In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Cambridge Analytica. Show all posts
Showing posts with label Cambridge Analytica. Show all posts

Monday, June 25, 2018

13711 - Privacy advocates seek stronger laws - The Hindu


NEW DELHI, JUNE 18, 2018 01:45 IST

A citizen advocacy group has put together a model Bill that focuses on user rights, data protection

The Cambridge Analytica scandal and the Aadhaar database security concerns have provoked a citizen advocacy group to launch a campaign to protect the privacy of individuals in India.
A set of lawyers and policy analysts have put together a model Bill — the Indian Privacy Code, 2018, — with an overriding effect over the Aadhaar Act. The initiative, backed by the Internet Freedom Foundation (IFF), is looking to garner public awareness and nudge the government into adopting a strong law focused on user rights.

The model Bill envisages a law that will prevent some of the fundamental features of the Aadhaar Act from allegedly operating against citizens. This, the advocacy group expects, will shift power from the Unique Identification Authority of India (UIDAI) to the people.

Advocate Apar Gupta, a co-founding member of IFF, said fundamental features of the Aadhaar Act make its use mandatory while being a universal digital ID not tied to a specific purpose.

Sensitive form of data
“It relies on biometrics, which are an incredibly sensitive form of data. It results in mass surveillance as precondition to availing essential services. Due to its architecture, it makes people vulnerable to data breach and identity theft,” Mr. Gupta said.
However, the model Bill seeks to allow people the option of knowing how much of their data are collected, what information is parted with and what are its consequences. More importantly, it will clearly demarcate an option for the people to refuse consent. This undercuts the Aadhaar Act but more importantly the administrative practices which have resulted in making it mandatory, Mr. Gupta said.

IFF members were also part of the ‘Save the Internet’ campaign that was instrumental in pushing back Facebook’s Free Basics in India.

The advocacy body said its latest campaign, ‘Save Our Privacy’, was to make sure that India gets a privacy and data protection law that protects the fundamental right to privacy.

Privacy law
There is no separate law in India on privacy and data protection. While many drafting efforts have been made since 2010, little has come out of it. In 2012, an Expert Group on Privacy, chaired by former Delhi High Court Chief Justice A.P. Shah, had submitted a report to the Planning Commission. The report had recommended passing a law that makes privacy safeguards technology-neutral and applicable to both government and private sectors.

During the Aadhaar hearing before the Supreme Court in mid-2017, the Centre had constituted a committee of experts under the chairmanship of former Supreme Court Justice B.N. Srikrishna. This committee had released a White Paper and is expected to recommend a draft law to the Ministry of Electronics and Information Technology.

A nine-judge Bench of the apex court had last year declared privacy as intrinsic to life and liberty, and an inherent right protected under the Constitution. This means that an ordinary citizen can now directly approach the court in case of violation of his/ her privacy. The verdict armed the common man against unreasonable State intrusions and protected informational privacy in a digital age.

During the hearing, the top court had expressed apprehensions against the State passing on personal data collected from citizens to private players.

Privacy commission
The model Bill is built on seven progressive privacy principles, including use and purpose limitation (personal data collected for specified purposes cannot be further processed for other purposes) in collection and processing of data. It said a strong and independent privacy commission was necessary to ensure that data protection rights are enforced. The model Bill provides the privacy commission wide powers of investigation, adjudication, rule-making and enforcement.

The model Bill said the government, its arms, bodies and programmes should be made compliant with the privacy protection principles through a data protection law. “We support the use of digital technologies for public benefit. However, it should not be privileged over fundamental rights,” the advocacy group said.

Mass surveillance
“The government is responsible for delivery of many essential services to the public. These services must not be withheld from an individual due to such individual not sharing data with the government...Withholding services on the pretext of requirement of collection of data effectively amounts to extortion of consent. Individuals cannot be forced to trade away data and citizenship at the altar of being permitted to use government services and access legal entitlements on welfare,” the advocacy group said.

The group said the data protection law will have to limit mass surveillance as it contravenes the principles of necessity, proportionality and purpose limitation. It said that evidence gathered illegally, such as telephone intercepts without valid tapping orders, is inadmissible as proof in legal proceedings. To ensure further accountability, all such orders need to be communicated to the person who was surveilled.

Collection of data
The model Bill seeks to ensure that no government or private entity collects sensitive personal data without consent from an individual. The individual will have the right to obtain information from the data controller. This information will include purposes of storage and processing; categories of personal data; recipients to whom personal data have been or will be disclosed; the right to lodge a complaint with a supervisory authority; and existence of automated decision-making.

More importantly, the individual will have a right to request erasure and destruction of data at any time, and data controllers and processors will have to comply with such requests within a fixed time frame.

Offences and penalties
The model Bill also seeks to provide punishment for those found illegally collecting, receiving, storing, processing, disclosing or otherwise handling any personal data. Punishment for this offence may include a fine of ₹1 crore and a three-year imprisonment. Even illegal surveillance of another person will be liable to a fine, which may extend to a fine of ₹10 crore and a five-year jail term.


The foundation has sent an e-mail to the Srikrishna Committee, with a copy of the model Bill. It said this was a policy fix for recurring concerns and controversies, including issues such as Aadhaar, Cambridge Analytica, the social media communication Hub and Edward Snowden’s revelations on mass surveillance.

Wednesday, May 2, 2018

13419 - Exposed: India's own Cambridge Analyticas stealing voter dat - India Today

Exposed: India's own Cambridge Analyticas stealing voter data

HIGHLIGHTS
  • Political consultancies secretly picking voter profiles for parties for targeted messaging during campaigns.
  • Agencies caught on camera selling voter data including numbers, emails, PAN, Aadhaar, and even economic details.
  • Agencies promise 50 per cent rise in voters.

Once this data is obtained by hook or by crook, voters are then slammed with messages customised to their financial status, professions and personality, without them volunteering.

Data harvesting to manipulate voters appears to be far more brazen at home than the lone case of UK-based Cambridge Analytica mining Facebook profiles of Americans for the 2016 Trump campaign, an India Today investigation has found.
This month, New Delhi issued a May 10 deadline to both the companies for a comprehensive response on breaches involving Indians.

Facebook has been struggling with its worst crisis since allegations surfaced Cambridge Analytica gleaned information of as many as 87 million people on the social media platform.

But that could just be the tip of the iceberg, given less-regulated environment in developing countries like India, home to 1.25 billion people, almost half of them now hooked to the Internet.

India Today's undercover investigation unearthed a number of home-grown political consultancies playing fast and loose with citizen data they scrape from various sources, let alone Facebook or Twitter.

The probe found them secretly culling voter profiles on behalf of political parties for targeted messaging during election campaigns.

Manish, founder of New Delhi-based Janadhar, an election management company, offered a trove of data scooped from retail chains, job portals, shopping apps, banks and telecom and DTH firms for unleashing a psychological warfare on voters.
"So we start from survey, strategy, execution and delivery. All put together, we do everything," he told India Today's reporter posing as an agent of a political party participating in Karnataka elections scheduled for May.

"Delivery means what? Can that convert into votes?" the journalist asked.

"Yes, if by that you mean a return on investment so far as your campaign is concerned," Manish replied. "Overall, we'll deliver everything to you from both offline and online sources. We'll also provide you information about the market and voter conversations regarding you."

Overall, we'll deliver everything to you from both offline and online sources. We'll also provide you information about the market and voter conversations regarding you.
He now explained how that information could then be exploited for targeted electioneering --- much the same way as the Donald Trump campaign is believed to have used Analytica's data in 2016.

"We'll let you know what's the buying behaviour, whether you (the voters) are shopaholic, which credit card they use," Manish insisted. "Cambridge Analytica is all about this only. You get an SMS on your card. That SMS is delivered on (mobile phones). So I have everything for you."
Before India Today's reporter met him again, Manish had secured email data of two lakh people from the South Bengaluru constituency.

As a sample, he also sent ten Excel sheets of citizen information containing their names, addresses, PAN, Aadhaar, mobile, SIM and even economic details.

"If anyone is in job and if their CV is put up on a job portal, then you'll get whatever you want," he revealed.
If anyone has a credit card, I'll get that data. If anyone has a loyalty membership of a lifestyle (service), I'll get that data. I'll get the data wherever it's given.

- Manish, founder of New Delhi-based Janadhar
Once this data is obtained by hook or by crook, voters are then slammed with messages customised to their financial status, professions and personality, without them volunteering.
"It's a 360-degree bombardment. When you wake up, you get a flier in the newspaper. You reach office, you see our (campaign) email. When you open your Facebook, you see a photo (advertisement). So what's being done here. It's to surround the voter from all sides," he continued.
"Repeating one thing over and over again. It's 'vote for me' if you want migrant welfare. This has to be penetrated deep into his mind. It's just like rote learning."
But the bill for this goldmine is extraordinarily high. Manish demanded around Rs 1.20 crore for data from one constituency in Bengaluru.

The information would be good value for money, he claimed.
"I am telling you it's (it will result in) an increase of 50 percent (in vote share)," said Manish.
Another consultancy, Pollstar, also promised a rich treasure of voter profiles from both on- and offline platforms.
Its founder, Manish Tiwari, confessed that his teams had swiped mobile data from around every cell tower in Bengaluru South in connivance with unscrupulous telecom officials.
"There are 4.5 lakh phone numbers active on towers in this constituency. Out of which, 1.5 lakh are WhatsApp users," he said. "This data shows the numbers that are linked to these towers at night in your constituency."

Manish's conventional tactics appeared equally deceitful. He would send his staff out as imposters to collect voter information from residential neighbourhoods.
"Our teams will reach out to up to 25,000 houses to collect the data. They would go there to raise awareness about voting, to appeal to people to come out and vote," he disclosed. "We will run this drive in the name of an NGO. We'll collect basic information about their phone numbers, family members there and then. If we target that data, we can influence a minimum of 5-6 percent (of the vote)."

Vivek Banka, director of the Delhi-based Maverick Digital company, boasted of executing multiple marketing campaigns for various stakeholders, including political clients.
There's no issue in sending out targeted messages to voters in the rival camp. Our message will reach out to them as well.
"For example, if the Congress wants that all its digital content becomes visible to the BJP supporters, they will get it 100 percent," he said.
Banka, who offered to track people's sentiments during elections, elaborated on the tools he'd deploy for such sneaky surveillance.
"We have to delve deep down. For us to mine this (voter) reaction strategically, we'll have to develop a customised tool, a device," he said.
"What's that?" asked the reporter.
"That's basically a sentiment-analysis tracker. What voters, people are talking, positive negative or neutral. This is divided into those three segments. We'll be able to access that. We'll have to design a customised tool for this. We'll get it outsourced," Banka explained.
He now quoted the price for the tool.
"It should cost you anywhere between Rs 2 lakh and Rs 4 lakh. It will have an unlimited capacity. The price can be less or more. Our requirement will be first identified. The tool is then customised. I know other (political) parties are also using it," he said.
His colleague and the company's creative head, Omm Dev Sharma, fleshed out the working of such snooping apps.
"Paid-for tools are used, with keywords embedded in them. Who's working for which party -- the BJP, Congress, the BSP, the SP. What people from rival parties are discussing, what is on agenda, which hashtag they are using. Is it positive or negative? What's the feedback there? We analyse everything and prepare our own feedback," Sharma said.
All that information would be tracked automatically and shared with the clients, he added.
Tarun Jain, the business head of Mumbai's Krono Digital marketing company, admitted to buying Facebook data from unknown vendors and selling it to political customers.
"You just tell me the pincodes of either Delhi or Karnataka. I'll show you sample data of any location you want. This data is already with me. We buy it every day. We cannot work without it," he said. "I conduct 40 services a day, which includes SMSes, WhatsApp and emails. How can I do it without data?"
On being asked if such political election management companies should be banned, BJP IT cell head Amit Malviya told India Today, "Yes, I hope Election Commission takes note of it and takes appropriate action. We don't want to undermine our democratic process".
"It is scary for us, as a political party, because we don't want anyone else to resort to such unfair means and try and bend the voter one way or the other. In the recent past, the Congress party has been called out for its alliance with Cambridge Analytica."
Congress spokesperson Sanjay Jha, in a counter-attack to Amit Malviya's allegations, said, "A COBRA post expose that happened in 2014 that told the world how BJP was actually abusing social media by buying out people who became the troll army, the BJP IT cell is known for producing fake videos, morphed images and indulging in fake news."
He also reiterated that such political election management should be banned in India. "India has a right to privacy, unfortunately PM Modi's government argued against it."'
Jha also brought in the Facebook angle, he said that no action was being taken against Facebook. "Facebook is at the linchpin of this entire issue".
Cyber security expert Pavan Duggal spoke about how India has no laws on data protection and cyber security. "It is a flourishing market and it is so because the vacuum is existing. All kinds of stakeholders require these kinds of services. They know India is a fertile ground, there is no data protection law in the country. The Information Technology Act, 2000, does not even come closer to the expectations of people. India does not have cyber security law."

Saturday, April 28, 2018

13385 - Tale of two whistle-blowers


Tale of two whistle-blowers
Chris Wylie took on a corporation, Facebook, Edward Snowden took on the state. With Aadhaar, we are up against the combined might of both.
Written by Reetika Khera | Updated: April 28, 2018 1:20:31 am
Chris Wylie took on a corporation, Facebook, Edward Snowden took on the state. Chris Wylie, who helped set up Cambridge Analytica, is the whistle-blower who has revealed the questionable practices that emerged out of this nexus. (Representational photo)
Its not (just) about Facebook. Or Cambridge Analytica.
In the Facebook-Cambridge (FB-CA) saga the three important players so far are: First, Facebook, with the data of millions of people, couched in an architecture with dubious privacy permissions. Second, Aleksandr Kogan, a psychology professor at Cambridge, whose app “thisisyourdigitallife” harvested the data of the person who downloaded the app as well as the Facebook friends of that person. Third, Cambridge Analytica, a UK company to whom this data was sold by Kogan and which used it to create profiles of individuals, and micro-targeted messages to manipulate their voting behaviour. Chris Wylie, who helped set up Cambridge Analytica, is the whistle-blower who has revealed the questionable practices that emerged out of this nexus.
Zooming out from this specific case is important. One possible silver lining to the FB-CA scandal is that it will lift the halo around data analytics, artificial intelligence (AI) and machine learning (ML), allowing us to see them with all their warts. FB-CA are not the only ones to exploit these techniques, which have been projected over the past few years as “the future”.
AI, ML and data analytics are generally heralded as a force to “do good”. A clutch of studies using these techniques have led to instructive insights related to crime, traffic management, health, etc. What appears to have happened subsequently is that the seminal studies are repeatedly cited, even oversold at times. The dark side of these techniques, that algorithms and data can be “weaponised”, hurting rather than helping the weak, tends to be underplayed. It is this — ugly face of algorithms — that Cathy O’Neil’s book, Weapons of Math Destruction, documents. She makes two other important points: Some claims are overstated and sometimes, contrary to the claims, these techniques replicate — even exacerbate — inequalities and biases. She demonstrates how algorithms can be deployed against the weak in car insurance, pay-day loans, screening job candidates, etc.
It is one thing for data as the by-product of our activities to be used to understand, with the intent of improving, human life. Others such as Zeynep Tufecki and Bruce Schneier (author of Data and Goliath) warn of another alarming shift: To nudge, even push, us to increase our digital footprint. This is done with the sole purpose, they warn, of enhancing data mining opportunities for targeted advertising. The recent evangelising of digital payments is a good example. Cash expenditures do not log how we spend our money in as much detail as digital payments. Metadata (anonymised data, for example, frequency, timing, size of spending, rather than specific purchases) from digital wallets provide useful signals for advertising. Ditto with aggregator apps (food, taxis, etc). Insurance companies are becoming notorious for using such techniques to identify susceptible customers. In this sense, the emerging data economy poses new and serious challenges to privacy.
Schneier warns against the corporate and government surveillance potential of the digital economy. The main concern with the deployment of algorithms by corporations was targeted advertising. Wylie’s FB-CA expose shows businesses may not be squeamish about going further, undermining democratic practices through manipulation and coercion.
Edward Snowden’s revelations in 2013 about mass government surveillance also demonstrated the dark side of these techniques. With Glen Greenwald and others, they exposed the unprecedented mass surveillance power of the NSA’s programmes such as “prism”, “xkeyscore”, “mystic” etc.
One contrast between Wylie and Snowden, the two whistle-blowers is worth flagging. Snowden having exposed his own government has paid a heavy price: He had to leave the country and seek asylum elsewhere (where he remains). For Wylie, thankfully, such a situation has not arisen.
One key reason for this contrast is that Wylie was blowing the whistle against corporations, whereas Snowden spoke out against government surveillance. Though FB-CA are powerful corporations, we have seen some semblance of action by the government against them. Whether the corporations will be held to account remains to be seen, as they tend to have the resources and influence to have their own way. Tech giants have been spending record sums on lobbying the US government, especially against anti-trust and privacy regulations.
This has lessons for us in India too, where Aadhaar is seen as a drill to get the “new oil”, data. Recently, some businesses built on the Aadhaar platform intervened in the Supreme Court arguing that “access to the Aadhaar eco-system.is critical” and declaring Aadhaar illegal will cause them “grave and irreparable harm”.
Like Facebook, Aadhaar’s consent architecture is weak at best, non-existent at worst (remember how Airtel opened Airtel bank accounts when people linked their Aadhaar numbers). Even if we get a robust data privacy and data sharing policy, do we have the enforcement machinery to prevent abuse (there was no serious action against Airtel)? Furthermore, there are genuine anxieties about how many of us are adequately equipped to successfully navigate a world of privacy permissions and protections.
The UIDAI, of course, maintains that all is well. In the face of the exposes by hackers (for example, ZDNet and Robert Baptiste) and journalists (for example, The Tribune) this assertion is vacuous, even laughable. What is alarming is that the UIDAI initiated legal action against the whistle-blowers, not the offenders.
Without pushing the parallel too far, one could view the emerging Aadhaar eco-system as the foundation of a state-sanctioned mega-Facebook project or like China’s scary social crediting system. With Aadhaar we are not up against the might of corporations (as Wylie is) or that of the state (as Snowden is), but against the combined might of the state and corporations.
The writer is a development economist at the Indian Institute of Technology Delhi
For all the latest Opinion News, download Indian Express App
More From Reetika Khera
  • The real beneficiary
    Aadhaar doesn’t empower people, only the state ..
  • Evidence no bar
    Discussion on Universal Basic Income shows an ignorance of inconvenient facts in our experience with direct benefit transfer and Aadhaar..
  • Digging holes, filling them up
    As it completes 10 years, there is enough evidence to show that India needs the MGNREGA..

Friday, April 20, 2018

13323 - Tough provisions, SEBI-like regulator in draft data law in a few weeks, says panel chairman - Factor Daily





An expert committee tasked by the Union government to recommend a data protection law for India is gravitating towards stringent provisions in the draft framework in the aftermath of the Facebook-Cambridge Analytica data scandal but will stop short of copying European Union regulations that are widely seen as the gold standard for user privacy.

It proposes to put in place a data regulatory structure on the lines of the Securities and Exchange Board of India or Insurance Regulatory and Development Authority with an appellate authority and designated courts of appeal.

And, it expects to submit its report to the government by the end of April or early May, the panel chairman B N Srikrishna has said in an interview. “It is for the government to take it from there,” he said.

In the Facebook data breach, analytics firm Cambridge Analytica harvested personal information of some 87 million Facebook users since 2014. In light of the role that fake news and advertisements on Facebook played in the 2016 US presidential elections, data privacy rules have become the focus of lawmakers and users of platforms such as Facebook, Google and others the world over.

The Facebook scandal is the second context-altering event for the Justice Srikrishna-headed data protection committee. Weeks after it was set up by the government end of July last year, a nine-member bench of the Supreme Court ruled that privacy was a fundamental right under the Indian Constitution with reasonable restrictions.

“Today, anybody can take (data) and use it for anything. No one is answerable,” said Justice Srikrishna on phone from Mumbai. “The law has to be agnostic to technology. If it is wedded to one, after two days, the technology will become obsolete and the law will have to be changed. And, you know how difficult that will be with how much the Parliament functions these days.”

After the Facebook-Cambridge Analytica data scandal, there has been a debate on the kind of rules that India’s data privacy law should have and how privacy should be central to the design of platforms. Some experts have pointed to EU’s General Data Protection Regulation (GDPR) as model rules for data protection, while others have called it too stringent. The GDPR law lays down fines of up to the greater of €20 million or 4% of global revenues of companies that violate privacy rules in the EU, among other tough measures.

Justice Srikrishna said the Indian privacy law recommendations, too, would have hefty fines and punishment but stopped short of saying GDPR was a model law for India. “A user will have the right to say that ‘I don’t want to be part of Google, I am deleting my account and make sure that all my data is deleted.’ If subsequently it is found that it was not done, the company will be answerable.”

Most internet companies have sent in their suggestions based on a white paper by the data privacy panel and held public discussions on in New Delhi, Hyderabad, Bengaluru, and Mumbai. “They say GDPR is too strict, we can’t have a law like that,” the retired Supreme Court judge said.

While appreciating the maturity in and thinking behind GDPR, Justice Srikrishna the Indian concept of privacy may not be ready for as strict legal measures. “We need a special law but something like the GDPR in our country to work will be very hard. One size does not fit everybody. We have to make laws for us. Our concept of privacy is very different from the European concept of privacy. We are evolving.”



The key factor in framing the Indian data privacy law will be enforceability. “In India, we are long on law and short on enforcement. We have all kinds of laws but how are they interpreted and enforced. At the same time, without it (a data privacy law), people will say, ‘There is no law. What have I done wrong?’”

The punitive measures in the draft law have not been finalised but they will be stringent and tough, the 76-year-old former judge said. “Every law has to have teeth. How heavy it should be, whether there should be proportionality… all that is up to debate (before the panel),” he said.

“Every law is intended for the benefit of our citizens, benefit of the country. Of course, the benefit of the country also requires improvement of business, ease of business in this country. You can’t take it to one extreme or the other.”

Justice Srikrishna, who chaired the committee on the Financial Sector Legislative Reforms Commission (FSLRC) in 2013, said he expected unanimity in the final recommendations of the 10-member panel. “I don’t see a problem unless somebody votes against me,” he said with a laugh, adding there may be dissenting notes. He pointed out there were a few dissenting notes in the FSLRC committee’s recommendations.


Besides Justice Srikrishna, the committee’s members are: IT and telecom secretary Aruna Sundararajan; Ajay Bhushan Pandey, CEO, UIDAI; Ajay Kumar, additional secretary, IT ministry; Rajat Moona, director, IIT Raipur; National Cybersecurity Coordinator Gulshan Rai; R T Krishnan, director, IIM Indore; Arghya Sengupta, director, research, Vidhi Centre for Legal Policy; Rama Vedashree, CEO, Data Security Council of India; and a joint secretary of the IT ministry who serves as the member-convener.

“I don’t hold the government’s brief. Nor am I an activist. I am a judge. I have to be objective,” Justice Srikrishna said.

To get more stories like this on email, click here and subscribe to our daily brief.

Images: Carnegie India on Twitter and Supreme Court of India website.

Disclosure: FactorDaily is owned by SourceCode Media, which counts Accel Partners, Blume Ventures and Vijay Shekhar Sharma among its investors. Accel Partners is an early investor in Flipkart. Vijay Shekhar Sharma is the founder of Paytm. None of FactorDaily’s investors have any influence on its reporting about India’s technology and startup ecosystem.


Thursday, April 19, 2018

13308 - SC red flags threat of Aadhaar data misuse, asks searching questions - TNN


PTI | Updated: Apr 17, 2018, 23:01 IST

HIGHLIGHTS
  • The SC bench referred to the Cambridge Analytica controversy and said these are not "imaginary apprehensions"
  • In the absence of robust data protection law, the issue of misuse of information becomes relevant: SC
  • Bench asked UIDAI counsel why authorities were allowing private entities to use the Aadhaar platform

NEW DELHI: The Cambridge Analytica data leak controversy today found mention in the Supreme Court, which red flagged the threat of probable misuse of citizens' information by entities which were getting Aadhaar details authenticated by the UIDAI

A five-judge constitution bench headed by Chief Justice Dipak Misra, hearing clutch of petitions challenging Aadhaar and enabling 2016 law, referred to the Cambridge Analytica controversy and said these are not "imaginary apprehensions" and, in the absence of robust data protection law, the issue of misuse of information becomes relevant. 

"The real apprehension is that elections are swayed using data analytics. These problems are symptomatic of the world we live in," the bench, also comprising Justices A K Sikri, A M Khanwilkar, D Y Chandrachud and Ashok Bhushan, said. 

"Please do not bring Cambridge Analytica into this. The UIDAI simply does not have the learning algorithms like Facebook, Google to analyse details of users," senior advocate Rakesh Dwivedi, appearing for Unique Identification Authority of India (UIDAI) and the Gujarat government, said. 

Besides the Aadhaar Act does not authorise any kind of data analysis, he said, adding the UIDAI has "simple matching algorithms" which give answers like 'yes' or 'no' after it receives a request for Aadhaar authentication from a requesting entity. 

The bench, which posed several searching questions, asked the lawyer why the authorities were allowing private entities to use the Aadhaar platform for various purposes and referred to the legal provision to this effect. 

"Why are words 'body corporate or any person' used in section 57 of the Act. It breaks the nexus of the Act with the Consolidated Fund of India... What is the point of involving private parties in the Aadhaar infrastructure," the bench asked. 

Dwivedi responded by saying that "it does not allow any 'chaiwala' or a 'panwala' to become a requesting entity under the Act. It is a limited exercise. The UIDAI will not approve anyone to become an requesting entity (RE) unless it is satisfied that the particular entity needs to use facility of authentication." 

He also referred to private companies like Reliance venturing into the defence sector and said at some point in time, the court will have to decide the aspect where private firms were dealing with public functions of the state, which are currently being carried out by public sector companies. 

He also urged the bench not to give in to the "hyper phobia" against the Aadhaar created by the petitioners opposed to the "inclusive scheme" of the government based on a law and the proper infrastructure. 

"Lobbies favouring smart cards do not want this scheme to succeed as they are opposed to Aadhaar," the senior lawyer said, adding there have been efforts from many quarters to ensure that this scheme, which is more secure and works offline, does not work. 

The bench then referred to the provisions of the Aadhaar Act and said the misuse of information at the end of UIDAI may not happen, but there could be possibility of misuse or commercial abuse of information by private entities involved in Aadhaar authentication. 

To this, the lawyer said the Aadhaar Act provided enough data protection to citizens and contained provisions to punish the offenders for any breach and moreover, the core biometric details cannot be shared by UIDAI. 

"No data protection law can provide hundred percent protection. The test should be 'reasonable, fair and just'," he said, adding that "aggregation, analysis or transfer of data" is not allowed under the statute. 

The lawyer also referred to uncertainties faced in life and said nothing was 100 per cent secure as people died in air travel and accidents on the highways. 

He then referred to the fact that documents like passport, PNR and boarding passes of airlines contain numbers only and it does not mean that identity of an individual is lost. 

He said biometric details do not contain genetic data and they are not intrusive and they are used in instant digital authentication of Aadhaar holder. 

"Aadhaar is not just an exercise to provide benefits and weed out fakes but also to bring the service providers face to face with the beneficiaries. That is the revolutionary aspect of Aadhaar," he said.


"Aadhaar is not the panacea for all evils but the problems that were occuring on account of fake identity documents will be solved," he said.

The bench took note of the plea that Aadhaar cannot be struck down solely on the ground that it is "probabilistic".

However, it said, "If probability leads to deprivation of fundamental rights, then there should be safeguards in place to ensure that this deprivation does not happen. There should be an administrative machinery in place to ensure no genuine beneficiary is deprived."

The advancing of arguments remained inconclusive and would resume tomorrow. 


Tuesday, April 17, 2018

13299 - Aadhaar linking must to prevent impersonation, UIDAI tells SC


Aadhaar linking must to prevent impersonation, UIDAI tells SC by Shelley Chandler | April 14, 2018 | 15:59 

The court said there might be a need for safeguards to ensure data is held safely by "requesting entities" (the place where one is undergoing Aadhaar authentication) seeking to use Aadhaar for authentication and asked the Centre to detail statutory and proposed steps to prevent UID centres from sharing demographic details of persons enrolled in the system.

 Appearing before a Constitution Bench led by Chief Justice Dipak Misra, the UIDAI countered the allegation raised by petitioners, and later taken up by the court, that insistence on Aadhaar for all stigmatises people. The remarks came when Dwivedi said that Aadhaar was not required for the government if it really wanted to do surveillance and that it would employ other means. "As of today, we do not have a robust data protection regime". "The Act does not preclude you (UIDAI) from employing such a technology", the bench said. "Purloining of data... for the goal of influencing elections in some of the most powerful nations... is an issue", Justice DY Chandrachud said, referring to the recent controversy surrounding Cambridge Analytica. "UIDAI neither has the tools to track users nor is it empowered by the law to do so", he said, and referred to provisions in the Aadhaar Act that make sharing of personal information of users a punishable offence. "We can not even tamper with the servers", Dwivedi told Justice Chandrachud, who was far from happy with the explanations. 

Now that Cambridge Analytica issue has been linked with Aadhaar, what new turn the SC hearings will take in the near term, will be worth watching. The bench also referred to the testimony of Facebook CEO Mark Zuckerberg before the US Congress and said "you open the newspapers every day and see reports of how elections in even some of the most powerful nations were influenced". However, counsel Diwedi dispelled the apprehension that the data is being shared by the collecting entities and said these information can not be shared. Justice Chandrachud pointed out that the law says information can be further shared on prior consent. People invariably give this consent, which is in the form of a contract. Counsel said individual data by itself has no value, unless the data of all the persons are aggregated. Justice Chandrachud observed, "Today all information in Whatsapp or Facebook are commercially sensitive". Why should somebody intrude on my privacy and keep a tab over the conversation when I share a message with my wife? "Our concern is it will affect a vast number of populations and the future generation and how are we going to lay down a law". The bench gave the example that even judges in an African country can get the access to his or her chamber by using his finger prints, which are used only for the objective of the entry and the problem was that such data was being stored at a central repository. Giving fingerprints for entry into the courtroom or getting access to something is per se not wrong. Answering questions on why UIDAI was storing metadata of users, he said "it was only limited data exclusively for the goal of authentication". "Then it is liable for sharing by the collecting entities". The CJI asked Dwivedi to explain on April 17 how the Aadhar data will be protected. 

10ThousandCouple http://10thousandcouples.com/2018/04/aadhaar-linking-must-to-prevent-impersonation-uidai-tells-sc/

Tuesday, April 10, 2018

13242 - You’re being watched - National Herald

You’re being watched

Published: Apr 09th 2018, 10.00 AM



                      Photo courtesy: social media
File photo of Facebook CEO Mark Zuckerberg and Prime Minister of India Narendra Modi

As virtual life becomes an extension of real life through extensive digitalisation, your government and digital monopolies like Google and Facebook are rendering the word ‘privacy’ meaningless

It has been iterated time and again by the UIDAI that none other than those working with the agency has any access to the Aadhaar database. However, Nandan Nilekani, in an 2010 interview to this writer, while he was the UIDAI chairman, had said, “The UIDAI will partner with agencies such as Central and state departments, banks, insurance companies, Census of India, cellular operators and other agencies who will be ‘registrars’ for the UIDAI. Registrars will process UID applications and connect to the CIDR (Central Identities Data Repository) to de-duplicate resident information and receive UID numbers. These registrars can either be enrollers or will appoint agencies as enrollers who will interface with people seeking UID numbers. The UIDAI will also partner with service providers for authentication (of the data).”

So it is evident that one’s personal details including biometric information not only rests with the UIDAI but with the many ‘registrars’. Things have not changed much since.

Deepti Kapoor, a young lawyer who came back to Mumbai in December 2018 after finishing her studies abroad, had gone to a mobile service operator’s store for a fresh connection. “I was not carrying my Aadhaar card with me and was flatly refused. The next day, when I went with it, they verified its authenticity by taking my finger impression on an electronic thumbpad and by tallying it with the one in the database,” says Kapoor. “How will that be possible if they did not have access to the database?”

The possibility of the scrutiny of one’s personal life is simply endless. “Since banks to mobile service operators still insist on Aadhaar, it is possible for those who have access to the data repository to monitor your financial transactions, call records and even your physical movements as long as you use mobile phone-based applications. It is no rocket science,” says Kenneth Lobo (name changed) who used to work with Qualcomm in the US till 2013.

Monetising your interactions and choices

Writer Nilanjana Bhowmick who penned an opinion piece for The Washington Post on Yogi Adityanath becoming the Uttar Pradesh Chief Minister was used to online trolling and bullying for her critical views. But what she was not ready for was a fictitious Facebook account holder divulging the sector she lived in the Delhi-NCR region and threatening to make her entire address public. “Since I hail from a different city, every document barring Aadhaar had my old residential address. And at that time, I had just moved to a different sector. There is no way he/she could know about it without accessing my Aadhaar information. How are trolls getting access to Aadhaar information? Is this the data security that UIDAI authorities are bragging about,” she wonders.

“The fear of being monitored is not at all unfounded. The Chinese government has just launched a Social Credit Scheme to rate the trustworthiness of its citizens. Aadhaar has all the ingredients to develop into a tool for the same, should the government decide to do so,” says Ritam Ghose, a technology professional with over a decade’s experience.

The entire debate about data security and how personal data is being used by collectors to pass on to third party vendors to influence people’s choices ranging from their votes to consumer preferences has of course been a raging issue following the role of the Cambridge Analytica-Facebook nexus in influencing the US presidential elections and the Brexit polls in the UK came to light.

Former Facebook executive Anthony Garcia Martinez has come out in the open about how Facebook influences the preferences of its users, notwithstanding repeated denials by its founder and CEO Mark Zuckerberg: “For two years I was charged with turning Facebook data into money, by any legal means. If you browse the internet or buy items in physical stores, and then see ads related to those purchases on Facebook, blame me. I helped create the first versions of that, way back in 2012.”

If you live a digital life, have a virtual presence on social media and use plastic instead of cash, every activity of yours can be monitored and analysed. If you are a doting consumer, your information will be processed and the right deals will reach you. If you are a political dissenter, you can be put under constant surveillance. Unless you decide to go off the grid, you can bid privacy goodbye

Your smartphone apps are stalking you

This happened to Tushar Senapati, who works in the development sector as a consultant in Hyderabad. “I was returning home to Bhubaneswar after nearly a year and called up some old friends. We discussed going on a trip to Kerala and created a Facebook group chat for the same. Surprisingly, from the next morning, I was being served details of hotels in Kerala via Facebook ads. My friends had the same experience. It was kind of spooky,” says the man in his late thirties.

That way, Tushar’s experience tallies with that of Hollywood actor Jim Carrey who tweeted on how he felt he was being stalked by his smartphone’s Facebook and Google apps. He decided to take his page off Facebook and dump the stocks he held in the company.

It was only towards the end of March, 2018 that Facebook users around the world discovered that Facebook’s Android app was snooping on extensive call data without them being aware. “When this feature is enabled, uploading your contacts also allows us to use information like when a call or text was made or received. This feature does not collect the content of your calls or text messages,” Facebook said, also saying that users voluntarily opted in when they were prompted. However, did the users understand what they were signing up for?

Garcia Martinez exposes what Zuckerberg has long been denying about Facebook influencing electoral outcomes. “Facebook deploys a political advertising sales team, specialised by political party, and charged with convincing deep-pocketed politicians that they do have the kind of influence needed to alter the outcome of elections…I was at Facebook in 2012, during the previous presidential race. The fact that Facebook could easily throw the election by selectively showing a Get Out the Vote reminder in certain counties of a swing state, for example, was a running joke,” he wrote in The Guardian.

Facebook has eventually admitted that about 126 million people saw Russian-sponsored ads intended to sway the 2016 US election. The company has also admitted that its algorithms recommended content created by Russian operatives. Initially Zuckerberg had rubbished these allegations, saying the idea of Facebook impacting the elections was “crazy.” Now, there has been an obvious climbdown in face of mounting evidence.

“I was returning home to Bhubaneswar after nearly a year and called up some old friends. We discussed going on a trip to Kerala and created a Facebook group chat for the same. Surprisingly, from the next morning, I was being served details of hotels in Kerala via Facebook ads. My friends had the same experience. It was kind of spooky,” Tushar Senapati

Former Rajya Sabha TV Editor-in-chief Gurdeep Singh Sappal wrotes on his Facebook wall: “Today, as I landed in Bangalore, I got a notification from Facebook. It showed several of my Facebook friends and gives details of places they visited in Bangalore in last 2-3 years, along with the month of visit!

I have cross-checked with a couple of friends. They were shocked and confirmed that the details are correct. Both say that didn’t even share it on Facebook. Yet I know it.

So much for privacy!!”

The development of complicated algorithms that decode everything from your consumer preferences to your mental state on one hand and official diktats like making Aadhaar mandatory for nearly all services and schemes on the other have put privacy in peril. In today’s wired world, every piece of digital signature that you leave behind is tracked and stored. Google, for example, stores every location you have been to ever since you started using its service on your phone. Facebook was recently caught storing videos deleted by its users. Of course, the company blamed it on faulty applications and bugs.

The truth lies someplace else. If you live a digital life, have a virtual presence on social media and use plastic instead of cash, every activity of yours can be monitored and analysed. If you are a doting consumer, your information will be processed and the right deals will reach you. If you are a political dissenter, you can be put under constant surveillance. Unless you decide to go off the grid, you can bid privacy goodbye.

Click here to subscribe to National Herald on WhatsApp

Sunday, April 8, 2018

13220 - Over 5 lakh Indian users’ data may have been ‘improperly’ shared with Cambridge Analytica, says Facebook - The Hindu






Yuthika Bhargava NEW DELHI:,  APRIL 05, 2018 13:28 IST

In a first such revelation, Facebook has admitted that data of nearly 5.6 lakh Indian users may have been “improperly” shared with British political analytics company Cambridge Analytica.

In a first such revelation, Facebook has admitted that data of nearly 5.6 lakh Indian users may have been “improperly” shared with British political analytics company Cambridge Analytica.   | Photo Credit: AFP


"The numbers that we have now are that only 335 people in India installed the App, which is 0.1% of the App's total worldwide installs,'' it says.

In a first revelation, Facebook has said that data of nearly 5.6 lakh Indian users may have been “improperly” shared with British political analytics company Cambridge Analytica (CA).

Responding to a notice from the Government of India, a spokesperson for Facebook said:

"We are investigating the specific number of people whose information was accessed by the app, including those in India.



"Cambridge Analytica’s acquisition of Facebook data through the app developed by Dr. Aleksandr Kogan and his company Global Science Research Limited (“GSR”) happened without our authorization and was an explicit violation of our Platform policies.

"The numbers that we have now are that only 335 people in India installed the App, which is 0.1% of the App's total worldwide installs.


"We further understand that 562,120 additional people in India were potentially affected, as friends of people who installed the App. This yields a total of 562,455 potentially affected people in India, which is 0.6% of the global number of potentially affected people.

Sunday, April 1, 2018

13163 - Tip of the Suckerberg - Outlook India

https://www.outlookindia.com/magazine/story/tip-of-the-suckerberg/299966
Tip Of The Suckerberg
ILLUSTRATION BY SAJITH KUMAR
Psychographics
  • Qualitative methodology to describe consumers’ psychological attributes.
  • Psychographic profile: profiles ­interests, activities, opinions, lifestyle.
  • Does this by looking at consumer behaviour, preferences, web surfing patterns, call records and purchases
  • All this is used to classify people.
  • Companies use profiles for targeted sales and marketing campaigns.
  • Trump presidential campaign used this to ­influence voters.
***
The revelation that Facebook had allowed personal infor­mation from 50 million user ­acc­ounts in the US to be used by British data analytics company Cambridge Analytica shook the world. It took a toll on the stock prices of many companies including Facebook, whose value tanked significantly, and cre­ated a trust deficit in social ­media worldwide. Facebook founder Mark Zuckerberg will face the US Congress next week to answer que­stions about how his social media beh­emoth ­has been sharing the confidential inf­ormation of its ­users for profit.
In India, this has led to a bitter debate and mudslinging between the BJP and the Congress over the latter employing the services of Cambridge Analytica to influence elections. While the slugfest between the two big parties ­continues, this has led to a larger question: how safe is ­personal information and data in the hands of social media companies such as Facebook and WhatsApp? Indians routinely open up their hearts on these sites to share ­information about themselves and their families—do the sites then sell this data to others to man­ipulate buying and, well, voting?
The Facebook problem began in 2014 when a Cambridge researcher, Alexander Kogan, developed an app with a personality quiz called “This is your Digital Life”, which was put up on Facebook. Through this, he collected data from 270,000 users. This then gave him access to data from those users’ friends, and ­ultimately he was able to harvest the data of 50 million people. All this was then given to Cambridge Analytica, who used it to influence Donald Trump’s US Presidential election campaign. The issue here for India is that whistleblower Christopher Wylie, who revealed the nexus between Cambridge Analytica and Facebook, also said that the data analytics company had worked in India with the Congress party. This brings up privacy issues relating to personal data in India and the ability of social media companies to ­potentially misuse such data.
What is of concern is that India currently lacks privacy protection laws and everything is out in the open for firms to misuse. Personal information and data are routinely sold by social media companies, credit card companies and telecom operators. The government has set up a committee led by Justice (retd) B.N. Srikrishna to look into privacy issues; this comm­itee has prepared a draft report but is yet to submit its final report. At the mom­ent, Section 43A of the IT Act and associated rules serve as India’s primary data protection provisions. Given that Facebook is a foreign company, the app­licablity of these provisions to the social media giant is unclear. Says Usha Ramanathan, privacy activist and legal expert, “Most people do not understand the nature of privacy policy. So they sign on everything when signing on to a ­social media app or website. As a result, personal data and information are sold and the user has ­become the product. You are the one being sold and so the service is free. We do not realise that, from being a consumer, we ourselves have become the product for these ­social media sites. Their business is only about using our data.”
Ramanathan explains that a high level of manipulation of data and information takes place through the social media sites, who not only make use of it themselves but also aggregate the data and sell it to others. “When the systems know you even better than you yourself, manipulation becomes inevitable. That is the tragedy of ­technology,” she says.
Amber Sinha, cyber analyst and senior programme manager at the Centre for Internet and Society (CIS) feels that there is a need to look at the various kinds of data one shares while engaging with a social media platform such as Facebook—volunteered data  (data that is ­actively provided by individuals, such as details in a form when they sign up for a service), observed data (behavioural data generated through an individual’s use of the service), and inferred data (which is neither actively nor passively provided by the individual, but arrived at through the analysis of ­collected data).
While individuals are aware of the first category, they are often unable to exercise meaningful control over the second, as it is continually and automatically collected. Observed data also includes the collection of data from other online behaviour of the individual through various tracking tools which are dep­loyed on the browser. 
Further, the third category is often outside the scope of regulation, as it is not directly collected from the user but is inf­erred by the controller based on other data collected. This loophole must be closed by regulation to cover data use as well as collection practices.
Just as there is no privacy for personal data, there is also no privacy for our ­onl­ine activity, which is con­­s­tantly mon­itored by companies such as Facebook and Google. Says K.K. Mookhey, founder and CEO at Global Cyber Security Service Pro­vider, Network Intelligence, “The Facebook model is inh­erently pro­­b­lematic. You and I are the producers and consumers of the content provided by companies like Facebook. Facebook tunes the content according to our habits. What we see on Facebook is according to our choices and general surfing habits. It tracks our general surfing habits on non-Facebook sites, analyses our online behaviour, and then tweaks our content accordingly on Facebook. This is gro­ss manipulation which is automated through algorithms.”
With the data in hand, marketers can choose specific parameters to provide content and do micro-targeting. Cam­bridge Analytica did psychogra­phical mapping of the preferences of voters in the US elections using this kind of data. The company started by looking at und­ecided voters, and kept pushing them tow­ards the Republican Party. According to Elonnai Hickok, COO with CIS, “Personalisation of ­content, be it advertising, news, a product on Amazon or your Facebook feed is a practice that is being used across the board. Per­­­­s­­o­n­alisation happens through algorithms and the data you feed into it. No alg­orithm is perfect and it is possible for manipulation to happen intrinsically. Manipulation of the type that has been attributed to Cam­bridge Analytica is an extension of personalising a message to influence, not buying habits, but larger choices.” Adds Sivarama Krishnan, leader, Cyber Security, with PwC, “There is a clear case of privacy violation from a principle standpoint. It is not a legal violation as users have signed up to it voluntarily. They are manipulating the behaviour of the user by suggesting ­options according to a user’s behaviour and surfing habits. This is what Cambridge Analytica has done. This is a big challenge.”
The public perception of all this is, however, quite different, and most people want their data to be secure. According to a survey done by ­online analytics company Local Circles, 86 per cent of people in a sample survey wanted a law that protected their ­private information and 84 per cent did not want their bank transaction details to be ­accessible after the linkage of Aadhaar and bank acc­ounts, while 75 per cent did not want their call records to be acc­essible after similar linkages. A who­pping 94 per cent wanted companies, particularly banks and telecoms operators, to face a penalty if information is leaked. Says Hic­kok, “Selling of data that allows for personalisation is one of the primary business drivers. Though Facebook all­ows for controlling who sees the data, the company itself has given access to the information as per its business needs. The selling of data does happen around the world on a routine basis. It is important that privacy regulation place a framework around how data can be collected and used, and the redress that individuals can seek if their privacy is violated.”
There is no doubt that there is gross vio­lation of privacy as social media ­companies use and manipulate content for users in order to mould the latter in a particular manner for the sake of ­business. While the European Union is ready to ­introduce the General Data Protection Regulations (GDPR) to ­protect personal information and data from May, India is still a long way from reaching this stage and does not have any legal way at all to safeguard personal data. The country needs to develop GDPR-like rules to  protect its citizens. Until that happens, Big Brothers like Facebook will continue to watch you and will continue to mine Big Data.