications and can be viewed as widely controversial, they do not technically permit the &lt;i&gt;mass&lt;/i&gt; surveillance of  communications. In other words, ClearTrail’s products, such as &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ComTrail&lt;/span&gt;&lt;/a&gt;, which enable the mass interception of IP networks, lack legal backing. However, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Unified&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Access&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Services&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; (&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;) &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt;&lt;/span&gt; regarding the Central Monitoring System mandates mass surveillance and requires ISP and Telecom operators to comply.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Through the licenses of the Department of Telecommunications, Internet service providers, cellular providers and telecoms are required to provide the Government of India direct access to all communications data and content &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;even&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;without&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;a&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;warrant&lt;/a&gt;, which is not permitted under the laws on interception. These licenses also require cellular providers to have ‘bulk encryption’ of less than 40 bits, which means that potentially any person can use off-the-air interception to monitor phone calls. However, such licenses do not regulate the capture of signal strength, target numbers like IMSI, TIMSI, IMEI or MSI SDN, which can be captured through ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;mTrail&lt;/span&gt;&lt;/a&gt; product.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;More importantly, following &lt;a class="external-link" href="http://www.financialexpress.com/news/states-begin-to-surrender-offair-phone-snooping-equipment/957859"&gt;allegations&lt;/a&gt; that the National Technical Research Organization (NTRO) had been using off-the-air interception equipment to snoop on politicians in 2011, the Home Ministry issued a directive to ban the possession or use of all off-the-air phone interception gear. As a result, the Indian Government asked the Customs Department to provide an inventory of all all such equipment imported over a ten year period, and it was uncovered that as many as 73,000 pieces of equipment had been imported. Since, the Home Ministry has informed the heads of law enforcement agencies that there has been a &lt;a class="external-link" href="http://m.indianexpress.com/news/state-govts-hand-over-few-offair-phonetapping-sets-to-centre/1185166/"&gt;compete ban on use of such equipment&lt;/a&gt; and that all those who possess such equipment and fail to inform the Government will face prosecution and imprisonment. In short, ClearTrail's product, mTrail, which undertakes off-the-air phone monitoring is illegal and Indian law enforcement agencies are prohibited from using it. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Astra&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;”&lt;/a&gt; product is capable of remote infection and monitoring, which can push bot to any targeted machine sharing the same LAN. While India’s ISP and telecommunications licenses generally provide some regulations, they appear to be inadequate in regulating specific surveillance technologies which have the capability to target machines and remotely monitor them. Such &lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;&lt;span style="text-decoration: underline;"&gt;licenses&lt;/span&gt;&lt;/a&gt; mandate mass surveillance, but legally, wireless communications are completely unregulated, which raises the question of whether the interception of public Internet networks is allowed. In other words, it is not clear if ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;QuickTrail&lt;/span&gt;&lt;/a&gt; is technically legal or not. The &lt;a class="external-link" href="http://www.auspi.in/policies/UASL.pdf"&gt;UAS License agreement&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;mandates mass surveillance, and while the law does not prohibit it, it does not mandate mass surveillance either. This remains a grey area.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The issue of data retention arises from &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;leaked&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;brochure&lt;/a&gt;. In particular, ClearTrail states in its brochure that ComTrail - which undertakes mass monitoring of IP and Voice networks - retains data upon request, with a capacity that exceeds several years. xTrail - for targeted IP monitoring - has the ability to retain huge volumes of data which can potentially be used as proof in court. However, India currently lacks privacy legislation which would regulate data retention, which means that data collected by ClearTrail could potentially be stored indefinitely.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;a class="external-link" href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Section 7 of the Information Technology (Amendment) Act, 2008&lt;/a&gt;, deals with the retention of electronic records. However, this section does not state a particular data retention period, nor who will have authorized access to data during its retention, who can authorize such access, whether retained data can be shared with third parties and, if so, under what conditions. Section 7 of the Information Technology (Amendment) Act, 2008, appears to be incredibly vague and to fail to regulate data retention adequately.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Data retention requirements for service providers are included in the &lt;a href="https://cis-india.org/internet-governance/blog/data-retention-in-india" class="external-link"&gt;ISP and UASL licenses&lt;/a&gt; and, while they clarify the type of data they retain, they do not specify adequate conditions for data retention. Due to the lack of data protection legislation in India, it remains unclear how long data collected by companies, such as ClearTrail, would be stored for, as well as who would have authorized access to such data during its retention period, whether such data would be shared with third parties and disclosed and if so, under what conditions.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;India currently lacks specific regulations for the use of various types of technologies, which makes it unclear whether &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;spy&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;products&lt;/a&gt;&lt;/span&gt; are technically legal or not. It is clear that ClearTrail’s mass interception products, such as ComTrail, are not legalized - since Indian laws allow for targeted interception- but they are mandated through the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;agreement&lt;/a&gt;&lt;/span&gt; regarding the Central Monitoring System.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, the legality of ClearTrail’s surveillance technologies remains ambiguous. While India’s ISP and telecom licenses and the &lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt; mandate mass surveillance, the laws - particularly the 2009 Information Technology Rules- mandate targeted surveillance and remain silent on the issue of mass surveillance. Technically, this does not constitute mass surveillance legal or illegal, but rather a grey area. Furthermore, while &lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;India&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;, &lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;and 2009 Rules allow for the interception, monitoring and decryption of communications and surveillance in general, they do not explicitly regulate the various types of surveillance technologies, but rather attempt to “legalize” them through the blanket term of surveillance.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;One thing is clear: India’s license agreements ensure that all ISPs and telecom operators are a part of the surveillance regime. The lack of regulations for India’s surveillance technologies appear to create a grey zone for the expansion of mass surveillance in the country. According to &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.outlookindia.com/article.aspx?265192"&gt;Saikat&lt;/a&gt;&lt;a href="http://www.outlookindia.com/article.aspx?265192"&gt; &lt;/a&gt;&lt;a href="http://www.outlookindia.com/article.aspx?265192"&gt;Datta&lt;/a&gt;&lt;/span&gt;, an investigative journalist, a senior privacy telecom official stated:&lt;/p&gt;
&lt;blockquote class="italized"&gt;“&lt;i&gt;Do you really think a private telecom company can stand up to the government or any intelligence agency and cite law if they want to tap someone’s phone?” &lt;/i&gt;&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;﻿&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Spy Files 3...and human rights in India&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;The facts speak for themselves. The latest Spy Files confirm that the same agencies involved in the development of the Central Monitoring System (CMS) are also interested in the latest surveillance technology sold in the global market. Spy Files 3 also provide data on one of India’s largest surveillance technology companies, &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ClearTrail&lt;/span&gt;&lt;/a&gt;, which sells a wide range of surveillance technologies to law enforcement agencies around the world. And Spy Files 3 show us exactly what these technologies can do.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In particular, ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ComTrail&lt;/span&gt;&lt;/a&gt; provides mass monitoring of IP and voice networks, which means that law enforcement agencies using it are capable of  intercepting millions of communications every day through Gmail, Yahoo, Hotmail and others, of correlating our identities across networks and of targeting our location. &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;xTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;/span&gt;enables law enforcement agencies to monitor us based on our “harmless” metadata, such as our IP address, our mobile number and our email ID. Think our data is secure when using the Internet through a cyber cafe? Well &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;QuickTrail&lt;/span&gt;&lt;/a&gt; proves us wrong, as it’s able to assist law enforcement agencies in monitoring and intercepting our communications even when we are using public Internet networks.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And indeed, carrying a mobile phone is like carrying a GPS device, especially since &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;mTrail&lt;/span&gt;&lt;/a&gt; provides law enforcement with off-the-air interception of mobile communications. Not only can mTrail target our location, listen to our calls and store our data, but it can also undertake passive off-the-air interception and monitor our voice, SMS and protocol information. Interestingly enough, mTrail also intercepts targeted calls from a predefined suspect list. The questions though which arise are: who is a suspect? How do we even know if we are suspects? In the age of the War on Terror, potentially anyone could be a suspect and thus potentially anyone’s mobile communications could be intercepted. After all, mass surveillance dictates that &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;we&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;are&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;all&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;suspicious&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;until&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;proven&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;innocent&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;. &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And if anyone can potentially be a suspect, then potentially anyone can be remotely infected and monitored by &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;Astra&lt;/span&gt;&lt;/a&gt;. Having physical access to a targeted device is a conventional surveillance mean of the past. Today, Astra can &lt;i&gt;remotely&lt;/i&gt; push bot to our laptops and listen to our Skype calls, capture our Webcams, search our browsing history, identify our location and much more. And why is any of this concerning? Because contrary to mainstream belief, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;we&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;should&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;all&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;have&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;something&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;to&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;hide&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;! &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;Privacy&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;protects&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;us&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;from&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;abuse&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;from&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;those&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;in&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;power&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;/span&gt;and safeguards our individuality and autonomy as human beings. If we are opposed to the idea of the police searching our home without a search warrant, we should be opposed to the idea of our indiscriminate mass surveillance. After all, mass surveillance - especially the type undertaken by &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;products&lt;/a&gt;&lt;/span&gt; -  can potentially result in the access, sharing, disclosure and retention of data much more valuable than that acquired by the police searching our home. Our credit card details, our photos, our acquaintances, our personal thoughts and opinions, and other sensitive personal information can usually be found in our laptops, which potentially can constitute much more incriminating information than that found in our homes.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And most importantly: even if we think that we have nothing to hide, it’s really not up to us to decide: it’s up to data analysts. While we may think that our data is “harmless”, a data analyst linking our data to various other people and search activities we have undertaken might indicate otherwise. Five years ago, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;a&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;UK&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;student&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;studying&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;Islamic&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;terrorism&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;for&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;his&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;Masters&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;dissertation&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;was&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;detained&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;for&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;six&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;days&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;.&lt;/a&gt;&lt;/span&gt; The student may not have been a terrorist, but his data said this: “Young, male, Muslim... who is downloading Al-Qaeda’s training material” - and that was enough for him to get detained. Clearly, the data analysts mining his online activity did not care about the fact that the only reason why he was downloading Al-Qaeda material was for his Masters dissertation. The fact that he was a male Muslim downloading terrorist material was incriminating enough.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;This incident reveals several concerning points: The first is that he was clearly already under surveillance, prior to downloading Al-Qaeda’s material. However, given that he did not have a criminal record and was “just a Masters student in the UK”, there does not appear to be any probable cause for his surveillance in the first place. Clearly he was on some suspect list on the premise that he is male and Muslim - which is a discriminative approach. The second point is that after this incident, it is likely that some male Muslims may be more cautious about their online activity - with the fear of being on some suspect list and eventually being prosecuted because their data shows that “they’re a terrorist”. Thus, mass surveillance today appears to also have implications on freedom of expression. The third point is that this incident reveals the extent of mass surveillance, since even a document downloaded by a Masters student is being monitored.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;This case proves that innocent people can potentially be under surveillance and prosecuted, as a result of mass, indiscriminate surveillance. Anyone can potentially be a suspect today, and maybe for the wrong reasons. It does not matter if we think our data is “harmless”, but what matters is who is looking at our data, when and why.  Every bit of data potentially hides several other bits of information which we are not aware of, but which will be revealed within a data analysis. We should always &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;“&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;have&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;something&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;to&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;hide&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;”&lt;/a&gt;&lt;/span&gt;, as that is the only way to protect us from abuse by those in power.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In the contemporary surveillance state, we are all suspects and mass surveillance technologies, such as the ones sold by &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ClearTrail&lt;/span&gt;&lt;/a&gt;, can potentially pose major threats to our right to privacy, freedom of expression and other human rights. And probably the main reason for this is because surveillance technologies in India legally fall in a grey area. Thus, it is recommended that law enforcement agencies in India regulate the various types of surveillance technologies in compliance with the &lt;a class="external-link" href="https://en.necessaryandproportionate.org/text"&gt;International Principles on Communications Surveillance and Human Rights.&lt;/a&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Spy Files 3 show us why our human rights are at peril and why we should fight for our right to be free from suspicion.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt; &lt;/p&gt;
&lt;p align="JUSTIFY"&gt;This article was &lt;a class="external-link" href="http://www.medianama.com/2013/11/223-spy-files-3-wikileaks-sheds-more-light-on-the-global-surveillance-industry-cis-india/"&gt;cross-posted in Medianama &lt;/a&gt;on 6th November 2013.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/spy-files-three'&gt;https://cis-india.org/internet-governance/blog/spy-files-three&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Homepage</dc:subject>
    

   <dc:date>2013-11-14T16:21:00Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you">
    <title>Why 'Facebook' is More Dangerous than the Government Spying on You</title>
    <link>https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you</link>
    <description>
        &lt;b&gt;In this article, Maria Xynou looks at state and corporate surveillance in India and analyzes why our "choice" to hand over our personal data can potentially be more harmful than traditional, top-down, state surveillance. Read this article and perhaps reconsider your "choice" to use social networking sites, such as Facebook. &lt;/b&gt;
        
&lt;p align="JUSTIFY"&gt;&lt;i&gt;Do you have a profile on Facebook?&lt;/i&gt; Almost every time I ask this question, the answer is ‘yes’. In fact, I think the amount of people who have replied ‘no’ to this question can literally be counted on my right hand. But this is not an article about Facebook per se. It’s more about the ‘Facebooks’ of the world, and of people’s increasing “choice” to hand over their most personal data. More accurate questions are probably:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;“&lt;i&gt;Would you like the Government to go through your personal diary? If not, then why do you have a profile on Facebook?”&lt;/i&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span&gt;&lt;b&gt;The Indian Surveillance State&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;Following &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;Snowden&lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;’&lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;s&lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt; &lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;revelations&lt;/a&gt;&lt;/span&gt;, there’s finally been more talk about surveillance. But what is surveillance?&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;David Lyon - who directs the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.sscqueens.org/"&gt;Surveillance&lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt; &lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt;Studies&lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt; &lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt;Centre&lt;/a&gt;&lt;/span&gt; - &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;defines&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;surveillance&lt;/a&gt;&lt;/span&gt; as &lt;i&gt;“any collection and processing of personal data, whether identifiable or not, for the purposes of influencing or managing those whose data have been garnered”&lt;/i&gt;. &lt;a href="http://www.polity.co.uk/book.asp?ref=9780745635910"&gt;&lt;span style="text-decoration: underline;"&gt;Surveillance&lt;/span&gt;&lt;/a&gt; can also be defined as the monitoring of the behaviour, activities or other changing information of individuals or groups of people. However, this definition implies that individuals and/or groups of people are being monitored in a top-down manner, without this being their “choice”. But is that actually the case? To answer this question, let’s have a look at how the Indian government and corporations operating in India spy on us.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;State Surveillance&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;The first things that probably come to mind when thinking about India from a foreigner’s perspective are poverty and corruption. Surveillance appears to be a “Western, elitist issue”, which mainly concerns those who have already solved their main survival problems. In other words, the most mainstream argument I hear in India is that surveillance is not a &lt;i&gt;real &lt;/i&gt;issue, especially since the majority of the population in the country lives below the line of poverty and does not even have any Internet access. Interestingly enough though, the other day when I was walking around a slum in Koramangala, I noticed that most people have Airtel satellites...even though they barely have any clean water!&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The point though is that surveillance in India is a fact, and the state plays a rather large role in it. In particular, Indian law enforcement agencies follow three steps in ensuring that targeted and mass surveillance is carried out in the country:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. They create surveillance schemes, such as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Monitoring&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;System&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; (&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;)&lt;/a&gt;&lt;/span&gt;, which carry out targeted and/or mass surveillance&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. They create laws, guidelines and license agreements, such as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; 2008&lt;/a&gt;&lt;/span&gt;, which mandate targeted and mass surveillance and which require ISP and telecom operators to comply&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. They buy surveillance technologies from companies, such as CCTV cameras and spyware, and use them to carry out targeted and/or mass surveillance&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While Indian law enforcement agencies don’t necessarily follow these steps in this precise order, they usually try to create surveillance schemes, legalise them and then buy the gear to carry them out.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In particular, surveillance in India is regulated under five laws: the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; 1885&lt;/a&gt;&lt;/span&gt;, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Post&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Office&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; 1898&lt;/a&gt;&lt;/span&gt;, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Wireless&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Telegraphy&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; 1933&lt;/a&gt;&lt;/span&gt;, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;section&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; 91 &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;of&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;the&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; 1973 &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;Code&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;of&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;Criminal&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;Procedure&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; (&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;CrPc&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;)&lt;/a&gt;&lt;/span&gt; and the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; 2008&lt;/a&gt;&lt;/span&gt;. These laws mandate targeted surveillance, but remain silent on the issue of mass surveillance which means that technically it is neither allowed nor prohibited, but remains a grey legal area.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While surveillance laws in India may not mandate mass surveillance, some of their sections are particularly concerning. Section 69 of the&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; 2008&lt;/a&gt;&lt;/span&gt; allows for the interception of all information transmitted through a computer resource, while requiring that all users disclose their private encryption keys or face a jail sentence of up to seven years. This appears to be quite bizarre, as individuals can only keep their data private and protect themselves from surveillance through encryption.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Section 44 of the Information Technology (Amendment) Act 2008 imposes stiff penalties on anyone who fails to provide requested information to authorities - which kind of reminds us of Orwell’s totalitarian regime in &lt;a href="http://www.ministryoflies.com/1984.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;“1984”&lt;/span&gt;&lt;/a&gt;. Furthermore, section 66A of the same law states that individuals will be punished for sending “offensive messages through communication services”. However, the vagueness of this section raises huge concerns, as it remains unclear what defines an “offensive message” and whether this will have grave implications on the freedom of expression. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;arrest&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;of&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;two&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;Indian&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;women&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;last&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;November&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;over&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;a&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;Facebook&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;post&lt;/a&gt;&lt;/span&gt; reminds us of this.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Laws in India may not mandate mass surveillance, but guidelines and license agreements issued by the Department of Telecommunications do. In particular, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;regarding&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;the&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Central&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;System&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; (&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;CMS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;) &lt;/a&gt;&lt;/span&gt;not only mandates mass surveillance, but also attempts to legalise a mass surveillance scheme which aims to intercept all telecommunications and Internet communications in India. Furthermore, the Department of Telecommunications has issued &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;numerous&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;guidelines&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;and&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;license&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;agreements&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;for&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;ISPs&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;and&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;telecom&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;operators&lt;/a&gt;&lt;/span&gt;, which require them to not only be “surveillance-friendly”, but to also enable law enforcement agencies to tap into their servers on the grounds of national security. And then, of course, there’s the new &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;National&lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;Cyber&lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;Security&lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;Policy&lt;/a&gt;&lt;/span&gt;, which mandates surveillance to tackle cyber-crime, cyber-terrorism, cyber-war and cyber-vandalism.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;As both a result and prerequisite of these laws, the Indian government has created various surveillance schemes and teams to aid them. In particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;India&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;’&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;s&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Computer&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Emergency&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Response&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Team&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; (&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;CERT&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;)&lt;/a&gt;&lt;/span&gt; is currently monitoring “any suspicious move on the Internet” in order to checkmate any potential cyber attacks from hackers. While this may be useful for the purpose of preventing and detecting cyber-criminals, it remains unclear how “any suspicious move” is defined and whether that inevitably enables mass surveillance, without individuals’ knowledge or consent.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Crime&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;and&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Criminal&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Tracking&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;and&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Network&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &amp;amp; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Systems&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; (&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;CCTNS&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;)&lt;/a&gt;&lt;/span&gt; is the creation of a nationwide networking infrastructure for enhancing the efficiency and effectiveness of policing and sharing data among 14,000 police stations across the country. It has been estimated that Rs. 2000 crore has been allocated for the CCTNS project and while it may potentially increase the effectiveness of tackling crime and terrorism, it raises questions around the legality of data sharing and its potential implications on the right to privacy and other human rights - especially if such data sharing results in data being disclosed or shared with unauthorised third parties.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Similarly, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;National&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt; &lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;Intelligence&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt; &lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;Grid&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt; (&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;NATGRID&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;)&lt;/a&gt;&lt;/span&gt; is an integrated intelligence grid that will link the databases of several departments and ministries of the Government of India so as to collect comprehensive patterns of intelligence that can be readily accessed by intelligence agencies. This was first proposed in the aftermath of the Mumbai 2008 terrorist attacks and while it may potentially aid intelligence agencies in countering crime and terrorism, enforced privacy legislation should be a prerequisite, which would safeguard our data from potential abuse.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;However, the most controversial surveillance scheme being implemented in India is probably the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Monitoring&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;System&lt;/a&gt;&lt;/span&gt; (CMS). While several states, such as Assam, already have &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Internet&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Systems&lt;/a&gt;&lt;/span&gt; in place, the Central Monitoring System appears to raise even graver concerns. In particular, the CMS is a system through which all telecommunications and Internet communications in India will be monitored by Indian authorities. In other words, the CMS will be capable of intercepting our calls and of analyzing our data on social networking sites, while all such data would be retained in a centralised database. Given that India currently lacks privacy legislation, such a system would mostly be unregulated and would pose major threats to our right to privacy and other human rights. Given that data would be centrally stored, the system would create a type of “honeypot” for centralised cyber attacks. Given that the centralised database would have massive volumes of data for literally a billion people, the probability of error in pattern and profile matching would be high - which could potentially result in innocent people being convicted for crimes they did not commit. Nonetheless, mass surveillance through the CMS is currently a reality in India.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And the even bigger question: How can law enforcement agencies mine the data of 1.2 billion people? How do they even carry out surveillance in practice? Well, that’s where surveillance technology companies come in. In fact, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;surveillance&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;industry&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;in&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;India&lt;/a&gt;&lt;/span&gt; is massively expanding - especially in light of its new surveillance schemes which require advanced and sophisticated technology. According to &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;CIS&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;’ &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;India&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;Privacy&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;Monitor&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;Map&lt;/a&gt;&lt;/span&gt; - which is part of ongoing research - Indian law enforcement agencies use CCTV cameras in pretty much every single state in India. The map also shows that Unmanned Aerial Vehicles (UAVs), otherwise known as drones, are being used in most states in India and the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;DRDO&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;’&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;s&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt; “&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;Netra&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;”&lt;/a&gt;&lt;/span&gt; - which is a lightweight drone, not much bigger than a bird - is particularly noteworthy.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;But Indian law enforcement agencies also buy surveillance software and hardware which is aimed at intercepting telecommunications and Internet communications. In particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.clear-trail.com/"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt; &lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt;Technologies&lt;/a&gt;&lt;/span&gt; is an Indian company - based in Indore - which equips law enforcement agencies in India and around the world with &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;surveillance&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;software&lt;/a&gt;&lt;/span&gt; which can probably be compared with the “notorious” FinFisher. So in short, there appears to be a tight collaboration between Indian law enforcement agencies and the surveillance industry, which can be clearly depicted in the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;surveillance&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;trade&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;shows&lt;/a&gt;&lt;/span&gt;, otherwise known as “the wiretappers’ ball”.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Corporate Surveillance&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;When I ask people about corporate surveillance, the answer I usually get is: &lt;i&gt;“Corporations only care about their profit - they don’t do surveillance per se”&lt;/i&gt;. And while that may be true, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;David&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;Lyon&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;’&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;s&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;definition&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;of&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;surveillance&lt;/a&gt;&lt;/span&gt; - as &lt;i&gt;“any collection and processing of personal data, whether identifiable or not, for the purposes of influencing or managing those whose data have been garnered” &lt;/i&gt;- may indicate otherwise.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Corporations, like Google, Amazon and Facebook, may not have an agenda for spying per se, but they do collect massive volumes of personal data and, in cases such as PRISM, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;allow&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;law&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;enforcement&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;to&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;tap&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;into&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;their&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;servers&lt;/a&gt;&lt;/span&gt;. Once law enforcement agencies get hold of data collected by companies, such as Facebook, they then use data mining software - equipped by various surveillance technology companies - to process and mine the data. And how do companies, like Google and Facebook, make money off our personal data? By selling it to big buyers, such as law enforcement agencies.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;So while Facebook and all the ‘Facebooks’ of the world may not profit from surveillance per se, they do profit from collecting our personal data and selling it to third parties, which include law enforcement agencies. And David Lyon argues that &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;surveillance&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;involves&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;the&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;collection&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;of&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;personal&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;data&lt;/a&gt;&lt;/span&gt; - which corporations, like Facebook, do - for the purpose of influencing and managing individuals. While this last point can probably be  widely debated on, it is clear that corporations share their collected data with third parties, which ultimately leads to the influence or managing of individuals - directly or indirectly. In other words, the collection of personal data, in combination with its disclosure to third parties, &lt;i&gt;is&lt;/i&gt; surveillance. So when we think about companies, like Google or Facebook, we should not just think of businesses interested in their profit - but also of spying agencies. After all, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;“&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;if&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;the&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;product&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;is&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;free&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;, &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;you&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;are&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;the&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;product&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;”&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Now if we look at online corporations more closely, we can probably identify three categories:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. Websites through which we &lt;i&gt;buy products &lt;/i&gt;and hand over our personal details - e.g. Amazon&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. Websites through which we &lt;i&gt;use services&lt;/i&gt; and hand over our personal details - e.g. flight ticket&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. Websites through which we &lt;i&gt;communicate&lt;/i&gt; and hand over our personal details - e.g. Facebook&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And why could the above be considered “spying” at all? Because such corporations collect massive volumes of personal data and subsequently:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;Disclose&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;such&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;data&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;to&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;law&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;enforcement&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;agencies&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;Allow&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;law&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;enforcement&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;agencies&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;to&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;tap&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;into&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;their&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;servers&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Sell such data to “third parties”&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;What’s notable about so-called corporate surveillance is that, in all cases, there is a mutual, key element: we &lt;i&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;consent&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;to&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;the&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;handing&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;over&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;of&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;our&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;personal&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;information&lt;/a&gt;&lt;/span&gt;. We are not forced to hand over our personal data when buying a book online, booking a flight ticket or using Facebook. Instead, we “choose” to hand over our personal data in exchange for a product or service. Now what significantly differentiates state surveillance to corporate surveillance is the factor of &lt;i&gt;“choice”&lt;/i&gt;. While we may choose to hand over our most personal details to large online corporations, such as Google and Facebook, we do not have a choice when the government monitors our communications, collects and stores our personal data.&lt;/p&gt;

&lt;h2 align="JUSTIFY"&gt;&lt;span&gt;&lt;b&gt;State Surveillance &lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt;vs.&lt;/b&gt;&lt;/i&gt;&lt;span&gt;&lt;b&gt; Corporate Surveillance&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;Both Indian law enforcement agencies and corporations collect massive volumes of personal data. In fact, it is probably noteworthy to mention that Facebook, in particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;collects&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; 20 &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;times&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;more&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;data&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;per&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;day&lt;/a&gt;&lt;/span&gt; than the NSA in total. In addition, Facebook has &lt;a href="http://www.ft.com/cms/s/0/7536d216-0f36-11e3-ae66-00144feabdc0.html#axzz2jDSrZPHv"&gt;&lt;span style="text-decoration: underline;"&gt;claimed&lt;/span&gt;&lt;/a&gt; that it has received more demands from the US government for information about its users than from all other countries combined. In this sense, the corporate collection of personal data can potentially be more harmful than government surveillance, especially when law enforcement agencies are tapping into the servers of companies like Facebook. After all, the Indian government and all other governments would have very little data to analyse if it weren’t for such corporations.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Surveillance is not just about “spying” or about “watching people” - it’s about much much more. Observing people’s behaviour only really becomes harmful when the data observed is collected, retained, analysed, shared and disclosed to unauthorised third parties. In other words, surveillance is meaningful to examine because it involves the &lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt;&lt;i&gt;&lt;span style="text-decoration: underline;"&gt;analysis&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt; &lt;/a&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt;of&lt;/a&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt; &lt;/a&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt;data&lt;/a&gt;&lt;/span&gt;, which in turn involves &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;pattern&lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;matching&lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;and&lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;profiling&lt;/a&gt;&lt;/span&gt;, which can potentially have actual, real-world implications - good or bad. But such analysis cannot be possible without having access to large volumes of data - most of which belong to large corporations, like Facebook. The question, though, is: How do corporations collect such large volumes of personal data, which they subsequently share with law enforcement agencies? Simple: Because &lt;i&gt;we “choose”&lt;/i&gt; to hand over our data!&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Three years ago, when I was doing research on young people’s perspective of Facebook, all of the interviewees replied that they feel that they are in control of their personal data, because they “choose” what they share online. While this may appear to be a valid point,  the “choice” factor can widely be debated on. There are many reasons why people “choose” to hand over their personal data, whether to buy a product, use a service, to communicate with peers or because they feel socially pressured into using social networking sites. Nonetheless, it all really comes down to one main reason: &lt;a href="http://edition.cnn.com/2010/TECH/04/14/oppmann.off.the.grid/"&gt;&lt;i&gt;&lt;span style="text-decoration: underline;"&gt;convenience&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;. Today, in most cases, the reason why we hand over our personal data online in exchange for products or services is because it is simply more convenient to do so. And while that is understandable, at the same time we are exposing our data (and ultimately our lives) in the name of convenience.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The irony in all of this is that, while many people reacted to &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;Snowden&lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;’&lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;s&lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt; &lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;revelations&lt;/a&gt;&lt;/span&gt; on NSA dragnet surveillance, most of these people probably have profiles on Facebook. Secret, warrantless government surveillance is undeniably intrusive, but in the end of the day, our profiles on Facebook - and on all the ‘Facebooks’ of the world - is what enabled it to begin with. In other words, if we didn’t choose to give up our personal data - especially without really knowing how it would be handled - large databases would not exist and the NSA - and all the ‘NSAs’ of the world - would have had a harder time gathering and analysing data.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, the main difference between state and corporate surveillance is that the first is imposed in a top-down manner by authorities, while the second is a result of our “choice” to give up our data. While many may argue that it’s worse to have control imposed on you, I strongly disagree. When control and surveillance are imposed on us in a top-down manner, it’s likely that we will perceive this - sooner or later - as a &lt;i&gt;direct&lt;/i&gt; threat to our human rights, which means that it’s likely that we will resist to it at some point. People usually react to what they perceive as a direct threat, whereas &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;they&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;rarely&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;react&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;to&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;what&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;does&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;not&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;directly&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;affect&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;them&lt;/a&gt;&lt;/span&gt;. For example, one may perceive murder or suicide as a direct threat due the immediateness of its effect, whereas smoking may not be seen as an equally direct threat, because its consequences are indirect and can usually be seen in the long term. It’s somehow like that with surveillance.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;University&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;students&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;have&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;protested&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;on&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;streets&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;against&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;installation&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;CCTV&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;cameras&lt;/a&gt;&lt;/span&gt;, but how many of them have profiles on social networking sites, such as Facebook? People may react to the installation of CCTV cameras, because it may appear as a direct threat to their right to privacy. However, the irony is that the real danger does not necessarily lie within some CCTV cameras, but rather within the profile of each person on a major commercial social networking site. At very best, a CCTV camera will capture some images of us and through that, track our location and possibly our acquaintances. What type of data is captured through a simple, “harmless” Facebook profile? The following probably only includes a tiny percentage of what is actually captured:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Personal photos&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Biometrics (possibly through photos)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Family members&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Friends and acquaintances&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Habits, hobbies and interests&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Location (through IP address)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Places visited&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Economic standing (based on pictures, comments, etc.)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Educational background&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Ideas and opinions (which may be political, religious, etc.)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Activities&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Affiliations&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The above list could potentially go on and on, probably depending on how much - or what type - of data is disclosed by the individual. The interesting element to this is that &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;we&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;can&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;never&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;really&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;know&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;how&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;much&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;data&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;we&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;are&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;disclosing&lt;/a&gt;&lt;/span&gt;, even if we think we control it. While an individual may argue that he/she chooses to disclose an x amount of data, while retaining the rest, that individual may actually be disclosing a 10x amount of data. This may be the case because usually every bit of data hides lots of other bits of data, that we may not be aware of. &lt;i&gt;It all really comes down to who is looking at our data, when and why.&lt;/i&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;For example, (fictional) Priya may choose to share on her Facebook profile (through photos, comments, or any other type of data) that she is female, Indian, a Harvard graduate and that her favourite book is &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;“&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;Anarchism&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt; &lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;and&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt; &lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;other&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt; &lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;Essays&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;”&lt;/a&gt;&lt;/span&gt; by Emma Goldman. At first glance, nothing appears to be “wrong” with what Priya is revealing and in fact, she appears to care about her privacy by not revealing “the most intimate details” of her life. Moreover, one could argue that there is absolutely nothing “incriminating” about her data and that, on the contrary, it just reflects that she is a “shiny star” from Harvard. However, I am not sure if a data analyst would be restricted to this data and if data analysis would show the same “sparkly” image.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In theory, the fact that Priya is an Indian who attended Harvard reveals another bit of information, that Priya did not choose to share: her economic standing. Given that the majority of Indians live below the line of poverty, there is a big probability that Priya belongs to India’s middle class - if not elite. Priya may not have intentionally shared this information, but it was indirectly revealed through the bits of data that she did reveal: female Indian and Harvard graduate. And while there may not be anything “incriminating” about the fact that she has a good economic standing, in India this usually means that there’s also some strong political affiliation. That brings us to her other bit of information, that her favourite author is a feminist, anarchist. While that may be viewed as indifferent information, it may be crucial depending on the specific political actors in the country she’s in and on the general political situation. If a data analyst were to map the data that Priya chose to share, along with all her friends and acquaintances that she inevitably has through Facebook, that data analyst could probably tell a story about her. And the concerning part is that that story may or may not be true. But that doesn’t really matter.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Today, governments don’t judge us and take decisions based on our version of our data, but&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;based&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;on&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;what&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;our&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;data&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;says&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;about&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;us&lt;/a&gt;&lt;/span&gt;. And perhaps, under certain political, social and economic circumstances, our “harmless” data could be more incriminating than what we think. While an individual may express strong political views within a democratic regime, if that political system were to change in the future and to become authoritarian, that individual would possibly be suspicious in the eyes of the government - to say the least. This is where data retention plays a significant role.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Most companies &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;retain&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;data&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;indefinitely&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;or&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;for&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;a&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;long&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;period&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;time&lt;/a&gt;&lt;/span&gt;, which means that future, potentially less-democratic governments may have access to it. And the worst part is that we can never really know what data is being held about us, because within data analysis, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;every&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;bit&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;data&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;may&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;potentially&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;entails&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;various&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;other&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;bits&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;data&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;that&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;we&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;are&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;not&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;even&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;aware&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;of&lt;/a&gt;&lt;/span&gt;. So, when we “choose” to hand over our data, we don’t necessarily know what or how much we are choosing to disclose. Thus, this is why I agree with Bruce Schneier’s argument that people have an &lt;i&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;illusionary&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;sense&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;of&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;control&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;&lt;span style="text-decoration: underline;"&gt; &lt;/span&gt;&lt;/a&gt;over their personal data.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;Social&lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt; &lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;network&lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt; &lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;analysis&lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt; &lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;software&lt;/a&gt;&lt;/span&gt; is specifically designed to mine huge volumes of data that is collected through social networking sites, such as Facebook. Such software is specifically designed to profile individuals, to create “trees of communication” around them and to &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.scs.ryerson.ca/~bgajdero/research/Malta08.pdf"&gt;match&lt;/a&gt;&lt;a href="http://www.scs.ryerson.ca/~bgajdero/research/Malta08.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.scs.ryerson.ca/~bgajdero/research/Malta08.pdf"&gt;patterns&lt;/a&gt;&lt;/span&gt;. In other words, this software tells a story about each and every one of us, based on our activities, interests, acquaintances, and all other data. And as mentioned before, such a story may or may not be true.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In data mining, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.sagepub.com/upm-data/40006_Chapter1.pdf"&gt;behavioural&lt;/a&gt;&lt;a href="http://www.sagepub.com/upm-data/40006_Chapter1.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.sagepub.com/upm-data/40006_Chapter1.pdf"&gt;statistics&lt;/a&gt;&lt;/span&gt; are being used to analyse our data and to predict how we are likely to behave. When applied to national databases, this may potentially amount to predicting how masses or groups within the public are likely to behave and to subsequently control them.  If a data analyst can predict an individual’s future behaviour - with some probability - based on that individuals’ data, the same could potentially occur on a mass, public level.  As such, the danger within surveillance - especially corporate surveillance through which we&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;voluntarily&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;disclose&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;massive&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;amounts&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;of&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;data&lt;/a&gt;&lt;/span&gt; about ourselves - is that it appears to come down to &lt;i&gt;public control&lt;/i&gt;.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;According to security expert Bruce Schneier, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;data&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;today&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;is&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;a&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;byproduct&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;of&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;the&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;Information&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;Society&lt;/a&gt;&lt;/span&gt;.  Unlike an Orwellian totalitarian state where surveillance is imposed in a top-down manner, surveillance today appears to widely exist because we indirectly choose and enable it (by handing over our data to online companies), rather than it being imposed on us in a solely top-down manner. However, contemporary surveillance may potentially be far worse than that described in Orwell’s “1984”, because surveillance is publicly perceived to be an &lt;i&gt;indirect &lt;/i&gt;threat - if considered to be a threat at all. It is more likely that people will resist a direct threat, than an indirect threat, which means that the possibility of mass violations of human rights as a result of surveillance is real.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Hannah Arendt argued that a main prerequisite and component of totalitarian power is &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;support&lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt; &lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;by&lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt; &lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;the&lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt; &lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;masses&lt;/a&gt;&lt;/span&gt;. Today, surveillance appears to be socially integrated within societies which indicates that contemporary power fueled by surveillance has mass support. While the argument that surveillance is being socially integrated can potentially be widely debated on and requires an entire in depth research of its own, few simple facts might be adequate to prove it at this stage. Firstly, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;CCTV&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;cameras&lt;/a&gt;&lt;/span&gt; are installed in most countries, yet there has been very little resistance - on the contrary, there appears to be a type of universal acceptance on the grounds of security. Secondly, different types of spy products exist in the market - such as &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;Spy&lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt; &lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;Coca&lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt; &lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;Cola&lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt; &lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;cans&lt;/a&gt;&lt;/span&gt; - which can be purchased by anyone online. Thirdly, countries all over the world carry out controversial surveillance schemes - such as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt;Central&lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt; &lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt; &lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt;System&lt;/a&gt;&lt;/span&gt; in India - yet public resistance to such projects is limited. And while one may argue that the above cases don’t necessarily prove that surveillance is being socially integrated, it would be interesting to look at a fourth fact: most people who have Internet access &lt;i&gt;choose &lt;/i&gt;to share their personal data through the use of social networking sites.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Reality shows, such as Big Brother, which broadcast the surveillance of people’s lives and present it as a form of entertainment - when actually, I think it should be worrisome - appear to enable the social integration of surveillance. The very fact that we all probably - or, hopefully - know that Facebook can share our personal data with unauthorised third parties and - now, after the Snowden revelations - that governments can tap into Facebook’s servers, should be enough to convince us to delete our profiles. Yet, why do we still all have Facebook profiles? Perhaps because surveillance is socially integrated and perhaps because it is just &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;convenient&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;to&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;be&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;on&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;Facebook&lt;/a&gt;&lt;/span&gt;. But that doesn’t change the fact that surveillance can potentially be a threat to our human rights. It just means that we perceive surveillance as an indirect threat and that we are unlikely to react to it.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In the long term, what does this mean? Well, it seems like we will probably be &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;more&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;acceptive&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;towards&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;more&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;authoritarian&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;power&lt;/a&gt;&lt;/span&gt;, that we will be used to the idea of censoring our own thoughts and actions (in the fear of getting caught by the CCTV camera on the street or the spyware which may or may not be implanted in our laptop) and that ultimately, we will be less politically active and more reluctant to challenge the authority.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;What’s particularly interesting though about surveillance today is that it is fueled and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;enabled&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;through&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;our&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;freedom&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;of&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;speech&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;and&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;general&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;Internet&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;freedom&lt;/a&gt;&lt;/span&gt;. If we didn’t have any Internet freedom - or as much as we do - we would have disclosed less personal data and thus surveillance would probably have been more restricted. The more Internet freedom we have, the more personal data we will disclose on Facebook - and on all the ‘Facebooks’ of the world - and the more data will potentially be available to mine, analyse, share and generally incorporate in the surveillance regime. So in this sense, Internet freedom appears to be a type of prerequisite of surveillance, as contradictory and ironic as it may seem. No wonder why the Chinese government has gone the extra mile in creating the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;Chinese&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;versions&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;of&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;Facebook&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;and&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;Twitter&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;/span&gt;- it’s probably no coincidence.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While we may blame governments for establishing surveillance schemes, ISP and TSP operators for complying with governments’ license agreements which often mandate that they create backdoors for spying on us and security companies for creating the surveillance gear in the first place, in the end of the day, we are all equally a part of this mess. If we didn’t &lt;i&gt;choose &lt;/i&gt;to hand over our personal data to begin with, none of the above would have been possible.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The real danger in the Digital Age is not necessarily surveillance per se, but our &lt;i&gt;choice&lt;/i&gt; to voluntarily disclose our personal data.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you'&gt;https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-23T08:38:30Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/Brochures.zip">
    <title>Brochures.zip</title>
    <link>https://cis-india.org/internet-governance/blog/Brochures.zip</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/Brochures.zip'&gt;https://cis-india.org/internet-governance/blog/Brochures.zip&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>


   <dc:date>2013-12-26T05:23:23Z</dc:date>
   <dc:type>File</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/report-on-the-third-privacy-round-table-meeting">
    <title>Report on the 3rd Privacy Round Table meeting</title>
    <link>https://cis-india.org/internet-governance/blog/report-on-the-third-privacy-round-table-meeting</link>
    <description>
        &lt;b&gt;This report entails an overview of the discussions and recommendations of the third Privacy Round Table meeting in Chennai, on 18th May 2013.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC.&lt;/i&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;In furtherance of Internet Governance multi-stakeholder Initiatives and Dialogue in 2013, the Centre for Internet and Society (CIS) in collaboration with the Federation of Indian Chambers of Commerce and Industry (FICCI), and the Data Security Council of India (DSCI), is holding a series of six multi-stakeholder round table meetings on “privacy” from April 2013 to August 2013. The CIS is undertaking this initiative as part of their work with Privacy International UK on the SAFEGUARD project.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In 2012, the CIS and DSCI were members of the Justice AP Shah Committee which created the “Report of Groups of Experts on Privacy”. The CIS has recently drafted a Privacy (Protection) Bill 2013, with the objective of contributing to privacy legislation in India. The CIS has also volunteered to champion the session/workshops on “privacy” in the meeting on Internet Governance proposed for October 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At the roundtables the Report of the Group of Experts on Privacy, DSCI´s paper on “Strengthening Privacy Protection through Co-regulation” and the text of the Privacy (Protection) Bill 2013 will be discussed. The discussions and recommendations from the six round table meetings will be presented at the Internet Governance meeting in October 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The dates of the six Privacy Round Table meetings are enlisted below:&lt;/p&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;li&gt;New Delhi Roundtable: 13 April 2013&lt;/li&gt;
&lt;li&gt;Bangalore Roundtable: 20 April 2013&lt;/li&gt;
&lt;li&gt;Chennai Roundtable: 18 May 2013&lt;/li&gt;
&lt;li&gt;Mumbai Roundtable: 15 June 2013&lt;/li&gt;
&lt;li&gt;Kolkata Roundtable: 13 July 2013&lt;/li&gt;
&lt;li&gt;New Delhi Final Roundtable and National Meeting: 17 August 2013&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Following the first two Privacy Round Tables in Delhi and Bangalore, this report entails an overview of the discussions and recommendations of the third Privacy Round Table meeting in Chennai, on 18&lt;/span&gt;&lt;sup&gt;th&lt;/sup&gt;&lt;span&gt; May 2013.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;Overview of DSCI´s paper on ´Strengthening Privacy Protection through Co-Regulation´&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2 style="text-align: justify; "&gt;&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;The third Privacy Round Table meeting began with an overview of the paper on “Strengthening Privacy Protection through Co-Regulation” by the Data Security Council of India (DSCI). In particular, the DSCI pointed out that although the IT (Amendment) Act 2008 lays down the data protection provisions in the country, it has its limitations in terms of applicability, which is why a comprehensive privacy law is required in India. The DSCI provided a brief overview of the Report of the Group of Experts on Privacy (drafted in the Justice AP Shah Committee) and argued that in light of the UID scheme, NATRGID, DNA profiling and the Central Monitoring System (CMS), privacy concerns have arisen and legislation which would provide safeguards in India is necessary. However, the DSCI emphasized that although they support the enactment of privacy legislation which would safeguard Indians from potential abuse, the economic value of data needs to be taken into account and bureaucratic structures which would hinder the work of businesses should be avoided.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The DSCI supported the enactment of privacy legislation and highlighted its significance, but also emphasized that such a legal framework should support the economic value of data. The DSCI appeared to favour the enactment of privacy legislation as it would not only oblige the Indian government to protect individuals´ sensitive personal data, but it would also attract more international customers to Indian online companies. That being said, the DSCI argued that it is important to secure a context for privacy based on Indian standards, rather than on global privacy standards, since the applicability of global standards in India has proven to be weak. The privacy bill should cover all dimensions (including, but not limited to, interception and surveillance) and the misuse of data should be legally prevented and prohibited. Yet, strict regulations on the use of data could potentially have a negative effect on companies’ competitive advantage in the market, which is why the DSCI proposed a co-regulatory framework – if not self-regulation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In particular, the DSCI argued that companies should be obliged to provide security assurances to their customers and that regulation should not restrict the way they handle customers´ data, especially since customers &lt;i&gt;choose &lt;/i&gt;to use a specific service in every case. This argument was countered by a participant who argued that in many cases, customers may not have alternative choices for services and that the issue of “choice” and consent is complicated. Thus it was argued that companies should comply with regulations which restrict the manner with which they handle customers´ data. Another participant argued that a significant amount of data is collected without users´ consent (such as through cookies) and that in most cases, companies are not accountable in regards to how they use the data, who they share it with or how long they retain it. Another participant who also countered the co-regulatory framework suggested by the DSCI argued that regulations are required for smartphones, especially since there is currently very low accountability as to how SMS data is being used or shared. Other participants also argued that, in every case, individual consent should be acquired prior to the collection, processing, retention, and disclosure of data and that that individual should have the right to access his/her data and make possible corrections.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The DSCI firmly supported its position on co-regulation by arguing that not only would companies provide security assurances to customers, but that they would also be accountable to the Privacy Commissioner through the provision of a detailed report on how they handle their customers´ data. Furthermore, the DSCI pointed out that in the U.S. and in Europe, companies provide privacy policies and security assurances and that this is considered to be adequate. Given the immense economic value of data in the Digital Age and the severe effects regulation would have on the market, the DSCI argued that co-regulation is the best solution to ensure that both individuals´ right to privacy and the market are protected.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The discussion on co-regulation proceeded with a debate on what type of sanctions should be applied to those who do not comply with privacy regulations. However, a participant argued that if a self-regulatory model was enforced and companies did not comply with privacy principles, the question of what would happen to individuals´ data would still remain. It was argued that neither self-regulation nor co-regulation provides any assurances to the individual in regards to how his/her data is protected and that once data is breached, there is very little that can be done to eliminate the damage. In particular, the participant argued that self-regulation and co-regulation provide very few assurances that data will not be illegally disclosed and breached. The DSCI responded to this argument by stating that in the case of a data breach, the both the Privacy Commissioner and the individual in question would have to be informed and that this issue would be further investigated. Other participants agreed that co-regulation should not be an option and argued that the way co-regulation would benefit the public has not been adequately proven.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The DSCI countered the above arguments by stating that the industry is in a better position to understand privacy issues than the government due to the various products that it produces. Industries also have better outreach than the Indian government and could enhance awareness to both other companies and individuals in terms of data protection, which is why the code of practice should be created by the industry and validated by the government. This argument was countered by a participant who stated that if the industry decides to participate in the enforcement process, this would potentially create a situation of conflict of interest and could be challenged by the courts in the future. The participant argued that an industry with a self-regulatory code of practice may be problematic, especially since there would be inadequate checks and balances on how data is being handled.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another participant argued that the Indian government does not appear to take responsibility for the right to privacy, as it is not considered to be a fundamental human right; this being said, a co-regulatory framework could be more appropriate, especially since the industry has better insights on how data is being protected on an international level. Thus it was argued that the government could create high level principles and that the industry would comply. However, a participant argued that every company is susceptible to some type of violation and that in such a case, both self-regulation and co-regulation would be highly problematic. It was argued that, as any company could probably violate users´ data in some way down the line either way, self-regulation or co-regulation would probably not be the most beneficial option for the industry. This argument was supplemented by another participant who stated that co-regulation would mandate the industry and the Privacy Commissioner as the ultimate authorities to handle users´ data and that this could potentially lead to major violations, especially due to inadequate accountability towards users.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Co-regulation was once again supported by the DSCI through the argument that customers &lt;i&gt;choose &lt;/i&gt;to use specific services and that by doing so, they should comply with the security measures and privacy policies provided. However, a participant asked whether other stakeholders should be involved, as well as what type of &lt;i&gt;incentives&lt;/i&gt; companies have in order to comply with regulations and to protect users´ data. Another participant argued that the very definition of privacy remains vague and that co-regulation should not be an option, since the industry could be violating individuals´ privacy without even realising it. Another issue which was raised is how data would be protected when many companies have servers based in other countries. The DSCI responded by arguing that checks and balances would be in place to deal with all the above concerns, yet a general consensus on co-regulation did not appear to have been reached.&lt;/p&gt;
&lt;h1 style="text-align: justify; "&gt;Discussion on the draft Privacy (Protection) Bill 2013&lt;/h1&gt;
&lt;h2 style="text-align: justify; "&gt;Discussion of definitions: Chapter II&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;The sections of the draft Privacy (Protection) Bill 2013 were discussed during the second session of the third Privacy Round Table meeting. In particular, the session started with a discussion on whether the draft Privacy (Protection) Bill 2013 should be split into two separate Bills, where the one would focus on data protection and the other on surveillance and interception. The split of a Bill on data protection to two consecutive Bills was also proposed, where the one would focus on data protection binding the public sector and the other on data protection binding the private sector. As the draft Privacy (Protection) Bill 2013 is in line with global privacy standards, the possibility of splitting the Bill to focus separately on the sections mentioned above was seriously considered.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The discussion on the definitions laid out in Chapter 2 of the draft Privacy (Protection) Bill 2013 started with a debate around the definitions of personal data and sensitive personal data and what exactly they should include. It was pointed out that the Data Protection Act of the UK has a much broader definition for the term ´sensitive personal data´ and it was recommended that the Indian draft Privacy (Protection) Bill complies with it. Other participants argued that a controversy lies in India on whether the government would conduct a caste census and if that were to be the case, such data (also including, but not limited to, religion and ethnic origin) should be included in the legal definition for ´sensitive personal data´ to safeguard individuals from potential abuse. Furthermore, the fact that the term ´sensitive personal data´ does not have a harmonious nature in the U.S. and in Europe was raised, especially since that would make it more difficult for India to comply to global privacy standards.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The broadness of the definition for ´sensitive personal data´ was raised as a potential problematic issue, especially since it may not be realistic to expect companies in the long term to protect everything it may include. The participants debated on whether financial information should be included in the definition of ´sensitive personal data´, but a consensus was not reached. Other participants argued that the terms ´data subject´ and ´data controller´ should be carefully defined, as well as that a generic definition for the term ´genetic data´ should be included in the Bill. Furthermore, it was argued that the word ´monitor´ should be included in the definitions of the Bill and that the universal norms in regards to the definitions should apply to each and every state in India. It was also noted that organizational affiliation, such as a trade union membership, should also be included in the definitions of the Bill, since the lack of legal protection may potentially have social and political implications.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Discussion of “Protection of Personal Data”: Chapter III &lt;/b&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The discussion on the data protection chapter of the draft Privacy (Protection) Bill began with the recommendation that data collected by companies should comply with a confidentiality agreement. Another participant argued that the UK looks at every financial mechanism to trace how information flows and that India should do the same to protect individuals´ personal data. It was also argued that when an individual is constantly under surveillance, that individual´s behaviour is more controlled and that extra accountability should be required for the use of CCTV cameras. In particular, it was argued that when entities outside the jurisdiction gain access to CCTV data, they should be accountable as to how they use it. Furthermore, it was argued that the Bill should provide provisions on how data is used abroad, especially when it is stored in foreign servers. &lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Issue of Consent&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The meeting proceeded with a discussion of Section 6 and it was pointed out that consent needs to be a prerequisite to data collection. Furthermore, conditions laid out in section 3 would have to be met, through which the individual would have to be informed prior to any data collection, processing, disclosure and retention of data. Section 11 of the Bill entails an accuracy provision, through which individuals have the right to access the data withheld about them and make any necessary corrections. A participant argued that the transmission of data should also be included in the Bill and that the transmitter would have to be responsible for the accuracy of the data. Another participant argued that transmitters should be responsible for the integrity of the data, but that individuals should be responsible for its accuracy. However, such arguments were countered by a participant who argued that it is not practically possible to inform individuals every time there is a change in their data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Outsourcing of Data&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It was further recommended that outsourcing guidelines should be created and implemented, which would specify the agents responsible for outsourcing data. On this note, the fact that a large volume of Indian data is being outsourced to the U.S. under the Patriot Act was discussed. In particular, it was pointed out that most data retention servers are based in the U.S., which makes it difficult for Indians to be able to be informed about which data is being collected, whether it is being processed, shared, disclosed and/or retained. A participant argued that most companies have special provisions which guarantee that data will not cross borders and that it actually depends on the type of ISP handling the data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another issue which was raised was that, although a consumer may have control over his/her data at the first stage, that individual ultimately loses control over his/her data in the next stages when data is being shared and/or disclosed without his/her knowledge or consent. Not only is this problematic because individuals lose control over their data, but also because the issue of accountability arises, as it is hard to determine who is responsible for the data once it has been shared and disclosed. Some participants suggested that such a problem could possibly be solved if the data subject is informed by the data processor that its data is being outsourced, as well as of the specific parties the data is being outsourced to. Another participant argued that it does not matter who the data is being outsourced to, but the manner of its use is what really matters.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Data Retention&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Acting on the powers given by POTA, it was argued that 50,000 arrests have been made. Out of these arrests, only seven convictions have been made, yet the data of thousands of individuals can be stored for many years under POTA. Thus, it was pointed out that it is crucial that the individual is informed when his/her data is destroyed and that such data is not retained indefinitely. This was supplemented by a participant who argued that most countries in the West have data retention laws and that India should too. Other participants argued that data retention does not end with data destruction, but with the return of the data to the individual and the assurance that it is not stored elsewhere. However, several participants argued that the return of data is not always possible, especially since parties may lack the infrastructure to take back their data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It was pointed out that civil society groups have claimed that collected data should be destroyed within a specific time period, but the debate remains polarized. In particular, some participants argued that data should be retained indefinitely, as the purpose of data collection may change within time and that data may be valuable in dealing with crime and terrorism in the future. This was countered by participants who argued that the indefinite retention of data may potentially lead to human rights violations, especially if the government handling the data is non-democratic. Another participant argued that the fact that data may be collected for purpose A, processed for purpose B and retained or disclosed for purpose C can be very problematic in terms of human rights violations in the future. Furthermore, another participant stated that destruction should mean that data is no longer accessible and that is should not only apply to present data, but also to past data, such as archives.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Data Processing&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The processing of personal data is regulated in section 8 of the draft Privacy (Protection) Bill 2013. A participant argued that the responsibility should lie with the person doing the outsourcing of the data (the data collector). Another participant raised the issue that although banks acquire consent prior to collection and use of data, they subsequently use that data for any form of data processing and disclosure. Credit information requires specific permission and it was argued that the same should apply to other types of personal data. Consent should be acquired for every new purpose other than the original purpose for data collection. It was strongly argued that general consent should not cover every possible disclosure, sharing and processing of data. Another issue which was raised in terms of data processing is that Indian data could be compromised through global cooperation or pre-existing cooperation with third parties.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Data Disclosure&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The disclosure of personal data was highlighted as one of the most important provisions within the draft Privacy (Protection) Bill 2013. In particular, three types of disclosure were pointed out: (1) disclosure with consent, (2) disclosure in outsourcing, (3) disclosure for law enforcement purposes. Within this discussion, principle liability issues were raised, as well as whether the data of a deceased person should be disclosed. Other participants raised the issue of data being disclosed by international third parties, who gain access to it through cooperation with Indian law enforcement agencies and cases of dual criminality in terms of the misuse of data abroad were raised. A participant highlighted three points: (1) the subject who has responsibility for the processing of data, (2) any obligation under law should be made applicable to the party receiving the information, (3) applicable laws for outsourcing Indian data to international third parties. It was emphasized that the failure to address these three points could potentially lead to a conflict of laws.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to a participant, a non-disclosure agreement should be a prerequisite to outsourcing. This was preceded by a discussion on the conditions for data disclosure under the draft Privacy (Protection) Bill 2013 and it was recommended that if data is disclosed without the consent of the individual, the individual should be informed within one year. It was also pointed out that disclosure of data in furtherance of a court order should not be included in the Bill because courts in India tend to be inconsistent. This was followed by a discussion on whether power should be invested in the High Court in terms of data disclosure.&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Discussion of “Interception of Communications”: Chapter IV&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;The third Privacy Round Table ended with a brief discussion on the fourth chapter of the draft Privacy (Protection) Bill 2013, which regulates the interception of communications. Following an overview of the sections and their content, a participant argued that interception does not necessarily need to be covered in the draft Privacy (Protection) Bill, as it is already covered in the Telegraph Act. This was countered by participants who argued that the interception of communications can potentially lead to a major violation of the right to privacy and other human rights, which is why it should be included in the draft Privacy (Protection) Bill. Other participants argued that a requirement that intercepted communication remains confidential is necessary, but that there is no need to include privacy officers in this. Some participants proposed that an exception for sting operations should be included in this chapter.&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Meeting conclusion&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;The third Privacy Round Table entailed a discussion of the definitions used in the draft Privacy (Protection) Bill 2013, as well as of chapters II, III and IV on the right to privacy, the protection of personal data and the interception of communications. The majority of the participants agreed that India needs a privacy legislation and that individuals´ data should be legally protected. However, participants disagreed in regards to how data would be safeguarded and the extent to which data collection, processing, sharing, disclosure, destruction and retention should be regulated. This was supplemented by the debate on self-regulation and co-regulation; participants disagreed on whether the industry should regulate the use of customers´ data autonomously from government regulation or whether the industry should co-operate with the Privacy Commissioner for the regulation of the use of data. Though a consensus was not reached in regards to co-regulation and self-regulation, the majority of the participants agreed upon the establishment of a privacy legislation which would safeguard individuals´ personal data. The major issue, however, with the creation of a privacy legislation in India would probably be its adequate enforcement.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/report-on-the-third-privacy-round-table-meeting'&gt;https://cis-india.org/internet-governance/blog/report-on-the-third-privacy-round-table-meeting&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T11:35:22Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers">
    <title>The Surveillance Industry in India: At Least 76 Companies Aiding Our Watchers!</title>
    <link>https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers</link>
    <description>
        &lt;b&gt;Maria Xynou is conducting research on surveillance technology companies operating in India. So far, 76 companies have been detected which are currently producing and selling different types of surveillance technology. This post entails primary data on the first ever investigation of the surveillance industry in India. Check it out! &lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;This blog post has been &lt;a class="external-link" href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;cross-posted&lt;/a&gt; in Medianama on May 8, 2013. &lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;So yes, we live in an &lt;a href="http://www.schneier.com/blog/archives/2013/03/our_internet_su.html"&gt;Internet Surveillance State&lt;/a&gt;. And yes, we are constantly under the microscope. But how are law enforcement agencies even equipped with such advanced technology to surveille us in the first place?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Surveillance exists because certain companies produce and sell products and solutions which enable mass surveillance. Law enforcement agencies would not be capable of mining our data, of intercepting our communications and of tracking our every move if they did not have the technology to do so. Thus an investigation of the surveillance industry should be an integral part of research for any privacy advocate, which is why I started looking at surveillance technology companies. India is a very interesting case not only because it&lt;/span&gt;&lt;a href="https://cis-india.org/internet-governance/blog/report-on-the-first-privacy-round-table-meeting"&gt; lacks privacy legislation &lt;/a&gt;&lt;span&gt;which could safeguard us from the use of intrusive technologies, but also because no thorough investigation of the surveillance industry in the country has been carried out to date.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The investigation of the Indian surveillance industry has only just begun and so far, 76 surveillance technology companies have been detected. No privacy legislation...and a large surveillance industry. What does this mean?&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;A glimpse of the surveillance industry in India&lt;/b&gt;&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;In light of the &lt;/span&gt;&lt;a href="http://uidai.gov.in/"&gt;UID scheme&lt;/a&gt;&lt;span&gt;, the &lt;/span&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;National Intelligence Grid&lt;/a&gt;&lt;span&gt; (NATGRID), the &lt;/span&gt;&lt;a href="http://ncrb.nic.in/cctns.htm"&gt;Crime and Criminal Tracking Network System&lt;/a&gt;&lt;span&gt; (CCTNS) and the &lt;/span&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central Monitoring System&lt;/a&gt;&lt;span&gt; (CMS), who supplies law enforcement agencies the technology to surveille us?&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;In an attempt to answer this question and to uncover the surveillance industry in India, I randomly selected a sample of 100 companies which appeared to produce and sell surveillance technology. This sample consisted of companies producing technology ranging from internet and phone monitoring software to  biometrics, CCTV cameras, GPS tracking and access control systems. The reason why these companies were randomly selected was to reduce the probability of research bias and out of the 100 companies initially selected, 76 of them turned out to sell surveillance technology. These companies vary in the types of surveillance technology they produce and it should be noted that most of them are not restricted to surveillance technologies, but also produce other non-surveillance technologies. Paradoxically enough, some of these companies &lt;/span&gt;&lt;a href="http://www.infoserveindia.com/products/26/Internet-Monitoring-System.html"&gt;simultaneously produce internet monitoring software and encryption tools&lt;/a&gt;&lt;span&gt;! Thus it would probably not be fair to label companies as ´surveillance technology companies´ per se, but rather to acknowledge the fact that, among their various products, they also sell surveillance technologies to law enforcement agencies.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Companies selling surveillance technology in India are listed in &lt;a href="https://cis-india.org/internet-governance/blog/table-1.pdf" class="internal-link"&gt;Table 1&lt;/a&gt;. Some of these companies are Indian, whilst others have international headquarters and offices in India. Not surprisingly, the majority of these companies are based in India's IT hub, Bangalore.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;a href="https://cis-india.org/internet-governance/blog/table-2.pdf" class="internal-link"&gt;Table 2&lt;/a&gt; shows the types of surveillance technology produced and sold by these 76 companies.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The graph below is based on &lt;a href="https://cis-india.org/internet-governance/blog/table-2.pdf" class="internal-link"&gt;Table 2&lt;/a&gt; and shows which types of surveillance are produced the most by the 76 companies.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/copy_of_Surveillancetechgraph.png" alt="Surveillance Graph" class="image-inline" title="Surveillance Graph" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;Graph on types of surveillance sold to law enforcement agencies by 76 companies in India&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Out of the 76 companies, the majority (32) sell surveillance cameras, whilst 31 companies sell biometric technology; this is not a surprise, given the &lt;/span&gt;&lt;a href="http://www.economist.com/node/21542814"&gt;UID scheme&lt;/a&gt;&lt;span&gt; which is rapidly expanding across India. Only &lt;/span&gt;&lt;a href="http://www.clear-trail.com/"&gt;one company&lt;/a&gt;&lt;span&gt; from the sample produces social network analysis software, but this is not to say that this type of technology is low in the Indian market, as this sample was randomly selected and many companies producing this type of software may have been excluded. Moreover, many companies (13) from the sample produce data mining and profiling technology, which could be used in social networking sites and which could have similar - if not the same - capabilities as social network analysis software. Such technology may potentially be aiding the &lt;/span&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central Monitoring System (CMS)&lt;/a&gt;&lt;span&gt;, especially since the project would have to monitor and mine Big Data.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;On countless occasions I have been told that surveillance is an issue which concerns the elite and which does not affect the poorer classes, especially since &lt;/span&gt;&lt;a href="https://opennet.net/research/profiles/india"&gt;the majority of the population in India does not even have Internet access&lt;/a&gt;&lt;span&gt;. However, the data in the graph above falsifies this mainstream belief, as many companies operating in India produce and sell phone and SMS monitoring technology, while &lt;/span&gt;&lt;a href="http://www.thehindu.com/news/national/half-of-indias-homes-have-cellphones-but-not-toilets/article2992061.ece"&gt;more than half the population owns mobile phones&lt;/a&gt;&lt;span&gt;.  Seeing as companies, such as &lt;/span&gt;&lt;a href="http://www.clear-trail.com/"&gt;ClearTrail Technologies&lt;/a&gt;&lt;span&gt; and &lt;/span&gt;&lt;a href="http://www.shoghicom.com/"&gt;Shoghi Communications&lt;/a&gt;&lt;span&gt;, sell phone monitoring equipment to law enforcement agencies and more than half the population in India has mobile phones, it is probably safe to say that surveillance is an issue which affects everyone, not just the elite.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Did you Know:&lt;/h2&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/spywarepic.jpg" alt="Spyware" class="image-inline" title="Spyware" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;CARLOS62 on flickr &lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;WSS Security Solutions Pvt. Ltd. is &lt;a href="http://www.wssgroup.in/aboutus.html"&gt;north India´s first CCTV zone&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Speck Systems Limited was &lt;a href="http://www.specksystems.com/sub-links/Strengths/core-strengths-UAV.htm"&gt;the first Indian company to design, manufacture and fly a micro UAV indigenously&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mobile Spy India (Retina-X Studios) has the following &lt;a href="http://www.mobilespy.co.in/"&gt;mobile spying features&lt;/a&gt;: &lt;/li&gt;
&lt;/ol&gt; 
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;SniperSpy&lt;/i&gt;: remotely monitors smartphones and computers from any location&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;i&gt;Mobile Spy: &lt;/i&gt;monitors up to three phones and uploads SMS data to a server using GPRS without leaving traces&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;4. Infoserve India Private Limited produces an&lt;a href="http://www.infoserveindia.com/products/26/Internet-Monitoring-System.html"&gt; Internet monitoring System&lt;/a&gt; with the following features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intelligence gathering for an entire state or a region&lt;/li&gt;
&lt;li&gt;Builds a chain of suspects from a single start point&lt;/li&gt;
&lt;li&gt;Data loss of less than 2%&lt;/li&gt;
&lt;li&gt;2nd Generation Interception System&lt;/li&gt;
&lt;li&gt;Advanced link analysis and pattern matching algorithms&lt;/li&gt;
&lt;li&gt;Completely Automated System&lt;/li&gt;
&lt;li&gt;Data Processing of up to 10 G/s&lt;/li&gt;
&lt;li&gt;Automated alerts on the capture of suspicious data (usually based on keywords)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;5.  ClearTrail Technologies&lt;b&gt; &lt;/b&gt;deploys &lt;a href="https://www.documentcloud.org/documents/409231-111-cleartrail.html#document/p3/a68269"&gt;spyware into a target´s machine&lt;/a&gt;&lt;br /&gt;6.  Spy Impex&lt;b&gt; &lt;/b&gt;sells &lt;a href="http://www.tradedir.in/s/coca-cola-tin-camera"&gt;Coca Cola Tin Cameras&lt;/a&gt;!&lt;br /&gt;7.  Nice Deal&lt;b&gt; &lt;/b&gt;also sells Coca Cola Spy Cameras, as well as Spy Pen Cameras, Wrist Watch Cameras and &lt;a href="http://www.indiamart.com/nicedeal/spy-hidden-cameras.html"&gt;Lighter Video Cameras&lt;/a&gt; to name a few...&lt;br /&gt;8. Raviraj Technologies&lt;b&gt; &lt;/b&gt;is an Indian company which supplies &lt;a href="http://www.ravirajtech.com/index.html"&gt;RFID and biometric technology&lt;/a&gt; to multiple countries all around the world... Countries served by Raviraj Technologies include non-democracies, such as Zimbabwe and Saudi Arabia...as well as post-revolutionary countries, such as Egypt and Tunisia... Why is this concerning?&lt;/p&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;Non-democracies lack adequate privacy and human rights safeguards and by supplying such regimes with biometric and tracking technology, the probability is that this will lead to further &lt;a href="http://www.rogerclarke.com/DV/Biometrics.html"&gt;oppression&lt;/a&gt; within these countries &lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;Egypt and Tunisia had elections to transit to democracy and by providing them biometric technology, this could lead to further oppression and stifle efforts to increase human rights safeguards&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;b&gt;“I´m not a terrorist, I have nothing to hide!”&lt;/b&gt;&lt;/h2&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/surveillancetechpic.jpg" alt="Surveillance Tec" class="image-inline" title="Surveillance Tec" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/r1chard/"&gt;r1chardm&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It´s not a secret: Everyone knows we are being surveilled, more or less. Everyone is aware of the CCTV cameras (luckily there are public notices to warn us...for now). Most people are aware that the data they upload on Facebook is probably surveilled...one way or the other. Most people are aware that mobile phones can potentially be wiretapped or intercepted. Yet, that does not prevent us from using our smartphones and from disclosing our most intimate secrets to our friends, from uploading hundreds of photos on Facebook and on other social networking sites, or from generally disclosing our personal data on the Internet. The most mainstream argument in regards to surveillance and the disclosure of personal data today appears to be the following:&lt;/p&gt;
&lt;blockquote class="italized"&gt;&lt;i&gt;“I´m not a terrorist, I have nothing to hide!”&lt;/i&gt;&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Indeed. You may not be a terrorist...and you may &lt;/span&gt;&lt;i&gt;think &lt;/i&gt;&lt;span&gt;you have nothing to hide. But in a surveillance state, to what extent does it really matter if you are a terrorist? And how do we even define ´risky´ and ´non-risky´ information?&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Last year at the &lt;/span&gt;&lt;a href="http://lcaunderthestars.org.au/programme/schedule"&gt;linux.conf.au&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;a href="http://www.youtube.com/watch?v=GMN2360LM_U"&gt;Jacob Appelbaum&lt;/a&gt;&lt;span&gt; stated that in a surveillance state, everyone can potentially be a suspect. The argument “I´m not a terrorist, I have nothing to hide” is merely a psychological coping mechanism when dealing with surveillance and expresses a lack of agency. &lt;/span&gt;&lt;a href="http://www.schneier.com/essay-155.html"&gt;Bruce Schneier&lt;/a&gt;&lt;span&gt; has argued that the psychology of security does not necessarily reflect the reality of security. In other words, we may feel or think that our data is secure because we consider it to ential ´non-risky´ information, but the reality of security may indicate that our data may entail ´risky information´ depending on who is looking at it, when, how and why. I disagree with the distinction between ´risky´ and ´non-risky´ information, as any data can potentially be ´risky´ depending on the circumstances of its access.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;That being said, we do not necessarily need to disclose nude photos or be involved in some criminal organization in order to be tracked. In a surveillance society, &lt;/span&gt;&lt;a href="http://www.schneier.com/blog/archives/2013/03/our_internet_su.html"&gt;we are all potentially suspects&lt;/a&gt;&lt;span&gt;. The mining and profiling of our data may lead to us somehow being linked to someone who, for whatever reason, is a suspect (regardless of whether that person has committed an actual offence) and thus may ultimately end us up being suspects. Perhaps one of our interests (as displayed in our data), our publicly expressed ideas or even our browsing habits may fall under ´suspicious activity´. It´s not really an issue of whether we are involved in a criminal organisation per se or if we are disclosing so-called &lt;/span&gt;&lt;a href="http://www.computerworld.com/s/article/9176265/Half_of_social_networkers_post_risky_information_study_finds_"&gt;´risky information´&lt;/a&gt;&lt;span&gt;.  As long as our data is being surveilled, we are all suspects, which means that &lt;/span&gt;&lt;a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2239412"&gt;we can all potentially be arrested, interrogated and maybe even tortured&lt;/a&gt;&lt;span&gt;, just like any other criminal suspect.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;But what fuels a surveillance society? How can law enforcement agencies mine such huge volumes of data? Many companies, such as the 76 listed in this research, equip law enforcement agencies with the technology to monitor the Internet and our phones, to deploy malware to our computers, to mine and profile our data on social networking sites and to track our vehicles and movement. A main reason why we currently live in a Surveillance State is because the surveillance industry is blooming and currently equipping law enforcement agencies with the technology to watch our every move. Thus companies producing and selling surveillance technologies play an essential role in maintaining the surveillance state and should be accountable for the implications their products have on individuals´ right to privacy and other human rights.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Surveillance technologies, however, are not the only factor which fuels a surveillance state. Companies produce technologies based on the market´s demand and without it, the surveillance industry would not exist. The &lt;/span&gt;&lt;a href="http://www.sourcesecurity.com/news/articles/co-1753-ga.4047.html"&gt;market appears to demand for surveillance technologies&lt;/a&gt;&lt;span&gt; because a pre-existing &lt;/span&gt;&lt;a href="http://www.abc.net.au/tv/bigideas/stories/2012/04/16/3476847.htm"&gt;surveillance culture&lt;/a&gt;&lt;span&gt; has been established which in turn may or may not have been created by political interests of public control. Nonetheless, surveillance appears to be socially integrated. The fact that some of the most profitable businesses in the world, such as &lt;/span&gt;&lt;a href="http://money.cnn.com/magazines/fortune/global500/2012/snapshots/284.html"&gt;3M&lt;/a&gt;&lt;span&gt;, produce and sell surveillance technologies, as well as the fact that, in most countries in the world, it is considered socially prestigious to work in such a company is minimum proof that &lt;/span&gt;&lt;a href="http://www.sscqueens.org/davidlyon/"&gt;surveillance is being socially integrated&lt;/a&gt;&lt;span&gt;. In other words, companies should be accountable in regards to the technologies they produce and who they sell them to, but we should also take into consideration that the only reason why these companies exist to begin with is because there is a demand for them.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;By not opposing to repressive surveillance laws, to the CCTV cameras in every corner, to surveillance schemes -such as &lt;/span&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;NATGRID &lt;/a&gt;&lt;span&gt;and the &lt;/span&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;span&gt; in India- or by handing over our data, &lt;/span&gt;&lt;a href="http://www.schneier.com/essay-167.html"&gt;&lt;i&gt;we &lt;/i&gt;&lt;/a&gt;&lt;a href="http://www.schneier.com/essay-167.html"&gt;are fuelling the surveillance state&lt;/a&gt;&lt;span&gt;. Unlike Orwell's totalitarian state described in 1984, surveillance today does not appear to be imposed in a top-down manner, but rather it appears to be a product of both the Information Revolution &lt;/span&gt;&lt;i&gt;and &lt;/i&gt;&lt;span&gt;of our illusionary sense of control over our personal data. Our ´apathy´ enables surveillance laws to be enacted and companies to produce the technology which will aid law enforcement agencies in putting us all under the microscope. As easy as it would be to blame companies for producing surveillance technologies, the reality of surveillance appears to be much more complicated than that, especially if surveillance is socially integrated.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Yet, the reality in India is that at least 76 companies are producing and selling surveillance technologies and equipping law enforcement agencies with them. This is extremely concerning because &lt;/span&gt;&lt;a href="https://cis-india.org/internet-governance/blog/report-on-the-first-privacy-round-table-meeting"&gt;India lacks privacy legislation &lt;/a&gt;&lt;span&gt;which could safeguard individuals from potential abuse. The fact that India has not enacted a privacy law ultimately means that individuals are not informed when their data is collected, who has access to it, whether it is being processed, shared, disclosed and/or retained. Furthermore, the absence of privacy legislation in India also means that law enforcement agencies are not held liable and this has an impact on accountability and transparency, as it is not possible to determine whether surveillance is effective or not. In other words, there are currently absolutely no safeguards for the individual in India and simultaneously, the rapidly expanding surveillance industry poses major threats to human rights.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Not only does India urgently need privacy legislation to be enacted to safeguard citizens from potential abuse, but the use of all surveillance technologies should be strictly regulated now. As previously mentioned, some companies, such as &lt;/span&gt;&lt;a href="http://www.ravirajtech.com/index.html"&gt;Raviraj Technologies&lt;/a&gt;&lt;span&gt;, are exporting biometric technology to non-democratic countries and to fragile states transitioning to democracy. This should be prevented, as equipping a country - which lacks adequate safeguards for its citizens - with the technology to ultimately control its citizens can potentially have severe effects on human rights within the country. Thus &lt;/span&gt;&lt;a href="https://www.privacyinternational.org/reports/our-response-to-eu-consultation-on-legality-of-exporting-surveillance-and-censorship-3"&gt;export controls&lt;/a&gt;&lt;span&gt; are necessary to prevent the expansion of surveillance technologies to countries which lack legal safeguards for their citizens. This also means that there should be some restrictions to international companies selling surveillance technologies from creating offices in India, since the country currently lacks privacy legislation.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Surveillance technologies can potentially have very severe effects, such as innocent people being arrested, interrogated, tortured...and maybe even &lt;/span&gt;&lt;a href="http://edition.cnn.com/2013/03/15/world/asia/u-n-drone-objections"&gt;murdered&lt;/a&gt;&lt;span&gt; in some states. Should they be treated as weapons? Should the same export restrictions that apply to arms apply to surveillance technologies? Sure, the threat posed by surveillance technologies appears to be indirect. But don't indirect threats usually have worse outcomes in the long run? We may not be terrorists and we may have nothing to hide...but we have no privacy safeguards and a massively expanding surveillance industry in India. We are exposed to danger...to say the least.&lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers'&gt;https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>surveillance technologies</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>SAFEGUARDS</dc:subject>
    

   <dc:date>2013-07-12T11:59:10Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/comparison-of-draft-dna-profiling-bills">
    <title>A Comparison of the Draft DNA Profiling Bill 2007 and the Draft Human DNA Profiling Bill 2012</title>
    <link>https://cis-india.org/internet-governance/blog/comparison-of-draft-dna-profiling-bills</link>
    <description>
        &lt;b&gt;In this post, Maria Xynou gives us a comparison of the Draft DNA Profiling Bill 2007 and the Draft Human DNA Profiling Bill 2012.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Last April, the most recent version of the DNA Profiling Bill was leaked in India. The draft 2007 DNA Profiling Bill failed to adequately regulate the collection, use, sharing, analysis and retention of DNA samples, profiles and data, whilst its various loopholes created a potential for abuse. However, its 2012 amended version is not much of an improvement. On the contrary, it excessively empowers the DNA Profiling Board, while remaining vague in terms of collection, use, analysis, sharing and storage of DNA samples, profiles and data. Due to its ambiguity and lack of adequate safeguards, the draft April 2012 Human DNA Profiling Bill can potentially enable the infringement of the right to privacy and other human rights.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Draft 2007 DNA Profiling Bill &lt;i&gt;vs.&lt;/i&gt; Draft 2012 Human DNA Profiling Bill&lt;/b&gt;&lt;/h2&gt;
&lt;h3&gt;&lt;b&gt; &lt;/b&gt;&lt;b&gt;1. &lt;/b&gt;&lt;b&gt;Composition of the DNA Profiling Board&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; The Draft 2007 DNA Profiling Bill listed the members which would be appointed by the Central Government to comprise the DNA Profiling Board. A social scientist of national eminence, as stated in section 4(q) of Chapter 3, was included. However, the specific section has been deleted from the Draft 2012 Human DNA Profiling Bill and no other social scientist has been added to the list of members to comprise the DNA Profiling Board. Despite the amendments to the section on the composition of the Board, no privacy or human rights expert has been included.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; The lack of human rights experts on the board can potentially be problematic as a lack of expertise on privacy laws and other human rights laws can lead to the regulation of DNA databases without taking privacy and other civil liberties into consideration.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 4): &lt;/b&gt;&lt;i&gt;“The DNA Profiling Board shall consist of the following members appointed by the Central Government from amongst persons of ability, integrity and standing who have knowledge or experience in DNA profiling including molecular biology, human genetics, population biology, bioethics , social sciences, law and criminal justice or any other discipline which would, in the opinion of the Central Government, be useful to DNA Profiling , namely:  (a) a Renowned Molecular Biologist to be appointed by the Central Government Chairperson, (b) Secretary, Ministry of Law and Justice,  or his nominee ex-officio Member; (c) Chairman, Bar Council of India, New Delhi  or his nominee ex-officio Member; (d) Vice Chancellor, NALSAR University of Law,  Hyderabad ex-officio Member; (e) Director, Central Bureau of Investigation  or his nominee ex-officio Member;  (f) Chief Forensic Scientist, Directorate of  Forensic Science, Ministry of Home Affairs,   New Delhi ex-officio Member; (g) Director, National Crime Records Bureau, New Delhi ex-officio Member; (h) Director, National Institute of Criminology  and Forensic Sciences, New Delhi ex-officio Member; (i) a Forensic DNA Expert to be nominated  by Secretary, Ministry of Home Affairs,  New Delhi, Government of India Member; (j) a DNA Expert from All India Institute of  Medical Sciences, New Delhi to be nominated by its Director, Member; (k) a Population Geneticist to be nominated by the President, Indian National Science  Academy, New Delhi Member; (l) an Expert to be nominated by the Director, Indian Institute of Science, Bangalore Member; (m) Director, National Accreditation Board for  Testing and Calibration of Laboratories, New Delhi ex-officio Member; (n) Director, Centre for Cellular and Molecular  Biology, Hyderabad ex-officio Member; (o) Representative of the Department of  Bio-technology, Government of India, New Delhi to be nominated by Secretary, DBT, Ministry of S&amp;amp;T, Government of India Member; (p) The Chairman, National Bioethics  Committee of Department of Biotechnology,  Government of India, New Delhi ex-officio Member; (q) a Social Scientist of National Eminence  to be nominated by Secretary, MHRD,  Government of India Member; (r) four Directors General of Police representing different regions of the country to be  nominated by MHA Members; (s) two expert Members to be nominated  by the Chairperson Members (t) Manager, National DNA Data Bank ex-officio Member; (u) Director, Centre for DNA and  Fingerprinting and Diagnostics  (CDFD), Hyderabad ex-officio Member Secretary”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 4):&lt;/b&gt;&lt;i&gt;“The Board shall consist of the following Members appointed from amongst persons of ability, integrity and standing who have knowledge or experience in DNA profiling including molecular biology, human genetics, population biology, bioethics, social sciences, law and criminal justice or any other discipline which would be useful to DNA profiling, namely:- (a) A renowned molecular biologist to be appointed by the Central Government- Chairperson; (b) Vice Chancellor of a National Law University established under an Act of Legislature to be nominated by the Chairperson- ex-officio Member; (c) Director, Central Bureau of Investigation or his nominee (not below the rank of Joint Director)- ex-officio Member; (d) Director, National Institute of Criminology and Forensic Sciences, New Delhi- ex-officio Member;(e) Director General of Police of a State to be nominated by Ministry of Home Affairs, Government of India- ex-officio Member; (f) Chief Forensic Scientist, Directorate of Forensic Science, Ministry of Home Affairs, Government of India - ex-officio Member&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;(g) Director of a Central Forensic Science Laboratory to be nominated by Ministry of Home Affairs, Government of India- ex-officio Member; (h) Director of a State Forensic Science Laboratory to be nominated by Ministry of Home Affairs, Government of India- ex-officio Member; (i) Chairman, National Bioethics Committee of Department of Biotechnology, Government of India- ex-officio Member; (j) Director, National Accreditation Board for Testing and Calibration of Laboratories, New Delhi- exofficio Member; (k) Financial Adviser, Department of Biotechnology, Government of India or his nominee- ex-officio Member; (l) Two molecular biologists to be nominated by the Secretary, Department of Biotechnology, Ministry of Science and Technology, Government of India- Members; (m) A population geneticist to be nominated by the President, Indian National Science Academy, New Delhi- Member; (n) A representative of the Department of Biotechnology, Government of India to be nominated by the Secretary, Department of Biotechnology, Ministry of Science and Technology, Government of India- Member; (o) Director, Centre for DNA and Fingerprinting and Diagnostics (CDFD), Hyderabad- ex-officio Member- Secretary” &lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;2. &lt;/b&gt;&lt;b&gt;Powers and functions of the Chief Executive Officer&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Although the Chief Executive Officer´s (CEO) powers and functions are set out in the 2007 Draft DNA Bill, these have been deleted from the amended 2012 Draft Bill. The Draft 2012 Bill merely states how the CEO will be appointed, the CEO´s status and that the CEO should report to the Member Secretary of the Board. As for the powers and functions of the CEO, the 2012 Bill states that they will be specified by the Board, without any reference to what type of duties the CEO would be eligible for. Furthermore, section 10(3) has been added which determines that the CEO will be ´a scientist with understanding of genetics and molecular biology´.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; The lack of legal guidelines which would determine the scope of such regulations indicates that the CEO´s power is subject to the Board. This could create a potential for abuse, as the CEO´s power and the criteria for the creation of the regulations by the Board are not legally specified. Although an understanding of genetics and molecular biology is a necessary prerequisite for the specific CEO, an official understanding of privacy and human rights laws should also be a prerequisite to ensure that tasks are carried out adequately in regards to privacy and data protection.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 11):&lt;/b&gt;&lt;i&gt;“(1) The DNA Profiling Board shall have a Chief Executive Officer who shall be appointed by the Selection Committee consisting of Chairperson and four other members nominated by the DNA Profiling Board. (2) The Chief Executive Officer shall be of the rank of Joint Secretary to the Govt. of India and report to the Member Secretary of the DNA Profiling Board. (3)The Chief Executive Officer appointed under sub-section (1)shall exercise powers of general superintendence over the affairs of the DNA Profiling Board and its day-to-day management under the direction and control of the Member Secretary. (4) The Chief Executive Officer shall be responsible for the furnishing of all returns, reports and statements required to be furnished, under this Act and any other law for the time being in force, to the Central Government. (5) It shall be the duty of the Chief Executive Officer to place before the DNA Profiling Board for its consideration and decision any matter of financial importance if the Financial Adviser suggests to him in writing that such matter be placed before the DNA Profiling Board.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 10): &lt;/b&gt;&lt;i&gt;“(1) There shall be a Chief Executive Officer of the Board who shall be appointed by a selection committee consisting of the Chairperson and four other Members nominated by the Board. (2) The Chief Executive Officer shall be a person not below the rank of Joint Secretary to the Government of India or equivalent and he shall report to the Member-Secretary of the Board. (3) The Chief Executive Officer shall be a scientist with understanding of genetics and molecular biology. (4) The Chief Executive Officer appointed under subsection (1) shall exercise such powers and perform such duties, as may be specified by the regulations made by the Board, under the direction and control of the Member-Secretary”&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;3. &lt;/b&gt;&lt;b&gt;Functions of the Board&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; The section on the functions of the DNA Profiling Board of the 2007 Draft DNA Profiling Bill has been amended. In particular, sub-section 12(j) of the Draft 2012 Human DNA Profiling Bill states that the Board would ´authorise procedures for communication of DNA profile for civil proceedings and for crime investigation by law enforcement and other agencies´. The equivalent sub-section in the 2007 Draft DNA Bill restricted the Board´s authorisation to crime investigation by law enforcement agencies, and did not include civil proceedings and other agencies.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; This amendment raises concerns, as the ´other agencies´ and the term ´civil proceedings´ are not defined and remain vague. The broad use of the terms ´other agencies´ and ´civil proceedings´ could create a potential for abuse, as it is unclear which parties would be authorised to use DNA profiles and under what conditions, nor is it clear what ´civil proceedings´ entail.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;DNA 2007 Bill (Section 13(x)): &lt;/b&gt;&lt;i&gt;The DNA Profiling Board constituted under section 3 of this Act shall exercise and discharge the following powers and functions, namely: “authorize communication of DNA profile for crime investigation by&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;law enforcement agencies;” &lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;DNA April 2012 Bill (Section 12(j)): &lt;/b&gt;&lt;i&gt;The Board shall exercise and discharge the following functions for the purposes of this Act, namely: “authorizing procedures for communication of DNA profile for civil proceedings and for crime investigation by law enforcement and other agencies;”&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;i&gt; &lt;/i&gt;&lt;b&gt;4. &lt;/b&gt;&lt;b&gt;Regional DNA Data Banks&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 33(1) of the 2007 Draft DNA Profiling Bill has been amended and its 2012 version (section 32(1)) states that the Central Government will establish a National DNA Data Bank and ´as many Regional DNA Data Banks thereunder, for every state or group of States, as necessary´.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; This amendment enables the potential establishment of infinite regional DNA Data Banks without setting out the conditions for their function, how they would use data, how long they would retain it for or who they would share it with. The establishment of such regional data banks could potentially enable the access to, analysis, sharing and retention of huge volumes of DNA data without adequate regulatory frameworks restricting their function.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 33(1)): &lt;/b&gt;&lt;i&gt;“The Central Government shall, by a notification published in the&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;Gazette of India, establish a National DNA Data Bank.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 32(1)): &lt;/b&gt;&lt;i&gt;“The Central Government shall, by notification, establish a National DNA Data Bank and as many Regional DNA Data Banks thereunder for every State or a group of States, as necessary.&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;5. &lt;/b&gt;&lt;b&gt;Data sharing&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;Section 33(2) of the 2007 Draft DNA Profiling Bill has been amended and section 32(2) of the 2012 draft Human DNA Profiling Bill includes that every state government should establish a State DNA Data Bank which should share the information with the National DNA Data Bank.&lt;/p&gt;
&lt;p&gt;This sharing of DNA data between state and national DNA Data Banks could potentially increase the probability of data being accessed, shared, analysed and retained by unauthorised third parties. Furthermore, specific details, such as which information should be shared, how often and under what conditions, have not been specified.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 33(2)): &lt;/b&gt;&lt;i&gt;“A State Government may, by notification in the Official Gazette, establish a State DNA Data Bank.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 32(2)):&lt;/b&gt;&lt;i&gt;“Every State Government may, by notification, establish a State DNA Data Bank which shall share the information with the National DNA Data Bank.”&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;6. &lt;/b&gt;&lt;b&gt;Data retention&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 32(3) of the 2012 draft DNA Bill has been amended from its original 2007 form to include that regulations on the retention of DNA data would be drafted by the DNA Profiling Board.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; This amendment does not set out the DNA data retention period, nor who would have the authority to access such data and under what conditions. Furthermore, regulations on the retention of such data would be drafted by the DNA Profiling Board, which could increase their probability of being subject to bias and lack of transparency.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 33(3)): &lt;/b&gt;&lt;i&gt;“The National DNA Data Bank shall receive DNA data from State DNA Data Banks and shall store the DNA Profiles received from different&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;laboratories in the format as may be specified by regulations.”&lt;/i&gt; &lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 32(3)): &lt;/b&gt;&lt;i&gt;“The National DNA Data Bank shall receive DNA data from State DNA Data Banks and shall store the DNA profiles received from different laboratories in the format as may be specified by the regulations made by the Board.”&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;7. &lt;/b&gt;&lt;b&gt;Data Bank Manager&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 33 has been added to the 2012 draft Human DNA Profiling Bill and establishes a DNA Data Bank Manager, who would carry out ´all operations of and concerning the National DNA Data Bank´.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; All such operations are not clearly specified and could create a potential for abuse. The DNA Data Manager would have the same type of status as the Chief Executive Officer, but he/she would be required to have an understanding of computer applications and statistics, possibly to support data mining efforts. However, the powers and duties that the DNA Data Bank Manager would be expected to have are not specified in the Bill, which merely states that they would be specified by regulations made by the DNA Profiling Board.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2012 Bill (Section 33):&lt;/b&gt;&lt;i&gt;“(1) All operations of and concerning the National DNA Data Bank shall be carried out under the supervision of a DNA Data Bank Manager who shall be appointed by a selection committee consisting of Chairperson and four other Members nominated by the Board.(2) The DNA Data Bank Manager shall be a person not below the rank of Joint Secretary to the Government of India or equivalent and he shall report to the Member-Secretary of the Board.(3) The DNA Data Bank Manager shall be a scientist with understanding of computer applications and statistics. (4) The DNA Data Bank Manager appointed under sub-section (1) shall exercise such powers and perform such duties, as may be specified by the regulations made by the Board, under the direction and control of the Member-Secretary.”&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;8. &lt;/b&gt;&lt;b&gt;Communication of DNA profiles to foreign agencies&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; The 2007 Draft DNA Profiling Bill has been amended and sub-sections 35(2, 3) have been excluded from the 2012 Draft Human DNA Profiling Bill. These sub-clauses prohibited the use of DNA profiles for purposes other than the administration of the Act, as well as the communication of DNA profiles. Furthermore, sub-section 36(1) has been added to the 2012 Bill, which authorises the communication of DNA profiles to international agencies for the purposes of crime investigation.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; The exclusion of sub-sections 35(2, 3) from the 2012 Bill indicates that the use and communication of DNA profiles without prior authorisation may be legally permitted, which raises major privacy concerns. Sub-section 36(1) does not define a ´crime investigation´, which indicates that DNA profiles could be shared with international agencies for loosely defined ´criminal investigations´ or even for civil proceedings. The lack of a strict definition to the term ´crime investigation´, as well as the broad reference to foreign states and international agencies raises concerns, as it remains unclear who will have access to information, for how long, under what conditions and whether that data will be retained.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Sections 35(2,3)): &lt;/b&gt;&lt;i&gt;“(2) No person who receives the DNA profile for entry in the DNA Data Bank shall use it or allow it to be used for purposes other than for the administration of this Act. (3) No person shall, except in accordance with the provisions hereinabove, communicate or authorize communication, or allow to be communicated a DNA profile that is contained in the DNA Data Bank or information that is referred to in sub-section (1) of Section 34”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 36(1)): &lt;/b&gt;&lt;i&gt;“On receipt of a DNA profile from the government of a foreign state, an international organisation established by the governments of states or an institution of any such government or international organization, the National DNA Data Bank Manager may compare the DNA profile with those in the DNA Data Bank in order to determine whether it is already contained in the Data Bank and may then communicate through Central Bureau of Investigation or any other appropriate agency of the Central Government and with the prior approval of the Central Government information referred to in subsection (1) of section 35 to that government, international organisation or institution.”&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;9. &lt;/b&gt;&lt;b&gt;Data destruction&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 37 of the 2007 draft DNA Profiling Bill states that the DNA Data Bank Manager shall expunge the DNA analysis of a person from the DNA index once the court has certified that the conviction of a person has been set aside. The 2007 Bill had no particular reference to data retention. The equivalent clause (37) of the 2012 draft DNA Bill, however, not only states that individuals´ DNA data will be kept on a ´permanent basis´, but also that the DNA Data Bank Manager shall expunge a DNA profile under the same conditions under the 2007 Bill.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; This amendment indicates that Indians´ DNA data will be kept indefinitely and that it will be deleted only once the court has cleared an individual from conviction. This raises major concerns, as it does not clarify under what conditions individuals can have access to data during its retention, nor does it give ´non-convicts´ the opportunity to have their data deleted from the data bank.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 37): &lt;/b&gt;&lt;i&gt;“The Data Bank Manager shall, on receiving a certified copy of the order of the court that has become final establishing that the conviction of a person included in the DNA data bank has been set aside, expunge forthwith the DNA analysis of such person from the DNA index. Explanation:- For the purposes of this section, a court order is not ‘final’ till the expiry of the period of limitation for filing an appeal, or revision application, or review if permissible under the law, with respect to the order setting aside the conviction.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 37):&lt;/b&gt;&lt;i&gt;“(1) Subject to sub-sections (2) and (3), the information in the offenders’ index pertaining to a convict shall be kept on a permanent basis. (2) The DNA Data Bank Manager shall, on receiving a certified copy of the order of the court that has become final establishing that the person in respect of whom the information is included in the offenders’ index has been acquitted of the charge against him, expunge forthwith the DNA profile of such person from the offenders’ index, under intimation to the individual concerned, in such manner as may be prescribed. (3) The DNA Data Bank Manager shall, on receiving a certified copy of the order of the court that has become final establishing that the conviction of a person in respect of whom the information is included in the offenders’ index has been set aside, expunge forthwith the DNA profile of such person from the offenders’ index, under intimation to the individual concerned, in such manner as may be prescribed.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;10. &lt;/b&gt;&lt;b&gt;Use of DNA profiles and DNA samples and records&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment&lt;/b&gt;: Section 39 of the 2007 draft DNA Profiling Bill has been amended and the equivalent section of the 2012 DNA Bill (section 39) states that DNA profiles, samples and records can be used for purposes related to ´other civil matters´ and ´other purposes´, as specified by the regulations made by the DNA Profiling Board.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; The vague use of the terms ´other civil matters´ and ´other purposes´ can create a potential for abuse, especially since the Board will not be comprised by an adequate amount of members with legal expertise on civil matters. This section enables the use of DNA data for potentially any purpose, as long as it is enabled by the Board. Furthermore, the section does not specify &lt;i&gt;who &lt;/i&gt;can be authorised to use DNA data under such conditions, which raises further concerns.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 39):&lt;/b&gt; &lt;i&gt;“(1)All DNA profiles, samples and records shall solely be used for the purpose of facilitating identification of the perpetrator(s) of a specified&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;offence: Provided that such records or samples may be used to identify victims of&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;accidents, disasters or missing persons or for such other purposes.&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;(2) Information stored on the DNA data base system may be accessed by the authorized persons for the purposes of:  (i) forensic comparison permitted under this Act; (ii) administering the DNA data base system; (iii) accessing any information contained in the DNA database system&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;by law enforcement officers or any other persons, as may be&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;prescribed, in accordance with provisions of any law for the time&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;being in force;  (iv) inquest or inquiry;  (v) any other purpose as may be prescribed: Provided that nothing contained in this section shall apply to information&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;which may be used to determine the identity of any person.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 39): &lt;/b&gt;&lt;i&gt;“All DNA profiles and DNA samples and records thereof shall be used solely for the purpose of facilitating identification of the perpetrator of a specified offence under Part I of the Schedule: Provided that such profiles or samples may be used to identify victims of accidents or disasters or missing persons or for purposes related to civil disputes and other civil matters listed in Part I of the Schedule or for other purposes as may be specified by the regulations made by the Board.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;11. &lt;/b&gt;&lt;b&gt;Availability of DNA profiles and DNA samples&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 40 of the 2007 draft DNA Bill has been amended and an extra paragraph has been included to the equivalent 2012 Bill. In particular, section 40 enables the availability of DNA profiles and samples in criminal cases, judicial proceedings and for defence purposes among others.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; ´Criminal cases´ are loosely defined and could enable the availability of DNA data on low profile cases.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 40):&lt;/b&gt;&lt;i&gt;“The information on DNA profiles, samples and DNA identification records&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;shall be made available only : (i) to law enforcement agencies for identification purposes in a criminal&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;case; (ii) in judicial proceedings, in accordance with the rules of&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;admissibility of evidence; (iii) for facilitating decisions in cases of criminal prosecution; (iv) for defense purposes, to a victim or the accused to the extent relevant and in connection with the case in which such accused is charged; (v) for population statistics data base, identification, research and&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;protocol development, or for quality control provided that it does not&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;contain any personally identifiable information and does not violate ethical norms, as specified by rules. (vi) for any other purposes as specified by rules.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 40):&lt;/b&gt;&lt;i&gt;“Information relating to DNA profiles, DNA samples and records relating thereto shall be made available in the following instances, namely:- (a) for identification purposes in criminal cases, to law enforcement agencies; (b) in judicial proceedings, in accordance with the rules of admissibility of evidence; (c) for facilitating decisions in cases of criminal prosecution; (d) for defence purposes, to the accused to the extent relevant and in connection with the case in which such accused is charged; (e) for creation and maintenance of a population statistics database that is to be used, as prescribed, for the purposes of identification research, protocol development or quality control provided that it does not contain any personally identifiable information and does not violate ethical norms; or (f) in the case of investigations related to civil dispute and other civil matter listed in Part I of the Schedule, to the concerned parties to the said civil dispute or civil matter and to the concerned judicial officer or authority; or (g) for any other purposes, as may be prescribed.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;12. &lt;/b&gt;&lt;b&gt;Restriction on access to information in DNA Data Banks&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 43 has been added to the 2012 draft Human DNA Profiling Bill which states that access to information shall be restricted in cases when a DNA profile derives from a victim or a person who has been excluded as a suspect.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; This section implies that everyone who does not belong in these two categories has his/her data exposed to (unauthorised) access by third parties.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 43): &lt;/b&gt;&lt;i&gt;“Access to the information in the National DNA Data Bank shall be restricted in the manner as may be prescribed if the information relates to a DNA profile derived from- (a) a victim of an offence which forms or formed the object of the relevant investigation, or (b) a person who has been excluded as a suspect in the relevant investigation.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;13. &lt;/b&gt;&lt;b&gt;Board exemption from tax on wealth and income, profits and gains&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Amendment:&lt;/b&gt; Section 53 of the 2007 draft DNA Bill on “Returns and Reports” on behalf of the Board has been deleted and section 62 on the Board exemption from tax on wealth and income, profits and gains, has been added to the 2012 DNA Bill.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Analysis:&lt;/b&gt; Although the 2007 DNA Bill stated that the Central Government was authorised to issue directions, this has been replaced by section 64 of the 2012 DNA Bill, which authorises the DNA Profiling Board to issue directions.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;DNA 2007 Bill (Section 53):&lt;/b&gt;&lt;i&gt;“(1) The DNA Profiling Board shall furnish to the Central Government at&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;such time and in such form and manner as may be specified by rules or &lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;as the Central Government may direct, such returns and statements as&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;the Central Government may, from time to time, require. (2) Without prejudice to the provisions of sub-section (1), the DNA Profiling&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;Board shall, within ninety days after the end of each financial&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;year, submit to the Central Government a report in such form, as may be&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;prescribed, giving a true and full account of its activities, policy and&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;programmes during the previous financial year. (3) A copy of the report received under sub-section (2) shall be laid, as soon may be after it is received, before each House of Parliament.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DNA April 2012 Bill (Section 62):  “&lt;/b&gt;&lt;i&gt;Notwithstanding anything contained in- (a) the Wealth-tax Act, 1957; (b) the Income-tax Act, 1961; or (c) any other enactment for the time being in force relating to tax, including tax on wealth, income, profits or gains or the provision of services,- the Board shall not be liable to pay wealth-tax, income-tax or any other tax in respect of its wealth, income, profits or gains derived.”&lt;/i&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/comparison-of-draft-dna-profiling-bills'&gt;https://cis-india.org/internet-governance/blog/comparison-of-draft-dna-profiling-bills&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T15:32:08Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance">
    <title>Hacking without borders: The future of artificial intelligence and surveillance</title>
    <link>https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance</link>
    <description>
        &lt;b&gt;In this post, Maria Xynou looks at some of DARPA´s artificial intelligence surveillance technologies in regards to the right to privacy and their potential future use in India. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="Normal1"&gt;Robots or computer systems controlling our thoughts is way beyond anything I have seen in science fiction; yet something of the kind may be a reality in the future. The US Defence Advanced Research Projects Agency (DARPA) is currently funding several artificial intelligence projects which could potentially equip governments with the most powerful weapon possible: mind control.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Combat Zones That See (CTS)&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;img src="http://farm5.staticflickr.com/4137/4749564682_9ab88cb4d1.jpg" /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Source: &lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/swanksalot/"&gt;swanksalot&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p class="Normal1"&gt;Ten years ago DARPA started funding the&lt;a href="http://www.freerepublic.com/focus/f-news/939608/posts"&gt; Combat Zones That See (CTS)&lt;/a&gt; project, which aims to ´track everything that moves´ within a city through a massive network of surveillance cameras linked to a centralized computer system. Groundbreaking artificial intelligence software is being used in the project to identify and track all movement within cities, which constitutes Big Brother as a reality. The computer software supporting the CTS is capable of automatically identifying vehicles and provides instant alerts after detecting a vehicle with a license plate on a watch list. The software is also able to analyze the video footage and to distinguish ´normal´ from ´abnormal´ behavior, as well as to discover links between ´places, subjects and times of activity´ and to identify patterns. With the use of this software, the CTS constitute the world´s first multi-camera surveillance system which is capable of automatically analyzing video footage.&lt;/p&gt;
&lt;p class="Normal1"&gt;Although the CTS project was initially intended to be used for solely military purposes, its use for civil purposes, such as combating crime, remains a possibility. In 2003 DARPA stated that&lt;span&gt; &lt;a class="external-link" href="http://www.wired.com/politics/law/news/2003/07/59471"&gt;40 million surveillance cameras were already in use around the &lt;/a&gt;&lt;/span&gt;&lt;a class="external-link" href="http://www.wired.com/politics/law/news/2003/07/59471"&gt;world &lt;/a&gt;by law enforcement agencies to combat crime and terrorism, with 300 million expected by 2005. &lt;a href="http://www.wired.com/politics/law/news/2003/07/59471"&gt;Police&lt;/a&gt; in the U.S. have stated that buying new technology which may potentially aid their work is an integral part of the 9/11 mentality. Considering the fact that literally millions of CCTV cameras are installed by law enforcement agencies around the world and that DARPA has developed the software that has the capability of automatically analyzing data gathered by CCTV cameras, it is very possible that law enforcement agencies are participating in the CTS network.&lt;/p&gt;
&lt;p class="Normal1"&gt;However if such a project was used for non-military level purposes, it could raise concerns in regards to data protection, privacy and human rights. As a massive network of surveillance cameras, the CTS ultimately could enable the sharing of footage between private parties and law enforcement agencies without individuals´ knowledge or consent. Databases around the world could be potentially linked to each other and it remains unclear what laws would regulate the access, use and retention of such databases by law enforcement agencies of multiple countries. Furthermore, there is no universal definition for ´normal´ and ´abnormal´ behaviour, thus if the software is used for its original purpose, to distinguish between “abnormal” and “normal” behaviour, and used beyond military purposes, then there is a potential for abuse, as the criteria for being monitored, and possibly arrested, would not be clearly set out.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Mind´s Eye&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;img src="http://farm9.staticflickr.com/8425/7775805386_8260b7836c.jpg" /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Source: &lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/58687716@N05/"&gt;watchingfrogsboil&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p class="Normal1"&gt;A camera today which is only capable of recording visual footage appears futile in comparison to what DARPA´s creating: a &lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt;thinking camera&lt;/a&gt;. The Mind´s Eye project was launched in the U.S. in early 2011 and is currently developing smart cameras endowed with &lt;a href="http://www.darpa.mil/Our_Work/I2O/Programs/Minds_Eye.aspx"&gt;´visual intelligence´&lt;/a&gt;. This ultimately means that artificial intelligence surveillance cameras can not only record visual footage, but also automatically detect ´abnormal´ behavior, alert officials and analyze data in such a way that they are able to &lt;a href="http://phys.org/news/2012-10-surveillance-tech-carnegie-mellon.html"&gt;predict future human activities and situations&lt;/a&gt;.&lt;/p&gt;
&lt;p class="Normal1"&gt;Mainstream surveillance cameras already have visual-intelligence algorithms, but none of them are able to automatically analyze the data they collect. Data analysts are usually hired for analyzing the footage on a per instance basis, and only if a policeman detects ´something suspicious´ in the footage. Those days are over. &lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt;General&lt;/a&gt;&lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt; &lt;/a&gt;&lt;a href="http://www.wired.com/dangerroom/2011/01/beyond-surveillance-darpa-wants-a-thinking-camera/"&gt;James Cartwright&lt;/a&gt;, the vice chairman of the Joint Chiefs of Staff, stated in an intelligence conference that “Star[ing] at Death TV for hours on end trying to find the single target or see something move is just a waste of manpower.” Today, the Mind´s Eye project is developing smart cameras equipped with artificial intelligence software capable of identifying &lt;a href="http://www.darpa.mil/Our_Work/I2O/Programs/Minds_Eye.aspx"&gt;operationally significant activity&lt;/a&gt; and predicting outcomes.&lt;/p&gt;
&lt;p class="Normal1"&gt;Mounting these &lt;a href="http://www.dailygalaxy.com/my_weblog/2011/01/minds-eye-darpas-new-thinking-camera-will-transform-the-world-of-surveillance.html"&gt;smart cameras on drones&lt;/a&gt; is the initial plan; and while that would enable military operations, many ethical concerns have arisen in regards to whether such technologies should be used for ´civil purposes.´ Will law enforcement agencies in India be equipped with such cameras over the next years? If so, how will their use be regulated?&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;SyNAPSE&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;img src="http://farm9.staticflickr.com/8230/8384110298_da510e0347.jpg" /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Source: &lt;span&gt; &lt;/span&gt;&lt;a href="http://www.flickr.com/photos/healthblog/"&gt;A Health Blog&lt;/a&gt; on flickr&lt;/p&gt;
&lt;p class="Normal1"&gt;The &lt;i&gt;Terminator &lt;/i&gt;could be more than just science fiction if current robots had artificial brains with similar form, function and architecture to the mammalian brain. DARPA is attempting this by funding HRL Laboratories, Hewlett-Packard and IBM Research to carry out this task through the &lt;a href="http://www.artificialbrains.com/darpa-synapse-program"&gt;Systems of Neuromorphic Adaptive Plastic Scalable Electronics (SyNAPSE)&lt;/a&gt; programme.  Is DARPA funding the creation of the &lt;i&gt;Terminator&lt;/i&gt;? No. Such artificial brains would be used to build robots whose intelligence matches that of mice and cats...for now.&lt;/p&gt;
&lt;p class="Normal1"&gt;SyNAPSE is a programme which aims to develop &lt;a href="http://celest.bu.edu/outreach-and-impacts/the-synapse-project"&gt;electronic neuromorphic machine technology&lt;/a&gt; which scales to biological levels. It started in the U.S. in 2008 and is scheduled to run until around 2016, while having received&lt;a href="http://www.artificialbrains.com/darpa-synapse-program"&gt; $102.6 million&lt;/a&gt; in funding as of January 2013. The ultimate aim is to build an electronic microprocessor system that matches a mammalian brain in power consumption, function and size. As current programmable machines are limited by their computational capacity, which requires human-derived algorithms to describe and process information, SyNAPSE´s objective is to create &lt;a href="http://www.darpa.mil/Our_Work/DSO/Programs/Systems_of_Neuromorphic_Adaptive_Plastic_Scalable_Electronics_(SYNAPSE).aspx"&gt;biological neural systems &lt;/a&gt;which can autonomously process information in complex environments. Like the mammalian brain, SyNAPSE´s &lt;a href="http://www.ibm.com/smarterplanet/us/en/business_analytics/article/cognitive_computing.html"&gt;cognitive computers&lt;/a&gt; would be capable of automatically learning relevant and probabilistically stable features and associations, as well as of finding correlations, creating hypotheses and generally remembering and learning through experiences.&lt;/p&gt;
&lt;p class="Normal1"&gt;Although this original type of computational device could be beneficial to &lt;a href="http://www.ibm.com/smarterplanet/us/en/business_analytics/article/cognitive_computing.html"&gt;predict natural disasters&lt;/a&gt; and other threats to security based on its cognitive abilities, human rights questions arise if it were to be used in general for surveillance purposes. Imagine surveillance technologies with the capacity of a human brain. Imagine surveillance technologies capable of remembering your activity, analyzing it, correlating it to other facts and/or activities, and of predicting outcomes; and now imagine such technology used to spy on us. That might be a possibility in the future.&lt;/p&gt;
&lt;p class="Normal1"&gt;Such cognitive technology is still in an experimental phase and although it could be used to tackle threats to security, it could also potentially be used to monitor populations more efficiently. No such technology currently exists in India, but it could only be a matter of time before Indian law enforcement agencies start using such artificial intelligence surveillance technology to supposedly enhance our security and protect us.&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Brain-Computer Interface (BCI)&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;iframe frameborder="0" height="360" src="http://www.youtube.com/embed/qCSSBEXBCbY?feature=player_embedded" width="640"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;p class="Normal1"&gt;Remember Orwell's ´&lt;i&gt;Thought Police&lt;/i&gt;´? Was Orwell exaggerating just to get his point across? Well, the future appears to be much scarier than Orwell's vision depicted in &lt;i&gt;1984&lt;/i&gt;. Unlike the ´&lt;i&gt;Thought Police&lt;/i&gt;´ which merely arrested individuals who openly expressed ideas or thoughts which contradicted the Party´s dogma, today, technologies are being developed which can &lt;i&gt;literally &lt;/i&gt;read our thoughts.&lt;/p&gt;
&lt;p class="Normal1"&gt;Once again, DARPA appears to be funding one of the world´s most innovative projects: the &lt;a href="http://www.wired.com/opinion/2012/12/the-next-warfare-domain-is-your-brain/"&gt;Brain-Computer Interface (BCI)&lt;/a&gt;. The human brain is far better at pattern matching than any computer, whilst computers have greater analytical speed than human brains. The BCI is an attempt to merge the two together, and to enable the human brain to control robotic devices and other machines. In particular, the BCI is comprised of a headset (an electroencephalograph -&lt;a href="http://www.extremetech.com/wp-content/uploads/2012/08/brain-hacking-accuracy-chart.jpg"&gt; an EEG&lt;/a&gt;) with sensors that rest on the human scalp, as well as of software which processes brain activity. This enables the human brain to be linked to a computer and for an individual to control technologies without moving a finger, but by merely &lt;i&gt;thinking &lt;/i&gt;of the action.&lt;/p&gt;
&lt;p class="Normal1"&gt;Ten years ago it was reported that the brains of &lt;a href="http://www.newscientist.com/article/dn2237"&gt;rats&lt;/a&gt; and &lt;a href="http://news.bbc.co.uk/2/hi/health/3186850.stm"&gt;monkeys&lt;/a&gt; could control robot arms through the use of such technologies. A few years later&lt;a href="http://www.newscientist.com/article/dn4540"&gt; brainstem implants&lt;/a&gt; were developed to tackle deafness. Today, brain-computer interface technologies are able to directly link the human brain to computers, thus enabling paralyzed people to conduct computer activity by merely thinking of the actions, as well as&lt;a href="http://www.cyborgdb.org/mckeever.htm"&gt; to control robotic limbs with their thoughts&lt;/a&gt;. BCIs appear to open up a new gateway for disabled persons, as all previously unthinkable actions, such as typing on a computer or browsing through websites, can now be undertaken by literally &lt;i&gt;thinking &lt;/i&gt;about them, while using a BCI.&lt;/p&gt;
&lt;p class="Normal1"&gt;Brain-controlled robotic limbs could change the lives of disabled persons, but&lt;a href="http://www.guardian.co.uk/science/2007/feb/09/neuroscience.ethicsofscience"&gt; ethical concerns&lt;/a&gt; have arisen in regards to the BCI´s mind-reading ability.  If the brain can be used to control computers and other technologies, does that ultimately mean that computers can also be used to control the human brain?  Researchers from the University of Oxford and Geneva, and the University of California, Berkley, have created a custom programme that was specially designed with the sole purpose of finding out &lt;a href="http://www.extremetech.com/extreme/134682-hackers-backdoor-the-human-brain-successfully-extract-sensitive-data"&gt;sensitive data&lt;/a&gt;, such as an individuals´ home location, credit card PIN and date of birth. Volunteers participated in this programme and it had up to 40% success in obtaining useful information. To extract such information, researchers rely on the &lt;i&gt;P300 response&lt;/i&gt;, which is a very specific brainwave pattern that occurs when a human brain recognizes something that is meaningful, whether that is personal information, such as credit card details, or an enemy in a battlefield. According to &lt;a href="http://www.digitaltrends.com/cool-tech/this-is-your-brain-on-silicon/"&gt;DARPA&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote class="italized"&gt;&lt;i&gt;´When a human wearing the EEG cap was introduced, the number of false alarms dropped to only five per hour, out of a total of 2,304 target events per hour, and a 91 percent successful target recognition rate was introduced.´&lt;/i&gt;&lt;/blockquote&gt;
&lt;p class="Normal1"&gt;This constitutes the human brain as&lt;a class="external-link" href="http://www.wired.com/opinion/2012/12/the-next-warfare-domain-is-your-brain/"&gt; a &lt;span&gt;new warfighting &lt;/span&gt;domain&lt;/a&gt; of the twenty-first century, as experiments have proven that the brain can control and maneuver quadcopter drones and other military technologies. Enhanced threat detection through BCI´s scan for P300 responses and the literal control of military operations through the brain, definitely appear to be changing the future of warfare. Along with this change, the possibility of manipulating a soldier´s BCI during conflict is real and could lead to absolute chaos and destruction.&lt;/p&gt;
&lt;p class="Normal1"&gt;Security expert, Barnaby Jack, of IOActive demonstrated the &lt;a href="http://www.computerworld.com/s/article/9232477/Pacemaker_hack_can_deliver_deadly_830_volt_jolt"&gt;vulnerability of biotechnological systems&lt;/a&gt;, which raises concerns that BCI technologies may also potentially be vulnerable and expose an individual's´ brain to hacking, manipulation and control by third parties. If the brain can control computer systems and computer systems are able to detect and distinguish brain patterns, then this ultimately means that the human brain can potentially be controlled by computer software.&lt;/p&gt;
&lt;p class="Normal1"&gt;Will BCI be used in the future to&lt;a href="http://www.guardian.co.uk/science/2007/feb/09/neuroscience.ethicsofscience"&gt; interrogate terrorists and suspects&lt;/a&gt;? What would that mean for the future of our human rights? Can we have human rights if authorities can literally hack our brain in the name of national security? How can we be protected from abuse by those in power, if the most precious thing we have - our &lt;i&gt;thoughts&lt;/i&gt; - can potentially be hacked? Human rights are essential because they protect us from those in power; but the &lt;i&gt;privacy of our thoughts&lt;/i&gt; is even more important, because without it, we can have no human rights, no individuality.&lt;/p&gt;
&lt;p class="Normal1"&gt;Sure, the BCI is a very impressive technological accomplishment and can potentially improve the lives of millions. But it can also potentially destroy the most unique quality of human beings: their personal thoughts. Mind control is a vicious game to play and may constitute some of the scariest political novels as a comedy of the past. Nuclear weapons, bombs and all other powerful technologies seem childish compared to the BCI which can literally control our mind! Therefore strict regulations should be enacted which would restrict the use of BCI technologies to visually impaired or handicapped individuals.  Though these technologies currently are not being used in India, explicit laws on the use of artificial intelligence surveillance technologies should be enacted in India, to help ensure that they do not infringe upon the right to privacy and other human rights.&lt;/p&gt;
&lt;p class="Normal1"&gt;Apparently, anyone can&lt;a href="http://www.extremetech.com/extreme/134682-hackers-backdoor-the-human-brain-successfully-extract-sensitive-data"&gt; buy Emotiv or Neurosky BCI online&lt;/a&gt; to mind control their computer with only $200-$300. If the use of BCI was imposed in a top-down manner, then maybe there would be some hope that people would oppose its use for surveillance purposes; but if the idea of mind control is being socially integrated...the future of privacy seems bleak.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance'&gt;https://cis-india.org/internet-governance/blog/hacking-without-borders-the-future-of-artificial-intelligence-and-surveillance&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T15:30:27Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/workshop-on-the-uid-and-npr">
    <title>Workshop on the Unique Identity Number (UID), the National Population Register (NPR) and Governance: What will happen to our data?</title>
    <link>https://cis-india.org/internet-governance/blog/workshop-on-the-uid-and-npr</link>
    <description>
        &lt;b&gt;On March 2nd, 2013, the Centre for Internet and Society and the Say No to UID campaign organized a workshop to discuss the present state of the UID and NPR schemes. Some of the questions which were addressed included ´How do the UID and NPR impact citizenship´, ´Why and how is national security linked to UID/NPR´, and ´What is the relationship between UID and Big Data´. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="italized" style="text-align: justify; "&gt;&lt;i&gt;“The UIDAI will own our data...When we hand over information, we hand over the ownership of that data...”&lt;/i&gt;, stated Usha Ramanathan, legal researcher and human rights activist.She also pointed out that, although the UID has been set up by an executive order, there is no statute which legally backs up the UID. In other words, the collection of our data through the UID scheme is currently illegal in India, hinging only on an executive order. However, Usha Ramanathan stated that if the UID scheme is going to be carried out, it is highly significant that a statute for the UID is enacted to prevent potential abuse of human rights, especially since the UIDAI is currently collecting, sharing, using and storing our data on untested grounds.&lt;/p&gt;
&lt;blockquote class="italized"&gt;&lt;i&gt;´What is alarming is that the Indian government has not even attempted to legalize the UID! When a government does not even care about legalizing its actions, then we have much bigger problems...” &lt;/i&gt;&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The NPR is legally grounded in the provisions of the Citizenship Act 1955 and in the Citizenship Rules 2003 and it is mandatory for every usual resident in India to register with the NPR. Even though the collection of biometrics is not accounted for in the statute or rules, the NPR is currently collecting photographs, iris prints and fingerprints. Concerns regarding the use of biometrics in the UID and NPR schemes were raised during the workshop; biometrics are not infallible and can be spoofed, an individual´s biometrics can change in response to a number of factors (including age, environment and stress), the accuracy of a biometric match depends on the accuracy of the technology used and the larger the population is, the higher the probability of an error. Thus, individuals are required to re-enrol every two to three years, to ensure that the biometric data collected is accurate; but the accuracy of the data is not the only problem. The Indian government is illegally collecting biometrics and as of yet has not amended the 2003 Citizenship Rules to include the collection of biometrics! As Usha Ramanathan stated:&lt;/span&gt;&lt;/p&gt;
&lt;blockquote class="italized" style="text-align: justify; "&gt;&lt;span&gt; &lt;/span&gt;&lt;i&gt;“It´s not really about the UID and the NPR per se...it´s more about the idea of profiling citizens and the technologies which enable this...”&lt;/i&gt;&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;In his presentation, Anant Maringanti, from the Hyderabad Urban Labs and Right to the City Foundation, stated that even though seventy seven lakh duplicates have been found, no action has been taken, other than discarding one of them. Despite the fact that enrolment with the UID is considered to be voluntary, children in India are forced to get a unique identification number as a prerequisite of going to school. Anant emphasized that the UID scheme supposedly provides some form of identity to the poor and marginalised groups in India, but it actually targets some of the most vulnerable groups of people, such as HIV patients and sex workers. Furthermore, though Indians living below the poverty line (BPL) are eligible for direct cash transfer programmes, apparently registration with the UID scheme is considered essential to determine whether beneficiaries belong in the BLP category. This is problematic as individuals who have not enrolled in the UID or do not want to enroll in the UID could risk being denied benefits because they did not enroll and thus were not classified in the BPL category. Anant also pointed out that, linking biometric data to a bank account through the UID scheme is basically exposing personal data to fraud. Anant Maringanti characteristically stated: &lt;/span&gt;&lt;/p&gt;
&lt;blockquote class="italized"&gt;&lt;span&gt; &lt;/span&gt;&lt;i&gt;“I wish the 100 people applying the UID scheme had UIDs so that we could track them...!”&lt;/i&gt;&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Following the end of the workshop on the UID and NPR schemes, CIS interviewed Usha Ramanathan and Anant Maringanti: &lt;iframe frameborder="0" height="250" src="http://www.youtube.com/embed/P1CdCkdKtcU" width="250"&gt;&lt;/iframe&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The workshop can be viewed in two parts: &lt;iframe frameborder="0" height="250" src="http://www.youtube.com/embed/o7X1Af5Jw3s" width="250"&gt;&lt;/iframe&gt; &lt;iframe frameborder="0" height="250" src="http://www.youtube.com/embed/rSFYOfvtOr8" width="250"&gt;&lt;/iframe&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/workshop-on-the-uid-and-npr'&gt;https://cis-india.org/internet-governance/blog/workshop-on-the-uid-and-npr&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T15:28:50Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>




</rdf:RDF>
