<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 221 to 235.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-priyanka-mittal-komal-gupta-march-13-2018-supreme-court-extends-aadhaar-linking-deadline-till-it-passes-verdict"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/outlook-march-26-2018-new-lock-for-eu-digital-mines"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-paypers-march-16-2018-aadhaar-unique-ids-in-india-a-qualified-success"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/white-paper-on-data-protection-and-privacy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/events/roundtable-on-a-i-and-governance-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/data-privacy-forum"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/quantified-identities-as-a-global-phenomenon-analyzing-the-impact-of-biometric-systems-in-our-societies"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-8-2018-from-march-1-only-registered-devices-to-be-used-to-authenticate-aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/a-series-of-op-eds-on-data-protection"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-fundamental-right-to-privacy-a-visual-guide"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/unpacking-data-protection-law-a-visual-representation"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/kaplan-herald-february-5-2018-aadhaar-safety-is-regularly-evolving"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-7-2017-to-protect-data-dont-opt-for-plastic-or-laminated-Aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/cis-submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-priyanka-mittal-komal-gupta-march-13-2018-supreme-court-extends-aadhaar-linking-deadline-till-it-passes-verdict">
    <title>Supreme Court extends Aadhaar linking deadline till it passes verdict</title>
    <link>https://cis-india.org/internet-governance/news/livemint-priyanka-mittal-komal-gupta-march-13-2018-supreme-court-extends-aadhaar-linking-deadline-till-it-passes-verdict</link>
    <description>
        &lt;b&gt;The Supreme Court, however, allowed the government to seek Aadhaar numbers to transfer benefits of government schemes funded from the consolidated fund of India.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Priyanka Mittal and Komal Gupta was &lt;a class="external-link" href="http://www.livemint.com/Politics/5j76JhsKSVEtgGPqAGbSJL/SC-extends-Aadhaar-linking-deadline-for-all-services-till-co.html"&gt;published in Livemint &lt;/a&gt;on March 13, 2018. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p class="S5l" style="text-align: justify; "&gt;The Supreme Court (SC) on Tuesday extended the deadline for linking of Aadhaar with mobile services, opening of new bank accounts and other services until it passes its verdict on a pending challenge to the constitutional validity of such linkages.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The court also noted that Aadhaar could not be made mandatory for issuance of a Tatkal passport, for now.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The extension would be applicable to the schemes of ministries/departments of the Union government as well as those of state governments, the court ruled in an interim order.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img src="http://www.livemint.com/r/LiveMint/Period2/2018/03/14/Photos/Processed/w_aadhaar.jpg" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It was however, clarified that the extension would not be applicable for availing services, subsidies and benefits under Section 7 of the Aadhaar (Targeted Delivery of Financial and other Subsidies, Benefits and Services) Act, 2016.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A Constitution bench comprising Chief Justice Dipak Misra and justices D.Y. Chandrachud, A.K. Sikri, A.M. Khanwilkar and Ashok Bhushan is hearing a challenge to the constitutional basis of the 12-digit unique identification project, which is now likely to conclude after 31 March, the earlier deadline for Aadhaar linking.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Even where Aadhaar hasn’t been mandated by the government, and even though the Supreme Court has extended the deadline for some mandatory linkages, if the software systems used by various governmental and private entities don’t make ‘Aadhaar number’ and authentication optional, then the SC’s orders gets nullified, effectively,” said Pranesh Prakash, policy director at think tank Centre for Internet and Society (CIS).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Similar concerns over the extent of Tuesday’s interim protection were also expressed by the Software Freedom Law Centre (SFLC), an organization working to protect freedom in the digital world. “While the extension is certainly welcome, it is also important to note that there is currently some uncertainty about this extension and how it applies to linkages made mandatory under Section 7 of the Aadhaar Act. If the latest order does indeed exclude Aadhaar linkages mandated under Section 7, a large number of central and state government schemes (such as PDS, LPG, MNREGA and many more) would still need to be linked to Aadhaar by the end of the month, significantly diminishing the relief brought by today’s order, ” said the organization.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The deadline for Aadhaar holders to link their PAN cards for taxation purposes will also be extended until disposal of the case as this linkage was mandated by Section 139AA of the Income Tax Act, 2000 and not Section 7 of the Aadhaar Act,” SFLC added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Last week, attorney general K.K. Venugopal had told the apex court that the centre would consider extending the linking deadline since arguments in the case were likely to proceed beyond the earlier deadline of 31 March.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-priyanka-mittal-komal-gupta-march-13-2018-supreme-court-extends-aadhaar-linking-deadline-till-it-passes-verdict'&gt;https://cis-india.org/internet-governance/news/livemint-priyanka-mittal-komal-gupta-march-13-2018-supreme-court-extends-aadhaar-linking-deadline-till-it-passes-verdict&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-03-17T15:02:10Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/outlook-march-26-2018-new-lock-for-eu-digital-mines">
    <title>New Lock For EU’s Digital Mines</title>
    <link>https://cis-india.org/internet-governance/news/outlook-march-26-2018-new-lock-for-eu-digital-mines</link>
    <description>
        &lt;b&gt;Indian companies dealing with European data wait ­anxiously as the EU pushes in new security rules&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Arindam Mukherjee was &lt;a class="external-link" href="https://www.outlookindia.com/magazine/story/new-lock-for-eus-digital-mines/299927"&gt;published in the Outlook&lt;/a&gt; in March 26, 2018 issue. Elonnai Hickok was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Pretty soon, Indian companies, especially those associated with European companies, will have to walk that extra mile to protect personal data. Come May 25, the European Union (EU) will enact a new set of regulations, called the General Data Protection Regulation (GDPR), which will impose stringent conditions for personal data protection and privacy laws.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What’s more, any violation of or non-compliance with the new regulations will ­attract the strictest of penalties and fines. On an ­average, the new regulations call for up to 4 per cent of a company’s global revenue as penalty.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With the already huge and rapidly ­expanding field of big data play across companies and industries, data protection has come under the limelight and many countries are talking in terms of putting in place stringent rules for personal data protection. The EU will be the first off the block with GDPR, which comes into effect in less than three months. It is expected that following the EU’s ­example, similar regulations will start coming up in other countries as well.&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;The GDPR will replace the 1995 Data Protection Directive ­currently operational ­in the EU.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The GDPR will replace the 1995 Data Protection Directive currently operational in the EU and its regulations will cover all EU member states and citizens. Accordingly, all companies operating in the EU and having customers there, or even having work outsourced from the EU which involves its citizens’ personal data, will have to fall in line and comply.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The rules under GDPR will be relevant for businesses collecting, processing, storing, and sharing data of EU data subjects. This would include all businesses located in India providing services ­directly or indirectly to EU data subjects, as well as Indian companies with a ­pre­sence in Europe.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This has put a lot of Indian IT and ITES companies in a bind given that few Indian companies are in a position to comply with the new GDPR rules and regulations within the given deadline. GDPR neces­sitates that adequate steps have to be taken to secure EU data wherever it is stored or processed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At present, India does not have any data privacy law. However, the government has set up a committee of experts under former Supreme Court Justice B.N. Srikrishna to look into matters related to data protection and privacy in the country. The comm­ittee has so far come up with a draft ­protection bill. But it is ­unlikely that the committee will be able to come out with its final report before the GDPR deadline of May 25.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Huzefa Goawala, who heads GRC, India &amp;amp; SAARC, RSA, says the impact of GDPR will be heavy on India. “A sizeable chunk of Indian companies operate out of the EU including IT/ITeS, manufacturing, financial services and telecom companies,” he adds. “The GDPR will apply to personally identifiable information and internal facing data and external facing data, and organisations will have to protect data on all these fronts. Unfortunately, very few organisations have taken measures to become GDPR compliant at the ground level and are waiting for others to make a move. Larger, tier 1 organisations are in a consultation mode at the moment and are in a preliminary stage of compliance.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to Ernst &amp;amp; Young’s ­forensic data analytics survey (2018) done among Indian companies, 60 per cent of Indian respondents are still not familiar with the GDPR, while only a little over 23 per cent have heard of it but have done nothing about it. “This puts India in a precarious position, especially because it takes time for a company to prepare for GDPR compliance, which involves identifying where all the data resides and taking measures to safeguard it,” says Mukul Shrivastava, partner, Fraud Investigation and Dispute Services, Ernst &amp;amp; Young.  “Many large IT-ITeS companies have sec­ure servers in the EU or on cloud. But a lot of EU data processing is either done in India or is outsourced to India. That data needs to be protected under the GDPR.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Experts say that under GDPR, a company will have to report any breach of data security within 72 hours. In case it fails to do so, stiff penalties will be imposed. With GDPR, the EU wants to stress on how important personally identifiable information is and see what companies are doing to protect it. It calls for deployment of ground level technologies by companies to ensure data security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To ensure full compliance under GDPR will be a difficult task. “It is not possible to check 100 per cent compliance,” says Vijayshankar Na, cyber law and international information security expert.  “There can be multiple versions of personal data in a process. To tap this data and see where all it is flowing in the system will be the toughest part under GDPR. Companies will have to identify all this in order to protect data.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To help Indian companies, India’s IT representative body Nasscom has sought a “data secure” status for its companies from the EU. The EU has given a similar status to American companies, which ensures some concessions for them. Indian companies would be entitled to similar concessions under GDPR if they get the data secure status. But a decision on this is yet to come.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“As India has not attained data secure status, the collection, processing, storing, and sharing of EU data subjects by Indian companies will continue to be through ‘binding corporate rules’,” says Elonnai Hickok, chief operating officer, CIS (Centre For Internet and Society), Bangalore. “Though GDPR will affect any company handling EU data, the IT sector in India could potentially be impacted the most given the amount of business that it does and potentially could do with the region. For instance, a Deloitte report has estimated the outsourcing oppor­tunity of the Indian IT industry with Europe at $45 billion.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Hickok says India’s legal regime around privacy, consisting primarily of section 43A of the IT Act and associated rules, has not been found to be data secure by the EU in past assessments. This means that unless practices are guided by binding corporate rules, the standard of practice in India is lower than required by the previous Data Protection Directive (1995) as well as the GDPR. Some of the potentially challenging requirements in the GDPR will include the requirement for reporting breaches, new standards for consent, ensuring the rights of data subjects including access and correction, portability, erasure and deletion, the right to objection, and, if the need arises,  the right to request human intervention in automated decisions.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What could also hit Indian companies is that the cost of GDPR compliance will be high—there will be costs related to human capital, periodic updates, IT infrastructure around the data (both hardware and software) and setting up cyber security and incident response programs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Europe is an important market for Indian companies,” says Vinayak Godse, senior director, Data Security Council of India (DSCI). “This heightened threshold of privacy may lead to some top line compromise for Indian IT companies. The compliance burden is also bound to increase. The small and mid-size companies looking at the EU as a market may struggle to comply with the new rules.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Indian government is trying to bring some order vis a vis data privacy and the Justice Srikrishna panel is expected to expedite the process. “The Government of India is currently developing a national data protection framework, following the Supreme Court judgment of August 2017 recognising an individual’s privacy as a fundamental right,” says Keshav Dhakad, director &amp;amp; assistant general counsel, corporate, External &amp;amp; Legal Affairs, Microsoft India. “The coming of GDPR will help galvanise the discussion in countries outside of Europe and in India.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As of now though, there is a lot of con­fusion and Indian companies, staring at a tight deadline, are under stress. If they can speed up the process and comply, they will be safe, but if they fail, they could lose business in one of India’s most promising markets.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/outlook-march-26-2018-new-lock-for-eu-digital-mines'&gt;https://cis-india.org/internet-governance/news/outlook-march-26-2018-new-lock-for-eu-digital-mines&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-03-17T13:10:52Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-paypers-march-16-2018-aadhaar-unique-ids-in-india-a-qualified-success">
    <title>Aadhaar unique IDs in India: a qualified success?</title>
    <link>https://cis-india.org/internet-governance/news/the-paypers-march-16-2018-aadhaar-unique-ids-in-india-a-qualified-success</link>
    <description>
        &lt;b&gt;Anshuman Jaswal form Kapronasia shares insights into the security and privacy concerns related to Aadhaar, which are often overlooked&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;&lt;em&gt;This editorial was first published in our &lt;a href="https://www.thepaypers.com/reports/web-fraud-prevention-and-online-authentication-market-guide-2017-2018/r770429" target="_blank"&gt;Web Fraud Prevention and Online Authentication Market Guide 2017/2018&lt;/a&gt;. The Guide is a complete overview of the fraud management, digital identity verification and authentication ecosystem provided by thought leaders in the industry from leading solution providers (both established and new players) to associations and experts.&lt;/em&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Digital India project initiated by the Government of India has made significant headway in the last few years. As part of this project, the Unique Identification Authority of India (UIDAI) has presided over the allotment of unique identification numbers to all Indian residents since 2009. Currently, more than 1.1 billion Indian citizens and residents have Aadhaar IDs, making this the largest exercise of this kind the world has ever seen. There are many potential benefits of such a scheme, but there are also concerns and pitfalls. Besides the advantages, this article also focuses on some of the security and privacy concerns related to Aadhaar, which are often overlooked.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Benefits of Aadhaar&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India is the second most populous nation on earth, with more than 1.3 billion people. Having a unique identification system in place would be a fillip for the government, as it would allow government schemes for poverty alleviation and improvement in health and educational well-being to be better targeted. For example, if a needy person’s bank account is linked to their Aadhaar biometric ID, then it would be easier for the government to provide funds to the individual without using any intermediary. In a country struggling with corruption throughout the government machinery, being able to reach the target audience directly is a significant benefit. Similarly, if both the bank accounts and the tax IDs of individuals are linked to the Aadhaar ID, then the government can trace the income and expenditure of its citizens, thereby obtaining vital information that would allow it to counter money-laundering and the shadow economy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Security challenges are paramount&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Creating a monumental technology infrastructure to meet the requirements of a population of more than 1.3 billion people does not come without its problems. Many people have questioned the wisdom of concentrating so much critical personal information in a government platform that is not known for having a robust security framework. There have been two prominent instances in which the Aadhaar database has been compromised.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://www.ndtv.com/india-news/aadhaar-issuing-authority-uidai-asks-research-firm-cis-to-justify-data-leak-claim-1695574" target="_blank"&gt;In May 2017&lt;/a&gt;, the Bengaluru-based Centre for Internet and Society (CIS) alleged that there had been an illegal breach of the database, and Aadhaar identity numbers of more than 130 million people had been leaked online, along with their dates of birth, addresses, and tax IDs (PAN). It is believed that the revealed information did not include the biometric identification of the people affected, but the breach was significant nonetheless as it exposed millions of people to possible fraud.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The response of the UIDAI was also insightful, because it asked the CIS to reveal on which servers the data was stored, and who might have been responsible for the breach. The UIDAI response quoted the relevant laws, namely sections of the Information Technology Act, 2000 and the Aadhaar Act, underlining the liability under law. The aggressive approach of the UIDAI forced the CIS to retract some of its claims, but then the focus of the discussion was shifted from the loss of critical information to the semantics of the claims of CIS. Instead of calling the breach a “leak”, after receiving the letter from UIDAI, CIS stated that it was merely an “illegal disclosure”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The second instance of a breach occurred between &lt;a href="https://www.medianama.com/2017/08/223-ola-ekyc-aadhaar-police-bangalore/" target="_blank"&gt;January to July 2017&lt;/a&gt;, when an IT expert hacked into the Aadhaar-enabled e-hospital system created under the Digital India project of the Government of India. His intention was to access the central identities data repository of UIDAI for verification of Aadhaar numbers, to be used for an ‘eKYC Verification’ app created by him. The UIDAI database gave him access considering that it was the e-hospital system that was requesting the Aadhaar identity verification. The hack shows that the security protocols of the UIDAI require significant overhaul before it can be trusted to protect the hundreds of millions of digital identities in its database.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Aadhaar and the right to privacy&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Indian constitution does not mention a right to privacy. This has been raised as a serious concern by the critics of Aadhaar, since there is no related privacy framework that outlines how the government can use the Aadhaar information. However, the Supreme Court of India addressed some of these concerns when it stated, in August 2017, that privacy is a fundamental right under the Constitution with reasonable restrictions. It was a landmark decision in the Indian context, since it could affect the way in which the unique identification data is collected, and especially the means for which it is used. For example, in the past, the government has mandated that Aadhaar data to be linked to citizens’ information from bank accounts, tax filings, medical records and phone numbers. Once this is achieved, the government would have unregulated access to such information. There is currently no statute or legal precedent to guard against abuse or to allow an individual to file a complaint.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Supreme Court decision gives encouragement to citizens and institutions that are concerned about the rights of ordinary individuals, while also laying the groundwork for further work that needs to be done to create a robust legal framework in this field.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Read the original blog post published by the &lt;a class="external-link" href="https://www.thepaypers.com/expert-opinion/aadhaar-unique-ids-in-india-a-qualified-success-/772349"&gt;Paypers here&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-paypers-march-16-2018-aadhaar-unique-ids-in-india-a-qualified-success'&gt;https://cis-india.org/internet-governance/news/the-paypers-march-16-2018-aadhaar-unique-ids-in-india-a-qualified-success&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-03-17T12:49:51Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/white-paper-on-data-protection-and-privacy">
    <title>White Paper on Data Protection and Privacy</title>
    <link>https://cis-india.org/internet-governance/news/white-paper-on-data-protection-and-privacy</link>
    <description>
        &lt;b&gt;National Institute of Public Finance and Policy is organizing a roundtable on data protection and privacy in New Delhi on March 8, 2018. Sunil Abraham is participating as a moderator in the session on Rights and Protections. Amber Sinha is also participating as a panelist.&lt;/b&gt;
        &lt;p&gt;Agenda &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/white-paper-on-data-protection-and-privacy/"&gt;here&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/white-paper-on-data-protection-and-privacy'&gt;https://cis-india.org/internet-governance/news/white-paper-on-data-protection-and-privacy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-03-07T14:57:53Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/events/roundtable-on-a-i-and-governance-in-india">
    <title>Roundtable on A.I. and Governance in India</title>
    <link>https://cis-india.org/internet-governance/events/roundtable-on-a-i-and-governance-in-india</link>
    <description>
        &lt;b&gt;The Centre for Internet and Society (CIS), Bangalore is organizing a roundtable on ‘A.I. and  Governance in India' at India Islamic Cultural Centre in New Delhi on March 16, 2018 from 10.00 a.m. to 1.30 p.m. &lt;/b&gt;
        
&lt;p style="text-align: justify;"&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/ai-in-governance"&gt;&lt;strong&gt;Download the Event Report&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify;"&gt;The Roundtable seeks to discuss the various issues and challenges surrounding the design, development and use of AI in Governance (including law enforcement and legal institutions).&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;In line with the changing times, the government, as well as its agencies, have started using technology and digitization to make governance more efficient and accessible. For example,through its flagship project Digital India, the Indian government has undertaken digitization and revamping of systems related to railways, land records, educational resource etc. As the government pursues its digital agenda, artificial intelligence can be a tool for efficiency and decision making. To realize the potential of AI, a clear understanding of the technology and how it can and should be used is necessary. The first step towards a robust AI policy is a sound Information and Communication Technology (ICT) policy that lays the edifice for algorithmic decision making using AI.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Though the adoption of AI in the public sector is still in its nascent stages, the government of India is taking various steps to increase the scale of adoption. The Union Ministry of&amp;nbsp;Commerce and Industry has constituted a task force on AI to facilitate India's economic transformation. This year’s Union Budget also recognised the need for government&amp;nbsp;investment in research, training and skill development in robotics, AI, digital manufacturing, Big Data intelligence and Quantum communications.&amp;nbsp;Though the adoption of AI in the public sector is still in its nascent stages, the government of India is taking various steps to increase the scale of adoption. The Union Ministry of Commerce and Industry has constituted a task force on AI to facilitate India's economic transformation. This year’s Union Budget also recognised the need for government investment in research, training and skill development in robotics, AI, digital manufacturing, Big Data intelligence and Quantum communications.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Our research on the application of AI in Indian governance aims to examine five broad sectors of application: law enforcement, discharge of governmental functions, defense,judicial/administrative decision making, and education. A few of the existing government research initiatives identified by CIS include the Center for Artificial Intelligence and Robotics (CAIR) hosted by the Indian Defense Research and Development Organization which focuses on research and development of ICT solutions for defense, and the Ministry of Finance’s use of geospatial analytics for their economic survey on human settlements. There are already instances where government bodies are using AI, an example being the case of the Indian Police force, which is revamping its investigation procedures by using Big Data and Artificial Intelligence. The Delhi police has already started using data and analytics to control crime. In the field of agriculture too, the Indian government has partnered with Microsoft to use AI to improve crop production.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;While AI can aid governance in numerous ways, there needs to be a system of checks and balances in order to ensure effectiveness, transparency, and accountability. Hence,governance mechanisms must be able to ensure inclusiveness, while minimising the risks that might arise with the use of the technology. Experts have also predicted that, as the government incorporates AI into specific areas of governance- such as service delivery, it will simultaneously need to incorporate it into broader policy structures such as cyber security and the national education framework.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The process of designing a governance ecosystem is a complex one, and AI poses several pre-existing ethical and legal for each application within this ecosystem. The effectiveness ofAI and Machine learning inherently depends on the availability of data, and it is predicted that the most imminent challenge will also involve the same, especially as India becomesincreasingly data dense and the government is entrusted with its citizens’ data. These challenges could range from the collection, storage, and use of data, to having to answerquestions of fairness, safety, and prevention of misuse. This roundtable seeks to deliberate on these questions and more so as to understand how to optimise the use of AI ingovernance for the public interest. In doing so, the roundtable will use preliminary research that CIS has undertaken into the use of AI and governance in India as an entry point into broader discussions on the challenges and benefits and way forward for AI.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify;"&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/ai-governance-and-concept-note"&gt;&lt;strong&gt;Agenda&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/events/roundtable-on-a-i-and-governance-in-india'&gt;https://cis-india.org/internet-governance/events/roundtable-on-a-i-and-governance-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>pranav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-04-20T07:41:21Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/data-privacy-forum">
    <title>Data Privacy Forum</title>
    <link>https://cis-india.org/internet-governance/news/data-privacy-forum</link>
    <description>
        &lt;b&gt;Amber Sinha took part in the Data Privacy Forum organized by the Asian Business Law Institute on February 7, 2018.   The forum was held at the Supreme Court of Singapore.


&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The forum was organised to discuss the findings of a compendium       of country reports on cross border data flow regulations in       countries from Asia and Australia, and the way forward. The forum       had attendance from 18 countries and had about 90 participants.       Elonnai Hickok and Amber Sinha were the reporters for India. Amber was a speaker on the first panel on “Adoption and reform of data protection laws in Asia: how legal systems adapt to global developments and regulatory competition”.&lt;/p&gt;
&lt;p&gt;Click to &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/data-privacy-forum"&gt;read more&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/data-privacy-forum'&gt;https://cis-india.org/internet-governance/news/data-privacy-forum&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-03-01T01:31:56Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/quantified-identities-as-a-global-phenomenon-analyzing-the-impact-of-biometric-systems-in-our-societies">
    <title>Quantified identities as a global phenomenon: analyzing the impact of biometric systems in our societies</title>
    <link>https://cis-india.org/internet-governance/news/quantified-identities-as-a-global-phenomenon-analyzing-the-impact-of-biometric-systems-in-our-societies</link>
    <description>
        &lt;b&gt;A session by Amber Sinha and Leandro Ucciferri of ADC, Argentina at the Internet Freedom Festival to be held in Valencia, Spain in March has been selected. Amber Sinha will make a presentation.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;In the last decade, societies all around the world have seen an exponential growth in the implementation of biometric identification systems, used from the most complex to the most mundane activities that we perform in our daily lives. The research work being carried out by ADC in Argentina, and more broadly in Latin America, allowed us to reach certain observations: In general, public policies related to the use of these types of technologies are carried out with little or no transparency vis-à-vis society; the lack of precise information, which varies country to country, about the technologies and mechanisms being used for the collection, analysis and storage of the biometric data, and the use cases behind such technologies (e.g. the purpose of the data, who will have access to it, if it will be shared and transferred between different public or private bodies); and finally the lack of sufficient legal frameworks to guarantee an adequate treatment of the biometric data collected, both by the State and the private sector.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Additionally, the research by CIS in India and other jurisdictions in Asia shows that biometric identification systems are being portrayed as critical to the use of online services such as e-governance or e-commerce platforms, and facilitates the generation of enormous amounts of transactional data. In India, the biometric identity is envisioned as a ‘cradle to grave’ identity. This unique identifier is key to the integration of different government and private sector databases and poses serious risks of profiling, function creep, lack of accountability and regulation by code.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With this session we aim to address some of the more pressing issues regarding the implementation of biometric technologies in our societies, specifically: a) Threats to bodily integrity and dignity: how biometrics reduce an individual to a number represented through a biometric sequence. b) Irreversible damages in case of breach: unlike passwords, biometrics –such as our fingerprints, our faces, iris or voice– cannot be changed; so once compromised, the damage is irreversible. c) Are biometrics appropriate forms of identifiers? How can we answer questions around uniqueness, discrimination and bias, resolving false positives and false negatives, as well as the change of biometrics over time (e.g. age or medical conditions that may affect our bodies). d) How biometrics are changing our perception of public spaces, specially due to technologies such as facial recognition? e) How are biometric based identification systems reconfiguring the relationship between citizen and state? Together with CIS, we will give a brief overview of the current trends in Latin America and Asia, in order to set the context of the conversation and then allow participants to freely express their own personal/professional expertise to learn about their concerns and experiences in terms of how biometric technologies have affected their day to day lives.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For more info, &lt;a class="external-link" href="https://platform.internetfreedomfestival.org/en/IFF2018/public/schedule/custom/189"&gt;click here&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/quantified-identities-as-a-global-phenomenon-analyzing-the-impact-of-biometric-systems-in-our-societies'&gt;https://cis-india.org/internet-governance/news/quantified-identities-as-a-global-phenomenon-analyzing-the-impact-of-biometric-systems-in-our-societies&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-03-01T00:56:20Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-8-2018-from-march-1-only-registered-devices-to-be-used-to-authenticate-aadhaar">
    <title>From 1 March, only registered devices to be used to authenticate Aadhaar</title>
    <link>https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-8-2018-from-march-1-only-registered-devices-to-be-used-to-authenticate-aadhaar</link>
    <description>
        &lt;b&gt;UIDAI directive to Aadhaar authentication agencies aims to avoid putting citizens’ biometric data at risk&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Komal Gupta was &lt;a class="external-link" href="http://www.livemint.com/Politics/FgXy2gorgyXaGVvpkl4yKN/From-1-Mar-only-registered-devices-to-be-used-to-authentica.html"&gt;published in Livemint&lt;/a&gt; on February 8, 2018.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Unique Identification Authority of India (UIDAI) has directed all Aadhaar authentication agencies to use only registered biometric devices from 1 March to avoid putting residents’ data at risk.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The initial deadline to upgrade these devices was 1 June 2017, but it has been extended several times. The latest is the sixth extension.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UIDAI wants the biometric devices registered with the Aadhaar system for encryption key management. The Aadhaar authentication server can individually identify and validate these devices and manage encryption keys on each registered device.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It is reiterated that to ensure encryption of biometrics of residents at time of capture, it is absolutely essential to use only the registered devices. Any further use of non-registered devices will be putting residents’ privacy at risk,” a UIDAI circular dated 2 February said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In January last year, UIDAI had instructed all the authentication user agencies (AUAs) and authentication service agencies (ASAs) to adhere to its new encryption standards and accordingly upgrade the devices to the new norms.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The AUA is an entity engaged in providing Aadhaar-enabled services. It may be a government, public or a private legal agency registered in India which uses Aadhaar authentication services provided by UIDAI.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The ASA is any entity that transmits authentication requests to the Central Identities Data Repository (CIDR) on behalf of one or more AUAs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Requests from AUAs to extend the timeline has been cited as the reason for delay by UIDAI. The last deadline was 31 January.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Still, UIDAI claims most of the entities have migrated to registered devices and “no further extension will be given in this regard.” Failure to meet the February-end deadline will lead to loss or disruption of services, the circular added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A privacy expert called for better security in the Aadhaar system.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The UIDAI should have gone in for smart cards, which are inherently more secure and would have proven a better basis for a national ID system. Given its choice of biometrics, UIDAI should have required hardware-level encryption — the yet-to-be-specified (Level 1) security standard— from 2010,” said Pranesh Prakash, policy director at think tank Centre for Internet and Society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Making the much-delayed Level 1 mandatory is what UIDAI should be focusing on; sadly, even basic registration and easily-defeated software-level encryption (Level 0) is yet to be made mandatory,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI has been under the scanner over the past few months over charges that random entities have been accessing personal information without the consent of individual Aadhaar number holders.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Last month, UIDAI put in place a two-layer security to reinforce privacy protections for Aadhaar holders—it introduced a virtual identification so that the actual number need not be shared to authenticate their identity. Simultaneously, it further regulated the storage of the Aadhaar numbers within various databases.&lt;br /&gt;There are more than 1.2 billion Aadhaar holders in the country.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-8-2018-from-march-1-only-registered-devices-to-be-used-to-authenticate-aadhaar'&gt;https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-8-2018-from-march-1-only-registered-devices-to-be-used-to-authenticate-aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-02-24T07:59:39Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/a-series-of-op-eds-on-data-protection">
    <title>A Series of Op-eds on Data Protection</title>
    <link>https://cis-india.org/internet-governance/blog/a-series-of-op-eds-on-data-protection</link>
    <description>
        &lt;b&gt;I wrote a short series of three op-eds for Asia Times this week.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The first article "&lt;a class="external-link" href="http://www.atimes.com/user-consent-key-data-protection-india/"&gt;User consent is the key to data protection in India&lt;/a&gt;" examines the debate around consent and the arguments made to discard it. I question the premise of big data exceptionalism, particularly in the absence of any mature governance models which address use regulation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the second article "Robust economic argument for a sound Indian data protection law", I examine the substance of the argument of 'innovation' as a legitimate competing interest with respect to privacy, and questionthe economic arguments made in support of innovation enabled by unregulated access to data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the third article "&lt;a class="external-link" href="http://www.atimes.com/indias-data-protection-needs-graded-enforcement-mechanism/"&gt;India’s data protection law needs graded enforcement mechanism&lt;/a&gt;", I look at the two competing arms of regulation - enforcement and compliance, and how a balance of two is need in India,with an empowered regulator and drawing from the principles from responsive regulation theory.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/a-series-of-op-eds-on-data-protection'&gt;https://cis-india.org/internet-governance/blog/a-series-of-op-eds-on-data-protection&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-02-19T02:08:28Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-fundamental-right-to-privacy-a-visual-guide">
    <title>The Fundamental Right to Privacy - A Visual Guide</title>
    <link>https://cis-india.org/internet-governance/blog/the-fundamental-right-to-privacy-a-visual-guide</link>
    <description>
        &lt;b&gt;Privacy is the ability of an individual or group to seclude themselves, or information about themselves, and thereby express themselves selectively. This visual guide to the story of privacy law in India and the recent judgement of the Puttaswamy v.
Union of India case is developed by Amber Sinha (research and content) and Pooja Saxena (design and conceptualisation).

&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;The Fundamental Right to Privacy - A Visual Guide: &lt;a href="https://cis-india.org/internet-governance/files/amber-sinha-and-pooja-saxena-the-fundamental-right-to-privacy-a-visual-guide/at_download/file"&gt;Download&lt;/a&gt; (PDF)&lt;/h4&gt;
&lt;hr /&gt;
&lt;iframe src="//www.slideshare.net/slideshow/embed_code/key/1MMYCXyxa2YBip" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" height="485" width="595"&gt; &lt;/iframe&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-fundamental-right-to-privacy-a-visual-guide'&gt;https://cis-india.org/internet-governance/blog/the-fundamental-right-to-privacy-a-visual-guide&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    

   <dc:date>2018-02-16T05:31:37Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/unpacking-data-protection-law-a-visual-representation">
    <title>Unpacking Data Protection Law: A Visual Representation</title>
    <link>https://cis-india.org/internet-governance/blog/unpacking-data-protection-law-a-visual-representation</link>
    <description>
        &lt;b&gt;This visual explainer unpacking data protection law was developed by Amber Sinha (research) and Pooja Saxena (design), and published as part of the Data Privacy Week celebrations on the Privacy International blog. Join the conversation on Twitter using #dataprivacyweek.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;Cross-posted from &lt;a href="https://medium.com/@privacyint/unpacking-data-protection-300e51c5f9b5" target="_blank"&gt;Privacy International blog&lt;/a&gt;.&lt;/h4&gt;
&lt;h4&gt;Credits: Flag illustrations, when not created by the authors, are from &lt;a href="http://www.freepik.com/" target="_blank"&gt;Ibrandify / Freepik&lt;/a&gt;.&lt;/h4&gt;
&lt;hr /&gt;
&lt;img src="https://github.com/cis-india/website/blob/master/img/AS-PS_UnpackingDataProtectionLaw_2018_01.png?raw=true" alt="Data protection law systems are usually seen as a dichotomy between the United State of America and the European Union" width="80%" /&gt;
&lt;img src="https://github.com/cis-india/website/blob/master/img/AS-PS_UnpackingDataProtectionLaw_2018_02.png?raw=true" alt="This dichotomy is not an accurate representation of the issue. Today, close to a hundred countries follow the omnibus approach, while less than a dozen, including the US, use the sectoral approach." width="80%" /&gt;
&lt;img src="https://github.com/cis-india/website/blob/master/img/AS-PS_UnpackingDataProtectionLaw_2018_03.gif?raw=true" alt="If too many laws apply to the same actor, compliance becomes difficult. As a result, the sectoral approach to data protection is becoming less relevant." width="80%" /&gt;
&lt;img src="https://github.com/cis-india/website/blob/master/img/AS-PS_UnpackingDataProtectionLaw_2018_04.png?raw=true" alt="Data protection regulation involve interaction between regulators and industry." width="80%" /&gt;
&lt;img src="https://github.com/cis-india/website/blob/master/img/AS-PS_UnpackingDataProtectionLaw_2018_05.gif?raw=true" alt="To be an effective data protection regulator, an entire range of regulatory tools are required, which the regulator can use to reward, support and sanction." width="80%" /&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/unpacking-data-protection-law-a-visual-representation'&gt;https://cis-india.org/internet-governance/blog/unpacking-data-protection-law-a-visual-representation&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-02-15T13:22:00Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/kaplan-herald-february-5-2018-aadhaar-safety-is-regularly-evolving">
    <title>Aadhaar: ‘Safety is regularly evolving‘</title>
    <link>https://cis-india.org/internet-governance/news/kaplan-herald-february-5-2018-aadhaar-safety-is-regularly-evolving</link>
    <description>
        &lt;b&gt;Experts say the new security features will significantly ensure there is no ‘large-scale theft of people‘s identity‘. Alnoor Peermohamed reports.&lt;/b&gt;
        &lt;p class="rbig" style="text-align: justify; "&gt;The blog post was published in &lt;a class="external-link" href="https://kaplanherald.com/2018/02/05/aadhaar-safety-is-regularly-evolving/"&gt;Kaplan Herald &lt;/a&gt;on February 5, 2018.&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="rbig" style="text-align: justify; "&gt;While the introduction of new features such as face authentication, virtual ID, and limited know-your-customer (KYC) by the Unique Identification Authority of India are being seen as reactions to mounting public pressure over the security of Aadhaar, experts, who have helped build the citizen identity system, say these have been in the pipeline for a long time.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pegged to be fully functional by July 1, the new features will make Aadhaar more secure, but that hasn‘t stopped the UIDAI from drawing flak over the recent issue of rogue agents selling demographic data of individuals.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Moreover, the agency‘s handling of the issue has not inspired confidence among the public and security researchers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Experts say for a system of Aadhaar‘s size, security is continually evolving.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Lalitesh Katragadda, former head of Google‘s product centre in India and who also helped build Aadhaar, says as a country we need to understand there‘s ‘no such thing as a 100 per cent secure system‘.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While security gaps will always exist, he says it‘s the UIDAI‘s duty to ensure there‘s no ‘large-scale theft of people‘s identity‘.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to him, the new security features will help significantly in this regard.&lt;/p&gt;
&lt;p class="rbig" style="text-align: justify; "&gt;Face authentication will be another biometric Aadhaar will begin offering to combat the reportedly high failure rates of fingerprint authentication.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The system will use common Webcams to capture photos of individuals and match them with the existing photo on the UIDAI‘s database.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The system will not use any high-end hardware backed facial recognition like the recently launched iPhone X, which the company claims is more accurate than its previous fingerprint authentication technology.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UIDAI will work around this issue by clubbing face authentication with other forms of authentication — fingerprint, iris scan or a one-time password sent to a user‘s mobile phone.&lt;/p&gt;
&lt;p class="rbig" style="text-align: justify; "&gt;While it isn‘t known how exactly the feature will be built into apps relying on Aadhaar authentication, Srikanth Nadhamuni, the former chief technology officer of Aadhaar, envisions a scenario where a photo of an individual could be captured and matched when fingerprint authentication fails, in order to improve the probability of a match.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But even this isn‘t a foolproof plan, some believe.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Your face is again a biometric, and that comes with the same host of issues that is plaguing the other biometrics that have so far been used,” says Sunil Abraham, executive director at the Bengaluru-based think-tank, Centre for Internet and Society.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/kaplan-herald-february-5-2018-aadhaar-safety-is-regularly-evolving'&gt;https://cis-india.org/internet-governance/news/kaplan-herald-february-5-2018-aadhaar-safety-is-regularly-evolving&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-02-07T16:44:50Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-7-2017-to-protect-data-dont-opt-for-plastic-or-laminated-Aadhaar">
    <title>To protect data, don’t opt for plastic or laminated Aadhaar card: UIDAI</title>
    <link>https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-7-2017-to-protect-data-dont-opt-for-plastic-or-laminated-Aadhaar</link>
    <description>
        &lt;b&gt;Unauthorized printing of Aadhaar cards could render the QR (quick response) code dysfunctional or even expose personal data without an individual’s informed consent, UIDAI says.&lt;/b&gt;
        &lt;p&gt;The article by Komal Gupta was &lt;a class="external-link" href="http://www.livemint.com/Politics/5Gr7j4bgNoLRVtf10cjrzK/To-protect-data-dont-opt-for-plastic-or-laminated-Aadhaar.html"&gt;published by Livemint&lt;/a&gt; on February 7, 2017&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="S3l" style="text-align: justify; "&gt;To protect information provided by holders of Aadhaar, the Unique Identification Authority of India (UIDAI) on Tuesday cautioned people against opting for plastic or laminated “smart” cards.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Unauthorized printing of the cards could render the QR (quick response) code dysfunctional or even expose personal data without an individual’s informed consent, it said in a statement on Tuesday.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Besides, opting for plastic or laminated cards opened up the possibility of Aadhaar details (personal sensitive demographic information) being shared with devious elements without the informed consent of holders, the statement added.&lt;/p&gt;
&lt;p&gt;According to UIDAI, the Aadhaar letter sent by it, a cutaway portion or downloaded versions of Aadhaar on ordinary paper or mAadhaar are perfectly valid.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“If a person has a paper Aadhaar card, there is absolutely no need to get his/her Aadhaar card laminated or obtain a plastic Aadhaar card or so called smart Aadhaar card by paying money. There is no concept such as smart or plastic Aadhaar card,” UIDAI chief executive officer Ajay Bhushan Pandey said in a statement.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Printing Aadhaar on a plastic/PVC sheet privately can cost anywhere between Rs50 and Rs300 or more, UIDAI said. It added that a printout of the downloaded Aadhaar card, even in black and white, is as valid as the original Aadhaar letter sent by UIDAI.&lt;/p&gt;
&lt;p&gt;It added that in case a person loses his Aadhaar card, he can download the card free from &lt;i&gt;https://eaadhaar.uidai.gov.in.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pandey asked holders not to share Aadhaar number or personal details with unauthorized agencies for getting the card laminated, or printed on plastic.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The agency also directed unauthorized agencies not to collect Aadhaar information from people, reminding them that collecting such information or unauthorized printing of Aadhaar card is a criminal offence punishable with imprisonment.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“I feel a lot more has to be done by UIDAI. Sadly, by encouraging people to rely on printed Aadhaar ‘cards’, UIDAI is ending up with the worst of both worlds with respect to personal data protection: photocopies of so-called Aadhaar cards/letter are being circulated to facilitate identity fraud as well as the kind of dangerous personal data disclosures that centralized databases enable,” said Pranesh Prakash, policy director at think tank Centre for Internet and Society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Last month, UIDAI put in place a two-layer security to reinforce privacy protections for Aadhaar holders—it introduced a virtual identification so that the actual number need not be shared to authenticate their identity. Simultaneously, it further regulated the storage of the Aadhaar numbers within various databases.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-7-2017-to-protect-data-dont-opt-for-plastic-or-laminated-Aadhaar'&gt;https://cis-india.org/internet-governance/news/livemint-komal-gupta-february-7-2017-to-protect-data-dont-opt-for-plastic-or-laminated-Aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-02-07T01:00:00Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/cis-submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india">
    <title>CIS Submission to the Committee of Experts on a Data Protection Framework for India</title>
    <link>https://cis-india.org/internet-governance/blog/cis-submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india</link>
    <description>
        &lt;b&gt;This submission presents comments by the Centre for Internet and Society, India (“CIS”) on the ‘White Paper of the Committee of Experts on a Data Protection Framework for India’ (“White Paper”) released by the Ministry of Electronics and Information Technology. The White paper was drafted by a Committee of Expert (“Committee”) constituted by the Ministry. CIS has conducted research on the issues of privacy, data protection and data security since 2010 and is thankful for the opportunity to put forth its views. The submission was made on January 31, 2018.&lt;/b&gt;
        &lt;p&gt;&lt;span&gt;The submission is divided into four parts — I. Preliminary, II. Scope and Exemption, III. Grounds of Processing, Obligations of Entities and Individual Rights and IV. Regulation and Enforcement. The submission follows the same the order as adopted by the White Paper.&lt;/span&gt;&lt;/p&gt;
&lt;h4&gt;&lt;/h4&gt;
&lt;p&gt;&lt;b&gt;Please access the &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/data-protection-submission"&gt;full submission here&lt;/a&gt;.&lt;/b&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/cis-submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india'&gt;https://cis-india.org/internet-governance/blog/cis-submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-04-18T16:39:11Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india">
    <title>Submission to the Committee of Experts on a Data Protection Framework for India</title>
    <link>https://cis-india.org/internet-governance/submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india</link>
    <description>
        &lt;b&gt;This submission presents comments by the Centre for Internet and Society, India (“CIS”) on the ‘White Paper of the Committee of Experts on a Data Protection Framework for India’ (“White Paper”) released by the Ministry of Electronics and Information Technology. The White paper was drafted by a Committee of Expert (“Committee”) constituted by the Ministry. CIS has conducted research on the issues of privacy, data protection and data security since 2010 and is thankful for the opportunity to put forth its views. The submission was made on January 31, 2018.&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india'&gt;https://cis-india.org/internet-governance/submission-to-the-committee-of-experts-on-a-data-protection-framework-for-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Data Governance</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Data Protection</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2018-02-05T13:39:00Z</dc:date>
   <dc:type>File</dc:type>
   </item>




</rdf:RDF>
