<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 111 to 125.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/pti-news-may-2-2017-aadhaar-numbers-of-135mn-may-have-leaked-claims-cis-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/bloomberg-quint-may-2-2017-mahima-kapoor-aadhaar-details-of-people-available-on-govt-sites"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/comments-on-the-statistical-disclosure-control-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/national-herald-sebastian-pt-april-26-2017-now-aadhaar-details-displayed-in-mizoram-too"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-april-21-2017-komal-gupta-apurva-vishwanath-suranjana-roy-aadhaar-a-widening-net"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-april-12-2017-komal-gupta-opposition-questions-govt-move-to-make-aadhaar-must"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/asian-age-amber-sinha-april-10-2017-privacy-in-the-age-of-big-data"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai">
    <title>Aadhaar data leaks not from UIDAI: Centre </title>
    <link>https://cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai</link>
    <description>
        &lt;b&gt;Aadhaar is foolproof, it tells SC &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Krishnadas Rajagopal was &lt;a class="external-link" href="http://www.thehindu.com/news/national/aadhaar-data-leaks-not-from-uidai-centre/article18379074.ece"&gt;published in the Hindu &lt;/a&gt;on May 3, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Leaks of Aadhaar card details are not from the UIDAI, but at the State level, the Union government told the Supreme Court on Wednesday.&lt;br /&gt;&lt;br /&gt;“As of today, Aadhaar is foolproof. Biometric technology is the best system in 2016. There has not been a single leak from the UIDAI. The leaks of details may have been from the States... their offices and agencies,” advocate Arghya Sengupta, counsel for the Centre, submitted in the court.&lt;br /&gt;&lt;br /&gt;The Centre’s clarification comes in the midst of reports that data of over 130 million Aadhaar cardholders have been leaked from four government websites.&lt;br /&gt;&lt;br /&gt;Reports, based on a study conducted by the Centre for Internet and Society (CIS), a Bengaluru-based organisation, said Aadhaar numbers, names and other personal details of people have been leaked.&lt;br /&gt;&lt;br /&gt;The Centre was washing its hands of the alleged leaks for the second consecutive day in the Supreme Court.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;A-G’s assurance&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;On Tuesday, Attorney-General Mukul Rohatgi had emphatically assured the Supreme Court that biometrics of Aadhaar cardholders were safe and had not fallen into other hands. He said the biometric details were kept in a central database run by the Centre.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai'&gt;https://cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>UID</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>UIDAI</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    

   <dc:date>2017-05-20T08:27:28Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone">
    <title>Around 130-135M Aadhaar Numbers published on 4 sites alone</title>
    <link>https://cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone</link>
    <description>
        &lt;b&gt;“Therefore, there is no data leak, there is no systematic problem, but, if any one tries to be smart, the law ignites into action.” – Ravi Shankar Prasad, IT Minister, in the Rajya Sabha, on 10th April 2017.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Nikhil Pahwa was &lt;a class="external-link" href="http://www.medianama.com/2017/05/223-aadhaar-numbers-data-leak/"&gt;published by Medianama&lt;/a&gt; on May 4, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Details of around 130-135 million Aadhaar Numbers, and around 100  million bank numbers have been leaked online by just four government  schemes alone: the National Social Assistance Programme, the National  Rural Employment Guarantee Scheme (NREGA), Daily Online Payments Reports  under NREGA (Govt of Andhra Pradesh), and the Chandranna Bima Scheme  (Govt of Andhra Pradesh), as per a research report from the Centre for  Internet and Society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Download the report &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information/at_download/file" rel="noopener noreferrer"&gt;here&lt;/a&gt;.&lt;/b&gt; Read full story on &lt;a class="external-link" href="http://www.medianama.com/2017/05/223-aadhaar-numbers-data-leak/"&gt;Medianama website&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone'&gt;https://cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T10:52:26Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report">
    <title>Aadhaar numbers of 135 mn may have leaked, claims CIS report</title>
    <link>https://cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report</link>
    <description>
        &lt;b&gt;Aadhaar numbers and personal information of as many as 135 million Indians could have been leaked from four government portals due to lack of IT security practices, the Centre for Internet and Society has claimed. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published by &lt;a class="external-link" href="http://www.dnaindia.com/india/report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report-2425384"&gt;DNA&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;"Based on the numbers available on the websites looked at, estimated  number of Aadhaar numbers leaked through these four portals could be  around 130-135 million," the report by CIS said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Further, as many as 100 million bank account numbers could have been "leaked" from the four portals, it added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The portals where the purported leaks happened were those of  National Social Assistance Programme, National Rural Employment  Guarantee Scheme, as well as two websites of the Andhra Pradesh  government.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Over 23 crore beneficiaries have been brought under Aadhaar  programme for DBT (Direct Benefit Transfer), and if a significant number  of schemes have mishandled data in a similar way, we could be looking  at a data leak closer to that number," it cautioned.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The disclosure came as part of a CIS report titled 'Information  Security Practices of Aadhaar (or lack thereof): A Documentation of  Public Availability of Aadhaar Numbers with Sensitive Personal Financial  Information'.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When contaced, a senior official of the Unique Identification  Authority of India (UIDAI) said that there was no breach in its own  database. The UIDAI issues Aadhaar to citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The CIS report claimed that the absence of "proper controls" in  populating the databases could have disastrous results as it may divulge  sensitive information about individuals, including details about  address, photographs and financial data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"The lack of consistency of data masking and de- identification  standard is an issue of great concern...the masking of Aadhaar numbers  does not follow a consistent pattern," the report added.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report'&gt;https://cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:10:37Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites">
    <title>১৩ কোটি আধার তথ্য ফাঁস চার সরকারি পোর্টাল থেকে! বিস্ফোরক দাবি রিপোর্টে </title>
    <link>https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites</link>
    <description>
        &lt;b&gt;খোদ সরকারি পোর্টাল থেকে কয়েক কোটি আধার নম্বর ও যাবতীয় তথ্য ‘ফাঁস’!&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This was published by &lt;a class="external-link" href="http://abpananda.abplive.in/india-news/13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites-334778"&gt;Amar Bazar Patrika&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;অভিযোগ, গত কয়েক মাসে প্রায় ১৩ কোটি আধার  নম্বরের যাবতীয় ব্যক্তিগত ও সংবেদনশীল তথ্য ফাঁস হওয়ার ঘটনা ঘটেছে। আর এসবই  হয়েছে চারটি সরকারি পোর্টাল থেকে তথ্যপ্রযুক্তি সুরক্ষার ঘাটতির জেরে! যা  ঘিরে এখন তোলপাড় দেশ।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সম্প্রতি, এমনই বিস্ফোরক রিপোর্ট প্রকাশ  করেছে অলাভদায়ক সংগঠন সেন্টার ফর ইন্টারনেট অ্যান্ড সোসাইটি (সিআইএস)।  তাদের আশঙ্কা, চারটি সরকারি পোর্টালের মাধ্যমে ১০ কোটি মানুষের ব্যাঙ্ক  অ্যাকাউন্ট নম্বরও ফাঁস হয়ে থাকতে পারে।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সংস্থার দাবি, যে চারটি পোর্টাল থেকে এই  সব তথ্য ফাঁসের অভিযোগ, তার মধ্যে দু’টি অন্ধ্রপ্রদেশ সরকারের ওয়েবসাইট।  বাকি দুটি পোর্টাল হল ন্যাশনাল সোশ্যাল অ্যাসিস্ট্যান্স প্রোগ্রাম এবং  ন্যাশনাল রুরাল এমপ্লয়মেন্ট গ্যারান্টি স্কিম-এর।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;এই গোটা ঘটনার জন্য ইউনিক আইডেন্টিফিকেশন  অথরিটি অফ ইন্ডিয়া বা ইউআইডিএআই–কেই দায়ী করেছে সিআইএস। তাদের দাবি, আধার  নিয়ন্ত্রক সংস্থার ‘দায়িত্বজ্ঞানহীনতার’ জন্যই এই উদ্ভুত পরিস্থিত সৃষ্টি  হয়েছে।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সিএনআই-এর আরও দাবি, বিভিন্ন সরকারি ও  বেসরকারি পোর্টাল—যারা আধার তথ্য ব্যবহার করে থাকে, তাদের নিজস্ব  সুরক্ষা-ব্যবস্থা খতিয়ে দেখেনি ইউআইডিএআই। ফলত, এই বিপত্তির সম্মুখীন কয়েক  কোটি মানুষ।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;যদিও, ইউআইডিএআই -এর দাবি, তাদের ডেটাবেস থেকে কোনও তথ্য ফাঁস হয়নি।&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites'&gt;https://cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:45:42Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals">
    <title>UIDAI remains silent on #Aadhaarleaks of 13 crore users through government portals</title>
    <link>https://cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals</link>
    <description>
        &lt;b&gt;As the arguments for making Aadhaar mandatory go on, is there any way to stem the leaks and identify who exactly has all this information.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Shruti Menon was &lt;a class="external-link" href="https://www.newslaundry.com/2017/05/02/uidai-remains-silent-on-aadhaarleaks-of-13-crore-users-through-government-portals"&gt;published by Newslaundry&lt;/a&gt; on May 2, 2017&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The verdict on linking Aadhaar with Permanent Account Number (PAN) and  making it mandatory for filing income tax returns (ITRs) will be out  soon. Attorney General Mukul Rohatgi had a tough challenge ahead of him  in the Supreme Court as the state presented its argument today. Rohatgi  defended the &lt;a href="http://www.livemint.com/Politics/3FcQ9lHm7TWX5B0Hn7ZXiO/Aadhaar-to-be-mandatory-for-income-tax-returns-getting-PAN.html" target="_blank"&gt;amendment in income tax law&lt;/a&gt; allowing this after senior lawyer Shyam Divan made a &lt;a href="http://www.livemint.com/Politics/sN0S5mYYx641tgrctGf03H/Shyam-Divan-concludes-arguments-in-Aadhaar-case-in-Supreme-C.html" target="_blank"&gt;strong case&lt;/a&gt; against  it on April 26 and 27. Divan became a hero to many overnight after he  presented compelling arguments against the amendment citing facets of  right to privacy - informational self-determination, personal autonomy,  and bodily integrity - as he did so. Though the court has &lt;a href="https://www.thequint.com/opinion/2017/05/01/aadhaar-case-privacy-and-bodily-integrity" target="_blank"&gt;refused to entertain&lt;/a&gt; arguments pertaining to privacy, he managed to argue these concerns without couching them under right to privacy laws.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Advocate Gautam Bhatia posted &lt;a href="https://barandbench.com/aadhar-hearing-number-tagging-nazi-concentration-camps/" target="_blank"&gt;minute-by-minute developments from the courtroom&lt;/a&gt;, and soon, #ThankYouMrDivan became one of the top trends on Twitter.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A day before the state presented its arguments, the Centre for Internet and Society (CIS) published a &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1" target="_blank"&gt;report &lt;/a&gt;titled  “Information, Security Practices of Aadhaar (or lack thereof): A  documentation of public availability of Aadhaar numbers with sensitive  personal financial information” late on Monday. Authored by Amber Sinha  and Srinivas Kodali, the report documents the leaks of over 13 crore  Aadhaar numbers and resulting information of beneficiaries through four  government portals-two at the centre and two at the state. “We are  primarily talking of lack of standards and data fact-checking, storage  and how all of this information- account numbers, phone numbers plus,  Aadhaar numbers- in public domain increases the nature of risk of the  backbone of digital payments,” Kodali told &lt;i&gt;Newslaundry. &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The four portals studied by the two are National Social Assistance  Programme (NSAP), National Rural Employment Guarantee Act (NREGA) and  two databases of Andhra Pradesh- NREGA and their scheme called Chandranna Bima.  The report claims that the aforementioned public portals compromised  personally identifiable information (PII) including “Aadhaar numbers and  financial details such as bank account numbers” of 13 crore people due  to a lack of security controls.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the details were masked for public view, someone with login  access could get the details,” the report read. “When one of the url  query parameters of the website showing the masked personal details was  modified from ‘nologin’ to ‘login’, that is, control access to login  based pages were allowed providing unmasked details without the need for  a password.” What this essentially means is that these portals allow  people to explore lists organised by states, districts, area,  sub-district, and municipalities which contain the personal information  of the people who are enrolled into the schemes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The report also  cites legal framework under the Aadhaar Act that allows the government  or private entities to store Aadhaar numbers on the grounds that they  won’t be used for purposes other than those listed in the act. CIS’s  study, however, reveals that information pertaining to religion, caste,  race, tribe or even income is sometimes collected and published on such  portals with little in the way of security checks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Speaking to &lt;i&gt;Newslaundry,&lt;/i&gt; Anupam Saraph, professor and former governance and IT advisor to Goa’s  Chief Minister, Manohar Parrikar, said that the data exposed could be  significantly more than what the report shows. “Many more Aadhaar  numbers have been exposed on websites relating to Pension Schemes, PDS,  Ministry of Water and Sanitation, Ministry of Human Resource  Development, Scholarships, Schools, Colleges, Universities, Kendriya  Sainik board, PM Avas Yojana to name a few,” he said. “Besides this  Registrars to the UIDAI (State Governments and various ministries of the  Central government, some Public Sector undertakings) were allowed to  retain the Aadhaar number, demographic and biometric data (associated  with the Aadhaar number). While this may not be exposed on websites, it  is unsecured and possibly accessible to data brokers within and outside  government,” said Saraph who has designed delivery channels and ID  schemes for better governance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What’s worth noting is that the  people whose data has been breached are unaware that their information  is available on public platforms and vulnerable to data theft. “It is  UIDAI’s [Unique Identification Authority of India] job to investigate  and inform them,” Kodali told &lt;i&gt;Newslaundry. “&lt;/i&gt;At some point of time, everybody is going to have everybody’s information,” he added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Currently, the government has an &lt;a href="https://data.gov.in/" target="_blank"&gt;open data portal&lt;/a&gt;. It  describes itself as a platform “intended to be used by Government  Ministries/Departments and their organisation to publish datasets,  documents, services, tools and applications collected by them for public  use”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So is it feasible to have open data portals for  transparency and accountability? “Having certain government data being  publicly accessible is certainly desirable.” Saraph continued that the  problem was, data on public expenditure should ideally be openly  accessible but it’s also where the most leakage occurs. “Making Aadhaar  mandatory is meaningless,” he said, as India does not have a policy on  open data portals yet, which can subject Aadhaar data to “misuse”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given  that the UIDAI is responsible for investigating and making people aware  of any data breach or theft, they have remained silent for an oddly  long time. It is unclear whether the UIDAI is itself aware of who has  accessed the data that is insecurely published on these government  portals. “They’re letting everybody collect this information but they  were not aware themselves that who had access to this information,  that’s the main problem,” Kodali said. While the Aadhaar ecosystem was  to ensure social inclusion and transparency, in its current form, the  system looks so opaque that the people who are running it may not be  aware themselves of what is going on.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;What does it mean to have access to someone else’s Aadhaar?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With  an increasing number of social welfare schemes being linked to Aadhaar,  it was touted as an attempt to remove the middlemen, frauds and  corruption with the government. According to the report, "A cumulative  amount of Rs 1,78,694.75 has been transferred using DBT for 138 schemes  under 27 ministries since 2013. Various financial frameworks like  Aadhaar Payments Bridge (APB) and Aadhaar Enabled Payment Systems (AePS)  have been built by National Payment Corporation of India to support DBT  and also to allow individuals use Aadhaar for payments."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given  that such systems are in place to ensure easier and accessible banking,  research shows that the Aadhaar seeding process led to government  portals putting personal information of so many people under various  schemes in the "absence of information security practices to handle so  much PII", as per the research. This is not only a breach of privacy but  also makes a person vulnerable to financial fraud in cases where their  bank details are public. "One of the prime examples is individuals  receiving phone calls from someone claiming to be from the bank. Aadhaar  data makes this process much easier for fraud and increases the risk  around transactions," the report reads.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;UIDAI on silent mode&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Unfortunately,  UIDAI has not addressed this concern, let alone acknowledge it. It has  been cracking down on people by filing first information reports (FIRs)  against those tracking and exposing the vulnerabilities of the Aadhaar  system. Recently, UIDAI’s Chief Executive Officer (CEO), ABP Pandey was  accused of blocking twitter handles of prominent security researchers  and analysts who have been extensively reporting about vulnerabilities  in the Aadhaar system.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One of the handles was blocked was Saraph’s. “I do not know why they  blocked me. I have been vocal about the problems associated with the UID  and its use,” he said&lt;i&gt;. &lt;/i&gt;He added that he served several &lt;a href="http://www.moneylife.in/article/resisting-violations-of-the-supreme-court-orders-on-aadhaar/49121.html," target="_blank"&gt;notices&lt;/a&gt; of  contempt of court to the CEO of UIDAI and has been questioning the  verification and audit of UID database. “Perhaps [he] was annoyed with  my efforts to make them accountable and responsible,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On  April 18, however, in a response to Right to Information (RTI) query  filed by Sushil Kambampati, UIDAI denied having blocked any twitter  handles. Almost immediately, it was called out on twitter for ‘lying’ in  the RTI response as many users claimed it had.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Saraph declared that such a move, the blocking of users asking  questions, was indicative of UIDAI’s cluelessness. Apar Gupta, a  Delhi-based lawyer working on cyber security, had told &lt;i&gt;Newslaundry &lt;/i&gt;that  it was unethical and unconstitutional of government bodies (such as the  UIDAI) to block people. He reiterated that in one of his tweets  recently.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Today, however, the Pandey’s individual twitter profile no longer  exists. It has now been changed to “ceo_office”. CIS’s report states  that the UIDAI has been pushing for more databases to get in sync with  Aadhaar, but with little or no accountability. “While the UIDAI has been  involved in proactively pushing for other databases to get seeded with  Aadhaar numbers, they take a little responsibility in ensuring the  security and privacy of such data,” the report reads. Kodali, however,  told &lt;i&gt;Newslaundry &lt;/i&gt;that the report was not aimed at questioning the  security of such seeding. “We’re not saying it is not really secure but  we’re just saying it increases the risk factors,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI has also not responded to several queries filed by vulnerability testers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Newslaundry &lt;/i&gt;reached out to the UIDAI with the following questions:&lt;/p&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; According to the report published, four government portals have  personally identifiable information of about 13 crore people including  their Aadhaar numbers and bank account details. What is being done about  this?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; If a person's privacy has been breached, what are the steps UIDAI would take for redressal?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; Is UIDAI investigating the 13 crore Aadhaar leaks?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; The report states "When one of the url query parameters of website  showing the masked personal details was modified from “nologin” to  “login”, that is control access to login based pages were allowed  providing unmasked details without the need for a password." Is this  true, and if so, what is your statement?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; How do you ensure data security on open data portals?&lt;/i&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;This piece will be updated if and when they respond.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While  UIDAI remains silent, A-G Rohatgi argued today that close to 10 lakh  PAN cards were found to be fake. "Are they propagating a general public  interest or propagating the fraud (fake PANs) which is going in," he  said at the court today while suggesting that Aadhaar was the only way  of preventing fake or duplicate cards.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Senior advocate Arvind  Datar, who is also appearing for one of the three petitioners in the  case said that the government could not take away his right to chose  whether or nor to have an Aadhaar. "The Supreme Court had directed them  that they cannot make it mandatory. The mandate of the Supreme Court can  not be undone. My right of not to have an Aadhaar can not be taken away  indirectly."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Though there are problems with the Aadhaar system  and apparently very little redressal at the citizen’s end, Aadhaar is  here to stay. As Divan and Rohatgi argue the constitutionality of making  Aadhaar mandatory at the Supreme Court, the pertinent question that  only the UIDAI can answer is whether they are technologically capable of  keeping data secure given how aggressively Aadhaar linkage is being  promoted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, Rohatgi's argument in court today, according to  a Business Standard report was that the government cannot destroy the  Aadhaar cards of people even after their death. Instead of being  reassuring, this only seems to increase the possibilities for identity  theft, as if there is little in the way of redressal mechanisms in life,  what choices do the dead have?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The author can be contacted on Twitter &lt;a href="https://twitter.com/shrutimenon10" target="_blank"&gt;@shrutimenon10&lt;/a&gt;.&lt;/b&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals'&gt;https://cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:06:16Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report">
    <title>Details of 135 million Aadhaar card holders may have leaked, claims CIS report</title>
    <link>https://cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report</link>
    <description>
        &lt;b&gt;The disclosure came as part of a CIS report titled ‘Information Security Practices of Aadhaar (or lack thereof): A Documentation of Public Availability of Aadhaar Numbers with Sensitive Personal Financial Information’.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The news from the Press Trust of India was published in the &lt;a class="external-link" href="http://www.hindustantimes.com/india-news/details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report/story-39nojShtnAmr3EruCKbdrL.html"&gt;Hindustan Times&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar numbers and personal information of as many as 135 million Indians could have been leaked from four government portals due to lack of IT security practices, the Centre for Internet and Society has claimed.&lt;br /&gt;&lt;br /&gt;“Based on the numbers available on the websites looked at, estimated number of Aadhaar numbers leaked through these four portals could be around 130-135 million,” the report by CIS said.&lt;br /&gt;&lt;br /&gt;Further, as many as 100 million bank account numbers could have been “leaked” from the four portals, it added.&lt;br /&gt;&lt;br /&gt;The portals where the purported leaks happened were those of National Social Assistance Programme, National Rural Employment Guarantee Scheme, as well as two websites of the Andhra Pradesh government.&lt;br /&gt;&lt;br /&gt;“Over 23 crore beneficiaries have been brought under Aadhaar programme for DBT (Direct Benefit Transfer), and if a significant number of schemes have mishandled data in a similar way, we could be looking at a data leak closer to that number,” it cautioned.&lt;br /&gt;&lt;br /&gt;The disclosure came as part of a CIS report titled ‘Information Security Practices of Aadhaar (or lack thereof): A Documentation of Public Availability of Aadhaar Numbers with Sensitive Personal Financial Information’.&lt;br /&gt;&lt;br /&gt;When contaced, a senior official of the Unique Identification Authority of India (UIDAI) said that there was no breach in its own database. The UIDAI issues Aadhaar to citizens.&lt;br /&gt;&lt;br /&gt;The CIS report claimed that the absence of “proper controls” in populating the databases could have disastrous results as it may divulge sensitive information about individuals, including details about address, photographs and financial data.&lt;br /&gt;&lt;br /&gt;“The lack of consistency of data masking and de- identification standard is an issue of great concern...the masking of Aadhaar numbers does not follow a consistent pattern,” the report added.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report'&gt;https://cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T08:42:57Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/pti-news-may-2-2017-aadhaar-numbers-of-135mn-may-have-leaked-claims-cis-report">
    <title>Aadhaar numbers of 135 mn may have leaked, claims CIS report</title>
    <link>https://cis-india.org/internet-governance/news/pti-news-may-2-2017-aadhaar-numbers-of-135mn-may-have-leaked-claims-cis-report</link>
    <description>
        &lt;b&gt;Aadhaar numbers and personal information of as many as 135 million Indians could have been leaked from four government portals due to lack of IT security practices, the Centre for Internet and Society has claimed.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The news was published by the &lt;a class="external-link" href="http://www.ptinews.com/news/8665876_Aadhaar-numbers-of-135-mn-may-have-leaked--claims-CIS-report.html"&gt;Press Trust of India &lt;/a&gt;on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;"Based on the numbers available on the websites looked at, estimated number of Aadhaar numbers leaked through these four portals could be around 130-135 million," the report by CIS said.&lt;br /&gt;&lt;br /&gt; Further, as many as 100 million bank account numbers could have been "leaked" from the four portals, it added.&lt;br /&gt;&lt;br /&gt;The portals where the purported leaks happened were those of National Social Assistance Programme, National Rural Employment Guarantee Scheme, as well as two websites of the Andhra Pradesh government.&lt;br /&gt;&lt;br /&gt;"Over 23 crore beneficiaries have been brought under Aadhaar programme for DBT (Direct Benefit Transfer), and if a significant number of schemes have mishandled data in a similar way, we could be looking at a data leak closer to that number," it cautioned.&lt;br /&gt;&lt;br /&gt;The disclosure came as part of a CIS report titled 'Information Security Practices of Aadhaar (or lack thereof): A Documentation of Public Availability of Aadhaar Numbers with Sensitive Personal Financial Information'.&lt;br /&gt;&lt;br /&gt;When contaced, a senior official of the Unique Identification Authority of India (UIDAI) said that there was no breach in its own database. The UIDAI issues Aadhaar to citizens.&lt;br /&gt;&lt;br /&gt;The CIS report claimed that the absence of "proper controls" in populating the databases could have disastrous results as it may divulge sensitive information about individuals, including details about address, photographs and financial data.&lt;br /&gt;&lt;br /&gt;"The lack of consistency of data masking and de- identification standard is an issue of great concern...the masking of Aadhaar numbers does not follow a consistent pattern," the report added.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/pti-news-may-2-2017-aadhaar-numbers-of-135mn-may-have-leaked-claims-cis-report'&gt;https://cis-india.org/internet-governance/news/pti-news-may-2-2017-aadhaar-numbers-of-135mn-may-have-leaked-claims-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T10:42:59Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/bloomberg-quint-may-2-2017-mahima-kapoor-aadhaar-details-of-people-available-on-govt-sites">
    <title>Aadhaar Details Of 13.5 Crore People Available On Government Sites </title>
    <link>https://cis-india.org/internet-governance/news/bloomberg-quint-may-2-2017-mahima-kapoor-aadhaar-details-of-people-available-on-govt-sites</link>
    <description>
        &lt;b&gt;Up to 13.5 crore Aadhaar numbers can be easily accessed through government portals and nearly three-fourths of these are linked to bank accounts, said non-profit research organisation the Centre For Internet &amp; Society (CIS).&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Calling the Unique Identification Authority of India (UIDAI)  “extremely irresponsible” in maintaining privacy standards, CIS blamed  the Aadhaar governing body for turning a "blind eye" to the lack of  standards regarding use of Aadhaar data by private and public bodies&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"It  is staggering that while these databases have existed in the public  domain for months, while framing the Aadhaar Act Regulations in late  2016, the UIDAI did not even deem these as important matters to be  addressed by way of regulations or standards," CIS said in a report  titled ‘Information Security Practices of Aadhaar (or lack thereof)’.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The CIS report points out several government sites which showcase  inefficiently masked Aadhaar codes with sensitive personally  identifiable information, also available for download as spreadsheets.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="external-link" href="https://www.bloombergquint.com/technology/2017/05/20/why-flipkart-needs-more-than-softbank-to-take-on-amazon"&gt;Read the full story on Bloomberg Quint&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/bloomberg-quint-may-2-2017-mahima-kapoor-aadhaar-details-of-people-available-on-govt-sites'&gt;https://cis-india.org/internet-governance/news/bloomberg-quint-may-2-2017-mahima-kapoor-aadhaar-details-of-people-available-on-govt-sites&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:00:55Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/comments-on-the-statistical-disclosure-control-report">
    <title>Comments on the Statistical Disclosure Control Report</title>
    <link>https://cis-india.org/internet-governance/comments-on-the-statistical-disclosure-control-report</link>
    <description>
        &lt;b&gt;This submission presents comments by the Centre for Internet and Society, India (“CIS”) on the ​Statistical Disclosure Control Report published on March 30th by Ministry of Statistics and Programme Implementation. 
&lt;/b&gt;
        
&lt;p&gt;&lt;strong id="docs-internal-guid-a12fe2b3-c746-4c1a-0287-1814414668af"&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify;" dir="ltr"&gt;1. PRELIMINARY&lt;/h3&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;This submission presents comments by the Centre for Internet and Society, India (“CIS”) on the ​Statistical Disclosure Control Report published on March 30th by Ministry of Statistics and Programme Implementation.&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;CIS is thankful for the opportunity to put forth its views.&lt;br class="kix-line-break" /&gt;This submission is divided into three main parts. The first part, ‘Preliminary’, introduces the document; the second part, ‘About CIS’, is an overview of the organization; and, the third part contains the ‘Comments’.&lt;br class="kix-line-break" /&gt;&lt;br class="kix-line-break" /&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify;" dir="ltr"&gt;2. ABOUT CIS&lt;/h3&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;CIS is a non-​profit organisation that undertakes interdisciplinary research on internet and digital technologies from policy and academic perspectives. The areas of focus include digital accessibility for persons with diverse abilities, access to knowledge, intellectual property rights, openness (including open data, free and open source software, open standards, open access, open educational resources, and open video), internet governance, telecommunication reform, freedom of speech and expression, intermediary liability, digital privacy, and cybersecurity.​&lt;br class="kix-line-break" /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;CIS values the fundamental principles of justice, equality, freedom and economic development. This submission is consistent with CIS' commitment to these values, the safeguarding of general public interest and the protection of India's national interest at the international level. Accordingly, the comments in this submission aim to further these principles.&lt;/p&gt;
&lt;h3 style="text-align: justify;" dir="ltr"&gt;3. Comments&lt;/h3&gt;
&lt;h4 style="text-align: justify;" dir="ltr"&gt;3.1 General Comments&lt;/h4&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;As a non-profit organisation we recognize the importance of the efforts by the Ministry of Statistics and Programme Implementation (MoSPI) to make the &amp;nbsp;data you collect available to the public in open formats with relevant information about reliability of statistical estimates.&lt;/p&gt;
&lt;p&gt;&lt;span style="text-align: justify;"&gt;We at CIS have recently released a report titled “Information Security Practices of Aadhaar (or lack thereof): A documentation of public availability of Aadhaar Numbers with sensitive personal financial information”. We encountered several central and state government departments collecting socioeconomic data from citizens, linking it with Aadhaar and even publishing them in exportable data formats like EXCEL and MS ACCESS Databases. &amp;nbsp;&lt;/span&gt;&lt;span style="text-align: justify;"&gt;While we understand this issue primarily concerns to Unique Identification Authority of India (UIDAI), the lack of standards around information/statistical disclosure are a general threat to transparency in a democracy and privacy of individuals.&amp;nbsp;&lt;/span&gt;&lt;span style="text-align: justify;"&gt;Going through the report we understand the committee is unable to prescribe a standard for other ministries and departments until they try and pilot these standards within Ministry of Statistics and Programme Implementation. This delay in prescribing the standards can be really dangerous in the current circumstances of massive data collection by government departments and linking all the databases with a unique identifier, Aadhaar Number. &amp;nbsp;&lt;/span&gt;&lt;span style="text-align: justify;"&gt;At the same time we understand the importance of data dissemination to be carried out and we recommend the following for improving the standards around data disclosure control.&lt;/span&gt;&lt;/p&gt;
&lt;h4 style="text-align: justify;" dir="ltr"&gt;3.2 Integrity of Information and Data&lt;/h4&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;We agree with the committee that the error rates need to be kept in mind while designing practices to convert raw data. But we request the process of changes being made be actively measured and documented. In case of errors being computed, guidelines can be made to decrease the possibilities of misinterpretation of errors causing loss of integrity of information. Statistics are important for decision making in governance, errors in computations can be biased towards millions of people. Statistical biases are important to be looked into while converting data from its raw format to make sure there are no damage caused by information.&lt;/p&gt;
&lt;h4 style="text-align: justify;" dir="ltr"&gt;3.3 Data Security&lt;/h4&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;One of the important issues around storage and publication of Aadhaar information is the lack of masking standards. With the availability of data from multiple departments, it is possible to reconstruct identification details by linking data from multiple databases. It is recommended to bring masking standards while personally identifiable micro data is being published. There is an urgent need for departments to also look at auditing access to information and tracking sharing of information. It is recommended the department digitally signs all the information and documents being published or shared by them to keep track of who had accessed the information and verifying the authenticity of information.&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;We request the department to define what exactly is “usage for statistical purposes only” and recommend standards to control and restrict usage of information for this purpose. It is important they design frameworks or mechanisms to allow others to report violations around this. This process should be transparent and documented heavily.&lt;/p&gt;
&lt;h4 style="text-align: justify;" dir="ltr"&gt;3.4 Anonymization of microdata&lt;/h4&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;We recommend the data being collected be anonymized at source to evade the possibility of the accidental disclosure of personally identifiable information. While the current anonymization efforts have been helpful, with steady increase in data mining and classification algorithms and practices it is recommended to evolve the standards around this area.&lt;/p&gt;
&lt;h4 style="text-align: justify;" dir="ltr"&gt;3.5 Data Dissemination&lt;/h4&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;Data dissemination is an important aspect for district statistics officers, we recommend they actively communicate their work through monthly newsletters, quarterly workshops to help improve the conversations around statistics and at the same time engage with the users who would benefit from the data.&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;We also recommend that data when being published includes metadata of collection, modification, storage and other important information. Also the information needs to be published in open formats which does not require proprietary software to be used to open them. At the same time data should be published in multiple formats like CSV, XLS, PDF,&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;The committee also recognizes the need for having data users part of discussions around important decisions and be part of committees. We would like the department to recognize our efforts and consider us for future committee representations.&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;Thank you for this opportunity and we look forward to work with you in future.&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/comments-on-the-statistical-disclosure-control-report'&gt;https://cis-india.org/internet-governance/comments-on-the-statistical-disclosure-control-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Srinivs Kodali and Amber Sinha</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Call for Comments</dc:subject>
    
    
        <dc:subject>Digital Access</dc:subject>
    
    
        <dc:subject>Open Data</dc:subject>
    
    
        <dc:subject>Open Government Data</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Digitisation</dc:subject>
    
    
        <dc:subject>Information Security</dc:subject>
    
    
        <dc:subject>Openness</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Management</dc:subject>
    

   <dc:date>2019-03-13T00:28:44Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1">
    <title>(Updated) Information Security Practices of Aadhaar (or lack thereof): A documentation of public availability of Aadhaar Numbers with sensitive personal financial information</title>
    <link>https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1</link>
    <description>
        &lt;b&gt;Since its inception in 2009, the Aadhaar project has been shrouded in controversy due to various questions raised about privacy, technological issues, welfare exclusion, and security concerns. In this study, we document numerous instances of publicly available Aadhaar Numbers along with other personally identifiable information (PII) of individuals on government websites. This report highlights four government projects run by various government departments that have made sensitive personal financial information and Aadhaar numbers public on the project websites.
&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;Read the updated report: &lt;a class="external-link" href="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof/" target="_blank"&gt;Download&lt;/a&gt; (pdf)&lt;/h4&gt;
&lt;h4&gt;Read the first statement of clarification (May 16, 2017): &lt;a class="external-link" href="https://cis-india.org/internet-governance/clarification-on-information-security-practices-of-the-aadhaar-report/" target="_blank"&gt;Download&lt;/a&gt; (pdf)&lt;/h4&gt;
&lt;h4&gt;Read the second statement of clarification (November 05, 2018): &lt;a class="external-link" href="https://cis-india.org/internet-governance/blog/clarification-on-the-information-security-practices-of-aadhaar-report" target="_blank"&gt;Link to page&lt;/a&gt; (html)&lt;/h4&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;We are grateful to Yesha Paul and VG Shreeram for research support.&lt;/em&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;In the last month, there have been various reports pointing out instances of the public disclosure of Aadhaar number through various databases, accessible easily on Twitter under the hashtag #AadhaarLeaks. Most of these public disclosures reported contain personally identifiable information of beneficiaries or subjects of the non UIDAI databases containing Aadhaar numbers of individuals along with other personal identifiers. All of these public disclosures are symptomatic of a significant and potentially irreversible privacy harm, however we wanted to point out another large fallout of such events, those that create a ripe opportunity for financial fraud. For this purpose, we identified benefits disbursement schemes which would require its databases to store financial information about its subjects. During our research, we encountered numerous instances of publicly available Aadhaar Numbers along with other PII of individuals on government websites. In this paper, we highlight four government projects run by various government departments with publicly available financial data and Aadhaar numbers. Our research is focussed largely on the data published by or pertaining to where Aadhaar data is linked with banking information. We chose major government programmes using Aadhaar for payments and banking transactions. We found sensitive and personal data and information very easily accessible on these portals.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1'&gt;https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Amber Sinha and Srinivas Kodali</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Digital ID</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>NDSAP</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Accountability</dc:subject>
    
    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Digitisation</dc:subject>
    
    
        <dc:subject>Homepage</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Management</dc:subject>
    

   <dc:date>2019-03-13T00:29:01Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/national-herald-sebastian-pt-april-26-2017-now-aadhaar-details-displayed-in-mizoram-too">
    <title>Now, Aadhaar details displayed in Mizoram too</title>
    <link>https://cis-india.org/internet-governance/news/national-herald-sebastian-pt-april-26-2017-now-aadhaar-details-displayed-in-mizoram-too</link>
    <description>
        &lt;b&gt;Contrary to the Centre’s assurances, government websites are revealing digital details of the poor, leaving them vulnerable to financial frauds and identity theft.&lt;/b&gt;
        &lt;p&gt;The article by Sebastian PT was &lt;a class="external-link" href="https://www.nationalheraldindia.com/news/2017/04/26/aadhaar-details-displayed-in-mizoram-jharkhand-chandigarh-financial-fraud-violating-supreme-court-order"&gt;published in the National Herald&lt;/a&gt; on April 26, 2017. Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Could there be a method to the madness? Or is it just carelessness? From the Jharkhand Government to the Union Territory of Chandigarh to the Union Ministry of Water and Sanitation to even Mizoram’s Food and Civil Supplies Department, government websites are found to have displayed Aadhaar details of citizens, a crime under the law.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In Jharkhand, details of 16 lakh beneficiaries – their bank account details, ration card and the 12-digit Aadhaar number – were displayed on the website of the Directorate of Social Security. Similar blunders were witnessed from different corners of the country from Chandigarh to Kerala, where details of 35 lakh people have been breached. This flies in the face of the Government’s repeated claims on data privacy, that Aadhaar details are completely safe.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The law doesn’t allow this. The displaying of the Aadhaar data, for instance, is in clear violation of Section 29 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. The provision clearly says that “no” Aadhaar number or core biometric information of an Aadhaar number holder shall be “published, displayed or posted publicly”.&lt;br /&gt;&lt;br /&gt;“There appears to be no regulation worth the name as far as the Aadhaar project is concerned,” says economist Reetika Khera from IIT Delhi.&lt;br /&gt;&lt;br /&gt;So, will these officials responsible be punished according to the Act? More importantly, what about the damage of leaking such sensitive, apparently confidential data?&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Irreparable Damage&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Several cyber security experts have been warning of the possibility of precisely such leaks and Opposition parties were vociferously pointing this out while the Centre was brazenly violating the Supreme Court’s orders and forcibly extending Aadhaar to almost everything – including it being linked to one’s Permanent Account Number (PAN), used for filing income tax.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“What has been broken through technology, can’t be fixed with the law,” says Sunil Abraham, Executive Director of Bangalore-based research organisation, the Centre for Internet and Society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The data breach just made it easy for players in the black market for ID (identification) documents to be lapped up to create false ID cards, for instance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When demonetisation was being implemented, sources say that black money hoarders apparently bought fake IDs which were made from stolen Aadhaar details to get the old notes exchanged – one way for doing this was perhaps by opening new bank accounts or to, say, utilise unused Jan Dhan accounts to deposit the money. Now, one can only imagine what terrorists can do with these details.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So far, perhaps, the only solace is that the biometric details of the beneficiaries weren’t leaked. But, in the backdrop of the lax attitude of the various government departments, even that too is just waiting to happen, fear experts.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Abraham warns that Aadhaar was always a risky proposition as it was based on biometrics, which “made it very insecure”. He terms it as a “mass surveillance technology” – that too a poorly-designed technology – which, in fact, “undermines security”. Once biometric data are compromised, it cannot be secured again. Instead of biometrics, he suggests the UIDAI shift to using smart cards.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The unfettered forcible linking of almost everything – from bank accounts to one’s PAN card – to Aadhaar only makes things worse. “The Centre is ‘seeding’ the various data bases with the Aadhaar number, which is a very bad move. And, involving various private and public agencies in this only makes the entire thing very precarious,” warns Abraham. He points out that, for instance, when the PAN cards are linked with the Aadhaar number, breach made possible.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Instead, he says, the government should adopt the ‘tokenisation approach’, instead of the ‘seeding approach’. What this means is that, say, if the PAN card is to be linked to Aadhaar, then UIDAI issues a token number and not the original 12-digit Aadhaar number. So, even if a breach happens, the hacker will not be able to get all the Aadhaar details, he says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, the government does not seem to be taking the issue of privacy very seriously. What perhaps is not being understood is that this is not just a privacy issue, but making the masses vulnerable to frauds. Instead of treading cautiously in implementing Aadhaar, the government seems to be in a hurry to extend it to almost every possible silo in an individual’s life.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Given the callous attitude of central and state governments, I hope that the Supreme Court will stop the government from a forced linking of Aadhaar, on the one hand, and bank accounts and PAN numbers on the other hand,” says Khera.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/national-herald-sebastian-pt-april-26-2017-now-aadhaar-details-displayed-in-mizoram-too'&gt;https://cis-india.org/internet-governance/news/national-herald-sebastian-pt-april-26-2017-now-aadhaar-details-displayed-in-mizoram-too&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-27T16:59:37Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-april-21-2017-komal-gupta-apurva-vishwanath-suranjana-roy-aadhaar-a-widening-net">
    <title>Aadhaar: A widening net</title>
    <link>https://cis-india.org/internet-governance/news/livemint-april-21-2017-komal-gupta-apurva-vishwanath-suranjana-roy-aadhaar-a-widening-net</link>
    <description>
        &lt;b&gt;As India makes Aadhaar compulsory for a range of services, concerns about potential data breaches remain more than six years after the govt started building the world’s largest biometric identification system.&lt;/b&gt;
        &lt;p&gt;The article by Komal Gupta, Apurva Vishwanath and Suranjana Roy was &lt;a class="external-link" href="http://www.livemint.com/Politics/eTxrtAxzFq738LzFdx7yXK/Aadhaar-A-widening-net.html"&gt;published in Livemint&lt;/a&gt; on April 21, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: center; "&gt;&lt;img alt="The Aadhaar project, under which a 12-digit identification number is to be allotted to every Indian resident, was originally supposed to be a way of plugging leakages in the delivery of state benefits such as subsidized grains to the poor. Photo: Priyanka Parashar/Mint" class="img-responsive" height="378" src="http://www.livemint.com/rf/Image-621x414/LiveMint/Period2/2017/04/21/Photos/Processed/asia-cover.JPG" title="The Aadhaar project, under which a 12-digit identification number is to be allotted to every Indian resident, was originally supposed to be a way of plugging leakages in the delivery of state benefits such as subsidized grains to the poor. Photo: Priyanka Parashar/Mint" width="582" /&gt;&lt;/p&gt;
&lt;p&gt;On 29 March, a storm broke out on social media after private data  that former Indian cricket captain M.S. Dhoni had furnished to get  enrolled in India’s unique identity system, known as Aadhaar, were  leaked online.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The popular cricketer’s wife, Sakshi, flagged the matter on Twitter,  tagging information technology (IT) minister Ravi Shankar Prasad. “Is  there any privacy left? Information of Aadhaar card, including  application, is made public property,” Sakshi fumed on the microblogging  site.&lt;/p&gt;
&lt;p&gt;The minister replied: “Sharing personal information is illegal. Serious action will be taken against this.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It turned out to be the fault of an overenthusiastic common services  centre in Dhoni’s home town of Ranchi licensed to enrol people in  Aadhaar. The centre was promptly blacklisted. “We have ordered further  inquiry on the matter and action will be taken against all those  involved in the leak,” said Ajay Bhushan Pandey, chief executive officer  of the Unique Identification Authority of India (UIDAI), which  administers Aadhaar.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The matter blew over soon enough, but it served to illustrate the lingering concerns about potential data breaches and privacy violations surrounding Aadhaar, which has become the world’s largest biometric identification database with 1.13 billion people enrolled in it in the past six years.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The project, under which a 12-digit identification number is to be allotted to every Indian resident, was originally supposed to be a way of plugging leakages in the delivery of state benefits such as subsidized grains to the poor.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It has now become mandatory for everything ranging from opening a bank account and getting a driver’s licence or a mobile phone connection to filing of income tax returns. Even government school students entitled to a free mid-day meal need an Aadhaar number.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img src="https://cis-india.org/home-images/AadhaarMint.jpg" alt="Aadhaar " class="image-inline" title="Aadhaar " /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The use of Aadhaar has only expanded with the government going on an overdrive to promote cashless transactions and payment systems linked to the biometric ID system after banning old, high-value bank notes in November in a crackdown on unaccounted wealth hidden away from the taxman.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For instance, the Aadhaar-Enabled Payment System (AEPS) empowers a bank customer to use Aadhaar as her identity to access her Aadhaar-enabled bank account and perform basic banking transactions like cash deposit or withdrawal through a bank agent or business correspondent.&lt;br /&gt;&lt;br /&gt;The customer can carry out transactions by scanning her fingerprint at any micro ATM or biometric point-of-sale (POS) terminal, and entering the Aadhaar number linked to the bank account. A merchant-led model of AEPS, called Aadhaar Pay, has also been launched.&lt;br /&gt;&lt;br /&gt;Last week, Prime Minister Narendra Modi launched the BHIM-Aadhaar platform—a merchant interface linking the unique identification number to the Bharat Interface for Money (BHIM) mobile application. This will enable merchants to receive payments through fingerprint scans of customers.&lt;br /&gt;&lt;br /&gt;“Any citizen without access to smartphones, Internet, debit or credit cards will be able to transact digitally through the BHIM-Aadhaar platform,” a government statement said.&lt;br /&gt;&lt;br /&gt;Aadhaar’s growing importance in the economy has only served to deepen concerns about potential data breaches. And there are other concerns as well.&lt;br /&gt;&lt;br /&gt;For instance, the Aadhaar biometric authentication failure rate in the rural job guarantee scheme, which assures 100 days of work a year to one member of every rural household, is as high as 36% in the southern state of Telangana, according to data released by the state government.&lt;br /&gt;&lt;br /&gt;“Aadhaar is supposed to be an enabler and it will happen only when it is made voluntary. Biometric authentications might fail due to poor data connectivity and transactions might not happen even though the Aadhaar number of the person is there; so, what’s the benefit,” asked Pranesh Prakash, policy director of the Centre for Internet and Society, a Bengaluru-based think tank.&lt;br /&gt;&lt;br /&gt;Aadhaar was the brainchild of the previous United Progressive Alliance (UPA) government, which lost power in the 2014 general election to the National Democratic Alliance (NDA). The first 10 Aadhaar numbers were handed over to residents of a small village called Tembhli in Maharashtra on 29 September 2010 in the presence of then prime minister Manmohan Singh, Congress party president Sonia Gandhi and Aadhaar’s chief architect Nandan Nilekani, a co-founder of software services giant Infosys Ltd.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;After coming to power, the NDA systematically went about making Aadhaar the pivot of government welfare programmes. In March last year, Parliament passed the Aadhaar Bill to make the use of Aadhaar mandatory for availing of government subsidies despite resistance from opposition parties.&lt;br /&gt;&lt;br /&gt;Last month, finance minister Arun Jaitley said the 12-digit number would eventually become a single, monolithic proof of identity for every Indian, replacing every other identity card.&lt;br /&gt;&lt;br /&gt;To be sure, Aadhaar has helped the government better target beneficiaries of its welfare programmes, cutting out middlemen and corruption. For instance, the government claims to have saved about Rs50,000 crore in cooking gas subsidies by linking the Aadhaar number with bank accounts in which the subsidy is directly transferred.&lt;br /&gt;&lt;br /&gt;Yet, Aadhaar has its critics, who have challenged the project on grounds including potential compromise of national security, violation of the right to privacy and exclusion of people from welfare programmes. The Supreme Court has cautioned the government that no citizen can be denied access to welfare programmes for lack of an Aadhaar number.&lt;br /&gt;&lt;br /&gt;Before cricketer Dhoni’s data breach made the headlines, in February, UIDAI filed a complaint against Axis Bank Ltd, business correspondent Suvidhaa Infoserve and e-sign provider eMudhra, alleging they had attempted unauthorized authentication and impersonation by illegally storing Aadhaar biometrics. The breach was noticed after one individual performed 397 biometric transactions between 14 July 2016 and 19 February 2017. All three entities have been temporarily barred from offering Aadhaar-related services until UIDAI makes a final decision.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash of the Centre for Internet and Society said rules on the use of Aadhaar data are inadequate.&lt;br /&gt;&lt;br /&gt;“UIDAI is allowed to share the information of a person from its database on its website, after taking proper consent of that person. However, there is no law which states what should be done if any other party does that with the same individual. Such rules must be in place,” Prakash said.&lt;br /&gt;&lt;br /&gt;Four years after the Aadhaar project took off, a retired judge took the government to court. K. Puttaswamy, a former judge of the Karnataka high court, moved the Supreme Court in 2013, arguing that Aadhaar violated his fundamental right to privacy under the constitution. The case opened the gates for legal challenges to Aadhaar. Over the next few years till date, at least a dozen cases had questioned the legality of the project.&lt;br /&gt;&lt;br /&gt;Ramon Magsaysay award winner Aruna Roy brought a case on behalf of manual workers whose faint finger prints, she said, often go undetected. Currently, only 44 million out of the 101 million beneficiaries of India’s rural job entitlement are paid through Aadhaar.&lt;br /&gt;&lt;br /&gt;To be sure, India’s Constitution does not contain a black and white reference to a “fundamental right to privacy”, that the government cannot violate. The list of rights says “no person shall be deprived of his life or personal liberty except according to a procedure established by law”—often interpreted by courts as an all-encompassing right including right to live with dignity, right to speedy justice and even a right to clean air.&lt;br /&gt;&lt;br /&gt;Nilekani, the man behind Aadhaar, has cautioned that privacy is a broader issue involving how people retain their privacy in day-to-day life. “Privacy is an all-encompassing issue because of the rapid rate of digitization the world is seeing. Your smartphone has sensors, GPS and is generating more and more information about everything; voice-activated devices could also be recording your conversations. There’s a profusion of CCTV cameras at malls, restaurants, ATMs recording your movements,” Nilekani said in a recent interview with The Economic Times.&lt;br /&gt;&lt;br /&gt;But this is where a problem arises. Although there is concurrence on the need for a privacy law, there is a great reluctance on the part of the government to come out with one.&lt;br /&gt;&lt;br /&gt;“We don’t have a comprehensive privacy law; all our databases are unlinked. The government is trying to link the databases using Aadhaar for all schemes but a separate privacy law must be there for protecting any piece of information, whether or not linked to Aadhaar,” said Rahul Matthan, a partner at law firm Trilegal and a Mint columnist.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Matthan said first a privacy law must be put in place and then there has to be a discussion on what all it must include.&lt;br /&gt;&lt;br /&gt;The government on its part pointed out that India’s apex court itself has been indecisive on a right to privacy.&lt;br /&gt;&lt;br /&gt;“The larger question on privacy needs to be settled by the court. Till then, one cannot comment on secondary concerns,” attorney general Mukul Rohatgi said in an interview.&lt;br /&gt;&lt;br /&gt;In 2015, the Supreme Court decided that a bench of at least seven judges will rule on the privacy issue, while clarifying that the government cannot make Aadhaar a mandatory proof of identity for its welfare schemes. Twenty months after the judicial order, the larger bench is yet to be formed by the apex court. The passing of the Aadhaar Act in Parliament to provide statutory backing to Aadhaar also indicates a departure from the Indian government’s position of not taking a legislative stand while an issue is under the apex court’s consideration.&lt;br /&gt;&lt;br /&gt;For example, one of the reasons the Indian government has shown restraint in repealing a colonial law that criminalizes homosexuality is because the apex court is seized of the issue.&lt;br /&gt;&lt;br /&gt;In the absence of legislation and pending an authoritative ruling by the top court, whether 1.3 billion Indians are entitled to their privacy remains a grey area. Meanwhile, the government is seemingly in the final stretch of its Aadhaar enrolment drive.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-april-21-2017-komal-gupta-apurva-vishwanath-suranjana-roy-aadhaar-a-widening-net'&gt;https://cis-india.org/internet-governance/news/livemint-april-21-2017-komal-gupta-apurva-vishwanath-suranjana-roy-aadhaar-a-widening-net&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Biometrics</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-22T05:06:23Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17">
    <title>11th Meeting of Information Systems Security Sectional Committee (LITD 17)</title>
    <link>https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17</link>
    <description>
        &lt;b&gt;Udbhav Tiwari represented CIS at this meeting organized by the Bureau of Indian Standards (BIS) at Manak Bhavan, New Delhi on April 13, 2017.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The meeting was the national mirror meeting for the 28th ISO/IEC JTC 1/SC 27 Plenary and Working Group Meetings being held at Hamilton, New Zealand between the April 18 and 25, 2017. The meeting provided a fascinating insight into the government and industry viewpoints on key cyber security and privacy issues, especially on the Aadhaar.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17'&gt;https://cis-india.org/internet-governance/news/11th-meeting-of-information-systems-security-sectional-committee-litd-17&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-19T02:57:03Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-april-12-2017-komal-gupta-opposition-questions-govt-move-to-make-aadhaar-must">
    <title>Opposition questions govt move to make Aadhaar must</title>
    <link>https://cis-india.org/internet-governance/news/livemint-april-12-2017-komal-gupta-opposition-questions-govt-move-to-make-aadhaar-must</link>
    <description>
        &lt;b&gt;Congress leader Jairam Ramesh claimed that the Aadhaar system was becoming an instrument of social exclusion rather than one of identity. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Komal Gupta was &lt;a class="external-link" href="http://www.livemint.com/Politics/nwqpFParHM0Ym8F4Dwt3yL/Rajya-Sabha-debates-Aadhaar-Opposition-points-to-flaws.html"&gt;published in Livemint&lt;/a&gt; on April 11, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The Rajya Sabha on Monday witnessed a lively debate on Aadhaar, with the opposition questioning the government’s move to make the 12-digit unique identification number mandatory for a host of welfare benefits.&lt;br /&gt;&lt;br /&gt;Congress leader Jairam Ramesh claimed that the Aadhaar system was becoming an instrument of social exclusion rather than one of identity.&lt;br /&gt;&lt;br /&gt;“My major concern is implementation, how Aadhaar is being used to exclude people to avail benefits of the schemes which have been designed for them…If you need to apply to avail benefits, it’s as good as mandatory,” said Ramesh.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The former cabinet minister argued that over 25% of the population will stand excluded.&lt;br /&gt;&lt;br /&gt;“The Rs50,000 crore savings due to Aadhaar linkage as given by the government is highly questionable,” he said, adding that according to Comptroller and Auditor General (CAG) reports, 92% of the savings on domestic gas subsidies is not on account of Aadhaar implementation or direct benefit transfer. “Instead, it is because of the fall in international oil prices,” Ramesh argued.&lt;br /&gt;&lt;br /&gt;Trinamool Congress member Derek O’Brien said that for manual labourers, biometric identification does not always match and that can deprive them of welfare.&lt;br /&gt;&lt;br /&gt;He gave the example of Andhra Pradesh, where almost half the 85,000 ration card holders in 2014 were unable to get subsidized foodgrains due to faulty point of sale machines and biometrics not matching.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;K.T.S Tulsi, member of Parliament and senior Supreme Court advocate, said, “Not in my whole career have I come across a greater mutilation of a statutory provision than what has taken place in the case of Aadhaar.” He said Section 29 of the Aadhaar Act doesn’t permit data stored with the Unique Identification Authority of India (UIDAI) to be shared with anyone but a provision was later made for voluntary agreement to allow the sharing of data.&lt;br /&gt;&lt;br /&gt;IT and law minister Ravi Shankar Prasad said, “No religion, income, medical history, ethnicity or education is asked in Aadhaar. Even email ID and phone number is optional.”&lt;br /&gt;&lt;br /&gt;“The right of privacy of individuals must be respected. The privacy of the data cannot be breached by us except in the case of national security,” Prasad added.&lt;br /&gt;&lt;br /&gt;He claimed that the government has been blacklisting operators that share data from the Aadhaar system. It has blacklisted 34,000 operators, and has taken action against 1,000 of them.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Prasad also said that UIDAI will be accountable to the Parliament.&lt;br /&gt;&lt;br /&gt;Expressing concern on mandating the use of Aadhaar for different services, Pranesh Prakash, Policy director of the Centre for Internet and Society, said, “As an enabler, people would want to have Aadhaar. But when it is made mandatory, it becomes more of a disenabler instead of an enabler.”&lt;br /&gt;&lt;br /&gt;“With the move towards a digital economy, setting up of a data protection authority as recommended by the Shah committee is important along with mass surveillance and greater accountability from the government,” he added.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-april-12-2017-komal-gupta-opposition-questions-govt-move-to-make-aadhaar-must'&gt;https://cis-india.org/internet-governance/news/livemint-april-12-2017-komal-gupta-opposition-questions-govt-move-to-make-aadhaar-must&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-12T14:19:20Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/asian-age-amber-sinha-april-10-2017-privacy-in-the-age-of-big-data">
    <title>Privacy in the Age of Big Data</title>
    <link>https://cis-india.org/internet-governance/blog/asian-age-amber-sinha-april-10-2017-privacy-in-the-age-of-big-data</link>
    <description>
        &lt;b&gt;Personal data is freely accessible, shared and even sold, and those to whom this information belongs have little control over its flow.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published in the &lt;a class="external-link" href="http://www.asianage.com/india/all-india/100417/privacy-in-the-age-of-big-data.html"&gt;Asian Age&lt;/a&gt; on April 10, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;In 2011 it was estimated that the quantity of data produced globally surpassed 1.8 zettabyte. By 2013, it had increased to 4 zettabytes. This is a result of digital services which involve constant data trails left behind by human activity. This expansion in the volume, velocity, and variety of data available, together with the development of innovative forms of statistical analytics on the data collected, is generally referred to as “Big Data”. Despite significant (though largely unrealised) promises about Big Data, which range from improved decision-making, increased efficiency and productivity to greater personalisation of services, concerns remain about the impact of such datafication of all human activity on an individual’s privacy. Privacy has evolved into a sweeping concept, including within its scope matters pertaining to control over one’s body, physical space in one’s home, protection from surveillance, and from search and seizure, protection of one’s reputation as well as one’s thoughts. This generalised and vague conception of privacy not only comes with great judicial discretion, it also thwarts a fair understanding of the subject. Robert Post called privacy a concept so complex and “entangled in competing and contradictory dimensions, so engorged with various and distinct meanings”, that he sometimes “despairs whether it can be usefully addressed at all”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This also leaves the idea of privacy vulnerable to considerable suspicion and ridicule. However, while there is a lack of clarity over the exact contours of what constitutes privacy, there is general agreement over its fundamental importance to our ability to lead whole lives. In order to understand the impact of datafied societies on privacy, it is important to first delve into the manner in which we exercise our privacy. The ideas of privacy and data management that are prevalent can be traced to the Fair Information Practice Principles (FIPP). These principles are the forerunners of most privacy regimes internationally, such as the OECD Privacy Guidelines, APEC Framework, or the nine National Privacy Principles articulated by the Justice A.P. Shah Committee Report. All of these frameworks have rights to notice, consent and correction, and how the data may be used, as their fundamental principles. It makes the data subject to the decision-making agent about where and when her/his personal data may be used, by whom, and in what way. The individual needs to be notified and his consent obtained before his personal data is used. If the scope of usage extends beyond what he has agreed to, his consent will be required for the increased scope.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In theory, this system sounds fair. Privacy is a value tied to the personal liberty and dignity of an individual. It is only appropriate that the individual should be the one holding the reins and taking the large decisions about the use of his personal data. This makes the individual empowered and allows him to weigh his own interests in exercising his consent. The allure of this paradigm is that in one elegant stroke, it seeks to ensure that consent is informed and free and also to implement an acceptable trade-off between privacy and competing concerns. This approach worked well when the number of data collectors were less and the uses of data was narrower and more defined. Today’s infinitely complex and labyrinthine data ecosystem is beyond the comprehension of most ordinary users. Despite a growing willingness to share information online, most people have no understanding of what happens to their data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The quantity of data being generated is expanding at an exponential rate. From smartphones and televisions, trains and airplanes, sensor-equipped buildings and even the infrastructures of our cities, data now streams constantly from almost every sector and function of daily life, “creating countless new digital puddles, lakes, tributaries and oceans of information”. The inadequacy of the regulatory approaches and the absence of a comprehensive data protection regulation is exacerbated by the emergence of data-driven business models in the private sector and the adoption of data-driven governance approach by the government. The Aadhaar project, with over a billion registrants, is intended to act as a platform for a number of digital services, all of which produce enormous troves of data. The original press release by the Central Government reporting the approval by the Cabinet of Ministers of the Digital India programme, speaks of “cradle to grave” digital identity as one of its vision areas.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While the very idea of the government wanting to track its citizens’ lives from cradle to grave is creepy enough in itself, let us examine for a minute what this form of datafied surveillance will entail. A host of schemes under Digital India shall collect and store information through the life cycle of an individual. The result, as we can see, is building databases on individuals, which when combined, will provide a 360 degree view into the lives of individuals. Alongside the emergence of India Stack, a set of APIs built on top of the Aadhaar, conceptualised by iSPIRT, a consortium of select IT companies from India, to be deployed and managed by several agencies, including the National Payments Corporation of India, promises to provide a platform over which different private players can build their applications.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The sum of these interconnected parts will lead to a complete loss of anonymity, greater surveillance and impact free speech and individual choice. The move towards a cashless economy — with sharp nudges from the government — could lead to lack of financial agencies in case of technological failures as has been the case in experiments with digital payments in Africa. Lack of regulation in emerging data driven sectors such as Fintech can enable predatory practices where right to remotely deny financial services can be granted to private sector companies. An architecture such as IndiaStack enables datafication of financial transactions in a way that enables linked and structured data that allows continued use of the transaction data collected. It is important to recognise that at the stage of giving consent, there are too many unknowns for us to make informed decisions about the future uses of our personal data. Despite blanket approvals allowing any kind of use granted contractually through terms of use and privacy policies, there should be legal obligations overriding this consent for certain kinds of uses that may require renewed consent.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Biometrics-based identification in UK: &lt;/b&gt;In  2005, researchers from London School of Economics and Political Science  came out with a detailed report on the UK Identity Cards Bill (‘UK  Bill’) — the proposed legislation for a national identification system  based on biometrics. The project also envisaged a centralised database  (like India) that would store personal information along with the entire  transaction history of every individual. The report pointed strongly  against the centralising storage of information and suggested other  alternatives such as a system based on smartcards (where biometrics are  stored on the card itself) or offline biometric-reader terminals.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As per the report, the alternatives would also have been cheaper as neither required real-time online connectivity. In India, online authentication is a far greater challenge. According to Network Readiness Index, 2016, India ranks 91, whereas UK is placed eight. Poor Internet connectivity can raise a lot of problems in the future including paralysis of transactions. The UK identification project was subsequently discarded as a result of the privacy and cost considerations raised in this report.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Aadhaar: Privacy concerns&lt;/h3&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;li&gt;Once the data is collected through National Information Utilities, it will be privatised and controlled by private utilities.&lt;/li&gt;
&lt;li&gt;Once an individual’s data is entered in the system, it cannot be deleted. That individual will have no control over it.&lt;/li&gt;
&lt;li&gt;Aadhaar Data (Demographic details along with photographs) are shared/transferred with the private entities including telecom companies as per the Aadhaar (Targeted delivery of Financial and other subsidies, benefits and services) Act, 2016 with the consent of Aadhaar number holder to fulfil their e-KYC requirements. The data is shared in encrypted form through secured channel.&lt;/li&gt;
&lt;li&gt;Aadhaar Enabled Payment System (AEPS) on which 119 banks are live.&lt;/li&gt;
&lt;li&gt;More than 33.87 crore transactions have taken place through AEPS, which was only 46 lakhs in May 2014.&lt;/li&gt;
&lt;li&gt;As on 30-9-2016, 78 government schemes were linked to Aadhaar.&lt;/li&gt;
&lt;li&gt;The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, provides that no core-biometric information (fingerprints, iris scan) shall be shared with anyone for any reason whatsoever (Sec 29) and that the biometric information shall not be used for any purpose other than generation of Aadhaar and authentication.&lt;/li&gt;
&lt;li&gt;Access to the data repository of UIDAI, called the Central Identities Data Repository(CIDR), is provided to third parties or private companies.&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Central Monitoring System&lt;/b&gt; (CMS) is already live in  Delhi, New Delhi and Mumbai. Union minister Ravi Shankar Prasad revealed  this in one of his replies in the Lok Sabha last year. CMS has been set  up to automate the process of Lawful Interception &amp;amp; Monitoring of  telecommunications.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Central Monitoring System&lt;/b&gt; (CMS) is already live in  Delhi, New Delhi and Mumbai. Union minister Ravi Shankar Prasad revealed  this in one of his replies in the Lok Sabha last year. CMS has been set  up to automate the process of Lawful Interception &amp;amp; Monitoring of  telecommunications.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Lawful Intercept &lt;/b&gt;and Monitoring (LIM) systems are used  by the Indian Government to intercept records of voice, SMSes, GPRS  data, details of a subscriber’s application and recharge history and  call detail record (CDR) and monitor Internet traffic, emails,  web-browsing, Skype and any other Internet activity of Indian users.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/asian-age-amber-sinha-april-10-2017-privacy-in-the-age-of-big-data'&gt;https://cis-india.org/internet-governance/blog/asian-age-amber-sinha-april-10-2017-privacy-in-the-age-of-big-data&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Big Data</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-11T14:43:59Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>




</rdf:RDF>
