<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 2891 to 2905.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/aadhaar-act-and-its-non-compliance-with-data-protection-law-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-april-13-2016-why-is-uidai-cracking-down-on-individuals-that-hoard-aadhaar-data"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-last-chance-for-a-welfare-state-doesnt-rest-in-the-aadhaar-system"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/privacy/surveillance-technologies"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/interview-with-finnish-data-protection-ombudsman"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-hoot-july-13-2013-chinmayi-arun-parsing-the-cyber-security-policy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/down-to-earth-july-17-2013-nishant-shah-you-have-the-right-to-remain-silent"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/firstpost-pierre-fitter-july-17-2013-snooping-technology"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/data-protection-experts-slam-state-for-sending-mass-smses"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/livemint-december-27-2012-surabhi-agarwal-un-agrees-to-review-agencies-governing-internet"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/cyber-regulations-advisory-committee-no-civil-society"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/smart-cities-in-india-an-overview"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-anita-babu-december-23-2015-start-up-india-turns-the-heat-on-facebook-free-basics"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/telecom/blog/millions-of-indians-slam-facebooks-2018free-basics2019-app"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/eight-key-privacy-events-in-india-in-the-year-2015"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/blog/aadhaar-act-and-its-non-compliance-with-data-protection-law-in-india">
    <title>Aadhaar Act and its Non-compliance with Data Protection Law in India</title>
    <link>https://cis-india.org/internet-governance/blog/aadhaar-act-and-its-non-compliance-with-data-protection-law-in-india</link>
    <description>
        &lt;b&gt;This post compares the provisions of the Aadhaar Act, 2016, with India's data protection regime as articulated in the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;Download the file: &lt;a href="https://cis-india.org/internet-governance/blog/aadhaar-act-43a-it-rules" class="internal-link"&gt;PDF&lt;/a&gt;.&lt;/h4&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify;"&gt;Amidst all the hue and cry, the Aadhaar Act 2016, which was introduced with the aim of providing statutory backing to the use of Aadhaar, was passed in the Lok Sabha in its original form on March 16, 2016, after rejecting the recommendations made by Rajya Sabha &lt;a name="_ftnref1"&gt;&lt;/a&gt; . Though the Act has been vehemently opposed on several grounds, one of the concerns that has been voiced is regarding privacy and protection of the 	demographic and biometric information collected for the purpose of issuing the Aadhaar number.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;In India, for the purpose of data protection, a body corporate is subject to section 43A of the Information Technology Act, 2000 ("&lt;strong&gt;IT Act&lt;/strong&gt; ") and subsequent Rules, i.e. -The Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 	2011 ("&lt;strong&gt;IT Rules&lt;/strong&gt;"). Section 43A of the IT Act, 2000 &lt;a name="_ftnref2"&gt;&lt;/a&gt; holds a body corporate, which is possessing, dealing or handling any sensitive personal data or information, and is negligent in implementing and maintaining reasonable security practices resulting in wrongful loss or wrongful gain to any person, liable to compensate the affected person and pay damages.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Rule 3 of the IT Rules enlists personal information that would amount to Sensitive personal data or information of a person and includes the biometric information. Even the Aadhaar Act states under section 30 that the biometric information collected shall be deemed as "sensitive personal data or information", which shall have the same meaning as assigned to it in clause (iii) of the Explanation to section 43A of the IT Act; this reflects that biometric data collected in the Aadhaar scheme will receive the same level of protection as is provided to other sensitive personal data under Indian law. This implies that, the agencies contracted by the UIDAI (and not the UIDAI itself) to perform functions like collection, authentication, etc. like the 	Registrars, Enrolling Agencies and Requesting Entities, which meet the criteria of being a 'body corporate' as defined in section 43A, &lt;a name="_ftnref3"&gt;&lt;/a&gt; could be held responsible under this provision, as well as the Rules, to ensure security of the data and information of Aadhaar holder and could potentially be held liable for breach of information that results in loss to an individual if it can be proven that they failed to implement reasonable 	security practices and procedures.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;In light of the fact that some actors in the Aadhaar scheme could be held accountable and liable under section 43A and associated Rules, this article compares the regulations regarding data security as found in section 43A and IT Rules 2011 with the provisions of Aadhaar Act 2016, and discusses the 	implications of the differences, if any.&lt;/p&gt;
&lt;h3&gt;1. Compensation and Penalty&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Section 43A:&lt;/strong&gt; Section 43A of the IT Act, 2000 (Amended in 2008) provides for compensation for failure to protect data. It states that a body corporate, which is 	possessing, dealing or handling any sensitive personal data or information, and is negligent in implementing and maintaining reasonable security practices 	resulting in wrongful loss or wrongful gain to any person, is liable to compensate the affected person and pay damages not exceeding five crore rupees.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar&lt;/strong&gt; &lt;strong&gt;Act :&lt;/strong&gt; Chapter VII of the Act provides for offences and penalties, but does not talk about damages to the affected party.&lt;/p&gt;
&lt;ul style="text-align: justify;"&gt;
&lt;li&gt;Section 37 states that intentional disclosure or dissemination of identity information, to any person not authorised under the Aadhaar Act, or in violation of any agreement entered into under the Act, will be punishable with imprisonment up to three years or a fine up to ten thousand rupees (in case of an individual), and fine up to one lakh rupees (in case of a company). &lt;/li&gt;
&lt;li&gt;Section 38 prescribes penalty with imprisonment up to three years and a fine not less than ten lakh rupees in case any of the acts listed under the provision are performed without authorisation from the UIDAI. &lt;/li&gt;
&lt;li&gt;Section 39 prescribes penalty with imprisonment for a term which may extend to three years and fine which may extend to ten thousand rupees for tampering with data in Central Identities Data Repository. &lt;/li&gt;
&lt;li&gt;Section 40 holds a requesting entity liable for penalty for use of identity information in violation of Section 8 (3) with imprisonment up to three years and/or a fine up to ten thousand rupees (in case of an individual), and fine up to one lakh rupees (in case of a company). &lt;/li&gt;
&lt;li&gt;Section 41 holds a requesting entity or enrolling agency liable for penalty for violation of Section 8 (3) or Section 3 (2) with imprisonment up to one year and/or a fine up to ten thousand rupees (in case of an individual), and fine up to one lakh rupees (in case of a company). &lt;/li&gt;
&lt;li&gt;Section 42 provides general penalty for any offence against the Act or regulations made under it, for which no specific penalty is provided, with imprisonment up to one year and/or a fine up to twenty five thousand rupees (in case of an individual), and fine up to one lakh rupees (in case of a company). &lt;/li&gt;&lt;/ul&gt;
&lt;p style="text-align: justify;"&gt;Though the Aadhaar Act prescribes penalty in case of unauthorised access, use or any other act contravening the Regulations, it fails to guarantee protection to the information and does not provide for compensation in case of violation of the provisions.&lt;/p&gt;
&lt;h3&gt;2. Privacy Policy&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 4 requires a body corporate to provide a privacy policy on their website, which is easily accessible, provides for the type and purpose of 	personal, sensitive personal information collected and used, and Reasonable security practices and procedures.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; Though in practise the contracting agencies (the body corporates under the Aadhaar ecosystem) may maintain a privacy policy on their website, 	the Aadhaar Act does not require a privacy policy for the UIDAI or other actors.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Implications:&lt;/strong&gt; Because contracting agencies will be covered by the IT Rules if they are 'body corporates', the requirement to maintain a privacy policy will be applicable to them.&lt;/p&gt;
&lt;h3&gt;3. Consent&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 5 requires that prior to the collection of sensitive personal data, the body corporate must obtain consent, either in writing or through fax regarding 	the purpose of usage before collection of such information.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act: &lt;/strong&gt; The Act is silent regarding consent being acquired in case of the enrolling agency or registrars. However, section 8 provides that any requesting entity 	will take consent from the individual before collecting his/her Aadhaar information for authentication purposes, though it does not specify the nature (written/through fax).&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Implications:&lt;/strong&gt; If the enrolling agency is a body corporate, they will also be required to take consent prior to collecting and processing biometrics. It is possible that since the Aadhaar Act envisages a scheme which is quasi-compulsory in nature, a consent provision was deliberately left out. This 	circumstance would give the enrolling agencies an argument against taking consent, by saying that the Aadhaar Act is a specific legislation which is also later in point of time than the IT Rules, and a deliberate omission of consent coupled with the compulsory nature of the Aadhaar scheme would mean that they are not required to take consent of the individuals before enrolment.&lt;/p&gt;
&lt;h3&gt;4. Collection Limitation&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules: &lt;/strong&gt; Rule 5 (2) requires that a body corporate should only collect sensitive personal data if it is connected to a lawful purpose and is considered necessary for that purpose.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; Section 3(1) of the Act states that every resident shall be entitled to obtain an aadhaar number by submitting his demographic information and biometric 	information by undergoing the process of enrolment.&lt;/p&gt;
&lt;h3&gt;5. Notice&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules: &lt;/strong&gt; Rule 5(3) requires that while collecting information directly from an individual, the body corporate must provide the following information:&lt;/p&gt;
&lt;ul style="text-align: justify;"&gt;
&lt;li&gt;The fact that information is being collected&lt;/li&gt;
&lt;li&gt;The purpose for which the information is being collected&lt;/li&gt;
&lt;li&gt;The intended recipients of the information&lt;/li&gt;
&lt;li&gt;The name and address of the agency that is collecting the information&lt;/li&gt;
&lt;li&gt;The name and address of the agency that will retain the information&lt;/li&gt;&lt;/ul&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; Section 3 of the Act states that at the time of enrolment and collection of information, the enrolling agency shall notify the individual as to how their 	information will be used; what type of entities the information will be shared with; and that they have a right to see their information and also tell them 	how they can see their information. However, the Act is silent regarding notice of name and address of the agency collecting and retaining the information.&lt;/p&gt;
&lt;h3&gt;6. Retention Limitation&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 5(4) requires that body corporate must retain sensitive personal data only for as long as it takes to fulfil the stated purpose or otherwise required 	under law.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; The Act is silent regarding this and does not mention the duration for which the personal information of an individual shall be retained by the 	bodies/organisations contracted by UIDAI.&lt;/p&gt;
&lt;h3&gt;7. Purpose Limitation&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 5(5) requires that information must be used for the purpose that it was collected for.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act&lt;a name="move447203643"&gt;&lt;/a&gt;&lt;/strong&gt; Section 57 contravenes this and states that the Act will not prevent use of Aadhaar number for other purposes under law by the State or other bodies. 	Section 8 of the Act states that for the purpose of authentication, a requesting entity is required to take consent before collection of Aadhaar 	information and use it only for authentication with the CIDR. Section 29 of the Act states that the core biometric information collected will not be shared 	with anyone for any reason, and must not be used for any purpose other than generation of Aadhaar numbers and authentication. Also, the Identity information available with a requesting entity will not be used for any purpose other than what is specified to the individual, nor will it be shared 	further without the individual's consent.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;a name="move4472036436"&gt;&lt;/a&gt; Act will not prevent use of Aadhaar number for other purposes under law by the State or other bodies.&lt;/p&gt;
&lt;h3&gt;8. Right to Access and Correct&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules :&lt;/strong&gt; Rule 5(6) requires a body corporate to provide individuals with the ability to review the information they have provided and access and correct their 	personal or sensitive personal information.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act :&lt;/strong&gt; The Act provides under section 3 that at the time of enrolment, the individual needs to be informed about the existence of a right to access information, the procedure for making requests for such access, and details of the person or department in-charge to whom such requests can be made. Section 28 of the Act provides that every aadhaar number holder may access his identity information except core biometric information. Section 32 provides that every Aadhaar number holder may obtain his authentication record. Also, if the demographic or biometric information about any Aadhaar number holder changes, is lost or is found to be incorrect, they may request the UIDAI to make changes to their record in the CIDR.&lt;/p&gt;
&lt;h3&gt;9. Right to 'Opt Out' and Withdraw Consent&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 5(7) requires that the individual must be provided with the option of 'opting out' of providing data or information sought by the body corporate. 	Also, they must have the right to withdraw consent at any point of time.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; The Aadhaar Act does not provide an opt- out provision and also does not provide an option to withdraw consent at any point of time. Section 7 of the 	Aadhaar Act actually implies that once the Central or State government makes aadhaar authentication mandatory for receiving a benefit then the individual has no other option but to apply for an Aadhaar number. The only concession that is made is that if an Aadhaar number is not assigned to an individual then s/he would be offered some alternative viable means of identification for receiving the benefit.&lt;/p&gt;
&lt;h3&gt;10. Grievance Officer&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 5(9) requires that body corporate must designate a grievance officer for redressal of grievances, details of which must be posted on the body corporate's website and grievances must be addressed within a month of receipt.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act&lt;/strong&gt;: The Aadhaar Act does not provide for any such mechanism for grievance redressal by the registrars, enrolling agencies or the requesting entities. However, since the contracting agencies will also get covered by the IT Rules if they are 'body corporates', the requirement to designate a 	grievance officer would be applicable to them as well due to the IT Rules.&lt;/p&gt;
&lt;h3&gt;11. Disclosure with Consent, Prohibition on Publishing and Further Disclosure&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 6 requires that body corporate must have consent before disclosing sensitive personal data to any third person or party, except in the case with Government agencies for the purpose of verification of identity, prevention, detection, investigation, on receipt of a written request. Also, the body corporate or any person on its behalf shall not publish the sensitive personal information and the third party receiving the sensitive personal information from body corporate or any person on its behalf shall not disclose it further.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; Regarding the requesting entities, the Act provides that they shall not disclose the identity information except with the prior consent of the individual 	to whom the information relates. The Act also states that the Authority shall take necessary measures to ensure confidentiality of information against 	disclosures. However, as an exception under section 33, the UIDAI may reveal identity information, authentication records or any information in the CIDR following a court order by a District Judge or higher. The Act also allows disclosure made in the interest of national security following directions by a 	Joint Secretary to the Government of India, or an officer of a higher rank, authorised for this purpose. The Act is silent on the issue of obtaining consent of the individual under these exceptions. Additionally, the Act also states that the Aadhaar number or any core biometric information collected or 	created regarding an individual under the Act shall not be published, displayed or posted publicly, except for the purposes specified by regulations.&lt;/p&gt;
&lt;h3&gt;12. Requirements for Transfer of Sensitive Personal Data&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules :&lt;/strong&gt; Rule 7 requires that body corporate may transfer sensitive personal data into another jurisdiction only if the country ensures the same level of protection and may be allowed only if it is necessary for the performance of the lawful contract between the body corporate or any person on its behalf and provider 	of information or where such person has consented to data transfer.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act :&lt;/strong&gt; The Act is silent regarding transfer of personal data into another jurisdiction by the any of the contracting bodies like the Registrar, Enrolling agencies or the requesting entities. However, if these agencies satisfy the requirement of being "body corporates" as defined under section 43A, then the above 	requirement regarding transfer of data to another jurisdiction under IT Rules would be applicable to them. However, considering the sensitive nature of the data involved, the lack of a prohibition of transferring data to another jurisdiction under the Aadhaar Act appears to be a serious lacuna.&lt;/p&gt;
&lt;h3&gt;13. Security of Information&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;IT Rules:&lt;/strong&gt; Rule 8 requires that the body corporate must secure information in accordance with the ISO 27001 standard or any other best practices notified by Central 	Government. These practices must be audited annually or when the body corporate undertakes a significant up gradation of its process and computer resource.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Aadhaar Act:&lt;/strong&gt; Section 28 of the Act states that the UIDAI must ensure the security and confidentiality of identity information and authentication records. It also states 	that the Authority shall adopt and implement appropriate technical and organisational security measures, and ensure the same are imposed through agreements/arrangements with its agents, consultants, advisors or other persons. However, it does not mention which standards/measures have to be adopted by all the actors in Aadhaar ecosystem for ensuring the security of information, though it can be argued that if the contractors employed by the UIDAI are body corporate then the standards prescribed under the IT Rules would be applicable to them.&lt;/p&gt;
&lt;h3&gt;Implications of the Differences for Body Corporates in Aadhaar Ecosystem&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;An analysis of the Rules in comparison to the data protection measures under the Aadhaar Act shows that the requirements regarding protection of personal or sensitive personal information differ and are not completely in line with each other. &lt;a name="move446519928"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Though the Aadhaar Act takes into account the provisions regarding consent of the individual, notice, restriction on sharing, etc., the Act is silent regarding many core measures like sharing of information across jurisdictions, taking consent before collection of information, adoption of security 	measures for protection of information, etc. which a body corporate in the Aadhaar ecosystem must adopt to be in compliance with section 43A of the IT Act. It is therefore important that the bodies collecting, handling, sharing the personal information and are governed by the Aadhaar Act, must adhere to section 43A and the IT Rules 2011. However, applicability of Aadhaar Act as well as section 43A and IT Rules 2011 would lead to ambiguity regarding interpretation and implementation of the Law. The differences must be duly taken into account and more clarity is required to make all the bodies under 	this Legislation like the enrolling agencies, Registrars and the Requesting Entities accountable under the correct provisions of Law. However, having two separate legislations governing the data protection standards in the Aadhaar scheme seems to have been overlooked. A harmonized and overarching privacy legislation is critical to avoid unclarity in the applicability of data protection standards and would also address many privacy concerns associated to the scheme.&lt;/p&gt;
&lt;h3&gt;Appendix I&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;The Rajya Sabha had proposed five amendments to the Aadhaar Act 2016, which are as follows:&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;i. Opt-out clause:&lt;/strong&gt; A provision to allow a person to "opt out" of the Aadhaar system, even if already enrolled.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;ii. Voluntary:&lt;/strong&gt; To ensure that if a person chooses not to be part of the Aadhaar system, he/she would be provided "alternate and viable" means of identification for purposes of delivery of government subsidy, benefit or service.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;iii.&lt;/strong&gt; Amendment restricting the use of Aadhaar numbers only for targeting of government benefits or service and not for any other purpose.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;iv.&lt;/strong&gt; Amendment seeking change of the term "national security" to "public emergency or in the interest of public safety" in the provision specifying situations in which disclosure of identity information of an individual to certain law enforcement agencies can be allowed.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;v. Oversight Committee:&lt;/strong&gt; The oversight committee , which would oversee the possible disclosure of information, should include either the Central Vigilance Commissioner or the Comptroller and Auditor-General.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt; &lt;a href="http://indianexpress.com/article/india/india-news-india/rajya-sabha-returns-aadhar-bill-to-lok-sabha-with-oppn-amendments/"&gt; http://indianexpress.com/article/india/india-news-india/rajya-sabha-returns-aadhar-act-to-lok-sabha-with-oppn-amendments/ &lt;/a&gt; &lt;/li&gt;
&lt;li&gt; &lt;a href="http://thewire.in/2016/03/16/three-rajya-sabha-amendments-that-will-shape-the-aadhaar-debate-24993/"&gt; http://thewire.in/2016/03/16/three-rajya-sabha-amendments-that-will-shape-the-aadhaar-debate-24993/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;h3&gt;Appendix II - Section 43A: Compensation for Failure to Protect Data&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;Where a body corporate, possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates, is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;For the purposes of this section:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;"body corporate" means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities;&lt;/li&gt;
&lt;li&gt;"reasonable security practices and procedures" means security practices and procedures designed to protect such information from unauthorised access, damage, use, modification, disclosure or impairment, as may be specified in an agreement between the parties or as may be specified in any law for the time being in force and in the absence of such agreement or any law, such reasonable security practices and procedures, as may be prescribed by the Central Government in consultation with such professional bodies or associations as it may deem fit;&lt;/li&gt;
&lt;li&gt;"sensitive personal data or information" means such personal information as may be prescribed by the Central Government in consultation with such professional bodies or associations as it may deem fit.'.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p style="text-align: justify;"&gt;The term 'body corporate' has been defined under section 43A as "any company and includes a firm, sole proprietorship or other association of individuals &lt;em&gt;engaged in commercial or professional activities&lt;/em&gt;"&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/aadhaar-act-and-its-non-compliance-with-data-protection-law-in-india'&gt;https://cis-india.org/internet-governance/blog/aadhaar-act-and-its-non-compliance-with-data-protection-law-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>vanya</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>UID</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Digital India</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Biometrics</dc:subject>
    

   <dc:date>2016-04-18T11:43:02Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-april-13-2016-why-is-uidai-cracking-down-on-individuals-that-hoard-aadhaar-data">
    <title>Why is the UIDAI cracking down on individuals that hoard Aadhaar data?</title>
    <link>https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-april-13-2016-why-is-uidai-cracking-down-on-individuals-that-hoard-aadhaar-data</link>
    <description>
        &lt;b&gt;Private firms' offer to print Aadhaar details on plastic card a breach of law.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Alnoor Peermohamed was published by &lt;a class="external-link" href="http://www.business-standard.com/article/economy-policy/why-is-the-uidai-cracking-down-on-individuals-that-hoard-aadhaar-data-116041200400_1.html"&gt;Business Standard &lt;/a&gt;on April 13, 2016. Sunil Abraham was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The billion-strong citizen identification system, Aadhaar, has given rise to businesses keen on illegal harnessing of this private data, say the authorities.&lt;br /&gt;&lt;br /&gt; Outfits are offering services to print the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;&lt;span&gt;Aadhaar &lt;/span&gt;&lt;/a&gt;details on plastic cards, something the Union information technology ministry warned against on Monday. These entities charge anywhere between Rs 50 and Rs 600, and are listed on e-commerce websites, apart from own online presence.&lt;br /&gt;&lt;br /&gt; Under the Aadhaar law, collecting and storing of the data by private companies without the user’s consent is a crime. Monday’s warning from the ministry to e-commerce marketplaces such as Amazon, Flipkart and eBay to disallow merchants from collecting and printing such details was a result of this.&lt;br /&gt;&lt;br /&gt; This newspaper could not find any listings of Aadhaar printing services on Flipkart but there was one on Amazon (taken down) and no less than five such listings on eBay.&lt;br /&gt;&lt;br /&gt; PrintMyAadhaar is one of the more well organised outfits operating in this space. “Get your E-Aadhaar printed on a PVC card for easier handling,” reads their website. Users are prompted to fill their Aadhaar details on the website, pay Rs 50 and have the card sent to their houses. PrintMyAadhaar even offers discounts for bulk orders.&lt;br /&gt;&lt;br /&gt; “Collecting such information or unauthorised printing of an Aadhaar card or aiding such persons in any manner may amount to a criminal offence, punishable with imprisonment under the Indian Penal Code and also Chapter VI of  The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016,” read the statement from the ministry.&lt;br /&gt;&lt;br /&gt; Currently, Aadhaar stores a person’s name, date of birth, sex and address, apart from their biometric data.&lt;br /&gt;&lt;br /&gt; While the biometric data isn’t available to these PDF printing shops, the rest of the information is, according to Srikanth Nadhamuni, chief executive officer of Khosla Labs and a former head of technology at the Unique Identification Authority of India. However, collecting this data poses no security risk to the Aadhaar infrastructure, he added.&lt;br /&gt;&lt;br /&gt; “Allowing somebody to accumulate large amounts of data from Aadhaar users in general is not a good practice. We should ensure that the Aadhaar details of people remain private and it should only be up to the discretion of the end-user to share this,” said Nadhamuni.&lt;br /&gt;&lt;br /&gt; Some security experts say Aadhaar does pose a security risk, as it makes available an individual's details in the public domain. Several institutions are treating Aadhaar just like any other proof of identity.&lt;br /&gt;&lt;br /&gt; “Transactions that should have been conducted using biometric authentication are being conducted just by presentation of paper documents. What is happening most commonly is that people are giving a printout or photocopy of their Aadhaar acknowledgement as their proof of identity to get a SIM card. The risk here is that somebody can get a mobile number against your name,” said Sunil Abraham, executive director of the non-profit Centre for Internet and Society.&lt;br /&gt;&lt;br /&gt; He says the other technical issue with Aadhaar is the lack of a smart card that stores a person’s information, as in a digital signature. Due to the lack of this, people don’t know what information to keep private and what to make public. Conventional security techniques would have had a person keeping their PIN private (as with a bank account). If this personal PIN would have been saved on a smart card, which users wouldn’t have had much to worry about.&lt;br /&gt;&lt;br /&gt; “In the case of Aadhaar, the authentication factor and the identification factor are in the public domain, because many people might have your UID number and people release their biometric data everywhere. Due to this broken technological solution, we are now through policy putting band-aids, saying people should not disclose their UID number unnecessarily,” added Abraham.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-april-13-2016-why-is-uidai-cracking-down-on-individuals-that-hoard-aadhaar-data'&gt;https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-april-13-2016-why-is-uidai-cracking-down-on-individuals-that-hoard-aadhaar-data&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2016-04-17T16:16:26Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-last-chance-for-a-welfare-state-doesnt-rest-in-the-aadhaar-system">
    <title>The Last Chance for a Welfare State Doesn’t Rest in the Aadhaar System</title>
    <link>https://cis-india.org/internet-governance/blog/the-last-chance-for-a-welfare-state-doesnt-rest-in-the-aadhaar-system</link>
    <description>
        &lt;b&gt;Boosting welfare is the message, which is how Aadhaar is being presented in India. The Aadhaar system as a medium, however, is one that enables tracking, surveillance, and data monetisation. This piece by Sumandro Chattapadhyay was published in The Wire on April 19, 2016.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Originally published in and cross-posted from &lt;a href="http://thewire.in/2016/04/19/the-last-chance-for-a-welfare-state-doesnt-rest-in-the-aadhaar-system-30256/"&gt;The Wire&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Once upon a time, a king desired that his parrot should be taught all the ancient knowledge of the kingdom. The priests started feeding the pages of the great books to the parrot with much enthusiasm. One day, the king asked the priests if the parrot’s education has completed. The priests poked the belly of the parrot but it made no sound. Only the rustle of undigested pages inside the belly could be heard. The priests declared that the parrot is indeed a learned one now.&lt;/p&gt;
&lt;p&gt;The fate of the welfare system in our country is quite similar to this parrot from Tagore’s parable. It has been forcefully fed identification cards and other official documents (often four copies of the same) for years, and always with the same justification of making it more effective and fixing the leaks. These identification regimes are in effect killing off the welfare system. And some may say that that has been the actual plan in any case.&lt;/p&gt;
&lt;p&gt;The Aadhaar number has been recently offered as &lt;a href="http://indianexpress.com/article/opinion/columns/aadhaar-project-uidai-last-chance-for-a-welfare-state/"&gt;the ‘last chance’ for the ailing welfare system&lt;/a&gt; – a last identification regime that it needs to gulp down to survive. This argument wilfully overlooks the acute problems with the Aadhaar project.&lt;/p&gt;
&lt;p&gt;Firstly, the ‘last chance’ for a welfare state in India is not provided by implementing a new and improved identification regime (Aadhaar numbers or otherwise), but by enabling citizens to effectively track, monitor, and ensure delivery of welfare, services, and benefits. This ‘opening up’ of the welfare bureaucracy has been most effectively initiated by the Right to Information Act. Instead of a centralised biometrics-linked identity verification platform, which gives the privilege of tracking and monitoring welfare flows only to a few expert groups, an effective welfare state requires the devolution of such privilege and responsibility.&lt;/p&gt;
&lt;p&gt;We should harness the tracking capabilities of electronic financial systems to disclose how money belonging to the Consolidated Fund of India travel around state agencies and departmental levels. Instead, the Aadhaar system effectively stacks up a range of entry barriers to accessing welfare – from malfunctioning biometric scanners, to connectivity problems, to the burden of keeping one’s fingerprint digitally legible under all labouring and algorithmic circumstances.&lt;/p&gt;
&lt;p&gt;Secondly, authentication of welfare recipients by Aadhaar number neither make the welfare delivery process free of techno-bureaucratic hurdles, nor does it exorcise away corruption. Anumeha Yadav has recently documented the emerging &lt;a href="http://scroll.in/article/805909/in-rajasthan-there-is-unrest-at-the-ration-shop-because-of-error-ridden-aadhaar"&gt;‘unrest at the ration shop’ across Rajasthan&lt;/a&gt;, as authentication processes face technical and connectivity delays, people get ‘locked out’ of public services for not having or having Aadhaar number with incorrect demographic details, and no mechanisms exist to provide rapid and definitive recourse.&lt;/p&gt;
&lt;p&gt;RTI activists at the &lt;a href="http://www.snsindia.org/"&gt;Satark Nagrik Sangathan&lt;/a&gt; have highlighted that the Delhi ration shops, using Aadhaar-based authentication, maintain only two columns of data to describe people who have come to the shop – those who received their ration, and those who did not (without any indication of the reason). This leads to erasure-by-design of evidence of the number of welfare-seekers who are excluded from welfare services when the Aadhaar-based authentication process fails (for valid reasons, or otherwise).&lt;/p&gt;
&lt;p&gt;Reetika Khera has made it very clear that using Aadhaar Payments Bridge to directly transfer cash to a beneficiary’s account, in the best case scenario, &lt;a href="http://www.epw.in/journal/2013/05/commentary/cost-benefit-analysis-uid.html"&gt;may only take care of one form of corruption&lt;/a&gt;: deception (a different person claiming to be the beneficiary). But it does not address the other two common forms of public corruption: collusion (government officials approving undue benefits and creating false beneficiaries) and extortion (forceful rent seeking after the cash has been transferred to the beneficiary’s account). Evidently, going after only deception does not make much sense in an environment where collusion and extortion are commonplace.&lt;/p&gt;
&lt;p&gt;Thirdly, the ‘relevant privacy question’ for Aadhaar is not limited to how UIDAI protects the data collected by it, but expands to usage of Aadhaar numbers across the public and private sectors. The privacy problem created by the Aadhaar numbers does begin but surely not end with internal data management procedures and responsibilities of the UIDAI.&lt;/p&gt;
&lt;p&gt;On one hand, the Aadhaar Bill 2016 has reduced the personal data sharing restrictions of the NIAI Bill 2010, and &lt;a href="http://scroll.in/article/806297/no-longer-a-black-box-why-does-the-revised-aadhar-bill-allow-sharing-of-identity-information"&gt;has allowed for sharing of all data except core biometrics (fingerprints and iris scan)&lt;/a&gt; with all agencies involved in authentication of a person through her/his Aadhaar number. These agencies have been asked to seek consent from the person who is being authenticated, and to inform her/him of the ways in which the provided data (by the person, and by UIDAI) will be used by the agency. In careful wording, the Bill only asks the agencies to inform the person about “alternatives to submission of identity information to the requesting entity” (Section 8.3) but not to provide any such alternatives. This facilitates and legalises a much wider collection of personal demographic data for offering of services by public agencies “or any body corporate or person” (Section 57), which is way beyond the scope of data management practices of UIDAI.&lt;/p&gt;
&lt;p&gt;On the other hand, the Aadhaar number is being seeded to all government databases – from lists of HIV patients, of rural citizens being offered 100 days of work, of students getting scholarships meant for specific social groups, of people with a bank account. Now in some sectors, such as banking, inter-agency sharing of data about clients is strictly regulated. But we increasingly have non-financial agencies playing crucial roles in the financial sector – from mobile wallets to peer-to-peer transaction to innovative credit ratings. Seeding of Aadhaar into all government and private databases would allow for easy and direct joining up of these databases by anyone who has access to them, and not at all by security agencies only.&lt;/p&gt;
&lt;p&gt;When it becomes publicly acceptable that &lt;a href="http://indianexpress.com/article/opinion/columns/aadhaar-project-uidai-last-chance-for-a-welfare-state/"&gt;the &lt;em&gt;money bill route&lt;/em&gt; was a ‘remedial’ instrument to put the Rajya Sabha ‘back on track’&lt;/a&gt;, one cannot not wonder about what was being remedied by avoiding a public debate about the draft bill before it was presented in Lok Sabha. The answer is simple: &lt;em&gt;welfare is the message, surveillance is the medium&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Acceptance and adoption of all medium requires a message, a content. The users are interested in the message. The message, however, is not the business. Think of Free Basics. Facebook wants people with none or limited access to internet to enjoy parts of the internet at zero data cost. Facebook does not provide the content that the users consume on such internet. The content is created by the users themselves, and also provided by other companies. Facebook own and control the medium, and makes money out of all content, including interactions, passing through it.&lt;/p&gt;
&lt;p&gt;The UIDAI has set up a biometric data bank and related infrastructure to offer authentication-as-a-service. As the Bill clarifies, almost all agencies (public or private, national or global) can use this service to verify the identity of Indian residents. Unlike Facebook, the content of these services do not flow through the Aadhaar system. Nonetheless, Aadhaar keeps track of all ‘authentication records’, that is records of whose identity was authenticated by whom, when, and where. This database is gold (data) mine for security agencies in India, and elsewhere. Further, as more agencies use authentication based on Aadhaar numbers, it becomes easier for them to combine and compare databases with other agencies doing the same, by linking each line of transaction across databases using Aadhaar numbers.&lt;/p&gt;
&lt;p&gt;Welfare is the message that the Aadhaar system is riding on. The message is only useful for the medium as far as it ensures that the majority of the user population are subscribing to it. Once the users are enrolled, or on-boarded, the medium enables flow of all kinds of messages, and tracking and monetisation (perhaps not so much in the case of UIDAI) of all those flows. It does not matter if the Aadhaar system is being introduced to remedy the broken parliamentary process, or the broken welfare distribution system. What matters is that the UIDAI is establishing the infrastructure for a universal surveillance system in India, and without a formal acknowledgement and legal framework for the same.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-last-chance-for-a-welfare-state-doesnt-rest-in-the-aadhaar-system'&gt;https://cis-india.org/internet-governance/blog/the-last-chance-for-a-welfare-state-doesnt-rest-in-the-aadhaar-system&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>sumandro</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>UID</dc:subject>
    
    
        <dc:subject>Data Systems</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Digital India</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Biometrics</dc:subject>
    

   <dc:date>2016-04-19T13:18:42Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/privacy/surveillance-technologies">
    <title>Surveillance Technologies </title>
    <link>https://cis-india.org/internet-governance/blog/privacy/surveillance-technologies</link>
    <description>
        &lt;b&gt;The following post briefly looks at different surveillance technologies, and the growing use of the them in India. &lt;/b&gt;
        
&lt;h3&gt;Surveillance...&lt;/h3&gt;
&lt;p&gt;New security technologies are constantly emerging that push the edge between privacy and a reasonable level of security. Society's tolerance level is constantly being tested by governments who use surveillance and monitoring technologies to protect the nation. Governments claim that they need absolute access to citizens life. They need to monitor phones, look through emails, peer into files – in-order to maintain security and protect against terrorism. Though as a side note, in an Economic Times article published on Nov. 4&amp;nbsp;2010 it was reported that government computers were being hacked into through viruses, and top secret documents were being stolen. The irony of the story is that the viruses were introduced to the computers through porn websites visited by officials.&lt;/p&gt;
&lt;h3&gt;...In a Car? On the Street? In an Airport?&lt;/h3&gt;
&lt;p&gt;Despite the fact that governmental monitoring might make the common man uncomfortable, the reality is that governments will always win the national security vs privacy fight. The story becomes more complicated when it moves from the government directly monitoring individuals, to security agencies monitoring individuals. For instance the use of full body scanners at airports, or trucks equipped with scatter x-ray machines used to control crime in neighborhoods - is a much more heated debate. There are other ways in which to check passengers for banned items, and other ways to keep crime off the streets without mandating that individuals submit themselves to invasive scans, or scanning unaware individuals.&lt;/p&gt;
&lt;h3&gt;...In the Movie Theater????..for Marketing Purposes????&lt;/h3&gt;
&lt;p&gt;Surveillance technology has now been taken even another step further. No longer is it being just used to prevent violent crimes or terrorist attacks. Today the movie industry is using controversial anti-piracy tools to protect the films they produce. For instance the security company Aralia Systems manufacturers products such as: CCTV cameras and anti-camcorder systems that shine infrared light beams on audiences as they watch a movie. The light beams reflect off camcorders and alerts the theater that there are camcorders present. Though this practice can be seen as invasive - individuals might be opposed to being probed by light beams throughout movies, the extent of potential privacy invasion does not stop there. Aralia Systems has partnered with Machine Vision Lab and has created a system that harvests audiences emotions and movements as they watch movies. The data can then be used by market researchers to better tailor their behavioral advertising schemes. Essentially movie theater monitoring has merged surveillance technologies with behavioral marketing technologies in a twisted invasion of movie watchers personal privacy.&lt;/p&gt;
&lt;h3&gt;Is this technology in India?&lt;/h3&gt;
&lt;p&gt;Though behavioral monitoring and piracy technologies such as ones produced by Aralia Systems are not yet used in Indian movie theaters – security measures against piracy are used. Movie theaters across India are equipped with metal detectors at the door, and security personel check your handbag or back pack for camcorders. According to a Indian Express article, the organization Allegiance Against Copyright Theft believes one of the reasons monitoring technology is not yet used in theaters is because there is no present Indian legislation that penalizes recording in halls. Once legislation is passed, they speculate there will be a push to use these technologies. Even though monitoring technology is not yet used in theaters, monitoring of consumers behavior is increasing. Recently in India the WPP owned research agency IMRB International has developed an online audience measurement system that uses tailored metering technology to track the sites that users visit. The Web Audience Measurement System has launched this technology in a sample size of 21,000 Indian households, covering 90,000 individuals. IMRB has said that the meters are capable of capturing usage data from multiple computers, and that they can then use the information to market to the individual. Does it seem ironic to anyone that companies now charge for a service – movie tickets, internet services, telephone services – and make an extra profit by data mining at the expense of a persons privacy?&lt;/p&gt;
&lt;h3&gt;Sources&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;http://economictimes.indiatimes.com/news/politics/nation/Govt-depts-asked-not-to-store-sensitive-info-on-Net-connected-computers/articleshow/6874631.cms&lt;/li&gt;&lt;li&gt;http://www.research-live.com/news/technology/imrb-unveils-web-measurement-service-for-indian-market/4003941.article&lt;/li&gt;&lt;li&gt;http://blogs.computerworld.com/17276/anti_piracy_tool_will_harvest_market_your_emotions?source=rss_blogs&lt;/li&gt;&lt;li&gt;&amp;nbsp;http://www.indianexpress.com/news/antipiracy-unit-joins-hands-with-cinema-halls-to-curb-camcording/695439/2&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/privacy/surveillance-technologies'&gt;https://cis-india.org/internet-governance/blog/privacy/surveillance-technologies&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-03-22T05:40:24Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/interview-with-finnish-data-protection-ombudsman">
    <title>Interview with Mr. Reijo Aarnio - Finnish Data Protection Ombudsman</title>
    <link>https://cis-india.org/internet-governance/blog/interview-with-finnish-data-protection-ombudsman</link>
    <description>
        &lt;b&gt;Maria Xynou recently interviewed Mr. Reijo Aarnio, the Finnish Data Protection Ombudsman, at the CIS' 5th Privacy Round Table. View this interview and gain an insight on recommendations for better data protection in India! &lt;/b&gt;
        &lt;p&gt;Mr. Reijo Aarnio - the Finnish Data Protection Ombudsman - was interviewed on the following questions:&lt;/p&gt;
&lt;p&gt;1. What activities and functions does the Finnish data commissioner's office undertake?&lt;/p&gt;
&lt;p&gt;2. What powers does the Finnish Data commissioner's office have? In your opinion, are these sufficient? Which powers have been most useful? If there is a lack, what would you feel is needed?&lt;/p&gt;
&lt;p&gt;3. How is the office of the Finnish data protection commissioner funded?&lt;/p&gt;
&lt;p&gt;4. What is the organizational structure at the Office of the Finnish Data Protection Commissioner and the responsibilities of the key executives?&lt;/p&gt;
&lt;p&gt;5. If India creates a Privacy Commissioner, what structure/framework would you suggest for the office?&lt;/p&gt;
&lt;p&gt;6. What challenges has your office faced?&lt;/p&gt;
&lt;p&gt;7. What is the most common type of privacy violation that your office is faced with?&lt;/p&gt;
&lt;p&gt;8. Does your office differ from other EU data protection commissioner offices?&lt;/p&gt;
&lt;p&gt;9. How do you think data should be regulated in India?&lt;/p&gt;
&lt;p&gt;10. Do you support the idea of co-regulation or self-regulation?&lt;/p&gt;
&lt;p&gt;11. How can India protect its citizens' data when it is stored in foreign servers?&lt;/p&gt;
&lt;p&gt;&lt;iframe frameborder="0" height="250" src="http://www.youtube.com/embed/zJzWD4LWLhY" width="250"&gt;&lt;/iframe&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/interview-with-finnish-data-protection-ombudsman'&gt;https://cis-india.org/internet-governance/blog/interview-with-finnish-data-protection-ombudsman&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>maria</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-19T13:02:14Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-hoot-july-13-2013-chinmayi-arun-parsing-the-cyber-security-policy">
    <title>Parsing the Cyber Security Policy</title>
    <link>https://cis-india.org/internet-governance/blog/the-hoot-july-13-2013-chinmayi-arun-parsing-the-cyber-security-policy</link>
    <description>
        &lt;b&gt;An effective cyber-security policy must keep up with the rapid evolution of technology, and must never become obsolete. The standard-setting and review bodies will therefore need to be very nimble, says Chinmayi Arun.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Chinmayi Arun's article was published in&lt;a class="external-link" href="http://www.thehoot.org/web/Parsing-the-cyber-security-policy/6899-1-1-19-true.html"&gt; the Hoot&lt;/a&gt; on July 13, 2013 and later cross-posted in the &lt;a class="external-link" href="http://thefsiindia.wordpress.com/2013/07/13/indias-national-cyber-security-policy-preliminary-comments/"&gt;Free Speech Initiative &lt;/a&gt;the same day.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;We  often forget how vulnerable the World Wide Web leaves us. If walls of  code prevent us from entering each other’s systems and networks, there  are those who can easily pick their way past them or disable essential  digital platforms. We are reminded of this by the doings of &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://www.thedailybeast.com/articles/2013/04/17/anonymous-next-move.html" target="_blank"&gt;&lt;span&gt;Anonymous&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which carried out a series of &lt;/span&gt;&lt;a href="http://www.pcmag.com/article2/0,2817,2404554,00.asp" target="_blank"&gt;&lt;span&gt;attacks&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, including the website &lt;span&gt;run by Computer Emergency Response Team India (CERT-In)&lt;span&gt; which is the government agency in charge of cyber-security. Even more  serious, are cyber-attacks (arguably cyber warfare) carried out by other  states, using digital weapons such as &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://www.wired.com/threatlevel/2011/07/how-digital-detectives-deciphered-stuxnet/all/" target="_blank"&gt;&lt;span&gt;Stuxnet&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, the digital worm&lt;span&gt;. More proximate and personal are perhaps the &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://articles.timesofindia.indiatimes.com/2013-06-22/internet/40133370_1_phishing-attacks-kaspersky-lab-unsuspecting-user" target="_blank"&gt;&lt;span&gt;phishing attacks&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, which are on the rise. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;We therefore run a great risk if we leave&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;a href="http://abcnews.go.com/US/story?id=95993&amp;amp;page=1" target="_blank"&gt;&lt;span&gt; air-traffic control&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://www.bbc.co.uk/news/world-us-canada-22692778" target="_blank"&gt;&lt;span&gt;defense resources&lt;/span&gt;&lt;/a&gt; &lt;span&gt; or databases containing several &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://www.nytimes.com/2013/05/10/us/hackers-access-personal-data-in-washington-state.html" target="_blank"&gt;&lt;span&gt;citizens’ personal data&lt;/span&gt;&lt;/a&gt;&lt;span&gt; vulnerable. Sure, there is no doubt that efforts towards better  cyber-security are needed. A cyber-security policy is meant to address  this need, and to help manage threats to individuals, businesses and  government agencies. We need to carefully examine the government’s  efforts to handle cyber-security, how effective it is and whether its  actions do not have too many negative spillovers.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;/div&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;The  National Cyber-Security Policy, unveiled last week, is merely a  statement of intention in broad terms. Much of  its real impact will be  ascertainable only after the language to be used in the law is  available.&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt; Nevertheless, the scope of the policy &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;a href="http://www.rediff.com/news/report/national-cyber-security-policy-fails-on-many-fronts/20130703.htm" target="_blank"&gt;&lt;span&gt;remains ambiguous&lt;/span&gt;&lt;/a&gt;&lt;span&gt; so far, leading to &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://groundreport.com/privacy-ignored-by-the-cyber-security-policy-of-india/" target="_blank"&gt;&lt;span&gt;much speculation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; about the different ways in which it might be intrusive. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;div style="text-align: justify; "&gt;&lt;br /&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;i&gt;&lt;span&gt;One Size Fits All?&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;The  policy covers very different kinds of entities: government agencies,  private companies or businesses, non-governmental entities and  individual users. These entities may need to be handled differently  depending on their nature. Therefore, while direct state action may be  most appropriate to secure government agencies’ networks, it may be less  appropriate in the context of purely private business. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;For  example, securing police records would involve the government directly  purchasing or developing sufficiently secure technology. However,  different private businesses and non-governmental entities may be left  to manage their own security. Depending on the size of each entity, each  may be differently placed to acquire sophisticated security systems. A  good policy would encourage innovation by those with the capacity to do  this, while ensuring that others have access to reasonably sound  technology, and that they use it. Grey-areas might emerge in contexts  where a private party is manages critical infrastructure. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;It  will also be important to distinguish between smaller and larger  organisations whilst creating obligations. Unless this distinction is  made at the implementation stage, start-up businesses and civil society  organisations may find requirements such as earmarking a budget for  cyber security implementation or appointing a Chief Information Security  Officer onerous. Additionally, the policy will need to translate into a  regulatory solution that provides under-resourced entities with ready  solutions to enable them to make their information systems secure, while  encouraging larger entities with greater purchasing power to invest in  procuring the best possible solutions. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;i&gt;&lt;span&gt;Race to the Top&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;Security  on the Internet works only if it stays one step ahead the people trying  to break in. An effective cyber-security policy must keep up with the  rapid evolution of technology, and must never become obsolete. The  standard-setting and review bodies will therefore need to be very  nimble.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;The  policy contemplates working with industry and supporting academic  research and development to achieve this. However the actual manner in  which resources are distributed and progress is monitored may make the  crucial difference between a waste of public funds and acquisition of  capacity to achieve a reasonable degree of cyber security.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;Additionally  the flow of public funds under this policy, particularly to purchase  technology, should be examined very carefully to see whether it is  justified. For example, if the government chooses to fund (even by way  of subsidy) a private company’s cyber-security research and development  rather than an equivalent public university’s endeavour, this decision  should be scrutinized to see whether it was necessary. Similarly, if  extensive public funds are spent training young people as a  capacity-building exercise, we should watch to see how many of these  people stay in India and how many leave such that other countries end up  benefiting from the Indian government’s investment in them!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;i&gt;&lt;span&gt;Investigation of Security Threats&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;Although  much of the policy focuses on defensive measures that can be taken  against security breaches, it is intended not only to cover  investigation subsequent to an attack but also to pinpoint ‘potential  cyber threats’ so that proactive measures may be taken. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;The  policy has outlined the need for a ‘Cyber Crisis Management Plan’ to  handle incidents that impact ‘critical national processes or endanger  public safety and security of the nation’. This portion of the policy  will need to be watched closely to ensure that the language used is very  narrow and allows absolutely no scope for misinterpretation or misuse  that would affect citizens’ rights in any manner. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;This  caution will be necessary both in view of the manner in which  restraints on freedom of speech permitted in the interests of public  safety have been flagrantly abused, and because of the &lt;/span&gt;&lt;span&gt;kind of paternalistic &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="https://www.eff.org/deeplinks/2009/04/cybersecurity-act" target="_blank"&gt;&lt;span&gt;state intrusion&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;span&gt; that might be conceived to give effect to this.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;Additionally,  since the policy also mentions information sharing with internal and  international security, defence, law enforcement and other such  agencies, it will also be important to find out the exact nature of  information to be shared.&lt;/span&gt;&lt;/span&gt; Of  course, how the policy will be put into place will only become clear as  the terms governing its various parts emerge. But one hopes the  necessary internal direct action to ensure the government agencies’  information networks are secure is already well underway.&lt;/div&gt;
&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;It  is also to be hoped that the government chooses to take implementation  of privacy rights at least as seriously as cyber-security. If some parts  of cyber security involve ensuring that user data is protected, the  decision about what data needs protection will be important to this  exercise. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;Additionally,  although the policy discusses various enabling and standard-setting  measures, it does not discuss the punitive consequences of failure to  take reasonable steps to safeguard individuals’ personal data online.  These consequences will also presumably form a part of the privacy  policy, and should be put in place as early as possible.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-hoot-july-13-2013-chinmayi-arun-parsing-the-cyber-security-policy'&gt;https://cis-india.org/internet-governance/blog/the-hoot-july-13-2013-chinmayi-arun-parsing-the-cyber-security-policy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>chinmayi</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-22T06:37:56Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/down-to-earth-july-17-2013-nishant-shah-you-have-the-right-to-remain-silent">
    <title>You Have the Right to Remain Silent</title>
    <link>https://cis-india.org/internet-governance/blog/down-to-earth-july-17-2013-nishant-shah-you-have-the-right-to-remain-silent</link>
    <description>
        &lt;b&gt;Reflecting upon the state of freedom of speech and expression in India, in the wake of the shut-down of the political satire website narendramodiplans.com.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Nishant Shah's &lt;a class="external-link" href="http://www.downtoearth.org.in/content/you-have-right-remain-silent"&gt;column was published in Down to Earth&lt;/a&gt; on July 17, 2013.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;It took less than a day for narendramodiplans.com, a political satire  website that had more than 60,000 hits in the 20 hours of its existence,  to be taken down. A simple webpage that showed a smiling picture of  Narendra Modi, the touted candidate for India’s next Prime Ministerial  campaign, flashing his now trademark ‘V’ for &lt;span&gt;&lt;s&gt;Vengeance&lt;/s&gt; &lt;/span&gt; Victory sign. At the first glimpse it looked like another smart media campaign by the  net-savvy minister who has already made use of the social web quite  effectively, to connect with his constituencies and influence the  younger voting population in the country. Below the image of Mr. Modi  was a text that said, "For a detailed explanation of how Mr. Narendra  Modi plans to run the nation if elected to the house as a Prime Minister  and also for his view/perspective on 2002 riots please click the link  below." The button, reminiscent of 'sale' signs on shops that offer  permanent discounts, promised to reveal, for once and for all, the puppy  plight of Mr. Modi's politics and his plans for the country that he  seeks to lead.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, when one tried to click on the button, hoping, at least for a  manifesto that combined the powers of Machiavelli with the sinister  beauty of Kafka, it proved to be an impossible task. The button wiggled,  and jiggled, and slithered all over the page, running away from the  mouse following it. Referencing the layers of evasive answers, the  engineered Public Relations campaigns that try to obfuscate the history  to some of the most pointed questions that have been posited to the Modi  government through judicial and public forums, the button never stayed  still enough to actually reveal the promised answers. For people who are  familiar with the history of such political satire and protest online  would immediately recognise that this wasn’t the most original of ideas.  In fact, it was borrowed from another website -  &lt;a href="http://www.thepmlnvision.com/" title="http://www.thepmlnvision.com/"&gt;http://www.thepmlnvision.com/&lt;/a&gt; that levelled similar accusations of lack of transparency and  accountability on the part of Nawaz Sharif of Pakistan. Another  instance, which is now also shut down, had a similar deployment where  the webpage claimed to give a comprehensive view into Rahul Gandhi’s  achievements, to question his proclaimed intentions of being the next  prime-minister. In short, this is an internet meme, where a simple web  page and a java script allowed for a critical commentary on the future  of the next elections and the strengthening battle between #feku and  #pappu that has already taken epic proportions on Twitter.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The early demise of these two websites (please do note, when you click  on the links that the Nawaz Sharif website is still working) warns us of  the tightening noose around freedom of speech and expression that  politicos are responsible for in India. It has been a dreary last couple  of years already, with the passing of the &lt;a href="http://www.downtoearth.org.in/content/cis-india.org/internet-governance/intermediary-liability-in-india" target="_blank"&gt;Intermediaries Liabilities Rules&lt;/a&gt; as an amendment to the IT Act of India, &lt;a href="http://www.indianexpress.com/news/spy-in-the-web/888509/1" target="_blank"&gt;Dr. Sibal proposing to pre-censor the social web&lt;/a&gt; in a quest to save the face of erring political figures,&lt;a href="http://www.indianexpress.com/news/two-girls-arrested-for-facebook-post-questioning-bal-thackeray-shutdown-of-mumbai-get-bail/1033177/" target="_blank"&gt; teenagers being arrested for voicing political dissent&lt;/a&gt;, and &lt;a href="http://en.wikipedia.org/wiki/Aseem_Trivedi" target="_blank"&gt;artists being prosecuted&lt;/a&gt; for exercising their rights to question the state of governance in our  country. Despite battles to keep the web an open space that embodies the  democratic potentials and the constitutional rights of freedom of  speech and expression in the country, it has been a losing fight to keep  up with the ad hoc and dictatorial mandates that seem to govern the  web.&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/Namo.png" alt="Narendra Modi Plans" class="image-inline" title="Narendra Modi Plans" /&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Above is a screen shot from narendramodiplans.com website&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;We have no indication of why this latest piece of satirical expression, which should be granted immunity as a work of art, if not as an individual’s right to free speech, was suddenly taken down. The website now has a message that says, “I quit. In a country with freedom of speech, I assumed that I was allowed to make decent satire on any politician more particularly if it is constructive. Clearly, I was wrong.” The web is already abuzz with conspiracy theories, each sounding scarier than the other because they seem so plausible and possible in a country that has easily sacrificed our right to free speech and expression at the altar of political egos. And whether you subscribe to any of the theories or not, whether your sympathies lie with the BJP or with the UPA, whether or not you approve of the political directions that the country seems to be headed in, there is no doubt that you should be as agitated as I am, about the fact that we are in a fast-car to blanket censorship, and we are going there in style.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What happens online is not just about this one website or the one person  or the one political party – it is a reflection on the rising  surveillance and bully state that presumes that making voices (and  sometimes people) invisible, is enough to resolve the problems that they  create. And what happens on the web is soon going to also affect the  ways in which we live our everyday lives. So the next time, you call  some friends over for dinner, and then sit arguing about the state of  politics in the country, make sure your windows are all shut, you are  wearing tin-foil hats and if possible, direct all conversations to the  task of finally &lt;a href="http://bollywoodjournalist.com/2013/07/08/desperately-seeking-mamta-kulkarni/" target="_blank"&gt;finding Mamta Kulkarni&lt;/a&gt;.  Because anything else that you say might either be censored or land you  in a soup, and the only recourse you might have would be a website that  shows the glorious political figures of the country, with a sign that  says “To defend your right to free speech and expression, please click  here”. And you know that you are never going to be able to click on that  sign. Ever.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/down-to-earth-july-17-2013-nishant-shah-you-have-the-right-to-remain-silent'&gt;https://cis-india.org/internet-governance/blog/down-to-earth-july-17-2013-nishant-shah-you-have-the-right-to-remain-silent&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>nishant</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Freedom of Speech and Expression</dc:subject>
    
    
        <dc:subject>Social Media</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Intermediary Liability</dc:subject>
    

   <dc:date>2013-07-22T06:59:53Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/firstpost-pierre-fitter-july-17-2013-snooping-technology">
    <title>Snooping technology: Will CMS work in India?</title>
    <link>https://cis-india.org/news/firstpost-pierre-fitter-july-17-2013-snooping-technology</link>
    <description>
        &lt;b&gt;The Indian government plans to spend $132 million on setting up its brand new Central Monitoring System this year.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Pierre Fitter's article was &lt;a class="external-link" href="http://www.firstpost.com/india/snooping-technology-will-cms-work-in-india-962545.html"&gt;published in FirstPost on July 17, 2013&lt;/a&gt;. Pranesh Prakash is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Several articles have raised valid questions about privacy violations, including &lt;a href="http://www.firstpost.com/india/indias-central-monitoring-system-security-cant-come-at-cost-of-privacy-944475.html" target="_blank"&gt;this one by Danish Raza&lt;/a&gt;. Elsewhere, &lt;a href="http://india.blogs.nytimes.com/2013/07/10/how-surveillance-works-in-india/" rel="nofollow" target="_blank"&gt;Pranesh Prakash has raised important points&lt;/a&gt; about how CMS may actually violate several laws and at least one Supreme Court verdict.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I ask a much more basic question: will CMS work? Can it really help  security agencies eavesdrop on criminals and terrorists, despite several  known technical hurdles?&lt;/p&gt;
&lt;table class="invisible"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;img src="https://cis-india.org/home-images/Daniel.png" title="Daniel" height="250" width="332" alt="Daniel" class="image-inline" /&gt;&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;&lt;b&gt;Encryption&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In 2008, a prominent Brazilian banker and investor named Daniel Dantas  was arrested and charged with money laundering and tax evasion along  with a former mayor of Sao Paulo. For five months, the Brazilian  National Institute of Criminology tried to read the contents of his hard  drive but failed to crack it. Dantas had encrypted his data using a  free program called &lt;a href="https://en.wikipedia.org/wiki/TrueCrypt" rel="nofollow" target="_blank"&gt;Truecrypt&lt;/a&gt;. The &lt;a href="http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/" rel="nofollow" target="_blank"&gt;INC sent the hard drive to the FBI in the US&lt;/a&gt;,  which spent a whole year trying to crack it; it too failed. Dantas’s  use of encryption likely helped him escape the money laundering and tax  evasion charges. He was ultimately &lt;a href="http://news.bbc.co.uk/2/hi/americas/7761823.stm" rel="nofollow" target="_blank"&gt;convicted of attempting to bribe a police officer&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;This story illustrates a fundamental loophole at the heart of CMS. A  criminal, using free and easy-to-use software, can protect his data from  even the most advanced surveillance tools available in law enforcement.  NSA whistle blower Edward Snowden himself used encrypted email to  communicate with journalists at the &lt;i&gt;Guardian&lt;/i&gt;. In an &lt;a href="http://discussion.guardian.co.uk/comment-permalink/24384968" rel="nofollow" target="_blank"&gt;online chat where he took questions from the public&lt;/a&gt;, Snowden noted that encryption was “one of the few things that you can rely on” to protect you from the &lt;a href="http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/" rel="nofollow" target="_blank"&gt;eavesdropping behemoth created of the NSA&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It should hardly be surprising then, that terror groups have been  encrypting their emails and data for at least the last five years. In  fact &lt;a href="http://intelwire.egoplex.com/2008_02_02_exclusives.html" rel="nofollow" target="_blank"&gt;Al Qaeda developed its own encryption software called ‘Mujahideen Secrets’&lt;/a&gt;,  to encrypt emails, chat sessions and files. Version two of Mujahideen  Secrets even included a tool to delete files securely so that they could  not be recovered using special software if the computer was captured.  Al Qaeda’s links to several terror groups operating in India has been  widely reported in the past. It is not inconceivable that they have  shared their encryption software with their comrades-in-arms.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Over the years it has become easier to encrypt one’s communication. &lt;a href="https://www.youtube.com/watch?v=MKehyXaY2XM" rel="nofollow" target="_blank"&gt;YouTube tutorials&lt;/a&gt; train even novice users to set up email encryption within minutes. &lt;a href="https://play.google.com/store/apps/details?id=org.thoughtcrime.redphone&amp;amp;hl=en" rel="nofollow" target="_blank"&gt;Phone calls&lt;/a&gt;, &lt;a href="https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms&amp;amp;hl=en" rel="nofollow" target="_blank"&gt;text messages&lt;/a&gt; and &lt;a href="http://www.cypherpunks.ca/otr/" rel="nofollow" target="_blank"&gt;online chats&lt;/a&gt; can also be encrypted with free, easy-to-install apps.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The biggest problem with encryption is that it is virtually impossible  to break the code in a time frame that’s useful for law-enforcement  purposes. Without getting too technical, modern encryption relies  calculating the prime factors of very, very large integers. In 2009, a  group of some of the world’s best-known mathematicians and  cryptographers reported that &lt;a href="http://security.stackexchange.com/questions/4518/how-to-estimate-the-time-needed-to-crack-rsa-encryption" rel="nofollow" target="_blank"&gt;it took them four years to factor a 768-bit integer&lt;/a&gt;. They estimated &lt;a href="https://www.digicert.com/TimeTravel/math.htm" rel="nofollow" target="_blank"&gt;it would take 1,000 times longer to factorise a 1024-bit integer&lt;/a&gt;.  GPG, which is the most widely-used email encryption software, allows  users up to 4096-bit encryption. Unless you have the password to the  encrypted files, it would take you a very long time to crack the  encryption.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Here’s an example to help you understand why encryption makes CMS  redundant. Let’s say the system intercepts an encrypted email sent by a  LeT handler in Karachi to a sleeper cell in Mumbai. The email contains  instructions to detonate a bomb in a specific market at a specific time  four days from now. Even if India’s intelligence agencies managed to  link up every computer they had available to process the encryption,  they would still not be able to crack it in time to learn the details  and stop the attack.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;What about ‘Metadata’?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It should be noted that encryption only protects the body of the email. The metadata, including the sender’s and receiver’s email addresses remain unencrypted, else the service provider would be unable to send the email to its destination. Law enforcement agencies often partner with email providers to track down the exact computer on which tell-tale emails were read.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, this method of tracing criminals has a limitation. Programs such as &lt;a href="https://en.wikipedia.org/wiki/Tor_%28anonymity_network%29" rel="nofollow" target="_blank"&gt;TOR&lt;/a&gt; and &lt;a href="https://en.wikipedia.org/wiki/Hotspot_Shield" rel="nofollow" target="_blank"&gt;Hotspot Shield&lt;/a&gt; disguise the IP address of a user’s PC. For example, when I use TOR,  Facebook will often ask me to confirm my identity as it sees me as  logging in from an unfamiliar location. TOR has thousands of servers  around the world through which it bounces your data before sending it to  its destination.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There is another limitation to using metadata. Due to obvious legal  hurdles, CMS will only be deployed to capture communication within  India. If terrorists were planning an attack from elsewhere in India’s  neighbourhood (as happened with 26/11), we would have to rely on that  country’s intelligence services for an alert. Good luck with that!&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;To make untraceable phone calls, terrorists have been known to use &lt;a href="https://en.wikipedia.org/wiki/Burner_phone#Privacy_rights_and_prepaid_mobile_phones" rel="nofollow" target="_blank"&gt;“burner” phones&lt;/a&gt;.  These are pre-paid phones that are easily available in the US and other  countries that do not require an ID for such mobile connections. They  can be topped up using cash, which makes their prolonged using even more  untraceable.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Even if CMS allowed spooks to listen to these calls, it would not be  able to tell who was talking to whom. From details that emerged  following the Abbottabad operation that killed Osama bin Laden, we also  know that terrorists have been trained to &lt;a href="http://www.foxnews.com/tech/2011/05/03/bin-laden-grid-govt-help-expert-says/" rel="nofollow" target="_blank"&gt;turn off their phones and remove the battery&lt;/a&gt; to prevent being tracked even while not on a call.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;So what is CMS good for?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;If terrorist communications can easily be hidden from CMS, you have  to wonder why the government is going through all the effort and expense  to set up such a system. What good can come off the mass hoovering of  data of ordinary citizens’?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Imagine if CMS intercepted a ‘BBM chat’ between two businessmen, who  were discussing a contract that could affect the business interests of a  government MP.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Imagine the government getting access to emails exchanged between a  journalist and a source in the IAS who wants to expose a major  corruption scandal involving a cabinet minister.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Imagine if the government had access to phone calls between two opposition politicians discussing election strategies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What if CMS tracks a PhD candidate who is researching Naxal terror  and has downloaded Naxal pamphlets? What if this researcher has been  able to establish contact with Naxals for an interview. Can the  government use such data to charge him with participating in a Naxal  conspiracy, even if his only intention was to research their  motivations? In a country where chief ministers label their critics as  “Naxals” for merely raising questions, are we certain we want such  unmitigated power in the government’s hands?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;These are all questions well worth asking, especially since the  ostensible reason for setting up the CMS—monitoring terrorists and  criminals—is a fool’s errand at best.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/firstpost-pierre-fitter-july-17-2013-snooping-technology'&gt;https://cis-india.org/news/firstpost-pierre-fitter-july-17-2013-snooping-technology&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-22T07:19:02Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/data-protection-experts-slam-state-for-sending-mass-smses">
    <title>Data protection experts slam state for sending mass SMSes</title>
    <link>https://cis-india.org/news/data-protection-experts-slam-state-for-sending-mass-smses</link>
    <description>
        &lt;b&gt;Experts in the field of data protection, privacy law and media have criticised the West Bengal government's mass SMS sent to individuals, companies and media houses through private mobile networks last Friday. Lara Choksey reports this in an article published in the Statesman on March 25, 2012.&lt;/b&gt;
        
&lt;p&gt;The government's use of private data in order to spread political messages is ethically dubious and dangerous, say some.&amp;nbsp; The SMS indirectly refers to The Telegraph's publication of the Poonam Pandey tweet, warning against the transmission of “provocative and indecent photographs for hurting the religious sentiments of people and disrupting communal harmony.” It urges recipients to “frustrate the designs of … unscrupulous people and maintain peace and communal harmony,” and is signed by “Mamata Banerjee, Chief Minister”.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Speaking to The Statesman on Saturday, Mumbai-based media lecturer Ms Geeta Seshu identified two issues with the government sending out political messages through mobile phone networks.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Firstly, from an ethical standpoint, the unchecked freedom of mobile phone companies to hand out private data is “completely wrong”, she said.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Secondly, the use of government funds for such dissemination needs to be transparent. If the state government has used public funds to distribute its message through a mobile phone network, then this information should be readily available, said Ms Seshu.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The Telecom Regulation Authority of India's (Trai) unsolicited commercial communications regulations allow unsolicited advertising through mobile phone networks.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Mr Apar Gupta, partner of Delhi-based law firm Advani and Co., explained, “The regulations are not wide enough to prohibit communications from a political party.” He observed, “Using SMS messages is a very efficient propaganda tool because so many people have access to mobile phones.”&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Mobile phone networks such as Vodafone make it clear in their privacy policies that the personal data of its customers “may be used for inclusion in any telephone or similar directory or directory enquiry service provided or operated by us or by a third party” (source Vodafone website).&lt;/p&gt;
&lt;p&gt;Any third party&amp;nbsp; ~ governmental or corporate ~ can therefore access the company's directory of private mobile numbers at the discretion of the network in question.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It is not yet clear which government department coordinated the SMS, or what funds were used to cover the costs. Representatives from the ministry of information and cultural affairs were not able to shed a light on the matter. “I know that a message was sent out,” said the I &amp;amp; CA director Umapada Chatterjee, "But it was not sent from this department. I do not know that information.”&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Some commentators did not condemn the government's SMS. Delhi High Court lawyer and cyber law expert, Mr Praveen Dalal, criticised the publication of the Poonam Pandey tweet on the grounds of it violating the due diligence guidelines of the Cyber Law of India. He commented, “If casual and careless publications … continue, there would be no other option left for the government but to regulate their affairs in a more intrusive manner.”&amp;nbsp;&lt;/p&gt;
&lt;p&gt;However, executive director of the Centre for Internet and Society, Mr Sunil Abraham, called the state government's use of unsolicited SMS a “clear abuse of the powers afforded by elected office.” Mr Abraham explained that elected representatives would be justified in such measures, and in utilising public funds, in the event of a disaster, or when public order, public health or national security are compromised.&lt;/p&gt;
&lt;p&gt;“However in this case, the government is abusing the provisions of the law and using this incident as a pretext to threaten media professionals with surveillance and to intimidate for the purposes of reigning in free speech,” he told The Statesman. The chief minister was unavailable to make a comment on the matter.&lt;/p&gt;
&lt;p&gt;&lt;a class="external-link" href="http://www.thestatesman.net/index.php?option=com_content&amp;amp;view=article&amp;amp;id=404338&amp;amp;catid=73"&gt;Read the original published in the Statesman&lt;/a&gt;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/data-protection-experts-slam-state-for-sending-mass-smses'&gt;https://cis-india.org/news/data-protection-experts-slam-state-for-sending-mass-smses&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-03-27T03:46:00Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/livemint-december-27-2012-surabhi-agarwal-un-agrees-to-review-agencies-governing-internet">
    <title>UN agrees to review agencies governing Internet</title>
    <link>https://cis-india.org/news/livemint-december-27-2012-surabhi-agarwal-un-agrees-to-review-agencies-governing-internet</link>
    <description>
        &lt;b&gt;Although India’s proposal has been criticized as an effort to control the Net, govt says this will ensure it has more say in policymaking.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The article by Surabhi Agarwal was &lt;a class="external-link" href="http://www.livemint.com/Industry/noxrdKdOmZMnXGpXyGzXUO/UN-agrees-to-review-agencies-governing-Internet.html"&gt;published in Livemint on December 27, 2012&lt;/a&gt;. Pranesh Prakash is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;In the fierce debate on who governs the Internet, the Indian government can claim a small victory of sorts after the UN decided to establish a working group to review the mandate of agencies administering the worldwide network of computers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India last year proposed creating an UN agency, dubbed the Committee on Internet-Related Policies (CIRP), that would decide on issues related to the Internet, including control of resources such as domain names and Internet Protocol (IP) addresses. The Internet Corporation for Assigned Names and Numbers (Icann), a non-governmental organization based in the US, currently administers these.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The US, the UK and Canada refused to sign a new communications treaty proposed at the 3-14 December Dubai conference of the International Telecommunications Union (ITU), which sets global telecom technical standards, on fears that it will give national governments greater control over the Internet and may restrict free speech. India, too, hasn’t signed the pact.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Even though the United Nations has not yet accepted India’s proposal for constituting CIRP, it (the formation of a working group) is a step forward, as now the working group on enhanced cooperation will deliberate on the need for CIRP,” a government official said, requesting anonymity.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Although India’s proposal has been criticized as an effort to control the Internet, the government has said this will ensure it has a greater say in Internet policymaking.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Commission on Science and Technology for Development, a UN body, has been asked to establish a working group on enhanced cooperation to examine the mandate of the World Summit on the Information Society, which issues non-binding guidelines on the Internet, “through seeking, compiling and reviewing inputs from all member states and all other stakeholders,” according to a 12 December letter from the UN to the Indian government. The working group has been asked to submit its report to the commission in 2014.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Mint &lt;/i&gt;has reviewed a copy of the letter and also India’s response to the UN welcoming the move.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UN’s move reflected India’s growing influence in multilateral policymaking bodies, according to &lt;a href="http://www.livemint.com/Search/Link/Keyword/Rajat%20Kathuria"&gt;Rajat Kathuria&lt;/a&gt;, chief executive and director of Indian Council for Research on International Economic Relations, a think tank.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“India’s increasing clout not only in the WTO (World Trade Organisation) but also in these kinds of forums is fairly obvious,” he said. The country should be able to stand its ground and use its negotiating powers well, he added. “Everybody is looking at India now and it should not be forced into getting into things it doesn’t want to.” Kathuria also agreed with India’s decision to consider in detail the new global telecom pact, which contains a resolution on the Internet, before signing it.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“We don’t have enough information on the impact of signing this treaty,” Kathuria said. “I agree with what India has done. We need to do our homework and understand clearly what it means.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Although the treaty is restricted to telecom standards, it contained a non-binding resolution on the Internet. The treaty stated that its purview doesn’t include content over telecommunications networks or the Internet.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, there have been divergent views on its implications. While some have argued that signing it would mean giving the ITU dominance over Internet governance, others dismiss it as harmless.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“This wasn’t an ITU takeover of the Internet and India’s signing of the treaty will not make it one,” said &lt;a href="http://www.livemint.com/Search/Link/Keyword/Pranesh%20Prakash"&gt;Pranesh Prakash&lt;/a&gt;, policy director at Centre for Internet Studies, a Bangalore-based think tank.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, India’s cautious approach is a good sign, he said. “I hope civil society is consulted before the decision is taken whether to support ITR (International Telecommunication Regulations) and the resolutions which were passed in Dubai.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Critical Internet resources such as domain names and IP addresses are like natural resources and no one country should monetize them or have control over them, said another government official.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It is of utmost importance for India to have a say in the matters of the Internet as the country has huge untapped potential in the area of Internet and technology,” said the official, who too declined to be named.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A white paper on Internet governance by Research and Information System for Developing Countries, chaired by &lt;a href="http://www.livemint.com/Search/Link/Keyword/Shyam%20Saran"&gt;Shyam Saran&lt;/a&gt;, former Indian diplomat, has said the Internet continues to be managed by private entities such as Icann “under contractual arrangements with the US government”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Icann is not controlled by the US government, an official of the Internet administrator said on condition of anonymity. It follows a multi-stakeholder model.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The paper on Internet governance argued against the allegation that India’s proposal of CIRP will lead to government’s control of the Internet.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“India’s proposal for CIRP, a multilateral and multi-stakeholder mechanism, is not intended to control content,” it said. “It does not insist that the governments have the last word in regulating the Internet.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The paper had argued that India should pursue the establishment of a working group on enhanced cooperation, which will pave the way for further consideration of India’s proposal for the establishment of CIRP.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/livemint-december-27-2012-surabhi-agarwal-un-agrees-to-review-agencies-governing-internet'&gt;https://cis-india.org/news/livemint-december-27-2012-surabhi-agarwal-un-agrees-to-review-agencies-governing-internet&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>ITU</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Censorship</dc:subject>
    

   <dc:date>2012-12-31T02:40:20Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/cyber-regulations-advisory-committee-no-civil-society">
    <title>No Civil Society Members in the Cyber Regulations Advisory Committee</title>
    <link>https://cis-india.org/internet-governance/blog/cyber-regulations-advisory-committee-no-civil-society</link>
    <description>
        &lt;b&gt;The Government of India has taken our advice and reconstituted the Cyber Regulations Advisory Commitee. But there is no representation of Internet users, citizens, and consumers — only government and industry interests.&lt;/b&gt;
        &lt;p&gt;In multiple op-eds (&lt;a href="http://cis-india.org/internet-governance/blog/india-broken-internet-law-multistakeholderism"&gt;Indian Express&lt;/a&gt; and &lt;a href="http://cis-india.org/internet-governance/blog/livemint-opinion-november-28-2012-pranesh-prakash-fixing-indias-anarchic-it-act"&gt;Mint&lt;/a&gt;), I have pointed out the need for the government to reconstitute the &amp;quot;Cyber Regulations Advisory Committee&amp;quot; (CRAC) under section 88 of the Information Technology Act. That it be reconstituted along the model of the Brazilian Internet Steering Committee was also &lt;a href="http://docs.google.com/viewer?url=www.iigc.in%2Fhtm%2F2.pdf"&gt;part of the suggestions that CIS sent to the government&lt;/a&gt; after a &lt;a href="http://www.thehindu.com/todays-paper/tp-national/tp-newdelhi/government-to-hold-talks-with-stakeholders-on-internet-censorship/article3860393.ece"&gt;meeting FICCI had convened along with the government on September 4, 2012&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Section 88 requires that people &amp;quot;representing the interests principally affected&amp;quot; by Internet policy or &amp;quot;having special knowledge of the subject matter&amp;quot; be present in this advisory body. The main function of the CRAC is to advise the the Central Government &amp;quot;either generally as regards any rules or for any other purpose connected with this Act&amp;quot;.&lt;/p&gt;
&lt;p&gt;Despite this important function, the CRAC had &amp;mdash; till November 2012 &amp;mdash; only ever met twice, &lt;a href="http://cis-india.org/internet-governance/resources/deity-response-to-rti-on-decisions-of-crac"&gt;both times in 2001&lt;/a&gt;. The response to an RTI informed us that the body had never provided any advice to the government.&lt;/p&gt;
&lt;h2 id="government-not-serious"&gt;Government Not Serious&lt;/h2&gt;
&lt;p&gt;The increasing pressure on the government for botching up Internet regulations has led it to reconstitute the CRAC. However, the list of members of the committee shows that the government is not serious about this committee representing &amp;quot;the interests primarily affected&amp;quot; by Internet policy.&lt;/p&gt;
&lt;p&gt;Importantly, this goes against the express wish of the Shri Kapil Sibal, the Union Minister for Communications and IT, who has repeatedly stated that he believes that Internet-related policymaking should be an inclusive process. Most recently, at the 2012 Internet Governance Forum he stated that we need systems that are:&lt;/p&gt;
&lt;blockquote&gt;
&amp;quot;collaborative, consultative, inclusive and consensual, for dealing with all public policies involving the Internet&amp;quot;
&lt;/blockquote&gt;

&lt;p&gt;Interestingly, despite the Hon'ble Minster verbally inviting civil society organizations (on November 23, 2012) for a meeting of the CRAC that happened on November 25, 2012, the Department of Electronics and Information Technology refused to send us invitations for the meeting.  This hints at a disconnect between the political and bureaucratic wings of the government, at least at some levels.&lt;/p&gt;
&lt;p&gt;Interestingly, this isn't the first time this has been pointed out. Na. Vijayashankar was levelling similar criticisms against the CRAC &lt;a href="http://www.naavi.org/cl_editorial/edit_18aug00_1.html"&gt;way back in August 2000&lt;/a&gt; when the original CRAC was constituted.&lt;/p&gt;
&lt;h2 id="breakdown-by-stakeholder-groupings"&gt;Breakdown by Stakeholder Groupings&lt;/h2&gt;
&lt;p&gt;While there is no one universal division of stakeholders in Internet governance, but four goups are widely recognized: governments (national and intergovernmental), industry, technical community, and civil society. Using that division, we get:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Government - 15 out of 22 members&lt;/li&gt;
&lt;li&gt;Industry bodies - 6 out of 22 members&lt;/li&gt;
&lt;li&gt;Technical community / Academia - 1 out of 22 members&lt;/li&gt;
&lt;li&gt;Civil society - 0 out of 22 members.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="list-of-members-of-cyber-regulatory-advisory-committee"&gt;List of Members of Cyber Regulatory Advisory Committee&lt;/h2&gt;
&lt;p&gt;The official notification &lt;a href="http://deity.gov.in/sites/upload_files/dit/files/gazzate(1).pdf"&gt;(G.S.R. 827(E)) is available on the DEIT website&lt;/a&gt; and came into force on November 16, 2012.&lt;/p&gt;
&lt;p&gt;(Note: Names with &lt;del&gt;strikethroughs&lt;/del&gt; have been removed from the CRAC since 2000, and those with &lt;i&gt;emphasis&lt;/i&gt; have been added.)&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Minister, Ministry of Communication and Information Technology - Chairman&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Minister of State, Ministry of Communications and Information Technology - Member&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;Secretary, Ministry of Communication and Information Technology, Department of Electronics and Information Technology - Member&lt;/li&gt;
&lt;li&gt;Secretary, Department of Telecommunications - Member &lt;br /&gt;&lt;del&gt;Finance Secretary - Member&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Secretary, Legislative Department - Member&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Secretary, Department of Legal Affairs - Member&lt;/i&gt; &lt;br /&gt;&lt;del&gt;Shri T.K. Vishwanathan, Presently Member Secretary, Law Commission - Member&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Secretary, Ministry of Commerce - Member&lt;/li&gt;
&lt;li&gt;Secretary, Ministry of Home Affairs - Member&lt;/li&gt;
&lt;li&gt;Secretary, Ministry of Defence - Member&lt;/li&gt;
&lt;li&gt;Deputy Governor, Reserve Bank of India - Member&lt;/li&gt;
&lt;li&gt;Information Technology Secretary from the states by rotation - Member&lt;/li&gt;
&lt;li&gt;Director, IIT by rotation from the IITs - Member&lt;/li&gt;
&lt;li&gt;Director General of Police from the States by rotation - Member&lt;/li&gt;
&lt;li&gt;President, NASSCOM - Member&lt;/li&gt;
&lt;li&gt;President, Internet Service Provider Association - Member&lt;/li&gt;
&lt;li&gt;Director, Central Bureau of Investigation - Member&lt;/li&gt;
&lt;li&gt;Controller of Certifying Authority - Member&lt;/li&gt;
&lt;li&gt;Representative of CII - Member&lt;/li&gt;
&lt;li&gt;Representative of FICCI - Member&lt;/li&gt;
&lt;li&gt;Representative of ASSOCHAM - Member&lt;/li&gt;
&lt;li&gt;&lt;i&gt;President, Computer Society of India - Member&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;Group Coordinator, Department of Electronic and Information Technology - Member Secretary&lt;/li&gt;
&lt;/ol&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/cyber-regulations-advisory-committee-no-civil-society'&gt;https://cis-india.org/internet-governance/blog/cyber-regulations-advisory-committee-no-civil-society&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>pranesh</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>IT Act</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Public Accountability</dc:subject>
    

   <dc:date>2013-01-09T17:56:57Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/smart-cities-in-india-an-overview">
    <title>Smart Cities in India: An Overview</title>
    <link>https://cis-india.org/internet-governance/blog/smart-cities-in-india-an-overview</link>
    <description>
        &lt;b&gt;The Government of India is in the process of developing 100 smart cities in India which it sees as the key to the country's economic and social growth. This blog post gives an overview of the Smart Cities project currently underway in India. The smart cities mission in India is at a nascent stage and an evolving area for research. The Centre for Internet and Society will continue work in this area.&lt;/b&gt;
        &lt;h3 style="text-align: justify; "&gt;&lt;b&gt;Overview of the 100 Smart Cities Mission&lt;/b&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Government of India announced its flagship programme- the 100 Smart Cities mission in the year 2014 and was launched in June 2015 to achieve urban 	transformation, drive economic growth and improve the quality of life of people by enabling local area development and harnessing technology. Initially, 	the Mission aims to cover 100 cities across the countries (which have been shortlisted on the basis of a Smart Cities Proposal prepared by every city) and 	its duration will be five years (FY 2015-16 to FY 2019-20). The Mission may be continued thereafter in the light of an evaluation to be done by the 	Ministry of Urban Development (MoUD) and incorporation of the learnings into the Mission. The Mission aims to focus on area-based development in the form 	of redevelopment of existing spaces, or the development of new areas (Greenfield) to accommodate the growing urban population and ensure comprehensive planning to improve quality of life, create employment and enhance incomes for all - especially the poor and the disadvantaged.	&lt;a href="#_ftn1" name="_ftnref1"&gt;&lt;sup&gt;&lt;sup&gt;[1]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; On 27th August 2015 the Centre unveiled 98 smart cities across India which were selected for this Project. Across the selected cities, 13 crore population ( 35% of the urban population will be included in the development plans.	&lt;a href="#_ftn2" name="_ftnref2"&gt;&lt;sup&gt;&lt;sup&gt;[2]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; The mission has been developed for the purpose of achieving urban transformation. 	The vision is to preserve India's traditional architecture, culture &amp;amp; ethnicity while implementing modern technology to make cities livable, use 	resources in a sustainable manner and create an inclusive environment. &lt;a href="#_ftn3" name="_ftnref3"&gt;&lt;sup&gt;&lt;sup&gt;[3]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The promises of the Smart City mission include reduction of carbon footprint, adequate water and electricity supply, proper sanitation, including solid 	waste management, efficient urban mobility and public transport, affordable housing, robust IT connectivity and digitalization, good governance, citizen 	participation, security of citizens, health and education.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Questions unanswered&lt;/span&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;Why and How was the Smart Cities project conceptualized in India? What was the need for such a project in India?&lt;/li&gt;
&lt;li&gt;What was the role of the public/citizens at the ideation and conceptualization stage of the project?&lt;/li&gt;
&lt;li&gt;Which actors from the Government, Private industry and the civil society are involved in this mission? Though the smart cities mission has been 	initiated by the Government of India under the Ministry of Urban Development, there is no clarity about the involvement of the associated offices and 	departments of the Ministry.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 style="text-align: justify; "&gt;&lt;b&gt;How are the Smart Cities being selected?&lt;/b&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The 100 cities were supposed to be selected on the basis of Smart cities challenge&lt;a href="#_ftn4" name="_ftnref4"&gt;&lt;sup&gt;&lt;sup&gt;[4]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; involving two stages. Stage I of the challenge involved Intra-State city selection on objective criteria to identify cities to compete in stage-II. In August 2015, The Ministry of Urban Development, Government of India announced 100 smart cities	&lt;a href="#_ftn5" name="_ftnref5"&gt;&lt;sup&gt;&lt;sup&gt;[5]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; evaluated on parameters such as service levels, financial and institutional 	capacity, past track record, called as the 'shortlisted cities' for this purpose. The selected cities are now competing for selection in the Second stage 	of the challenge, which is an All India competition. For this crucial stage, the potential 100 smart cities are required to prepare a Smart City Proposal 	(SCP) stating the model chosen (retrofitting, redevelopment, Greenfield development or a mix), along with a Pan-City dimension with Smart Solutions. The 	proposal must also include suggestions collected by way of consultations held with city residents and other stakeholders, along with the proposal for 	financing of the smart city plan including the revenue model to attract private participation. The country saw wide participation from the citizens to 	voice their aspirations and concerns regarding the smart city. 15th December 2015 has been declared as the deadline for submission of the SCP, which must be in consonance with evaluation criteria set by The MoUD, set on the basis of professional advice.	&lt;a href="#_ftn6" name="_ftnref6"&gt;&lt;sup&gt;&lt;sup&gt;[6]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; On the basis of this, 20 cities will be selected for the first year. According to 	the latest reports, the Centre is planning to fund only 10 cities for the first phase in case the proposals sent by the states do not match the expected quality standards and are unable to submit complete area-development plans by the deadline, i.e. 15th December, 2015.	&lt;a href="#_ftn7" name="_ftnref7"&gt;&lt;sup&gt;&lt;sup&gt;[7]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Questions unanswered&lt;/span&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;Who would be undertaking the task of evaluating and selecting the cities for this project?&lt;/li&gt;
&lt;li&gt;What are the criteria for selection of a city to qualify in the first 20 (or 10, depending on the Central Government) for the first phase of 	implementation?&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 style="text-align: justify; "&gt;&lt;b&gt;How are the smart cities going to be Funded?&lt;/b&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Smart City Mission will be operated as a Centrally Sponsored Scheme (CSS) and the Central Government proposes to give financial support to the Mission to the extent of Rs. 48,000 crores over five years i.e. on an average Rs. 100 crore per city per year.	&lt;a href="#_ftn8" name="_ftnref8"&gt;&lt;sup&gt;&lt;sup&gt;[8]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; The additional resources will have to be mobilized by the State/ ULBs from 	external/internal sources. According to the scheme, once list of shortlisted Smart Cities is finalized, Rs. 2 crore would have been disbursed to each city 	for proposal preparation.&lt;a href="#_ftn9" name="_ftnref9"&gt;&lt;sup&gt;&lt;sup&gt;[9]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to estimates of the Central Government, around Rs 4 lakh crore of funds will be infused mainly through private investments and loans from multilateral institutions among other sources, which accounts to 80% of the total spending on the mission.	&lt;a href="#_ftn10" name="_ftnref10"&gt;&lt;sup&gt;&lt;sup&gt;[10]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; For this purpose, the Government will approach the World Bank and the Asian 	Development Bank (ADB) for a loan costing £500 million and £1 billion each for 2015-20. If ADB approves the loan, it would be it will be the 	bank's highest funding to India's urban sector so far.&lt;a href="#_ftn11" name="_ftnref11"&gt;&lt;sup&gt;&lt;sup&gt;[11]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; Foreign Direct Investment regulations have been relaxed to invite foreign capital and help into the Smart City Mission.	&lt;a href="#_ftn12" name="_ftnref12"&gt;&lt;sup&gt;&lt;sup&gt;[12]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;Questions unanswered&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;The Government notes on Financing of the project mentions PPPs for private funding and leveraging of resources from internal and external 	resources. There is lack of clarity on the external resources the Government has/will approach and the varied PPP agreements the Government is or is 	planning to enter into for the purpose of private investment in the smart cities.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 style="text-align: justify; "&gt;&lt;b&gt;How is the scheme being implemented?&lt;/b&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Under this scheme, each city is required to establish a Special Purpose Vehicle (SPV) having flexibility regarding planning, implementation, management and 	operations. The body will be headed by a full-time CEO, with nominees of Central Government, State Government and ULB on its Board. The SPV will be a 	limited company incorporated under the Companies Act, 2013 at the city-level, in which the State/UT and the Urban Local Body (ULB) will be the promoters 	having equity shareholding in the ratio 50:50. The private sector or financial institutions could be considered for taking equity stake in the SPV, 	provided the shareholding pattern of 50:50 of the State/UT and the ULB is maintained and the State/UT and the ULB together have majority shareholding and 	control of the SPV. Funds provided by the Government of India in the Smart Cities Mission to the SPV will be in the form of tied grant and kept in a 	separate Grant Fund.&lt;a href="#_ftn13" name="_ftnref13"&gt;&lt;sup&gt;&lt;sup&gt;[13]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For the purpose of implementation and monitoring of the projects, the MoUD has also established an Apex Committee and National Mission Directorate for 	National Level Monitoring&lt;a href="#_ftn14" name="_ftnref14"&gt;&lt;sup&gt;&lt;sup&gt;[14]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;, a State Level High Powered Steering Committee (HPSC) for State Level Monitoring&lt;a href="#_ftn15" name="_ftnref15"&gt;&lt;sup&gt;&lt;sup&gt;[15]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; and a Smart City Advisory Forum at the City Level	&lt;a href="#_ftn16" name="_ftnref16"&gt;&lt;sup&gt;&lt;sup&gt;[16]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Also, several consulting firms&lt;a href="#_ftn17" name="_ftnref17"&gt;&lt;sup&gt;&lt;sup&gt;[17]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; have been assigned to the 100 cities to help them prepare action plans.&lt;a href="#_ftn18" name="_ftnref18"&gt;&lt;sup&gt;&lt;sup&gt;[18]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; Some of them include CRISIL, KPMG, McKinsey, etc.	&lt;a href="#_ftn19" name="_ftnref19"&gt;&lt;sup&gt;&lt;sup&gt;[19]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;Questions unanswered&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;What policies and regulations have been put in place to account for the smart cities, apart from policies looking at issues of security, privacy, 	etc.?&lt;/li&gt;
&lt;li&gt;What international/national standards will be adopted while development of the smart cities? Though the Bureau of Indian Standards is in the 	process of formulating standardized guidelines for the smart cities in India&lt;a href="#_ftn20" name="_ftnref20"&gt;&lt;sup&gt;&lt;sup&gt;[20]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;, yet 	there is lack of clarity on adoption of these national standards, along with the role of international standards like the ones formulated by ISO.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;&lt;b&gt;What is the role of Foreign Governments and bodies in the Smart cities mission?&lt;/b&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Ever since the government's ambitious project has been announced and cities have been shortlisted, many countries across the globe have shown keen interest 	to help specific shortlisted cities in building the smart cities and are willing to invest financially. Countries like Sweden, Malaysia, UAE, USA, etc. 	have agreed to partner with India for the mission.&lt;a href="#_ftn21" name="_ftnref21"&gt;&lt;sup&gt;&lt;sup&gt;[21]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; For example, UK has partnered 	with the Government to develop three India cities-Pune, Amravati and Indore.&lt;a href="#_ftn22" name="_ftnref22"&gt;&lt;sup&gt;&lt;sup&gt;[22]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; Israel's start-up city Tel Aviv also entered into an agreement to help with urban transformation in the Indian cities of Pune, Nagpur and Nashik to foster 	innovation and share its technical know-how.&lt;a href="#_ftn23" name="_ftnref23"&gt;&lt;sup&gt;&lt;sup&gt;[23]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; France has piqued interest for 	Nagpur and Puducherry, while the United States is interested in Ajmer, Vizag and Allahabad. Also, Spain's Barcelona Regional Agency has expressed interest 	in exchanging technology with the Delhi. Apart from foreign government, many organizations and multilateral agencies are also keen to partner with the 	Indian government and have offered financial assistance by way of loans. Some of them include the UK government-owned Department for International 	Development, German government KfW development bank, Japan International Cooperation Agency, the US Trade and Development Agency, United Nations Industrial 	Development Organization and United Nations Human Settlements Programme. &lt;a href="#_ftn24" name="_ftnref24"&gt;&lt;sup&gt;&lt;sup&gt;[24]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;Questions unanswered&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;Do these governments or organization have influence on any other component of the Smart cities?&lt;/li&gt;
&lt;li&gt;How much are the foreign governments and multilateral bodies spending on the respective cities?&lt;/li&gt;
&lt;li&gt;What kind of technical know-how is being shared with the Indian government and cities?&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 style="text-align: justify; "&gt;&lt;b&gt;What is the way ahead?&lt;/b&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;On the basis of the SCP, the MoUD will evaluate, assess the credibility and select 20 smart cities out of the short-listed ones for execution of the plan 	in the first phase. The selected city will set up a SPV and receive funding from the Government.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;Questions unanswered&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;Will the deadline of submission of the Smart Cities Proposal be pushed back?&lt;/li&gt;
&lt;li&gt;After the SCP is submitted on the basis of consultation with the citizens and public, will they be further involved in the implementation of the 	project and what will be their role?&lt;/li&gt;
&lt;li&gt;How will the MoUD and other associated organizations as well as actors consider the implementation realities of the project, like consideration of 	land displacement, rehabilitation of the slum people, etc.&lt;/li&gt;
&lt;li&gt;How are ICT based systems going to be utilized to make the cities and the infrastructure "smart"?&lt;/li&gt;
&lt;li&gt;How is the MoUD going to respond to the concerns and criticism emerging from various sections of the society, as being reflected in the news items?&lt;/li&gt;
&lt;li&gt;How will the smart cities impact and integrate the existing laws, regulations and policies? Does the Government intend to use the existing legislations in entirety, or update and amend the laws for implementation of the Smart Cities Mission?&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: justify; "&gt;&lt;br clear="all" /&gt; 
&lt;hr /&gt;
&lt;div id="ftn1"&gt;
&lt;p&gt;&lt;a href="#_ftnref1" name="_ftn1"&gt;&lt;sup&gt;&lt;sup&gt;[1]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; Smart Cities, Mission Statement and Guidelines, Ministry of Urban Development, Government of India, June 2015, Available at : 			http://smartcities.gov.in/writereaddata/SmartCityGuidelines.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn2"&gt;
&lt;p&gt;&lt;a href="#_ftnref2" name="_ftn2"&gt;&lt;sup&gt;&lt;sup&gt;[2]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://articles.economictimes.indiatimes.com/2015-08-27/news/65929187_1_jammu-and-kashmir-12-cities-urban-development-venkaiah-naidu&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn3"&gt;
&lt;p&gt;&lt;a href="#_ftnref3" name="_ftn3"&gt;&lt;sup&gt;&lt;sup&gt;[3]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://india.gov.in/spotlight/smart-cities-mission-step-towards-smart-india&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn4"&gt;
&lt;p&gt;&lt;a href="#_ftnref4" name="_ftn4"&gt;&lt;sup&gt;&lt;sup&gt;[4]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/Process%20of%20Selection.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn5"&gt;
&lt;p&gt;&lt;a href="#_ftnref5" name="_ftn5"&gt;&lt;sup&gt;&lt;sup&gt;[5]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; Full list : http://www.scribd.com/doc/276467963/Smart-Cities-Full-List&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn6"&gt;
&lt;p&gt;&lt;a href="#_ftnref6" name="_ftn6"&gt;&lt;sup&gt;&lt;sup&gt;[6]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/Process%20of%20Selection.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn7"&gt;
&lt;p&gt;&lt;a href="#_ftnref7" name="_ftn7"&gt;&lt;sup&gt;&lt;sup&gt;[7]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://www.ibtimes.co.in/modi-govt-select-only-10-cities-under-smart-city-project-this-year-report-658888&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn8"&gt;
&lt;p&gt;&lt;a href="#_ftnref8" name="_ftn8"&gt;&lt;sup&gt;&lt;sup&gt;[8]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/Financing%20of%20Smart%20Cities.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn9"&gt;
&lt;p&gt;&lt;a href="#_ftnref9" name="_ftn9"&gt;&lt;sup&gt;&lt;sup&gt;[9]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; Smart Cities presentation by MoUD : http://smartcities.gov.in/writereaddata/Presentation%20on%20Smart%20Cities%20Mission.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn10"&gt;
&lt;p&gt;&lt;a href="#_ftnref10" name="_ftn10"&gt;&lt;sup&gt;&lt;sup&gt;[10]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://indianexpress.com/article/india/india-others/smart-cities-projectfrom-france-to-us-a-rush-to-offer-assistance-funds/&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn11"&gt;
&lt;p&gt;&lt;a href="#_ftnref11" name="_ftn11"&gt;&lt;sup&gt;&lt;sup&gt;[11]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://indianexpress.com/article/india/india-others/funding-for-smart-cities-key-to-coffer-lies-outside-india/#sthash.5lnW9Jsq.dpuf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn12"&gt;
&lt;p&gt;&lt;a href="#_ftnref12" name="_ftn12"&gt;&lt;sup&gt;&lt;sup&gt;[12]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://india.gov.in/spotlight/smart-cities-mission-step-towards-smart-india&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn13"&gt;
&lt;p&gt;&lt;a href="#_ftnref13" name="_ftn13"&gt;&lt;sup&gt;&lt;sup&gt;[13]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/SPVs.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn14"&gt;
&lt;p&gt;&lt;a href="#_ftnref14" name="_ftn14"&gt;&lt;sup&gt;&lt;sup&gt;[14]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/National%20Level%20Monitoring.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn15"&gt;
&lt;p&gt;&lt;a href="#_ftnref15" name="_ftn15"&gt;&lt;sup&gt;&lt;sup&gt;[15]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/State%20Level%20Monitoring.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn16"&gt;
&lt;p&gt;&lt;a href="#_ftnref16" name="_ftn16"&gt;&lt;sup&gt;&lt;sup&gt;[16]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/City%20Level%20Monitoring.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn17"&gt;
&lt;p&gt;&lt;a href="#_ftnref17" name="_ftn17"&gt;&lt;sup&gt;&lt;sup&gt;[17]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://smartcities.gov.in/writereaddata/List_of_Consulting_Firms.pdf&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn18"&gt;
&lt;p&gt;&lt;a href="#_ftnref18" name="_ftn18"&gt;&lt;sup&gt;&lt;sup&gt;[18]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://pib.nic.in/newsite/PrintRelease.aspx?relid=128457&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn19"&gt;
&lt;p&gt;&lt;a href="#_ftnref19" name="_ftn19"&gt;&lt;sup&gt;&lt;sup&gt;[19]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;a href="http://economictimes.indiatimes.com/articleshow/49242050.cms?utm_source=contentofinterest&amp;amp;utm_medium=text&amp;amp;utm_campaign=cppst"&gt; http://economictimes.indiatimes.com/articleshow/49242050.cms?utm_source=contentofinterest&amp;amp;utm_medium=text&amp;amp;utm_campaign=cppst &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn20"&gt;
&lt;p&gt;&lt;a href="#_ftnref20" name="_ftn20"&gt;&lt;sup&gt;&lt;sup&gt;[20]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://www.business-standard.com/article/economy-policy/in-a-first-bis-to-come-up-with-standards-for-smart-cities-115060400931_1.html&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn21"&gt;
&lt;p&gt;&lt;a href="#_ftnref21" name="_ftn21"&gt;&lt;sup&gt;&lt;sup&gt;[21]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://accommodationtimes.com/foreign-countries-have-keen-interest-in-development-of-smart-cities/&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn22"&gt;
&lt;p&gt;&lt;a href="#_ftnref22" name="_ftn22"&gt;&lt;sup&gt;&lt;sup&gt;[22]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://articles.economictimes.indiatimes.com/2015-11-20/news/68440402_1_uk-trade-three-smart-cities-british-deputy-high-commissioner&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn23"&gt;
&lt;p&gt;&lt;a href="#_ftnref23" name="_ftn23"&gt;&lt;sup&gt;&lt;sup&gt;[23]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://www.jpost.com/Business-and-Innovation/Tech/Tel-Aviv-to-help-India-build-smart-cities-435161?utm_campaign=shareaholic&amp;amp;utm_medium=twitter&amp;amp;utm_source=socialnetwork&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn24"&gt;
&lt;p&gt;&lt;a href="#_ftnref24" name="_ftn24"&gt;&lt;sup&gt;&lt;sup&gt;[24]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; http://indianexpress.com/article/india/india-others/smart-cities-projectfrom-france-to-us-a-rush-to-offer-assistance-funds/#sthash.nCMxEKkc.dpuf&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/smart-cities-in-india-an-overview'&gt;https://cis-india.org/internet-governance/blog/smart-cities-in-india-an-overview&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>vanya</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Homepage</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2016-01-11T01:30:07Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-anita-babu-december-23-2015-start-up-india-turns-the-heat-on-facebook-free-basics">
    <title>Start-up India turns the heat on Facebook Free Basics</title>
    <link>https://cis-india.org/internet-governance/news/business-standard-anita-babu-december-23-2015-start-up-india-turns-the-heat-on-facebook-free-basics</link>
    <description>
        &lt;b&gt;Facebook launched its "Save Free Basics" campaign last week, asking users to support "digital equality" in India.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Anita Babu was published in &lt;a class="external-link" href="http://www.business-standard.com/article/companies/start-up-india-turns-the-heat-on-facebook-free-basics-115122300056_1.html"&gt;Business Standard&lt;/a&gt; on December 22, 2015. Pranesh Prakash gave inputs.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="p-content"&gt;Nearly a week after Facebook launched its  controversial "Save Free Basics" campaign in India, the net neutrality  debate has come to the fore again. This time around, India's star  internet entrepreneurs such as Vijay Shekhar Sharma, founder and chief  executive of Paytm, and Dippak Khurana of Vserv have joined the crusade  for free internet.&lt;br /&gt; &lt;br /&gt; "Oh my fellow Indians, either choose this and do a jihad for independent  internet later or pick net neutrality today," Sharma of Paytm, India's  largest digital wallet, tweeted on Tuesday. "Digital world war heads! We  have to load &lt;a href="http://www.savetheinternet.in%20for%20#NetNeutrality" target="_blank"&gt;http://www.savetheinternet.in for #NetNeutrality&lt;/a&gt;,"  said Sharma in another tweet. Savetheinternet.in, a volunteer group,  has urged people to lend their support for an unfettered internet in  India.&lt;br /&gt; &lt;br /&gt; Facebook launched its "Save Free Basics" campaign last week, asking  users to support "digital equality" in India, in response to a paper by  the telecom regulator which is seeking comments on differential pricing  practices like Airtel Zero of Facebook's Free Basics, which was earlier  called Internet.org.&lt;br /&gt; &lt;br /&gt; Facebook launched a print and digital media campaign for a "connected  India" asking users to give a missed call, automatically sending a  message to the regulator in support of Free Basics.&lt;br /&gt; &lt;br /&gt; Facebook has also been asking its users to send an e-mail to Telecom  Regulatory Authority of India (TRAI) supporting "essential internet for  all". The social network claims to have gained support from 3.2 million  of its 130 million users in India.&lt;br /&gt; &lt;br /&gt; On Tuesday, the social media giant earned flak for soliciting support  from international users for the campaign. Later, Facebook withdrew the  campaign outside India claiming it was an "accident".&lt;br /&gt; &lt;br /&gt; However, some net neutrality volunteers said that many of Facebook's 3.2 million supporters for Free Basics were non-Indians.&lt;br /&gt; &lt;br /&gt; Activists and tech leaders are calling the Facebook campaign "misleading" and "destructive".&lt;br /&gt; &lt;br /&gt; "People are being tricked into supporting Free Basics under the guise of  digital equality," wrote Amol Malviya, former chief technology officer  at Flipkart, India's largest e-commerce firm, on his blog. "Notice the  language on the page? It makes any critic of Free Basics appear to be an  enemy of digital equality. People will listen to the critics' arguments  much lesser when there's a question mark on their intent."&lt;br /&gt; &lt;br /&gt; Nikhil Pahwa, editor and publisher of MediaNama, said India should  question the intent of Facebook and its campaign. "There is  misrepresentation in the language they have used. It makes people assume  that we can't have universal internet access without net-neutrality  violating services such as Free Basics. It is important for a country to  take note of how much power a platform with as much reach as Facebook  has to influence an important government process," said Pahwa, who led a  fight against TRAI's move to allow telecom firms charge for internet  services like WhatsApp and Hike.&lt;br /&gt; &lt;br /&gt; The basic premise of net neutrality is that of freedom - an open  internet that protects and enables free communication. Anything that  takes away this freedom violates the fundamentals of free Internet.  "Facebook's Free Basics is neither free nor basic - it is a cleverly  disguised way of walling a garden, and hardly the philanthropic  initiative that it is marketed to be," said Khurana of Vserv. He urged  internet users to uninstall the Facebook App from their mobile phones in  protest.&lt;br /&gt; &lt;br /&gt; Pranesh Prakash, policy director at the Centre for Internet and Society,  said, "Facebook, a foreign company, is allowed to campaign with  impunity, but NGOs receiving funding from foreign trusts are subject to  all manners of restrictions and may not campaign in India." &lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-anita-babu-december-23-2015-start-up-india-turns-the-heat-on-facebook-free-basics'&gt;https://cis-india.org/internet-governance/news/business-standard-anita-babu-december-23-2015-start-up-india-turns-the-heat-on-facebook-free-basics&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Free Basics</dc:subject>
    
    
        <dc:subject>Social Media</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2015-12-29T15:54:30Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/telecom/blog/millions-of-indians-slam-facebooks-2018free-basics2019-app">
    <title>Millions of Indians Slam Facebook's ‘Free Basics’ App </title>
    <link>https://cis-india.org/telecom/blog/millions-of-indians-slam-facebooks-2018free-basics2019-app</link>
    <description>
        &lt;b&gt;It has been less than two months since the nationwide launch of the Free Basics app in India. The smart phone application (formerly known as Internet.org) offers free access to Facebook, Facebook-owned products like WhatsApp, and a select suite of other websites for users who do not pay for mobile data plans.&lt;/b&gt;
        &lt;p&gt;This was published in &lt;a class="external-link" href="https://globalvoices.org/2015/12/29/millions-of-indians-slam-facebooks-free-basics-app/"&gt;Global Voices&lt;/a&gt; on December 29, 2015.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;But the app has already been suspended, at least temporarily, as the Telecommunications Regulatory Authority considers new rules governing network neutrality. Depending on how they're written, the rules could render Free Basics a violation of the policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Free Basics, which has been deployed in 30 developing countries across  the globe, gives users free access to websites that meet Facebook's  technical standards for the application. The application does not give  users access to the Internet at large. For open Internet advocates, this  &lt;a href="http://www.latimes.com/world/asia/la-fg-facebook-marketing-india-20151228-story.html" target="_blank"&gt;undercuts consumer choice&lt;/a&gt; and violates the principle of network neutrality, under which Internet  providers are to treat all Internet traffic equally. Net neutrality  allows users equal access to any website they want to visit, and gives  website operators equal opportunities to attract visitors.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img src="https://cis-india.org/home-images/Polarist.png" alt="Polarist" class="image-inline" title="Polarist" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Facebook has responded to the pending regulation with an &lt;a href="http://techcrunch.com/2015/12/17/save-free-basics/" target="_blank"&gt;aggressive ad campaign&lt;/a&gt; both online and off. Over the last week, Facebook users across India (and &lt;a href="http://www.hindustantimes.com/tech/facebook-is-accidentally-asking-international-users-to-support-free-basics-in-india/story-CV3pyC5KDOnuJozMWLLWeO.html" target="_blank"&gt;some in the US&lt;/a&gt;) upon logging into the site have been greeted with notifications urging them to take action. The &lt;a href="https://www.facebook.com/savefreebasics" target="_blank"&gt;Free Basics&lt;/a&gt; page on Facebook now leads to a pleading form that asks users to contact the &lt;a href="http://www.trai.gov.in/" target="_blank"&gt;Telecom Regulatory Authority of India&lt;/a&gt; (TRAI) and voice their support for making Free Basics available in  India. The company has also purchased a smattering of billboard  advertisements across the country and taken out numerous two-page ads in  leading national newspapers, as seen above.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;The Indian Internet bites back&lt;/h3&gt;
&lt;p&gt;Indian netizens and activists have spoken out against the company's actions en masse, &lt;a href="http://blogs.wsj.com/indiarealtime/2015/12/28/mark-zuckerbergs-latest-bid-to-get-india-on-board-with-free-basics-internet-is-like-a-library/" target="_blank"&gt;protesting&lt;/a&gt; heavily on social media, blogs and newspapers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The grassroots open Internet group, &lt;a href="http://www.savetheinternet.in/" target="_blank"&gt;SavetheInternet.in&lt;/a&gt;,  that has been advocating for net neutrality in India throughout 2015,  has launched an email campaign asking users to send letters to TRAI  explaining how Free Basics violates net neutrality principles and  propagates an inaccurate picture of the Internet for new users by  placing it inside the confines of Facebook's application.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Multiple stand-up comedy groups have created videos explaining the  regulatory debate and supporting net neutrality, which have gone viral:&lt;/p&gt;
&lt;p&gt;&lt;iframe frameborder="0" height="315" src="https://www.youtube.com/embed/AAQWsTFF0BM" width="560"&gt;&lt;/iframe&gt; &lt;br /&gt; Above, the third in a series of videos created by All India Bakchod, in partnership with SavetheInternet.in. Below, a video by East India Comedy.&lt;/p&gt;
&lt;p&gt;&lt;iframe frameborder="0" height="315" src="https://www.youtube.com/embed/UCwaKje44fQ" width="560"&gt;&lt;/iframe&gt; &lt;br /&gt; The issue has also been hotly debated on Twitter, with technology and law experts leading the way.&lt;/p&gt;
&lt;p&gt;Internet policy expert and lead staff member of the Center for Internet and Society in Bengaluru Pranesh Prakash tweeted:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/home-images/PraneshTweet.png" alt="Pranesh Tweet" class="image-inline" title="Pranesh Tweet" /&gt;&lt;/p&gt;
&lt;p&gt;New Delhi-based technology lawyer Mishi Choudhary, who leads the legal team at the Software Freedom Law Center, tweeted:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://cis-india.org/home-images/MishiTweet.png" alt="Mishi" class="image-inline" title="Mishi" /&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Free Software Movement of India, a non-profit promoting use of free  software and its philosophy in India via their local chapters, also has &lt;a href="http://timesofindia.indiatimes.com/tech/tech-news/FSMI-Hyderabad-launches-campaign-against-Free-Basics/articleshow/50341156.cms" target="_blank"&gt;taken&lt;/a&gt;&lt;a href="http://timesofindia.indiatimes.com/tech/tech-news/FSMI-Hyderabad-launches-campaign-against-Free-Basics/articleshow/50341156.cms" target="_blank"&gt; the campaign&lt;/a&gt; to the streets where the volunteers raised public awareness about Free Basic's adverse side.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Apart from local experts and activists, companies like Reddit, Truecaller and Indian e-commerce platform Paytm have &lt;a href="http://mashable.com/2015/12/28/aib-eic-facebook-free-basics/#0Gg8lzzilgqw" target="_blank"&gt;publicly shared&lt;/a&gt; their opposition to Facebook's actions.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Facebook targets open Web activists&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Facebook is paying close attention to civil society opposition to its activities in India. Across the globe, the company's &lt;a href="https://www.facebook.com/savefreebasics"&gt;Free Basics page&lt;/a&gt; now opens to a plea for users to contact TRAI, and includes a statement  that directly targets open Internet advocates, suggesting that their  motives are somehow driven by financial incentives:&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;…Free Basics is in danger in India. A small, vocal group of critics are lobbying to have Free Basics banned on the basis of net neutrality. Instead of giving people access to some basic internet services for free, they demand that people pay equally to access all internet services – even if that means 1 billion people can't afford to access any services.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;SavetheInternet.in explicitly states in their &lt;a href="http://blog.savetheinternet.in/about/" target="_blank"&gt;About page&lt;/a&gt; that they are entirely volunteer-run and have no affiliation with any political party in India or elsewhere.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Users also have tweeted screenshots alleging that Facebook is  restricting access for individuals sending messages opposing Free  Basics. This has not been confirmed, but the tweets have only further  stoked public frustration with the company.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;img src="https://cis-india.org/home-images/copy_of_Facebook.png" alt="Facebook" class="image-inline" title="Facebook" /&gt;&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Zuckerberg vs. SavetheInternet&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;On December 28, Facebook CEO Mark Zuckerberg penned a piece in the Times of India arguing that Free Basics will help “achieve digital equality for India,” and claiming that the initiative “isn’t about Facebook’s commercial interests.” India represents the world's largest market of Internet users after the US and China, where Facebook remains blocked.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In response, Nikhil Pawa, founder of online portal MediaNama and a volunteer with Savetheinternet.in, &lt;a href="http://blogs.timesofindia.indiatimes.com/toi-edit-page/its-a-battle-for-internet-freedom/" target="_blank"&gt;authored&lt;/a&gt; a critical opinion piece in the same newspaper:&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;[…] Why hasn’t Facebook chosen the options that do not violate Net Neutrality? For example, in India, Aircel has begun providing full internet access for free at 64 kbps download speed for the first three months….In Bangladesh, Grameenphone users get free data in exchange for watching an advertisement. In Africa, Orange users get 500 MB of free access on buying a $37 handset…&lt;br /&gt;&lt;br /&gt; […]&lt;br /&gt;&lt;/blockquote&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;Facebook is being disingenuous — as disingenuous as the company’s promotional programmes for Free Basics to its Indian users — when it says that Free Basics is in conformity with Net Neutrality.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;Pawa also quoted Naveen Patnaik, Chief Minister of Indian state of Odisha, who wrote to TRAI supporting net neutrality. “If you dictate what the poor should get, you take away their right to choose what they think is best for them,” he wrote.&lt;/p&gt;
&lt;p class="callout" style="text-align: justify; "&gt;“If you dictate what the poor should get, you take away their right to choose what they think is best for them.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Writing for Quartz, technology critic &lt;a href="http://qz.com/582587/mark-zuckerberg-cant-believe-india-isnt-grateful-for-facebooks-free-internet/" target="_blank"&gt;Alice Truong expressed similar sentiment:&lt;/a&gt; “Zuckerberg almost portrays net neutrality as a first-world problem  that doesn’t apply to India because having some service is better than  no service.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For Mahesh Murthy, an Indian venture capitalist and self-described net neutrality activist, it all comes down to revenue. &lt;a href="http://thewire.in/2015/12/26/facebook-is-misleading-indians-with-its-full-page-ads-about-free-basics-17971/"&gt;On the Wire,&lt;/a&gt; Murthy offered untempered criticism of Facebook and Zuckerberg's efforts to appease the country's leaders:&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;[..] Unlike Facebook, who tried to silently slime this thing through last year when it was called Internet.org, and then are spending about Rs. 100 crores on ads – a third of its India revenue? – to try and con us Indians this year again. This is after we’d worked hard to ban these kind of products, technically called “zero rating apps” last year.[..] This Facebook ad [spread] doesn’t include the full-on Mark Zuckerberg love event put up for our Prime Minister when he visited the US, aimed again at greasing the way for this Free Basics thing through our government.&lt;/blockquote&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/telecom/blog/millions-of-indians-slam-facebooks-2018free-basics2019-app'&gt;https://cis-india.org/telecom/blog/millions-of-indians-slam-facebooks-2018free-basics2019-app&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>subha</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Free Basics</dc:subject>
    
    
        <dc:subject>Social Media</dc:subject>
    
    
        <dc:subject>Telecom</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2015-12-30T14:37:09Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/eight-key-privacy-events-in-india-in-the-year-2015">
    <title>Eight Key Privacy Events in India in the Year 2015</title>
    <link>https://cis-india.org/internet-governance/blog/eight-key-privacy-events-in-india-in-the-year-2015</link>
    <description>
        &lt;b&gt;As the year draws to a close, we are enumerating some of the key privacy related events in India that transpired in 2015. Much like the last few years, this year, too, was an eventful one in the context of privacy.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;While we did not witness, as one had hoped, any progress in the passage of a privacy law, the year saw significant developments with respect to the ongoing 	Aadhaar case. The statement by the Attorney General, India's foremost law officer, that there is a lack of clarity over whether the right to privacy is a fundamental right, and the fact the the matter is yet unresolved was a huge setback to the jurisprudence on privacy.	&lt;a href="#_ftn1" name="_ftnref1"&gt;[1]&lt;/a&gt; However, the court has recognised a purpose limitation as applicable into the Aadhaar scheme, limiting 	the sharing of any information collected during the enrollment of residents in UID. A draft Encryption Policy was released and almost immediately withdrawn 	in the face of severe public backlash, and an updated Human DNA Profiling Bill was made available for comments. Prime Minister Narendra Modi's much 	publicised project "Digital India" was in news throughout the year, and it also attracted its' fair share of criticism in light of the lack of privacy 	safeguards it offered. Internationally, a lawsuit brought by Maximilian Schrems, an Austrian privacy activist, dealt a body blow to the fifteen year old 	Safe Harbour Framework in place for data transfers between EU and USA. Below, we look at what were, according to us, the eight most important privacy 	events in India, in 2015.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;1. &lt;/b&gt; &lt;b&gt;August 11, 2015 order on Aadhaar not being compulsory&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In 2012, a writ petition was filed by Judge K S Puttaswamy challenging the government's policy in its attempt to enroll all residents of India in the UID 	project and linking the Aadhaar card with various government services. A number of other petitioners who filed cases against the Aadhaar scheme have also 	been linked with this petition and the court has been hearing them together. On September 11, 2015, the Supreme Court reiterated its position in earlier orders made on September 23, 2013 and March 24, 2014 stating that the Aadhaar card shall not be made compulsory for any government services.	&lt;a href="#_ftn2" name="_ftnref2"&gt;[2]&lt;/a&gt; Building on its earlier position, the court passed the following orders:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;a) The government must give wide publicity in the media that it was not mandatory for a resident to obtain an Aadhaar card,&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;b) The production of an Aadhaar card would not be a condition for obtaining any benefits otherwise due to a citizen,&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;c) Aadhaar card would not be used for any purpose other than the PDS Scheme, for distribution of foodgrains and cooking fuel such as kerosene and for the 	LPG distribution scheme.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;d) The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except 	as may be directed by a Court for the purpose of criminal investigation.&lt;a href="#_ftn3" name="_ftnref3"&gt;[3]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Despite this being the fifth court order given by the Supreme Court&lt;a href="#_ftn4" name="_ftnref4"&gt;[4]&lt;/a&gt; stating that the Aadhaar card cannot 	be a mandatory requirement for access to government services or subsidies, repeated violations continue. One of the violations which has been widely 	reported is the continued requirement of an Aadhaar number to set up a Digital Locker account which also led to activist, Sudhir Yadav filing a petition in 	the Supreme Court.&lt;a href="#_ftn5" name="_ftnref5"&gt;[5]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;2. &lt;/b&gt; &lt;b&gt;No Right to Privacy - Attorney General to SC&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Attorney General, Mukul Rohatgi argued before the Supreme Court in the Aadhaar case that the Constitution of India did not provide for a fundamental 	Right to Privacy.&lt;a href="#_ftn6" name="_ftnref6"&gt;[6]&lt;/a&gt; He referred to the body of case in the Supreme Court dealing with this issue and made a 	reference to the 1954 case, MP Sharma v. Satish Chandra&lt;a href="#_ftn7" name="_ftnref7"&gt;[7]&lt;/a&gt; stating that there was "clear divergence of 	opinion" on the Right to Privacy and termed it as "a classic case of unclear position of law." He also referred to the discussion on this matter in the 	Constitutional Assembly Debates and pointed to the fact the framers of the Constitution did not intend for this to be a fundamental right. He said the 	matter needed to be referred to a nine judge Constitution bench.&lt;a href="#_ftn8" name="_ftnref8"&gt;[8]&lt;/a&gt; This raises serious questions over the 	jurisprudence developed by the Supreme Court on the right to privacy over the last five decades. The matter is currently pending resolution by a larger 	bench which needs to be constituted by the Chief Justice of India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;3. &lt;/b&gt; &lt;b&gt;Shreya Singhal judgment and Section 69A, IT Act&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the much celebrated judgment, Shreya Singhal v. Union of India, in March 2015, the Supreme Court struck down Section 66A of the Information Technology 	Act, 2000 as unconstitutional and laid down guidelines for online takedowns under the Internet intermediary rules. However, significantly, the court also 	upheld Section 69A and the blocking rules under this provision. It was held to be a narrowly-drawn provision with adequate safeguards. The rules prescribe 	a procedure for blocking which involves receipt of a blocking request, examination of the request by the Committee and a review committee which performs 	oversight functions. However, commentators have pointed to the opacity of the process in the rules under this provisions. While the rules mandate that a 	hearing is given to the originator of the content, this safeguard is widely disregarded. The judgment did not discuss Section 69 of the Information 	Technology Act, 2000 which deal with decrypting of electronic communication, however, the Department of Electronic and Information Technology brought up 	this issue subsequently, through a Draft Encryption Policy, discussed below.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;4. &lt;/b&gt; &lt;b&gt;Circulation and recall of Draft Encryption Policy&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On October 19, 2015, the Department of Electronic and Information Technology (DeitY) released for public comment a draft National Encryption Policy. The draft received an immediate and severe backlash from commentators, and was withdrawn by September 22, 2015.	&lt;a href="#_ftn9" name="_ftnref9"&gt;[9]&lt;/a&gt; The government blamed a junior official for the poor drafting of the document and noted that it had been 	released without a review by the Telecom Minister, Ravi Shankar Prasad and other senior officials.&lt;a href="#_ftn10" name="_ftnref10"&gt;[10]&lt;/a&gt; The 	main areas of contention were a requirement that individuals store plain text versions of all encrypted communication for a period of 90 days, to be made 	available to law enforcement agencies on demand; the government's right to prescribe key-strength, algorithms and ciphers; and only government-notified 	encryption products and vendors registered with the government being allowed to be used for encryption.&lt;a href="#_ftn11" name="_ftnref11"&gt;[11]&lt;/a&gt; The purport of the above was to limit the ways in which citizens could encrypt electronic communication, and to allow adequate access to law enforcement 	agencies. The requirement to keep all encrypted information in plain text format for a period of 90 days garnered particular criticism as it would allow 	for creation of a 'honeypot' of unencrypted data, which could attract theft and attacks.&lt;a href="#_ftn12" name="_ftnref12"&gt;[12]&lt;/a&gt; The withdrawal of the draft policy is not the final chapter in this story, as the Telecom Minister has promised that the Department will come back with a revised policy.	&lt;a href="#_ftn13" name="_ftnref13"&gt;[13]&lt;/a&gt; This attempt to put restrictions on use of encryption technologies is not only in line with a host of 	surveillance initiatives that have mushroomed in India in the last few years,&lt;a href="#_ftn14" name="_ftnref14"&gt;[14]&lt;/a&gt; but also finds resonance with a global trend which has seen various governments and law enforcement organisations argue against encryption.	&lt;a href="#_ftn15" name="_ftnref15"&gt;[15]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;5. &lt;/b&gt; &lt;b&gt;Privacy concerns raised about Digital India&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Digital India initiative includes over thirty Mission Mode Projects in various stages of implementation.	&lt;a href="#_ftn16" name="_ftnref16"&gt;[16]&lt;/a&gt; All of these projects entail collection of vast quantities of personally identifiable information of 	the citizens. However, most of these initiatives do not have clearly laid down privacy policies.&lt;a href="#_ftn17" name="_ftnref17"&gt;[17]&lt;/a&gt; There 	is also a lack of properly articulated access control mechanisms and doubts over important issues such as data ownership owing to most projects involving public private partnership which involves private organisation collecting, processing and retaining large amounts of data.	&lt;a href="#_ftn18" name="_ftnref18"&gt;[18]&lt;/a&gt; Ahead of Prime Minister Modi's visit to the US, over 100 hundred prominent US based academics released a statement raising concerns about "lack of safeguards about privacy of information, and thus its potential for abuse" in the Digital India project.	&lt;a href="#_ftn19" name="_ftnref19"&gt;[19]&lt;/a&gt; It has been pointed out that the initiatives could enable a "cradle-to-grave digital identity that is unique, lifelong, and authenticable, and it plans to widely use the already mired in controversy Aadhaar program as the identification system."	&lt;a href="#_ftn20" name="_ftnref20"&gt;[20]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;6. &lt;/b&gt; &lt;b&gt;Issues with Human DNA Profiling Bill, 2015&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Human DNA Profiling Bill, 2015 envisions the creation of national and regional DNA databases comprising DNA profiles of the categories of persons 	specified in the Bill.&lt;a href="#_ftn21" name="_ftnref21"&gt;[21]&lt;/a&gt; The categories include offenders, suspects, missing persons, unknown deceased 	persons, volunteers and such other categories specified by the DNA Profiling Board which has oversight over these banks. The Bill grants wide discretionary powers to the Board to introduce new DNA indices and make DNA profiles available for new purposes it may deem fit.	&lt;a href="#_ftn22" name="_ftnref22"&gt;[22]&lt;/a&gt; These, and the lack of proper safeguards surrounding issues like consent, retention and collection 	pose serious privacy risks if the Bill becomes a law. Significantly, there is no element of purpose limitation in the proposed law, which would allow the 	DNA samples to be re-used for unspecified purposes.&lt;a href="#_ftn23" name="_ftnref23"&gt;[23]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;7. &lt;/b&gt; &lt;b&gt;Impact of the Schrems ruling on India&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In Schrems v. Data Protection Commissioner, the Court of Justice in European Union (CJEU) annulled the Commission Decision 2000/520 according to which US 	data protection rules were deemed sufficient to satisfy EU privacy rules enabling transfers of personal data from EU to US, otherwise known as the 'Safe 	Harbour' framework. The court ruled that broad formulations of derogations on grounds of national security, public interest and law enforcement in place in 	the US goes beyond the test of proportionality and necessity under the Data Protection rules.&lt;a href="#_ftn24" name="_ftnref24"&gt;[24]&lt;/a&gt; This 	judgment could also have implications for the data processing industry in India. For a few years now, a framework similar to the Safe Harbour has been 	under discussion for transfer of data between India and EU. The lack of a privacy legislation has been among the significant hurdles in arriving at a 	framework.&lt;a href="#_ftn25" name="_ftnref25"&gt;[25]&lt;/a&gt; In the absence of a Safe Harbour framework, the companies in India rely on alternate 	mechanisms such as Binding Corporate Rules (BCR) or Model Contractual Clauses. These contracts impose the obligation on the data exporters and importers to 	ensure that 'adequate level of data protection' is provided. The Schrems judgement makes it clear that 'adequate level of data protection' entails a regime 	that is 'essentially equivalent' to that envisioned under Directive 95/46.&lt;a href="#_ftn26" name="_ftnref26"&gt;[26]&lt;/a&gt; What this means is that any 	new framework of protection between EU and other countries like US or India will necessarily have to meet this test of essential equivalence. The PRISM 	programme in the US and a host of surveillance programmes that have been initiated by the government in India in the last few years could pose problems in 	satisfying this test of essential equivalence as they do not conform to the proportionality and necessity principles.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;8. &lt;/b&gt; &lt;b&gt;The definition of "unfair trade practices" in the Consumer Protection Bill, 2015&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Consumer Protection Bill, 2015, tabled in the Parliament towards the end of the monsoon session&lt;a href="#_ftn27" name="_ftnref27"&gt;[27]&lt;/a&gt; has 	introduced an expansive definition of the term "unfair trade practices." The definition as per the Bill includes the disclosure "to any other person any 	personal information given in confidence by the consumer."&lt;a href="#_ftn28" name="_ftnref28"&gt;[28]&lt;/a&gt; This clause exclude from the scope of unfair 	trade practices, disclosures under provisions of any law in force or in public interest. This provision could have significant impact on the personal data 	protection law in India. Currently, the only law governing data protection law are the Reasonable security practices and procedures and sensitive personal 	data or information Rules, 2011&lt;a href="#_ftn29" name="_ftnref29"&gt;[29]&lt;/a&gt; prescribed under Section 43A of the Information Technology Act, 2000. Under these rules, sensitive personal data or information is protected in that their disclosure requires prior permission from the data subject.	&lt;a href="#_ftn30" name="_ftnref30"&gt;[30]&lt;/a&gt; For other kinds of personal information not categorized as sensitive personal data or information, the only recourse of data subjects in case to claim breach of the terms of privacy policy which constitutes a lawful contract.	&lt;a href="#_ftn31" name="_ftnref31"&gt;[31]&lt;/a&gt; The Consumer Protection Bill, 2015, if enacted as law, could significantly expand the scope of 	protection available to data subjects. First, unlike the Section 43A rules, the provisions of the Bill would be applicable to physical as well as 	electronic collection of personal information. Second, disclosure to a third party of personal information other than sensitive personal data or 	information could also have similar 'prior permission' criteria under the Bill, if it can be shown that the information was shared by the consumer in 	confidence.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What we see above are events largely built around a few trends that we have been witnessing in the context of privacy in India, in particular and across 	the world, in general. Lack of privacy safeguards in initiatives like the Aadhaar project and Digital India is symptomatic of policies that are not 	comprehensive in their scope, and consequently fail to address key concerns. Dr Usha Ramanathan has called these policies "powerpoint based policies" which are implemented based on proposals which are superficial in their scope and do not give due regard to their impact on a host of issues.	&lt;a href="#_ftn32" name="_ftnref32"&gt;[32]&lt;/a&gt; Second, the privacy concerns posed by the draft Encryption Policy and the Human DNA Profiling Bill point to the motive of surveillance that is in line with other projects introduced with the intent to protect and preserve national security.	&lt;a href="#_ftn33" name="_ftnref33"&gt;[33]&lt;/a&gt; Third, the incidents that championed the cause of privacy like the Schrems judgment have largely been 	initiated by activists and civil society actors, and have typically entailed the involvement of the judiciary, often the single recourse of actors in the 	campaign for the protection of civil rights. It must be noted that jurisprudence on the right to privacy in India has not moved beyond the guidelines set 	forth by the Supreme Court in PUCL v. Union of India.&lt;a href="#_ftn34" name="_ftnref34"&gt;[34]&lt;/a&gt; However, new mass surveillance programmes and 	massive collection of personal data by both public and private parties through various schemes mandated a re-look at the standards laid down twenty years 	ago. The privacy issue pending resolution by a larger bench in the Aadhaar case affords an opportunity to revisit those principles in light of how 	surveillance has changed in the last two decades and strengthen privacy and data protection.&lt;/p&gt;
&lt;div style="text-align: justify; "&gt;
&lt;hr /&gt;
&lt;div id="ftn1"&gt;
&lt;p&gt;&lt;a href="#_ftnref1" name="_ftn1"&gt;&lt;sup&gt;&lt;sup&gt;[1]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Right to Privacy not a fundamental right, cannot be invoked to scrap Aadhar: Centre tells Supreme Court, available at 			&lt;a href="http://articles.economictimes.indiatimes.com/2015-07-23/news/64773078_1_fundamental-right-attorney-general-mukul-rohatgi-privacy"&gt; http://articles.economictimes.indiatimes.com/2015-07-23/news/64773078_1_fundamental-right-attorney-general-mukul-rohatgi-privacy &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn2"&gt;
&lt;p&gt;&lt;a href="#_ftnref2" name="_ftn2"&gt;&lt;sup&gt;&lt;sup&gt;[2]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; SC allows govt to link Aadhaar card with PDS and LPG subsidies, available at 			&lt;a href="http://timesofindia.indiatimes.com/india/SC-allows-govt-to-link-Aadhaar-card-with-PDS-and-LPG-subsidies/articleshow/48436223.cms"&gt; http://timesofindia.indiatimes.com/india/SC-allows-govt-to-link-Aadhaar-card-with-PDS-and-LPG-subsidies/articleshow/48436223.cms &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn3"&gt;
&lt;p&gt;&lt;a href="#_ftnref3" name="_ftn3"&gt;&lt;sup&gt;&lt;sup&gt;[3]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://judis.nic.in/supremecourt/imgs1.aspx?filename=42841"&gt;http://judis.nic.in/supremecourt/imgs1.aspx?filename=42841&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn4"&gt;
&lt;p&gt;&lt;a href="#_ftnref4" name="_ftn4"&gt;&lt;sup&gt;&lt;sup&gt;[4]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Five SC Orders Later, Aadhaar Requirement Continues to Haunt Many, available at 			&lt;a href="http://thewire.in/2015/09/19/five-sc-orders-later-aadhaar-requirement-continues-to-haunt-many-11065/"&gt; http://thewire.in/2015/09/19/five-sc-orders-later-aadhaar-requirement-continues-to-haunt-many-11065/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn5"&gt;
&lt;p&gt;&lt;a href="#_ftnref5" name="_ftn5"&gt;[5]&lt;/a&gt; Digital Locker scheme challenged in Supreme Court, available at 			&lt;a href="http://www.moneylife.in/article/digital-locker-scheme-challenged-in-supreme-court/42607.html"&gt; http://www.moneylife.in/article/digital-locker-scheme-challenged-in-supreme-court/42607.html &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn6"&gt;
&lt;p&gt;&lt;a href="#_ftnref6" name="_ftn6"&gt;&lt;sup&gt;&lt;sup&gt;[6]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Privacy not a fundamental right, argues Mukul Rohatgi for Govt as Govt affidavit says otherwise, available at 			&lt;a href="http://www.legallyindia.com/Constitutional-law/privacy-not-a-fundamental-right-argues-mukul-rohatgi-for-govt-as-govt-affidavit-says-otherwise"&gt; http://www.legallyindia.com/Constitutional-law/privacy-not-a-fundamental-right-argues-mukul-rohatgi-for-govt-as-govt-affidavit-says-otherwise &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn7"&gt;
&lt;p&gt;&lt;a href="#_ftnref7" name="_ftn7"&gt;&lt;sup&gt;&lt;sup&gt;[7]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; 1954 SCR 1077.&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn8"&gt;
&lt;p&gt;&lt;a href="#_ftnref8" name="_ftn8"&gt;&lt;sup&gt;&lt;sup&gt;[8]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Supra Note 1.&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn9"&gt;
&lt;p&gt;&lt;a href="#_ftnref9" name="_ftn9"&gt;&lt;sup&gt;&lt;sup&gt;[9]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Government to withdraw draft encryption policy, available at 			&lt;a href="http://www.thehindu.com/news/national/govt-to-withdraw-draft-encryption-policy/article7677348.ece"&gt; http://www.thehindu.com/news/national/govt-to-withdraw-draft-encryption-policy/article7677348.ece &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn10"&gt;
&lt;p&gt;&lt;a href="#_ftnref10" name="_ftn10"&gt;&lt;sup&gt;&lt;sup&gt;[10]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Encryption policy poorly worded by officer: Telecom Minister Ravi Shankar Prasad, available at 			&lt;a href="http://economictimes.indiatimes.com/articleshow/49068406.cms?utm_source=contentofinterest&amp;amp;utm_medium=text&amp;amp;utm_campaign=cppst"&gt; http://economictimes.indiatimes.com/articleshow/49068406.cms?utm_source=contentofinterest&amp;amp;utm_medium=text&amp;amp;utm_campaign=cppst &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn11"&gt;
&lt;p&gt;&lt;a href="#_ftnref11" name="_ftn11"&gt;&lt;sup&gt;&lt;sup&gt;[11]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Updated: India's draft encryption policy puts user privacy in danger, available at 			&lt;a href="http://www.medianama.com/2015/09/223-india-draft-encryption-policy/"&gt; http://www.medianama.com/2015/09/223-india-draft-encryption-policy/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn12"&gt;
&lt;p&gt;&lt;a href="#_ftnref12" name="_ftn12"&gt;&lt;sup&gt;&lt;sup&gt;[12]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Bhairav Acharya, The short-lived adventure of India's encryption policy, available at 			&lt;a href="http://notacoda.net/2015/10/10/the-short-lived-adventure-of-indias-encryption-policy/"&gt; http://notacoda.net/2015/10/10/the-short-lived-adventure-of-indias-encryption-policy/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn13"&gt;
&lt;p&gt;&lt;a href="#_ftnref13" name="_ftn13"&gt;&lt;sup&gt;&lt;sup&gt;[13]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Supra Note 9.&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn14"&gt;
&lt;p&gt;&lt;a href="#_ftnref14" name="_ftn14"&gt;&lt;sup&gt;&lt;sup&gt;[14]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Maria Xynou, Big democracy, big surveillance: India's surveillance state, available at 			&lt;a href="https://www.opendemocracy.net/opensecurity/maria-xynou/big-democracy-big-surveillance-indias-surveillance-state"&gt; https://www.opendemocracy.net/opensecurity/maria-xynou/big-democracy-big-surveillance-indias-surveillance-state &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn15"&gt;
&lt;p&gt;&lt;a href="#_ftnref15" name="_ftn15"&gt;&lt;sup&gt;&lt;sup&gt;[15]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; China passes controversial anti-terrorism law to access encrypted user accounts, available at 			&lt;a href="http://www.theverge.com/2015/12/27/10670346/china-passes-law-to-access-encrypted-communications"&gt; http://www.theverge.com/2015/12/27/10670346/china-passes-law-to-access-encrypted-communications &lt;/a&gt; ; Police renew call against encryption technology that can help hide terrorists, available at 			&lt;a href="http://www.washingtontimes.com/news/2015/nov/16/paris-terror-attacks-renew-encryption-technology-s/?page=all"&gt; http://www.washingtontimes.com/news/2015/nov/16/paris-terror-attacks-renew-encryption-technology-s/?page=all &lt;/a&gt; .&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn16"&gt;
&lt;p&gt;&lt;a href="#_ftnref16" name="_ftn16"&gt;&lt;sup&gt;&lt;sup&gt;[16]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://www.mmp.cips.org.in/digital-india/"&gt;http://www.mmp.cips.org.in/digital-india/&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn17"&gt;
&lt;p&gt;&lt;a href="#_ftnref17" name="_ftn17"&gt;[17]&lt;/a&gt; &lt;a href="http://slides.com/cisindia/big-data-in-indian-governance-preliminary-findings#/"&gt; http://slides.com/cisindia/big-data-in-indian-governance-preliminary-findings#/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn18"&gt;
&lt;p&gt;&lt;a href="#_ftnref18" name="_ftn18"&gt;&lt;sup&gt;&lt;sup&gt;[18]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Indira Jaising, Digital India Schemes Must Be Preceded by a Data Protection and Privacy Law, available at 			&lt;a href="http://thewire.in/2015/07/04/digital-india-schemes-must-be-preceded-by-a-data-protection-and-privacy-law-5471/"&gt; http://thewire.in/2015/07/04/digital-india-schemes-must-be-preceded-by-a-data-protection-and-privacy-law-5471/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn19"&gt;
&lt;p&gt;&lt;a href="#_ftnref19" name="_ftn19"&gt;&lt;sup&gt;&lt;sup&gt;[19]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; US academics raise privacy concerns over 'Digital India' campaign, available at			&lt;a href="http://yourstory.com/2015/08/us-digital-india-campaign/"&gt;http://yourstory.com/2015/08/us-digital-india-campaign/&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn20"&gt;
&lt;p&gt;&lt;a href="#_ftnref20" name="_ftn20"&gt;&lt;sup&gt;&lt;sup&gt;[20]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Lisa Hayes, Digital India's Impact on Privacy: Aadhaar numbers, biometrics, and more, available at 			&lt;a href="https://cdt.org/blog/digital-indias-impact-on-privacy-aadhaar-numbers-biometrics-and-more/"&gt; https://cdt.org/blog/digital-indias-impact-on-privacy-aadhaar-numbers-biometrics-and-more/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn21"&gt;
&lt;p&gt;&lt;a href="#_ftnref21" name="_ftn21"&gt;&lt;sup&gt;&lt;sup&gt;[21]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://www.prsindia.org/uploads/media/draft/Draft%20Human%20DNA%20Profiling%20Bill%202015.pdf"&gt; http://www.prsindia.org/uploads/media//draft/Draft%20Human%20DNA%20Profiling%20Bill%202015.pdf &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn22"&gt;
&lt;p&gt;&lt;a href="#_ftnref22" name="_ftn22"&gt;&lt;sup&gt;&lt;sup&gt;[22]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Comments on India's Human DNA Profiling Bill (June 2015 version), available at 			&lt;a href="http://www.genewatch.org/uploads/f03c6d66a9b354535738483c1c3d49e4/IndiaDNABill_FGPI_15.pdf"&gt; http://www.genewatch.org/uploads/f03c6d66a9b354535738483c1c3d49e4/IndiaDNABill_FGPI_15.pdf &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn23"&gt;
&lt;p&gt;&lt;a href="#_ftnref23" name="_ftn23"&gt;&lt;sup&gt;&lt;sup&gt;[23]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Elonnai Hickok, Vanya Rakesh and Vipul Kharbanda, CIS Comments and Recommendations to the Human DNA Profiling Bill, June 2015, available at 			&lt;a href="http://cis-india.org/internet-governance/blog/cis-comments-and-recommendations-to-human-dna-profiling-bill-2015"&gt; http://cis-india.org/internet-governance/blog/cis-comments-and-recommendations-to-human-dna-profiling-bill-2015 &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn24"&gt;
&lt;p&gt;&lt;a href="#_ftnref24" name="_ftn24"&gt;&lt;sup&gt;&lt;sup&gt;[24]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://curia.europa.eu/jcms/upload/docs/application/pdf/2015-10/cp150117en.pdf"&gt; http://curia.europa.eu/jcms/upload/docs/application/pdf/2015-10/cp150117en.pdf &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn25"&gt;
&lt;p&gt;&lt;a href="#_ftnref25" name="_ftn25"&gt;&lt;sup&gt;&lt;sup&gt;[25]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Jyoti Pandey, Contestations of Data, ECJ Safe Harbor Ruling and Lessons for India, available at 			&lt;a href="http://cis-india.org/internet-governance/blog/contestations-of-data-ecj-safe-harbor-ruling-and-lessons-for-india"&gt; http://cis-india.org/internet-governance/blog/contestations-of-data-ecj-safe-harbor-ruling-and-lessons-for-india &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn26"&gt;
&lt;p&gt;&lt;a href="#_ftnref26" name="_ftn26"&gt;&lt;sup&gt;&lt;sup&gt;[26]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Simon Cox, Case Watch: Making Sense of the Schrems Ruling on Data Transfer, available at 			&lt;a href="https://www.opensocietyfoundations.org/voices/case-watch-making-sense-schrems-ruling-data-transfer"&gt; https://www.opensocietyfoundations.org/voices/case-watch-making-sense-schrems-ruling-data-transfer &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn27"&gt;
&lt;p&gt;&lt;a href="#_ftnref27" name="_ftn27"&gt;&lt;sup&gt;&lt;sup&gt;[27]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://www.prsindia.org/billtrack/the-consumer-protection-bill-2015-3965/"&gt; http://www.prsindia.org/billtrack/the-consumer-protection-bill-2015-3965/ &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn28"&gt;
&lt;p&gt;&lt;a href="#_ftnref28" name="_ftn28"&gt;&lt;sup&gt;&lt;sup&gt;[28]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Section 2(41) (I) of the Consumer Protection Bill, 2015.&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn29"&gt;
&lt;p&gt;&lt;a href="#_ftnref29" name="_ftn29"&gt;&lt;sup&gt;&lt;sup&gt;[29]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://www.ijlt.in/pdffiles/IT-(Reasonable%20Security%20Practices)-Rules-2011.pdf"&gt; http://www.ijlt.in/pdffiles/IT-%28Reasonable%20Security%20Practices%29-Rules-2011.pdf &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn30"&gt;
&lt;p&gt;&lt;a href="#_ftnref30" name="_ftn30"&gt;&lt;sup&gt;&lt;sup&gt;[30]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Rule 6 of Reasonable security practices and procedures and sensitive personal data or information Rules, 2011&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn31"&gt;
&lt;p&gt;&lt;a href="#_ftnref31" name="_ftn31"&gt;&lt;sup&gt;&lt;sup&gt;[31]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Rule 4 of Reasonable security practices and procedures and sensitive personal data or information Rules, 2011&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn32"&gt;
&lt;p&gt;&lt;a href="#_ftnref32" name="_ftn32"&gt;&lt;sup&gt;&lt;sup&gt;[32]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; &lt;a href="http://cis-india.org/internet-governance/events/communication-rights-in-the-age-of-digital-technology"&gt; http://cis-india.org/internet-governance/events/communication-rights-in-the-age-of-digital-technology &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn33"&gt;
&lt;p&gt;&lt;a href="#_ftnref33" name="_ftn33"&gt;&lt;sup&gt;&lt;sup&gt;[33]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Supra Note 11.&lt;/p&gt;
&lt;/div&gt;
&lt;div id="ftn34"&gt;
&lt;p&gt;&lt;a href="#_ftnref34" name="_ftn34"&gt;&lt;sup&gt;&lt;sup&gt;[34]&lt;/sup&gt;&lt;/sup&gt;&lt;/a&gt; &lt;sup&gt; &lt;/sup&gt; Chaitanya Ramachandra, PUCL V. Union of India Revisited: Why India's Sureveillance Law must be redesigned for the Digital Age, available at 			&lt;a href="http://nujslawreview.org/wp-content/uploads/2015/10/Chaitanya-Ramachandran.pdf"&gt; http://nujslawreview.org/wp-content/uploads/2015/10/Chaitanya-Ramachandran.pdf &lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/eight-key-privacy-events-in-india-in-the-year-2015'&gt;https://cis-india.org/internet-governance/blog/eight-key-privacy-events-in-india-in-the-year-2015&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Amber Sinha</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2016-01-03T05:43:42Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>




</rdf:RDF>
