In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Rajeev Chandrasekhar Independent MP. Show all posts
Showing posts with label Rajeev Chandrasekhar Independent MP. Show all posts

Sunday, January 14, 2018

12738 - Rajeev Chandrasekhar for Aadhaar 2.0 secured by blockchain -Hindu Businessline


VINSON KURIAN


THIRUVANANTHAPURAM, JANUARY 12: 

The launch of a virtual id for Aadhaar is, in a sense, an acknowledgement on the part of the UIDAI about its design flaws and breaches into the database.

But this could well mean locking the stable door after that horse has bolted, says Rajeev Chandrasekhar, MP, an UIDAI critic.

‘Welcome, but belated’
“For the first time after many years of criticism, it has woken up and found its own slogans and speeches on data security failing it,” he told BusinessLine here.

“It has for the first time responded to critics like me saying that Aadhaar is unsafe and acknowledged its obligation to keep it safe. Hence this virtual id.”

This is welcome, though belated. But this clearly is not enough. One has been crying hoarse saying from 2010 that Aadhaar is faulty design-wise.

UIDAI has now got to create a road map to redesign Aadhaar for the future. It can use technology like blockchain to create a much more secure and encrypted database.

Go for Aadhaar 2.0
“I would call it Aadhaar Version 2.0. Aadhaar has to be re-architectured to become a solidly reliable part of the digital governance ecosystem.”

Chandrasekhar recalled that Aadhaar Act would itself soon come up for review before the Supreme Court. It will decide whether the Act is Constitutional or is consistent with the right to privacy having been declared a fundamental right.

The Finance Minister has said that the government is open to making changes to Aadhaar Act if necessary. Because this Act was passed by Parliament before the Supreme Court ruled that privacy is a fundamental right.

The Act has to be made consistent with privacy being a fundamental right. Which means that UIDAI will have a legal obligation to enrollees with respect to security of their data.
Today, nobody can file a case against it unless it decides to sue itself. This imbalance and asymmetry in the Act needs to be addressed.

Proof of citizenship
Chandrasekhar said that he had been saying from 2010 that there was a need to bring Aadhaar to Parliament and debate about its design, concept, and architecture. But this was not done.

The concept about Aadhaar being merely a proof of identity, and not of citizenship or domicile, is not just right. This too would be challenged in court for sure, he said.

These, he said, were some of the short-cuts made in the Aadhaar design during the UPA period when no law was enacted, no debate held or scrutiny performed.

Some of the petitioners in the Supreme Court say Aadhaar makes for a surveillance state, others say biometrics are unreliable or intrusion into privacy, even that Aadhaar should be scrapped.

“But my position is that Aadhaar should stay. We should address these design flaws. Make sure that privacy is an important issue that is addressed, that your data is never misused.”

The issue of citizenship should be addressed at least in version 2.0. If you can’t identify between a citizen and a non-citizen, then what is the use of Aadhaar?


Thursday, November 9, 2017

12337 - Aadhaar was a rushed decision by authorities, says Rajeev Chandrasekhar - Business Today



 BT Online        Last Updated: November 7, 2017  | 23:54 IST

Aadhaar was a rushed decision by authorities, resulting from consumer rights not being focal in bureaucratic way of working in India, said Rajya Sabha MP Rajeev Chandrasekhar today. He was speaking at the India Today Conclave Next 2017.

"Consumers and consumer rights are almost never the principle focus of the public policy, especially in the digital space. It is only in recent times, with RERA for example, that consumers are getting to get real acts, real rights embedded in law," he said while delivering the keynote address on Privacy 

Privacy -- The Fundamental Right for the Digital Citizen.

Chandrasekhar lauded the Supreme Court for its ruling declaring privacy a fundamental right. He stated that the apex court categorising privacy as a fundamental right will help in making required changes when the time comes.

Moreover, as a Supreme Court bench is about to hear the case of Aadhaar being a threat to privacy, Chandrasekhar said, "Citizens will have an obligation to provide data to states, will have obligation to provide data to those private entities that are delivering services to them. But these entities, whether they are state or these private entities, will have clear obligations on how they collect, how they store, how they manage the  above data, and how they reuse it."

Pointing security loopholes in the structure of Aadhaar under UPA government, Chandrasekhar said, "Crores of people were being onlined, their information was being onlined with kind of a canned narrative and a rush for numbers without addressing other issues relating to privacy, security and even integrity. And in many ways Aadhaar was a classic example of how a government system would push for technology in governance without addressing key bits of the ecosystem around the citizen and the consumer."

"We have about 30 crore Indians online today, and over the next maybe two, two-and-a-half, three years we expect about 80 crores Indians to come online, transforming India from being one of the largest unconnected nations in the world to becoming one of the largest online nations. And so therefore the awareness of the challenges and the problems that come along with it are increasingly coming to the fore," he said.

The Rajya Sabha MP, however, also emphasised on the still prevalent absence of proper structure in digital India. "Despite the obvious success of the telecom sector in having over one billion Indians connected, the basic issues around consumer rights remain," he said.

He further added, "Data privacy, and privacy in the digital world, is not an elitist issue. There is an attempt to characterise this as some kind of an elitist issue, and it is not. It becomes more and more important as more and more Indians come online and consumers do not have the adequate protection against the misuse of data or information."?

Thursday, May 18, 2017

11422 - Time to Fix Aadhaar - Rajeev Chandrasekhar

Time to Fix Aadhaar
In spite of high-decibel promotion, Aadhaar has several loopholes that can impact national security and invade people's privacy


Rajeev Chandrasekhar   New Delhi     Print Edition: June 4, 2017

There has seldom been so much fog and noise around a programme as we have around Aadhaar.

First conceived under the Vajpayee government as a national ID Card, it was taken up by the UPA as the watered down but heavily hyped Aadhaar. The narratives around this through the entire UPA term were about the miracles of technology and what it would do to transform governance - the broad-brush, sweeping characterisation of the benefit of technology without much thought about how it would be used. As one of the earliest critics of its watered down specs, I jokingly referred to it as a solution looking for a cause way back in 2012.

But the few voices like mine that did point out the obvious mistakes in its design and concept were brushed aside by the tidal wave of PR that was unleashed. The Unique Identification Authority of India (UIDAI) had even hired a journalist as its full-time PR. There was no parliamentary debate or scrutiny except for one in the Standing Committee of Finance, which was blunt in its critique of it - possibly the reason why there was a conscious effort to duck Parliament for the rest of the UPA term. Despite the lack of public scrutiny, thousands of crores were spent on collecting and building the database that is known today as the Aadhaar DB.

Fast forward to 2014 and the NDA government had two options - to shelve it or to fix it and move ahead. I was among those who felt that the money spent should not be wasted and it could still be used to deliver subsidies better. It is to this government's credit that it did not just junk this project. This government, from its first day, was invested in the vision of technology enabling the transformation of governance. Hence, we have come across Digital India and Transform India! Aadhaar, with all its flaws, can still be used to implement this vision.

Aadhaar was subjected to Parliamentary scrutiny and given legislative backing by the Aadhaar Act passed in 2016. The government addressed the issue of lack of verification and fake entries by making the UIDAI statutorily responsible under Section 3(3) of the Act, for verifying the entries. So if there is a fake entry, the officials of the UIDAI will be responsible. But the problem is: Prior to the law being passed, over 100 crore enrolments had already happened.

It was widely known that in the run-up to 2014 elections, the Congress and then UIDAI Chairman, who was also contesting, were in a race to enrol large numbers for Aadhaar. Because of the strange (or maybe deliberate) loose verification process of using small, often fly-by-night enrolment agencies, many fakes were being reported. In the absence of any audit and reverification/clean-up, this made the Aadhaar DB an unverified or poorly verified database.

Fast forward to now and a recent case highlights the risks. Two Pakistani spies were found with Aadhaars under fake names but with their own biometric data. 

A new definition of fake is now standard where biometrics are real but the identity is fake. There are thousands of reports highlighting such incidents, caused by the casual and almost criminally negligent pre-enrolment verification process during the UPA regime. This should give us cause for worry at a time when there are attempts (often without knowing its implications) to expand the use of Aadhaar into a full identification system - for accessing airports, opening bank accounts and so on. It is causing worry as terrorists may use fake Aadhaars to enter the financial system or carry out money laundering. Who will be responsible if a fake Aadhaar (fake ID with real biometrics) is used by terrorists/foreigners to get into the financial system or obtain a passport or get a voter identity card? What protections exist to ensure that the 110 crore Aadhaar entries do not have any such entry among them?

This authenticity issue is seen as a victimless flaw because it does not seem to impact any person. But it impacts the larger issues of national security and financial sector integrity and risk.

 These are legitimate issues to be dealt with by institutions like the Reserve Bank of India (RBI) and the National Security Council/Home Ministry, but they have been behind the curve and seem to have unquestioningly bought into the narrative of a technological miracle that had been peddled for several years.

Thankfully, and as I had predicted way back, issues like data security and privacy have come to the fore and people are now focusing on Aadhaar. The debate and scrutiny have become mainstream, moving away from a few MPs and activists to consumers and citizens. As the use of Aadhaar is expanding, more and more concerns about its design, operation and misuse have surfaced. Moreover, it is common knowledge that there have been data breaches, exposing sensitive personal information of millions of citizens, including Aadhaar numbers.
Who is responsible for ensuring that data and information pertaining to each member is not made public and not misused? What is the method of adjudicating and getting damages if such a thing happens?

Who is responsible for ensuring that databases are managed securely against hackers and data breaches? What kind of accountability exists in those organisations that manage and control this data?

Unfortunately, the Aadhaar Act and regulations place no reciprocal accountability on the UIDAI to protect the database of personal information provided by citizens and are silent on the liability of the UIDAI and its personnel in case of non-compliance with the provisions of Section 3 and Chapter VI that require verification and protection of such data. The UIDAI has maintained a studied silence about these breaches because it is not required to report such cases. This must be fixed and reporting all data breaches should be made mandatory.
Many of these issues were raised long ago by some people and I was one of them. But they were dismissed or subsumed in the tidal wave of PR that Aadhaar had unleashed. There was even an epic article in which the Chairman of UIDAI claimed that the design of Aadhar had privacy built into it. A few years and many data breaches later, the song that is being sung now is about the need for a privacy law - precisely what was argued by me several years ago.

The current provisions regarding privacy and data protection under the Aadhaar and the Information Technology Acts are skewed in favour of those who hold our data and place an extraordinary burden on the individual to get justice. The issue of privacy is a broader issue that goes beyond Aadhaar. It raises legitimate questions about the roles and responsibilities of the State and other private agencies that are custodians of our digital footprints at the time of rapid digitisation of our lives and economy. It is a significant issue and I would encourage the government to take the lead. Concerns among citizens can be addressed only if the government articulates clear and public safeguards to prevent misuse and breaches. Technology solutions and even databases like Aadhaar are only going to improve governance and use of public money. But that must not blind us to their design flaws and Aadhaar is one that needs to be fixed.

The writer is Member of Parliament, Rajya Sabha, and Vice Chairman , NDA Kerala




















Saturday, April 15, 2017

11053 - With 100 Cr Unverified Aadhaar Numbers, Time for Accountability - Quint

With 100 Cr Unverified Aadhaar Numbers, Time for Accountability
TheQuintOpinion

Rajeev Chandrasekhar
April 13, 2017, 5:26 am

There is no doubt in my mind that most people still do not understand what is Aadhaar. One reason is that there has been little real debate around what Aadhaar is because of a lot of slick PR by those who built it. There is a need to understand it before we criticise it or attempt to repair its failings.

1) Aadhaar Escaped Initial Scrutiny
The UPA government spent thousands of crore on Aadhaar with no debate in or outside Parliament, no legislative backing for it and most importantly, not one word on legal accountability for the authenticity of this biometric database.

As a result, thousands of crore were spent on creating a biometric database, which conducted very poor verification of identities and did not and does not have any details of who was a citizen.

The only time Aaadhar was scrutinised was by the Standing Committee on Finance which concluded very correctly that having poor verification and without having citizenship identification, Aadhaar was simply a collection of fingerprints of people whose identity was unverified. The Standing Committee recommended that Aadhar be merged with the National Population Register.



2) Aadhaar Bill

This government brought the Aadhaar Bill, repositioned it as a subsidy delivery platform and encouraged parliamentary debate.

It has developed a strategy to use Aadhaar and other tools to launch a sharp attack on the vexed and cursed problem of leakages, ghost and fraudulent claimants to public subsidies. It has addressed the issue of lack of verification and fake entries by making UIDAI statutorily responsible for verifying the entries.


3) 100 Crore Unverified Aadhaar Cards

The issue of use of Aadhaar as an ID for purposes goes beyond subsidies, ie to ensuring access to airports, as an ID to open bank accounts, for air tickets. Obviously, this goes beyond the remit of what the Aadhaar bill was supposed to be for.

When there is clear evidence all over of fake Aadhaars, what safeguards has UIDAI taken before Aadhaar is being permitted to be used as an identification card or tool? This needs to be answered.


The issue of rampant fake Aadhaar entries is a real one and it’s a direct consequence of the sloppy way this database was built.
While the Aadhaar Act passed in 2016 makes it the responsibility of the UIDAI to issue Aadhaar numbers only after verification – the government must know that between 2010 and 2014 there were over 60 crore and then 2014 and 2016 over additional 40 crore – totally 100 crore Aadhaar numbers with little or no verification.

Through the entire term of the UPA, Aadhaar numbers were issued with almost non-existent form of verification. This involved numerous small companies becoming enrolment agencies that were paid for each enrolee and who would collect the biometrics and collect documents without any responsibility of authenticity. There are hundreds and thousands of reports of enrolment agencies that took bribes to issue Aadhaar cards.

4) Using Aadhaar as an ID Card

While using Aadhaar to deliver subsidies is an acceptable cost of fakes, to use it as an ID is creating a situation of systemic risk. If this is not resolved and fixed at this stage, you will create a cascading crisis of fake and ghost bank accounts, voters and passport holders that you will find very difficult to unravel later.

There are solutions to this, but to develop that solution, we need to first accept that there are some shortcomings with Aadhaar.


5) Audit of Database

The problems of ghost and fake entries in Aadhaar will need to be addressed through an audit or cleanup or re-verification of the database. This is unavoidable. Ignoring it is unacceptable in the interests of the country.

6) Linking Aadhaar with Subsidy Delivery

There is another question for the Minister to ponder upon. Is it your case that non-citizens are entitled to government subsidies? There is a legal proposition that as a citizen and taxpayer, I can object to or insist that subsidies not be provided to any non-citizen till the needs of all our citizens are met.

If that proposition holds, then doesn’t it imply that citizenship information is essential for any subsidy delivery? This shortcoming of Aadhaar too can be fixed, provided that the government first accepts that this is required.

7) Plugging Leakages in Schemes

Secondly, moving to the main focus of Aadhaar – to better delivery of public subsidies. The issue of mandatory or non-mandatory needs to be discussed. I am also a petitioner in the PIL in the Supreme Court. The Act that Parliament passed is very clear: Aadhaar can be used as well as other IDs to avail benefits and subsidies.

I am of the view that there should be a roadmap to ensure that eventually Aadhaar will be the sole gateway for needy Indians to avail government subsidies and benefits. It is but natural for the government to ensure that money for the poor and needy reach only the poor and needy.

Corruption and leakages harm the poor and needy the most. So, the biggest beneficiary of ensuring that money for poor reach only the poor are the poor.

The government and minister must realise that many government departments are issuing rules making Aadhaar mandatory both for subsidies and most dangerously as primary IDs. More recently, to my question to the HRD ministry, they responded in contradiction to their own notification on this issue. So, confusion exists in many ministries and departments.

(Infographic: Rahul Gupta/ The Quint)

8) Fixing Accountability with UIDAI

A lot of the problems around Aadhaar can be placed squarely at the doorstep of the UIDAI, its vague and contradictory regulations, and lack of clear guidelines for its use. Proper oversight of UIDAI is lacking and needs to be put into place. For several years during UPA rule it was because there was a celebrity head of the UIDAI who spent considerable time trumpeting the virtues of Aadhaar in the media and so blunted any attempt at proper oversight.

The Aadhaar Act needs amendments on the issue of UIDAI accountability, because as custodians of this very important database, they need to be held to account because the implications in terms of security and other issues are significant.

Also Read: UIDAI Blacklists Centre That Leaked MS Dhoni’s Aadhaar Details

9) Issue of Privacy
The third point is data integrity and the broader issue of privacy. In recent times, as more and more people have become aware of Aadhaar and its design and its expansion into other areas, more and more concerns about its design and operations have surfaced.

Some are legitimate concerns, many are caused by a lack of understanding and lack of communication and transparency by UIDAI. The concerns of a surveillance state are misplaced if certain safety measures are put into place.

Also Read: Aadhaar and Three Other Cases Where Centre Went Against SC Orders


(Infographic: Rahul Gupta/ The Quint)
(Infographic: Rahul Gupta/ The Quint)

10) No Grievance Redressal Mechanism

Aadhaar’s architecture of a centralised database is an archaic way of storing sensitive data and therefore represents a serious data security risk.

There could have been far smarter and better ways to store these large databases. But this government inherited what it has and there is no wishing it away without wasting a lot of public money.

Despite mandatory and substantive provisions laying out the requirement of verification, the Aadhaar Act and the regulations made thereunder remain silent on the liability of the UIDAI, or its personnel, in case of non-compliance, contravention, or violation of such provisions. There is no grievance redressal mechanism for those who suffer data breaches or leaks.

Also Read: UIDAI Blacklists Centre That Leaked MS Dhoni’s Aadhaar Details

11) Action Against the Miscreants

In a modern and increasingly digital world that is being created, a set of rights for digital consumers vis a vis the custodian of data is a must. The current section on offences and penalties in the Act is in effect an incentive to lack of accountability of the UIDAI.

The proof is simple – despite all the overwhelming evidence of fake Aadhaars, there is no action by UIDAI on any of the enrolling agencies. Despite widespread evidence of misuse of access, the UIDAI has not taken any action.

12) Gauging Performance of UIDAI

The solution is to make UIDAI accountable. I would suggest regulations that require it to mandatorily disclose performance of its database in terms of errors and frauds and in addition a standing committee to oversee it, preferably a Parliamentary Standing Committee on National Identity Programme.



13) Burden on the User to Get Justice

The broader issue of privacy raises legitimate questions about the role and responsibility of the state or other agencies that are custodians of our digital footprints at a time of rapid digitisation of our lives and economies. The leader of the House conceded that he believes that privacy is a fundamental right even without waiting for the Supreme Court to opine on this.

The current protections to consumers and citizens under both the Aadhaar Act and the IT Act is skewed in favour of those who hold the data and places an extraordinary burden on the individual or user to get justice. I would encourage the government to enter this discussion, because many are concerned about this.

Also Read: Decoding The Aadhaar Debate: Do The Risks Outweigh The Benefits?



(Infographic: Rahul Gupta/ The Quint)
(Infographic: Rahul Gupta/ The Quint)



14) Balancing Privacy Rights and National Security Concerns

I understand that our national security concerns are sometimes at odds with the privacy rights of our citizens. But as the world’s largest democracy and soon perhaps the world’s leading digital democracy, we must take an enlightened and global lead in showing how we can balance our citizens’ rights to privacy and our national security considerations. I have heard the minister say there are enough safeguards in the IT and Aadhaar Act. With great respect, he is wrong.

As ‘onlining’ of our lives increases and our digital signature and footprint is increasingly all over, we will be met with scenarios and changes that we didn’t anticipate or were aware of. Constant change is the normal in this world. These kinds of debates will help the government and Parliament keep reviewing and adapting to these changes and challenges.


(The writer is a Rajya Sabha MP. These are excerpts from his speech in Parliament on 10 April 2017. The views expressed above are the author’s own.The Quint neither endorses nor is responsible for the same.)

Join The Quint on WhatsApp. Type “JOIN” and send to 9910181818.
TheQuint

Tuesday, April 11, 2017

11018 - Oppn punches holes in Aadhaar scheme - Outlook

THE NEWS SCROLL
10 APRIL 2017  Last Updated at 5:07 PM

New Delhi, Apr 10 Punching holes in the Aadhaar scheme, the Opposition in the Rajya Sabha today said it was based on unverified data and violated the Supreme Court order that it should not be made mandatory for schemes which are not linked to subsidies
    
New Delhi, Apr 10 Punching holes in the Aadhaar scheme, the Opposition in the Rajya Sabha today said it was based on unverified data and violated the Supreme Court order that it should not be made mandatory for schemes which are not linked to subsidies.

They also raised concern over data integrity and privacy issues while attacking the government for using the Aadhaar system to "exclude" the beneficiaries for delivery of subsidies and claiming to have made huge government savings.

Just before a short duration debate on Aadhaar started in the Upper House, IT and Law Minister Ravi Shankar Prasad said the government saved about Rs 50,000 crore LPG subsidy due to the linking of Aadhaar card with Jhan Dhan accounts.

"The World Bank and a UN body have clearly stated that the extraordinary technological innovation of India needs to be followed by the world. Surely they (UPA government) started it, but after improvements, it is showing results and the benefits have to be considered objectively," he said.

The Aadhaar scheme was started by the UPA government. "Now there is a robust legisation that has laid down the entire format of how the biometric data will be collected, processed, stored and under what terms and conditions will it be used," Prasad said.
If there is unauthorised use of Aadhar card details, the law provides for prosecution and punishment for up to 3 years, he added.

Initiating the debate, Rajeev Chandrashekar (Ind) expressed concern over fake aadhaar cards, data integrity and privacy issues and also exclusion of subsidies by making it mandatory.

He said he was not against the Aadhaar system but the risks and problems need to be addressed by the government. The government should not take a "rigid position".

On fake Aadhaar cards, Chandrashekar said the government has inherited "100 crore unverified database" created prior to bringing the law in 2016.

These 100 crore entries do not come under the section 303 of the Aadhaar Act. The section provides for issue of Aadhar card only after verification, he said.

"What has Unique Identity Authority of India (UIDAI) done to comply with section 303 for all Aadhaar entries prior to 2016? 
...Who is responsible for verifying these 100 crore entries before it is used as identity for elections, bank accounts and entering the airports for CISF?"

When there is "clear evidence" of fake Aadhaar, he sought to know what safeguards the UIDAI had taken before permitting Aadhaar for use as an identification beyond delivering subsidies. "This needs to be answered," he said.

congress leader Jairam Ramesh attacked the government for violating Supreme Court orders which clearly outlined where to use Aadhaar. Making it mandatory beyond subsidies is in gross violation of the SC orders, he said.

Expressing grave concern over implementation of the scheme, he said making Aadhaar mandatory for availing subsidies was resulting in exclusion of beneficiaries and the government cannot claim to have saved huge subsidies by this. (More)
Elaborating on implementation issues, Ramesh said the
government claims to have saved Rs 49,000 crore LPG subsidies by linking with Aadhaar but a CAG report has debunked this in a recent report.

The CAG has found that 92 per cent of the savings in LPG subsidy was due to fall in global crude oil prices and not due to Aadhaar seeding, he said, adding that similar was the case with food subidy, old-age pension and MNREGA.

"You must have had some savings, but saying it was around Rs 50,000 crore subsidy is mind-boggling," Ramesh said, adding that PDS, old-age pension and MNREGA were three schemes where maximum exclusion was taking place.

Citing PDS data of Rajasthan, he said 26 per cent of beneficiaries could not draw PDS wheat last month and "that is exclusion and not savings".

In case of MNREGA, officials are so much under pressure to achieve 100 per cent Aadhaar seeding that workers are denied of wages. For example in Chitradurga district in Karnataka, Rs 10-15 crores of wages are not paid on time as local functioneries are busy with Aadhaar seeding, he added.
Ramesh urged the government to revisit the amendments which he had moved last year when the Aadhaar bill was listed for passage in the Rajya Sabha.

There are many petitions pending on this issue. "I hope at some stage, the Supreme Court would bring finality to this issue," he said.

Participating in the debate, Vinay P Sahasrabuddhe (BJP) said that the Congress was not only nostalgic about it but is now indulging in "political paranoia".

Some kind of identity is required at a time when there are corruption and security issues. So far, 115 crore people have Aadhaar cards, he said.

The government has saved subsidies in the last few years, not because of exclusion but by curbing duplicate beneficiaries, he said, adding that those opposing implemenation of Aadhaar are "big ATM and hawala lobbies".

Participating in the discussion, Ravi Prakash Verma (SP) alleged that the government was using Aadhaar as a tool for revenue realisation.

"You are dreaming of a cashless society by effecting cash transfers into BPL accounts. You have linked Aadhaar to income tax returns and bank accounts. This will help in revenue realisation. Government is taking the help of this tool for revenue realisation," he said.

Attacking the government, Verma said "You have launched not only economic reforms but administrative and judicial reforms as well."
A Navaneethakrishnan (AIADMK) raised objections against direct benefit transfer to beneficiaries' bank accounts under Public Distribution System (PDS).

He said the poor will tend to buy items other than essentials for which the money is being transferred into their account.
Derek O Brien (AITC) criticised the government for using Aadhaar for various schemes like MGNREGA and mid-day meal schemes. He said that in case of stone workers and other labourers, the biometrics often do not match and the people were being harassed unduly, especially for the mid-day meal scheme.

C P Narayanan (CPI-M) opined that Aadhaar should not be made mandatory for availing benefits by the citizens. He said that there is data of 100 crore people under Aadhaar with private companies and they should not make profit from this wealth of huge data.

D Raja (CPI) pointed towards the UIDAI tie-up with some US based information technology firms which have been working closely with US intelligence agencies. He also said that Aadhaar should not be made mandatory for mid day meal scheme.

ARTICLE TAGS:

Thursday, February 16, 2017

10844 Privacy advocate notes Aadhaar records are not verified - Biometric Update

Privacy advocate notes Aadhaar records are not verified

February 14, 2017 - 
An Indian MP has claimed that none of the records contained within the Aadhaar database have been verified, according to a report recently published by Mashable.
Independent Member of Parliament and privacy advocate, Rajeev Chandrasekhar told Mashable India: “There are two fundamental flaws in Aadhaar: it is poorly designed, and it is being poorly verified. Aadhaar isn’t foolproof, and this has resulted in fake data get into the system. This in turn opens new gateways for money launderers.”
Chandrasekhar also told Mashable that “there is no firm legislation to safeguard the privacy and rights of the billion people who have enrolled into the system. There’s little a person whose Aadhaar data has been compromised could do.”
“Citizens who have voluntarily given their data to Aadhaar authority, as of result of this, are at risk,” he added.
Aadhaar is the 12-digit unique identification number issued by the Indian government to every individual resident of India. The Aadhaar project aims to provide a single, unique identifier which captures all the demographic and biometric details of every Indian resident. Currently, Aadhaar has issued over 900 million Aadhaar numbers. Over one billion people have now been enrolled for the project, which initially was only used for the provision of social services. The Indian government’s next intention is to extend Aadhaar to the majority of consumer financial transactions.
Advertisement
Recently, BiometricUpdate.com reported however that the Indian public is concerned about new fingerprint payment schemes that leverage Aadhaar, and that the prospect of using fingerprint authentication for everyday payments has raised concerns at theCentre for Internet and Society.
Sunil Abraham, executive director of the centre, told Mashable: “Aadhaar is remote, covert, and non-consensual.” He also added that Aadhaar doesn’t use basic principles of cryptography, and that much of its security is not known.
Other prominent critics, who include lawyer Rahul Narayan, an advocate who has argued in front of the Supreme Court of India, also told Mashable that “there’s no concrete regulation in place” that governs Aahaar.

Friday, March 25, 2016

9639 - Aadhaar Bill: Why did the Congress take so long to wake up to the need for a strong privacy law? - Scroll.In



As India goes digital, the Centre must start a debate on privacy and evolve the legal framework for it.


Mar 22, 2016 · 11:30 am  


Last week, Parliament passed the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Bill, 2016. The passage of the law aimed at creating legislative backing belatedly for a programme that has spent thousands of crores without debate or scrutiny, has predictably sparked debates – about non-citizens availing of public benefits and subsidies and the other important issue of privacy. Given the National Democratic Alliance government’s focus on governance efficiency and execution, I have no doubt that Aadhaar, in its new avatar as a subsidy delivery platform, will benefit our country greatly – it will plug leakages and improve the quality of life of our citizens.

Ironically, political parties like the Congress, which conceived of Aadhaar in its original form, and the Left, which remained silent through its growth backed by thousands of crores of taxpayers money, have woken up belatedly to this debate on individual privacy rights.

The complete disregard of the call for privacy protections from various quarters by the Congress-led United Progressive Alliance and the architects of Aadhaar was what caused it to land in the Supreme Court. Having been closely involved in the debate on Aadhaar and privacy, both as a legislator and an impleading petitioner in the Aadhaar matter in the Supreme Court, I can attest to the fact that the NDA Aadhaar is very different from the UPA Aadhaar in many ways – specifically on the issue of privacy rights – starting with the acknowledgement by the government that privacy is a fundamental right. This is reflected in the NDA’s Aadhaar Bill 2016, with its substantively expanded sections on privacy and protection of information.
Digital privacy for Digital India
This significant progress in privacy around Aadhaar has been welcomed by many – and in a case of heavy irony – including those who paid short shrift to this aspect in the last five years as Aadhaar was being rolled out. Ironic, because my friend Nandan Nilekani (the former head of the Unique Identification Authority of India, which manages the project) only in September last year, in an op-ed in The Indian Express (to which I wrote a counter), tried making a case that no privacy protection was required because the UPA Aadhaar with its supposedly “federated architecture”, ensured “privacy by design”, and that the manner in which the system collated and stored data of citizens “hardly qualifies as a violation of their right to privacy”. Nilekani used this to question the Supreme Court’s interim order that called for the limited use of Aadhaar due to privacy concerns. From that position to marking a new one on March 9, Nilekani has welcomed the privacy provisions in the NDA’s Aadhaar bill and termed it as “unprecedented level for Indian law”.
Whilst I agree with Nilekani’s welcoming of the NDA Aadhaar Bill’s privacy provisions as a significant step from his original discourse, I am afraid that his position remains as it has been throughout the Aadhaar debate – behind the curve on both the architecture and privacy aspects of Aadhaar. Because the reality is that while the NDA’s Aadhaar bill has made big strides on privacy, there are still some ways to travel before digital privacy is a reality for consumers in India.
Need for a privacy law
The Aadhaar built by the UPA was violative of the Citizenship Act, 1955, as the database did not even identify whether a person who was enrolling was a citizen or not. This allowed illegal migrants and non-citizens to enrol with Aadhaar and avail of public money and subsidies. To its credit, the NDA, which had inherited a poorly-conceived Aadhaar, did exceedingly well to convert what was being pushed as a flawed national identification programme into a limited programme that will exclusively deliver subsidies, benefits and services to those who enrol.
This, however, as I’d mentioned in my speech in Parliament, makes Aadhaar only useful if it works alongside many other databases for schemes such as Jan Dhan Yojana, LPG, Mobile and BPL. Since these databases are not covered under the privacy clauses of Aadhaar, a separate robust, overarching privacy legislation will be required to bring all allied government databases into its ambit.
Further, as I’d stated in Parliament, the inherent dangers arising from the centralised nature of the Central Identities Data Repository [a government agency that stores and manages data for the Aadhaar project] under Aadhaar cannot be ignored. A centralised database is inherently less secure and easy to break into. In the past, the government has mishandled Aadhaar data. In 2013, the Maharashtra government admitted the loss of personal data of about 3 lakh applicants for Aadhaar cards. Experts recognise the inherent failings of a centralised system – that information systems and databases with a central point of failure are inherently vulnerable because the possibility of failure exists.
IT Act and privacy protections
Further, while the Aadhaar Bill, 2016, offers expanded privacy protections by invoking Section 43A of the IT Act, 2000, there is a need for this to be further bolstered. There is ample evidence in the public domain which points to how easy it is for governments to get personal data out from entities that have no liabilities under any legislation. In a letter to the minister of communications & information technology last year, Ravi Shankar Prasad, I had urged for amendments to the IT Act – these include an expansion of the definition of sensitive personal data under Rule 3 of the sensitive personal data rules; the extension of data protection provisions to government agencies, not for profits and others; correcting the flaws in the drafting of Section 72A; and aligning India’s privacy protection to international standards.
Further, the cyber appellate tribunals meant to be constituted under the IT Act are currently inactive, and their constitution does not equip them with the kind of technical capacity needed to adjudicate these disputes.
Most will agree that these must be acted on as an urgent priority, in order for us to reach an “unprecedented level of protections for privacy”.
The road ahead
I have argued for several years now that as India becomes more digital under prime minister Narendra Modi’s visionary Digital India programme – a corresponding set of consumer rights needs to be developed to protect Digital Indians. Net neutrality, quality of service or QoS, security and privacy are some of what needs to be in the Magna Carta of Digital India. So, as we are evolving our net neutrality legal framework, the government too should start the debate on privacy and evolve the legal framework for it. I was reassured in Parliament during the Aadhaar Bill debate by Finance Minister Arun Jaitley that the government would look into this need for privacy legislation after the Supreme Court’s decision.
While we await the court to take a view on the issue, the best course of action for the government would be to initiate a multi-stakeholder consultation on the right to privacy, so that the views of various stakeholders, including security agencies, are taken into account while this legislation is being conceived and architected.
Rajeev Chandrasekhar is a Member of Parliament from the Rajya Sabha.
We welcome your comments at letters@scroll.in.

Wednesday, March 23, 2016

9611- MP writes to PM Modi: Bring in new Legislation that gives privacy rights to all Indians - Indian Express


In the letter, the MP stated that that a multi-stakeholder consultation be initiated so that the views of various stakeholders, including security agencies, are taken into account while this legislation is being conceived.

By: Express Web Desk | New Delhi | Published:March 18, 2016 10:09 pm - See more at: 


A member of parliament, Rajeev Chandrasekhar, on Friday wrote a letter to Prime Minister Narendra Modi pitching for privacy rights for all Indians and urged him to proactively explore the possibility of a new Privacy Legislation or review the existing IT Act, Sec 43 A and other sections.

In the letter, the MP stated that that a multi-stakeholder consultation be initiated so that the views of various stakeholders, including security agencies, are taken into account while this legislation is being conceived.

Chandrashekar noted that while the NDA’s Aadhaar Bill significantly expanded the rights to privacy and protection of information, there was a need for a new overarching privacy legislation given that there are many other databases, like Jan Dhan Yojana, BPL, LPG etc. that are out of the purview of the Aadhaar Bill, but are significant parts of the subsidy delivery mechanism of the Government.

Here is the full letter: 

Respected Prime Minister,
Sub: Privacy Rights for All Indians

At the outset, I thank and congratulate the Government for recognizing that privacy is a fundamental right – a significant departure from the position that the UPA Government had taken all these years.

While I welcome the significantly expanded rights to privacy and protection of information in the NDA’s new Aadhaar Bill, I had, during the debate in Parliament on this Bill, suggested that there is a need for an overarching privacy legislation – given that there are many other databases, like Jan Dhan Yojana, BPL, LPG etc. that are out of the purview of the Aadhaar Bill, but are significant parts of the subsidy delivery mechanism of the Government that also need to be covered under the Citizens’ Rights to Privacy and Protection of Information.

As you are aware, I have been consistently pursuing the need for recognition of Privacy as a fundamental right for several years, starting with the Aadhaar effort, during the UPA Government. I had raised the issue of privacy on several occasions with the UPA Government, and consequent to the lack of sensitivity and response, the matter of UID/privacy ended up being heard in front of the Constitutional Bench of the Hon’ble Supreme Court, where I am also an impleading petitioner.

You will agree that it is, therefore, ironic and amusing to read and hear about the belated awakening of the Congress party and the architects of Aadhaar, to this real issue of privacy and the need for protection of information.

As you are aware, I have spoken extensively about this in Parliament and written to you after the NDA Government was formed (copies of my letters and Parliamentary Question are enclosed herewith).

The Hon’ble Finance Minister was gracious enough to respond to me in Parliament, and with a promise that the Government would look into this need for privacy legislation after the Hon’ble Supreme Court’s decision. However, I would urge that the Government proactively explore the possibility of either a new Privacy legislation, or review and amend the existing IT Act, Section 43 A and other applicable sections at the earliest. I would also recommend that a multi-stakeholder consultation be initiated so that the views of various stakeholders, including security agencies, are taken into account while this legislation is being conceived and architected.

© The Indian Express Online Media Pvt Ltd

- See more at: http://indianexpress.com/article/india/india-news-india/mp-writes-to-pm-modi-bring-in-new-legislation-that-gives-privacy-rights-to-all-indians/#sthash.U5OZUUk8.dpuf

Tuesday, March 22, 2016

9609 - NDA Aadhaar is a far cry from what UPA proposed -


Rajeev Chandrasekhar   New Delhi     Last Updated: March 19, 2016  | 13:19 IST


The NDA government, over the last two years, has launched an unprecedented and determined effort to reform public subsidy spending, and this new Aadhaar is part of their execution strategy for this. In addition, the milestone of delivering cash subsidies to bank accounts of the needy with over Rs 36,000 crores deposited in 22 crore accounts is testimony to the focus on execution and getting things done by this government.

The recent opposition to Aadhaar by many in the present Opposition is amusing and perplexing. Neither the Left nor the Congress raised a murmur when Aadhaar was being rolled out from 2010 violating everything that they are complaining about - privacy, lack of debate, lack of legislation etc. While there were a few like me who kept raising this issue, I did not find any voices from that side.

Governance
I am a big supporter and advocate of embedding technology into governance, and so, have always supported the creation of the national ID platform, which the UPA chose to call Aadhaar. But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.

Aadhaar is simply a biometric database that contains only three pieces of information of the person - name, age and address along with his/her biometrics. The country must know that this UPA-initiated database, ostensibly for the purpose of identification, doesn't have even the basic citizenship information. Crores were spent compiling a database that will not even identify a person as a citizen - thus allowing illegal migrants and non-citizens to avail of public money and subsidies, arguably in violation of The Citizenship Act, 1955.
The NDA Aadhaar is a far cry from what the UPA was proposing as Aadhaar. It is no longer a national identification platform; rather, it is limited to only delivering subsidies and services. This is a good response to a fundamental weakness of Aadhaar that this government inherited.

The whole database is a poorly verified database that needs slow and steady cleaning up. The process of using small enrolment agencies has created countless fake entries in this database. Getting an Aadhaar enrolment in a fake name had become as simple as getting a fake BPL card, and so attempts to make it a National Identification platform would have been dangerous.

Under the UPA, the government intended to use it as Identity proof. Given the ease with which Aadhaar cards are available, there would have been nothing to prevent David Headley from getting it - and by using the same getting upstream identity proofs like Indian passports, Voter IDs or Tax PAN Cards etc.
The UPA government did not acknowledge the danger like the NDA government has. Aadhaar could be a trapdoor for infiltration into formal identity processes like Passports, Voter IDs, and could become an Identity Laundering Platform - but for the NDA government confirming that it will be restricted to subsidy delivery.

Privacy
In sharp contrast to UPA's contention that there was no need for privacy rights for enrolees, the NDA has acknowledged that privacy is a fundamental right, and substantively expanded the privacy and protection of information. NDA's approach to privacy is good and well-constructed.

There is protection under Section 43 A of the IT Act, and that is good. But, is that adequate given the dangers of a centralized repository? The cyber tribunals under the IT Act are hardly active, and capacity doesn't exist for these kind of disputes.
Therefore, as I have repeatedly advocated in the past, the government now needs to urgently formulate a robust overarching privacy legislation. The right to privacy has not been addressed by previous governments, and the NDA has done well to acknowledge this gap.

This Bill will evolve as the use of directed subsidy increases. Clause 33 deals with data interception/inspection rights and conditions. I have urged that the oversight committee be expanded to include elements of legal oversight and have the Attorney General and a Retired Judge - to ensure the fair, just and reasonable test.

Sanction
Clauses 47 and 50 are ones that will need to go when this law is revisited next - Why is there a need for sanction for prosecution by the authority in the event of a complaint or breach? The principle of accountability and citizen rights is a theme that has been played out by the government in other bills like the Real Estate Bill. Why not here? And how can Clause 50 seek to give powers to government to supersede the authority, when Parliament enacted law is giving the powers to the authority?
Apart from this long delayed scrutiny and debate about Aadhaar, the other strange thing is the total lack of accountability of any entity on the verification of the data. The bill must cast the obligation of this aspect of data integrity. The bill currently completely leaves the authority without any obligations to the enrolee on the critical issues of data security, integrity and privacy. Since Aadhaar in itself is useless for any subsidy delivery and has to work with other databases, Government must plan to also bring those databases like JDY in the ambit of privacy clause of this law, and also possibly to bring to Parliament an overarching privacy legislation.
In the future, a repaired and cleaned up Aadhaar has to be integrated to work with other databases like JDY, LPG, Mobile to direct public spending more effectively and with less leakage and corruption - a transformation indeed!

Sunday, March 20, 2016

9574 - Rajeev speaks on the Discussion on The Aadhaar



SPEECH BY SHRI RAJEEV CHANDRASEKHAR, MPDURING THE DISCUSSION ON  THE AADHAAR (TARGETED DELIVERY OF FINANCIAL AND OTHER SUBSIDIES, BENEFITS AND SERVICES) BILL, 2016 IN PARLIAMENT


  1. Sir, this government’s determined effort to reform public subsidy spending is unprecedented, and I support this completely. The focus on delivering cash subsidies to bank accounts of the needy with over Rs.36000 crores deposited in 22 crore accounts is testimony to the focus on execution and getting things done by this Government.

     
  2. Sir, I must say that I find the recent opposition to Aadhaar by my friends in the opposition amusing and perplexing. Neither the Left nor the Congress raised a murmur when Aadhaar was being rolled out from 2010 violating everything that they are complaining about – Privacy, without legal sanction etc. The irony is that the only opposition to Aadhaar came from the then Home Minister P. Chidambaram, who of course, was also at the same time presiding over re-editing some petitions also.

     
  3. Sir, as you are aware, I am a big supporter and advocate of embedding Technology into Governance, and so, have always supported the creation of the National ID platform, which the UPA called Aadhaar. But Aadhaar has been mythologized during the previous Government by its creators into some technology super force that will transform Governance in a miraculous manner. It has been backed up more by PR and spin than substantive examination. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian Will Durant.  I congratulate the Government for doing what the UPA Government didn’t do – to have a debate that will cut through all this hyperbole, and for a calm, reasoned analysis of what have we got for these thousands of crores spent.

     
  4. Aadhaar is simply a biometric database that contains ONLY three pieces of information of the person - Name, Age and Address along with his/her biometrics. The country must know that this UPA-initiated database, ostensibly for the purpose of Identification, doesn’t have even the basic citizenship information. Let it be known to all Sir that several thousand crores were spent compiling a database that will not even identify a person as a citizen. This question needs to be answered by those in the UPA who sanctioned this expenditure.  Was it their contention that subsidies and Identities will be spenton people who aren’t citizens?

     
  5. So, some discussion and testing of these claims and hyperbole was overdue as also a debate to ensure it is not wasted and dumped because of its design flaws and limitations. That this debate has been successfully stymied by some people for so long while thousands of crores of taxpayer money were being spent without a challenge or debate is, of course, a tragic post script, and I hope this is the last time this kind of thing is allowed.

     
  6. The UPA Government should have brought this Bill into Parliament before crores of taxpayer money were shovelled into this project. Perhaps, they didn’t want a debate or discussion, or perhaps they were chasing numbers to show and talk about, rather than creating a substantive functional platform.

     
  7. But Sir, now that we are discussing this new Bill, let me say this.

     
  8. I welcome the fact that the Bill is no longer called National Identification Bill, and rather is limited to only delivering subsidies. This is a good response to a fundamental problem with Aadhaar that this Government inherited. The whole database is a poorly verified database that needs slow and steady cleaning up. The process of using small enrolment agencies has created countless fake entries in this database. Getting an Aadhaar enrolment in a fake name had become as simple as getting a fake BPL card, and so attempts to make it a National Identification platform would have been dangerous. I am glad the FM in his Budget Speech said that it cannot be used as citizenship proof, because simply it failed to capture this information during enrolment.

     
  9. Sir, but despite the few changes in this Bill from the original UPA Bill – many questions remain. I would urge the government to carefully examine the points I am raising.

     
  10. Why is the bill allowing subsidies to all residents? Is it the government’s contention that non-citizens should get Taxpayer-funded subsidies and benefits? I would like the Government to clarify that this is not their intention, but rather forced on them due to how Aadhaar was built.

     
  11. Sir, Clause 4(3) suggests that the government intends to allow Aadhaar as Identify proof. Sir, I firmly and will steadfastly oppose this. The Government must realize the dangers of using an unverified or poorly verified database as Identity proof.Sir, let me explain – Person X crosses over the border into, say, Assam, takes on an Indian name and easily enrols himself in Aadhaar with little verification.This is made easy because the Aadhaar enrolment process does very little verification and absolutely no verification of citizenship. If Aadhaar is then used as Identify proof, for say, Passports or Voter IDs or Tax PAN Cards – you create a dangerous situation of easy Identity conversion. It is a trapdoor for infiltration into formal identity processes like Passports, Voter IDs, and becomes an Identity Laundering Platform. The only way 4(3) can survive, Sir, is with an express prohibition on use of Aadhaar in all non-subsidy related Identify proofs.  As I have written in 2014 and 2015 to the Government, the Aadhaar database needs a significant audit and clean-up over time before it can be used for anything else. I am aware that this Government isn’t responsible for this messy situation, but it is definitely responsible to ensure protection against improper use of this. The language needs change and it needs to be explicit, and not ambiguous.
     
  12. Sir, apart from this long delayed scrutiny and debate about Aadhaar, the other strange thing about Aadhaar is the total lack of accountability of any entity on the verification of the data. I believe the Bill must cast the obligation of this aspect of Data integrity – of verification on the Authority. I also believe the Bill currently completely leaves the Authority without any obligations to the enrolee on the critical issues of Data security, Integrity and Privacy, and hence I would suggest amending Clauses 11,23,28 and 29.

     
  13. Sir, this Government has substantively expanded the privacy and protection of information section. I congratulate the Government for recognizing the importance of this. The issue of consumer and citizen rights was something that was missing from all UPA legislations, including their National ID bill and also examples of Section 66A.  This is a good, well-constructed section and puts paid to the defence put out there by the UPA’s architects of Aadhaar that there was no need for privacy rights for enrollees.  There is protection under Section 43 A of the IT Act, and that is good. The FM himself remembers how easy it is for people to get personal data out from entities that have no liabilities arising out of such an Act.  E.g.: Call records from Telcos.

    But Sir, is that adequate given the dangers of a centralized repository? The cyber tribunals under the IT Act are hardly active, and capacity doesn’t exist for these kind of disputes. I believe amending this section to create express obligations that can be agitated under the provisions of this Act may be considered to strengthen the privacy rights of the enrolees. Sir, I leave another thought with you – since Aadhaar in itself is useless for any subsidy delivery and has to work with other databases – is there any way that the Government can use this legislation to also bring those databases like JDY in the ambit of privacy clause of this law, and also possibly to bring to Parliament anoverarching privacy legislation?

     
  14. There are other changes that I would suggest in the Bill – that powers of adding additional information to the Aadhaar database can be only if it’s transparently done with Parliament sanction.

     
  15. Sir, Clause 33 deals with data interception/inspection rights and conditions – I propose that under Clause 33(2), the oversight committee be expanded to include elements of legal oversight, and I propose that the oversight committee have the Attorney General and a Retired Judge.

     
  16. Clauses 47 and 50 are ones that the Government may explain – Why is there a need for sanction for prosecution by the Authority in the event of a complaint or breach? The principle of accountability and citizen rights is a theme that has been played out by the Government in other bills like the Real Estate bill. Why not here? And how can Clause 50 seek to give powers to Government to supersede the Authority, when Parliament enacted law is giving the powers to the Authority?
Sir, I understand this is a money bill. But I would request the Government to listen carefully to what is being asked to improve the Bill. Otherwise, we will have a repeat of the IT Act and Section 66A, which is what becomes of hastily passed Bills that create more problems than they solve.

I reaffirm that I am supportive of the Government’s brave decision to go ahead with this very flawed platform that they inherited. But let’s do so in a manner where the flaws are recognized and acknowledged, and so, Aadhaar’s use is limited and cautiously directed in areas where they don’t cause any other damage. In the future, a repaired and cleaned up Aadhaar has to be integrated to work with other databases like JDY, LPG, Mobile to direct public spending more effectively and with less leakage and corruption.

I thank you sir for giving me the opportunity to speak on this – I have been waiting for many years for this. I hope the Government pays heed to my suggestions and gives the country a repaired version of Aadhaar – that we deserve!


Thank you.
Jai Hind.