Showing posts with label PRAVEEN DALAL. Show all posts
Showing posts with label PRAVEEN DALAL. Show all posts

Tuesday, January 17, 2012

Ministry Of Home Affairs Would Scrutinise Online Contents

Foreign websites and social media platforms are defending themselves in India under the cyber law of India. In fact, the cyber law due diligence and social media due diligence have emerged as the perspective cyber law trends of India in 2012. Clearly, foreign companies and websites must keep in mind the conflict of laws across the world that they have to adhere to.

Although cyberspace is not a safe place for any person yet children are more vulnerable to the evils of cyber crimes. Protecting children in cyberspace is of utmost importance. Realising this requirement, the home ministry of India would scrutinise social networking sites for the risks they may pose before children. Home ministry plans to monitor social networking sites that host obscene material that induces children to sexually explicit acts or crimes.

In fact, the home ministry has communicated to other states that it is essential to monitor and regulate various websites, including social networking websites, and to train teachers, cyber café owners and parents on deploying parental control software to mitigate spoofing of age, gender and identity.

B Bhamathi, additional secretary at the home ministry has issued a letter to all state police chiefs and chief secretaries and has directed that in appropriate cases, the police should request social networking sites to remove undesirable contents. Bhamathi has also suggested that police officers must act as undercover agents to identify internet criminals and apprehend them to safeguard children’s interests.

According to Praveen Dalal, managing partner of law firm Perry4Law and leading techno legal cyber law expert of Asia, if Websites are “Violating” Laws of India and they have been “Notified” to this effect and still they “do not Remedy the Situation”, then the Safe Harbour Protection under Indian Information Technology Act, 2000 is “Lost” and such Websites/Owners can be Prosecuted in India.

Thus, social networking websites that are duly notified by police officers in India are required to take down contents that are detrimental to children and may pose threat to them. If these social media websites refuse to or fail to do so, they may be prosecuted in India.

This is a reasonable step on the part of home ministry as cases of child pornography, online harassment, cyber stalking and cyber bullying are increasing world over. In fact, recently Interpol helped India to track child porn surfers in Kerala. Clearly the grip of Indian cyber law is tightening upon websites and social media platforms and they cannot afford to ignore cyber law due diligence any more.

Friday, January 13, 2012

Google, Facebook, Microsoft, Yahoo Etc Summoned Before Indian Court

There are certain offences against the State that cannot be tried by any court in India till central/state government grants its permission. Such permission is granted under section 196 of the Code of Criminal Procedure (CrPC), 1973 and once granted certain criminal offense committed against a nation/state can be prosecuted.

Lack of cyber due diligence and weak arguments before the Delhi High court has brought a situation where websites like Google, Facebook, Microsoft, Yahoo, etc would have to face criminal trial in India. The Indian government has sanctioned prosecution of social networking sites like Facebook, Google, Microsoft and Yahoo India over objectionable content on their sites and with this the criminal trial process has begun. Even these websites may be blocked in India if they fail to comply with Indian laws.

Meanwhile, the trial court adjourned the matter till March 13, 2012. The trial court has also directed the external affairs ministry to serve the summons issued to foreign-based social networking sites. With this the excuse of being an Indian subsidiary is also gone and now parent companies would have to face the heat.

Indian government, while granting such permission, said “Government of India, after being satisfied that such content are violative of the provisions of the Information Technology (Intermediaries Guidelines) Rules, 2011, and after due application of judicious minds finds it appropriate to grant sanction under section 196 of CrPC to proceed against the accused persons in the aforesaid complaint in national harmony, integration and national interest”. This was said in a report submitted by the department of information technology to the trial court.

According to Praveen Dalal, managing partner of law firm Perry4Law and leading techno legal expert of India, if Websites are “Violating” Laws of India and they have been “Notified” to this effect and still they “do not Remedy the Situation”, then the Safe Harbour Protection under Indian Information Technology Act, 2000 is “Lost” and such Websites/Owners can be Prosecuted in India.

This entire situation could have been avoided by simply removing the offending contents. I do not know why websites failed to consider such request. Even otherwise when such a media rage was raised over the issue, there was nothing that prevented such websites to remove the offending contents on their own. Now these websites cannot even claim that they had no knowledge of such offending contents.

The best option for these websites seems to be to remove the infringing material and report to the concerned courts. The sooner they do it the better it would be to diffuse this tension and situation.

Thursday, January 12, 2012

Can Google And Facebook Be Blocked In India?

Recently we covered an article titled should Wordpress be blocked in India? The article was a result of the increasingly denial of US based and foreign companies to comply with Indian laws like copyright law and cyber law of India. As matters of fact foreign companies are openly violating the intellectual property rights and cyber law of Indians and even if contacted they are not willing to remedy the situation.

Techno legal experts in India have even suggested that US must change its policy towards foreign IP infringements and must stay away from getting involved in controversial laws and actions. However, it seems foreign companies are not listening and experts in India have suggested taking drastic steps like reasonable judicial blocking of such offending websites in India.

According to Praveen Dalal, managing partner of law firm Perry4Law and leading techno legal expert of India, Websites Blocking in India by Judiciary must be Just, Reasonable and Fair. There should not be an “Unreasonable” or “Casual Approach” towards Blocking of Websites in India by Indian Courts. If Websites are “Violating” Laws of India and they have been “Notified” to this effect and still they “do not Remedy the Situation”, then the Safe Harbour Protection under Indian Information Technology Act, 2000 is “Lost” and such Websites/Owners can be Prosecuted in India, informs Praveen Dalal.

This explains the prosecution part of such websites. However, what happens if the prosecuted websites fail to comply with court’s directions? Such Websites can be “Legally Blocked” in India if they fail to “Comply” with Court’s Directions or Directions of Indian Government Agencies like Computer Emergency Response Team, India (CERT-IN) that are duly ordered in this regard by a Designated Officer, informs Praveen Dalal.

The way foreign websites are refusing to comply with Indian laws, blocking of such websites in India is going to increase. In fact, US has proposed laws like Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act of 2011 (PIPA) and the "Stop Online Piracy Act (SOPA) that are primarily targeted toward foreign websites blocking, including those of India. India must also enact such law that can block foreign websites if they do not comply with Indian laws.

While pre screening of contents is not possible yet there is nothing that prevents foreign companies from removing objectionable contents. In fact, they are legally bound to remove such offending contents once they become aware of such contents. Cyber due diligence for India companies and foreign websites is now well established and websites owners cannot deny the same.

In fact, the Delhi High Court has today reiterated this position that websites of social networking site Facebook India and search engine Google India can be "blocked" like in China if they fail to devise a mechanism to check and remove objectionable material from their web pages.

The court proceedings against Google and Facebook would continue before the magistrate's court and it would decide the fate of these two companies as per Indian laws. The arguments put forward on behalf of Google and Facebook seem to be weak and they must come up with something really brilliant to show that they are compliant with Indian laws.

Thursday, December 22, 2011

Internet Banking Risks In India

Technology has brought many benefits for banking consumers in India. However, technology has also given birth to many unforeseen challenges. Cyber security challenges of Internet banking in India have grown tremendously in the past. In fact, Internet banking in India is not cyber secure despite the recommendations of Reserve Bank of India (RBI). Banks in India are ignoring the cyber security due diligence requirements prescribed by Reserve Bank of India (RBI).

Internet banking is a very important aspect of Indian banking industry. Internet banking not only provides instant banking facilities but it also confers mobility to the account holders. However, cyber security of internet banking infrastructure of India is the need of the hour. Instances of theft of money through hacking of accounts of the accounts holders are fast becoming a trend in India.

This is partly due to the ignorance of the accounts holders and partly due to the weak cyber laws of India. The account holders are increasingly targeted for phishing attacks that result in loosing of sensitive banking information.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, the Information Technology Act 2008 has made most of the cyber crimes and cyber offences “bailable”. India has made its cyberspace a “free zone” and “safe heaven” for cyber criminals and cyber offenders. He says that now even after committing hacking in India a person would be entitled to “bail” as a matter of right. There is nothing that prevents such cyber criminals from committing cyber crimes in India in the absence of a deterrent law.

This has resulted in an increased spate of cyber crimes including hacking of the e-mail IDs of the Internet banking users and stealing of their money.

Further, India has also become one of the most endemic surveillance societies of the World. Confidential information is already vulnerable and with the proposed Indian plans of installing key loggers at cyber cafes, the same would exclude the use of cyber cafes for these purposes. Although cyber cafés are not a good place to transact confidential matters yet with a poor Internet penetration in India this may still happen, says Dalal.

With a weak cyber law, lack of cyber security awareness and increasing e-surveillance initiatives in India, Internet banking disputes are bound to increase in India. The government is least bothered about these issues and ultimately the account holders would have to bear the financial losses.

Is ICICI Online Banking System Cyber Secure?

Online banking transactions in India and electronic banking in India are in a real mess. Thanks to the defunct cyber law of India, inadequate cyber security mechanisms like encryption usages for banks, ignoring the cyber security due diligence requirements prescribed by Reserve Bank of India (RBI) and many more such issues.

Naturally, online banking risks in India have increased tremendously. We have no dedicated Internet or e-banking laws in India. Further, online banking systems in India are not cyber secure. Even mobile banking in India is risky.

This position is obvious if we analyse the present trends occurring in India. For example Citigroup had recently confirmed cyber attack upon bank’s network. It is also well known that a timely and appropriate cyber due diligence could have prevented such attacks and various cyber frauds that are growing in the banking sector of India.

Now it has been reported that a proof-of-concept virus has been developed by a security professional to attack the ICICI Online banking using the Man-in-Middle / Man-in-Browser attack method. It shows what an attack can do to an online banking customer who uses ICICI online banking facility and how it can result in financial loss.

Naturally, cyber security of banks in India is not in order at all. Cyber Security Policy for Banks in India is an issue that is very important for Banks of India, says Praveen Dalal, managing partner of New Delhi base ICT law firm Perry4Law and leading cyber law expert of India. With the growing use of Internet Banking, ATM machines, Credit and Debit Cards, Online Banking, etc, Banks of India must also upgrade their Cyber Security Infrastructure and establish a Cyber Security Policy, suggests Dalal.

An integrated modern banking law for India is in pipeline and it would be a good idea to make it techno legal in nature so that it can address cyber crimes and cyber security in a more effective manner. Corporate and banking laws in India are in the process of being streamlined. RBI has even issues a notification prescribing enhanced due diligence measures for high risks customers in India. RBI is planning to boost ATM security in India. On similar lines, RBI must curb online banking crimes and frauds in India.

Banks in India need to adopt techno legal measures to prevent ATM and other similar financial frauds and cyber crimes. Further, cyber due diligence trainings for bank employees can also be beneficial in this regard. Banks must also appoint steering committees and CIOs as soon as possible.

Monday, August 29, 2011

Proposed Jan Lokpal Law Must Be Techno Legal

The drafting of final Jan Lokpal Bill of India is pending before the Parliament Standing Committee (PSC). The task before the PSC is enormous as it has to analyse the inputs of various stakeholders and experts while suggesting the final Jan Lokpal Bill.

There are many drafts of Jan Lokpal bills that have been in circulation. Besides, there are many good suggestions from techno legal experts of India that have shown the necessity to make the proposed Jan Lokpal law techno legal in nature.

According to Praveen Dalal, managing partner of New Delhi based techno legal ICT law firm Perry4Law and leading techno legal expert of India, the proposed Jan Lokpal Law of India must be Techno Legal and Technology Driven in nature.

The issues like E-Procurement, E-Banking, E-Delivery of Services, etc would bring their own share of Scams and Corrupt Practices and the same cannot be dealt with by the Jan Lokpal Law unless it is Techno Legal in nature, suggests Dalal.

So far the proposed drafts of Jan Lokpal have failed to address these crucial issues. Fortunately, the PSC on Jan Lokpal can consider the suggestions of techno legal experts of India while suggesting final bill in this regard.

Wednesday, June 22, 2011

Attorney General Bats For CBI Exclusion From RTI Act 2005

Central Bureau of Investigation (CBI) is the premier investigating authority of India. It is, however, not at all an intelligence agency though it may be handling few intelligence related aspects or cases. Intelligence work was the main excuse that was given by Indian government to exempt CBI from the applicability of right to information act 2005 (RTI Act 2005).

Indian government also exempted national investigation agency of India (NIA) and national intelligence grid (Natgrid) from the applicability of RTI Act 2005. Interestingly, the constitutional validity of national investigation agency act, 2008 (NIA 2008) is still doubtful and CBI and Natgrid are not governed by any legal framework.

Attorney General of India Goolam Vahanvati has opined that the exclusion of CBI from the purview of RTI Act 2005 is justified on the ground that CBI was also involved in intelligence-gathering as well as safeguarding the country’s economic security. He, however, failed to understand that national security and fundamental rights must be reconciled and primacy of one over another without reconciliation attempts would itself violate the constitutional provisions.

Further, Natgrid, CBI and Intelligence Agencies of India are presently not “Accountable” to Parliament of India, informs Praveen Dalal, leading techno legal expert of India and CEO of Human Rights Protection Centre in Cyberspace of India. Human Rights are regularly targeted by Indian Government and its Agencies without “Constitutional Laws”. Without Parliamentary Scrutiny and Judicial Review these Agencies cannot be considered to be “Constitutional”. If these Agencies are themselves “Unconstitutional” their functioning is also “Unconstitutional”, suggests Dalal.

Vahanvati justifies the stand of Indian government by saying that while the “main purpose of intelligence gathering and assessment is prevention and occurrence of activities which would endanger the security of the country, it cannot be restricted only to gathering of intelligence prior to happening of an event but should extend to post-event intelligence gathered which falls under investigation.

While this is a sound proposition but it does not mean that intelligence work should be an excuse for non accountability and non transparency. If Indian Government wishes to make the functioning of Intelligence Agencies “secret” there must a “Mechanism” to ensure that “Parliamentary Oversight” of these agencies does exists, opines Dalal. Presently there is no Parliamentary Oversight of these Agencies, informs Dalal.

In these circumstances, the decision of Indian Government to exempt CBI and Natgrid is not based upon “National Interest” and “National Security” but upon “Extraneous Considerations” and it deserves to be set aside by our Constitutional Courts, suggests Dalal. Let us see how things develop in this regard in India.

Sunday, June 5, 2011

Jan Lokpal Bill Of India 2011

The efforts to have the Jan Lokpal Act of India 2011 are in full progress. However, till now they are at the stage of drafting a Bill for that purpose.

Even a final draft Bill has not yet been prepared. In all probability it may not be prepared till the deadline of 30th June 2011.

Meanwhile, Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India has explained what an ideal Jan Lokpal Bill must have. He has also sent these suggestions to the government of India.

He has also introduced the element of information and communication technology (ICT) for effective applicability of the proposed law.

The present Drafts proposed by both Indian government and civil liberty activists do not cover the points suggested by Praveen Dalal.

Since he has also sent these suggestions to Indian government, they may be considered while drafting the final draft.

Till now Indian government has not shown any serious efforts to make the proposed Jan Lokpal Bill strong and effective.

The suggestions given by Praveen Dalal, if incorporated, can make the final draft strong and effective.

Sunday, May 15, 2011

Cyber Command And Control Authority Of India

Cyber security is an issue that has always been ignored by India. As a result, cyber security of India is in a poor condition. Cyber security is not mere formulation of policies but their actual implementation. At this level of implementation, Indian government fails miserably as it lacks the techno legal skill necessary to implement cyber security policies.

India needs skilled techno legal professionals who can implement the cyber security policy of India. As a matter of fact, till now we have no cyber security policy in India and we need to formulate a good one as soon as possible.

India must formulate effective Preventive and Offensive Cyber Capabilities to safeguard its Cyberspace and Critical Infrastructure, suggests Praveen Dalal, managing partner of New Delhi based techno legal firm Perry4Law and leading techno legal expert of India. India must develop Cyber Warfare Capabilities as soon as possible, suggests Dalal.

There is no doubt that Indian national security must have information warfare as an essential component. Taking clue from various suggestions of techno legal experts of India, the Manmohan Singh government is in the process of establishing a cyber command and control authority for India. This would be a centralised mechanism that would be placed under the National Security Adviser who reports to the PM.

This is a good step in the right direction, says Dalal. This was a much needed initiative that has, at last, got the attention of Indian Government. The only thing that remains to be seen is how effectively this initiative would be handled by Indian Government, says Dalal. Let us see how the National Security Adviser would proceed with this initiative.

Wednesday, May 11, 2011

Does World Bank Ensures Accountability To Its Loans?

I wrote a critical article titled “Does World Bank Sees What Happens To Its Loans?. For some strange reasons, this article of mine was censored by Google. Of late Google has been censoring views and opinions that are critical to Indian government. For instance, articles on Aadhar project and UIDAI are frequently censored by Google. Thanks to the draconian cyber law of India, this is now possible without following any due process in India. I am reposting this article so that Google can censor it one more time and I can repost it once again.

Loans are granted by international organisations and institutions for the development of a nation. But it is a rare occasion when such loans are actually utilised for the development of such nation. On the contrary, such loans just ensure the personal development of ministers and bureaucrats and common man never receives the benefits of such loans or grants.

Recently the World Bank and Indian government signed a loan agreement of $150 million for the e-delivery of public services in India. The loan has been granted as the e-delivery of public services development policy loan to be utilised under the national e-governance plan of India (NEGP). However, the bigger question is would this loan be utilised for the benefit of common man?

Keeping in mind the past record, the answer seems to be in negative. India has a poor track record of e-governance utilisation and providing of electronic delivery of services in India. We have no legal enablement of ICT systems in India and legal framework for e-delivery of services in India is also missing. In fact, as per e-governance experts of India, e-governance in India is dying. Without a mandatory e-governance services in India, e-delivery of services in India cannot be achieved.

According to Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India, “The Government and Indian Bureaucrats need to change their mindset and stress more upon outcomes and services rather than mere ICT procurement. India needs a services-based approach that is not only transparent but also backed by a more efficient and willing Government. Presently the Bureaucrats and Government of India are in a “resistance mode” towards novel and effective e-governance policies and strategies and they are merely computerising traditional official functions only. This is benefiting neither the Government nor the citizens and is resulting in wastage of thousands of crores of public money and United Nations Development Programme (UNDP) and World Bank Grants amount”.

“The Governmental will and leadership is missing in India. To worsen the situation the Government of India is concentrating more upon the image rather than upon the end results. The grassroots level action is missing and the benefits of ICT are not reaching to the under privileged and deserving masses due to defective ICT strategies and policies of Indian Government. India is suffering from the “vicious circle” of defective e-governance, as the basic input .i.e. governance itself is poor. India needs a “virtuous circle” of e-governance through good governance that would have multiplication and amplification effect upon e-governance efforts of Indian Government, says Praveen Dalal.

E-delivery of public services in India is missing and World Bank is not at all interested in establishing transparency and accountability in Indian NEGP. World Bank must ensure accountability of Indian NEGP in order to show that its loans are actually meant for growth and development of Indian masses rather than benefiting few politicians and bureaucrats as is happening right now.

The loans granted by World Bank must be tied up and accountable loans. These loans must be tied up with performance and achievement and must be released in stages only. Once the first stage is accomplished satisfactorily then only the next stage loan must be given.

However, neither World Bank nor Indian government is in a mood to actually utilise the granted loans for the betterment of Indian masses. Why and for whom these loans are granted would always remain a big question.

Monday, May 2, 2011

Electronic Banking In India

This is the updated version of my previous article on same topic. Electronic banking in India or e-banking in India is increasingly being used by both banks and customers alike. This brings mobility and convenience to both banks and customers. However, with the benefits there are drawbacks of e-banking as well. This article addresses some of these concerns.

Reserve Bank of India (RBI) has come across many complaints and disputes regarding fraudulent credit card, online banking and ATM transactions. Even phishing incidences have sharply arisen in India resulting in loss of money of public at large. RBI ombudsmen office has been flooded with such complaints.

In these circumstances, online banking in India is risky. We have no e-banking laws in India and this also makes the mobile banking in India risky. Even RBI has acknowledged risks of e-banking in India.

E-banking in India cannot succeed till a strong legal framework in this is enacted. According to Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India, we have no dedicated E-Banking Law in India. Although, RBI has issued many guidelines in this regard and even our Information Technology Act, 2000 contains some indirect and implied provisions for Internet or E-Banking yet we need a separate and dedicated law in this regard, opines Praveen Dalal.

Recently, G Gopalakrishna, the executive director of RBI, said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest, informs Dalal. This step was taken to ensure proper Cyber Security Policies and Strategies at the highest Board Level of Banks, says Dalal.

Although RBI has mandated cyber due diligence for banks in India especially the due diligence for banks under IT Act 2000 yet banks have still to keep their functions in order. Indian banks are poor at cyber security and they are in no mood to appoint CIOs and steering committee.

Recently the final report of working group of RBI on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds has been released. It has prescribed the time limits for implementation of RBI recommendations on information security. With the deterrent approach of RBI towards non compliance, it would be safe to presume that CIOs, steering committee and cyber security related compliances would also be taken seriously by RBI.

It is high time for banks operating in India to keep their e-banking infrastructure technologically and legally sound. The best option for banks seems to be to adopt Techno Legal Measures that covers both Technical and Legal aspects of Banking, suggests Dalal.

Monday, April 25, 2011

Draft Right To Privacy Bill 2011 Of India

The right to privacy bill 2011 of India may be the first attempt to regulate privacy related issues. However, as per media reports it seems to be more like a data protection initiative rather than a privacy safeguarding law.

India has created a problem for itself by neglecting the privacy protection requirements for long. India has been launching projects without any legal framework and procedural safeguards. For instance, we have projects like central monitoring system (CMS), national intelligence grid (Natgrid), Aadhar, crime and criminal tracking network and systems (CCTNS), etc that are not governed by any legal framework and procedural safeguards. Even we do not have any lawful interception law in India that can be claimed to be constitutionally sound.

According to Praveen Dalal, managing partner of New Delhi base law firm Perry4Law and leading techno legal expert of India, India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more, informs Dalal.

What is more surprising is the fact that the law enforcement agencies and the intelligence agencies that indulge in unconstitutional e-surveillance and phone tapping are themselves governed by no law. It is no surprise that the central bureau of India (CBI) is also not governed by any law and it is operating in India without any law. It is only now that the central bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the constitutional validity of the national investigation agency act 2008 is doubtful. Even the draft Intelligence Services (Powers and Regulations) Bill, 2011 has been recently circulated in the Parliament of India.

If the proposed privacy bill sees the light of the day, a data protection authority of India may be constituted. This authority must be constituted through an Indian regulatory services examination so that it can perform the challenging tasks that it would be entrusted with. For the time being, let us wait for the final draft of privacy bill available for public discussion.

Sunday, April 24, 2011

Indian Regulatory Services Examination In India

Regulatory bodies like securities and exchange board of India (SEBI), competition commission of India (CCI), cyber appellate tribunal (CAT), telecom regulatory authority of India (TRAI), proposed telecom security council of India (TSCI), etc requires domain specific experts to manage the same. Till now Indian government has been deputing its officers from its own departments to these regulatory bodies thereby undermining the required expertise.

In the past, Indian government has proposed Indian legal services examinations so that qualitative legal professionals can be produced in India. Now it has been felt that Indian regulatory services are needed in India. Institutions like Perry4Law Techno Legal Base (PTLB) are already providing training, education and research in these regulatory fields and many more techno legal fields.

Perry4Law and PTLB have been providing various techno legal trainings, education, research and coaching in India and world wide. Some of the areas covered by PTLB are continuing legal education in India, online lawyers and judges training in India, Indian legal services examinations training and education, Indian regulatory services examinations and trainings, etc.

PTLB provides Domain Specific and Highly Specialised Trainings in areas like Regulatory Services, Cyber Law, Cyber Forensics, E-Courts, Digital Evidencing, E-Discovery, etc, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and CEO of PTLB. We need “Domain Specific Experts” to manage different areas of Governmental Dealings, suggests Dalal.

Recently, Indian government proposed to constitute data protection authority of India (DPAI). The DPAI would require tremendous techno legal acumen as its areas of operations would be very large and challenging. The members of all regulatory bodies must have good techno legal expertise so that their functions can be performed in best possible manner.

With the proposal to introduce e-delivery of public services in India these regulatory authorities would have enhanced roles to perform. Even the department of information technology (DIT) has proposed a framework for citizens’ engagement in NEGP. Services of institutions like PTLB can be availed of under public private partnership (PPP) model for governmental projects and initiatives. Let us see how various proposals of Indian government would be actually executed.

Tuesday, April 12, 2011

Computer Security In India

Computer security is no more a luxury but an absolute necessity. In the present era, information and data is of extreme importance and value. We cannot allow strategic, sensitive, commercial and crucial data to be lost or stolen by cyber criminals.

From mere pranks, hobby and boasting, cyber crime has been transformed into a white collor and organised crime. Crime syndicates are actively engaging in identity theft, information stealing, data theft and so on. With the borderless and transborder nature of the crime, cyber crime is very difficult to pursue.

We have no computer security policy of India and we need one urgently. India has already been a victim of cyber attacks, cracking, cyber espionage, website defacements, etc and its cyberspace is highly vulnerable. India is facing a growing threat of cyber attacks and cyber crimes. In such circumstances, enacting strong cyber laws and establishing effective and robust cyber security is required.

National Security Policy of India is urgently required and Computer Security Policy of India must be an essential part of the same, says Praveen Dalal, managing partner of New Delhi based Law Firm Perry4Law and leading techno legal expert of India. Increasing Computer Security Readiness with Adaptive Threat Management is need of the hour, suggests Dalal. Further, Measurement of ICT Resilience and Robustness on regular basis is also required, suggests Dalal.

Further, another factor that is responsible for low level of computer security in India is that computer security research and development in India is lacking. We have a single and exclusive techno legal computer security research, training and education institution of India. The same is managed by Perry4Law and Perry4Law Techno Legal Base (PTLB). It is managing issues like cyber law, computer security, cyber war, cyber espionage, cyber forensics, etc.

So on the fronts of policy formulation, legislation making and computer security awareness, India needs to take some immediate steps. The present indifferent attitude of Indian government and Parliament of India is doing no good to Indian cyberspace. I hope some concrete actions would be taken by Indian government in these directions as soon as possible.

Sunday, March 27, 2011

Mandatory E-Governance Services In India

Legal framework for mandatory e-governance services in India is long due. If we make e-governance service optional or discretionary, the whole purpose would be defeated. This is the reason why we need time bound and accountable e-governance based public services in India.

Keeping this objective in mind, the central government formulated the draft electronic delivery of services bill 2011 (EDS Bill 2011). The EDS Bill 2011 intends to provide delivery of government services to all citizens by electronic means by phasing out of manual delivery of services delivered by the government including matters connected therewith or incidental thereto.

The Bill if made a law would require complete overhaul of the present e-governance infrastructure and services delivery mechanism of Indian government. However, the real problem with Indian e-governance initiative is that legal framework for mandatory electronic delivery of services in India is missing, says Praveen Dalal, Supreme Court lawyers and Managing Partner of India’s exclusive techno legal law firm Perry4Law.

Till now there was no provision under which citizens could ask for mandatory electronic delivery of services by the government. After the Bill becomes an enforceable law, the Indian Government would be under an obligation to mandatorily provide electronic services to its citizens, opines Dalal.

To effectuate this objective, high-level delegates from all ministries will be meeting next month to decide on a cut off date to switch to total e-governance. However, before introducing it in the Parliament, each ministry will assess its readiness and accordingly fix the timelines for mandatory electronic service delivery in India. However, no department will exceed a cut off date fixed for the country.

I wish this initiative would become reality very soon.

Saturday, March 26, 2011

Cyber Crime Policy Of India

Cyber crime is an area that requires policy formulation at the national level. In the Indian context, there is no national cyber crimes policy of India. In fact, cyber crime policy and strategies of India is so important that the issue must be taken up by the Prime Minister’s Office (PMO) of India. The present cyber law of India is not effective and PMO must ensure a new cyber law for India.

India needs to do extensive research on the legal and policy related issues pertaining to regulation of cyber crime at the national and global levels. Although India is not a signatory to the EU Convention on Cyber Crimes yet there is no reason for it to remain aloof from International Norms and Standards, says Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and a Supreme Court lawyer.

India has been lax regarding policy formulation for techno legal issues. For instance, there is no cyber security policy and strategy in India, no national security policy of India, no national security and ICT policy of India, no ICT policy in India, no national ICT crisis management plan of India, etc.

In this background, it is no surprise that we have no cyber crime policy in India as well. When issues like Cyber Terrorism, Cyber Warfare, Cyber Espionage, etc are troubling India, having no Cyber Crime Policy is not a good indication, cautions Dalal.

We must urgently formulate a good and effective Techno Legal Cyber Crime Policy for India, suggests Dalal. It is for the government of India to take the initiative as sooner or later it has to adopt ICT related policies for India. The sooner these policies are adopted the better it would be for the national interest of India.

EU Convention On Cyber Crime


European Union’s Convention on Cyber Crime is the first international treaty on cyber law. The treaty endeavours to regulate cyber crimes at international level by harmonising national laws, improving cyber crimes investigative techniques and increasing cooperation among nations. The treaty came into force on 1 July 2004.

On 1 March 2006 the Additional Protocol to the Convention on Cybercrime came into force. The additional protocol requires the States to punish as a criminal offence the dissemination of racist and xenophobic material through computer systems, as well as of racist and xenophobic-motivated threats and insults.

Among other things, the convention deals with infringements of copyright, computer-related fraud, child pornography and violations of network security. It also contains a series of powers and procedures such as the search of computer networks and lawful interception.

Although the objectives of the convention are praiseworthy, they have been by and large remained unfulfilled, says Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India. For instance, lawful interception laws are missing in most countries including India. Similarly, protecting children in cyberspace from various cyber crimes like cyber stalking, sexual abuses, etc is still an unfulfilled dream, informs Dalal. The truth is that cyberspace is still an unfriendly place for juveniles, says Dalal.

Similarly, on the front of civil liberties in cyberspace as well the convention failed to make much difference. For instance, there should be a balance between law enforcement requirements and civil liberties. However, in the name of national security, human rights are very frequently and openly violated by various nations, including India, informs Dalal.

International cyber law harmonisation is still an unfulfilled dream as various nations are not willing to cooperate in this regard. All nations have their own agendas and priorities that are preventing adoption of an internationally acceptable cyber law treaty.

International Cyber Crime Treaty And India

Cyber law is no more confined to the limits of a nation alone. Being extra territorial in nature, the cyber law of a nation often travels far beyond the territorial jurisdictions of a nation. Realising the practical difficulties of this extra territorial nature of various cyber law, an International cyber law treaty was formulated at the international level.

However, there is no relationship between this international cyber crime treaty and India as India is not a signatory to the same. India is still governed by its distinct cyber law incorporated in the information technology act, 2000 (IT Act 2000).

Recently, efforts were made at the United Nations (UN) to adopt a “more comprehensive” and “truly global” International cyber crime treaty, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India. However, the proposal was rejected by UN and till now there is no globally acceptable cyber crime treaty in existence, informs Dalal.

Even the Indian cyber law is far from perfect and it has decayed. It has been amended by the information technology amendment act 2008 (IT Act 2008) that made the sole cyber law of India a big mess. There are no stringent provisions to punish cyber criminals as almost all the cyber crimes have been made bailable by this amendment.

Presently, India is neither following a good model cyber law based upon international standards nor is legislating an effective law that can meet the challenges of contemporary digital economy.

The present cyber law of India is worst than no cyber law at all and it must be repealed as soon as possible. This is more so when India has decided not to sign any international cyber crime treaty and stick to its own domestic legislation.

Thursday, March 24, 2011

Cyber Terrorism In India And Its Preparedness

Cyber terrorism in India is no more a new concept. India has been facing constant cyber security attacks. Further, cyber terrorism attacks are also common in Indian cyberspace though their execution and detection is by and large unnoticeable and undetected in India.

Cyber terrorism is becoming a big nuisance for India and India has to be technologically as well as legally sound to tackle the same. There is an emergent need to amend the cyber law of India, i.e. Information Technology Act, 2000 (IT Act, 2000) in this regard as a single provision is not sufficient as per the cyber law experts.

Even there is no national ICT crisis management plan of India that is addressing the menace of cyber terrorism in India. The critical infrastructure of India has become vulnerable due to inadequate cyber security. This vulnerability can not only be exploited by cyber criminals but also be the cyber terrorists.

Securing the critical national infrastructure of India from cyber attacks should be a priority area for India. This requires formulating a cyber security policy of India that is presently missing. Without a cyber security policy and strategy of India, the cyber security initiatives of India are directionless.

Even there is no legal framework for cyber security in India. By incorporating a few ineffective and irrelevant provisions in the IT Act 2000, Indian government thinks that it has the cyber security law in India.

In fact, cyber terrorism preparedness must be an essential part of the homeland security of India. Homeland security of India must be strengthened and in order to do so we must take care of issues like cyber law, cyber security, cyber espionage, cyber terrorism, cyber warfare, etc.

Homeland Security is in infancy stage in India, says Praveen Dalal, Managing Partner of Perry4Law and leading techno legal expert of India. Further, India also needs a separate Framework for Cyber Security, Critical Infrastructure Protection (CIP), Cyber Terrorism, Cyber Warfare, Homeland Security issues, etc suggest Praveen Dalal.

Clearly, India has not yet taken enough initiatives to tackle the menace of cyber terrorism. Lack of legislative skills seems to be the main reason why India is running short of good and effective cyber legislations.

India must urgently enact a suitable cyber security policy and homeland security that clearly demarcates its preparedness to deal with growing menace of cyber attacks and cyber terrorism activities against India.

Friday, March 18, 2011

Securing Critical National Infrastructure From Cyber Attack

Cyber security in India has started gaining attention of Indian government. However, the cyber security initiatives of Indian government are still far from satisfactory. We do not have a cyber security policy in India that clearly stipulates the cyber security strategy of India.

Cyber security of India is also an essential part of National ICT Policy and Strategy of India. However, despite some very good suggestions by experts, India has not taken cyber security seriously. On the other hand, the International Community is focusing really hard to make cyber security an essential part of their day to day lives.

Internationally, it is an accepted fact that to ensure effective cyber security, there must be a coordinated and collaborative approach, metrics and assessment tools must be developed, an effective legal and policy framework for security must be created and the human dimension of security must be addressed.

Although there are numerous aspects of Cyber Security Policy of India yet Critical Infrastructure Protection in India is one of the most important aspects of the same, informs Praveen Dalal, leading techno legal expert of India and managing partner of New Delhi based techno legal law firm Perry4Law. The Critical National Infrastructure of India is under constant cyber attacks and India must urgently do something in this regard, informs Dalal.

Experts like Praveen Dalal also feel that India does not have strong and effective cyber laws to deal with issue pertaining to Critical Infrastructure. India is blind towards cyber law, cyber security and cyber forensics requirements. The IT Act, 2000 is a poorly drafted law and badly implemented legislation. It is weak and ineffective in dealing with growing Cyber Crimes in India as it is the most Soft and Cyber Criminal Friendly Legislation of the World.

Thus, on all the fronts of policy, legal framework and effective cyber security initiatives, India has failed to give proper attention. In these circumstances, critical national infrastructures of India are at grave cyber security risks. They are vulnerable to cyber threats and cyber attacks. India must urgently do something in this regard as soon as possible.