<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 581 to 595.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/news/nlsir-december-21-2013-nlsir-symposium"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/internet-monitor-2013-malavika-jayaram-indias-identity-crisis"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/privacy/privacy-cloud-computing"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/data-retention-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/privacy-highlights-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/workshop-on-urban-data-inequality-and-justice-in-the-global-south"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-news-minute-shilpa-s-ranipeta-june-10-2019-no-fintech-company-meets-every-single-privacy-requirement-under-it-act-cis-report"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-wire-mira-swaminathan-and-shweta-reddy-july-20-2019-old-isnt-always-gold-face-app-and-its-privacy-policies"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/bis-litd-17-meeting"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/observer-research-foundation-shashidhar-kj-and-kashish-parpiani-july-22-2019-easing-the-us-india-divergence-on-data-localisation"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/the-wire-shweta-mohandas-july-30-2019-in-india-privacy-policies-of-fintech-companies-pay-lip-service-to-user-rights"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/samyukta-prabhu-ambika-tandon-torsha-sarkar-and-aayush-rathi-august-4-2019-comments-on-national-digital-health-blueprint"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/digital-id-forum-2019"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/national-stakeholders-consultation-on-the-national-digital-health-blueprint"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/ietf-105"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/news/nlsir-december-21-2013-nlsir-symposium">
    <title>VII NLSIR Symposium</title>
    <link>https://cis-india.org/news/nlsir-december-21-2013-nlsir-symposium</link>
    <description>
        &lt;b&gt;The National Law School of India Review (NLSIR) - the flagship journal of the National Law School of India University (NLSIU), Bangalore is pleased to announce the seventh NLSIR Symposium on “Bridging the Security-Liberty Divide” scheduled to be held on December 21 and December 22, 2013 at the National Assessment and Accreditation Council (NAAC, opposite NLSIU Campus, Nagarhavi) Conference Hall, Bangalore.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;This was &lt;a class="external-link" href="http://nlsir.in/symposium.html"&gt;published by NLSIR&lt;/a&gt; on December 20, 2013.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The decade following September 11 has been dubbed “liberty’s lost decade”, not just for the United States of America but for the world at large, marked by increasing tension between State interests in national security and individual liberty. As we continue to grapple with the implications of this clash, one clear winner seems to be emerging, best observed by examining changes in legal systems throughout this decade. The recent upsurge of criticism against NSA activity globally, however, could be seen as indicative of a changing trend. The VIIth NLSIR Symposium seeks to trace this dialogue between competing notions of security and liberty, and hopes to assess and analyse similar developments in India Confirmed speakers for the symposium include renowned legal experts such as Hon’ble Justice Muralidhar, Menaka Guruswamy, Mrinal Satish, Bharat Karnad, Aparna Chandra, Chinmayi Arun, Shyam Diwan, Bhairav Acharya, Roshni, Yug Mohit Chaudhary and Saikat Datta.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This year, the discussions will be divided into four panels:&lt;br /&gt;&lt;br /&gt; &lt;b&gt;Session I: Securing Liberty from the State - Redefining Criminal Thresholds in Law &lt;/b&gt;&lt;br /&gt; (Forenoon, December 21, 2013, Saturday)&lt;br /&gt;&lt;br /&gt; &lt;b&gt;Session II: Intrusive Intelligence - Surveillance Programs and Privacy in India &lt;/b&gt;&lt;br /&gt; (Afternoon, December 21, 2013, Saturday)&lt;br /&gt;&lt;br /&gt; &lt;b&gt;Session III: Beyond Borders - Extradition, Asylum and Concerns of State Security &lt;/b&gt;&lt;br /&gt; (Forenoon, December 22, 2013, Sunday)&lt;br /&gt;&lt;br /&gt; &lt;b&gt;Session IV: Connecting the Dots &lt;/b&gt;&lt;br /&gt; (Afternoon, December 22, 2013, Sunday)&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/nlsir-december-21-2013-nlsir-symposium'&gt;https://cis-india.org/news/nlsir-december-21-2013-nlsir-symposium&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-01-09T07:08:33Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/internet-monitor-2013-malavika-jayaram-indias-identity-crisis">
    <title>India's Identity Crisis</title>
    <link>https://cis-india.org/internet-governance/blog/internet-monitor-2013-malavika-jayaram-indias-identity-crisis</link>
    <description>
        &lt;b&gt;Malavika Jayaram's article was published in 2013 Internet Monitor Annual Report: Reflections on the Digital World, published by Harvard's Berkman Center for Internet and Society.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;India’s Unique Identity (UID) project is already the world’s largest biometrics identity program, and it is still growing. Almost 530 million people have been registered in the project database, which collects all ten fingerprints, iris scans of both eyes, a photograph, and demographic information for each registrant. Supporters of the project tout the UID as a societal game changer. The extensive biometric information collected, they argue, will establish the uniqueness of each individual, eliminate fraud, and provide the identity infrastructure needed to develop solutions for a range of problems. Despite these potential benefits, however, critical concerns remain about the UID’s legal and physical architecture as well as about unforeseen risks associated with the linking and analysis of personal data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The most basic concerns regarding the UID project stem from the fact that biometric technologies have never been tested on such a large population. As a result, well-founded concerns exist around scalability, false acceptance and rejection rates, and the project’s core premise that biometrics can uniquely and unambiguously identify people in a foolproof manner. Some of these concerns are based on technical issues—collecting fingerprints and iris scans “in the field,” for instance, can be complicated when a registrant’s fingerprints are eroded by manual labor or her irises are affected by malnutrition and cataracts. Other concerns relate to the project’s federated implementation architecture, which, by outsourcing collection to a massive group of private and public registrars and operators, increases the chance for data breaches, error, and fraud.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Perhaps even more vexing are concerns regarding how the UID, which promises financial inclusion (by reducing the identification barriers to opening bank accounts, for example), might in fact lead to new types of exclusion for already marginalized groups. Members of the LGBT community, for instance, question whether the inclusion of the transgender category within the UID scheme is a laudable attempt at inclusion, or a new means of listing and targeting members of their community for exclusion. More fundamentally, as more and more services and benefits are linked to the UID, the project threatens to exclude all those who cannot or will not participate in the scheme due to logistical failures or philosophical objections.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is worth noting that the UID is not the only large data project in India. A slew of “Big Brother” projects exist: the Centralised Monitoring System (CMS), the Telephone Call Interception System (TCIS), the National Population Register (NPR), the Crime and Criminal Tracking Network and Systems (CCTNS), and the National Intelligence Grid (NATGRID), which is working to aggregate up to 21 different databases relating to tax, rail and air travel, credit card transactions, immigration, and other domains. The UID is intended to serve as a common identifier across these databases, creating a massive surveillance state. It also facilitates an ecosystem where access to goods and services, from government subsidies to drivers’ licenses to mobile phones to cooking gas, increasingly requires biometric authentication.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UID project was originally vaunted as voluntary, but the inexorable slippery slope toward compulsory participation has triggered a series of lawsuits challenging the legality of forced enrollment and the constitutionality of the entire project. Most recently, in September 2013, India’s federal Supreme Court affirmed by way of an interim decision that the UID was not mandatory, that not possessing a UID should not disadvantage anybody, and that citizenship should be ascertained as a criteria for registering in order to ensure that UIDs are not issued to illegal immigrants. This last stipulation is particularly thorny given that the Unique Identification Authority of India (UIDAI, the body in charge of the UID project) has consistently distanced the UID from questions of citizenship under the justification that it is a matter beyond their remit (i.e., the UID is open to residents, and is not linked to citizenship). The government moved quickly to urge a modification of the order, but the Supreme Court declined to do so and will instead release its final decision after it reviews a batch of petitions from activists and others. The UIDAI approached the court, arguing that not making the UID mandatory has serious consequences for welfare schemes, but the court recently ordered the federal government, the Reserve Bank of India, and the Election Commission to delink the LPG cooking gas scheme from the UID. This is a considerable setback for the project, given that this was one of the most hyped linkages for the UID. It remains to be seen whether the court will similarly halt other attempts to make the UID mandatory.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the meantime, the UID project is effectively being implemented in a legal vacuum without support from the Supreme Court or Parliament. The Cabinet is seeking to rectify this and has cleared a bill that would finally provide legal backing for the UID program—its previous attempt was rejected by the Standing Committee on Finance in 2010. This bill is scheduled to come up for debate during the winter session of Parliament. The bill’s progress, along with the final decision of the Supreme Court, will have far reaching consequences for the UID project’s implementation and longevity, as well as for the relationship between India’s citizens and the state.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;If fully implemented, the UID system will fundamentally alter the way in which citizens interact with the government by creating a centrally controlled, technology-based standard that mediates access to social services and benefits, financial systems, telecommunications, and governance. It will undoubtedly also have implications for how citizens relate to private sector entities, on which the UID rests and which have their own vested interests in the data. The success or failure of the UID represents a critical moment for India. Whatever course the country takes, its decision to travel further toward or turn away from becoming a “database nation” will have implications for democracy, free speech, and economic justice within its own borders and also in the many neighboring countries that look to it as a technological standard bearer.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Indian government seems to envision “big data” as a panacea for fraud, corruption, and abuse, but it has given little attention to understanding and addressing the fraud, corruption, and abuse that massive databases can themselves engender. The government’s actions have yet to demonstrate an appreciation for the fact that the matrix of identity and surveillance schemes it has implemented can create a privacy-invading technology layer that is not only a barrier to online activity but also to social participation writ large.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The lack of identification documents for a large portion of the Indian population does need to be addressed. Whether the UID project is the best means to do this—whether it has the right architecture and design, whether it can succeed without an overhaul of several other failures of governmental institutions, and whether fixing the identity piece alone causes more harm than good—should be the subject of intense debate and scrutiny. Only through rigorous threat modeling and analysis of the risks arising out of this burgeoning “data industrial complex” can steps be taken to stem the potential repercussions of the project not just for identity management, fraud, corruption, distributive justice, and welfare generally, but also for autonomy, openness, and democracy.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;a href="https://cis-india.org/internet-governance/blog/internet-monitor-2013.pdf" class="internal-link"&gt;Click to download the article published in the annual report of Berkman's Center for Internet and Society &lt;/a&gt;(PDF 7223 Kb)&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/internet-monitor-2013-malavika-jayaram-indias-identity-crisis'&gt;https://cis-india.org/internet-governance/blog/internet-monitor-2013-malavika-jayaram-indias-identity-crisis&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>malavika</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-01-09T07:56:08Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/privacy/privacy-cloud-computing">
    <title>Privacy, Free/Open Source, and the Cloud </title>
    <link>https://cis-india.org/internet-governance/blog/privacy/privacy-cloud-computing</link>
    <description>
        &lt;b&gt;A look into the questions that arise in concern to privacy and cloud computing, and how open source plays into the picture. &lt;/b&gt;
        
&lt;h3&gt;Introduction&lt;/h3&gt;
&lt;p&gt;Cloud computing, in basic terms,&amp;nbsp; is internet-based computing where shared resources and services are taken from the primary infrastructure of the internet and provided on demand. Cloud computing creates a shared network between major corporations like Google, Microsoft, Amazon and Yahoo. In this way, cloud systems are related to grid computing systems/service- oriented architectures, and create the potential for the entire I.T. infrastructure to be programmable. Because of this, cloud computing establishes a new consumption and delivery standard for IT services based on the internet. It is a new consumption and delivery model, because it is made up of services delivered through common centers and built on servers which act as a point of access for the computing needs of consumers.&amp;nbsp; The access points facilitate the tailoring and delivering of targeted applications and services to consumers.&amp;nbsp; Details are taken from the users, who no longer need to have an understanding of, or control over the technology infrastructure in the cloud that supports their desired application.&lt;/p&gt;
&lt;p&gt;There are both corporate and consumer implications for such a system. For example, according cloud computing lowers the barriers to entry for corporations and new services. It also enables innovative enterprise in locations where there is an insufficient supply of human or other resources through the provision of inexpensive hardware, software, and applications. The consumer, in turn, is provided with information that he or she is projected to be interested in based on information he or she has already “consumed.”&amp;nbsp; Thus, for example: Google has the ability to monitor a person’s consuming habits through searches and to reduce those habits to a pattern which selects applications to display – and consumption of those reinforces the pattern.&lt;/p&gt;
&lt;h3&gt;Privacy Concerns:&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;Though cloud computing can be a useful tool for&amp;nbsp; consumers, corporations, and countries, cloud computing poses significant privacy concerns for all actors involved. For the consumer, a major concern is that future business models may rely on the use of personal data from consumers of cloud services for advertising or behavioral targeting. This concern brings to light the fundamental problem of cloud computing which is that consumers consent to the secondary use of their personal data only when they are signing up for services, and that “consent” is almost automatically generated. How can the cloud assure users that their private data will be properly protected? It is true that high levels of encryption can be (and are) used, and that many companies also take other precautionary measures, but protective measures vary, and the secondary sources that gain access to information may not protect it as well as the initial source.&amp;nbsp; Moreover, even strong protection measures are vulnerable to hackers. As well, what happens if a jurisdiction, like the Indian government, gains access to information about a foreign national?&amp;nbsp;&amp;nbsp; India still does not have a comprehensive data protection law, nor does it have many forms of redress for violations of privacy. How is that individuals information protected?&lt;/p&gt;
&lt;p&gt;These questions give rise to other privacy concerns with respect to the data that is circulated and stored on the cloud, which are the questions of territory, sovereignty, and regulation. Many of these were brought up at the Internet Governance Forum, which took place on the 16th of September including: Which jurisdiction has authority in cases of dispute or digital crime? If you lose data or your data is damaged, stolen, or manipulated, where do you go? Is the violation enforced under local laws, and, if so, under the law of the violator or the law of the violated?&amp;nbsp; If international law, who can access the tribunals, and which tribunals have this jurisdiction?&amp;nbsp; What if a person's data is replicated in two data centres in two different countries? &amp;nbsp;Are the data subject to scrutiny by the officials of all three?&amp;nbsp; Is there a remedy against abuse by any of them?&amp;nbsp; Does it matter whether the country in which the data centre resides does not require a warrant for government access?&amp;nbsp; And how will a consumer know any of that up front?&amp;nbsp; As a corollary, if content is being sent to one country but resides on a data centre in another country, whose data protection standards apply?&amp;nbsp; For example, certain governments in Europe require data retention for limited amount of time for purposes for law enforcement, but other countries may allow retention of data for shorter or longer periods of time.&lt;/p&gt;
&lt;h3&gt;How are privacy, free/open source, and the cloud related ?&lt;/h3&gt;
&lt;p&gt;Eben Moglen, a professor from Columbia law school, and founder and chairman of the Software Freedom Law Center who spoke on cloud computing, privacy, and free/open software at the Indian Institute for science on Thursday September 25, had another solution to the privacy concerns that arise out of the cloud. His lecture explains how the internet has moved from a tool that once promoted equality between people – no servants and no masters – to a tool that reinforces social hierarchies. The reinforcement of these hierarchies is directly related to the language used and communication facilitated between the computer and the individual.&amp;nbsp; Professor Moglen describes how initially, when computers were first introduced to the public, humans spoke directly to computers, and computers responded directly to humans. This open, two-way communication changed when Microsoft, Apple, and IBM removed the language between humans and computers and created proprietary software based on a server-client computing relationship. By removing the language between humans and computers, these corporations dis-empowered individuals. Professor Moglen used this as a springboard to address the privacy concerns that come up in cloud computing. Privacy at its base is the ability of an individual to control access to various aspects of self, such as decisional, informational, and locational. In having the ability to control these factors, privacy consists of a relation between a person and another person or an entity. Professor Moglen postulated that free/open access to code would make the internet an environment where choices over that relationship were still in the hands of an individual, and, among other protections, the individuals could build up their desired levels of privacy.&lt;/p&gt;
&lt;h3&gt;Is free/open software the solution?&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;Eben Moglen's solution to the many privacy concerns that arise out of cloud computing is the application and use of free software/open source by individuals.&amp;nbsp; Unlike some applications on the cloud, open source is free, and once an individual has access to the code, that person can control how a program functions, including how a program uses personal information, and thus the person would be able to protect their privacy. Of course, this presumes that the consumer of the internet is sophisticated enough to access and manipulate code.&amp;nbsp; But even putting that presumption aside, is the ability to write code enough to protect data (will help you protect data better – add more security)?&amp;nbsp; Perhaps if a person could create his own server and bypass the cloud, but this does not seem like an ideal (or practical) solution. Though free/open source is an important element that should be incorporated into cloud computing, free/open source depends on open standards.&amp;nbsp;According to Pranesh Prakash, in his presentation at the Internet Governance Forum, the role of standards in ensuring interoperability is critical to allowing consumers to choose between different devices to access the cloud, to choose between different software clients, and to shift between one service and another. This would include moving information, both the data and the metadata, from one cloud to another. Clouds would need to be able to talk to one another to enable data sharing, and open source is key to this, though it is important to note that if one uses free/open source, they must set up their own infrastructure.&lt;/p&gt;
&lt;h3&gt;Conclusion&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;Even though Moglen believes that free/open source software brings freedom and provides the solution to protect an individual’s privacy in the context of cloud computing, he was not speaking to the specific context of India. To do that, it is important to expand the definitions that one uses of free/open source and privacy, and then to contextualize them.&amp;nbsp; Looking closely at the words “free/open source,” they are not limited to access to a software's code, even though that is free/open source’s base.&amp;nbsp; For the ideology of free/open source to work, access to code is just a key to the puzzle. A person, community, culture and state must understand the purpose of free/open source, know how to use it,&amp;nbsp; and know how it can be applied in order for it to be transformative, liberating, and protective. There needs to be a shared understanding that free/open source is&amp;nbsp; not just about being able to change code, but about a shared commitment to sharing code and making it transparent and accessible. In the United States and other countries,&amp;nbsp; free/open source did not just enter into American society and immediately fix issues of&amp;nbsp; privacy by bringing freedom, as it seems Professor Moglen is suggesting free/open source will do in India.&amp;nbsp;&amp;nbsp;&amp;nbsp; Though Professor Moglen promises freedom and privacy protection through free/open source, perhaps this is not an honest appraisal of the technology.&amp;nbsp; Free/open source, if not equally accessed or misapplied, protects neither freedom nor privacy.&amp;nbsp; As noted above, even if a person has access to code, he can protect data only to a certain extent.&amp;nbsp; Thus, he might think that he has created a privacy wall around information that actually is readily accessible.&amp;nbsp; In other words, free/open source cannot be the only answer to freedom, but instead a piece to a collective answer.&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/privacy/privacy-cloud-computing'&gt;https://cis-india.org/internet-governance/blog/privacy/privacy-cloud-computing&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Openness</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-03-22T05:50:10Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/data-retention-in-india">
    <title>Data Retention in India</title>
    <link>https://cis-india.org/internet-governance/blog/data-retention-in-india</link>
    <description>
        &lt;b&gt;As part of its privacy research, the Centre for Internet and Society has been researching upon data retention mandates from the Government of India and data retention practices by service providers. Globally, data retention has become a contested practice with regards to privacy, as many governments require service providers to retain more data for extensive time periods, for security purposes. Many argue that the scope of the retention is becoming disproportional to the purpose of investigating crimes. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;The Debate around Data Retention&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;According to the EU, data retention &lt;i&gt;“refers to the storage of traffic and location data resulting from electronic communications (not data on the content of the communications)”&lt;/i&gt;.&lt;a href="#fn1" name="fr1"&gt;[1]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The debate around data retention has many sides, and walks a fine line of balancing necessity with proportionality. For example, some argue that the actual retention of data is not harmful, and at least some data retention is necessary to assist law enforcement in investigations. Following this argument, the abuse of information is not found in the retention of data, but instead is found by who accesses the data and how it is used. Others argue that any blanket or &lt;i&gt;a priori &lt;/i&gt;data&lt;i&gt; &lt;/i&gt;retention requirements are increasingly becoming disproportional and can lead to harm and misuse. When discussing data retention it is also important to take into consideration what type of data is being collected and by what standard is access being granted. Increasingly, governments are mandating that service providers retain communication metadata for law enforcement purposes. The type of authorization required to access retained communication metadata varies from context to context. However, it is often lower than what is required for law enforcement to access the contents of communications. The retention and lower access standards to metadata is controversial because metadata can encompass a wide variety of information, including IP address, transaction records, and location information — all of which can reveal a great deal about an individual.&lt;a href="#fn2" name="fr2"&gt;[2] &lt;/a&gt;Furthermore, the definition of metadata changes and evolves depending on the context and the type of information being generated by new technologies.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Data Retention vs. Data Preservation&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Countries have taken different stances on what national standards for data retention by service providers should be. For example, in 2006 the EU passed the Data Retention Directive which requires European Internet Service Providers to retain telecom and Internet traffic data from customers' communications for at least six months and upto two years. The stored data can be accessed by authorized officials for law enforcement purposes.&lt;a href="#fn3" name="fr3"&gt;[3]&lt;/a&gt; Despite the fact that the Directive pertains to the whole of Europe, in 2010 the German Federal Constitutional Court annulled the law that harmonized German law with the Data Retention Directive.&lt;a href="#fn4" name="fr4"&gt;[4]&lt;/a&gt; Other European countries that have refused to adopt the Directive include the Czech Republic and Romania.&lt;a href="#fn5" name="fr5"&gt;[5]&lt;/a&gt; Instead of mandating the retention of data, Germany, along with the US, mandates the 'preservation' of data. The difference being that the preservation of data takes place through a specified request by law enforcement, with an identified data set. In some cases, like the US, after submitting a request for preservation, law enforcement must obtain a court order or subpoena for further access to the preserved information.&lt;a href="#fn6" name="fr6"&gt;[6]&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Data Retention in India&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;In India, the government has established a regime of data retention. Retention requirements for service providers are found in the ISP and UASL licenses, which are grounded in the Indian Telegraph Act, 1885.&lt;/p&gt;
&lt;h3&gt;ISP License&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;According to the ISP License,&lt;a href="#fn7" name="fr7"&gt;[7]&lt;/a&gt; there are eight categories of records that service providers are required to retain for security purposes that pertain to customer information or transactions. In some cases the license has identified how long records must be maintained, and in other cases the license only states that the records must be made available and provided. This language implies that records will be kept.&lt;/p&gt;
&lt;p&gt;According to the ISP License, each ISP must maintain:&lt;b&gt;&lt;span&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;span&gt; &lt;/span&gt;
&lt;li&gt;&lt;span&gt;&lt;b&gt;&lt;span&gt;Users and Services&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;: A log of all users connected and the service they are using, which must be available in real time to the Telecom Authority. (Section 34.12).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;&lt;b&gt;&lt;span&gt;Outward Logins or Telnet&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;: A log of every outward login or telnet through an ISPs computer must be available in real time to the Telecom Authority. (Section 34.12).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Packets&lt;/span&gt;:&lt;/span&gt;&lt;/b&gt; Copies of all packets originating from the Customer Premises Equipment of the ISP must be available in real time to the Telecom Authority. (Section 34.12).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Subscribers&lt;/span&gt;:&lt;/span&gt;&lt;/b&gt; A complete list of subscribers must be made available on the ISP website with password controlled access, available to authorized Intelligence Agencies at any time. (Section 34.12).&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Internet Leased Line Customers&lt;/span&gt;:&lt;/span&gt;&lt;/b&gt; A complete list of Internet leased line customers and their sub-customers consisting of the following information: name of customer, IP address allotted, bandwidth provided, address of installation, date of installation/commissioning, and contact person with phone no./email. These must be made available on a password protected website (Section 34.14).  The password and login ID must be provided to the DDG (Security), DoT HQ and concerned DDG(VTM) of DoT on a monthly basis. The information should also be accessible to authorized government agencies (Section 34.14).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Diagram Records and Reasons&lt;/span&gt;:&lt;/span&gt;&lt;/b&gt; A record of complete network diagram of set-up at each of the internet leased line customer premises along with details of connectivity must be made available at the site of the service provider. All details of other communication links (PSTN, NLD, ILD, WLL, GSM, other ISP) plus reasons for taking the links by the customer must be recorded before the activation of the link. These records must be readily available for inspection at the respective premises of all internet leased line customers (Section 34.18).&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; 
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Commercial Records&lt;/span&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; All commercial records with regard to the communications exchanged on the network must be maintained for a year (Section 34.23).&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Location&lt;/span&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt; The service provider should be able to provide the geographical location of any subscriber at a given point of time (Section 34.28(x).&lt;/p&gt;
&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;span&gt; &lt;/span&gt;
&lt;li style="text-align: justify; "&gt;&lt;span&gt; &lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;Remote Activities&lt;/span&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; A complete audit trail of the remote access activities pertaining to the network operated in India. These must be retained for a period of six months, and must be provided on request to the licensor or any other agency authorized by the licensor (Section 34.28 (xv).&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;UASL License&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;According to the UASL License&lt;a href="#fn8" name="fr8"&gt;[8]&lt;/a&gt;, &lt;span&gt;there are twelve categories of records that ISP’s are required to retain that pertain to costumer information or transactions for security purposes. In some cases the license has identified how long records must be maintained, and in other cases the license only states that the information must be provided and made available when requested. This language implies that records will be kept. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;According to the license, service providers must maintain and make available: &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Numbers&lt;/span&gt;&lt;/span&gt;&lt;span&gt;: &lt;/span&gt;&lt;/b&gt;&lt;span&gt;Called/calling party mobile/PSTN numbers when required. Telephone numbers of any call-forwarding feature when required (Section 41.10).&lt;/span&gt;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; &lt;b&gt;&lt;span&gt;&lt;span&gt;Interception records: &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;Time, date and duration of interception when required (Section 41.10).&lt;/span&gt;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; 
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Location:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; Location of target subscribers. For the present, cell ID should be provided for location of the target subscriber when required (Section 41.10).&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;All call records:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; All call data records handled by the system when required (Section 41.10). This includes:&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Failed call records:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; Call data records of failed call attempts when required. (Section 41.10).&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Roaming subscriber records&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;: Call data records of roaming subscribers when required. (Section 41.10)&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Commercial records: &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;All commercial records with regards to the communications exchanged on the network must be retained for one year (Section 41.17).&lt;/span&gt;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; &lt;b&gt;&lt;span&gt;&lt;span&gt;Outgoing call records: &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;A record of checks made on outgoing calls completed by customers who are making large outgoing calls day and night to various customers (Section 41.19(ii)).&lt;/span&gt;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; &lt;b&gt;&lt;span&gt;&lt;span&gt;Calling line Identification:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; A list of subscribers including address and details using calling line identification should be kept in a password protected website accessible to authorized government agencies (Section 41.19 (iv)).&lt;/span&gt;&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; 
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span&gt;&lt;span&gt;Location:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt; The service provider must be able to provide the geographical location of any subscriber at any point of time (Section 41.20(x)).&lt;/span&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li style="text-align: justify; "&gt; &lt;b&gt;&lt;span&gt;&lt;span&gt;Remote access activities:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;Complete audit trail of the remote access activities pertaining to the network operated in India for a period of six months (Section&lt;span&gt; &lt;/span&gt;41.20 (xv)).&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;RTI Request to &lt;a href="https://cis-india.org/internet-governance/blog/bsnl-rti" class="internal-link"&gt;BSNL&lt;/a&gt; and &lt;a href="https://cis-india.org/internet-governance/blog/mtnl-rti-request.pdf" class="internal-link"&gt;MTNL&lt;/a&gt;&lt;span&gt; &lt;/span&gt;&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;On September 10,&lt;sup&gt;&lt;/sup&gt; 2012, the Centre for Internet and Society sent an RTI to MTNL and BSNL with the following questions related to the respective data retention practices: &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
&lt;ul type="disc"&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Does      MTNL/BSNL store the following information/data:&lt;/span&gt;&lt;/li&gt;
&lt;ul type="circle"&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Text       message detail (To and from cell numbers, timestamps)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Text       message content (The text and/or data content of the SMS or MMS)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Call       detail records (Inbound and outbound phone numbers, call duration)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Bill       copies for postpaid and recharge/top-up billing details for prepaid&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Location       data (Based on cell tower, GPS, Wi-Fi hotspots or any combination       thereof)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;If it      does store data then&lt;/span&gt;&lt;/li&gt;
&lt;ul type="circle"&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;For what       period does MTNL/BSNL store: SMS and MMS messages, cellular and mobile       data, customer data?&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;What       procedures for retention does MTNL/BSNL have for: SMS and MMS messages,       cellular and mobile data, and customer data?&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;What       procedures for deletion of: SMS and MMS messages, cellular and mobile       data, and customer data?&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;What       security procedures are in place for SMS and MMS messages, cellular and       mobile data, and customer data?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;h3&gt;BSNL Response&lt;/h3&gt;
&lt;p&gt;BSNL replied by stating that it stores at least three types of information including:&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;ol type="1"&gt;
&lt;li style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;IP session information -      connection start end time, bytes in and out (three years offline)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;MAC address of the modem/router/device (three years offline)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal"&gt;&lt;span&gt;Bill copies for post paid and recharge/top up billing details      for prepaid. Billing information of post paid Broadband are available in      CDR system under ITPC, prepaid voucher details (last six months).&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;MTNL Response&lt;/h3&gt;
&lt;p&gt;MTNL replied by stating that it stores at least () types of information including:&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;ol type="1"&gt;
&lt;li class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;Text message details (to and from cell number, timestamps) in      the form of CDRs&lt;span&gt; &lt;/span&gt;(one year)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;Call detail records including inbound and outbound phone      numbers and call duration (one year)&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;Bill copies from postpaid (one year) &lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;Recharge details for prepaid (three months) &lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;Location of the mobile number if it has used the MTNL      GSM/3GCDMA network (one year)&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;It is interesting that BSNL stores information that is beyond the required time period required in both the ISP and the UASL licenses. The responses to the RTI showed that each service provider also stores different types of information. This could or could not be the actual case, as each question could have been interpreted differently by the responding officer.&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;span&gt;&lt;span&gt;Conclusion &lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt; &lt;span&gt;The responses to the RTI from BSNL and MTNL are a step towards understanding data retention practices in India, but there are still many aspects about data retention in India which are unclear including:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;What constitutes a ‘commercial record’ which must be stored for one year by service providers?&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;How much data is retained by service providers on an annual basis?&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;What is the cost involved in retaining data? For the service provider? For the public?&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;How frequently is retained information accessed by law enforcement? What percentage of the data is accessed by law enforcement?&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;How many criminal and civil cases rely on retained data?&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;What is the authorization process for access to retained records? Are these standards for access the same for all types of retained data?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;Having answers to these questions would be useful for determining if the Indian data retention regime is proportional and effective. It would also be useful in determining if it would be meaningful to maintain a regime of data retention or switch over to a more targeted regime of data preservation. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;Though it can be simple to say that a regime of data preservation is the most optimal choice as it gives the individual the greatest amount of immediate privacy protection, &lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;A regime of data preservation would mean that all records would be treated like an interception, where the police or security agencies would need to prove that a crime was going to take place or is in the process of taking place and then request the ISP to begin retaining specific records. This approach to solving crime would mean that the police would never use retained data or historical data as part of an investigation – to either solve a case or to take the case to the next level.&lt;span&gt; &lt;/span&gt;If Indian law enforcement is at a point where they are able to concisely identify a threat and then begin an investigation is a hard call to make. It is also important to note that though preservation of data can reduce the risk to individual privacy as it is not possible for law enforcement to track individuals based off of their historical data and access large amounts of data about an individual, preservation does not mean that there is no possibility for abuse. Other factors such as:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;Any request for preservation and access to records must be legitimate and proportional&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Accessed and preserved records must be used only for the purpose indicated &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;Accessed and preserved records can only be shared with authorized authorities&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;Any access to preserved records that do not pertain to an investigation must be deleted &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-align:justify; "&gt;&lt;span&gt;These factors must be enforced through the application of penalties for abuse of the system. These factors can also be applied to not only a data preservation regime, but also a data retention regime and are focused on preventing the actual abuse of data after retained. That said, before an argument for either data retention or data preservation can be made for India it is important to understand more about data retention practices in India and use of retained data by Indian law enforcement and access controls in place. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr1" name="fn1"&gt;1&lt;/a&gt;].&lt;span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;European Commission – Press  Release. Commission Takes Germany to Court Requesting that Fines be  Imposed. May 31st 2012. Available at:  &lt;a class="external-link" href="http://bit.ly/14qXW6o"&gt;http://bit.ly/14qXW6o&lt;/a&gt;. Last accessed:  January 21st 2013&lt;br /&gt;[&lt;a href="#fr2" name="fn2"&gt;2&lt;/a&gt;].Draft International Principles on Communications Surveillance and Human Rights: &lt;a class="external-link" href="http://bit.ly/UpGA3D"&gt;http://bit.ly/UpGA3D&lt;/a&gt;&lt;br /&gt;[&lt;a href="#fr3" name="fn3"&gt;3&lt;/a&gt;]. European Commission – Press Release. Commission Takes Germany to Court Requesting that Fines be Imposed. May 31&lt;sup&gt;st&lt;/sup&gt; 2012. Available at:  &lt;a class="external-link" href="http://bit.ly/14qXW6o"&gt;http://bit.ly/14qXW6o&lt;/a&gt;&lt;a href="http://europa.eu/rapid/press-release_IP-12-530_en.htm"&gt;&lt;/a&gt;. Last accessed: January 21&lt;sup&gt;st&lt;/sup&gt; 2013.&lt;br /&gt;[&lt;a href="#fr4" name="fn4"&gt;4&lt;/a&gt;]. European Commission – Press Release. Commission Takes Germany to Court Requesting that Fines be Imposed. May 31&lt;sup&gt;st&lt;/sup&gt; 2012. Available at:  &lt;a class="external-link" href="http://bit.ly/14qXW6o"&gt;http://bit.ly/14qXW6o&lt;/a&gt;. Last accessed: January 21&lt;sup&gt;st&lt;/sup&gt; 2013.&lt;br /&gt;[&lt;a href="#fr5" name="fn5"&gt;5&lt;/a&gt;]. Tiffen, S. Sweden passes controversial data retention directive. DW. March 22 2012. Available at: &lt;a class="external-link" href="http://bit.ly/WOfzaX"&gt;http://bit.ly/WOfzaX&lt;/a&gt;. Last Accessed: January 21&lt;sup&gt;st&lt;/sup&gt; 2013.&lt;br /&gt;[&lt;a href="#fr6" name="fn6"&gt;6&lt;/a&gt;].  Kristina, R. The European Union's Data Retention Directive and the  United State's Data Preservation Laws: Fining the Better Model. 5  Shilder J.L. Com. &amp;amp; Tech. 13 (2009) available at: &lt;a class="external-link" href="http://bit.ly/VoQxQ9"&gt;http://bit.ly/VoQxQ9&lt;/a&gt;. Last accessed: January 21&lt;sup&gt;st&lt;/sup&gt; 2013&lt;br /&gt;[&lt;a href="#fr7" name="fn7"&gt;7&lt;/a&gt;].  Government of India. Ministry of Communications &amp;amp; IT Department of  Telecommunications. License Agreement for Provision of Internet  Services.&lt;br /&gt;[&lt;a href="#fr8" name="fn8"&gt;8&lt;/a&gt;].  Government of India. Ministry of Communications &amp;amp; IT Department of  Telecommunications. License Agreement for Provision of Unified Access  Services after Migration from CMTS. Amended December 3&lt;sup&gt;rd&lt;/sup&gt; 2009.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/data-retention-in-india'&gt;https://cis-india.org/internet-governance/blog/data-retention-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T15:51:13Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/privacy-highlights-in-india">
    <title>2012: Privacy Highlights in India</title>
    <link>https://cis-india.org/internet-governance/privacy-highlights-in-india</link>
    <description>
        &lt;b&gt;In this blog post, Elonnai Hickok summarizes the top privacy moments of 2012 in India. In doing so she lists out the major ones like the Report of Group of Experts on Privacy, the RIM Standoff, the Nira Radia controversy, the Centralized Monitoring System, Unmanned Aerial Vehicles, NATGRID, CCTNS, the growth of CCTVs, the leaked DNA Profiling Bill, and the UID project.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;&lt;b&gt;The Report of Group of Experts on Privacy:&lt;/b&gt; In October 2012 the "Report of Group of Experts on Privacy" was published by a governmental committee chaired by Justice A.P. Shah. The report contains recommendations for comprehensive privacy legislation, including defining nine privacy principles, establishing a regulatory framework consisting of privacy commissioners at the regional and central level, and self regulatory organizations, and analyzing the present challenges to privacy in India.&lt;a href="#fn1" name="fr1"&gt;[1]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Before the report was published, two draft privacy bills had been leaked to the public, and a concept paper drafted in 2010. The report received mixed reviews from the media, including questions about the relationship between the Right to Information and the Right to Privacy. Before the publishing of the Report, Prime Minister Manmohan Singh recognized that disclosures under the RTI Act could, in some instances, violate individual privacy. In a statement to the public, the Prime Minister stated &lt;i&gt;"citizens&lt;ins cite="mailto:Author" datetime="2012-11-16T15:34"&gt;’&lt;/ins&gt; right to know should definitely be circumscribed if disclosure of information encroaches upon someone's personal privacy.  But where to draw the line is a complicated question"&lt;/i&gt;.&lt;a href="#fn2" name="fr2"&gt;[2]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Three months before the report was published, the EU had publicly stated that current data protection provisions in India are not sufficient enough, and that India is not considered to be 'data secure'.&lt;a href="#fn3" name="fr3"&gt;[3]&lt;/a&gt; If the recommendations in the report are turned into legislation, among other things, individuals in India will have a right to privacy and a right to redress for violations of privacy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Governmental Interception&lt;/b&gt;: In early 2013 it was revealed that the Ministry of Home Affairs ordered interception of 10,000 phones and 1300 email ids during October 2012 to December 2012.&lt;a href="#fn4" name="fr4"&gt;[4]&lt;/a&gt; Continuing its efforts to access all communications, in May 2012, the Government of India gave service providers a month to develop a method for intercepting calls using VoIP services.&lt;a href="#fn5" name="fr5"&gt;[5]&lt;/a&gt; In February 2012 the Telecom Department proposed a new set of security guidelines that would allow for real time interception of communications and the tracking of the location of users. Among other things, the proposal establishes telecom security assurance and testing labs for the purpose of testing and certifying telecom equipment.&lt;a href="#fn6" name="fr6"&gt;[6]&lt;/a&gt; Additionally, in October of 2012, Bharti Airtel refused to wiretap telephones for RAW. The Department of Telecommunications eventually ordered Bharti Airtel to comply with the order, which they did.&lt;a href="#fn7" name="fr7"&gt;[7]&lt;/a&gt; The events around interception in 2012 show that the Indian government is still trying to gain access to as much information as possible. The constant push for real time access by the government is concerning, as many safeguards are missing from the Indian interception regime such as, penalty to security agencies for unauthorized interception and avenues of redress for the individual.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The RIM Standoff&lt;/b&gt;: Since 2008, the Indian government has been negotiating with RIM access to BlackBerry communications. Over the years, a number of solutions have been proposed by RIM and the GoI, yet a final agreement was never reached. Continuing the negotiations, In October 2012, RIM agreed to set up a server in Mumbai, which would allow security agencies to access Blackberry Messenger services.&lt;a href="#fn8" name="fr8"&gt;[8]&lt;/a&gt; Blackberry also provided a solution that would allow access to Blackberry Internet Services.&lt;a href="#fn9" name="fr9"&gt;[9]&lt;/a&gt; Following this, the Government of India mandated that Telecom Service Providers must incorporate the Blackberry interception solution, or risk being forced to shut their service by December 31, 2012. In compliance with this order, many service providers have set time frames for incorporation of the interception solution including and installed the necessary software.&lt;a href="#fn10" name="fr10"&gt;[10]&lt;/a&gt; It is important to note that the lawful access solutions provided do not extend to the Blackberry Enterprise Server.&lt;a href="#fn11" name="fr11"&gt;[11]&lt;/a&gt; Though it seems that the BlackBerry controversy might be resolved, the solution does not appear to be a long term solution, as BES communications are still not accessible, and the solution is not universal for all international providers. Thus, the Indian government will have to negotiate individually with each provider and service that they currently cannot access communications of.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Nira Radia Controversy:&lt;/b&gt; Continuing the Nira Radia controversy, which began in 2008-2009, in September 2012 the Supreme Court ordered the Income Tax Department to transcribe the 5,831 recorded conversations that were originally intercepted by the department. In January this year, the Supreme Court of India ordered that a "random check" be run through the Radia Tapes to check for instances of possible criminality.&lt;a href="#fn12" name="fr12"&gt;[12]&lt;/a&gt; This case has become an important moment for privacy in India, as it intersects the dilemma between the right to privacy and public interest. Since 2010, Ratan Tata has been claiming that his right to privacy was violated by the publishing of the leaked tapes.&lt;a href="#fn13" name="fr13"&gt;[13]&lt;/a&gt; The Supreme Court’s final decision will be important for drawing another contour of how the right to privacy is shaped in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Centralized Monitoring System&lt;/b&gt;: In 2012 the Telecom Ministry set aside Rs. 400 crore for the Central Monitoring System, which is projected to be finished by August 2014.&lt;a href="#fn14" name="fr14"&gt;[14]&lt;/a&gt; The project, which first began in 2007, is envisioned to allow security agencies to bypass service providers and intercept communications on their own. The system is designed to have regional databases and a central database which will be accessible to law enforcement and security agencies. Privacy concerns related to the project include how the system will incorporate current legal regulations for interception in India, as a system that bypasses service providers essentially means that every communication can be read by law enforcement. Furthermore, it is not clear exactly who, and on what conditions will officials be allowed and authorized to access and use the system. The exact capabilities of the system have also not been identified. For example, will the CMS be able to intercept VoIP calls, will it be able to decrypt messages, and will it employ techniques such as Deep Packet Inspection.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Unmanned Aerial Vehicles (UAVs):&lt;/b&gt; Since the late 90’s the Defense Research Development Organisation (DRDO) has been developing UAV’s for military purposes, and before this, India was acquiring UAV’s from Israel.&lt;a href="#fn15" name="fr15"&gt;[15]&lt;/a&gt; Since that time there has been an increase in domestic companies and institutes developing UAVs, and an increase in the procurement of the technology by state police for generic reasons purposes as crowd control, traffic management, and security. For example, in August of 2012 the city of Mumbai used the UAV "Netra", as part of their security protocol during the Raj Thackeray rally to capture and send real time images back to the police. Netra is manufactured by the company Idea Forge.&lt;a href="#fn16" name="fr16"&gt;[16]&lt;/a&gt; The Mumbai police also used the Netra in September 2012 after the Azad Maidan riots, and again on New Year’s Eve to monitor and track crime such as sexual harassment.&lt;a href="#fn17" name="fr17"&gt;[17]&lt;/a&gt; Similarly, Chennai city police are looking to procure from Anna University a UAV developed by the Madras Institute of Technology. The UAV will be used to assist in traffic monitoring and control.&lt;a href="#fn18" name="fr18"&gt;[18]&lt;/a&gt; The increased procurement and use of UAV’s by state police is concerning as there is no clear legal regulation over the deployment of the vehicles. Thus, they have shifted from being used as a tool by the military, and are being used for monitoring traffic, crowd monitoring, etc. Furthermore, the process for authorization for use of the vehicles is not clear, and it is not clear how the captured information is protected and handled. Though UAV’s are clearly a useful tool for the military, for military purposes, the permitted use of them by other actors should be defined and regulated. The use of UAV’s for generic purposes could place individual privacy at risk, because of the amount of information and the level of detail that the vehicles are able to capture without the knowledge of the individual.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The National Intelligence Grid (NATGRID):&lt;/b&gt; Plans for the NATGRID project, which was first piloted after the Mumbai attacks, has been continuing forward through 2012 and is envisioned to be operational sometime in 2013. During 2012, a detailed project report was submitted for the project, and in June the government approved Rs. 1,100 crore for purchase of technological equipment.&lt;a href="#fn19" name="fr19"&gt;[19]&lt;/a&gt; NATGRID is a project that envisions networking 21 databases for purposes of crime investigation including tax, health, and travel information. The information will be accessible to 11 security agencies and law enforcement agencies. Though it has been clarified that NATGRID will ensure that privacy is protected, the design of NATGRID is one that could create potential risks – as it brings together large amounts of personal data for easy access by security agencies. In doing so it could potentially eliminate the steps security agencies must take currently to access information – such as submitting a request and obtaining permission for access. Furthermore, it is unclear how current legal protections such as secrecy clauses in banking legislation will be incorporated and upheld by the NATGRID system. Other questions that the project raises include – though currently there are only eleven agencies listed that will have access to NATGRID – will this list expand? Without a policy in place how will this standard and other standards be enforced?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Crime and Criminal Tracking Network &amp;amp; System (CCTNS): &lt;/b&gt;Though the CCTNS project has been in the works since 2009, a call for companies to develop the technology for the system was taken in early 2012, and pilot projects were launched later that year. The CCTNS is being headed by the National Crime Records Bureau, and will allow for the sharing of crime related information on a national level, in real time. In 2012, the system was allocated 2,000 crores by the government, and currently 2,000 police stations and other offices have been connected under the system.&lt;a href="#fn20" name="fr20"&gt;[20]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For example, police in Chhattisgarh,&lt;a href="#fn21" name="fr21"&gt;[21]&lt;/a&gt; Uttarakhand&lt;a href="#fn22" name="fr22"&gt;[22]&lt;/a&gt; and Odisha have all been connected to the CCTNS system.&lt;a href="#fn23" name="fr23"&gt;[23]&lt;/a&gt; Though it will be beneficial for the police to have access to a networked system, it has not been made clear yet what type of security system the project will adopt to ensure that the information is not compromised or accessed without authorization. It has also not been clarified what information will be placed on the database, and will all records be accessible to any individual accessing the system. Because the project is still in pilot stages it is hard to tell if it could put individual privacy at risk. Hopefully, before the project is realized in its full, many of the details will be clarified.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Growth of CCTVs:&lt;/b&gt; Throughout 2012 the use of CCTV’s has continued to grow across India. For example, the Maharashtra government has undertaken a "CCTV surveillance project" in which it is in the process of taking bids for.&lt;a href="#fn24" name="fr24"&gt;[24]&lt;/a&gt; The state of Karnataka is also planning on installing CCTV cameras in Bangalore and other major cities to help detect incidents of crime.&lt;a href="#fn25" name="fr25"&gt;[25]&lt;/a&gt; While the Delhi Transport Department is contemplating installing CCTVs in buses,&lt;a href="#fn26" name="fr26"&gt;[26]&lt;/a&gt; and the Indian Rail Authorities have also decided to install CCTVs throughout stations to increase security.&lt;a href="#fn27" name="fr27"&gt;[27]&lt;/a&gt; There still does not exist regulation of the use of CCTV cameras, thus it is unclear who can operate a CCTV camera, which departments of the government can mandate for the installation of CCTVs, if public notice must be given that a CCTV camera is in use, and who can access the footage from a CCTV.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Study on Privacy Perceptions&lt;/b&gt;: In a study that came out in December 2012 by Ponnurangam K, among other things, it was found that 75 per cent of participants never read the privacy policy on a website – including social networking sites, participants also thought that there was a privacy legislation in place in India, and that individuals in India are most concerned about financial privacy.&lt;a href="#fn28" name="fr28"&gt;[28]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The National Counter Terrorism Centre (NCTC):&lt;/b&gt; The NCTC was originally created in response to the Mumbai terror attacks, under the Unlawful Prevention Act, 1967. The NCTC was meant to be realized in 2012, but in March, plans for the Centre were put on hold, because of the controversial nature of the project.&lt;a href="#fn29" name="fr29"&gt;[29]&lt;/a&gt; The Centre was meant to bring Indian intelligence agencies under one umbrella, and analyze and store information related to terrorism. The proposed body has been highly controversial, as states object to the powers given to the Centre and see it as intruding on their powers and jurisdiction. If passed, the NCTC will have the powers of arrest, search and seizure, and the ability to access information from other intelligence agencies.&lt;a href="#fn30" name="fr30"&gt;[30]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Leaked DNA Profiling Bill:&lt;/b&gt; In 2012, a version of the DNA Profiling Bill, originally drafted in 2007, was leaked to the public. The Bill is being piloted by the department of biotechnology, and seeks to establish DNA databases at the regional and central level for forensic purposes, yet the Bill does not establish strong protections for the privacy of DNA samples taken and important technical standards for ensuring that DNA samples are not misused or tampered with.&lt;a href="#fn31" name="fr31"&gt;[31]&lt;/a&gt; What will happen to the Bill in 2013 is yet to be seen, but hopefully it will not be passed without the appropriate safeguards incorporated into its provisions.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The Unique Identification Project and the National Population Registrar:&lt;/b&gt; Throughout 2012, the UID has continued to carry out enrollments across the country, and sign MoU's with private sector companies for the adoption of the UID platform. Parallel to the UID project, the NPR project is also being implemented. The NPR seeks to provide every citizen of India with an identity that will be stored in an identity database maintained by the Registrar General and Census Commissioner of India.&lt;a href="#fn32" name="fr32"&gt;[32]&lt;/a&gt; According to the NPR scheme, individuals who had already enrolled with the UID and given their biometrics would not need to re-submit their biometrics with the NPR. Yet, this has not been the case, and instead individuals are now being required to provide their biometrics for enrollment with the UID and the NPR.&lt;a href="#fn33" name="fr33"&gt;[33]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Privacy has been raised as a concern of the UID since the start of the project. For both the UID and the NPR now the transaction record will be stored by agencies, and whether it will be possible to track individuals across databases using their NPR or UID  identity?&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr1" name="fn1"&gt;1&lt;/a&gt;]. The Report of Group of Experts on Privacy. See &lt;a class="external-link" href="http://bit.ly/VqzKtr"&gt;http://bit.ly/VqzKtr&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr2" name="fn2"&gt;2&lt;/a&gt;]. Tikku, A., "RTI doesn’t trample upon privacy, says expert panel", Hindustan Times, October 29, 2012, available at &lt;a class="external-link" href="http://bit.ly/TNAzRF"&gt;http://bit.ly/TNAzRF&lt;/a&gt;, last accessed on January 8, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr3" name="fn3"&gt;3&lt;/a&gt;]. Sen, A. India protests European Union study of data laws. Economic Times. July 9, 2012, available at &lt;a class="external-link" href="http://bit.ly/Y9ahHs"&gt;http://bit.ly/Y9ahHs&lt;/a&gt;, last accessed on January 8, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr4" name="fn4"&gt;4&lt;/a&gt;]. Harismran, J., Thomas, J. "Home Ministry ordered 10k wire taps in last 90 days, order tapping of 1300 email Ids", The Economic Times, January 3,&lt;sup&gt;&lt;/sup&gt; 2013, available at &lt;a class="external-link" href="http://bit.ly/TKk7yN"&gt;http://bit.ly/TKk7yN&lt;/a&gt;, last accessed on January 7th 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr5" name="fn5"&gt;5&lt;/a&gt;].The Economic Times, "Provide solution to intercept VoIP within a month: Govt", May 6, 2012, available at &lt;a class="external-link" href="http://bit.ly/VQDQ4k"&gt;http://bit.ly/VQDQ4k&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr6" name="fn6"&gt;6&lt;/a&gt;]. The Economic Times, "New policy for real time interception to security agencies", February 1, 2012, available at &lt;a class="external-link" href="http://bit.ly/11DrlvB"&gt;http://bit.ly/11DrlvB&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr7" name="fn7"&gt;7&lt;/a&gt;]. The Economic Times, "RAW irked as Airtel keeps its request for phone tapping on hold", October 21, 2012, available at &lt;a class="external-link" href="http://bit.ly/12IujhF"&gt;http://bit.ly/12IujhF&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr8" name="fn8"&gt;8&lt;/a&gt;]. Reyes, D., "RIM installs BlackBerry server in Mumbai", CrackBerry, February 23, 2012, available at &lt;a class="external-link" href="http://bit.ly/yBQsSo"&gt;http://bit.ly/yBQsSo&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr9" name="fn9"&gt;9&lt;/a&gt;]. Economic Times, "DoT makes telecom operators fall in line on Blackberry issue", December 30, 2012, available at &lt;a class="external-link" href="http://bit.ly/1169ufn"&gt;http://bit.ly/1169ufn&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr10" name="fn10"&gt;10&lt;/a&gt;]. Economic Times, "MTNL, BSNL fail to give dates for Blackberry interception", October 29, 2012, available at &lt;a class="external-link" href="http://bit.ly/1169ufp"&gt;http://bit.ly/1169ufp&lt;/a&gt;, last accessed on January 7, 2012.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr11" name="fn11"&gt;11&lt;/a&gt;]. The Economic Times, "Telecom companies agreed to provide real-time intercept facilities for BlackBerry smartphones", December 31, 2012, available at &lt;a class="external-link" href="http://bit.ly/Y9gjYt"&gt;http://bit.ly/Y9gjYt&lt;/a&gt;, last accessed on January 7, 2012.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr12" name="fn12"&gt;12&lt;/a&gt;]. Mahapatra, D., "SC to examine Radia tapes for criminality", Times of India, January 9, &lt;sup&gt;&lt;/sup&gt; 2013, available at &lt;a class="external-link" href="http://bit.ly/VD7eWX"&gt;http://bit.ly/VD7eWX&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr13" name="fn13"&gt;13&lt;/a&gt;]. Times of India, "Ratan Tata softens stand on Radia tapes", August 23, 2012, available at &lt;a class="external-link" href="http://bit.ly/158CZxl"&gt;http://bit.ly/158CZxl&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr14" name="fn14"&gt;14&lt;/a&gt;]. The Economic Times, "Govt. to place phone tapping system worth Rs. 400 cr by 2014", March 21, 2012, available at &lt;a class="external-link" href="http://bit.ly/V2P9q6"&gt;http://bit.ly/V2P9q6&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr15" name="fn15"&gt;15&lt;/a&gt;]. Monsonis, G., "UAVs gaining currency with Indian Armed Forces", Indian Defence Review, October 30, 2012, available at &lt;a class="external-link" href="http://bit.ly/KVYyIr"&gt;http://bit.ly/KVYyIr&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr16" name="fn16"&gt;16&lt;/a&gt;]. Mumbai Mirror, "Raj Thackeray’s mega rally: Unmanned Aerial Vehicle kept an eye on Azed Maidan", Economic Times, August 22, 2012, available at &lt;a class="external-link" href="http://bit.ly/PYTGAG"&gt;http://bit.ly/PYTGAG&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr17" name="fn17"&gt;17&lt;/a&gt;].Ali, A. &amp;amp; Narayan. V., "Netra cameras to keep a close watch , over New Year’s Eve hotspots", Times of India, December 31, 2012, available at &lt;a class="external-link" href="http://bit.ly/Z7orxt"&gt;http://bit.ly/Z7orxt&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr18" name="fn18"&gt;18&lt;/a&gt;]. Venugopal, V., "It flies, it swoops, it records and monitors", The Hindu, December 20, 2012, available at &lt;a class="external-link" href="http://bit.ly/V89sLo"&gt;http://bit.ly/V89sLo&lt;/a&gt;, last accessed January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr19" name="fn19"&gt;19&lt;/a&gt;]. The Economic Times, "Cabinet Committee on Security approves Rs. 1,100 crore for NATGRID", June 14, 2012.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr20" name="fn20"&gt;20&lt;/a&gt;]. Mohan, V., "Centre launches pilot project to track criminals", The Times of India, January 5, 2013, available at &lt;a class="external-link" href="http://bit.ly/UPk2fh"&gt;http://bit.ly/UPk2fh&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr21" name="fn21"&gt;21&lt;/a&gt;]. The Pioneer, "Civil Lines Police Station gets connected with CCTNS", January 2012, available at &lt;a class="external-link" href="http://bit.ly/VRXKGJ"&gt;http://bit.ly/VRXKGJ&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr22" name="fn22"&gt;22&lt;/a&gt;]. CIOL Bureau, "CCTNS to be made public through internet: Dehradun DGP", January 4, 2012, available at &lt;a class="external-link" href="http://bit.ly/X4JISx"&gt;http://bit.ly/X4JISx&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr23" name="fn23"&gt;23&lt;/a&gt;]. The Hindu, "Odisha to launch CCTNS on January 12", January 7, 2013, available at &lt;a class="external-link" href="http://bit.ly/Vd9Ay1"&gt;http://bit.ly/Vd9Ay1&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr24" name="fn24"&gt;24&lt;/a&gt;]. Padmakshan, M., "Maharashtra plans to invite new bids for CCTV surveillance project", September 18, 2012, available at &lt;a class="external-link" href="http://bit.ly/VRYrQm"&gt;http://bit.ly/VRYrQm&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr25" name="fn25"&gt;25&lt;/a&gt;]. Ashoka, R., "Karnataka to install CCTV cameras in Bangalore, major cities", Economic Times. July 26, 2012, available at &lt;a class="external-link" href="http://bit.ly/11Dxt6Z"&gt;http://bit.ly/11Dxt6Z&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr26" name="fn26"&gt;26&lt;/a&gt;]. Economic Times, "Buses to come with CCTV cameras for safety of women: Delhi government", December 17, 2012, available at &lt;a class="external-link" href="http://bit.ly/158Gtjo"&gt;http://bit.ly/158Gtjo&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr27" name="fn27"&gt;27&lt;/a&gt;]. Economic Times, "Railways to step by security apparatus at stations", February 15, 2012, available at &lt;a class="external-link" href="http://bit.ly/11DxSX8"&gt;http://bit.ly/11DxSX8&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr28" name="fn28"&gt;28&lt;/a&gt;]. Times of India, "Most Indians ignorant about privacy issues on Facebook, Twitter: Study", December 10, 2012, available at &lt;a class="external-link" href="http://bit.ly/X4KVt1"&gt;http://bit.ly/X4KVt1&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr29" name="fn29"&gt;29&lt;/a&gt;]. Kumar, H., "Does India Need a National Counter Terrorism Center?", The New York Times, India Ink, February 28, 2012, available at &lt;a class="external-link" href="http://nyti.ms/A5VU5P"&gt;http://nyti.ms/A5VU5P&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr30" name="fn30"&gt;30&lt;/a&gt;]. Times of India. CM to attend National Counter- Terrorism Centre Meet in Delhi. May 4, 2012, available at &lt;a class="external-link" href="http://bit.ly/12IDoH9"&gt;http://bit.ly/12IDoH9&lt;/a&gt;, last accessed on January 8, 2012.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr31" name="fn31"&gt;31&lt;/a&gt;]. Hickok, E., "Rethinking DNA Profiling in India", Economic Political Weekly, October 27, 2012, available at &lt;a class="external-link" href="http://bit.ly/TUrH7j"&gt;http://bit.ly/TUrH7j&lt;/a&gt;, last accessed on January 7, 2013.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr32" name="fn32"&gt;32&lt;/a&gt;]. Department of Information Technology, "National Population Register", available at &lt;a class="external-link" href="http://bit.ly/12rzyOh"&gt;http://bit.ly/12rzyOh&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr33" name="fn33"&gt;33&lt;/a&gt;]. Pandit, A., "NPR must even if you have Aadhar number", Times of India, October 31, 2012, available at &lt;a class="external-link" href="http://bit.ly/Y9oXGq"&gt;http://bit.ly/Y9oXGq&lt;/a&gt;, last accessed on January 8, 2013.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/privacy-highlights-in-india'&gt;https://cis-india.org/internet-governance/privacy-highlights-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-02-12T12:39:05Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/workshop-on-urban-data-inequality-and-justice-in-the-global-south">
    <title>Workshop on 'Urban Data, Inequality and Justice in the Global South'</title>
    <link>https://cis-india.org/internet-governance/news/workshop-on-urban-data-inequality-and-justice-in-the-global-south</link>
    <description>
        &lt;b&gt;Aayush Rathi and Ambika Tandon presented our research on video-based surveillance in New Delhi at a workshop on urban data, inequality, and justice in the global South at the University of Manchester on 14 June 2019.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The agenda for the workshop and the presentations made by CIS can be &lt;a class="external-link" href="https://cis-india.org/raw/unpacking-video-based-surveillance-in-new-delhi-urban-data-justice"&gt;accessed here&lt;/a&gt;. &lt;span&gt;The research was conducted as part of a grant from the University, as part of a project on justice in data systems within cities. It will bepublished as a working paper by the university in July-August.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/workshop-on-urban-data-inequality-and-justice-in-the-global-south'&gt;https://cis-india.org/internet-governance/news/workshop-on-urban-data-inequality-and-justice-in-the-global-south&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Surveillance</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-07-06T01:30:16Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-news-minute-shilpa-s-ranipeta-june-10-2019-no-fintech-company-meets-every-single-privacy-requirement-under-it-act-cis-report">
    <title>No Fintech company meets every single privacy requirement under IT Act: CIS report</title>
    <link>https://cis-india.org/internet-governance/news/the-news-minute-shilpa-s-ranipeta-june-10-2019-no-fintech-company-meets-every-single-privacy-requirement-under-it-act-cis-report</link>
    <description>
        &lt;b&gt;The study shows that privacy policies companies such as Paytm, Jio Payments Bank, Airtel Payments Bank, Amazon Pay, Bhim are not accessible from the main website.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Shilpa S. Ranipeta published by the News Minute on June 10, 2019, &lt;a class="external-link" href="https://www.thenewsminute.com/article/no-fintech-company-meets-every-single-privacy-requirement-under-it-act-cis-report-103366"&gt;quotes the research done by Aayush Rathi and Shweta Mohandas&lt;/a&gt; of the Centre for Internet &amp;amp; Society.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;A study by the Centre for Internet and Society on privacy and security policies of Fintech companies in India has shown that no company met every single requirements under the Section 43A Rules of the IT Act. A study of privacy policies of 48 companies has also shown that privacy policies of major entities such as Paytm, Jio Payments Bank, Airtel Payments Bank, Amazon Pay, Bhim are not accessible from the main website of the company.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The privacy policies were assessed based on the privacy policy requirements mandated by the Sensitive Personal Data or Information (SPD/I) Rules.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A fintech company is one that combines financial services and products with technology. The companies categorised as Fintech in this study are payment gateways, payment gateway aggregators, mobile and online wallets, digital payments banks, peer-to-peer lending platforms and miscellaneous entities that share features of the above categorisation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Rule 4 of the SPD/I Rules mandates that a company that handles information should have a privacy policy that ensures it is dealing with the information provided by users as per the SPD/I Rules. It is also required that the privacy policy is published on the website of the company and is ‘clear and easily accessible’. However, the SPD/I Rules doesn’t specify what would constitute a ‘clear and easily accessible’ privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In this research, CIS has studied accessibility as how many times a person has to click to access the privacy policy, if it is readily available on the homepage, if the company states its practices for privacy in language that can be understood by someone fluent in English and does not require prior legal or technical knowledge to be understood.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Here are some observations from the research:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Accessibility:&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The study found that 38 companies have a privacy policy accessible on the main website of the company, 38 also have the privacy policy included in terms and conditions of all documents of the company that collects personal information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, policies of only 20 companies can be understood by someone without legal and technical knowledge and 16 can be partially understood. Privacy policies of RazorPay, Oxigen, Airtel Payments Bank, Capital Float, Freecharge, BHIM couldn’t be understood by someone without legal and technical knowledge.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“For some of the companies the privacy policy had to be located in the terms of service or under separate categories such as ‘legal agreements’, ‘key policies’, ‘security’, further making the privacy police more inaccessible. We anticipate that unless the user is specifically looking for the privacy policy, it is unlikely for the privacy policy to be perused in the usual course of a user’s usage of the services of the fintech provider,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The study found that while most fintech companies in the sample explicitly specified personal information that was being collected, fewer privacy policies contained categorical provisions segregating the sensitive personal information that was being collected. However, it was unclear what each category specifically entailed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Another terminology that is often incorporated to broaden the ambit of information being collected is the definition of personal information as any information that may be provided by the user. This squarely places the onus of restricting information collection on the user, further compounding the handicaps users face in ascertaining the information that that firms are seeking to collect because of the illustrative nature of the listing of information,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Option to not provide information and withdrawal of consent:&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Interpretation Rule 5(7) states that the company should inform users even before collecting information that they have an option to not provide the data or information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The rule also specifies that the individual must also be informed that he/she has an option to subsequently withdraw consent from the use of the data or information collected by the data controller.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, Privacy Policies of 30 companies do not specify that the user has the option to not provide information. These include companies such as PayU, CitrusPay, Jio Money, Airtel Payments Bank, Paytm, Fino Paytech, Capital Float, Walnut, etc.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Only 17 companies specify that the user has the option to subsequently withdraw consent.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Registering grievances&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The study showed that only 16 of companies mention the existence of grievance officer in their privacy policies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Rule 5(9) of the SPD/I Rules state that companies are required to have a grievance redress mechanism in place vis-a-vis the user’s privacy practices.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Thirty-two companies failed to not just provide a redressal mechanism but also failed to mention the existence of a grievance officer specific to the resolution of issues that users may encounter vis-à-vis the data controller’s privacy practices,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;strong&gt;Language barrier&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;All companies, except PhonePe, had a privacy policy only in one language – English. PhonePe provided a privacy policy in both English and Hindi.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“With the growth of the digital economy, a multitude of Indians are using online 46 services, and it is imperative that privacy policies be accessible and understandable to all users of the service. In the context of the fintech sector, accessibility to privacy policies takes on added significance given the fintech sector’s avowed promise of increasing access to financial products to hitherto underserved sections of the society,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The research showed that few consumers, if any, read online privacy policies, despite expressing concern about their online privacy. And privacy policies are often very technical and not comprehensible by a regular user.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-news-minute-shilpa-s-ranipeta-june-10-2019-no-fintech-company-meets-every-single-privacy-requirement-under-it-act-cis-report'&gt;https://cis-india.org/internet-governance/news/the-news-minute-shilpa-s-ranipeta-june-10-2019-no-fintech-company-meets-every-single-privacy-requirement-under-it-act-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Shilpa S. Ranipeta</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-07-08T02:34:59Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-wire-mira-swaminathan-and-shweta-reddy-july-20-2019-old-isnt-always-gold-face-app-and-its-privacy-policies">
    <title>Old Isn't Always Gold: FaceApp and Its Privacy Policies</title>
    <link>https://cis-india.org/internet-governance/blog/the-wire-mira-swaminathan-and-shweta-reddy-july-20-2019-old-isnt-always-gold-face-app-and-its-privacy-policies</link>
    <description>
        &lt;b&gt;Leaving aside the Red Scare for a moment, FaceApp's own rebuttal of privacy worries are highly problematic in nature.&lt;/b&gt;
        
&lt;p style="text-align: justify;"&gt;The article by Mira Swaminathan and Shweta Reddy was published in &lt;a class="external-link" href="https://thewire.in/tech/old-isnt-always-gold-faceapp-privacy-data-policies"&gt;the Wire&lt;/a&gt; on July 20, 2019.&lt;/p&gt;
&lt;hr style="text-align: justify;" /&gt;
&lt;p style="text-align: justify;"&gt;If you, much like a large number of celebrities, have spammed your followers with the images of ‘how you may look in your old age’,&amp;nbsp;&lt;a href="https://yourstory.com/2019/07/faceapp-photo-filter-virat-kohli-arjun-kapoor-jonas-brothers"&gt;you have successfully been a part of the FaceApp fad &lt;/a&gt;that has gone viral this week.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The problem with the FaceApp trend isn’t that it has penetrated most social circles, but rather, the fact that it has gone viral with minimal scrutiny&amp;nbsp;&lt;a href="https://www.huffingtonpost.in/entry/faceapp-privacy-issues_n_5d2f3ba7e4b02fd71dde0bc2"&gt;of its vaguely worded privacy policy guidelines.&lt;/a&gt; We click ‘I agree’ without understanding that our so called ‘explicit consent’ gives the app permission to use our likeness, name and username, for any purpose, without our knowledge and consent,&amp;nbsp;&lt;a href="https://edition.cnn.com/2019/07/17/tech/faceapp-privacy-concerns/index.html"&gt;even after we delete the app&lt;/a&gt;. FaceApp&amp;nbsp;&lt;a href="https://www.hindustantimes.com/tech/faceapp-is-trending-again-all-you-need-to-know-about-the-viral-ai-photo-editing-app/story-5VQurpSMSogKwiqX03GbNK.html"&gt;is currently the most downloaded free app on the Apple Store&lt;/a&gt; due to a large number of people downloading the app to ‘turn their old selfies grey’.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;There are many things that the app could do. It could process the images on your device,&amp;nbsp;&lt;a href="https://www.forbes.com/sites/thomasbrewster/2019/07/17/faceapp-is-the-russian-face-aging-app-a-danger-to-your-privacy/#3a8cbcb32755"&gt;rather than take submitted photos to an outside server&lt;/a&gt;.&amp;nbsp; It could also upload your photos to the cloud without making it clear to you that processing is not taking place locally on their device.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Further, if you have an Apple product, the iOS app appears to be overriding your settings even if you have denied access to their camera roll. People have reported that they could still select and upload a photo despite the app not having permission to access their photos.&amp;nbsp;&lt;a href="https://techcrunch.com/2019/07/16/ai-photo-editor-faceapp-goes-viral-again-on-ios-raises-questions-about-photo-library-access-and-clo/"&gt;This ‘allowed behaviour’ in iOS&lt;/a&gt; is quite concerning, especially when we have apps with loosely worded terms and conditions.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;FaceApp responded&amp;nbsp;&lt;a href="https://techcrunch.com/2019/07/17/faceapp-responds-to-privacy-concerns/"&gt;to these privacy concerns by issuing a statement with a list of defences.&lt;/a&gt; The statement clarified that FaceApp performs most of the photo processing in the cloud, that they only upload a photo selected by a user for editing and also confirmed that they never transfer any other images from the phone to the cloud. However, even in their clarificatory statement, they stated that they ‘might’ store an uploaded photo in the cloud and explained that the main reason for that is “performance and traffic”. They also stated that ‘most’ images are deleted from their servers within 48 hours from the upload date.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Further, the statement ends by saying that “all pictures from the gallery are uploaded to our servers after a user grants access to the photos”. This is highly problematic.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;We have explained the concerns arising out of the privacy policy with reference to the global gold standards: the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data, APEC Privacy Framework, Report of the Group of Experts on Privacy chaired by Justice A.P. Shah and the General Data Protection Regulation in the table below:&lt;/p&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Privacy Domain&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.oecd.org/internet/ieconomy/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm"&gt;OECD Guidelines &lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.apec.org/Publications/2005/12/APEC-Privacy-Framework"&gt;APEC Privacy Framework &lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="http://planningcommission.nic.in/reports/genrep/rep_privacy.pdf"&gt;Report of the Group of Experts on Privacy&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1528874672298&amp;amp;uri=CELEX%3A32016R0679"&gt;General Data Protection Regulation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://faceapp.com/privacy"&gt;FaceApp Privacy Policy&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Transparency&lt;/td&gt;
&lt;td&gt;There should be a general policy of openness about developments, practices and policies with respect to personal data.&lt;/td&gt;
&lt;td&gt;Personal information controllers should provide clear and easily accessible statements about their practices and policies with respect to personal data.&lt;/td&gt;
&lt;td&gt;A data controller shall give&amp;nbsp;a&amp;nbsp;notice that is understood simply of its information practices to all individuals, in clear and concise language, before any personal information is collected from them.&lt;/td&gt;
&lt;td&gt;Transparency:
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The controller shall take appropriate measures to provide information relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language.&lt;/p&gt;
&lt;p&gt;Article 29 working party guidelines on Transparency:&lt;/p&gt;
&lt;p&gt;The information should be concrete and definitive, it should not be phrased in abstract or ambivalent terms or leave room for different interpretations.&lt;/p&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;“We may use your personal data to develop new services” (as it is unclear what the services are or how the data will help develop them);&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;Information we collect
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;“When you visit the Service, we may use cookies and similar technologies”……. provide features to you.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;We may ask advertisers or other partners to serve ads or services to your devices, which may use cookies or similar technologies placed by us or the third party.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;“We may also collect similar information from emails sent to our Users..”&lt;/p&gt;
&lt;p&gt;Sharing your information&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;“We may share User Content and your information with businesses…”&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;“We also may share your information as well as information from tools like cookies, log files..”&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;“We may also combine your information with other information..”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: justify;" colspan="6"&gt;A simple reading of the guidelines in comparison with the privacy policy of FaceApp can help us understand that the terms used by the latter are ambiguous and vague. The possibility of a ‘may not’ can have a huge impact on the privacy concerns of the user.
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The entire point of ‘transparency’ in a privacy policy is for the user to understand the extent of processing undertaken by the organisation and then have the choice to provide consent. Vague phrases do not adequately provide a clear indication of the extent of processing of personal data of the individual.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Privacy Domain&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.oecd.org/internet/ieconomy/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm"&gt;OECD Guidelines &lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://www.apec.org/Publications/2005/12/APEC-Privacy-Framework"&gt;APEC Privacy Framework &lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="http://planningcommission.nic.in/reports/genrep/rep_privacy.pdf"&gt;Report of the Group of Experts on Privacy&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1528874672298&amp;amp;uri=CELEX%3A32016R0679"&gt;General Data Protection Regulation&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="https://faceapp.com/privacy"&gt;FaceApp Privacy Policy&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security Safeguards&lt;/td&gt;
&lt;td&gt;Personal data should be protected by reasonable security safeguards against such risks as loss or unauthorised access, destruction, use, modification or disclosure of data&lt;/td&gt;
&lt;td style="text-align: left;"&gt;Personal information controllers should protect personal information that they hold with appropriate safeguards against risks, such as loss or unauthorised access to personal information or unauthorised destruction, use, modification or disclosure of information or other misuses.&lt;/td&gt;
&lt;td style="text-align: justify;"&gt;A data controller shall secure personal information that they have either collected or have in their custody by reasonable security safeguards against loss, unauthorised access, destruction, use, processing, storage, modification, deanonymization, unauthorised disclosure or other reasonably foreseeable risks&lt;/td&gt;
&lt;td&gt;The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.&lt;/td&gt;
&lt;td&gt;How we store your information
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;“We use commercially reasonable safeguards to help keep the information collected through the Service secure and take reasonable steps… However, FaceApp cannot ensure the security of any information you transmit to FaceApp or guarantee that information on the Service may not be accessed, disclosed, altered, or destroyed.”&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify;"&gt;The obligation of implementing reasonable security measures to prevent unauthorised access and misuse of personal data is placed on the organisations processing such data. FaceApp’s privacy policy assures that reasonable security measures according to commercially accepted standards have been implemented. Despite such assurances, FaceApp’s waiver of the liability by stating that it cannot ensure the security of the information against it being accessed, disclosed, altered or destroyed itself says that the policy is faltered in nature.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The privacy concerns and the issue of transparency (or the lack thereof) in FaceApp are not isolated. After all, as a&amp;nbsp;&lt;a href="https://www.buzzfeednews.com/article/daveyalba/what-happens-when-you-upload-faceapp-photos" rel="noopener" target="_blank"&gt;&lt;em&gt;Buzzfeed&lt;/em&gt; analysis of the app noted&lt;/a&gt;, while there appeared to be no data going back to Russia, this could change at any time due to its overly broad privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The business model of most mobile applications being developed currently relies heavily on personal data collection of the user. The users’ awareness regarding the type of information accessed based on the permissions granted to the mobile application is questionable.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;In May 2018,&amp;nbsp;&lt;a href="https://www.symantec.com/blogs/threat-intelligence/mobile-privacy-apps"&gt;Symantec tested&lt;/a&gt; the top 100 free Android and iOS apps with the primary aim of identifying cases where the apps were requesting ‘excessive’ access to information of the user in relation to the functions being performed. The study identified that 89% of Android apps and 39% of the iOS app request for what can be classified as ‘risky’ permissions, which the study defines as permissions where the app requests data or resources which involve the user’s private information, or, could potentially affect the user’s locally stored data or the operation of other apps.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Requesting risky permissions may not on its own be objectionable, provided clear and transparent information regarding the processing, which takes place upon granting permission, is provided to the individuals in the form of a clear and concise privacy notice. The study concluded that 4% of the Android apps and 3% of the iOS apps seeking risky permissions didn’t even have a privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The lack of clarity with respect to potentially sensitive user data being siphoned off by mobile applications became even more apparent with the case of a&amp;nbsp;&lt;a href="https://www.huffingtonpost.in/entry/fintech-apps-privacy-snooping-credit-vidya_in_5d1cbc34e4b082e55373370a?guccounter=1"&gt;Hyderabad based fintech company&lt;/a&gt; that gained access to sensitive user data by embedding a backdoor inside popular apps.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;In the case of the Hyderabad-based fintech company, the user data which was affected included GPS locations, business SMS text messages from e-commerce websites and banks, personal contacts, etc. This data was used to power the company’s self-learning algorithms which helped organisations determine the creditworthiness of loan applicants. It is pertinent to note that even when apps have privacy policies,&amp;nbsp;&lt;a href="http://snip.ly/2dfaj0#http://www.cuts-ccier.org/cdpp/pdf/survey_analysis-dataprivacy.pdf"&gt;users can still find it difficult to navigate&lt;/a&gt; through the long content-heavy documents.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The&amp;nbsp;&lt;em&gt;New York Times&lt;/em&gt;, as part of its&amp;nbsp;&lt;a href="https://www.nytimes.com/interactive/2019/06/12/opinion/facebook-google-privacy-policies.html"&gt;Privacy Project&lt;/a&gt;,&amp;nbsp;analysed the length and readability of privacy policies of around 150 popular websites and apps. It was concluded that the vast majority of the privacy policies that were analysed exceeded the college reading level. Usage of vague language like “adequate performance” and “legitimate interest” and wide interpretation of such phrases allows organisations to use data in extensive ways while providing limited clarity on the processing activity to the individuals.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The Data Protection Authorities operating under the General Data Protection Regulation are paying close attention to openness and transparency of processing activities by organisations.&amp;nbsp;&lt;a href="https://www.cnil.fr/en/cnils-restricted-committee-imposes-financial-penalty-50-million-euros-against-google-llc"&gt;The French Data Protection Authority&lt;/a&gt; fined Google for violating their obligations of transparency and information. The UK’s Information Commissioner’s office issued an&amp;nbsp;&lt;a href="https://ico.org.uk/media/action-weve-taken/enforcement-notices/2260123/aggregate-iq-en-20181024.pdf"&gt;enforcement notice&lt;/a&gt; to a Canadian data analytics firm for failing to provide information in a transparent manner to the data subject.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Thus, in the age of digital transformation, the unwelcome panic caused by FaceApp should be channelled towards a broader discussion on the information paradox currently existing between individuals and organisations. Organisations need to stop viewing ambiguous and opaque privacy policies as a get-out-of-jail-free card. On the contrary, a clear and concise privacy policy outlining the details related to processing activity in simple language can go a long way in gaining consumer trust.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The next time an “AI-based Selfie App” goes viral, let’s take a step back and analyse how it makes use of user-provided data and information both over and under the hood, since if data is the new gold, we can easily say that we’re in the midst of a gold rush.&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-wire-mira-swaminathan-and-shweta-reddy-july-20-2019-old-isnt-always-gold-face-app-and-its-privacy-policies'&gt;https://cis-india.org/internet-governance/blog/the-wire-mira-swaminathan-and-shweta-reddy-july-20-2019-old-isnt-always-gold-face-app-and-its-privacy-policies&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Mira Swaminathan and Shweta Reddy</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-08-09T10:12:11Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/bis-litd-17-meeting">
    <title>BIS LITD 17 meeting</title>
    <link>https://cis-india.org/internet-governance/news/bis-litd-17-meeting</link>
    <description>
        &lt;b&gt;On July 3, 2019, Gurshabad Grover attended the sixteenth meeting of the Information Systems Security and Biometrics Section Committee (LITD17) at the Bureau of Indian Standards (BIS) in New Delhi.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;In a previous meeting, a panel was formed to review two biometric standards: ISO/ IEC 24745 'Security Techniques - Biometric Information Protection' (2011), and ISO/IEC 19792 'Security techniques - Security evaluation of biometrics' (2009). Elonnai Hickok, Karan Saini and Gurshabad Grover had reviewed the documents and sent comments to BIS in December 2018 and January 2019 respectively. The Centre for Internet &amp;amp; Society (CIS) had also shared a document that compared the security guidelines in the standards to the provisions of the draft data protection bill.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The committee discussed whether the aforementioned standards should be adopted as Indian standards by BIS. A decision will be taken on the matter after future discussions that CIS will participate in.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Members updated the committee on their participation at the ISO/IEC. Iupdated the committee on the progress of the study period on the impact of machine learning on privacy, which I am a co-rapporteur for in the identity management and privacy group working group at ISO/IEC IT Security Techniques committee. We also planned our participation at the next ISO/IEC SC 27 meeting, which is in October.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/bis-litd-17-meeting'&gt;https://cis-india.org/internet-governance/news/bis-litd-17-meeting&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-07-21T13:58:29Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/observer-research-foundation-shashidhar-kj-and-kashish-parpiani-july-22-2019-easing-the-us-india-divergence-on-data-localisation">
    <title>Easing the US-India divergence on data localisation</title>
    <link>https://cis-india.org/internet-governance/news/observer-research-foundation-shashidhar-kj-and-kashish-parpiani-july-22-2019-easing-the-us-india-divergence-on-data-localisation</link>
    <description>
        &lt;b&gt;Addition of data localisation to the basket of persisting trade issues warrants greater compartmentalisation and consultative approaches to US-India ties.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Shashidhar KJ and Kashish Parpiani was &lt;a class="external-link" href="https://www.orfonline.org/expert-speak/easing-us-india-divergence-data-localisation-53256/"&gt;published by Observer Research Foundation&lt;/a&gt; on July 22, 2019.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The Reserve Bank of India’s (RBI) finally &lt;a href="https://rbi.org.in/Scripts/FAQView.aspx?Id=130" rel="noopener" target="_blank"&gt;clarified &lt;/a&gt;its position eight months after it issued the controversial April 2018 circular mandating the storage of all payment data of Indians in the country and allowing the central bank “unfettered access”. The circular particularly aimed at US-based companies such as Mastercard, Visa, American Express, PayPal, Facebook and Google, as they scrambled to comply. The clarification was a welcome relief for companies seeking guidance on how to comply, what kind of data needs to be stored in India, and if the payment companies needed to move their processing infrastructure. Note, the RBI has yet to issue a formal directive with these clarifications.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Meanwhile, media reports have indicated that Facebook-owned WhatsApp would &lt;a href="https://economictimes.indiatimes.com/tech/internet/local-data-storage-ready-whatsapp-to-open-payments-tap/articleshow/69966898.cms" rel="noopener" target="_blank"&gt;obey&lt;/a&gt; the RBI norm as it looks to kick off its payments business. This runs counter to what Facebook CEO Mark Zuckerberg had &lt;a href="https://www.nasdaq.com/aspx/call-transcript.aspx?StoryId=4256521&amp;amp;Title=facebook-s-fb-ceo-mark-zuckerberg-on-q1-2019-results-earnings-call-transcript" rel="noopener" target="_blank"&gt;told &lt;/a&gt;investors in April:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“&lt;em&gt;You should expect that we won’t store sensitive data in countries where it might be improperly accessed because of weak rule of law or governments that can forcibly get access to your data&lt;/em&gt;.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India is still debating passing a Personal Data Protection legislation, and as such, India doesn’t have any legal safeguards protecting users’ data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This has revealed yet another faultline in the persisting trade issues between the US and India.&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;India is still debating passing a Personal Data Protection legislation, and as such, India doesn’t have any legal safeguards protecting users’ data.&lt;/blockquote&gt;
&lt;h2 style="text-align: justify; "&gt;Indian data rights vs. American IPR protectionism&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;New Delhi has started to assert its right over its citizens’ data as India’s footprint on the Internet increases. Moreover, without clear guidance from Personal Data Protection legislation, there has been a glut of policy prescriptions from sector regulators. The Centre for Internet and Society &lt;a href="https://cis-india.org/internet-governance/resources/the-localisation-gambit.pdf" rel="noopener" target="_blank"&gt;published&lt;/a&gt; a paper in which it chronicles 10 policy measures for both ‘soft’ and ‘hard’ data localisation across health, telecommunications, e-commerce, insurance and others. These measures range from storing copies of specific data, local content production requirements, or imposing conditions on cross-border data transfers that act as a localisation mandate.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This oversupply of policy prescriptions is leading to blurring of jurisdictions. Often, the policy measures given have many a slip between the cup and the lip. For example, one of the reasons for insisting on localisation is security, but even if companies localise data, there is no framework to access this data by the local security apparatus.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India’s policy thinking on the matter often begins with the idea: ‘data is the new oil.’ The thinking is that data generated by Indians should be viewed as a natural resource that must be protected by the state through localisation. This notion is &lt;a href="https://www.orfonline.org/expert-speak/indias-draft-e-commerce-policy-a-need-to-look-beyond-data-as-the-new-oil-49413/" rel="noopener" target="_blank"&gt;problematic&lt;/a&gt;. Data, unlike oil, which is found in limited quantities, has different properties. Newer ideas of regulation must be thought of and that’s where Indian policy makers have not been accommodative.&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;Oversupply of policy prescriptions is leading to blurring of jurisdictions. Often, the policy measures given have many a slip between the cup and the lip.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;A gripe that US-based companies mention is that there is a distinctive domestic tilt and that company representatives have turned away from consultations as they do not serve the “national interests.” This was best exemplified in October 2018 when a closed-door discussion between the RBI and the US-India Strategic Partnership Forum (USISPF representing the interests of US companies) &lt;a href="https://economictimes.indiatimes.com/news/economy/policy/data-localisation-sparking-complaints-of-bias-us-companies-seek-12-months-time-from-rbi/articleshow/66210317.cms?from=mdr" rel="noopener" target="_blank"&gt;broke down&lt;/a&gt;and the latter accused the RBI of having a bias. During the discussions, the RBI placed a lot of emphasis on the inputs from iSPIRT (Indian Software Product Industry Roundtable), an Indian think tank which has been advocating for data protectionism.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The aforementioned sentiment has been carried over to international summits. At the recently concluded G20 summit, India &lt;a href="https://www.livemint.com/news/world/india-boycotts-osaka-track-at-g20-summit-1561897592466.html" rel="noopener" target="_blank"&gt;boycotted &lt;/a&gt;the Osaka Track on the digital economy as it felt that it would undermine multilateral consensus-based decisions on trade and deny policy space for digital industrialisation. The Osaka Track pushed hard for the creation of laws which would allow data flows between countries and the removal of data localisation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India’s foreign secretary, Vijay Gokhale, &lt;a href="https://www.thehindu.com/news/national/on-5g-and-data-india-stands-with-developing-world-not-us-japan-at-g20/article28207169.ece" rel="noopener" target="_blank"&gt;mentioned &lt;/a&gt;that data is a new form of wealth and wanted latitude on domestic rule-making on data. And in the age of digital commerce, this may signify a broader trend of a developed-developing nations’ impasse. The tussle has now moved beyond the security angle with the United States &lt;a href="https://cis-india.org/internet-governance/blog/an-analysis-of-the-cloud-act-and-implications-for-india" rel="noopener" target="_blank"&gt;enacting &lt;/a&gt;the Clarifying Lawful Overseas Use of Data (CLOUD) Act for security agencies to procure data stored in servers regardless of whether in the US or foreign soil. With monetisation now at the core of the dispute, the discussed divergences on data localisation tie into the US’ broader, long-standing issues pertaining to US-India bilateral trade.&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Divergence on data localisation issue crosses path with trade tensions&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;The &lt;a href="https://ustr.gov/about-us/policy-offices/press-office/fact-sheets/2019/march/fact-sheet-2019-national-trade-estimate" rel="noopener" target="_blank"&gt;2019 National Trade Estimate&lt;/a&gt; (NTE) by the Office of the United States Trade Representative (USTR) focuses on reducing “barriers to digital trade.” Taking a tone of American stewardship on open liberal market economics, it notes:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“&lt;em&gt;When governments impose unnecessary barriers to cross-border data flows or discriminate against foreign digital services, local firms are often hurt the most, as they cannot take advantage of cross-border digital services that facilitate global competitiveness&lt;/em&gt;.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At a time when the Trump administration has sought to re-calibrate America’s trade relationships via the adoption of punitive sanctions that run counter to the fundamentals of the liberal world order, the aforementioned American concern for the competitiveness of foreign nation’s local firms may seem like sardonic preaching.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;President Trump’s ‘America First’ worldview in many ways upended conventional tenets of US foreign policy. But on some fronts, it has presented opportunities for marginal establishment agendas. For instance, Trump’s heightened focus on ties with Israel and the US’ Sunni allies in the Middle East, complements the realisation of &lt;a href="https://www.google.com/search?q=neoconservatives+bolton+iran+trump&amp;amp;rlz=1C1GCEU_enIN821IN821&amp;amp;oq=neoconservatives+bolton+iran+trump&amp;amp;aqs=chrome..69i57j33.7943j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8&amp;amp;safe=active" rel="noopener" target="_blank"&gt;neoconservatives’ penchant for regime change in Iran&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;At a time when the Trump administration has sought to re-calibrate America’s trade relationships via the adoption of punitive sanctions that run counter to the fundamentals of the liberal world order, the aforementioned American concern for the competitiveness of foreign nation’s local firms may seem like sardonic preaching.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;On Trump’s fixation with recalibrating US trade relationships on “&lt;a href="https://www.whitehouse.gov/briefings-statements/president-donald-j-trump-will-promote-worldwide-economic-growth-prosperity-g20-summit/" rel="noopener" target="_blank"&gt;fair and reciprocal&lt;/a&gt;” footing, the American trade establishment successfully addressed US’ belated concerns over absence of digital trade rules in case of the North American Free Trade Agreement (NAFTA) with Canada and Mexico. Similarly, the emerging divergences over data localisation with India are subsumed under the ongoing — albeit repeatedly stalled, US-India trade negotiations.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Hence, the NTE underscores India’s decision with regards to payment service suppliers to be part of trade barriers hampering digital commerce and US-India trade at-large.&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Fixing the strained Carter &lt;em&gt;mantra&lt;/em&gt; via compartmentalisation and consultation&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;India has &lt;a href="https://www.orfonline.org/expert-speak/us-recent-decisions-to-cloud-pompeos-visit-to-india-52012/" rel="noopener" target="_blank"&gt;approached&lt;/a&gt; trade talks from the standpoint of addressing the Trumpian aberration of the US pushing for reduction of its trade deficits with other countries. Whereas, USTR negotiators have approached negotiations with India with regards to, what they view as longstanding issues in bilateral trade, such as market access for dairy products and price caps on medical equipment.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In the past, those outstanding issues were downplayed in view of the promising long-term trajectory of US-India strategic ties. The same has come to be known as the understated dictum of the &lt;a href="https://www.cfr.org/content/publications/attachments/052416_Ayres_Testimony.pdf"&gt;Carter &lt;/a&gt;&lt;a href="https://www.cfr.org/content/publications/attachments/052416_Ayres_Testimony.pdf" rel="noopener" target="_blank"&gt;&lt;em&gt;mantra&lt;/em&gt;&lt;/a&gt; — named after former US Secretary of Defense Ashton Carter and architect of the &lt;a href="https://dod.defense.gov/Portals/1/Documents/pubs/US-IND-Fact-Sheet.pdf" rel="noopener" target="_blank"&gt;US-India Defense Technology and Trade Initiative&lt;/a&gt;. The approach encompassed the US to focus on harnessing strategic ties and not let differences on other fronts like trade to &lt;a href="https://www.orfonline.org/wp-content/uploads/2018/10/ORF_Issue_Brief_262_US_Legislature.pdf" rel="noopener" target="_blank"&gt;crowd out minimal-yet-positive developments&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In recent times, that dictum has come under strain as trade tensions have resurfaced. Cases in-point being, the Trump administration’s &lt;a href="https://indianexpress.com/article/explained/donald-trump-wilbur-ross-commerce-industry-india-us-trade-suresh-prabhu-5717901/" rel="noopener" target="_blank"&gt;recent revocation&lt;/a&gt; of India’s designation as a “beneficiary developing country” under its Generalised System of Preferences programme, and India’s &lt;a href="https://www.livemint.com/politics/policy/india-imposes-tariffs-on-28-us-goods-as-global-trade-war-heats-up-1560616982719.html" rel="noopener" target="_blank"&gt;imposition of retaliatory tariffs&lt;/a&gt; on 28 US products.&lt;/p&gt;
&lt;blockquote class="quoted" style="text-align: justify; "&gt;The US-India dynamic is graduating from the erstwhile top-heavy approach based on the personal relations developed between head of states, to an institutionalised format of consultative platforms on varied bureaucratic, legislative, military, and even public-private partnership levels.&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;Furthermore, ahead of Secretary of State Mike Pompeo’s visit to New Delhi last month, the Trump administration &lt;a href="https://thewire.in/diplomacy/us-india-h1b-visa-data-localisation" rel="noopener" target="_blank"&gt;reportedly&lt;/a&gt; mulled capping the issuance of H1B visas to about 15 percent for any country that “&lt;a href="https://thewire.in/diplomacy/us-india-h1b-visa-data-localisation" rel="noopener" target="_blank"&gt;does data localisation&lt;/a&gt;.” It bore ominous prospects for India’s &lt;a href="https://thewire.in/diplomacy/us-india-h1b-visa-data-localisation" rel="noopener" target="_blank"&gt;$150 billion IT sector&lt;/a&gt; as &lt;a href="https://thewire.in/diplomacy/us-india-h1b-visa-data-localisation" rel="noopener" target="_blank"&gt;70 percent of the 85,000 H1B visas&lt;/a&gt; issued every year go to Indians. With regards to the broader trajectory of US-India ties, the report came to be seen as another blow to the Carter &lt;em&gt;mantra&lt;/em&gt;’s prescription for compartmentalisation of issues from promising aspects of the bilateral relationship.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Both sides however, have attempted to temper tensions, and keep the Carter &lt;em&gt;mantra &lt;/em&gt;in place with the continued focus on evolving strategic ties — with continued impetus on US-India &lt;a href="https://timesofindia.indiatimes.com/india/india-lining-up-defence-deals-worth-10-billion-with-us-amid-trade-row/articleshow/69919916.cms" rel="noopener" target="_blank"&gt;defence trade&lt;/a&gt; and &lt;a href="https://www.hindustantimes.com/india-news/india-us-to-take-forward-talks-for-key-military-pact/story-bi2IfgMjKtKsfA2wjTqQzM.html" rel="noopener" target="_blank"&gt;force interoperability agreements&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;More importantly, there seems to be an overt attempt to reinstitute a sense of compartmentalisation. For instance, Secretary Pompeo, during his visit to New Delhi &lt;a href="https://www.news18.com/news/india/mike-pompeo-in-india-live-india-us-relationship-has-made-strides-but-we-can-do-more-says-us-secy-of-state-2203957.html" rel="noopener" target="_blank"&gt;eased fears&lt;/a&gt; by denouncing reports about the US considering H1B visa caps. Whereas, India, too, has sought to institute a sense of compartmentalisation with Commerce Minister Piyush Goyal announcing that the contentious data protection issue will be &lt;a href="https://www.livemint.com/politics/policy/data-storage-rules-out-of-e-commerce-policy-1561488393145.html" rel="noopener" target="_blank"&gt;kept out of the e-commerce policy draft&lt;/a&gt;, and will be dealt with by the IT ministry instead.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Lastly, the US-India dynamic is graduating from the erstwhile top-heavy approach based on the personal relations developed between head of states, to an institutionalised format of consultative platforms on varied bureaucratic, legislative, military, and even public-private partnership levels. Examples of which include, the &lt;a href="https://www.timesnownews.com/india/article/india-us-officials-to-meet-for-laying-groundwork-for-two-plus-two-dialogue-with-china-on-agenda/405609" rel="noopener" target="_blank"&gt;US-India 2+2&lt;/a&gt; consultative platform between foreign and defense portfolio chiefs, and the &lt;a href="https://www.livemint.com/industry/energy/india-us-discuss-crude-oil-price-volatility-1560179681174.html" rel="noopener" target="_blank"&gt;India-US Strategic Energy Partnership&lt;/a&gt; working groups between India’s Petroleum Minister and US Energy Secretary. The upcoming editions of these forums are set to be critical in addressing outstanding issues in the strategic realm, like India’s &lt;a href="https://www.orfonline.org/expert-speak/the-turkish-interjection-in-indo-us-relations-49800/" rel="noopener" target="_blank"&gt;purchase of the Russian S-400 systems inviting the prospect of American CAATSA sanctions&lt;/a&gt;, and India’s push for a &lt;a href="https://qz.com/india/1651932/mike-pompeos-india-visit-to-push-us-oil-and-gas-over-irans/" rel="noopener" target="_blank"&gt;gas-based economy in light of reduced oil purchases from Iran following recent tensions between Washington and Tehran&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Similarly, on easing the hardening American and Indian stances on data localisation, in addition to compartmentalisation, a consultative approach must be explored. Towards that end, the &lt;a href="http://pib.nic.in/newsite/PrintRelease.aspx?relid=188617" rel="noopener" target="_blank"&gt;India-US Commercial Dialogue and India-US CEO Forum&lt;/a&gt; could serve as appropriate starting points for a joint working group involving a diverse set of stakeholders from the public and private realm.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/observer-research-foundation-shashidhar-kj-and-kashish-parpiani-july-22-2019-easing-the-us-india-divergence-on-data-localisation'&gt;https://cis-india.org/internet-governance/news/observer-research-foundation-shashidhar-kj-and-kashish-parpiani-july-22-2019-easing-the-us-india-divergence-on-data-localisation&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Shashidhar KJ and Kashish Parpiani</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-07-30T01:40:24Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/the-wire-shweta-mohandas-july-30-2019-in-india-privacy-policies-of-fintech-companies-pay-lip-service-to-user-rights">
    <title>In India, Privacy Policies of Fintech Companies Pay Lip Service to User Rights</title>
    <link>https://cis-india.org/internet-governance/blog/the-wire-shweta-mohandas-july-30-2019-in-india-privacy-policies-of-fintech-companies-pay-lip-service-to-user-rights</link>
    <description>
        &lt;b&gt;A study of the privacy policies of 48 fintech companies that operate in India shows that none comply with even the basic requirements of the IT Rules, 2011.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Shweta Mohandas highlighting the key observations in Fintech study conducted by CIS was &lt;a class="external-link" href="https://thewire.in/tech/india-fintech-data-privacy"&gt;published in the Wire&lt;/a&gt; on July 30, 2019.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Earlier this month, an &lt;a href="https://www.huffingtonpost.in/entry/fintech-apps-privacy-snooping-credit-vidya_in_5d1cbc34e4b082e55373370a"&gt;investigation&lt;/a&gt; revealed that a Hyderabad-based fintech company called CreditVidya was sneakily collecting user data through their devotional and music apps to assess people’s creditworthiness.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This should be unsurprising as the privacy policies of most Indian fintech companies do not specify who they will be sharing the information with. Instead, they employ vague terminology to identify sharing arrangements such as ‘third-party’, ‘affiliates’ etc.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This is one of the many findings that we came across while analysing the &lt;a href="https://cis-india.org/internet-governance/files/Hewlett%20A%20study%20of%20FinTech%20companies%20and%20their%20privacy%20policies.pdf"&gt;privacy policies of 48 fintech companies&lt;/a&gt; that operate in India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The study looked at how the privacy policies complied with the requirements of the existing data protection regime in India – the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) &lt;a href="https://www.wipo.int/edocs/lexdocs/laws/en/in/in098en.pdf"&gt;Rules&lt;/a&gt;, 2011.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The &lt;a href="https://www.wipo.int/edocs/lexdocs/laws/en/in/in098en.pdf"&gt;IT Rules&lt;/a&gt;, among other things, require that privacy policies specify the type of data being used, the purpose of collection, the third parties the data will be shared with, the option to withdraw consent and the grievance redressal mechanism.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The rules also require the privacy policy to be easily accessible as well as easy to understand. The problem is that they are not as comprehensive and specific as, say, the draft Personal Data Protection Bill, which is awaiting passage through parliament, and hence require the companies to do much less than privacy and data protection practices emerging globally.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nevertheless, despite the limited requirements, none of the companies in our sample of 48 were fully compliant with the parameters set by the IT Rules.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While 95% of the companies did fulfil the basic requirement of actually formulating and having a privacy policy, two major players stood out as defaulters: Airtel Payments Bank and Bhim UPI, for which we were not able to locate a privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Though a majority of the privacy policies contained the statement “we take your privacy and security seriously”, 43% of the companies did not provide adequate details of the reasonable security practices and procedures followed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The requirement in which most companies did not provide information for was regarding a grievance redressal mechanism, where only 10% of the companies comply.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While 31% of the companies provided the contact of a grievance redressal officer (some without even mentioning the redressal mechanism), 37% of the companies provided contact details of a representative but did not specify if this person could be contacted in case of any grievance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Throughout the study, it was noted that the wording of the IT Rules allowed companies to use ambiguous terms to ensure compliance without exposing their actual data practices. For example, Rule 5 (7) requires a fintech company to provide an option to withdraw consent. Twenty three percent of the companies allowed the user to opt out or withdraw from certain services such as mailing list, direct marketing and in app public forums but they did not allow the user to withdraw their consent completely. While several of 17 companies did provide the option to withdraw consent, they did not clarify whether the withdrawal also meant that the user’s data was no processed or shared.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, when it came to data retention, most of the 27 companies that provided some degree of  information about the retention policy stated that some data would be stored for perpetuity either for analytics or for complying with law enforcement. The remaining 21 companies say nothing about their data retention policy.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;In local languages&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The issue of ambiguity most clearly arises when the user is actually able to cross the first hurdle – reading an app’s privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With fintech often projected as one of the drivers of greater financial inclusion in India, it is telling that only one company (PhonePe) had the option to read the privacy policy in a language other than English. With respect to readability, we noted that the privacy policies were difficult to follow not just because of legalese and length, but also because of fonts and formatting – smaller and lighter texts, no distinction between paragraphs etc. added to the disincentive to read the privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Privacy policies act as a notice to individuals about the terms on which their data will be treated by the entity collecting data. However, they are a monologue in terms of consent where the user only has the option to either agree to it or decline and not avail the services. Moreover, even the notice function is not served when the user is unable to read the privacy policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;They, thus, serve as mere symbols of compliance, where they are drafted to ensure bare minimum conformity to legal requirements. However, the responsibility of these companies lies in giving the user the autonomy to provide an informed consent as well as to be notified in case of any change in how the data is being handled (this could be when and whom the data is being shared with, if there has been a breach etc).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With the growth of fintech companies and the promise of financial inclusion, it is imperative that the people using these services make informed decisions about their data. The draft Personal Data Protection Bill – in its current form – would encumber companies processing sensitive personal data with greater responsibility and accountability than before. However, the Bill, similar to the IT Rules, endorses the view of &lt;a href="https://www.medianama.com/wp-content/uploads/Centre-for-Internet-and-Society-Submission-India-Draft-Data-Protection-Bill-Privacy-2018.pdf"&gt;blanket consent&lt;/a&gt;, where the requirement for change in data processing is only of periodic notice (Section 30 (2)), a lesson that needs to be learnt from the CreditVidya story.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In addition to blanket consent, the SPD/I Rules and well as the PDP Bill does not require the user to be notified in all cases of a breach. While the information that is provided to data subjects is necessary to be designed keeping the user in mind, neither the SPD/I Rules, nor the PDP Bill take into account the manner in which data flows operate in the context of ‘disruptive’ business models that are a hallmark of the ‘fintech revolution’.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/the-wire-shweta-mohandas-july-30-2019-in-india-privacy-policies-of-fintech-companies-pay-lip-service-to-user-rights'&gt;https://cis-india.org/internet-governance/blog/the-wire-shweta-mohandas-july-30-2019-in-india-privacy-policies-of-fintech-companies-pay-lip-service-to-user-rights&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>shweta</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-07-31T02:21:40Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/samyukta-prabhu-ambika-tandon-torsha-sarkar-and-aayush-rathi-august-4-2019-comments-on-national-digital-health-blueprint">
    <title>Comments on the National Digital Health Blueprint</title>
    <link>https://cis-india.org/internet-governance/blog/samyukta-prabhu-ambika-tandon-torsha-sarkar-and-aayush-rathi-august-4-2019-comments-on-national-digital-health-blueprint</link>
    <description>
        &lt;b&gt;The Ministry of Health and Family Welfare had released the National Digital Health Blueprint on 15 July 2019 for comments. The Centre for Internet &amp; Society submitted its comments.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This submission presents comments by the Centre for Internet and Society (CIS), on the National Digital Health Blueprint (NDHB) Report, released on 15th July 2019 for publicconsulations. It must be noted at the outset that the time given for comments was less than three weeks, and such a short window of time is inadequate for all stakeholdersinvolved to comprehensively address the various aspects of the Report. Accordingly, on behalf of all other interested parties, we request more time for consultations.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;We also note that the nature of data which would be subject to processing in the proposed digital framework pre-supposes a robust data protection regime in India, onewhich is currently absent. Accordingly, we also urge ceasing the implementation of the framework until the Personal Data Protection Bill is passed by the parliament. We wouldbe explaining our reasonings on this particular point below.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Click to download the &lt;a class="external-link" href="http://cis-india.org/internet-governance/files/cis-comments-on-ndhb"&gt;full submission here&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/samyukta-prabhu-ambika-tandon-torsha-sarkar-and-aayush-rathi-august-4-2019-comments-on-national-digital-health-blueprint'&gt;https://cis-india.org/internet-governance/blog/samyukta-prabhu-ambika-tandon-torsha-sarkar-and-aayush-rathi-august-4-2019-comments-on-national-digital-health-blueprint&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Samyukta Prabhu, Ambika Tandon, Torsha Sarkar and Aayush Rathi</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-08-07T13:24:55Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/digital-id-forum-2019">
    <title>Digital ID Forum 2019</title>
    <link>https://cis-india.org/internet-governance/news/digital-id-forum-2019</link>
    <description>
        &lt;b&gt;Sunil Abraham was one of the panelists at this event at Chulalongkorn University on July 3, 2019.&lt;/b&gt;
        &lt;p&gt;&lt;img src="https://cis-india.org/home-images/DigitalID.png" alt="Digital ID" class="image-inline" title="Digital ID" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Click to &lt;/span&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/digital-id-forum"&gt;view the agenda&lt;/a&gt;&lt;span&gt;. Also see &lt;/span&gt;&lt;a class="external-link" href="https://en.wikipedia.org/wiki/Asia_Source"&gt;Wikipedia page&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/digital-id-forum-2019'&gt;https://cis-india.org/internet-governance/news/digital-id-forum-2019&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Digital ID</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Appropriate Use of Digital ID</dc:subject>
    
    
        <dc:subject>Digital Identity</dc:subject>
    

   <dc:date>2019-08-07T14:09:16Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/national-stakeholders-consultation-on-the-national-digital-health-blueprint">
    <title>National Stakeholders Consultation on the National Digital Health Blueprint</title>
    <link>https://cis-india.org/internet-governance/news/national-stakeholders-consultation-on-the-national-digital-health-blueprint</link>
    <description>
        &lt;b&gt;Ambika Tandon and Aayush Rathi attended the National Stakeholders Consultation on the National Digital Health Blueprint organised by the Ministry of Health and Family Welfare on 6 August 2019 at Constitution Club of India in New Delhi. &lt;/b&gt;
        &lt;p&gt; &lt;/p&gt;
&lt;div id="_mcePaste" style="text-align: justify; "&gt;It was also attended by representatives from MeitY apart from industry and civil society. We raised questions about the provisions for privacy andinteroperability in the NDHB, in relation to provisions in the DISHA Act and the Srikrishna report. The public call for the event can be &lt;a class="external-link" href="http://pib.nic.in/newsite/PrintRelease.aspx?relid=192436"&gt;found here&lt;/a&gt;.&lt;/div&gt;
&lt;p&gt; &lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/national-stakeholders-consultation-on-the-national-digital-health-blueprint'&gt;https://cis-india.org/internet-governance/news/national-stakeholders-consultation-on-the-national-digital-health-blueprint&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-08-07T14:21:29Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/ietf-105">
    <title>IETF 105</title>
    <link>https://cis-india.org/internet-governance/news/ietf-105</link>
    <description>
        &lt;b&gt;Gurshabad Grover attended a meeting of the Internet Engineering Task Force (IETF), IETF105, held in Montreal from July 20 - 26.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Gurshabad &lt;span&gt;participated in several IETF working group meetings, IRTF researchgroups meetings and other sessions, including ones on Captive Portals,Transport Layer Security, Applications Doing DNS, DNS Privacy, andSoftware Updates for IoT Devices. &lt;/span&gt;&lt;span&gt;At the meeting of the Human Rights Protocol Considerations (hrpc) research group of the IRTF, I co-presented (with Niels ten Oever) an update to the Internet Draft we are editing, 'Guidelines for Human Rights Protocol and Architecture Considerations'. For more info, &lt;a class="external-link" href="https://www.ietf.org/blog/ietf-105-highlights/"&gt;click here&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/ietf-105'&gt;https://cis-india.org/internet-governance/news/ietf-105&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2019-08-13T01:38:36Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
