Advertisement
Sections
TRAI's recommendations on privacy are welcome but some questions still need to be answered
A common platform should be created for the sharing of information relating to data security breaches.

The talk of the tech policy circles in Delhi these days is about the delays in the release of the Srikrishna Committee report on data privacy: Will they release a law, or will it just be recommendations? Have the recommendations been delayed because the committee is indecisive now about data localisation, given the reaction to the RBI’s seemingly “out of the blue” diktat regarding localisation of financial transaction data? Is the iSpirt/UIDAI/'Nandan-Nilekani-friendly' faction in the Srikrishna Committee digging its heels in about data localisation?Or is it that they don’t want it to affect Aadhaar and Justice Srikrishna does? Is there a point to the Srikrishna Committee, since the bill may never get tabled: the opposition may not let the Monsoon session to run in Parliament, and there’s very little chance of any work in the winter session?In that context, the TRAI’s recommendations are very important, especially given that the TRAI Chairman is the former CEO of the UIDAI, the fact that the TRAI took on this consultation suo moto, and there’s talk of him possibly becoming head of India’s first data protection authority after his term finishes at the TRAI.These recommendations are being seen as a signal for what’s to come from the Srikrishna Committee.[caption id="attachment_4766241" align="alignnone" width="1024"]
Representational image.[/caption]Issues that the TRAI has avoidedBefore we get into what the TRAI has recommended, I think it’s worth looking at what the TRAI has avoided talking about:
R S Sharma, head of Telecom Regulatory Authority of India (TRAI). Image: Reuters[/caption]3. Data minimisation & privacy by design:
Representational image. Reuters.[/caption]7. Breach and notification
Representational image.[/caption]Issues that the TRAI has avoidedBefore we get into what the TRAI has recommended, I think it’s worth looking at what the TRAI has avoided talking about:- Data Localisation,
- Cross-border data flows,
- Legitimate Exceptions to privacy,
- Lawful interception,
- Responsibilities of data controllers and technology-based audits.
- Each user owns his/ her personal information/ data collected by/ stored with the entities in the digital ecosystem. The entities, controlling and processing such data, are mere custodians and do not have primary rights over this data.
- All entities in the digital ecosystem, which control or process the data, should be restrained from using metadata to identify the individual users.
- Till such time a general data protection law is notified by the Government, the existing Rules/ License conditions applicable to TSPs for protection of users’ privacy be made applicable to all the entities in the digital ecosystem. For this purpose, the Government should notify the policy framework for regulation of Devices, Operating Systems, Browsers, and Applications.
- Since the data is collected by private as well as government entities, the data protection framework should be equally applicable to both the Government as well as private entities.
R S Sharma, head of Telecom Regulatory Authority of India (TRAI). Image: Reuters[/caption]3. Data minimisation & privacy by design:- Privacy by design principle should be made applicable to all the entities in the digital ecosystem viz, Service providers, Devices, Browsers, Operating Systems, Applications etc. The concept of “Data Minimisation” should be inherent to the Privacy by Design principle implementation. Here “Data Minimisation” denotes the concept of the collection of bare minimum data which is essential for providing that particular service to the consumers.
- The Right to Data Portability and Right to be Forgotten are restricted rights, and the same should be subjected to applicable restrictions due to prevalent laws in this regard. The TRAI here appears to conflate the Right to be Forgotten, which refers to removal from search engine index with data deletion. That said, empowering users to delete telecom data, and port their data (and not just from their numbers), is a welcome move.
- “In order to ensure sufficient choices to the users of digital services, granularities in the consent mechanism should be built-in by the service providers.” Apart from that, the TRAI has recommended that a framework, “on the basis of the Electronic Consent Framework developed by MeitY and the master direction for data fiduciary (account aggregator) issued by Reserve Bank of India, should be notified for telecommunication sector also. It should have provisions for revoking the consent, at a later date, by users.
- Data Controllers should be prohibited from using “pre-ticked boxes” to gain users consent. Clauses for data collection and purpose limitation should be incorporated in the agreements.
- (g) Devices should disclose the terms and conditions of use in advance, before the sale of the device.
- (h) It should be made mandatory for the devices to incorporate provisions so that user can delete such pre-installed applications, which are not part of the basic functionality of the device if he/she so decides. Also, the user should be able to download the certified applications on his/ her own will and the devices should in no manner restrict such actions by the users.
- To ensure the privacy of users, National Policy for encryption of personal data, generated and collected in the digital ecosystem, should be notified by the Government at the earliest.
- For ensuring the security of the personal data and privacy of telecommunication consumers, personal data of telecommunication consumers should be encrypted during the motion as well as during the storage in the digital ecosystem.
- Decryption should be permitted on a need basis by authorised entities in accordance to the consent of the consumer or as per requirement of the law. This is a very welcome suggestion from the TRAI, and it’s about time that this issue got addressed. That said given the mess that the last (now withdrawn) Draft Encryption Policy was, this needs to be looked at carefully.
Representational image. Reuters.[/caption]7. Breach and notification- All entities in the digital ecosystem including Telecom Service Providers should be encouraged to share the information relating to vulnerabilities, threats, etc, in the digital ecosystem/ networks to mitigate the losses and prevent recurrence of such events.
- All entities in the digital ecosystem including Telecom Service Providers should transparently disclose the information about the privacy breaches on their websites along with the actions taken for mitigation, and preventing such breaches in the future.
- A common platform should be created for the sharing of information relating to data security breach incidences by all entities in the digital ecosystem including Telecom Service Providers. It should be made mandatory for all entities in the digital ecosystem including all such service providers to be a part of this platform.
- Data security breaches may take place in-spite of adoption of best practices/ necessary measures taken by the data controllers and processors. Sharing of information concerning data security breaches should be encouraged and incentivised to prevent/ mitigate such occurrences in the future.
First Published:Jul 18, 2018, 12:37:23 IST
Advertisement
Advertisement

Why AI notetakers are raising serious privacy and security concerns
AI notetakers promise effortless meeting summaries, but experts warn they could expose confidential conversations, corporate secrets and personal voiceprints. As businesses increasingly adopt AI-powered meeting assistants, questions over data storage, privacy, consent and legal risks are becoming impossible to ignore
5 min read
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
As Chinese firms continue to improve performance while keeping prices low, the AI race is no longer just about building the smartest model—it is increasingly becoming a battle over who can deliver the best value
2 min read
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
How did Instagram run ads promoting child abuse in India?
India has issued a notice to Meta after an investigation alleged that Instagram displayed paid advertisements promoting child sexual abuse material. MeitY ordered Meta to remove such Instagram ads and explain within seven days how they were approved
8 min read
Why has India halted WhatsApp’s username feature before launch?
India has halted WhatsApp’s planned username feature, citing concerns about cybercrime, impersonation, and law enforcement challenges. As Meta races to address security concerns, here’s why MeitY has paused the rollout, what the feature does, and how it could influence privacy and online safety in India
3 min read
Advertisement
Advertisement
