Monday, 5 March 2012

Privacy Law Firms In India Must Be Proactive

Indian privacy and data protection laws are complicated in nature as they are scattered among multiple legislations, rules and regulations. Further, information and communication technology (ICT) and outsourcing has added their own complexities to the same. Thus, privacy laws, lawyers and law firms in India are still maturing.

Not only we have very few privacy and data protection law firms in India but we have only a handful of cyber law firms in India. One area that has recently interested the legal community pertains to cyber security. Although cyber security as a legal field has started gaining attention of foreign lawyers and law firms yet cyber security law firms in India or cyber security lawyers in India are still missing.

Privacy and data protection has assumed a centre stage due to recent growth of ICT related industries, including e-commerce. Further, sensitive and personal information is also required to be maintained and preserved not only by the government but also private individuals and companies.

According to India’s leading techno legal ICT law firm Perry4Law and its techno legal segment named Perry4Law Techno Legal Base (PTLB), e-commerce regulations and laws in India require the e-commerce companies to maintain privacy and data protection and data security of the information supplied by their customers. Similarly, e-health laws and regulations in India require that sensitive personal information of patients must be kept intact, secure and private. The telemarketing laws of India also intend to prohibit spam communication to protect privacy of individuals. The cloud computing regulations in India must also carry stringent privacy protection safeguards.

We must also have well defined procedure and cell site data location laws in India. As we have no dedicated privacy laws, data protection laws, data security laws, anti telemarketing laws, anti spam laws, etc, cell phones monitoring in India is not legally sustainable.

The role of privacy law firms in India can be very productive. They must insist upon enactment of dedicated privacy laws, data protection laws and data security laws. However, since there are handfuls of privacy law firms in India this task would take some time before Indian government would pay heed to their suggestions.

Wednesday, 25 January 2012

Is Google Censoring Recent Video Conferencing Controversy Results?

Use of video conferencing in India is not new but its blocking is certainly new. The recent fiasco of Rajasthan government and Rajasthan police that did not allow the video conferencing of Salman Rushdie shows that India is not comfortable with technology uses for serious issues.

The recent episode has proved that video conferencing in India is a troubled technology and shows Indian struggle with information technology. We have no dedicated video conferencing laws and regulations in India. Similarly we have no dedicated video conferencing blocking laws in India as well. In the absence of a clear cut law, constitutional issues like speech and expression are at stake.

However, my interest in blocking of video conferencing in India is also associated with another crucial issue. It seems Google has been manipulating search and blog results pertaining to posts criticizing recent blocking of video conferencing in India. India wanted companies like Google and Facebook to censor users’ contents and this is exactly what seems to be happening in India.

Recently two posts titled video conferencing laws and regulations in India and video conferencing blocking laws in India, posted at PTLB Blog, appeared in both search results and blog search results. Now they do not appear anymore in both search results. Surprisingly, they are still available in both search results outside Indian cyberspace.

Google, Facebook, etc are facing a criminal trail for not removing objectionable contents. What is more surprising is the argument taken by Google India in Delhi High Court. Google India claimed that it is a subsidiary of Google Incorporation and has no control over contents available at latter’s platforms.

If this is the situation, who has removed the search results of the abovementioned two articles on video conferencing is an interesting question. Naturally, it can be only Google Incorporation that can remove such results as per Google India’s claim. However, since search results of the two posts are available outside India, it seems to be a job of Google India. May be Google India had requested Google Incorporation to remove the same or it did the same on its own.

It is high time to ascertain the true nature, role, powers and functions of Google India as posts are frequently disappearing from India based search results. I hope Delhi High Court would take note of this fact and the averments made in this article while deciding the case of Google India and Google Incorporation.

Update: It seems Google Incorporation (California, US) has approved the posts. These posts have resurfaced. Thanks to Google US for doing the needful. So it seems Google US is not censoring recent video conferencing controversy results in India.

Tuesday, 17 January 2012

LPO And KPO In India Is Changing

Legal process outsourcing (LPO) and knowledge process outsourcing (KPO) are two of the most important segments of outsourcing industry. Legal process outsourcing usually covers areas like contract drafting and vetting, legal research, para legal work, arguments drafting, legal due diligence services, etc. Knowledge process outsourcing, on the other hand, takes care of highly specilaised aspects of the outsourcing industry.

Legal process outsourcing (LPO) in India is not a new phenomenon. Even many firms and companies are providing knowledge process outsourcing (KPO) services in India. So basically LPO and KPO in India is well established and world renowned. LPO and KPO firms and companies in India are also world renowned and they provide valuable services to world at large.

However, techno legal LPO and KPO in India is still in its infancy stage. For instance, very few LPO and KPO in India are providing e-discovery services in India. Similarly, very few LPO providers in India are providing that are providing technology related legal due diligence services in India. Further, when it comes to electronic legal due diligence services in India, there seems to be no LPO and KPO services provider except Perry4Law Techno Legal Base (PTLB).

The cyber law trends in India 2012 by Perry4Law and PTLB have predicted that techno legal issues like cyber law due diligence, corporate laws due diligence, social media due diligence, e-discovery, etc would assume more importance in the year 2012. Further, citizen to government (C2G) LPO and KPO services would also rise in the year 2012.

LPO and KPO is a competitive and dynamic field and only the most competent would survive in the long run. With increasing competition from Asian countries, Indian LPO and KPO providers must be more innovative and adapt as per the technological requirements.

Saturday, 7 January 2012

Aadhar Project Is Unconstitutional, Undemocratic And Anti Parliamentarian

The Aadhar project of India is a project that has neither a legal backing nor a project evaluation and management support. Naturally, Indian government is now considering scrapping the Aadhar project of India. Aadhar project has been considered to be futile by many experts in India. They have been suggesting that Aadhar project must be suspended till it is made legally valid and constitutionally sound.

However, Aadhar project was kept intact despite it lack of utility and illegal manner of implementation. Sooner or later it is going to be scrapped however till than millions of public money would already be lost. Why not the Indian government could scrap the Aadhar project few years back when it was so suggested by the experts.

According to Praveen Dalal, managing partner of techno legal firm Perry4Law and leading techno legal expert of India, Aadhar Project must be supported by a Techno Legal Framework that must be supplemented by robust Cyber Security, Privacy Protection and Data Protection.

In the absence of these Procedural and Constitutional Safeguards, both Aadhar Project and UIDAI are Unconstitutional, says Praveen Dalal. Even if the National Identification Authority of India Bill 2010 (NIDAI Bill 2010) would have been passed, both Aadhar Project and UIDAI would have “Remained Unconstitutional”, opines Praveen Dalal. We need an altogether different Law than NIDAI Bill 2010 and till such a Constitutional Law is passed, Aadhar Project should be suspended suggests Praveen Dalal.

According to the Aadhar Watch Initiative of India maintained by Praveen Dalal, Aadhar project is suffering from the following illegalities and shortcomings:

(1) Absence of legal framework supporting Aadhar project,

(2) Absence of privacy protections safeguards,

(3) Absence of data protection safeguards,

(4) Possible abuse of Aadhar project as an e-surveillance tool,

(5) Absence of cyber security safeguards to prevent cyber attacks,

(6) Absence of data leakages and data breaches protections,

(7) Mutual disharmony between various governmental agencies and departments.

In the past fake UID cards were freely available to anybody. This undermines the very purpose of the Aadhar number. It has also been reported that home ministry of India is also opposing the Aadhar project. The truth is that Aadhar project is a very dangerous project and it must be scrapped as soon as possible.

However, the unique identification authority of India (UIDAI) kept on pushing the project despite ferocious protests all over India. What is more surprising is the fact that UIDAI has been functioning under an executive order of the ministry of planning. This violates all the constitutional principles that are well established in India.

It seems the Indian government is adopting double standards. While responding to the benign call for a jan lokpal law for India, Indian government was very quick to label it as anti democratic and anti parliamentary. Surprisingly, Indian government is finding nothing wrong with an executive order constitution UIDAI that is clearly violating constitutional scheme. It is now for the Indian government to give this issue a serious consideration as Aadhar project cannot be continues in these circumstances.

Friday, 23 December 2011

Data Security, Cyber Security And Privacy In Indian Banking Industry

Banking industry of India is passing through a transformation age. From technological upgradations to enacting new regulatory norms, banking sector of India is all set for a big change. However, this change is also very demanding and challenging in terms of legal obligations and technological knowledge. Banks in India are finding it difficult to cope with both.

For instance, banks in India are required to not only ensure cyber due diligence in India but also cyber security due diligence in India. Reserve Bank of India (RBI) has very categorically told Indian banks to ensure effective cyber security in their day to day affairs and banking transactions. However, banks in India are not complying with RBI’s cyber security due diligence requirements due to lack of awareness and technical expertise.

Further, on the compliances front as well, banks in India are not doing the needful. For instance, as per RBI’s recommendations, all banks should create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest. Till now banks in India have not fulfilled these requirements.

Similarly on the front of cyber security Indian banks have not performed well. Cyber security for banking and financial sectors of India is not up to the mark. Internet banking risks in India are in abundance and we have no cyber security of Internet banking in India. Even cyber due diligence for banks in India is not taken seriously by Indian banks. Cyber security of online banking systems in India is by and large below average and many cases of banking financial frauds and cyber crimes have been reported in India.

Even the mobile banking in India is risky as the present banking and other technology related legal frameworks are not conducive for mobile banking in India. We have no dedicated Internet banking laws in India or mobile banking laws in India. Mobile banking transactions in India are risky and untrusting in the absence of mobile cyber security in India. We are still not ready for mobile governance in India as m-governance in India is not going to be successful in the absence of a sound mobile governance policy of India.

Data security and privacy in Indian banking industry is another area that requires special attention of Indian banks. Banks in India must ensure privacy protection and data protection of its customers.

The corporate and banking laws in India are in the process of being streamlined. An Integrated modern banking law in India is also in pipeline. RBI has also prescribed an enhanced due diligence measures by banks of India for higher risks customers. Overall, the emphasis is upon ensuring data security, cyber security and privacy protection by banks operating in India.

Friday, 16 December 2011

Cyber Law Lawyers And Law Firms in India

Cyber law is a technical subject that requires thorough understanding of both technical and legal aspects. This is the reason why most of the lawyers and law firms find it difficult to deal with the same.

There are very few cyber law firms in India and cyber law lawyers in India. Even lesser are cyber security law firms in India. Similarly, e-commerce lawyers and law firms in India also limited in number.

When it comes to cyber forensics law firms in India, we have a single firm in India that provides techno legal cyber forensics litigation, consultancy, corporate advisory and skills development services. Perry4Law is the sole techno legal ICT and IP law firm of India and world wide.

Further, Perry4Law Techno Legal Base (PTLB) is the premier techno legal segment of Perry4Law that takes cares of various techno legal services of Perry4Law.

With the passage of information technology act 2000 (IT Act 2000), the foundation for cyber law of India was laid down. However, even after more than 10 years of passing of the same, very few lawyers, judges, police officers, etc are aware of the same. This ha also led to a limited growth of cyber law jurisprudence in India.

There is an urgent need develop techno legal skills of lawyers, police officers, judges, etc in India. Suitable trainings and skills development exercises must be undertaken by Indian government in this regard.

Thursday, 15 December 2011

Corporate And Banking Laws In India Rejuvenated

Of late, parliament of India is working really hard in the direction of rejuvenating corporate and banking laws of India. Many important bills are pending in the lok sabha that if passed would strengthen the corporate and banking laws of India.

Corporate laws in India are old and outdated. The Companies Bill 2011 has been tabled in the Lok Sabha. Similarly, banking laws in India are also outdated and does not accommodate the modern technology.

A significant development in this regard is happening in the banking sector of India. An integrated modern banking law for India is in pipeline. The parliamentary standing committee on finance has suggested for such integrated law for the banking sector of India.

However, Reserve Bank of India (RBI) need to implement the technological aspects more stringently and effectively. While RBI has acknowledged risks of e-banking in India still the proposed bill has not addressed the issues of online banking risks in India and their redressal. Although RBI has recently directed that all banks would have to create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest yet these recommendations have not been implemented by the banks. Indian banks are poor at cyber security implementation.

Further, crucial issues like encryption standards for banks of India have also been ignored. Further ATM frauds in India and their techno legal prevention has also been missed by the committee. Cyber law due diligence for banks in India and Internet intermediary liability for banks of India have also skipped the attention of the committee. It would be better if the parliament of India also considers the techno legal issues and add them to the proposed Banking Laws (Amendment) Bill, 2011 before passing the same.