Showing posts with label Praveen Dalal. Show all posts
Showing posts with label Praveen Dalal. Show all posts

Friday, 2 March 2012

Electronic Commerce Laws In India

Electronic commerce is the buzz word these days. Many national and international players are exploring e-commerce field. While e-commerce is well known and widely used in western countries, it is still at the infancy stage in India. Further, we have no dedicated electronic commerce laws in India.

E-commerce regulations and laws in India can be found under the information technology act (IT Act 2000) that is the cyber law of India. It prescribes basic level legal requirements for undertaking e-commerce in India. However, besides the IT Act, 2000 we have no dedicated e-commerce laws in India.

So what does techno legal experts of India think about e-commerce environment and regulatory aspects of the same? According to Praveen Dalal, managing partner of New Delhi based ICT law firm Perry4Law and leading techno legal expert of Asia, E-Commerce in India requires compliance with various Statutory Laws of India. The chief among them are the Cyber Law of India, Indian Contract Act, Privacy and Data Protection Regulations, Cyber Security Regulations, Foreign Investments Regulations, etc.

Although E-Commerce in India has great potentials yet Legal Aspects of E-Commerce in India must be taken care of before launching an E-Commerce Project or Website, suggests Praveen Dalal.

With growing establishment of e-commerce websites and platforms in India, disputes are also bound to arise. E-commerce lawyers and law firms in India have been suggesting active use of information technology for e-commerce dispute resolution in India. For instance, online dispute resolution (ODR) in India can be used for resolving transborder e-commerce disputes. Similarly, e-courts and ODR in India can also be used for resolving various e-commerce related disputes in India.

Perry4Law and Perry4Law Techno Legal Base (PTLB) have been providing the exclusive techno legal ODR services in India for resolving e-commerce and various technology related dispute resolutions in India.

Keeping in mind the future and growth of e-commerce in India, it would be a good idea to formulate a dedicated e-commerce law for India. It may cover all the abovementioned aspects to make it holistic and comprehensive.

Monday, 16 January 2012

E-Discovery In India Needs To Be Developed

Electronic discovery in India was considered an important cyber aspect by the cyber law trend of India 2011 of Perry4Law and Perry4Law Techno Legal Base (PTLB). Even the projected cyber law trends in India 2012 by Perry4Law and PTLB have placed e-discovery services in India at a prominent position.

Despite the importance of e-discovery in India the same has not yet been adopted suitably. There are very selective e-discovery LPO and KPO in India that are providing e-discovery LPO and KPO services in India. The information technology act 2000 (IT Act 2000) is the cyber law of India that incorporates provisions regarding electronic evidence. All electronic evidences must comply with the requirements of IT Act 2000 in order to be legal and valid.

According to Praveen Dalal, managing partner of ICT and IP law firm Perry4Law and leading cyber law and cyber forensics expert of Asia, “Despite popular belief, Cyber Forensics is different from E-Discovery, Digital Recovery or other synonymous terms. Cyber Forensics primarily caters the “Legal Requirements” whereas E-Discovery meets the requirements of private individuals and organisations as well.

He gives an example to explain the difference. “Take an example of a security breach like hacking in an organisation. The management of the organisation decides to trace the origin of this breach. After proper analysis they come to know about the source of that breach. Till this stage it is only an E-Discovery. The management can take whatever preventive or remedial measure as it may deem fit”, informs Praveen Dalal.

If the management decides to take a “Legal Action” against the offender, it has to prove the acquired digital evidence before the Court of Law. Mere E-Discovery may not be enough to prove the guilt of the accused as legal requirements regarding evidence and procedural laws must also be complied with. When the E-Discovery is “Law Compliant” it becomes “Cyber Forensics”, suggests Praveen Dalal.

This difference between e-discovery and cyber forensics has become a well accepted principle and well established standard of e-discovery and cyber forensics in India and world over. So firms and companies performing e-discovery must keep in mind this crucial difference.

In short, if e-discovery is not performed as per the cyber law of India and other Indian laws, the same may be held inadmissible in court of laws. In fact, every e-discovery investigation must be conducted with the objective that the same would be used in various civil and criminal proceedings. This essentially means that when stakes are high, e-discovery must always be supplemented with cyber forensics investigation. This also means that e-discovery practices in India need to be developed for the proper growth and sue of e-discovery in India.

Saturday, 24 December 2011

Internet Banking Risks In India

Technology has brought many benefits for banking consumers in India. However, technology has also given birth to many unforeseen challenges. Cyber security challenges of Internet banking in India have grown tremendously in the past. In fact, Internet banking in India is not cyber secure despite the recommendations of Reserve Bank of India (RBI). Banks in India are ignoring the cyber security due diligence requirements prescribed by Reserve Bank of India (RBI).

Internet banking is a very important aspect of Indian banking industry. Internet banking not only provides instant banking facilities but it also confers mobility to the account holders. However, cyber security of internet banking infrastructure of India is the need of the hour. Instances of theft of money through hacking of accounts of the accounts holders are fast becoming a trend in India.

This is partly due to the ignorance of the accounts holders and partly due to the weak cyber laws of India. The account holders are increasingly targeted for phishing attacks that result in loosing of sensitive banking information.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, the Information Technology Act 2008 has made most of the cyber crimes and cyber offences “bailable”. India has made its cyberspace a “free zone” and “safe heaven” for cyber criminals and cyber offenders. He says that now even after committing hacking in India a person would be entitled to “bail” as a matter of right. There is nothing that prevents such cyber criminals from committing cyber crimes in India in the absence of a deterrent law.

This has resulted in an increased spate of cyber crimes including hacking of the e-mail IDs of the Internet banking users and stealing of their money.

Further, India has also become one of the most endemic surveillance societies of the World. Confidential information is already vulnerable and with the proposed Indian plans of installing key loggers at cyber cafes, the same would exclude the use of cyber cafes for these purposes. Although cyber cafés are not a good place to transact confidential matters yet with a poor Internet penetration in India this may still happen, says Dalal.

With a weak cyber law, lack of cyber security awareness and increasing e-surveillance initiatives in India, Internet banking disputes are bound to increase in India. The government is least bothered about these issues and ultimately the account holders would have to bear the financial losses.

Thursday, 22 December 2011

Is Online Banking System Of India Cyber Secure?

Cyber security in India is still not considered seriously by various stakeholders. Whether it is governmental departments, financial institutions, banks, private companies, etc none of them have taken cyber security seriously so far. An implementable national cyber security policy of India is also missing. In the absence of India’s national cyber security policy, cyber security has not been suitable adopted by various stakeholders. Even there is no legal framework for cyber security in India.

Cyber security for banking and financial sectors of India is urgently required as they perform very crucial functions. Realising the necessity of ensuring cyber security for these sectors, the Reserve Bank of India (RBI) has in the past constituted a working group on information security. RBI issued a “notification” asking the banks of India to comply with its recommendations.

As per RBI’s recommendations, all banks should create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest. However, banks of India have shown no willingness to incorporate cyber security into their day to day functions. Till now the directions of RBI to appoint CIOs and steering committee has not been followed by banks of India. The recommendations of the RBI have still not been implemented. Naturally, Indian banks are poor at developing cyber security policies and implementing the same.

Cyber Security Policy is an issue that is very important for Banks of India, says Praveen Dalal, managing partner of New Delhi base ICT law firm Perry4Law and leading cyber law expert of India. With the growing use of Internet Banking, ATM machines, Credit and Debit Cards, Online Banking, etc, Banks of India must also upgrade their Cyber Security Infrastructure and establish a Cyber Security Policy, suggests Dalal.

For example Citigroup had recently confirmed cyber attack upon bank’s network. It is also well known that a timely and appropriate cyber due diligence could have prevented such attacks and various cyber frauds that are growing in the banking sector of India.

Few more areas that Indian banks must keep in mind include cyber security due diligence for banks in India, e-discovery for due diligence for banks in India, cyber law compliances, ATM frauds and phishing attacks, etc. However, the big question is are Indian banks ready for cyber due diligence?

In the past, RBI imposed penalty upon 19 banks for non compliance of prescribed standards. Similarly, RBI has also directed that any strictures passed against directors of a bank by any financial sector regulators must be reported to it. Non compliance of the recommendations of RBI working group may attract both penalty and strictures. However, banks in India are least bothered regarding cyber law and cyber security due diligence in India. Times again instances of cyber crimes and cyber breaches are reported in India and the position remains the same.

For instance, Yash, a chief technology officer in a cyber-security startup firm, has developed a proof-of-concept virus to attack the ICICI Online banking using the Man-in-Middle / Man-in-Browser attack method. It shows what an attack can do to an online banking customer who uses ICICI online banking facility and how it can result in financial loss.

A video also shows how virus can control your Internet explorer and manipulate ICICI Bank transactions in real time. The user is unaware that a virus is running, he logs into ICICI Online bank and performs an online transaction, the virus modifies the destination payee information in real-time and redirects the fund to an attacker account without the knowledge of the user. The same virus can be extended to any browser.

An integrated modern banking law for India is in pipeline and it would be a good idea to make it techno legal in nature so that it can address cyber crimes and cyber security in a more effective manner. Corporate and banking laws in India are in the process of being streamlined. RBI has even issues a notification prescribing enhanced due diligence measures for high risks customers in India.

Banks in India need to adopt techno legal measures to prevent ATM and other similar financial frauds and cyber crimes. Further, cyber due diligence trainings for bank employees can also be beneficial in this regard. Banks must also appoint steering committees and CIOs as soon as possible.

Cyber due diligence for banks in India should be made mandatory by RBI and through various pending and existing legal frameworks. Cyber law due diligence in India is already applicable to banks of India in certain circumstances and these liabilities are going to be more stringent in near future. The sooner the banks adopt these due diligence practices the better it would be for these banks.

Saturday, 11 June 2011

The Central Monitoring System (CMS) Of India

The central monitoring system (CMS) is a centralised mechanism that can assist in lawful interception of communications from landline, mobile and Internet. Although it can be used only if there is a lawful interception law in India yet it seems to have been tested recently without any lawful interception law in India at place.

For a constitutionally sound lawful interception law, there must a well defined law with constitutional safeguards to protect its abuses. India has no constitutionally sound lawful interception law at present.

According to Praveen Dalal, a Supreme Court Lawyer and leading Techno Legal Expert of India, one of the laws that require an immediate repeal is the Indian Telegraph Act, 1885. It is the most abused law of India when it comes to Phone Tapping and Illegal Surveillance. The fact and truth is that India does not have a Legal and Constitutionally Sound Phone Tapping and E-Surveillance Law.

So much so that phone tapping in India is done by private individual that also without any authorisation and on the basis of forged documents. There is no mechanism through which these private individuals can be held responsible for illegal phone tapping in India. In fact, to a greater extent these private individuals are actively encouraged by Indian government to engage in phone tapping by not enacting sufficient and stringent laws in this regard.

After strong protests and constant demands for lawful interception law in India, Indian government has given some hints that guideline in this would be issued very soon. However, mere guidelines under the Telegraph Act are not sufficient and nothing short of a constitutionally sound lawful interception law would be enough to make the CMS legal and constitutional.

The present phone tapping, e-surveillance, interceptions, website blocking, Internet censorship, etc are done in an unconstitutional and undemocratic manner in India. This is despite what Indian government claims.

The matter is pending before the Supreme Court of India and it would be a good opportunity to declare the Telegraph Act unconstitutional so that the government may be forced to enact a constitutionally sound law in this regard.

Lawful Interception Law In India Is Missing

Lawful interception consists of many segments. It includes e-surveillance, phone tapping, eavesdropping, wiretaps, pen registers, etc. As the name suggests, lawful interception must be supported by a law. This is the lay man’s interpretation of the definition of lawful interception.

However, a legal mind should not be confused by this layman’s definition. Any good lawyer would tell you that lawful interception must not only be supported by a law but that law must also pass the tests of constitutionality.

Nations all over the world are enacting laws whose primary purpose is to strengthen unlawful interceptions through the instrumentality of laws. Since this is going to be challenged by people, nations are playing the card of “national security” by creating fear, uncertainty and doubt (FUD factor).

India is no exception to this rule. Under the guise of national security, India is sticking to the same law that it considered draconian before its independence. The Indian Telegraph Act, 1885 is the colonial and draconian law that Indian government in general and home ministry of India in particular uses to indulge in unconstitutional phone tapping.

According to Praveen Dalal, a Supreme Court Lawyer and leading Techno Legal Expert of India, India is the only country of the World where phone tapping is done without a Court Warrant and by Executive Branch of the Constitution of India. Phone tapping in India is “Unconstitutional” and the Parliament of India has not thought it fit to enact a “Constitutionally Sound Law” in this regard. Even the Supreme Court’s directions in PUCL case have proved futile and presently the Court is dealing with the issue once more, informs Dalal.

Not only phone tapping, but even e-surveillance and eavesdropping is not regulated by a constitutionally sound law in India. India urgently needs a Lawful Interception Law, suggests Praveen Dalal. The present Cyber Law of India contained in Information Technology Act, 2000 (IT Act, 2000) is not a Constitutionally Sound Law for Lawful Interceptions in India, opines Dalal.

There is a growing distrust and anger among Indian masses regarding privacy violations and violations of other civil liberties. Further, with projects like Aadhar, national intelligence grid (Natgrid), etc privacy violations and other civil liberty violations are further bound to increase. In the absence of a constitutionally sound lawful interception law in India, only self defence measures can come to the rescue of Indian citizens.

The prime minister’s office (PMO) of India in general and our Prime Minister Dr. Manmohan Singh in particular must ensure a constitutional sound lawful interception law in India. Further, he must also ensure a good, effective and constitutional cyber law for India as well.

Friday, 10 June 2011

Indian Cyber Law Must Be Scrapped

Many techno legal experts of India are saying that cyber law of India is in bad shape and it deserves to be repealed. For instance, according to Praveen Dalal, managing partner of New Delhi based IP and ICT law firm Perry4Law and leading techno legal expert of Asia, the Information Technology Act 2000 is more on the side of a collection of “Legal Jargon” than a Law as contemplated by the Constitution of India and it deserves an urgent repeal.

Technology related laws are the need of hour these days. The more technology has become a part of our daily lives the greater is a need to regulate it use in a legal manner. Deviance from lawful use of technology often results in cyber crimes. However, legal enablement of ICT systems in India is still missing.

In India cyber crimes and nuisance like spam communication are increasing at an alarming rate. However, the laws required to tackle the same are missing in India. For instance, the information technology act, 2000 (IT Act, 2000) is the sole cyber law of India.

It was amended by information technology act, 2008 (IT Act, 2008). This amendment also made almost all the cyber crimes bailable, giving enough incentives to commit cyber crimes in India without any fear of law or punishment.

Recently, telecom minister Mr. Kapil Sibal showed his intentions to frame rules under the IT Act, 2000. What is not understandable is why he is lingering with this weak and ineffective law? Why cannot he start an exercise of repealing the present cyber law and enacting comprehensive laws regarding cyber crimes, cyber security, e-governance, e-commerce, etc?

The present approach and attitude of Mr. Sibal is piecemeal in nature that can never give an enduring and strong solution against growing cyber crimes in India. It is high time for him to repeal the present cyber law of India and come up with a good one.