Monday, November 5, 2012

Cyber Forensics And Indian Approach


Cyber Forensics is an area that has not aroused much interest among the Governmental corridors of India. Even the Parliament of India and Indian Judiciary are not very enthusiastic about this much needed Science and Art.

Before I proceed further, it is pertinent to explain the concepts like “Cyber” or “Cyberspace” and “Cyber Forensics” as per my own understanding and with my own personal definitions.

In my opinion the word “Cyber” or “Cyberspace” signifies a “Combination of Information and Communication Technologies (ICT) that includes both Hardware and Software.

Similarly, according to me the word “Cyber Forensics” means “A Scientific and Forensics analysis of “Cyberspace” that includes ICT Components, Hardware and Software in such a manner that the end result is “Presentable and Admissible” in a Court of Law”.

Another concept that I would like to discuss pertains to Electronic Discovery (E-Discovery). According to me there is a difference between Cyber Forensics and E-Discovery. I believe that Cyber Forensics is a “Wider Concept” than E-Discovery. To put it on other words, Cyber Forensics includes E-Discovery but not Vice Versa.

For instance, a properly conducted Cyber Forensics Exercise is “Relevant and “Admissible” for all purposes including Litigation purposes. But E-Discovery may not be “Relevant” and “Admissible” while deciding a Criminal Litigation.

Now coming back to the Indian position, Cyber Forensics has not found favour with the Executive, Judiciary, Legislature and the Administrative Branches of India. We have no dedicated Cyber Forensics Laws in India. Even the Information Technology Act 2000 (IT Act 2000), which is the Cyber Law of India, is not covering Cyber Forensics. A going reference of Cyber Forensics may be found in the IT Act 2000 but that is nothing more than a reference with no actual “Utility” as on date.

This “Poor Condition” of Cyber Forensics in India is attributable to many factors. Firstly, we have no Legal Enablement of ICT Systems in India. Concepts like E-Courts, Online Dispute Resolution (ODR), etc are still missing in India. Secondly, the ICT Policies and Strategies of India are “Defective” and they do not cater the requirements of Cyber Law, Cyber Security, Cyber Forensics, etc. Thirdly, the Parliament of India is not “Comfortable” with ICT related issues. If Parliament is itself not aware of the Techno Legal Concepts like Cyber Law, Cyber Security, Cyber Forensics, etc not much development can take place.

I personally believe that Cyber Law of India should be repealed and a more comprehensive Cyber Law must be enacted. Similarly we need “Dedicated Laws” for Cyber Security and Cyber Forensics in India.

In my subsequent posts, I would try to cover every possible aspect of Cyber Forensics that is applicable to India and World Wide. Perry4Law and Perry4Law Techno Legal Base (PTLB) believe that this Blog would prove useful to all Stakeholders.

The Basics Of Internet Protocol (IP) Address System

An Internet Protocol (IP) Address is an important aspect of not only the World Wide Web (WWW)/Internet but is also required for conducting a successful Cyber Forensics Analysis. So it is important to have a basic knowledge about IP Address. In this Article I would try to cover the most significant aspects of IP Address and a detailed and technical analysis is beyond the scope of this Article.

Every Computer that communicates on the Internet is allotted a unique IP Address. Through this unique IP Address the “Identity” of the Individual may be established. However, there are exceptions to this case. For instance using of a Proxy Server may not reveal the true IP Address of the Individual. Similarly, IP Address Spoofing may not provide the correct details of the Computer that has been used to send the communication. 

There are two Standards for IP addresses i.e. IP Version 4 (IPv4) and IP Version 6 (IPv6). Presently, most Computers are using IPv4 but soon the same would be migrated to IPv6 as IPv4 is no more able to cope up with the growing demands of IP Addresses.

An IP Address can be either Static or Dynamic. Generally, a Static IP Address is one that your Administrator/ISPs allots and configures by editing your Computer's Network Settings. It produces a single and constant identifiable IP Address that can be easily attributable to the Computer using the same.

A Dynamic IP Address is assigned by the Dynamic Host Configuration Protocol (DHCP), a service running on the Network. DHCP typically runs on Network Hardware such as Routers or dedicated DHCP Servers. A Computer using Dynamic IP Address is allotted a new IP Address for each “New Session” during its “Lease Period”.

A single IP Address may further be shared by different Computers using a “Router”. If you use a Router to share an Internet connection, the Router gets the IP Address issued directly from the ISP. Then, it creates and manages a Subnet for all the Computers connected to that Router. The Router would get the External IP Address and the Computers connected to the Router would get Internal IP Addresses to further “Identify” each Individual Computer.

The most common locations for finding IP Addresses are Log Files, in the Received Header fields of an E-Mail, Tcpdump Traces, etc. In some circumstances only a Host Name must have been recorded, but this can simply be translated into an IP Address.

IP Addresses are the “First Step” in the Cyber Forensics Investigations. However, IP Tracking must be done with great caution and with good application of mind. A casual IP tracking exercise may not only provide wrong results but can also implicate an innocent person.  I would cover these issues in more detail in my subsequent articles.

Data Security Laws In India

The need and demand for data protection laws in India and data security laws in India are increasing. This is so because data protection and data security touches almost all the spheres of personal lives and business transactions.

India has remained indifferent towards data protection and data security for long. Now Indian government has shown some inclination towards ensuring a legal framework for data protection and privacy protection in India.

Data is the backbone of any society that primarily relies upon information and communication technology (ICT). Protection of data is both the personal and proprietary requirement of various individuals and institutions. This is the reason why data must be secured through techno legal means.

As on date, we have no dedicated Data Privacy Laws In India and Data Protection Law In India. Even a dedicated Privacy Law Of India is missing. There is an urgent need to formulate Techno Legal Data Security Laws In India, Cyber Security Law In India, Privacy Rights And Laws In India, etc. While formulating such laws, we must keep in mind that Privacy Rights In India In The Information Age are different from the traditional privacy requirements.

Data security is closely related to cyber security expertise. Thus, Cyber Security Issues In India need better and focused attention of Indian government as Managing India’s Cyber Security Problems is a very delicate and tedious task. In these circumstances, Indian Data Protection Laws Are Urgently Needed. We cannot ignore data Protection Laws In India and privacy rights in India anymore. Similarly, Encryption Laws And Regulation In India must also be formulated as soon as possible.

At the national policy levels as well the Indian government has to do lots of hard work. For instance, the Encryption Policy Of India Is Needed. Similarly, an implementable Cyber Security Policy Of India is also need of the hour.

Indian government has also suggested projects and initiatives like National Cyber Coordination Centre (NCCC) Of India, Central Monitoring System (CMS) Project Of India, National Intelligence Grid (Natgrid) Project Of India, etc that would require dealing with the data and information in a constitutional manner.

Clearly data security laws of India are urgently needed. The sooner they would be formulated the better it would be for the interest of various stakeholders in general and national interest of India in particular.

Source: Legal Enablement Of ICT Systems In India

IP Address Spoofing And Its Defenses

Internet Protocol Address (IP Address) plays a very significant role in our day to day lives. Whether it is Cyber Security or Cyber Forensics, IP Address has a crucial role to play. IP Address is also the Starting Point for any Cyber Crime Investigation. So it is of utmost importance that an IP Address must be correctly ascertained.

Similarly, the Crackers and Cyber Criminals are interested in hiding their “Digital Footprints” through various means. IP Spoofing, use of Proxies, utilising Botnet for nefarious activities, exploiting Unsecured Wireless Access Points and Connections, etc are some of the methods that are used by Cyber Criminals.

IP Address is also the starting point to determine the “Authorship Attribution” that is a must before an accused is “Convicted” by a Court of Law. For instance, if a single Computer of Internet connection is used by multiple users, it is absolutely essential to ascertain who in fact used the Computer/Connection for the “Offending Act”.

Similarly, it is absolutely essential to ensure that the owner of a Wireless Connection is actually the person who committed the Cyber Crime or Cyber Contravention. In the majority of cases, such an Unsecured Wireless Connection is misused by others and the IP Address of the owner is reflected for that activity.

Thus, Authorship Attribution is an important aspect of “Determining the Culpability” of an Offender where the means to commit the Offence are common and accessible to many people simultaneously. Data Mining and Profiling of the accused to “Attribute Culpability” to him/her alone is an emerging area of Cyber Crime Investigation.

IP Spoofing is one of the methods used by Cyber Criminals to deny “Authorship Attribution” to them. A Cyber Crime Investigator would first ascertain the IP Address and then after analysing the E-Mail Headers/Logs, She would come to a conclusion that the IP Address reflected in the communication is a Forged or Spoofed one. Ascertaining the true and correct IP Address is required to proceed further in such case. 

IP Address Spoofing requires creation of IP packets with a forged source IP Address with a purpose of concealing the real identity of the sender or impersonating another System. The most common Protocol for data exchange over Internet is the TCP/IP. The header of each IP Packet contains, among other things, the numerical source and destination address of the Packet. The source address is normally the address that the packet was sent from. By forging the header so it contains a different address, an attacker can make it appear that the packet was sent by a different Computer.

However, there is a “Limitation” to such a use. To establish a Connection, TCP uses a “Three Way Handshake” and IP Spoofing by its very nature fails to satisfy this handshake. So the purposes of IP Spoofing are limited in nature. For instance, IP Spoofing can be used for Denial of Service Attacks (DOS) as the attacker is least bothered to receive a “Response”. IP Spoofing can also be a method of attack used by network intruders to defeat network security measures, such as authentication based on IP Addresses. IP Spoofing can also be used for Session Hijacking or Host Impersonation.

There are some services that are vulnerable to IP Spoofing. These include RPC (Remote Procedure Call services), any service that uses IP address authentication, the X Window System, the R services suite (rlogin, rsh, etc.), etc.

IP Spoofing can take many forms. In Non-Blind Spoofing the attacker is on the same subnet as the victim and this enables him to perform session hijacking. Using this technique, an attacker could effectively bypass any authentication measures that have taken place to build a connection.

In Blind Spoofing several packets are sent to the target machine in order to sample sequence numbers. Computers in the past used basic techniques for generating sequence numbers. It was relatively easy to discover the exact formula by studying packets and TCP sessions. Today, most Operating Systems (OSs) implement random sequence number generation, making it difficult to predict them accurately.

In Man in the Middle Attack (MITM) the attacker intercepts a legitimate communication between two Computers. The malicious host then controls the flow of communication and can eliminate or alter the information sent by one of the original participants without the knowledge of either the original sender or the recipient. In this way, an attacker can fool a victim into disclosing confidential information by “Spoofing” the identity of the original sender, who is presumably trusted by the recipient.

There is a “General Consensus” that IP Spoofing does not allow gaining Anonymous Internet Access, which is a common misconception for those unfamiliar with the practice. Any sort of Spoofing beyond simple floods is relatively advanced and used in very specific instances such as evasion and connection hijacking.

However, some believe that if a Website is not using syncookies and is using predictable initial sequence numbers, it is possible to create a live TCP connection without actually revealing the original IP Address. This may be possible as the attacker may be least interested in getting back the “Responses”. I would deal with this issue separately and in greater details subsequently.

IP Spoofing can be prevented and defended against through methods like Packet Filtering, Websites using syncookies and unpredictable initial sequence numbers, use of multiple authentication protocols so that they do not exclusively rely on the IP Address for authentication, use of Encryption, etc.

Some upper layer protocols provide their own defense against IP Spoofing attacks. For example, TCP uses sequence numbers negotiated with the remote machine to ensure that arriving packets are part of an established connection. Since the attacker normally cannot see any reply packets, the sequence number must be guessed in order to hijack the connection. The poor implementation in many older operating systems and network devices, however, means that TCP sequence numbers can be predicted.

There is an urgent need to do more in depth research in the field of IP Spoofing and I would try to cover this field in great details in my subsequent posts.

Cyber And High Tech Crime Investigation And Training Centre

In this post we are discussing about the Cyberand Hi-Tech Crime Investigation and Training (CHCIT) Centre of India managed by Perry4Law Techno Legal Base (PTLB). This is the exclusive techno legal cyber and hi-tech crime investigation and training centre of India that is managing both technical and legal issues of cyber crimes and high tech crimes.

Techno legal issues especially cyber crimes and cyber security issues in India are complicated to manage and tackle. Countries all over the world are struggling to deal with the same. Even in India we have to cover a long road before expertise pertaining to cyber security in India and cyber forensic in India can be achieved.

Research and development plays a major role in developing cyber security capabilities. It is also crucial to develop methods to fight against cyber crimes and cyber attacks. Private initiatives like cyber security research centre of India (CSRCI), cyber forensics research and development centre of India (CFRDCI), cyber crimes investigation centre of India (CCICI), etc are crucial in this regard.

At Perry4Law and PTLB we are managing the exclusive techno legal cyber crime and high tech investigation and training centre of India. We are also managing the exclusive techno legal centre of excellence for cyber crimes investigation in India.

Further, in order to inculcate techno legal skills among police, lawyers, judges, professionals, etc we have been managing the exclusive techno legal centre of excellence for lifelong learning in India where we are providing trainings, courses and education in the fields like cyber law, cyber security, cyber forensics, etc. PTLB e-learning platform further helps in achieving this objective.

The cyber crimes investigation centre of India by PTLB aims at developing techno legal skills among cyber crime investigators on the pone hand and modernisation of police force of India on the other. We provide cyber crimes investigation trainings in India to various stakeholders.

Perry4Law and PTLB have also provided cyber crimes trends in India 2012, cyber law trends in India 2012, cyber security trends in India 2012, etc. Previous years trends have also been provided by Perry4Law and PTLB to give various stakeholders a good look of cyber environment of India. 

We have been providing ICT trends in India since 2005-06. The ICT trends in India 2009 and subsequent trends have discussed both the positive and negative aspects of Indian ICT policies and strategies.

We hope that this exclusive techno legal cyber crime investigation centre of India would prove useful to all stakeholders in India and abroad.

Cyber Security Council Of India Established

This article has reported that a cyber security council of India has been constituted by Indian government. We at Perry4Law Techno Legal Base (PTLB) welcome this move of Indian government as it was a much needed initiative. 

According to the report published by my colleague, the cyber security council of India has been constituted by Indian government. This is a good step in the right direction as such an action was long due on the part of Indian government.

Although this is a modest beginning yet if Indian government is committed this can transform into a major cyber security initiative by Indian government. I am hereby sharing the report of my friend for our readers.

Cyber security of India has finally got the attention of Indian government. Indian government has been announcing many initiatives that could strengthen cyber security of India. Although these initiatives have come late yet this is a good beginning from all counts.

Now it has been reported that the Indian government has launched a new and dedicated wing of the country's National Security Council Secretariat (NSCC). The function of the proposed wing would be to deal with the growing cyber threat especially those from cyber terrorists.

Cyber terrorism against India, cyber warfare against India, cyber espionage against India, etc are on rise and this dedicated wing can be really helpful in this regard. The wing would coordinate with other existing law enforcement agencies. The objective of the wing would be to keep both public and private computer safe from cyber attack and malicious activities.

The proposed wing would work in the direction of ensuring coordination among various government departments of India so that both national and international cyber threats can be countered. Gradually the wind would be extended to make its initiatives and efforts more holistic and wide.

However, India still needs to stress upon cyber security research and development. Till now we have a sole techno legal cyber security research centre of India that is managed by Perry4Law and PTLB.


Close association and coordination with expert techno legal institutions like PTLB is the need of the hour. Let us hope that Indian government would collaborate and coordinated with institutions like PTLB to make its cyber security initiatives more holistic and effective.

Data Protection Laws In India

We have no dedicated data protection laws in India. Data of individuals and companies require both constitutional as well as statutory protection. The constitutional analysis of data protection in India has still not attracted the attention of either Indian individuals/companies nor of Indian government.

The statutory aspects of data protection in India are scattered under various enactments. The Information Technology Act 2000 (IT Act 2000), which is the cyber law of India, also incorporate few provisions regarding data protection in India. However, till now we have no dedicated statutory and constitutional data privacy laws in India and data protection law in India.

Further, we do not have a dedicated privacy law in India as well. Privacy rights in India are still not recognised although the Supreme Court of India has interpreted Article 21 of Indian constitution as the source of privacy rights in India. Just like data protection, provisions pertaining to privacy laws in India are also scattered in various statutory enactments. Privacy rights and laws in India need to be strengthened keeping in mind the privacy rights in India in the information age.

Another related aspect pertains to data security in India. In the absence of proper data protection, privacy rights and cyber security in India, data security in India is also not adequate. Further, we do not have a dedicated cyber security law in India as well.

Perry4Law and Perry4Law Techno Legal Base (PTLB) believe that data protection requirements are essential part of civil liberties protection in cyberspace. With the growing use of information and communication technology (ICT), data protection requirement has become very important. It would not be wrong to assume privacy and data protection rights as integral part of human rights protection in cyberspace.

Perry4Law and PTLB believe that Indian government must formulate different laws for privacy, data protection and data security. The IT Act 2000 has already committed the mistake of incorporating all cyberspace related aspects at a single place. This has resulted in a chaos and we have no effective law for any aspect of cyberspace.

Perry4Law and PTLB suggest that India government must formulate separate laws for issues like privacy, data security and data protection.

Source: Corporate Laws In India

Legal Formalities Required For Starting E-Commerce Business In India

E-commerce laws and regulations in India are still evolving. This has created a sort of confusion and uncertainty among e-commerce entrepreneurs in India. While some have opened e-commerce outlets through websites others are exploring a more appropriate and legal way of running an e-commerce business in India.

Legal issues of e-commerce in India vary as per different business models. For instance, electronic trading of medical drugs in India requires more stringent e-commerce and legal compliances as compared to other e-commerce activities. Digital communication channels for drugs and healthcare products in India are scrutinised more aggressively than other e-commerce activities. In fact, regulatory and legislative measures to check online pharmacies trading in banned drugs in India are already in pipeline.

Besides there are many legal formalities that are required in order to start a company and e-commerce activity in India. A business can be operated as:

(1) Sole Proprietorship.

(2) Partnership.

(3) Company – Public/Private.

(4) Limited Liability Partnerships (LLP).

Mostly people decide to open a private company to substantiate an e-commerce activity and this article would cover that aspect alone. To incorporate a private limited company you must approve its name, registered office address, have at least 2 directors with director identification numbers (DINs), must have a minimum authorised capital of Rs. 1 Lakh, memorandum of association (MOA) and articles of association (AOA), digital signature certificates (DSCs) wherever applicable, etc. Once these conditions and requirements are fulfilled, a certificate of incorporation is sent by post to the registered office of the newly registered company.

The private limited company is also required to comply with income tax related compliances. These include obtaining permanent account number (PAN), tax deduction account number (TAN), value added tax (VAT) registration and obtaining of tax identification number (TIN), professional tax if applicable, service tax, etc.

In certain cases, compliance with labour laws is also required. For instance, the Shops and Establishment Act is a legislation implemented by various States in India. The Act lays down mutual statutory obligation and rights of employers and employees. Registration of shop/establishment is mandatory within 30 days of commencement of work. Other workmen and labour related legislations cover areas like employees provident fund, employees state insurance, etc.

However, e-commerce in India is also required to be conducted in a legally permissible manner. This is more so when the information technology act 2000 (IT Act 2000) prescribes stringent penal and pecuniary penalties for violation of its provisions during e-commerce transactions.

The e-commerce players must ensure cyber law due diligence in India. This is more so when the cyber law due diligence for companies in India has become very stringent and foreign companies and websites are frequently prosecuted in India for non exercise of cyber due diligence.

The legal requirements for undertaking e-commerce in India also involve compliance with other laws like contract law, Indian penal code, etc. Further, online shopping in India also involves compliance with the banking and financial norms applicable in India. For instance, take the example of PayPal in this regard. If PayPal has to allow online payments receipt and disbursements for its existing or proposed e-commerce activities, it has to take a license from Reserve Bank of India (RBI) in this regard. Further, cyber due diligence for Paypal and other online payment transferors in India is also required to be observed.

Perry4Law and Perry4Law Techno Legal Base (PTLB) wish all the best to all e-commerce players in India and abroad.

FDI In Non-Banking Finance Companies (NBFC) Sector Of India Under Consolidated FDI Policy Of India 2012

This is in continuance of our series on Consolidated FDI Policy of India 2012 by DIPP. In this article Perry4Law and Perry4Law Techno Legal Base (PTLB) would discuss the FDI in Non-Banking Finance Companies (NBFC) sector of India under the consolidated FDI policy of India 2012.

FDI in Non-Banking Finance Companies (NBFC) is allowed up to 100% under the automatic route in only the following activities:

(i) Merchant Banking
(ii) Under Writing
(iii) Portfolio Management Services
(iv) Investment Advisory Services
(v) Financial Consultancy
(vi) Stock Broking
(vii) Asset Management
(viii) Venture Capital
(ix) Custodian Services
(x) Factoring
(xi) Credit Rating Agencies
(xii) Leasing & Finance
(xiii) Housing Finance
(xiv) Forex Broking
(xv) Credit Card Business
(xvi) Money Changing Business
(xvii) Micro Credit
(xviii) Rural Credit


The other conditions in this regard are:

(1) Investment would be subject to the following minimum capitalisation norms:
(i) US $0.5 million for foreign capital up to 51% to be brought upfront
(ii) US $ 5 million for foreign capital more than 51% and up to 75% to be brought upfront

(iii) US $ 50 million for foreign capital more than 75% out of which US$ 7.5 million to be brought upfront and the balance in 24 months.
(iv) 100% foreign owned NBFCs with a minimum capitalisation of US$ 50 million can set up step down subsidiaries for specific NBFC activities, without any restriction on the number of operating subsidiaries and without bringing in additional capital. The minimum capitalization condition shall not apply to downstream subsidiaries.

(v) Joint Venture operating NBFCs that have 75% or less than 75% foreign investment can also set up subsidiaries for undertaking other NBFC activities, subject to the subsidiaries also complying with the applicable minimum capitalisation norm mentioned in (i), (ii) and (iii) above and (vi) below.

(vi) Non- Fund based activities : US $0.5 million to be brought upfront for all permitted non-fund based NBFCs irrespective of the level of foreign investment subject to the following condition:
It would not be permissible for such a company to set up any subsidiary for any other activity, nor it can participate in any equity of an NBFC holding/operating company.

The following activities would be classified as Non-Fund Based activities:

(a) Investment Advisory Services
(b) Financial Consultancy
(c) Forex Broking
(d) Money Changing Business
(e) Credit Rating Agencies
(vii) This will be subject to compliance with the guidelines of RBI.
(i) Credit Card business includes issuance, sales, marketing and design of various payment products such as credit cards, charge cards, debit cards, stored value cards, smart card, value added cards etc.

(ii) Leasing & Finance covers only financial leases and not operating leases.
(2) The NBFC will have to comply with the guidelines of the relevant regulator/s, as applicable.

FDI In Banking Sector Of India Under Consolidated FDI Policy Of India 2012

This is in continuance of our series on Consolidated FDI Policy of India 2012 by DIPP. In this article Perry4Law and Perry4Law Techno Legal Base (PTLB) would discuss the FDI in banking sector of India under the consolidated FDI policy of India 2012.

FDI in private banking sector of India is allowed up to 74% where FDI up to 49% is allowed through automatic route and FDI beyond 49% but up to 74% is allowed through government approval route.

These conditions must also be satisfied in this regard:
(1) This 74% limit will include investment under the Portfolio Investment Scheme (PIS) by FIIs, NRIs and shares acquired prior to September 16, 2003 by erstwhile OCBs, and continue to include IPOs, Private placements, GDR/ADRs and acquisition of shares from existing shareholders.

(2) The aggregate foreign investment in a private bank from all sources will be allowed up to a maximum of 74 per cent of the paid up capital of the Bank. At all times, at least 26 per cent of the paid up capital will have to be held by residents, except in regard to a wholly-owned subsidiary of a foreign bank.

(3) The stipulations as above will be applicable to all investments in existing private sector banks also.

(4) The permissible limits under portfolio investment schemes through stock exchanges for FIIs and NRIs will be as follows:
(i) In the case of FIIs, as hitherto, individual FII holding is restricted to 10 per cent of the total paid-up capital, aggregate limit for all FIIs cannot exceed 24 per cent of the total paid-up capital, which can be raised to 49 per cent of the total paid-up capital by the bank concerned through a resolution by its Board of Directors followed by a special resolution to that effect by its General Body.

(a) Thus, the FII investment limit will continue to be within 49 per cent of the total paid-up capital.

(b) In the case of NRIs, as hitherto, individual holding is restricted to 5 per cent of the total paid-up capital both on repatriation and non-repatriation basis and aggregate limit cannot exceed 10 per cent of the total paid-up capital both on repatriation and non-repatriation basis. However, NRI holding can be allowed up to 24 per cent of the total paid-up capital both on repatriation and non-repatriation basis provided the banking company passes a special resolution to that effect in the General Body.

(c) Applications for foreign direct investment in private banks having joint venture/subsidiary in insurance sector may be addressed to the Reserve Bank of India (RBI) for consideration in consultation with the Insurance Regulatory and Development Authority (IRDA) in order to ensure that the 26 per cent limit of foreign shareholding applicable for the insurance sector is not being breached.

(d) Transfer of shares under FDI from residents to non-residents will continue to require approval of RBI and Government as per para 3.6.2 above as applicable.
(e) The policies and procedures prescribed from time to time by RBI and other institutions such as SEBI, D/o Company Affairs and IRDA on these matters will continue to apply.

(f) RBI guidelines relating to acquisition by purchase or otherwise of shares of a private bank, if such acquisition results in any person owning or controlling 5 per cent or more of the paid up capital of the private bank will apply to non-resident investors as well.

(ii) Setting up of a subsidiary by foreign banks

(a) Foreign banks will be permitted to either have branches or subsidiaries but not both.
(b) Foreign banks regulated by banking supervisory authority in the home country and meeting Reserve Bank‘s licensing criteria will be allowed to hold 100 per cent paid up capital to enable them to set up a wholly-owned subsidiary in India.

(c) A foreign bank may operate in India through only one of the three channels viz., (i) branches (ii) a wholly-owned subsidiary and (iii) a subsidiary with aggregate foreign investment up to a maximum of 74 per cent in a private bank.

(d) A foreign bank will be permitted to establish a wholly-owned subsidiary either through conversion of existing branches into a subsidiary or through a fresh banking license. A foreign bank will be permitted to establish a subsidiary through acquisition of shares of an existing private sector bank provided at least 26 per cent of the paid capital of the private sector bank is held by residents at all times consistent with para (i) (b) above.

(e) A subsidiary of a foreign bank will be subject to the licensing requirements and conditions broadly consistent with those for new private sector banks.

(f) Guidelines for setting up a wholly-owned subsidiary of a foreign bank will be issued separately by RBI.

(g) All applications by a foreign bank for setting up a subsidiary or for conversion of their existing branches to subsidiary in India will have to be made to the RBI.

(iii) At present there is a limit of ten per cent on voting rights in respect of banking companies, and this should be noted by potential investor. Any change in the ceiling can be brought about only after final policy decisions and appropriate Parliamentary approvals.

FDI in public banking sector of India is allowed up to 20% (FDI and Portfolio Investment) through government approval route subject to Banking Companies (Acquisition and Transfer of Undertakings) Acts 1970/80. This ceiling (20%) is also applicable to the State Bank of India and its associate Banks.

Source: Corporate Laws In India

FDI In Pharmaceuticals Sector Of India Under Consolidated FDI Policy Of India 2012


This is in continuance of our series on Consolidated FDI Policy of India 2012 by DIPP. In this article Perry4Law and Perry4Law Techno Legal Base (PTLB) would discuss the FDI in Pharmaceuticals sector of India under the consolidated FDI policy of India 2012.

FDI in Greenfield is allowed up to 100% through automatic route. FDI in Existing Companies is allowed up to 100% through government approval route.

Draft Payment System Vision Document 2012-15 Of RBI

Reserve Bank of India (RBI) is trying really hard to streamline the payment system of India. This is more so regarding the online payment system that needs urgent reforms in India. For instance, RBI has issued guidelines pertaining to national electronic funds transfer (NEFT) system of India but banks in India are not providing positive confirmations of NEFT transactions.  

Similarly Internet banking guidelines in India by RBI have also been issued. However, by and large, cyber security for banking industry of India is not taken seriously in India. Even RBI has warned Indian banks for inadequate cyber security adoption.

Another area that requires urgent attention pertains to mobile banking security. Mobile banking cyber security in India is still an ignored world. In such circumstances adoption of mobile banking in India is a risky policy decision.

Recently, a report of RBI working group on securing card present transaction was also released. Now RBI has released the draft Payment System Vision Document 2012-15 for public consultation. Comments can be sent by email by 31 July, 2012.

The Payments System Vision Document 2012-15 envisages by ways and means of ensuring that “payment and settlement systems in the country are safe, efficient, interoperable, authorised, accessible, inclusive and compliant with international standards”. Accordingly, it proposes to “proactively encourage electronic payment systems for ushering in a less-cash society in India” as its Vision.

The Reserve Bank had earlier published a Vision Document outlining the course of action that would be undertaken in the field of payment and settlement systems over a three year period. The tasks laid out in the above document have been completed to a large extent. The new Vision Document intends to take the Mission further to meet the growing payment needs of the nation.

Source: Corporate Laws In India

HIPAA Compliances Services in India

Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of the most important health related legislations of United States (US). HIPPA ensures health care coverage, privacy protection, electronic information security, and fraud prevention regarding health care related issues.

Although we have no dedicated laws like HIPPA in India yet many outsourcing related services and assignments are still sent to India. Outsourcing of healthcare services to India, such as medical transcription, medical billing medical coding and medico-legal services involves the transfer and maintenance of important data are some of the areas that are managed by Indian BPO/LPO/KPO service providers of India.

However, HIPPA outsourcing services have also brought many techno legal risks that BPO/LPO/KPO service providers must take care of. Further, privacy, data security and cyber security issues have also made the scenario complicated.

Perry4Law firmly believes that these techno legal risks and compliances must be taken seriously by all stakeholders. We also believe that Indian government must pay more attention to areas like privacy, data security, data protection, cyber security, etc.

HIPPA compliance in India cannot be achieved till professionals are provided techno legal trainings regarding HIPPA. Perry4Law Techno Legal Base (PTLB) has been providing various techno legal trainings in India and abroad that include HIPPA trainings in India as well.

HIPPA compliance in India would also be required to be ensured by pharmaceutical e-commerce providers of India. Besides fulfilling the legal requirements for starting e-commerce business in India, medicines and drugs e-commerce providers of India must also comply with the requirements pertaining to websites opening in India. Cyber law due diligence in India is also required to be fulfilled by HIPAA stakeholders of India.

We hope all stakeholders would ensure HIPPA compliances in India in true letter and spirit.

Source: Corporate Laws In India

Consolidated FDI Policy Of India 2012

It is very cumbersome and inconvenient to report all links to our previous posts on the topic consolidated FDI policy of India 2012 in every subsequent post. Therefore, Perry4Law and Perry4Law Techno Legal Base (PTLB) have decided to report the previous posts in this regard at this post.

This post would act as the base for all previous posts on this topic and we would keep on updating this post from time to time to make it updated, holistic and composite. We hope our readers would find this arrangement more useful and convenient.

Till now we have covered the following posts in this regard:

















Source: PTLB Blog

New FDI Norms And Regulations For Pharmaceutical Sector Of India 2012

The consolidated FDI policy of India 2012 by DIPP is proactive on many counts and it covers vast areas of public importance. One such area pertains to FDI in pharmaceuticals sector of India.

Recently, India has been taking special interest in FDI in pharmaceutical companies producing life saving drugs in India. This is also somewhat controversial and complicated in nature. Many FDI proposals in this category are still pending to be cleared by Indian government and its agencies.

In order to expedite the pending FDI proposals for pharmaceutical industry of India, the Indian government is planning to announce fresh norms and rules in this regard next week.

The Foreign Investment Promotion Board (FIPB) in its meeting on July 20 is planning to consider FDI proposals for the pharmaceutical sector. It is also expected that the Department of Industrial Policy and Promotion (DIPP) would notify the new rules soon as the inter-ministerial group (IMG) has finalised its recommendations.

IMG has addressed concerns of the health ministry and recommended stiff riders defining the quantity of generic drugs that foreign companies manufacture in India. Further, it has prescribed norms for higher investment in research and development activities by such companies. It has also suggested doing away with the mandatory clause of technology transfer by the foreign company in brownfield investment.

In a significant and parallel development, Unites States has accused India of WTO rules violations. The accusation arose out of the activities of Hyderabad-based Natco Pharma that is making generic version of cancer drug Nexavar.

India government has invoked the compulsory licensing provision that allowed Natco to sell Nexavar at a price not exceeding Rs 8,880 for a pack of 120 tablets required for a month's treatment as compared to a whopping Rs 2.80 lakh per month charged by Bayer for its patented Nexavar drug. India has also defended its stand and claims that its decision does not violate any WTO norms.

Source: Corporate Laws In India

Patents Registration In India


Patents registration in India is a complicated process that requires thorough knowledge of Indian Patent Act and other legal formalities. Once registered, patents confer tremendous tangible and intangible benefits. It is always required to get your inventions patented as soon as possible without public disclosure of the same.

The starting point for the same is to file a patent application at the concerned patent office of your jurisdiction. After filing of the patent application, a request for examination is required to be made by the applicant or by third party and thereafter it is taken up for examination by the patent office.

Usually, the first examination report is issued and the applicant is given an opportunity to correct the deficiencies in order to meet the objections raised in the said report. The applicant must comply with the requirements within the prescribed time otherwise his application would be treated as deemed to have been abandoned. 

When all the requirements are met, the patent is granted and notified in the patent office journal. However before the grant of patent and after the publication of application, any person can make a representation for pre-grant opposition.

Once a patent is granted, a patentee enjoys exclusive right to prevent a third party from an unauthorised act of making, using, offering for sale, selling or importing the patented product or process within the country during the term of the patent. A patented invention becomes free for public use after expiry of the term of the patent or when the patent ceases to have effect on account of non-payment of renewal fee.

Import Of Mobiles Or Cell Phones In India With Fake IMEI Proposed To Be Banned

We have no dedicated cell phone laws in India or mobile phone laws in India though they are very much required. Similarly, we have no mobile cyber security in India and mobile connections and handsets are vulnerable to cyber attacks and malware infections.

We also do not have any electronic authentication policy of India and many e-surveillance oriented projects like Aadhar project of India are managed in India without any parliamentary oversight and legislative framework. This is definitely violation of privacy rights of Indians. We must also have a national policy for mobile governance and e-authentication in India.

However, Indian government is least bothered to mange these crucial fields. Indian government becomes active in these fields only when its own interests are at stake. For instance, India is getting stricter regarding false IMEI numbers and norms. This is because India is finding it difficult to indulge in e-surveillance with false IMEI capable mobile sets.

Now media reports have suggested that the telecom regulator TRAI is planning to approach the Commerce and Industry Ministry to ban imports of mobile phones carrying unauthentic unique IMEI identification number, which helps authorities track users.

In order to archive this task, TRAI would soon write to the Commerce Ministry to ban such phones. It has been suggested that import of only those cell phones should be allowed which are certified by GSMA and TIA authorised bodies for GSM and CDMA handsets respectively.

Further, the Department of Telecom (Govt of India) (vide reference NO-20-40/2006/BS-III(PT)(VOL.I)/201 dated 3rd September 2009), has directed all cellular mobile service providers not to allow calls to be made from Mobile handsets with invalid IMEI number after 30th Nov 2009. However, during a recent test conducted in a telecom service area, government officials were surprised to see over 18,000 mobile handsets using same IMEI number.

Besides IMEI numbers, Indian government is also serious of regulating pre paid SIM cards so that they may not be misused by criminals and terrorists. However, Indian government must a take a holistic action in this regard and mere piecemeal actions, that also those serving its own interest, would not be in the larger interest of India.

Source: Corporate Laws In India

Implementation Of The Madrid Protocol In India

The Trade Marks Act, 1999 (TMA 1999) and the corresponding Trade Marks Rules, 2002 (TMR 2002) is the law that regulates trademarks registration and protection in India. Similarly, the law also prescribes a procedure for filing of a convention application under Indian trademark law.

At the international level, the international registration of trademarks under Madrid Agreement and Madrid Protocol are also possible. However, India is not a party to Madrid Agreement. This is the reason why the Madrid Protocol becomes important for India.

The Madrid Protocol was adopted to render the Madrid system more flexible and more compatible with the domestic legislations of certain countries which had not been able to accede to the Madrid Agreement. India is one such country that has not acceded to the Madrid Agreement. The two treaties are parallel and independent and States may adhere to either of them or to both.

The Madrid Agreement and Madrid Protocol and their applicability and implementation in India are still missing as India is neither a party to Madrid Agreement nor it has ratified or acceded to Madrid Protocol. Although India has enacted the Trademark (Amendment) Act, 2010 yet the same has not been notified so far. In the absence of the same, the proposed Act has no applicability in India. 

However, some hints have been given by Indian government that Madrid Protocol may be implemented in India. If this is the intention of Indian government, both advantages and disadvantages of Madrid Protocol should be analysed in detail before acceding to the same.

Source: Corporate Laws Of India