New IT rules give Big Brother free access to sensitive personal information

The government can now obtain passwords and financial information without a warrant or person's consent

May 10, 2011 02:01 am | Updated August 21, 2016 05:21 pm IST - NEW DELHI:

According to the  Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, the government has the power to obtain sensitive personal information about individuals from companies without a warrant or the concerned person's consent. File photo

According to the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, the government has the power to obtain sensitive personal information about individuals from companies without a warrant or the concerned person's consent. File photo

While cyber activists, bloggers and legal experts have criticised the new rules under the IT Amendment Act, 2008, for gagging free speech, what has gone unnoticed is the fact that the new regulations also give the government the power to obtain sensitive personal information about individuals from companies without a warrant or the concerned person's consent.

The sensitive personal data or information of a person covers passwords, financial information such as bank accounts or credit card details, his or her physiological and mental health condition, medical records and history, their sexual orientation, and biometric information, says the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, which came into force in April this year.

Though the rules provide for keeping this information confidential from third parties except with the individual's prior consent, they explicitly state that all sensitive personal details “shall be shared, without obtaining prior consent from the provider of information, with government agencies mandated under the law to obtain information including sensitive personal data or information for the purpose of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution, and punishment of offences.”

Criticising the government for giving itself the “master key” to access the sensitive personal information of individuals, including their medical records, Delhi-based PRS Legislative Research, which works with MPs to provide research support on legislative and policy issues, has noted that “there are no checks on this power [with the government] except that the request for information be made in writing, and stating clearly the reason for seeking the information.”

Pointing out that “information requests [made by government agencies] usually have certain inbuilt checks,” PRS Legislative Research said that for example, search warrants in criminal cases were issued by a court. Similarly, tapping of telephones or interception of electronic communication can only be authorised by the Union or State Home Secretary after following a prescribed process.

The new bill for the Unique Identification Number (UID) also permits such use only by the order of a court or for national security (by an order of an authorised officer of at least Joint Secretary rank in the Central Government).

However, the new rules under the amended IT Act have no such checks and balances — a government agency just needs to send a request in writing to the company possessing the sensitive personal data or information stating clearly the purpose of seeking such information.

The rules also state that a company can transfer sensitive personal data or information to any company or individual in India or abroad that “ensures the same level of data protection” that is adhered to by that company as per the new rules.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.