Thursday, September 23, 2021

How much reliable is NCRB 2020 report on Cyber-crimes?

 

The National crime records bureau of India has recently published the statistics related to various crimes in India. According to this report Cyber-crimes have seen growth of @37% over year to year. In 2018 Cyber-crimes reported to police were 27248, whereas in 2019 the cyber-crimes were 44735 and in year 2020 cyber-crimes were 50035. It can be deduced that cyber-crimes saw huge growth of @ 65% in year 2019 whereas in year 2020 growth is only @15%. So, in fact it can be said that Cyber-crimes have gone down by about 50% as compared to its growth rate in last year. This is very appreciable and also a sign that people are becoming more alert and more digital literate and sensible.

“A total of over 3.17 lakh cybercrimes and 5,771 FIRs were registered online through a centralized portal www.cybercrime.gov.in in the last 18 months -- a sizeable number of them in Maharashtra and Karnataka”, the Lok Sabha was informed on Tuesday, 9’th March 2021 by Union Minister of State for Home G Kishan Reddy. If 3.17 Lakhs crimes were reported on portal in 18 months ending March 2021 and NCRB report says 50035 crimes were registered in 2020 then it needs serious churning and thinking regarding the huge difference of reporting’s and actual registration of crimes. It also raises other questions about ability of local police regarding registration of cyber-crimes. In my opinion if police are discouraging the registration of cyber-crimes, then the situation is very grim and needs urgent attention of the concerned stake-holders.

“Over 2.9 lakh cyber security incidents related to digital banking were reported in 2020”, Parliament was informed on Thursday, 4’th February 2021 by Minister of State for Electronics and IT Sanjay Dhotre in a written reply to the Rajya Sabha. As per the information reported to and tracked by Indian Computer Emergency Response Team (CERT-In), a total number of 1,59,761; 2,46,514 and 2,90,445 cyber security incidents pertaining to digital banking were reported during 2018, 2019 and 2020 respectively, minister said in a written reply to the Rajya Sabha. These incidents included phishing attacks, network scanning and probing, viruses and website hacking.

Now if we compare reports of NCRB and CERT and www.cybercrime.gov.in portal, we will be confused about the actual number of cyber-crimes happening in India. Whether to believe on NCRB or CERT or government’s cyber-crime reporting becomes a more serious question and needs to be answered by Government. And more significantly why three premier agencies in India are coming up with completely contrasting statistics?

Now if we analyze the NCRB report we find that in UP 11097 cases were registered in 2020 followed by Karnataka (10741) and Maharashtra (5496). The overall cyber-crime rate is 3.7% of total population which is estimated to be 13533.7 Lakhs in entire India. So with respect to the country's digital population amounting to approximately 624 million active users as of February 2021, the total crimes in India as per NCRB is 50035, which are very low as compared to other traditional crimes.

Another interesting statistics’ is about charge-sheet ratio which says that it is over-all 47.5% in India with MP topping with 85.6% and Assam at 19.4 % performing very poorly with Maharashtra at 27.1%. The overall Indian scenario tells that in 14176 cases the chargesheet was filed by the police and total 74142 offences are pending investigation till end of 2020.

As regards to matters disposed by the court, the report raises more concerns because out of 25140 cases pending in courts across India for trial, only 2692 i.e., 10% pending cases were disposed by the courts in entire year. The only satisfying part is @85% conviction rate.

The statistics also highlights the Cyber crimes in 19 Metros of India.

In 2020 only 18657 crimes were registered in Metros with Bangalore topping with 8893 followed by Hyderabad 2553 and Mumbai with 2433. Nagpur with 243 crimes is at 9th rank and surprisingly cyber crimes in Nagpur exceed Pune which has recorded 238 crimes. But as compared to last year Nagpur witnessed doble growth in cyber-crimes and Mumbai and Pune saw marginal decline in cyber-crimes. In 2019 cyber-crimes in Nagpur were only 119. Also, the pending charge-sheet percentage is 85% in Nagpur.

Being a keen observer of cyberspace since a decade, these figures are totally unbelievable and does not project true scenario. The Nagpur police has sanctioned strength of about 60-70 and presently the posted staff may be @ 30-35 and if only 243 cyber-crimes are registered in Nagpur, then does this number justify? The same is scenario across India where Police machinery is trying to increase its capacity to fight cyber-crimes but NCRB report paints totally contract dimension.

The only inference could be the NCRB statistics is wrong and this should be dealt and debated very seriously.

Dr. Mahendra Limaye (09422109619)

Cyber Legal and Data Privacy Consultant

Saturday, August 15, 2020

India to have new CYBER SECURITY POLICY - My Wish-list

 The aim of policy should be to protect personal information by way of passing much awaited PERSONAL DATA PROTECTION BILL in coming session of Parliament.

Protecting Critical Information infrastructure and building data storage capabilities could also be part of the same.

Cyber Awareness regarding careful use of digital platforms for carrying out any online transactions and precautions to be followed while using Social Media should be other points which need focus in this new policy.

Centralized cyber crime quick response force should be the other priority. All police stations irrespective of their state location should be able to co-operate/ participate in investigation of cyber crimes and the solution for territorial jurisdiction should be worked out.

Improving Cyber Civil/Criminal Judicial system must be a priority.

Wednesday, August 12, 2020

Olx: most favoured portal to cheat people

 

Chief Information Security Officer in the Prime Minister's Office Mr. Gulshan Rai has said recently that there has been a 200 per cent rise in cyber incidents in India in the last couple of months. He observed that there have been larger cases of phishing, service issues and ransom ware.

 “Cyber fraudsters are adopting modern techniques to cheat innocent people and the OLX platform is being one of these methods to dupe unsuspecting people,” said Ch Y Srinivas Kumar, ACP, Cybercrime (Cyberabad). “The reason is that people believe that buying and selling things on OLX is very easy and that everyone on the platform is trustworthy. Fraudsters are using this trust to cheat innocent people to the tune of several lakhs,” the ACP said as reported in The Telangana Today newspaper dated 23 July 2020.

The above two news reports are sufficient to send shivers among online purchasers. Though digitalisation has proven to be beneficial in many walks of life there are these grey areas which are yet to be taken care of. The online selling portals are being used by many criminals to sell either stolen goods or non-existent goods.

OLX is most favoured portal to cheat the people owing to its popularity. With 55’Th overall ranked portal in India and with average 20 million visits per day, this portal is proving to be a bane for online purchasers. The typical frauds which have been reported to Cyber Crime Helpline, a free voluntary advisory service managed By Adv Dr. Mahendra Limaye’s Cyber Awareness Organisation, are related to Vehicle sell involving a soldier. The seller pretends to be a soldier from Indian Army and offers to sell either two wheeler or Four Wheeler at throw away price due to his transfer from one location to another. He also publishes few photos in Uniform to make people believe that seller is from Indian Army. Many times there are photos of vehicle bearing stickers or some marks related to army so that people believe that vehicle seller is genuinely belonging to Indian Army.

With this much input subsequent transfer of money in form of Advance or clearance charges takes place and buyers transfer money in sellers account through IMPS using mobile wallet transfers. Generally after first transfer of payment the seller tries to get confidence of the buyer and many times sends fake shipment receipt details and also claims balance money. There are various reasons like payment of tax, RTO Clearance, Insurance Clearance etc which are exploited by these fake sellers to extract as much money as possible from the buyer.

Many a times it’s too late when the buyer realises that he has been cheated but by that time huge amount is lost be him. The popularity of the portal and belief of the people that portal has followed due diligence prior to posting the advertisement proves wrong in such matters.

People must understand that these portals take the defence of Intermediary provisions available in Information technology Act and do not claim to be a part of such transaction. They make themselves safe by shifting entire blame on wisdom of Buyers and Sellers.

It is advised that people should follow due diligence by verifying authenticity of such sellers by all possible means. The unbelievable offer itself is best hint that trap is laid for you. The prompt response/acceptance to your offer is another red flag. Always insist for test ride of the said vehicle from someone known to you from the location where vehicle is currently available. Even this insistence of test ride can save you since the seller will avoid the same. You can also insist for video of the seller while riding/driving the vehicle which will also be refused by these fake sellers and will save you. You can also check the account details provided to you with those of the name of the person available on registration certificate of the vehicle.     

It’s not bad idea to purchase things online but you must follow the diligence in entire process is the key advice.

The investigation in such frauds is very complicated involving different states jurisdiction as well as different payment wallets and many banks. It has been also observed that people are reluctant to file the police complaints due to reputation issue or other social stigma. The criminals are well aware about these habits of non-reporting of the complaints and hence are becoming bolder.

So prevention and due diligence is the only remedy which can be presently prescribed for the Online Shopping Addicts by the author.

 

About the Author

Dr. Mahendra Limaye is practising lawyer by profession and specialises in Cyber Litigation, Civil as well as Criminal. He has vast experience of 12 years in the Cyber Litigation and also runs a unique venture in the form of CYBER CRIME HELPLINE, which has provided free remedial guidance to more than 10,000 cyber fraud victims so far across India.

 

.

 

Friday, July 3, 2020

PERSONAL DATA PROTECTION ACT: NEED OF THE HOUR


Apex Courts 9 Bench unanimous judgement in Justice Puttaswamy case pronouncing that, “The right of privacy is a fundamental right; It is a right which protects the inner sphere of the individual from interference from both State and non-State actors and allows the individuals to make autonomous life choices” had attracted various reactions from all the sections of society when pronounced in 2017.
The then Union finance minister Shri Arun Jaitley, a legal acumen in himself, reacted that “Privacy issue went to Supreme Court because previous UPA government brought Aadhaar without legal framework. We framed Aadhaar law ensuring privacy as fundamental right will be protected. Supreme Court accepted privacy is a fundamental right but not an absolute right; judgment is a positive development."
The past and present Law minister, Shri Ravi Shankar Prasad said “The government welcomes the Supreme Court order on right to privacy. SC has affirmed what government had said in Parliament while moving Aadhar Bill. Privacy should be a fundamental right subject to reasonable restrictions."
 “Welcome the SC verdict upholding Right to Privacy as an intrinsic part of individual’s liberty, freedom and dignity. The SC decision marks a major blow to fascist forces," the Congress vice-president Rahul Gandhi tweeted. It was a “sound rejection" of the BJP’s ideology of “suppression through surveillance", Gandhi said.
R. Chandrashekhar, President, Nasscom in 2017 said, “This landmark judgment will ensure that protection of citizen’s privacy is a cardinal principle in our growing digital economy. Besides, it will enhance citizens’ trust in digital services, a prerequisite for widespread digital adoption. The ruling also significantly boosts India’s attractiveness as a safe destination for global sourcing."
Soli Sorabjee, India’s most respected legal luminary commented that “It is a very progressive judgment and protects the fundamental rights of the people. Privacy is a basic right which is inherent in every individual. The unanimity of the bench in giving this decision shows a very good approach of the Supreme Court. Any judgment which enlarges the fundamental rights of the people should be welcome."
These reactions were of 2017 and many expected government to come out with a law soon for protection of Privacy of the individual as a committee was set up under stewardship of Retired Justice Srikrishna to draft the act for Data Protection in 2017 itself.
Much water has been passed between pronouncement of judgement, setting up the committee and today. An Act for protection of Fundamental Rights of People is still a distant dream. It was in July 2018 that the Justice BN Srikrishna-led committee timely submitted its draft bill to the Ministry of Electronics and Information Technology (MEITY) to create a powerful data protection law in India. The draft was finalized after a year of consultations with various stakeholders and came just after the European Union General Data Protection Regulation (GDPR) came into force in May 2018. The Personal Data Protection Bill, 2019 is more important because of the urgent need to regulate data protection and data privacy, be it for online platforms, apps, social networks or even online services including by the government. It was expected when the Winter Session of the Parliament began in November 2019, that key bill, the Personal Data Protection Bill, 2019, will be passed. But it did not happen and presently the bill is before the Committee of Parliament for deliberations and consultations.
The 25% growth from 437.4 million in 2017 to 564.5 million currently in digital users should come as some sort of eye-opener. In a country where digital education, digital security or digital awareness is not priority of any of the digital service providers, the digital users are left on mercy of cyber criminals. These cyber criminals are carrying out innovative cyber attacks which are beyond imagination of the digital users. The most favoured white collared cyber crime is DATA THEFT. It is committed before open eyes of the digital users and digital users are not able to recognise the crime of data theft being committed. There are many high end cyber crimes which cannot be even noticed or detected by 90% of the digital users. Present digital era’s description as Golden Era of Cyber Crimes is not misconceived or ill-founded.
Recently, in view of information available with government of India that 59 Apps are engaged in activities which is prejudicial to sovereignty and integrity of India, defence of India, security of state and public order, the government of India has banned these apps , all of which are originated from China. The government said that the Ministry of Information Technology has received "many representations raising concerns from citizens regarding security of data and risk to privacy relating to operation of certain apps". As per government press release, The Computer Emergency Response Team (CERT-IN) has also received many representations from citizens regarding security of data and breach of privacy impacting upon public order issues”.  So, on this backdrop with the relevant provisions of the Information Technology (Procedure and Safeguards for Blocking of Access of Information by Public) Rules 2009 and in view of the emergent nature of threats these apps were banned.
The measure reason as stated by government is the Risk to Privacy as well as risk to data of the citizen. It is open secret that most of the apps are designed to collect huge personal data from the users. The terms and conditions of each of the app very categorically mention the permissions to be provided by gadget owner prior to installing that specific app. With our permission only, these apps are installed in our devices and hence there are very few who regret this decision of providing permission to camera, messages, contacts, GPRS Location, enabling calls and many more such activities by the apps. This is true for all the apps whether having origin in China or from any other part of world. You will rarely find any app/program which is not interested and designed for collection/storage of personal data. In short we need to have a permanent solution for Protection of the Personal Data of the individual as banning any app is short term solution.
Data is the lifeline of today’s business activities in digitalised world and on backdrop COVID 19 where most the world is opting for Work from Home and making maximum use of online platforms, the data theft threat is looming large in cyberspace. Yes , the incidents on Chinese Border has added fuel and security dimension to this Data Theft and Data security of the citizen and banning the 59 apps of Chinese origin by government can be justified. But bigger issue of Data Security and Protection of Privacy by other apps remains to be resolved. What can be said about big social media giants like Facebook, Whatsapp, Instagram or online meeting platforms like Zoom? Are these companies not involved in compromising Security of individual citizen and thereby invading constitutional guaranteed Privacy Right of the Indian citizen?
The most recent incident of trolling of Hon. Chief Justice of India for just sitting on a high-end mobike without headgear and mask and subsequent clarification/warning about not invading Privacy of Hon Chief Justice of India justifies the need of passage of Personal Data Protection Act by the parliament. When Hon Chief Justice’s privacy is vulnerable, what could be said about Privacy of we individual citizen? Are all citizens so powerful like Hon. CJI? What remedies are available to individual citizen for protection of their Right to Privacy? Under which law the reliefs can be sought?
Putting of Personal Data Protection Act in place is the only solution. The preamble of act itself describes the objects of the act as the act to provide for protection of the privacy of individuals relating to their personal data, specify the flow and usage of personal data, create a relationship of trust between persons and entities processing the personal data, protect the rights of individuals whose personal data are processed, to create a framework for organisational and technical measures in processing of data, laying down norms for social media intermediary, cross-border transfer, accountability of entities processing personal data, remedies for unauthorised and harmful processing, and to establish a Data Protection Authority of India for the said purposes and for matters connected therewith or incidental thereto.

The preamble states that the right to privacy is a fundamental right and it is necessary to protect personal data as an essential facet of informational privacy and whereas the growth of the digital economy has expanded the use of data as a critical means of communication between persons and which needs to be protected.

So the significance of Personal Data Protection Act can be found in its preamble only and various rights available, after passage of this Act, to Data Principal like correction of Information, Erasure of information, discontinuing the use of information after the purpose of consent is over and deletion of information etc. highlights how personal data of the individual can be protected.

As most of the apps are exploiting our sensitive personal information without our explicit consent and this can be verified by huge spike in cyber crimes recently, the best way to deter/ control these apps and make citizen more powerful is by passage of Personal Data Protection Act. This act will give much needed tools to the citizen as well as government to check culprits involved in theft of personal data or invasion of Data privacy.

  
To allow the individuals to make autonomous life choices including choice about his Data sharing, the Hon Apex Court mandated a need of law which can give an individual, right about his personal data protection. This object can only be achieved by passage of The Personal Data Protection Act and its effective implementation. Hence in my view, passing and enforcing The Personal Data Protection Act is need of hour and should be top priority of the government.

Thursday, May 21, 2020

Session with Adv. Mahendra Limaye on Cyber Laws and Cyber Safety

Session with Adv. Mahendra Limaye on Cyber Laws and Cyber Safety

Tuesday, May 12, 2020

Who has legal liability if Aarogya Setu Data is compromised?



The Aarogya Setu Data Access and Knowledge Sharing Protocol, 2020 was notified by Ministry of Electronics and Information Technology on 11 May 2020. This has again led to new debate regarding whether after this notification Aarogya Setu app Data is safe? Adv Dr Mahendra Limaye, a cyber legal consultant, analyzed the notification and his reading of the notification is as below.
Functioning of Aarogya Setu app as per notification relates to technology and data management and certain necessary steps required to be taken to ensure its effective operation to detect and mitigate the spread of Covid 19 pandemic and enhance government preparedness at all levels. So the aim and object of the Aarogya Setu App was never a question and it is much applauded move by the government.
In order to ensure secure collection of data, protection of personal data of individuals and efficient use and sharing of personal or non-personal data for mitigation and redress this notification was specially issued. So we must understand that this notification was fall out of many objections raised towards security of the personal data collected through this app and about accountability of the data collected through this app and specially when some hacker claimed about vulnerability of this huge database. This response also shows government’s responsive approach to security concerns raised about the app and this is welcome move.
The notifications says that in order to formulate appropriate health responses for addressing the COVID-19 pandemic, data pertaining to persons who are infected, at high risk of being infected or who have come in contact with infected individuals is urgently required. This data includes demographic data, contact data, self assessment data and location data, collectively called ‘response. The demographic data includes the name, mobile number, age, gender, profession and travel history of an individual. Contact data covers data about any other individual that a given individual has come in close proximity with, including the duration of the contact, the proximate distance between the individuals and the geographical location at which the contact occurred. Self assessment data means the responses provided by that individual to the self assessment test administered within the Aarogya Setu mobile application. Finally Location data means data about the geographical position of an individual in latitude and longitude. So the broad categories of data collected through this app by government is once again made public by this notification.

The notification also states that the Ministry of Electronics and Information Technology, Government of India (“MeitY”) is designated as the agency responsible for the implementation of this Protocol and its developer, the National Informatics Center shall, under this Protocol be responsible for collection, processing and managing response data collected by the Aarogya Setu mobile application.

So it is highlighted that MeitY will be only supervising authority. So the government has brought NIC in picture for protection of entire data in the capacity of developer and made its role minimal in capacity of implementer.



Highlights of Principles for collection and processing of response data:
a. Any response data and the purpose for which it is collected by NIC shall be clearly specified in the Privacy Policy of the Aarogya Setu mobile application.
b. NIC shall collect only such response data as is necessary and proportionate to formulate or implement appropriate health responses. Further, such data shall be used strictly for the purpose of formulating or implementing appropriate health responses and constantly improving such responses.
c. NIC shall process any data collected by it in a fair, transparent and non-discriminatory manner.
d. Contact and location data shall by default, remain on the device on which the Aarogya
Setu mobile application has been installed after such data has been collected. It may be uploaded to the server only for the purpose of formulating or implementing appropriate health responses.
e. Contact, location and self assessment data of an individual that has been collected by NIC shall not be retained beyond the period necessary to satisfy the purpose for which it is obtained which, unless a specific recommendation to this effect is made in the review under Para 10 of this Protocol, shall not ordinarily extend beyond 180 days from the date on which it is collected, after which such data shall be permanently deleted. Demographic data of an individual that has been collected by NIC shall be retained for as long as this Protocol remains in force or if the individual requests that it be deleted, for a maximum of 30 days from such request, whichever is earlier.
f. The response data shall be securely stored by NIC and shall only be shared in accordance with this Protocol.

Principles for sharing of response data have also been stated which highlights that 1) Response data containing personal data may be shared with various government agencies/bodies where such sharing is strictly necessary to directly formulate or implement an appropriate health response.2) Response data in de-identified form may be shared with various bodies with whom such sharing is necessary to assist in the formulation or implementation of a critical health response.3) NIC shall, to the extent reasonable, document the sharing of any data and maintain a list of the agencies with whom such data has been shared.

Obligations of entities with which response data is shared are like use of such data strictly for the purpose for which it is shared, the data accessed and used by such entities should not be retained beyond the period necessary to satisfy the purpose for which it is shared, in any circumstance; such data shall not ordinarily be retained beyond
180 days from the date on which it was accessed, after which such data shall be permanently deleted etc.

The main concern is who is liable for any privacy violations committed through security breach of Aarogya Setu App? This notification does not provide any clarity to said concern. It was clarified that any violation of these directions may lead to penalties as per section 51 to 60 of the Disaster Management Act, 2005 and other legal provisions as may be applicable. Legal position for the protection of sensitive personal information under section 43A of Information Technology Act 2000 is that state cannot be made responsible in case of breach of data or lapse in protection of sensitive personal data. Through this Notification State has clarified that it is acting only in supervisory capacity and National Informatics Center, which is developer of the Aarogya Setu app will own entire responsibility as far as security and sharing of Response Data is concerned.
As regards section 51 to 60 of the Disaster Management Act they have one important protection as related to breach of data and the protection is “ unless he proves that the offense was committed without his knowledge or that he exercised all due diligence to prevent the commission of such offense”.

In case of any data breach through Aarogya Setu app defense will be always available that all due diligence was observed to prevent the commission of offense like Data Theft etc. So in my view this notification clearly fails to provide any specific measures which government has suggested for protection of Data of millions of Aarogya Setu app users. Also the other question remains is whether the provisions of the Disaster management Act can be enforced after Disaster is over? If data breach is reported after present pandemic is over then whether these provisions can be enforced, remains a question in my mind.     


Advocate Dr. Mahendra Limaye

About the author- Advocate Dr Mahendra Limaye is Cyber Legal Consultant and Cyber Law practitioner in India. He specifically practices in Information Technology Act based litigation's before Civil as well as Criminal Courts in India. He has obtained his doctorate on topic Fundamental Rights and Cyberspace. He can be contacted on mahendralimaye@yahoo.com or + 919422109619.