Sunday, May 15, 2011

Cyber Command And Control Authority Of India

Cyber security is an issue that has always been ignored by India. As a result, cyber security of India is in a poor condition. Cyber security is not mere formulation of policies but their actual implementation. At this level of implementation, Indian government fails miserably as it lacks the techno legal skill necessary to implement cyber security policies.

India needs skilled techno legal professionals who can implement the cyber security policy of India. As a matter of fact, till now we have no cyber security policy in India and we need to formulate a good one as soon as possible.

India must formulate effective Preventive and Offensive Cyber Capabilities to safeguard its Cyberspace and Critical Infrastructure, suggests Praveen Dalal, managing partner of New Delhi based techno legal firm Perry4Law and leading techno legal expert of India. India must develop Cyber Warfare Capabilities as soon as possible, suggests Dalal.

There is no doubt that Indian national security must have information warfare as an essential component. Taking clue from various suggestions of techno legal experts of India, the Manmohan Singh government is in the process of establishing a cyber command and control authority for India. This would be a centralised mechanism that would be placed under the National Security Adviser who reports to the PM.

This is a good step in the right direction, says Dalal. This was a much needed initiative that has, at last, got the attention of Indian Government. The only thing that remains to be seen is how effectively this initiative would be handled by Indian Government, says Dalal. Let us see how the National Security Adviser would proceed with this initiative.

Wednesday, May 11, 2011

Does World Bank Ensures Accountability To Its Loans?

I wrote a critical article titled “Does World Bank Sees What Happens To Its Loans?. For some strange reasons, this article of mine was censored by Google. Of late Google has been censoring views and opinions that are critical to Indian government. For instance, articles on Aadhar project and UIDAI are frequently censored by Google. Thanks to the draconian cyber law of India, this is now possible without following any due process in India. I am reposting this article so that Google can censor it one more time and I can repost it once again.

Loans are granted by international organisations and institutions for the development of a nation. But it is a rare occasion when such loans are actually utilised for the development of such nation. On the contrary, such loans just ensure the personal development of ministers and bureaucrats and common man never receives the benefits of such loans or grants.

Recently the World Bank and Indian government signed a loan agreement of $150 million for the e-delivery of public services in India. The loan has been granted as the e-delivery of public services development policy loan to be utilised under the national e-governance plan of India (NEGP). However, the bigger question is would this loan be utilised for the benefit of common man?

Keeping in mind the past record, the answer seems to be in negative. India has a poor track record of e-governance utilisation and providing of electronic delivery of services in India. We have no legal enablement of ICT systems in India and legal framework for e-delivery of services in India is also missing. In fact, as per e-governance experts of India, e-governance in India is dying. Without a mandatory e-governance services in India, e-delivery of services in India cannot be achieved.

According to Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India, “The Government and Indian Bureaucrats need to change their mindset and stress more upon outcomes and services rather than mere ICT procurement. India needs a services-based approach that is not only transparent but also backed by a more efficient and willing Government. Presently the Bureaucrats and Government of India are in a “resistance mode” towards novel and effective e-governance policies and strategies and they are merely computerising traditional official functions only. This is benefiting neither the Government nor the citizens and is resulting in wastage of thousands of crores of public money and United Nations Development Programme (UNDP) and World Bank Grants amount”.

“The Governmental will and leadership is missing in India. To worsen the situation the Government of India is concentrating more upon the image rather than upon the end results. The grassroots level action is missing and the benefits of ICT are not reaching to the under privileged and deserving masses due to defective ICT strategies and policies of Indian Government. India is suffering from the “vicious circle” of defective e-governance, as the basic input .i.e. governance itself is poor. India needs a “virtuous circle” of e-governance through good governance that would have multiplication and amplification effect upon e-governance efforts of Indian Government, says Praveen Dalal.

E-delivery of public services in India is missing and World Bank is not at all interested in establishing transparency and accountability in Indian NEGP. World Bank must ensure accountability of Indian NEGP in order to show that its loans are actually meant for growth and development of Indian masses rather than benefiting few politicians and bureaucrats as is happening right now.

The loans granted by World Bank must be tied up and accountable loans. These loans must be tied up with performance and achievement and must be released in stages only. Once the first stage is accomplished satisfactorily then only the next stage loan must be given.

However, neither World Bank nor Indian government is in a mood to actually utilise the granted loans for the betterment of Indian masses. Why and for whom these loans are granted would always remain a big question.

Intellectual Property Rights Services In India

Intellectual property rights in India (IPRs in India) need no introduction. These include areas like copyright, trademarks, patents, geographical indications, semiconductor protection, domain name protection, etc. Even IPRs services of India are world renowned. We have professionals and firms that are world renowned for providing world class IPRs services in India.

However, today’s IPR environment has become techno legal in nature. IP Professionals of India must be well versed with both technical and legal aspects of IPRs. Technological issues of IPRs in India are difficult to understand and apply. Cyber crimes are affecting IPRs like trade secrets and data protection severely. Techno legal IPR skill development in India is the need of the hour.

Similarly, legal process outsourcing in India (LPO in India) and knowledge process outsourcing in India (KPO in India) pertaining to IPRs is also required to be tuned up. LPO and KPO is no more a simple clerical work. They now require expertise that very few firms can provide.

Perry4Law and Perry4Law Techno Legal Base (PTLB) specialise in Techno Legal IPR Services. Further, PTLB is also managing the exclusive techno legal IPR LPO and KPO of India. PTLB is also providing exclusive techno legal ICT and IPR skill development in India.

While the IPR field is thriving upon innovation yet IPRs service providers are themselves have to be more innovative to cater the service requirements of these IP owners. PTLB manages one such resource that provides innovative IPR LPO, KPO and techno legal services to clients worldwide.

If you are interested in the techno legal intellectual property rights services in India and abroad, keep a close watch upon the IP Blog of PTLB. The Blog is covering areas like copyright, trademarks, patents, traditional knowledge, semiconductor industry, geographical indications, etc.

Further, if you are interested in great IPR LPO and KPO services in India and world wide, Perry4Law and PTLB are the number one choice. In short, Perry4Law and PTLB provide world class intellectual property rights services in India.

Tuesday, May 10, 2011

Self Defence And Deterrence In Indian Cyberspace

Self defence in cyberspace may be exercised either against private individuals or against government and its agencies. In both cases, a well established self defence infrastructure must be established at the governmental and individual levels. India urgently needs a proactive self defence mechanism in cyberspace to effectively tackle private and governmental cyber intrusions.

Any government agency of India can tap your phone or engages in e-surveillance of your e-mails and other electronic communication without a constitutionally sound law. We have no constitutionally sound lawful interception law in India and phone tapping and e-surveillance in India are done in an illegal and unconstitutional manner.

India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India, informs Praveen Dalal, managing partner of New Delhi based exclusive ICT law firm Perry4Law and leading techno legal expert of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more, informs Dalal.

Of all e-surveillance project, nothing is worst than the Aadhar project of India and its implementing unique identification authority of India (UIDAI) headed by Nandan Nilekani. Irrespective of what Nandan Nilekani and Indian government says, Aadhar project and UIDAI are serving a very vicious, evil and nefarious objective of e-surveillance without procedural safeguards. Surprisingly, even Google is censoring results pertaining to Aadhar project and UIDAI and is messing up with search placement results.

India has an exclusive Techno Legal Centre for Protection of Human Rights In Indian Cyberspace (HRPIC). Indian Government must maintain a “Delicate Balance” between National Security requirements and Protection of Fundamental Rights, suggests Dalal.

However, expecting this type of fair and honest behaviour from Indian government and its agencies would itself be unfair. Indian government is least bothered to protect human rights in cyberspace of Indian netizens. Even United Nations (UN) has failed to take notice of this serious situation.

The exercise of self defence against Indian government and its agencies seems to be the only option especially when the Parliament of India has abdicated its role of law making and parliamentary oversight.

Tuesday, May 3, 2011

Technology Arbitration In India

Both technology related and technology assisted arbitrations in India are rare. Cyber arbitration in India and cyber arbitration and mediation centers in India is difficult to find in India. In fact, we have a single techno legal technology arbitration and mediation centre in India.

Recently World Intellectual Property Organisation (WIPO) has revealed in a statement that cyber squatting has increased significantly. Now the problem in India is that we have no domain name protection law hence securing domain name protection in India is a very tedious job. Further, there are very few individuals and institutions that provide domain name dispute resolution services in India or technology related dispute resolution services in India.

Perry4Law Techno Legal Base (PTLB) is the premier techno legal segment of exclusive techno legal ICT law firm of India Perry4Law. It is providing techno legal online dispute resolution services. Further, it is also managing the exclusive e-courts training and consultancy center of India.

We have to invest in adequate skill developments in India regarding ODR and e-courts as most of the technology related disputes would be solved through theses mediums only in the future.

Monday, May 2, 2011

Electronic Banking In India

This is the updated version of my previous article on same topic. Electronic banking in India or e-banking in India is increasingly being used by both banks and customers alike. This brings mobility and convenience to both banks and customers. However, with the benefits there are drawbacks of e-banking as well. This article addresses some of these concerns.

Reserve Bank of India (RBI) has come across many complaints and disputes regarding fraudulent credit card, online banking and ATM transactions. Even phishing incidences have sharply arisen in India resulting in loss of money of public at large. RBI ombudsmen office has been flooded with such complaints.

In these circumstances, online banking in India is risky. We have no e-banking laws in India and this also makes the mobile banking in India risky. Even RBI has acknowledged risks of e-banking in India.

E-banking in India cannot succeed till a strong legal framework in this is enacted. According to Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India, we have no dedicated E-Banking Law in India. Although, RBI has issued many guidelines in this regard and even our Information Technology Act, 2000 contains some indirect and implied provisions for Internet or E-Banking yet we need a separate and dedicated law in this regard, opines Praveen Dalal.

Recently, G Gopalakrishna, the executive director of RBI, said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest, informs Dalal. This step was taken to ensure proper Cyber Security Policies and Strategies at the highest Board Level of Banks, says Dalal.

Although RBI has mandated cyber due diligence for banks in India especially the due diligence for banks under IT Act 2000 yet banks have still to keep their functions in order. Indian banks are poor at cyber security and they are in no mood to appoint CIOs and steering committee.

Recently the final report of working group of RBI on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds has been released. It has prescribed the time limits for implementation of RBI recommendations on information security. With the deterrent approach of RBI towards non compliance, it would be safe to presume that CIOs, steering committee and cyber security related compliances would also be taken seriously by RBI.

It is high time for banks operating in India to keep their e-banking infrastructure technologically and legally sound. The best option for banks seems to be to adopt Techno Legal Measures that covers both Technical and Legal aspects of Banking, suggests Dalal.

Sunday, May 1, 2011

Implementation Of RBI Recommendation On Information Security

The forming of Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds by Reserve Bank of India (RBI) was a landmark step taken by RBI. Equally impressive was the imposition of penalty upon 19 commercial banks by RBI for non compliance of prescribed standards.

This shows that RBI is not tolerating the causal and non compliance attitude of commercial banks in India. It would be even better if RBI is equally concerned about non compliance of the recommendations regarding adoption of information security related policy and infrastructure.

For instance, the report of working group has recommended that all banks would have to create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest. Till now these recommendations have not been complied with. Further, Indian banks are also poor at formulating and implementing cyber security policies.

Now the RBI has issued a notification for the implementation of the recommendations of its working group. The group examined various issues arising out of the use of information and communication technology (ICT) in banks and made its recommendations in nine broad areas. These areas are IT Governance, Information Security, IS Audit, IT Operations, IT Services Outsourcing, Cyber Fraud, Business Continuity Planning, Customer Awareness programmes and Legal aspects.

The report was placed on the RBI website on January 21, 2011. Subsequently, on February 1, 2011, views/comments of all stake-holders and the public at large on the Report were invited. After taking into account various responses, final guidelines in the respective areas as mentioned above are now being issued to banks for implementation.

The guidelines are not “one-size-fits-all” and the implementation of these recommendations need to be risk based and commensurate with the nature and scope of activities engaged by banks and the technology environment prevalent in the bank and the support rendered by technology to the business processes. Banks with extensive leverage of technology to support business processes would be expected to implement all the stipulations outlined in the circular. For example, banks which do not offer transactional facilities in internet banking would not be required to implement specific measures for transactional internet banking facility outlined in the guidelines. Further, various instructions in “IT operations” chapter like detailed configuration management practices may not be necessary for banks that do not develop or maintain critical applications internally, though such practices may be expected from the external vendor providing such services.

The group had endeavored to generate self-contained and comprehensive guidelines. This has resulted in reiteration of certain guidelines already prescribed by RBI, for example, in certain areas relating to information security, outsourcing, BCP and IS Audit. However, there are certain guidelines like the checklist for computer audit prescribed in the year 2002 which on the whole cannot be ignored since the nature of coverage is different. In the event of a direct conflict with an earlier guideline, the new guideline would be the basis for implementation by banks. Else, the relevant guidelines prescribed earlier would be an adjunct to the present guidelines issued herewith. It would be the endeavor of RBI to develop the enclosed guidelines as a Master Circular incorporating relevant old and new circulars on related subject areas in due course. In the event of any further clarifications in the matter, banks may approach RBI for further guidance.

The Group’s report was largely technology neutral except in exceptional circumstances where a specific technology/methodology may be suggested due to legal reasons or for enhanced security or for illustrative purpose. It is clarified that except where legally required, banks may consider any other equivalent/better and robust technology/methodology based on new developments after carrying out a diligent evaluation exercise.

Banks may have already implemented or implementing some or many of the requirements indicated in the circular. In order to provide focused project oriented approach towards implementation of guidelines, banks would be required to conduct a formal gap analysis between their current status and stipulations as laid out in the circular and put in place a time-bound action plan to address the gap and comply with the guidelines. However, banks need to ensure implementation of basic organizational framework and put in place policies and procedures which do not require extensive budgetary support, infrastructural or technology changes, by October 31, 2011. The rest of the guidelines need to be implemented within period of one year unless a longer time-frame is indicated in the circular. There are also a few provisions which are recommendatory in nature, implementations of which are left to the discretion of banks.

Given the fact the guidelines are fundamentally expected to enhance safety, security, efficiency in banking processes leading to benefits for banks and their customers, the progress in implementation of recommendations may be monitored by the top management on an ongoing basis and a review of the implementation status may be put up to the Board at quarterly intervals. Banks may also incorporate in their Annual Report from 2011-12 onwards broadly the measures taken in respect of various subject areas indicated in these guidelines.

The measures suggested for implementation cannot be static. Banks need to pro-actively create/fine-tune/modify their policies, procedures and technologies based on new developments and emerging concerns. Reserve Bank of India would review the progress in implementation of the guidelines in its Quarterly Discussions with banks and would examine comprehensively the efficacy of implementation of the guidelines commensurate with nature and scope of operations of individual banks from the next AFI cycle (for the period 2011-12) onwards.

Wednesday, April 27, 2011

Cyber Forensics Course In India

Cyber forensics in India is still not in much use. This is primarily because neither the legal frameworks of India have adopted cyber forensics nor the legal and judicial fraternities are well aware of the technicalities of the same. The scientific knowledge that is essential for legal and judicial fraternity is presently missing in India.

On the front of research, education and training as well, India has very few cyber forensics training centers. For instance, India has an exclusive techno legal cyber forensics research, training and education centre managed by Perry4Law.

Perry4Law Techno Legal Base (PTLB), the leading techno legal segment of Perry4Law, provided exclusive techno legal online cyber forensics course in India. This course is one of the techno legal courses that are provided by PTLB. The other courses include cyber law, cyber security, digital evidencing, e-courts, online dispute resolution (ODR), Indian legal services courses, Indian regulatory services courses, etc.

The courses are meant for police officers, lawyers, judges, corporate executives, computer professionals, law graduates, etc. From the stage of investigation to final adjudication by a court, cyber forensics must be used in proper manner. However, cyber forensics in India is not used at all in the absence of adequate training and education.

The cyber forensics courses provided by PTLB can go a long way in strengthening the investigative, legal and judicial system of India. In fact, Perry4Law and PTLB are in the process of circulating the first and exclusive techno legal cyber crime investigation manual of India for selective law enforcement agencies and intelligence agencies of India. This manual is the best cyber crime investigation manual of India so far. It would strengthen the cyber crime investigation capabilities of Indian police and other agencies.

The practices and methods of cyber crime investigation and cyber forensics incorporated in the manual would also be taught to the individuals who have enrolled for the cyber forensics course of PTLB. Further, a special emphasis is given to techno legal skill development so that professional graduates are found more suitable by big companies and industrial houses. So hurry and be a techno legal professional this year and join the cyber forensics course of PTLB.

Monday, April 25, 2011

Draft Right To Privacy Bill 2011 Of India

The right to privacy bill 2011 of India may be the first attempt to regulate privacy related issues. However, as per media reports it seems to be more like a data protection initiative rather than a privacy safeguarding law.

India has created a problem for itself by neglecting the privacy protection requirements for long. India has been launching projects without any legal framework and procedural safeguards. For instance, we have projects like central monitoring system (CMS), national intelligence grid (Natgrid), Aadhar, crime and criminal tracking network and systems (CCTNS), etc that are not governed by any legal framework and procedural safeguards. Even we do not have any lawful interception law in India that can be claimed to be constitutionally sound.

According to Praveen Dalal, managing partner of New Delhi base law firm Perry4Law and leading techno legal expert of India, India is the only country of the World where Phone Tapping and Interceptions are done without a Court Warrant and by Executive Branch of the Constitution of India. Phone Tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” for Phone Tappings and Lawful Interceptions. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more, informs Dalal.

What is more surprising is the fact that the law enforcement agencies and the intelligence agencies that indulge in unconstitutional e-surveillance and phone tapping are themselves governed by no law. It is no surprise that the central bureau of India (CBI) is also not governed by any law and it is operating in India without any law. It is only now that the central bureau of investigation act 2010 was drafted. Till now it is a mere draft and has not become an enforceable law. Even the constitutional validity of the national investigation agency act 2008 is doubtful. Even the draft Intelligence Services (Powers and Regulations) Bill, 2011 has been recently circulated in the Parliament of India.

If the proposed privacy bill sees the light of the day, a data protection authority of India may be constituted. This authority must be constituted through an Indian regulatory services examination so that it can perform the challenging tasks that it would be entrusted with. For the time being, let us wait for the final draft of privacy bill available for public discussion.

Sunday, April 24, 2011

Indian Regulatory Services Examination In India

Regulatory bodies like securities and exchange board of India (SEBI), competition commission of India (CCI), cyber appellate tribunal (CAT), telecom regulatory authority of India (TRAI), proposed telecom security council of India (TSCI), etc requires domain specific experts to manage the same. Till now Indian government has been deputing its officers from its own departments to these regulatory bodies thereby undermining the required expertise.

In the past, Indian government has proposed Indian legal services examinations so that qualitative legal professionals can be produced in India. Now it has been felt that Indian regulatory services are needed in India. Institutions like Perry4Law Techno Legal Base (PTLB) are already providing training, education and research in these regulatory fields and many more techno legal fields.

Perry4Law and PTLB have been providing various techno legal trainings, education, research and coaching in India and world wide. Some of the areas covered by PTLB are continuing legal education in India, online lawyers and judges training in India, Indian legal services examinations training and education, Indian regulatory services examinations and trainings, etc.

PTLB provides Domain Specific and Highly Specialised Trainings in areas like Regulatory Services, Cyber Law, Cyber Forensics, E-Courts, Digital Evidencing, E-Discovery, etc, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and CEO of PTLB. We need “Domain Specific Experts” to manage different areas of Governmental Dealings, suggests Dalal.

Recently, Indian government proposed to constitute data protection authority of India (DPAI). The DPAI would require tremendous techno legal acumen as its areas of operations would be very large and challenging. The members of all regulatory bodies must have good techno legal expertise so that their functions can be performed in best possible manner.

With the proposal to introduce e-delivery of public services in India these regulatory authorities would have enhanced roles to perform. Even the department of information technology (DIT) has proposed a framework for citizens’ engagement in NEGP. Services of institutions like PTLB can be availed of under public private partnership (PPP) model for governmental projects and initiatives. Let us see how various proposals of Indian government would be actually executed.

E-Discovery And Litigation Services LPO And KPO In India

E-discovery and litigations services in India are managed by few firms. However, when it comes to techno legal e-discovery and litigation services in India only one name comes into the mind. Perry4Law Techno Legal Base (PTLB) is the exclusive techno legal e-discovery and litigation services providers of India.

Another unique aspect of e-discovery and litigation services of PTLB is that it is the only institution of the world that is managed by world renowned techno legal law firm Perry4Law.

PTLB is also the exclusive techno legal e-discovery related litigation, LPO and KPO services provider of India and world wide. Perry4Law and PTLB are also managing the exclusive techno legal Digital Evidencing and E-Discovery Centre of India. It is taking care of innovative digital evidence LPO and KPO and other techno legal digital evidencing and e-discovery related issues. PTLB is also the Exclusive Citizens to Government (C2G) LPO and KPO Providers in India.

Some of the areas where Perry4Law and PTLB provide their techno legal LPO and KPO services include Cyber Law, Cyber Security, Cyber Forensics, Cyber Warfare, Cyber Terrorism, Cyber Espionage, Homeland Security, Internal Security, Digital Evidencing, E-Discovery, Cyber Due Diligence, E-Courts, National E-governance Plan (NEGP), etc.

E-discovery related issues are of tremendous importance for both litigation and non litigation related matters. Business houses and even banks must have e-discovery and due diligence mechanisms at their places. Further, e-discover is also an essential prerequisite for successful litigation and dispute resolution.

Companies, banks, corporate houses, law firms, etc must have a dedicated e-discovery centre for their successful day to day functions. For those who do not wish to have such a centre may seek the expert services of institutions like PTLB.

Tuesday, April 12, 2011

Computer Security In India

Computer security is no more a luxury but an absolute necessity. In the present era, information and data is of extreme importance and value. We cannot allow strategic, sensitive, commercial and crucial data to be lost or stolen by cyber criminals.

From mere pranks, hobby and boasting, cyber crime has been transformed into a white collor and organised crime. Crime syndicates are actively engaging in identity theft, information stealing, data theft and so on. With the borderless and transborder nature of the crime, cyber crime is very difficult to pursue.

We have no computer security policy of India and we need one urgently. India has already been a victim of cyber attacks, cracking, cyber espionage, website defacements, etc and its cyberspace is highly vulnerable. India is facing a growing threat of cyber attacks and cyber crimes. In such circumstances, enacting strong cyber laws and establishing effective and robust cyber security is required.

National Security Policy of India is urgently required and Computer Security Policy of India must be an essential part of the same, says Praveen Dalal, managing partner of New Delhi based Law Firm Perry4Law and leading techno legal expert of India. Increasing Computer Security Readiness with Adaptive Threat Management is need of the hour, suggests Dalal. Further, Measurement of ICT Resilience and Robustness on regular basis is also required, suggests Dalal.

Further, another factor that is responsible for low level of computer security in India is that computer security research and development in India is lacking. We have a single and exclusive techno legal computer security research, training and education institution of India. The same is managed by Perry4Law and Perry4Law Techno Legal Base (PTLB). It is managing issues like cyber law, computer security, cyber war, cyber espionage, cyber forensics, etc.

So on the fronts of policy formulation, legislation making and computer security awareness, India needs to take some immediate steps. The present indifferent attitude of Indian government and Parliament of India is doing no good to Indian cyberspace. I hope some concrete actions would be taken by Indian government in these directions as soon as possible.

Monday, April 4, 2011

Technology Arbitration And Mediation Centre Of India

Recently World Intellectual Property Organisation (WIPO) has revealed in a statement that cyber squatting has increased significantly. Cyber squatting is basically done through deliberately registering and using popular trade marks as domain name. Once these domain names are registered, they are offered for resale at a much higher price. The genuine trade mark holder has to either give the amount or fight the issue at courts or through arbitration or mediation.

India has no domain name protection law hence securing domain name protection in India is a very troublesome task. Further, there are very few individuals and institutions that provide domain name dispute resolution services in India.

Cyber squatting dispute resolution services in India is not very popular for the simple reason that we have neither a conducive legal framework nor suitable techno legal expertise to handle such cases. Of course, some very selective individuals and institutions provide such services in India.

Technology has also introduced a novel element to dispute resolution. Now alternative dispute resolution (ADR) services are supplemented by online dispute resolution (ODR) methods. International organisations like Internet Corporation for Assigned Names and Numbers (ICANN), United National Commission on International Trade Law (UNCITRAL), WIPO, etc are stressing upon the need of technology related dispute resolution mechanisms at regional and international level.

Technology disputes involving fields like Cyber Law, Cyber Security, Cyber Forensics, Technology Transfer, Cyber Squatting etc require Domain Specific and Highly Specialised Techno Legal Acumen, says Praveen Dalal, Managing Partner Perry4Law a New Delhi based and exclusive Techno Legal IP and ICT Law Firm of India. The future trends of International Commercial Arbitration is indicating towards Technology Related Dispute Resolution, informs Dalal.

Thus, dispute resolution of cross border technology transactions would be one of the emerging trends in international commercial arbitration in India. Further, cross border technology transactions and dispute resolution may take lots of shape and requirements. India has to do lots of hard work to capatilise these opportunities. For instance, contemporary dispute resolution methods like online dispute resolution (ODR) and e-courts are missing in India. Even the national litigation policy of India (NLPI) failed to consider ODR and e-courts as effective methods of out of court dispute resolution.

In fact, we have a single and exclusive techno legal Technology Arbitration and Mediation Centre of India (TAMCI) managed by Perry4Law and Perry4Law Techno Legal Base (PTLB). We need more such expert institutions so that India may be a hub for technology disputes resolution. Let us wait and watch the scope and future of technology related dispute resolutions in India.

Sunday, April 3, 2011

Cyber Squatting Dispute Resolution Services In India

Cyber squatting has increased significantly as per a recent statement by World Intellectual Property Organisation (WIPO). This shows the importance of domain names in today’s commercial and inter connected world.

Securing domain name protection in India is a very tedious and troublesome task as India has no domain name protection law as well as cyber squatting law. All cases of cyber squatting are dealt with under the trade mark act, 1999 of India. This is the main reason why domain name dispute resolution services in India are provided by few selective players only.

Technology has also introduced a novel element to dispute resolution. Now alternative dispute resolution (ADR) services are supplemented by online dispute resolution (ODR) methods. Technology disputes involving fields like Cyber Law, Cyber Security, Cyber Forensics, Technology Transfer, Cyber Squatting etc require Domain Specific and Highly Specialised Techno Legal Acumen, says Praveen Dalal, Managing Partner Perry4Law a New Delhi based and exclusive Techno Legal IP and ICT Law Firm of India.

However, there are very few technology related dispute resolution providers and ODR service providers in India. For instance, Perry4Law through Perry4Law Techno Legal Base (PTLB) is the exclusive techno legal ADR and ODR service provider of India. Although ODR services are provided by a few others as well in India yet none of them, except Perry4Law and PLTB, provide techno legal ODR services in India.

These initiatives of Perry4Law and PTLB assume significance as dispute resolution of cross border technology transactions would be one of the emerging trends in international commercial arbitration in India. Further, cross border technology transactions and dispute resolution may take lots of shape and requirements. These technologies related dispute resolution services would also need techno legal expertise that very selective individuals and organisations possess.

India can become a global hub for international commercial dispute resolution (ICDR) services. ICDR services can be provided for disputes arising out of contracts on sales of goods, distributorship, agency and intermediary contracts, construction, engineering and infrastructure contracts, intellectual property contracts, domain name dispute resolutions, joint venture agreements, maritime contracts, employment contracts, etc. The list is fast expanding as the world is moving away from the traditional litigation system. All we need to make India a hub for ADR and ODR is a conducive.

Firstly, the ADR system of India needs reforms as it is in a really bad shape. Secondly, the arbitration infrastructure in India needs to be established. Thirdly, contemporary dispute resolution methods like online dispute resolution (ODR) and e-courts are missing in India. Even the national litigation policy of India (NLPI) failed to consider ODR and e-courts as effective methods of out of court dispute resolution. These issues must be resolved to make India a favourite destination for technology related dispute resolutions.

Wednesday, March 30, 2011

Cyber Crime Fight Is Hampered By Lack Of Harmonisation

Cyber crime is a global menace whereas its dealing is a territorial aspect. This has resulted in inadequate and ineffective measures to fight against cyber crimes. There is no universally acceptable cyber crime treaty of the world. Further, India is also not a part of any treaty or convention on cyber crimes.

European Union (EU) has in the past tired to being international norms in this regard through the EU convention on cyber crime. However, not all countries of the world are member party to this convention. In fact Indian response to the international cyber crime treaty is somewhat indifferent.

India has its own Cyber Law in the form of Information Technology Act 2000. It is based upon the Model Law on Electronic Commerce adopted by the United Nations Commission on International Trade Law, informs Praveen Dalal, managing partner of Perry4Law and leading cyber law expert of India. However, India is still not a part of any International Treaty or Convention on Cyber Crimes, informs Dalal.

Indian cyber law is not upto the mark and it deserves to be repealed immediately. The IT Act 2000 was enacted more than 10 years back and since then lots of changes have taken place. Further, India has not yet formulated a cyber crime policy that can effectively deal with cyber law related issues in India.

Indian government is also planning to provide mandatory electronic governance service in India. Further, areas like mobile governance, mobile banking, etc are also being explored by India.

Indian Legal Framework and Administrative Infrastructure are not conductive for issues like Cloud Computing, E-Governance, M-Governance, Mobile Banking, etc, suggests Dalal. Before embarking upon these crucial fields, India must adopt Sound International Practices and Standards, suggest Dalal.

International community, especially European Union, must also work in the direction of formulating a Universally Acceptable Standard so that the fight against Cyber Crimes can be truly Global. Further, International Collaboration in the fields like Law Enforcement Cooperation, Cyber Security Cooperation, etc must also be undertaken, suggests Dalal.

For the time being, global cyber crime fight is hampered due to lack of harmonisation and international standards. This is causing loss and damage to all countries and none is benefited due to this void. Let us hope that international standards and norm regarding cyber crimes would be formulated very soon.

Monday, March 28, 2011

Data Protection Law In India

This is the updated version of my previous article on data protection law in India. Although data protection law in India is urgently required yet Indian government has slept over the issue. Instead of protecting the civil liberties of Indians, it has chosen the opposite method of illegal e-surveillance and eavesdropping.

Even the projects of government of India have been victim of lack of privacy and data protection safeguards in India. Recently, the proposal to establish national counter terrorism centre (NCTC) of India was rejected by Finance Ministry of India citing privacy concerns.

Similarly, the proposal to launch national intelligence grid (Natgrid) in India was recently put on hold by Cabinet Committee on Security (CCS) of India. The CCS took a clue from precautionary advice given by techno-legal experts regarding the possible political misuse and violation of civil liberties of the Indian citizens.

As a result, the CCS withheld its nod and asked the Home Ministry to come back after further consultation with all stakeholders and incorporating adequate safeguards in this regard. CCS must be more proactive regarding data protection and privacy protection requirements of India.

Data protection is an important aspect of privacy rights protection and commercial expediency. On the one hand it ensures that privacy rights are respected by not divulging the sensitive information whereas on the other hand it is “must have” requirement of many business models.

Outsourcing industry relies heavily upon a sufficient and strong data protection law. In the Indian context, outsourcing industry is relying upon contractual terms as there is no dedicated data protection law in India. This is also hampering the outsourcing business to a great extent.

However, although commercial aspects of data protection can be ignored to a certain limit, this cannot be said about the constitutional requirements of privacy protection in India.

According to Praveen Dalal, a Supreme Court lawyers and leading techno legal expert of India, we have no “Dedicated” Data Protection Law in India. Even India does not have a Data Security Law and Privacy Law. This makes the sensitive information and personal details of Indian Citizens “Highly Vulnerable” to misuse, informs Dalal.

If we analyse this situation in the light of recent e-surveillance projects of Indian government, the matter becomes worst. E-surveillance projects like Aadhar/UID, national intelligence grid (Natgrid), crime and criminals tracking networks and systems (CCTNS), central monitoring system (CMS), etc are not supported by any legal framework and parliamentary oversight.

What is ironical is that Intelligence Agencies of India and Law Enforcement Agencies of India themselves are not subject to any “Parliamentary Scrutiny”, informs Praveen Dalal. Indian Government must maintain a “Balance” between National Security and Civil Liberties, suggests Dalal.

When intelligence agencies are themselves outside the purview of parliamentary oversight and there are no privacy laws, data protection laws and data security laws, we cannot trust Indian government and its agencies much. Even the phone tapping in India is done in an unconstitutional manner in India.

In this background, it becomes absolutely essential for the Supreme Court of India to interfere. A writ petition regarding protection of privacy rights of an individual is already pending before the Supreme Court of India. I hope the court would do the justice once more.

Sunday, March 27, 2011

Mandatory E-Governance Services In India

Legal framework for mandatory e-governance services in India is long due. If we make e-governance service optional or discretionary, the whole purpose would be defeated. This is the reason why we need time bound and accountable e-governance based public services in India.

Keeping this objective in mind, the central government formulated the draft electronic delivery of services bill 2011 (EDS Bill 2011). The EDS Bill 2011 intends to provide delivery of government services to all citizens by electronic means by phasing out of manual delivery of services delivered by the government including matters connected therewith or incidental thereto.

The Bill if made a law would require complete overhaul of the present e-governance infrastructure and services delivery mechanism of Indian government. However, the real problem with Indian e-governance initiative is that legal framework for mandatory electronic delivery of services in India is missing, says Praveen Dalal, Supreme Court lawyers and Managing Partner of India’s exclusive techno legal law firm Perry4Law.

Till now there was no provision under which citizens could ask for mandatory electronic delivery of services by the government. After the Bill becomes an enforceable law, the Indian Government would be under an obligation to mandatorily provide electronic services to its citizens, opines Dalal.

To effectuate this objective, high-level delegates from all ministries will be meeting next month to decide on a cut off date to switch to total e-governance. However, before introducing it in the Parliament, each ministry will assess its readiness and accordingly fix the timelines for mandatory electronic service delivery in India. However, no department will exceed a cut off date fixed for the country.

I wish this initiative would become reality very soon.

Cyber Security Of Social Networks And Cloud Computing

Cyber security business model has been passing through a transformation phase. This is happening due to the growing pace at which technology is changing and evolving. Newer technologies and concepts are revealed on daily basis giving rise to novel cyber security challenges.

Senior executives of corporations have expressed great concerns regarding their ability to ensure enterprise security arising out of the use of social networking, mobile platforms and cloud computing model. Accessibility, use and control of data and the potential danger of having unauthorised access to confidential and proprietary information is also troubling security professionals.

Mobility, Cloud Computing, Security and Innovation have become the main issues for Cyber Security Professionals, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law. Mobility of handheld devices like cell phone has given rise to Mobile Phone Security Requirements. Similarly, Cloud Computing Security is also becoming a headache, informs Dalal. Cyber Security Requirements and Innovation Requirements of Cyber Security also need to be addressed, says Dalal.

The fact is that digital economy is expanding too fast and this is well beyond the capacities of cyber security professionals. There is an urgent need to safeguard the digital economy from cyber attacks and cyber threats.

At the same time, using concepts like cloud computing, virtualisation services, software as a service, etc also requires a cautious approach. This is more so for India that lacks data security, data protection and privacy laws.

In the absence of legal framework to protect sensitive and commercial data, self protection measures of cyber security must be more robust and effective. Cyber security of social networking sites and cloud computing environment is a challenging task and cyber security professionals must be aware of the cyber threats and must accordingly arrange their cyber security environments.

Saturday, March 26, 2011

Cyber Crime Policy Of India

Cyber crime is an area that requires policy formulation at the national level. In the Indian context, there is no national cyber crimes policy of India. In fact, cyber crime policy and strategies of India is so important that the issue must be taken up by the Prime Minister’s Office (PMO) of India. The present cyber law of India is not effective and PMO must ensure a new cyber law for India.

India needs to do extensive research on the legal and policy related issues pertaining to regulation of cyber crime at the national and global levels. Although India is not a signatory to the EU Convention on Cyber Crimes yet there is no reason for it to remain aloof from International Norms and Standards, says Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and a Supreme Court lawyer.

India has been lax regarding policy formulation for techno legal issues. For instance, there is no cyber security policy and strategy in India, no national security policy of India, no national security and ICT policy of India, no ICT policy in India, no national ICT crisis management plan of India, etc.

In this background, it is no surprise that we have no cyber crime policy in India as well. When issues like Cyber Terrorism, Cyber Warfare, Cyber Espionage, etc are troubling India, having no Cyber Crime Policy is not a good indication, cautions Dalal.

We must urgently formulate a good and effective Techno Legal Cyber Crime Policy for India, suggests Dalal. It is for the government of India to take the initiative as sooner or later it has to adopt ICT related policies for India. The sooner these policies are adopted the better it would be for the national interest of India.

EU Convention On Cyber Crime


European Union’s Convention on Cyber Crime is the first international treaty on cyber law. The treaty endeavours to regulate cyber crimes at international level by harmonising national laws, improving cyber crimes investigative techniques and increasing cooperation among nations. The treaty came into force on 1 July 2004.

On 1 March 2006 the Additional Protocol to the Convention on Cybercrime came into force. The additional protocol requires the States to punish as a criminal offence the dissemination of racist and xenophobic material through computer systems, as well as of racist and xenophobic-motivated threats and insults.

Among other things, the convention deals with infringements of copyright, computer-related fraud, child pornography and violations of network security. It also contains a series of powers and procedures such as the search of computer networks and lawful interception.

Although the objectives of the convention are praiseworthy, they have been by and large remained unfulfilled, says Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India. For instance, lawful interception laws are missing in most countries including India. Similarly, protecting children in cyberspace from various cyber crimes like cyber stalking, sexual abuses, etc is still an unfulfilled dream, informs Dalal. The truth is that cyberspace is still an unfriendly place for juveniles, says Dalal.

Similarly, on the front of civil liberties in cyberspace as well the convention failed to make much difference. For instance, there should be a balance between law enforcement requirements and civil liberties. However, in the name of national security, human rights are very frequently and openly violated by various nations, including India, informs Dalal.

International cyber law harmonisation is still an unfulfilled dream as various nations are not willing to cooperate in this regard. All nations have their own agendas and priorities that are preventing adoption of an internationally acceptable cyber law treaty.

Online Cyber Law Courses In India

Cyber law is one of the emerging career options. It can be pursued by computer professionals, lawyers, management students, corporate executives, etc. Cyber law is also a very important aspect of legal training and corporate management. Legal and management professionals regularly enroll for cyber law training in India these days.

Cyber due diligence requirements in banks, companies, firms, etc has also increased the scope of cyber law professionals in India. Further, cyber law professionals would also be much required for legal management system of India in future. Cyber crime professionals are also in demand for conducting cyber crime investigations in India.

The present cyber law education trends in India show that online cyber law education in India would be the norm in the near future. Cyber law education through e-learning and online mode has many advantages over the traditional learning model. Professionals from any part of the world can enroll and get good quality cyber law training and education through e-learning method.

In India, Perry4Law Techno Legal Base (PTLB) is the exclusive techno legal online cyber law education and training provider. It provides a good combination of technical as well as legal cyber law education for various professionals.

The online platform of PTLB enables any professional from any part of the world to get enrolled and successfully complete the cyber law and other courses. Once the basic level courses are successfully undertaken, professionals can enroll for higher and specialised techno legal courses of PTLB.

However, professionals should not confine themselves to selective few courses alone. They must develop a habit of engaging in lifelong learning so that their cyber skills can be developed on a continuous basis.

Cyber law is a dedicated field and it requires good aptitude and practical skills. It cannot be practices by getting academic qualifications like diplomas etc. A person must possess practical knowledge to be a successful cyber law professional. Prospective cyber law professionals must keep this aspect in mind while choosing a cyber law education institution.

International Cyber Crime Treaty And India

Cyber law is no more confined to the limits of a nation alone. Being extra territorial in nature, the cyber law of a nation often travels far beyond the territorial jurisdictions of a nation. Realising the practical difficulties of this extra territorial nature of various cyber law, an International cyber law treaty was formulated at the international level.

However, there is no relationship between this international cyber crime treaty and India as India is not a signatory to the same. India is still governed by its distinct cyber law incorporated in the information technology act, 2000 (IT Act 2000).

Recently, efforts were made at the United Nations (UN) to adopt a “more comprehensive” and “truly global” International cyber crime treaty, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India. However, the proposal was rejected by UN and till now there is no globally acceptable cyber crime treaty in existence, informs Dalal.

Even the Indian cyber law is far from perfect and it has decayed. It has been amended by the information technology amendment act 2008 (IT Act 2008) that made the sole cyber law of India a big mess. There are no stringent provisions to punish cyber criminals as almost all the cyber crimes have been made bailable by this amendment.

Presently, India is neither following a good model cyber law based upon international standards nor is legislating an effective law that can meet the challenges of contemporary digital economy.

The present cyber law of India is worst than no cyber law at all and it must be repealed as soon as possible. This is more so when India has decided not to sign any international cyber crime treaty and stick to its own domestic legislation.

Thursday, March 24, 2011

Cyber Terrorism In India And Its Preparedness

Cyber terrorism in India is no more a new concept. India has been facing constant cyber security attacks. Further, cyber terrorism attacks are also common in Indian cyberspace though their execution and detection is by and large unnoticeable and undetected in India.

Cyber terrorism is becoming a big nuisance for India and India has to be technologically as well as legally sound to tackle the same. There is an emergent need to amend the cyber law of India, i.e. Information Technology Act, 2000 (IT Act, 2000) in this regard as a single provision is not sufficient as per the cyber law experts.

Even there is no national ICT crisis management plan of India that is addressing the menace of cyber terrorism in India. The critical infrastructure of India has become vulnerable due to inadequate cyber security. This vulnerability can not only be exploited by cyber criminals but also be the cyber terrorists.

Securing the critical national infrastructure of India from cyber attacks should be a priority area for India. This requires formulating a cyber security policy of India that is presently missing. Without a cyber security policy and strategy of India, the cyber security initiatives of India are directionless.

Even there is no legal framework for cyber security in India. By incorporating a few ineffective and irrelevant provisions in the IT Act 2000, Indian government thinks that it has the cyber security law in India.

In fact, cyber terrorism preparedness must be an essential part of the homeland security of India. Homeland security of India must be strengthened and in order to do so we must take care of issues like cyber law, cyber security, cyber espionage, cyber terrorism, cyber warfare, etc.

Homeland Security is in infancy stage in India, says Praveen Dalal, Managing Partner of Perry4Law and leading techno legal expert of India. Further, India also needs a separate Framework for Cyber Security, Critical Infrastructure Protection (CIP), Cyber Terrorism, Cyber Warfare, Homeland Security issues, etc suggest Praveen Dalal.

Clearly, India has not yet taken enough initiatives to tackle the menace of cyber terrorism. Lack of legislative skills seems to be the main reason why India is running short of good and effective cyber legislations.

India must urgently enact a suitable cyber security policy and homeland security that clearly demarcates its preparedness to deal with growing menace of cyber attacks and cyber terrorism activities against India.