<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 61 to 75.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-july-10-2017-reliance-jio-data-leaked-on-website-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/biometric-update-july-4-2017-justin-lee-uidai-declining-multiple-requests-by-police-to-share-indian-citizens-biometrics"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/indian-express-kiran-jonnalgadda-june-10-2017-why-did-nandan-nilekani-praise-a-twitter-troll"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-hindu-yuthika-bhargava-june-9-2017-new-law-to-unlock-data-economy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/indian-express-june-1-2017-pranav-mukul-privacy-is-culture-specific-mncs-hit-by-aadhaar-says-trai-chief"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-june-2-2017-komal-gupta-new-rules-for-govt-agencies-to-ensure-security-of-personal-data"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/electronic-frontier-foundation-jyoti-panday-june-1-2017-aadhaar-ushering-in-a-commercialized-era-of-surveillance-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/economic-times-june-2-2017-nidhi-sharma-centre-brings-in-new-safeguards-following-cases-of-aadhaar-data-leaks-on-government-websites"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/global-voices-rohith-jyothish-may-31-2017-online-troll-attack-critics-of-indias-aadhaar-state-id-system"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/economic-times-may-29-2017-bharat-joshi-bbmp-faces-ire-for-publishing-pourakarmikas-aadhaar-details-on-website"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/raw/indian-express-nishant-shah-may-28-2017-digital-native-look-before-you-digitally-leap"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/inc42-may-23-2017-shweta-modgil-sharad-sharma-aplogises-for-trolling-aadhaar-critics"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-times-of-india-may-24-2017-shalina-pillai-anand-j-ispirts-sharad-sharma-sorry-i-trolled-aadhaar-critics"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-indiasaga-may-25-2017-aadhaar-card-one-identity-multiple-disorders"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/scroll-may-20-2017-anumeha-yadav-will-aadhaar-leaks-be-used-as-an-excuse-to-shut-out-scrutiny-of-welfare-schemes"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-july-10-2017-reliance-jio-data-leaked-on-website-report">
    <title>Reliance Jio data leaked on website : report</title>
    <link>https://cis-india.org/internet-governance/news/livemint-july-10-2017-reliance-jio-data-leaked-on-website-report</link>
    <description>
        &lt;b&gt;Reliance Jio customer data was leaked on independent website magicapk.com, including details such as names, mobile numbers and email IDs , said a report.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was &lt;a class="external-link" href="http://www.livemint.com/Industry/ucK2SJDM4Ws8k36ovZVj6H/Reliance-Jio-customer-data-allegedly-compromised-report.html"&gt;published by Livemint&lt;/a&gt; on July 10, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Reliance Jio Infocomm Ltd’s customer data was allegedly leaked on an  independent website, magicapk.com, a report said. Jio, which crossed the  100 million mark in February, barely six months after it was launched,  ended the financial year with &lt;b&gt;&lt;a href="http://www.livemint.com/Industry/wVDwB0wKqaXxqVFqEWp4kK/Reliance-Jio-crosses-108-million-subscribers-claims-to-be-l.html" target="_blank"&gt;108.9 million subscribers &lt;/a&gt;&lt;/b&gt;as of 31 March.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The report, published first in a late-night article on Sunday on &lt;b&gt;&lt;a href="http://www.fonearena.com/blog/224741/jio-customer-database-of-over-120-million-users-leaked-could-be-biggest-data-breach-in-india.html#more-224741" target="_blank"&gt;Fonearena.com&lt;/a&gt;&lt;/b&gt;,  alleged that “several sensitive details” were exposed, including  customers’ first and last names, mobile numbers, email IDs, circles, SIM  activation dates and even the Aadhaar numbers. The Aadhaar numbers,  however, were redacted on magicapk.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“To my disbelief I found my own details in the database and also couple  of my colleagues are affected too,” wrote Varun Krish, the author of the  article. However, if you now click on Magicapk.com, it reads: “This  Account has been &lt;a href="http://magicapk.com/cgi-sys/suspendedpage.cgi" target="_blank"&gt;suspended&lt;/a&gt; .” The Registrar of the site, according to the &lt;b&gt;&lt;a href="https://www.whois.com/whois/magicapk.com"&gt;whois database&lt;/a&gt;&lt;/b&gt;, is Godaddy.com, LLC.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When contacted, a Reliance Jio spokesperson said, “We have come  across the unverified and unsubstantiated claims of the website and are  investigating it. Prima facie, the data appears to be unauthentic. We  want to assure our subscribers that their data is safe and maintained  with highest security. Data is only shared with authorities as per their  requirement. We have informed law enforcement agencies about the claims  of the website and will follow through to ensure strict action is  taken.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Fonearena.com, on its site, has responded with a: “We still stand by our story.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The  report assumes significance because the site exposed redacted Aadhaar  card details. There are nearly 1.2 billion Aadhaar number holders in the  country. Aadhaar aims to plug leakages in the delivery of state  benefits, such as subsidized grains to the poor, and aid in generating a  savings of about Rs70,000 crore a year for the government. But data  breaches have rattled citizens, especially since India does not have a  Privacy Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In March, the Unique Identification Authority of  India (UIDAI) blacklisted a common services centre for 10 years after it  shared the Aadhaar details of former cricket captain Mahendra Singh  Dhoni. On 25 April, &lt;i&gt;Mint &lt;/i&gt;reported that many government  departments, including the ministry of drinking water and sanitation,  the Jharkhand Directorate of Social Security, and the Kerala  government’s pension department, had published Aadhaar numbers of  beneficiaries of the schemes they run in &lt;b&gt;&lt;a href="http://www.livemint.com/Politics/bM6xWCw8rt6Si4seV43C2H/Govt-departments-breach-Aadhaar-Act-leak-details-of-benefic.html" target="_blank"&gt;violation of the Aadhaar Act&lt;/a&gt;&lt;/b&gt; .&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On 1 May, Bengaluru-based think tank Centre for Internet and Society  (CIS) reported that a Central government ministry and a state government  may have &lt;b&gt;&lt;a href="https://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1"&gt;made public up to 135 million Aadhaar numbers&lt;/a&gt;&lt;/b&gt; .&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Under the Aadhaar (Targeted Delivery of Financial Subsidies, Benefits  and Services) Act, 2016, the unique identity number is mandatory only to  receive social welfare benefits. However, tagging of the Aadhaar number  is being made mandatory by the government for various schemes including  PAN (permanent account number) accounts for taxation. On 7 July, the  Supreme Court refused to pass any interim order against the mandatory  use of Aadhaar for various government schemes. It, instead, suggested  that petitioners call for&lt;a href="http://www.livemint.com/Politics/5bZrxjf4FpfbxZFhc9inbI/Aadhaarlinked-issues-to-be-decided-by-constitution-bench-S.html" target="_blank"&gt; immediate formation of a Constitution bench &lt;/a&gt;to decide on the case .&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;News of the alleged data leak also comes at a time when there have been a spate of cyber hacks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For instance, just when companies started believing that WannaCry—the  malware that held over 200,000 individuals across 10,000 organizations  in nearly 100 countries to ransom—was on the wane, a virus christened  GoldenEye (a variant of the Petya ransomware) by security firm  Bitdefender Labs attacked companies, mostly in Ukraine. And while the  target primarily appeared to be European countries, the &lt;b&gt;&lt;a href="http://www.livemint.com/Technology/IUkweIPadyeIHRW7lFTysI/GoldenEye-ransomware-follows-in-WannaCrys-footsteps.html" target="_blank"&gt;ransomware was also reported&lt;/a&gt;&lt;/b&gt; to be making inroads in countries like India.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-july-10-2017-reliance-jio-data-leaked-on-website-report'&gt;https://cis-india.org/internet-governance/news/livemint-july-10-2017-reliance-jio-data-leaked-on-website-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-07-10T14:53:42Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/biometric-update-july-4-2017-justin-lee-uidai-declining-multiple-requests-by-police-to-share-indian-citizens-biometrics">
    <title>UIDAI declining multiple requests by police to share Indian citizens’ biometrics</title>
    <link>https://cis-india.org/internet-governance/news/biometric-update-july-4-2017-justin-lee-uidai-declining-multiple-requests-by-police-to-share-indian-citizens-biometrics</link>
    <description>
        &lt;b&gt;The Unique Identification Authority of India (UIDAI), the governing agency in charge of Aadhaar, has declined multiple requests from all law enforcement agencies, including the Delhi Police, for biometrics of citizens for criminal investigations, according to a report by The Indian Express.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Justin Lee was &lt;a class="external-link" href="http://www.biometricupdate.com/201707/uidai-declining-multiple-requests-by-police-to-share-indian-citizens-biometrics"&gt;published by Biometric Update&lt;/a&gt; on July 4, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Investigating agencies such as CBI and NIA have been repeatedly  requesting the details of Aadhaar cardholders including their  biometrics, UIDAI said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI Deputy Director General Rajesh Kumar Singh has written to the  heads of each agency, ordering them to stop asking for such details.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“This is regarding requests frequently received by the UIDAI from  police and other law enforcement agencies, seeking demographic and  biometric information of residents for facilitating identification of  individuals in different cases,” Singh said in his letter. “In this  regard, I would like to draw your kind attention to provisions under  Sections 28 and 29 of the Aadhaar (Targeted delivery of financial and  other subsidies, benefits and services) Act, 2016, which prohibits  sharing of core biometric and identity related information with other  authorities.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Rather than asking forensic labs to match fingerprints, state police  and investigating agencies are requesting biometrics data from UIDAI.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Identity information cannot be shared by UIDAI,” Singh said. “The  requests received from law enforcement agencies lead to avoidable delays  in investigation by the police authorities and unnecessary increase in  the workload of subordinate authorities.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI is also concerned about data potentially leaking as the central  government has confirmed that identities of individuals, including  Aadhaar numbers and other private information, has been leaked to the  public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="http://www.biometricupdate.com/201705/report-claims-millions-of-aadhaar-registration-and-bank-numbers-compromised"&gt;In May&lt;/a&gt;,  the Centre for Internet and Society published a report that claimed  between 130 to 135 million numbers in India’s Aadhaar biometric registry  system, and around 100 million bank numbers of pensioners and rural  jobs-for-work beneficiaries, have been leaked online by four key  government programs.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/biometric-update-july-4-2017-justin-lee-uidai-declining-multiple-requests-by-police-to-share-indian-citizens-biometrics'&gt;https://cis-india.org/internet-governance/news/biometric-update-july-4-2017-justin-lee-uidai-declining-multiple-requests-by-police-to-share-indian-citizens-biometrics&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-07-06T15:25:32Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/indian-express-kiran-jonnalgadda-june-10-2017-why-did-nandan-nilekani-praise-a-twitter-troll">
    <title>Why did Nandan Nilekani praise a Twitter troll?</title>
    <link>https://cis-india.org/internet-governance/news/indian-express-kiran-jonnalgadda-june-10-2017-why-did-nandan-nilekani-praise-a-twitter-troll</link>
    <description>
        &lt;b&gt;As the Supreme Court upholds the linking of ‘Aadhar’ with PAN, questions around ex-UIDAI chairman Nandan Nilekani praising iSPIRT head Sharad Sharma Twitter troll and ‘Aadhar’s privacy properties will continue to be asked.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Kiran Jonnalgadda was published in the &lt;b&gt;&lt;a class="external-link" href="http://indianexpress.com/article/opinion/why-did-nandan-nilekani-praise-a-twitter-troll-4697235/"&gt;Indian Express&lt;/a&gt;&lt;/b&gt; on June 10, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Last month, Sharad Sharma, the head of the Indian Software Product  Industry Round Table (iSPIRT) Foundation, an organisation that promotes  Aadhaar to industry, was outed as the operator of at least two anonymous  Twitter troll accounts that viciously harassed and defamed critics of  Aadhaar. The shocking revelation was first met with denial by iSPIRT,  and then followed by what may be understood as a reticent apology from  Mr Sharma.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In a bizarre sequence of events, the apology received praise from  several quarters. iSPIRT’s Guidelines and Compliance Committee (IGCC)  investigated Mr Sharma and the ‘Sudham’ team that coordinated the  trolling campaign. Two members of the investigating committee  subsequently resigned, although only one confirmed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The committee’s findings, confirming that Mr Sharma was responsible,  were summarised for the public by Mr Sharma himself, who then announced  that his role as a public spokesperson would now be handled  by Sanjay Jain. Mr Jain was once with the Unique Identification  Authority of India (UIDAI), launched by Nandan Nilekani, is currently a  director at Nandan Nilekani’s EkStep Foundation, and a close confidante  of Mr Sharma. The two have often pitched iSPIRT’s IndiaStack initiative  together.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In an internal email questioning this decision, an iSPIRT member  asked whether Mr Jain was a part of the ‘Sudham’ team, and whether he  was also “at least partially culpable for the [troll] campaign and the  violation of the code of conduct.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The victims of the trolling have received no report, and the two  apologies posted by Mr Sharma were both for having “condoned uncivil  behaviour”, but not for personally orchestrating the attacks. Among  those who praised him was Nandan Nilekani, former chairman of UIDAI  and chief mentor of iSPIRT.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Critics have been pointing out for years that Aadhaar lacks  sufficient checks and balances, and that claims of benefits  are overstated. These concerns have been met with denial, condemnation  of critics, and often outright refusal to engage in debate. This has  unfortunately only served to alienate an even larger section of the  population, turning ordinary citizens into activists.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;We can gain an insight into how Aadhaar is promoted by examining  iSPIRT. The organisation was founded in 2013 by volunteers who had  been working together on the sidelines of the NASSCOM Product Conclave.  These volunteers felt the need for an independent grassroots  organisation to represent tech entrepreneurs who were building  products for India and the world. iSPIRT has grown phenomenally  influential over its few years, largely by the work of volunteers who  were truly interested in building a mutual assistance community.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Level playing fields are a recurring topic. Just as there is a desire  to lower bureaucratic hurdles to give every entrepreneur a fair chance,  there is also the question of how a startup can compete against a  foreign competitor that has the advantage of a stronger home market.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="http://indianexpress.com/about/flipkart/"&gt;Flipkart&lt;/a&gt; and  Ola are two prominent examples in their fight to defend their market  share against Amazon and Uber, competitors armed with global experience,  more capital, and better trained talent. iSPIRT’s take is that for  Indian companies to thrive they must have a supportive ecosystem that  enables rapid growth, and so iSPIRT must step up as an “activist think  tank”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One aspect of this activism is IndiaStack, which seeks to help  startups by promoting a suite of ‘public goods’: Aadhaar and eKYC for id  verification, eSign and Digilocker for digital contracts and  certificates, and UPI for payments. If one accepts at face value that  these services are well intentioned, then IndiaStack is on a noble  quest. The details, unfortunately, are less pristine.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;iSPIRT is a private non-profit, but its volunteers include several  former members of UIDAI. The guidance and compliance committee (IGCC)  investigating the trolling included a current member of government.  iSPIRT helped build and evangelise the UPI (United Payments Interface)  platform and BHIM app for NPCI, but the level of involvement and terms  of the agreement are not public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For an organisation that claims to champion public goods, iSPIRT is  opaque on the level of influence they wield with government (Mr Sharma  once claimed some influence but no control), and on who exactly built  the various components of IndiaStack, within or outside of government.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;They showed a remarkable degree of influence when foisting UPI on a  change-resistant banking sector. They have funding from four banks  (IDFC, SBI, Bank of Baroda and Axis Bank) and from fintech startups.  Despite this level of responsibility, they also have no accountability  since they are a pro bono volunteer force, allowing them to distance  themselves from failures (UPI failures are NPCI’s problem and Aadhaar  failures are UIDAI’s problem, etc) and unpleasant incidents such as the  ‘Sudham’ trolling project. (No one has accepted responsibility for  operating a troll account.)&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At the core of IndiaStack is ‘Aadhaar’, which as it currently stands  has serious concerns from its technical architecture to institutional  safeguards. Aadhaar lacks publicly verifiable audits, a data breach  disclosure policy, or an engagement process for researchers to report  concerns.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For reasons best known to them, the promoters of ‘Aadhaar’ are in a  tearing hurry to impose it everywhere, in every aspect of an Indian’s  life, out of an apparent fear that it will die if adoption slows  down. This is eerily reminiscent of startup mantras like “fake it till  you make it” and “move fast and break things”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But ‘Aadhaar’ already has a billion enrollments and the backing of  legal measures pushed by the Union Government. There is no threat of  imminent demise. And yet, as the Twitter trolling shows, this fear  continues to exist for ‘Aadhaar’s proponents, so much so that critics  must be silenced at any cost.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Where trolling failed to work, subtler attacks are sure to follow. There have been some in the recent past.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Centre for Internet and Society (CIS) is facing one such attack  for its report on the leak of 130 million Aadhaar numbers. The report  received wide coverage and was followed by new rules from MEITy  (ministry of Electronics &amp;amp; Information Technology) regarding the  handling of Aadhaar numbers, but instead of commending CIS for its role  in improving safeguards, UIDAI is accusing it of hacking, demanding the  identity of the researcher so that he or she may be individually  prosecuted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When Sameer Kochhar demonstrated that previously captured  fingerprints were being reused because Aadhaar’s API lacked technical  safeguards, UIDAI responded by prosecuting him. A News18 journalist was  also prosecuted for demonstrating how double application for enrollment  was possible using different names.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As of September 30, 2017, ‘registered’ devices will be mandatory as  the current devices are not secure against fingerprint reuse, and an  unknown number of fingerprints have already been captured and stored.  This sort of forced technological upgrade will happen again as more  problems surface into public consciousness, with more researchers and  critics harassed for pointing these out.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;‘Aadhaar’ pursues inherently contradictory goals. The process of  ‘inorganic seeding’, for instance, allows a database to be seeded with  ‘Aadhaar’ numbers, to help a service provider identify and eliminate  duplicates without the individual’s cooperation. (Inorganic seeding is  an official UIDAI scheme.) And yet, the law prohibits using and sharing  ‘Aadhaar’ numbers without the individual’s consent.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;‘Aadhaar’ aims to be an inclusive project, providing an identity for  everyone, and yet easily lends itself to being an instrument of  exclusion. There is technical exclusion when biometrics fail to match,  and there is institutional exclusion when Aadhaar is made mandatory and  an individual is then blacklisted from a service or denied Aadhaar  enrollment.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aviation minister &lt;a href="http://indianexpress.com/about/jayant-sinha"&gt;Jayant Sinha&lt;/a&gt; recently announced a proposal to use digital id for just this  purpose. ‘Aadhaar’ in its current state makes it extraordinarily simple  for an organisation to demand it for authentication, but what of the  necessary safeguards to protect an individual’s rights? Or of ensuring  that grievance redressal mechanisms are in place and actually  functional? These are not solved by a technical API integration.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Just as we’ve seen with nuclear power, weak institutions which are  sensitive to criticism and fail to ensure effective oversight amplify  the risks of the underlying technology. Aadhaar’s supporting  institutions, whether government bodies like UIDAI or private bodies  like iSPIRT, are immature for the mandate they carry. All technology  improves with time, but weak institutions hamper their benefit to  society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As the leading promoter of Aadhaar, founding chairman of UIDAI, and  chief mentor of iSPIRT, Mr Nilekani must step up and commit to improving  the institutions he commands, and take responsibility for their  failures. Condemning critics instead does not help build institutions.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/indian-express-kiran-jonnalgadda-june-10-2017-why-did-nandan-nilekani-praise-a-twitter-troll'&gt;https://cis-india.org/internet-governance/news/indian-express-kiran-jonnalgadda-june-10-2017-why-did-nandan-nilekani-praise-a-twitter-troll&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-12T01:34:53Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-hindu-yuthika-bhargava-june-9-2017-new-law-to-unlock-data-economy">
    <title>New law to unlock data economy </title>
    <link>https://cis-india.org/internet-governance/news/the-hindu-yuthika-bhargava-june-9-2017-new-law-to-unlock-data-economy</link>
    <description>
        &lt;b&gt;Proposal has been sent to PMO for approval. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Yuthika Bhargava was &lt;a class="external-link" href="http://www.thehindu.com/news/national/new-law-to-unlock-data-economy/article18951772.ece"&gt;published in the Hindu&lt;/a&gt; on June 9, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The government is mulling a new data protection law to protect  personal data of citizens, while also creating an enabling framework to  allow public data to be mined effectively. The move assumes significance  amid the debate over security of individuals’ private data, including  Aadhaar-linked biometrics, and the rising number of cyber-crimes in the  country.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The Ministry of Electronics and Information Technology  (MEIT) is working on a new data protection law. A proposal to this  effect has been sent to the Prime Ministers’ Office for approval,” a  senior ministry official told &lt;i&gt;The Hindu&lt;/i&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Once the PMO approves it, the ministry will set up a “cross-functional committee” on the issue.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“We  want to include all stakeholders. It will be a high-level committee,  and all current and future requirements of the sector will be  discussed.”&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Two chief aims&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;The official said: “We  are working with two main aims – to ensure that personal data of  individuals remain protected and is not misused, and to unlock the data  economy.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The official explained that a lot of benefits can be derived from the data that is publicly available, by using technology and big data analytics. “The information can be used for the benefit of both individuals and companies,” the official said.&lt;br /&gt;&lt;br /&gt;“The underlying infrastructure of the digital economy is data. India is woefully unprepared to protect its citizens from the avalanche of companies that offer services in exchange for their data, with no comprehensive framework to protect users,” Software Freedom Law Centre (SFLC.in), a non-profit, said in an emailed reply.&lt;br /&gt;&lt;br /&gt;Currently, India does not have a separate law for data protection, and there is no body that specifically regulates data privacy.&lt;br /&gt;&lt;br /&gt;“There is nominally a data protection law in India in the form of the Reasonable Security Guidelines under Section 43A of the Information Technology Act. However, it is a toothless law and is never used. Even when data leaks such as the ones from the official Narendra Modi app or McDonald’s McDelivery app have happened, section 43A and its rules have not proven of use,” said Pranesh Prakash, policy director at CIS.&lt;br /&gt;&lt;br /&gt;Some redress for misuse of personal data by commercial entities is also available under the Consumer Protection Act enacted in 2015, according to information on the website of Privacy International, an NGO. As per the Act, the disclosure of personal information given in confidence is an unfair trade practice.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-hindu-yuthika-bhargava-june-9-2017-new-law-to-unlock-data-economy'&gt;https://cis-india.org/internet-governance/news/the-hindu-yuthika-bhargava-june-9-2017-new-law-to-unlock-data-economy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-12T01:10:06Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/indian-express-june-1-2017-pranav-mukul-privacy-is-culture-specific-mncs-hit-by-aadhaar-says-trai-chief">
    <title>Privacy is culture specific, MNCs hit by Aadhaar, says TRAI chief</title>
    <link>https://cis-india.org/internet-governance/news/indian-express-june-1-2017-pranav-mukul-privacy-is-culture-specific-mncs-hit-by-aadhaar-says-trai-chief</link>
    <description>
        &lt;b&gt;A clutch of petitions filed by those opposing what they call the unchecked use of Aadhaar is currently in the Supreme Court. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Pranav Mukul was published in the       &lt;a href="http://indianexpress.com/article/india/privacy-is-culture-specific-mncs-hit-by-aadhaar-says-trai-chief-4683613/"&gt;Indian  Express&lt;/a&gt; on June 1, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Questioning the anti-Aadhaar campaigns by       non-governmental organisations and civil society groups, Telecom       Regulatory Authority of India’s (TRAI) Chairman R S Sharma, who is       also the former Director General of Unique Identification       Authority of India (UIDAI), said that various multinational       companies were being affected by Aadhaar as it was in conflict       with their attempts to create their own database of users.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It’s making a mountain out of a molehill. There       are motivated campaigns being launched. Various multinationals are       getting affected. There are companies, which are creating their       own identities. Someone has called it digital colonisation. The       fingerprint scanners on smartphones can be easily used for       authenticating Aadhaar but they don’t allow it. A lot of       fraudulent or benami transactions can go down because of Aadhaar,”       Sharma told The Indian Express. While he refused to elaborate on       these multinationals, the remarks are an apparent reference to       Silicon Valley giants such as &lt;a href="http://indianexpress.com/about/facebook/"&gt;Facebook&lt;/a&gt; and       &lt;a href="http://indianexpress.com/about/google/"&gt;Google&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sharma’s remarks come at a time when civil       society groups have flagged serious concerns on issues such as       privacy and accountability that arise from the Centre’s increasing       use of Aadhaar. A clutch of petitions filed by those opposing what       they call the unchecked use of Aadhaar is currently in the Supreme       Court.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Recently, a Bengaluru-based NGO — Centre for       Internet &amp;amp; Society (CIS) — released a report suggesting 130       million Aadhaar numbers were leaked on government portals. CIS       later updated its report to say that there were no “leaks” or       “leakages” but a “public disclosure”. The UIDAI served a       show-cause notice to CIS, asking it to explain its claims.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The TRAI chairman defended UIDAI’s decision to       send the notice to CIS and said that there were no leakages from       Aadhaar, or decryption of of biometric data from the UIDAI server.       At the same time, Sharma made a case for having a comprehensive       data protection law in the country. “There is a need for a larger       data protection law. In today’s digitally connected world, data       protection law is a must. Data security, its protocols, rules,       responsibilities, accountabilities, damage, payments,       compensations, all these issues must come in that law,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Aadhaar Act, itself, is very self-contained,       which takes into account all data protection and privacy issues,”       Sharma said, adding that privacy was a cultural concept. “Privacy       is a culture specific concept, which they are trying to import       here. Except for NGOs, has any individual or poor person       complained, or filed a case about privacy?” he asked.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In a recent interview to The Indian Express,       Minister of Law &amp;amp; Justice and Electronics &amp;amp; Information       Technology Ravi Shankar Prasad had tried to allay fears of any       loopholes in the Aadhaar security system and said “this systematic       campaign against Aadhaar comes as a surprise for me”. He said that       the voter ID information was also in public domain, but “I don’t       see any campaign there”.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/indian-express-june-1-2017-pranav-mukul-privacy-is-culture-specific-mncs-hit-by-aadhaar-says-trai-chief'&gt;https://cis-india.org/internet-governance/news/indian-express-june-1-2017-pranav-mukul-privacy-is-culture-specific-mncs-hit-by-aadhaar-says-trai-chief&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-07T13:57:08Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-june-2-2017-komal-gupta-new-rules-for-govt-agencies-to-ensure-security-of-personal-data">
    <title>New rules for govt agencies to ensure security of personal data</title>
    <link>https://cis-india.org/internet-governance/news/livemint-june-2-2017-komal-gupta-new-rules-for-govt-agencies-to-ensure-security-of-personal-data</link>
    <description>
        &lt;b&gt;The new rules put the onus on government departments and agencies to safeguard personal data or information held by them.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Komal Gupta was &lt;a href="http://www.livemint.com/Politics/iTcwgoIUnkEnGSqOvekhUL/New-rules-for-govt-agencies-to-ensure-security-of-personal-d.html"&gt;published by Livemint&lt;/a&gt; on June 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Government departments handling personal data or information will have to ensure that end-users are made aware of the data usage and collection and their consent is taken either in writing or electronically, according to new guidelines issued by the government for security of personal data. Sensitive personal data such as passwords, financial information (bank account, credit card, debit card and other payment instrument details), medical records and history, sexual orientation, physical and mental health, and biometric information cannot be stored by agencies without encryption, say the guidelines issued by the ministry of electronics and information technology (IT) on 22 May.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The rules put the onus on government departments and agencies to safeguard personal data or information held by them. To be sure, the Information Technology Act 2000 and Aadhaar Act 2016 have laid down most of these rules. The new guidelines seek answers to questions being asked on data protection under the Aadhaar Act. “If agency is storing Aadhaar number or sensitive personal information in database, data must be encrypted and stored. Encryption keys must be protected securely, preferably using Hardware Security Modules (HSMs). If simple spreadsheets are used, it must be password protected and securely stored,” according to the guidelines.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In April, the IT Ministry issued a notification directing all government departments to remove any personal data published on their websites or through other avenues. The guidelines require regular audits to ensure effectiveness of data protection and also call for swift action on any breach of personal data. In cases where an Aadhaar number has to be printed, it should be truncated or masked. The guidelines say only the last four digits of the 12-digit unique identity number can be displayed or printed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to a research report issued by Bengaluru-based think tank Centre for Internet and Society on 1 May, four government portals could have made public around 130-135 million Aadhaar numbers and around 100 million bank account numbers.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-june-2-2017-komal-gupta-new-rules-for-govt-agencies-to-ensure-security-of-personal-data'&gt;https://cis-india.org/internet-governance/news/livemint-june-2-2017-komal-gupta-new-rules-for-govt-agencies-to-ensure-security-of-personal-data&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-07T13:51:29Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/electronic-frontier-foundation-jyoti-panday-june-1-2017-aadhaar-ushering-in-a-commercialized-era-of-surveillance-in-india">
    <title>Aadhaar: Ushering in a Commercialized Era of Surveillance in India</title>
    <link>https://cis-india.org/internet-governance/news/electronic-frontier-foundation-jyoti-panday-june-1-2017-aadhaar-ushering-in-a-commercialized-era-of-surveillance-in-india</link>
    <description>
        &lt;b&gt;Since last year, Indian citizens have been required to submit their photograph, iris and fingerprint scans in order to access legal entitlements, benefits, compensation, scholarships, and even nutrition programs. Submitting biometric information is needed for the rehabilitation of manual scavengers, the training and aid of disabled people, and anti-retroviral therapy for HIV/AIDS patients. Soon police in the Alwar district of Rajasthan will be able to register criminals, and track missing persons through an app that integrates biometric information with the Crime and Criminal Tracking Network Systems (CCTNS).&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Jyoti Panday was published by the &lt;a class="external-link" href="https://www.eff.org/deeplinks/2017/05/aadhaar-ushering-commercialized-era-surveillance-india"&gt;Electronic Frontier Foundation&lt;/a&gt; on June 1, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;These instances demonstrate how intrusive India’s controversial  national biometric identity scheme, better known as Aadhaar has grown.  Aadhaar is a 12-digit unique identity number (UID) issued by the  government after verifying a person’s biometric and demographic  information. As of April 2017, the Unique Identification Authority of  India (&lt;a href="https://uidai.gov.in/"&gt;UIDAI&lt;/a&gt;) has issued &lt;a href="http://www.financialexpress.com/opinion/why-centre-will-have-to-devise-a-comprehensive-aadhaar-bill-and-not-a-money-bill-to-address-challenges/680820/"&gt;1.14 billion&lt;/a&gt; UIDs covering nearly 87% of the population making Aadhaar, the largest  biometric database in the world. The government asserts that enrollment  reduces fraud in welfare schemes and brings greater social inclusion.  Welfare schemes that provide access to basic services for marginalized  and vulnerable groups are essential. However, unlike countries where  similar schemes have been implemented, invasive biometric collection is  being imposed as a condition for basic entitlements in India. The  privacy and surveillance risks associated with the scheme have caused  much dissension in India.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Identity and Privacy in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Initiated as an identity authentication tool, the critical problem  with Aadhaar is that it is being pushed as a unique identifier to access  a range of services. The government &lt;a href="http://www.dnaindia.com/india/report-alive-to-earlier-orders-that-aadhaar-should-be-voluntary-sc-2418854"&gt;continues to maintain&lt;/a&gt; that  the scheme is voluntary, and yet it has galvanized enrollment by  linking Aadhaar to over 50 schemes. Aadhaar has become the de-facto  identity document accepted at private, banks, schools, and hospitals.  Since Aadhaar is linked to the delivery of essential services,  authentication errors or deactivation &lt;a href="https://scroll.in/topic/38792/identity-project"&gt;has serious consequences&lt;/a&gt; including exclusion and denial of statutory rights. But more  importantly, using a unique identifier across a range of schemes and  services enables seamless combination and comparison of databases. By  using Aadhaar, &lt;a href="https://scroll.in/article/833080/aadhaar-amid-the-hullabaloo-about-privacy-the-more-pressing-issue-of-exclusion-has-been-forgotten"&gt;the government&lt;/a&gt; can  match existing records such as driving license, ration card, financial  history to the primary identifier to create detailed profiles. Aadhaar  may not be the only mechanism, but essentially, it's a surveillance tool  that the Indian government can use to surreptitiously identify and  track citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This is worrying, particularly in context of the ambiguity regarding  privacy in India. The right to privacy for Indian citizens is not  enshrined in the Constitution. Although, the Supreme Court &lt;a href="https://thewire.in/7398/sorry-mr-attorney-general-we-do-actually-have-a-constitutional-right-to-privacy/"&gt;has located&lt;/a&gt; the right to privacy as implicit in the concept of “ordered liberty”  and held that it is necessary in order for citizens to effectively enjoy  all other fundamental rights. There is also no comprehensive national  framework that regulates the collection and use of personal  information. In 2012, Justice K.S. Puttaswamy&lt;a href="http://judis.nic.in/supremecourt/imgs1.aspx?filename=42841"&gt; challenged&lt;/a&gt; Aadhaar in the Supreme Court of India on the grounds that it violates  the right to privacy. The Court passed an interim order restricting  compulsory linking of Aadhaar for benefits delivery, and referred the  clarification on privacy as a right to a larger bench. More than a year  later, the constitutional bench &lt;a href="http://indianexpress.com/article/opinion/columns/supreme-test-4642608/"&gt;is yet to be&lt;/a&gt; constituted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The delay in sorting out the nature and scope of privacy as right in  India has allowed the government to continue linking Aadhaar to as many  schemes as possible, perhaps with the intention of ensuring the scheme  becomes too big to be rolled back. In 2016, the government enacted the '&lt;a href="https://uidai.gov.in/images/the_aadhaar_act_2016.pdf"&gt;Aadhaar Act&lt;/a&gt;' passing the legislation without any debate, discussion or even approval of both houses of Parliament. In April this year, &lt;a href="http://www.hindustantimes.com/business-news/now-aadhaar-a-must-to-file-income-tax-returns-and-apply-for-pan-card/story-71CBEXGGD8yd9iFjUn4oNI.html"&gt;Aadhaar was made compulsory&lt;/a&gt; for filing income tax or PAN number application and the decision is being challenges in Supreme Court. &lt;a href="http://www.dnaindia.com/india/report-arguments-on-so-called-privacy-is-bogus-ag-rohtagi-defends-making-aadhaar-mandatory-for-pan-card-in-sc-2425525"&gt;Defending the State &lt;/a&gt;, the  Attorney-General of India claimed that the arguments on so-called  privacy and bodily intrusion is bogus, and citizens cannot have an  absolute right over their body! The State’s articulation is chilling,  especially in light of the &lt;a href="https://qz.com/463279/indias-dna-profiling-bill-may-become-one-of-the-worlds-most-intrusive-laws/"&gt;Human DNA Profiling Bill&lt;/a&gt; seeking  the right to collect biological samples and DNA indices of citizens.  Such anti-rights arguments are worth note because biometric tracking of  citizens isn't just government policy - it is also becoming big  business.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Role of Private Companies&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Private companies supply hardware, software, programs, and the  biometric registration services for rolling out Aadhaar to India’s large  population. UIDAI’s Committee on Biometrics acknowledges that  biometrics data are national assets though American biometric technology  provider L-1 Identity Solutions, and consulting firms Accenture and  Ernst and Young can &lt;a href="https://www.bloombergquint.com/technology/2017/05/03/who-has-your-aadhaar-data"&gt;access and retain&lt;/a&gt; citizens' data. The Aadhaar Act introduces electronic  Know-Your-Customer (eKYC) that allows government agencies and private  companies to download data such as name, gender and date of birth from  the Aadhaar database at the time of authentication. Banks and telecom  companies using authentication process to download data and auto-fill  KYC forms and to profile users. Over the last few years, the number of  companies or applications built around profiling of citizens’ personally  sensitive data has grown exponentially.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A number of people linked with creating the UIDAI infrastructure have  founded iSPIRT, an organisation that is pushing for commercial uses of  Aadhaar. Private companies are using Aadhaar for authentication purposes  and background checks. Microsoft has &lt;a href="http://gadgets.ndtv.com/apps/news/skype-lite-for-android-launched-what-it-is-how-it-works-and-everything-else-you-need-to-know-1662147"&gt;announced&lt;/a&gt; SkypeLite integration with Aadhaar to verify users. Others, such as &lt;a href="https://www.trustid.in/"&gt;TrustId &lt;/a&gt;and &lt;a href="http://timesofindia.indiatimes.com/city/delhi/eko-partners-npci-to-allow-aadhaar-linked-money-transfers/articleshow/53046280.cms"&gt;Eko&lt;/a&gt; are  integrating rating systems into their authentication services and  tracking users through platforms they create. In essence such companies  are creating their own private database to track authenticated Aadhaar  users and they may sell this data to other companies. The growth of  companies that &lt;a href="https://scroll.in/article/823274/how-private-companies-are-using-aadhaar-to-deliver-better-services-but-theres-a-catch"&gt;share and combine databases&lt;/a&gt; to profile users is an indication of the value of personal data and its  centrality for both large and small companies in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Integrating and linking large biometrics collections to each other,  which are then linked with traditional data points that private  companies hold such as geolocation or phone number enables constant  surveillance to take over. So far, there has been no parliamentary  discussion on the role of private companies. UIDAI remains the ultimate  authority in deciding the nature, level and cost of access granted to  private companies. For example, there is nothing in Aadhaar Act that  prevents Facebook from entering into an agreement with the Indian  government to make Aadhaar mandatory to access WhatsApp or any of its  other services. Facebook could also pay data brokers and aggregators to  create customer profiles to add to its ever growing data points for  tracking and profiling its users.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Security Risks and Liability&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;A series of data leakages have raised concerns about which private  entities are involved, and how they handle personal and sensitive data.  In February, UIDAI registered a complaint against three companies for  storing and using biometric data for multiple transactions. Aadhaar  numbers of over 130 million people and bank account details of about 100  million people&lt;a href="http://www.thehindubusinessline.com/info-tech/aadhaar-data-leak-exposes-cyber-security-flaws/article9677360.ece"&gt; have been publicly displayed&lt;/a&gt; through government portals owing to poor security practices. A &lt;a href="https://sabrangindia.in/sites/default/files/aadhaarfinancialinfo_02b_1.pdf?498"&gt;recent report&lt;/a&gt; from Centre for Internet and Society (CIS) showed that a &lt;a href="https://thewire.in/133916/taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar/"&gt;simple tweaking of URL query parameters&lt;/a&gt; of  the National Social Assistance Programme (NSAP) website could unmask  and display private information of a fifth of India's population.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Such data leaks pose a huge risk as compromised biometrics can never  be recovered. The Aadhaar Act establishes UIDAI as the primary custodian  of identity information, but &lt;a href="https://scroll.in/article/830589/under-the-right-to-information-law-aadhaar-data-breaches-will-remain-a-state-secret"&gt; is silent on the liability&lt;/a&gt; in  case of data breaches. The Act is also unclear about notice and  remedies for victims of identity theft and financial frauds and citizens  whose data has been compromised. UIDAI has continued to fix breaches  upon being notified, but maintains that storage in federated databases  ensures that no agency can track or profile individuals.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;After almost a decade of pushing a framework for mass collection of data, the Indian government has &lt;a href="http://www.dot.gov.in/sites/default/files/2017_05_26%20Circulation%20Letter%20for%20Security%20of%20Information.pdf"&gt;issued guidelines &lt;/a&gt; to  secure identity and sensitive personal data in India. The guidelines  could have come earlier, and given large data leaks in the past may also  be redundant. Nevertheless, it is reassuring to see practices for  keeping information safe and the idea of positive informed consent being  reinforced for government departments. To be clear, the guidelines are  meant for government departments and private companies using Aadhaar for  authentication, profiling and building databases fall outside its  scope. With political attitudes to corporations exploiting personal  information changing the world over, the stakes for establishing a  framework that limits private companies commercializing personal data  and tracking Indian citizens are as high as they have ever been.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/electronic-frontier-foundation-jyoti-panday-june-1-2017-aadhaar-ushering-in-a-commercialized-era-of-surveillance-in-india'&gt;https://cis-india.org/internet-governance/news/electronic-frontier-foundation-jyoti-panday-june-1-2017-aadhaar-ushering-in-a-commercialized-era-of-surveillance-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-07T12:45:30Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/economic-times-june-2-2017-nidhi-sharma-centre-brings-in-new-safeguards-following-cases-of-aadhaar-data-leaks-on-government-websites">
    <title>Centre brings in new safeguards following cases of Aadhaar data leaks on government websites</title>
    <link>https://cis-india.org/internet-governance/news/economic-times-june-2-2017-nidhi-sharma-centre-brings-in-new-safeguards-following-cases-of-aadhaar-data-leaks-on-government-websites</link>
    <description>
        &lt;b&gt;The Centre has put in new safeguards following a number of cases of Aadhaar data leaks on government websites. All ministries are being asked to encrypt all Aadhaar data and personal financial details. Also, officials are being "sensitised" about legal consequences of data breach. And every government department is to now have one official responsible for Aadhaar data protection.
&lt;/b&gt;
        &lt;p&gt;The article by Nidhi Sharma was published in the &lt;a class="external-link" href="http://economictimes.indiatimes.com/news/economy/policy/centre-brings-in-new-safeguards-following-cases-of-aadhaar-data-leaks-on-government-websites/articleshow/58952785.cms"&gt;Economic Times&lt;/a&gt; on June 2, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The ministry of electronics and information technology has written to all departments on better data security. ET has reviewed the new guidelines. Aadhaar, a 12-digit unique identity number issued on the basis of biometric data, is linked to a person's bank account and used by government agencies to directly transfer benefits of several social welfare schemes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Senior officials, who spoke off record, told ET all departments have been asked to immediately review their website content to check if personal data is on display.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img alt="Untitled-4" src="http://economictimes.indiatimes.com/img/58952889/Master.jpg" title="Untitled-4" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A set of 27 dos and 9 don'ts has been circulated on data handling. This includes instructions on masking Aadhaar data and bank details as well as encrypting data. The government has mandated regular audits to check safety of personal data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The ministry letter says, "It has come to notice there have been instances wherein personal identity or information of residents, along with Aadhaar numbers and demographic information, and other sensitive personal data ... have been published online."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The letter also spells out legal consequences of such data breach and warns the government departments to check future leaks. "Publishing identity information, i.e. Aadhaar number along with demographic information is in clear contravention of the provisions of the Aadhaar Act 2016 and constitutes an offence punishable with imprisonment up to 3 years. Further, publishing of financial information including bank details, being sensitive personal data, is also in contravention of provision under IT Act 2000 with violations liable to pay damages by way of compensation to persons affected."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The move to protect personal data comes after reports that data of 130 million Aadhaar cardholders has been leaked from four government websites. Reports, based on a study conducted by the Centre for Internet and Society (CIS) said Aadhaar numbers and details have been leaked.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/economic-times-june-2-2017-nidhi-sharma-centre-brings-in-new-safeguards-following-cases-of-aadhaar-data-leaks-on-government-websites'&gt;https://cis-india.org/internet-governance/news/economic-times-june-2-2017-nidhi-sharma-centre-brings-in-new-safeguards-following-cases-of-aadhaar-data-leaks-on-government-websites&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-06T15:41:16Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/global-voices-rohith-jyothish-may-31-2017-online-troll-attack-critics-of-indias-aadhaar-state-id-system">
    <title>Online Trolls Attack Critics of India's Aadhaar State ID System </title>
    <link>https://cis-india.org/internet-governance/news/global-voices-rohith-jyothish-may-31-2017-online-troll-attack-critics-of-indias-aadhaar-state-id-system</link>
    <description>
        &lt;b&gt;India's biometric state ID system has been leaking citizens’ data for months. When this information surfaced in April 2017, it stoked fears that the system could be used as an instrument of surveillance against Indian residents.&lt;/b&gt;
        &lt;p&gt;The blog post by Rohith Jyothish was &lt;a class="external-link" href="https://advox.globalvoices.org/2017/05/31/online-trolls-attack-critics-of-indias-aadhaar-state-id-system/"&gt;published by Global Voices&lt;/a&gt; on May 31, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The &lt;a href="https://uidai.gov.in/about-uidai/about-uidai.html"&gt;Unique Identity Authority of India (UIDAI)&lt;/a&gt;, which administrates the system known as &lt;a href="https://en.wikipedia.org/wiki/Aadhaar"&gt;Aadhaar&lt;/a&gt; (meaning foundation in Hindi) &lt;a href="http://indianexpress.com/article/opinion/columns/criticism-without-aadhaar-4653369/v"&gt;maintains&lt;/a&gt; that it only collects minimal personal data and stores it securely. But critics have firmly expressed &lt;a href="https://advox.globalvoices.org/2017/05/05/is-indias-aadhaar-system-an-instrument-for-surveillance/"&gt;doubts&lt;/a&gt; about these claims.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The implications of these leaks, and of any system flaw in Aadhaar  technology, are substantial, especially for Indians who depend on the  Aadhaar system in order to authenticate their identities when they use  any number of government services. The Aadhaar system has become the &lt;a href="https://globalvoices.org/2017/05/02/the-worlds-largest-biometric-database-is-leaking-indian-citizens-data-but-keeps-on-growing/"&gt;gatekeeper of state systems&lt;/a&gt; and services ranging from voting to financial savings to food subsidies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The digital sphere is now starting to see a pushback against Aadhaar  critics through articles and blogposts that describe concerned citizens  and privacy experts as the ‘&lt;a href="https://yourstory.com/2017/05/5-questions-for-the-anti-aadhaar-brigade/"&gt;anti-Aadhaar brigade&lt;/a&gt;‘ and &lt;a href="https://yourstory.com/2017/05/aadhaar-debate-5-more-questions-for-critics/"&gt;accuse them&lt;/a&gt; of publishing “half-truths” and “spread[ing] confusion to advance their own interests.” One such &lt;a href="https://uidai.gov.in/images/news/5_questions_for_the_anti_Aadhaar_brigade_08052017.pdf"&gt;article&lt;/a&gt; was even featured on the UIDAI website.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Some of the most &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1"&gt;well-researched critiques&lt;/a&gt; of the system have come from the &lt;a href="http://cis-india.org/"&gt;Centre for Internet and Society&lt;/a&gt; (CIS), an inter-disciplinary research organisation in Bangalore that  has now become a target of the pro-Aadhaar lobby. Shortly after CIS  released a report that pointed out security flaws in the Aadhaar  ecosystem, the UIDAI &lt;a href="http://timesofindia.indiatimes.com/india/provide-hacker-details-outfit-that-claimed-data-leak-told/articleshow/58725132.cms"&gt;accused&lt;/a&gt; the organization of hacking into the Aadhaar system themselves.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In fact, CIS had investigated databases of four specific government websites. Three were available publicly, the fourth one was &lt;a href="https://thewire.in/131698/before-aadhaar-pan-card-verdict-debate-over-bodily-autonomy-and-living-a-dignified-life/"&gt;accessible&lt;/a&gt; by simply changing one of the URL parameters. Following the accusation from UIDAI, CIS &lt;a href="http://tech.firstpost.com/news-analysis/uidais-questioning-of-cis-over-aadhaar-leaks-brings-the-sanctity-of-investigative-activities-into-question-377244.html"&gt;clarified&lt;/a&gt; that  the Aadhaar numbers along with other sensitive personal financial  information like bank account details were made available by government  websites themselves, putting a sizeable portion of Indian citizens at  risk of financial fraud.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://en.wikipedia.org/wiki/Press_Trust_of_India"&gt;Press Trust of India&lt;/a&gt; (India's largest news agency) &lt;a href="http://www.thehindubusinessline.com/news/national/unique-identification-authority-of-india-puts-posers-to-centre-for-internet-and-society-over-aadhaar-data-leak-claim/article9707647.ece"&gt;referred&lt;/a&gt; to it as a “flip-flop”, which was contested by researchers at CIS.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Independent technology news platform Medianama &lt;a href="http://www.medianama.com/2017/05/223-uidai-cis-india-aadhaar/"&gt;reported&lt;/a&gt; that the accusation by the UIDAI is regrettably consistent with  previous actions in which they filed a case against a journalist for&lt;a href="http://www.medianama.com/2017/03/223-uidai-fir-aadhaar/" rel="bookmark" title="UIDAI files FIR against journalist for exposing flaws in Aadhaar enrolment"&gt; exposing flaws&lt;/a&gt; in Aadhaar's enrollment mechanism.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A website called ‘&lt;a href="http://supportaadhaar.com/"&gt;Support Aadhaar&lt;/a&gt;‘ and its &lt;a href="https://twitter.com/SupportAadhaar"&gt;Twitter handle&lt;/a&gt; sought to collate opinions supporting Aadhaar and quell those speaking against it. However, most of their &lt;a href="http://supportaadhaar.com/facts-myths/"&gt;messages&lt;/a&gt; appear  to evade or deflect the concerns that critics have raised by touting  the benefits of the system and portraying critics as having a poor  understanding of the benefits of technology.&lt;/p&gt;
&lt;p&gt;Many Twitter users have also begun noticing patterns in the pro-Aadhaar posts:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Meanwhile, several critics of Aadhaar have repeatedly been trolled by anonymous handles on Twitter. These ‘sock puppet’ accounts seemed to be targeting those who criticise Aadhaar on social media.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One of the most active trolls issued an open challenge to reveal their identity with just their Aadhaar number. Technology entrepreneur Kiran Jonnalagadda accepted the challenge and &lt;a href="https://medium.com/@jackerhack/inside-the-mind-of-indias-chief-tech-stack-evangelist-ca01e7a507a9"&gt;found that&lt;/a&gt; ‘@Confident_India’, one of the many anonymous troll Twitter handles, is Sharad Sharma, the co-founder and director of &lt;a href="http://ispirt.in/"&gt;iSPIRT Foundation&lt;/a&gt; (Indian Software Product Industry Roundtable), the software lobby that built the backbone of the Aadhaar ecosystem.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sharma accidentally tweeted a denial from the troll account which has  since been deleted. He then tweeted again from his personal handle which  was captured.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;iSPIRT &lt;a href="https://medium.com/@mtrajan/ispirt-response-to-kiran-jonnalagadda-3f977fb91df4"&gt;officially denied&lt;/a&gt; allegations  by Jonnalgadda that the “evidence presented is a deliberate misreading  of our intent to engage with those speaking against &lt;a href="https://en.wikipedia.org/wiki/India_Stack"&gt;India Stack&lt;/a&gt;.” India Stack is the digital infrastructure that has been built over Aadhaar.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But several other Twitter users have confirmed that Sharma's phone number is linked to ‘@Confident_India’. By their own admission, iSPIRT seemed to have an &lt;a href="https://thewire.in/137371/aadhaar-ispirt-trolling-sharad-sharma/"&gt;officially sanctioned project&lt;/a&gt; intended  to systematically challenge anti-Aadhaar campaigners in online  platforms. But they refuse to term these actions as “trolling”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, Sharma later &lt;a href="https://thewire.in/139188/sharad-sharma-aadhaar-trolling/"&gt;made an apology for trolling&lt;/a&gt; and called it a “lapse of judgement”. CIS Executive Director Sunil Abraham seemed to appreciate the message. He tweeted: Bravo to &lt;a class="h-card customisable profile PrettyLink" dir="ltr" href="https://twitter.com/sharads"&gt;&lt;span class="PrettyLink-prefix"&gt;@&lt;/span&gt;&lt;span class="PrettyLink-value"&gt;sharads&lt;/span&gt;&lt;/a&gt; for this! All of us at &lt;a class="h-card customisable profile PrettyLink" dir="ltr" href="https://twitter.com/cis_india"&gt;&lt;span class="PrettyLink-prefix"&gt;@&lt;/span&gt;&lt;span class="PrettyLink-value"&gt;cis_india&lt;/span&gt;&lt;/a&gt; look fwd to collaborating with &lt;a class="h-card customisable profile PrettyLink" dir="ltr" href="https://twitter.com/Product_Nation"&gt;&lt;span class="PrettyLink-prefix"&gt;@&lt;/span&gt;&lt;span class="PrettyLink-value"&gt;Product_Nation&lt;/span&gt;&lt;/a&gt; &amp;amp; &lt;a class="h-card customisable profile PrettyLink" dir="ltr" href="https://twitter.com/sharads"&gt;&lt;span class="PrettyLink-prefix"&gt;@&lt;/span&gt;&lt;span class="PrettyLink-value"&gt;sharads&lt;/span&gt;&lt;/a&gt; to serve Indian s/w sector. &lt;a class="customisable link" dir="ltr" href="https://t.co/TEz0fxnloo" rel="nofollow noopener" target="_blank" title="https://twitter.com/sharads/status/866943195678035968"&gt;&lt;span class="u-hiddenVisually"&gt;https://&lt;/span&gt;twitter.com/sharads/status&lt;span class="u-hiddenVisually"&gt;/866943195678035968 &lt;/span&gt;…&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;iSPIRT is an initiative which finds far-reaching support from several IT  industry leaders in India. What is worrying is that there is still no  clarification from iSPIRT on the identities of the other anonymous  trolls and their position on trolling against genuine concerns raised by  citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;More than a week after the trolling revelations, iSPIRT announced on its website, the results of an investigation carried out by an Internal Guidelines and Compliance Committee over the allegations against Sharma of operating the anonymous handles, ‘@Confident_India’ and ‘@Indiaforward2′. Jonnalgadda was one of the trolling victims who testified in the internal meeting. A summary of the investigation was posted bafflingly by the accused himself in which he says that project Sudham has been dissolved and that he has been told to not make public appearances on behalf of iSPIRT for four months while he remains Director and the face of the organisation. FactorDaily reported that iSPIRT members on the condition of anonymity said that Pallav Nadhani (Founder, Chief Executive, FusionCharts) and Naveen Tewari (Co-founder, InMobi) who quit iSPIRT were upset with their excessive focus on India Stack.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One wonders whether this kind of behavior would be treated differently if it took place offline. Is intimidating those who appear to be ‘detractors’ the most effective way of dealing with criticism? Why is a software lobby taking it upon themselves to defend the idea of Aadhaar and India Stack through such means?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Many are hoping that experts on both sides of the issue can find a way to debate questions around the privacy and security of Aadhaar's technology — that affect some 1.3 billion people — in a more democratic way.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/global-voices-rohith-jyothish-may-31-2017-online-troll-attack-critics-of-indias-aadhaar-state-id-system'&gt;https://cis-india.org/internet-governance/news/global-voices-rohith-jyothish-may-31-2017-online-troll-attack-critics-of-indias-aadhaar-state-id-system&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-07T13:34:00Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/economic-times-may-29-2017-bharat-joshi-bbmp-faces-ire-for-publishing-pourakarmikas-aadhaar-details-on-website">
    <title>BBMP faces ire for publishing pourakarmikas' Aadhaar details on website</title>
    <link>https://cis-india.org/internet-governance/news/economic-times-may-29-2017-bharat-joshi-bbmp-faces-ire-for-publishing-pourakarmikas-aadhaar-details-on-website</link>
    <description>
        &lt;b&gt;The Bruhat Bengaluru Mahanagara Palike (BBMP) has published the Aadhaar details and other personal information of thousands of its pourakarmikas - civic workers who sweep streets and collect waste door-to-door.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This has angered activists who believe it could be misused. BBMP claims it was done to bring transparency in the city's solid waste management. &lt;i&gt;The article by Bharat Joshi was published in the &lt;a class="external-link" href="http://economictimes.indiatimes.com/news/politics-and-nation/bbmp-faces-ire-for-publishing-pourakarmikas-aadhaar-details-on-website/articleshow/58889617.cms"&gt;Economic Times&lt;/a&gt; on May 29, 2017&lt;/i&gt;.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The Aadhaar number, provident fund number, employee state insurance  (ESIC) number and residential addresses of thousands of pourakarmikas  are available ward-wise on the civic body's website. ET accessed as many  as 4,215 Aadhaar numbers and 5,744 PF and ESI numbers of pourakarmikas  from 58 wards. The number could be much higher across the city's 198  wards. An ESI number grants access to personal details of an employee on  the esic.nic.in website, such as father's name and date of birth.  &lt;br /&gt; &lt;br /&gt; The city has over 30,000 pourakarmikas, most of them Dalit women and  employed by contractors. The disclosure of their Aadhaar numbers comes  at a time when the Modi administration's push for wider application of  the unique identification number has triggered a nationwide debate on &lt;a href="http://economictimes.indiatimes.com/topic/privacy" target="_blank"&gt;privacy&lt;/a&gt;.  &lt;br /&gt; &lt;br /&gt; "(Disclosure) happens because authorities don't read the law," Supreme  Court advocate KV Dhananjay said. "There is every possibility of  misuse, especially identity theft. What hackers do is they start  aggregating such information because the Aadhaar is used as a platform  for transfer of benefits. And with Aadhaar set to become the anchor for  many things, the BBMP should immediately remove those details."  &lt;br /&gt; &lt;br /&gt; A recent report by city-based Centre for Internet and Society flagged  four government agencies for publishing Aadhaar and other financial  data. It blamed the Unique Identification Authority of India (UIDAI) for  turning a blind eye to the lack of standards prescribed for how other  agencies deal with data, such cases of massive public disclosure and  "the myriad ways in which it could be used for mischief."  &lt;br /&gt; &lt;br /&gt; Earlier this month, UIDAI chief executive officer Ajay Bhushan Pandey  wrote to chief secretaries of all states, reminding them that publishing  an Aadhaar number is prohibited under Sections 29(2), 29(3) and 29(4)  of the Aadhaar Act, 2016. "Our intention was not to cause anyone any  harm," BBMP Joint Commissioner (solid waste management) Sarfaraz Khan  said. The idea was to prevent contractors from taking payments against  non-existent pourakarmikas. "We're also planning to make public details  of which exact street a pourakarmika is working on."  &lt;br /&gt; &lt;br /&gt; He added that he would discuss the disclosure with the Commissioner,  "If there is any violation, the Aadhaar numbers will be removed."  &lt;br /&gt; &lt;br /&gt; This points to the need for BBMP to have a policy on data and privacy,  said Vinay K Sreenivasa of the Alternative Law Forum. "Of what use is  an Aadhaar number to the BBMP? Names and photographs would have sufficed  to ensure transparency."  &lt;br /&gt; &lt;br /&gt; &lt;b&gt;ET Follow-up on Scare in Malleswaram&lt;/b&gt; &lt;br /&gt; BBMP Joint Commissioner Sarfaraz Khan was unaware that publishing  Aadhaar data is a punishable offence. However, the election wing of the  BBMP has ordered a probe after ET reported how a certain Hanumantharaju,  claiming to be a municipal official, collected Aadhaar details from  residents of the Atma KT Apartment in Malleswaram.  &lt;br /&gt; &lt;br /&gt; Residents also filed a complaint with the Malleswaram police. "We called  the man's mobile number but a woman picked up. Further investigation is  underway and BBMP is also checking its records," a police officer said.   &lt;br /&gt; &lt;br /&gt; Residents also plan to submit a representation to  Malleswaram MLA CN Ashwathnarayan. "We have taken this seriously and are  awaiting a report from the Malleswaram BBMP revenue office," Assistant  Commissioner (election) TR Shobha told ET.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/economic-times-may-29-2017-bharat-joshi-bbmp-faces-ire-for-publishing-pourakarmikas-aadhaar-details-on-website'&gt;https://cis-india.org/internet-governance/news/economic-times-may-29-2017-bharat-joshi-bbmp-faces-ire-for-publishing-pourakarmikas-aadhaar-details-on-website&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-06T14:27:27Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/raw/indian-express-nishant-shah-may-28-2017-digital-native-look-before-you-digitally-leap">
    <title>Digital native: Look before you (digitally) leap</title>
    <link>https://cis-india.org/raw/indian-express-nishant-shah-may-28-2017-digital-native-look-before-you-digitally-leap</link>
    <description>
        &lt;b&gt;Creating a digital future is great, but there’s a serious need to secure the infrastructure first.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published in the &lt;a class="external-link" href="http://indianexpress.com/article/technology/tech-news-technology/digital-native-look-before-you-digitally-leap-4676270/"&gt;Indian Express&lt;/a&gt; on May 28, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Digital technologies of connectivity have one unrelenting promise —  they offer us new ways of doing things, augmenting existing practices,  amplifying capacities and affording new possibilities of information and  data transactions that accelerate the ways in which we live. This idea  of the internet as infrastructure is central to India’s transition into  an information technologies future.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nandan Nilekani, almost a decade ago, in his book, Imagining India,  had clearly charted how the digital is the basis for shaping the future  of our communities, societies and governance. As one of the architects  of Aadhaar, Nilekani had argued that the country of the 21st century  will have to be one that seriously invests in the digital  infrastructure.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In 10 short years, we have reached a point where we no longer  question the enormous investment we make in digital systems of  governance and functioning, and we appreciate the economic and networked  values of projects like #DigitalIndia and #MakeInIndia that shape our  markets and cities into becoming the new cyber-hubs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There is no denying that digital offers a new way of consolidating a  country as polyphonic, multicultural, expansive and diverse as India. We  also have to appreciate that, even if selectively, the digitisation of  public records, government services, and state support is clearly  producing an administrative momentum that is reforming various practices  of corruption and incompetence in the massive state machinery. The role  of the digital as infrastructure has been a boon for many developing  countries.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This positioning, however, masks the fact that infrastructure needs  its own support and care systems. Take roads, for example. Roads allow  for connectivity, movement and mobility between different spaces. They  are one of the most important of state and public infrastructures and  for all our jokes about pot-holes and eroding spaces for pedestrians,  roads remain the life-line of our everyday life. A complex mechanism of  planning, regulation and maintenance needs to be put into place in order  to make roads survive.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The amount of attention we pay to roads — the material quality, the  land that it occupies, the lanes for different vehicles, the traffic  lights and zebra crossings, blockages and streamlines, authorising  specific use of roads and disallowing certain activities to happen there  — is staggering. A public planner would tell you that before the road  comes into being, the idea of the road has to be formulated. The road  needs protection and planning and its own infrastructure of support and  creation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When it comes to the information superhighway of the digital web,  this remains forgotten. We are so focused on the digital as  infrastructure that we seem to pay no attention to its infrastructure.  Thus, when we proposed, deployed and now enforced a project like  Aadhaar, the focus remained on its unfolding and its operations. Aadhaar  as an aspiration of governance has its values and has the capacity to  become a system that augments statecraft.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, the infrastructure that is needed to make Aadhaar possible —  rules and regulations around privacy, bills and acts about data sharing  and ownership, contexts of informed consent and engagement, community  awareness and data security protocol — have been missing from the  debates. For years now, activists have been advising and warning the  state that building this digital infrastructure without building the  contexts within which they make sense is not just irresponsible, but  downright dangerous.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Different governments have turned a deaf ear to these protests. Now,  when the Aadhaar portals are found disclosing massive volumes of public  data, making people vulnerable to data and identity theft and fraud, we  are realising the massive projects we have started without thinking  about the context of security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With the ongoing controversies around #AadhaarLeaks, the question is  not whether the disclosure of this information was a leak, a breach or  an ignorant exposure of sensitive information. The response to it cannot  be just about fixing the infrastructure and building more robust  systems. The question that we need to confront is how do we stop  thinking of the internet as infrastructure and start focusing on the  infrastructure that needs to be set into place so that these digital  systems promise safety, security, and protection for the lives they  intersect with.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/raw/indian-express-nishant-shah-may-28-2017-digital-native-look-before-you-digitally-leap'&gt;https://cis-india.org/raw/indian-express-nishant-shah-may-28-2017-digital-native-look-before-you-digitally-leap&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>nishant</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Biometrics</dc:subject>
    
    
        <dc:subject>Researchers at Work</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    

   <dc:date>2017-06-08T01:22:54Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/inc42-may-23-2017-shweta-modgil-sharad-sharma-aplogises-for-trolling-aadhaar-critics">
    <title>Sharad Sharma Apologises for Trolling Aadhaar Critics; Unmasking Ispirit's Controversial Trolling Program</title>
    <link>https://cis-india.org/internet-governance/news/inc42-may-23-2017-shweta-modgil-sharad-sharma-aplogises-for-trolling-aadhaar-critics</link>
    <description>
        &lt;b&gt;Last weekend I was at Aditi Mittal’s standup comedy show in Mumbai where she made a cheeky remark that stayed with me – “Do you guys know what India’s soft power is today? It is trolling!” &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Shweta Modgil was &lt;a class="external-link" href="https://inc42.com/buzz/sharad-sharma-trolling-aadhaar/"&gt;published by Inc 42&lt;/a&gt; on May 23, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;While she was poking fun at the Snapchat-Snapdeal-Evan Spiegel controversy, in a bizarre coincidence those words came back to haunt me three days later. That was when one of biometric authentication system Aadhaar’s most vocal critics, Kiran Jonnalagadda, co-founder of Internet Freedom Foundation (IFF), an advocacy group, revealed in a series of tweets that @Confident_India, one of the anonymous accounts arguing in favour of Aadhaar and attacking its critics on Twitter, was being operated by none other than Sharad Sharma, the founder of software products think tank iSPIRT.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At the time, &lt;b&gt;Sharad had completely denied that he was tweeting from an anonymous account&lt;/b&gt;. But today, on Twitter, Sharad apologised for the anonymous trolling &lt;a class="external" href="https://twitter.com/sharads/status/866943195678035968/photo/1" rel="noopener noreferrer nofollow" target="_blank"&gt;on Twitter&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In a tweet, Sharad stated that “There was a lapse of judgement on my part. I condoned tweets with uncivil comments. So I’d like to unreservedly apologise to everybody who was hurt by them.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;He added that “Anonymity seemed easier than propriety, and tired as I was by personal events and attacks on iSPIRT’s reputation, I slipped.” Furthermore, he stated that he would not be part of anything like this again or allow such behaviour to continue. He also revealed that an iSPIRT Guidelines and Compliance Committee (IGCC) has been set up to investigate the matter and recommend corrective action.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;On Catching a Troll&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;On 17 May, Kiran tweeted out a revelation, which shook a lot of people – “Have we caught an Aadhaar troll?” Kiran used Twitter’s account reset option on Confident_India with Sharad Sharma’s number to see if it is was accepted. And, as per a screenshot posted by him, it did.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This was further corroborated by many other Twitter users. Medianama’s Nikhil Pahwa (and co-founder of IFF) also confirmed the same, tweeting that the troll account does link to Sharad Sharma.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In a &lt;a class="external-link" href="https://medium.com/@jackerhack/inside-the-mind-of-indias-chief-tech-stack-evangelist-ca01e7a507a9"&gt;detailed&lt;/a&gt; Medium post, Kiran then revealed how he investigated the rise of anonymous Twitter accounts and trolls responding to critics of Aadhaar. But what he revealed next was the shocking part – that at the 27th Fellows meeting of the think tank, a plan was hatched to respond to critics of India Stack which involved the use of trolls. A group called Sudham, created earlier, divided people who were broadcasting different views on Aadhaar, into different categories and then underlined various proposals on dealing with them. One of the groups called “archers” was entrusted to carry out the mainstream debate, while another group of “swordsmen” was entrusted to challenge people who were categorised as informed yet “trolling.” Swordsmen would do this by coordinating on WhatsApp with quick responses and in numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img src="https://cis-india.org/home-images/WhatCanYoDo.jpg" alt="Trolled" class="image-inline" title="Trolled" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kiran got a hold of the presentation and also shared how one controversial slide also showed a detractor matrix.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is this slide which Kiran uses to illustrate the fact that: “ iSPIRT has an officially sanctioned trolling program where the trolls coordinate on WhatsApp and attack together on Twitter, exactly the behaviour seen in all the tweets above—and I’ve only covered the leader’s tweets. There are at least a dozen known troll accounts that attack in packs.”&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;First Denial&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Back when the information was first revealed, Sharad Sharma responded by denying that he was tweeting from the &lt;a class="external" href="https://twitter.com/Confident_India" rel="nofollow" target="_blank"&gt;@&lt;b&gt;Confident_India&lt;/b&gt;&lt;/a&gt; Twitter account.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;He further added that he was in for a family emergency in the US. And that he was clueless as to why his number was linked with that account.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But, interestingly, what roused the investigator’s suspicions was that Sharad shared the same denial from another troll account @indiaforward2 – which was captured by another Twitter user before it was deleted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The denial from Sharad’s true account came half an hour later. But the damage had been done and all fingers pointed in the direction of Sharad Sharma engaging in trolling from those accounts. Kiran then wrote another damning post on Sharad’s &lt;a class="external-link" href="https://medium.com/@jackerhack/sharad-sharmas-dubious-denial-b0b9aa6c6b8f"&gt;dubious denial&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As can be guessed, all the tweets related to this matter from Sharad’s and Indiaforward’s accounts have been deleted. The last tweet from Confident India’s account on 17 May professed that he is not Sharad Sharma.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Meanwhile, iSPIRT finally &lt;a class="external-link" href="https://medium.com/@mtrajan/ispirt-response-to-kiran-jonnalagadda-3f977fb91df4"&gt;responded&lt;/a&gt; to Kiran’s revelations on Medium –“We want to categorically state that the allegations against iSPIRT coordinating and/or promoting any troll campaign are false and the evidence presented is a deliberate misreading of our intent to engage with those speaking against India Stack.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The post further explained that in its Fellows meeting held in February and April 2017, it did address the issue of the chatter around India Stack. It says, “Our volunteer, Tanuj Bhojwani, led the discussion and we outlined our strategy for dealing with our detractors. The slide in question is clearly titled “Detractor Matrix.” The slide outlines how we classify those speaking against India Stack, and how we are engaging with them. We called one category of people “informed yet trolling (IYT),” a category of people deliberately misleading people, despite understanding the nuance behind the debate.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The post admitted that the think tank encouraged volunteers to respond to these IYT Twitter handles directly from their own personal handles. However, at no point did it endorse or recommend anonymous trolling.&lt;br /&gt;&lt;br /&gt;“We are aware that some volunteers and their friends have created an anonymous campaign to Support Aadhaar. This is not a troll campaign, but an informational one. It is also not an iSPIRT campaign.”&lt;br /&gt;&lt;br /&gt;It concluded with: “Kiran’s motivated misrepresentation of the slides perhaps speaks to his biases against iSPIRT.” The post added that it plans to investigate the confusion around the alleged mobile number and account link and clarify all outstanding questions.&lt;br /&gt;&lt;br /&gt;Meanwhile coming back to trolling from where we started. Though Sharad’s apology did not say directly whether he operated the two Twitter accounts — @Confident_ India and @Indiaforward2 — which he was suspected of using for trolling- he signs off by saying that he requests “those who I have disappointed to look at this as an exception.”&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;The Aadhaar Controversy&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;While the series of incidents raises many doubts over an esteemed organisation such as iSPIRT, the controversy over Aadhaar, India’s massive biometric identification programme, has been raging for many months now.&lt;br /&gt;&lt;br /&gt;Over the last few months, it has come under fire for not addressing the privacy concerns of an individual and leaking individual data. Aadhaar critics have pointed out that it is more a mass surveillance tool, can lead to identity thefts, and linking basic services with it spells doom.&lt;br /&gt;&lt;br /&gt;&lt;a class="external-link" href="http://timesofindia.indiatimes.com/business/india-business/aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report/articleshow/58529002.cms"&gt;This month&lt;/a&gt;, a CIS (Centre for Internet and Society ) report revealed that Aadhaar numbers and personal information of as many as 135 million Indians could have been leaked from four government portals, due to lack of IT security practices. The report claimed that the absence of “proper controls” in populating the databases could have disastrous results as it may divulge sensitive information about individuals, including details about the address, photographs, and financial data. It also added that as many as 100 Mn bank account numbers could have been “leaked.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, on May 16, the CIS &lt;a class="external-link" href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof/view"&gt;updated its report&lt;/a&gt; and clarified that although the term ‘leak’ was originally used 22 times in its report, &lt;b&gt;it is at “best characterised as an illegal data disclosure or publication and not a breach or a leak.&lt;/b&gt;” It also claimed that some of its findings were “misunderstood or misinterpreted” by the media and that it never suggested that the biometric database had been breached.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Meanwhile, the Aadhaar-issuing authority UIDAI has asked CIS to explain its sensational claim that 13 crore Aadhaar numbers were “leaked” and provide details of servers where they are stored. The UIDAI also wants CIS to clarify what kind of “sensitive data” is still with the Centre or anyone else. The UIDAI has strongly denied any breach of its database and has asked CIS to provide details such as the servers where the downloaded “sensitive data” is stored.&lt;br /&gt;&lt;br /&gt;While the security of the above-mentioned Aadhaar data is still being debated, the government’s push towards making it compulsory across industries has become a major topic of debate in India.&lt;br /&gt;&lt;br /&gt;From linking bank accounts, to PAN numbers, to obtaining free gas connections under the Pradhan Mantri Ujjwala Yojana, to linking scholarships to linking Aadhaar numbers to social welfare schemes for electronically disbursing money to specific beneficiaries, or the Aadhaar-enabled Payment System (AEPS), the government has been pushing on with Aadhaar to make it a mandatory ID rather than the voluntary one it was envisaged to be originally. India still does not have a data protection and privacy law and making Aadhaar mandatory in such a country is not without risks.&lt;br /&gt;&lt;br /&gt;Given the fact that the UIDAI cannot afford to carry out authentication-based rollouts across schemes in haste as the failure rate of AEPS can lead to denial of direct benefits, it makes more sense to retain Aadhaar as a voluntary authenticator, at least until the government solves on-ground issues around Aadhaar-based authentication. Because any failure can erode public faith in Aadhaar as the beneficiary would not get his rightful ration over authentication failure— and, to that extent, in the government itself. So, for beneficiaries who depend on public distribution systems (PDS) for rice, sugar, kerosene or oil, authentication failure is a serious problem.&lt;br /&gt;&lt;br /&gt;It is to this effect that PILs (public interest litigation suits) have been filed in the Supreme Court stating that making Aadhaar compulsory is illegal and would virtually convert citizens into “slaves” as they would be under the government’s surveillance all the time. The Supreme Court had itself stated in August 2015 that Aadhaar cards will not be mandatory for availing benefits of government’s welfare schemes and had also barred authorities from sharing personal biometric data collected for enrollment under the scheme.&lt;br /&gt;&lt;br /&gt;Last month too, it lambasted the Narendra Modi-led BJP government at the Centre for making Aadhaar card a mandatory prerequisite to avail government services. The court will examine all applications against Aadhaar on June 27 2017, while the government remains steadfast on not extending the deadline of June 30 by which various schemes such as the grant of scholarships, Sarva Shiksha Abhiyan and various other social welfare schemes were to seek mandatory Aadhaar number.&lt;br /&gt;&lt;br /&gt;While the debate rages on, controversies keep on piling up. Recently, linking people living with HIV/ AIDS with Aadhaar cards has allegedly driven away patients from hospitals and antiretroviral therapy (ATR) centres in Madhya Pradesh. As per health department sources, the MP State AIDS Control Society made Aadhaar card number compulsory from February this year for those affected by the virus to get free medicines and treatment in accordance with the Central government’s policy making Aadhaar mandatory to avail benefits of any government scheme.&lt;br /&gt;&lt;br /&gt;However, this led to negative fallout as many patients and suspected victims started avoiding ATR centres and district hospitals after the new rule came into effect. The patients feared that the compulsory submission of Aadhaar card to get free medicines and medical check-ups could lead to the disclosure of their identity, inviting social stigma.&lt;br /&gt;&lt;br /&gt;While there is no denying the fact that, in a welfare state, technology can play a big role in enabling the state to hand out entitlements more efficiently and distribute public services at scale. But doing the same at the cost of an individual citizen’s privacy and resting it all on one mandatory number whose authentication is still not completely foolproof, is hardly the way a welfare state would like to operate.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/inc42-may-23-2017-shweta-modgil-sharad-sharma-aplogises-for-trolling-aadhaar-critics'&gt;https://cis-india.org/internet-governance/news/inc42-may-23-2017-shweta-modgil-sharad-sharma-aplogises-for-trolling-aadhaar-critics&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-26T01:08:09Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-times-of-india-may-24-2017-shalina-pillai-anand-j-ispirts-sharad-sharma-sorry-i-trolled-aadhaar-critics">
    <title>iSpirt's Sharad Sharma: Sorry, I trolled Aadhaar critics</title>
    <link>https://cis-india.org/internet-governance/news/the-times-of-india-may-24-2017-shalina-pillai-anand-j-ispirts-sharad-sharma-sorry-i-trolled-aadhaar-critics</link>
    <description>
        &lt;b&gt;Sharad Sharma, the man who is seen as one of the critical backbones of India's digital drive, profusely apologized on Tuesday for anonymously trolling those arguing for better privacy and security standards in Aadhaar.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Shalina Pillai and Anand J was published in the &lt;a class="external-link" href="http://timesofindia.indiatimes.com/people/ispirts-sharad-sharma-sorry-i-trolled-aadhaar-critics/articleshow/58817320.cms"&gt;Times of India&lt;/a&gt; on May 24, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The apology came a few days after &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/Kiran-Jonnalagadda"&gt;Kiran Jonnalagadda&lt;/a&gt;,  co-founder of developer community platform HasGeek and one of those who  were at the receiving end of the trolling, used internet tools to  discover the faces behind the trolling.   &lt;br /&gt; &lt;br /&gt; The trolls allegedly included several other members of iSpirt, the  software product association co-founded by Sharma and which leads  IndiaStack, a set of technologies that can be used to digitise many  everyday processes used by common people. The issue has divided India's  nascent startup community like never before, and coming soon after the  division over the arrest of &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/Stayzilla"&gt;Stayzilla&lt;/a&gt; co-founder Yogendra Vasupal, there are many who now worry for the  ecosystem.This may also explain the apology by Sharma, who has been at  the forefront of building this ecosystem.   &lt;br /&gt; &lt;br /&gt; In the apology mail that he tweeted, Sharma said: "There was a lapse  of judgment on my part. I condoned tweets with uncivil comments. So I  would like to unreservedly apologise to everybody who was hurt by them.  Anonymity seemed easier than propriety, and tired as I was by personal  events and attack on iSpirt's reputation, I slipped. I won't be part of  anything like this again nor passively allow such behaviour to happen,  even in the worst of times."   &lt;br /&gt; &lt;br /&gt; &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/Nandan-Nilekani"&gt;Nandan Nilekani&lt;/a&gt; tweeted in response to Sharma's apology that it was brave of him to do  so. Several others in iSpirt also backed Sharma after the public apology  . There was a surge of tweets in response to Sharma's and Nilekani's  tweets, some welcoming the turn of events and others saying it wasn't  enough. Jonnalagadda is among those who are not satisfied. "There were  several individuals at iSpirt behind these trolls and Sharma's apology  is not enough," he told TOI.   &lt;br /&gt; &lt;br /&gt; Aadhaar, aggressively pushed by the government, is being fiercely  questioned by privacy and security advocates. Though most of these  activists say they are asking for implementation of safeguards, the  Twitter hashtags used by some of them include #antiaadhaar,  #destroyaadhaar and #attackaadhaar, which seem to suggest they are  entirely opposed to the authentication mechanism.   &lt;br /&gt; &lt;br /&gt; Both sides have used intemperate and often abusive language on social  media -many using anonymous names. The latest flashpoint was a report by  the Centre for Internet and Society (CIS) released earlier this month  that said some 135 million Aadhaar numbers were leaked through  government databases. There have also been accusations that private  companies that verify Aadhaar credentials often get access to the full  Aadhaar information of individuals. These provoked the proAadhaar  trolls. Jonnalagadda, Nikhil Pahwa, co-founder of the Internet Freedom  Foundation, which works on issues including net neutrality, and free  expression and privacy on the internet, and Sunil Abraham of CIS were  under particular attack.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Some of the iSpirt fellows and volunteers TOI spoke to had little  remorse. "I am not saying iSpirt should have done what it did. But I can  imagine why iSpirt reacted like this as we all have been under constant  personal attack for a year now," said an iSpirt fellow, who did not  want to be identified. Jas Gulati, co-founder and CEO at &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/Nowfloats"&gt;Nowfloats&lt;/a&gt; and a volunteer at iSprit, said iSpirt was an open organisation. "Sharad was upfront about it and I think it's very positive."   &lt;br /&gt; &lt;br /&gt; The Aadhaar privacy advocates, including Jonnalagadda and Pahwa, are  clear they value iSpirt, but say it was undermining itself by its  actions. One pointed to a February meeting of iSpirt where they created a  programme called Sudham that distributed prominent Aadhaar critiques  into four quadrants -`Misinformed, fearful and engaging', `Informed,  fearful and engaging', `Misinformed and trolling' and `Informed and  trolling' -and assigned different members to deal with each quadrant.  Some of those who were assigned responsibilities appear to have taken  their job too seriously .   &lt;br /&gt; &lt;br /&gt; Pahwa told TOI, "The work done by the Product Nation initiative at  iSpirt is what makes it an important organization. But when people raise  questions of IndiaStack and Aadhaar, many in that team respond with  venom. iSpirt is unique, in that it is a thinktank that plays the role  of an activist and lobbyist with a high degree of influence with the  government and so they must develop processes for better governance,  transparency and accountability ."   &lt;br /&gt; &lt;br /&gt; Anand Venkatanarayanan, a senior engineer at &lt;a class="key_underline" href="http://timesofindia.indiatimes.com/topic/NetApp"&gt;NetApp&lt;/a&gt; and independent Aadhaar researcher, said iSpirt should not be judged  based on what Sharma did. "What we are trying to do is strengthen the  Aadhaar system. Currently, they do not even have a process to report  bugs. Large companies all have SOPs (standard operating procedures) to  deal with issues. UIDAI does not," he said, noting that his views are  personal and not that of his employer's.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-times-of-india-may-24-2017-shalina-pillai-anand-j-ispirts-sharad-sharma-sorry-i-trolled-aadhaar-critics'&gt;https://cis-india.org/internet-governance/news/the-times-of-india-may-24-2017-shalina-pillai-anand-j-ispirts-sharad-sharma-sorry-i-trolled-aadhaar-critics&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-26T00:13:38Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-indiasaga-may-25-2017-aadhaar-card-one-identity-multiple-disorders">
    <title>Aadhaar Card: One Identity, Multiple Disorders</title>
    <link>https://cis-india.org/internet-governance/news/the-indiasaga-may-25-2017-aadhaar-card-one-identity-multiple-disorders</link>
    <description>
        &lt;b&gt;It is still hazy to see the desperation of the union government to imposing the Aadhaar Card mandatory when matters related to Aadhaar Card are already sub judice. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This was blog post by Gaurav Raj was &lt;a class="external-link" href="http://theindiasaga.com/politics-governance/aadhaar-card-one-identity-multiple-disorders"&gt;published by India Saga&lt;/a&gt; on May 25, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The constitutionality of Aadhaar is yet to be decided by the Supreme Court, however, the enrolment of Aadhaar has reached the mark of more than one billion. Recently, the government declared Aadhaar mandatory to file Income Tax Return (ITR) while the Supreme Court is opined not to treat Aadhaar mandatory, but voluntarily. Now it is imperative of the government to confide the citizens that the Aadhaar information- demography and biometrics-are in safe hands, a debate which has been heating up, and the contempt of the court’s decision by the government is for greater good. But the uproar against the speculation of identity revelation threat and possible misuse of Aadhaar details by the government-corporate nexus, plausible reasons to doubt the security of privacy, which is a fundamental right of Indian citizen. Ironically, after the Finance Minister Arun Jaitley defended the ‘Aadhaar Money Bill controversy’ filed by former congress MP Jairam Ramesh in the court, the Supreme Court is in dilemma and yet to decide whether ‘Right to Privacy' is a fundamental right or not.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Why Aadhaar Card Mandatory?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Nandan Nilekani, the co-founder of Infosys and the ideologue of Aadhaar, said that Aadhaar will change the PDS system in India since it ensures no ghost or fake beneficiaries to avail unentitled benefits of the various welfare schemes and subsidies. Nilekani also says that there might be margin of error up to 5 per cent in distributing the subsidies or benefits of various welfare schemes to the masses. The top-honcho technocrat has also defended Aadhaar that any breach of privacy of citizens is not possible as the Unique Identification Authority of India (UIDAI) is efficient to secure the public data under CIDR.&lt;br /&gt;&lt;br /&gt;The government claims that the corruption-mounted Public Distribution System (PDS) in India is reformed due to the introduction of the 12 digit unique identification number. More than 40000 crore have been saved in the form of exchequer due to curb of fake and ghost beneficiaries in the PDS system. Now if we believe Nilekani claim of 5% error, then more than 5 crore beneficiaries would be losing their benefits due the error in the biometric identification. The Infosys co-founder later said that if there is a margin of error then ‘One Time Password’ (OTP) comes in. However, he didn’t define what if there is a congestion of network in the remotest Indian villages where phone signals are rare? Standing on the PDS shop waiting for food grains and network, is certainly not an ideal way to avail the benefits of the government welfare schemes. In 2011, activist and writer Ruchika Gupta said in an interview to Tahalka, “The UID cannot address the bulk of delivery problems in the two of the biggest social sectors programmes like MGNREGA and PDS. Linking UID with social sector legislation is completely baseless.”&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;PAN Card Linked with Aadhaar Card?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The government has directed the Reserve Bank of India to make Aadhaar mandatory for Income Tax Return filing. Currently, there are approximately 24.37 crores PAN holders in India, however 3.8 crore people file income tax return every year. There have been cases of people owned not more than one but 100 PAN Cards with them. PAN cards in India are mostly used by the citizens as a proof of identity. The government believes that PAN card linking with Aadhaar will curb the tax evasion.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;How Safe Is Your Data In This Panopticon Model Of Mass Surveillance?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In the late 18th century, the well-known English social reformer and jurist Jeremy Bentham wanted to build a ‘panoptican’ for a mass surveillance of the prisoners in England. He advocated designing an institutional building be used to keep an eye on all the jail inmates by a single watchman. Very similarly, India is witnessing the biggest surveillance program ever under the name of single identity and availing benefits of governments’ schemes. Another logic behind enrolment of Aadhaar is the ‘national security’. National security? How can any government ensure national security backing Aadhaar, when international companies have been hired in consortium to collect residents’ biometric and demography details? In 2010, Accenture, Mahindra-Satyam Morpho and L1 identity solutions were pooled in by UIDAI for leveraging de-duplication exercise of Aadhaar and data collection.  L1 Identity Solutions’ top brasses are the former Director CIA George Tenet and former Homeland Security deputy secretary Adm James. With its headquarters in Connecticut, this company is one of the biggest defence contractors specialised in facial recognition and biometrics. L1 Identity Solutions and Accenture work in a close affinity to US intelligence agencies. This is an age of information. Corporate houses and big telecom players are dying to get details of consumers. Obvious are the concerns about the safety and security of the people’s data. It is feared that the database can be used for various marketing and business purposes.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;CIDR, A Single Database Of People’s Data&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Central Identities Data Repository (CIDR) is a data management and storing agency in India which is initiated for the Aadhaar project. It is regulated by the statutory body of Unique Identification Authority of India (UIDAI). This centralised database is probably one of the biggest repositories on this planet.&lt;br /&gt;&lt;br /&gt;In 2010, experts had claimed that more than a thousand government sites and portals were attacked more than 4000 times by China alone in one year. In April 2011, 77 million Sony Playstations and digital media delivery service Qriocity were hacked which resulted into a shutdown of the network for a week. The London School of Economics also reported that a central database of vulnerable to hacking and other terrorist and cyber crime activities. Recently Wannacry Ransomware virus hits the globe. More than 99 countries were affected.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Building one single repository for billions of Aadhaar Card data seems to be a big risk in the most vulnerable country where dat breach is at most.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Data Leak Crisis&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;UIDAI has so far spent approximately 5982.62 crores for more than a billion enrolments of Aadhaar Cards. 1615.34 crores have been spent between the financial year 2015-2016. Centre for Internet and Society, Bengaluru-based organization (CIS) has learned that data of more than 130 million Aadhaar card holders has been leaked from four government websites. They are National Social Assistance Programme, National Rural Employment Guarantee Scheme, Chandranna Bima Scheme and Daily Online Payments Reports of NREGA. It also includes Bank details and other confidential details of millions of residents.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What is Next?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Lok Sabha has passed the Aadhaar Bill as Money Bill. Mukul Rohatgi said in the Supreme Court that according to Article 110 of the constitution, there is use of consolidated funds of India so the bill is a Money bill. Chief Justice Khehar said, “Your object might be good but whether it is a ‘Money Bill’ or not is the question.” Justice Ramana referred to a 2014 judgment passed by the Apex court that courts had no jurisdiction over procedurals matters of legislative.” In response P. Chidambram, the counsel for Jairam Ramesh said, “This petition is not about a procedural matter. There has been substantive infraction.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-indiasaga-may-25-2017-aadhaar-card-one-identity-multiple-disorders'&gt;https://cis-india.org/internet-governance/news/the-indiasaga-may-25-2017-aadhaar-card-one-identity-multiple-disorders&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-26T00:01:54Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/scroll-may-20-2017-anumeha-yadav-will-aadhaar-leaks-be-used-as-an-excuse-to-shut-out-scrutiny-of-welfare-schemes">
    <title>Will Aadhaar leaks be used as an excuse to shut out scrutiny of welfare schemes?</title>
    <link>https://cis-india.org/internet-governance/news/scroll-may-20-2017-anumeha-yadav-will-aadhaar-leaks-be-used-as-an-excuse-to-shut-out-scrutiny-of-welfare-schemes</link>
    <description>
        &lt;b&gt;Aadhaar data of all 23 crore beneficiaries of Direct Benefit Transfer schemes could be publicly available, says a report by Centre for Internet and Society. &lt;/b&gt;
        &lt;div class="article-body" style="text-align: justify; "&gt;
&lt;p&gt;The blog post by Anumeha Yadav was &lt;a class="external-link" href="https://scroll.in/article/837717/will-aadhaar-leaks-be-used-as-an-excuse-to-shut-out-scrutiny-of-welfare-schemes"&gt;published on Scroll &lt;/a&gt;on May 20, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;In the past three months, there have been several &lt;a href="https://scroll.in/article/835546/the-centres-casual-response-to-aadhaar-data-breaches-spells-trouble"&gt;reports&lt;/a&gt; about caches of Aadhaar data being publicly displayed on government websites across the country.&lt;/p&gt;
&lt;p&gt;Personal  information associated with the biometric-based 12-digit unique  identification number, which the government wants every Indian resident  to have, is mandated to be confidential under the Aadhaar Act, 2016.&lt;/p&gt;
&lt;p&gt;But exactly how much Aadhaar data has been compromised by negligent government departments?&lt;/p&gt;
&lt;p&gt;On  May 2, researchers at the non-profit Centre for Internet and Society  released a comprehensive report on the extent of the data breaches. They  documented four government portals using Aadhaar for making payments  and found that sensitive personal and financial information of nearly 13  crore people was being displayed on them, including details of about 10  crore bank accounts.&lt;/p&gt;
&lt;p&gt;Two of the portals, for the Mahatma Gandhi  National Rural Employment Guarantee Act and the National Social  Assistance Programme, belong to the Union rural development ministry.  The others are run by the Andhra Pradesh government for the workers’  insurance scheme Chandranna Bima and for filing Daily Online Payment  Reports of MNREGA.&lt;/p&gt;
&lt;p&gt;The researchers estimated that Aadhaar data of  all 23 crore beneficiaries of the central government’s various Direct  Benefit Transfer schemes could be publicly available. This means nearly a  fifth of India’s population is potentially exposed to irreversible  privacy harm, and financial and &lt;a href="https://scroll.in/article/833230/explainer-aadhaar-is-vulnerable-to-identity-theft-because-of-its-design-and-the-way-it-is-used"&gt;identity fraud&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Unique Identification Authority of India, the agency which manages the Aadhaar database, however, and had earlier &lt;a class="link-external" href="http://timesofindia.indiatimes.com/india/no-leak-biometric-data-safe-says-uidai/articleshow/58486390.cms" rel="nofollow" target="_blank"&gt;denied any breach&lt;/a&gt; of confidential data, has now reportedly said that such a data leak could only be the result of a potentially &lt;a class="link-external" href="http://timesofindia.indiatimes.com/india/provide-hacker-details-outfit-that-claimed-data-leak-told/articleshow/58725132.cms?from=mdr" rel="nofollow" target="_blank"&gt;illegal hack attack&lt;/a&gt; and asked CIS to provide details of the persons involved in the data theft.&lt;/p&gt;
&lt;p&gt;The  rural development ministry, on its part, has changed how its MNREGA  database is accessed, redacting Aadhaar numbers and bank account details  of the beneficiaries. Senior officials of the ministry, however, denied  making systemic changes in the wake of the Centre for Internet and  Society report.&lt;/p&gt;
&lt;p&gt;“The researchers claimed that financial  information of over 10 crore individuals was available publicly, on  pension and MNREGA portals,” said Nagesh Singh, additional secretary in  the ministry, “but bank account details were displayed only on two state  department websites of Andhra Pradesh and Telangana as these states are  far advanced in transparency practices.”&lt;/p&gt;
&lt;p&gt;“For all other states,”  Singh added, “financial information and Aadhaar numbers were removed or  masked last year. For pension schemes we masked the data in June 2016,  and for MNREGA this data was removed in December. Even if any data was  showing, it would only be for the particular block the resident is in,  not for any other state workers.”&lt;/p&gt;
&lt;p&gt;All this was done, he said,  “because the UIDAI communicated to us that this information is sensitive  and should not be displayed and the Aadhaar regulations prohibit  display of Aadhaar numbers”. The Aadhaar (Sharing of Information)  Regulations were introduced last September.&lt;/p&gt;
&lt;figure class="cms-block-image cms-block"&gt;&lt;img src="https://d1u4oo4rb13yy8.cloudfront.net/grvhfkothd-1494862823.png" /&gt;&lt;/figure&gt;
&lt;p&gt;Contrary  to Singh’s claims, social activists outside Andhra Pradesh and  Telangana confirmed they could access bank account details of MNREGA  workers until May 3. Only on May 4, two days after the Centre for  Internet and Society report was released, did the details stop showing  on the Management Information System.&lt;/p&gt;
&lt;p&gt;“We could no longer access  the electronic muster roll, and it started returning error messages,”  said Ashish Ranjan of Jan Jagran Shakti Sangathan, a registered union of  unorganised workers in Araria, Bihar. But until early May, he added,  the Management Information System allowed anyone in any state to access  the personal information of workers, even from other states.&lt;/p&gt;
&lt;p&gt;Activists  and beneficiaries relied on this system for two things. “Several of the  new bank accounts have errors, and accessing this information directly  helped get the discrepancies corrected without going to block level  officials,” Ranjan explained. “It also helped track where the wages of  workers were stuck.”&lt;/p&gt;
&lt;p&gt;When activists asked why the data was no  longer accessible, Ranjan said, rural development department officials  said the Management Information System was changed “on the directions of  the Supreme Court and the Union cabinet secretary.”&lt;/p&gt;
&lt;p&gt;“This has  been the pattern with the MNREGA MIS for long,” Ranjan said, referring  to the information system. “Senior officials change access to a feature  as they wish without clear processes or explanations.”&lt;/p&gt;
&lt;p&gt;James  Herenj, an activist with NREGA Watch, a non-profit which monitors the  implementation of MNREGA in Jharkhand, had the same experience. “Bank  account details were removed from the website last week,” he said, “this  is a problem as we can no longer help MNREGA workers get data entry  errors corrected.”&lt;/p&gt;
&lt;p&gt;The Centre for Internet and Society researchers  too contested the rural development ministry’s claim that Aadhaar  numbers and bank account details were displayed only on Andhra Pradesh  and Telangana government websites. They released a video clip showing  them accessing bank account details and Aadhaar numbers of 801 MNREGA  workers of Agara panchayat in Bengaluru through an internet search on  March 25.&lt;/p&gt;
&lt;figure class="has-subtext cms-block-image cms-block"&gt;&lt;img alt="Screenshot of a Chandigarh Union Territory website displaying Aadhaar information." src="https://scroll-img-process.s3.amazonaws.com/original/ogghbkwxim-1493054055.png" title="Screenshot of a Chandigarh Union Territory website displaying Aadhaar information." /&gt;Screenshot of a Chandigarh Union Territory website displaying Aadhaar information.&lt;/figure&gt;
&lt;h3 class="cms-block-heading cms-block"&gt;&lt;b&gt;Consent, please?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;The &lt;a class="link-external" href="https://uidai.gov.in/images/the_aadhaar_act_2016.pdf" rel="nofollow" target="_blank"&gt;Aadhaar Act&lt;/a&gt;,  2016 requires both government and private agencies to take informed  consent before using a person’s Aadhaar for authentication, but there is  little evidence that consent is sought before Aadhaar is seeded with  personal and financial information.&lt;/p&gt;
&lt;p&gt;Indeed, when the Supreme Court  first permitted the voluntary use of Aadhaar for MNREGA in October  2015, Aadhaar numbers of 2.36 crore workers had already been seeded to  their bank accounts, without the consent of over 99% of them.&lt;/p&gt;
&lt;p&gt;The rural development ministry’s &lt;a class="link-external" href="http://nrega.nic.in/Netnrega/WriteReaddata/Circulars/1669D.O._letter_MGNREGA_dtd_10.06.2016.pdf" rel="nofollow" target="_blank"&gt;data&lt;/a&gt; shows that until June 2016, only about 4,10,000, or less than 1% of the  10.7 crore MNREGA workers, had agreed to Aadhaar-based payments. The  ministry worked around this by organising “consent camps” to  retrospectively collect proof of consent.&lt;/p&gt;
&lt;h3 class="cms-block-heading cms-block"&gt;&lt;b&gt;Poor standards&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;Writing in &lt;i&gt;The Economic Times&lt;/i&gt;,  Ram Sewak Sharma, chairperson of the Telecom Regulatory Authority of  India and former director general of the Unique Identification Authority  of India, &lt;a class="link-external" href="http://blogs.economictimes.indiatimes.com/et-commentary/there-has-been-no-aadhaar-data-leak/" rel="nofollow" target="_blank"&gt;argued&lt;/a&gt; that the reports about “Aadhaar leaks” on government websites failed to  account for provisions of the Right to Information Act, 2005. Section 4  of this law provides for proactive disclosure of government decisions  while Section 8 mandates public authorities to publish all information  on welfare schemes, including details of beneficiaries.&lt;/p&gt;
&lt;p&gt;This has  created a situation, Sharma pointed out, where the transparency law may  require even Aadhaar numbers of beneficiaries to be made public even  though the Aadhaar Act mandates them to be confidential.&lt;/p&gt;
&lt;p&gt;Right  to Information activists, however, said the authorities were anything  but devoted to the transparency law. Crucial information they seek on  the &lt;a href="https://scroll.in/article/833060/how-efficient-is-aadhaar-theres-no-way-to-know-as-the-government-wont-tell"&gt;efficacy of Aadhaar&lt;/a&gt; in welfare schemes is routinely denied.&lt;/p&gt;
&lt;p&gt;“The  government is willfully manipulating information systems to subvert  details of biometric failures,” said Amrita Johri, a member of the  National Campaign for People’s Right to Information and an activist with  the Right to Food campaign, which has petitioned the Delhi High Court  against Aadhaar being mandatory for food rations. “We have come across  instances of ration cardholders being turned back because of  fingerprints being falsely rejected, or network failure, but on the  Delhi government’s website, this is shown as the beneficiaries not  having come to the ration shop at all.”&lt;/p&gt;
&lt;p&gt;“Similarly, the government  claims it has removed bogus ration cards through Aadhaar,” Johri added,  “but they do not show any administrative action if such bogus cards  were really found through Aadhaar even though Section 4 of the RTI Act  requires disclosure of such decisions.”&lt;/p&gt;
&lt;figure class="has-subtext cms-block-image cms-block"&gt;&lt;img alt="Jharkhand Directorate of Social Security displayed Aadhaar numbers, bank accounts numbers and transaction details of over 15 lakh pensioners." src="https://d1u4oo4rb13yy8.cloudfront.net/rzxkohofbe-1493106358.jpg" title="Jharkhand Directorate of Social Security displayed Aadhaar numbers, bank accounts numbers and transaction details of over 15 lakh pensioners." /&gt;Jharkhand  Directorate of Social Security displayed Aadhaar numbers, bank accounts  numbers and transaction details of over 15 lakh pensioners.&lt;/figure&gt;
&lt;p&gt;Johri  is concerned that the “Aadhaar leaks” could become an excuse to deny  people “other useful information”. “When we requested officials to  display how many biometric transaction were not successful, they told us  that in a few days, they will remove the entire MIS as there had  received orders from the food ministry to not display demographic data  associated with Aadhaar,” she said. “But we pointed out that it was the  creation of a single identification number that is the problem. Why  should information on all other government schemes be removed?”&lt;/p&gt;
&lt;p&gt;The  Centre for Internet and Society report points out that while the law  now makes Aadhaar numbers confidential, the government has failed to  specify data masking standards. Section 6 of the Aadhaar Regulations  lays down that no government or private agency should publish Aadhaar  numbers unless they are redacted or blacked out “through appropriate  means”.&lt;/p&gt;
&lt;p&gt;But this is too vague, the report points out. “In some  instances, the first four digits are masked while in others the middle  digits are masked,” Srinivas Kodali, one of the authors of the report,  explained, “which means someone with access to different databases can  use tools for aggregation to reconstruct information hidden or masked in  a particular database.”&lt;/p&gt;
&lt;p&gt;Kodali said that for information other  than Aadhaar numbers, each ministry and department is required to  classify the data that is sensitive, restricted or open, which they have  failed to do. “The National Data Sharing and Accessibility Policy, 2012  requires securing information of sensitive and restricted data but it  does not recommend the ways to do it,” he said. “The standards around  information disclosure and control do not exist, and the Ministry of  Statistics expert committee on this was &lt;a class="link-external" href="http://www.mospi.gov.in/sites/default/files/publication_reports/SDC_Report_30mar17.pdf?download=1" rel="nofollow" target="_blank"&gt;unable to suggest&lt;/a&gt; one last month.”&lt;/p&gt;
&lt;p&gt;“Even  for MNREGA data,” Kodali continued, “the Ministry of Rural  Development’s chief data officer should have classified the financial  information as restricted or open when the database was first created.  But did they do this.”&lt;/p&gt;
&lt;p&gt;Nagesh Singh, the additional secretary,  however said his ministry “does not have a chief data officer to do  this”. “The ministry’s economic advisor is the official responsible for  categorising data and advises us on this,” he added.&lt;/p&gt;
&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/scroll-may-20-2017-anumeha-yadav-will-aadhaar-leaks-be-used-as-an-excuse-to-shut-out-scrutiny-of-welfare-schemes'&gt;https://cis-india.org/internet-governance/news/scroll-may-20-2017-anumeha-yadav-will-aadhaar-leaks-be-used-as-an-excuse-to-shut-out-scrutiny-of-welfare-schemes&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Anumeha Yadav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T07:09:51Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
