Congratulations!

[Valid RSS] This is a valid RSS feed.

Recommendations

This feed is valid, but interoperability with the widest range of feed readers could be improved by implementing the following recommendations.

Source: http://www.naavi.org/wp/?feed=rss2

  1. <?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
  2. xmlns:content="http://purl.org/rss/1.0/modules/content/"
  3. xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  4. xmlns:dc="http://purl.org/dc/elements/1.1/"
  5. xmlns:atom="http://www.w3.org/2005/Atom"
  6. xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  7. xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
  8. >
  9.  
  10. <channel>
  11. <title>Naavi.org</title>
  12. <atom:link href="https://www.naavi.org/wp/feed/" rel="self" type="application/rss+xml" />
  13. <link>https://www.naavi.org/wp</link>
  14. <description>Towards building Cyber Jurisprudence in India</description>
  15. <lastBuildDate>Sat, 04 May 2024 02:15:20 +0000</lastBuildDate>
  16. <language>en-US</language>
  17. <sy:updatePeriod>
  18. hourly </sy:updatePeriod>
  19. <sy:updateFrequency>
  20. 1 </sy:updateFrequency>
  21. <generator>https://wordpress.org/?v=6.0.3</generator>
  22.  
  23. <image>
  24. <url>https://www.naavi.org/wp/wp-content/uploads/2015/08/cropped-naavi_lecture2-32x32.jpg</url>
  25. <title>Naavi.org</title>
  26. <link>https://www.naavi.org/wp</link>
  27. <width>32</width>
  28. <height>32</height>
  29. </image>
  30. <item>
  31. <title>Dutch fine on Uber.. Is it justified?</title>
  32. <link>https://www.naavi.org/wp/dutch-fine-on-uber-is-it-justified/</link>
  33. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  34. <pubDate>Sat, 04 May 2024 02:06:50 +0000</pubDate>
  35. <category><![CDATA[Cyber Law]]></category>
  36. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17073</guid>
  37.  
  38. <description><![CDATA[The Dutch protection authority recently imposed a fine of Euro 10 million on Uber technologies for failure to disclose the full details of its retention periods. In this context one has to question the decision from the point of view &#8230; <a href="https://www.naavi.org/wp/dutch-fine-on-uber-is-it-justified/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  39. <content:encoded><![CDATA[
  40. <p style="text-align: justify;">The Dutch protection authority <strong><a href="https://autoriteitpersoonsgegevens.nl/en/current/uber-fined-eu10-million-for-infringement-of-privacy-regulations" target="_blank" rel="noreferrer noopener">recently imposed a fine of Euro 10 million on Uber technologies</a></strong> for failure to disclose the full details of its retention periods.</p>
  41. <p style="text-align: justify;">In this context one has to question the decision from the point of view of whether the &#8220;Uber Driver&#8217;s Data&#8221; is &#8220;Personal Data&#8221; or &#8220;Business Data&#8221; . If it is considered as &#8220;Business Data&#8221; then it should not come under the GDPR restrictions.</p>
  42. <p style="text-align: justify;">To answer this question, one has to see what is the relationship between a Uber driver and Uber. If the driver is under an employment contract then he would be treated as any other employee.</p>
  43. <p style="text-align: justify;">Otherwise if he is sharing a business commission, it is difficult to accept that the relationship is any thing other than B2C. The driver as an individual is doing business with Uber and in India we recognize him as a taxable entity different from the same individual for personal tax of non business nature.</p>
  44. <p style="text-align: justify;">The data of the driver that comes with the driving license should therefore be considered as &#8220;Business Contact Data&#8221; and &#8220;Mandatory statutory data to be retained under law&#8221;. As a Business contact data it is outside the scope of GDPR/DPDPA and as a mandatory data to be collected it is bound by the terms of agreement as a contract.</p>
  45. <p style="text-align: justify;">Any data collected by the driver of the passengers for the journey is data collected on behalf of Uber and it belongs to Uber and not the driver. The driver is a processor in this context.</p>
  46. <p>DPDPA 2023 recognizes &#8220;Business Contact Data&#8221; as a concept in the context of the DPO and hence it accepts that a &#8220;personal looking data&#8221; may actually be shared for the &#8220;Business Purpose&#8221; which can be considered different from personal data shared for processing for a service.</p>
  47. <p>For example, an Uber driver hiring another Uber car for reaching home is a customer of the second driver and his information shared is for the purpose of travelling and is like personal data. But his own data with the  Contract department is to be considered as &#8220;Business Data&#8221;. It is possible that Uber may run some welfare measures to the drivers &#8220;. In this context it may be considered similar to employee&#8217;s personal data.</p>
  48. <p style="text-align: justify;">The classification of data as &#8220;Personal&#8221; and &#8220;Non Personal&#8221; may therefore depend on the context and purpose. This needs to be identified during compliance. The process oriented classification of data under DGPSI addresses this.</p>
  49. <p style="text-align: justify;">Please let me know your views.</p>
  50.  
  51.  
  52.  
  53. <p class="has-text-align-right">Naavi</p>
  54. ]]></content:encoded>
  55. </item>
  56. <item>
  57. <title>Independent Director or  Company Secretary should be the first respondents to DPDPA compliance</title>
  58. <link>https://www.naavi.org/wp/independent-director-or-company-secretary-should-be-the-first-respondents-to-dpdpa-compliance/</link>
  59. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  60. <pubDate>Thu, 02 May 2024 01:30:07 +0000</pubDate>
  61. <category><![CDATA[Cyber Law]]></category>
  62. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17071</guid>
  63.  
  64. <description><![CDATA[After August 11, 2023, DPDPA 2023 or Digital Personal Data Protection Act 2023 has become a law in India. Though the notification of rules is pending, DPDPA 2023 as of today is considered &#8220;Due Diligence&#8221; and part of &#8220;Reasonable Security &#8230; <a href="https://www.naavi.org/wp/independent-director-or-company-secretary-should-be-the-first-respondents-to-dpdpa-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  65. <content:encoded><![CDATA[
  66. <p style="text-align: justify;">After August 11, 2023, DPDPA 2023 or Digital Personal Data Protection Act 2023 has become a law in India. Though the notification of rules is pending, DPDPA 2023 as of today is considered &#8220;Due Diligence&#8221; and part of &#8220;Reasonable Security Practice&#8221; under Sections 43A and Section 79 of ITA 2000.</p>
  67. <p style="text-align: justify;">The provisions of the Act are therefore considered effective as of now though the penalty clauses may not be fully relevant. However the Adjudicator under ITA 2000 has the powers to impose penalties if there is an adequate cause of action and may use the penalty table under DPDPA 2023 as a guidance.</p>
  68. <p style="text-align: justify;">To be fair however, no Adjudicator in India may be aware of this power nor are inclined to use them. So the companies who want to procrastinate can breath easily for some more time. Assuming that the Modi Government comes back to power after the elections, the notification of rules may be in the First 100 day agenda.</p>
  69. <p style="text-align: justify;">Hence companies need to start working on compliance today.</p>
  70. <p style="text-align: justify;">If however we try to identify the accountability at corporate level on who has to raise the red flag first, it appears that only the CISOs/CIOs or GDPR aware CCOs/designated privacy officers are the first to recognize the potential impact of the DPDPA and trying to draw the attention of their Board into sanctioning budgets for next level action.</p>
  71. <p style="text-align: justify;">Ideally it should have been the &#8220;Independent Directors&#8221; or the &#8220;Company Secretaries&#8221; who should have brought it to the notice of the Board the need to initiate compliance action.</p>
  72. <p style="text-align: justify;">Given the importance of DPDPA compliance and the need to cover the potential penalty risk, associations of these professionals need to draw the attention of these professionals to start understanding their specific responsibility in this regard.</p>
  73. <p style="text-align: right;">Naavi</p>
  74. <p> </p>
  75. ]]></content:encoded>
  76. </item>
  77. <item>
  78. <title>&#8220;Product-DTS&#8221; -an evaluation of  &#8220;Compliance Ready  when in use&#8221; status  under DGPSI</title>
  79. <link>https://www.naavi.org/wp/product-dts-an-evaluation-of-compliance-readiness-when-in-use-crwiu-under-dgpsi/</link>
  80. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  81. <pubDate>Tue, 30 Apr 2024 03:44:43 +0000</pubDate>
  82. <category><![CDATA[Cyber Law]]></category>
  83. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17055</guid>
  84.  
  85. <description><![CDATA[DGPSI (Data Governance and Protection Standard of India which is the premier framework for DPDPA Compliance in India) focusses on compliance of Data Fiduciaries who process personal data collected from India. It includes compliance requirements under DPDPA 2023, ITA 2000 &#8230; <a href="https://www.naavi.org/wp/product-dts-an-evaluation-of-compliance-readiness-when-in-use-crwiu-under-dgpsi/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  86. <content:encoded><![CDATA[
  87. <div class="wp-container-1 is-content-justification-center is-nowrap wp-block-group has-small-font-size">
  88. <div class="wp-block-tpgb-tp-image tpgb-image tpgb-block-490b_17055"><figure class="tpgb-figure"><img src="http://www.naavi.org/wp/wp-content/uploads/2024/01/dgpsi_no_base_line-300x253.jpg" class="tpgb-img-inner"/></figure></div>
  89. </div>
  90.  
  91.  
  92.  
  93. <p style="text-align: justify;">DGPSI (Data Governance and Protection Standard of India which is the premier framework for DPDPA Compliance in India) focusses on compliance of Data Fiduciaries who process personal data collected from India. It includes compliance requirements under DPDPA 2023, ITA 2000 and BIS standard for Data Governance.</p>
  94. <p style="text-align: justify;">A Data Fiduciary often conducts its business with the assistance of software suppliers. may  supply products or software services. </p>
  95. <p style="text-align: justify;">If the service provider is providing service as exactly prescribed by the DF, then he will  be a Data Processor whose obligations are only to follow instructions in the contract and the compliance obligations are borne by the DF.</p>
  96. <p style="text-align: justify;">In many practical instances, the service provider either does not reveal the complete details of the “Means of processing” either because he treats them as his trade secret or he is too big for the DF. Most cloud service providers fall into this category.</p>
  97. <p style="text-align: justify;">In such cases, the DF who determines the purpose of processing is not in control of the “Means of processing”.</p>
  98. <p style="text-align: justify;">Hence such data processors may have the responsibility of the Data Fiduciary (DF) under the law though we all may call them as  &#8220;Data Processors&#8221;. </p>
  99. <p style="text-align: justify;">DGPSI addresses this issue by defining the role of the service provider as a “Joint Data Fiduciary” and makes him directly responsible for the compliance.</p>
  100. <p style="text-align: justify;">In many cases the service of the service provider is contracted through dotted line contracts and not through negotiated contracts. Hence the DF is forced to pick a service available on the web by simply clicking the “I accept” button for the terms of service along with the privacy policy of the service provider.</p>
  101. <p style="text-align: justify;">In such cases the DF is expected to at least send a proper notice to the service provider that the DF treats him as a Joint Data Fiduciary for the purpose of compliance of DPDPA 2023 and tries to get an acknowledgement.</p>
  102. <p style="text-align: justify;">Going further, some DFs may request the service provider to produce an assurance in the form of an audit such as ISO 13485 for medical devices or FDA CFR audit certification.</p>
  103. <p style="text-align: justify;">The same issue arises when an AI service is provided in the form of an algorithm or managed services.</p>
  104. <p style="text-align: justify;">DGPSI considers such sub systems as a “Compliance Entity” and expects them to separately be assessed for compliance of DPDPA as if that sub system is an enterprise by itself.</p>
  105. <p style="text-align: justify;">In such cases, the AI algorithm becomes the subject “Data Fiduciary” which is required to be compliant with the DPDPA 2023.</p>
  106. <p style="text-align: justify;">Hence the AI algorithm has to be evaluated on the basis of</p>
  107.  
  108.  
  109.  
  110. <ol type="1"><li>Who is the owner of the algorithm</li><li>What personal data elements it collects and from where?</li><li>Is there a Consent or other forms of established legal basis for processing?</li><li>What is the evidence that there is a notice and consent?</li><li>Who accesses the personal data and why at the time of processing or storage as long as it is within the control of the algorithm</li><li>How does the “Rights of data principals fulfilled”?</li><li>How does security of data handled and &nbsp;“Breach” gets recognized?</li><li>How does other obligations like handling of cross border restrictions, minor data handling and nomination handling etc addressed by the algorithm owner?</li><li>What does the contractual terms of use state in terms of inter-se obligations of compliance?</li></ol>
  111.  
  112.  
  113.  
  114. <p style="text-align: justify;">The Data Trust Score mechanism of DGPSI addresses an evaluation of these requirements against the parameters used for compliance and through some weightage system arrives at a score which is called the &#8220;DTS&#8221;. We have already discussed <a href="https://www.naavi.org/wp/the-challenge-of-webdts-compliance/" target="_blank" rel="noopener">Web-DTS</a> and <a href="https://www.naavi.org/wp/intersection-point-for-eu-ai-act-and-dgpsi-ai-dts/" target="_blank" rel="noopener">AI-DTS</a> as two concepts covering compliance of the website and an AI algorithm.</p>
  115. <p style="text-align: justify;">A similar system is now being applied for vendors of specific devices or services to evaluate whether during the lifecycle of the data processing that happens within the service, the obligations of DPDPA is complied with and if so how.</p>
  116. <p style="text-align: justify;">This evaluation can be done only if there is a specific context in which we are aware what type of data is collected and processed.</p>
  117. <p style="text-align: justify;">However there will be some instances where a device or a system supplier would kike to claim that &#8220;When you use our products, you can meet your regulatory obligations&#8221;. This would be like evaluating a product for &#8220;Compliance Readiness When in use&#8221;.</p>
  118. <p style="text-align: justify;">This compliance ready evaluation has to assume a context which is representative of the most relevant use case and makes an assessment.</p>
  119. <p style="text-align: justify;">&#8220;Compliance Ready-when in use&#8221; is evaluation is  a DTS evaluation that represents the maturity of the product or service which addresses this issue. We may simply call them &#8220;Product-DTS&#8221; for easy reference.</p>
  120. <p style="text-align: justify;">When it comes to evaluation of AI algorithms, the DGPSI will draw from the EU-AI act to define the risk etc. Similarly when it comes to medical devices, DGPSI will draw from ISO 13485. With such an approach, DGPSI will remain the unified approach for compliance not only at the &#8220;Data Fiduciary&#8221; but also at the &#8220;Joint Data fiduciary&#8221; who is a contract partner of the Data Fiduciary .</p>
  121. <p style="text-align: justify;">Attend FDPPI training programs to discuss this further.</p>
  122.  
  123.  
  124.  
  125. <p>(Comments are welcome)</p>
  126.  
  127.  
  128.  
  129. <p class="has-text-align-right">Naavi</p>
  130. ]]></content:encoded>
  131. </item>
  132. <item>
  133. <title>Mumbai High Court should apologize to citizens of India for their  Kunal Kamra judgement.</title>
  134. <link>https://www.naavi.org/wp/mumbai-high-court-should-apologize-to-citizens-of-india-for-their-kunal-kamra-judgement/</link>
  135. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  136. <pubDate>Tue, 30 Apr 2024 01:35:16 +0000</pubDate>
  137. <category><![CDATA[Cyber Law]]></category>
  138. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17052</guid>
  139.  
  140. <description><![CDATA[As expected Congress has used a &#8220;Fake video&#8221; of Mr Amit Shah to falsely claim that Mr Amit Shah has stated that if it comes to power, BJP will remove reservations to SC/ST etc. Actually he had said that BJP &#8230; <a href="https://www.naavi.org/wp/mumbai-high-court-should-apologize-to-citizens-of-india-for-their-kunal-kamra-judgement/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  141. <content:encoded><![CDATA[
  142. <figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
  143. <iframe loading="lazy" title="Amit Shah Fake Video: Debunking the Fake Video of Amit Shah On Reservations" width="640" height="360" src="https://www.youtube.com/embed/DEcBvhcdDsM?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
  144. </div></figure>
  145.  
  146.  
  147.  
  148. <p style="text-align: justify;">As expected Congress has used a &#8220;Fake video&#8221; of Mr Amit Shah to falsely claim that Mr Amit Shah has stated that if it comes to power, BJP will remove reservations to SC/ST etc. Actually he had said that BJP will remove the unconstitutional reservation given to Muslims on the basis of religion.</p>
  149. <p style="text-align: justify;">This was not a simple fake video like the Rakshita Mandanna case which was a case of personal reputation damage to a celebrity. In another instance, Rahul Gandhi&#8217;s video was modified to remove words about &#8220;Hindustan&#8217;s Ka &#8230;&#8221; when he was referring to redistribution of wealth .&#8221;Removal of some portions of the video&#8221; is also a fake video meant to alter the meaning of the electronic document.</p>
  150. <p style="text-align: justify;">On the other hand the Amit Shah video included removal of a portion and re-arrangement to some extent.</p>
  151. <p style="text-align: justify;">I am certain that before the election is over, we will have an even more dangerous fake video in the name of Mr Modi himself which may be created for the purpose of filing a complaint with the election commission. We will come to know only if such videos come to public but if they are being circulated in private circles of voters, we will ever come t know.</p>
  152. <p style="text-align: justify;">It is important that NIA should take over the Amit Shah case and investigate since this is a gross violation which includes Section 66, 66C, 66D and 66F of ITA 2000 besides some IPC sections. It also involves conspiracy since it was distributed. Section 79 and Section 85 may also be invoked to fix the liabilities of the intermediaries who facilitated the distribution of the video.</p>
  153. <p style="text-align: justify;">Mr Revant Reddy may not be directly responsible, but is definitely carrying the vicarious liability and should co-operate in the investigation.</p>
  154. <p style="text-align: justify;">The investigation should be carried out immediately (as is being done) so that culprits are put behind bars before the next phase of elections.</p>
  155. <p style="text-align: justify;">In this context I want to recall the Mumbai High Court judgement in the case of Kunal Kamra where one judge did not see the danger of the fake news and did not uphold the right of the Government to at least call out fake news distributed in respect of the Government bodies.</p>
  156. <p style="text-align: justify;">Judges have their own biased views and often their judgements are not based on neutral evaluation. The judgement on Kunal Kamra case was one such instance which was however saved to some extent by one of the judges taking a right stand. But this was sufficient for the Supreme Court to stay further action by the Government and the media to keep blaming the Government.</p>
  157. <p style="text-align: justify;">Now the WhatsAPP case is before the Government and the lawyers are already speaking falsehood and creating the ground for the Judges to give wrong judgements. I wish the Judges be aware that technology is being not only misused by people but are also mis represented in the Courts.</p>
  158. <p style="text-align: justify;">For example, WhatsApp is arguing that if they agree to &#8220;Identification of the original forwarder of a message&#8221;, it has to break the encryption and therefore the Privacy of the message. This is falsehood and the petitioners have to be castigated for making such wrong claims.</p>
  159. <p style="text-align: justify;">Adding a header information to an encrypted message is not breaking the encryption of the message. It may require some technology changes but is not to be considered as impossible. Hence the Court should not accept this false argument.</p>
  160. <p style="text-align: justify;">Instead, Court should ask WhatsApp why their grievance redressal system requires customers to go to US courts/Arbitration and not settle it within the Indian jurisdiction and why they have different privacy policies for EU, US and India?</p>
  161. <p style="text-align: justify;">If WhatsApp threatens to leave India, it only shows their arrogance. To some extent Courts are responsible for this arrogance since the Supreme Court and several High Courts have honoured WhatsApp in the past with recognition of the blue tick etc. and become dependent themselves.</p>
  162. <p style="text-align: justify;">The dependency of India on WhatsApp as a messaging platform is not desirable and is a national risk. Just as there was movement against Zoom at one point of time (which was not justified fully), monopoly of WhatsApp must be broken by encouraging indigenous solutions.</p>
  163. <p style="text-align: justify;">This should be possible even with the preservation of end to end encryption from the user to user which is more effective than the device to device encryption currently used by WhatsApp (with an ability for itself to decrypt if required.).</p>
  164. <p style="text-align: justify;">The messaging platform needs to become a carrier of message only and whether the payload is encrypted or not should be the choice of the messaging parties. Use of two key encryption should be actually more effective than the current device to device encryption.</p>
  165. <p style="text-align: justify;">Hopefully the Courts will treat these technology related cases with an admission of their own ignorance and offer apologies when they make a mistake. One such apology is due from the Mumbai judge who did not foresee the dangers of fake news.</p>
  166. <p style="text-align: right;">Naavi</p>
  167.  
  168.  
  169.  
  170. <p><strong>Also read:</strong></p>
  171.  
  172.  
  173.  
  174. <p><a href="https://www.naavi.org/wp/we-want-license-to-misinform/" target="_blank" rel="noreferrer noopener">We Want License to Misinform?</a></p>
  175. ]]></content:encoded>
  176. </item>
  177. <item>
  178. <title>WhatsApp threatens Bharath : Great opportunity for indigenous firms</title>
  179. <link>https://www.naavi.org/wp/whatsapp-threatens-bharath-great-opportunity-for-indigenous-firms/</link>
  180. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  181. <pubDate>Sat, 27 Apr 2024 02:25:24 +0000</pubDate>
  182. <category><![CDATA[Cyber Law]]></category>
  183. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17045</guid>
  184.  
  185. <description><![CDATA[In a high court proceeding in Delhi High Court challenging the Intermediary Guidelines WhatsApp has threatened that if the Government of India goes ahead with implementation of its Intermediary Guidelines, it may be forced to quit India. WhatsApp is perhaps &#8230; <a href="https://www.naavi.org/wp/whatsapp-threatens-bharath-great-opportunity-for-indigenous-firms/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  186. <content:encoded><![CDATA[
  187. <p style="text-align: justify;">In a high court proceeding in Delhi High Court challenging the Intermediary Guidelines WhatsApp has threatened that if the Government of India goes ahead with implementation of its Intermediary Guidelines, it may be forced to quit India.</p>
  188. <p style="text-align: justify;">WhatsApp is perhaps emboldened by the fact that Indian Judiciary including the Supreme Court have been naive enough in recent times to judicially accept WhatsApp messages for sending Court notices etc developing a dependency which would create some operational problems if WhatsApp quits.</p>
  189. <p style="text-align: justify;">The reason behind this is that the Government of India has for security reasons stated that if required and a proper notice is served, WhatsAPP should be able to provide the origin of messages in WhatsApp. This does not need decryption of the message but only the header information.</p>
  190. <p style="text-align: justify;">It is possible that in certain cases decryption of messages may be required for national security reasons. In such cases, whether it is WhatsAPP/Meta or Apple, there should not be an embargo that no such demand would be made.</p>
  191. <p style="text-align: justify;">At best, it can be made subject to a quasi judicial committee consisting of a special judge of Supreme Court along with the designated representatives of Meity and MOH for quick decision making in times of crisis.</p>
  192. <p style="text-align: justify;">According to this <a href="https://www.hindustantimes.com/india-news/then-whatsapp-goes-firm-warns-delhi-high-court-of-india-exit-over-encryption-101714096354368.html?utm_source=ht_site_copyURL&amp;utm_medium=social&amp;utm_campaign=ht_site" target="_blank" rel="noreferrer noopener">report in Hindustan Times</a> Mr Tejas Karla, the counsel of WhatsAPP has told the High Court that without the concurrence of WhatsApp, Government of India has no right to introduce such rules.</p>
  193. <p style="text-align: justify;">The contention of WhatsApp which is a commercial entity owned by a US Citizen is in principle unacceptable. It is a rebellion against the sovereignty of India. It has no such fundamental rights and it has no right to represent the Indian citizens for their fundamental rights only to protect the commercial interests of the company.</p>
  194. <p>WhatsApp has also threatened that</p>
  195. <p style="text-align: justify;">&#8220;Requiring messaging apps to &#8216;trace&#8217; chats is the equivalent of asking us to keep a fingerprint of every single message sent on WhatsApp, which would break end-to-end encryption and fundamentally undermines people&#8217;s right to privacy,&#8230; and such an action could a message could disturb the peace and harmony in the country and could pose public order issues.&#8221;</p>
  196. <p style="text-align: justify;">The Company has therefore admitted that a message when decrypted could pose public order issues meaning that it was inherently a message that was meant to destabilize public order within a community. It&#8217;s argument is that this conspiracy should be allowed to continue and not be exposed.</p>
  197. <p style="text-align: justify;">The Court should not only reject this argument but also castigate the company to have taken such a stand against the sovereign rights of the company.</p>
  198. <p style="text-align: justify;">In the meantime, Naavi.org has been suggesting companies to switch over to indigenous applications which may provide similar services in a &#8220;Cyber Law Compliant Manner&#8221;. There could be more than one such solution to be available and we have come across one such application called &#8220;Ledger Chat&#8221; which provides the functionalities of WhatsApp within the Indian legal jurisdiction. Presently it is being used for Corporate requirements and can be used by Supreme Court or the High Court.</p>
  199. <p style="text-align: justify;">Considering the volume of information to be handled in public domain, the app can be used by other intermediaries including network giants like Tata Telecom to develop a WhatsApp equivalent services without riding on the foreign powers like WhatsApp.</p>
  200. <p>I hereby request Ledger Chat to</p>
  201. <p style="text-align: justify;">a) Implead in the suit in Delhi High Court and present its product as a solution to replace WhatsApp.</p>
  202. <p style="text-align: justify;">b) Provide the solution to Delhi High Court and Supreme Court for their use if necessary in association with a reputed company like Tat Telecom.</p>
  203. <p style="text-align: justify;">I request the advocates representing the Government not to yield to the WhatsApp arguments as they tend to do in the past. We are aware of the enormous financial muscle of WhatsApp to sway opinions but we hope there are still enough nationalists left in the Judicial system in India who will uphold that the country cannot be held to ransom by these companies.</p>
  204. <p style="text-align: justify;">I am aware that a bigger threat awaits if similar stand is taken by Google and Microsoft and we as a Country have to be ready to meet such challenges.</p>
  205. <p style="text-align: justify;">Hopefully if Modi is around, we can atleast demand this from the Government whether it is done or not. For advocates who represent such parties without remembering that their duty is to &#8220;Justice&#8221;, I would like to say that your first duty is to protect the nation and representing a client is only secondary.  For those advocates who still have a ethical mindset, kindly contact LegerChat company and offer to represent them in the Delhi High Court. Any IT solutions integrator who is interested in taking this solution to the Delhi High Court and Supreme Court should also contact them and offer help. In case there are any other similar solution providers they are welcome to contact Naavi.org so that their solutions can also be highlighted.  </p>
  206. <p>More info on LedgerChat is available here: https://ledgerfi.io/</p>
  207.  
  208.  
  209.  
  210. <p class="has-text-align-right">Naavi</p>
  211.  
  212.  
  213.  
  214. <p><strong>Comments Received and Our views</strong></p>
  215.  
  216.  
  217.  
  218. <p>Comment 1: India may not be able to create a product at a global scale. Koo did not succeed.</p>
  219.  
  220.  
  221.  
  222. <p>Comment 2: Data Security in messaging can be preserved through e2e encryption and WhatsApp is guaranteeing it. What is the need for putting 140 crores under surveillance by providing the option to break the e2e.</p>
  223.  
  224.  
  225.  
  226. <p>Comment 3: WhatsApp is used globally . The sender and receiver should both be using the same messaging app.</p>
  227.  
  228.  
  229.  
  230. <p><strong>My Views:</strong></p>
  231.  
  232.  
  233.  
  234. <p style="text-align: justify;">I donot think that India cannot create a global scale product. Our software engineers sit with other MNCs and create the products which today are considered as global products. It is a journey and we need to support the Made In India initiative. The scaling up for global use depends on the network capacity and there could be issues that should be sorted out. Koo did not succeed because we did not support it. Had we supported it and had Mr Modi and his team supported it, it could have succeeded. (<a href="https://www.bing.com/search?cp=CODE+PAGE+USED+BY+YOUR+HTML+PAGE&amp;FORM=FREESS&amp;q=koo&amp;q1=site%3Awww.naavi.org" target="_blank" rel="noreferrer noopener">Refer various articles on Koo at naavi.org</a>). Finally Twitter failed for its own reasons and sold out to X. X is trying to re-engineer the model and we need to wait and see how their model will succeed.</p>
  235. <p style="text-align: justify;">WhatsApp may have e2e encryption from device to device. What is important for us to recognize is that WhatsApp is lying when it says that the Government wants the encryption to be broken. What the Government has stated is that every message needs to have a &#8220;Origination ID&#8221; when it enters the systems in India. This means that the customers of WhatsApp should be tagged as &#8220;Indian&#8221; and &#8220;Non Indian&#8221;. When a message is received by the Indian, it should be assigned with a header information which contains the message ID. Any further forwarding of the message should identify &#8220;Message Id&#8221;, &#8220;From&#8221; and &#8220;To&#8221; . There is no need to break the message encryption. Hence &#8220;Surveillance&#8221; of 140 crores does not arise. These are falsehood circulated by WhatsApp and its lawyers.</p>
  236. <p style="text-align: justify;">Every messaging application as a platform wants both to be on the platform. But if customer@gmail.com can send a message to customer@hotmail.com, there can be a message exchange system that can send and receive messages across multiple messaging platforms. It may require some standardization but is not impossible.</p>
  237.  
  238.  
  239.  
  240. <p class="has-text-align-right">Naavi</p>
  241. ]]></content:encoded>
  242. </item>
  243. <item>
  244. <title>Sanatan Economics&#8230; A wonderful analysis</title>
  245. <link>https://www.naavi.org/wp/sanatan-economics-a-wonderful-analysis/</link>
  246. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  247. <pubDate>Thu, 25 Apr 2024 01:31:00 +0000</pubDate>
  248. <category><![CDATA[Cyber Law]]></category>
  249. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17039</guid>
  250.  
  251. <description><![CDATA[This video introduces a beautiful interpretation of economics and compares the Capitalism, Communalism and the unique concept which Dr Ankit Shah the speaker speaks about Sanatan Economics.  The video has emerged consequence  of the Rahul Gandhi Concept of &#8220;Re-distribution  of &#8230; <a href="https://www.naavi.org/wp/sanatan-economics-a-wonderful-analysis/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  252. <content:encoded><![CDATA[
  253. <p style="text-align: justify;">This video introduces a beautiful interpretation of economics and compares the Capitalism, Communalism and the unique concept which Dr Ankit Shah the speaker speaks about Sanatan Economics. </p>
  254. <p><iframe loading="lazy" title="Is Congress Wealth Redistribution Idea Dharmic? • What does Sanatana Economics say? • Dr Ankit Shah" width="640" height="360" src="https://www.youtube.com/embed/Mjw8crA648k?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
  255. <p style="text-align: justify;">The video has emerged consequence  of the Rahul Gandhi Concept of &#8220;Re-distribution  of wealth&#8221;. But what has emerged is a new knowledge which has application in many other fields.</p>
  256. <p style="text-align: justify;">The Concept revolves around &#8220;Dharma&#8221; and &#8220;Karma&#8221;&#8230;which is &#8220;Obligation&#8221; and &#8220;Duties&#8221;. The speaker also discusses how the &#8220;Temples&#8221; acted as an &#8220;Intermediary&#8221; to ensure that the society follows Dharma through the institution of Temples and how &#8220;Food Security&#8221; was ensured through the system of &#8220;Prasadam&#8221;.</p>
  257. <p style="text-align: justify;">I wish readers do not look at this as a political idea but appreciate the new concept.</p>
  258. <p style="text-align: justify;">Comments are welcome.</p>
  259. <p style="text-align: right;">Naavi</p>
  260. ]]></content:encoded>
  261. </item>
  262. <item>
  263. <title>Nip this Apple air-pod in the bud.</title>
  264. <link>https://www.naavi.org/wp/nip-this-apple-air-pod-in-the-bud/</link>
  265. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  266. <pubDate>Tue, 23 Apr 2024 02:59:55 +0000</pubDate>
  267. <category><![CDATA[Cyber Law]]></category>
  268. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17032</guid>
  269.  
  270. <description><![CDATA[The article published yesterday about &#8220;Digital Marketing&#8221; and its future in the society increasingly becoming sensitive to Privacy issues has evoked a few responses from other professionals. One such response worth noting is the linked in article &#8220;Neuro Data, Capitalism &#8230; <a href="https://www.naavi.org/wp/nip-this-apple-air-pod-in-the-bud/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  271. <content:encoded><![CDATA[
  272. <p style="text-align: justify;">The article published yesterday about &#8220;Digital Marketing&#8221; and its future in the society increasingly becoming sensitive to Privacy issues has evoked a few responses from other professionals.</p>
  273. <p style="text-align: justify;">One such response worth noting is the linked in article &#8220;Neuro Data, Capitalism &amp; Privacy Regulation&#8221; by Deepti Bhatia. (Incidentally Deepti is the President of Delhi Chapter of FDPPI).</p>
  274. <p style="text-align: justify;">In this article, Deepti raises many issues requiring further debate. We shall take one issue issue raised in this article for discussion today and that is the &#8220;Apple Patent on a Bio sensor embedded air pods&#8221;.</p>
  275. <p style="text-align: justify;">We have discussed &#8220;Neuro Rights&#8221; extensively in this website in the past and highlighted how Brain Computer interfaces, Humanoid Robots and CyBorgs with AI could transform the society in directions that may not be desirable. In such discussions, we have factored the raise of technology in neuro science which can read brain waves either through electrodes fixed on a skull cap or a chip embedded surgically inside the human skull.</p>
  276.  
  277.  
  278. <div class="wp-block-image">
  279. <figure class="aligncenter size-full"><img loading="lazy" width="463" height="618" src="https://www.naavi.org/wp/wp-content/uploads/2024/04/neuro_sensors.png" alt="" class="wp-image-17033" srcset="https://www.naavi.org/wp/wp-content/uploads/2024/04/neuro_sensors.png 463w, https://www.naavi.org/wp/wp-content/uploads/2024/04/neuro_sensors-225x300.png 225w" sizes="(max-width: 463px) 100vw, 463px" /></figure></div>
  280.  
  281.  
  282. <p style="text-align: justify;">In using such devices there was a &#8220;Technology Barrier&#8221; that would restrict the wide use of such technologies.</p>
  283. <p style="text-align: justify;">However Technology has now progressed alarmingly with Apple applying their skills to develop a wearable which can perhaps read brain waves and claiming a patent.</p>
  284. <p style="text-align: justify;"><a href="https://patentscope.wipo.int/search/en/detail.jsf?docId=US402825807&amp;_cid=P10-LRT3OJ-01103-1" target="_blank" rel="noreferrer noopener">The US patent number US20230225659 titled &#8220;Biosignal sensing device using dynamic selection of electrodes&#8221;</a> is a dangerous patent that makes the common discussions on &#8220;Deceptive Privacy Invasion techniques through Dark Pattern&#8221; look absolutely childish.</p>
  285. <p style="text-align: justify;">This device is being designed as &#8220;Airpods&#8221; looking just like normal airpods and hiding all the electrodes that make the earlier devices clumsy.</p>
  286.  
  287.  
  288.  
  289. <figure class="wp-block-table aligncenter"><table><tbody><tr><td><img loading="lazy" width="234" height="132" src="http://www.naavi.org/wp/wp-content/uploads/2024/04/airpod_neuros_Signal_reading.webp" alt=""/></td><td><img loading="lazy" width="489" height="671" class="wp-image-17034" style="width: 150px;" src="http://www.naavi.org/wp/wp-content/uploads/2024/04/apple_bio_sensor_airpod.png" alt="" srcset="https://www.naavi.org/wp/wp-content/uploads/2024/04/apple_bio_sensor_airpod.png 489w, https://www.naavi.org/wp/wp-content/uploads/2024/04/apple_bio_sensor_airpod-219x300.png 219w" sizes="(max-width: 489px) 100vw, 489px" /></td></tr></tbody></table></figure>
  290.  
  291.  
  292.  
  293. <p style="text-align: justify;">Further the Apple device can be used for deceptive marketing since it can capture signals such as brain waves, muscle movements etc. It can be much more than the wearables like the Watch and interact directly with the brain activity to read the &#8220;Neuro-data&#8221; generated by the humans.</p>
  294. <p style="text-align: justify;">The background of the invention states:</p>
  295. <p style="text-align: justify;">Brain activity can be monitored using electrodes placed on the scalp of a user. The electrodes may in some cases be placed inside or around the outer ear of the user. Measuring of the brain activity using electrodes placed in or around the outer ear may be preferred due to benefits such as reduced device mobility and decreased visibility of the electrodes when compared to other devices that require electrodes to be placed on visible areas around the scalp of the user&#8230;&#8221;</p>
  296. <p style="text-align: justify;">In this context the invention is designed as a wearable where the electrodes are invisible. Hence this is eminently suited for deceptive marketing and taking over of human brain activity through remote influence exercised on the human brain.</p>
  297. <p style="text-align: justify;">Imagine that a person wearing this airpod is taking a buying decision. The airpod server knows the buying intention and can broadcast it to vendors who can instantly bid for neuro messages to be sent to influence the purchase in favour of one supplier over the other. This would be like the dynamic advertisement that would be displayed when you search for a product on google.</p>
  298. <p style="text-align: justify;">The society should recognize the potential for misuse of this technology and take steps that such technologies are killed in the bud.</p>
  299. <p style="text-align: justify;">I urge Indian law makers and particularly Mr Rajeev Chandrashekar (expected to be back as IT Minister) to ensure that this AI device should be banned for sale in India or made subject to very strict licensing.</p>
  300. <p style="text-align: justify;">The IPR authorities should also re-consider if they should provide IPR protection to such devices.</p>
  301. <p style="text-align: justify;">In most of the new Privacy laws, IPR is always respected and granted an exemption. But the time has come to put reigns on IPR through other laws. Forget the international treaties on IPR, it is time to reign in IPR laws in preference to laws that are meant to protect the human society.</p>
  302. <p style="text-align: justify;">Let us remember that Technology can be disruptive but not destructive.</p>
  303.  
  304.  
  305.  
  306. <p class="has-text-align-right">Naavi</p>
  307.  
  308.  
  309.  
  310. <p><strong>Refer also:</strong></p>
  311.  
  312.  
  313.  
  314. <p><strong><a href="https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6479924/" target="_blank" rel="noreferrer noopener">Wearable system for bio signal acquisition and monitoring&#8230;</a></strong></p>
  315. ]]></content:encoded>
  316. </item>
  317. <item>
  318. <title>How Will Digital Marketing Survive DPDPA?</title>
  319. <link>https://www.naavi.org/wp/how-will-digital-marketing-survive-dpdpa/</link>
  320. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  321. <pubDate>Mon, 22 Apr 2024 03:29:14 +0000</pubDate>
  322. <category><![CDATA[Cyber Law]]></category>
  323. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17030</guid>
  324.  
  325. <description><![CDATA[One of the industries which is directly under threat of survival after DPDPA is the &#8220;Digital marketing industry&#8221;. Marketing requires understanding the consumer&#8217;s buying behaviour and creating a communication that convinces the prospective customer that a given product or service &#8230; <a href="https://www.naavi.org/wp/how-will-digital-marketing-survive-dpdpa/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
  326. <content:encoded><![CDATA[
  327. <p style="text-align: justify;">One of the industries which is directly under threat of survival after DPDPA is the &#8220;Digital marketing industry&#8221;.</p>
  328. <p style="text-align: justify;">Marketing requires understanding the consumer&#8217;s buying behaviour and creating a communication that convinces the prospective customer that a given product or service satisfies the requirement of the consumer.</p>
  329. <p style="text-align: justify;">The principle of AIDAS namely, Creating Awareness, Generating Interest, Eliciting a Desire, making the product available and achieving satisfaction in the post sale scenario is the formula for successful marketing of any product or service.</p>
  330. <p style="text-align: justify;">If Marketing does not exist, then the products and services will wither away.</p>
  331. <p style="text-align: justify;">An excessive importance to placing restrictions on Consumer Marketing will eventually increase the cost of the product which will fall on the consumer. If the consumer is vary of bearing this cost, he will reject all offers other than the existing brands about which he already has some information. This means that &#8220;New Products&#8221; and &#8220;New Companies&#8221; will have a tough time to promote their existence.</p>
  332. <p style="text-align: justify;">Have we as Privacy professionals thought about the difficulties in &#8220;Profiling&#8221; and &#8220;Targeted Advertising&#8221; that any privacy law considers as abhorring?</p>
  333. <p style="text-align: justify;">Has the Digital Marketing Industry thought of how they will survive the post DPDPA scenario in India? . If they try any tricks to hood wink the consumer, they may be accused of practicing &#8220;Dark Patterns&#8221;. If they are too open and ask for consents, they need to be ready for about a response which will be not more than 1% .</p>
  334. <p style="text-align: justify;">If we look at the responses for &#8220;Pay Per Clicks&#8221; advertising vs &#8220;Banner Ads&#8221; and the responses in specific sites like Linked in vs advertising in Blogs we will understand that the Clickthrough rate for social media is around 1.36 % (<a href="https://www.statista.com/statistics/872099/social-media-advertising-ctr/" target="_blank" rel="noreferrer noopener">Q2 2023 statistics</a>). This is for a product which is advertised. If we consider &#8220;Request for Consent&#8221; as an advertisement, then the click through could be even less.</p>
  335. <p style="text-align: justify;">This means that to get 1 consent, an organization may have to spend cost of 100 notices. Currently the &#8220;Privacy Policies&#8221; as a &#8220;Declaration&#8221; does not require a specific consent.</p>
  336. <p style="text-align: justify;">This scenario is an existential threat to Digital Marketing Companies.</p>
  337. <p style="text-align: justify;">As consultants it is difficult for us to either advise an organization to ignore this risk or to provide a suitable compliance solution.</p>
  338. <p style="text-align: justify;">Unfortunately the Digital marketing industry and Internet advertising industry in India has not woken up to the problems and designing a sectoral approach to counter the business risks.</p>
  339. <p style="text-align: justify;">I invite industry professionals to write back and let us know what can be done in this aspect.</p>
  340.  
  341.  
  342.  
  343. <p class="has-text-align-right">Naavi</p>
  344. ]]></content:encoded>
  345. </item>
  346. <item>
  347. <title></title>
  348. <link>https://www.naavi.org/wp/17026-2/</link>
  349. <comments>https://www.naavi.org/wp/17026-2/#respond</comments>
  350. <dc:creator><![CDATA[Vijayashankar Na]]></dc:creator>
  351. <pubDate>Mon, 22 Apr 2024 02:40:45 +0000</pubDate>
  352. <category><![CDATA[Cyber Law]]></category>
  353. <guid isPermaLink="false">https://www.naavi.org/wp/?p=17026</guid>
  354.  
  355. <description><![CDATA[]]></description>
  356. <content:encoded><![CDATA[<div class="wp-block-image">
  357. <figure class="aligncenter size-full"><img loading="lazy" width="764" height="106" src="https://www.naavi.org/wp/wp-content/uploads/2024/04/gukesh.png" alt="" class="wp-image-17027" srcset="https://www.naavi.org/wp/wp-content/uploads/2024/04/gukesh.png 764w, https://www.naavi.org/wp/wp-content/uploads/2024/04/gukesh-300x42.png 300w" sizes="(max-width: 764px) 100vw, 764px" /></figure></div>]]></content:encoded>
  358. <wfw:commentRss>https://www.naavi.org/wp/17026-2/feed/</wfw:commentRss>
  359. <slash:comments>0</slash:comments>
  360. </item>
  361. </channel>
  362. </rss>
  363.  

If you would like to create a banner that links to this page (i.e. this validation result), do the following:

  1. Download the "valid RSS" banner.

  2. Upload the image to your own server. (This step is important. Please do not link directly to the image on this server.)

  3. Add this HTML to your page (change the image src attribute if necessary):

If you would like to create a text link instead, here is the URL you can use:

http://www.feedvalidator.org/check.cgi?url=http%3A//www.naavi.org/wp/%3Ffeed%3Drss2

Copyright © 2002-9 Sam Ruby, Mark Pilgrim, Joseph Walton, and Phil Ringnalda