<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 391 to 405.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-hindu-businessline-march-31-2017-sunil-abraham-its-the-technology-stupid"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/hindu-op-ed-sunil-abraham-march-31-2017-how-aadhaar-compromises-privacy-and-how-to-fix-it"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/ndtv-march-27-2017-discussion-on-aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/openness/news/idrc-open-development-book-authors-workshop"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/financial-times-march-27-2017-amy-kazmin-indias-biometric-id-scans-make-sci-fi-a-reality"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/round-table-on-privacy-and-data-protection-at-nipfp"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/huffington-post-rimin-dutt-ivan-mehta-march-24-2017-why-we-should-all-worry-about-the-mandatory-imposition-of-aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/state-of-digital-rights-in-india-delhi-march-24"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/one-world-indentity-kaelyn-lowmaster-march-17-2017-privacy-concerns-multiply-for-aadhaar-indias-national-biometric-identity-registry"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-guardian-march-21-2017-no-id-no-benefits"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-statesman-smriti-sharma-vasudeva-march-14-2017-evms-how-transparent-is-the-indian-election-process"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/first-post-march-16-nimish-sawant-nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/richa-mishra-hindu-businessline-march-13-2017-the-12-digit-conundrum"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-wire-amber-sinha-february-21-2017-can-the-judiciary-upturn-the-lok-sabha-speakers-decision-on-aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/vocativ-joshua-kopstein-india-private-companies-citizens-biometric-data"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-hindu-businessline-march-31-2017-sunil-abraham-its-the-technology-stupid">
    <title>It’s the technology, stupid</title>
    <link>https://cis-india.org/internet-governance/blog/the-hindu-businessline-march-31-2017-sunil-abraham-its-the-technology-stupid</link>
    <description>
        &lt;b&gt;Eleven reasons why the Aadhaar is not just non-smart but also insecure.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was &lt;a class="external-link" href="http://www.thehindubusinessline.com/blink/cover/11-reasons-why-aadhaar-is-not-just-nonsmart-but-also-insecure/article9608225.ece"&gt;published in Hindu Businessline&lt;/a&gt; on March 31, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar is insecure because it is based on biometrics. Biometrics is surveillance technology, a necessity for any State. However, surveillance is much like salt in cooking: essential in tiny quantities, but counterproductive even if slightly in excess. Biometrics should be used for targeted surveillance, but this technology should not be used in e-governance for the following reasons:&lt;br /&gt;&lt;br /&gt;One, biometrics is becoming a remote technology. High-resolution cameras allow malicious actors to steal fingerprints and iris images from unsuspecting people. In a couple of years, governments will be able to identify citizens more accurately in a crowd with iris recognition than the current generation of facial recognition technology.&lt;br /&gt;&lt;br /&gt;Two, biometrics is covert technology. Thanks to sophisticated remote sensors, biometrics can be harvested without the knowledge of the citizen. This increases effectiveness from a surveillance perspective, but diminishes it from an e-governance perspective.&lt;br /&gt;&lt;br /&gt;Three, biometrics is non-consensual technology. There is a big difference between the State identifying citizens and citizens identifying themselves to the state. With biometrics, the State can identify citizens without seeking their consent. With a smart card, the citizen has to allow the State to identify them. Once you discard your smart card the State cannot easily identify you, but you cannot discard your biometrics.&lt;br /&gt;&lt;br /&gt;Four, biometrics is very similar to symmetric cryptography. Modern cryptography is asymmetric. Where there is both a public and a private key, the user always has the private key, which is never in transit and, therefore, intermediaries cannot intercept it. Biometrics, on the other hand, needs to be secured during transit. The UIDAI’s (Unique Identification Authority of India overseeing the rollout of Aadhaar) current fix for its erroneous choice of technology is the use of “registered devices”; but, unfortunately, the encryption is only at the software layer and cannot prevent hardware interception.&lt;br /&gt;&lt;br /&gt;Five, biometrics requires a centralised network; in contrast, cryptography for smart cards does not require a centralised store for all private keys. All centralised stores are honey pots — targeted by criminals, foreign States and terrorists.&lt;br /&gt;&lt;br /&gt;Six, biometrics is irrevocable. Once compromised, it cannot be secured again. Smart cards are based on asymmetric cryptography, which even the UIDAI uses to secure its servers from attacks. If cryptography is good for the State, then surely it is good for the citizen too.&lt;br /&gt;&lt;br /&gt;Seven, biometrics is based on probability. Cryptography in smart cards, on the other hand, allows for exact matching. Every biometric device comes with ratios for false positives and false negatives. These ratios are determined in near-perfect lab conditions. Going by press reports and even UIDAI’s claims, the field reality is unsurprisingly different from the lab. Imagine going to an ATM and not being sure if your debit card will match your bank’s records.&lt;br /&gt;&lt;br /&gt;Eight, biometric technology is proprietary and opaque. You cannot independently audit the proprietary technology used by the UIDAI for effectiveness and security. On the other hand, open smart card standards like SCOSTA (Smart Card Operating System for Transport Applications) are based on globally accepted cryptographic standards and allow researchers, scientists and mathematicians to independently confirm the claims of the government.&lt;br /&gt;&lt;br /&gt;Nine, biometrics is cheap and easy to defeat. Any Indian citizen, even children, can make gummy fingers at home using Fevicol and wax. You can buy fingerprint lifting kits from a toystore. To clone a smart card, on the other hand, you need a skimmer, a printer and knowledge of cryptography.&lt;br /&gt;&lt;br /&gt;Ten, biometrics undermines human dignity. In many media photographs — even on the @UIDAI’s Twitter stream — you can see the biometric device operator pressing the applicant’s fingers, especially in the case of underprivileged citizens, against the reader. Imagine service providers — say, a shopkeeper or a restaurant waiter — having to touch you every time you want to pay. Smart cards offer a more dignified user experience.&lt;br /&gt;&lt;br /&gt;Eleven, biometrics enables the shirking of responsibility, while cryptography requires a chain of trust.&lt;br /&gt;&lt;br /&gt;Each legitimate transaction has repudiable signatures of all parties responsible. With biometrics, the buck will be passed to an inscrutable black box every time things go wrong. The citizens or courts will have nobody to hold to account.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The precursor to Aadhaar was called MNIC (Multipurpose National Identification Card). Initiated by the NDA government headed by Atal Bihari Vajpayee, it was based on the open SCOSTA standard. This was the correct technological choice.&lt;br /&gt;&lt;br /&gt;Unfortunately, the promoters of Aadhaar chose biometrics in their belief that newer, costlier and complex technology is superior to an older, cheaper and simpler alternative.&lt;br /&gt;&lt;br /&gt;This erroneous technological choice is not a glitch or teething problem that can be dealt with legislative fixes such as an improved Aadhaar Act or an omnibus Privacy Act. It can only be fixed by destroying the centralised biometric database, like the UK did, and shifting to smart cards.&lt;br /&gt;&lt;br /&gt;In other words, you cannot fix using the law what you have broken using technology.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-hindu-businessline-march-31-2017-sunil-abraham-its-the-technology-stupid'&gt;https://cis-india.org/internet-governance/blog/the-hindu-businessline-march-31-2017-sunil-abraham-its-the-technology-stupid&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>sunil</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Biometrics</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-07T12:53:21Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/hindu-op-ed-sunil-abraham-march-31-2017-how-aadhaar-compromises-privacy-and-how-to-fix-it">
    <title>How Aadhaar compromises privacy? And how to fix it?</title>
    <link>https://cis-india.org/internet-governance/blog/hindu-op-ed-sunil-abraham-march-31-2017-how-aadhaar-compromises-privacy-and-how-to-fix-it</link>
    <description>
        &lt;b&gt;Aadhaar is mass surveillance technology. Unlike targeted surveillance which is a good thing, and essential for national security and public order – mass surveillance undermines security. And while biometrics is appropriate for targeted surveillance by the state – it is wholly inappropriate for everyday transactions between the state and law abiding citizens. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The op-ed was published in the &lt;a class="external-link" href="http://www.thehindu.com/opinion/op-ed/is-aadhaar-a-breach-of-privacy/article17745615.ece"&gt;Hindu&lt;/a&gt; on March 31, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;When assessing a technology, don't ask - “what use is it being put to today?”. Instead, ask “what use can it be put to tomorrow and by whom?”. The original noble intentions of the Aadhaar project will not constrain those in the future that want to take full advantage of its technological possibilities.  However, rather than frame the surveillance potential of Aadhaar in a negative tone as three problem statements - I will propose three modifications to the project that will reduce but not eliminate its surveillance potential.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Shift from biometrics to smart cards:&lt;/b&gt;&lt;span&gt; In January 2011, the Centre for Internet and Society had written to the parliamentary finance committee that was reviewing what was then called the “National Identification Authority of India Bill 2010”. We provided nine reasons for the government to stop using biometrics and instead use an open smart card standard. Biometrics allows for identification of citizens even when they don't want to be identified. Even unconscious and dead citizens can be identified using biometrics. Smart cards, on the other hand, require pins and thus citizens' conscious cooperation during the identification process. Once you flush your smart cards down the toilet nobody can use them to identify you. Consent is baked into the design of the technology. If the UIDAI adopts smart cards, we can destroy the centralized database of biometrics just like the UK government did in 2010 under Theresa May's tenure as Home Secretary. This would completely eliminate the risk of foreign governments, criminals and terrorists using the biometric database to remotely, covertly and non-consensually identify Indians.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Destroy the authentication transaction database:&lt;/b&gt;&lt;span&gt; The Aadhaar Authentication Regulations 2016 specifies that transaction data will be archived for five years after the date of the transaction. Even though the UIDAI claims that this is a zero knowledge database from the perspective of “reasons for authentication”, any big data expert will tell you that it is trivial to guess what is going on using the unique identifiers for the registered devices and time stamps that are used for authentication.  That is how they put Rajat Gupta and Raj Rajratnam in prison. There was nothing in the payload ie. voice recordings of the tapped telephone conversations – the conviction was based on meta-data. Smart cards based on open standards allow for decentralized authentication by multiple entities and therefore eliminate the need for a centralized transaction database.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Prohibit the use of Aadhaar number in other databases:&lt;/b&gt;&lt;span&gt; We must, as a nation, get over our obsession with Know Your Customer [KYC] requirements. For example, for SIM cards there is no KYC requirement is most developed countries. Our insistence on KYC has only resulted in retardation of Internet adoption, a black market for ID documents and unnecessary wastage of resources by telecom companies. It has not prevented criminals and terrorists from using phones. Where we must absolutely have KYC for the purposes of security, elimination of ghosts and regulatory compliance – we must use a token issued by UIDAI instead of the Aadhaar number itself. This would make it harder for unauthorized parties to combine databases while at the same time, enabling law enforcement agencies to combine databases using the appropriate authorizations and infrastructure like NATGRID. The NATGRID, unlike Aadhaar, is not a centralized database. It is a standard and platform for the express assembly of sub-sets of up to 20 databases which is then accessed by up to 12 law enforcement and intelligence agencies.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;To conclude, even as a surveillance project – Aadhaar is very poorly designed. The technology needs fixing today, the law can wait for tomorrow.&lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/hindu-op-ed-sunil-abraham-march-31-2017-how-aadhaar-compromises-privacy-and-how-to-fix-it'&gt;https://cis-india.org/internet-governance/blog/hindu-op-ed-sunil-abraham-march-31-2017-how-aadhaar-compromises-privacy-and-how-to-fix-it&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>sunil</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Surveillance</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-04-01T07:00:06Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/ndtv-march-27-2017-discussion-on-aadhaar">
    <title>क्‍या आधार पर जल्दबाज़ी में है सरकार?</title>
    <link>https://cis-india.org/internet-governance/news/ndtv-march-27-2017-discussion-on-aadhaar</link>
    <description>
        &lt;b&gt;Amber Sinha took part in a discussion on Aadhaar aired by NDTV on March 27, 2017. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;एक जुलाई 2017 से आयकर रिटर्न भरने और पैन नंबर के लिए आधार नंबर देना  अनिवार्य हो जाएगा. बिना आधार के अब आयकर रिटर्न नहीं भरा जा सकेगा. जिस  किसी के पास पैन कार्ड है उसे एक जुलाई तक आधार नंबर देना होगा. अगर ऐसा  नहीं करेंगे तो पैन कार्ड अवैध हो जाएगा. माना जाएगा कि आपके पास पैन कार्ड  या पैन नंबर नहीं है. आयकर फार्म और पैन नंबर में आधार को अनिवार्य किये  जाने से कई सवाल फिर से उठे हैं. 2009 से लेकर 2017 के बीच आधार के इस्तमाल  को लेकर, इसके लीक होने से लेकर अनिवार्य किये जाने के ख़तरे को लेकर कई  बहसें सुनी, पचासों लेख पढ़े. दूसरी तरफ हमने समाज में देखा कि आधार को लेकर  ग़ज़ब का उत्साह है.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="external-link" href="http://www.ndtv.com/video/shows/prime-time/is-the-government-in-a-hurry-on-aadhaar-452934?relatedviaplayer"&gt;Watch the Video on NDTV&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/ndtv-march-27-2017-discussion-on-aadhaar'&gt;https://cis-india.org/internet-governance/news/ndtv-march-27-2017-discussion-on-aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-29T03:52:08Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/openness/news/idrc-open-development-book-authors-workshop">
    <title>IDRC - Open Development Book - Authors' Workshop</title>
    <link>https://cis-india.org/openness/news/idrc-open-development-book-authors-workshop</link>
    <description>
        &lt;b&gt;Sumandro Chattapadhyay participated in the authors' workshop organized by the International Development Research Centre (IDRC) and the Centre for Innovation in Learning and Teaching at the University of Cape Town in South Africa on March 11 and 12, 2017. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The workshop gathered the contributers to an upcoming book by IDRC on open development. This volume will continue, extend, and reflect back on the previously published "Open Development: Networked Innovations in International Development" (Edited by Matthew L. Smith and Katherine M. A. Reilly). Elonnai Hickok, Gus Hosein from Privacy International and Sumandro Chattapadhyay are writing a chapter for this book that is tentative titled as "Six Principles for Openness and Privacy in the Time of Data Revolution".&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This chapter will bring together personal and institutional experiences from policy advocacy and grounded practice in open data and privacy across the “South” and the “West” to discuss a potential framing of these two concerns as not opposing but complimentary rights. We locate this discussion of openness and privacy within the context of the ongoing “data revolution”, and propose six principles towards engaging with present and future challenges in generation and management of, innovation with, and reliance on data as an economic and social resource.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/openness/news/idrc-open-development-book-authors-workshop'&gt;https://cis-india.org/openness/news/idrc-open-development-book-authors-workshop&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Openness</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-29T03:47:14Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/financial-times-march-27-2017-amy-kazmin-indias-biometric-id-scans-make-sci-fi-a-reality">
    <title>India’s biometric ID scans make sci-fi a reality</title>
    <link>https://cis-india.org/internet-governance/news/financial-times-march-27-2017-amy-kazmin-indias-biometric-id-scans-make-sci-fi-a-reality</link>
    <description>
        &lt;b&gt;I have been thinking about my fingerprints and the secrets that may lie within my eyes — and whether I want to share them with the Indian government. I may not however have a choice.
&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Amy Kazmin was published in the &lt;a class="external-link" href="https://www.ft.com/content/46dcb248-0fcb-11e7-a88c-50ba212dce4d"&gt;Financial Times&lt;/a&gt; on March 27, 2017. Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;India has the world’s largest domestic biometric identification system, known as Aadhaar. Since 2010, the government has collected fingerprints and iris scans from more than 1bn residents, and each has been assigned a 12-digit &lt;a class="external-link" href="https://uidai.gov.in/"&gt;identification number&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The scheme is championed by Nandan Nilekani, the billionaire co-founder of IT company Infosys. It was initially conceived to ensure poor Indians received subsidised food entitlements and other welfare benefits that were previously siphoned off by unscrupulous intermediaries. It was also seen as offering poor Indians, many of whom lack birth certificates, with a portable ID that can be used anywhere in the country.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Until now, obtaining an Aadhaar number was voluntary, though most Indians enrolled without hesitation as they see its potential benefits. But New Delhi is now enlisting Aadhaar, which means “foundation” or “base” in Hindi, in more than just welfare schemes. This would mean sharing one’s biometric details isn’t really optional any more despite a Supreme Court ruling that it should be “purely voluntary”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Last week, the government issued a rule requiring an Aadhaar number for filing tax returns, ostensibly to improve tax compliance. It has also decided that all cell phone numbers must be linked to an Aadhaar number by 2018. Even Indian Railways has plans to demand Aadhaar from those booking train tickets online.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What was once touted as an initiative to improve delivery of welfare suddenly now seems like the foundation of a surveillance state — and I admit the prospect of putting my own biometrics in the database leaves me uneasy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As a US citizen, I’ve never had to give my biometric data to my government. Domestically, fingerprints are only taken from criminal suspects, or applicants for government jobs, though I know foreign citizens are fingerprinted on arrival.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To me, the idea of sharing eye scans evokes the dystopian Hollywood film, Minority Report, which depicts a near future in which optical-recognition cameras allow the authorities to identify anyone in any public place. The hero on the run, played by Tom Cruise, has an illegal eye transplant to avoid detection.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In recent days, many Indian academics and activists have raised concerns about Aadhaar data security, the lack of privacy rules and the absence of any accountability structure if data are misused.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Biometrics is being weaponised," says Sunil Abraham, executive director of the Bangalore-based Centre for Internet and Society. "What you need to be worried about is that someone will clean out your bank account or frame you in a crime," he says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pratap Bhanu Mehta, director of the Centre for Policy Research, has written of the “conversion of Aadhaar from a tool of citizen empowerment to a tool of state surveillance and citizen vulnerability”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I call &lt;a class="external-link" href="https://www.ft.com/content/058c4b48-d43c-11e6-9341-7393bb2e1b51"&gt;Mr Nilekani&lt;/a&gt;, of whose honourable intentions I have no doubt. After leaving Infosys in 2009, he spent five years in government, working to get Aadhaar off the ground. He says he is “extremely offended” when his project is accused of being part of a surveillance society, a narrative he says is “completely misrepresenting” the project. “I can steal your fingerprint off your glass. I don’t need this fancy technology,” he says. “Surveillance is far better done by following my phone, or when I use a map to order a taxi: the map knows where I am. Our internet companies know where you are.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But in a society known for ingenious means of bypassing rules, such as having multiple taxpayer ID cards to aid evasion, Mr Nilekani says biometric authentication of individuals can bring discipline and reduce cheating. “It’s like you are creating a rule-based society,” he says, “it’s the transition that is going on right now.”  I hang up, hardly reassured. To me, it seems clear that in India, as in so many places these days, Big Brother is increasingly watching.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/financial-times-march-27-2017-amy-kazmin-indias-biometric-id-scans-make-sci-fi-a-reality'&gt;https://cis-india.org/internet-governance/news/financial-times-march-27-2017-amy-kazmin-indias-biometric-id-scans-make-sci-fi-a-reality&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Biometrics</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-28T02:45:28Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/round-table-on-privacy-and-data-protection-at-nipfp">
    <title>Round Table on Privacy and Data Protection at NIPFP </title>
    <link>https://cis-india.org/internet-governance/news/round-table-on-privacy-and-data-protection-at-nipfp</link>
    <description>
        &lt;b&gt;National Institute of Public Finance &amp; Policy organized a round-table on privacy and data protection on March 24, 2017 in New Delhi. &lt;/b&gt;
        &lt;p&gt;Click to see the &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/nipfp-round-table-on-privacy-and-data-protection"&gt;agenda&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/round-table-on-privacy-and-data-protection-at-nipfp'&gt;https://cis-india.org/internet-governance/news/round-table-on-privacy-and-data-protection-at-nipfp&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-27T16:02:59Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/huffington-post-rimin-dutt-ivan-mehta-march-24-2017-why-we-should-all-worry-about-the-mandatory-imposition-of-aadhaar">
    <title>Why We Should All Worry About The Mandatory Imposition Of Aadhaar</title>
    <link>https://cis-india.org/internet-governance/news/huffington-post-rimin-dutt-ivan-mehta-march-24-2017-why-we-should-all-worry-about-the-mandatory-imposition-of-aadhaar</link>
    <description>
        &lt;b&gt;It appears that with each passing day, the government is linking an increasing number of benefits and government services to the 12-digit biometric-based Aadhaar number for Indians, despite growing concerns around its data privacy and security.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Rimin Dutt and Ivan Mehta was published by &lt;a class="external-link" href="http://www.huffingtonpost.in/2017/03/24/why-we-should-all-worry-about-the-mandatory-imposition-of-aadhaa_a_22009826/"&gt;Huffington Post&lt;/a&gt; on March 24, 2017. Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar, which collects among other information, citizens' iris scans and fingerprints and stores them into a centralised database for a prolonged time with only loose guidelines and no pre-existing laws to ensure the privacy of that data, is now linked to no less than 38 government schemes, including the government's latest directive –- that Aadhaar become mandatory for tax filing and securing PAN numbers -- introduced by Finance Minister Arun Jaitley earlier this week.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Jaitley openly admitted on Wednesday in the Parliament that the government, in effect, would be forcing people to get Aadhaar in an effort to increase tax compliance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar's use, by no means, is restricted to government agencies alone. A  growing number of private financial institutions are now fulfilling  their "Know Your Customer" or e-KYC formalities by making Aadhaar  compulsory. The government is also in the &lt;a href="http://economictimes.indiatimes.com/news/economy/policy/aadhaar-based-kyc-likely-across-financial-sector/articleshow/57800209.cms" target="_blank"&gt;process&lt;/a&gt; of making Aadhaar the basis of all financial transactions.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While the timing of the government's aggressive push of Aadhaar, in itself, is raising eyebrows among &lt;a href="https://scroll.in/article/832503/what-explains-the-desperation-to-make-aadhaar-mandatory-for-tax-returns-after-july-1-2017" target="_blank"&gt;political observers&lt;/a&gt;, there are some serious concerns about this unique experiment that deserve stronger scrutiny.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Why disregard the Supreme Court?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In making Aadhaar mandatory for filing taxes and securing core  taxpayer identity, the government has openly gone against a Supreme  Court order from last year that explicitly stated that the Aadhaar Card  scheme is "purely voluntary" and cannot be made mandatory until the  court has decided on this.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The government has defended its move, saying it is allowed to do so  under the Aadhaar (Targeted Delivery of Financial and Other Subsidies,  Benefits and Services) Act 2016.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, as Gopal Krishna, a member of the Citizens Forum for Civil Liberties, &lt;a target="_blank"&gt;writes&lt;/a&gt; in Business Today, the passage of the Act by the Parliament "does not  automatically imply that any agency can make UID/Aadhaar compulsory  disregarding the Supreme Court's orders."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to Krishna, in doing so, the government is "clearly  stepping beyond" the mandate of the Aadhaar Act, and also acting in  contempt of the Parliament, according to him.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In addition, if tax evasion was the driving factor behind the move,  it begs the question — wouldn't forcing people to get Aadhaar actually  do the opposite by adding another layer of hassle?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Indeed, tax experts have noted how this requirement may hinder tax  collection. Archit Gupta, Founder &amp;amp; CEO ClearTax.com, a tax service  provider &lt;a href="http://www.huffingtonpost.in/2017/03/22/budget-part-ii-here-are-the-highlights-of-the-sweeping-changes_a_21905740/" target="_blank"&gt;told &lt;/a&gt;&lt;i&gt;HuffPost India, "&lt;/i&gt;The  [Aadhaar] announcement is likely to be a dampener to tax filers,  specially first-timers ... FY 2016-17 filing is expected to see a large  number of first-time filers due to demonetisation efforts, and this move  may make them more guarded."&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Why not strengthen PAN?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The government already has an extensive mandate for the Permanent  Account Number (PAN) cards, which are required to validate several  important services or for undertaking transactions such as buying and  selling property or jewellery worth over ₹2 lakhs. Last year, the  government, in fact, said that the National Pension System (NPS) scheme  would accept PAN cards over Aadhaar cards to validate new customers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On Wednesday, however, Jaitley said PAN cards have been misused by  certain people to evade taxes, and there are reports that Aadhaar may  become the ultimate authenticating document. However, the continued and  growing use of PAN along with Aadhaar adds an extra layer of formalities  for citizens to access government services, which are their  constitutionally guaranteed rights.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;How safe is Aadhaar anyway?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Depending on who you talk to, the safety concerns of Aadhaar come up  as a pressing issue, especially in the wake of a recent security  incident when the Unique Identification Authority of India initiated  police action against entities associated with Axis Bank including  Suvidhaa Infoserve and e-sign provider eMudhra, which had allegedly &lt;a href="http://www.livemint.com/Industry/IKgrYL5pg3eTgfaP253XKI/Aadhaar-data-breach-triggers-privacy-concerns.html" target="_blank"&gt;engaged &lt;/a&gt;in unauthorised authentication and impersonation by illegally storing Aadhaar biometrics.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Earlier this month, in a separate incident, security researcher  Srinivas Kodali warned Indian authorities of a website that was leaking  Aadhaar demographic data of over five lakh minors, as well as the  existence several parallel databases that had key identification data  linked to Aadhaar, &lt;i&gt;Scroll &lt;/i&gt;&lt;a href="https://scroll.in/article/830589/under-the-right-to-information-law-aadhaar-data-breaches-will-remain-a-state-secret" target="_blank"&gt;reported.&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the absence of any privacy laws in India, these security concerns have assumed even greater significance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI, the authority behind Aadhaar, has &lt;a href="https://uidai.gov.in/images/news/Press_Statement_06032017.pdf" target="_blank"&gt;maintained &lt;/a&gt;the  technology behind Aadhaar is robust and that it uses advanced  encryption to transmit and store data. It specifically denied that any  breach of centralised data took place in the Axis Bank incident, saying  the case was an isolated incident.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, in a rather ironic twist in the Aadhaar Act, which itself  contains no provisions to address privacy concerns, any legal action  against any misuse or theft of Aadhaar data can only be initiated by  UIDAI, leaving citizens with no legal recourse should a breach occur.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;That represents an obvious conflict of interest as it gives exclusive  power to the very authority that is responsible for the security and  confidentiality of identity information and authentication records, PRS  Legislative Research, has noted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In addition, the controversial Aadhaar Act contains several other  inherent dangers such as the potential to profile citizens based on the  linking of other databases with Aadhaar by studying patterns of  behaviour.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Techniques such as running computer programmes across datasets for  pattern recognition can be used for various purposes such as detecting  potential illegal activities...However, these can also lead to  harassment of innocent individuals who get identified incorrectly as  potential threats," noted PRS Legislative.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There are currently no safeguards to prevent inappropriate profiling,  instances of which could increase as more and more private  organisations link their data to Aadhaar, and potentially exploit data  for&lt;a href="https://scroll.in/article/824874/what-happens-to-privacy-when-companies-have-your-aadhaar-number" target="_blank"&gt; commercial purposes&lt;/a&gt; without the consent of citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The US, in comparison, has laws in place that require agencies that  collects data to submit an annual report to US Congress on all such data  mining activities.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Other unresolved concerns&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;There are several other concerns related to the widespread use of  Aadhaar card and the power it is afforded under the Aadhar act. The act  allows UIDAI to collect biometric information beyond iris and  fingerprint scans, for example, to include other bio-data such as DNA,  noted PRS.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The act also allows private agencies to use Aadhaar, which  contradicts an earlier stated objective of the scheme that sought to  restrict the use of Aadhaar for only government expenditures.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"It allows private persons to use Aadhaar as a proof of identity for  any purpose. This provision will enable private entities such as,  airline, telecom, insurance, real estate etc. companies, to require  Aadhaar as a proof of identity for availing their services," PRS has  noted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There's also the worrying prospect of Aadhaar being used as a  surveillance tool by the government, instead of an e-governance  technology, Sunil Abraham, executive director of research organisation,  Centre for Internet and Society, &lt;a href="http://www.thehindubusinessline.com/specials/india-file/aadhaar-the-12digit-conundrum/article9582271.ece" target="_blank"&gt;told &lt;/a&gt;the &lt;i&gt;The Hindu Business Line, &lt;/i&gt;adding&lt;i&gt; &lt;/i&gt;biometrics only make citizens transparent to the state and not the state transparent to citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"We warned the government six years ago, but they ignored us," said Abraham.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Krishna has a more dire &lt;a href="http://www.businesstoday.in/current/economy-politics/will-aadhaar-cause-death-of-civil-rights/story/248331.html" target="_blank"&gt;warning:&lt;/a&gt; "The JAM Trinity -- Jan Dhan Yojana, Aadhaar and mobile numbers -- may  well be a fish bait to trap unsuspecting citizens into the world's  biggest transnational biometric database to turn them into subjects  under surveillance forever in the name of a set of welfare and  anti-poverty policies.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What has been done to address the security concerns?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;It is unclear what the government or UIDAI may have done in the wake  of the security incident to upgrade its systems. According to an expert &lt;i&gt;HuffPost Post India &lt;/i&gt;talked to, many third party apps that are using Aadhar data may not be screened or audited for security, which is a huge worry.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kodali told HuffPost India that Aadhaar has potential design issues when it comes to information security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"By design it allows anyone store information of the Aadhaar holder  through [application programming interface]. This is creating many  parallel databases with Aadhaar as a key," he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;He notes that security is an afterthought for many institutions and companies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"UIDAI and the architects of Aadhaar do not accept that data can be a  liability instead of an asset," he said. "The mandatory nature of  Aadhaar without the right infrastructure and skilled workforce is not  just a cyber security issue, but a national security issue."&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;When will India get privacy laws?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;No one quite knows. But there's a growing call for a need for strict  privacy laws, given the move towards digital financial transactions and  growing e-commerce use. Most advanced economies including the US, the  UK, France, Australia and New Zealand have &lt;a href="http://www.pcquest.com/no-your-aadhaar-data-is-not-secure/" target="_blank"&gt;enacted privacy laws.&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, in India, the right to privacy still doesn't exist despite  it being recognised by even the UN charter of human rights. Article 12  of the Universal Declaration of Human Rights states, "No one shall be  subjected to arbitrary interference with his privacy, family, home or  correspondence, nor to attacks upon his honour and reputation. Everyone  has the right to the protection of the law against such interference or  attacks."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The potential for cyber criminals to misuse citizen data isn't lost on even prominent IT industry experts.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Recently, the chief of IT industry body Nasscom R Chandrashekhar &lt;a href="http://tech.firstpost.com/news-analysis/nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber-367183.html" target="_blank"&gt;told&lt;/a&gt; &lt;i&gt;PTI &lt;/i&gt;that  personal data of online consumers can never be fully secure,  emphasising the need for strict consumer protection laws. "More than 3  million credit card data details were misused recently. Let us face it,  these kind of security breaches will take place. There is nothing called  fully perfect security in IT," he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To be sure, Aadhaar has been lauded by several prominent experts and  economists, and it is, undoubtedly, an ambitious project to potentially  aid financial inclusion for a large population that has historically  been outside of a formal financial services net. India also has one of  the lowest tax compliance rates, making tax collection a priority for  the government.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Recently, Paul Romer, World Bank's chief economist &lt;a href="https://qz.com/933907/paul-romer-on-aadhaar-world-banks-top-economist-says-indias-controversial-id-program-should-be-a-model-for-other-nations/" target="_blank"&gt;told &lt;/a&gt;&lt;i&gt;Bloomberg, "&lt;/i&gt;The  system in India is the most sophisticated that I've seen ... It's the  basis for all kinds of connections that involve things like financial  transactions. It could be good for the world if this became widely  adopted."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But given the sensitivity of citizen biometrics data and potential  for misuse, the government ought to be held accountable for its proper  use and ensure enough safeguards are put in place before its imposition  on each citizen.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;&lt;b&gt; &lt;/b&gt;&lt;/i&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/huffington-post-rimin-dutt-ivan-mehta-march-24-2017-why-we-should-all-worry-about-the-mandatory-imposition-of-aadhaar'&gt;https://cis-india.org/internet-governance/news/huffington-post-rimin-dutt-ivan-mehta-march-24-2017-why-we-should-all-worry-about-the-mandatory-imposition-of-aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-27T15:02:10Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/state-of-digital-rights-in-india-delhi-march-24">
    <title>State of Digital Rights in India (Delhi, March 24)</title>
    <link>https://cis-india.org/internet-governance/news/state-of-digital-rights-in-india-delhi-march-24</link>
    <description>
        &lt;b&gt;The Centre for Communication Governance at National Law University, Delhi and the Internet Freedom Foundation, in association with Access Now, are hosting a discussion on The State of Digital Rights in India on March 24, 2017 (Friday) from 6.00 pm onwards at Lecture Room-I, India International Centre- Annexe, New Delhi. Japreet Grewal and Sumandro Chattapadhyay will participate in the panel discussions.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;Registration: &lt;a href="https://www.eventbrite.com/e/state-of-digital-rights-in-india-tickets-33001450226"&gt;Eventbrite&lt;/a&gt;&lt;/h4&gt;
&lt;hr /&gt;
&lt;p&gt;March 24, 2017 marks the two year anniversary of the landmark Shreya Singhal judgment. This was a very significant ruling on freedom of speech and expression and occupies an important place in the Supreme Court’s discourse on civil liberties. The judgment traces out the contours of free speech on the Internet in India and unequivocally holds that the right to freedom of expression provided under Article 19(1)(a) applies to speech over the Internet, making it clear that this is a medium-neutral right.&lt;/p&gt;
&lt;p&gt;The event aims to shed some light on this key judgment and discuss ongoing discussions regarding our civil liberties and freedoms online before courts and the Parliament. We would also like to take this opportunity to discuss some of the other pressing issues like Network Neutrality, Internet shutdowns, Privacy and User Security which need immediate attention and engagement of our democratic institutions. We hope to formulate effective strategies which will further shape the legal and policy framework in India, and facilitate better collaborative efforts between stakeholders.&lt;/p&gt;
&lt;p&gt;We hope to bring together everyone who contributed to the judgment, and those who do work connected with it, so that we may build on it to seek a better legal framework to protect online speech and to discuss the threats surrounding digital rights and how best build on the foundations of the judgment.&lt;/p&gt;
&lt;p&gt;We would be grateful if you could take out some time on Friday evening (6PM) and be a part of this important discussion. The discussion will be followed by dinner and an Open Bar for an Open Internet, which will start from 9.00 pm at the Annexe Court in the India International Centre - Annexe. In case you are unable to attend the seminar, please do join us for dinner!&lt;/p&gt;
&lt;p&gt;Featuring:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;A keynote address on our online freedoms and policymaking, by Shri Tathagata Satpathy (Member of Parliament, Lok Sabha)&lt;/li&gt;
&lt;li&gt;A legal panel analysing the legacy of the Shreya Singhal v. Union of India judgment&lt;/li&gt;
&lt;li&gt;Beyond Shreya Singhal: A conversation with women on the future of our digital rights&lt;/li&gt;
&lt;li&gt;Briefings on the state of digital rights in our courts and in Parliament&lt;/li&gt;
&lt;li&gt;A conversation on the path ahead for our civil liberties and digital rights community&lt;/li&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/ul&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/state-of-digital-rights-in-india-delhi-march-24'&gt;https://cis-india.org/internet-governance/news/state-of-digital-rights-in-india-delhi-march-24&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Japreet Grewal and Sumandro Chattapadhyay</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Civil Society</dc:subject>
    
    
        <dc:subject>Security</dc:subject>
    
    
        <dc:subject>Digital Rights</dc:subject>
    

   <dc:date>2017-03-27T13:21:20Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/one-world-indentity-kaelyn-lowmaster-march-17-2017-privacy-concerns-multiply-for-aadhaar-indias-national-biometric-identity-registry">
    <title>Privacy concerns multiply for Aadhaar, India’s national biometric identity registry</title>
    <link>https://cis-india.org/internet-governance/news/one-world-indentity-kaelyn-lowmaster-march-17-2017-privacy-concerns-multiply-for-aadhaar-indias-national-biometric-identity-registry</link>
    <description>
        &lt;b&gt;The largest and most sophisticated biometric identity system of any country in the world, India’s Aadhaar, is sparking new fears that the personal data it stores on more than 1.1 billion people could be vulnerable to exploitation.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Kaelyn Lowmaster was published by &lt;a class="external-link" href="https://oneworldidentity.com/2017/03/17/privacy-concerns-multiply-aadhaar-indias-national-biometric-identity-registry/"&gt;One World Identity&lt;/a&gt; on March 17, 2017, Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar, which translates to “foundation” in Hindi, is a unique 12-digit code tied to citizens’ &lt;a href="https://oneworldidentity.com/2017/02/02/indias-aadhaar-id-program-improve-biometric-security-new-bionetra-iris-partnership/"&gt;biometric data&lt;/a&gt; and personal information. The system was launched in 2009 in an effort  to extend social services to India’s millions of unregistered citizens,  and to cut down on welfare benefit “leakage” resulting from an opaque  and often corrupt bureaucracy.&lt;/p&gt;
&lt;blockquote class="td_box_right td_quote_box" style="text-align: justify; "&gt;
&lt;h5&gt;Constructing a centralized repository of biometric data on nearly a  fifth of the world’s population has raised serious concerns among  privacy advocates.&lt;/h5&gt;
&lt;p&gt; &lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;The government has also looked to Aadhaar data to underpin mobile  payment transfer platforms, which have become crucial for cashless  transactions during the country’s &lt;a href="https://www.forbes.com/sites/wadeshepard/2016/12/14/inside-indias-cashless-revolution/#d38bb294d124"&gt;demonetization push&lt;/a&gt; over past year.&lt;/p&gt;
&lt;blockquote class="pullquote" style="text-align: justify; "&gt;But constructing a centralized repository of biometric data on nearly  a fifth of the world’s population has raised serious concerns among  privacy advocates, who cite several vulnerabilities both with the  Aadhaar system and the Modi administration’s planned expansion.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;Despite this, recent metrics indicate that Aadhaar has been  enormously successful in achieving those goals. Though the program is  theoretically voluntary, &lt;a href="http://timesofindia.indiatimes.com/india/99-of-indians-over-18-now-have-aadhaar/articleshow/56820818.cms"&gt;more than 99%&lt;/a&gt; of Indian adults are now enrolled. Over &lt;a href="http://www.economist.com/news/business/21712160-nearly-all-indias-13bn-citizens-are-now-enrolled-indian-business-prepares-tap"&gt;three billion&lt;/a&gt; individual identity verifications have been conducted, and some reports indicate that the Indian government is saving &lt;a href="http://economictimes.indiatimes.com/news/economy/finance/aadhaar-id-saving-indian-govt-about-1-billion-per-annum-world-bank/articleshow/50575112.cms"&gt;a billion dollars per year&lt;/a&gt; now that welfare subsidies can be paid to citizens directly through Aadhaar-verified fund transfers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Prime Minister Narendra Modi has ambitions to broaden the system even  further, seeking to use Aadhaar as the gateway for accessing government  programs ranging from public education to subsidized cooking gas, as  well as partnering with private companies to offer services facilitated  by the Aadhaar database.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Concerns, however, remain. One primary worry is that India’s legal  framework for information security is still weak and fragmented, despite  government &lt;a href="http://pib.nic.in/newsite/mberel.aspx?relid=158849"&gt;assurances&lt;/a&gt; that Aadhaar biometrics have never been misused or stolen.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Despite this, recent metrics indicate that Aadhaar has been enormously  successful in achieving those goals. Though the program is theoretically  voluntary, &lt;a href="http://timesofindia.indiatimes.com/india/99-of-indians-over-18-now-have-aadhaar/articleshow/56820818.cms"&gt;more than 99%&lt;/a&gt; of Indian adults are now enrolled. Over &lt;a href="http://www.economist.com/news/business/21712160-nearly-all-indias-13bn-citizens-are-now-enrolled-indian-business-prepares-tap"&gt;three billion&lt;/a&gt; individual identity verifications have been conducted, and some reports indicate that the Indian government is saving &lt;a href="http://economictimes.indiatimes.com/news/economy/finance/aadhaar-id-saving-indian-govt-about-1-billion-per-annum-world-bank/articleshow/50575112.cms"&gt;a billion dollars per year&lt;/a&gt; now that welfare subsidies can be paid to citizens directly through Aadhaar-verified fund transfers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Prime Minister Narendra Modi has ambitions to broaden the system even  further, seeking to use Aadhaar as the gateway for accessing government  programs ranging from public education to subsidized cooking gas, as  well as partnering with private companies to offer services facilitated  by the Aadhaar database.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Concerns, however, remain. One primary worry is that India’s legal  framework for information security is still weak and fragmented, despite  government &lt;a href="http://pib.nic.in/newsite/mberel.aspx?relid=158849"&gt;assurances&lt;/a&gt; that Aadhaar biometrics have never been misused or stolen.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img class="td-animation-stack-type0-1 aligncenter wp-image-30798" height="447" src="https://oneworldidentity.com/wp-content/uploads/2017/03/Adhar_DSCN4543-1024x768-2-300x225.jpg" width="596" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“There are no regulations in India on safeguards over and procedures  for the collection, processing, storage, retention, access, disclosure,  destruction, and anonymization of sensitive personal information by any  service provider,” according to a 2016 &lt;a href="http://pubdocs.worldbank.org/en/655801461250682317/WDR16-BP-Aadhaar-Paper-Banerjee.pdf"&gt;World Bank report&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A &lt;a href="http://www.livemint.com/Opinion/C4NOYNosPTZuRGjgH7UMLP/Indias-privacy-nonlaw.html"&gt;patchwork of rules&lt;/a&gt; outlining “reasonable security practices and procedures” for personal  data has accumulated since Aadhaar was launched, but there is no  codified law outlining how data in the system must be secured, or what  penalties exist for potential leaks, fraud or misuse.&lt;/p&gt;
&lt;blockquote class="pullquote" style="text-align: justify; "&gt;“Imagine a situation where the police (are) secretly capturing the iris data of protesters and then identifying them through their biometric records” – Sunil Abraham, executive director of the Centre for Internet and Society in Bangalore&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;This regulatory gap poses a particularly acute risk now  that the   government has begun offering companies and app developers  support for   starting new businesses that use Aadhaar data. Through a  new  initiative  called &lt;a href="https://indiastack.org/about/"&gt;IndiaStack&lt;/a&gt;,   the  administration is providing open program interfaces for companies   in  fintech, healthcare, and other areas to integrate Aadhaar-based    transactions into their business platforms. While IndiaStack’s terms of    use explicitly state that user consent is required for any information    sharing between service providers and the Aadhaar database, doubts    remain about the integrity of the network infrastructure and the lack of    clarity surrounding acceptable information sharing and storing    protocols.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another source of concern is the risk that Aadhaar information could be  leveraged by the government itself for political purposes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Maintaining a central database is akin to getting the keys of every  house in Delhi and storing them at a central police station,” Sunil  Abraham, executive director of the Centre for Internet and Society in  Bangalore, &lt;a href="http://in.reuters.com/article/india-aadhaar-privacy-fears-idINKCN0WI2JW"&gt;told&lt;/a&gt; Reuters. “It is very easy to capture iris data of any individual with  the use of next generation cameras. Imagine a situation where the police  (are) secretly capturing the iris data of protesters and then  identifying them through their biometric records.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Further stoking fears of federal overreach, the Modi administration has &lt;a href="http://www.thehindu.com/news/national/Supreme-Court-finds-govt.-defying-its-order-on-Aadhaar/article14999391.ece"&gt;attempted&lt;/a&gt; to make Aadhaar registration mandatory in certain sectors, violating a  Supreme Court ruling from October 2015 that enrollment must remain  voluntary.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Still, the benefits of building on the Aadhaar identity system appear to  be outweighing the risks for now, and the system is gathering momentum  worldwide. The World Bank is &lt;a href="http://www.livemint.com/Politics/UEQ9o8Eo8RiaAaNNMyLbEK/Aadhaar-goes-global-finds-takers-in-Russia-and-Africa.html"&gt;helping market&lt;/a&gt; the Aadhaar model abroad, and Russia, Morocco, Tunisia, and Algeria  have all expressed interest in instituting national biometric identity  programs of their own. Microsoft is already &lt;a href="http://economictimes.indiatimes.com/industry/tech/software/microsoft-to-launch-skype-with-aadhaar-seeding-for-banking/articleshow/57299071.cms"&gt;on board&lt;/a&gt;, and Google is &lt;a href="http://economictimes.indiatimes.com/opinion/interviews/google-in-talks-with-government-to-partner-for-aadhaar-upi-caesar-sengupta-vice-president-next-billion-users-at-google/articleshow/54556320.cms"&gt;negotiating&lt;/a&gt; ways to get involved.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar may indeed live up to is potential and become the global  standard for universal legal identity, but until India can manage to  create more robust mechanisms to protect citizens’ personal data, their  security could remain uncertain.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/one-world-indentity-kaelyn-lowmaster-march-17-2017-privacy-concerns-multiply-for-aadhaar-indias-national-biometric-identity-registry'&gt;https://cis-india.org/internet-governance/news/one-world-indentity-kaelyn-lowmaster-march-17-2017-privacy-concerns-multiply-for-aadhaar-indias-national-biometric-identity-registry&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-22T14:38:52Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-guardian-march-21-2017-no-id-no-benefits">
    <title>No ID, no benefits: thousands could lose lifeline under India’s biometric scheme</title>
    <link>https://cis-india.org/internet-governance/news/the-guardian-march-21-2017-no-id-no-benefits</link>
    <description>
        &lt;b&gt;Controversial Aadhaar card restricts fundamental rights, argue critics, limiting access to free school meals and exposing 1 billion people to privacy risks.&lt;/b&gt;
        &lt;p&gt;The article was published in the &lt;a class="external-link" href="https://www.theguardian.com/global-development/2017/mar/21/no-id-no-benefits-thousands-could-lose-lifeline-india-biometric-scheme-aadhaar-card"&gt;Guardian&lt;/a&gt; on March 21, 2017. Sumandro Chattapadhyay was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img alt="An Aadhaar biometric identity card, which will be mandatory for Indians to access many essential government services and benefits." class="responsive-img maxed" src="https://i.guim.co.uk/img/media/cfb15b17bf824d857a561f3167b26793cb2e5583/0_136_4000_2400/master/4000.jpg?w=300&amp;amp;q=55&amp;amp;auto=format&amp;amp;usm=12&amp;amp;fit=max&amp;amp;s=5253b0eb088c65cfdc3b013302b0eb76" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="discreet"&gt;An Aadhaar biometric identity card, which will be mandatory for Indians  to access many essential government services and benefits. Photograph: Bloomberg/Getty Images&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Hundreds of thousands of people in &lt;a class="u-underline" href="https://www.theguardian.com/world/india"&gt;India&lt;/a&gt; could be left without essential government services and benefits –  including free school meals and uniforms, food subsidies and pensions –  under new rules that make access to more than three dozen state-funded  schemes conditional on showing identification.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Over the past month, citizens have been notified that they have to prove their identity with a biometric ID, known as an &lt;a class="u-underline" href="https://uidai.gov.in/"&gt;Aadhaar card&lt;/a&gt;,  to be eligible to use various services. Booking railway tickets online,  applying for some jobs, and getting fuel subsidies will also be  dependent on showing the controversial card.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar cards were introduced by the Indian government in 2009, and  rolled out by prime minister Narendra Modi in 2014. They record personal  biometric data, including fingerprints and eye scans, which the  government says allows it to ensure that welfare services are being  delivered to those who really need them, and saving billions of rupees  by reducing welfare fraud.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The &lt;a class="u-underline" href="https://uidai.gov.in/"&gt;Unique Identification Authority of India&lt;/a&gt; (UIDAI), which oversees the Aadhaar programme, says that more than 1.13  billion people have been enrolled on an official database. But  activists say that hundreds of thousands of Indians and migrants are  still undocumented and could miss out on their fundamental rights  because of the new rules.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“What if a Facebook account was necessary to log in to the internet,  and what if Facebook was owned by the government of the US?” asked  Sumandro Chattapadhyay, research director at the Centre for Internet and  Society (CIS), a thinktank with offices in Bangalore and Delhi. “We are  building a system that will decide whether a child will eat or not on  an afternoon based on [the] quality of internet connectivity and  cleanliness of the child’s thumbprint.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Chattapadhyay argued that Aadhaar, which is effectively being forced  upon Indians, and which is used increasingly by private companies,  exposed more than a billion people to huge privacy risks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The  Aadhaar ID is being connected to digital communications via sim card  registration, it is being connected to financial transactions via bank  accounts, and all Indian citizens are being forced to enrol for it  against the threat of losing out from welfare services,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The potential of unmonitored and unregulated use of such linked data  by the private sector is massive. It does not matter if the Indian  state will finally go ahead with implementing this system or not. The  fact that [it] is considering such a system is scary enough.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nanu Bhasin, spokesperson at the ministry of women and child  development, confirmed that the order to link Aadhaar to government  schemes had come directly from the Modi government. “There are leakages  in the system,” she said. “This will plug leakages.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Bhasin said Aadhaar was now mandatory: “You have to take it, it is  necessary. You cannot take the right to a benefit if you don’t have the  Aadhaar card.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;She said she did not know if those who did not want to enrol  in the scheme because of potential privacy risks would still be able to  receive benefits. “You have bank accounts, there you give all your  details, everything. Why make a fuss [about privacy] for Aadhaar?” she  said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One of the most contentious new rules introduced this month, and  coming into force in July, requires children to show Aadhaar cards to  get free school meals. The notice led to a media storm in India, where  malnutrition rates are high and nearly &lt;a class="u-underline" href="http://www.worldbank.org/en/news/feature/2013/05/13/helping-india-combat-persistently-high-rates-of-malnutrition"&gt;60 million children&lt;/a&gt; are underweight.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On 7 March the government said &lt;a class="u-underline" href="http://pib.nic.in/newsite/PrintRelease.aspx?relid=158933"&gt;alternative forms of ID would be accepted&lt;/a&gt; for free school meals where people did not yet have Aadhaar cards, and  urged schools and childcare centres to enrol all attendees.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Activists argue that setting any barriers to free school meals is  unethical and unconstitutional. Ambarish Rai, national convenor of the  Right to Education Forum, said: “This is a very insensitive decision of  the government. How can you make it mandatory? It is a clear-cut  violation of the Right to Education Act 2009.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Compulsory identification could deter school attendance if children  struggle to get free school meals or uniforms, said Swati Narayan,  visiting research scholar from the LSE and food activist. “India’s  school meal programme covers almost 100 million children – the largest  in the world. Instead of creating unnecessary barriers, the focus should  be on how to improve these modest meals by adding eggs, fruit and  nutritious foods to the menu.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Glitches in the Aadhaar system have already led to reports of people  being unfairly denied government subsidies. In February, the news  website Scroll &lt;a class="u-underline" href="https://scroll.in/article/829071/in-jharkhand-compulsory-biometric-authentication-for-rations-sends-many-away-empty-handed"&gt;recorded a number of people in the state of Jharkhand being denied rice subsidies&lt;/a&gt; because of problems with Aadhaar card machines.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The constitutional validity of the government’s new orders is  currently being debated in court, with questions raised as to whether  the Indian parliament can restrict fundamental rights enshrined in the  constitution, and whether the government has the power to force citizens  to enrol.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In 2015, a supreme court order had ruled that the scheme was purely  voluntary, and that it could not become mandatory with a court ruling.  But in 2016, parliament passed the &lt;a class="u-underline" href="https://www.google.co.uk/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=6&amp;amp;ved=0ahUKEwi_2pSUx-XSAhUMjpAKHV1bDLIQFgg7MAU&amp;amp;url=https%3A%2F%2Fuidai.gov.in%2Fimages%2Fthe_aadhaar_act_2016.pdf&amp;amp;usg=AFQjCNHDmJKdO8jdfGZJKLKRJQpHdf1Frw&amp;amp;sig2=ds56EfksGTNm2PpBKqhjtA&amp;amp;cad=rja"&gt;Aadhaar Act&lt;/a&gt;, which allowed the government to require identification for government services.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Khagesh Jha, a lawyer and activist, argued that the act was  fundamentally unconstitutional. “Rescued children, children who have  been trafficked or those who have been forced into child labour – [you]  can’t expect them to hold an Aadhaar card or documents like a birth  certificate. Right to education is a fundamental right, and is protected  by the core of the constitution. It cannot be challenged by any other  document.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI, the agency overseeing Aadhaar, issued a statement saying the government had &lt;a class="u-underline" href="http://pib.nic.in/newsite/PrintRelease.aspx?relid=158849"&gt;made savings of more than 490bn rupees&lt;/a&gt; (£6bn) in the past two and a half years, thanks to schemes linking  government benefits to Aadhaar. It added that during the past seven  years, there had been no report of a breach or leak of residents’ data.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-guardian-march-21-2017-no-id-no-benefits'&gt;https://cis-india.org/internet-governance/news/the-guardian-march-21-2017-no-id-no-benefits&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-22T14:27:25Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-statesman-smriti-sharma-vasudeva-march-14-2017-evms-how-transparent-is-the-indian-election-process">
    <title>EVMs: How transparent is the Indian election process?</title>
    <link>https://cis-india.org/internet-governance/news/the-statesman-smriti-sharma-vasudeva-march-14-2017-evms-how-transparent-is-the-indian-election-process</link>
    <description>
        &lt;b&gt;Electronic Voting Machines (EVMs) have become a bone of contention after the results of the Assembly elections in five states were declared last Saturday and the BSP president Mayawati alleged tampering. The Congress party and the Aam Aadmi Party (AAP) have called for a probe into her allegation. Social media too is abuzz with messages and videos showing how the machines can be allegedly manipulated to sway the votes in favour of a particular candidate.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Smriti Sharma Vasudeva was &lt;a href="http://www.thestatesman.com/india/evms-how-transparent-is-the-indian-election-process-1489512231.html"&gt;published         in the Statesman&lt;/a&gt; on March 14, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Overnight, several videos on Whatsapp have surfaced wherein people can be seen explaining the "mechanism" on how to alter the votes polled for a candidate in another candidate's favour. Several similar posts and articles are doing the rounds on Facebook.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;BBC added fuel to the fire when it shared a 2010       article on how 'US "Scientists" hack India Electronic Machines' .       The article details how scientists at a US university say they       have developed a technique to hack into Indian electronic voting       machines. While the article was posted on the BBC website a day       after the election results were declared, it drew considerable       flak from users on Facebook who criticised the website for its       'irresponsible' act of sharing an article with a "click bait"       headline just to grab eyeballs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Amid all this frenzy, the Election Commission of       India has issued statements clarifying how the entire process is       transparent and fool proof and tampering with the EVMs is a       far-fetched thing given the checks and balances in place. For       instance, the EVMs undergo the process of randomisation wherein       which machine will go to which constituency and to which booth is       not known to anyone till the last moment. Similarly, before the       polling starts, mock polling takes place in the presence of       representatives of all the political parties and then each of       these machines are tested and a satisfactory report is generated       and only after that polling begins.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, all these checks and balances still do       not ensure a fool proof system if experts are to be believed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash, Policy Director for The Centre       for Internet and Society, a non-profit organisation that       undertakes interdisciplinary research on internet and digital       technologies from policy and academic perspectives, said: "The       Electronic Voting Machines used in India are the simplest, with no       large operating system requirements and are not networked. Thus,       from a software design perspective, these are really good and the       chances of these being tampered with are bleaker. However it       doesn't mean these are fool proof. Most of the developed countries       do not trust these machines and these are definitely not secure       enough for democratic elections.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"While there are many advantages of using EVMs in       the electoral process over the traditional ballot papers, still       there are many ways in which one can tamper with these machines       without any technical ingenuity. The best way is to make use of       the EVMs and ensure that the Voter Verified Paper Audit Trail       (VVPAT) are effectively utilised to make it an overall effective       system".&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Recently, the Supreme Court had mandated that       VVPAT machines should be used in all the polls and thus the       Election Commission had installed VVPAT machines in several       constituencies. However, not sure of the efficacy of this system,       the Election Commission had itself raised apprehensions regarding       performance of the paper-trail machine, which gives a receipt to       the voter, verifying the vote went in favour of the candidate       against whose name the button was pressed on the electronic voting       machine.a&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-statesman-smriti-sharma-vasudeva-march-14-2017-evms-how-transparent-is-the-indian-election-process'&gt;https://cis-india.org/internet-governance/news/the-statesman-smriti-sharma-vasudeva-march-14-2017-evms-how-transparent-is-the-indian-election-process&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Digital India</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-17T01:57:19Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/first-post-march-16-nimish-sawant-nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber">
    <title>Nasscom chief saying full data protection isn’t possible should wake us from our digital slumber</title>
    <link>https://cis-india.org/internet-governance/news/first-post-march-16-nimish-sawant-nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber</link>
    <description>
        &lt;b&gt;Considering India is rapidly moving towards a digital economy, the hurdles not withstanding, data and identity security are topics which have to be taken very seriously. Since the demonetisation, a large part of the population who would never bother with digital transactions has suddenly come online. But there is no such thing as complete security of personal data, according to Nasscom chief R Chandrashekhar.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This was published by &lt;a class="external-link" href="http://tech.firstpost.com/news-analysis/nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber-367183.html"&gt;First Post&lt;/a&gt; on March 16, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Attending the World Consumer Rights Day, R Chandrashekhar  said that personal data of online consumers cannot be completely secure  and stressed on the need to have strict enforcement of consumer  protection laws. Speaking to &lt;i&gt;PTI,&lt;/i&gt; Chandrashekhar said, “More  than 3 million credit card data details were misused recently. Let us  face it, these kind of security breaches will take place. There is  nothing called fully perfect security in IT.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;It’s high time we call a spade, a spade&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;img alt="Image: PIB" class="wp-image-367245 size-full" height="360" src="http://tech.firstpost.com/wp-content/uploads/2017/03/RChandrasekhar_PIB380.jpg" width="640" /&gt;&lt;br /&gt;&lt;/b&gt;R Chandrashekhar, President Nasscom. Image: PIB&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Coming from the head of Nasscom, this announcement pertaining to security is very important. According to Chandrashekhar one cannot expect complete cyber security, but there are definitely ways in which such attacks and incidents can be minimised. He very rightly said that that protecting the online consumer data, specially looking at how rapidly e-commerce is growing in the country, is of prime importance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One cannot help but agree with Chandrashekhar, specially considering the fact India &lt;a href="http://tech.firstpost.com/news-analysis/demonetisation-privacy-laws-need-to-be-in-place-before-giving-the-biggest-push-to-digital-transactions-348478.html"&gt;&lt;b&gt;does not have a privacy law ecosystem&lt;/b&gt;&lt;/a&gt; that is present in countries such as the US and the UK, where online consumer protection is taken very seriously. &lt;a href="http://tech.firstpost.com/news-analysis/facebook-asked-to-delete-whatsapp-user-data-in-germany-over-data-protection-law-infringement-337708.html"&gt;&lt;b&gt;Germany&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://www.google.co.in/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=5&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0ahUKEwjljYHpzNrSAhUkSI8KHa6oB_MQFgg2MAQ&amp;amp;url=http%3A%2F%2Ftech.firstpost.com%2Fnews-analysis%2Ffrance-fines-google-150000-euros-over-data-privacy-216266.html&amp;amp;usg=AFQjCNE15FPlAi9rR5yCXNzS_hnua81QAw&amp;amp;sig2=GVGgF_cxGNhXo-SJhLo4Gg&amp;amp;bvm=bv.149397726,d.c2I" rel="nofollow"&gt;&lt;b&gt;other EU nations&lt;/b&gt;&lt;/a&gt; have always been at the forefront, when it comes to protecting data  privacy, and it has ensured that consumer-facing technology companies do  not run roughshod when it comes to protecting user data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Chandrashekhar stated that there was no need for separate  regulations for e-commerce sites, but the priority was ensuring means to  enforce consumer laws in the digital world.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Lack of dedicated privacy laws&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to cyberlaw and cybersecurity expert, Pavan  Duggal, “Going forward, there is an urgent need for India to take a  strong view on privacy in terms of legislative frameworks.  Unfortunately, at the time of writing, &lt;a href="http://tech.firstpost.com/news-analysis/privacy-protection-need-for-proactive-cyber-legal-approaches-in-india-357248.html"&gt;&lt;b&gt;India does not have a dedicated law on privacy&lt;/b&gt;&lt;/a&gt;.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img alt="Image: Foamy Media" class="wp-image-353936 size-full" height="360" src="http://tech.firstpost.com/wp-content/uploads/2016/12/social-media.jpeg" width="640" /&gt;&lt;br /&gt;Image: Foamy Media&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Social media websites for instance have a lot of user data. But what happens when they suddenly change their privacy policies? For instance, a lot of users signed on to WhatsApp when it was an independent company. But post the Facebook acquisition, there have been a lot of instances where WhatsApp has updated its terms and conditions to suit its parent Facebook.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;That’s not completely illegal one may say. Loss of privacy  is a price you pay for free services. But what if, I as a consumer of  WhatsApp &lt;a href="http://tech.firstpost.com/news-analysis/german-consumer-rights-group-accuses-whatsapp-of-illegally-sharing-user-data-with-facebook-359979.html"&gt;&lt;b&gt;do not want the app to share any of my data with Facebook&lt;/b&gt;&lt;/a&gt;?  The only option I am left with is to delete WhatsApp. But then again, I  do not know if my data is also deleted from WhatsApp servers or it has  already been shared. Social media apps, only let you know what updates  are being added. Consent is only required to update the app. You can  stall that, up to a point. But there will come a time when you will have  to update an app. Then by default you have given approval to all the  terms and conditions associated with the app.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Two students had challenged WhatsApp’s revision to its  privacy policy before Delhi High Court. The Court dismissed the petition  insisting that users could opt out by &lt;a href="http://www.thehindu.com/news/cities/Delhi/delete-or-share-high-court-tells-whatsapp-users/article9143285.ece" rel="nofollow"&gt;&lt;b&gt;deleting their accounts&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When a similar challenge was mounted before the authorities  in UK, Facebook had to put a pause on their data sharing – and this was  because of its strong data protection policy. Under the UK data  protection law, the company has to inform the authority established  under the Act of any changes in the use of user data. In the case of  WhatsApp, the &lt;a href="http://tech.firstpost.com/news-analysis/why-india-failed-to-prevent-whatsapp-data-sharing-with-facebook-while-uk-succeeded-346115.html"&gt;&lt;b&gt;UK authority objected to such sharing.&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Aadhaar – the 12-digit biometric storehouse&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="http://tech.firstpost.com/wp-content/uploads/2016/03/aadhar_251002219381.jpg"&gt;&lt;img alt="aadhaar_251002219381" class="wp-image-303751 size-full aligncenter" height="360" src="http://tech.firstpost.com/wp-content/uploads/2016/03/aadhar_251002219381.jpg" width="640" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar card is being used for many financial and non  financial transactions. Also the Aadhaar number associated with an  individual also holds a lot of personal and biometric data. So when  recently, there was news about a possible Aadhaar data breach when &lt;a href="http://tech.firstpost.com/news-analysis/aadhaar-data-breach-uidai-finds-multiple-transactions-done-with-the-same-fingerprint-364155.html"&gt;&lt;b&gt;UIDAI filed a police complaint&lt;/b&gt;&lt;/a&gt; against Axis Bank, business correspondent Suvidhaa Infoserve and e-sign provider eMudhra, it was naturally a shock to many.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Unlike a password which can be changed, with biometric  information there is no scope to do that if it is compromised. Although  UIDAI claims that there are &lt;a href="http://tech.firstpost.com/news-analysis/aadhaar-is-being-used-by-few-corporates-for-salary-disbursements-but-the-potential-is-immense-361749.html"&gt;&lt;b&gt;multiple levels of security and firewalls&lt;/b&gt;&lt;/a&gt; to ensure there is no breach of Aadhaar information of an individual,  one can only hope that it is robust enough to withstand any attack.  Collection of biometric data by the government to form a database, for  instance, was debated and ultimately not used in the UK.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash, policy director of the Centre for Internet  and Society, expressed concern about the pace at which we are  progressing when it comes to having a legal and regulatory framework  when it comes to the Digital India push. “While the security  architecture of Aadhaar Enabled Payment Systems (AEPS) might in itself  be good, the idea of providing your fingerprints to merchants for  financial transactions is a terrible idea since that is like asking you  to give your bank password to a merchant, and the merchant can reuse  that password, and you can’t ever change the password,” said Prakash.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Enforcing the correct processes&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Last year, a malware affected the systems of Hitachi Payment  Services, which provides back end services to ATM machines and Point of  Sale nodes across India. As a result of this, around &lt;b&gt;&lt;a href="http://tech.firstpost.com/news-analysis/32-lakh-debit-cards-compromised-affected-banks-include-sbi-hdfc-yes-axis-bob-and-icici-342220.html" target="_blank"&gt;32 lakh debit cards were compromised&lt;/a&gt;&lt;/b&gt; including those issued by SBI, HDFC, Yes Bank, Axis, BOB and ICICI. Security experts and consultants have pointed out &lt;b&gt;&lt;a href="http://tech.firstpost.com/news-analysis/banks-need-to-switch-to-fully-encrypted-security-solutions-to-avoid-security-breaches-343696.html" target="_blank"&gt;various holes in the electronic transaction systems&lt;/a&gt;&lt;/b&gt; in place in India. Intel has also warned that &lt;b&gt;&lt;a href="http://tech.firstpost.com/news-analysis/demonetisation-security-experts-warn-that-atms-are-easy-targets-for-hackers-351182.html" target="_blank"&gt;ATM machines in India&lt;/a&gt;&lt;/b&gt; are vulnerable to malicious attacks. Intel points out that countries in  the Asia Pacific region are developing and are particularly vulnerable  because of old systems and machines being used.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="http://tech.firstpost.com/wp-content/uploads/2016/12/atm-queue-demonetisation.jpg"&gt;&lt;img alt="Image: REUTERS/Amit Dave " class="wp-image-353328" height="360" src="http://tech.firstpost.com/wp-content/uploads/2016/12/atm-queue-demonetisation.jpg" width="640" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div class="prodtxtinf" style="text-align: justify; "&gt;Image: REUTERS/Amit Dave&lt;/div&gt;
&lt;p style="text-align: justify; "&gt;According to Mahesh Patel, president and group CTO, AGS  Transact Technologies this was more of a governance issue of the data  centre than any technical error. “It is not about the software, but it  is about the processes and procedures you put in place to ensure that  the system is secure. Everything from physical security to computing  security to admin management, etc should be process driven. So somewhere  there could have been a weak link there. Cloud has to be secure and  encrypted which suffices the use case of payments. This cloud is  different from the ones used by e-commerce sites to display all their  products,” said Patel.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;We may have the best of software and security measures, but  ensuring that they are implemented the right way is equally important.  Plugging the loopholes in current regulations is also important.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Existing laws and regulations, not enough&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to Duggal, “The Information Technology Act, 2000  hardly has effective provisions to protect any data and personal privacy  in the digital ecosystem. The Indian Government needs to come up with  strong privacy law which can protect both personal privacy and data  privacy in an effective manner.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One may find it really shocking to hear the head of Nasscom  saying something to the extent that full data protection for online  consumers is not possible, but there is definitely truth to the matter.  It will require concerted efforts from not only regulators, governments,  digital wallet players and banking industry to come up with these  privacy laws, but also you the consumer has to ensure that you are aware  of the dangers lurking in the digital world. Educating oneself of the  various ways in which your data can be compromised is a good way to  protect your online self.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Because, let’s face it, for all practical purposes if you are online, your &lt;a href="http://tech.firstpost.com/news-analysis/privacy-is-dead-stop-whining-and-get-some-real-work-done-357090.html"&gt;&lt;b&gt;privacy is dead&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="tags"&gt; &lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/first-post-march-16-nimish-sawant-nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber'&gt;https://cis-india.org/internet-governance/news/first-post-march-16-nimish-sawant-nasscom-chief-saying-full-data-protection-isnt-possible-should-wake-us-from-our-digital-slumber&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>WhatsApp</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-17T01:47:25Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/richa-mishra-hindu-businessline-march-13-2017-the-12-digit-conundrum">
    <title>The 12-digit conundrum</title>
    <link>https://cis-india.org/internet-governance/news/richa-mishra-hindu-businessline-march-13-2017-the-12-digit-conundrum</link>
    <description>
        &lt;b&gt;Even as the Centre plans to link as many as 500 schemes to Aadhaar, concerns over data safety are rising. Richa Mishra reports.&lt;/b&gt;
        &lt;p class="body" style="text-align: justify; "&gt;The article by Richa Mishra was published in the       &lt;a href="http://www.thehindubusinessline.com/specials/india-file/aadhaar-the-12digit-conundrum/article9582271.ece"&gt;Hindu         Businessline&lt;/a&gt; on March 13, 2017. Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p class="body" style="text-align: justify; "&gt;The developments of last few weeks       seem to have made real some of the worst fears about Aadhaar. In       February, UIDAI (Unique Identification Authority of India) filed a       police complaint alleging attempts of unauthorised authentication       and impersonation of data related to Aadhaar. Since then, each and       every machinery within the government has been trying to convince       otherwise, that Aadhaar database is safe and secure, and that the       data is protected both by the best available advanced technology       as well as by the stringent legal provisions in the Aadhaar Act.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Not everyone is convinced. Critics       say, biometrics only make the citizen transparent to the State, it       does not make the State transparent to citizens. “We warned the       government six years ago, but they ignored us,” said Sunil       Abraham, Executive Director of Bengaluru-based research       organisation, Centre for Internet and Society. According to him,       the legislation implementing Aadhaar has almost no data protection       guarantees for citizens. He also believes that by opting for       biometrics instead of smart cards the government is using       surveillance technology instead of e-governance technology.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;“Biometrics is remote, covert and       non-consensual identification technology. It is totally       inappropriate for authentication. This has only increased the       fragility of Indian cyber security,” he stresses.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;However, officials associated with       UIDAI dismiss these arguments. Collecting biometrics does not pose       any threat to the right to privacy because people have been giving       their thumb impression for ages, they say. “The biometrics are       encrypted at source and kept safe and secure. Unauthorised sharing       and leakage of the data does not happen. Fears related to       collection of biometrics are not justified,” an official at the       helm of affairs said. He requested anonymity.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;“However, as and when we find that       some suspicious activity or misuse is happening, we will strike at       the very beginning itself. UIDAI has full authentication       regulation under the Aadhaar Act that has to be followed. It       specifies in what manner authorities can use Aadhaar,” the       official pointed out.&lt;/p&gt;
&lt;div style="text-align: justify; "&gt;&lt;b&gt;On the ground&lt;/b&gt;&lt;/div&gt;
&lt;p class="body" style="text-align: justify; "&gt;Even as the debate over data       security rages, the &lt;i&gt;aam aadmi &lt;/i&gt; seem to be little       perturbed about the alleged risks involved. For Padmini, who works       as a domestic help in East Delhi and is the sole bread earner for       her family of four, the Aadhaar card meant access to all       government benefits.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;“&lt;i&gt;Koi farak nahi padta, kaun         dekhta hai mera card. Mujhko &lt;/i&gt;LPG cylinder &lt;i&gt;ka paisa bank         mein mil jata hai,”&lt;/i&gt; (It doesn’t matter to me who sees my       card. The subsidy for LPG gets transferred to my account) she       says. “&lt;i&gt;Baccho ke school admission mein bhi zaroorat pada,&lt;/i&gt;”       (I needed it to get my children’s admission in school), she added.       Sukh, a cab driver also uses it to get the LPG subsidy.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;While everyone &lt;i&gt;BusinessLine &lt;/i&gt;talked       to were convinced that Aadhaar was not a citizenship card, the       more aware ones saw it as a door that gave access to government       schemes.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;While they had a point, government       officials are careful to make it clear that Aadhaar is not       mandatory. But the popular perception increasingly points to the       opposite view, especially after it emerged that Aadhaar might be       made mandatory for children to receive midday meals at schools.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Another senior government official       said, “Aadhaar is not mandatory under any welfare scheme of the       government and no one is being deprived of a service or benefit       for the want of Aadhaar…it’s required for availing a       service/subsidy/benefit that accrues through the Consolidated Fund       of India.” He added that those who do not have the 12-digit number       would be provided with the facility to enrol by the Requiring       Agency. “And till the time Aadhaar is assigned, alternative IDs       would be allowed,” he said.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;If a school which has to get Aadhaar       enrolment done for its students puts the Aadhaar numbers of its       students on its site and the same is used by someone, you can’t       blame us, the official argues. Then, who is accountable?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Pushing for Aadhaar, the UIDAI       officials cite the example of Kerala’s Department of General       Education (DGE), which has integrated Aadhaar with the student       databases and has thereby optimised the teacher-student ratio and       identified the schools with excess teachers. In a single academic       year, 3,892 excess teacher posts were identified.&lt;/p&gt;
&lt;p class="_hoverrDone body" style="text-align: justify; "&gt;“Due to this exercise,       no new posts have been sanctioned for the last two years,       resulting in notional savings of ₹540 crore per annum,” said a       UIDAI official. After student enrolment in the state was linked to       Aadhaar since 2012-2013, the head count of pupils have fallen by 5       lakh. Similar trends have been reported in Haryana. Critics have       also pointed out the possible security risk in using AadhaarPay,       the Andriod-based app. Merchants can download the app in their       phone and install a fingerprint scanner linked to the phone.       Customers with Aadhaar numbers can use their fingerprints (like       the secret PIN in case of debit cards) to do a transaction. While       doubts have been raised about the safety of fingerprint data,       officials in the know blame the controversy on the “card lobbies.”&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;“Thirty crore Indians have no       mobiles. They find it difficult to handle password, pin or card,       this is where AadhaarPay will come handy,” the official added.       “They don’t need a smart phone or feature phone. They don’t need a       debit card.&lt;/p&gt;
&lt;p class="_hoverrDone body" style="text-align: justify; "&gt;“Today more than 112       crore people have the Aadhaar card. Approximately, 52.95 crore       people have linked their Aadhaar numbers to their bank accounts.       We already have a system of Aadhaar authentication in place,” the       official added.&lt;/p&gt;
&lt;p class="_hoverrDone body" style="text-align: justify; "&gt;Government officials are       at pain to point out the larger benefits of Aadhaar, including       savings of more than ₹49,000 crore by plugging leakages in       government schemes like PDS. Government plans to increase the       number of welfare schemes linked to Aadhaar from 36 to over 500.       While the intent is good, concerns remain.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/richa-mishra-hindu-businessline-march-13-2017-the-12-digit-conundrum'&gt;https://cis-india.org/internet-governance/news/richa-mishra-hindu-businessline-march-13-2017-the-12-digit-conundrum&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-03-14T13:50:05Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-wire-amber-sinha-february-21-2017-can-the-judiciary-upturn-the-lok-sabha-speakers-decision-on-aadhaar">
    <title>Can the Judiciary Upturn the Lok Sabha Speaker’s Decision on Aadhaar?</title>
    <link>https://cis-india.org/internet-governance/blog/the-wire-amber-sinha-february-21-2017-can-the-judiciary-upturn-the-lok-sabha-speakers-decision-on-aadhaar</link>
    <description>
        &lt;b&gt;When ruling on the petition filed by Jairam Ramesh challenging passing the Aadhaar Act as a money Bill, the court has differing precedents to look at.&lt;/b&gt;
        &lt;p&gt;The article was &lt;a class="external-link" href="https://thewire.in/110795/aadhaar-money-bill-judiciary/"&gt;published in the Wire&lt;/a&gt; on February 21, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;In &lt;a href="http://thewire.in/2016/04/24/the-aadhaar-act-is-not-a-money-bill-31297/" target="_blank" title="an earlier article"&gt;an earlier article&lt;/a&gt;, I had argued that the characterisation of the &lt;a href="https://www.google.co.in/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=5&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0ahUKEwj0xo6U_KDSAhVHLo8KHcygCVEQFggvMAQ&amp;amp;url=https%3A%2F%2Fuidai.gov.in%2Fimages%2Fthe_aadhaar_act_2016.pdf&amp;amp;usg=AFQjCNHDmJKdO8jdfGZJKLKRJQpHdf1Frw&amp;amp;sig2=B_YbWncu6eyZHJ1MFTD0NA" rel="external nofollow" target="_blank" title="Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act"&gt;Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act&lt;/a&gt;,  as a money Bill by Sumitra Mahajan, speaker of the Lok Sabha, was  erroneous. Specifically, I had argued that upon perusal of Article 110  (1) of the constitution, the Aadhaar Act does not satisfy the conditions  required of a money Bill. For a legislation to be classified as a money  Bill, it must comprise of ‘only’ provisions dealing with the following  matters: (a) imposition, regulation and abolition of any tax, (b)  borrowing or other financial obligations of the government of India, (c)  custody, withdrawal from or payment into the Consolidated Fund of India  (CFI) or Contingent Fund of India, (d) appropriation of money out of  CFI, (e) expenditure charged on the CFI or (f) receipt or custody or  audit of money into CFI or public account of India; or (g) any matter  incidental to any of the matters specified in sub-clauses (a) to (f).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Article 110 is modelled on Section 1(2) of the UK’s Parliament Act, 1911, which also defines money Bills as those only dealing with certain enumerated matters. The use of the word ‘only’ was brought up by Ghanshyam Singh Gupta during the constituent assembly debates. He pointed out that the use of the word ‘only’ limits the scope money Bills to only those legislations which did not deal with other matters. His amendment to delete the word ‘only’ was rejected, clearly establishing the intent of the framers of the constitution to keep the ambit of money Bills extremely narrow. G.V. Mavalankar, the first speaker of Lok Sabha, had stated that the word ‘only’ must not be construed so as to give an overly restrictive meaning. For instance, a Bill which deals with taxation could have provisions which deal with the administration of the tax. The finance minister, Arun Jaitley, referred to these words by Mavalankar, justifying the classification of the Aadhaar Act as a money Bill.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While the Aadhaar Bill does makes references to benefits, subsidies and services funded by the CFI, even a cursory reading of the Bill reveals its main objectives as creating a right to obtain a unique identification number and providing for a statutory apparatus to regulate the entire process. Any reasonable reading of the legislation would be hard pressed to view all provisions in the Aadhaar Act, aside from the one creating a charge on the CFI, as merely administrative provisions incidental to the creation such charge. The mere fact of establishing the Aadhaar number as the identification mechanism for benefits and subsidies funded by the CFI does not give it the character of a money Bill. The Bill merely speaks of facilitating access to unspecified subsidies and benefits rather than their creation and provision being the primary object of the legislation. Erskine May’s seminal textbook, Parliamentary Practice, is instructive in this respect and makes it clear that a legislation which simply makes a charge on the consolidated fund does not becomes a money Bill if otherwise its character is not that of one. Further, the subordinate regulations notified under the Aadhaar Act deal almost entirely with matters to do with enrolment, updation, authentication of the Aadhaar number and related matters such as data security regulations and sharing of information collected, rather than the provision of benefits or subsidies or disbursal of funds otherwise from the CFI.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, in the context of the petition filed by former Union minister Jairam Ramesh challenging the passage of the law on Aadhaar as a money Bill, the more important question is whether the judiciary has a right to question the speaker’s decision in such a matter. If not, any other questions about whether the legislation is a money Bill will remain merely academic in nature.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Irregularity vs illegality&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Article 110 (3) clearly states that with regard to the question whether a legislation is a money Bill or not, the decision of the speaker is final and binding. The question is whether such a clause completely excludes any judicial review. Further, Article 122 prohibits the courts from questioning the validity of any proceedings in parliament on the ground of any alleged irregularity of procedure.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;During the arguments in the court, the attorney general questioned the locus standi of Ramesh. The petition has been made under Article 32 of the constitution and the government argued that no fundamental rights of Ramesh were violated. However, the court has asked Ramesh to make his submission and adjourned the hearing to July. The petition by Ramesh would hinge largely on the powers of the judiciary to question the decision of the speaker of the Lok Sabha.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The powers of privilege that parliamentarians enjoy are integral to the principle of separation of powers. The rationale behind parliamentary privilege is to prevent interference in the lawmakers’ powers to perform essential functions. The ability to speak and vote inside the legislature without the fear of punishment is certainly essential to the role of a lawmaker. However, the extent of this protection lies at the centre of this discussion. During the constituent assembly debates, H.V. Kamath and others had argued for a schedule to exhaustively codify the existing privileges. However, B.R. Ambedkar pointed to the difficulty of doing so and parliamentary privilege on the lines of the British parliamentary practice was retained in the constitution. In the last few decades, a judicial position has emerged that courts could exercise a limited degree of scrutiny over privileges, as they are primarily responsible for interpreting the constitution.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the matter of &lt;a href="https://indiankanoon.org/doc/1757390/" rel="external nofollow" target="_blank" title="Raja Ram Pal vs The Hon’ble Speaker, Lok Sabha"&gt;&lt;i&gt;Raja Ram Pal vs The Hon’ble Speaker, Lok Sabh&lt;/i&gt;a&lt;/a&gt;,  it had been clarified that proceedings of the legislature were immune  from questioning by courts in the case of procedural irregularity but  not in the case of illegality. In this case, the Supreme Court while  dealing with Article 122 stated that it does not oust review by the  judiciary in cases of “gross illegality, irrationality, violation of  constitutional mandate, mala fides, non-compliance with rules of natural  justice and perversity.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In 1968, the speaker of the Punjab legislative assembly adjourned the  proceedings for a period of two months following rowdy behaviour.  Subsequently, an ordinance preventing such a suspension was promulgated  and the legislature was summoned by the governor to consider some  expedient financial matters. The speaker disagreed with the decision and  after some confusion, the deputy speaker passed a few Bills as money  Bills. While looking into the question of what was protected from  judicial review, the &lt;a href="https://indiankanoon.org/doc/36589/" rel="external nofollow" target="_blank" title="court stated"&gt;court stated&lt;/a&gt; that the protection did not extend to breaches of mandatory provisions  of the constitution, only to directory provisions. By that logic, if  Article 110 (1) is seen as a mandatory provision, a breach of its  provisions could lead to an interpretation that the Supreme Court may  well question an erroneous decision by the speaker of the Lok Sabha to  certify a legislation as a money Bill. The use of the word “shall” in  Article 110 (1), the nature and design of the provision, its overriding  impact on the other constitutional provisions granting the Rajya Sabha  powers are ample evidence of its mandatory nature. Based on the above,  Anup Surendranath has &lt;a href="http://ccgdelhi.org/doc/%28CCG-NLU%29%20Aadhaar%20Money%20Bill.pdf" rel="external nofollow" target="_blank" title="argued"&gt;argued&lt;/a&gt; that  the passage of the Aadhaar Act as a money Bill when it does not satisfy  the constitutional conditions for it does amount to a gross illegality.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The judicial precedent in &lt;i&gt;&lt;a href="https://indiankanoon.org/doc/60568976/" rel="external nofollow" target="_blank" title="Mohd. Saeed Siddiqui vs State of Uttar Pradesh"&gt;Mohd. Saeed Siddiqui vs State of Uttar Pradesh&lt;/a&gt;&lt;/i&gt; where the matter of the court’s power to question the decision of a  speaker was considered, though, leans in the other direction. In 2012,  the &lt;a href="https://www.google.co.in/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=1&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0ahUKEwiRtov_iKHSAhVLuo8KHYhsClcQFggbMAA&amp;amp;url=http%3A%2F%2Fwww.lawsofindia.org%2Fdownloadfile.php%3Flawid%3D7834%26file%3Duttar_pradesh%2F1981%2F1981UP7.pdf%26pageurl%3D%252Fsingle%252Falpha%252F7.html&amp;amp;usg=AFQjCNGRW8-NChXALunaUbjZRrlM4IvCkA&amp;amp;sig2=rg6YCMf7qRqNw08NnctuhQ" rel="external nofollow" target="_blank" title="Uttar Pradesh Lokayukta and Up-Lokayuktas (Amendment) Act"&gt;Uttar Pradesh Lokayukta and Up-Lokayuktas (Amendment) Act&lt;/a&gt;,  2012 was passed as money Bill by the Uttar Pradesh state legislature.  Subsequently, a writ petition was filed challenging its constitutional  validity. A three-judge bench of the Supreme Court looked into the  application of Article 212. It is the provision corresponding to Article  122, dealing with the power of the courts to inquire into the  proceedings of the state legislature. The court held that Article 212  makes “it clear that the finality of the decision of the Speaker and the  proceedings of the State Legislature being important privilege of the  State Legislature, viz., freedom of speech, debate and proceedings are  not to be inquired by the Courts.” Importantly, ‘proceedings of the  legislature’ were deemed to include within its scope everything done in  transacting parliamentary business, including the passage of the Bill.  While the court did acknowledge the limitations of parliamentary  privilege as established in the &lt;i&gt;Raja Ram Pal&lt;/i&gt; case, it did not adequately take into account the reasoning in it.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Aadhaar Act is a legislation which makes it mandatory of all  residents to enrol for a biometric identification system in order to  avail certain subsidies, benefits and services. It has huge potential  risks for individual privacy and national security and has been the  subject of an extremely high profile Public Interest Litigation. Its  passage as a money Bill, without any oversight from the Rajya Sabha and  an opportunity for substantial debate and discussion, is a fraud on the  Constitution. Whether or not the court chooses to see it that way  remains to be seen.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-wire-amber-sinha-february-21-2017-can-the-judiciary-upturn-the-lok-sabha-speakers-decision-on-aadhaar'&gt;https://cis-india.org/internet-governance/blog/the-wire-amber-sinha-february-21-2017-can-the-judiciary-upturn-the-lok-sabha-speakers-decision-on-aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>amber</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-02-27T15:44:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/vocativ-joshua-kopstein-india-private-companies-citizens-biometric-data">
    <title>India To Let Private Companies Access Citizens’ Biometric Data</title>
    <link>https://cis-india.org/internet-governance/news/vocativ-joshua-kopstein-india-private-companies-citizens-biometric-data</link>
    <description>
        &lt;b&gt;India, home to the world’s largest national biometric registry, plans to begin sharing citizens’ data with the country’s private companies and startups.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Joshua Kopstein was published by &lt;a class="external-link" href="http://www.vocativ.com/404338/india-private-companies-citizens-biometric-data/"&gt;Vocativ&lt;/a&gt; on February 21, 2017. Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The government-backed program, called  “India Stack,” will allow the second most populous country on Earth to  share nearly all of its 1.3 billion citizens’ fingerprints, iris scans,  and more, potentially creating unprecedented security and privacy risks  in the name of convenience and digital commerce.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India Stack will open up the country’s troves of biometric data to  Indian software developers, health care providers, and any other  business interested in using the government’s identification records in  their apps and services. The Indian government hopes the move will spur  innovation, jumpstarting its effort to create a centralized system of  digital commerce where citizens can purchase goods, apply for health  insurance, or even qualify for a loan using the biometric sensors on  their smartphones.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Opponents, however, warn that the sharing scheme opens a Pandora’s  box of security and privacy problems, dramatically increasing the  likelihood of data breaches and abuse.&lt;/p&gt;
&lt;div class="page" style="text-align: justify; " title="Page 2"&gt;
&lt;div class="layoutArea"&gt;
&lt;div class="column"&gt;
&lt;p&gt;“It’s the worst time for privacy policy in the country,” Sunil  Abraham, the executive director of the Bangalore-based Centre for  Internet and Society, &lt;a href="https://www.wsj.com/articles/india-begins-building-on-its-citizens-biometrics-1487509205" target="_blank"&gt;told the Wall Street Journal&lt;/a&gt;. “We are very caught up in technological exuberance. Techno-utopians are ruling the roost.”&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p style="text-align: justify; "&gt;The dangers aren’t just hypothetical. In 2015, an unprecedented breach at the U.S. Office of Personnel Management &lt;a href="https://www.washingtonpost.com/news/the-switch/wp/2015/09/23/opm-now-says-more-than-five-million-fingerprints-compromised-in-breaches/?utm_term=.8dc8ac825cd8" target="_blank"&gt;allowed hackers to steal the fingerprints of 5.6 million federal employees&lt;/a&gt;. Researchers have found that stolen fingerprints can be used to commit fraud and identity theft, and even &lt;a href="http://www.npr.org/sections/alltechconsidered/2016/07/27/487605182/police-use-fingertip-replicas-to-unlock-a-murder-victims-phone" target="_blank"&gt;replicated and used to unlock smartphones and other personal devices&lt;/a&gt;.  Worst of all, unlike passwords and social security numbers, biometric  identifiers like fingerprints can never be changed, meaning that any  breach is virtually guaranteed to have long-term consequences.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The India Stack program is the latest in several recent schemes to  push the country toward a fully-digitized and cashless economy. As of  December 2016, the Unique Identification Authority of India had  registered more than 91% of the population into a centralized system  called Aadhaar, which integrates with banks and allows citizens to  complete transactions and access government services using their  fingerprints. The country has also temporarily withdrawn its  higher-denomination bank notes from circulation in an effort to bolster  digital payment systems.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the efforts of the government are commendable, the efficacy of  these programs in the absence of sufficient infrastructure for security  raises various concerns,” the Centre For Internet and Society wrote in &lt;a href="http://cis-india.org/internet-governance/blog/privacy-gaps-in-indias-digital-india-project" target="_blank"&gt;a paper&lt;/a&gt; outlining the privacy risks of India’s digital identity system.  “Increased awareness among citizens and stronger security measures by  the governments are necessary to combat the cogent threats to data  privacy arising out of the increasing rate of cyberattacks.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India’s program has already gone far beyond other countries’  biometric data collection schemes, which have mostly been limited to  passports and border control. &lt;span&gt;But law  enforcement officials’ smaller, more piecemeal efforts to collect  biometric information have also raised alarm over their potential for  abuse. &lt;/span&gt;Thanks to the cooperation of 16 state DMVs, &lt;a href="http://www.vocativ.com/394147/face-recognition-government-weapon" target="_blank"&gt;one in two Americans currently has their photo registered to a law enforcement face recognition database&lt;/a&gt; – regardless of whether they’ve been charged or even suspected of a  crime. Local police in several U.S. states have also begun collecting &lt;a href="http://www.reuters.com/article/us-crime-identification-iris-idUSTRE76J4A120110720" target="_blank"&gt;iris scans&lt;/a&gt; and &lt;a href="https://www.propublica.org/article/dna-dragnet-in-some-cities-police-go-from-stop-and-frisk-to-stop-and-spit" target="_blank"&gt;DNA swabs&lt;/a&gt; from people randomly stopped on the street, in some cases &lt;a href="http://www.vocativ.com/403313/stop-and-spit-lawsuit/" target="_blank"&gt;specifically targeting African American children&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/vocativ-joshua-kopstein-india-private-companies-citizens-biometric-data'&gt;https://cis-india.org/internet-governance/news/vocativ-joshua-kopstein-india-private-companies-citizens-biometric-data&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-02-27T15:09:16Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
