Banks can be fined upto Rs 1 crore for violating RBI regulation

The Banking Regulation Act amendment Act 2012 which was recently passed by the Parliament has now become effective.(See PIB Press Release).  It amends several provisions of the Banking Regulation Act 1949.

Some of the amendments are directed towards new Branch licensing , raising of capital, voting rights etc.

The Act will

a) Increase the powers of RBI to regulate the erring Banks

b) Provides greater freedom for public Banks for mergers, captital issue etc

c) Increase voting rights

What is of specific interest to the general public are  the following  amendments

1. Depositor Education and Awareness Fund

A new section 26A has been introduced in the Act which provides for setting up of a “Depositor Education and Awareness Fund” to which the balances in the inoperative accounts in accounts not operated upon for 10 years would be transferred. (Can be claimed back by genuine depositors even after the period). The fund may be utilized for purposes which RBI may specify from time to time in “Depositor’s interest”.

2.Increased Fine for Non Compliance

Further for various kinds of violations under the Act the fines that RBI may impose have been substantially raised. The maximum penalty which was Rs 5 lakhs at present has been increased to Rs 1 crore.

This development is considered good for the industry since it has been found in recent days that the regulations of RBI addressing depositor’s interests were being repeatedly ignored by some Banks.

In recent days “Money Laundering” which generally means “Facilitating the use of Banking services for criminal funds” has been indulged in by Banks as a matter of general policy of business promotion. A sting operation recently exposed such activities un ICICI Bank, HDFC Bank and Axis Bank.

This Business Standard article advocates that fines upto Rs 1 crore may be imposed for KYC failures.

Naavi.org has been discussing how KYC failures are the essential ingredients of any Bank fraud and needs to be curtailed with heavy fines. We have also pointed out how most of the losses of Depositors arising out of Phishing Frauds could be met out of collection of fines on KYC failures at the maximum rate of Rs 5 lakhs per failure if a fund is created for the purpose of insuring the depositors against such losses.

It appears that the scope for creation of such funds has now increased with the above amendment.

RBI may now examine if under the amended Banking Regulations Act, it may create a suitable “Electronic Banking Fraud Protection Fund” from out of a corpus built from the fines collected out of KYC failures observed during encashment of any phishing frauds. The suggestion is that while the Banks can pursue the legal means of locating the offenders and recovering the money from them, the victims must be reimbursed the amount of loss immediately from out of such funds. The payments can be considered as a loan to the Bank and suitable interest may be charged.

The fund may absorb losses arising out of cases where the offenders are not apprehended and money becomes irrecoverable in which case the loan already raised in the name of the Bank is written off. In other cases, recovered money maybe reimbursed to the fund.

The initial fund may be started with a corpus created out of contributions from member banks based on their deposits like the fees payable under DICGC or ECGC schemes.

Naavi

 

Posted in Bank, ITA 2008 | Leave a comment

Can Minors open Facebook account?

For the regular users of Facebook or Google, the question whether minors can open an account appears funny. But this is precisely what the Delhi High Court has asked the Indian Government in a PIL. (Details here). It would be interesting to know how Government of India will respond. Facebook and Google are also respondents to the case and their reply is also to be made in the next 10 days.

It is well known that minors constitute a large part of Facebook users and their business model thrives on the activity of these minors who seek friends and post messages of all kinds.

During the registration, Facebook asks for the date of birth and gives an explanation why the date of birth is asked, with the following pop up message.

“Providing your birthday helps make sure you get the right Facebook experience for your age. You can choose to hide this info from your timeline later if you want. For more details, please visit our Data Use Policy.

Not creating a personal account? If you’re here to represent your band (Sic), business or product,  please create a Facebook Page.”

There is also a page on “Minors and Safety” which states as follows:

“We take safety issues very seriously, especially with children, and we encourage parents to teach their children about safe internet practices. To learn more, visit our Safety Center.
To protect minors, we may put special safeguards in place (such as placing restrictions on the ability of adults to share and connect with them), recognizing this may provide minors a more limited experience on Facebook.”
There is therefore a clear admission from Facebook that accounts can be opened by minors and except for the warnings no other preventive measures are taken by Facebook to block minors.
It is also not easy to accept an argument that minors should be barred from using Facebook because they cannot enter into a valid contract and agree for terms and conditions.
The fact is that even adults donot have a valid contract for opening the accounts either with Facebook or Google since Indian law does not recognize the “Click Wrap Contracts” represented by the “I Gree” kind of acceptances which these websites use.
At the same time Facebook is not concerned since it does not have any financial stake if minors use the account.
From the perspective of technology development, it is also undesirable to say that a person has to be of 18 years of age to use the Facebook. At a time when 16 year olds commit rapes and murders  it is ridiculous to suggest that minors cannot use technology devices such as Facebook and Google. In fact today’s 16 year olds are more techno savvy than many older people. It will therefore be a regressive step to expect that minors cannot use social media or Google.
In fact, the Indian Majority Act itself is in need of change with the age of majority to be brought down from 18 to 16 for the contractual and CrPc purpose. The Internet use should be available under parental  supervision from at least 12 years on wards.
I remember that earlier Yahoo used to get parental consent for opening accounts of minors above 13 years of age. Today Yahoo mail account can be opened using a facebook ID or a Google ID. Hence at present even Yahoo appears to have diluted the norms of providing service to minors.
Keeping the earlier practice of Yahoo, solutions can be found to this issue which both Facebook and Google can adopt which may satisfy the concerns of the Court without affecting their business interests to a significant extent.
It would be interesting to see how these companies now respond to the Court’s order.
Even when this issue of social media is being discussed,  one can also raise the issue of whether minors can use mobile phones because mobiles also are individual communication devices though SIM cards or handsets can be owned by adults.
Naavi
Posted in ITA 2008, Uncategorized | Leave a comment

46% of Bank Customers donot trust Internet Banking System! (?)

An interesting survey conducted in three countries namely US,UK and Germany have indicated that 46% of the consumers donot trust websites which rely only on “Passwords” for authentication. (Refer findings here)

If the findings of this survey is extended to India, then it means that the Internet Banking system in India where passwords are being used as a means of authentication instead of the legally mandated “Digital Signature” is also not being trusted by the customers. Though from the research angle it may not be proper to extend the findings without appropriate correction, if we consider that “Frequent users of Internet Banking” can be equated with the profile of the website users referred to in the survey, the situation in India may be qualitatively similar.

The survey also reports that an additional factor of authentication is prefered by the users. But different customers prefer different types of additional factor of authentication such as the mobile based authentication or ID cards or biometrics. Thus the Two Factor authentication which is being pushed by RBI appears to provide some additional comfort to the customers.

The current generation intelligent malware has however grown beyond the security offered by th 2F authentication and we need to have a serious re thinking on the authentication systems that can secure Indian Banking systems.

The Digital Signature System is definitely a legally recommended choice which is the minimum compliance standard. But time is fast approaching for the industry to start looking beyond mere adoption of the digital signature system and to think of further hardening of the authentication methodologies which are legally compliant and also is technologically as good as possible.

At the same time, we need to keep in mind the factor of “Social Engineering” and “Lack of Security Awareness” as additional factors for considerations and not assume that what is technologically superior will necessarily be so in practice. We are aware how the Certifying authorities in India abuse the digital signature system and how the Controller of Certifying Authorities (CCA) is turning a blind eye to the irregularities.

Since our country has adopted the PKI system with a regulatory body controlled by the statute, the security of digital signature in usage is dependent on how effectively the system is monitored by the public authority such as the CCA.

Presently CCA would be happy just if digital signature is adopted. But this attitude needs to be quickly shifted to tightening the system so that the respect accorded to digital signatures in Indian law should not be eroded.

Naavi

Posted in Bank, Cyber Law, RBI | Leave a comment

Beware of the Micro Credit Card Fraud

Credit Cards are today being used by many of us as a means of convenience to make payments for various day to day requirements. Some times we use the same credit card also online. While the use of credit cards is on the increase, a new Micro payment scam is being reported from US.

According to this article in bloggernews.net fraudsters open a website and register themselves as “Merchants”. They then pass on small charges of 10 cents or so in the hope that card holders donot bother to check their statements and raise a dispute.

We in India might not have yet observed this sort of a fraud. However we may expect similar frauds in India also since Banks are not very vigilant in appointing the merchants.

According to the latest RBI guidelines of February 28, 2013 on Risk Mitigation, it is mandatory for Banks to ensure that the merchants are subjected to PCI DSS audits. If this is faithfully followed the risk may be contained. However credit card users need to be vigilant and check their statements without fail.

Naavi

Posted in Uncategorized | Leave a comment

Government issues clarification on Section 79 rules

The rules issued under Section 79 for Intermediaries had created a confusion in some circles about the action to be taken by the intermediary on receipt of a complaint about a specific content. Since the rules suggested that action had to be taken within 36 hours, most intermediaries had wrongly interpreted that they need to take down the objectionable content within 36 hours. This had made many intermediaries assume the role of censoring any objectionable content.

Naavi has been suggesting that this interpretation is incorrect and it would be sufficient to initiate a remedial action within 36 hours thought he resolution may require more time.

Now the DeiTy has provided the required clarification on similar lines. See the clarification here.

Naavi

Posted in Cyber Law, ITA 2008 | Leave a comment

Adjudicator Maharashtra on Privacy of employee data

In an interesting award from the Adjudicator of Maharashtra, an employer (Rud India Chains Private Limited) who fought the complaint of  an employee (Amit Patwardhan) for privacy violation with the counter charge of employee sharing confidential company data with a rival company, for financial benefit has been caught in his own web and faces the charge of wrongfully hacking into the information of the employee.

See the Judgement here

The employer has produced a bank statement of the employee as evidence that he had received some money from a rival company. However they have failed to convince the adjudicator about the legality of the means by which they have obtained the information since the Bank has denied having officially provided the data. This has lead to the inference that the employer must have obtained the information through “unauthorized access”. The Award has made a mention of recognizing the offence under Section 43(b) read with Section 66.

The Adjudicator has however not awarded any compensation or costs to anybody. There is a good logic here because it appears that the Adjudicator was otherwise convinced that the employee had made money from the rivals of the company and had not therefore come with “Clean Hands”. He has therefore considered that he should not be given any benefit as a compensation against privacy violation. At the same time the employer also cannot benefit from an illegal activity though it is to prove another activity which may be unethical and against an employment contract. So the Adjudicator has felt that he also does not deserve any benefit from law.

The judgement appears to be in accordance with the principle of natural justice and deserves to be commended.

The incident also indicates the common mistake that some litigants commit without knowing the legal implications of their action. The ill advised litigants hire the services of half baked security practitioners who help them use key loggers to hack into employee e-mails or otherwise illegally extract information to be used in a legal battle. The end result is that for sustaining a civil damage claim they expose themselves to a criminal liability.

For example now that a judicial entity such as the Adjudicator has categorically given a view that “Section 66 Offence has occurred”, the  police will not have any option but to take cognizance of the offence and proceed against the employer for criminal prosecution. On the other hand it will be difficult for them to get  civil compensation from any other Court. It is therefore a situation where the employer is doomed. Probably the blame for this should be taken by the person who advised the employer to take this route of “hacking for evidence.”. Such an activity is only possible on specific permission of a Court of law or under special powers that the Police may exercise under emergencies.

Naavi

Posted in ITA 2008, Uncategorized | 1 Comment