Advertisement

CyberBRICS pp 133-181 | Cite as

Cybersecurity and Data Protection Regulation in India: An Uneven Patchwork

Chapter
  • 131 Downloads

Abstract

Cybersecurity has been an important policy concern for the Indian government since at least the early 1990s. Until today, however, the landscape of its cybersecurity policies remains an uneven patchwork. In particular, as this essay will illustrate, where the concerns of technology users are at odds with the interests of law enforcement and intelligence agencies, the former tend to lose out. Thus, while India was one of the first countries, in 2000, to pass a law dealing with cybercrime and electronic commerce and has, in 2019, also approved law to strengthen consumer protection in the digital age, at the time of writing the country still does not have a horizontal personal data protection law. At the same time, law enforcement and intelligence agencies can legally access and retain user data under a wide range of loosely worded provisions. In the absence of additional checks and balances, the relationship between the citizens of India and the state is, thus, fundamentally reconfigured. Moreover, with the focus so firmly on surveillance and control of digital spaces, other aspects of cybersecurity policy, such as cyberdefence, have taken a backseat.

References

  1. Bhatia, Gautam (17 February 2016). Free Speech and Public Order. Centre for Internet and Society. <https://cis-india.org/internet-governance/blog/free-speech-and-public-order-1>.
  2. Bommakanti, Kartik (2019). Electronic and Cyber Warfare: A Comparative Analysis of the PLA and the Indian Army. ORF Occasional Paper 203. New Delhi, July 2019. Observer Research Foundation. <https://www.orfonline.org/research/electronic-and-cyber-warfare-a-comparative-analysis-of-the-pla-and-the-indian-army-53098/>.
  3. Chawla, Gunjan (4 October 2019). India’s New Cyber Defence Agency – II: Balancing Constitutional Constraints and Covert Ops? Medianama. <https://www.medianama.com/2019/10/223-india-defence-cyber-agency-part-2/>.
  4. Committee of Experts under the Chairmanship of Justice B.N. Srikrishna (2018). A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians. New Delhi, 27 July 2019. Ministry of Electronics and Information Technology, Government of India. <https://meity.gov.in/writereaddata/files/Data_Protection_Committee_Report.pdf>.
  5. Comptroller and Auditor General of India (2016). Report of the Comptroller and Auditor General of India for the Year Ended March 2015. Union Government (Communications and IT Sector). Report No. 29 of 2016. New Delhi, 2016. Comptroller and Auditor General of India. <https://cag.gov.in/content/report-no-29-2016-compliance-audit-communication-it-sector-union-government>.
  6. Concerned People (2018). Solving for Data Justice: A Response to the Draft Personal Data Protection Bill. New Delhi, 18 October 2018. Internet Democracy Project. <https://internetdemocracy.in/reports/datajustice/>.
  7. Corbridge, Stuart & Harriss, John (2003). Reinventing India: Liberalisation, Hindu Nationalism and Popular Democracy. Second edition. New Delhi, Oxford University Press.Google Scholar
  8. Das, Debak (4 November 2019). An Indian Nuclear Power Plant Suffered a Cyberattack. Here’s What You Need to Know. Washington Post. <https://www.washingtonpost.com/politics/2019/11/04/an-indian-nuclear-power-plant-suffered-cyberattack-heres-what-you-need-know/>.
  9. Datta, Bishakha (2017). Guavas and Genitals: An Exploratory Study on Section 67 of the Information Technology Act, India. Mumbai: Point of View.Google Scholar
  10. Datta, Saikat (2016). Cybersecurity, Internet Governance and India’s Foreign Policy: Historical Antecedents. New Delhi, January 2016. Internet Democracy Project. <https://internetdemocracy.in/reports/cybersecurity-ig-ifp-saikat-datta/>.
  11. Datta, Saikat & Venkatanarayan, Anand (30 October 2019). Cyberattack Scare Dogs India’s Nuclear Plants. Asia Times. <https://www.asiatimes.com/2019/10/article/cyberattack-scare-dogs-indias-nuclear-plants/>.
  12. Duggal, Pavan (2005). Cyber Law and Its Implementation in India. Bagga, R.K.; Keniston, Kenneth & Mathur, Rohit Raj (eds.), The State, IT and Development. New Delhi, Sage.Google Scholar
  13. Dutta, Prabhash K (24 August 2017). Right to Privacy: 5 Bills Yet No Law, How Parliament Has Dealt With Personal Data Protection. India Today. <https://www.indiatoday.in/india/story/right-to-privacy-fundamental-right-parliament-1031136-2017-08-24>.
  14. Frankel, Francine R. (2005). India’s Political Economy 1947-2004: The Gradual Revolution. Second Edition. New Delhi, Oxford University Press.Google Scholar
  15. Galiya, Stuti (20 August 2019). India: Consumer Protection Act, 2019 – Key Highlights. Mondaq. <http://www.mondaq.com/india/x/838108/Dodd-Frank+Wall+Street+Reform+Consumer+Protection+Act/CONSUMER+PROTECTION+ACT+2019+KEY+HIGHLIGHTS>.
  16. Gandhi, Jatin (27 March 2018). Srikrishna Committee Report on Data Protection and Privacy by May-End. Hindustan Times. <https://www.hindustantimes.com/india-news/srikrishna-committee-report-on-data-protection-and-privacy-by-may-end/story-KYTHD6DxcgkA9VwtZ24OrN.html>.
  17. Glanz, James; Rotella, Sebastian; & Sanger, David E. (21 December 2014). In 2008 Mumbai Attacks, Piles of Spy Data, But an Uncompleted Puzzle. New York Times. <https://www.nytimes.com/2014/12/22/world/asia/in-2008-mumbai-attacks-piles-of-spy-data-but-an-uncompleted-puzzle.html>.
  18. Gopalakrishnan, Kris S. (26 April 2016). Indian IT and ITeS Journey: Liberalisation and Beyond. Live Mint. <https://www.livemint.com/Opinion/fNjocJ9cwlGCDqLWt2OjXP/Indian-IT-and-ITeS-journey-Liberalization-and-beyond.html>.
  19. Greenleaf, Graham (1 June 2014). India’s Draft the Right to Privacy Bill 2014 – Will Modi’s BJP Enact it? Privacy Laws & Business International Report. N°. 129. Pp. 21-24. Available at SSRN. <https://ssrn.com/abstract=2481796>.
  20. Group of Experts on Privacy Chaired by Justice A.P. Shah (2012). Report of the Group of Experts on Privacy (Chaired by Justice A.P. Shah, Former Chief Justice, Delhi High Court). New Delhi, 16 October 2012. Planning Commission, Government of India. <planningcommission.nic.in/reports/genrep/rep_privacy.pdf>.
  21. Gupta, Apar (18 September 2007). The Personal Data Protection Bill, 2006. India Law and Technology Blog. <https://iltb.net/the-personal-data-protection-bill-2006-7c66721ef8d>.
  22. Guruswamy, Menaka (27 September 2010). Regulating the Gentleman’s Game: Intelligence Reform in India. Centre for the Advanced Study of India, University of Pennsylvania. <https://casi.sas.upenn.edu/iit/guruswamy>.
  23. Headquarters Integrated Defence Staff (2017). Joint Doctrine Indian Armed Forces. New Delhi, April 2017. Directorate of Doctrine, Headquarters Integrated Defence Staff, Ministry of Defence. <https://www.ids.nic.in/IDSAdmin/upload_images/doctrine/JointDoctrineIndianArmedForces2017.pdf>.
  24. Hooda, DS (26 June 2019). India’s New Defence Cyber Agency Will Have to Work around Stovepipes Built by Army, Navy & Air Force: Lt Gen DS Hooda. News18. <https://www.news18.com/news/opinion/new-defence-cyber-agency-will-have-to-work-around-stovepipes-built-by-army-navy-air-force-lt-gen-hooda-2204033.html>.
  25. IAMAI (2019). India Internet 2019. New Delhi, 26 September 2019. IAMAI and Nielsen.Google Scholar
  26. Institute for Defence Study and Analyses (2012). A Case for Intelligence Reforms in India. IDSA Task Force Report. New Delhi, 2012. Institute for Defence Study and Analyses. <https://idsa.in/system/files/book/book_IntellegenceReform.pdf.>.
  27. Internet Democracy Project (2018). Is the Fourth Way Going Far Enough? Our Submission to Meity on Draft Personal Data Protection Bill 2018. New Delhi, 12 October 2018. Internet Democracy Project. <https://internetdemocracy.in/reports/pdpb/>.
  28. Jain, Rohit (29 August 2019). Consumer Protection Act 2019 Ushers in More Benefits for Consumers. Bloomberg Quint. <https://www.bloombergquint.com/law-and-policy/will-the-new-consumer-protection-act-make-consumers-king>.
  29. Jasrotia, Sahil Singh; Sharma, Roop Lal & Mishra, Hari Govind (2019). Disruptions in Indian Telecom Sector: A Qualitative Study on Reliance Jio. Indore Management Journal. Vol. 11, n°. 1. Pp. 37-45. <https://www.iimidr.ac.in/wp-content/uploads/Vol11-1-03.pdf>.
  30. Joshi, Manoj & Das, Pushan (2015). India’s Intelligence Agencies: In Need of Reform and Oversight. ORF Issue Brief No. 98. New Delhi, July 2015. Observer Research Foundation. <https://www.orfonline.org/wp-content/uploads/2015/07/IssueBrief_98.pdf>.
  31. Kanwal, Gurmeet (2018). Introduction: The Need for Defence Reforms. Kanwal, Gurmeet & Kohli, Neha (eds.), Defence Reforms: A National Imperative. New Delhi, Pentagon Press and Institute for Defence Studies and Analyses. <https://idsa.in/system/files/book/book-defence-reform.pdf>.
  32. Kovacs, Anja & Ranganathan, Nayantara (2017). India. Association for Progressive Communications (ed.), Unshackling Expression: A Study on Laws Criminalising Expression Online in Asia. South Africa, Association for Progressive Communications. <https://www.giswatch.org/sites/default/files/giswspecial2017_web.pdf>.
  33. Kovacs, Anja & Ranganathan, Nayantara (2019). Data Sovereignty, of Whom? Limits and Suitability of Sovereignty Frameworks for Data in India. Data Governance Network Working Paper 03. Mumbai, November 2019. Data Governance Network. <http://datagovernance.org/report/data-sovereignty>.
  34. Krishnan, Vinayak & Sinha, Roshni (2019). Draft Information Technology [Intermediaries Guidelines (Amendment) Rules] 2018. Rules & Regulation Review. New Delhi, 30 January 2019. PRS Legislative Research. <prsindia.org/sites/default/files/bill_files/IT%20Intermediary%20Guidelines%20Amendment%20Rules%20Brief-For%20Upload.pdf>.
  35. Law Commission of India (2017). Hate Speech. Report 267. New Delhi, March 2017. Law Commission of India. <lawcommissionofindia.nic.in/reports/Report267.pdf>.
  36. Mankotia, Anandita Singh (24 July 2019). Data Protection Bill: Changes Likely in Proposed Data Privacy Rules: Only Critical Data May Need to Be Housed in India. Economic Times. <https://economictimes.indiatimes.com/tech/internet/changes-likely-in-proposed-data-privacy-rules-only-critical-data-may-need-to-be-housed-in-india/articleshow/70355298.cms?from=mdr>.
  37. Ministry of Electronics and Information Technology (2017). Constitution of a Committee of Experts to Deliberate on a Data Protection Framework for India. Office Memorandum No. 3(6)/2017-CLES. New Delhi, 31 July 2017. Ministry of Electronics and Information Technology, Government of India. <https://meity.gov.in/writereaddata/files/MeitY_constitution_Expert_Committee_31.07.2017.pdf>.
  38. Ministry of Electronics and Information Technology (2018). Comments Invited on Draft Intermediary Guidelines 2018. New Delhi, 24 December 2018. Ministry of Electronics and Information Technology, Government of India. <https://meity.gov.in/comments-invited-draft-intermediary-rules>.
  39. Ministry of Home Affairs (2011). Draft Bill on Right to Privacy. Office Memorandum No. II/20034/250/2011-IS-II. New Delhi, 29 September 2011. Ministry of Home Affairs, Government of India. <https://cis-india.org/internet-governance/draft-bill-on-right-to-privacy>.
  40. Na, Vijayashankar (9 July 2018). Cyber Appellate Tribunal Back in Action through TDSAT. Naavi. <https://www.naavi.org/wp/cyber-appellate-tribunal-back-in-action-through-tdsat/>.
  41. Nappinai, N.S. (2010). Cyber Crime Law in India: Has Law Kept Pace with Emerging Trends? An Empirical Study. Journal of International Commercial Law and Technology. Vol. 5., n° 1. Pp. 22-28.Google Scholar
  42. Narrain, Siddharth (2016). Hate Speech, Hurt Sentiment and the (Im)Possibility of Free Speech. Economic and Political Weekly. Vol. 51, n°. 17. <https://www.epw.in/journal/2016/17/special-articles/hate-speech-hurt-sentiment-and-impossibility-free-speech.html>.
  43. Pal, Sherill (6 February 2019). Intermediary Liability: Un-safe Harbour? Fortune India. <https://www.fortuneindia.com/opinion/intermediary-liability-un-safe-harbour/102944>.
  44. Pandit, Rajat (29 April 2019). Forces Prepare to Deal with Cyber-attacks on Key Infrastructure. Economic Times. <https://economictimes.indiatimes.com/news/defence/forces-prepare-to-deal-with-cyber-attacks-on-key-infrastructure/articleshow/69091292.cms>.
  45. Planning Commission (2011). Constitution of Group of Experts to Deliberate on Privacy Issues. Office Memorandum No. 13040/47/2011-CIT&I. New Delhi, 26 December 2011. CIT & I Division, Planning Commission, Government of India. <https://cis-india.org/internet-governance/constitution-of-group-of-experts.pdf>.
  46. Ranganathan, Nayantara (9 August 2018). India’s Data Protection Draft Ignores Key Next-Generation Rights. Asia Times. <https://www.asiatimes.com/2018/08/opinion/indias-data-protection-draft-ignores-key-next-generation-rights/>
  47. Rej, Abhijnan & Joshi, Shashank (2018). India’s Joint Doctrine: A Lost Opportunity. ORF Occasional Paper 139. New Delhi, January 2018. Observer Research Foundation. <https://www.orfonline.org/research/india-joint-doctrine-lost-opportunity/>.
  48. Reserve Bank of India (2018). Storage of Payment System Data. Circular DPSS.CO.OD.No 2785/06.08.005/2017-18. Mumbai, 6 April 2018. Reserve Bank of India. <https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11244&Mode=0>.
  49. Saikia, Arunabh (7 April 2018). India’s Internet Shutdown: Most States Block Services without Following Centre’s Rules. Scroll. <https://scroll.in/article/874565/internet-shutdown-most-states-continue-to-block-services-without-adhering-to-the-centres-new-rules>.
  50. Sagar, Pradip R. (1 June 2019). Three-pronged Plan. The Week. <https://www.theweek.in/theweek/current/2019/05/31/three-pronged-plan.html>.
  51. Sagar, Pradip R. (9 November 2019). Tech, A Risk. The Week. <https://www.theweek.in/theweek/cover/2019/11/09/tech-a-risk.html>.
  52. Samanta, Pranab Dhal (7 January 2019). Government Exploring Ways to Exempt Security Agencies from Data Protection Bill. Economic Times. <https://economictimes.indiatimes.com/news/politics-and-nation/government-exploring-ways-to-exempt-security-agencies-from-data-protection-bill/articleshow/67413173.cms?from=mdr>.
  53. Sarkar, Torsha (12 August 2019). Rethinking the Intermediary Liability Regime in India. CyberBRICS. <https://cyberbrics.info/rethinking-the-intermediary-liability-regime-in-india/>.
  54. Sawhney, Pravin (17 August 2019). Where Does CDS Fit In? The Tribune. <https://www.tribuneindia.com/news/archive/where-does-cds-fit-in-818565>.
  55. Shourie, Arun (2003). Statement by H.E. Mr. Arun Shourie, Minister for Information Technology, Communications and Privatisation, Government of India, at the World Summit on Information Society. Geneva, 11 December 2003. Permanent Mission of India to the Offices of the United Nations, Its Specialised Agencies and Other International Organisations in Geneva. <http://www.itu.int/net/wsis/geneva/coverage/statements/india/in.html>.
  56. Sinha, Amber (2017). Social Media Monitoring. Bangalore, 13 January 2017. Centre for Internet and Society. <https://cis-india.org/internet-governance/files/social-media-monitoring/at_download/file>.
  57. Sircar, Sushovan & Sachdev, Vakasha (30 October 2019). Kudankulam Cyber Attack Did Happen, Says NPCIL a Day after Denial. Bloomberg Quint. <https://www.bloombergquint.com/politics/kudankulam-nuclear-power-plant-malware-attack-correct-confirms-npcil>.
  58. SFLC.in (2014). India’s Surveillance State. New Delhi, March 2014. SFLC.in. <https://sflc.in/sites/default/files/wp-content/uploads/2014/09/SFLC-FINAL-SURVEILLANCE-REPORT.pdf>.
  59. SFLC.in (2018). Living in Digital Darkness: A Handbook on Internet Shutdowns in India. New Delhi, May 2018. SFLC.in. <https://sflc.in/sites/default/files/reports/Living%20in%20Digital%20Darkness%20-%20A%20Handbook%20on%20Internet%20Shutdowns%20in%20India%2c%20May%202018%20-%20by%20SFLCin.pdf>.
  60. Srikumar, Madhulika; Srinivasan, Sreenidhi; Kennedy-Mayo, DeBrae & Swire, Peter (2019). India-US Data Sharing for Law Enforcement: Blueprint for Reforms. New Delhi, January 2019. Observer Research Foundation and Cross-Border Requests for Data Project of the Georgia Tech Institute for Information Security and Privacy. <https://www.orfonline.org/research/india-us-data-sharing-for-law-enforcement-blueprint-for-reforms-47425/>.
  61. Srivas, Anuj (12 December 2016). The Tragic and Comedic Functioning of India’s Cyber Appellate Tribunal. The Wire. <https://thewire.in/banking/tragic-comedic-functioning-indias-cyber-appellate-tribunal>.
  62. Suhag, Roopal & Sinha, Roshni (2018). The Consumer Protection Bill 2018. Legislative Brief. New Delhi, 27 April 2018. PRS Legislative Research. <prsindia.org/sites/default/files/bill_files/Legislative%20Brief%20-%20Consumer%20Protection%20Bill%2C%202018_0.pdf>.
  63. Tewari, Ruhi & Nayak, Malathi (23 December 2008). Govt Pushes Through IT Bill; Wins Digital Snooping Right. Live Mint. <https://www.livemint.com/Home-Page/wRQFhAdHHDhAHWBj6qEUBJ/Govt-pushes-through-IT-Bill-wins-digital-snooping-right.html>.
  64. Upadhya, Carol (2011). Software and the ‘New’ Middle Class in the ‘New India’. Baviskar, Amita & Ray, Raka (eds.), Elite and Everyman: The Cultural Politics of the Indian Middle Classes. New Delhi, Routledge.Google Scholar
  65. Varma, Satvik (2 September 2019). Consumer Protection Act 2019: Enhancing Consumer Rights. Bar and Bench. <https://www.barandbench.com/columns/consumer-protection-act-2019-enhancing-consumer-rights>.
  66. Vivekananda International Foundation (2019). Credible Cyber Deterrence in Armed Forces of India. VIF Taks Force Report. New Delhi, March 2019. Vivekananda International Foundation. <https://www.vifindia.org/sites/default/files/Credible-Cyber-Deterrence-in-Armed-Forces-of-India_0.pdf>.

Copyright information

© The Editor(s) (if applicable) and The Author(s), under exclusive license to Springer Nature Switzerland AG 2021

Authors and Affiliations

  1. 1.Internet Democracy ProjectNew DelhiIndia

Personalised recommendations