PDPSI Vs ISO 27701 Vs BS 10012

PIMS (Personal Information Management System) is the next buzzword in the Information Security domain that will be discussed by the Data Protection professionals.

Presently, two international frameworks namely the BS 10012 and ISO27701 are available for us to follow. The undersigned has however developed a separate framework titled the Personal Data Protection Standard of India (PDPSI) which has been developed with the exclusive idea of assisting Indian Organizations and more particularly the SMEs and MSMEs.

It is our belief that Information Security Framework is developed by experts in order to guide the community for adopting it as a business practice that benefits the organization. When multiple organizations adopt a food framework of information security, the community would benefit.

Such a framework should be “Open Source” and not looked upon as a Cash Cow by charging exorbitant fees for the community members to know what is the best practice to follow.

Whether it is BS 10012 or ISO 27701, it costs around Rs 13000/- each to acquire and read. ISO 27701 makes normative reference to four other standards namely ISO 27000,ISO 27001,ISO 27002,ISO 29100. To understand ISO 27701 we therefore need to acquire and study all these collateral documents. Fortunately BS10012 does not have any normative references.

Those organizations which are considering the PIMS now and donot have earlier ISO implementations, need to therefore spend a significant money just to acquire a document that lists out the suggested practices. The interpretation and implementation through a consultant is the additional expenses.

Basically these frameworks list out the broad outlines of compliance requirements as follows:

1.Leadership
2.Planning
3. Support
4.Operation
5.Performance evaluation
6.Improvement.

ISO 27001 continues with specific guidance related to ISO27001 and ISO 27002 as also guidance directed to Controllers and Processors.

The PDPSI incorporates all these principles though the document is under development. In principle, PDPSI focuses on five foundation principles represented by the following diagram.

This model compresses the normal technical controls into one segment and all policy controls into a second segment. The need to manage the human elements is packed into the third segment. The Leadership, commitment etc is clubbed under Responsibilities. The classification of data is considered a separate foundation requirement which defines also the scope of the implementation. 

PDPSI recommends a “Distributed Implementation Leadership with a Top level policy leadership along with a designated person for accountability”.

For those who are accustomed to a specific format of the ISO/BS, PDPSI appears as a raw document. Salient features of PDPSI is explained under www.pdpsi.in

The normative references (to keep to the familiar term) are made to IISF 309 (Indian Information Security Framework), Theory of Information Security Motivation, Naavi’s pyramid model of Prioritization of Information security objectives.

The Classification model is depicted in the following diagram.

The classification of the data incorporates the “Subject Laws” so that PI-GDPR is classified differently from PI-PDPA.

The measurability aspect will point to a “Data Trust Score” for which one of the recommended approaches is the Naavi’s 5X5 DTS system indicated below.

The distributed model of responsibility sharing is reflected in the Governance model indicated below. (Explained in greater detail on www.pdpsi.in) 

Overall, PDPSI attempts to cover the principles inherent in both ISO27701 and BS10012 and provides a greater focus for an Indian organization with a few innovations thrown in between.

Once PDPSI is fully developed with the assistance of other professionals who are well versed in ISO/BS but are free mentally to pursue a more “Made in India” framework, it could be adopted widely.

In the meantime, some of the principles enunciated in PDPSI is expected to become part of the ISO/BS in their revised versions. Also the Data Protection Authority of India which is likely to come up in 2020 may adopt most of the principles under PDPSI as suggested framework under PDPA.

In the meantime, Naavi.org will continue to develop this concept which is already being applied by Naavi where ever it is relevant.

Naavi

Posted in Cyber Law | 1 Comment

We need Insurance against Traffic Fines…Mr Gadkari, are you listening?

Mr Nitin Gadkari is set to lose all his popularity he had gained in the last few years for his work as a minister over his quixotic decision of raising traffic fines to astronomical levels.

While creating deterrence against drunken driving, rash driving etc are necessary, across the board increase of fines such as for not wearing helmet or not wearing seat belts etc was unwarranted.

The traffic offences have to be ideally classified into two important categories. Offences that endanger third parties and offences which affect only the individual vehicle user for his safety.  Helmet and seat belts fall in this category. Penalties  have to be less for the second  category since  it is only to promote  own safety and has no impact on others.

The non maintenance of roads leading to potholes and consequential accidents should be held as traffic offences by the civic bodies and they should be fined at a larger level because their negligence affects the community as a whole. Similarly, invisible signs of no parking, non working traffic lights etc also cause problems to those who are essentially followers of law.

In the last two days there are reports of one fine of Rs 87500/- on a Truck driver and Rs 47500/- on an Auto driver. Not withstanding the crime, these fines are insane. Mr Gadkari should bear the direct responsibility for such a situation and be answerable to the voters in Maharashtra. Shivasena should have a cakewalk in the elections if they make this MV act as an election issue.

I have always held that such crazy levels of fine will only increase the corruption level in the Police. It is early days and Police may be now accounting the fines and the department is increasing its revenue by a few lakhs each day in major towns. Soon the fine collection will start stagnating and getting converted into bribes to the Police. Police will pass on a part of their loot to the politicians also and therefore the corrupt system will grow with political patronage.

Instead of targeting the consumers by increasing the fines, I want Mr Nitin Gadkari to do some thing that is beneficial to the road users. One such requirement is to check the Toll booth contracts many of which should have ended over time but are continuing without any maintenance of the roads. Recently, I had an occasion to travel in the Nice Road in Bangalore towards Magadi and found the road full of pot holes just like the City roads. One wonders why we need to pay any fees for such roads. Is not the Transport ministry responsible for these?

Some time back some ill informed politicians in Karnataka went against Uber and Ola and taxed them as Taxi operators, which resulted in increase of the rentals for the consumer. Similarly these fines will also increase the Uber/Ola rates since the companies have to factor this fine as part of the regular expense. The truck operators would also factor some fines in their cost and the cost of goods transport will also go up.

Mr Nitin Gadkari will be solely responsible for this increase in transport related costs.

Vehicle Insurance should include Traffic Fines

While these criticisms are well known and understood by all except the egoistic politicians who donot want to correct their mistakes, the main purpose of writing this article is to bring it to the notice of Mr Gadkari and others including Mr Modi that there is an urgent need to introduce a component of “Insurance against Traffic fines” as part of vehicle insurance.

Since the new fines have the effect of “Deterrence”, accidents will come down (Should come down). This should reduce vehicle insurance claims. Insurance companies should be therefore persuaded to reduce the insurance premium on all  existing policies.

Additionally the Traffic Fine endorsement should be provided at an extra premium.

Insurance companies today provide such covers for administrative fines under say GDPR or even the Extortion under ransomware. If these are acceptable as insurable risks, why not traffic fines?

I would like IRDAI to engage in discussions with the Insurance companies to quickly introduce the coverage on such fines.

If Mr Gadkari is still walking on the ground, he should push the insurance companies into providing such insurance coverage besides reducing the fines on “Non Third Party Risk Creating offences” to a reasonable level.

I wish a petition is raised in this regard by some public interested person.

Naavi

Posted in Cyber Law | Tagged , , , | Leave a comment

List of Nodal Officer Contacts

Many times disputes that arise with service providers of various agencies are resolved easily when we are able to reach out to the right persons in the organization.

ITA 2000/8 mandates that every online service organization (who is an intermediary) needs to mandatorily provide the name and contact details of the Grievance Redressal officer on their website.

Unfortunately, most websites not only hide their contacts for receiving complaints but also hide their physical address to which any notice can be sent by a consumer.

Though this is a violation in itself that can be penalized by either an Adjudicator or perhaps by a criminal Court too, most organizations out of ignorance donot provide the contact details.

I am happy to provide a compilation of nodal officer’s contacts which have been compiled by one diligent law enforcement professional. While care has been taken to update the list, errors and omissions could be present. I hope the public will consider this useful.

List of Nodal Officers of different e commerce agencies in India.

I request these and other organizations to point out if any corrections are required. We welcome other intermediaries to share their contact addresses.

We may also bring to the attention  of readers 5t our Associate service center at ODRGLOBAL.IN provides online dispute resolution service which can be effectively used to resolve consumer disputes. We invite these agencies to use the services of ODR Global. It should be economical and also convenient.

CDMAC (Cyber Disputes Mediation and Arbitration Center) is one ADR center whose services may be invoked if a more serious arbitration of a dispute is required. First level disputes can be mediated by Naavi. For the time being, in the interest of the e-Consumers, such mediation would be provided free of charge.

Any collaboration  in developing  the ODR platform  and CDMAC are welcome.

Any enquiries in this regard  may be sent to Naavi.

Naavi

P.S: The following address in the list was corrected on 8th September 2019:

Yahoo India Pvt Ltd, Unit No 304, A wing, 3rd Floor, Satellite Gazebo East Wing, Guru Hargobindji Marg, Andheri (East),Mumbai 400093.
E Mail: in-legalpoc@verizonmedia.com

 

Posted in Cyber Law | 1 Comment

New Cyber Crime Act in the anvil?

Recently, Mr Amit Shah, the honourable Home Minister of India collected information from across the country on the amendments that are required to the law to effectively counter Cyber crimes. Information coming out of the ministry seems to suggest that a new “Cyber Crime Act” may be in the anvil to supplement and partially replace the provisions of Information Technology Act 2000 as amended in 2008 (ITA 2000/8).

According to this report in Times of India  the new approach would be to amend the ITA 2000/8 to keep most of the civil offences under the present act and create a new Cyber Crime Act to address the issue of Cyber Crimes.

One of the features being considered is to ensure that there will be no inter state jurisdictional barrier for Cyber Crime investigations. This would be a good move if it is extended to the full extent including the creation of the National Cyber Crime Police cadre which is a long term necessity in India.

Other than this provisions of Chapter XI of ITA2000/8 may be shifted into the new Act. In the earlier act there was no recognition of  “Cyber Squatting” as an offence and this is due. Section 66A which covered Cyber harassment was wrongly scrapped by the Supreme Court and requires to be reinstated in some form.

The Intermediary guidelines which were sought to be amended and were opposed by some activists may now find a place in the new Act.

Hopefully some of the evidentiary issues including Section 65B of IEA that affect prosecution may get tampered with.

Let us wait and watch what more changes are going to be proposed. We hope the law will be stringent and at the time fairly implemented with checks and balances to prevent misuse by the Police and clever criminals and harassment of honest Netizens.

We need to specially watch out for lobbyists specially from the Banking sector will try to influence the changes in their favour.

Hopefully the draft would be available for public comments during the winter session along with the revised Data Protection Bill.

Naavi

Posted in Cyber Law | Leave a comment

Will Fintech Steering Committee report bring changes to PDPA?

The Subhash Garg Committee’s report on Fintech has touched on several aspects of the industry. It has interalia recommended on two aspects which are immediately relevant for us as observers of ITA 2000 and PDPA.

Firstly it has recommended changes to ITA 2000, to bring in the documents kept out of ITA 2000 under Section 1(4).

The recommendation is as under

Para 2.4.6: Re-engineering Legal Processes for the Digital world

The Committee recommends review by Department of Legal Affairs of all such legal processes that have a bearing on financial services and consider amendments permitting digital alternatives in cases such as power-of-attorney, trust deeds, wills, negotiable instrument, other than a cheque, any other testamentary disposition, any contract for the sale or conveyance of immovable property or any interest in such property, etc., (where IT Act is not applicable), compatible with electronic service delivery by financial service providers.

These exemptions had come in due to some specific thoughts which were relevant in 1998-2000 when the law was drafted. There are certain changes that have occurred in technology that may warrant a rethink on some of the aspects. However, the steering committee was neither tasked to think about changes in ITA 2000 nor it had the necessary expertise.

Hence the suggestions can only be taken as nothing more than an indication to the Government and should be handled with care.

Secondly, the committee has also made suggestions regarding the powers of the proposed Data Protection Authority proposed under PDPA, as under.

Para 4.4.3: Coordination with Financial Regulators:

The Committee is of the view that in some cases, data privacy requirements in existing legislation may need to be reviewed in order to tailor them to the emerging data privacy legislation. The Committee also considers that given the fact that sectoral regulators are already taking steps to maintain the security and confidentiality of consumer data in their respective jurisdictions, some obligations the Data Protection Bill seeks to place on the DPA may be given to the sectoral regulators to discharge. Regulators must therefore carefully review their existing regulatory framework and identify any changes or modifications that may be required to the current regulatory framework.

It appears that the committee was apprehensive of the loss of power of some of the other authorities who may have to work as per the directions of the DPA. It is obvious that the DPA will respect the sectoral regulators and accommodate their views in the implementation of the Data Protection regulations. But there has been a tendency by different departments of the Government to come up with their own Privacy related regulations that could overlap with the PDPA and confuse the market players.

This should be avoided. Let the DPA come into existence as per law with suitable flexibility in defining the codes and practices in different sectors and then discussions can be had with individual sectoral regulators so that their views can be accommodated.

Naavi

Posted in Cyber Law | Leave a comment

FINTECH Steering Committee Report

On 5th March 2018, GOI constituted a Steering Committee on Fintech related issues which has now come up with its recommendations. It was comprised of Secretaries of different ministries and headed by the Secretary of Economic Affairs (DEA) , Mr Subhash Chandra Garg.

Refer copy of Report here

The objective of the committee was to “Consider various issues relating to development of Fintech space in India with a view to make Fintech related regulations more flexible and generate enhanced entrepreneurship in an area where India has distinctive comparative strengths vi a vis emerging economies”.

We look at the salient features of the recommendations as briefly indicated below.

  1. The committee recommends the use of fintech, especially by PSE financial service companies to bolster cybersecurity, fraud control and anti-money laundering. The Committee also recommends that fintech firms specialising in this field should be encouraged to set up their businesses in India and provided necessary regulatory approvals for expanding their services in the country.
  2. The Committee recommends that the Ministry of Finance may develop a marketplace model of debt financing in India by reforming the present model of P2P lending platforms. Potential hindrance in terms of restrictions on overall and individual exposure limits may be reviewed and options like allowing Mudra Bank to directly fund or co-fund SMEs and MSMEs through P2P platforms may also be examined as an alternative credit delivery channel.
  3. The Committee recommends that DFS and RBI may examine the suitability of ‘virtual banking system’ in the Indian context, costs and benefits regarding allowing virtual banks and prepare for a possible future scenario where banks do not need to set up branches and yet deliver the full scale retail banking services ranging from extending loans, savings accounts, issuing cards and offering payment services through their app or website.
  4.  For facilitating KYC by Fintech industry, the Committee recommends that various options, including possibility of Video-based KYC, making available validated electronic versions of KYC related documents through DigiLocker, making these available for verification by service providers with prior customer consent, etc., may be considered early.
  5. In order to increase access to credit and to stabilise the growth of such practices and keeping in view recommendations of the Justice Srikrishna
  6. A Taskforce has been recommended to be set up with the participation of the regulators and make suitable recommendations to safeguard the interests of Consumers, while also enabling a positive climate for innovation.
  7. The Committee notes that the poor and the unbanked are often unable to access credit due to the lack of formal credit history and non-availability of other relevant documents. Fintech companies focus on a number of unconventional sources of data and advanced data analytics to create better credit profiles of such individuals. These fintech companies collect information pertaining to social media behaviour, financial transaction behaviour, product purchase behaviour etc. These kinds of information are not captured by CICs. Fintech companies collect these kinds of information from the mobile phones of consumers with prior consent. Banks are being encouraged to explore the possibility of establishing new alliances with players like fintech companies for ease of loan sanctioning process enabled by new technologies. In order to increase access to credit and to stabilise the growth of such practices and keeping in view recommendations of the Justice Srikrishna Committee, this Committee recommends that MeitY and TRAI may formulate a policy to enable such practices through a formal, consent-based mechanism.
  8. Centers of Excellence for FINTECH are recommended to be set up in 2 or 3 premier National institutions like IITs/NITs and Government Financial sector institutions like IDRBT/NIBM/NIFM
  9. The Committee recommends that the Ministry of MSME should work with DFS and RBI for testing and implementing block-chain solutions in trade finance for MSMEs in public sector banks as well.
  10. The Committee recommends that the Government takes up modernisation and standardisation of land records in the country on a war footing with a deadline to complete such a system in the country in a period of three years. For this purpose, a steering committee comprising of Department of Economic Affairs, Department of Financial Services, Ministry of Agriculture, Ministry of Rural Development, Department of Land Resources and MEITY with involvement of State Land and Registration departments should be constituted to draw up a blueprint for doing so.
  11. The Committee recommends review by Department of Legal Affairs of all such legal processes that have a bearing on financial services and consider amendments permitting digital alternatives in cases such as power-of-attorney, trust deeds, wills, negotiable instrument, other than a cheque, any other testamentary disposition, any contract for the sale or conveyance of immovable property or any interest in such property, etc., (where IT Act is not applicable), compatible with electronic service delivery by financial service providers.
  12. The Committee recommends that MEITY coordinate the process of identification of the datasets that can be shared through open APIs, setting targets for the creation of such APIs by the relevant Ministries while enabling and supporting Central, State and Local governments to create relevant open APIs. The Committee also recommends that greater nudge from all regulators combined with development of open API eco system will enable account aggregator services to take off.
  13. Regulators should establish prudential regulations for fintech to enable the moderate and high impact scenarios of fintech development to emerge.
  14. The Committee recommends that RBI may consider making available banking data (such as transaction and account history data) for use by the financial sector, including fintech firms, (based on consumer consent and with other appropriate safeguards) through APIs. It also recommends that all financial sector regulators study the potential of open data access among their respective regulated entities, for enhancing competition in the provision of financial services.
  15. It therefore recommends that all financial sector regulators fix deadlines for on-boarding existing KYC data to the Central KYC registry and make C-KYC (central KYC) fully operational and make KYC a digital and paperless process. At least the KYC data from the time the concept of Officially Valid Documents was introduced vide PML rules should be uploaded. In respect of legacy accounts, data may be uploaded by banks during the process of re-KYC.
  16. The Committee recommends that a legal framework for consumer protection be put in place early keeping mind the rise of fintech and digital services. It further recommends enacting such a law early keeping the rise of financial technologies in view.
  17. The Committee recommends creating a common digital platform for all micro-pension schemes and Government pension schemes, including EPF, through which pension subscribers can subscribe to specific schemes seamlessly and reduce access barriers by allowing payments through various modes such as Jan Dhan Yojana accounts, debit card, credit card, internet banking, mobile wallets etc.
  18. In order to expand the reach of small savings schemes, provide ease of access and transactions to consumers, reduce risk of frauds, enable trading in secondary markets, etc., the Committee also recommends that all Small Savings Products, which are neither accessible online nor available in demat form, should be brought on a common online platform in demat form. For vulnerable groups and weaker sections who are neither digitally and financially literate, a combination of both human interface and technological application may be effective.
  19. The Committee recommends use of fintech by Public sector commercial banks to enhance credit scoring, follow up of repayments, predictive analytics, etc., so as to enable reduction of NPAs in this space.

A rough glance at the above indicate that the recommendations indicate several new business opportunities which can be explored by the industry. However, most recommendations need to be carefully evaluated for the risks before they are actually implemented.

A lot more discussion is required on the recommendations.

Naavi

Posted in Cyber Law | Leave a comment