In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Data Protection Law. Show all posts
Showing posts with label Data Protection Law. Show all posts

Sunday, May 27, 2018

13598 - ET View: India must enact a data protection law quickly - Economic Times

ET View: India must enact a data protection law quickly
ET Bureau|
Updated: May 25, 2018, 03.22 PM IST

Read more at:

Saturday, May 5, 2018

13461 - Without strong data law, India will end up as digital colony of US, Chinese firms - Ravi Venkatesan - TOI

BY INVITATION


RAVI VENKATESAN

Ram Vilas Mahato and Kapil Prasad, master-weavers from Bihar, are among the last living exponents of their craft. They are also the faintest echoes of the Big Bang of the first industrial revolution. In 1750 AD, India’s share of global industrial output was 25%; by 1900, this had declined to 2%.The main reason was that India missed out on the industrial revolution. This revolution saw the invention of the steam engine and powered looms which made handlooms uncompetitive. The British East India Company forcefully colonised India and converted Indian weavers from producers of the world’s most exquisite and prized handloom fabrics to exporters of commodity cotton and consumers of mill cloth from Manchester. India’s handloom industry was decimated; India deindustrialised and fell into abject poverty from which it is struggling to emerge. Today a few people are racing against time to revive the few remaining traditions using modern methods and designs, thereby creating employment for a new generation of weavers. The lucky ones will make $3-4 a day.

What does this have to do with Amazon, Google, Facebook, Uber or other tech companies? All these companies use technology and new business models to re-architect industry after industry, leaving a swathe of destruction in their wake. The new business models delight consumers, create eye-popping wealth for their shareholders and employees but often impose huge costs on society such as invasion of privacy, destruction of trust, net loss of middle-income jobs.

This has remarkable parallels with the industrial revolution that created wealthy citizens in Britain and western Europe while leaving hundreds of millions of people impoverished in China and India. The British East India Company was the first example of a successful global monopoly that massively extracted and redistributed wealth. The danger today is that we stand at the cusp of a new era of exploitation, this time not by other countries but companies; we should all be grateful to Facebook for alerting us to this threat. We must be careful before mindlessly celebrating disruptive innovation.

The response isn’t to become Luddites or protectionist and vainly attempt to stall technology-driven innovation. India desperately needs the productivity revolution of new technology. We also need foreign capital, technology and skills. 

However we must have a thoughtful technology policy and regulation that encourages innovation but safeguards the interests of our society and citizens and ensures that India doesn’t become a digital colony of US or Chinese firms.

There are two imperatives. First, India must have a strategy to moderate the behaviour of foreign companies so that the relationship is genuinely symbiotic, not exploitative. This is particularly important in the case of platform companies like Google and Amazon that are near monopolies; their behaviour must the closely monitored and occasionally regulated to ensure that they are “good for India and Indians”. 

Nandan Nilekani has been advocating a National Data Strategy to ensure that data is used to empower people, not to exploit them. A key element of this is a data and privacy protection law like Europe’s GDPR, and hopefully the data protection law being drafted by the Srikrishna Committee will strike a fine balance between regulation and innovation.

India could also learn much from China which is a master at trading market access for investments in building indigenous capability in new technologies. More than a decade ago, India successfully leveraged open-source software to get Microsoft, at that time at the peak of its power, to moderate its pricing in India, develop India-specific products, set up a local data centre and research lab and make huge investments to develop the Indian software ecosystem. Microsoft also ended up with a thriving business, resulting in a win-win outcome. Global technology companies need India every bit as much as India needs them. A similar nuanced approach is needed with other major tech companies. This is not economic nationalism; this is strategic prudence.

Second, we must do much more to ensure that India has a thriving, competitive local ecosystem of companies that are leaders in the technologies of the fourth industrial revolution. Yes, India does have a genuine world-leading platform innovation in the India Stack that includes Aadhaar and UPI. But there are few other examples where Indian firms are at the leading edge in key technologies. The blunt fact is that the technologies of the fourth industrial revolution are overwhelmingly dominated by American and Chinese companies, some of which are the biggest investors in the Indian innovation ecosystem. Our vaunted champions Ola, Flipkart, PayTm and others are essentially owned by the likes of Alibaba, Tencent, Softbank and perhaps Walmart. In areas like artificial intelligence, robotics, autonomous vehicles, India has no world champions. China has done a spectacularly superior job in creating flourishing world-class companies in these areas and is therefore much better positioned to win the battle for the future.

The first of these imperatives is easier to address than the second but we can do a few things. We can start by ensuring that there is a thoughtful public discourse on these matters so that we progress with awareness rather than wake up with regret. There must be forums for an informed, intelligent dialogue between key stakeholders: innovators, policymakers, scientists, civil society and business leaders, and from this a real technology strategy can emerge. In the 1960s, India approached space and atomic energy in mission mode; it may be time for missions in some of the new areas. Perhaps India needs the equivalent of America’s DARPA, which led to successes like the internet, GPS, the graphical user interface and the driverless car. America’s leadership in these areas is no accident.

The fourth industrial revolution simultaneously poses the biggest opportunity and the largest threat to a prosperous future. India cannot afford to squander this moment.


Venkatesan is former chairman of Microsoft India 

Monday, March 26, 2018

13107 - Centre collecting, using personal info illegally, says govt committee - TNN


Chethan Kumar | TNN | 

Mar 26, 2018, 04:29 IST

BENGALURU: At a time when discussions on data privacy have put the Centre in a spot in the Supreme Court, the Committee of Experts (CoE) under Justice (retd) BN Srikrishna has said the government is “collecting and using personal data in certain contexts, like intelligence gathering and counter-terrorism, without the backing of any law”.

“The public and private sector are collecting and using personal data on an unprecedented scale. While data can be put to beneficial use, unregulated and arbitrary use of data, especially personal data, raise concerns relating to centralisation of databases, profiling of individuals, increased surveillance and a consequent erosion of individual autonomy,” the paper notes.

The committee, which released the paper in November 2017 and is currently in the process of conducting consultations, has also considered the SC judgment on privacy, whose lead petitioner, Justice (retd) KS Puttaswamy, told TOI that collection and use of data without laws can lead to erosion of privacy as it leaves the citizen with no forum to challenge.

While stating that processing of information in the interest of national security, or the security of the state, is permissible as long as the government is able to demonstrate that it is necessary to achieve the purpose, the committee says the challenge lies in ensuring the derogations to an individual’s right to privacy must be permissible only if it is necessary for these objectives.

Speaking about prior legislation for data protection, the paper points to the Information Technology (IT) Act of 2000 and notes that there are many discrepancies despite the introduction of Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011, known as SPDI Rules.

“SPDI Rules apply only to corporate entities and leave government and government bodies outside its ambit; the rules are restricted to ‘sensitive personal data’, which includes attributes like sexual orientation, medical records and history, biometric information et al and not the larger category of personal data,” the paper notes.

The committee said that the absence of effective enforcement machinery raises concerns about the implementation of the SPDI Rules, making a comprehensive law to protect personal data.


Arguing that certain exemptions — as in the UK and European Union’s General Data Protection Regulation (GDPR) — must be provided to the government when it comes to using data for national security, it bats for proper regulation. “The law may provide exemptions for Information collected for investigation and prosecution; Maintenance of national security and public order. But exemptions must be defined to ensure that data processing is done only for the stated purpose. It must be demonstrable that the data was necessary for the purpose. In order to ensure that the exemptions are reasonable and not granted arbitrarily, an effective review mechanism must be devised,” the paper notes.

Wednesday, January 24, 2018

12773 - Aadhaar hearing: Bill on data protection to be ready by March, Centre tells Supreme Court - New Indian Express


By IANS  |   Published: 23rd January 2018 06:30 PM  |  

NEW DELHI: The Centre on Tuesday told the Supreme Court that the much-awaited bill on data protection -- being drafted by a committee of experts headed by Justice BN Srikrishna (retd) -- would be ready by March.

Attorney General KK Venugopal gave the information to a Constitution Bench of Chief Justice Dipak Misra, Justice AK Sikri, Justice AM Khanwilkar, Justice DY Chandrachud and Justice Ashok Bhushan, which is hearing a batch of petitions that challenged the constitutional validity of the Aadhaar Act as violative of the fundamental right to privacy.

The expert committee headed by Justice Srikrishna -- a former Judge of the apex court -- has Department of Telecom Secretary Aruna Sundararajan, Unique Identification Authority of India head Ajay Bhushan Pandey, MeitY Additional Secretary Ajay Kumar, Indian Institute of Technology-Raipur Director Prof Rajat Moona, National Cybersecurity Coordinator Gulshan Rai, Indian Institute of Management-Indore Director Prof Rishikesha Krishnan, Vidhi Centre for Legal Policy's Arghya Sengupta and Data Security Council of India's Rama Vedashree as its members.
Continuing his arguments, senior counsel Shyam Divan took the court through the Aadhaar Act provisions to demonstrate that under the statute itself the demographic and biometric data of Indian citizens could be shared with private entities.
As the apex court said that if there were "deficiencies" in the Aadhaar scheme's implementation, resulting in leaks, the same could be plugged, Divan said: "It (collection of data) can't be reconciled with (working of) a democratic open society. The entire programme is bad as everyone is entitled to protect himself/herself against exposure of their demographic and biometric data.

Telling the court that the way Aadhaar was being linked with everything "you will have a huge proliferation of data for the purpose of identification", Divan said: "Lift your imagination much higher than where we are", understand the implications of the state possessing the biometric data of the citizens.

Monday, December 18, 2017

12516 - At Express Thinc: Data protection about protecting people - Indian Express


The topic of the discussion was Data Protection and Privacy: Where Are We in India and What’s the Future.

By: Express News Service | New Delhi | Published: December 15, 2017 5:24 am

(From left) Shruti Dhapola, G N Nath, Usha Ramanathan, Nikhil Pahwa and Malavika Raghavan at The Indian Express Thinc in New Delhi on Thursday. (Express Photo: Amit Mehra)

Stricter laws for data protection will not necessarily lead to stifling of the Internet economy, and people need to be at the centre of any data protection law, a panel at The Indian Express Thinc on Thursday said.

The panel consisted of legal researcher Usha Ramanathan, journalist Nikhil Pahwa, Deputy Director General at the Department of Telecommunications in the Union Ministry of Communications G N Nath, and public policy expert Malavika Raghavan.

The topic of the discussion was Data Protection and Privacy: Where Are We in India and What’s the Future. Though the discussion was about the wider scope of data protection, Aadhaar and related issues of privacy inevitably became the primary focus.
Ramanathan at the start of the discussion mentioned that it was while arguing over the challenge to Aadhaar in the Supreme Court that the Union government stated that Indians did not have a fundamental right to privacy, which “told us what the intention” with Aadhaar was. If the data protection framework protects the Unique Identification Authority of India, Ramanathan added on the upcoming law on data protection, then it will fail. “Can’t save the UID and have data protection,” she said, adding that India was becoming a surveillance society from a surveillance state.
Nath of the Communications Ministry said that there are already domain-specific laws that protect data of consumers, even if the country lacks an overarching data protection legislation. He admitted that mobile applications, which are a large collector of consumer data today, is an unregulated space.
Giving the example of industry-specific data protection rules, he mentioned that in the telecom space the licensing agreement any service provider has to sign includes provisions on how the data will be stored and used. He also emphasised that Aadhaar was just an identity, a number, which carried attributes like the biometric and demographic details.
Pahwa said there is a growing fatalism among people regarding allowing companies and governments to collect data about them. With larger private companies continuously collecting data on people, Pahwa said nations across the world are feeling “insecure” because private internet companies have more data on citizens than governments. Further, he said that people do not have any control on the kind of data being collected about them, or how and when it is being done. Today the government demands privacy for itself while arguing for transparency from the citizens, Pahwa said.
The idea that there cannot be stricter laws for data protection alongside a growing Internet economy was a false binary, Raghavan said. She added that both the government and private companies were just gathering data because the cost of data storage was very less and it led to irrelevant data being collected.
Ramanathan stressed the idea that as the government prepares a new data protection law it must keep people in mind. The balance between innovation and privacy must lean towards people’s rights, and not the industry, she said. “The balance cannot be what will suit the industry,” she said, added that it must be within the framework of the Indian Constitution respecting people’s rights. “Data protection is not about protecting data, it is about protecting the people.”
The discussion was moderated by Assistant Editor, The Indian Express, Shruti Dhapola.

Sunday, December 17, 2017

12505 - At Indian Express Thinc: Data protection about protecting people - Financial Express

Stricter laws for data protection will not necessarily lead to stifling of the Internet economy, and people need to be at the centre of any data protection law, a panel at The Indian Express Thinc on Thursday said.
By: Express News Service | New Delhi | Published: December 16, 2017 2:43 AM


The topic of the discussion was Data Protection and Privacy: Where Are We in India and What’s the Future.(Reuters)

Stricter laws for data protection will not necessarily lead to stifling of the Internet economy, and people need to be at the centre of any data protection law, a panel at The Indian Express Thinc on Thursday said. The panel consisted of legal researcher Usha Ramanathan, journalist Nikhil Pahwa, Deputy Director General at the Department of Telecommunications in the Union Ministry of Communications G N Nath, and public policy expert Malavika Raghavan.

The topic of the discussion was Data Protection and Privacy: Where Are We in India and What’s the Future. Though the discussion was about the wider scope of data protection, Aadhaar and related issues of privacy inevitably became the primary focus. Ramanathan at the start of the discussion mentioned that it was while arguing over the challenge to Aadhaar in the Supreme Court that the Union government stated that Indians did not have a fundamental right to privacy, which “told us what the intention” with Aadhaar was. If the data protection framework protects the Unique Identification Authority of India, Ramanathan added on the upcoming law on data protection, then it will fail. “Can’t save the UID and have data protection,” she said, adding that India was becoming a surveillance society from a surveillance state. Nath of the Communications Ministry said that there are already domain-specific laws that protect data of consumers, even if the country lacks an overarching data protection legislation. He admitted that mobile applications, which are a large collector of consumer data today, is an unregulated space.

Giving the example of industry-specific data protection rules, he mentioned that in the telecom space the licensing agreement any service provider has to sign includes provisions on how the data will be stored and used. He also emphasised that Aadhaar was just an identity, a number, which carried attributes like the biometric and demographic details.

Pahwa said there is a growing fatalism among people regarding allowing companies and governments to collect data about them. With larger private companies continuously collecting data on people, Pahwa said nations across the world are feeling “insecure” because private internet companies have more data on citizens than governments. Further, he said that people do not have any control on the kind of data being collected about them, or how and when it is being done. Today the government demands privacy for itself while arguing for transparency from the citizens, Pahwa said.

The idea that there cannot be stricter laws for data protection alongside a growing Internet economy was a false binary, Raghavan said. She added that both the government and private companies were just gathering data because the cost of data storage was very less and it led to irrelevant data being collected. Ramanathan stressed the idea that as the government prepares a new data protection law it must keep people in mind. The balance between innovation and privacy must lean towards people’s rights, and not the industry, she said. “The balance cannot be what will suit the industry,” she said, added that it must be within the framework of the Indian Constitution respecting people’s rights. “Data protection is not about protecting data, it is about protecting the people.” The discussion was moderated by Assistant Editor, The Indian Express, Shruti.

Friday, December 1, 2017

12452 - Enable privacy: Data protection must strictly impose purpose limitation and penalties for breaches - - TOI

November 29, 2017, 2:00 AM IST TOI Edit in TOI Editorials | Edit Page, India | TOI

A high-level government committee of experts headed by Justice BN Srikrishna has released a white paper seeking views from stakeholders on data protection. Coming against the backdrop of the apex court’s landmark decision upholding right to privacy as a fundamental right, data protection has certainly become a hot-button issue. Driving the debate is government and other agencies increasing the scope of Aadhaar linking for services – a matter slated to be adjudicated by a constitution bench of the Supreme Court.
In fact, the unique identification number bolstered by an individual’s biometric data is now being used for everything from school admissions to obtaining death certificates. While the utility of such moves is left vague, the fear that the data provided could be leaked or misused is real. Current data collection practices in the country hardly inspire confidence, with personal information regularly being shared among different parties without the knowledge of customers. In such a scenario, pushing Aadhaar linking for day-to-day transactions is akin to having a digital master key that can open all facets of an individual’s life.
Such a master key would certainly violate the right to privacy upheld by the Supreme Court. Not only could unscrupulous elements misuse personal data for profit or crime, there are also concerns that an Aadhaar-backed data architecture can be used to profile individuals on the basis of their caste, religion, sexual orientation, political opinion, etc. Given these anxieties, the need of the hour is for a comprehensive data protection framework. This should include an independent data protection authority to handle issues related to use of information collected by governments and corporations.
Among other things, data protection norms should strictly implement the purpose limitation principle whereby data collected is only used for the purpose stated to the individual. And tough penalties should also be imposed for breaches of purpose limitation. This could include stiff financial compensation to customers and even criminal prosecution of violators. Many of these provisions are part of BJD MP Baijayant Jay Panda’s private member’s bill on data privacy, which can be used as a guide. Add to this the need for a strong cyber security architecture to ensure data isn’t stolen through digital attacks. With the digital environment set to grow further – and government looking to push Digital India initiatives – it’s time to give data privacy its due importance.


DISCLAIMER : Views expressed above are the author's own.

12450 - The 7 pillars of data protection law, according to Srikrishna Committee - Economic Times


BY MUGDHA VARIYAR & SURABHI AGARWAL, ET BUREAU | NOV 28, 2017, 09.36 AM IST

On Aadhaar, the committee said that despite its attempt to incorporate various data protection principles and safeguards, Aadhaar has come under public criticism.

Big Change:

The government-appointed Srikrishna committee on Monday released a white paper as part of its work to prepare a data protection framework. The committee has called on stakeholders to discuss and debate various issues under the ambit of the ambitious legislation, which includes issues pertaining to data transfer and accumulation, informed consent, data portability, as well as appointment of a data authority. 

The committee has sought views from all stakeholders by December 31 post which it will work on writing the draft of the Bill. 

“A firm legal framework for data protection is the foundation on which data driven innovation and entrepreneurship can flourish in India. Fostering such innovation and entrepreneurship is essential if India is to lead its citizens and the world into a digital future committed to empowerment, experiment and equal access,” the paper said. It added that the committee‘s view is that the law must be cognisant of international practices and at the same time it must be aware of the views of Indians. 

The Srikrishna Committee, set up by the ministry of electronics and IT, has identified seven principles for the data protection law, which include technology agnosticism, where it states that the data protection law must be flexible to include changing technologies, data minimisation — stating that data sought and processed must be minimal and as necessary, and informed consent. 

“Consent is an expression of human autonomy. For such expression to be genuine, it must be informed and meaningful. The law must ensure that consent meets the aforementioned criteria,” the ten-member expert committee said. 

The other principles include accountability of data controller, penalties for wrongful processing and enforcement of data protection framework by a statutory authority. 

Rahul Dev, technology lawyer and patent attorney at Tech Corp Law Group, said the committee will need to draw a clear line between data privacy and intellectual property owned by companies in the form of user data. 

“For example, as per the white paper’s note on purpose and use of data, an ecommerce company may not be justified to use the user’s earlier collected data to launch and market a new mobile wallet service without obtaining the user’s consent,” Dev said. The committee has also highlighted key issues relating to data protection in the light of new technologies including internet of things and machine learning based on big data. It notes that the “biggest challenge in regulating emerging technologies such as big data, artificial intelligence and the internet of things, lies in the fact that they may operate outside the framework of traditional privacy principles.” 

On Aadhaar, the committee said that despite its attempt to incorporate various data protection principles and safeguards, Aadhaar has come under public criticism and the committee will analyse the “interplay between any proposed data protection framework and the existing Aadhaar framework.” 

“The advent of the internet of things also poses a challenge to the degree of anonymity that can be achieved,” the committee said in the paper. “New devices capture data in forms which are unique. An example is that of a person’s gait being uniquely identified by a wearable activity tracker. Such data can perhaps never be completely de-identified. The current methods of using aggregated anonymised data might not be secure enough when applied to such data.” 

Some industry members hailed the paper, and said it has touched important points such as data portability and data-driven access to services.


Stay on top of business news with The Economic Times App. Download it Now!

Monday, September 18, 2017

12060 - For a law to protect privacy and data - Economic Times Blog

September 14, 2017, 10:58 PM IST ET Edit in ET Editorials | India | ET

At Wednesday’s conclave on financial inclusion organised by the UN, finance minister Arun Jaitley was confident that the Aadhaar law would stand the test of confidentiality. At the same event, Niti Aayog vice-chairman Rajiv Kumar felt that the law would need to be strengthened, in the wake of the Supreme Court ruling privacy to be a fundamental right under the Constitution. Privacy and data protection are issues that go beyond Aadhaar.

Regardless of whether the Aadhaar law takes care of privacy in relation to the biometrics gathered by the Unique Identification Authority of India, India needs a separate law on privacy and data protection, ideally on the lines of the European Union’s General Data Protection Regulation, adopted in 2016 and slated to come into force in May 2018. Recently, the Chinese law enforcement agencies nabbed 25 wanted criminals using facial recognition software applied to security camera images from a beer festival.

A Chinese airline has started using similar software in place of boarding passes. In India itself, a number of private enterprises ask employees to mark attendance by putting their thumbs to a fingerprint scanning machine. Phones now unlock themselves reading the user’s fingerprints or facial features. When people download and instal apps on their smartphones, they accept all sorts of conditions, including many that invade privacy. Social media open up a great deal of private data. The use of GPS to navigate leaves a trail of your movements. All this data is out there, without a law securing their integrity and protecting the data subject against harm. This must be remedied, without losing time. We have to go beyond Aadhaar.


There must be specific protection for the individual against unjustified, and not merely unauthorised, snooping by government agencies. Any breach of privacy must be authorised by a court order and the agency responsible must be held to account by a committee of Parliament, and not merely the executive. We need a law to create data protection and a regulator who would be accountable for the job.

Monday, September 11, 2017

12002 - UIDAI declines privacy activist request for Aadhaar data protection information - Biometric Update



The Unique Identification Authority of India (UIDAI), the authority for Aadhaar, have declined Indian privacy activist Vivek Velankar’s request to reveal the names of companies responsible for storing sensitive data as well as the manufacturers of the servers over ‘security reasons’, according to a report by The Times of India.September 5, 2017 - 
To address data privacy concerns regarding the compulsory Aadhaar registration, Velankar had filed an RTI application asking for the names of the companies storing Aadhaar data, name of the country where the data is stored and the names of the server manufacturers.
“I had sought the information regarding UIDAI under RTI,” Velankar said. “However, the identification authority has denied the information citing Section 8 (1) (a) of the RTI Act, which says that if the information is provided, the country’s security will be endangered.”
Velankar said that such basic information should be publically available to assure people that the stored information has not been given to a foreign company, is stored within the country, and that the servers housing the information are not manufactured in China.
UIDAI officials responded by stating that the information is too sensitive and cannot be shared outside the authority, unless it is ordered by the government.

The authority also said that UIDAI’s central identities data repository facilities, information, assets, logistics, infrastructure and dependencies installed at the authority’s locations are protected by the Information Technology Act, 2000.

In early August, theUnique Identification Authority of India (UIDAI) told India’s Supreme Court that it is nearly impossible to use Aadhaar to track citizens.

Friday, September 1, 2017

11940 - Aadhaar data kept, processed only on own secure servers: UIDAI - Economic Times

PTI|

Updated: Aug 30, 2017, 08.05 PM IST

NEW DELHI: The UIDAI today rejected charges that foreign firms were accessing sensitive data, saying no Aadhaar information has ever been stored or processed outside its own data centre and resides only within its fully-secured servers. 

"Aadhaar data is fully safe and secure and has robust uncompromised security. The UIDAI data centre is an infrastructure of critical importance and is protected accordingly with high technology, conforming to the best standards of security," the UIDAI said in a statement. 

The Unique Identification Authority of India (UIDAI), which is the Aadhaar issuing body, said such data is accessible only to the biometric software provider's solution for the purpose of processing of data "within the highly secure environment of UIDAI data centre". 

The Aadhaar data is stored, kept and processed only on the UIDAI severs within its data centre. Moreover, it said these servers have no linkages to the "outside world" through the Internet or any other means, including laptops and pen drives. 

The data centre premises are fully protected "physically", the UIDAI claimed, adding that hardware supplies are also tested twice before being put to use in the data centre. 

"No Aadhaar data has ever been kept, stored or processed outside the UIDAI data centre and is always on UIDAI servers," it added. 

The UIDAI said the role of the biometric service providers is to offer de-duplication software which too runs on UIDAI's secure servers and data centres. 

"The biometric image data is never in physical possession of biometric service provider or any of its employees at any point of time, in any case," it said further. 

The terms of contract require the software solution to be secure and conform to the government's data security guidelines, the statement said, adding that applications running on UIDAI IT hardware too are secured through firewall and intrusion prevention system. 

All the service providers are bound by strict confidentiality regime under the contract, and violation would lead to three years of imprisonment, it added. 

The statement from the UIDAI comes amid reports that an RTI application has revealed that the Aadhaar contract gave foreign firms access to classified personal data such as fingerprints and iris scan information. 

The UIDAI has been fire-fighting allegations of unauthorised access to data. Last week, WikiLeaks hinted that the CIA had allegedly accessed the Aadhaar database, a claim strongly refuted by the UIDAI. 

WikiLeaks, in a tweet last week, had said, "Have CIA spies already stolen #India's national ID card database?" 

It was alleged that the Central Intelligence Agency (CIA) was leveraging tools of US-based technology provider Cross Match -- incidentally, an Aadhaar vendor -- for snooping, and that sensitive data could have been compromised. 


Friday, August 18, 2017

11796 - ‘Enact data protection law soon’ - The Hindu


BENGALURU, AUGUST 16, 2017 21:37 IST
UPDATED: AUGUST 1

India’s tech community, including technology billionaire Nandan Nilekani, who spearheaded Aadhaar, say India quickly needs a “data protection law.”
Mr. Nilekani said the country needed a strategic position on data which represented risks such as colonisation, privacy issues and a “winner-takes-all market,” in which the best players are able to seize a very big portion of the rewards, and the remaining contenders are left with very little. “Data is being vacuumed out of the country and going into unaccountable systems that don't come under Indian law, which probably share data with foreign governments,” he said at an event here organised by Carnegie India, a think tank. “How do you protect people's privacy and how do you make companies accountable.” Mr. Nilekani said that the law also has to make it incumbent on the data collector to immediately notify if there is any data breach.

Due to the rapid adoption of smartphones, digital payments, social media platforms and Aadhaar authentications, Mr. Nilekani said that India is going to become data rich very quickly, but there is a need to strategically think about data in a way that people of the country benefit from it. “We are running out of time, it is happening at a very fast pace.”

The government led by Prime Minister Narendra Modi has appointed a committee of experts led by former Supreme Court judge, Justice B.N. Srikrishna, to identify “key data protection issues” and recommend methods to address them.

Data inversion
Mr. Nilekani proposed a concept called 'data inversion' which puts the creator of the data at the centre where she can have access to her own information and take it back. This would make sure that Indians are able to use their own data to improve their lives such as getting better credit or improve productivity on the farm. Mr. Nilekani said that India is a hugely underserved market for credit. “All credit goes to the big guys, they all go to London (Vijay Mallya). The small guy doesn't get the credit from the financial system as they don't have enough data about these guys,” he said.

Mr. Nilekani was of the view that this is 'inversion of data' is not protectionism but empowering the users as global as well as Indian companies should function in an open competitive market. However the there has to be a strategic framework or law which decides how data can be collected and used. “This has nothing to do with Indian or foreign companies. Let every body flourish,” he said.

Sharad Sharma, co-founder of software product think tank iSPIRT, which works closely with hundred of product firms was of the view that India has an opportunity not to replicate the data protection laws and framework of countries like Europe, China and the US but build a system which is intuitive to the country. This is also because such systems in regions like Europe were built before the advent smart phones and new technologies like artificial intelligence and Internet of Things. “Ultimately we need educated users, people who know what to do with their data. It requires some public education, we have already seen it for people to adopt digital payments,” he said.
Rahul Matthan, a partner at law firm Trilegal, said that data protection around the world is based on the consent given by the user, but there needs an additional level to be imposed in the form of accountability. He said there is a need to have a legal framework which prevents data controllers from using consent as an indemnity for all the actions. “Add a layer of protection for the user in the centre. We don't need consent, we need accountability,” he said.

Monday, August 14, 2017

11756 - Aadhaar is fully protected: UIDAI's former tech head - Deccan herald


N V Vijayakumar, DH News Service, Bengaluru, 
Aug 12 2017, 23:16 IST

                             Srikant Nandhamuni

Aadhaar system is fully protected and well-designed from any data breach, according to Srikanth Nadhamuni, who was the first technology head of Unique Identification Authority of India (UIDAI), which issues identification numbers to citizens. 

In an interaction with DH, Nadhamuni said Aadhaar system can proactively plug any attempts to steam data. “I firmly rule out any possibility of hacking into the Central Identities Data Repository (CIDR), where the Aadhaar data is saved in the country. It is extremely secure and well-designed system,” Nadhamuni said.

Commenting on the recent attempt by technology professional Abhinav Srivastava to illegally create a public app that could obtain details of Aadhaar holders, Nadhamuni said the National Informatics Centre (NIC) website which is giving AUA (Authentication User Agency) services is not secure.

“NIC, which is giving AUA service provider is outside the purview of Aadhaar, is not complying with its security standards. Instead of Aadhaar’s HTTPS, NIC is hosting their data on HTTP website, application layer protocol designed within the framework of the Internet protocol suite,” he said.

Misinformation

Nadhamuni said it is a misinformation that the hackers got into the CIDR.

“There is no way Aadhaar servers can be hacked. The government and other parties who are using Aadhaar services have to make their systems secure. In this recent case, the person impersonated and acted as a NIC person to directly take data from Aadhaar server,” he said.

The Khosla Lab India head also pointed out that all the entities directly availing Aadhaar services should comply with strict security standards. “We have to further strengthen this security standard so that it is ensured that they are following it,” he said.

UIDAI has appointed 27 KYC Service Agencies to provide authentication services and under them, there are different KYC User Agencies to verify users details.
According to experts, in the recent incident, the accused accessed passwords by hacking E-Hospital - a healthcare delivery platform developed by NIC.

Recently Nandan Nilekani, former head of UIDAI, stated that Aadhaar security was a big concern. The Aadhaar security issue is coming up a time when the Supreme Court is hearing a petition to decide if data privacy is a fundamental right. The Centre made it very clear to the apex court on July 27 that data privacy cannot be a fundamental right as it has many facets.

To give further momentum on data privacy, the government on August 1 formed an expert committee to deliberate on data protection laws, which will also come up with a draft data protection Bill.


Sunday, August 6, 2017

11726 - Why is the govt leaving out independent voices from data protection framework panel - Hindustan Times


Why is the govt leaving out independent voices from data protection framework panel

It is a good move to institute a committee to an expert committee to deliberate on a data protection framework for India. However, independent experts must be included
EDITORIALS Updated: Aug 02, 2017 20:34 Ist

Hindustan Times
As the distinction between ‘users’ of ICT-enabled applications and ‘citizens’ of the country become more and more conflated, it is critically important for the government to put in place a framework for the manner in which users’ data can be protected. (AFP)

In itself, it is a commendable move by the ministry of electronics and information technology (MeitY) to have set up an expert committee to deliberate on a data protection framework for India. Given that the IT Act was written almost two decades ago in 2000, and was last amended almost 10 years ago in 2008, it is high time that the laws in this fast changing sector were re-examined. As the presence of technology companies such as Facebook and Whatsapp become ubiquitous; and the government continues to push for increased collection of citizens’ data through Aadhaar and DNA profiling, questions of data protection and data privacy have become vitally important.

As the distinction between ‘users’ of ICT-enabled applications and ‘citizens’ of the country become more and more conflated, it is critically important for the government to put in place a framework for the manner in which users’ data can be protected. Seen in light of the current case being heard in Supreme Court regarding the collection and use of Aadhaar data, this committee becomes even more relevant and important. However, the composition of the committee leaves much to be desired in terms of the number of points of view on the issue that will be represented in it.

It is vital that the composition of the panel that will make recommendations to the government include independent cyber security experts along with jurists and legal experts. Given that most of the members of the panel have spoken against a right to privacy in the past, the composition of the committee is heavily skewed in the direction of the government’s slated policy that data privacy cannot be a fundamental right.
The implications of strong data protection legislation will have repercussions on all data collected, stored, and used in various forms – be it in the private sector with companies that collect and analyse big data or the government with linking bank accounts and PAN numbers with Aadhaar, and the collection and use of DNA samples.

























Friday, August 4, 2017

11706 - Government Forms Panel to Suggest Data Protection Framework Amid Aadhaar Concerns - NDTV


Press Trust of India, 02 August 2017

HIGHLIGHTS
  • Formation of the panel comes amid concerns over data breaches
  • Panel will study and identify key data protection issues
  • The panel will make specific suggestions to the government
The government has constituted a 10-member committee to recommend a framework for securing personal data in the increasingly digitised economy as also address privacy concerns and build safeguards against data breaches.

The formation of the panel comes amid concerns over personal information being compromised with increasing use of biometric identifier Aadhaar in an array of services - from filing tax returns to availing government doles.

The committee of experts headed by Justice B N Srikrishna, former judge of Supreme Court, will suggest a draft data protection bill, the IT Ministry said in a release.

The panel which draws its members from government, academia and industry will study and identify key data protection issues and recommend methods to address them.



An office memorandum issued by the Ministry of Electronics and IT said: "The government is cognizant of the growing importance of data protection in India. The need to ensure growth of the digital economy while keeping personal data of citizens secure and protected is of utmost importance."

The panel will make specific suggestions to the government on principles to be considered for data protection in India and "also suggest a draft data protection bill", it said.

The official note did not specify a timeframe for submission of report by the panel but said it will endeavour to do so "as expeditiously as possible".

The panel also includes Aruna Sundararajan, Secretary, Department of Telecom; Ajay Bhushan Pandey, CEO of Unique Identification Authority of India; Ajay Kumar, Additional Secretary, IT Ministry; Gulshan Rai, National Cyber Security Coordinator; and Rajat Moona, Director, IIT Raipur.



The constitution of the panel is significant given the offtake of digital transactions in the country, as also the rising apprehensions around safety of personal data. Although, the Information Technology (IT) Act provisions deal with cyber crime and data protection, but the spike in cashless transactions in the country post demonetisation and an increasing number of business going online have necessitated the need for fresh look at the existing laws.

Questions have also been raised over data security and privacy safeguards after some websites of the central and state government departments were found to be displaying personal details and Aadhaar numbers of beneficiaries.

Aadhaar has been issued to over 115 crore people, and many government schemes and subsidies now mandate quoting of the 12 digit identification number. Also, the biometric identifier has been made mandatory for applying for PAN and bank accounts.

Telecom regulator TRAI too intends to start a consultation on data privacy and security within the telecom networks, particularly with regard to mobile apps seeking user data.

For the latest tech news and reviews, follow Gadgets 360 on Twitter, Facebook, and subscribe to our YouTube channel.


Friday, June 16, 2017

11531 - New law to unlock data economy - The Hindu





NEW DELHI, JUNE 09, 2017 23:28 IST

Proposal has been sent to PMO for approval.

The government is mulling a new data protection law to protect personal data of citizens, while also creating an enabling framework to allow public data to be mined effectively. The move assumes significance amid the debate over security of individuals’ private data, including Aadhaar-linked biometrics, and the rising number of cyber-crimes in the country.
“The Ministry of Electronics and Information Technology (MEIT) is working on a new data protection law. A proposal to this effect has been sent to the Prime Ministers’ Office for approval,” a senior ministry official told The Hindu.
Once the PMO approves it, the ministry will set up a “cross-functional committee” on the issue.
“We want to include all stakeholders. It will be a high-level committee, and all current and future requirements of the sector will be discussed.”

Two chief aims
The official said: “We are working with two main aims – to ensure that personal data of individuals remain protected and is not misused, and to unlock the data economy.”

The official explained that a lot of benefits can be derived from the data that is publicly available, by using technology and big data analytics. “The information can be used for the benefit of both individuals and companies,” the official said.
“The underlying infrastructure of the digital economy is data. India is woefully unprepared to protect its citizens from the avalanche of companies that offer services in exchange for their data, with no comprehensive framework to protect users,” Software Freedom Law Centre (SFLC.in), a non-profit, said in an emailed reply.
Currently, India does not have a separate law for data protection, and there is no body that specifically regulates data privacy.
“There is nominally a data protection law in India in the form of the Reasonable Security Guidelines under Section 43A of the Information Technology Act. However, it is a toothless law and is never used. Even when data leaks such as the ones from the official Narendra Modi app or McDonald’s McDelivery app have happened, section 43A and its rules have not proven of use,” said Pranesh Prakash, policy director at CIS.

Some redress for misuse of personal data by commercial entities is also available under the Consumer Protection Act enacted in 2015, according to information on the website of Privacy International, an NGO. As per the Act, the disclosure of personal information given in confidence is an unfair trade practice.