<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 661 to 675.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/keeping-it-private"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/whose-data-is-it"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/how-facebook-is-blatantly-abusing-our-trust"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/india-privacy-meet"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/indias-biometric-identification-programs-and-privacy-concerns"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/events/privacy-round-table-in-bangalore"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/comments-on-the-it-reasonable-security-practices-and-procedures-and-sensitive-personal-data-or-information-rules-2011"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/comments-on-it-electronic-service-delivery-rules-2011"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-hindu-december-28-2014-ajai-sreevatsan-targeting-surveillance"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/symposium-on-human-rights-and-internet-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/security-and-surveillance-optimizing-security-while-safeguarding-human-rights"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/connecting-the-dots-options-for-future-action"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-hindu-march-17-2015-aadhaar-an-identity-crisis"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/what-does-facebook-transparency-report-tell-us-about-indian-government-record-on-free-expression-and-privacy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-namrata-acharya-april-12-2015-surveillance-rises-privacy-retreats"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/keeping-it-private">
    <title>Keeping it Private</title>
    <link>https://cis-india.org/internet-governance/keeping-it-private</link>
    <description>
        &lt;b&gt;As we disclose more information online, we must ask who might access it and why. This article by Nishant Shah was published in the Indian Express on Sunday, 15 January 2012. &lt;/b&gt;
        
&lt;p&gt;As a researcher of the blink-and-change cyberspaces, I am often asked 
about the future of all things digital. I generally refuse to answer 
such questions because researchers are happier talking about things past
 than things present. Also, when people ask questions of the future, 
they are more interested in gadgets and platforms. Will Facebook survive
 the next year? Will more people use Twitter? Is the mobile the new 
weapon of protest? Shall we all soon talk only on FaceTime? I shrug my 
shoulders at these questions. However private information and privacy 
ties all these questions.&lt;/p&gt;
&lt;p&gt;I pronounce that 2012 is going to be the year of Personal Information Management and the need for increased privacy, where more than anything else, people will realise that what they do online is not only significant to their present, but that it might bite them in their digital futures. We have heard stories that have hinted at management of information and reputations online. Young people put compromising pictures and videos online, severely damaging their social and professional relationships; people express opinions on public forums, which might not necessarily reflect them well; users reveal personal information, which can be abused by those with malice. These instances should remind us that unlike in the physical worlds, where our foot-in-the-mouth moments, youthful indiscretions or embarrassing behaviour quickly runs through the grapevine and is forgotten, in the digital worlds, the things that we say and do, stay long after we have forgotten them.&lt;/p&gt;
&lt;p&gt;And this is where privacy kicks in. Many people in India, when they encounter the idea of “privacy”, raise their eyebrows. Culturally, we are not very private people. We celebrate our triumphs and sorrows in public, freely part with information to strangers on train rides, and don’t have qualms asking about age, marital status or salary. In the age of ubiquitous computing, we must remember that once something has been committed to the online world, it will be etched somewhere and will be available for somebody else to look at. The internet, specially with increasing bandwidth, expanded spectrum and cloud-based distributed data storage, is an unforgiving space that never lets go.&lt;/p&gt;
&lt;p&gt;Privacy, in this brave new world, is not about disclosure. It is becoming increasingly clear that we will need to disclose more and more of our private information if we want services — from government public delivery systems to private credit and education — online. However, once we have disclosed our private information, then what? Who uses it? Who reads it? Who stores it for what purpose? What are the implications of having that private information out there?&lt;/p&gt;
&lt;p&gt;In the digital world, privacy is about having more control over the personal information that we have disclosed, the right to know who, where, when, how and for what purposes information that we have willingly disclosed is used. And as the country finalises privacy bills, this right of the individual, whose private information is going to feed government and business ecologies, is at stake.&lt;/p&gt;
&lt;p&gt;There is a need to institute better regulation around data protection, data mining, data retention and data retrieval that is still in the limbo in our country, at the mercy of privately crafted terms of service that we blindly accept while signing into the digital world.&lt;/p&gt;
&lt;p&gt;It is time to move away from understanding privacy as disclosure to privacy as control of information — to know who is doing what with your private information and how you should have a say in it. And it is time to realise that just because you don’t have anything to hide, does not mean that you need to be in a state of disclosure. There is a reason why you have curtains in your house, or do not allow strangers to look into your bags.&lt;/p&gt;
&lt;p&gt;&lt;a class="external-link" href="http://www.indianexpress.com/news/keeping-it-private/899804/1"&gt;The article was originally published in the Indian Express&lt;/a&gt;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/keeping-it-private'&gt;https://cis-india.org/internet-governance/keeping-it-private&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>nishant</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-01-27T03:50:51Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/whose-data-is-it">
    <title> Whose Data is it Anyway?</title>
    <link>https://cis-india.org/internet-governance/whose-data-is-it</link>
    <description>
        &lt;b&gt;Tactical Technology Collective and the Centre for Internet &amp; Society invite you to the second round of discussions of the Exposing Data Series at the CIS office in Bangalore on 24 January 2012. Siddharth Hande and Hapee de Groot will be speaking on this occasion.&lt;/b&gt;
        
&lt;p&gt;Like countless others, this title is a convenient adaptation of a 1972 play by Brian Clark, Whose Life is it Anyway?, a meditation on 'euthanasia' and the extent to which governments or the law can determine the private life of an individual. In a similar sense we use the title to help frame the second set of conversations in the Exposing Data Series, to zero in on the idea of data and who has the right to decide what happens with it. Philosophically, and also at the level of code, computing and the law, the ownership of data can be a somewhat odd and a contentious thing to grapple with. The only other understandings of 'ownership' we really have are those of property and identity and these get imputed onto the intangibility of data. And, in some senses now, many aspects of one's identity exist as data.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;There are a range of experiences of data ownership that we talk about and experience daily. On the one hand you can hoard hard disks with favourite content to retrieve memories and experiences. On the other end of things, you can aggregate your experiences and memories with that of thousands of others, that then gets treated almost like a private hard disk belonging to some mysterious X. Who is this Mysterious X? Is there a Y? Or an XY? What is the trajectory of data in its movement from the individual to a larger, shadowy infrastructure that harvests it? What happens to our idea of data in its reconfiguration from intangible code to an idea of politics and rights? To introduce another provocation, do our existing ideas of data ownership objectify individuals? What does this objectification imply for the notion of personal privacy? For example, does the fetishization of 'things' called data obfuscate the idea of personal privacy?&lt;/p&gt;
&lt;p&gt;One of the ways in which we may consider looking at open data initiatives for transparency and accountability is to assess it as discourse, and in relation to what happens when communities aggregate data. Open Government Data usually involves a top-down approach in terms of how it is aggregated, collated, shared, whilst community based approaches are more particular, contextual and local. What do these different approaches give us when we bring them to the same table?&lt;/p&gt;
&lt;p&gt;The second event in the Exposing Data Series will focus on data ownership, looking into open government data and community-based data aggregation, to explore the various levels of data collection, the movement of data and its exchange, its representation, and dissemination in different contexts.&lt;/p&gt;
&lt;h2&gt;Speakers&lt;br /&gt;&lt;/h2&gt;
&lt;ol&gt;&lt;li&gt;Siddharth Hande, Transparent Chennai&lt;/li&gt;&lt;li&gt;Hapee de Groot, Hivos, Netherlands&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;This event is free and open to everyone. However, we would appreciate a confirmation of attendance ahead of time so as to ensure that your space is reserved. To confirm your attendance please write to:&amp;nbsp; &lt;a class="external-link" href="mailto:yelena.gyulkhandanyan@gmail.com"&gt;yelena.gyulkhandanyan@gmail.com &lt;br /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Photo Source:&lt;a class="external-link" href="http://www.freedigitalphotos.net/images/view_photog.php?photogid=2000"&gt; http://www.freedigitalphotos.net/images/view_photog.php?photogid=2000&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a class="external-link" href="http://www.freedigitalphotos.net/images/view_photog.php?photogid=2000"&gt;&lt;strong&gt;VIDEOS&lt;/strong&gt;&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;iframe src="http://blip.tv/play/AYLsxhgA.html?p=1" frameborder="0" height="250" width="250"&gt;&lt;/iframe&gt;&lt;embed style="display:none" src="http://a.blip.tv/api.swf#AYLsxhgA" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;

&lt;iframe src="http://blip.tv/play/AYLsxj8A.html?p=1" frameborder="0" height="250" width="250"&gt;&lt;/iframe&gt;&lt;embed style="display:none" src="http://a.blip.tv/api.swf#AYLsxj8A" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;

&lt;iframe src="http://blip.tv/play/AYLsxwAA.html?p=1" frameborder="0" height="250" width="250"&gt;&lt;/iframe&gt;&lt;embed style="display:none" src="http://a.blip.tv/api.swf#AYLsxwAA" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;

&lt;iframe src="http://blip.tv/play/AYLsxxUA.html?p=1" frameborder="0" height="250" width="250"&gt;&lt;/iframe&gt;&lt;embed style="display:none" src="http://a.blip.tv/api.swf#AYLsxxUA" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;


        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/whose-data-is-it'&gt;https://cis-india.org/internet-governance/whose-data-is-it&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Event Type</dc:subject>
    
    
        <dc:subject>Video</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-04-28T04:12:15Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/how-facebook-is-blatantly-abusing-our-trust">
    <title>How Facebook is Blatantly Abusing our Trust</title>
    <link>https://cis-india.org/internet-governance/how-facebook-is-blatantly-abusing-our-trust</link>
    <description>
        &lt;b&gt;‘Don’t fix it, if it ain’t broken’ is not an adage Facebook seems to subscribe to. Nishant Shah's column on privacy and Facebook was published in First Post on June 27, 2012.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Facebook is just re-emerging from the controversies around how it conducted the voting on its new privacy policies, when it goes and digs itself deeper by trying to push down its email services down the throats of its users. If you have recently logged-in to Facebook, you will have received a notification that says that you have been ‘gifted’ with a free Facebook email account.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, that is a later phenomenon. A couple of days ago, the whole community of Facebook users went about their usual way, without knowing that something substantial had changed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Facebook, who launched their email service as a part of their social networking empire, with or without your consent, has given us a ‘yourname@facebook.com’ email account. I know free things are considered good, but not an email account that I did not sign up for!&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;And to make things worse, this email account was, without our consent, added to our time-line and displayed as the primary email address.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In itself, it is a small move – with the redesign of the Timeline, Facebook had already introduced many such forced disclosures and changes that most of just had to accept, even if it might have had us fuming. However, with this change, Facebook has now started showing exactly what it can do in building your public profile and creating information about you, without your consent.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In their lame PR spiel, the company tried to pass it off as a freebie that they were gifting their users. But anybody who was not born yesterday realises that this is a desperate attempt to make a floundering service work.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Facebook messaging may work despite the clunky user interface, but its email services remain terribly underused. One of the paradoxes for this lies in the fact that you cannot open a Facebook account without a primary email account with another service, which is used as your authentication as well as the system through which Facebook notifications work.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Thus, many times, when introducing Facebook to first-time users of the web, we have to first train them in creating and using an email account before they can get on to the social network.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Hence, when Facebook did offer users the option of using a Facebook email service, most of them politely declined because nobody in their right mind is going to migrate to new a email services unless there was a substantial range of benefits being offered.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So how did Facebook respond? It just forced the email service upon its millions of users. While this is no different from the other kind of restrictions that are imposed upon us within the Facebook universe – the advertisements we see, the design and layout, the insipid white-and-blue background, the kind of information we can and cannot share and display – etc. this is the first time that Facebook actually added to our information profile and displayed it to the public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Which means, that the next time somebody looks you up on Facebook – and let’s face it, one of the things we all use Facebook for, is to find people we know and get connected with them – they will see your Facebook email id listed as your contact address. And while you might get a notification in your primary email about any mails that you receive in your Facebook account, the fact is that, all those emails will become a part of Facebook’s huge data farms.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In a move that is almost a pale imitation of Google’s growing monopoly over our private information, Facebook seems to be now looking to expand its data empires. However, while Google did it through strategic design and marketing, offering innovations and incentives for its users to use their services, Facebook seems to have decided to build a Trojan horse and sneak these services in through the back door.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While this might not seem a big deal right now, it has deeper repercussions for what this corporate behemoth can do, not only with our data, but also to our data that we think is actually our own.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;If your alarm bells aren’t already ringing, they should be, as Facebook demonstrates a blatant abuse of the trust that we have put in its system, to keep our private data safe.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The million dollar question – or maybe a slightly reduced price, given its public listing status on the stock-exchange right now – is that while Facebook might keep us safe from other people using our data, will it also be able to keep us safe from itself?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="external-link" href="http://www.firstpost.com/tech/how-facebook-is-blatantly-abusing-our-trust-359263.html"&gt;&lt;span class="visualHighlight"&gt;Read the original here&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/how-facebook-is-blatantly-abusing-our-trust'&gt;https://cis-india.org/internet-governance/how-facebook-is-blatantly-abusing-our-trust&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>nishant</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-06-28T12:42:32Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/india-privacy-meet">
    <title>India Privacy Meet</title>
    <link>https://cis-india.org/news/india-privacy-meet</link>
    <description>
        &lt;b&gt;Microsoft, DSCI and Greyhead came together to organise India Privacy Meet at Hotel LeMeridien on June 29, 2012 in New Delhi. Sunil Abraham was a panelist in the event.&lt;/b&gt;
        &lt;h2&gt;Agenda&lt;/h2&gt;
&lt;table class="listing"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;10:00a.m.- &lt;br /&gt;10:10a.m.&lt;/td&gt;
&lt;td&gt;Welcome and Introduction: Rahul Neel Mani, Editor &amp;amp; Co-founder Grey Head Media&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10:10a.m.- &lt;br /&gt;10:30a.m.&lt;/td&gt;
&lt;td&gt;Conference Opening Remarks: Dr. Kamlesh Bajaj, CEO Data Security Council of India&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10:30a.m.- &lt;br /&gt;10:45a.m.&lt;/td&gt;
&lt;td&gt;Theme Address: Deepak Rout, CSO &amp;amp; Director Privacy, Microsoft India&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10:45a.m.- &lt;br /&gt;11:00a.m.&lt;/td&gt;
&lt;td&gt;Tea/Coffee Break&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11:00a.m.- &lt;br /&gt;12:00p.m.&lt;/td&gt;
&lt;td&gt;Panel 1: Consumer Privacy – Creating the Right Balance&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Brief&lt;/b&gt;: Data Privacy is perhaps the most concerning issue in the digital age.  Consumer privacy or customer privacy, involves the handling and protection of sensitive personal information that individuals provide in the course of everyday  commercial or professional transactions. This involves exchange or use of data electronically or  by other means, including telephone, fax, writing, and word of mouth. With the advent and evolution of Internet and other electronic methods of mass communications, consumer privacy has become a major concern to deal with. Personal information, when misused or inadequately protected, can result in identity theft, financial fraud, and other problems that collectively cost  individuals, businesses, and governments. In addition, Internet crimes and civil disputes consume  law enforcement and judicial  resources, confound legislators and bureaucracy, and produce untold personal aggravation.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Key Discussion Areas:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Handling of Personal Information including Sensitive Personal Information&lt;/li&gt;
&lt;li&gt;Customer education on understanding business models and motives behind collection and use of Personal Information? &lt;/li&gt;
&lt;li&gt;Privacy legislation and striking the right balance between various objectives&lt;/li&gt;
&lt;li&gt;Privacy by design, online tracking, and transparency issues&lt;/li&gt;
&lt;li&gt;Role of Government, Academia and Citizen groups &lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Panelists:&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;Chair - Dr. Kamlesh Bajaj, CEO, Data Security Council of India (DSCI)&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Sivarama Krishnan, Executive Director, PwC India&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Pankaj Agarwal, Head of IT Governance &amp;amp; CISO Aircel&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Prashant Mali, Advocate &amp;amp; Cyber Law Expert &lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Deepak Rout, CSO &amp;amp; Director Privacy, Microsoft India&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Vishal Jain, Director, Ernst &amp;amp; Young&lt;/li&gt;
&lt;/ul&gt;
&lt;table class="listing"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;12:00p.m.- 01:00p.m.&lt;/td&gt;
&lt;td&gt;Panel 2: Citizen Privacy &lt;br /&gt;Transparency, Accountability and Social Progress&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Brief&lt;/b&gt;:  While citizens are  adopting  new technologies  which  are  increasingly  making it easier to share information more freely and thereby track individuals more easily, they are also demanding more accountability and openness. Experience indicates that having a more informed citizenry improves services, and accelerates innovation; thus the era of copious content has the potential to generate a host of new services and businesses. However, there is a need for greater transparency in the handling of citizen data and its legitimate use  in  governance and law enforcement. While new age technologies, if inappropriately used, have a potential impact on citizens’ privacy, they also arm us with the capability to protect citizen data and  provide opportunities for privacy conscious and transparent usage of such data, provided there is an enabling environment created by informed and responsible privacy legislation.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Key Discussion Areas:&lt;/h3&gt;
&lt;ul&gt;
&lt;li style="text-align: justify; "&gt;Core objectives for privacy legislation&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Role of government in protecting citizen privacy&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Citizen awareness of privacy  concerns in today’s legal, business and technology landscape&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Expectations of government  and  citizens on policies around usage and collection of personal data and ability to build profiles for being used for different purposes&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Model privacy legislation&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Panelists:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Chair - &lt;b&gt;Nirmaljeet Singh Kalsi&lt;/b&gt;, Jt. Secretary, Ministry of Home Affairs&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Na Vijaya Shankar&lt;/b&gt;, E-business Consultant &amp;amp; Cyber Law Specialist (Coordinator)&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Sunil Abraham&lt;/b&gt;, Executive Director, Centre for Internet &amp;amp; Society&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Akhilesh Tuteja&lt;/b&gt;, Executive Director, KPMG India&lt;/li&gt;
&lt;li&gt;&lt;b&gt;A P Singh&lt;/b&gt;, DDG, Unique Identification Authority of India (UIDAI)&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Kailas Karthikeyan&lt;/b&gt;, Regulatory &amp;amp; Pub Policy Manager, Legal and Corp Affairs Microsoft&lt;/li&gt;
&lt;/ul&gt;
&lt;table class="listing"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;01:00p.m.- &lt;br /&gt;01:10p.m.&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Conference Closing Remarks by Deepak Rout, CSO &amp;amp; Director, Privacy Microsoft India&lt;/p&gt;
&lt;p&gt;Vote of Thanks&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;01:15p.m. onwards&lt;/td&gt;
&lt;td&gt;Lunch&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/india-privacy-meet'&gt;https://cis-india.org/news/india-privacy-meet&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2012-07-02T10:48:54Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/indias-biometric-identification-programs-and-privacy-concerns">
    <title>India's Biometric Identification Programs and Privacy Concerns</title>
    <link>https://cis-india.org/internet-governance/blog/indias-biometric-identification-programs-and-privacy-concerns</link>
    <description>
        &lt;b&gt;The invasiveness of individual identification coupled with the fallibility of managing big data which biometric identification presents poses a huge risk to individual privacy in India.
&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify;"&gt;Divij Joshi is a 2nd year at NLS. He is interning with the Centre for Internet and Society for the privacy project. &lt;em&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/em&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;Introduction&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;Biometric technology looks to be the way ahead for the Indian government in its initiatives towards identification. From the Unique Identity Scheme (Aadhaar) to the National Population Register and now to Election ID’s, [1] biometric identification seems to have become the government’s new go-to solution for all kinds of problems. Biometrics prove to be an obvious choice in individual identification schemes – it’s easiest to identify different individuals by their faces and fingerprints, unique and integral aspects of individuals – yet, the unflinching optimism in the use of biometric technology and the collection of biometric data on a massive scale masks several concerns regarding compromises of individual privacy.&lt;/p&gt;
&lt;h3 style="text-align: justify;"&gt;‘Big Data’ and Privacy Issues&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;Biometric data is going to be collected under several existing and proposed identification schemes of the government, from the Centralized Identities Data Register of the UID to the draft DNA Profiling Bill which seeks to improve criminal forensics and identification. With the completion of the biometric profiling under the UID, the Indian government will have the largest database of personal biometric data in the world. [3] With plans for the UID to be used for several different purposes — as a ration card, for opening a banking account, for social security and healthcare and several new proposed uses emerging everyday,&lt;a name="fr1" href="#fn1"&gt;[1]&lt;/a&gt; the creation of ‘Big Data’ becomes possible. ‘Big Data’ is characterized by the volume of information that is produced, the velocity by which data is produced, the variety of data produced and the ability to draw new conclusions from an analysis of the data.&lt;a name="fr2" href="#fn2"&gt;[2]&lt;/a&gt; The UID will generate “Big Data” as it is envisioned that the number will be used in every transaction for any platform that adopts it — for all of the 1.2 billion citizens of India. In this way the UID is different any other identity scheme in India, where the identifier is used for a specific purpose at a specific point of time, by a specific platform, and generates data only in connection to that service. Though the creation of “Big Data” through the UID could be beneficial through analysing data trends to target improved services, for example, at the same time it can be problematic in case of a compromise or breach, or if generated information is analyzed to draw new and unintended conclusions about individuals without their consent, and using information for purposes the individuals did not mean for it to be used.&lt;/p&gt;
&lt;h3 style="text-align: justify;"&gt;Biometric ID and Theft of Private Data&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;The government has touted identification schemes such as the UID and NPR as a tool to tackle rural poverty, illegal immigration and national security issues and with this as the premise, the concerns about privacy seem to have been left in the lurch. The optimism driving the programmes also means that its potential fallibility is often overlooked in the process. Biometric technology has been proven time and again to be just as easily jeopardized as any other and the threat of biometric identity theft is as real and common as something like credit card fraud, with fingerprints and iris scans being easily capable of replication and theft without the individual owners consent. [2] In fact, compromise or theft of biometric identity data presents an even greater difficulty than other forms of ID because of the fact that it is unique and intrinsic, and hence, once lost cannot be re-issued or reclaimed like traditional identification like a PIN, leaving the individual victim with no alternative system for identification or authentication. This would also defeat the entire purpose behind any authentication and identification schemes. With the amount of personal data that the government plans to store in databases using biometrics, and without adequate safeguards which can be publicly scrutinized, using this technology would be a premature and unsafe move.&lt;/p&gt;
&lt;h3 style="text-align: justify;"&gt;Biometric data and Potential Misuse&lt;/h3&gt;
&lt;p style="text-align: justify;"&gt;Centralised data storage is problematic not only for the issues with data compromise and identity theft, but the problems of potential third-party misuse in the absence of an adequate legal framework for protecting such personal data, and proper technical safeguards for the same, as has been pointed out by the Standing Committee on Finance in its report on the UIDAI project.&lt;a name="fr4" href="#fn4"&gt;[4]&lt;/a&gt; The threat to privacy which these massive centralized databases pose has led to the shelving of similar programmes in England as well as France. [4] Further, concerns have been voiced about data sharing and access to the information contained in the biometric database. The biometric database is to be managed by several contracting companies based in the US. These same companies have legal obligations to share any data with the US government and Homeland Security. [5]&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;A second, growing concern over biometric identification schemes is over the use of biometrics for state surveillance purposes. While the UID’s chief concern on paper has been development, poverty, and corruption alleviation, there is no defined law or mandate which restricts the number from being used for other purposes, hence giving rise to concerns of a function creep - a shift in the use of the UID from its original intended purpose. For example, the Kerala government has recently proposed a scheme whereby the UID would be used to track school children.&lt;a name="fr5" href="#fn5"&gt;[5]&lt;/a&gt; Other schemes such as the National Population Register and the DNA Profiling Bill have been specifically set up with security of the State as the mandate and aim.&lt;a name="fr6" href="#fn6"&gt;[6]&lt;/a&gt; With the precise and accurate identification which biometrics offers, it also means that individuals are that much easier to continuously survey and track, for example, by using CCTV cameras with facial recognition software, the state could have real-time surveillance over any activities of any individual.&lt;a name="fr7" href="#fn7"&gt;[7]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;With all kinds of information about individuals connected by a single identifier, from bank accounts to residential and voter information, the threat of increased state surveillance, and misuse of information becomes more and more pronounced. By using personal identifiers like fingerprints or iris scans, agencies can potentially converge data collected across databases, and use it for different purposes. It also means that individuals can potentially be profiled through the information provided from their various databases, accessed through identifiers, which leads to concerns about surveillance and tracking, without the individuals knowledge. There are no Indian laws or policies under data collection schemes which address concerns of using personal identifiers for tracking and surveillance.&lt;a name="fr8" href="#fn8"&gt;[8]&lt;/a&gt; Even if such such use is essential for increased national security, the implementation of biometrics for constant surveillance under the present regime ,where individuals are not notified about the kind of data being collected and for what its being used, would be a huge affront on civil liberties, as well as the Right to Privacy, and prove to be a powerful and destructive weapon in the hands of a police state. Without these concerns being addressed by a suitable, publicly available policy, it could pose a huge threat to individual privacy in the country. As was noted by the Deputy Prime Minister of the UK, Nick Clegg, in a speech where he denounced the Identity Scheme of the British government, saying that “This government will end the culture of spying on its citizens. It is outrageous that decent, law-abiding people are regularly treated as if they have something to hide. It has to stop. So there will be no ID card scheme. No national identity register, a halt to second generation biometric passports.” [6]&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;Biometric technology has been useful in several programmes and policies where its use has been open to scrutiny and restricted to a specific function, for example, the recent use of facial recognition in Goa to tackle voter fraud, and similar schemes being taken up by the Election Commission. [7] However, with lack of any guidelines or specific legal framework covering the implementation and collection of biometric data schemes, such schemes can quickly turn into ‘biohazards’ for personal liberty and individual privacy, as has been highlighted above and these issues must be brought to light and adequately addressed before the Government progresses on biometric frontiers.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;[&lt;a name="fn1" href="#fr1"&gt;1&lt;/a&gt;]. &lt;a href="http://www.goacom.com/goa-news-highlights/3520-biometric-scanners-to-be-used-for-elections"&gt;http://www.goacom.com/goa-news-highlights/3520-biometric-scanners-to-be-used-for-elections&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn2" href="#fr2"&gt;2&lt;/a&gt;]. &lt;a href="http://www.wired.com/threatlevel/2008/03/hackers-publish"&gt;http://www.wired.com/threatlevel/2008/03/hackers-publish&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn3" href="#fr3"&gt;3&lt;/a&gt;].&lt;a href="https://www.eff.org/deeplinks/2012/09/indias-gargantuan-biometric-database-raises-big-questions"&gt;https://www.eff.org/deeplinks/2012/09/indias-gargantuan-biometric-database-raises-big-questions&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn4" href="#fr4"&gt;4&lt;/a&gt;]. &lt;a href="http://www.informationweek.com/security/privacy/britain-scraps-biometric-national-id-car/228801001"&gt;http://www.informationweek.com/security/privacy/britain-scraps-biometric-national-id-car/228801001&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn5" href="#fr5"&gt;5&lt;/a&gt;]. &lt;a href="http://www.thehindu.com/opinion/op-ed/questions-for-mr-nilekani/article4382953.ece"&gt;http://www.thehindu.com/opinion/op-ed/questions-for-mr-nilekani/article4382953.ece&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn6" href="#fr6"&gt;6&lt;/a&gt;]. &lt;a href="http://news.bbc.co.uk/2/hi/8691753.stm"&gt;http://news.bbc.co.uk/2/hi/8691753.stm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[&lt;a name="fn7" href="#fr7"&gt;7&lt;/a&gt;]. Supra note 1.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/indias-biometric-identification-programs-and-privacy-concerns'&gt;https://cis-india.org/internet-governance/blog/indias-biometric-identification-programs-and-privacy-concerns&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>divij</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2016-07-21T10:51:42Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/events/privacy-round-table-in-bangalore">
    <title>A Privacy Round Table in Bangalore</title>
    <link>https://cis-india.org/internet-governance/events/privacy-round-table-in-bangalore</link>
    <description>
        &lt;b&gt;The Centre for Internet and Society, Data Security Council of India  and the Federation of Indian Chambers of Commerce and Industry cordially invite you to a "Privacy Round Table" at Jayamahal Palace in Jayamahal Road, Bangalore on Saturday, April 20, 2013, 10.30 a.m. to 4.00 p.m.&lt;/b&gt;
        &lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="external-link" href="http://planningcommission.nic.in/reports/genrep/rep_privacy.pdf"&gt;Report of the Group of Experts on Privacy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy-protection-bill-2013.pdf" class="external-link"&gt;The Privacy Protection Bill, 2013&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/strengthening-privacy-protection.pdf" class="internal-link"&gt;Strengthening Privacy Protection through Co-Regulation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/privacy-roundtable-bangalore" class="internal-link"&gt;Invitation for the Privacy Roundtable&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;To discuss, in furtherance of Internet Governance Initiatives and Dialogue in 2013, the "Report of the Group of Experts on Privacy" by the Justice AP Shah Committee, the text of the Citizens' Privacy (Protection) Bill 2013, drafted by the Centre for Internet and Society, and the paper "Strengthening Privacy Protection through Co-Regulation" by DSCI.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The discussions and recommendations from the meeting will be published  into a compilation, and presented at the Internet Governance meeting  planned for October 2013.&lt;/p&gt;
&lt;table class="listing"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Time&lt;/th&gt;&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;10.30 &lt;br /&gt;&lt;/td&gt;
&lt;td style="text-align: justify; "&gt;Overview, explanation, and discussion: The Report of the Group of Experts on Privacy&lt;br /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;11.30  &lt;br /&gt;&lt;/td&gt;
&lt;td style="text-align: justify; "&gt;Overview, explanation, and discussion: Strengthening Privacy Protection through Co-regulation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;12.15&lt;/td&gt;
&lt;td style="text-align: justify; "&gt;Tea&lt;br /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;
&lt;p&gt;12.30&lt;/p&gt;
&lt;/td&gt;
&lt;td style="text-align: justify; "&gt;Overview, explanation, and discussion: The Citizens (Protection) Bill 2013&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;13.15&lt;/td&gt;
&lt;td&gt;Lunch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: justify; "&gt;14.15  &lt;br /&gt;&lt;/td&gt;
&lt;td style="text-align: justify; "&gt;In depth discussions: The Citizens’ Privacy (Protection) Bill 2013 &lt;br /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;p&gt;16.15&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;Tea&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;Confirmations and RSVP&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;Please send your email confirmations for attending the Bangalore Privacy Roundtable on &lt;b&gt;April 20, 2013&lt;/b&gt;, to &lt;b&gt;Snehashish Ghosh&lt;/b&gt; at &lt;a class="mail-link" href="mailto:snehashish@cis-india.org"&gt;snehashish@cis-india.org&lt;/a&gt;, mobile no. +91- 9902763325,latest by end-of-business 5:30 p.m. on Monday &lt;b&gt;April 15, 2013&lt;/b&gt;. As the conference is a roundtable dialogue, we request that attendees  submit a brief introduction about themselves and their interest in the  topic.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/events/privacy-round-table-in-bangalore'&gt;https://cis-india.org/internet-governance/events/privacy-round-table-in-bangalore&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Event</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-04-17T06:55:52Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/comments-on-the-it-reasonable-security-practices-and-procedures-and-sensitive-personal-data-or-information-rules-2011">
    <title>Comments on the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011</title>
    <link>https://cis-india.org/internet-governance/blog/comments-on-the-it-reasonable-security-practices-and-procedures-and-sensitive-personal-data-or-information-rules-2011</link>
    <description>
        &lt;b&gt;Bhairav Acharya on behalf of the Centre for Internet and Society prepared the following comments on the Sensitive Personal Data Rules. These were submitted to the Committee on Subordinate Legislation of the 15th Lok Sabha.&lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;b&gt;I &lt;span&gt;&lt;span&gt;Preliminary&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;1.1  The Centre for Internet and Society (&lt;b&gt;“CIS”&lt;/b&gt;) is pleased to present this submission on the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 that were notified by the Central Government in the Gazette of India vide Notification GSR 313(E) on 11 April 2011 (&lt;b&gt;“Sensitive Personal Data Rules” or “Rules”&lt;/b&gt;) to the Committee on Subordinate Legislation of the Fifteenth Lok Sabha.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;1.2 The protection of personal information lies at the heart of the right to privacy; and, for this reason, it is an imperative legislative and policy concern in liberal democracies around the world. In India, although remedies for invasions of privacy exist in tort law and despite the Supreme Court of India according limited constitutional recognition to the right to privacy&lt;a href="#fn1" name="fr1"&gt;[1]&lt;/a&gt;, there have never been codified provisions protecting the privacy of individuals and their personal information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Sensitive Personal Data Rules represent India’s first legislative attempt to recognise that all persons have a right to protect the privacy of their personal information. However, the Rules suffer from numerous conceptual, substantive and procedural weaknesses, including drafting defects, which demand scrutiny and rectification. The interpretation and applicability of the Rules was further confused when, on 24 August 2011, the Department of Information Technology of the Ministry of Communications attempted to reinterpret the Rules through a press release oblivious to the universally accepted basic proposition that law cannot be made or reinterpreted via press releases.&lt;a href="#fn2" name="fr2"&gt;[2]&lt;/a&gt; Therefore, the attention of the Committee on Subordinate Legislation of the Fifteenth Lok Sabha is called to the following submissions:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;II &lt;span&gt;Principles to Facilitate Appraisal&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;2.1  The Sensitive Personal Data Rules are an important step towards building a legal regime that protects the privacy of individuals whilst enabling the secure collection, use and storage of personal information by state and private entities. The Rules are to be welcomed in principle. However, at present, the Rules construct an incomplete regime that does not adequately protect privacy and, for this reason, falls short of internationally accepted data protection standards.&lt;a href="#fn3" name="fr3"&gt;[3]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This not only harms the personal liberties of Indian citizens, it also affects the ability of Indian companies to conduct commerce in foreign countries. More importantly, the Rules offer no protection against the state.&lt;/p&gt;
&lt;p&gt;2.2  To enact a comprehensive personal information protection regime, CIS believes that the Rules should proceed on the basis of the following broad principles:&lt;/p&gt;
&lt;p&gt;(a)   &lt;span&gt;Principle of Notice / Prior Knowledge&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;All persons from whom personal information is collected have a right to know, before the personal information is collected and, where applicable, at any point thereafter: (i) of an impending collection of personal information; (ii) the content and nature of the personal information being collected; (iii) the purpose for which the personal information is being collected; (iv) the broad identities of all natural and juristic persons who will have access to the collected personal information; (v) the manner in which the collected personal information will be used; (vi) the duration for which the collected personal information will be stored; (vii) whether the collected personal information will be disclosed to third parties including the police and other law enforcement agencies; (viii) of the manner in which they may access, check, modify or withdraw their collected personal information; (ix) the security practices and safeguards that will govern the sanctity of the collected personal information; (x) of all privacy policies and other policies in relation to the collected personal information; (xi) of any breaches in the security, safety, privacy and sanctity of the collected personal information; and, (xii) the procedure for recourse, including identities and contact details of ombudsmen and grievance redress officers, in relation to any misuse of the collected personal information.&lt;/p&gt;
&lt;p&gt;(b)    &lt;span&gt;Principle of Consent&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Personal information must only be collected once the person to whom it pertains has consented to its collection. Such consent must be informed, explicit and freely given. Informed consent is conditional upon the fulfilment of the principle of notice/prior knowledge set out in the preceding paragraph. Consent must be expressly given: the person to whom the personal information to be collected pertains must grant explicit and affirmative permission to collect personal information; and, he must know, or be made aware, of any action of his that will constitute such consent. Consent that is obtained using threats or coercion, such as a threat of refusal to provide services, does not constitute valid consent. Any person whose personal information has been consensually collected may, at any time, withdraw such consent for any or no reason and, consequently, his personal information, including his identity, must be destroyed. When consent is withdrawn in this manner, the person who withdrew consent may be denied any service that requires the use of the personal information for which consent was withdrawn.&lt;/p&gt;
&lt;p&gt;(c)  &lt;span&gt;Principle of Necessity / Collection Limitation&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Personal information must only be collected when, where and to the extent necessary. Necessity cannot be established in general; there must be a specific nexus connecting the content of the personal information to the purpose of its collection. Only the minimal amount of personal information necessary to achieve the purpose should be collected. If a purpose exists that warrants a temporally specific, or an event-dependent, collection of personal information, such a collection must only take place when that specific time is reached or that event occurs. If the purpose of personal information is dependent upon, or specific to, a geographical area or location, that personal information must only be collected from that geographical area or location.&lt;/p&gt;
&lt;p&gt;(d)  &lt;span&gt;Right to be Forgotten / Principle of Purpose Limitation&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Once collected, personal information must be processed, used, stored or otherwise only for the purpose for which it was collected. If the purpose for which personal information was collected is achieved, the collected personal information must be destroyed and the person to whom that personal information pertained must be ‘forgotten.’ Similarly, collected personal information must be destroyed and the person to whom it pertained ‘forgotten’ if the purpose for which it was collected expires or ceases to exist. Personal information collected for a certain purpose cannot be used or stored for another purpose nor even used or stored for a similar purpose to arise in the future without the express and informed consent of the person from whom it was collected in accordance with the principles of notice/prior knowledge and consent.&lt;/p&gt;
&lt;p&gt;(e)    &lt;span&gt;Right of Access&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;All persons from whom personal information is collected have a right to access that personal information at any point following its collection to check its accuracy, make corrections or modifications and have destroyed that which is inaccurate. Where personal information of more than one person is held in an aggregated form such that affording one person access to it may endanger the right to privacy of another person, the entity holding the aggregated personal information must, to the best of its ability, identify the portion of the personal information that pertains to the person seeking access and make it available to him. All persons from whom personal information is collected must be given copies of their personal information upon request.&lt;/p&gt;
&lt;p&gt;(f)   &lt;span&gt;Principle­ regarding Disclosure&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Personal information, once collected, must never be disclosed. However, if the person to whom certain personal information pertains consents to its disclosure in accordance with the principle of consent after he has been made aware of the proposed disclosee and other details related to the personal information in accordance with the principle of notice/prior knowledge, the personal information may be disclosed. Consent to a disclosure of this nature may be obtained even during collection of the personal information if the person to whom it pertains expressly consents to its future disclosure. Notwithstanding the rule against disclosure and the consent exception to the rule, personal information may be disclosed to the police or other law enforcement agencies on certain absolute conditions. Since the protection of personal information is a policy imperative, the conditions permitting its disclosure must be founded on a clear and serious law enforcement need that overrides the right to privacy; and, in addition, the disclosure conditions must be strict, construed narrowly and, in the event of ambiguity, interpreted to favour the individual right to privacy. Therefore, (i) there must be a demonstrable need to access personal information in connection with a criminal offence; (ii) only that amount of personal information that is sufficient to satisfy the need must be disclosed; and, (iii), since such a disclosure is non-consensual, it must follow a minimal due process regime that at least immediately notifies the person concerned and affords him the right to protest the disclosure.&lt;/p&gt;
&lt;p&gt;(g)  &lt;span&gt;Principle of Security&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;All personal information must be protected to absolutely maintain its sanctity, confidentiality and privacy by implementing safeguards against loss, unauthorised access, destruction, use, processing, storage, modification, de-anonymisation, unauthorised disclosure and other risks. Such a level of protection must include physical, administrative and technical safeguards that are constantly and consistently audited. Protection measures must be revised to incorporate stronger measures and mechanisms as and when they arise.&lt;/p&gt;
&lt;p&gt;(h) &lt;span&gt;Principle of Transparency / ‘Open-ness’&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;All practices, procedures and policies governing personal information must be made available to the person to whom that personal information pertains in a simple and easy-to-understand manner. This includes policies relating to the privacy, security and disclosure of that personal information. If an entity that seeks to collect personal information does not have these policies, it must immediately draft, publish and display such policies in addition to making them available to the person from whom it seeks to collect personal information before the collection can begin.&lt;/p&gt;
&lt;p&gt;(i)  &lt;span&gt;Principle of Accountability&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Liability attaches to the possession of personal information of another person. Since rights and duties, such as those in relation to privacy of personal information, are predicated on accountability, this principle binds all entities that seek to possess personal information of another person. As a result, an entity seeking to collect, use, process, store or disclose personal information of another person is accountable to that person for complying with all these principles as well as the provisions of any law. The misuse of personal information causes harm to the person to whom it pertains to attract and civil and criminal penalties.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;2.3 These principles are reflective of internationally accepted best practices to form the basis upon which Indian legislation to protect personal information should be drafted. The Sensitive Personal Data Rules, in their current form, fall far short of the achieving the substantive intent of these principles. &lt;b&gt;CIS submits that either (i) the Sensitive Personal Data Rules should be replaced with new and comprehensive legislation that speaks to the objectives and purpose of these principles, or (ii) the Sensitive Personal Data Rules are radically modified by amendment to bring Indian law to par with world standards.&lt;/b&gt; Nevertheless, without prejudice to the preceding submission, CIS offers the following clause-by-clause comments on the Sensitive Personal Data Rules:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;III &lt;span&gt;&lt;span&gt;Clause-by-Clause Analysis and Comments&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;span&gt;Rule 2 - Definitions&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;3.1.1    Rule 2(1)(b) of the Sensitive Personal Data Rules defines “biometrics” as follows:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;"Biometrics" means the technologies that measure and analyse human body characteristics, such as 'fingerprints', 'eye retinas and irises', 'voice patterns', "facial patterns', 'hand measurements' and 'DNA' for authentication purposes.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.1.2   &lt;span&gt;Firstly&lt;/span&gt;, the Sensitive Personal Data Rules do not use the term “biometrics.” Instead, rule 3(vi), which defines sensitive personal data, uses the term “biometric information.” It is unclear why rule 2(1)(b) provides a definition of the technologies by which information is obtained instead of clearly identify the information that constitutes sensitive personal data. This is one of several examples of poor drafting of the Sensitive Personal Data Rules. &lt;span&gt;Secondly&lt;/span&gt;, biometric information is not used only for authentication; there are many other reasons for collecting and using biometric information. For instance, DNA is widely collected and used for medical research. Restricting the application of the definition to only that biometric information that is used for authentication is illogical to deprive the Rules of meaning.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.1.3    Therefore, it is proposed that rule 2(1)(b) be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;““Biometric information” means any information relating to the physical, physiological or behavioural characteristics of an individual which enable their unique identification including, but not limited to, fingerprints, retinas, irises, voice patterns, facial patterns, Deoxyribonucleic acid (DNA) and genetic information.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.2.1  Rule 2(1)(c) of the Sensitive Personal Data Rules defines “body corporate” in accordance with the definition provided in clause (i) of the Explanation to section 43A of the Information Technology Act, 2000 (&lt;b&gt;“IT Act”&lt;/b&gt;) as follows:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;“body corporate” means any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.2.2 &lt;span&gt;Firstly&lt;/span&gt;, this definition of a body corporate is poorly drafted to extend beyond incorporated entities to bring within its ambit even unincorporated professional organisations such as societies and associations which, by their very nature, are not bodies corporate.&lt;a href="#fn4" name="fr4"&gt;[4]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This is an arbitrary reinterpretation of the fundamental principles of company law. As it presently stands, this peculiar definition will extend to public and private limited companies, including incorporated public sector undertakings, ordinary and limited liability partnerships, firms, sole proprietorships, societies and associations; but, &lt;span&gt;&lt;span&gt;will exclude public and private trusts&lt;/span&gt;&lt;/span&gt;&lt;a href="#fn5" name="fr5"&gt;[5]&lt;/a&gt; &lt;span&gt;and unincorporated public authorities&lt;/span&gt;. Hence, whereas non-governmental organisations that are organised as societies will fall within the definition of “body corporate,” those that are organised as trusts will not. Similarly, incorporated public authorities such as Delhi Transport Corporation and even municipal corporations such as the Municipal Corporation of Delhi will fall within the definition of “body corporate” but unincorporated public authorities such as the New Delhi Municipal Council and the Delhi Development Authority will not. This is a &lt;i&gt;prima facie&lt;/i&gt; violation of the fundamental right of all persons to be treated equally under the law guaranteed by Article 14 of the Constitution of India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.2.3  &lt;span&gt;Secondly&lt;/span&gt;, whereas state entities and public authorities often collect and use sensitive personal data, with the exception of state corporations the Sensitive Personal Data Rules do not apply to the state. This means that the procedural safeguards offered by the Rules do not bind the police and other law enforcement agencies allowing them a virtually unfettered right to collect and use, even misuse, sensitive personal data without consequence. Further, state entities such as the Unique Identification Authority of India or the various State Housing Boards which collect, handle, process, use and store sensitive personal data are not covered by the Rules and remain unregulated. It is not possible to include these unincorporated entities within the definition of a body corporate; but, in pursuance of the principles set out in paragraph 2.2 of this submission, the Rules should be expanded to all state entities, whether incorporated or not.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.2.4  Therefore, it is proposed that rule 2(1)(c) be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;““body corporate” means the body corporate defined in sub-section (7) of section 2 read with section 3 of the Companies Act, 1956 (1 of 1956) and includes those entities which the Central Government may, by notification in the Official Gazette, specify in this behalf but shall not include societies registered under the Societies Registration Act, 1860 (21 of 1860), trusts created under the Indian Trusts Act, 1882 (2 of 1882) or any other association of individuals that is not a legal entity apart from the members constituting it and which does not enjoy perpetual succession.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Further, it is proposed that the Sensitive Personal Data Rules be re-drafted to apply to societies registered under the Societies Registration Act, 1860 and trusts created under the Indian Trusts Act, 1882 in a manner reflective of their distinctiveness from bodies corporate&lt;/b&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Furthermore, it is proposed that the Sensitive Personal Data Rules be re-drafted to apply to public authorities and the state as defined in Article 12 of the Constitution of India&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;3.3.1  Rule 2(1)(d) of the Sensitive Personal Data Rules defines “cyber incidents” as follows:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;"Cyber incidents" means any real or suspected adverse event in relation to cyber security that violates an explicitly or implicitly applicable security policy resulting in unauthorised access, denial of service or disruption, unauthorised use of a computer resource for processing or storage of information or changes to data, information without authorisation.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.3.2  Before examining the provisions of this clause, CIS questions the need for this definition. The term “&lt;i&gt;cyber incidents&lt;/i&gt;” is used only once in these rules: the proviso to rule 6(1) which specifies the conditions upon which personal information or sensitive personal data may be disclosed to the police or other law enforcement authorities without the prior consent of the person to whom the information pertains. An analysis of rule 6(1) is contained at paragraphs 3.11.1 – 3.11.4 of this submission. &lt;span&gt;Firstly&lt;/span&gt;, personal information and sensitive personal data should only be disclosed in connection with the prevention, investigation and prosecution of an existing offence. Offences cannot be created in the definitions clause of sub-statutory rules, they can only be created by a parent statute or another statute. &lt;span&gt;Secondly&lt;/span&gt;, the scope and content of “cyber incidents” are already covered by section 43 of the IT Act. When read with section 66 of IT Act, an offence is created that is larger than the scope of the term “cyber incidents” to render this definition redundant.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;3.3.3   Therefore, it is proposed that the definition of “cyber incidents” in rule 2(1)(d) be deleted and the remaining clauses in sub-rule (1) of rule 2 be accordingly renumbered.&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.4.1  Rule 2(1)(g) of the Sensitive Personal Data Rules defines “intermediary” in accordance with the definition provided in section 2(1)(w) of the IT Act. However, the term “intermediary” is not used anywhere in the Sensitive Personal Data Rules and so its definition is redundant. This is another instance of careless drafting of the Sensitive Personal Data Rules.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;3.4.2   Therefore, it is proposed that the definition of “intermediary” in rule 2(1)(g) be deleted and the remaining clauses in sub-rule (1) of rule 2 be accordingly renumbered.&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 3 - Sensitive Personal Data&lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;3.5.1    Rule 3 of the Sensitive Personal Data Rules provides an aggregated definition of sensitive personal data as follows:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Sensitive personal data or information of a person means such personal information which consists of information relating to – &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(i)   password; &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;(ii)  financial information such as Bank account or credit card or debit card or other payment instrument details ; &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;(iii) physical, physiological and mental health condition; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(iv) sexual orientation; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(v)  medical records and history; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(vi) Biometric information; &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;(vii) any detail relating to the above clauses as provided to body corporate for providing service; and &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;(viii) any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise: &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt; &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;provided that, any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as sensitive personal data or information for the purposes of these rules.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.5.2    In accordance with the principle that certain kinds of personal information are particularly sensitive, due to the intimate nature of their content in relation to the right to privacy, to invite privileged protective measures regarding the collection, handling, processing, use and storage of such sensitive personal data, it is surprising that rule 3 does not protect electronic communication records of individuals. Emails and chat logs as well as records of internet activity such as online search histories are particularly vulnerable to abuse and misuse and should be accorded privileged protection.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.5.3    Therefore, it is proposed that rule 3 be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;“Sensitive personal data or information of a person means personal information as to that person’s –&lt;/p&gt;
&lt;p&gt;(i)  passwords and encryption keys;&lt;/p&gt;
&lt;p&gt;(ii)  financial information including, but not limited to, information relating to his bank accounts, credit cards, debit cards, negotiable instruments, debt and other payment details;&lt;/p&gt;
&lt;p&gt;(iii) physical, physiological and mental condition;&lt;/p&gt;
&lt;p&gt;(iv)  sexual activity and sexual orientation;&lt;/p&gt;
&lt;p&gt;(v)   medical records and history;&lt;/p&gt;
&lt;p&gt;(vi)  biometric information; and&lt;/p&gt;
&lt;p&gt;(vii) electronic communication records including, but not limited to, emails, chat logs and other communications made using a computer;&lt;/p&gt;
&lt;p&gt;and shall include any data or information related to the sensitive personal data or information set out in this rule that is provided to, or received by, a body corporate.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Provided that, any information that is freely available or accessible in the public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as sensitive personal data or information for the purposes of these rules.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 4 - Privacy and Disclosure Policy&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;3.6.1    Rule 4 of the Sensitive Personal Data Rules, which obligates certain bodies corporate to publish privacy and disclosure policies for personal information, states:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;i&gt;Body corporate to provide policy for privacy and disclosure of information. – &lt;/i&gt;&lt;/b&gt;&lt;i&gt;(1) The body corporate or any person who on behalf of body corporate collects, receives, possess, stores, deals or handle information of provider of information, shall provide a privacy policy for handling of or dealing in personal information including sensitive personal data or information and ensure that the same are available for view by such providers of information who has provided such information under lawful contract. Such policy shall be published on website of body corporate or any person on its behalf and shall provide for –&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(i)  Clear and easily accessible statements of its practices and policies; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(ii) type of personal or sensitive personal data or information collected under rule 3; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(iii) purpose of collection and usage of such information; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(iv) disclosure of information including sensitive personal data or information as provided in rule 6; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(v)  reasonable security practices and procedures as provided under rule 8. &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.6.2  This rule is very badly drafted, contains several discrepancies and is legally imprecise. &lt;span&gt;Firstly&lt;/span&gt;, this rule is overbroad to bind all bodies corporate that receive and use information, as opposed to “personal information” or “sensitive personal data.” All bodies corporate receive and use information, even a vegetable seller uses information relating to vegetables and prices; but, not all bodies corporate receive and use personal information and even fewer bodies corporate receive and use sensitive personal data. The application of this provision should turn on the reception and use of personal information, which includes sensitive personal data, and not simply information. &lt;span&gt;Secondly&lt;/span&gt;, although this rule only applies when a provider of information provides information, the term “provider of information” is undefined. It may mean any single individual who gives his personal information to a body corporate, or it may even mean another entity that outsources or subcontracts work that involves the handling of personal information. This lack of clarity compromises the enforceability of this rule. The government’s press release of 24 August 2011 acknowledged this error but since it is impossible, not to mention unconstitutional, for a statutory instrument like these Rules to be amended, modified, interpreted or clarified by a press release, CIS is inclined to ignore the press release altogether. It is illogical that privacy policies not be required when personal information is directly given by a single individual. This rule should bind all bodies corporate that receive and use personal information irrespective of the source of the personal information. &lt;span&gt;Thirdly&lt;/span&gt;, it is unclear whether separate privacy policies are required for personal information and for sensitive personal data. There is a distinction between personal information and sensitive personal data and since these Sensitive Personal Data Rules deal with the protection of sensitive personal data, this rule 4 should unambiguously mandate the publishing of privacy policies in relation to sensitive personal data. Any additional requirement for personal information must be set out to clearly mark its difference from sensitive personal data. &lt;span&gt;Fourthly&lt;/span&gt;, because of sloppy drafting, the publishing duties of the body corporate in respect of any sensitive personal data are unclear. For example, the phrase “&lt;i&gt;personal or sensitive personal data or information&lt;/i&gt;” used in clause (ii) is meaningless since “personal information” and “sensitive personal data or information” are defined terms.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.6.3  Therefore, it is proposed that rule 3 be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“&lt;b&gt;Duty to publish certain policies. – &lt;/b&gt;(1) Any body corporate that collects, receives, possesses, stores, deals with or handles personal information or sensitive personal data from any source whatsoever shall, prior to collecting, receiving, possessing, storing, dealing with or handling such personal information or sensitive personal data, publish and prominently display the policies listed in sub-rule (2) in relation to such personal information and sensitive personal data.&lt;/p&gt;
&lt;p&gt;(2) In accordance with sub-rule (1) of this rule, all bodies corporate shall publish separate policies for personal information and sensitive personal data that clearly state –&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(i) the meanings of personal information and sensitive personal data in accordance with these rules;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(ii) the practices and policies of that body corporate in relation to personal information and sensitive personal data;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(iii) descriptive details of the nature and type of personal information and sensitive personal data collected, received, possessed, stored or handled by that body corporate;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(iv) the purpose for which such personal information and sensitive personal data is collected, received, possessed, stored or handled by that body corporate;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(v) the manner and conditions upon which such personal information and sensitive personal data may be disclosed in accordance with rule 6 of these rules; and&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(vi) the reasonable security practices and procedures governing such personal information and sensitive personal data in accordance with rule 8 of these rules.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 5 - Collection of Information&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;3.7.1    Rule 5(1) of the Sensitive Personal Data Rules lays down the requirement of consent before personal information can be collected as follows:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;Body corporate or any person on its behalf shall obtain consent in writing through letter or Fax or email from the provider of the sensitive personal data or information regarding purpose of usage before collection of such information.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.7.2 &lt;span&gt;Firstly&lt;/span&gt;, the principle and requirement of consent is of overriding importance when collecting personal information, which includes sensitive personal data. Pursuant to the principles laid down in paragraph 2.2 of this submission, consent must be informed, explicit and freely given. Since sub-rule (3) of rule 5 attempts to secure the informed consent of persons giving personal information, this sub-rule must establish that all personal information can only be collected upon explicit consent that is freely given, irrespective of the medium and manner in which it is given. &lt;span&gt;Secondly&lt;/span&gt;, it may be noted that sub-rule (1) only applies to sensitive personal data and not to other personal information that is not sensitive personal data. This is ill advised.  &lt;span&gt;Thirdly&lt;/span&gt;, this sub-rule relating to actual collection of personal information should follow a provision establishing the principle of necessity before collection can begin. The principle of necessity is currently laid down in sub-rule (2) of rule 5 which should be re-numbered to precede this sub-rule relating to collection.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.7.3   Therefore, it is proposed that rule 5(1) be re-numbered to sub-rule (2) of rule 5 and re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;“A body corporate seeking to collect personal information or sensitive personal data of a person shall, prior to collecting that personal information or sensitive personal data, obtain the express and informed consent of that person in any manner, and through any medium, that may be convenient but shall not obtain such consent through threat, duress or coercion.”&lt;/p&gt;
&lt;p&gt;3.8.1    Rule 5(2) of the Sensitive Personal Data Rules sets out the principle of necessity governing the collection of personal information as follows:&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Body corporate or any person on its behalf shall not collect sensitive personal data or information unless — &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;(a)  the information is collected for a lawful purpose connected with a function or activity of the body corporate or any person on its behalf; and &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;(b) the collection of the sensitive personal data or information is considered necessary for that purpose.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.8.2    &lt;span&gt;Firstly&lt;/span&gt;, before allowing a body corporate to collect personal information, which includes sensitive personal data, the law should strictly ensure that the collection of such personal information is necessary. Necessity cannot be established in general, there must be a nexus connecting the personal information to the purpose for which the personal information is sought to be collected. This important sub-rule sets out the principles upon which personal information can be collected; and, should therefore be the first sub-rule of rule 5. &lt;span&gt;Secondly&lt;/span&gt;, this sub-rule only applies to sensitive personal data instead of all personal information. It is in the public interest that the principle of necessity applies to all personal information, including sensitive personal data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.8.3 &lt;b&gt;Therefore, it is proposed that rule 5(2) be re-numbered to sub-rule (1) of rule 5 and re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;“No body corporate shall collect any personal information or sensitive personal data of a person unless it clearly establishes that –&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;(a) the personal information or sensitive personal data is collected for a lawful purpose that is directly connected to a function or activity of the body corporate; and&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;(b) the collection of the personal information or sensitive personal data is necessary to achieve that lawful purpose.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.9.1 Rule 5(3) of the Sensitive Personal Data Rules attempts to create an informed consent regime for the collection of personal information as follows:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;While collecting information directly from the person concerned, the body corporate or any person on its behalf snail take such steps as are, in the circumstances, reasonable to ensure that the person concerned is having the knowledge of — &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(a)  the fact that the information is being collected; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(b)  the purpose for which the information is being collected; &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(c)  the intended recipients of the information; and &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(d)  the name and address of — &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(i)   the agency that is collecting the information; and &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;(ii)  the agency that will retain the information.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.9.2   &lt;span&gt;Firstly&lt;/span&gt;, this sub-rule (3) betrays the carelessness of its drafters by bringing within its application any and all information collected by a body corporate from a person instead of only personal information or sensitive personal data. &lt;span&gt;Secondly&lt;/span&gt;, this provision is crucial to establishing a regime of informed consent before personal information is given by a person to a body corporate. For consent to be informed, the person giving consent must be made aware of not only the collection of that personal information or sensitive personal data, but also the purpose for which it is being collected, the manner in which it will be used, the intended recipients to whom it will be sent or made accessible, the duration for which it will be stored, the conditions upon which it may be disclosed, the conditions upon which it may be destroyed as well as the identities of all persons who will collect, receive, possess, store, deal with or handle that personal information or sensitive personal data. &lt;span&gt;Thirdly&lt;/span&gt;, the use of the phrase “&lt;i&gt;take such steps as are, in the circumstances, reasonable&lt;/i&gt;” dilutes the purpose of this provision and compromises the establishment of an informed consent regime. Instead, the use of the term “reasonable efforts”, which has an understood meaning in law, will suffice to protect individuals while giving bodies corporate sufficient latitude to conduct their business.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.9.3    Therefore, it is proposed that rule 5(3) be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;“A body corporate seeking to collect personal information or sensitive personal data of a person shall, prior to such collection, make reasonable efforts to inform that person of the following details in respect of his personal information or sensitive personal data –&lt;/p&gt;
&lt;p&gt;(a)  the fact that it is being collected;&lt;/p&gt;
&lt;p&gt;(b)  the purpose for which it is being collected;&lt;/p&gt;
&lt;p&gt;(c)  the manner in which it will be used;&lt;/p&gt;
&lt;p&gt;(d)  the intended recipients to whom it will be sent or made available;&lt;/p&gt;
&lt;p&gt;(e)  the duration for which it will be stored;&lt;/p&gt;
&lt;p&gt;(f)   the conditions upon which it may be disclosed;&lt;/p&gt;
&lt;p&gt;(g)  the conditions upon which it may be destroyed; and&lt;/p&gt;
&lt;p&gt;(h)  the identities of all persons and bodies corporate who will collect, receive, possess, store, deal with or handle it.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.10.1  Rule 5(4) of the Sensitive Personal Data Rules lays down temporal restrictions to the retention of personal information:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;Body corporate or any person on its behalf holding sensitive personal data or information shall not retain that information for longer than is required for the purposes for which the information may lawfully be used or is otherwise required under any other law for the time being in force.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.10.2  Since this sub-rule (4) only applies to sensitive personal data instead of all personal information, bodies corporate are permitted to hold personal information of persons that is not sensitive personal data for as long as they like even after the necessity that informed the collection of that personal information expires and the purpose for which it was collected ends. This is a dangerous provision that deprives the owners of personal information of the ability to control its possession to jeopardise their right to privacy. The Sensitive Personal Data Rules should prescribe a temporal limit to the storage of all personal information by bodies corporate.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.10.3  Therefore, it is proposed that rule 5(4) be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;“No body corporate shall store, retain or hold personal information or sensitive personal data for a period longer than is required to achieve the purpose for which that personal information or sensitive personal data was collected.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 6 - Disclosure of Information&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.11.1  Rule 6(1) of the Sensitive Personal Data Rules, which deals with the crucial issue of disclosure of personal information, states:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Disclosure of sensitive personal data or information by body corporate to any third party shall require prior permission from the provider of such information, who has provided such information under lawful contract or otherwise, unless such disclosure has been agreed to in the contract between the body corporate and provider of information, or where the disclosure is necessary for compliance of a legal obligation: &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt; &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Provided that the information shall be shared, without obtaining prior consent from provider of information, with Government agencies mandated under the law to obtain information including sensitive personal data or information for the purpose of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution, and punishment of offences. The Government agency shall send a request in writing to the body corporate possessing the sensitive personal data or information stating clearly the purpose of seeking such information. The Government agency shall also state that the information so obtained shall not be published or shared with any other person.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.11.2  In addition to errors and discrepancies in drafting, this sub-rule contains wide and vague conditions of disclosure of sensitive personal data to gravely impair the privacy rights and personal liberties of persons to whom such sensitive personal data pertains. A summary of drafting errors and discrepancies follows: &lt;span&gt;Firstly&lt;/span&gt;, this sub-rule only applies to sensitive personal data instead of all personal information. The protection of personal information that is not sensitive personal data is an essential element of the right to privacy; hence, prohibiting bodies corporate from disclosing personal information at will is an important public interest prerogative. &lt;span&gt;Secondly&lt;/span&gt;, the use of the phrase “&lt;i&gt;any third party&lt;/i&gt;” lends vagueness to this provision since the term “third party” has not been defined. &lt;span&gt;Thirdly&lt;/span&gt;, the repeated use of the undefined phrase “&lt;i&gt;provider of information&lt;/i&gt;” throughout these Rules and in this sub-rule is confusing since, as pointed out in paragraph 3.6.2 of this submission, it could mean either or both of the single individual who consents to the collection of his personal information or another entity that transfers personal information to the body corporate.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.11.3  Further, the conditions upon which bodies corporate may disclose personal information and sensitive personal data without the consent of the person to whom it pertains are dangerously wide. &lt;span&gt;Firstly&lt;/span&gt;, the disclosure of personal information and sensitive personal data when it is “&lt;i&gt;necessary for compliance of a legal obligation&lt;/i&gt;” is an extremely low protection standard. The law must intelligently specify the exact conditions upon which disclosure sans consent is possible; since the protection of personal information is a public interest priority, the conditions upon which it may be disclosed must outweigh this priority to be significant and serious enough to imperil the nation or endanger public interest. The disclosure of personal information and sensitive personal data for mere compliance of a legal obligation, such as failure to pay an electricity bill, is farcical. &lt;span&gt;Secondly&lt;/span&gt;, the proviso sets out the conditions upon which the state, through its law enforcement agencies, may access personal information and sensitive personal data without the consent of the person to whom it pertains. Empowering the police with access to personal information can serve a public good if, and only if, it results in the prevention or resolution of crime; if not, this provision will give the police carte blanche to misuse and abuse this privilege. Hence, personal information should only be disclosed for the prevention, investigation and prosecution of an existing criminal offence. &lt;span&gt;Thirdly&lt;/span&gt;, the definition and use of the term “&lt;i&gt;cyber incidents&lt;/i&gt;” is unnecessary because section 43 of the IT Act already lists all such incidents. In addition, when read with section 66 of the IT Act, there emerges a clear list of offences to empower the police to seek non-consensual disclosure of personal information to obviate the need for any further new terminology. &lt;span&gt;In sum&lt;/span&gt;, with regard to the non-consensual disclosure of personal information for the purposes of law enforcement: a demonstrable need to access personal information to prevent, investigate or prosecute crime must exist; only that amount of personal information sufficient to satisfy the need must be disclosed; and, finally, no disclosure may be permitted without clearly laid down procedural safeguards that fulfil the requirements of a minimal due process regime.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.11.4  Therefore, it is proposed that rule 6(1) be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;“No body corporate shall disclose any personal information or sensitive personal data to anyone whosoever without the prior express consent of the person to whom the personal information or sensitive personal data to be disclosed pertains.&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;Provided that if the personal information or sensitive personal data was collected pursuant to an agreement that expressly authorises the body corporate to disclose such personal information or sensitive personal data, and if the person to whom the personal information or sensitive personal data pertains was aware of this authorisation prior to such collection, the body corporate may disclose the personal information or sensitive personal data without obtaining the consent of the person to whom it pertains in the form and manner specified in such agreement.&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;Provided further that if a reasonable threat to national security, defence or public order exists, or if the disclosure of personal information or sensitive personal data is necessary to prevent, investigate or prosecute a criminal offence, the body corporate shall, upon receiving a written request from the police or other law enforcement authority containing the particulars and details of the personal information or sensitive personal data to be disclosed, disclose such personal information or sensitive personal data to such police or other law enforcement authority without the prior consent of the person to whom it pertains.”&lt;/p&gt;
&lt;p&gt;3.12.1  Rule 6(2) of the Sensitive Personal Data Rules creates an additional disclosure mechanism:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;Notwithstanding anything contain in sub-rule (1), any sensitive personal data on Information shall be disclosed to any third party by an order under the law for the time being in force.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.12.2  This sub-rule is overbroad to enable anyone’s sensitive personal data to be disclosed to any other person without the application of any standards of necessity, proportionality or due process and without the person to whom the sensitive personal data pertains having any recourse or remedy. Such provisions are the hallmarks of authoritarian and police states and have no place in a liberal democracy. For instance, the invocation of this sub-rule will enable a police constable in Delhi to exercise unfettered power to access the biometric information or credit card details of a politician in Kerala since an order of a policeman constitutes “&lt;i&gt;an order under the law&lt;/i&gt;”. Pursuant to our submission in paragraph 3.11.4, adequate measures exist to secure the disclosure of personal information or sensitive public data in the public interest. The balance of convenience between privacy and public order has already been struck. This sub-rule should be removed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;3.12.3 Therefore, it is proposed that rule 6(2) be deleted and the remaining sub-rules in rule 6 be accordingly renumbered.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;3.13.1  Rule 6(4) of the Sensitive Personal Data Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The third party receiving the sensitive personal data or information from body corporate or any person on its behalf under sub-rule (1) shall not disclose it further.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.13.2  &lt;span&gt;Firstly&lt;/span&gt;, as mentioned elsewhere in this submission, the phrase “&lt;i&gt;third party&lt;/i&gt;” has not been defined. This is a drafting discrepancy that must be rectified. &lt;span&gt;Secondly&lt;/span&gt;, this sub-rule only encompasses sensitive personal data and not other personal information that is not sensitive personal data. &lt;span&gt;Thirdly&lt;/span&gt;, it may be necessary, in the interests of business or otherwise, for personal information or sensitive personal data that has been lawfully disclosed to a third person to be disclosed further if the person to whom that personal information consents to it.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.13.3  Therefore, it is proposed that rule 6(4) be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;“Personal information and sensitive personal data that has been lawfully disclosed by a body corporate to a person who is not the person to whom such personal information or sensitive personal data pertains in accordance with the provisions of these rules may be disclosed further upon obtaining the prior and express consent of the person to whom it pertains.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 7 - Transfer of Information&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.14.1  Rule 7 of the Sensitive Personal Data Rules sets out the conditions upon which bodies corporate may transfer personal information or sensitive personal data to other bodies corporate in pursuance of a business arrangement:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;A body corporate or any person on its behalf may transfer sensitive personal data or information including any information, to any other body corporate or a person in India, or located in any other country, that ensures the same level of data protection that is adhered to by the body corporate as provided for under these Rules. The transfer may be allowed only if it is necessary for the performance of the lawful contract between the body corporate or any person on its behalf and provider of information or where such person has consented to data transfer.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.14.2  This provision allows personal information and sensitive personal data to be transferred across international borders to other bodies corporate in pursuance of a business agreement. The transfer of such information is a common feature of international commerce in which Indian information technology companies participate with significant success. Within India too, personal information and sensitive personal data is routinely transferred between companies in furtherance of an outsourced business model. Besides affecting ease of business, the sub-rule also affects the ability of persons to control their personal information and sensitive personal data. However, the sub-rule has been poorly drafted: &lt;span&gt;firstly&lt;/span&gt;, the simultaneous use of the phrases “&lt;i&gt;provider of information&lt;/i&gt;” and “&lt;i&gt;such person&lt;/i&gt;” is imprecise and misleading; &lt;span&gt;secondly&lt;/span&gt;, the person to whom any personal information or sensitive personal data pertains must pre-consent to the transfer of such information.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3.14.3  Therefore, it is proposed that rule 7 be re-drafted to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;“A body corporate may transfer any personal information or sensitive personal data in its possession to another body corporate, whether located in India or otherwise, if the transfer is pursuant to an agreement that binds the other body corporate to same, similar or stronger measures of privacy, protection, storage, use and disclosure of personal information and sensitive personal data as are contained in these rules, and if the express and informed consent of the person to whom the personal information or sensitive personal data pertains is obtained prior to the transfer.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 8 - Reasonable Security Practices&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.15.1  Following rule 8(1) of the Sensitive Personal Data Rules that prescribes reasonable security practices and procedures necessary for protecting personal information and sensitive personal data, rule 8(2) asserts that the international standard ISO/IEC 27001 fulfils the protection standards required by rule 8(1):&lt;/p&gt;
&lt;p style="padding-left: 30px; "&gt;&lt;i&gt;The international Standard IS/ISO/IEC 27001 on "Information Technology - Security Techniques - Information Security Management System - Requirements" is one such standard referred to in sub-rule (1).&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.15.2  ISO/IEC 27001 is an information security management system standard that is prescribed by the International Organisation for Standardisation and the International Electrotechnical Commission. CIS raises no objection to the content or quality of the ISO/IEC 27001 standard. However, to achieve ISO/IEC 27001 compliance and certification, one must first purchase a copy of the standard. A copy of the ISO/IEC 27001 standard costs approximately Rs. _____/-. The cost of putting in place the protective measures required by the ISO/IEC 27001 standard are higher: these include the cost of literature and training, the cost of external assistance, the cost of technology, the cost of employees’ time and the cost of certification.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;3.15.3  Therefore, to bring these standards within the reach of small and medium-sized Indian bodies corporate, an appropriate Indian authority, such as the Bureau of Indian Standards, should re-issue affordable standards that are equivalent to ISO/IEC 27001. &lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;IV &lt;span&gt;The Press Release of 24 August 2011&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;4.1  The shoddy drafting of the Sensitive Personal Data Rules resulted in national and international confusion about its interpretation. However, instead of promptly correcting the embarrassingly numerous errors in the Rules, the Department of Information Technology of the Ministry of Communications and Information Technology chose to issue a press release on 24 August 2011 that was published on the website of the Press Information Bureau. The content of that press release is brought to the attention of the Committee of Subordinate Legislation as follows:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;Clarification on Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 Under Section 43A of the Information Technology ACT, 2000.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;Press Note&lt;/i&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;The Department of Information Technology had notified Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 under section 43A of the Information Technology Act, 2000 on 11.4.2011 vide notification no. G.S.R. 313(E).&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt; &lt;/i&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;These rules are regarding sensitive personal data or information and are applicable to the body corporate or any person located within India. Any such body corporate providing services relating to collection, storage, dealing or handling of sensitive personal data or information under contractual obligation with any legal entity located within or outside India is not subject to the requirement of Rules 5 &amp;amp; 6. Body corporate, providing services to the provider of information under a contractual obligation directly with them, as the case may be, however, is subject to Rules 5 &amp;amp; 6. Providers of information, as referred to in these Rules, are those natural persons who provide sensitive personal data or information to a body corporate. It is also clarified that privacy policy, as prescribed in Rule 4, relates to the body corporate and is not with respect to any particular obligation under any contract. Further, in Rule 5(1) consent includes consent given by any mode of electronic communication.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt; &lt;/i&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;Ministry of Communications &amp;amp; Information Technology (Dept. of Information Technology) &lt;/i&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;Press Information Bureau, Government of India, Bhadra 2, 1933, August 24, 2011&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt; &lt;/i&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; "&gt;&lt;i&gt;SP/ska &lt;br /&gt; (Release ID :74990)&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;4.2  It is apparent from a plain reading of the text that this press release seeks to re-interpret the application of rules 5 and 6 of the Sensitive Personal Data Rules insofar as they apply to Indian bodies corporate receiving personal information collected by another company outside India. Also, it seeks to define the term “providers of information” to address the confusion created by the repeated use this term in the Rules. Further, it re-interprets the scope and application of rule 4 relating to duty of bodies corporate to publish certain policies. Furthermore, it seeks to amend the provisions of rule 5(1) relating to manner and medium of obtaining consent prior to collecting personal information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;4.3  At the outset, it must be understood that a press release is not valid law. According to Article 13(3) of the Constitution of India,&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;...&lt;i&gt;law&lt;/i&gt; &lt;i&gt;includes any Ordinance, order, bye law, rule, regulation, notification, custom or usages having in the territory of India the force of law.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Law includes orders made in exercise of a statutory power as also orders and notifications made in exercise of a power conferred by statutory rules.&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;[See, &lt;i&gt;Edward Mills&lt;/i&gt; AIR 1955 SC 25 at pr. 12, &lt;i&gt;Babaji Kondaji Garad&lt;/i&gt; 1984 (1) SCR 767 at pp. 779-780 and &lt;i&gt;Indramani Pyarelal Gupta&lt;/i&gt; 1963 (1) SCR 721 at pp. 73-744]&lt;/p&gt;
&lt;p&gt;Sub-delegated orders, made in exercise of a power conferred by statutory rules, cannot modify the rules.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px; "&gt; &lt;span&gt;[See, &lt;i&gt;Raj Narain Singh&lt;/i&gt; AIR 1954 SC 569 and &lt;i&gt;Re Delhi Laws Act&lt;/i&gt; AIR 1951 SC 332]&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;span&gt;Therefore, press releases, which are not made or issued in exercise of a delegated or sub-delegated power are not “law” and cannot modify statutory rules.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;b&gt;V &lt;span&gt;Summary&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span&gt;5.1&lt;span&gt; &lt;/span&gt;CIS submits that the following provisions of the Sensitive Personal Data Rules be amended or annulled&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;Rule 2(1)(b);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 2(1)(c);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 2(1)(d);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 2(1)(g);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 3;&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 4(1);&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 5(1);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 5(2);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 5(3);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 5(4);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 6(1);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 6(1) Proviso;&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 6(2);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 6(4);&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 7; and&lt;/span&gt;&lt;span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Rule 8.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;5.2 CIS submits that the Committee on Subordinate Legislation &lt;span&gt;should take a serious view of the press release issued by the &lt;/span&gt;&lt;span&gt;Department of Information Technology of the Ministry of Communications and Information Technology on 24 August 2011.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;5.3 CIS submits &lt;/span&gt;&lt;span&gt;that in exercise of the powers granted to the Committee on Subordinate Legislation under Rules 317 and 320 of the Lok Sabha Rules of Procedure, the provisions of the Sensitive Personal Data Rules listed in the preceding paragraph 5.1 should be annulled; and, the Committee may be pleased to consider and recommend as an alternative the amendments proposed by CIS in this submission.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;5.4 CIS thanks the Committee on Subordinate Legislation for the opportunity to present this submission and reiterates its commitment to supporting the Committee with any clarification, question or other requirement it may have.&lt;/span&gt;&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr1" name="fn1"&gt;1&lt;/a&gt;]. See generally, &lt;i&gt;Kharak Singh&lt;/i&gt; AIR 1963 SC 1295, &lt;i&gt;Gobind&lt;/i&gt; (1975) 2 SCC 148, &lt;i&gt;R. Rajagopal&lt;/i&gt; (1994) 6 SCC 632, &lt;i&gt;People’s Union for Civil Liberties&lt;/i&gt; (1997) 1 SCC 301 and &lt;i&gt;Canara Bank&lt;/i&gt; (2005) 1 SCC 496.&lt;/p&gt;
&lt;p&gt;[&lt;a href="#fr2" name="fn2"&gt;2&lt;/a&gt;]. See &lt;i&gt;infra&lt;/i&gt; pr. 4.3.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr3" name="fn3"&gt;3&lt;/a&gt;]. See, for comparison, Directive 95/46/EC of 24 October 1995 of the European Parliament and Council, the Data Protection Act, 1998 of the United Kingdom and the Proposed EU Regulation on on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).&lt;/p&gt;
&lt;p class="MsoFootnoteText"&gt;[&lt;a href="#fr4" name="fn4"&gt;4&lt;/a&gt;].&lt;span&gt;See generally, &lt;i&gt;Board of Trustees of Ayurvedic College&lt;/i&gt; AIR 1962 SC 458 and &lt;i&gt;S. P. Mittal&lt;/i&gt; AIR 1983 SC 1.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt; &lt;/p&gt;
&lt;p&gt;[&lt;a href="#fr5" name="fn5"&gt;5&lt;/a&gt;]. &lt;span&gt;See &lt;/span&gt;&lt;span&gt;generally, &lt;i&gt;W. O. Holdsworth&lt;/i&gt; AIR 1957 SC 887 and &lt;i&gt;Duli Chand&lt;/i&gt; AIR 1984 Del 145.&lt;/span&gt;&lt;/p&gt;
&lt;div id="_mcePaste"&gt; &lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/comments-on-the-it-reasonable-security-practices-and-procedures-and-sensitive-personal-data-or-information-rules-2011'&gt;https://cis-india.org/internet-governance/blog/comments-on-the-it-reasonable-security-practices-and-procedures-and-sensitive-personal-data-or-information-rules-2011&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>bhairav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T12:13:53Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/comments-on-it-electronic-service-delivery-rules-2011">
    <title>Comments on the Information Technology (Electronic Service Delivery) Rules, 2011</title>
    <link>https://cis-india.org/internet-governance/blog/comments-on-it-electronic-service-delivery-rules-2011</link>
    <description>
        &lt;b&gt;Bhairav Acharya on behalf of the Centre for Internet and Society prepared the following comments on the Information Technology (Electronic Services Delivery) Rules, 2011. These were submitted to the Committee on Subordinate Legislation of the 15th Lok Sabha. These were submitted to the Committee on Subordinate Legislation of the 15th Lok Sabha. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;I &lt;span&gt;&lt;span&gt;Preliminary&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;1.1  This submission presents comments from the Centre for Internet and Society (&lt;b&gt;“CIS”&lt;/b&gt;) on the Information Technology (Electronic Service Delivery) Rules, 2011 that were notified by the Central Government in the Gazette of India vide Notification GSR 316(E) on 11 April 2011 (&lt;b&gt;“ESD Rules”&lt;/b&gt; or &lt;b&gt;“Rules”&lt;/b&gt;).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;1.2  The ESD Rules were notified only eight months before the Electronic Delivery of Services Bill, 2011 was tabled in the Lok Sabha on 27 December 2011 (Bill 137 of 2011) (&lt;b&gt;“EDS Bill” &lt;/b&gt;or&lt;b&gt; “Bill”&lt;/b&gt;). Both the ESD Rules and the EDS Bill are concerned with enabling computer-based electronic delivery of government services to Indian citizens (&lt;b&gt;“electronic service delivery”&lt;/b&gt;). Both the Rules and the Bill originate from the same government department: the Department of Electronics and Information Technology of the Ministry of Communications and Information Technology. Since the EDS Bill seeks to enact a comprehensive legislative framework for mandating and enforcing electronic service delivery, the purpose of the ESD Rules are called into question.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;II &lt;span&gt;&lt;span&gt;Basic Issues Regarding Electronic Service Delivery&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;2.1  CIS believes that there are significant conceptual issues regarding electronic service delivery that demand attention. The Department-related Parliamentary Standing Committee on Information Technology of the Fifteenth Lok Sabha (&lt;b&gt;“Standing Committee”&lt;/b&gt;) raised a few concerns when it submitted its 37th Report on the EDS Bill on 29 August 2012. There is a clear need for a national debate on the manner of effecting exclusive electronic service delivery to the exclusion of manual service delivery. Some of these issues are briefly summarised as follows:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(a) Mandatory exclusive electronic service delivery pre-supposes the ability of all Indian citizens to easily access such mechanisms. While there are no authoritative national statistics on familiarity with computer-related technologies, it is apparent that a large majority of Indians, most of whom are likely to be already marginalised and vulnerable, are totally unfamiliar with such technologies to endanger their ability to receive basic government services;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(b)  Consequent upon mandatory exclusive electronic service delivery for basic government services, a large group of ‘middlemen’ will arise to facilitate access for that majority of Indians who cannot otherwise access these services. This group will control the interface between citizens and their government. As a result, citizens’ access to governance will deteriorate. This problem may be mitigated to a certain extent by creating a new class of public servants to solely facilitate access to electronic service delivery mechanisms;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(c) The issue of governmental incapacity at the citizen-government interface might be addressed by contracting private service providers to operate mandatory exclusive electronic service delivery mechanisms. However, it is difficult to see how commercialising access to essential government services serves the public interest, especially when public funds will be expended to meet the costs of private service providers. Permitting private service providers to charge a fee from the general public to allow access to essential government services is also ill advised;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(d)  All electronic service delivery, whether mandatory to the exclusion of other service delivery mechanisms or offered simultaneously with manual service delivery, must be accompanied by strong data protection measures to ensure the sanctity of sensitive personal information shared online with the state. At present, there are no specific laws that bind the state, or its agents, to the stringent requirements of privacy necessary to protect personal liberties. In the same vein, strong data security measures are necessary to prevent sensitive personal information from being compromised or lost;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(e) All electronic service delivery, whether mandatory to the exclusion of other service delivery mechanisms or offered simultaneously with manual service delivery, must ensure ease and equality of accessibility. For this reason, electronic service delivery mechanisms should conform to the National Policy on Open Standards, 2010 (or the proposed National Electronic Access Policy which is currently awaiting adoption), the Interoperability Framework for E-Governance in India and the Website Guidelines of the National Informatics Centre;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;(f) Electronic service delivery requires infrastructure which India does not currently have but can develop. Only 1.44 per cent of India’s population has access to a broadband internet connection&lt;a href="#fn1" name="fr1"&gt;[1]&lt;/a&gt; and current daily energy demand far exceeds supply. On the other hand, the number of broadband subscribers is increasing,&lt;a href="#fn2" name="fr2"&gt;[2]&lt;/a&gt; the annual installed capacity for electricity generation is growing&lt;a href="#fn3" name="fr3"&gt;[3]&lt;/a&gt; and the literacy rate is increasing.&lt;a href="#fn4" name="fr4"&gt;[4]&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;2.2  The ESD Rules do not address any of the issues raised in the preceding paragraph. As a result, they cannot be seen to represent the result of a national consensus on the crucial question of mandating exclusive electronic service delivery and the means of enforcing such a scheme. Further, very few of the provisions of the Rules are binding; instead, the Rules appear to be drafted to serve as a minimal model for electronic service delivery. &lt;b&gt;In this background, CIS believes that the Rules should be treated as an incomplete arrangement that prescribe the minimal standards necessary to bind private service providers before comprehensive and statutory electronic service delivery legislation is enacted, perhaps in the form of the EDS Bill or otherwise. &lt;/b&gt;Therefore, without prejudice to the issues raised in the preceding paragraph, CIS offers the following comments on the provisions of the Rules while reserving the opportunity to make substantive submissions on electronic service delivery in general to an appropriate forum at a later date.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;III &lt;span&gt;Improper Exercise of Subordinate Legislative Power&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.1  Rule 317 of the Rules of Procedure and Conduct of Business in the Lok Sabha (Fourteenth Edition, July 2010) (&lt;b&gt;“Rules of Procedure”&lt;/b&gt;), which empowers the Committee on Subordinate Legislation to scrutinise exercises of statutory delegation of legislative powers for impropriety, states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;There shall be a Committee on Subordinate Legislation to scrutinize and report to the House whether the powers to make regulations, rules, subrules, bye-laws etc., conferred by the Constitution or delegated by Parliament are being properly exercised within such delegation.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Further, the Committee on Subordinate Legislation is specifically empowered by rule 320(vii) of the Rules of Procedure to examine any provision of the ESD Rules to consider “&lt;i&gt;whether it appears to make some unusual or unexpected use of the powers conferred by the Constitution or the Act pursuant to which it is made.&lt;/i&gt;”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.2 Accordingly, the attention of the Committee on Subordinate Legislation is called to an improper exercise of delegated power under rule 3(1) of the ESD Rules, which states:&lt;/p&gt;
&lt;p style="padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government may on its own or through an agency authorised by it, deliver public services through electronically- enabled kiosks or any other electronic service delivery mechanism.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;This sub-rule (1) empowers both the Central Government and State Governments to provide electronic service delivery on their own.&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;3.3 The ESD Rules are made in exercise of delegated powers conferred under section 87(2)(ca) read with section 6-A(2) of the Information Technology Act, 2000 (&lt;b&gt;“IT Act”&lt;/b&gt;). Section 87(2)(ca) of the IT Act empowers the Central Government to make rules to provide for:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;the manner in which the authorised service provider may collect, retain and appropriate service charges under sub-section (2) of section 6-A.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;Section 6-A(2) of the IT Act states:&lt;/p&gt;
&lt;p style="padding-left: 30px; text-align: justify; "&gt;&lt;i&gt;The appropriate Government may also authorise any service provider authorised under sub-section (1) to collect, retain and appropriate such service charges, as may be prescribed by the appropriate Government for the purpose of providing such services, from the person availing such service.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Prima facie&lt;/i&gt;, the delegated powers under section 87(2)(ca) read with section 6-A(2) of the IT Act, in exercise of which the ESD Rules are made, only permit delegated legislation to regulate private service providers, &lt;span&gt;they do not permit the executive to exercise these powers to empower itself to conduct electronic service delivery on its own&lt;/span&gt;.&lt;b&gt; Therefore, to the extent that the ESD Rules authorise the Central Government and State Governments to provide electronic service delivery on their own, such authorisation constitutes an improper exercise of delegated power and is &lt;i&gt;ultra vires&lt;/i&gt; the IT Act.&lt;/b&gt; This may be resolved by deriving the delegated legislative competence of the ESD Rules from section 87(1) of the IT Act, instead of section 87(2)(ca) read with section 6-A(2).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;IV &lt;span&gt;Clause-by-Clause Comments&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Rule 2 - Definitions&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;4.1.1     Rule 2(c) of the ESD Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;"authorised agent" means an agent of the appropriate Government or service provider and includes an operator of an electronically enabled kiosk who is permitted under these rules to deliver public services to the users with the help of a computer resource or any communication device, by following the procedure specified in the rules&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In accordance with the argument regarding improper exercise of delegated power contained in paragraphs 3.1 – 3.3 of this submission, the appropriate Government cannot undertake electronic service delivery under these Rules. Consequently, the appropriate Government cannot appoint an agent to provide electronic service delivery on behalf, and under the control, of the appropriate Government since, as the principal, the appropriate Government would be responsible for the acts of its agents. Instead, private service providers may provide electronic service delivery as contractees of the appropriate Government who might enter into such contracts as a sovereign contractor. Therefore, only a private service provider may appoint an authorised agent under these Rules.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;4.1.2 Therefore, it is proposed that rule 2(c) is amended to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;““authorised agent” means an agent of a service provider, and includes an operator of an electronically enabled kiosk, who is permitted under these rules to deliver public services with the help of a computer resource or any communication device, by following the procedure specified in these rules”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Rule 3 - &lt;span&gt;System of Electronic Service Delivery&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;4.2.1    Rule 3(3) of the ESD Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government may determine the manner of encrypting sensitive electronic records requiring confidentiality, white they are electronically signed.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This sub-rule is supposed to prescribe stringent standards to maintain the security, confidentiality and privacy of all personal information used during electronic service delivery transactions. In the absence of transactional security, electronic service delivery will invite fraud, theft and other misuse to impugn its viability as a means of delivering public services. However, the use of the term “&lt;i&gt;may&lt;/i&gt;” leaves the prescription of security standards up to the discretion of the appropriate Government. Further, the language of the sub-rule is unclear and imprecise.&lt;/p&gt;
&lt;p&gt;4.2.2    &lt;b&gt;Therefore, it is proposed that rule 3(3) is amended to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;“The appropriate Government shall, prior to any electronic service delivery, determine the manner of encrypting electronic records and shall prescribe standards for maintaining the safety, security, confidentiality and privacy of all information collected or used in the course of electronic service delivery.”&lt;/p&gt;
&lt;p&gt;4.3.1    Rule 3(5) of the ESD Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government may allow receipt of payments made by adopting the Electronic Service Delivery System to be a deemed receipt of payment effected in compliance with the financial code and treasury code of such Government.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Firstly&lt;/span&gt;, if these Rules enable payments to be made electronically, they must also validate the receipt of these payments. Inviting citizens to make electronic payments for government services without recognising the receipt of those payments is farcical to attract abusive and corrupt practices. Therefore, it is imperative that these Rules compulsorily recognise receipt of payments, either by deeming their receipt to be valid receipts under existing law or by specially recognising their receipt by other means including the law of evidence. Either way, electronic receipts of electronic payments must be accorded the validity in law that manual/paper receipts have; and, copies of such electronic receipts must be capable of being adduced in evidence. &lt;span&gt;Secondly&lt;/span&gt;, the use of the phrase “&lt;i&gt;financial code and treasury code&lt;/i&gt;” is avoidable since these terms are undefined.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;4.3.2 Therefore, it is proposed that rule 3(5) be amended to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;“Any receipt of payment made by electronic service delivery shall be deemed to be a valid receipt of such payment under applicable law and shall be capable of being adduced as evidence of such payment.”&lt;/p&gt;
&lt;p&gt;4.4.1    Rule 3(6) of the ESD Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government may authorise service providers or their authorised agents to collect, retain and appropriate such service charges as may be specified by the appropriate Government for the purpose of providing such services from the person availing such services: &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt; &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;Provided that the apportioned service charges shall be clearly indicated on the receipt to be given to the person availing the services.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This sub-rule is an almost verbatim reproduction of the provisions of section 6-A(2) of the IT Act which reads as follows:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government may also authorise any service provider authorised under sub-section (1) to collect, retain and appropriate such service charges, as may be prescribed by the appropriate Government for the purpose of providing such services, from the person availing such service.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Since the IT Act specifically delegates to the appropriate Governments the power to authorise service providers to levy charges, rule 3(6) of the ESD Rules that merely copies the provisions of the parent statute is meaningless. The purpose of delegated legislation is to give effect to the provisions of a statute by specifying the manner in which statutory provisions shall be implemented. Copying and pasting statutory provisions is a absurd misuse of delegated legislative powers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;4.4.2 Therefore, it is proposed that sub-rule (6) is deleted and the remaining sub-rules of rule 3 are renumbered.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;4.5.1 Rule 3(7) of the ESD Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government shall by notification specify the scale of service charges which may be charged and collected by the service providers and their authorised agents for various kinds of services.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;This is an almost verbatim reproduction of the provisions of section 6-A(4) of the IT Act which reads as follows:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government shall, by notification in the Official Gazette, specify the scale of service charges which may be charged and collected by the service providers under this section.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As noted in paragraph 4.3.1 of this submission, the purpose of delegated legislation is not to copy the provisions of the parent statute, but to amplify the scope of the delegated power and the manner of effecting its implementation.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;4.5.2  Therefore, it is proposed that sub-rule (7) is deleted and the remaining sub-rules of rule 3 are renumbered.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;4.6.1 Rule 3(8) of the ESD Rules states:&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;&lt;i&gt;The appropriate Government may also determine the norms on service levels to be complied with by the Service Provider and the authorised agents.&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There is no quarrel with the power of the government to determine norms for, or directly prescribe, service levels to regulate service providers. However, without a scheme of statutory or sub-statutory penalties for contravention of the prescribed service levels, a sub-delegated service level cannot enforce any penalties. Simply put, &lt;span&gt;the state cannot enforce penalties unless authorised by law&lt;/span&gt;. Unfortunately, rule 3(8) contains no such authorisation. Service levels for service providers without a regime of penalties for non-compliance is meaningless, especially since service providers will be engaged in providing access to essential government services.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;4.6.2  Therefore, it is proposed that rule 3(8) be amended to read as follows:&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; padding-left: 30px; "&gt;“The appropriate Government shall prescribe service levels to be complied with by all service providers and their authorised agents which shall include penalties for failure to comply with such service levels.”&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr1" name="fn1"&gt;1&lt;/a&gt;]. Thirty-Seventh Report of the Standing Committee on Information Technology (2011-12) on the Electronic Delivery of Services Bill, 2011 (New Delhi: Lok Sabha Secretariat, 29 August 2012) at pp. 13, 17 and 34. See also, &lt;i&gt;Telecom Sector in India: A Decadal Profile&lt;/i&gt; (New Delhi: Telecom Regulatory Authority of India, 8 June 2012).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr2" name="fn2"&gt;2&lt;/a&gt;]. Annual Report (2011-12) of the Department of Telecommunications, Ministry of Communications and Information Technology, Government of India (New Delhi: Department of Telecommunications, 2012) at pp. 5 and 1-3.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr3" name="fn3"&gt;3&lt;/a&gt;]. Report of the Working Group on Power of the Twelfth Plan (New Delhi: Planning Commission, Government of India, January 2012).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr4" name="fn4"&gt;4&lt;/a&gt;]. Provisional Report of the Census of India 2011 (New Delhi: Registrar General and Census Commissioner, 2011) from p. 124.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/comments-on-it-electronic-service-delivery-rules-2011'&gt;https://cis-india.org/internet-governance/blog/comments-on-it-electronic-service-delivery-rules-2011&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>bhairav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>SAFEGUARDS</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-12T12:12:16Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-hindu-december-28-2014-ajai-sreevatsan-targeting-surveillance">
    <title>Targeting surveillance</title>
    <link>https://cis-india.org/internet-governance/news/the-hindu-december-28-2014-ajai-sreevatsan-targeting-surveillance</link>
    <description>
        &lt;b&gt;In the fall of 2005, Scotland Yard raided a flat in west London and arrested a suspected al-Qaeda militant known by a teasing Arabic nickname, Irhabi (“Terrorist”) 007.&lt;/b&gt;
        &lt;p class="body" style="text-align: justify; "&gt;The article by Ajai Sreevatsan was &lt;a class="external-link" href="http://www.thehindu.com/sunday-anchor/targeting-surveillance/article6731202.ece"&gt;published in the Hindu&lt;/a&gt; on December 28, 2014. Sunil Abraham gave his inputs.&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="body" style="text-align: justify; "&gt;The similarities between Irhabi 007, later identified as Younis Tsouli, and India’s Mehdi Masoor Biswas are uncanny.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Neither  participated in any terror attack. Their reputation stems from an  alleged involvement as cyber propagandists for proto-terror groups —  Irhabi was distributing manuals and teaching online seminars on behalf  of the emerging al-Qaeda faction in Iraq, while Mehdi is alleged to be  an IS sympathiser. Both in their early 20s with cover identities during  the day, and separated by a decade in technological evolution.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Such  expertise within terror groups is hardly surprising, says Sunil Abraham  of the Centre for Internet and Society. “Any organisation engaged in a  war for hearts and minds and oil fields will exploit contemporary  technology to its fullest potential,” he says.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Irhabi  currently serves a 16-year jail term, while Mehdi awaits his trial.  What their cases highlight is that the phenomenon of young, tech-savvy  armchair radicals is nothing new.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Research done at  Israel’s Haifa University, which tracks the proliferation of terrorist  websites, shows that the number of such sites went up from fewer than  100 in the late-1990s to more than 4,800 in just a decade. There is also  credible evidence that an al-Qaeda website posted a sketched-out  proposal for the 2004 Madrid bombings three months before the attack.  Another macabre example is the crowd-sourcing effort launched in 2005 by  the Victorious Army Group to build its website. By the competition’s  rules, the winner would get to fire a rocket at an American base.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;As  Indian agencies gear up to respond to similar online threats in this  part of the world, Mr. Abraham says India should not repeat the mistakes  made by the West over the previous decade. “We should not get caught up  in big data surveillance,” he says.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;“Surveillance is  like salt. It could be counter-productive even if slightly in excess.  Ideally, surveillance must be targeted. Indiscriminate surveillance just  increases the size of the haystack, making it difficult to find the  needles,” Mr. Abraham says.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;“Even in the case of  Mehdi, his identity was uncovered not by online spying but by Channel 4  which did some old-fashioned detective work,” he says.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;In  any case, recent events show that the threat of online terror  propaganda might be overblown. Much like online activism, it is subject  to the law of diminishing returns.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;A set of letters sent by newly recruited volunteers of IS was leaked to the French newspaper &lt;i&gt;Le Figaro &lt;/i&gt;earlier  this month and it shows youngsters complaining about being made to do  the dishes or the Iraqi winter. One of them wrote: “I’m fed up to the  back teeth. My iPod no longer works out here. I have got to come home.”  Of the estimated 1,100 young French who are believed to have joined the  IS, more than 100 have already returned.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The IS may  have Twitter on its side. But the harsh realities of Iraq and the  gruesome ideology behind the slick doctrinal videos are a lot harder to  sell.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Mr. Abraham says there is no such thing as a  Twitter revolution or a social media terror group. “Such statements  underestimate the role of ideology and human beings,” he says.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-hindu-december-28-2014-ajai-sreevatsan-targeting-surveillance'&gt;https://cis-india.org/internet-governance/news/the-hindu-december-28-2014-ajai-sreevatsan-targeting-surveillance&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Surveillance</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-12-30T14:10:58Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/symposium-on-human-rights-and-internet-in-india">
    <title>Symposium on Human Rights and the Internet in India</title>
    <link>https://cis-india.org/internet-governance/news/symposium-on-human-rights-and-internet-in-india</link>
    <description>
        &lt;b&gt;On January 17, 2015 the Center for Communication Governance at National Law University, Delhi in collaboration with the UNESCO Chair on Freedom of Communication and Information at the University of Hamburg hosted a pubic symposium on “Human Rights and Internet in India” as a Network of Centers (NoC) regional event. Bhairav Acharya was a panelist.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;See the &lt;a class="external-link" href="http://networkofcenters.net/sites/networkofcenters.net/files/dehli-concept-note.pdf"&gt;concept note here&lt;/a&gt;.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The event convened a diverse group of collaborators working on issues of Privacy, Surveillance, Data Protection, Freedom of Expression and Intermediary Liability in India, the surrounding region, and internationally.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Agenda | Saturday, January 17 | Public Symposium&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Opening words&lt;br /&gt; &lt;i&gt;Prof. (Dr.) Ranbir Singh, Vice Chancellor, National Law University, Delhi&lt;/i&gt;&lt;br /&gt; &lt;i&gt;Prof. (Dr.) Wolfgang Schulz, Director, Alexander von Humboldt Institute for Internet &amp;amp; Society &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;b&gt;17:45 – 19:00 Panel I: Surveillance &amp;amp; Databases: Experiences &amp;amp; Privacy&lt;/b&gt;&lt;/b&gt;&lt;br /&gt; The panel will explore how surveillance in India might become more  consistent with international human rights standards and Indian  constitutional values. It will also discuss the consequences of  ubiquitous database programs for citizens’ human rights. This will  include comparative perspectives around similar problems and a  discussion of privacy-compatible practices in other countries.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Panelists:&lt;/b&gt;&lt;br /&gt; &lt;i&gt;Dr. Usha Ramanathan, Independent Law Researcher&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Mr. Bhairav Acharya, Lawyer, Supreme Court of India and Adviser Centre for Internet &amp;amp; Society, Bangalore&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Mr. Saikat Datta, Editor (National Security), Hindustan Times&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Professor KS Park, Former Commissioner, Korea Communications Standards Commission and Professor, Korea University Law School&lt;/i&gt;&lt;br /&gt; &lt;b&gt; &lt;/b&gt;&lt;br /&gt; &lt;b&gt;&lt;b&gt;19:00 – 20:15 Panel II: Unpacking the Intermediary Liability Debate in India&lt;/b&gt;&lt;/b&gt;&lt;br /&gt; The panel will focus on the legal framework governing Internet platforms  in India, especially with regard to online content and its implications  for rights of the citizens. It has been argued that the current legal  framework creates incentives for online intermediaries to take down  content even when no substantive notice or legitimate reasons have been  offered. The panel will consider the debate around intermediary  liability in India in light of the ongoing litigation at the Supreme  Court. It will reflect on the international experience with intermediary  liability legislation and discuss how to ensure that laws support an  innovative and competitive environment for intermediaries, while  ensuring that they prioritize the preservation of their users’ human  rights.&lt;br /&gt; &lt;b&gt; &lt;/b&gt;&lt;br /&gt; &lt;b&gt;Panelists:&lt;/b&gt;&lt;br /&gt; &lt;i&gt;Dr. Joris van Hoboken, Fellow, Information Law Institute at NYU School of Law&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Professor (Dr.) Wolfgang Schulz, Director, Alexander von Humboldt Institute for Internet &amp;amp; Society (HIIG)&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Mr. Raman Jit Singh Chima, Lawyer&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Chinmayi Arun and Sarvjeet Singh, Centre for Communication Governance at National Law University, Delhi&lt;/i&gt;&lt;b&gt; &lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/symposium-on-human-rights-and-internet-in-india'&gt;https://cis-india.org/internet-governance/news/symposium-on-human-rights-and-internet-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-02-07T00:50:00Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/security-and-surveillance-optimizing-security-while-safeguarding-human-rights">
    <title>Security and Surveillance – Optimizing Security while Safeguarding Human Rights</title>
    <link>https://cis-india.org/internet-governance/blog/security-and-surveillance-optimizing-security-while-safeguarding-human-rights</link>
    <description>
        &lt;b&gt;The Centre for Internet and Society (CIS) on December 19, 2014 held a talk on “Security and Surveillance – Optimizing Security while Safeguarding Human Rights.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The talk focused on a project that is being undertaken by CIS in collaboration with Privacy International, UK. Initiated in 2014, the project seeks to study the regulatory side of surveillance and related technologies in the Indian context. The main objective of the project is to initiate dialogue on surveillance and security in India, government regulation, and the processes that go into the same. The talk saw enthusiastic participation from civil society members, policy advisors on technology, and engineering students.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;During the event it was highlighted that requirements of judicial authorization, transparency and proportionality are currently lacking in the legal regime for surveillance in India and at the same time India has a strong system of ‘security’ that service providers must adhere to – which works towards enhancing cyber security in the country.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Discussions played out with regard to how most of the nine intelligence agencies that are authorized to intercept information in India are outside the ambit of parliamentary oversight, the RTI and the CAG, making them virtually unaccountable to the Indian public.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another conversation focused on the sharing of information between various intelligence agencies within the country, and the fact that this area is virtually unregulated. The discussion then steered to cyber-security in general, emerging technologies used by the Government of India for surveillance, cooperative agreements for surveillance technologies that India has with other countries, the export and import of such technologies from India, and most importantly, the role of service providers in the surveillance debate, and the regulations they are subject to.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A common theme seemed to be emerging from the discussion was that the agencies responsible for regulating information interception and surveillance in the country are shockingly unaccountable to the Indian public. As an active civil society member noted today - &lt;i&gt;“There is no oversight/monitoring of the agencies themselves, so there’s no way anyone would even know of how many instances of surveillance or unauthorized interception have actually occurred.”&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The talk successfully concluded with inputs from members of the audience, and a broad consensus on the fact that the Government of India would have to adhere to stronger regulatory standards, harmonized surveillance standards, stronger export and import certification standards, etc., in order to make surveillance in India more transparent and accountable. As was stated at the talk, &lt;i&gt;“We don’t have a problem with the concept of surveillance per se, - it has more to do with its problematic implementation”.&lt;/i&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/security-and-surveillance-optimizing-security-while-safeguarding-human-rights'&gt;https://cis-india.org/internet-governance/blog/security-and-surveillance-optimizing-security-while-safeguarding-human-rights&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>elonnai</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-02-13T02:41:46Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/connecting-the-dots-options-for-future-action">
    <title>CONNECTing the Dots: Options for Future Action</title>
    <link>https://cis-india.org/internet-governance/news/connecting-the-dots-options-for-future-action</link>
    <description>
        &lt;b&gt;Conference on UNESCO’s Internet Study: access, free expression, privacy and ethics.&lt;/b&gt;
        &lt;p&gt;Elonnai Hickok participated in the &lt;a class="external-link" href="http://www.unesco.org/new/fileadmin/MULTIMEDIA/HQ/CI/CI/pdf/Events/connecting_dots_agenda.pdf"&gt;conference organized&lt;/a&gt; by UNESCO on 3 and 4 March 2015 in Paris. The programme focused on topics like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Freedom of Expression&lt;/li&gt;
&lt;li&gt;Access and Ethics&lt;/li&gt;
&lt;li&gt;Privacy and Ethics&lt;/li&gt;
&lt;li&gt;Access and Freedom of Expression&lt;/li&gt;
&lt;li&gt;Access and Privacy&lt;/li&gt;
&lt;li&gt;The Internet Ecosystem and UNESCO's role - which options for future action?&lt;/li&gt;
&lt;/ul&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/connecting-the-dots-options-for-future-action'&gt;https://cis-india.org/internet-governance/news/connecting-the-dots-options-for-future-action&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-04-01T15:31:45Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-hindu-march-17-2015-aadhaar-an-identity-crisis">
    <title>Live Chat: Aadhaar: An identity crisis? </title>
    <link>https://cis-india.org/internet-governance/news/the-hindu-march-17-2015-aadhaar-an-identity-crisis</link>
    <description>
        &lt;b&gt;The Aadhaar card is not compulsory for citizens and "no person should be denied any benefits or ‘suffer’ for not having the Aadhaar cards issued by Unique Identification Authority of India," the Supreme Court ruled on Monday. &lt;/b&gt;
        &lt;p class="body" style="text-align: justify; "&gt;The live chat was &lt;a class="external-link" href="http://www.thehindu.com/news/national/the-debate-around-aadhaar-card/article7003376.ece"&gt;published in the Hindu&lt;/a&gt; on March 17, 2015. Sunil Abraham took part in the discussions.&lt;/p&gt;
&lt;hr /&gt;
&lt;p class="body" style="text-align: justify; "&gt;Four years after Aadhaar was launched – and touted as a panacea to  access social services and subsidies – its users continue to be dogged  by an array of problems ranging from technical glitches to procedural  delays. And those who do not have an Aadhaar card find themselves  quizzed by government authorities.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;i&gt;The Hindu&lt;/i&gt;’s Tamil Nadu edition today &lt;a href="http://www.thehindu.com/news/cities/chennai/issues-in-obtaining-aadhaar-from-glitches-to-lack-of-forms/article7000268.ece" target="_self"&gt;highlighted the challenges&lt;/a&gt; ordinary citizens - both those who have cards and those who do not –  face, be it from non-availability of application forms or glitches in  the biometrics process.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;We will be hosting a live chat on Aadhaar at 5 pm today. You can pose  questions and share your views with Sunil Abraham, Executive Director of  Bangalore-based research organisation, Centre for Internet and Society;  K. Gopinath, Professor at the Computer Science and Automation  Department at the Indian Institute of Science (IISc) and The Hindu’s K.  Venkatraman.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Anon &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;What could have happened such that the current government, who were once  in the opposition, were members of the parliamentary committee that  strongly opposed UIDAI, now suddenly wants to use it everywhere? What  could have transpired such that the PM got so convinced that it would  help its citizens more than it could potentially harm?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham: &lt;/b&gt;Usually the party that is in power is  pro-surveillance and anti-censorship and the opposition is pro-privacy  and pro-free speech. After the elections - if the parties swap positions  as a result of the mandate - then they usually also swap positions on  surveillance and censorship. This phenomenon is not specific to India.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath:&lt;/b&gt; The leakage in the current models is very high. Hence, the attraction.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The issue earlier was whether there was some costs to the use of sw  (esp. proprietary) from outside the country. Probably, these have been  addressed.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Saurabh &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Aadhaar was supposed to be a good 2 factor authentication mechanism, what happens to it now ?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; Aadhaar architecture was designed to allow for  multiple authentication factors. Unfortunately biometrics is a poor  authentication factor since it cannot be revoked. Any two-factor  authentication scheme where one factor is biometrics is in reality only a  one-factor scheme. Pin code as with credit cards and debit cards would  have been much more secure for authentication.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K Venkataramanan:&lt;/b&gt; It will continue to be relevant, but is unlikely to be mandatory for quite some time.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath:&lt;/b&gt; Real-time 2-factor auth (biometrics, signatures) are not easy, esp over Internet, and would require a much longer rollout&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Saurabh &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I did not get Aadhar for myself or my family. Does this mean, I will not have to as yet.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; As per the UIDAI - Aadhaar is not mandatory. Also  according to the latest remarks from the Supreme Court - Aadhaar should  not be made mandatory without enabling law. But many state and central  government agencies have ignored the comments made by the SC and have  made Aadhaar mandatory for various programmes and schemes.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;The Hindu:&lt;/b&gt; Is Aadhaar virtually redundant now following the SC order? Nothing more than an expensive experiment?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath: &lt;/b&gt;I think it will be used as an addl auth mechanism  (just like elec./ph. receipts). May be once the technology is demo'ed  properly (it has not been done seriously anywhere else), it will be  taken up again.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Abubacker &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I am an NRI and need to have Aadhaar Card? How to obtain Appointmet - I am from Tuticorin, Tamil Nadu&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K Venkataramanan:&lt;/b&gt; Your family member or representative living in  Tuticorin may apply for Aadhaar through the local body. It may be  possible to get a date for recording biometrics. However, you have to  come down here for recording biometric details.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Kishore J &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Why is Govt. not able to legalize the Aadhar, I'm assuming the only  reason Supreme court keeps blocking it is because its not a law passed  by Parliament ?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath:&lt;/b&gt; SC goes by the constitution. If there is some concern someone is being "excluded", they will block it.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham: &lt;/b&gt;The NIA bill was proposed in parliament and then  referred to a Standing Committee. Our summary and detailed feedback to  the Bill is available here: http://cis-india.org/intern... The Standing  Committee harshly criticized the Bill. See:  http://164.100.47.134/lsscommittee/Finance/42%20Report.pdf After which  the Bill has not been reworked by the UIDAI or the Planning Commission  /Niti Aayog for re-presentation to the Parliament.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; No - it is not just an expensive experiment. It is  much more dangerous - it is what security experts call a Honey Pot. A  centralized repository of biometrics harvested from residents of India.  These biometrics can be used to authenticate transactions in the UIDAI  database and other services. If there is a breach - then this huge  collection of authentication factors will end us in the hands of  criminal elements or some foreign state.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From vaz &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Aadhar is a joke, i have so many IDs and i cannot get any benefits out  of it, it is simply wasting time, if Govt really want mandate make it  easy for people, i pay taxes and Govt should treat me like one , i can  not waste my time standing in queues to get that card, get me time slot  and don't waste my time.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; This is because the process of registration has  been outsourced to private agencies. These private agencies have futher  outsourced to others and so on and so forth. Consequently, there is very  poor management and quality control by these agencies. If indeed  corruption was a priority - we should have tackled high-ticket  corruption first. We could have had biometric registration just for only  the politicians and bureaucrats. We could use biometric authentication  with them to create a non-repudiable audit trail of subsidies flowing  from the Centre to the Panchayat. Unfortunately, we tried to register  everybody simultaneously and that has resulted in poor quality of  biometrics and demographic data. We have visited some of the  registration centre and have seen the reality on the ground.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Guest &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I have been threatened by Gas Agency people if i don't link Aadhar to  Bank Account, won't be given a refilling cylinder.Is this a right one?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K Venkataramanan:&lt;/b&gt; There is an option for getting DBT even without  Aadhaar. The bank account and the gas agency consumer account can be  linked without Aadhar. Please check www.mylpg.in for knowing how to  apply for DBT registration without Aadhaar&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;The Hindu: &lt;/b&gt;Your views Prof Gopinath? Do you see it as a biometrics Honey Pot too?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath: &lt;/b&gt;From a security pov, it is certainly risky. It needs  really robust technologies before one can think of rolling out. For  example, we have "denial of service" attacks. ie, a service can be shut  out by random bombardment of msgs. Most curr large scale systems are  designed to handle it but some cannot handle it if large numbers  collude. This only prevents access to service but other attacks can  exfiltrate (take out) data, modify data, etc.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;The Hindu:&lt;/b&gt; And Mr. Venkataramanan, your thoughts?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From kuldeep singh chauhan &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;We need a strong law for data security. Aadhar is collecting data but  there is no provision except some provisions of IT Act and IPC for data  security.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath:&lt;/b&gt; Yes, the legislation is weak or unnecessarily vague  (eg. the IT2000 act) or too broad in scope. I think what we need is a  citizen's charter for data access, security and privacy. Also, what  needs to be done when systems do not work!&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; There are two interpretations of Sec. 43A of the  IT Act. Acccording to most experts it only applies to Body Corporates in  other words it does not apply to the Government when it plays the role  of a data controller. According to an order issued by the IT Secy of  Maharastra [the court of first instance for 43A of ITA] -this section  will also apply to the Government. But beyond that order we have no  clarity on this question.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Pavan &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;With no privacy laws, isn't it a bad idea to store citizen's data in a  database? We all know how inept our government is in ensuring any  security/privacy.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; With or without laws. Centralized approaches to  identity/authentication management are much more fragile and vulnerable  compared to decentralized options. The Internet is secured by digital  signatures - there is no centralized repository of all these signatures.  Therefore there is no centralized point of failure for the Internet. If  the Aadhaar project was based on Smart Cards instead of Biometrics -  then just like the Internet it would be robust without a central point  of failure. http://cis-india.org/intern...&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K. Gopinath:&lt;/b&gt; Storing all info in a single place is a big security  risk. It needs very robust technologies (such as replication and  "secret sharing protocols") that work inspite of failures. These have  been done here and there but doing it on a large scale requires care.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Kunal Soni &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;SC Adhar card recommendations, ok Got it! But what about the banks for  example SBI who ask for adhar cards stating its the bank's rule? Who's  going to answer the question as they would never listen to common man  and they never did.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Sandeep &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Hi,May be it is a strong message, but what exactly is the need to  make/introduce the Adhaar card, which is not recognizable worldwide? Why  dont we make our passport smart enough and reduce it to a chip as in  Europe. This will also enable everyone to get enrolled in our  administrative system. Basically, we are only repeating the entire  process with no international recognition.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Krishna Rao &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Need to make it mandatory in the lines of SSN in US. Else it would be  very difficult to manage and ensure the subsidies and benefits reach the  really deserved section.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Ramesh &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;It is a great concept it all information like property purchases, tax  returns, ration card, pf, esi, bank accounts , rail, air tickets are all  linked. will reduce corrupt practice considerably. It should be the  main identity of an Indian&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From arun &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;@Sunil what are the privacy safeguards that are in place currently  regarding protection of information collected by the government and  private agencies designated for this?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; Do you mean legal or technical?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;K Venkataramanan:&lt;/b&gt; @The Hindu: Yes, there are serious privacy  issues involved in a centralised database. However, their is a  counter-view that this is no different from any other data base  available in the hands of the government such as the one relating to  PAN. The main concern of those worried about the privacy problem in  Aadhaar is that data collection is done by private agencies, and details  such as biometric data could be misused&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;The Hindu:&lt;/b&gt; Sunil, a question for you from arun&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Pawan &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Govt should give it legal recognition and give legal guarantee about the  usage and storage of the data... After that there would be no concern  related to identity security or enforcing it on the people.. People  would trust it and come forward to register for it.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Sunil Abraham:&lt;/b&gt; Legal recognition and guarantees are not  sufficient. You cannot use the law to fix poor technology design. The  security of the Internet is not a function of good law. It is a function  of good technological design.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;&lt;b&gt;Comment From Pappan &lt;/b&gt;&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;the so called Europe, US an other developed countries already have  Social security numbers, why cant we just look at it like that?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Social Security Number are an additional identifier. The  database just contains a collection of identifiers. If that database is  compromised the information cannot be used to authenticate transactions.  This is very unlike the UIDAI centralized database which is a  collection of authentication factors. Think of it as a database filled  with the passwords of all Indian residents.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: @Kunal Soni - SBI can't insist on it as of now. The  person who issued any circular to that effect may be hauled up in court&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I have two questions. First, why is the honourable supreme court strking  down aadhar, on what grounds? Second, how can the government come  around those objections and allay the courts fears/objections? The  informed panelists may please give their opinions too. Thank you&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: There are 3 sets of petitioners who are being heard by  the SC in the combined case. Some of them associated with the right are  arguing that the UID is a threat to national security as it legitimizes  illegal immigrants. Those associated with the left are arguing that it  is a violation of the right to privacy. Still other who are ex-officers  from the armed forces are arguing that the project is mired in corrupt  practices.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: The Court has not struck down Aadhaar. It has only  passed interim orders protecting the access to services of those who  have not yet had them.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Aashish Gupta&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Aadhaar was supposed to usher in portability of benefits. That is, you  could migrate to a different state and still get the benefit you  deserved.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: The Aadhaar database only contains information that  identifies you and also allow you to authenticate against that database.  It does not indicate eligibility for various schemes/subsidies. The  migration across State level eligibility lists has to be done by the  State. It is not a functionality provided by the UIDAI.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Ramesh&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Supreme Court should have suggested a better option instead of coming  down heavily on the Aadhar Card. The card will straight eliminate  multiple rations cards and voter ids.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: The previous technology adopted by the NDA government -  smart cards or SCOSTA [for the MNIC]. This technology option is free  from many of the flaws of UIDAI's current design.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Mrigesh&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Why is Aadhaar needed? I am for a middle class or for the elite class?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Geetha&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Has the government (or concerned agencies/departments) formulated any  policy on using the Aadhar information collected? For instance, what  agency can use the information, under what conditions, with whose  approval, for what limited purposes? Is this policy publicly available?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: No. Anyone who is approved by the UIDAI as a legitimate  can use the KYC API. Absolutely anyone can use the Authentication API.  There is no policy on what data collection/retention practices must be  adhered to by the users of both these APIs.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Arun Jayapal&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Has the government ever considered/analyzed a way to link the existing  resources (such as ration card, DL, passport, voter id, etc.,) and not  have come up with a completely new system (aadhaar). Is this not an  absolute waste of time and resources?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Yes, you are absolutely right. The government should have  used biometrics as a means to dedup an existing high value database  like the Electoral Rolls or more importantly the PAN Card database. That  would have been better RoI for our anti-corruption Rupee.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: @Ramesh The Court has come down heavily on only  officials who insist on Aadhar for delivery of services when there are  clear orders that it should not be mandatory&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From George J&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I'm an NRI. I presently work and live in a country where the first order  of business on landing/Birth is to register one self and get a unique  ID number and ID. This the case for expats as well as residents be they  foreigners or Citizens. The registration process includes collection of  Biometric data. This single No and Id is used for everything from Bank  Accounts to School Admissions. It is good that India is doing something  similar. It is high time people with multiple ration cards, Passports  and the like are weeded out and provided a single verifiable identity.  Data Security is of essence and necessary safeguards are available.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Could you name the country? And can you use biometrics  your country to authenticate transactions in a centralized database for  all sorts of transactions? If yes, then the technology design in your  country is as poor as in ours and it is only a question of time when the  centralized database leaks.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Aashish Gupta&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Apart from the Honey Pot, Aadhaar does not serve its primary purpose:  tackling corruption. Most pilots of Aadhaar have crash landed, and as a  result, state governments have created their own simpler systems to  tackle corruption.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: See: http://www.thehindu.com/opi... If the authentication  match is not working [1:1 match]. Then basically the dedup will not  work [1:n] match. That is why they are doing demographic dedup before  biometric dedup - because they know that the biometric dedup is  fallible.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Balu&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;A citizenship card , backed with a strond database is a must for every  citixen . Some serious thoughts should be done in this matter at the  earliest , instead of wasting time and money on different schemes .&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: We should use decentralized Internet scale technologies  based on open standards that are already proven. If we had used smart  cards based on SCOSTA or EMV standard we would be in a much better  place.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From PRASHANTH&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Has the government (or concerned agencies/departments) formulated any  policy on using the Aadhar information collected? For instance, what  agency can use the information, under what conditions, with whose  approval, for what limited purposes? Is this policy publicly available?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From vikash&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;supreme court should not have to push such legal hurdles given that the  750 million card has already been generated.A lot of money has been  investad in the project&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Saket&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Aaadhar card is full of errors. At the place where I got registered  person was issuing it in a hurry which creates lots of typing errors in  DOB and Place.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Aashish Gupta&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The supreme court has not struck down aadhaar, it has said that aadhaar  cannot be mandatory. This is to make sure that people who do not have an  aadhaar card do not miss out on their entitlements.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Ramesh&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Aadhaar should be made mandatory with necessary safeguards. Unless there  is an ultimatum and time frame to get the card it will never be  implemented. Even now many do not know where to get it done.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Aadharam&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Could you clarify whether this is an interim order or a final order on  Aadhar? Is there scope for a retraction/shift on the Supreme Court's  part?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Onkar Tiwari&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Why supreme court doesnt understand Adhar is necessary? it can curb  corruption. it wll reduce corruption specially in manrega where people  enters fake details and grab the money.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: It is only an interim order. The Court will,  hopefully, resolve the questions raised by the petitioners about privacy  and data security issues&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From George J&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I have taken Aadhar Card. The procedure asks the applicant themselves to  verify the data entered for typing mistakes etc. before being uploaded,  in fact where I registered they had asked for a sign off on the final  data on a printout. So how errors can creep in is beyond me. However the  photography equipment and skill of the data entry operator leave much  to be desired as the mug shot is not very kind to me!&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;There should be a guide line which need to be followed as it is in the  hands of private partners who are also ask for bribe from the poor  people for the aadhar and they have no other option to pay for it as  they thought that this only can help them to get the govt. facilities  and subsidies.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: @Onkar Tiwari, It is up to the government to convince  the court that Aadhaar will help curb corruption, and how. The Court is  unlikely to stop the use of technology to improve delivery of services  and curb corruption.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From v subrahmanian&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;help line over phone and the email correspondence is total waste.. they  themselves are helpless. Any query has never been replied to the  caller's satisfaction. Getting them on line itself is a challenge. It's  so complex. Of course, every eligible citizen of this complex country  must have the identity card. Why not if it is done through employer in  case of organized salaried employees?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Ramakrishna Rao&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Hi !! I request the panelists to kindly sum up in few 4 or 5 points the  reasons/grounds on which the parliamentary committee has rejected the  aadhar&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The agencies who are collecting data for Aadhar Card are not doing good.  The aadhar card is full with many kind of errors including Name and  DOB.. Even a person is able to register twice under this scheme.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hindu: Mr. Venkataramanan would you like to respond to Ramakrishna Rao?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;@K Gopinath - how robust is the de-duplication UID claims to have. And  in real time transactions, is it possible to authenticate n request  without 'false positives' or 'negatives'?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K. Gopinath: Dedup claims assume “good” conditions. For example, a  farmhand may have rough skin, etc that may make the fingerprints  problematic. 1% errors have been reported in the past. Real time txns: I  think the current Aadhar is not geared for it. The connectivity is not  there. Also, with fingerprint technologies, the ability to check large  number of fingerprints for a match is not good enough. It has never been  scaled to the extent that is being planned.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Sandeep&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Still not sure if Aadhaar then other ID cards not needed ? Or Still all  along with Aadhaar ? then what is meaning of Aadhaar ? Only for LPG  connection? Why not govt making Aadhaar is mandatory in all other fields  as well , As Govt spent huge money for Aadhaar&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;@ Sunil - How plausible is the idea that govt can use UID data to profile public?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Sushubh&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I for one is very happy that at least the Supreme Court is not falling  for this privacy infringing scam. People defending this card here on  this platform needs to read more about it.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Govt. created panic among public regarding adhaar. Public is highly  annoyed with the way the government is handling this adhaar project.  Only court reprimands,govt. backtracks as far as the adhaar is  concerned. It is high time for govt. to have serious insight into this.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: The parliamentary committee on Finance had objected to  the UID being extended to non-citizens on the ground that it may end up  in illegal immigrants getting Aadhaar numbers.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;It had also questioned the rollout ofthe scheme before legislation was  passed. It had objected to its implementation without regard to its  consequences.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Srinivasa&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I believe Nandan Nilkeni had mentioned certain very good examples of the  system flagging duplicates. So I assume the system is robust. We need  to make it mandatory for all services delivery and have suitable policy  and technology to protect data.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: I don't think we can go by the assurance of someone no  longer associated with the project. It is not persons that keep us safe  it is proper technology and law.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hindu: Welcome back Sunil! Lots of questions await you&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: The committee had said UIDAI had no conceptual  clarity, no proper assessment of the costs involved, and that it could  end up in the hands of private agencies, that the technology was  untested and the UID may not meet the objectives for which it was  conceived&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Sorry I was logged out.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;There was a recent news in The Hindu about linking of Adhar cards to  election voter ID cards in Andhra Pradesh. Do you think that adopting  such moves by every state result in mandating the procedure eventually?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;First Passport then PAN , voter id and now adahar, in any country there  is only passport and SSN, why india needs so many identity cards&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K. Gopinath: The PAN database has been problematic just as the voter id.  Hence, every technology cycle, a new system is usually attempted that  attempts to be "better" than the before. However, this requires care  which is not in good supply in the govt where the "lowest" bidder wins  or outsourcing happens.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hindu: We have Prof Gopinatha back too. Sorry about that technical glitch.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Deepak Vasudevan&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Why are different apex agencies managing Aadhar like UIDAI, Census and  NPR? There should be one root (apex) body and others should report onto  it.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Yes. The division of work between UIDAI and NPR is not very clear and has added to the confusion.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: The parliamentary standing committee, too pointed out the overlap of functions involving UIDAI and NPR&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hindu: There was this question for you earlier on the thread @K  Gopinath - how robust is the de-duplication UID claims to have. And in  real time transactions, is it possible to authenticate n request without  'false positives' or 'negatives'?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K. Gopinath: Dedup claims assume “good” conditions. For example, a  farmhand may have rough skin, etc that may make the fingerprints  problematic. 1% errors have been reported in the past. Real time txns: I  think the current Aadhar is not geared for it. The connectivity is not  there. Also, with fingerprint technologies, the ability to check large  number of fingerprints for a match is not good enough. It has never been  scaled to the extent that is being planned.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;When Union Of India aimed to greater transparency... these are the road  blocks they get... If Aadhar is not mandatory... then make Voter ID, PAN  Card, Ration card also not mandatory in their respective Govt  Businesses ... make self declaration as mandatory .. lets go to the  stone age in this Information age. Instead SC should direct the center  to come up with procedure to accommodate legitimate citizens of India  into the scheme in a time bound manner and frame policies to avoid  misuse of the personal data. are we looking the current world  Information age thru the same old glasses... it is time to adopt the  change...&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Indeed we need more transparency. But privacy protections  must be inversely proportionate to power and as Julian Assange says  transparency requirements should be directly proportionate to power See:  http://openup2014.org/priva...&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;K Venkataramanan: Linking Aadhaar and voter ID cards is also being tried  out in other states It is only one more means of eliminating fake  voters or duplicates, but is unlikely tobe a ground to make Aadhaar  mandatory&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Ganesh&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;@Mr.Sunil, The current technology adopted for UIDAI is not good compared to last regime?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Please see my our open letter on this question http://cis-india.org/intern...&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Madhavan R&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Just because UPA government bring this, its not good for NDA to object  it.. STOP wasting our money.. Just try to make best out of it..&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Pouring more money into a failed project will not save  it. It has serious technological flaw and without addressing it we are  just making a bad situation worse.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From George J&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Currently all embassy's are collecting biometric data when you apply for  a visa. Most of this collection is done by private parties on behalf of  the respective governments. So if an Indian has travelled abroad the  chances of his Biometric data being available to foreign govts is 99%.  So what is the big scare about this? The need that it should be secure  and should not be misused is sacrosanct. with the kind of revelations  that have been made about mass eavesdropping I think people should get  used to living in glass houses!&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Pappan&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;@Sunil, please clarify about your comment on technology inadequecy&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Yuvaraj&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I strongly support Adhaar card implemenataion. intially they may face  challeneges but for the long run its very effective mechanism to monitor  every thing&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Monitoring everything means you monitor nothing. The  bigger the haystack the harder it is to find the needle. Good  surveillance practices means targetting survelliance not en masse data  collection.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;It is heard that privacy of citizens is at stake with adhaar card. can panelists respond to this?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: I have dealt with your question here: http://www.business-standar...&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Srinivasa&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;That comparison of the two standards (SCOSTA and Aadhar) made  interesting reading. Why not a system where you collect biometrics and  iris and then issue a SCOSTA card? the biometrics and iris can be used  to remove duplicates and maintain a clean registry by failing the  duplicate SCOSTA cards. And all further transactions will only need a  card based access.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Loganathan&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;This is one the worst move by any government in the center to remember.  With no motive for the card, they introduced just to add to the loss in  exchequer and there is no benefit out of it. Many have wrong data  entered against their name and totally the waste one of all&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Sabari Arasu&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;I am aware of someone who is not Indian citizen got Aadhar card for  himself and his family. This scares me a lot as anyone(read  Bangaladheshis, Sri Lankans, Pakintanis, etc..) can get Aadhar card. Is  there a measure taken by Government to identify these issues?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: This is possible because the technology [biometrics]  cannot verify citizenship. Even worse biometrics can be imported from  foreign countries and can be used to create resident ghosts. This is  because the technology cannot even verify if the person in India. We  will need surveillance cameras at every point of registration to take  care of this possible fraud.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Chandra Sekhar&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Aadhaar card was a huge opportunity for the government to improve the  efficiency of governance.It was a challenging task and required great  amount accuracy.The way this project was executed is a question mark on  efficiency of governance.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;The Hindu: Sunil, Venkatramanan, Gopinath - would you agree that Aadhaar  was an opportunity to improve governance? @chandra sekhar&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Freebee lovers/netas will always oppose when you want to implement some thing which might deny them the benefit.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Any evidence to backup this statement?&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Comment From Guest&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;if the ASDHAAR is nt necessary as per SC then why everywhere it is being preferred identity such as Subsidy, Passport etc.&lt;/p&gt;
&lt;p class="body" style="text-align: justify; "&gt;Sunil Abraham: Preference is not the same as a mandatory requirement.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-hindu-march-17-2015-aadhaar-an-identity-crisis'&gt;https://cis-india.org/internet-governance/news/the-hindu-march-17-2015-aadhaar-an-identity-crisis&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-04-03T06:54:25Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/what-does-facebook-transparency-report-tell-us-about-indian-government-record-on-free-expression-and-privacy">
    <title>What Does Facebook's Transparency Report Tell Us About the Indian Government's Record on Free Expression &amp; Privacy?</title>
    <link>https://cis-india.org/internet-governance/blog/what-does-facebook-transparency-report-tell-us-about-indian-government-record-on-free-expression-and-privacy</link>
    <description>
        &lt;b&gt;Given India's online population, the number of user data requests made by the Indian government aren't very high, but the number of content restriction requests are not only high on an absolute number, but even on a per-user basis.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Further, Facebook's data shows that India is more successful at getting Facebook to share user data than France or Germany.  Yet, our government complains far more about Facebook's lack of cooperation with Indian authorities than either of those countries do.  I think it unfair for any government to raise such complaints unless that government independently shows to its citizens that it is making legally legitimate requests.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Since the Prime Minister of India Shri Narendra Modi has stated that "&lt;a class="external-link" href="http://pmindia.gov.in/en/quest-for-transparency/"&gt;transparency and accountability are the two cornerstones of any pro-people government&lt;/a&gt;", the government ought to publish a transparency report about the requests it makes to Internet companies, and which must, importantly, provide details about how many user data requests actually ended up being used in a criminal case before a court, as well as details of all their content removal requests and the laws under which each request was made.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;At the same time, &lt;a class="external-link" href="https://govtrequests.facebook.com/"&gt;Facebook's Global Government Requests Report&lt;/a&gt; implicitly showcases governments as the main causes of censorship and surveillance.  This is far from the truth, and it behoves Facebook to also provide more information about private censorship requests that it accedes to, including its blocking of BitTorrent links, it's banning of pseudonymity, and the surveillance it carries out for its advertisers.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/what-does-facebook-transparency-report-tell-us-about-indian-government-record-on-free-expression-and-privacy'&gt;https://cis-india.org/internet-governance/blog/what-does-facebook-transparency-report-tell-us-about-indian-government-record-on-free-expression-and-privacy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>pranesh</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Freedom of Speech and Expression</dc:subject>
    
    
        <dc:subject>Transparency Reports</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-04-05T05:08:37Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-namrata-acharya-april-12-2015-surveillance-rises-privacy-retreats">
    <title>Surveillance rises, privacy retreats</title>
    <link>https://cis-india.org/internet-governance/news/business-standard-namrata-acharya-april-12-2015-surveillance-rises-privacy-retreats</link>
    <description>
        &lt;b&gt;WikiLeaks founder Julian Assange and former US National Security Agency contractor Edward Snowden have, at considerable personal cost, revealed how surveillance has eroded the private space in a world driven by digital technology.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published in the &lt;a class="external-link" href="http://www.business-standard.com/article/opinion/surveillance-rises-privacy-retreats-115041200669_1.html"&gt;Business Standard&lt;/a&gt; on April 12, 2015. Sunil Abraham is quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;In India, the extent of surveillance became evident after Union human resource development minister &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Smriti+Irani" target="_blank"&gt;Smriti Irani &lt;/a&gt;walked into the trial room of a &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Fabindia" target="_blank"&gt;FabIndia &lt;/a&gt;outlet  in Goa last week, only to discover closed-circuit television (CCTV)  cameras pointed towards the trial room. The country woke up to the  porous divide between privacy and surveillance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Now, senior officials of FabIndia find themselves embroiled in a case of  voyeurism and seven of them have taken interim anticipatory bail from a  district court. They claim the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Cctv+Cameras" target="_blank"&gt;CCTV cameras &lt;/a&gt;were in the retail area, not the trial room.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The FabIndia incident might have blown the lid on how flimsily our  privacy is protected but there is no doubt that India is slowly but  surely moving towards a surveillance regime, both in the private and the  public spheres.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“After the Snowden episode, there are only two kinds of nations: Ones  that know they are being watched, and others that don’t,” said Pavan  Duggal, an advocate at the  Supreme Court of India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Despite the surge in surveillance, there are hardly any specific laws governing this.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;A few laws&lt;/b&gt;&lt;br /&gt; In 2000, India enacted the Information Technology Act, primarily to  bring e-commerce under legal framework. After the Mumbai terrorist  attack in 2008, the Act was amended, to give the government sweeping  powers for mass surveillance.&lt;br /&gt; &lt;br /&gt; In the context of private surveillance, the 2008 amendment added two definitions: (a) communication device; (b) intermediary.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A communication device, according to the law, means cell phones,  personal digital assistance, or a combination of both or any other  device used to communicate, send or transmit any text, video, audio, or  image. An intermediary was defined as any person who, on behalf of  another person, stores or transmits message or provides any service with  respect to that message.&lt;br /&gt; &lt;br /&gt; Rules regarding CCTV surveillance are governed by the IT Act, 2008, as  CCTVs are considered to be communication devices, with computerised  memory. However, the laws in relation to a communication device and  intermediary deal mostly with third-party data sharing.&lt;br /&gt; &lt;br /&gt; “&lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Article+21" target="_blank"&gt;Article 21 &lt;/a&gt;of  the Constitution guards the right to privacy as a Fundamental Right. We  do not have an explicit Act in this regard, but Section 43A of the IT  Act, 2000, along with the IT Rules, 2011, protects data privacy in  India,” said Prashant Mali, a cyber law and cyber security lawyer.&lt;br /&gt; &lt;br /&gt; There were no amendments of the laws governing CCTVs.&lt;br /&gt; &lt;br /&gt; However, &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Section+66e" target="_blank"&gt;Section 66E &lt;/a&gt;of  the IT Act, states: “Whoever, intentionally or knowingly, captures,  publishes or transmits, the image of a private area of any person,  without his or her consent, under circumstances violating the privacy of  that person, shall be punished with imprisonment, which may extend to  three years, or with a fine not exceeding Rs 2 lakh, or both, with  explanation.”&lt;br /&gt; &lt;br /&gt; “The IT Act is not a privacy enabling law. Hence, the challenges to  privacy in surveillance are not fully addressed in it,” said Duggal.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Internationally, there are more stringent laws governing CCTV cameras.  For example, in the UK, there is a prescribed code. A person filmed by a  surveillance camera can seek the footage. In the US, too, there are  state-specific laws which prohibit the unauthorised installation or use  of cameras in private places, like restrooms and trial rooms.&lt;br /&gt; &lt;br /&gt; “Privacy laws must be compliant with international practices. Laws  governing CCTVs should be more comprehensive. It should not be specific  to voyeurism,” said Sunil Abraham, the executive director of  Bengaluru-based research organisation, the Centre for Internet and  Society.&lt;br /&gt; &lt;br /&gt; The government has been working on a Privacy (Protection) Bill, which  provides safeguards on personal data of individuals and sets conditions  under which surveillance is allowed. It is expected that the Bill will  lead to the creation of the offices of privacy commissioner and data  protection commissioner. However, it is mostly silent on laws governing  CCTV usage.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“In India, the concern over enacting privacy laws, implementing them and  our understanding of privacy are low, compared to the global context.  The Privacy Protection Bill, 2013 is pending before Parliament. When  this gets enacted, our laws would be at par with those in the West,”  said Mali. “But doubts remain about their implementation.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Government surveillance&lt;/b&gt;&lt;br /&gt; Amendments to the IT Act in 2008 gave the government wide powers of  interception, encryption and blocking. The amendment introduced Section  66A, which made sending “offensive” messages through a computer or any  other communication device, such as a cell phone or a tablet, a  punishable offense.&lt;br /&gt; &lt;br /&gt; The Supreme Court recently struck down the provision as infringing the constitutional right of freedom of speech.&lt;br /&gt; &lt;br /&gt; “Every nation is under the classical dilemma to balance national  security with privacy and freedom of expression. Always, when there is a  conflict between the two, national security wins hands down. However,  apart from international consensus, we need customise national  solutions,” said Duggal.&lt;br /&gt; &lt;br /&gt; Today, some of the biggest government projects based on the powers  vested to it under the IT Act. It has enabled the progression of  surveillance procedures like the Central Monitoring System (CMS) and  National Intelligence Grid (Natgrid), enabled through information on  Aadhar card or unique identification number.&lt;br /&gt; &lt;br /&gt; The CMS gives the government access to records of any mobile to landline  calls, to read private emails, texts, and even browsing history through  telecom operators. Natgrid could make the information available to  nearly 11 central agencies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It is reported that the CMS can monitor close to 900 million people at  one go. There is neither confirmation nor denial from the government,”  said Duggal. However, compared to the US and China, that practice  blanket surveillance, India is still considered a low-surveillance  category nation.&lt;br /&gt; &lt;br /&gt; “India is still low on surveillance. In India, we have targeted  surveillance. At any given point in time, less than 200,000 phone calls  are being intercepted. Not more than a couple of lakh of surveillance  orders are given by both state and central governments,” said Abraham.&lt;br /&gt; &lt;br /&gt; Surely, with so many surveillance devices around,  it is a closely watched world like never before.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span&gt;&lt;b&gt;SALIENT FEATURES ON PRIVACY IN THE IT ACT, 2008&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt; Communication Device: Cell phones, personal digital assistance, or  combination of both or any other device used to communicate, send or  transmit any text, video, audio, or image&lt;/li&gt;
&lt;li&gt; Intermediary: Any person, who on behalf of another person, stores or transmits messages or provides any service&lt;/li&gt;
&lt;li&gt; Sections 66A to 66F: Added to Section 66, prescribing punishment  for offences such as sending obscene messages, identity theft, cheating  by impersonation using computer resources, violation of privacy and  cyber terrorism&lt;/li&gt;
&lt;li&gt; Section 69: Amended to give power to the state to issue directions  for interception or monitoring or decryption of any information through  any computer resource&lt;/li&gt;
&lt;li&gt; Sections 69A and B: These grant power to the state to issue  directions for blocking public access of any information through any  computer resource and to authorise to monitor and collect traffic data  or information through any computer resource for cyber security.&lt;/li&gt;
&lt;/ul&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-namrata-acharya-april-12-2015-surveillance-rises-privacy-retreats'&gt;https://cis-india.org/internet-governance/news/business-standard-namrata-acharya-april-12-2015-surveillance-rises-privacy-retreats&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2015-05-02T06:43:33Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
