<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 741 to 755.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/report-of-sevent-privacy-round-table"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/hindustan-times-november-2-2013-nagender-sharma-alok-tikku-spy-agencies-ib-and-raw-put-spanner-in-proposed-privacy-law"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/indian-express-october-27-2013-nishant-shah-open-secrets"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/first-post-october-28-2013-nowhere-to-hide"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/business-standard-october-29-2013-somesh-jha-surabhi-agarwal-your-private-data-may-be-online-courtesy-govt"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/business-standard-october-29-2013-surabhi-agarwal-somesh-jha-saving-privacy-as-we-knew-it"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/spy-files-three"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/economic-times-october-18-2013-indu-nandakumar-bouquets-brickbats-google-new-privacy-policy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/yahoo-october-23-2013-what-india-can-learn-from-snowden-revelations"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/interview-with-berlin-data-protection-commissioner"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/outlookindia-october-28-2013-debarshi-dasgupta-beyond-the-searchlight"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/livemint-moulishree-srivastava-october-22-2013-bali-meet-to-discuss-internet-governance-issues"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/blog/report-of-sevent-privacy-round-table">
    <title>Seventh Privacy Round-table</title>
    <link>https://cis-india.org/internet-governance/blog/report-of-sevent-privacy-round-table</link>
    <description>
        &lt;b&gt;On October 19, 2013, the Centre for Internet and Society (CIS) in collaboration with the Federation for Indian Chambers of Commerce and Industry, the Data Security Council of India, and Privacy International held a “Privacy Round-table” in New Delhi at the FICCI Federation House.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The Round-table was the last in a series of seven, beginning in April 2013, which were held across India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Previous Privacy Round-tables were held in:&lt;/p&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/internet-governance/blog/report-on-the-first-privacy-round-table-meeting" class="external-link"&gt;New Delhi&lt;/a&gt;: (April 13, 2013) with 45 participants;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;a class="external-link" href="http://bit.ly/162t8rU"&gt;Bangalore&lt;/a&gt;: (April 20, 2013) with 45 participants;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;a class="external-link" href="http://bit.ly/12ICGYD"&gt;Chennai&lt;/a&gt;: (May 18, 2013) with 25 participants;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;a class="external-link" href="http://bit.ly/12fJSvZ"&gt;Mumbai&lt;/a&gt;, (June 15, 2013) with 20 participants;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;a class="external-link" href="http://bit.ly/11dgINZ"&gt;Kolkata&lt;/a&gt;: (July 13, 2013) with 25 participants; and&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;a class="external-link" href="http://bit.ly/195cWIf"&gt;New Delhi&lt;/a&gt;: (August 24, 2013) with 40 participants.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;Chantal Bernier, Assistant Privacy Commissioner Canada, Jacob Kohnstamm, Dutch Data Protection Authority and Chairman of the Article 29 Working Party, and Christopher Graham, Information Commissioner UK were the featured speakers for this event.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Privacy Round-tables were organised to ignite spark in public dialogues and gain feedback for a privacy framework for India. To achieve this, &lt;a href="https://cis-india.org/internet-governance/blog/privacy-protection-bill-2013-amendments.pdf" class="external-link"&gt;the Privacy Protection Bill, 2013&lt;/a&gt;, drafted by the Centre for Internet and Society, &lt;a href="https://cis-india.org/internet-governance/blog/strengthening-privacy-protection.pdf" class="external-link"&gt;Strengthening Privacy through Co-regulation by the Data Security Council of India&lt;/a&gt;, and the &lt;a class="external-link" href="http://planningcommission.nic.in/reports/genrep/rep_privacy.pdf"&gt;Report of the Group of Experts on Privacy by the Justice A.P. Shah committee&lt;/a&gt; were used as background documents for the Round-tables. As a note, after each Round-table, CIS revised the text of the Privacy Protection Bill, 2013 based on feedback gathered from the general public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Seventh Privacy Round-table meeting began with an overview of the past round-tables and a description of the evolution of a privacy legislation in India till date, and an overview of the Indian interception regime. In 2011, the Department of Personnel and Training drafted a Privacy Bill that incorporated provisions regulating data protection, surveillance, interception of communications, and unsolicited messages. Since 2010, India has been seeking data secure status from the European Union, and in 2012 a report was issued noting that the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules found under &lt;a href="https://cis-india.org/internet-governance/blog/privacy/safeguards-for-electronic-privacy" class="external-link"&gt;section 43A of the Information Technology Act&lt;/a&gt;, were not sufficient to meet EU data secure adequacy.  In 2012, the Report of the Group of Experts on Privacy was published recommending a privacy framework for India and was accepted by the government, and the Department of Personnel and Training is presently responsible for drafting of a privacy legislation for India.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Presentation: &lt;b&gt;Jacob Kohnstamm&lt;/b&gt;, &lt;i&gt;Dutch Data Protection Authority and Chairman of the Article 29 Working Group &lt;/i&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Jacob Kohnstamm, made a presentation on the privacy framework in the European Union. In his presentation, Khonstamm shared how history, such as the Second World War, shaped the present understanding and legal framework for privacy in the European Union, where privacy is seen as a fundamental human right. Kohnstamm also explained how over the years technological developments have made data gold, and subsequently, companies who process this data and create services that allow for the generation of more data are becoming monopolies. This has created an unbalanced situation for the individual consumer, where his or her data is being routinely collected by companies, and once collected — the individual loses control over the data. Because of this asymmetric relationship, data protection regulations are critical to ensure that individual rights are safeguarded. &lt;br /&gt;&lt;br /&gt;Kohnstamm recognized the tension between stringent data protection regulations and security for the government, and the provision of services for businesses was recognized. However, he argued that the use of technology without regulation — for commercial reason or security reasons, can lead to harm. Thus, it is key that any regulation incorporate proportionality as a cornerstone to the use of these technologies to ensure trust between the individual and the State, and the individual and the corporation. This will also ensure that individuals are given the right of equality, and the right to live free of discrimination. Kohnstamm went on to explain that any regulation needs to ensure that individuals are provided the necessary tools to control their data and that a robust supervisory authority is established with enough powers to enforce the provisions, and that checks and balances are put in place to safeguard against abuse.&lt;br /&gt;&lt;br /&gt; In response to a question asked about how the EU addresses the tension of data protection and national security, Kohnstamm clarified that in the EU, national security is left as a matter for member states to address but the main principles found in the EU Data Protection Directive also apply to the handling of information for national security purposes. He emphasized the importance of the creation of checks and balances. As security agencies are given additional and broader powers, they must also be subjected to stronger safeguards.&lt;br /&gt; &lt;br /&gt;Kohnstamm also discussed the history of the fair trade agreement with India, and India’s request for data secure status. It was noted that currently the fair trade agreement between India and the EU is stalled, as India has asked for data secure status. For the EU to grant this status, it must be satisfied that when European data is transferred and processed in India and that it is subject to the same level of protections as it would be if it were processed in the EU. Without a privacy legislation in place, India’s present  regime does not reflect the same level of protections as the EU regime. To find a way out of this ‘dead lock’, the EU and India have agreed to set up an expert group — with experts from both the EU and India to find a way in which India’s regime can be modified to meet EU date secure adequacy. As of date, no experts from the Indian side have been nominated and communicated to the EU.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;Europe’s history has influenced the understanding and formulation of the right to privacy as a fundamental right.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Any privacy regulation must have strong checks and balances in place and ensure that individuals are given the tools to control their data. &lt;/li&gt;
&lt;li style="text-align: justify; "&gt;India’s current regime does not meet EU data secure adequacy. Currently, the EU is waiting for India to nominate experts to work with the EU to find a way of the ‘dead lock’.&lt;/li&gt;
&lt;/ol&gt; 
&lt;ul&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;Discussion: &lt;b&gt;National Security, Surveillance and Privacy&lt;/b&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Opening the discussion up to the floor, it was discussed how in India, there is a tension between data protection and national security, as national security is always a blanket exception to the right to privacy. This tension has been discussed and debated by both democratic institutions in India and commercial entities. It was pointed out that though data protection is a new debate, national security is a debate that has existed in India for many years. It was also pointed out that currently there are not sufficient checks and balances for the powers given to Indian security agencies. One missing safeguard that the Indian regime has been heavily criticized for is the power of the Secretary of the Home Ministry to authorize interception requests, as having the authorization power vested in the executive leaves little space between interested parties seeking approval of interception orders, and could result in abuse or conflict of interest. With regards to the Indian interception regime, it was explained that currently there are five ways in which messages can be intercepted in India. Previously, the Law Commission of India had asked that amendments be made to both the Indian Post Office Act and the Indian Telegraph Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Moving the discussion to the Privacy Protection Bill, 2013 by CIS, in Chapter V “Surveillance and Interception of Communications” clause 34, the authorization of interception and surveillance orders is left to a magistrate. Previously, the authorization of interception orders rested with the Privacy Commissioner, but this model was heavily critiqued in previous round-tables, and the authorizing authority has been subsequently changed to a magistrate. Participants pointed out that the Bill should specify the level of the magistrate that will be responsible for the authorization of surveillance orders, and also raised the concern that the lower judiciary in India is not adequately functioning as the courts are overwhelmed, thus creating the possibility for abuse. Participants also suggested that perhaps data protection and surveillance should be de-linked from each other and placed in separate bills. This echoes public feedback from previous roundtables.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While discussing needed safeguards in an interception and surveillance regime for India, it was called out that transparency of surveillance, by both the government and the service providers as key safeguards to ensuring the protection of privacy, as it would enable individuals to make educated decisions about the services they choose to use and the extent of governmental surveillance. The need to bring in a provision that incorporated the idea of "nexus of surveillance" was also highlighted. It was also pointed out that in Canada, entities wanting to deploy surveillance in the name of public safety, must take steps to prove nexus. For example, the organization must empirically prove that there is a need for a security requirement, demonstrate that only data that is absolutely necessary will be collected, show how the technology will be effective, prove that there is not a less invasive way to collect the information, demonstrate security measures in place to ensure against loss and misuse, and the organizations must have in place both internal and external oversight mechanisms. It was also shared that in Canada, security agencies are regulated by the Office of the Canadian Privacy Commissioner, as privacy and security are not seen as separate matters. In the Canadian regime, because security agencies have more powers, they are also subjected to greater oversight.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;The Indian surveillance regime currently does not have strong enough safeguards.&lt;/li&gt;
&lt;li&gt;The concept of ‘nexus’ should be incorporated into the Privacy Protection Bill, 2013.&lt;/li&gt;
&lt;li&gt;A magistrate, through judicial oversight for interception and surveillance requests, might not be the most effective authority for this role in India.&lt;/li&gt;
&lt;/ol&gt; 
&lt;ul&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;Presentation: &lt;b&gt;Chantal Bernier&lt;/b&gt;, &lt;i&gt;Deputy Privacy Commissioner, Canada&lt;/i&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;In her presentation, Bernier made the note that in the Canadian model there are multiple legislative initiatives that are separate but connected, and all provide a legislative basis for the right to privacy. Furthermore, it was pointed out that there are two privacy legislations in Canada, one regulating the private sector and the other regulating the public sector. It has been structured this way as it is understood that the relationship between individuals and business is based on consent, while the relationship between individuals and the state is based on human rights. Furthermore, aspects of privacy, such as consent are different in the public sector and the private sector. In her presentation, Bernier pointed out that privacy is a global issue and because of this, it is critical that countries have privacy regimes that can speak to each other. This does not mean that the regimes must be identical, but they must at the least be inter-operable.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Bernier described three main characteristics of the Canadian privacy regime including:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;It is comprehensive and applies to both the public and the private sectors.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The right to privacy in Canada is constitutionally based and is a fundamental right as it is attached to personal integrity. This means that privacy is above contractual fairness. That said, the right to privacy must be balanced collectively with other imperatives.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The Canadian privacy regime is principle based and not rule based. This flexible model allows for quick adaption to changing technologies and societal norms. Furthermore, Bernier explained how Canada places responsibility and accountability on companies to respect, protect, and secure privacy in the way in which the company believes it can meet. Bernier also noted that all companies are responsible and accountable for any data that they outsource for processing. &lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;Furthermore, any company that substantially deals with Canadians must ensure that the forum for which complaints etc., are heard is Canada. Furthermore, under the Canadian privacy regime, accountability for data protection rests with the original data holder who must ensure — through contractual clauses — that any information processed through a third party meets the Canadian level of protection. This means any company that deals with a Canadian company will be required to meet the Canadian standards for data protection.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Speaking to the governance structure of the Office of the Privacy Commissioner in Canada, Bernier explained that the OPC is a completely independent office and reports directly to the Parliament. The OPC hears complaints from both individuals and organizations. The OPC does not have any enforcement powers, such as finding a company, but does have the ability to "name" companies who are not in compliance with Canadian regulations, if it is in the public interest to do so. The OPC can perform audits upon discretion with respect to the public sector, and can perform audits on the private sector if they have reasonable grounds to investigate.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Bernier concluded her presentation with lessons that have been learned from the Canadian experience including:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The importance of having strong regulators.&lt;/li&gt;
&lt;li&gt;Privacy regulators must work and cooperate together.&lt;/li&gt;
&lt;li&gt;Privacy has become a condition of trade.&lt;/li&gt;
&lt;li&gt;In today’s age, issues around surveillance cannot be underestimated.&lt;/li&gt;
&lt;li&gt;Companies that have strong privacy practices now have a competitive advantage in place in today’s global market.&lt;/li&gt;
&lt;li&gt;Privacy frameworks must be clear and flexible.&lt;/li&gt;
&lt;li&gt;Oversight must be powerful to ensure proper protection of citizens in a world of asymmetry between individuals, corporations, and governments. &lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;The Right to Privacy is a fundamental right in Canada.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The Canadian privacy regime regulates the public sector and the private sector, but through two separate legislations.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The OPC does not have the power to levy fines, but does have the power to conduct audits and investigations and ‘name’ companies who are not in compliance with Canadian regulations if it is in the public interest. &lt;/li&gt;
&lt;/ol&gt; 
&lt;hr /&gt;
&lt;p&gt;Discussion: &lt;b&gt;The Data Protection Authority&lt;/b&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Participants also discussed the composition of the Data Protection Authority as described in chapter IV of the Privacy Protection Bill. It was called out that the in the Bill, the Data Protection Authority might need to be made more independent. It was suggested that to avoid having the office of the Data Protection Authority be filled with bureaucrats, the Bill should specify that the office must be staffed by individuals with IT experience, lawyers, judges, etc. On the other hand it was cautioned, that though this might be useful to some extent, it might not be helpful to be overly prescriptive, as there is no set profile of what composition of employees makes for a strong and effective Data Protection Authority. Instead the Bill should ensure that the office of the Data Protection Authority is independent, accountable, and chosen by an independent selection board.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When discussing possible models for the framework of the Data Protection Authority, it was pointed out that there are many models that could be adopted. Currently in India the commission model is not flexible, and many commissions that are set up, are not effective due to funding and internal bureaucracy. Taking that into account, in the Privacy Protection Bill, 2013, the Data Protection Authority, could be established as a small regulator with an appellate body to hear complaints.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;The Data Protection Authority established in the Privacy Protection Bill must be adequately independent.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The composition of the Data Protection Authority be diverse and it should have the competence to address the dynamic nature of privacy.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The Data Protection Authority could be established as a small regulator with an appellate body attached. &lt;/li&gt;
&lt;/ol&gt; 
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Presentation: &lt;b&gt;Christopher Graham&lt;/b&gt;,&lt;i&gt; Information Commissioner, United Kingdom&lt;/i&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Christopher Graham, the UK Information Commissioner, spoke about the privacy regime in the United Kingdom and his role as the UK Information Commissioner. As the UK Information Commissioner, his office is responsible for both the &lt;a class="external-link" href="https://www.gov.uk/data-protection"&gt;UK Data Protection Act&lt;/a&gt; and the&lt;a class="external-link" href="http://www.legislation.gov.uk/ukpga/2000/36/contents"&gt; Freedom of Information Act&lt;/a&gt;. In this way, the right to know is not in opposition to the right to privacy, but instead an integral part.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Graham said that his office also provides advice to data controllers on how to comply with the privacy principles found in the Data Protection Act, and his office has the power to fine up to half a million pounds on non-compliant data controllers. Despite having this power, it is rarely used, as a smaller fine is usually sufficient enough for the desired effect. Yet, at the end of the day, whatever penalty is levied, it must be proportionate and risk based i.e., selective to be effective. In this way the regulatory regime should not be heavy handed but instead should be subtle and effective. In fact, one of the strongest regulators is the reality of the market place where the price of not having strong standards is innovation and economic growth. To this extent, Graham also pointed out that self regulation and co-regulation are both workable models, if there is strong enforcement mechanisms. Graham emphasized the fact that any data protection must go beyond, and cannot be limited to, just security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Graham also explained that he has found that currently there is a lack of confidence in Indian partners. This is problematic as the Indian industry tries to grow with European partners. For example, he has been told that customers are moving banks because their previous bank’s back offices were located in India. Citing other examples of cases of data breaches from Indian data controllers, such as a call center merging the accounts of two customers and another call centre selling customer information, he explained that the lack of confidence in the Indian regime has real economic implications. Graham further explained that one difficulty that the office of the UK ICO is faced with, is that India does not have the equivalent of the ICO. Thus, when a breach does happen, it is unclear who can be approached in India about the breach.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Touching upon the issue of data adequacy with the EU, Graham noted that if data adequacy is a goal of India, the privacy principles as defined in the Directive and reflected in the UK Data Protection Act, must be addressed in addition to security. In his presentation, Graham emphasized the importance of India amending their current regime, if they want data secure status and spoke about the economic benefits for both Europe and India, if India does in fact obtain data secure status. In response to a question about why it is so important that India amend its laws, if in effect the UK has the ability to enforce the provisions of UK Data Protection Act, Graham clarified that most important is the rule of law, and according to UK law and more broadly the EU Directive, companies cannot transfer information to jurisdictions that do not have recognized adequate levels of protection. Thus, if companies still wish to transfer information to India, this must be done through binding corporate rules.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another question which was put forth was about how the right to privacy differs from other human rights, and why countries are requiring that other countries to uphold the right to privacy to the same level, when, for example this is not practiced for other human rights such as children’s rights. In response Graham explained that data belongs to the individual, and when it is transferred to another country — it still belongs to the individual. Although the UK would like all countries to uphold the rights of children to the standard that they do, the UK is not exporting UK citizen’s children to India. Thus, as the Information Commissioner he has a responsibility to protect his citizen’s data, even when it leaves the UK jurisdiction.  Graham explained further that in the history of Europe, the misuse of data to do harm has been a common trend, which is why privacy is seen as a fundamental right, and why it is paramount that European data is subject to the same level of protection no matter what jurisdiction it is in. India needs to understand that privacy is a fundamental right and goes beyond security, and that when a company processes data it does not own the data, the individual owns the data and thus has rights attached to it to understand why Europe requires countries to be ‘data secure’ before transferring data to them.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;The UK Information Commissioners Office regulates both the right to information and privacy, and thus the two rights are seen as integral to each other.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Penalties must be proportionate and scalable to the offense. &lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Co-regulation and self-regulation can both be viable models to for privacy, but enforcement is key to them being effective. &lt;/li&gt;
&lt;/ol&gt; 
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Discussion: &lt;b&gt;Collection of Data with Consent and Collection of Data without Consent&lt;/b&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Participants also discussed the collection of data with consent and the collection of data without consent found in Chapter III of the Bill. When asked opinions about the circumstances when informed consent should not be required,  it was pointed out that in the Canadian model, the option to collect information without consent only applies to the public sector if it is necessary for the delivery of a service by the government. In the private sector all collection of information requires informed and meaningful consent. Yet, collection of data without consent in the commercial context is an area that Canada is wrestling with, as there are instances, such as online advertising, where it is unreasonable to expect consent all the time. It was also pointed out that in the European Directive, consent is only one of the seven grounds under which data can be collected. As part of the conversation on consent, it was pointed out that the Bill currently does not take explicitly take into account the consent for transfer of information, and it does not address changing terms of service and if companies must re-take consent, or if providing notice to the individual was sufficient. The question about consent and additional collection of data that is generated through use of that service was also raised. For example, if an individual signs up for a mobile connection and initially provides information that the service provider stores in accordance to the privacy principles, does the service provider have an obligation to treat all data generated by the user while using the service of the same? The exception of disclosure without consent was also raised and it was pointed out that companies are required to disclose information to law enforcement when required. For example, telecom service providers must now store location data of all subscribers for up to 6 months and share the same when requested by law enforcement.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;There are instances where expecting companies to have informed consent for every collection of information is not reasonable. Alternative models, based on — for example transparency — must be explored to address these situations.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The Privacy Protection Bill should explicitly address transfer of information to other countries. &lt;/li&gt;
&lt;li style="text-align: justify; "&gt;The Privacy Protection Bill should address consent in the context of changing terms of service. &lt;/li&gt;
&lt;/ol&gt; 
&lt;hr /&gt;
&lt;p&gt;Discussion: &lt;b&gt;Penalties and Offences&lt;/b&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The penalties and offenses prescribed in chapter VI of the Privacy Protection Bill were discussed by participants. While discussing the chapter, many different opinions were voiced. For example, some participants held the opinion that offences and penalties should not exist in the Privacy Protection Bill, because in reality they are more likely than not to be effective. For example, when litigating civil penalties, it takes a long time for the money to be realized. Others argued that in India, where enforcement of any law is often weak, strong, clear, and well defined criminal penalties are needed. Another comment raised the point that a distinction should be made between breaches of the law by data controllers and breaches by rogue individuals — as the type of violation. For example, a breach by a data controller is often a matter identifying the breach and putting in place strictures to ensure that it does not happen again by holding the company accountable through oversight. Where as a breach by a rogue agent entails identifying the breach and the rogue agent and creating a strong enough penalty to ensure that they will not repeat the violation.  Adding to this discussion, it was pointed out that in the end, scalability is key in ensuring that penalties are proportional and effective. It was also noted that in the UK, any fine that is levied is appealable. This builds in a system of checks and balances, and ensures that companies and individuals are not subject to unfair or burdensome penalties.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The possibility of incentivizing compliance, through rewards and distinctions, was discussed by participants. Some felt that incentivizing compliance would be more effective as it would give companies distinct advantages to incorporating privacy protections, while others felt that incentives can be included but penalties cannot be excluded, otherwise the provisions of the Privacy Protection Bill 2013 will not be enforceable. It was also pointed out that in the context of India, ideally there should be a mechanism to address the ‘leakages’ that happen in the system i.e., corruption. Though this is difficult to achieve, regulations could take steps like specifically prohibiting the voluntary disclosure of information by companies to law enforcement. Taking a sectoral approach to penalties was also suggested as companies in different sectors face specific challenges and types of breaches. Another approach that could be implemented is the statement of a time limit for data controllers and commissioners to respond to complaints. This has worked for the implementation of the Right to Information Act in India, and it would be interesting to see how it plays out for the right to privacy. Throughout the discussion a number of different possible ways to structure offenses and penalties were suggested, but for all of them it was clear that  it is important to be creative about the type of penalties and not rely only on financial penalty, as for many companies, a fine has less of an impact than perhaps having to publicly disclose what happened around a data breach.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;Penalties and offenses by companies vs. rogue agents should be separately addressed in the Bill.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Instead of levying penalties, the Bill should include incentives to ensure compliance. &lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Penalties for companies should go beyond fines and include mechanisms such as requiring the company to disclose to the public information about the breach. &lt;/li&gt;
&lt;/ol&gt; 
&lt;hr /&gt;
&lt;p&gt;Discussion: &lt;b&gt;Cultural Aspects of Privacy&lt;/b&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The cultural realities of India, and the subsequent impact on the perception of privacy in India were discussed. It was pointed out that India has a history of colonization, multiple religions and languages, ethnic tensions, a communal based society, and a large population. All of these factors impact understandings, perceptions, practices, and the effectiveness of different frameworks around privacy in India. For example, the point was raised that given India’s cultural and political diversity, having a principle based model might be too difficult to enforce as every judge, authority, and regulator will have a different perspective and agenda. Other participants pointed out that there is a lack of awareness around privacy in India, and this will impact the effectiveness of the regulation. It was also highlighted that anecdotal claims that cultural privacy in India is different, such as the fact that in India on a train everyone will ask you personal questions, and thus Indian’s do not have a concept of privacy, cannot influence how a privacy law is framed for India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Key Points:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;India’s diverse culture will impact perceptions of privacy and the implementation of any privacy regulation.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Given India’s diversity, a principle based model might not be adequate. &lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Though culture is important to understand and incorporate into the framing of any privacy regulation in India, anecdotal stories and broad assumptions about India’s culture and societal norms around privacy cannot influence how a privacy law is framed for India. &lt;/li&gt;
&lt;/ol&gt;
&lt;h3 style="text-align: justify; "&gt;Conclusion&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The seventh privacy round-table concluded with a conversation on the NSA spying and the Snowden Revelations. It was asked if domestic servers could be an answer to protect Indian data. Participants agreed that domestic servers are just a band aid to the problem. With regards to the Privacy Protection Bill it was clarified that CIS is now in the process of collecting public statements to the Bill and will be submitting a revised version to the Department of Personnel and Training. Speaking to the privacy debate at large, it was emphasized that every stakeholder has an important voice and can impact the framing of a privacy law in India.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/report-of-sevent-privacy-round-table'&gt;https://cis-india.org/internet-governance/blog/report-of-sevent-privacy-round-table&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-20T09:58:39Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you">
    <title>Why 'Facebook' is More Dangerous than the Government Spying on You</title>
    <link>https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you</link>
    <description>
        &lt;b&gt;In this article, Maria Xynou looks at state and corporate surveillance in India and analyzes why our "choice" to hand over our personal data can potentially be more harmful than traditional, top-down, state surveillance. Read this article and perhaps reconsider your "choice" to use social networking sites, such as Facebook. &lt;/b&gt;
        
&lt;p align="JUSTIFY"&gt;&lt;i&gt;Do you have a profile on Facebook?&lt;/i&gt; Almost every time I ask this question, the answer is ‘yes’. In fact, I think the amount of people who have replied ‘no’ to this question can literally be counted on my right hand. But this is not an article about Facebook per se. It’s more about the ‘Facebooks’ of the world, and of people’s increasing “choice” to hand over their most personal data. More accurate questions are probably:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;“&lt;i&gt;Would you like the Government to go through your personal diary? If not, then why do you have a profile on Facebook?”&lt;/i&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span&gt;&lt;b&gt;The Indian Surveillance State&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;Following &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;Snowden&lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;’&lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;s&lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt; &lt;/a&gt;&lt;a href="http://news.yahoo.com/nsa-revelations-timeline-whats-come-since-snowden-leaks-203656274.html"&gt;revelations&lt;/a&gt;&lt;/span&gt;, there’s finally been more talk about surveillance. But what is surveillance?&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;David Lyon - who directs the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.sscqueens.org/"&gt;Surveillance&lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt; &lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt;Studies&lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt; &lt;/a&gt;&lt;a href="http://www.sscqueens.org/"&gt;Centre&lt;/a&gt;&lt;/span&gt; - &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;defines&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;surveillance&lt;/a&gt;&lt;/span&gt; as &lt;i&gt;“any collection and processing of personal data, whether identifiable or not, for the purposes of influencing or managing those whose data have been garnered”&lt;/i&gt;. &lt;a href="http://www.polity.co.uk/book.asp?ref=9780745635910"&gt;&lt;span style="text-decoration: underline;"&gt;Surveillance&lt;/span&gt;&lt;/a&gt; can also be defined as the monitoring of the behaviour, activities or other changing information of individuals or groups of people. However, this definition implies that individuals and/or groups of people are being monitored in a top-down manner, without this being their “choice”. But is that actually the case? To answer this question, let’s have a look at how the Indian government and corporations operating in India spy on us.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;State Surveillance&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;The first things that probably come to mind when thinking about India from a foreigner’s perspective are poverty and corruption. Surveillance appears to be a “Western, elitist issue”, which mainly concerns those who have already solved their main survival problems. In other words, the most mainstream argument I hear in India is that surveillance is not a &lt;i&gt;real &lt;/i&gt;issue, especially since the majority of the population in the country lives below the line of poverty and does not even have any Internet access. Interestingly enough though, the other day when I was walking around a slum in Koramangala, I noticed that most people have Airtel satellites...even though they barely have any clean water!&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The point though is that surveillance in India is a fact, and the state plays a rather large role in it. In particular, Indian law enforcement agencies follow three steps in ensuring that targeted and mass surveillance is carried out in the country:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. They create surveillance schemes, such as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Monitoring&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;System&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; (&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;)&lt;/a&gt;&lt;/span&gt;, which carry out targeted and/or mass surveillance&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. They create laws, guidelines and license agreements, such as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; 2008&lt;/a&gt;&lt;/span&gt;, which mandate targeted and mass surveillance and which require ISP and telecom operators to comply&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. They buy surveillance technologies from companies, such as CCTV cameras and spyware, and use them to carry out targeted and/or mass surveillance&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While Indian law enforcement agencies don’t necessarily follow these steps in this precise order, they usually try to create surveillance schemes, legalise them and then buy the gear to carry them out.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In particular, surveillance in India is regulated under five laws: the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; 1885&lt;/a&gt;&lt;/span&gt;, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Post&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Office&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; 1898&lt;/a&gt;&lt;/span&gt;, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Wireless&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Telegraphy&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; 1933&lt;/a&gt;&lt;/span&gt;, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;section&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; 91 &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;of&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;the&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; 1973 &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;Code&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;of&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;Criminal&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; &lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;Procedure&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt; (&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;CrPc&lt;/a&gt;&lt;a href="http://indiankanoon.org/doc/911085/"&gt;)&lt;/a&gt;&lt;/span&gt; and the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; 2008&lt;/a&gt;&lt;/span&gt;. These laws mandate targeted surveillance, but remain silent on the issue of mass surveillance which means that technically it is neither allowed nor prohibited, but remains a grey legal area.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While surveillance laws in India may not mandate mass surveillance, some of their sections are particularly concerning. Section 69 of the&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; 2008&lt;/a&gt;&lt;/span&gt; allows for the interception of all information transmitted through a computer resource, while requiring that all users disclose their private encryption keys or face a jail sentence of up to seven years. This appears to be quite bizarre, as individuals can only keep their data private and protect themselves from surveillance through encryption.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Section 44 of the Information Technology (Amendment) Act 2008 imposes stiff penalties on anyone who fails to provide requested information to authorities - which kind of reminds us of Orwell’s totalitarian regime in &lt;a href="http://www.ministryoflies.com/1984.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;“1984”&lt;/span&gt;&lt;/a&gt;. Furthermore, section 66A of the same law states that individuals will be punished for sending “offensive messages through communication services”. However, the vagueness of this section raises huge concerns, as it remains unclear what defines an “offensive message” and whether this will have grave implications on the freedom of expression. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;arrest&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;of&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;two&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;Indian&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;women&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;last&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;November&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;over&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;a&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;Facebook&lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt; &lt;/a&gt;&lt;a href="http://www.hindustantimes.com/india-news/mumbai/outrage-after-arrest-of-2-women-for-facebook-post-on-mumbai-shutdown/article1-961377.aspx"&gt;post&lt;/a&gt;&lt;/span&gt; reminds us of this.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Laws in India may not mandate mass surveillance, but guidelines and license agreements issued by the Department of Telecommunications do. In particular, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;regarding&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;the&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Central&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;System&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; (&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;CMS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;) &lt;/a&gt;&lt;/span&gt;not only mandates mass surveillance, but also attempts to legalise a mass surveillance scheme which aims to intercept all telecommunications and Internet communications in India. Furthermore, the Department of Telecommunications has issued &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;numerous&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;guidelines&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;and&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;license&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;agreements&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;for&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;ISPs&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;and&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;telecom&lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/data-services/internet-services"&gt;operators&lt;/a&gt;&lt;/span&gt;, which require them to not only be “surveillance-friendly”, but to also enable law enforcement agencies to tap into their servers on the grounds of national security. And then, of course, there’s the new &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;National&lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;Cyber&lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;Security&lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/national-cyber-security-policy-2013-1"&gt;Policy&lt;/a&gt;&lt;/span&gt;, which mandates surveillance to tackle cyber-crime, cyber-terrorism, cyber-war and cyber-vandalism.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;As both a result and prerequisite of these laws, the Indian government has created various surveillance schemes and teams to aid them. In particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;India&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;’&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;s&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Computer&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Emergency&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Response&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; &lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;Team&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt; (&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;CERT&lt;/a&gt;&lt;a href="http://deity.gov.in/content/indian-computer-emergency-response-team-cert"&gt;)&lt;/a&gt;&lt;/span&gt; is currently monitoring “any suspicious move on the Internet” in order to checkmate any potential cyber attacks from hackers. While this may be useful for the purpose of preventing and detecting cyber-criminals, it remains unclear how “any suspicious move” is defined and whether that inevitably enables mass surveillance, without individuals’ knowledge or consent.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Crime&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;and&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Criminal&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Tracking&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;and&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Network&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; &amp;amp; &lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;Systems&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt; (&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;CCTNS&lt;/a&gt;&lt;a href="http://ncrb.gov.in/cctns.htm"&gt;)&lt;/a&gt;&lt;/span&gt; is the creation of a nationwide networking infrastructure for enhancing the efficiency and effectiveness of policing and sharing data among 14,000 police stations across the country. It has been estimated that Rs. 2000 crore has been allocated for the CCTNS project and while it may potentially increase the effectiveness of tackling crime and terrorism, it raises questions around the legality of data sharing and its potential implications on the right to privacy and other human rights - especially if such data sharing results in data being disclosed or shared with unauthorised third parties.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Similarly, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;National&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt; &lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;Intelligence&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt; &lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;Grid&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt; (&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;NATGRID&lt;/a&gt;&lt;a href="http://cybersecurityforindia.blogspot.in/2012/12/national-intelligence-grid-natgrid.html"&gt;)&lt;/a&gt;&lt;/span&gt; is an integrated intelligence grid that will link the databases of several departments and ministries of the Government of India so as to collect comprehensive patterns of intelligence that can be readily accessed by intelligence agencies. This was first proposed in the aftermath of the Mumbai 2008 terrorist attacks and while it may potentially aid intelligence agencies in countering crime and terrorism, enforced privacy legislation should be a prerequisite, which would safeguard our data from potential abuse.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;However, the most controversial surveillance scheme being implemented in India is probably the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Monitoring&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;System&lt;/a&gt;&lt;/span&gt; (CMS). While several states, such as Assam, already have &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Internet&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Systems&lt;/a&gt;&lt;/span&gt; in place, the Central Monitoring System appears to raise even graver concerns. In particular, the CMS is a system through which all telecommunications and Internet communications in India will be monitored by Indian authorities. In other words, the CMS will be capable of intercepting our calls and of analyzing our data on social networking sites, while all such data would be retained in a centralised database. Given that India currently lacks privacy legislation, such a system would mostly be unregulated and would pose major threats to our right to privacy and other human rights. Given that data would be centrally stored, the system would create a type of “honeypot” for centralised cyber attacks. Given that the centralised database would have massive volumes of data for literally a billion people, the probability of error in pattern and profile matching would be high - which could potentially result in innocent people being convicted for crimes they did not commit. Nonetheless, mass surveillance through the CMS is currently a reality in India.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And the even bigger question: How can law enforcement agencies mine the data of 1.2 billion people? How do they even carry out surveillance in practice? Well, that’s where surveillance technology companies come in. In fact, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;surveillance&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;industry&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;in&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/the-surveillance-industry-in-india-at-least-76-companies-aiding-our-watchers"&gt;India&lt;/a&gt;&lt;/span&gt; is massively expanding - especially in light of its new surveillance schemes which require advanced and sophisticated technology. According to &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;CIS&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;’ &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;India&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;Privacy&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;Monitor&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;Map&lt;/a&gt;&lt;/span&gt; - which is part of ongoing research - Indian law enforcement agencies use CCTV cameras in pretty much every single state in India. The map also shows that Unmanned Aerial Vehicles (UAVs), otherwise known as drones, are being used in most states in India and the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;DRDO&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;’&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;s&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt; “&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;Netra&lt;/a&gt;&lt;a href="http://defence.pk/threads/drdo-develops-uav-netra-to-aid-anti-terrorist-operations.64086/"&gt;”&lt;/a&gt;&lt;/span&gt; - which is a lightweight drone, not much bigger than a bird - is particularly noteworthy.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;But Indian law enforcement agencies also buy surveillance software and hardware which is aimed at intercepting telecommunications and Internet communications. In particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.clear-trail.com/"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt; &lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt;Technologies&lt;/a&gt;&lt;/span&gt; is an Indian company - based in Indore - which equips law enforcement agencies in India and around the world with &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;surveillance&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;software&lt;/a&gt;&lt;/span&gt; which can probably be compared with the “notorious” FinFisher. So in short, there appears to be a tight collaboration between Indian law enforcement agencies and the surveillance industry, which can be clearly depicted in the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;surveillance&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;trade&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;shows&lt;/a&gt;&lt;/span&gt;, otherwise known as “the wiretappers’ ball”.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Corporate Surveillance&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;When I ask people about corporate surveillance, the answer I usually get is: &lt;i&gt;“Corporations only care about their profit - they don’t do surveillance per se”&lt;/i&gt;. And while that may be true, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;David&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;Lyon&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;’&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;s&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;definition&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;of&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;surveillance&lt;/a&gt;&lt;/span&gt; - as &lt;i&gt;“any collection and processing of personal data, whether identifiable or not, for the purposes of influencing or managing those whose data have been garnered” &lt;/i&gt;- may indicate otherwise.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Corporations, like Google, Amazon and Facebook, may not have an agenda for spying per se, but they do collect massive volumes of personal data and, in cases such as PRISM, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;allow&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;law&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;enforcement&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;to&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;tap&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;into&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;their&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;servers&lt;/a&gt;&lt;/span&gt;. Once law enforcement agencies get hold of data collected by companies, such as Facebook, they then use data mining software - equipped by various surveillance technology companies - to process and mine the data. And how do companies, like Google and Facebook, make money off our personal data? By selling it to big buyers, such as law enforcement agencies.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;So while Facebook and all the ‘Facebooks’ of the world may not profit from surveillance per se, they do profit from collecting our personal data and selling it to third parties, which include law enforcement agencies. And David Lyon argues that &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;surveillance&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;involves&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;the&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;collection&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;of&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;personal&lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt; &lt;/a&gt;&lt;a href="https://globalsociology.pbworks.com/w/page/14711234/Network%20Society%20or%20Surveillance%20Society"&gt;data&lt;/a&gt;&lt;/span&gt; - which corporations, like Facebook, do - for the purpose of influencing and managing individuals. While this last point can probably be  widely debated on, it is clear that corporations share their collected data with third parties, which ultimately leads to the influence or managing of individuals - directly or indirectly. In other words, the collection of personal data, in combination with its disclosure to third parties, &lt;i&gt;is&lt;/i&gt; surveillance. So when we think about companies, like Google or Facebook, we should not just think of businesses interested in their profit - but also of spying agencies. After all, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;“&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;if&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;the&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;product&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;is&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;free&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;, &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;you&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;are&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;the&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;product&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/marketshare/2012/03/05/if-youre-not-paying-for-it-you-become-the-product/"&gt;”&lt;/a&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Now if we look at online corporations more closely, we can probably identify three categories:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. Websites through which we &lt;i&gt;buy products &lt;/i&gt;and hand over our personal details - e.g. Amazon&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. Websites through which we &lt;i&gt;use services&lt;/i&gt; and hand over our personal details - e.g. flight ticket&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. Websites through which we &lt;i&gt;communicate&lt;/i&gt; and hand over our personal details - e.g. Facebook&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And why could the above be considered “spying” at all? Because such corporations collect massive volumes of personal data and subsequently:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;Disclose&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;such&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;data&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;to&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;law&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;enforcement&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/03/22/technology/microsoft-releases-report-on-law-enforcement-requests.html"&gt;agencies&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;Allow&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;law&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;enforcement&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;agencies&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;to&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;tap&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;into&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;their&lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt; &lt;/a&gt;&lt;a href="http://www.nytimes.com/2013/06/09/us/revelations-give-look-at-spy-agencys-wider-reach.html?_r=2&amp;amp;"&gt;servers&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Sell such data to “third parties”&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;What’s notable about so-called corporate surveillance is that, in all cases, there is a mutual, key element: we &lt;i&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;consent&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;to&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;the&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;handing&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;over&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;of&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;our&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;personal&lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt; &lt;/a&gt;&lt;a href="https://www.eff.org/wp/know-your-rights"&gt;information&lt;/a&gt;&lt;/span&gt;. We are not forced to hand over our personal data when buying a book online, booking a flight ticket or using Facebook. Instead, we “choose” to hand over our personal data in exchange for a product or service. Now what significantly differentiates state surveillance to corporate surveillance is the factor of &lt;i&gt;“choice”&lt;/i&gt;. While we may choose to hand over our most personal details to large online corporations, such as Google and Facebook, we do not have a choice when the government monitors our communications, collects and stores our personal data.&lt;/p&gt;

&lt;h2 align="JUSTIFY"&gt;&lt;span&gt;&lt;b&gt;State Surveillance &lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt;vs.&lt;/b&gt;&lt;/i&gt;&lt;span&gt;&lt;b&gt; Corporate Surveillance&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;Both Indian law enforcement agencies and corporations collect massive volumes of personal data. In fact, it is probably noteworthy to mention that Facebook, in particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;collects&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; 20 &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;times&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;more&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;data&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;per&lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt; &lt;/a&gt;&lt;a href="http://www.zdnet.com/data-driven-analysis-debunks-claims-that-nsa-is-out-of-control-special-report-7000019522/"&gt;day&lt;/a&gt;&lt;/span&gt; than the NSA in total. In addition, Facebook has &lt;a href="http://www.ft.com/cms/s/0/7536d216-0f36-11e3-ae66-00144feabdc0.html#axzz2jDSrZPHv"&gt;&lt;span style="text-decoration: underline;"&gt;claimed&lt;/span&gt;&lt;/a&gt; that it has received more demands from the US government for information about its users than from all other countries combined. In this sense, the corporate collection of personal data can potentially be more harmful than government surveillance, especially when law enforcement agencies are tapping into the servers of companies like Facebook. After all, the Indian government and all other governments would have very little data to analyse if it weren’t for such corporations.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Surveillance is not just about “spying” or about “watching people” - it’s about much much more. Observing people’s behaviour only really becomes harmful when the data observed is collected, retained, analysed, shared and disclosed to unauthorised third parties. In other words, surveillance is meaningful to examine because it involves the &lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt;&lt;i&gt;&lt;span style="text-decoration: underline;"&gt;analysis&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt; &lt;/a&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt;of&lt;/a&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt; &lt;/a&gt;&lt;a href="https://www.sogeti.nl/updates/vint/internet-things-has-dark-side-well-surveillance"&gt;data&lt;/a&gt;&lt;/span&gt;, which in turn involves &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;pattern&lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;matching&lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;and&lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.surveillance-and-society.org/articles1/whatsnew.pdf"&gt;profiling&lt;/a&gt;&lt;/span&gt;, which can potentially have actual, real-world implications - good or bad. But such analysis cannot be possible without having access to large volumes of data - most of which belong to large corporations, like Facebook. The question, though, is: How do corporations collect such large volumes of personal data, which they subsequently share with law enforcement agencies? Simple: Because &lt;i&gt;we “choose”&lt;/i&gt; to hand over our data!&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Three years ago, when I was doing research on young people’s perspective of Facebook, all of the interviewees replied that they feel that they are in control of their personal data, because they “choose” what they share online. While this may appear to be a valid point,  the “choice” factor can widely be debated on. There are many reasons why people “choose” to hand over their personal data, whether to buy a product, use a service, to communicate with peers or because they feel socially pressured into using social networking sites. Nonetheless, it all really comes down to one main reason: &lt;a href="http://edition.cnn.com/2010/TECH/04/14/oppmann.off.the.grid/"&gt;&lt;i&gt;&lt;span style="text-decoration: underline;"&gt;convenience&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;. Today, in most cases, the reason why we hand over our personal data online in exchange for products or services is because it is simply more convenient to do so. And while that is understandable, at the same time we are exposing our data (and ultimately our lives) in the name of convenience.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The irony in all of this is that, while many people reacted to &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;Snowden&lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;’&lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;s&lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt; &lt;/a&gt;&lt;a href="http://america.aljazeera.com/articles/multimedia/timeline-edward-snowden-revelations.html"&gt;revelations&lt;/a&gt;&lt;/span&gt; on NSA dragnet surveillance, most of these people probably have profiles on Facebook. Secret, warrantless government surveillance is undeniably intrusive, but in the end of the day, our profiles on Facebook - and on all the ‘Facebooks’ of the world - is what enabled it to begin with. In other words, if we didn’t choose to give up our personal data - especially without really knowing how it would be handled - large databases would not exist and the NSA - and all the ‘NSAs’ of the world - would have had a harder time gathering and analysing data.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, the main difference between state and corporate surveillance is that the first is imposed in a top-down manner by authorities, while the second is a result of our “choice” to give up our data. While many may argue that it’s worse to have control imposed on you, I strongly disagree. When control and surveillance are imposed on us in a top-down manner, it’s likely that we will perceive this - sooner or later - as a &lt;i&gt;direct&lt;/i&gt; threat to our human rights, which means that it’s likely that we will resist to it at some point. People usually react to what they perceive as a direct threat, whereas &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;they&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;rarely&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;react&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;to&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;what&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;does&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;not&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;directly&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;affect&lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/essay-155.html"&gt;them&lt;/a&gt;&lt;/span&gt;. For example, one may perceive murder or suicide as a direct threat due the immediateness of its effect, whereas smoking may not be seen as an equally direct threat, because its consequences are indirect and can usually be seen in the long term. It’s somehow like that with surveillance.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;University&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;students&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;have&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;protested&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;on&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;streets&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;against&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;installation&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;CCTV&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy/cctv-in-universities"&gt;cameras&lt;/a&gt;&lt;/span&gt;, but how many of them have profiles on social networking sites, such as Facebook? People may react to the installation of CCTV cameras, because it may appear as a direct threat to their right to privacy. However, the irony is that the real danger does not necessarily lie within some CCTV cameras, but rather within the profile of each person on a major commercial social networking site. At very best, a CCTV camera will capture some images of us and through that, track our location and possibly our acquaintances. What type of data is captured through a simple, “harmless” Facebook profile? The following probably only includes a tiny percentage of what is actually captured:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Personal photos&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Biometrics (possibly through photos)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Family members&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Friends and acquaintances&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Habits, hobbies and interests&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Location (through IP address)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Places visited&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Economic standing (based on pictures, comments, etc.)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Educational background&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Ideas and opinions (which may be political, religious, etc.)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Activities&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Affiliations&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The above list could potentially go on and on, probably depending on how much - or what type - of data is disclosed by the individual. The interesting element to this is that &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;we&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;can&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;never&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;really&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;know&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;how&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;much&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;data&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;we&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;are&lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt; &lt;/a&gt;&lt;a href="http://www.forbes.com/sites/cherylsnappconner/2012/10/19/sharing-too-much-itll-cost-you/"&gt;disclosing&lt;/a&gt;&lt;/span&gt;, even if we think we control it. While an individual may argue that he/she chooses to disclose an x amount of data, while retaining the rest, that individual may actually be disclosing a 10x amount of data. This may be the case because usually every bit of data hides lots of other bits of data, that we may not be aware of. &lt;i&gt;It all really comes down to who is looking at our data, when and why.&lt;/i&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;For example, (fictional) Priya may choose to share on her Facebook profile (through photos, comments, or any other type of data) that she is female, Indian, a Harvard graduate and that her favourite book is &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;“&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;Anarchism&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt; &lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;and&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt; &lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;other&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt; &lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;Essays&lt;/a&gt;&lt;a href="http://www.free-ebooks.net/ebook/Anarchism-and-other-essays/pdf/view"&gt;”&lt;/a&gt;&lt;/span&gt; by Emma Goldman. At first glance, nothing appears to be “wrong” with what Priya is revealing and in fact, she appears to care about her privacy by not revealing “the most intimate details” of her life. Moreover, one could argue that there is absolutely nothing “incriminating” about her data and that, on the contrary, it just reflects that she is a “shiny star” from Harvard. However, I am not sure if a data analyst would be restricted to this data and if data analysis would show the same “sparkly” image.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In theory, the fact that Priya is an Indian who attended Harvard reveals another bit of information, that Priya did not choose to share: her economic standing. Given that the majority of Indians live below the line of poverty, there is a big probability that Priya belongs to India’s middle class - if not elite. Priya may not have intentionally shared this information, but it was indirectly revealed through the bits of data that she did reveal: female Indian and Harvard graduate. And while there may not be anything “incriminating” about the fact that she has a good economic standing, in India this usually means that there’s also some strong political affiliation. That brings us to her other bit of information, that her favourite author is a feminist, anarchist. While that may be viewed as indifferent information, it may be crucial depending on the specific political actors in the country she’s in and on the general political situation. If a data analyst were to map the data that Priya chose to share, along with all her friends and acquaintances that she inevitably has through Facebook, that data analyst could probably tell a story about her. And the concerning part is that that story may or may not be true. But that doesn’t really matter.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Today, governments don’t judge us and take decisions based on our version of our data, but&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;based&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;on&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;what&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;our&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;data&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;says&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;about&lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt; &lt;/a&gt;&lt;a href="http://www.npr.org/blogs/alltechconsidered/2013/10/02/228134269/your-digital-trail-does-the-fourth-amendment-protect-us"&gt;us&lt;/a&gt;&lt;/span&gt;. And perhaps, under certain political, social and economic circumstances, our “harmless” data could be more incriminating than what we think. While an individual may express strong political views within a democratic regime, if that political system were to change in the future and to become authoritarian, that individual would possibly be suspicious in the eyes of the government - to say the least. This is where data retention plays a significant role.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Most companies &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;retain&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;data&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;indefinitely&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;or&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;for&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;a&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;long&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;period&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.bryancave.com/files/Publication/cbd3503b-c968-4565-9cc7-016b9aa3b6f1/Presentation/PublicationAttachment/b24d1c5a-4550-4207-9486-062a025da8d9/Data%20Privacy%20and%20Security%20Team_Retaining%20Data_March%202012.pdf"&gt;time&lt;/a&gt;&lt;/span&gt;, which means that future, potentially less-democratic governments may have access to it. And the worst part is that we can never really know what data is being held about us, because within data analysis, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;every&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;bit&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;data&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;may&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;potentially&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;entails&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;various&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;other&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;bits&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;data&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;that&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;we&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;are&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;not&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;even&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;aware&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/spy-files-three"&gt;of&lt;/a&gt;&lt;/span&gt;. So, when we “choose” to hand over our data, we don’t necessarily know what or how much we are choosing to disclose. Thus, this is why I agree with Bruce Schneier’s argument that people have an &lt;i&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;illusionary&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;sense&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;of&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;control&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;a href="https://www.schneier.com/blog/archives/2006/09/facebook_and_da.html"&gt;&lt;span style="text-decoration: underline;"&gt; &lt;/span&gt;&lt;/a&gt;over their personal data.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;Social&lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt; &lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;network&lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt; &lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;analysis&lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt; &lt;/a&gt;&lt;a href="http://www.faculty.ucr.edu/~hanneman/nettext/"&gt;software&lt;/a&gt;&lt;/span&gt; is specifically designed to mine huge volumes of data that is collected through social networking sites, such as Facebook. Such software is specifically designed to profile individuals, to create “trees of communication” around them and to &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.scs.ryerson.ca/~bgajdero/research/Malta08.pdf"&gt;match&lt;/a&gt;&lt;a href="http://www.scs.ryerson.ca/~bgajdero/research/Malta08.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.scs.ryerson.ca/~bgajdero/research/Malta08.pdf"&gt;patterns&lt;/a&gt;&lt;/span&gt;. In other words, this software tells a story about each and every one of us, based on our activities, interests, acquaintances, and all other data. And as mentioned before, such a story may or may not be true.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In data mining, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.sagepub.com/upm-data/40006_Chapter1.pdf"&gt;behavioural&lt;/a&gt;&lt;a href="http://www.sagepub.com/upm-data/40006_Chapter1.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.sagepub.com/upm-data/40006_Chapter1.pdf"&gt;statistics&lt;/a&gt;&lt;/span&gt; are being used to analyse our data and to predict how we are likely to behave. When applied to national databases, this may potentially amount to predicting how masses or groups within the public are likely to behave and to subsequently control them.  If a data analyst can predict an individual’s future behaviour - with some probability - based on that individuals’ data, the same could potentially occur on a mass, public level.  As such, the danger within surveillance - especially corporate surveillance through which we&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;voluntarily&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;disclose&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;massive&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;amounts&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;of&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/08/the_publicpriva_1.html"&gt;data&lt;/a&gt;&lt;/span&gt; about ourselves - is that it appears to come down to &lt;i&gt;public control&lt;/i&gt;.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;According to security expert Bruce Schneier, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;data&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;today&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;is&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;a&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;byproduct&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;of&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;the&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;Information&lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt; &lt;/a&gt;&lt;a href="http://edition.cnn.com/2013/10/16/opinion/schneier-surveillance-trajectories/"&gt;Society&lt;/a&gt;&lt;/span&gt;.  Unlike an Orwellian totalitarian state where surveillance is imposed in a top-down manner, surveillance today appears to widely exist because we indirectly choose and enable it (by handing over our data to online companies), rather than it being imposed on us in a solely top-down manner. However, contemporary surveillance may potentially be far worse than that described in Orwell’s “1984”, because surveillance is publicly perceived to be an &lt;i&gt;indirect &lt;/i&gt;threat - if considered to be a threat at all. It is more likely that people will resist a direct threat, than an indirect threat, which means that the possibility of mass violations of human rights as a result of surveillance is real.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Hannah Arendt argued that a main prerequisite and component of totalitarian power is &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;support&lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt; &lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;by&lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt; &lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;the&lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt; &lt;/a&gt;&lt;a href="http://livingtext.wordpress.com/2012/11/26/totalitarianism-was-supported-by-the-masses/"&gt;masses&lt;/a&gt;&lt;/span&gt;. Today, surveillance appears to be socially integrated within societies which indicates that contemporary power fueled by surveillance has mass support. While the argument that surveillance is being socially integrated can potentially be widely debated on and requires an entire in depth research of its own, few simple facts might be adequate to prove it at this stage. Firstly, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;CCTV&lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/cisprivacymonitor"&gt;cameras&lt;/a&gt;&lt;/span&gt; are installed in most countries, yet there has been very little resistance - on the contrary, there appears to be a type of universal acceptance on the grounds of security. Secondly, different types of spy products exist in the market - such as &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;Spy&lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt; &lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;Coca&lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt; &lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;Cola&lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt; &lt;/a&gt;&lt;a href="http://www.medianama.com/2013/05/223-surveillance-industry-study-shows-at-least-76-companies-aiding-surveillance-in-india-cis-india/"&gt;cans&lt;/a&gt;&lt;/span&gt; - which can be purchased by anyone online. Thirdly, countries all over the world carry out controversial surveillance schemes - such as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt;Central&lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt; &lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt; &lt;/a&gt;&lt;a href="http://www.techdirt.com/articles/20130629/17255423670/how-indian-governments-central-monitoring-system-makes-nsa-look-like-paragon-restraint.shtml"&gt;System&lt;/a&gt;&lt;/span&gt; in India - yet public resistance to such projects is limited. And while one may argue that the above cases don’t necessarily prove that surveillance is being socially integrated, it would be interesting to look at a fourth fact: most people who have Internet access &lt;i&gt;choose &lt;/i&gt;to share their personal data through the use of social networking sites.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Reality shows, such as Big Brother, which broadcast the surveillance of people’s lives and present it as a form of entertainment - when actually, I think it should be worrisome - appear to enable the social integration of surveillance. The very fact that we all probably - or, hopefully - know that Facebook can share our personal data with unauthorised third parties and - now, after the Snowden revelations - that governments can tap into Facebook’s servers, should be enough to convince us to delete our profiles. Yet, why do we still all have Facebook profiles? Perhaps because surveillance is socially integrated and perhaps because it is just &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;convenient&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;to&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;be&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;on&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2013/06/trading_privacy_1.html"&gt;Facebook&lt;/a&gt;&lt;/span&gt;. But that doesn’t change the fact that surveillance can potentially be a threat to our human rights. It just means that we perceive surveillance as an indirect threat and that we are unlikely to react to it.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In the long term, what does this mean? Well, it seems like we will probably be &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;more&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;acceptive&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;towards&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;more&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;authoritarian&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate"&gt;power&lt;/a&gt;&lt;/span&gt;, that we will be used to the idea of censoring our own thoughts and actions (in the fear of getting caught by the CCTV camera on the street or the spyware which may or may not be implanted in our laptop) and that ultimately, we will be less politically active and more reluctant to challenge the authority.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;What’s particularly interesting though about surveillance today is that it is fueled and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;enabled&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;through&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;our&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;freedom&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;of&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;speech&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;and&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;general&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;Internet&lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt; &lt;/a&gt;&lt;a href="http://www.amazon.com/The-Net-Delusion-Internet-Freedom/dp/1610391063"&gt;freedom&lt;/a&gt;&lt;/span&gt;. If we didn’t have any Internet freedom - or as much as we do - we would have disclosed less personal data and thus surveillance would probably have been more restricted. The more Internet freedom we have, the more personal data we will disclose on Facebook - and on all the ‘Facebooks’ of the world - and the more data will potentially be available to mine, analyse, share and generally incorporate in the surveillance regime. So in this sense, Internet freedom appears to be a type of prerequisite of surveillance, as contradictory and ironic as it may seem. No wonder why the Chinese government has gone the extra mile in creating the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;Chinese&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;versions&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;of&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;Facebook&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;and&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt;Twitter&lt;/a&gt;&lt;a href="http://www.mirror.co.uk/news/world-news/weibo-chinese-version-of-twitter-can-1545515"&gt; &lt;/a&gt;&lt;/span&gt;- it’s probably no coincidence.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While we may blame governments for establishing surveillance schemes, ISP and TSP operators for complying with governments’ license agreements which often mandate that they create backdoors for spying on us and security companies for creating the surveillance gear in the first place, in the end of the day, we are all equally a part of this mess. If we didn’t &lt;i&gt;choose &lt;/i&gt;to hand over our personal data to begin with, none of the above would have been possible.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The real danger in the Digital Age is not necessarily surveillance per se, but our &lt;i&gt;choice&lt;/i&gt; to voluntarily disclose our personal data.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you'&gt;https://cis-india.org/internet-governance/blog/why-facebook-is-more-dangerous-than-the-government-spying-on-you&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-23T08:38:30Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/hindustan-times-november-2-2013-nagender-sharma-alok-tikku-spy-agencies-ib-and-raw-put-spanner-in-proposed-privacy-law">
    <title>Spy agencies, IB and RAW, put spanner in proposed privacy law</title>
    <link>https://cis-india.org/news/hindustan-times-november-2-2013-nagender-sharma-alok-tikku-spy-agencies-ib-and-raw-put-spanner-in-proposed-privacy-law</link>
    <description>
        &lt;b&gt;The country’s intelligence agencies are out to scuttle a law that’s being drafted to protect your privacy.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The article by Nagender Sharma and Aloke Tikku was &lt;a class="external-link" href="http://www.hindustantimes.com/india-news/spy-agencies-ib-and-raw-put-spanner-in-proposed-privacy-law/article1-1146418.aspx"&gt;published in the Hindustan Times&lt;/a&gt; on November 2, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Intelligence Bureau and the Research and Analysis Wing (RAW) have  told the government to water down the proposed law that makes it a  crime to leak sensitive personal information collected by government  departments and the private sector.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The agencies conveyed their views to national security adviser  Shivshankar Menon at a recent meeting at the prime minister’s office.  With home secretary Anil Goswami backing the spooks, even arguing that  “the very need for such a bill” should be reviewed, Menon has called for  revisiting the provisions the agencies have objected to.&lt;/p&gt;
&lt;div class="nocontent" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;p style="text-align: justify; "&gt;The Right to Privacy Bill 2013 lays down privacy principles and  standards, and stipulates jail terms and fines for leak of sensitive  personal data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“If such a bill was to be considered, intelligence agencies should be exempted from its purview,” Goswami argued at the meeting.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The intelligence agencies also spoke about how the bill would  “adversely affect or compromise” the functioning of many agencies and  projects, such as the Central Monitoring System that is used to  intercept phone calls and internet communication, and the National  Intelligence Grid that would give law enforcement agencies access to  information combat terror threats.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The proposed privacy law was initially conceptualised to address data  privacy, particularly in the context of data handled by the Indian IT  industry for foreign clients.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But the Department of Personnel and Training – that drew up the bill –  expanded its scope to cover information collected by the government and  interception by intelligence agencies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sunil Abraham of the Centre for Internet and Society, a  Bangalore-headquartered advocacy group, said the security  establishment’s attempts to scuttle the privacy law were a step back.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Civil society isn’t against surveillance by security agencies. All that we ask for is due process and oversight,” Abraham said.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/hindustan-times-november-2-2013-nagender-sharma-alok-tikku-spy-agencies-ib-and-raw-put-spanner-in-proposed-privacy-law'&gt;https://cis-india.org/news/hindustan-times-november-2-2013-nagender-sharma-alok-tikku-spy-agencies-ib-and-raw-put-spanner-in-proposed-privacy-law&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-19T09:50:05Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate">
    <title>Interview with Caspar Bowden - Privacy Advocate and former Chief Privacy Adviser at Microsoft</title>
    <link>https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate</link>
    <description>
        &lt;b&gt;Maria Xynou recently interviewed Caspar Bowden, an internationally renowned privacy advocate and former Chief Privacy Adviser at Microsoft. Read this exciting interview and gain an insight on India's UID and CMS schemes, on the export of surveillance technologies, on how we can protect our data in light of mass surveillance and much much more!&lt;/b&gt;
        &lt;div dir="ltr" style="text-align: justify; "&gt;&lt;a class="external-link" href="http://www.isodarco.it/courses/andalo12/doc/CBowden.pdf"&gt;Caspar Bowden&lt;/a&gt; is an independent advocate for better Internet privacy technology and regulation. He is a specialist  in  data  protection  policy,  privacy  enhancing  technology  research,  identity  management  and authentication.  Until  recently  he  was  Chief Privacy  Adviser  for  Microsoft,  with  particular  focus on  Europe and regions with horizontal privacy law.&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;From 1998-2002, he was the director of the Foundation for Information Policy Research (www.fipr.org) and was also an expert adviser to the UK Parliament for the passage of three bills concerning privacy, and was co-organizer of the influential Scrambling for Safety public conferences on UK encryption and surveillance policy.  His  previous  career  over  two  decades  ranged  from  investment  banking  (proprietary  trading  risk-management for option arbitrage), to software engineering (graphics engines and cryptography), including work for Goldman Sachs, Microsoft Consulting Services, Acorn, Research Machines, and IBM.&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: justify; "&gt;The Centre for Internet and Society interviewed Caspar Bowden on the following questions:&lt;/div&gt;
&lt;p align="JUSTIFY"&gt; &lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;1. Do you think India needs privacy legislation? Why / Why not?&lt;/h3&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Well I think it's essential for any modern democracy based on a constitution to now recognise a universal human right to privacy. This isn't something that would necessarily have occurred to the draft of constitutions before the era of mass electronic communications, but this is now how everyone manages their lives  and maintains social relationships at a distance, and therefore there needs to be an entrenched right to privacy – including communications privacy – as part of the core of any modern state. &lt;/span&gt;&lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;2. The majority of India's population lives below the line of poverty and barely has any Internet access. Is surveillance an elitist issue or should it concern the entire population in the country? Why / Why not?&lt;/h3&gt;
&lt;p align="JUSTIFY"&gt; &lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Although the majority of people in India are still living in conditions of poverty and don't have access to the Internet or, in some cases, to any electronic communications, that's changing very rapidly. India has some of the  highest growth rates in take up with both mobile phones and mobile Internet and so this is  spreading very rapidly through all strata of society. It's becoming an essential tool for transacting with business and government, so it's going to be increasingly important to have a privacy law which guarantees rights equally, no matter what anyone's social station or situation. There's also, I think, a sense in which having a right to privacy based on individual rights is much preferable to some sort of communitarian approach to privacy, which has a certain philosophical following; but that model of privacy - that somehow, because of a community benefit, there should also be a sort of community sacrifice in individual rights to privacy - has a number of serious philosophical flaws which we can talk about. &lt;/span&gt;&lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;3. "I'm not a terrorist and I have nothing to hide...and thus surveillance can't affect me personally." Please comment.&lt;/h3&gt;
&lt;p&gt; &lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;&lt;/h3&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Well, it's hard to know where to begin. Almost everybody in fact has “something to hide”, if you consider all of the social relationships and the way in which you are living your life. It's just not true that there's anybody who literally has nothing to hide and in fact I think that it's rather a dangerous idea, in political culture, to think about imposing that on leaders and politicians. There's an increasing growth of the idea – now, probably coming from America- that political leaders (and even their staff - to get hired in the current White House) should open up their lives, even to the extent of requiring officials to give up their passwords to their social network accounts (presumably so that they can be vetted for sources of potential political  embarrassment in their private life). This is a very bad idea because if we only elect leaders, and if we only employ bureaucrats, who do not accord any subjective value to privacy, then it means we will almost literally be electing (philosophical) zombies. And we can't expect our political leaders  to respect our privacy rights, if we don't recognise that they have a right to privacy in their own lives also. The main problem with the “nothing to hide, so nothing to fear” mantra is that this is used as a rhetorical tool by authoritarian forces in government and society, who simply wish to take a more paternalistic and protective attitude. This reflects a disillusionment within the “deep state” about how democratic states should function.&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Essentially, those who govern us are given a license through elections to exercise power with consent, but  this entails no abrogation of a citizen's duty to question authority. Instead, that should be seen as a civic duty - providing the objections are reasonable. People actually know that there are certain things in their lives that they don't wish other people to know, but by indoctrinating the “nothing to hide” ideology, it inculcates a general tendency towards more conformism in society, by inhibiting critical voices.&lt;/p&gt;
&lt;h3&gt;4. Should people have the right to give up their right to privacy? Why / Why not?&lt;/h3&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;In European data protection law there is an obscure provision which is particularly relevant to medical privacy, but almost never used in the area of so-called sensitive personal data, like political views or philosophical views. It is possible currently for European governments to legislate to override the ability of the individual to consent. So this might arise, for example, if a foreign company sets up a service to get people to consent to have their DNA analysed and taken into foreign databases, or generally where people might consent to a big foreign company analysing and capturing their medical records. I think there is a legitimate view that, as a matter of national policy, a government could decide that these activities were threatening to data sovereignty, or that was just bad public policy. For example, if a country has a deeply-rooted social contract that guarantees the ability to access medical care through a national health service, private sector actors could try to undermine that social-solidarity basis for universal provision of health care. So for those sorts of reasons I  do think it's defensible for governments to have the ability in those sectors to say: “Yes, there are areas where people should not be able to consent to give up their privacy!” &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;But then going back to the previous answer, more generally, commercial privacy policies are now so complicated – well, they've always been complicated, but now are mind-blowingly devious as well - people have no real possibility of knowing what they're consenting to. For example, the secondary uses of data flows in social networks are almost incomprehensible, even for technologists at the forefront of research.  The French Data Protection authorities are trying to penalize Google for replacing several very complicated privacy policies by one so-called unified policy, which says almost nothing at all. &lt;/span&gt;There's&lt;span&gt; no possible way for people to give informed consent to this over-simplified policy, because it doesn't even tell anything useful to an expert. So again in these circumstances, it's right for a regulator to intercede to prevent unfair exploitation of the deceptive kind of “tick-box” consent. Lastly, it is not possible for EU citizens to waive or trade away their basic right to access (or delete) their own data in future, because this seems a reckless act and it cannot be foreseen when this right might become essential in some future circumstances. So in these three senses, I believe it is proper for legislation to be able to prevent the abuse of the concept of consent.&lt;/span&gt;&lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;5. Do you agree with India's UID scheme? Why / Why not?&lt;/h3&gt;
&lt;p&gt; &lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;&lt;/h3&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;There is a valid debate about whether it's useful for a country to have a national identity system of some kind - and there's about three different ways that can be engineered technically. The first way is to centralise all data storage in a massive repository, accessed through remote terminal devices. The second way is a more decentralised approach with a number of different  identity databases or systems which can interoperate (or “federate” with eachother), with technical and procedural rules to  enforce privacy and security safeguards. In general it's probably a better idea to decentralise identity information, because then if there is a big disaster (or cyber-attack) or data loss, you haven't lost everything. The third way is what's called “user-centric identity management”, where the devices (smartphones or computers) citizens use to interact with the system keep the identity information in a totally decentralised way. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Now the obvious objection to that is: “Well, if the data is decentralised and it's an official system, how can we trust that the information in people's possession is authentic?”. Well, you can solve that with cryptography. You can put digital signatures on the data, to show that the data hasn't been altered since it was originally verified. And that's a totally solved problem. However, unfortunately, not very many policy makers understand that and so are easily persuaded that centralization is the most efficient and secure design – but that hasn't been true technically for twenty years. Over that time, cryptographers have refined the  techniques (the alogithms can now run comfortably on smartphones) so that user-centric identity management is totally achievable, but policy makers have not generally understood that. But there is no technical reason a totally user-centric vision of identity architecture should not be realized. But still the UID appears to be one of the most centralised large systems ever conceived. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;There are still questions I don't understand about its technical architecture. For example, just creating an identity number by itself doesn't guarantee security and it's a classic mistake to treat an identifier as an authenticator. In other words, to use an identifier or knowledge of an identifier - which could become public information, like the American social security number – to treat knowledge of that number as if it were a key to open up a system to give people access to their own private information is very dangerous. So it's not clear to me how the UID system is designed in that way. It seems that by just quoting back a number, in some circumstances this will be the key to open up the system, to reveal private information, and that is an innately insecure approach. There may be details of the system I don't understand, but I think it's open to criticism on those systemic grounds. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;And then more fundamentally, you have to ask what's the purpose of that system in society. You can define a system with a limited number of purposes – which is the better thing to do – and then quite closely specify the legal conditions under which that identity information can be used. It's much more problematic, I think, to try and just say that “we'll be the universal identity system”, and then you just try and find applications for it later. A number of countries tried this approach, for example Belgium around 2000, and they expected that having created a platform for identity, that many applications would follow and tie into the system. This really didn't happen, for a number of social and technical reasons which critics of the design had predicted. I suppose I would have to say that the UID system is almost the anithesis of the way I think identity systems should be designed, which should be based on quite strong technical privacy protection mechanisms - using cryptography - and where, as far as possible, you actually leave the custody of the data with the individual. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Another objection to this user-centric approach is “back-up”: what happens when you lose the primary information and/or your device? Well, you can anticipate that. You can arrange for this information to be backed-up and recovered, but in such a way that the back-up is encrypted, and the recovered copy can easily be checked for authenticity using cryptography.&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;6. Should Indian citizens be concerned about the Central Monitoring System (CMS)? Why / Why not?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;h3&gt;&lt;/h3&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Well, the Central Monitoring System does seem to be an example of very large scale “strategic surveillance”, as it is normally called. Many western countries have had these for a long time, but normally only for international communications. Normally surveillance of domestic communications is done under a particular warrant, which can only be applied one investigation at a time. And it's not clear to me that that is the case with the Central Monitoring System. It seems that this may also be applicable to mass surveillance of communications inside India. Now we're seeing a big controversy in the U.S - particularly at the moment - about the extent to which their international strategic surveillance systems are also able to be used internally. What has happened in the U.S. seems rather deceptive; although the “shell” of the framework of individual protection of rights was left in place, there are actually now so many exemptions when you look in the detail, that an awful lot of Americans' domestic communications are being subjected to this strategic mass surveillance. That is unacceptable in a democracy. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;There are reasons why, arguably, it's necessary to have some sort of strategic surveillance in international communications, but what Edward Snowden revealed to us is that in the past few years many countries – the UK, the U.S, and probably also Germany, France and Sweden – have constructed mass surveillance systems which knowingly intrude  on  domestic communications also. We are living through a transformation in surveillance power, in which the State is becoming more able to monitor and control  the population secretively than ever before in history. And it's very worrying that all of these systems appear to have been constructed without the knowledge of Parliaments and without precise legislation. Very few people in government even seem to have understood the true mind-boggling breadth of this new generation of strategic surveillance. And no elections were fought on a manifesto asking “Do people want this or not?”. It's being justified under a counter-terrorism mantra, without very much democratic scrutiny at all. The long term effects of these systems on democracies are really uncharted territory. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;We know that we're not in an Orwellian state, but the model is becoming more Kafkaesque. If one knows that this level of intensive and automated surveillance exists, then it has a chilling effect on society. Even if not very much is publicly known about these systems, there is still a background effect that makes people more conformist and less politically active, less prepared to challenge authority. And that's going to be bad for democracy in the medium term – not just the long term. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;7. Should surveillance technologies be treated as traditional arms / weapons? If so, should export controls be applied to surveillance technologies? Why / Why not?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;Surveillance technologies probably do need to be treated as weapons, but not necessarily as traditional weapons. One probably is going to have to devise new forms of export control, because tangible bombs and guns are physical goods – well, they're not “goods”, they're “bads” -  that you can trace by tagging and labelling them, but many of the “new generation” of surveillance weapons are &lt;/span&gt;&lt;i&gt;&lt;span&gt;software&lt;/span&gt;&lt;/i&gt;&lt;span&gt;. It's very difficult to control the proliferation of bits – just as it is with copyrighted material. And I remember when I was working on some of these issues thirteen years ago in the UK – during the so-called crypto wars – that the export of cryptographic software from many countries was prohibited. And there were big test cases about whether the source code of these programs was protected under the US First Amendment, which would prohibit such controls on software code. It was intensely ironic that in order to control the proliferation of cryptography in software, governments seemed to be contemplating the introduction of strategic surveillance systems to detect (among other things) when cryptographic software was being exported. In other words, the kind of surveillance systems which motivated the “cypherpunks” to proselytise cryptography, were being introduced (partly) with the perverse justification of preventing such proliferation of such cryptography!&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;In the case of the new, very sophisticated software monitoring devices (“Trojans”) which are being implanted into people's computers – yes, this has to be subject to the same sort of human rights controls that we would have applied to the exports of weapon systems to oppressive regimes. But it's quite difficult to know how to do that. You have to tie responsibility to the companies that are producing them, but a simple system of end-user licensing might not work. So we might actually need governments to be much more proactive than they have been in the past with traditional arms export regimes and actually do much more actively to try and follow control after export – whether these systems are only being used by the intended countries. As for the law enforcement agencies of democratic countries which are buying these technologies: the big question is whether law enforcement agencies are actually applying effective legal and operational supervision over the use of those systems. So, it's a bit of a mess! And the attempts that have been made so far to legislate this area I don't think are sufficient. &lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;8. How can individuals protect their data (and themselves) from spyware, such as FinFisher?&lt;/h3&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;In democratic countries, with good system of the rule of law and supervision of law enforcement authorities, there have been cases – notably in Germany – where it's turned out that the police using techniques, like FinFisher, have actually disregarded legal requirements from court cases laying down the proper procedures. So I don't think it's good enough to assume that if one was doing ordinary lawful political campaigning, that one would not be targeted by these weapons. So it's wise for activists and advocates to think about protecting themselves – of course, other professions as well who look after confidential information – because these techniques may also get into the hands of industrial spies, private detectives and  generally by people who are not subject to even the theoretical constraints of law enforcement agencies. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;After Edward Snowden's revelations, we understand that all our computer infrastructure is much more vulnerable – particularly to foreign and domestic intelligence agencies – than we ever imagined. So for example, I don't use Microsoft software anymore – I think that there are techniques which are now being sold to governments and available to governments for penetrating Microsoft platforms and probably other major commercial platforms as well. So, I've made the choice, personally, to use free software – GNU/Linux, in particular – and it still requires more skill for most people to use, but it is much much easier than even a few years ago. So I think it's probably wise for most people to try and invest a little time getting rid of proprietary software if they care at all about societal freedom and privacy. I understand that using the latest, greatest smartphone is cool, and the  entertainment and convenience of Cloud and tablets – but people should not imagine that they can keep those platforms secure. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;It might sound a bit primitive, but I think people should have to go back to the idea that if they really want confidential communications with their friends, or if they are involved with political work, they have to think about setting aside one machine - which they keep offline and just use essentially for editing and encrypting/decrypting material. Once they've encrypted their work on their “air gap” machine, as it's called, then they can put their encrypted emails on a USB stick and transfer them to their second machine which they use to connect online (I notice Bruce Schneier is just now recommending the same approach). Once the “air gap” machine has been set up and configured, you should not connect that to the network – and preferably, don't connect it to the network, ever! So if you follow those sorts of protocols, that's probably the best that is achievable today. &lt;/span&gt;&lt;/p&gt;
&lt;h3 align="JUSTIFY"&gt;9. How would you advise young people working in the surveillance industry?&lt;/h3&gt;
&lt;p&gt; &lt;/p&gt;
 &lt;ol&gt; &lt;/ol&gt;
&lt;p&gt;&lt;span&gt;Young 	people should try and read a little bit into the ethics of 	surveillance and to understand their own ethical limits in what they 	want to do, working in that industry. And in some sense, I think 	it's a bit like contemplating  a career in the arms industry. There 	are defensible uses of military weapons, but the companies that 	build these weapons are, at the end of the day, just corporations 	maximizing value for shareholders. And so, you need to take a really 	hard look at the company that you're working for or the area you 	want to work in and satisfy your own standard of ethics, and that 	what you're doing is not violating other people's human rights. I 	think that in the fantastically explosive growth of surveillance 	industries that we've seen over the past few years – and it's 	accelerating – the sort of technologies particularly being 	developed for electronic mass surveillance are fundamentally and 	ethically problematic. And I think that for a talented engineer, 	there are probably better things that he/she can do with his/her 	career. &lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;ol&gt; &lt;/ol&gt; &lt;ol&gt;&lt;/ol&gt;&lt;ol&gt; &lt;/ol&gt; &lt;ol&gt; &lt;/ol&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate'&gt;https://cis-india.org/internet-governance/blog/interview-with-caspar-bowden-privacy-advocate&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-06T08:16:05Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/indian-express-october-27-2013-nishant-shah-open-secrets">
    <title> Open Secrets</title>
    <link>https://cis-india.org/internet-governance/blog/indian-express-october-27-2013-nishant-shah-open-secrets</link>
    <description>
        &lt;b&gt;We need to think of privacy in different ways — not only as something that happens between people, but between you and corporations.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Dr. Nishant Shah's article was originally &lt;a class="external-link" href="http://www.indianexpress.com/news/open-secrets/1187814/0"&gt;published in the Indian Express&lt;/a&gt; on October 27.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;If you are a part of any social networking site, then you know that privacy is something to be concerned about. We put out an incredible amount of personal data on our social networks. Pictures with family and friends, intimate details about our ongoing drama with the people around us, medical histories, and our spur-of-the-moment thoughts of what inspires, peeves or aggravates us. In all this, the more savvy use filters and group settings which give them some semblance of control about who has access to this information and what can be done with it.&lt;br /&gt;&lt;br /&gt;But it is now a given that in the world of the worldwide web, privacy is more or less a thing of the past. Data transmits. Information flows. What you share with one person immediately gets shared with thousands. Even though you might make your stuff accessible to a handful of people, the social networks work through a "friend-of-a-friend effect", where others in your networks use, like, share and spread your information around so that there is an almost unimaginable audience to the private drama of our lives. Which is why there is a need for a growing conversation about what being private in the world of big data means.&lt;br /&gt;&lt;br /&gt;Privacy is about having control over the data and some ownership about who can use it and for what purpose. Interface designs and filters that allow limited access help this process. The legal structures are catching up with regulations that control what individuals, entities, governments and corporations can do with the data we provide. However, most people think of privacy as a private matter. Just look at last month's conversations around Facebook's new privacy policies, which no longer allow you to hide. If you are on Facebook, people can find you using all kinds of parameters — meta data — other than just your name. They might find you through hobbies, pages you like, schools you have studied in, etc. This can be scary because it means that based on particular activities, people can profile and follow you. Especially for people in precarious communities — the young adults, queer people who might not be ready to be out of the closet, women who already face increased misogyny and hostility online. This means they are officially entering a stalkers' paradise.&lt;br /&gt;&lt;br /&gt;While those concerns need to be addressed, there is something that seems to be missing from the debate. Almost all of these privacy alarms are about what people can do to people. That we need to protect ourselves from people, when we are in public — digital or otherwise. We are reminded that the world is filled with predators, crackers and scamsters, who can prey on our personal data and create physical, emotional, social and financial havoc. But this is the world we already know. We live in a universe filled with perils and we have learned and coped with the fact that we navigate through dangerous spaces, times and people all the time. The digital is no different than the physical when it comes to the possible perils that we live in, though digital might facilitate some kinds of behaviour and make data-stalking easier.&lt;br /&gt;&lt;br /&gt;What is different with the individualised, just-for-you crafted world of the social web is that there are things which are not human, which are interacting with you in unprecedented ways. Make a list of the top five people you interact with on Facebook. And you will be wrong. Because the thing that you interact with the most on Facebook, is Facebook. Look at the amount of chatter it creates — How are you feeling today?; Your friend has updated their status; Somebody liked your comment… the list goes on. In fact, much as we would like to imagine a world that revolves around us, we know that there are a very few people who have the energy and resources to keep track of everything we do. However, no matter how boring your status message or how pedestrian your activity, deep down in a server somewhere, an artificial algorithm is keeping track of everything that you do. Facebook is always listening, and watching, and creating a profile of you. People might forget, skip, miss or move on, but Facebook will listen, and remember long after you have forgotten.&lt;br /&gt;&lt;br /&gt;If this is indeed the case, we need to think of privacy in different ways — not only as something that happens between people, but between people and other entities like corporations. The next time there is a change in the policy that makes us more accessible to others, we should pay attention. But what we need to be more concerned about are the private corporations, data miners and information gatherers, who make themselves invisible and collect our personal data as we get into the habit of talking to platforms, gadgets and technologies.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/indian-express-october-27-2013-nishant-shah-open-secrets'&gt;https://cis-india.org/internet-governance/blog/indian-express-october-27-2013-nishant-shah-open-secrets&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>nishant</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-30T08:21:21Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/first-post-october-28-2013-nowhere-to-hide">
    <title>Nowhere to hide: Govt making your personal details public</title>
    <link>https://cis-india.org/news/first-post-october-28-2013-nowhere-to-hide</link>
    <description>
        &lt;b&gt;The worst fears are coming true. Your sensitive private data may be up online turning you into a potential target of frauds. What is all the more dangerous is that you may be not even aware of this.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by First Post editors was &lt;a class="external-link" href="http://www.firstpost.com/business/nowhere-to-hide-govt-making-your-personal-details-public-1197977.html?utm_source=hp-footer"&gt;published&lt;/a&gt; on October 28, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;An investigation by the  Business Standard has revealed that various state and central  government departments have already started putting up citizen’s  personal details such as bank accounts and income on websites. The  rationale behind the move is bringing about transparency.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The report also provides details of two persons, which the reporters  could access online – a 25-year-old from Haryana and another farmer from  Uttar Pradesh.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the first instance, the paper got the details from the state government website which has published all the details as the youth is a beneficiary of the NREGS.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Haryana government made public the details of the NREGS beneficiaries in its bid to bring about transparency. In Rural Development Minister Jairam Ramesh’s words, the aim is to make available all these data for public scrutiny.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the second instance, the paper has obtained the occupation and yearly income, ration card number, full address, age, father’s/husband’s name, category and poverty status of the farmer. These details are available online as the state government is computerising the public distribution system.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;If you thought, not everybody’s data will be made public this way, you are wrong, because before long the details of all the beneficiaries of direct benefit transfer will also be published online.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Though the Information Technology Act does not permit publishing sensitive personal financial details online, there is an exception if such information is come under Right to Information Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At the face of it transparency is a lame excuse to publish such data. How can the government provide all the details, including the bank account details of its citizen, at a time when cyber crime has increased many-fold.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;And nobody knows the gravity of the situation better than the government. Minister of State for Communications &amp;amp; IT Milind Deora recently told Lok Sabha that this year until June as many as 78 government websites were hacked.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Citing Indian Computer Response Team (CERT-In) data he said in 2011 as many as 308 government sites were hacked and in 2012 the figure was 371.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The number of security breach incidents in 2011 stood at 13,301 and in 2012 at 22,060. The corresponding figure for this year until June has already hit 16,035, he said. Security breach included incidents related to spam, malware infection and system break-in.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In such an environment, the governments’ transparency drive comes at the cost of personal security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The problem with making public details such as date of birth and names of family members is that it helps the hackers crack passwords. Most of the people have such details as their passwords and pins, the BS report says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sunil Abraham of Centre for Internet and Society rightly says in the BS report, “If people start publishing information like these and the government doesn’t regulate it through a data protection law, criminal minds can harvest and combine all databases accurately.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/first-post-october-28-2013-nowhere-to-hide'&gt;https://cis-india.org/news/first-post-october-28-2013-nowhere-to-hide&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-29T06:15:06Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/business-standard-october-29-2013-somesh-jha-surabhi-agarwal-your-private-data-may-be-online-courtesy-govt">
    <title>Your private data may be online, courtesy govt</title>
    <link>https://cis-india.org/news/business-standard-october-29-2013-somesh-jha-surabhi-agarwal-your-private-data-may-be-online-courtesy-govt</link>
    <description>
        &lt;b&gt;Some depts have posted bank account &amp; income details on net for transparency; experts cry privacy breach.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The article by Somesh Jha and Surabhi Agarwal was &lt;a class="external-link" href="http://www.business-standard.com/article/economy-policy/your-private-data-may-be-online-courtesy-govt-113102800020_1.html"&gt;published in the Business Standard&lt;/a&gt; on October 29, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;To push the government's agenda of greater transparency and  accountability, several states and central departments might be,  unwittingly, following a bare-it-all approach in posting citizen data  online. And, even sensitive and personal information, such as bank  account numbers and income status, is not being spared. A Business  Standard investigation reveals, with so much citizen data already in the  public domain and more getting added every day, the government could be  jeopardising the privacy of its 1.2 billion citizens, who stand exposed  to a variety of risks, including those of 360-degree profiling and  financial frauds.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For instance, the Centre's National Rural Employment Guarantee Scheme  puts out full bank account numbers of its beneficiaries, along with  details like the amount they received. So, one can easily know the bank  in which most residents of, say, Punjab's Machhiwara district have their  accounts. Also, their account numbers are complete, with photographs.  In the case of Haryana's 25-year-old Ram (surname withheld), the  photograph is not available but one can get his financial details on the  portal, along with the first eight digits of his &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar&lt;/a&gt; number (the last four have been muted).&lt;br /&gt; &lt;br /&gt; Sample this: The occupation and yearly income of one Amrita of Uttar  Pradesh are just a matter of a few clicks and so are her ration card  number, full address, age, father's/husband's name, category and poverty  status. A farmer from Amethi district, she doesn't have a gas or an  electricity connection, but Lucknow-based Manu, who earns Rs 4 lakh a  year, does have. Amrita's yearly income is Rs 1.2 lakh a year. These  details are all there on their respective ration cards, out in the open  on the government website of Uttar Pradesh, a state that might have gone  overboard in revealing citizen data under the ongoing computerisation  of the public distribution system.&lt;br /&gt; &lt;br /&gt; "If people start publishing information like these and the government  doesn't regulate it through a data protection law, criminal minds can  harvest and combine all databases accurately," says Sunil Abraham,  executive director of Centre for Internet and Society, a Bangalore based  think-tank. People often create passwords and pins based on dates and  numbers very important to them. "A little bit of intelligence and some  amount of social engineering could lead to guesses... and financial  fraud." Even by sifting through just three databases, it is quite easy  to get a random person's details like voter identity card number,  address, name, age, date of birth, ration card number, information on  family members, along with income status and photograph.&lt;br /&gt; &lt;br /&gt; One can argue the electoral roll is a public document and there is  nothing wrong with a person's voter identity card number, full address,  name, age, father's name and even date of birth being easily searcheable  online. But a few states like Uttarakhand have even published  photographs, an element barred from online posting under the law.  Experts argue a massive digitisation exercise is underway in the country  and, with the lack of standards and clear advisories from the Centre,  the situation could worsen in the future.&lt;br /&gt; &lt;br /&gt; A Cabinet minister, who did not wish to be named, said there was a  continuous tug-of-war between the imperative of privacy, which doesn't  allow you to share information; and transparency, which says you should  share it. "Also, the Right to Information Act says if somebody is  receiving government subsidy, it is public information." However, the  Indian laws might not be consistent on this issue as "under Section 43a  of the Information Technology Act, any kind of financial information is  classified as 'sensitive personal information' and can't be put online,"  says an official of the communications and information technology  ministry who has closely worked on drafting of the IT Act.&lt;br /&gt; &lt;br /&gt; But, the IT Act provides an exception for matters covered under the RTI  Act. This could infer that when the recently-approved Food Security Act  comes into being, the income status of two-thirds of the population  (that the Act covers) could be posted online. Also, the law would permit  bank account numbers of beneficiaries of various welfare schemes like  cooking gas subsidy under the ongoing direct benefit transfer scheme to  be made public, as subsidies are transferred directly to accounts under  the project.&lt;br /&gt; &lt;br /&gt; A statement from the office of Rural Development Minister &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Jairam+Ramesh" target="_blank"&gt;Jairam Ramesh&lt;/a&gt; explained the National Rural Employment Guarantee Act provided for  "making available for public scrutiny" all accounts and records related  to the scheme. It added "there appears to be no evident risk of  misappropriation or financial fraud". Sudhir Kumar, secretary in the  Department of Food and Public Distribution, says the whole system needs  to be transparent, especially when huge government subsidy is going out  in the case of PDS. However, "if states are putting unnecessary details  online, it can be looked into". Deputy Election Commissioner Alok Shukla  says, according to an EC order, states are not allowed to put  photographs of voters online to ensure their privacy is safeguarded.  These will be removed if such cases are found. He adds a standard  protocol is also being worked out for states.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/business-standard-october-29-2013-somesh-jha-surabhi-agarwal-your-private-data-may-be-online-courtesy-govt'&gt;https://cis-india.org/news/business-standard-october-29-2013-somesh-jha-surabhi-agarwal-your-private-data-may-be-online-courtesy-govt&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-29T05:50:59Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/business-standard-october-29-2013-surabhi-agarwal-somesh-jha-saving-privacy-as-we-knew-it">
    <title>Saving privacy as we knew it</title>
    <link>https://cis-india.org/news/business-standard-october-29-2013-surabhi-agarwal-somesh-jha-saving-privacy-as-we-knew-it</link>
    <description>
        &lt;b&gt;Long overdue protection law still on the back-burner; meanwhile, depts put more of one's personal details online.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The article by Surabhi Agarwal and Somesh Jha was &lt;a class="external-link" href="http://www.business-standard.com/article/economy-policy/saving-privacy-as-we-knew-it-113102900024_1.html"&gt;published in the Business Standard &lt;/a&gt;on October 29, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;It was in 2010 when the central government decided to institute a legal  framework on privacy. This was in the wake of increasing data collection  by both government and corporate agencies. Concerns had mounted in the  wake of projects such as the National Population Register, &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar&lt;/a&gt; and the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=National+Intelligence+Grid" target="_blank"&gt;National Intelligence Grid&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Over three years and hundreds of consultations later, several drafts of  the proposed Bill were written and rejected, and at least two committees  have given recommendations. However, the law has not seen the light of  day. Meanwhile, citizen data digitisation is moving at a pace like never  before in the country.&lt;br /&gt; &lt;br /&gt; &lt;i&gt;Business Standard&lt;/i&gt; had reported on October 28 about how an  investigation revealed that several states and central departments might  be, unwittingly, following a bare-it-all approach in posting citizen  data online in order to push the government's agenda of greater  transparency and accountability. While the Centre's National Rural  Employment Guarantee Scheme puts out full bank account numbers of its  beneficiaries, government website of Uttar Pradesh has put out full  details of ration card holders, including annual income along with  address and information about members of the family. By putting such  sensitive information online, the government could be jeopardising the  privacy of its 1.2 billion citizens, who stand exposed to a variety of  risks, including those of 360-degree profiling and financial frauds. &lt;b&gt;(&lt;a href="http://www.business-standard.com/content/general_pdf/102913_04.pdf" target="_blank"&gt;INFORMATION DELUGE&lt;/a&gt;)&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;br /&gt;According to government officials, the department of personnel and  training has finished compiling the final draft of the privacy  legislation, now awaiting approval from the prime minister; the  department is under him.&lt;br /&gt; &lt;br /&gt; "In the absence of a privacy Bill, the only data protection, pseudo, is  through Section 43A of the Information Technology (IT) Act.  Unfortunately, that is not a data protection law; it is only a data  security provision," said Sunil Abraham, executive director of the  Centre for Internet and Society.&lt;br /&gt; &lt;br /&gt; Pavan Duggal, a Supreme Court lawyer and cyber security expert, said  India needs more security while collecting data and "currently a lot of  these websites don't have these security layers". Take for instance, the  website of the chief electoral officer of New Delhi. Type a person's  first or last name and select the constituency - the website throws up  the details of all people with this name, along with all the details  such as address and voter identity number. According to officials of the  &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Election+Commission" target="_blank"&gt;Election Commission&lt;/a&gt;,  the searchability feature helps in easy access of voter details by  people themselves or by interested political parties. "There has been no  evidence to prove its use otherwise," an official of the EC told  Business Standard.&lt;br /&gt; &lt;br /&gt; However, experts said otherwise. Abraham said the electronic version of  the electoral roll has a unique identifier, the voter ID number. "And,  if there are other databases with the same identifier, a comprehensive  profile of a citizen can be created." He added, at the moment, we are  saved from 360-degree profiling to some extent, since there is no common  identifier.&lt;br /&gt; &lt;br /&gt; Once a privacy law comes into being, the government or a private agency  will have to adequately inform citizens before collecting data, stating  the reasons and only collecting as much information as is necessary for  the purpose. It will also have to clearly define the time period for  which the data will be stored and the security measures taken to protect  it from misuse. The law also lays down the penalties in case of a  breach.&lt;br /&gt; &lt;br /&gt; Though in a less detailed manner, the current IT Act also addresses some  of these issues. It defines anything which reveals financial  information, biometric, health and medical records, etc, as sensitive  financial information which cannot be put in the public domain.&lt;br /&gt; &lt;br /&gt; However, experts said the government is lax in even enforcing the  existing laws. To be fair, some states and departments have started  being prudent about the data they put online. For instance, the state  government of Chhattisgarh, a trend setter in effectively implementing  the Public Distribution System, doesn't reveal much in terms of citizen  information that can identify a person or can be termed as a breach of  privacy. Similarly, Odisha and some northeastern states have put in a  layer of security which creates some deterrents while using common  keywords to search the electoral roll and create a profile of residents  in a particular locality.&lt;br /&gt; &lt;br /&gt; However, for now, most departments stuck in the tradeoff between privacy  and transparency find solace in pointing fingers at contemporaries who  might have also put "more sensitive and dangerous" citizen details  online. The blame game doesn't end.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/business-standard-october-29-2013-surabhi-agarwal-somesh-jha-saving-privacy-as-we-knew-it'&gt;https://cis-india.org/news/business-standard-october-29-2013-surabhi-agarwal-somesh-jha-saving-privacy-as-we-knew-it&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-29T05:01:25Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/spy-files-three">
    <title>Spy Files 3: WikiLeaks Sheds More Light On The Global Surveillance Industry</title>
    <link>https://cis-india.org/internet-governance/blog/spy-files-three</link>
    <description>
        &lt;b&gt;In this article, Maria Xynou looks at WikiLeaks' latest Spy Files and examines the legality of India's surveillance technologies, as well as their potential connection with India's Central Monitoring System (CMS) and implications on human rights. &lt;/b&gt;
        
&lt;p align="JUSTIFY"&gt;Last month, WikiLeaks released &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt;“&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt;Spy&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt;Files&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html"&gt; 3”&lt;/a&gt;&lt;/span&gt;, a mass exposure of the global surveillance trade and industry. WikiLeaks first released the Spy Files in December 2011, which entail brochures, presentations, marketing videos and technical specifications on the global trade of surveillance technologies. Spy Files 3 supplements this with 294 additional documents from 92 global intelligence contractors.&lt;/p&gt;

&lt;h2&gt;&lt;b&gt;So what do the latest Spy Files reveal about India?&lt;/b&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;When we think about India, the first issues that probably come to mind are poverty and corruption, while surveillance appears to be a more “Western” and elitist issue. However, while many other developing countries are excluded from WikiLeaks’ list of surveillance technology companies, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;India&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;is&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;once&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;again&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;on&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;the&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;list&lt;/a&gt;&lt;/span&gt; with some of the most controversial spyware.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;ISS World Surveillance Trade Shows&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;The latest Spy Files include a &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;brochure&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;the&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; 2013&lt;/a&gt;&lt;/span&gt; -the so-called “wiretapper’s ball”- which is the world’s largest surveillance trade show. &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;This&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;years&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;’ &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;ISS&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;World&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_ap/"&gt;Asia&lt;/a&gt;&lt;/span&gt; will take place in Malaysia during the first week of December and law enforcement agencies from around the world will have another opportunity to view and purchase the latest surveillance tech. The&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;leaked&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; 2013 &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;brochure&lt;/a&gt;&lt;/span&gt; entails a list of last years’ global attendees. According to the brochure, 53% of the attendees included law enforcement agencies and individuals from the defense, public safety and interior security sectors, 41% of the attendees were ISS vendors and technology integrators, while only 6% of the attendees were telecom operators and from the private enterprise. The brochure boasts that 4,635 individuals from 110 countries attended the ISS World trade shows last year and that the percentage of attendance is increasing.&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;The following table lists the &lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;&lt;i&gt;&lt;span style="text-decoration: underline;"&gt;Indian&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;attendees&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;at&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;last&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;years&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;’ &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;/span&gt;:&lt;/p&gt;
 
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;Law Enforcement, Defense and Interior Security Attendees&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;&lt;th&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;Telecom Operators and Private Enterprises Attendees&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;&lt;th&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;ISS Vendors and Technology Integrators Attendees&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Andhra Pradesh India Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;BT&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;AGC Networks&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;CBI Academy&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Cogence Investment Bank&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Aqsacom India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Government of India, Telecom Department&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Reliance Communications&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;ClearTrail Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Cabinet Secretariat&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Span Telecom Pvt. Ldt. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Foundation Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Centre for Development of Telematics (C-DOT)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;Kommlabs&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Chandigarh Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Paladion Networks&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Defence Agency&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Polaris Wireless&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India General Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Polixel Security Systems&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Intelligence Department&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Pyramid Cyber Security&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India National Institute of Criminology&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Schleicher Group&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India office LOKAYUKTA NCT DELHI&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Span Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Police Department, A.P.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;TATA India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;India Tamil Nadu Police Department&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Tata Consultancy Services&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Indian Police Service, Vigilance&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Telecommunications India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Indian Telecommunications Authority&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Vehere Interactive&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;NTRO India&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;SAIC Indian Tamil Nadu Police&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt; 17                                                        4                                                      15&lt;br /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p align="JUSTIFY"&gt;According to the above table - which is based on data from the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;WikiLeaks&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;’ &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; 2013 &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;brochure&lt;/a&gt;&lt;/span&gt;- the majority of Indian attendees at last years’ ISS World were from the law enforcement, defense and interior security sectors. 15 Indian companies exhibited and sold their surveillance technologies to law enforcement agencies from around the world and it is notable that India’s popular ISP provider, Reliance Communications, attended the trade show too.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In addition to the ISS World 2013 brochure, the Spy Files 3 entail a detailed brochure of a major Indian surveillance technology company: ClearTrail Technologies.&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;ClearTrail Technologies&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.clear-trail.com/"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt; &lt;/a&gt;&lt;a href="http://www.clear-trail.com/"&gt;Technologies&lt;/a&gt;&lt;/span&gt; is an Indian company based in Indore. The document titled &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Internet&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Suite&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;”&lt;/a&gt;&lt;/span&gt; from ClearTrail Technologies boasts about the company’s mass monitoring, deep packet inspection, COMINT, SIGINT, tactical Internet monitoring, network recording and lawful interception technologies. ClearTrail’s Internet Monitoring Suite includes the following products:&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;1. ComTrail: Mass Monitoring of IP and Voice Networks&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ComTrail&lt;/span&gt;&lt;/a&gt; is an integrated product suite for centralized interception and monitoring of voice and data networks. It is equipped with an advanced analysis engine for pro-active analysis of thousands of connections and is integrated with various tools, such as Link Analysis, Voice Recognition and Target Location.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;ComTrail is deployed within a service provider network and its monitoring function correlates voice and data intercepts across diverse networks to provide a comprehensive intelligence picture. ComTrail supports the capture, record and replay of a variety of Voice and IP communications in pretty much any type of communication, including - but not limited to- Gmail, Yahoo, Hotmail, BlackBerry, ICQ and GSM voice calls.&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;Additionally, ComTrail intercepts data from any type of network -whether Wireless, packet data, Wire line or VoIP networks- and can decode hundreds of protocols and P2P applications, including HTTP, Instant Messengers, Web-mails, VoIP Calls and MMS.&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;In short, ComTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Equipped to handle millions of communications per day intercepted over high speed STM &amp;amp; Ethernet Links&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Doubles up as Targeted Monitoring System&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- On demand data retention, capacity exceeding several years&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Instant Analysis across thousands of Terabytes&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Correlates Identities across multiple networks&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Speaker Recognition and Target Location&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;2. xTrail: Targeted IP Monitoring&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;xTrail&lt;/span&gt;&lt;/a&gt; is a solution for interception, decoding and analysis of high speed data traffic over IP networks and independently monitors ISPs/GPRS and 3G networks. xTrail has been designed in such a way that it can be deployed within minutes and enables law enforcement agencies to intercept and monitor targeted communications without degrading the service quality of the IP network. This product is capable of intercepting all types of networks -including wireline, wireless, cable, VoIP and VSAT networks- and acts as a black box for “record and replay” targeted Internet communications.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Interestingly enough, xTrail can filter based on a “pure keyword”, a URL/Domain with a keyword, an IP address, a mobile number or even with just a user identity, such as an email ID, chat ID or VoIP ID. Furthermore, xTrail can be integrated with link analysis tools and can export data in a digital format which can allegedly be presented in court as evidence.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, xTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Pure passive probe&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Designed for rapid field operations at ISP/GPRS/Wi-Max/VSAT Network Gateways&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Stand-alone solution for interception, decoding and analysis of multi Gigabit IP traffic&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Portable trolley based for simplified logistics, can easily be deployed and removed from any network location&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Huge data retention, rich analysis interface and tamper proof court evidence&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Easily integrates with any existing centralized monitoring system for extended coverage&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;3. QuickTrail: Tactical Wi-Fi Monitoring&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;Some of the biggest IP monitoring challenges that law enforcement agencies face include cases when targets operate from public Internet networks and/or use encryption.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;QuickTrail&lt;/span&gt;&lt;/a&gt; is a device which is designed to gather intelligence from public Internet networks, when a target is operating from a cyber cafe, a hotel, a university campus or a free Wi-Fi zone. In particular, QuickTrail is equipped with multiple monitoring tools and techniques that can help intercept almost any wired, Wi-Fi or hybrid Internet network so that a target communication can be monitored. QuickTrail can be deployed within fractions of seconds to intercept, reconstruct, replay and analyze email, chat, VoIP and other Internet activities of a target. This device supports real time monitoring and wiretapping of Ethernet LANs.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;According to ClearTrail’s brochure, QuickTrail is a “all-in-one” device which can intercept secured communications, know passwords with c-Jack attack, alert on activities of a target, support active and passive interception of Wi-Fi and wired LAN and capture, reconstruct and replay. It is noteworthy that QuickTrail can identify a target machine on the basis of an IP address, MAC ID, machine name, activity status and several other parameters. In addition, QuickTrail supports protocol decoding, including HTTP, SMTP, POP3 and HTTPS. This device also enables the remote and central management of field operations at geographically different locations.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, QuickTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Conveniently housed in a laptop computer&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Intercepts Wi-Fi and wired LANs in five different ways&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Breaks WEP, WPA/WPA2 to rip-off secured Wi-Fi networks&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Deploys spyware into a target’s machine&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Monitor’s Gmail, Yahoo and all other HTTPS-based communications&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Reconstructs webmails, chats, VoIP calls, news groups and social networks&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;4. mTrail: Off-The-Air Interception&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;mTrail&lt;/span&gt;&lt;/a&gt; offers active and passive ‘off-the-air’ interception of GSM 900/1800/1900 Mhz phone calls and data to meet law enforcement surveillance and investigation requirements. The mTrail passive interception system works in the stealth mode so that there is no dependence on the network operator and so that the target is unaware of the interception of its communications.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The mTrail system has the capability to scale from interception of 2 channels (carrier frequencies) to 32 channels. mTrail can be deployed either in a mobile or fixed mode: in the mobile mode the system is able to fit into a briefcase, while in the fixed mode the system fits in a rack-mount industrial grade chassis.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Target location identification is supported by using signal strength, target numbers, such as IMSI, TIMSI, IMEI or MSI SDN, which makes it possible to listen to the conversation on so-called “lawfully intercepted” calls in near real-time, as well as to store all calls. Additionally, mTrail supports the interception of targeted calls from pre-defined suspect lists and the monitoring of SMS and protocol information.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, mTrail’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Designed for passive interception of GSM communications&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Intercepts Voice and SMS “off-the-air”&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Detects the location of the target&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Can be deployed as a fixed unit or mounted in a surveillance van&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- No support required from GSM operator&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;b&gt;5. Astra: Remote Monitoring and Infection framework&lt;/b&gt;&lt;/p&gt;

&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Astra&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;”&lt;/a&gt;&lt;/span&gt; is a remote monitoring and infection framework which incorporates both conventional and proprietary infection methods to ensure bot delivery to the targeted devices. It also offers a varied choice in handling the behavior of bots and ensuring non-traceable payload delivery to the controller.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The conventional methods of infection include physical access to a targeted device by using exposed interfaces, such as a CD-ROM, DVD and USB ports, as well as the use of social media engineering techniques. However, Astra also supports bot deployment &lt;i&gt;without&lt;/i&gt; requiring any physical access to the target device.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In particular, Astra can push bot to &lt;i&gt;any&lt;/i&gt; targeted machine sharing the &lt;i&gt;same&lt;/i&gt; LAN (wired, wi-fi or hybrid). The SEED is a generic bot which can identify a target’s location, log keystrokes, capture screen-shots, capture Mic, listen to Skype calls, capture webcams and search the target’s browsing history. Additionally, the SEED bot can also be remotely activated, deactivated or terminated, as and when required. Astra allegedly provides an un-traceable reporting mechanism that operates without using any proxies, which overrules the possibility of getting traced by the target.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Astra’s key features include the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Proactive intelligence gathering&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- End-to-end remote infection and monitoring framework&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Follow the target, beat encryption, listen to in-room conversations, capture keystrokes and screen shots&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Designed for centralized management of thousands of targets&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- A wide range of deployment mechanisms to optimize success ration&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Non-traceable, non-detectable delivery mechanism&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Intrusive yet stealthy&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Easy interface for handling most complex tasks&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Successfully tested over the current top 10 anti-virus available in the market&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- No third party dependencies&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Free from any back-door intervention&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Technologies&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;argue&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;that&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;they&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;meet&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;lawful&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;interception&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;regulatory&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;requirements&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;/span&gt;across the globe. In particular, they claim that their products are compliant with &lt;a href="http://www.etsi.org/technologies-clusters/technologies/regulation-legislation"&gt;&lt;span style="text-decoration: underline;"&gt;ETSI&lt;/span&gt;&lt;/a&gt; and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;CALEA&lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt; &lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;regulations&lt;/a&gt;&lt;/span&gt; and that they are efficient to cater to region specific requirements as well.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The latest Spy Files also include data on foreign  surveillance technology companies operating in India, such as &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Telesoft&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Technologies&lt;/a&gt;&lt;/span&gt;, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/AGTINTERNATIONAL-2011-UrbaManaSolu-fr.pdf"&gt;AGT&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/AGTINTERNATIONAL-2011-UrbaManaSolu-fr.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/AGTINTERNATIONAL-2011-UrbaManaSolu-fr.pdf"&gt;International&lt;/a&gt;&lt;/span&gt; and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Verint&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;Systems&lt;/a&gt;&lt;/span&gt;. In particular, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://verint.com/"&gt;Verint&lt;/a&gt;&lt;a href="http://verint.com/"&gt; &lt;/a&gt;&lt;a href="http://verint.com/"&gt;Systems&lt;/a&gt;&lt;/span&gt; has its headquarters in New York and offices all around the world, including Bangalore in India. Founded in 1994 and run by Dan Bodner, Verint Systems produces a wide range of surveillance technologies, including the following:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Impact 360 Speech Analytics&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Impact 360 Text Analytics&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Video Management Software (VMS)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Physical Security Information Management (PSIM)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Network Video Recorders (NVRs)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Video Business Intelligence (VBI)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva Surveillance Analytics&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- Nextiva IP cameras&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- CYBERVISION Network Security&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- ENGAGE suite&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- FOCAL-INFO (FOCAL-COLLECT &amp;amp; FOCAL-ANALYTICS)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- RELIANT&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;- STAR-GATE&lt;/p&gt;
&lt;p&gt;- VANTAGE&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://verint.com/"&gt;Verint&lt;/a&gt;&lt;a href="http://verint.com/"&gt; &lt;/a&gt;&lt;a href="http://verint.com/"&gt;Systems&lt;/a&gt;&lt;/span&gt; claims to be in compliance with ETSI, CALEA and other worldwide lawful interception and standards and regulations, it remains unclear whether such products successfully help law enforcement agencies in tackling crime and terrorism, without violating individuals’ right to privacy and other human rights. After all, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;Verint&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;Systems&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;has&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;participated&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;in&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;ISS&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;World&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;Trade&lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt; &lt;/a&gt;&lt;a href="http://www.issworldtraining.com/iss_europe/"&gt;shows&lt;/a&gt;&lt;/span&gt; which exhibit some of the most controversial spyware in the world, used to target individuals and for mass surveillance.&lt;/p&gt;

&lt;h2&gt;&lt;b&gt;And what do the latest Spy Files mean for India?&lt;/b&gt;&lt;/h2&gt;

&lt;p align="JUSTIFY"&gt;Why is it even important to look at the latest Spy Files? Well, for starters, they reveal data about which Indian law enforcement agencies are interested in surveillance and which companies are interested in selling and/or buying the latest spy gear. And why is any of this important? I can think of three main reasons:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. The Central Monitoring System (CMS)&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. Is any of this surveillance even legal in India?&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. Can such surveillance result in the violation of human rights?&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Spy Files 3...and the Central Monitoring System (CMS)&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;Following the &lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt;Mumbai&lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt; 2008 &lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt;terrorist&lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt; &lt;/a&gt;&lt;a href="http://www.noeman.org/gsm/hindi/71159-26-november-2008-mumbai-terrorist-attacks.html"&gt;attacks&lt;/a&gt;, the Telecom Enforcement, Resource and Monitoring (TREM) cells and the Centre for Development of Telematics (C-DOT) started preparing the &lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Central&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;Monitoring&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;System&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; (&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;)&lt;/a&gt;. As of April 2013, this project is being manned by the Intelligence Bureau, while agencies which are planned to have access to it include the Research &amp;amp; Analysis Wing (RAW) and the Central Bureau of Investigation (CBI). ISP and Telecom operators are required to&lt;b&gt; &lt;/b&gt;&lt;span&gt;install the gear which enables law enforcement agencies to carry&lt;/span&gt; out the Central Monitoring System under the &lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Unified&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Access&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Services&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; (&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;) &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The Central Monitoring System aims at centrally monitoring all telecommunications and Internet communications in India and its estimated cost is &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ciol.com/ciol/news/184770/governments-central-monitoring-system-operational-soon"&gt;Rs&lt;/a&gt;&lt;a href="http://www.ciol.com/ciol/news/184770/governments-central-monitoring-system-operational-soon"&gt;. 4 &lt;/a&gt;&lt;a href="http://www.ciol.com/ciol/news/184770/governments-central-monitoring-system-operational-soon"&gt;billion&lt;/a&gt;&lt;/span&gt;. In addition to &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;equipping&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;government&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;agencies&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;/span&gt;with Direct Electronic Provisioning, filters and alerts on the target numbers, the CMS will also enable Call Data Records (CDR) analysis and data mining to identify personal information of the target numbers. The CMS supplements&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;regional&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Internet&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Monitoring&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Systems&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;, &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;such&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;as&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;that&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.assampolice.gov.in/tenders/20092012/EOI_IMS_20092012.pdf"&gt;Assam&lt;/a&gt;&lt;/span&gt;, by providing a nationwide monitoring of telecommunications and Internet communications, supposedly to assist law enforcement agencies in tackling crime and terrorism.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;However, data monitored and collected through the CMS will be stored in a&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt; &lt;/a&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt;centralised&lt;/a&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt; &lt;/a&gt;&lt;a href="http://www.globalpost.com/dispatch/news/regions/asia-pacific/india/130509/india-central-monitoring-system-government-internet-access"&gt;database&lt;/a&gt;&lt;/span&gt;, which could potentially increase the probability of centralized cyber attacks and thus increase, rather than reduce, threats to national security. Furthermore, some basic rules of statistics indicate that &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;bigger&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;amount&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;data&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;, &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;bigger&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;probability&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;of&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;an&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;error&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;in&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;matching&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;profiles&lt;/a&gt;&lt;/span&gt;, which could potentially result in innocent people being charged with crimes they did not commit. And most importantly: the CMS currently lacks adequate legal oversight, which means that it remains unclear how monitored data will be used. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;regarding&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;the&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;CMS&lt;/a&gt;&lt;/span&gt; mandates mass surveillance by requiring ISPs and Telecom operators to enable the monitoring and interception of communications. However, targeted and mass surveillance through the CMS not only raises serious questions around its legality, but also creates the potential for abuse of the right to privacy and other human rights.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Interestingly enough, Indian law enforcement agencies which attended &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;last&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;years&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;’ &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;ISS&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;World&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;trade&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/ISS-2013-Sche2013-en.pdf"&gt;shows&lt;/a&gt;&lt;/span&gt; are linked to the Central Monitoring System. In particular, last years’ law enforcement, defense and interior security attendees include the Centre for Development of Telematics (C-DOT) and the Department of Telecommunications, both of which prepared the Central Monitoring System. The list of attendees also includes India’s Intelligence Bureau, which is manning the CMS, as well as the &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;agencies&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;which&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;will&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;have&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;access&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;to&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;the&lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt; &lt;/a&gt;&lt;a href="https://cis-india.org/internet-governance/blog/indias-big-brother-the-central-monitoring-system"&gt;CMS&lt;/a&gt;&lt;/span&gt;: the Central Bureau of Investigation (CBI), the Research and Analysis Wing (RAW), the National Technical Research Organization (NTRO) and various other state police departments and intelligence agencies.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Furthermore, Spy Files 3 entail a &lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;list&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;of&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;last&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;years&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;’ &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;ISS&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;World&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;security&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;company&lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt; &lt;/a&gt;&lt;a href="http://wikileaks.org/spyfiles3.html#an1"&gt;attendees&lt;/a&gt;, which includes several Indian companies. Again, interestingly enough, many of these companies may potentially be aiding law enforcement with the technology to carry out the Central Monitoring System. ClearTrail Technologies, in particular, provides &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;solutions&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;for&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;targeted&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;and&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;mass&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;monitoring&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;of&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;IP&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;and&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;voice&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;networks&lt;/a&gt;, as well as remote monitoring and infection frameworks - all of which would potentially be perfect to aid the Central Monitoring System.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In fact, ClearTrail states in its brochure that its &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ComTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;product&lt;/a&gt; is equipped to handle millions of communications per day, while its &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;xTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;product&lt;/a&gt; can easily be integrated with any existing centralised monitoring system for extended coverage. And if that’s not enough, ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Astra&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;” &lt;/a&gt;is designed for the centralized management of thousands of targets. While there may not be any concrete proof that ClearTrail is indeed aiding the Centralized Monitoring System, the facts speak for themselves: ClearTrail is an Indian company which sells target and mass monitoring products to law enforcement agencies. The Centralized Monitoring System is currently being implemented. What are the odds that ClearTrail is &lt;i&gt;not &lt;/i&gt;equipping the CMS? &lt;span&gt;And what are the odds that such technology is &lt;/span&gt;&lt;i&gt;&lt;span&gt;not&lt;/span&gt;&lt;/i&gt;&lt;span&gt; being used for other mass electronic surveillance programmes, such as the Lawful Intercept and Monitoring (LIM)?&lt;/span&gt;&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Spy Files 3...and the legality of India’s surveillance technologies&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;ClearTrail Technologies’ &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;brochure&lt;/span&gt;&lt;/a&gt; -the only leaked document on Indian surveillance technology by the latest Spy Files- states that the company complies with &lt;a href="http://www.etsi.org/technologies-clusters/technologies/regulation-legislation"&gt;&lt;span style="text-decoration: underline;"&gt;ETSI&lt;/span&gt;&lt;/a&gt; and &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;CALEA&lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt; &lt;/a&gt;&lt;a href="http://cryptome.org/laes/calea-require.pdf"&gt;regulations&lt;/a&gt;&lt;/span&gt;. While it’s clear that the company complies with U.S. and European regulations on the interception of communications to attract more customers in the international market, such regulations don’t really apply &lt;i&gt;within&lt;/i&gt; India, which is part of ClearTrail’s market. Notably enough, ClearTrail does not mention any compliance with Indian regulations in its brochure. So let’s have a look at them.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;India has five laws which regulate surveillance:&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;1. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 1885&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;2. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Post&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Office&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 1898&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;3. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Wireless&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Telegraphy&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 1933&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;4. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;Code&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; &lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;of&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; &lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;Criminal&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; &lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;Procedure&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt; (&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;CrPc&lt;/a&gt;&lt;a href="http://www.delhidistrictcourts.nic.in/CrPC.htm"&gt;)&lt;/a&gt;&lt;/span&gt;, 1973: Section 91&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;5. The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt;, 2008&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Post&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Offices&lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.indiapost.gov.in/Pdf/Manuals/TheIndianPostOfficeAct1898.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt; does not cover electronic communications and the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Wireless&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Telegraphy&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://tdsat.nic.in/New%20Compendium19.11.2008/TD%20Set%20Vol-1%20PDF/53-58.pdf"&gt; &lt;/a&gt;&lt;/span&gt;lacks procedures which would determine if surveillance should be targeted or not. Neither the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Indian&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt; nor the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; (&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Amendment&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;) &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;/span&gt; cover mass surveillance, but are both limited to targeted surveillance. Moreover, targeted interception in India according to these laws requires case-by-case authorization by either the home secretary or the secretary department of information technology. In other words, unauthorized, limitless, mass surveillance is not technically permitted by law in India.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The Indian Telegraph Act mandates that the interception of communications can only be carried out on account of &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;a&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;public&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;emergency&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;or&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;for&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;public&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;safety&lt;/a&gt;. However, in 2008, the Information Technology Act copied most of the interception provisions of the Indian Telegraph Act, but removed the preconditions of public emergency or public safety, and instead expanded the power of the government to order interception for the “investigation of any offense”.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The interception of Internet communications is mainly covered by the &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;2009 &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Rules&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;under&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;the&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Information&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Technology&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Act&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; 2008 &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;and&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;Sections&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; 69 &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;and&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; 69&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;B&lt;/a&gt; are particularly noteworthy. According to these Sections, an Intelligence Bureau officer who leaked national secrets may be imprisoned for up to three years, while Section 69 not only allows for the interception of any information transmitted through a computer resource, but also requires that users disclose their encryption keys upon request or face a jail sentence of up to seven years.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;While these laws allow for the interception of communications and can be viewed as widely controversial, they do not technically permit the &lt;i&gt;mass&lt;/i&gt; surveillance of  communications. In other words, ClearTrail’s products, such as &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ComTrail&lt;/span&gt;&lt;/a&gt;, which enable the mass interception of IP networks, lack legal backing. However, the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Unified&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Access&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Services&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; (&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;) &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt;&lt;/span&gt; regarding the Central Monitoring System mandates mass surveillance and requires ISP and Telecom operators to comply.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Through the licenses of the Department of Telecommunications, Internet service providers, cellular providers and telecoms are required to provide the Government of India direct access to all communications data and content &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;even&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;without&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;a&lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt; &lt;/a&gt;&lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/?_r=0"&gt;warrant&lt;/a&gt;, which is not permitted under the laws on interception. These licenses also require cellular providers to have ‘bulk encryption’ of less than 40 bits, which means that potentially any person can use off-the-air interception to monitor phone calls. However, such licenses do not regulate the capture of signal strength, target numbers like IMSI, TIMSI, IMEI or MSI SDN, which can be captured through ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;mTrail&lt;/span&gt;&lt;/a&gt; product.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span&gt;More importantly, following &lt;a class="external-link" href="http://www.financialexpress.com/news/states-begin-to-surrender-offair-phone-snooping-equipment/957859"&gt;allegations&lt;/a&gt; that the National Technical Research Organization (NTRO) had been using off-the-air interception equipment to snoop on politicians in 2011, the Home Ministry issued a directive to ban the possession or use of all off-the-air phone interception gear. As a result, the Indian Government asked the Customs Department to provide an inventory of all all such equipment imported over a ten year period, and it was uncovered that as many as 73,000 pieces of equipment had been imported. Since, the Home Ministry has informed the heads of law enforcement agencies that there has been a &lt;a class="external-link" href="http://m.indianexpress.com/news/state-govts-hand-over-few-offair-phonetapping-sets-to-centre/1185166/"&gt;compete ban on use of such equipment&lt;/a&gt; and that all those who possess such equipment and fail to inform the Government will face prosecution and imprisonment. In short, ClearTrail's product, mTrail, which undertakes off-the-air phone monitoring is illegal and Indian law enforcement agencies are prohibited from using it. &lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;“&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;Astra&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;”&lt;/a&gt; product is capable of remote infection and monitoring, which can push bot to any targeted machine sharing the same LAN. While India’s ISP and telecommunications licenses generally provide some regulations, they appear to be inadequate in regulating specific surveillance technologies which have the capability to target machines and remotely monitor them. Such &lt;a href="http://www.dot.gov.in/licensing/access-services"&gt;&lt;span style="text-decoration: underline;"&gt;licenses&lt;/span&gt;&lt;/a&gt; mandate mass surveillance, but legally, wireless communications are completely unregulated, which raises the question of whether the interception of public Internet networks is allowed. In other words, it is not clear if ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;QuickTrail&lt;/span&gt;&lt;/a&gt; is technically legal or not. The &lt;a class="external-link" href="http://www.auspi.in/policies/UASL.pdf"&gt;UAS License agreement&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;mandates mass surveillance, and while the law does not prohibit it, it does not mandate mass surveillance either. This remains a grey area.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;The issue of data retention arises from &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;leaked&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;brochure&lt;/a&gt;. In particular, ClearTrail states in its brochure that ComTrail - which undertakes mass monitoring of IP and Voice networks - retains data upon request, with a capacity that exceeds several years. xTrail - for targeted IP monitoring - has the ability to retain huge volumes of data which can potentially be used as proof in court. However, India currently lacks privacy legislation which would regulate data retention, which means that data collected by ClearTrail could potentially be stored indefinitely.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;a class="external-link" href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Section 7 of the Information Technology (Amendment) Act, 2008&lt;/a&gt;, deals with the retention of electronic records. However, this section does not state a particular data retention period, nor who will have authorized access to data during its retention, who can authorize such access, whether retained data can be shared with third parties and, if so, under what conditions. Section 7 of the Information Technology (Amendment) Act, 2008, appears to be incredibly vague and to fail to regulate data retention adequately.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Data retention requirements for service providers are included in the &lt;a href="https://cis-india.org/internet-governance/blog/data-retention-in-india" class="external-link"&gt;ISP and UASL licenses&lt;/a&gt; and, while they clarify the type of data they retain, they do not specify adequate conditions for data retention. Due to the lack of data protection legislation in India, it remains unclear how long data collected by companies, such as ClearTrail, would be stored for, as well as who would have authorized access to such data during its retention period, whether such data would be shared with third parties and disclosed and if so, under what conditions.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;India currently lacks specific regulations for the use of various types of technologies, which makes it unclear whether &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;spy&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;products&lt;/a&gt;&lt;/span&gt; are technically legal or not. It is clear that ClearTrail’s mass interception products, such as ComTrail, are not legalized - since Indian laws allow for targeted interception- but they are mandated through the &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;agreement&lt;/a&gt;&lt;/span&gt; regarding the Central Monitoring System.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In short, the legality of ClearTrail’s surveillance technologies remains ambiguous. While India’s ISP and telecom licenses and the &lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;UAS&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;License&lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.dot.gov.in/sites/default/files/DOC231013-004.pdf"&gt;Agreement&lt;/a&gt; mandate mass surveillance, the laws - particularly the 2009 Information Technology Rules- mandate targeted surveillance and remain silent on the issue of mass surveillance. Technically, this does not constitute mass surveillance legal or illegal, but rather a grey area. Furthermore, while &lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;India&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Telegraph&lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.ijlt.in/pdffiles/Indian-Telegraph-Act-1885.pdf"&gt;Act&lt;/a&gt;, &lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Information&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Technology&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt;Act&lt;/a&gt;&lt;a href="http://police.pondicherry.gov.in/Information%20Technology%20Act%202000%20-%202008%20%28amendment%29.pdf"&gt; &lt;/a&gt;and 2009 Rules allow for the interception, monitoring and decryption of communications and surveillance in general, they do not explicitly regulate the various types of surveillance technologies, but rather attempt to “legalize” them through the blanket term of surveillance.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;One thing is clear: India’s license agreements ensure that all ISPs and telecom operators are a part of the surveillance regime. The lack of regulations for India’s surveillance technologies appear to create a grey zone for the expansion of mass surveillance in the country. According to &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.outlookindia.com/article.aspx?265192"&gt;Saikat&lt;/a&gt;&lt;a href="http://www.outlookindia.com/article.aspx?265192"&gt; &lt;/a&gt;&lt;a href="http://www.outlookindia.com/article.aspx?265192"&gt;Datta&lt;/a&gt;&lt;/span&gt;, an investigative journalist, a senior privacy telecom official stated:&lt;/p&gt;
&lt;blockquote class="italized"&gt;“&lt;i&gt;Do you really think a private telecom company can stand up to the government or any intelligence agency and cite law if they want to tap someone’s phone?” &lt;/i&gt;&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;﻿&lt;/p&gt;

&lt;h3&gt;&lt;b&gt;Spy Files 3...and human rights in India&lt;/b&gt;&lt;/h3&gt;

&lt;p align="JUSTIFY"&gt;The facts speak for themselves. The latest Spy Files confirm that the same agencies involved in the development of the Central Monitoring System (CMS) are also interested in the latest surveillance technology sold in the global market. Spy Files 3 also provide data on one of India’s largest surveillance technology companies, &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ClearTrail&lt;/span&gt;&lt;/a&gt;, which sells a wide range of surveillance technologies to law enforcement agencies around the world. And Spy Files 3 show us exactly what these technologies can do.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In particular, ClearTrail’s &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ComTrail&lt;/span&gt;&lt;/a&gt; provides mass monitoring of IP and voice networks, which means that law enforcement agencies using it are capable of  intercepting millions of communications every day through Gmail, Yahoo, Hotmail and others, of correlating our identities across networks and of targeting our location. &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;xTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;/span&gt;enables law enforcement agencies to monitor us based on our “harmless” metadata, such as our IP address, our mobile number and our email ID. Think our data is secure when using the Internet through a cyber cafe? Well &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;QuickTrail&lt;/span&gt;&lt;/a&gt; proves us wrong, as it’s able to assist law enforcement agencies in monitoring and intercepting our communications even when we are using public Internet networks.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And indeed, carrying a mobile phone is like carrying a GPS device, especially since &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;mTrail&lt;/span&gt;&lt;/a&gt; provides law enforcement with off-the-air interception of mobile communications. Not only can mTrail target our location, listen to our calls and store our data, but it can also undertake passive off-the-air interception and monitor our voice, SMS and protocol information. Interestingly enough, mTrail also intercepts targeted calls from a predefined suspect list. The questions though which arise are: who is a suspect? How do we even know if we are suspects? In the age of the War on Terror, potentially anyone could be a suspect and thus potentially anyone’s mobile communications could be intercepted. After all, mass surveillance dictates that &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;we&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;are&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;all&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;suspicious&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;until&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;proven&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;innocent&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;. &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And if anyone can potentially be a suspect, then potentially anyone can be remotely infected and monitored by &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;Astra&lt;/span&gt;&lt;/a&gt;. Having physical access to a targeted device is a conventional surveillance mean of the past. Today, Astra can &lt;i&gt;remotely&lt;/i&gt; push bot to our laptops and listen to our Skype calls, capture our Webcams, search our browsing history, identify our location and much more. And why is any of this concerning? Because contrary to mainstream belief, &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;we&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;should&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;all&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;have&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;something&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;to&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;hide&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;! &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;Privacy&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;protects&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;us&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;from&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;abuse&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;from&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;those&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;in&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt;power&lt;/a&gt;&lt;a href="https://www.schneier.com/blog/archives/2008/03/privacy_and_pow.html"&gt; &lt;/a&gt;&lt;/span&gt;and safeguards our individuality and autonomy as human beings. If we are opposed to the idea of the police searching our home without a search warrant, we should be opposed to the idea of our indiscriminate mass surveillance. After all, mass surveillance - especially the type undertaken by &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;ClearTrail&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;’&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;s&lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt; &lt;/a&gt;&lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;products&lt;/a&gt;&lt;/span&gt; -  can potentially result in the access, sharing, disclosure and retention of data much more valuable than that acquired by the police searching our home. Our credit card details, our photos, our acquaintances, our personal thoughts and opinions, and other sensitive personal information can usually be found in our laptops, which potentially can constitute much more incriminating information than that found in our homes.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;And most importantly: even if we think that we have nothing to hide, it’s really not up to us to decide: it’s up to data analysts. While we may think that our data is “harmless”, a data analyst linking our data to various other people and search activities we have undertaken might indicate otherwise. Five years ago, &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;a&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;UK&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;student&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;studying&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;Islamic&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;terrorism&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;for&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;his&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;Masters&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;dissertation&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;was&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;detained&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;for&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;six&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt; &lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;days&lt;/a&gt;&lt;a href="http://www.timeshighereducation.co.uk/402844.article"&gt;.&lt;/a&gt;&lt;/span&gt; The student may not have been a terrorist, but his data said this: “Young, male, Muslim... who is downloading Al-Qaeda’s training material” - and that was enough for him to get detained. Clearly, the data analysts mining his online activity did not care about the fact that the only reason why he was downloading Al-Qaeda material was for his Masters dissertation. The fact that he was a male Muslim downloading terrorist material was incriminating enough.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;This incident reveals several concerning points: The first is that he was clearly already under surveillance, prior to downloading Al-Qaeda’s material. However, given that he did not have a criminal record and was “just a Masters student in the UK”, there does not appear to be any probable cause for his surveillance in the first place. Clearly he was on some suspect list on the premise that he is male and Muslim - which is a discriminative approach. The second point is that after this incident, it is likely that some male Muslims may be more cautious about their online activity - with the fear of being on some suspect list and eventually being prosecuted because their data shows that “they’re a terrorist”. Thus, mass surveillance today appears to also have implications on freedom of expression. The third point is that this incident reveals the extent of mass surveillance, since even a document downloaded by a Masters student is being monitored.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;This case proves that innocent people can potentially be under surveillance and prosecuted, as a result of mass, indiscriminate surveillance. Anyone can potentially be a suspect today, and maybe for the wrong reasons. It does not matter if we think our data is “harmless”, but what matters is who is looking at our data, when and why.  Every bit of data potentially hides several other bits of information which we are not aware of, but which will be revealed within a data analysis. We should always &lt;span style="text-decoration: underline;"&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;“&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;have&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;something&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;to&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt; &lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;hide&lt;/a&gt;&lt;a href="https://www.aclu.org/blog/national-security/you-may-have-nothing-hide-you-still-have-something-fear"&gt;”&lt;/a&gt;&lt;/span&gt;, as that is the only way to protect us from abuse by those in power.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;In the contemporary surveillance state, we are all suspects and mass surveillance technologies, such as the ones sold by &lt;a href="http://www.wikileaks.org/spyfiles/docs/CLEARTRAIL-2011-Intemonisuit-en.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;ClearTrail&lt;/span&gt;&lt;/a&gt;, can potentially pose major threats to our right to privacy, freedom of expression and other human rights. And probably the main reason for this is because surveillance technologies in India legally fall in a grey area. Thus, it is recommended that law enforcement agencies in India regulate the various types of surveillance technologies in compliance with the &lt;a class="external-link" href="https://en.necessaryandproportionate.org/text"&gt;International Principles on Communications Surveillance and Human Rights.&lt;/a&gt;&lt;/p&gt;
&lt;p align="JUSTIFY"&gt;Spy Files 3 show us why our human rights are at peril and why we should fight for our right to be free from suspicion.&lt;/p&gt;
&lt;p align="JUSTIFY"&gt; &lt;/p&gt;
&lt;p align="JUSTIFY"&gt;This article was &lt;a class="external-link" href="http://www.medianama.com/2013/11/223-spy-files-3-wikileaks-sheds-more-light-on-the-global-surveillance-industry-cis-india/"&gt;cross-posted in Medianama &lt;/a&gt;on 6th November 2013.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/spy-files-three'&gt;https://cis-india.org/internet-governance/blog/spy-files-three&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Homepage</dc:subject>
    

   <dc:date>2013-11-14T16:21:00Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/economic-times-october-18-2013-indu-nandakumar-bouquets-brickbats-google-new-privacy-policy">
    <title>Bouquets &amp; brickbats for Google's new privacy policy</title>
    <link>https://cis-india.org/news/economic-times-october-18-2013-indu-nandakumar-bouquets-brickbats-google-new-privacy-policy</link>
    <description>
        &lt;b&gt;Google's recent privacy policy change that allows the internet search company to use names, photographs and endorsements by its users in online advertisements is getting mixed reviews in India - advertisers love it, and activists love to hate it.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;This article by Indu Nandakumar was &lt;a class="external-link" href="http://articles.economictimes.indiatimes.com/2013-10-18/news/43178518_1_google-plus-google-play-user-privacy"&gt;published in the Economic Times&lt;/a&gt; on October 18, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Internet rights activists called it another incursion into individual  privacy by the California-based company that uses 'Don't be evil' as an  informal corporate motto. Brand advisers and marketers praised the  ingenuity of personalisation that can make advertising much more  effective.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"From a user perspective, there is a higher chance of them buying a  product if it is endorsed by a friend," said Kunal Jeswani, chief  digital officer at Ogilvy &amp;amp; Mather India. To his mind, the argument  about user privacy is "naive" because when a user enters a social  network, he/she should know his/her personal information, such as  profile photographs and names, is already on the web.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Google  announced its policy change regarding user information will be effective  on November 11, giving the company the right to use profile names,  photos and comments alongside advertisements by clients who use its  online advertising network of over 2 million websites.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For  instance, if a user has endorsed a product by giving it a "+1" or rated a  product on the Google Play app store, his/her image will appear next to  the ad when it is displayed to people who are part of his/her social  circle on the social networking service Google Plus. The move is seen as  Google's attempt to catch up with rival Facebook, which first  introduced the concept of 'social ads' that let corporations use the  power of influence of people within a person's social network to sell  products.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/NewShot.png" alt="New Shot" class="image-inline" title="New Shot" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Internet rights activists said such practices raise privacy concerns as they do not take prior consent of users.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"We are not comfortable with user information being used without  their permission, especially since Google's privacy standards are not  very high," said Uday Mehta, associate director at Consumer Unity and  Trust Society (CUTS International).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Last year, the agency  complained to Competition Commission of India to investigate Google's  alleged anti-competitive practices here. An investigation is ongoing.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In an emailed response, Google said it is notifying users about the  change in policy, so that if a user does not like it, he/she can turn it  off.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Since we're updating an existing setting, we will continue  to respect the choice you made about the old setting. That means if you  already told us that you didn't want your +1s to appear in ads, none of  your other shared endorsements will appear in ads," a Google spokesman  said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For example, Google said, if a user reviewed a restaurant,  people who aren't in his/her Google Plus Circles of friends would not  see that review in an ad that the restaurant might run through Google.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The latest ad strategy comes at a time when companies such as Google  and Facebook have been attempting to increase their ad revenues by  personalising advertisements to attract user attention. Over 90% of  Google's $46-billion revenue in 2012 came from advertisements.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sunil Abraham, executive director of the Center for Internet and  Society said the issue highlights the need for a stronger internet  privacy statute in India. The absence of clear privacy laws makes it  impossible for government officials to understand the harm caused to  personal rights because of the default settings of Google, he observed.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/economic-times-october-18-2013-indu-nandakumar-bouquets-brickbats-google-new-privacy-policy'&gt;https://cis-india.org/news/economic-times-october-18-2013-indu-nandakumar-bouquets-brickbats-google-new-privacy-policy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-25T05:40:56Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/yahoo-october-23-2013-what-india-can-learn-from-snowden-revelations">
    <title>What India can Learn from the Snowden Revelations</title>
    <link>https://cis-india.org/internet-governance/blog/yahoo-october-23-2013-what-india-can-learn-from-snowden-revelations</link>
    <description>
        &lt;b&gt;Big Brother is watching, across cyberspace and international borders. Meanwhile, the Indian government has few safeguards in theory and fewer in practice. There’s no telling how prevalent or extensive Indian surveillance really is.&lt;/b&gt;
        &lt;p&gt;The title of the article was changed in the&lt;a class="external-link" href="http://in.news.yahoo.com/why-india-needs-a-snowden-of-its-own-054956734.html"&gt; version published by Yahoo&lt;/a&gt; on October 23, 2013.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Since the ‘&lt;a href="http://www.theguardian.com/world/edward-snowden" target="_blank"&gt;Snowden revelations&lt;/a&gt;’, which uncovered the United States government’s massive global &lt;span class="cs4-ndcor yshortcuts" id="lw_1382621265093_3"&gt;surveillance&lt;/span&gt; through the &lt;a href="http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%29" target="_blank"&gt;PRISM&lt;/a&gt; program, there have been reactions aplenty to their impact.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Snowden revelations highlighted the issue of human rights in the context of the existing cross-border and jurisdictional nightmare: the data of foreign citizens surveilled and harvested by agencies such as the National Security Agency through programs such as PRISM are not subject to protection found in the laws of the country. Thus, the US government has the right to access and use the data, but has no responsibility in terms of how the data will be used or respecting the rights of the people from whom the data was harvested.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Snowden revelations demonstrated that the biggest global surveillance efforts are now being conducted by democratically elected governments – institutions of the people, by the people, for the people – that are increasingly becoming suspicious of all people.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Adding irony to this worrying trend, Snowden sought asylum from many of the most repressive regimes: this dynamic speaks to the state of society today. The Snowden revelations also demonstrate how government surveillance is shifting from targeted surveillance, warranted for a specific reason and towards a specified individual, to blanket surveillance where security agencies monitor and filter massive amounts of information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This is happening with few checks and balances for cross-border and  domestic surveillance in place, and even fewer forms of redress for the  individual. This is true for many governments, including &lt;span class="cs4-visible yshortcuts" id="lw_1382621265093_1"&gt;India&lt;/span&gt;.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;India’s reaction&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;After the first news of the Snowden revelations, the Indian Supreme Court &lt;a href="http://www.medianama.com/2013/06/223-supreme-court-to-hear-pil-against-nsa-surveillance-of-indian-data-report/" target="_blank"&gt;agreed&lt;/a&gt; to hear a Public Interest Litigation requesting that foreign companies  that shared the information with US security agencies be held  accountable for the disclosure. In response to the PIL, the Supreme  Court stated it did not have jurisdiction over the US government.&lt;br /&gt;&lt;br /&gt;The  response of the Supreme Court of India demonstrates the potency of  jurisdiction in today’s global information economy in the context of  governmental surveillance. Despite being upset at the actions of  America’s National Security Agency (NSA), there is little direct legal  action that any &lt;span class="cs4-ndcor yshortcuts" id="lw_1382621265093_7"&gt;government&lt;/span&gt; or individual can take against the US government or companies incorporated there.&lt;br /&gt;&lt;br /&gt;In  the PIL, the demand that companies be held responsible is interesting  and representative of a global debate, as it implies that in the context  of governmental surveillance, companies have a responsibility to  actively evaluate and reject or accept governmental surveillance  requests. Although I do not disagree with this as a principle, in  reality, this evaluation is a difficult step for companies to take. &lt;br /&gt;&lt;br /&gt;For  example, in India, under Section 69 of the Information Technology Act,  2000, service providers are penalized with up to seven years in prison  for non-compliance with a governmental request for surveillance. The  incentives for companies to actually reject governmental requests are  minimal, but one factor that could possibly push companies to become  more pronounced in their resistance to installing backdoors for the  government and complying with governmental surveillance requests is  market pressure from consumers.&lt;br /&gt;&lt;br /&gt;To a certain extent, this has  already started to happen. Companies such as Facebook, Yahoo and Google  have created ‘transparency reports’ that provide – at different  granularities – information about governmental requests and the  company’s compliance or rejection of the same. &lt;br /&gt;&lt;br /&gt;In India, P. Rajeev, Member of Parliament from Kerala, has started a &lt;a href="http://www.change.org/petitions/google-facebook-microsoft-yahoo-reveal-information-on-data-of-indian-citizens-given-to-us-security-agencies-2" target="_blank"&gt;petition&lt;/a&gt; asking that the companies disclose information on &lt;span class="cs4-ndcor yshortcuts" id="lw_1382621265093_8"&gt;Indian data&lt;/span&gt; given to US security agencies. Although transparency by complying  companies does not translate directly into regulation of surveillance,  it allows the customer to make informed choices and decide whether a  company’s level of compliance with governmental requests will impact  his/her use of that service.&lt;br /&gt;&lt;br /&gt;The PIL also called for the establishment of Indian servers to protect the privacy of Indian data. This solution has been &lt;a href="http://articles.economictimes.indiatimes.com/2013-08-14/news/41409701_1_traffic-originating-and-terminating-servers-mocit" target="_blank"&gt;voiced by many&lt;/a&gt;,  including government officials. Though the creation of domestic servers  would ensure that the US government does not have direct and unfettered  access to Indian data, as it would require that foreign governments  access Indian information through a formal &lt;a href="http://mha.nic.in/Policy_Planing_Division" target="_blank"&gt;Mutual Legal Assistance Treaty&lt;/a&gt; process, it does not necessarily enhance the privacy of Indian data. &lt;br /&gt;&lt;br /&gt;As  a note, India has MLAT treaties with 34 countries. If domestic servers  were established, the information would be subject to Indian laws and  regulations.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Snooping&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Snowden Revelations are not the first instance to spark a discussion on domestic servers by the Government of India. &lt;br /&gt;&lt;br /&gt;For  example, in the back-and-forth between the Indian government and the  Canadian company RIM, now BlackBerry, the company eventually &lt;a href="http://timesofindia.indiatimes.com/tech/tech-news/telecom/BlackBerry-sets-up-server-in-Mumbai-to-aid-interception/articleshow/11969224.cms" target="_blank"&gt;set up servers in Mumbai&lt;/a&gt; and provided a lawful interception solution that satisfied the Indian  government. The Indian government made similar demands from &lt;a href="http://news.cnet.com/8301-1009_3-20015418-83.html" target="_blank"&gt;Skype and Google&lt;/a&gt;. In these instances, the domestic servers were meant to facilitate greater surveillance by Indian law enforcement agencies.&lt;br /&gt;&lt;br /&gt;Currently  in India there are a number of ways in which the government can legally  track data online and offline. For example, the interception of  telephonic communications is regulated by the Indian Telegraph Act,  1885, and relies on an order from the Secretary to the Ministry of Home  Affairs. Interception, decryption, and monitoring of digital  communications are governed by Section 69 of the Information Technology  Act, 2000 and again rely on the order of the executive. &lt;br /&gt;&lt;br /&gt;The  collection and monitoring of traffic data is governed by Section 69B of  the Information Technology Act and relies on the order of the Secretary  to the government of India in the Department of Information Technology.  Access to stored data, on the other hand, is regulated by Section 91 of  the Code of Criminal Procedure and permits access on the authorization  of an officer in charge of a police station.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The gaps in the Indian &lt;span class="cs4-ndcor yshortcuts" id="lw_1382621265093_4"&gt;surveillance&lt;/span&gt; regime are many and begin with a lack of enforcement and harmonization of existing safeguards and protocols. Presently, &lt;span class="cs4-visible yshortcuts" id="lw_1382621265093_2"&gt;India&lt;/span&gt; is in the process of realizing a privacy legislation. &lt;br /&gt;&lt;br /&gt;In 2012, a committee chaired by Justice AP Shah (of which the Center for Internet and Society was a member) wrote &lt;a href="http://planningcommission.nic.in/reports/genrep/rep_privacy.pdf" target="_blank"&gt;The Report of the Group of Experts on Privacy&lt;/a&gt;,  which laid out nine national privacy principles meant to be applied to  different legislation and sectors – including Indian provisions on  surveillance.&lt;br /&gt;&lt;br /&gt;The creation of domestic servers is just one  example of how the Indian government has been seeking greater access to  information flowing within its borders. New requirements for Indian  service providers and the creation of projects that go beyond the legal  limits of governmental surveillance in India enable greater access to  details about an individual on a real-time and blanket basis.&lt;br /&gt;&lt;br /&gt;For example, telecoms in India are now required to include &lt;a href="http://www.firstpost.com/tech/exclusive-location-tracking-of-every-indian-mobile-user-by-2014-876109.html/2" target="_blank"&gt;user location data&lt;/a&gt; as part of the ‘call detail record’ and be able to &lt;a href="http://www.medianama.com/2012/08/223-indian-government-revises-location-accuracy-guidelines-says-telcos-should-bear-the-cost/" target="_blank"&gt;provide&lt;/a&gt; the same to law enforcement agencies on request under &lt;a href="http://www.cca.ap.nic.in/i_agreement.pdf" target="_blank"&gt;provisions&lt;/a&gt; in the Unified Access Service and Internet Service Provider Licenses. &lt;br /&gt;&lt;br /&gt;At the same time, the Government of India is in the process of putting in place a &lt;a href="http://en.wikipedia.org/wiki/Central_Monitoring_System" target="_blank"&gt;Central Monitoring System&lt;/a&gt; that would provide Indian security agencies the ability to directly intercept communications, bypassing the service provider.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Even if the Central Monitoring System were to adhere to the legal  safeguards and procedures defined under the Indian Telegraph Act and  Information Technology Act, the system can only do so partially, as both  provisions create a clear chain of custody that the government and  service providers must follow – that is, the service provider was  included as an integral component of the interception process.&lt;br /&gt;&lt;br /&gt;If  the Indian government implements the Central Monitoring System, it  could remove governmental surveillance completely from the public eye.  Bypassing the service provider allows the government to fully determine  how much the public knows about surveillance. It also removes the market  and any pressure that consumers could exert from insight provided by  companies on the surveillance requests that they are facing.&lt;br /&gt;&lt;br /&gt;Though  the Indian government could (and should) be transparent about the  amount and type of surveillance it is undertaking, currently there is no  legal requirement for the government of India to disclose this  information, and security agencies are exempt from the Right to  Information Act. Thus, unless India has a Snowden somewhere in the  apparatus, the Indian public cannot hope to get an idea of how prevalent  or extensive Indian surveillance really is.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Policy vacuum&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;For any &lt;span class="cs4-ndcor yshortcuts" id="lw_1382621265093_5"&gt;government&lt;/span&gt;,  the surveillance of its citizens, to some degree, might be necessary.  But the Snowden revelations demonstrate that there is a vacuum when it  comes to surveillance policy and practices. This vacuum has permitted  draconian measures of surveillance to take place and created an  environment of mistrust between citizens and governments across the  globe. &lt;br /&gt;&lt;br /&gt;When governments undertake surveillance, it is critical  that the purpose, necessity and legality of monitoring, and the use of  the material collected are built into the regime to ensure it does not  violate the human rights of the people surveilled, foreign or domestic.&lt;br /&gt;&lt;br /&gt;In 2013, the &lt;a href="https://en.necessaryandproportionate.org/text" target="_blank"&gt;International Principles on the Application of Human Rights to Communications Surveillance&lt;/a&gt; were drafted, in part, to address this vacuum. The principles seek to  explain how international human rights law applies to surveillance of  communications in the current digital and technological environment.  They define safeguards to ensure that human rights are protected and  upheld when governments undertake surveillance of communications. &lt;br /&gt;&lt;br /&gt;When  the Indian surveillance regime is measured against these principles, it  appears to miss a number of them, and does not fully meet several  others. In the context of surveillance projects like the Central  Monitoring System, and in order to avoid an Indian version of the PRISM  program, India should take into consideration the safeguards defined in  the principles and strengthen its surveillance regime to ensure not only  the protection of human rights in the context of surveillance, but to  also establish trust in its surveillance regime and practices with other  countries.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Elonnai Hickok is the Program Manager for Internet Governance at the  Centre for Internet and Society, and leads its research on privacy.&lt;/i&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/yahoo-october-23-2013-what-india-can-learn-from-snowden-revelations'&gt;https://cis-india.org/internet-governance/blog/yahoo-october-23-2013-what-india-can-learn-from-snowden-revelations&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-25T07:29:57Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm">
    <title>An Interview with Jacob Kohnstamm, Dutch Data Protection Authority and Chairman of the Article 29 Working Party</title>
    <link>https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm</link>
    <description>
        &lt;b&gt;The Centre for Internet and Society interviewed Jacob Kohnstamm, Dutch Data Protection Authority and Chairman of the Article 29 Working Party.&lt;/b&gt;
        &lt;h3 style="text-align: justify; "&gt;What activities and functions does your office undertake?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The activities and functions of the Dutch data protection authority can roughly be divided in 4 different categories: supervisory activities, giving advise on draft legislation, raising awareness and international tasks. &lt;br /&gt;&lt;br /&gt;The Dutch DPA supervises the legislation applicable in the Netherlands with regard to the use of personal data. The most important law is the Dutch Data Protection Act, but the Dutch DPA also supervises for example the Acts governing data processing by police and justice as well as parts of the Telecoms Act. &lt;br /&gt;&lt;br /&gt;The supervisory activities mainly consist of investigating, ex officio, violations of the law, with the focus on violations that are serious, structural and impact a large amount of people. Where necessary, the Dutch DPA can use its sanctioning powers, including imposing a conditional fine, to enforce the law. The Dutch DPA can also decide to examine sector-wide codes of conduct that are submitted to it and provide its views in the form of a formal opinion. &lt;br /&gt;&lt;br /&gt;In addition to investigations, the Dutch DPA advises the government, and sometimes the parliament, on draft legislation related to the processing of personal data. Following the Data Protection Act, the government is obliged to submit both primary and secondary legislation related to data processing to the DPA for advice. &lt;br /&gt;&lt;br /&gt;As regards awareness-raising, next to publishing the results of the investigations, its views on codes of conduct and its advice on legislation, the Dutch DPA also issues guidelines, on its own initiative, explaining legal norms. Via its websites, the Dutch DPA provides more information to both data subjects and controllers on how data can and cannot be processed. Specifically for data subjects, self-empowerment tools – including standard letters to exercise their rights – are made available. Furthermore, they can contact the Dutch DPA daily via a telephone hotline.&lt;br /&gt;&lt;br /&gt;Last but not least, the Dutch DPA participates in several International and European fora, including the Article 29 Working Party of which I am the Chair, the European and the International Conference of data protection and privacy commissioners, of whose Executive Committee I am also the Chair.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What powers does your office have? in your opinion are these sufficient? Which powers have been most useful? If there is a lack, what do you feel is needed?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Dutch DPA has a broad range investigative powers, including the power to order the controller to hand over all relevant information and entering the premises of the controller unannounced. All organisations subjected to the supervision of the Dutch DPA are obligated to cooperate. &lt;br /&gt;&lt;br /&gt;The Dutch DPA also has a considerable range of sanctioning powers, it can for example order the suspension or termination of certain processing operations and can also impose a conditional fine. Currently a bill is before Parliament to provide the Dutch DPA with fining powers as well.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Especially when the bill providing the Dutch DPA with fining powers will be passed, I feel the powers are sufficient, giving us all the necessary enforcement tools to ensure compliance with the law.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;How is your office funded?&lt;/h3&gt;
&lt;p&gt;The Dutch DPA is funded through the government who, together with the parliament, each year determines the budget for the next year. The budget is drafted on the basis of a proposal from the Dutch DPA.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What is the organizational structure of your office and the responsibilities of the key executives?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Dutch DPA consists of a college of commissioners and the supporting Secretariat, itself consisting of 6 departments and headed by the Director. The Dutch DPA has 2 supervision departments, one for the private and one for the public sector, a legal department, a communications department, an international department and a department providing the operational support.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;If India creates a  framework of co-regulation, how would you suggest the overseeing body be structured?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Considering the many differences between India and the Netherlands - and Europe - this is a very hard question to answer. But whatever construction is chosen in India, it is of utmost importance to guarantee the independence of the supervisory authorit(y)(ies), who shall be provided with sufficient and scalable powers to be able to sanction violations.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What legal challenges has your office faced?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The biggest legal challenge we face at the moment is the new European legal framework currently being discussed. It is as yet uncertain whether and when this will enter into force, but it is clear that it will bring new challenges for our office.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What are the main differences between your offices?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Generally, I think that the differences between my office and the UK and Canadian offices mostly stem from our different legal and cultural backgrounds, especially the difference between the common law and codified law systems. &lt;br /&gt;&lt;br /&gt;In addition, the norms and powers differ per supervisory authority. The Dutch DPA for example can enter a building without prior notice, while the ICO, if I understand correctly, can only enter with the consent of the supervised organisation. &lt;br /&gt;&lt;br /&gt;I however prefer to look at the similarities and possibilities to overcome our differences, because I think that we all feel that providing a high level of data protection and ensuring user control are all of our main priorities.&lt;br /&gt;&lt;br /&gt;Naturally, I am very curious to hear from Chrisopher and Chantal as well.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What are the most recent privacy developments for each of your respective offices?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The technological developments of the past decades and the increasing use of smartphones and tablets, have also made privacy developments necessary and have obliged us, as data protection authorities, to consider the rules and norms in this new environment.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What would you broadly recommend for a privacy legislation for India?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In my view the privacy legislation in India should in any case contain the basic principles of the protection of personal data, applicable to both the public and the private sector. Naturally with some exceptions for law enforcement purposes. &lt;br /&gt;&lt;br /&gt;Furthermore, the Indian law should protect the imported data of citizens from other parts of the world as well, including the EU. &lt;br /&gt;&lt;br /&gt;And as mentioned in my answer to question 5, it is of utmost importance that the Indian legislation guarantees the establishment of (a) completely independent supervisory authorit(y)(ies), provided with sufficient sanctioning powers, to supervise compliance with the legislation also of the government, including police and justice.&lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm'&gt;https://cis-india.org/internet-governance/blog/interview-with-jacob-kohnstamm&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-25T04:50:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/interview-with-berlin-data-protection-commissioner">
    <title>Interview with Dr. Alexander Dix - Berlin Data Protection and Freedom of Information Commissioner</title>
    <link>https://cis-india.org/internet-governance/blog/interview-with-berlin-data-protection-commissioner</link>
    <description>
        &lt;b&gt;Maria Xynou recently interviewed Berlin's Data Protection and Freedom of Information Commissioner: Dr. Alexander Dix. View this interview and gain an insight on recommendations for better data protection in India!&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;&lt;a class="external-link" href="http://www.ediscovery-exchange.com/SpeakerInfo.aspx?tp_spkid=37916"&gt;Dr. Alexander Dix&lt;/a&gt; has been Berlin's Data Protection and Freedom of Information Commissioner since June 2005. He has more than 26 years of practical experience in German data protection authorities and previously served as Commissioner for the state of Bradenburg for seven years.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Dr. Dix is a specialist in telecommunications and media and has dealt  with a number of issues regarding the cross-border protection of  citizen’s privacy. He chairs the International Working Group on Data  Protection in Telecommunications (“Berlin Group”) and is a member of the  Article 29 Working Party of European Data Protection Supervisory  Authorities. In this Working Party he represents the Data Protection  Authorities of the 16 German States (Länder).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A native of Bad Homburg, Hessen, Dr. Alexander Dix graduated from Hamburg  University with a degree in law in 1975. He received a Master of Laws  degree from the London School of  Economics and Political Science in 1976 and a Doctorate in law from  Hamburg University in 1984. He has published extensively on issues of  data protection and freedom of information. Inter alia he is a co-editor  of the German Yearbook on Freedom of Information and Information Law.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Centre for Internet and Society interviewed Dr. Alexander Dix on the following questions:&lt;/p&gt;
 &lt;ol&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;What activities and functions does the Berlin data 	commissioner's office undertake?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;What powers does the Berlin data commissioner's office 	have? In your opinion, are these sufficient? Which powers have been 	most useful? If there is a lack, what would you feel is needed?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;How is the office of the Berlin Data Protection 	Commissioner funded?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;What is the organisational structure at the Office of 	the Berlin Data Protection Commissioner and the responsibilities of 	the key executives?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;If India creates a Privacy Commissioner, what 	structure/framework would you suggest for the office?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;What challenges has your office faced?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;What is the most common type of privacy violation that 	your office is faced with?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;Does your office differ from other EU data protection 	commissioner offices?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;How do you think data should be regulated in India?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;Do you support the idea of co-regulation or 	self-regulation?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p align="JUSTIFY"&gt;How can India protect its citizens' data when it is 	stored in foreign servers?&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;VIDEO &lt;iframe frameborder="0" height="250" src="http://www.youtube.com/embed/agXVs7ZlKdU" width="250"&gt;&lt;/iframe&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/interview-with-berlin-data-protection-commissioner'&gt;https://cis-india.org/internet-governance/blog/interview-with-berlin-data-protection-commissioner&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-11-06T09:29:32Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/outlookindia-october-28-2013-debarshi-dasgupta-beyond-the-searchlight">
    <title>Beyond the Searchlight</title>
    <link>https://cis-india.org/news/outlookindia-october-28-2013-debarshi-dasgupta-beyond-the-searchlight</link>
    <description>
        &lt;b&gt;Should we be wary of Google’s all-pervasiveness? &lt;/b&gt;
        &lt;p&gt;This article Debarshi Dasgupta was &lt;a class="external-link" href="http://www.outlookindia.com/article.aspx?288214"&gt;published in the Outlook&lt;/a&gt; on October 23, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;b&gt;Search Google&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Some queries to type in the window&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Is what is good for Google good for India, especially after Brazil and the EU question its actions?&lt;/li&gt;
&lt;li&gt;Are politicians sending out the right signals by associating with Google’s initiatives?&lt;/li&gt;
&lt;li&gt;Is Google directing the internet intellectual discourse in a way that will benefit it?&lt;/li&gt;
&lt;li&gt;Does Google initiate the kind of offline activities it does here in other democracies?&lt;/li&gt;
&lt;li&gt;Is Google shutting out potential competition by obtaining a stranglehold on the internet?&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;Google’s policy, its CEO Eric Schmidt had once said, was to get right  up to the creepy line, but not cross it. It has generated contentious  debate about the firm’s activities and products, whether it’s accessing  your e-mails to feed you targeted ads, something we have now come to  accept grudgingly, or its soon-to-be-rel­eased Google Glass that comes  fitted with miniature cameras and has advocates all worried about the  next big breach on the privacy frontier.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Not just online, where privacy violations and anti-competitive  practices have raised concerns globally, some of Google’s offline  activities in India too should have us asking questions based on  conflict of interest and lack of transparency. Here too, the company  seems to have placed itself right next to the creepy line. Especially  the way it has gone about sponsoring research at key think-tanks and  academia on areas that direc­tly concern its business interests.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nothing illustrates this better than the work of PRS Legislative  Research, which Google has funded  in the past. PRS produces policy  briefi­ngs that are sent out to lawmakers and the media, including on  internet governance. PRS hasn’t got a clearance to receive foreign funds  since it became independent of the Centre for Policy Research in 2010,  where it was launched, and has since then been largely funded by  domestic sources.&lt;/p&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/ISpy.png/@@images/3132fe8b-54a1-4e6b-a14a-f744172a7cc9.png" alt="I Spy" class="image-inline" title="I Spy" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/home-images/Prashant.png" alt="Prashant" class="image-inline" title="Prashant" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Prashant Reddy, Blogger&lt;/p&gt;
&lt;p&gt;&lt;b&gt;“That an Indian user seeking arbitration&lt;br /&gt;with Google has to do so in a California &lt;br /&gt;court reeks of double standards.”&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p style="text-align: justify; "&gt;Does this growing network mean Google is having a say in shaping  internet governance laws? Maybe yes. They should have a say by all  means, just as other interested parties must get theirs. But given its  influence and the certain opaqueness that marks its activities, some  more transparency can only boost the cred­entials of a firm whose  informal motto is—“Don’t be evil”. Google may have helped you find that  bit of information from the googol tera bytes of online data but it has  so far largely evaded discussion on how it has gone on to become big and  influential in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But while it may have been forced to back out from fun­ding PRS   direc­tly, Google’s web of res­earch fellows in this country is growing.   In August this year, the Asia Internet Coalition, of which Goo­gle is a   founding member, selected its two inaugural India fellows—Shehla  Rashid  Shora and Astik Sinha, both of whom will analyse policies  concerning  the internet environment here. Sinha also happens to be a  social media  advisor for BJP MP Anurag Thakur.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;So big that it hobnobs with Narendra Modi in the first of its Hangout series  and, quite contrary to its espousal of free speech, has comfortable  questions pitched to him. Or so influential that it has telecom minister  Kapil Sibal, its bete noire from 2011 when his ministry was forcing  them to pull down content, to attend the launch of  chand­nichowkonline.in, a business direct­ory of Sibal’s constituency. &lt;i&gt;Outlook&lt;/i&gt; made several attempts to get a reaction from Google but rec­eived none by the time this article had to go to the press.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/Google.png" alt="Nikon" class="image-inline" title="Nikon" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class="fsppicturecaption"&gt;&lt;b&gt;Blurred lines&lt;/b&gt; Paid ads seem no different from search results for cameras &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;Google, since 2011, has also placed three fellows so far under its  annual Google Public Policy Fellowship prog­ramme at the Bangalore-based  Cen­tre for Internet and Society (CIS). The research is supposed to  focus on “acc­ess to knowledge, openness in India, freedom of  expression, pri­vacy, and telecom”. Yet another crucial funding in May  2013 went to the Centre for Communication Gover­na­nce at the National  Law University in New Delhi, which does research on areas directly  linked to its business interests. The agreement contains a clause that  says “Google will not be excluded from any future business  opportunities”. Its research director Chi­n­mayi Arun did not respond to  &lt;i&gt;Outlook&lt;/i&gt;’s e-mail and said she was too busy to speak when &lt;i&gt;Outlook&lt;/i&gt; called her up.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;
&lt;p&gt;A third institution Google has fun­ded is the media watch website The  Hoot. After the 26/11 attacks in Mum­bai when the government hastily  amended the IT Act, clamping down in a restrictive spirit, noted  journalist and the website’s editor Sevanti Ninan was one of the many  criticising the government publi­cly in her articles. Google, she says,  contac­ted her somewhere around mid-2009 seeking a proposal on how they  could help with what she was working on. Ninan sent one proposing a Free  Speech Hub and received a grant of $22,000 in January 2010  (approximately Rs 10 lakh at 2010 exchange rates) from Google to do so.  The hub is an online forum to track free speech violation and highlight  problems surrounding freedom of speech and expression and regulation of  media.&lt;/p&gt;
&lt;p&gt;The commitment was renewed in February 2012 with ano­ther grant  of Rs 42 lakh. Ninan says that while Goo­gle was “not interested in  media ethics but free speech”, its app­roach was entirely “hands-off” to  what the site could include on the hub. “I think it’s entirely up to  the org­anisation being funded to decide how it handles a grant. At the  same time, anything Google does should be under scrutiny just like other  corporations.”&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/home-images/Anja.png" alt="Anja Kovacs" class="image-inline" title="Anja Kovacs" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;“More transparency&lt;br /&gt;and accountability&lt;br /&gt;can only be good,&lt;br /&gt;both for Google and for the organisation&lt;br /&gt;it funds.”&lt;br /&gt;&lt;/b&gt;Anja Kovacs, Internet Democracy Project&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;So just as it is necessary to publicise that Shell has ties with the India  chapter of Brookings Institution or that Reliance sponsors the Observer  Resea­rch Foundation, it is important that people know where Google is  putting its money and for what gains. In fact, more so in the case of  Google, a firm that touches our lives in so many more ways that Shell or  Reliance does. Yet, a lot of what Google has been doing has gone  without adequate publicity and scrutiny. Should we be any less sceptical  of Google funding resea­rch that helps formulate policies on internet  governance than we should be of, let’s say, the Tatas and Jindals on  mining? “Google has huge money and its funding of research can be a very  contentious issue, especially if it seeks to influence resea­rch.  Therefore, parties who swear by full disclosure and transparency must  adhere to it,” says senior journalist Paranjoy Guha Thakurta. “More  transpare­ncy and accountability can only be good, both for Google and  the organisations it funds,” adds Anja Kovacs, who works with the  Internet Democracy Project.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/narendramodi.png" alt="Narendra Modi" class="image-inline" title="Narendra Modi" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;span class="fsppicturecaption"&gt;&lt;b&gt;The great connector&lt;/b&gt; Hangout with Narendra Modi&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;But there has been little of that transparency online. For instance, the  Rules and Regulations Review of The Infor­mation Technology Rules, 2011,  put out and sent to MPs by PRS Legislative Research has no mention that  an interested party (Google) has funded its work. Similarly, The Hoot  has no mention of Google funding it on the ‘About the Hub’ page even  though it has details of Google’s funding on the ‘Support The Hoot’  page. Google has also funded numerous ngos, in areas such as health and  education, and has sought to promote the use of technology (often  theirs, such as in the ongoing Google Impact Challenge Award).&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/home-images/sunil.png" alt="sunil" class="image-inline" title="sunil" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;“Because there is &lt;br /&gt;no privacy &lt;br /&gt;commissioner, &lt;br /&gt;Indian citizens are &lt;br /&gt;left vulnerable to &lt;br /&gt;Google when it comes to &lt;br /&gt;privacy.”&lt;/b&gt;&lt;br /&gt;Sunil Abraham, CIS, Bangalore&lt;/p&gt;
&lt;/td&gt;
&lt;td style="text-align: justify; "&gt;
&lt;p&gt;This offline influence apart, Google’s hold online is worrying enough to  call for action. The way it manipulates search results to favour  clients of its AdSense programme is a global concern. For instance, a  search for a popular phone model throws up matches of Google’s clients  and features them more prominently than the actual site of the product.  The Jaipur-based Consumer Unity and Trust Society (CUTS) conducted a  survey that found most internet users could not tell an ad from an  organic search result from Google. Says Madhav Dar, an independent  anti-trust economist, “Given its financial clout and dominance of  e-commerce, Google can directly deny traffic to downstream sites. And  because the internet ecosystem is still in a formative stage here, this  is something that requires intense and urgent scrutiny by the  Competition Commission of India (CCI).”&lt;/p&gt;
&lt;p&gt;CUTS filed a formal complaint with the CCI in June last year alleging  anti-competitive practices and abuse of its dominant position.  Bharat­Matrimony.com too filed a complaint with the CCI in 2012 accusing  it of directing online users’ search for “Bharat+Matrimony” to its  rivals.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;For many, Google crossed the creepy line when it declared, in a court  filing in August this year, that people sending e-mails to any of  Google’s 425 million Gmail users need have no “reasonable expectation”  that their communications are confidential. This is something that  concerns Sunil Abraham, the executive director of CIS, which hosts  Google fellows but has received no funding from the firm. “India has no  omnibus horizontal statutes, neither sufficiently evolved vertical  statutes in specific areas of telecommunication or the internet,” he  says. “And because of that there is no office of the privacy  commissioner in India and the absence of this regulator doesn’t tame the  voracious appetite that Google has for personal information. This  happens in other jurisdictions, but the Indian citizen is left  vulnerable to Google when it comes to privacy.” “Part of Google’s  practice can be absolutely abhorrent, such as the way in which it seeks  to have a monopoly in digitising information and being the only one to  organise it,” adds Kovacs.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/amitabh.png" alt="Amitabh" class="image-inline" title="Amitabh" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Amitabh Bachchan Google maps his home at WEF in Davos&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;Another controversial move online has been the decision between Airtel and Google to allow the former’s subscribers free usage of Google’s service up to 1 GB. This has thrown up concerns of violation of “network neutrality”, a widely acknowledged concept that requires internet service providers to not discriminate against third party applications and service.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;
&lt;p&gt;Journalist and blogger Shivam Vij, however, thinks concerns surrounding Google’s offline activities are misplaced. “As long as they keep coming out with transparency reports that show the majority of requests for user data and content removal are refused, I’d consider them an ally. One should be grateful that Google is funding to protect free speech and ashamed that Indian firms aren’t,” he says. “And if they really have been trying to influence MPs, they would have bribed them, not put out research.”&lt;/p&gt;
&lt;p&gt;Nikhil Pahwa, who runs Medianama, a digital media news and analysis website, is another person who says “he won’t look a gift horse in the mouth”. “I don’t know what the motives are, but I support what they are doing, especially given the way the state and Indian firms are failing us when it comes to protecting free speech online,” he adds. The only concern he has about Google is regarding its reported unwillingness to agree to a deal between the Advertising Agencies Association of India (AAAI) and the Internet and Mobile Association of India (IAMAI). The deal seeks to ensure smaller online publishers and advertising networks are paid on time by advertisers, who, in most cases, delay payments to smaller entities but always pay bigger players like Google on time. “Smaller players are suffering due to delay in payments, which can extend up to a year, a problem that Google does not face. The IAMAI initiative is something that Google is unwilling to support because it does not impact them,” he adds.&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/home-images/SevantiNinan.png" alt="Sevanti Ninan" class="image-inline" title="Sevanti Ninan" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;"Anything that &lt;br /&gt;Google does should &lt;br /&gt;be under scrutiny &lt;br /&gt;just like other corporations."&lt;/b&gt;&lt;br /&gt;Sevanti Ninan, Editor, The Hoot&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/ChandniChowk.png" alt="Chandni Chowk" class="image-inline" title="Chandni Chowk" /&gt;&lt;/th&gt;&lt;th&gt;&lt;img src="https://cis-india.org/home-images/Qutub.png" alt="Qutub" class="image-inline" title="Qutub" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;&lt;span class="fsppicturecaption"&gt;&lt;b&gt;The outreach&lt;/b&gt; Sibal attends the launch of chandnichowkonline, a business directory of his constituency; Qutub Minar, digitised&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;Criticising or questioning some of Google’s policies does not amount to  siding with the government on cracking down on free speech on the  internet. &lt;a href="http://images.outlookindia.com/images/coverpics/outlookindia/large/big_cover_20111219.jpg" target="_blank"&gt;&lt;i&gt;Outlook&lt;/i&gt; ran a cover in December 2011&lt;/a&gt; where it was severely critical of the government’s atte­mpt to muzzle  online dissent. Neither does concern about Google’s activities stem from  a fear of the foreign hand. Its expansion into Indian civil society has  to be seen as an attempt by a profits-driven corporation to ensure its  market interests in India are protected. The country becomes all the  more important given the trouble it has been having in Brazil and in  Europe, where the firm has been slapped with a slew of anti-trust  charges. Keeping a close watch will only help enforce Google’s policy in  India—not crossing the creepy line.&lt;/p&gt;
&lt;ul&gt;
&lt;/ul&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/outlookindia-october-28-2013-debarshi-dasgupta-beyond-the-searchlight'&gt;https://cis-india.org/news/outlookindia-october-28-2013-debarshi-dasgupta-beyond-the-searchlight&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-23T11:15:27Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/livemint-moulishree-srivastava-october-22-2013-bali-meet-to-discuss-internet-governance-issues">
    <title>Bali meet to discuss Internet governance issues</title>
    <link>https://cis-india.org/news/livemint-moulishree-srivastava-october-22-2013-bali-meet-to-discuss-internet-governance-issues</link>
    <description>
        &lt;b&gt;Four-day event hosted by Internet Governance Forum to also discuss Internet access and diversity, privacy, security.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;This article by Moulishree Srivastava was &lt;a class="external-link" href="http://www.livemint.com/Politics/nSMWfhzTld5AHD3lJFrv3L/Bali-meet-to-discuss-Internet-governance-issues.html"&gt;published in Livemint&lt;/a&gt; on October 22, 2013. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Representatives of governments around the world,  technology executives and activists will discuss issues such as Internet  access and diversity, privacy, security, inter-governmental  corporation, and Internet governance at a four-day event hosted by the  Internet Governance Forum (IGF) that begins on Tuesday in Bali,  Indonesia.&lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/J.%20Satyanarayana"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/J.%20Satyanarayana"&gt;J. Satyanarayana&lt;/a&gt;&lt;/span&gt;,  secretary, ministry of communications and information technology,  confirmed India’s participation in the forum and said the country would  be represented by Dr Govind, a senior director and head of department,  e-infrastructure and Internet governance division, department of  information technology.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“We  will also be taking part in a working group on Internet governance and  enhanced cooperation, which will be convened by the United Nations  Commission on Science and Technology for Development in November,” said  Satyanarayana.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“IGF  is a valuable learning forum wherein different stakeholders can discuss  Internet governance policy issues without any antagonism. Other fora for  Internet policy like ICANN, WIPO (World Intellectual Property  Organization), ITU (International Telecommunication Union), etc., are  places where international law and policy are developed, and do not  allow for such learning because negotiations are always very  acrimonious. Since IGF is only meant for learning, it does not directly  address the global policy vacuum that exists for cyber crime, data  protection and privacy,” said &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Sunil%20Abraham"&gt;Sunil Abraham&lt;/a&gt;&lt;/span&gt;, executive director of Bangalore-based Centre for Internet and Society, who will be participating in the Bali event.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Indian  government, private sector, civil society, technical and academic  community can become more competent and effective through such a  dialogue in other multilateral and multi-stakeholder fora where  international Internet standards, policies and laws are formulated. It  also helps the stakeholders contribute to the development of  internationally interoperable domestic policy,” he added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In  2006, the UN secretary general established a small secretariat in Geneva  to assist him in the convening of IGF. The first meeting was convened  in October-November 2006 in Athens. In December 2010, IGF’s mandate was  extended for five years.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In its  eighth edition, IGF will have detailed discussions on issues such as  free flow of information on the Internet, regulatory approaches to  privacy, and protection of interests of individuals and communities in  cyberspace, Internet surveillance and legal framework for cyber crime,  said the forum in a statement on its website.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;During  the four-event, for instance, one of the workshops “will explore what  core principles and strategies are needed to achieve a balanced and fair  approach to data protection that is effective internationally and  regionally”, according to IGF.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Some of the prominent speakers in the event include &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Jari%20Arkko"&gt;Jari Arkko&lt;/a&gt;&lt;/span&gt;, chairman, Internet Engineering Task Force, Finland; &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Virat%20Bhatia"&gt;Virat Bhatia&lt;/a&gt;&lt;/span&gt;, president, South Asia, &lt;span class="company"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/AT&amp;amp;T%20Inc."&gt;AT&amp;amp;T Inc.&lt;/a&gt;&lt;/span&gt;; &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Chris%20Painter"&gt;Chris Painter&lt;/a&gt;&lt;/span&gt;, coordinator for cyber issues, US department of state; &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Karen%20Mulberry"&gt;Karen Mulberry&lt;/a&gt;&lt;/span&gt;, policy adviser, Internet Society; and &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Matthew%20Shears"&gt;Matthew Shears&lt;/a&gt;&lt;/span&gt;, director of Internet policy and human rights, Center for Democracy and Technology.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According  to industry estimates, over 2.5 billion Internet users interact in  shared cross-border online spaces where they can post content  potentially accessible worldwide.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“No  clear frameworks exist yet to handle the tensions between these  competing normative orders or values and enable peaceful cohabitation in  cross-border cyberspace. This challenge constitutes a rare issue of  common concern for all stakeholder groups,” said IGF on its website.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According  to a UN estimate, nearly 40% of the world’s population will be online  by the end of 2013. “The Internet has become an essential tool for the  creation of jobs and the delivery of basic public services,” said the UN  undersecretary-general for economic and social affairs, &lt;span class="person"&gt;&lt;a href="http://www.livemint.com/Search/Link/Keyword/Wu%20Hungbo"&gt;Wu Hungbo&lt;/a&gt;&lt;/span&gt;,  in a statement, adding that it is also essential “for improving access  to knowledge and education, for empowering women, for enhancing  transparency, and for giving marginalized populations a voice in  decision-making processes”.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/livemint-moulishree-srivastava-october-22-2013-bali-meet-to-discuss-internet-governance-issues'&gt;https://cis-india.org/news/livemint-moulishree-srivastava-october-22-2013-bali-meet-to-discuss-internet-governance-issues&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-10-23T08:29:23Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
