In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label SC judge B N Srikrishna. Show all posts
Showing posts with label SC judge B N Srikrishna. Show all posts

Sunday, July 29, 2018

13800 - Srikrishna panel recommends changes in Aadhaar Act; moots new safeguards for data protection - Money Control


The panel — whose views on Aadhaar are captured in its 213-page report, but are not part of the draft Personal Data Protection Bill — seeks greater autonomy, both functional and financial, for the Aadhaar-issuing body.
PTI

https://www.moneycontrol.com/news/india/srikrishna-panel-recommends-changes-in-aadhaar-act-moots-new-safeguards-for-data-protection-2775181.html

Srikrishna panel recommends changes in Aadhaar Act; moots new safeguards for data protection

The Justice Srikrishna panel on data protection has recommended that the Aadhaar Act be amended "significantly" to bolster privacy safeguards and mooted that only public authorities approved by the UIDAI or entities mandated by law be given the right to request for identity authentication.

The panel — whose views on Aadhaar are captured in its 213-page report, but are not part of the draft Personal Data Protection Bill, also submitted by it to the government yesterday — seeks greater autonomy, both functional and financial, for the Aadhaar-issuing body.

The panel asserted that the Unique Identification Authority of India (UIDAI) should not only be autonomous in its decision-making, functioning independently of the user agencies in the government, but also be vested with powers akin to a traditional regulator for enforcement actions.

It has prescribed that UIDAI should be granted powers to impose civil penalties on various errant entities and be armed with power to give directions, issue cease and desist orders to state and private contractors in cases involving statutory violations or non-compliance, and for actual or impending privacy breach.

"The Aadhaar Act needs to be amended significantly to bolster privacy protections and ensure autonomy of the UIDAI," said the report by the panel, a telling statement given the numerous reports of personal information being allegedly compromised with increasing use of biometric identifier Aadhaar in an array of services.
The recommendations of the committee also assume significance as the Supreme Court has reserved its judgement on a clutch of petitions challenging the constitutional validity of the Aadhaar Act.
"...it is salient that the data protection regime proposed by the Committee will require close introspection by the Government on various aspects pertaining to the existing functioning of the UIDAI (Unique Identification Authority of India). Currently the Aadhaar Act is silent on the powers of the UIDAI to take enforcement action against errant companies in the Aadhaar ecosystem," the report said.
Citing "several instances" in the recent past of companies wrongly insisting on Aadhaar numbers, those using the numbers for unauthorised purposes and those leaking the numbers, the report said these episodes can affect informational privacy and "requires urgent redressal".
The much-touted virtual ID feature and offline verification models rolled out by the UIDAI also came under the panel's lens, as it noted that while the twin measures have the potential to ensure safeguards like collection limitation and data minimisation, they do not come armed with a statutory backing.
"However, there is no statutory backing for such announcements as on date and it is unclear as to how they are to be effectively implemented," it said.
Significantly, on the entities that are entitled to request for authentication, the panel made it clear that this should be "restricted" to outfits that "perform a public function and require verifiable identification for the purpose of performing such public function".
It listed out two situation under which the entities can request for authentication — one where it is mandated by law made by Parliament, and in second instance a public authority performing a public function that is approved by the UIDAI.
"In granting such approval, the UIDAI should take into account security standards employed by the entity as well as the steps it has taken to incorporate privacy protections for Aadhaar number holders," it said.
For entities which do not perform a public function, but where identification of individuals may still be required, the panel said that only offline verification of Aadhaar numbers with the consent of the Aadhaar holder should be used for identity verification of an individual.
"Currently, many such entities, as a matter of course, ask for the Aadhaar number of individuals. This represents a significant privacy concern," the report said.
The panel batted for greater autonomy for UIDAI, seeking amendments in this regard.
The changes it has favoured with regard to UIDAI are that the nodal body must enjoy autonomy in decision-making, functioning independently of the user agencies in the government and outside it, and that it must be equipped with powers similar to those vested with traditional regulators for enforcement actions.
The panel said following an examination of the powers and functions of existing statutory regulators such as TRAI, SEBI, CCI and the deficiencies in the existing framework for Aadhaar, it has come to a view that the UIDAI should be vested with the functions of ensuring effective enforcement, better compliance, consumer protection and prevention and redressal of privacy breaches.
"In cases involving statutory violations or non-compliance, or an actual or impending privacy breach, the UIDAI will be tasked with the power to issue directions, as well as cease and desist orders to state and private contractors, and other entities discharging functions under the Aadhaar Act," it said.
And even UIDAI in its role as data collector will be subject to the rigours and penalties of the data protection law -- currently in the draft stage.
"Finally, in its role as a data fiduciary under the proposed data protection framework, the UIDAI will, in the eyes of the data protection law, be viewed as any other entity processing personal data of individuals, and will be subject to the rigours and penalties of the law. It is thus critical that these changes be made hand-in-hand with a new data protection legislation," it said.

First Published on Jul 28, 2018 02:07 pm

Friday, July 27, 2018

13788 - DATA-PROTECTION BILL DRAFT COULD DILUTE GOVT ACCOUNTABILITY ON AADHAAR: REPORT - First Post


This draft comprising around 15 chapters covers topics such as data localisation, the creation of a data protection authority among other things
The justice BN Srikrishna committee had been appointed to draft a data-protection law for India on August 2017, following the Right to Privacy ruling. The 10-member panel was expected to present its draft last month, after many delays. But so far, there is still no certain date as to when it will be released.

In the meantime, TRAI has released its recommendations on privacy, security and data ownership in the telecom sector.
There have also been reports of how the Srikrishna committee may ask Google, Facebook and others to store their data locally.

Caravan claims to have got access to the draft of the proposed law, which is tentatively titled, "The Protection of Personal Data Bill, 2018".

This draft comprising around 15 chapters covers topics such as data localisation, the creation of a data protection authority, data protection measures, separating personal and sensitive data and also proposes some amendments to the Aadhaar Act, 2016 and the Right to Information Act, 2005.

Measures pertaining to the Aadhaar Act 2016
The report goes on to state that the changes to the Aadhaar Act include offline verification process for Aadhaar, increasing or creating civil and criminal penalties for contravening the Aadhaar Act and a new adjudication process to address disputes arising out of Aadhaar. There is a proposal for the appointment of an adjudicating officer above the rank of a joint secretary in the Union government, with the power to make inquiries in case the Aadhaar Act is found to be violated in any manner.
The Telecom Disputes Settlement and Appellate Tribunal has been suggested as the appellate body for any appeal against the appointed adjudicating authority and only appeals from this tribunal will be heard by the Supreme Court.
This really does not change the status quo by much, as the common man still cannot approach the courts in case of any Aadhaar-related disputes. As the report notes, in the current setup, only the Unique Identification Authority of India (UIDAI) can approach the courts in case of any disputes. A look at the number of Aadhaar-related data breaches in the last couple of years and the attitude of UIDAI, which refuses to acknowledge its own shortcomings, should give you enough of an idea of how flawed the system is.

The suggestion by the draft on data protection law on 'offline' Aadhaar verification also seems incomplete. Offline verification, under the current Aadhaar Act, cannot be deemed as a method to authenticate, as any authorised body seeking Aadhaar verification does a real-time query with the Central Identities Data Repository (CIDR) which is maintained by the UIDAI. In the case of offline verification, there is no clarity on how it will be executed, even though on the surface it does intend to address issues with authentication, such as poor network connectivity, change in biometric information and so on. But 'offline' means there would be no real-time querying of the CIDR database. How then would the Aadhaar identity be verified? Does it mean that the agency doing the offline verification will have access to a local CIDR database? Will the data be stored on a new type of Aadhaar card? What about potential data breaches in these cases? There seem to be no clear directions on this.

Measures pertaining to RTI Act, 2005
The changes proposed to the RTI Act could possibly allow officials to withhold details and make them less accountable under the garb of increased privacy.

According to the current Section 8(1)(j) of the RTI Act, "information which relates to personal information, the disclosure of which has no relationship to any public activity or interest, or which would cause unwarranted invasion of the privacy of the individual unless the Central Public Information Officer or the State Public Information Officer or the appellate authority, as the case may be, is satisfied that the larger public interest justifies the disclosure of such information: Provided that the information, which cannot be denied to the Parliament or a State Legislature shall not be denied to any person.."

This section of the act, according to the report, is misused by a lot of information officers to deny answering RTI queries.
According to the draft data protection bill, this section has been done away with altogether.

In its place, there is another provision in the bill which requires three conditions to be fulfilled before disclosing any personal data under the RTI. These conditions include:

(a) the personal data relates to a function, action or any other activity of the public authority in which transparency is required to be maintained having regard to larger public interest in the accountability of the working of the public authority;
(b) if such disclosure is necessary to achieve the object of transparency referred to in clause (a); and
(c) any harm likely to be caused to data principal by the disclosure is outweighed by the interest of the citizen in obtaining such personal data having regard to the object of transparency referred to in clause (a).

With no clear definitions of 'public interest', these requirements give the information officers more leeway against disclosing personal information, says the report.


We are yet to see the actual draft of the data protection bill, but these two measures suggesting amendments to two major acts definitely raise a lot of concerns at face value. Hopefully, the final draft of the bill, when it is finally, if ever, disclosed, will address the questions raised by the report.

Friday, December 1, 2017

12452 - Enable privacy: Data protection must strictly impose purpose limitation and penalties for breaches - - TOI

November 29, 2017, 2:00 AM IST TOI Edit in TOI Editorials | Edit Page, India | TOI

A high-level government committee of experts headed by Justice BN Srikrishna has released a white paper seeking views from stakeholders on data protection. Coming against the backdrop of the apex court’s landmark decision upholding right to privacy as a fundamental right, data protection has certainly become a hot-button issue. Driving the debate is government and other agencies increasing the scope of Aadhaar linking for services – a matter slated to be adjudicated by a constitution bench of the Supreme Court.
In fact, the unique identification number bolstered by an individual’s biometric data is now being used for everything from school admissions to obtaining death certificates. While the utility of such moves is left vague, the fear that the data provided could be leaked or misused is real. Current data collection practices in the country hardly inspire confidence, with personal information regularly being shared among different parties without the knowledge of customers. In such a scenario, pushing Aadhaar linking for day-to-day transactions is akin to having a digital master key that can open all facets of an individual’s life.
Such a master key would certainly violate the right to privacy upheld by the Supreme Court. Not only could unscrupulous elements misuse personal data for profit or crime, there are also concerns that an Aadhaar-backed data architecture can be used to profile individuals on the basis of their caste, religion, sexual orientation, political opinion, etc. Given these anxieties, the need of the hour is for a comprehensive data protection framework. This should include an independent data protection authority to handle issues related to use of information collected by governments and corporations.
Among other things, data protection norms should strictly implement the purpose limitation principle whereby data collected is only used for the purpose stated to the individual. And tough penalties should also be imposed for breaches of purpose limitation. This could include stiff financial compensation to customers and even criminal prosecution of violators. Many of these provisions are part of BJD MP Baijayant Jay Panda’s private member’s bill on data privacy, which can be used as a guide. Add to this the need for a strong cyber security architecture to ensure data isn’t stolen through digital attacks. With the digital environment set to grow further – and government looking to push Digital India initiatives – it’s time to give data privacy its due importance.


DISCLAIMER : Views expressed above are the author's own.

12449 - SriKrishna Panel moots Data Protection Authority - The Wire



The panel had been set up on July 31 following the government’s decision to make Aadhaar compulsory for all its services.

The government is unlikely to table a data protection Bill in the winter session of parliament. Credit: PTI

The Justice B. N. Srikrishna Committee, which was set up to draft a data protection and privacy Bill, in a white paper on Monday suggested setting up a data protection authority, data audit, registration of data collectors, enacting provisions for protecting children’s personal information, defining penalties and compensation in case of a data breach.

The committee, which studied the privacy and data protection laws of many countries, including the US, Singapore, Australia and the EU, has released a 200-page document inviting comments from the public on various issues such as the definition of personal data and proposed penalties for misuse of data. The deadline for sending feedback is December 31, 2017, implying the government is unlikely to table a data protection Bill in the winter session of parliament.

The Srikrishna Committee was set up on July 31 following a government decision to make Aadhaar compulsory for all its services. The government gave the panel three months to suggest a draft Bill.

“Despite an obligation to adopt adequate security safeguards, no database is 100% secure. In light of this, the interplay between any proposed data protection framework and the existing Aadhaar framework will have to be analysed,” the paper read.

The Unique Identification Authority of India (UIDAI) has issued a 12-digit unique identification number called Aadhaar to over one billion people after collecting their personal and biometric data. The Aadhaar number is now used by both the government and private entities for the purpose of authentication and financial transactions. Though the UIDAI has various in-built data protection mechanisms, it is not bound to inform an individual in cases of misuse or theft of his or her data.


“The law may require that individuals be notified of data breaches where there is a likelihood that they will suffer privacy harms as a result of data breaches… fixing too short a time period for individual notifications may be too onerous on smaller organisations and entities. This may prove to be counter-productive as well as an organisation may not have the necessary information about the breach and its likely consequences,” the paper added.

The committee, which has met thrice since its formation, is of the opinion that both the government and the private entities be brought under the ambit of the proposed law. At present only private or corporate entities are governed by the Reasonable Security Practices and Sensitive Personal Data or Information (SPDI) Rules under the Information Technology Act.
The committee appears to be taking a middle path between the EU privacy law, where protection of personal data is equated with protecting the fundamental right to privacy, and the US law, which focuses on protecting the individual from excessive state regulation.


The committee has divided the white paper into three substantive parts, including scope and exemptions; grounds for processing, obligation on entities and individual rights; and regulation and enforcement. The committee is of the view that certain exemptions should be granted by law for collecting information for investigating a crime, apprehension or prosecution of offenders, and maintaining national security and public order. But the paper stated, “An effective review mechanism must be devised.”
The panel suggested strict penalties be imposed on data controllers in cases of violation. “A civil penalty of a specific amount may be imposed on the data controller for each day such violation continues, which may or may not be subject to an upper limit. An upper limit may be a fixed amount or may be linked to a variable parameter, such as a percentage of the annual turnover of the defaulting data controller,” the paper read.

By arrangement with Business Standard.

12445 - The Daily Fix: As pressure to link Aadhaar to vital services grows, Supreme Court needs to act fast - Scroll.In


Everything you need to know for the day (and a little more).


Published Nov 28, 2017 · 09:25 am


The Big Story: Aadhaar impasse
As deadlines to link Aadhaar, a 12-digit unique identity number, to various schemes and services loom closer, another potential date in the Supreme Court flits past with no decision taken on the matter. The case had been scheduled for a hearing in early November and then the last week of November. As of now, there is no date for hearing the main Aadhaar challenge or the plea for interim relief from the deadline to link Aadhaar to bank accounts by December 31. The attorney general argued that it would be better to wait until the Srikrishna Committee’s new white paper on data protection was studied, and that the government was willing to consider moving the deadline to March 31. The caveat is that it may push back the deadline only for those who do not have Aadhaar already. For those who do, nothing changes.

The last time the Supreme Court pronounced on Aadhaar was August 11, 2015, when it ruled that the unique identity number was optional and not mandatory, that it could not be a condition for citizens to claim the benefits due to them, that it could only be used in the public distribution and liquefied petroleum gas schemes. A key question on privacy, which came up in the course of the Aadhaar case, was later sectioned off. Earlier this year, the Supreme Court ruled that the right to privacy was a fundamental right but was silent on how this would affect Aadhaar.

The slow pace of the legal process is in sharp contrast to the speed with which the government has spread the ambit of Aadhaar. The Aadhaar (Targeted Delivery of Financial & Other Subsidies, Benefits & Services) Act was notified in March 2016 after hastily being pushed through Parliament as a money bill. The identity number is now to be linked to bank accounts, PAN cards, phone numbers and insurance. In many states, it is already required for vital supplies and services like food rations and mid day meals in schools. In short, Aadhaar is to be mandatory for both rich and poor, no matter what the Supreme Court said.

As both court and Centre prevaricate, thousands of apprehensive citizens across the country are bombarded with messages to link their biometric identity number with their bank accounts and mobile numbers. Many will now troop to Aadhaar centres to get the number, while others will rush to get their accounts and phone numbers seeded. This in spite of continuing anxieties about privacy and security. The panic created by the current impasse will probably add more people to the system and widen the Aadhaar net, but it reinforces the impression that the unique identity scheme is being imposed on people without their consent and without legality. To the jaundiced eye, this could look like coercion by another name.

The Big Scroll
Read the Scroll.in series, Identity Project, on Aadhaar and its various ramifications.



Sunday, November 5, 2017

12250 - Government may go easy on rules to link Aadhaar with bank accounts, mobile numbers - Economic Times

Updated: Oct 26, 2017, 08.51 AM IST

Centre has decided to extend till March 31 the December 31 deadline for mandatory Aadhaar for availing benefits under government-run social welfare schemes....

Concerns over stringent penalties under the Prevention of Money Laundering Rules for not linking Aadhaar with bank accounts saw the Centre seeking four days from the Supreme Court to consider suggestions to dispense with coercive methods to bring about the linkage. 

Attorney general K K Venugopal informed a bench of Chief Justice Dipak Misra and Justices A M Khanwilkar and D Y Chandrachud on Wednesday that the Centre has decided to extend till March 31 the December 31 deadline for mandatory Aadhaar for availing benefits under government-run social welfare schemes, including ration under the public distribution system. Till March 31, no benefit will be denied for want of Aadhaar, he said. 

But petitioners' advocates Shyam Divan, Anand Grover and Meenakshi Arora launched a counter offensive and accused the Centre of employing coercive methods under PMLA rules to force citizens to link bank accounts and mobile phones with their Aadhaar numbers. 

Divan said, "On one hand the government says it would not take coercive action to force citizens to link their Aadhaar with social welfare schemes. But on the other hand, it says extension of deadline is to enable those who do not have Aadhaar to enrol for it. Surprisingly, at the same time, it is ready to invoke money laundering penal provisions if one does not link bank account with Aadhaar." 

He said validity of Aadhaar needs to be decided expeditiously as the Central Board for Secondary Education was demanding Aadhaar to issue hall tickets to students for Class 12 board examination. "If CBSE says no hall ticket without Aadhaar number, then it amounts to coercing students to part with their biometrics. Imagine school children having to part with their fingerprints like prisoners." 

Venugopal contested this strongly and said a nine-judge constitution bench, while ruling on August 24 that right to privacy was a fundamental right and part of right to life, had stressed on robust data protection regime for safeguarding citizens' biometrics and taken note of the Centre's decision to appoint a committee headed by retired SC judge B N Srikrishna to study various issues relating to data protection and suggest a robust data protection regime as well as necessary changes in the Aadhaar Act and Information Technology Act in this regard. 

When the CJI and Justice Khanwilkar were impressing upon petitioners' counsel that no urgent hearing on petitions was needed, Justice Chandrachud said, "The government has told us that they have initiated steps for a robust data protection regime. It is not an easy thing to formulate..." With petitioners remaining adamant on an early hearing, Venugopal said the government had no objection if a constitution bench heard and expeditiously decided the validity of Aadhaar. 

He also told the court that he would take instruction from the Centre whether those who have Aadhaar and are not linking it with social welfare schemes, bank accounts and mobile numbers would face any difficulty.On August 24, Justice Chandrachud, writing the main judgment in right to privacy, had said, "In a social welfare state, the government embarks upon programmes which provide benefits to impoverished and marginalised sections of society." 

(This article was originally published in The Times of India)