Search interesting materials

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, January 10, 2024

Evaluating capital market responses to cybersecurity incidents in Indian listed companies

by Sayan Dasgupta, Renuka Sane and Karthik Suresh.

In a previous report on the Information Technology Act, 2000 we described the infirmities in the laws and institutions that govern cybersecurity threat detection and response in India. However, two questions persist. Firstly, what is the true scale of the cybersecurity problem among Indian firms? Secondly, what are the financial and reputational consequences of a cybersecurity breach at an Indian firm?

It is difficult to find answers to the first question in the public domain. But when it comes to the second question, we can gain some insights by looking at how investors respond to the news of cybersecurity incidents whenever such details are made public. In the United States, the results of these studies range from a slightly negative effect on stock prices following the announcement of an incident (e.g. Cavusoglu et al, 2004 estimated an average 2.1% loss in the first two days after disclosure) to no significant effects (e.g. Kannan et al, 2007). Amir et al (2018) however observed that there is a significant difference between the fall in stock prices for firms that disclosed the cybersecurity incident (0.7% decline in one month) vs. firms that withheld this information (3.6% decline in one month).

It is important and interesting to understand the current state of play. How many Indian listed companies made public disclosures of cybersecurity incidents? How did investors in these companies respond to this news given the limited information they had? We attempt to provide some insights into this question by conducting an event study of stock price movements that follow cybersecurity incidents in Indian listed companies. We found that there was a significant negative effect on stock prices given the prior system of disclosures.

Why is it important to make disclosures of cybersecurity incidents?

A cybersecurity incident can be a costly negative externality. In 2022, IBM surveyed 49 Indian companies and estimated the loss they suffered from a single data breach to be USD 2.32 million (INR 184.5 million). A firm suffers direct costs (e.g. costs of data recovery) as well as indirect costs (e.g. loss of trust and goodwill) due to a cybersecurity incident. These costs, along with the reluctance to divulge details about its vulnerabilities to competitors, mean that firms are not incentivized to share information on their cybersecurity incidents.

There are two reasons why firms should make disclosures about cybersecurity incidents. Firstly, consumers have a reasonable expectation of privacy. In India, the Supreme Court in the Puttaswamy decision traced this expectation of privacy to one's right to life and personal liberty. On these grounds, data privacy legislations, such as Article 34 of the EU General Data Protection Regulation and Section 8 of the Digital Personal Data Protection Act, 2023 require firms to disclose details of data breaches to their users. Secondly, securities laws are concerned with whether cybersecurity risks are "material information" that should be disclosed to investors. The concept originated in the United States --- the US Supreme Court in TSC Industries v. Northway held that a given piece of information is "material" if there is "a substantial likelihood that a reasonable shareholder would consider it important in deciding how to vote".

Specifically on materiality, the US Securities and Exchanges Commission (SEC) issued non-binding guidance in 2011 and 2018 which provided the format in which a listed entity or market participant should report on cybersecurity risks. However, in March 2023, the SEC proposed a framework for compulsory disclosures of cybersecurity risk and preparedness. In India, SEBI's general disclosure requirements on materiality are found in Regulation 30 read with Schedule III of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 ("LODR Regulations"). Sub-part B, no. 6 requires the listed entity to report "disruption of operations of any one or more units or division ... due to natural calamity (earthquake, flood, fire etc.), force majeure or events such as strikes, lockouts etc." While it was not explicitly mentioned that cybersecurity risks are to be reported, many listed companies (example) made such disclosures anyway. In June 2023, specific reporting requirements for cybersecurity incidents were added to the LODR regulations which we describe in the discussion section.

Data

Our list of cybersecurity incidents comes from two datasets that provide firm-specific incident information. The first dataset --- the "CISSM Cyber Attacks Database" --- is based on the work of Harry and Gallagher (2018). It is hosted by the University of Maryland (UoM). It has a set of 285 incidents that took place in India between 2014 and 2023. Of these, 45 incidents took place in companies listed in India. This dataset includes detailed information on the type of data that was compromised, the method of attack, and the responses of the affected companies. This data was collected by deploying a customised script that queries a list of news websites for articles or news items on cybersecurity incidents which are collected, sorted and stored. Another script then categorizes these incidents into various types.

The other dataset, called the Data Breach Investigations Report (DBIR), is hosted by Verizon. It has information on the type of breach (e.g., malware, hacking, social engineering), the target of the breach (e.g., government, enterprise, small business), the method of attack (e.g., phishing, spear phishing, watering hole attack) and the impact of the breach (e.g., data loss, financial loss, reputational damage). The DBIR dataset accepts information from a broad set of user-reported sources which are manually sorted by varying levels of confidence. The dataset has 83 incidents that took place in India between 2009 and 2017, of which 11 incidents took place in Indian-listed companies. 8 of the 11 incidents are already mentioned in the UoM database, so we are left with 3 unique entries in the DBIR. We manually categorized these three incidents based on the typology provided by Harry and Gallagher (2018).

The distribution of the different types of cybersecurity incidents is as follows:

Type Description No. of incidents
Data attack This type of attack covers the manipulation, destruction, or encryption of data in the target network. 7
Exploitation of application server This type of attack uses a misconfiguration or vulnerability to gain access to data in a server-side application (e.g. a database) or the server itself. 27
Exploitation of network infrastructure This type of attack covers the theft of data through direct access to network infrastructure such as routers, switches and modems. 1
Denial of service This type of attack is meant to degrade or deny access to other parts of the firm's network. 3
Message manipulation This type of attack covers interferences with the target's ability to accurately communicate information to its customers. 3
Combination of methods 5
Undetermined 2
Total 48

In total, our dataset has 40 unique companies and 48 incidents that took place between June 2013 and March 2023.

For stock prices, we retrieved the NSE daily closing prices for all the affected companies from CMIE Prowess for the period between 1 March 2013 to 31 July 2023.

Methodology

The event study methodology (ESM) is commonly used to measure stock price reactions to certain events (Fama et al, 969). We use the ESM to analyze the stock price consequences of cybersecurity incidents. Price reactions are represented by abnormal returns, which are stock returns adjusted for the normal daily stock price and market. We use the eventstudies package developed by Anand et al (2014) for our analysis.

This methodology involves the following steps:

  1. Identifying the event date: The event dates are the dates on which each of the cybersecurity incidents were made public i.e. the date of the news article.
  2. Calculating the abnormal returns: The abnormal returns for the affected companies are calculated on the event date and 45 days before and after the event. Abnormal returns are the difference between the actual returns of the affected companies and the expected returns of the market. The expected returns are calculated using the market model.
  3. Statistical tests: They help us determine whether the abnormal returns are statistically significant. The abnormal returns are used to test whether the cybersecurity incidents had a significant impact on the stock prices of the affected companies. The statistical tests are conducted using a variety of methods such as the t-test and the Wilcoxon signed-rank test.
  4. Analyzing the results: The results of the event study are analyzed to determine (i) the magnitude of the impact of cybersecurity incidents on stock prices, (ii) the factors that influence the impact of cybersecurity incidents on stock prices, and (iii) the implications of the results for investors, companies, and regulators.

Results

Event study results covering all incidents

Fig 1: Event study results for all 48 incidents.

We observe a significant decrease in the cumulative abnormal return (CAR) after the event date. The average decrease in the first month after the event was 3.48%. At its lowest, the CAR was -8.06%. However, with a widening 95% confidence interval, there is some uncertainty about the true effect of the cybersecurity incident on the stock prices of the companies. The sample size is low and the information available regarding the nature and magnitude of the incident is limited.

Event study covering incidents of the type "exploitation of application server"

Fig 2: Event study results for 27 incidents which were of the type "exploitation of application server".

The majority of the cybersecurity incidents were of the type "exploitation of application server". We conducted another event study on this set of incidents. However, we do not see significant results. In the first month after the event, the CAR increased by an average of 9.79%.

Limitations

Our list of 48 incidents is certainly not exhaustive. Many cybersecurity incidents may not have been reported. Given that the majority of our data comes from news sources, some disclosures may have been made long past the incident date.

Discussion

We began by asking about the financial and reputational consequences of a cybersecurity breach in a listed Indian firm. The trends in our analysis show that investors do tend to react negatively to the news of a cybersecurity incident.

As time progresses, we may be able to find more conclusive answers to both questions. This is thanks to some recent changes in the disclosure regime which will give us the true picture of cybersecurity incidents at Indian listed companies. In November 2022, SEBI in its consultation paper proposed amendments to these regulations. The consultation paper notes that cybersecurity incidents "may impact the operations and/or performance of the listed entity" but also recognizes that the "immediate disclosure of such events may not be desired since the entity may be vulnerable to further attacks". SEBI therefore proposed that the disclosures be made on a quarterly basis in the corporate governance report where the listed entity mentions the root cause of the incident as well as the remedial measures that they undertook. In June 2023, these proposals were adopted by amending Regulation 27(2) of the LODR regulations. Given the recent amendments to the SEBI LODR regulations, the quality of information on cybersecurity incidents could become richer. This could inform further studies which could deploy more sophisticated methodologies that control for other factors that could affect stock prices and remove the variation caused by them before performing the event study.

References

Chirag Anand, Vimal Balasubramaniam, Vikram Bahure and Ajay Shah, eventstudies: an R package for conducting event studies and a platform for methodological research on event studies, NIPFP Macro/Finance group, 2014.

Hassan Cavusoglu, B. K. Mishra, and S. Raghunathan, The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers, International Journal of Electronic Commerce, Vol. 9 (2004), no. 104, pp. 70--104.

Karthik Kannan, Jackie Rees and Sanjay Sridhar, Market Reactions to Information Security Breach Announcements: An Empirical Analysis, International Journal of Electronic Commerce, Vol. 12 (2007), no. 1, pp. 69--91.

Eli Amir, Shai Levi and Tsafrir Livne, Do Firms Underreport Information on Cyber-Attacks? Evidence from Capital Markets, Review of Accounting Studies, Vol. 23 (2018), issue 3, no. 11, pp. 1177-1206.

Charles Harry and Nancy Gallagher, Classifying cyber events: a proposed taxonomy, Journal of Information Warfare, Vol. 17 (Summer 2018), no. 3, pp. 17-31.

Eugene F. Fama, Lawrence Fisher, Michael C. Jensen and Richard Roll, The Adjustment of Stock Prices to New Information, International Economic Review, Vol. 10, no. 1, pp. 1--21.


Sayan Dasgupta and Karthik Suresh are researchers at XKDR Forum. Renuka Sane is a researcher at TrustBridge. We thank Ajay Shah, Geetika Palta and Siddhant Bharti for their useful comments.

Monday, May 10, 2021

Backdoors to Encryption: Analysing an Intermediary's Duty to Provide 'Technical Assistance'

by Rishab Bailey, Vrinda Bhandari, and Faiza Rahman.

The rising use of encryption is often said to be problematic for law enforcement agencies (LEAs) in that it directly impacts their ability to collect data required to prosecute online offences. While certainly not a novel issue, the matter has risen to global prominence over the last four or five years, possibly due to the increased usage of privacy enhancing technologies across the digital ecosystem.

While there have been a number of policy proposals that seek to address this perceived impasse, no globally accepted best practice or standard has been evolved thus far. In India (as in many other jurisdictions), the government has increasingly sought to regulate the use of encryption. For instance, the recently announced Intermediary Guidelines under the Information Technology Act, 2000, seek to extend the "technical assistance" mandate of certain intermediaries to ensure traceability, by enabling identification of the first originator of the information on a computer resource. The scope of the term "technical assistance" has not been clearly defined. However, the provision appears to go well beyond existing mandates in the law that require holders of encryption keys to provide decryption assistance, when called upon to do so, in accordance with due process, and based on their capability of decrypting the encrypted information. Courts have also weighed in on this debate, with the Madras High Court and the Supreme Court hearing petitions that seek to create mechanisms whereby LEAs could gain access to content protected by end-to-end encryption (E2E), thereby enabling access to user conversations on popular platforms such as WhatsApp. A Rajya Sabha Ad-hoc Committee Report released in 2020 has also recommended that LEAs be permitted to break or weaken E2E to trace distributors of illegal child sexual abuse content.

Against this background, our recently released paper examines the scope of the obligations that ought to be imposed on intermediaries to provide "technical assistance" to LEAs, and whether that should extend to weakening standards of encryption, for instance, through the creation of backdoors. Broadly speaking the term "backdoors" refers to covert methods of circumventing encryption systems, without the consent of the owner or the user. The paper also evaluates, in brief, proposals for alternatives, such as the use of escrow mechanisms and ghost protocols.

We argue that the government should not impose a general mandate for intermediaries to either weaken encryption standards or create backdoors in their products/platforms. This can significantly affect the privacy of individuals and would constitute a disproportionate infringement into the right to privacy. Such a mandate will also likely fail a cost-benefit analysis, not least in view of the possible effects on network security as well as broader considerations such as growth of the Indian market in securities products, geopolitical considerations, etc. This however, does not mean that the law enforcement agencies have no options when faced with the prospect of having to access encrypted digital data. A first step in this regard would be to implement rights-respecting processes to enable law enforcement to access data collected by intermediaries in a timely manner. In addition, there should be greater focus on enhancing government and law enforcement capacities, including by developing hacking capabilities, with sufficient oversight and due process checks and greater funding to research and development efforts in the cybersecurity and crypto spaces.

This post seeks to throw light on the key issues around the encryption debate, and summarises our main arguments and suggestions on how India should address them.

Understanding the encryption debate

Encryption is the process of using a mathematical algorithm to render plain, understandable text into unreadable letters and numbers (Gill, 2018). Typically, an encryption key is used to carry out this conversion. Reconverting the encrypted text back to plain-text also requires an encryption key. Depending on the manner of encryption, the same encryption key can be used to encrypt or decrypt information, or alternatively, one may require different encryption and decryption keys. Encryption therefore ensures that the message can only be read by the person who has the appropriate decryption key, particularly as newer forms of encryption make it inefficient, if not impossible, to reverse the encryption process (Gill, 2018).

Encryption essentially improves the security of information. It secures information against unwarranted access and ensures the confidentiality and integrity of data, thereby fostering trust in the digital ecosystem and protecting the private information of citizens and businesses alike.

However, the use of encryption can also enable criminals to "go dark", making it difficult for LEAs to carry out their functions. For instance, it is estimated that upwards of 22 percent of global communication traffic uses end-to-end encryption (Lewis et al, 2017). This puts a quarter of communications virtually out of reach for LEAs, not least as the use of modern encryption systems makes it harder for LEAs to use the traditional "brute force" method to access encrypted data (Haunts, 2019). LEAs therefore have increasingly called for limitations to be placed on the use of encryption so as to enable them to have access to information they require to pursue their law enforcement functions. They point to the need to ensure accountability for online harms, and therefore argue that intermediaries must provide them with all data relevant to an investigation.

The concerns with the use of encryption are driven by a number of factors such as the growing instances of cybercrime, the use of data minimisation practices such as disappearing messages and the use of encryption by default in various technology products. For instance, WhatsApp and Signal automatically encrypt communications in transit and also give users the option of automatically deleting their messages. Similarly, Apple uses encryption based authentication on its iPhones (which render the content accessible only if an appropriate passcode is provided. If not, the content on the phone could even be deleted after a certain number of failed attempts) (Lewis et. al, 2017).

These concerns have led to calls for Internet intermediaries to weaken encryption standards or create backdoors in their products/services. These demands are not new. Notably, the 1990s saw the issue being debated in the United States, with the FBI proposing the use of the "Clipper Chip", a mechanism whereby decryption keys would be copied from the devices of users and sent to a trusted third party, where they could be accessed on appropriate authorisation by LEAs. More recently, the FBI has been involved in face-offs with technology companies such as Apple, when it refused to provide exceptional access to an iPhone linked to a terrorist. In India too, the government has encountered similar issues - notably forcing Blackberry manufacturers to relocate their servers to India and hand over plain text of communications. The government also circulated a draft National Encryption Policy in 2015, which sought to implement obligations involving registration of encryption software vendors, and the need for intermediaries to store plain text of user data. The draft was however withdrawn after much criticism.

In response to such proposals, security researchers, cryptographers and service providers, have been near unanimous in pointing out that the creation of backdoors is likely to lead to significant costs to the entire digital ecosystem, especially as it leads to the entire population being exposed to vulnerabilities and security threats. Indeed, the need for stronger encryption and other security standards to protect user data is only heightened by the numerous and frequent data breaches that have been reported in India. Interestingly, even the Telecom Regulatory Authority of India has adopted a similar position in its Recommendations on Regulatory Framework for OTT Communication Services of 2020.

Even two commonly discussed methods of a "balanced solution" to the problem - the use of escrow mechanisms and ghosting protocols - have faced significant criticism. For instance, the use of escrow mechanisms (which, as with the Clipper Chip system described above, involve storage of the decryption key with a trusted third-party, who can then provide the same to LEAs when called upon to do so) is likely to lead to significant vulnerabilities being created in computer systems. Not only will such a system require faith in the integrity of the entity holding the decryption key, such an entity would constitute a single point of failure, which is poor system design (Kaye, 2015). Deployment of complex key recovery infrastructure is also likely to impose huge costs on the ecosystem (Abelson et al., 1997). Similarly, suggestions for using ghost protocols (which would require service providers to secretly add an extra LEA participant to private communications) have also faced significant criticism (Levy and Robinson, 2018). Given that this system would essentially require service providers to convert a private conversation between two individuals into a group chat, with a hidden third participant, critics have argued that it is just another form of a backdoor. It would erode trust between consumers and service providers, and provide for a "dormant wiretap in every user's pocket" that can be activated at will. This would also require fundamental changes in system architecture, thereby introducing vulnerabilities that can create threats for all users on platforms (Access Now et al., 2019).

Thus, while the use of such methods can enable LEAs to access user data more quickly than is currently possible, there are numerous concerns - from a civil liberties, economic and technical perspective. We outline the key concerns in this regard below.

Concerns with mandating backdoors

  • Privacy: In view of the recognition of privacy as a fundamental right, private thoughts and communications are protected from government intrusion subject to satisfaction of tests of necessity and proportionality. Mass surveillance can be considered to be per se disproportionate. It is recognised that government surveillance can lead to unwanted behavioural changes, and create a chilling effect. Encryption therefore serves as a method to protect individual privacy, particularly from government excesses.
  • Security: Creating backdoors can weaken network security as a whole since it can be exploited by governments and hackers alike (Abelson et al., 2015). Backdoors can also lead to increased complexity in systems, which can make them more vulnerable to attack (Abelson et al., 2015).
  • Right against self-incrimination: Mandating decryption of data can arguably also be seen as violating an individual's right against self-incrimination (Gripman, 1999; ACLU and EFF, 2015).
  • Due process requirements: Criminal investigation in general and surveillance in particular is not meant to be a frictionless process. Introducing inefficiencies in the functioning of LEAs is what separates a police state from a democracy (Richards, 2013; Hartzog and Selinger, 2013). As is the case of due process requirements, encryption creates procedural hurdles, ensuring some checks and balances over the functioning of LEAs and the possibility of mass surveillance. It therefore helps re-balance the asymmetric power distribution between the State and citizen.

Scope of "technical assistance": Should it extend to creating backdoors?

Given the aforementioned concerns, the question arises, should the duty of "technical assistance" that intermediaries are required to provide to LEAs, extend to the creation of backdoors or otherwise weakening encryption systems?

We argue that as far as recoverable encryption is concerned, i.e. encryption where a service provider already has a decryption key in the normal course of service provision, there is no requirement for such a mandate. Indian law already requires service providers to decrypt data in such cases, in addition to providing various other forms of assistance. Here, the need is to focus on implementing proper oversight and other procedural frameworks to ensure that LEAs exercise their powers of surveillance or decryption in an appropriate manner. We find however, that the Indian framework is lacking in this regard. There is no judicial oversight of decryption requests, no proportionality requirements in the law, and no meaningful checks and balances over decryption processes at all. We therefore proposed various changes in order to improve the transparency and accountability of the system. Further, research indicates that the primary problem of LEAs in India may relate to the relatively old and slow processes that must be used by LEAs when accessing data held by intermediaries, particularly those based outside India. This points more to the need for LEA data access processes to be revised/streamlined in accordance with modern needs.

As far as unrecoverable encryption is concerned, i.e. encryption where even the service provider cannot access the content (such as with E2E) as it does not have access to the decryption key, which is retained by the user, the situation is undoubtedly more complex. However, even in such instances, for the reasons elaborated above, we believe that mandating backdoors or weakening encryption is not an appropriate solution.

Moreover, LEAs already have multiple alternatives to collect information, including by accessing metadata and unencrypted backups of encrypted communications. They can also use targeted surveillance methods to conduct investigations (National Academy of Science, Engineering and Medicine, 2018). Indeed, the current Indian framework - governing telecom service providers in particular, but also other intermediaries - already gives significant and arguably excessive powers to the State. It should also be noted that LEAs in India are already using spying technology, as we saw in the Pegasus case. LEAs also have other covert methods of gathering data - from key-stroke logging programmes to exploiting weaknesses in implementation of encryption systems. While one cannot argue against the use of such systems in appropriate cases, it is clear that such powers must only be exercised through institutionalised processes, and importantly, subject to appropriate regulatory oversight. There is therefore a case for formulating a legal framework in India, along the lines of the US vulnerabilities equities process, to ensure due process even when the government resorts to exploitation of vulnerabilities within information systems for national security and law enforcement purposes.

Accordingly, we point to the need to carry out a more detailed cost-benefit analysis before deciding on the need to implement such a mandate (which unfortunately, has not been done in the case of the recent Intermediary Guidelines Rules). We point to how such a cost-benefit analysis should consider:

  • Whether the use of unrecoverable encryption is indeed a significant hurdle for LEAs in collecting relevant information. While no data is available in this context in India, data from the US in the period 2012-2015 indicates that of the 14,500 wiretaps ordered under the Communications Assistance for Law Enforcement Act, only about 0.2 percent of wiretaps encountered unrecoverable encryption (Lewis et al., 2017). While this share has likely increased in view of the greater use of unrecoverable encryption in the ecosystem, a similar empirical analysis must be conducted in India to understand the impact of such types of encryption.
  • The cost to intermediaries in changing their platform architecture are unlikely to be insignificant. It is also worth keeping in mind that often intermediaries will avoid using certain types of encryption purely to keep in the good books of LEAs in a form of "weakness by design". Notably, companies such as Apple and WhatsApp have dropped plans to encrypt user back-ups stored in the cloud. Such data can therefore be accessed by LEAs without compromising encryption.
  • The risk of such laws getting caught up in global geopolitics. This has been the case for example, with Huawei and ZTE, who have faced significant international pressure in view of the Chinese government's purported ability to access data flowing through their networks.
  • The possible effectiveness of such laws, considering that many criminals may use open source encryption or encryption from platforms that are not amenable to Indian jurisdiction. Further, the pace of technical development is difficult to keep up with from a regulatory perspective. Notably, institutions such as Europol and Interpol are increasingly concerned about the use of steganography (the technique of hiding the very existence of a message) and open source encryption by international criminals and terrorist groups. Therefore, even if there is a bar on using strong encryption, those who want to break this law, will continue to do so.

We therefore argue that while a mandate for targeted decryption or technical assistance may be constitutional if backed by a law with sufficient safeguards, a general mandate for the creation of backdoors (or an interpretation of the Intermediary Guidelines requirement to provide "technical assistance" to extend to such generic obligations) is unlikely to pass constitutional muster, assuming a high intensity of proportionality review is applied. A higher intensity of review will have to look at not just whether the proposed intervention would substantially improve national security, but would also need to engage with the fact that it would (a) compromise the privacy and security of individuals at all times, regardless of whether there is any evidence of illegal activity on their party, and (b) the existence of alternative means that are available to LEAs to carry out their investigations. Thus, we believe that a general mandate for creating backdoors will not be the least restrictive measure available.

Conclusions and Recommendations

We argue that a general mandate that requires Internet intermediaries to break encryption, use poor quality encryption, or create backdoors in encryption is not a proportionate policy response given the significant privacy and security concerns, and the relatively less harmful alternatives available to LEAs. Instead, the Indian government should support the development and use of strong encryption systems.

Rather than limiting the use of certain technologies, or mandating significant changes in platform/network architecture of intermediaries that compromises encryption, the government ought to take a more rights-preserving and long-term view of the issue. This will enable a more holistic consideration of interests involved, avoid unintended consequences, and limit costs that come with excessive government interference in the technology space. The focus of the government must be on achieving optimal policy results, while reducing costs to the ecosystem as a whole (including privacy and security costs). A substantive mandate to limit the use of strong encryption would increase costs for the entire ecosystem, without commensurate benefits as far as state security is concerned.

The tussle between LEAs and criminal actors has always been an arms race. Rather than adopting steps that may have significant negative effects on the digital ecosystem, the government could learn from the policies adopted by countries such as Germany, Israel and the USA. This would involve interventions along two axes - legal changes and measures to enhance state capacity.

Legal changes that the government must consider implementing, include:

  • Reforming surveillance and decryption processes, to clarify the powers of LEAs, and ensure appropriate transparency, oversight and review. It is also essential to standardise and improve current methods of information access by LEAs at both domestic and international levels. There must be greater transparency in the entire surveillance and information access apparatus, including by casting obligations on intermediaries and the State to make relevant disclosures to the public.
  • Adoption of a Vulnerabilities Equities Process, such as that adopted in the United States, which could enable reasoned decisions to be made by the government about the disclosure of software/network vulnerabilities (thereby allowing these to be patched, in circumstances where this would not significantly affect security interests of the State). Such a process, while not without critics, does chart a path forward and must become central to the Indian conversation around due process in LEA access to personal data.
  • Amending telecom licenses, which currently give excessive leeway for exercise of executive authority, without sufficient checks or safeguards.

Rather than implement ill-thought out policy solutions that would significantly harm the digital ecosystem and user rights, the government could also focus on enhancing its own capacities. This can include measures such as:

  • Developing and enhancing covert hacking capacities (though these must be implemented only subject to appropriate oversight and review processes). To this end, there must be appropriate funding of LEAs, including by hiring security and technical researchers.
  • Investing in academic and industry research into cryptography and allied areas. The government should also aid the development of domestic entities who can participate in the global market for data security related products. Enhancing coordination between industry, academia and the State is essential.
  • Increasing participation in international standard setting and technical development processes.

To conclude, the crux of this issue can be understood using an analogy. Would it be prudent for a government, engaged in a fight against black money, to require all banks to deposit a key to their customer's safe deposit boxes with it? One would venture that this would be an unworkable proposition in a democracy. It would lead to people looking for alternatives to the use of safe-deposit boxes due to the lack of trust such a system will create. Innocent people will be exposed to increased risks. A preferable solution may be for the government to develop the ability to break into a specific safe deposit box, upon learning of its illegal contents, and subsequent to following due process. This would enable more targeted interventions, that would also preserve the broader privacy interests of innocent customers while protecting banks from increased costs (or loss of business).

References

Gill, 2018: L Gill, Law, Metaphor and the Encrypted Machine, Osgoode Hall L.J. 55(2) 2018, 440-477.

Lewis et al., 2017: James Lewis, Denise Zheng and William Carter, The Effect of Encryption on Lawful Access to Communications and Data, Center for Strategic and International Studies, February 2017.

Haunts, 2019: Stephen Haunts, Applied Cryptography in .Net and Azure Key Vault: A Practical Guide to Encryption in .Net and .Net Core, APress, February 2019.

Kaye, 2015: David Kaye, Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, United Nations, Human Rights Council, May 2015.

Abelson et al., 1997: Hal Abelson, Ross Anderson, Steven Bellovin, Josh Benaloh, Matt Blaze, Whitfield Diffie, John Gilmore, Peter Neumann, Ronald Rivest, Jeffrey Schiller, and Bruce Schneier, The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption, May 27, 1997.

Levy and Robinson, 2018: Ian Levy and Crispin Robinson, Principles for a More Informed Exceptional Access Debate, LawFare Blog, November 29, 2018.

Cardozo, 2019: Nate Cardozo, Give Up the Ghost: A Backdoor by Another Nam et al.e, Electronic Frontier Foundation, January 7, 2019.

Access Now et al., 2019: Access Now, Big Brother Watch, Center for Democracy and Technology, et al., Open Letter to GCHQ, May 22, 2019.

Harold Abelson et al., 2015: Harold Abelson, Ross Anderson, Steven Bellovin, Josh Benaloh, et al., Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications, MIT-CSAIL Technical Report, July 6, 2015.

Gripman, 1999: David Gripman, Electronic Document Certification: A Primer on the Technology Behind Digital Signatures, 17 J. Marshall J. Computer and Info. L. 769 (1999).

ACLU and EFF, 2015: American Civil Liberties Foundation of Massachusetts, the American Civil Liberties Union Foundation, and Electronic Frontier Foundation, Brief for Amici Curiae in Support of the Defendant-Appellee in Commonwealth of Massachusetts v. Leon Gelfgatt, 2015

Richards, 2013: Neil Richards, Don't Let US Government Read Your E-Mail, CNN, August 18, 2013.

Hartzog and Selinger, 2013: Woodrow Hartzog and Evan Selinger, Surveillance as Loss of Obscurity, Washington and Lee L.R. 72(3), 2015.

National Academy of Science, Engineering and Medicine, 2018: National Academy of Science, Engineering and Medicine, Decrypting the Encryption Debate: A Framework for Decision Makers, National Academies Press, Washington DC.


Rishab Bailey is a researcher at NIPFP. Vrinda Bhandari is a practising advocate. Faiza Rahman is a PhD candidate at the University of Melbourne.

Thursday, March 25, 2021

Towards better enforcement by regulatory agencies in India

by Trishee Goyal and Renuka Sane.

India is on the verge of establishing yet another regulator, the Data Protection Authority (DPA), to implement the provisions under the Personal Data Protection Bill, 2019. As per the Bill, the DPA will regulate anyone who collects data for commercial use with a turnover of more than INR 20 lakh annually. This would cover entities from small time telemarketers to social media behemoths. The scope of its regulated entities will thus be more extensive than any of the regulators previously established in India. The DPA has the power to either suo motu or on a complaint take action against a data fiduciary or a data processor who may be violating the law. It can, inter alia, issue directions, call for information, conduct inquiries, issue orders for injunctive relief, suspend or cancel the registration of businesses.

With such an expansive responsibility, it is important to get the design of the enforcement processes of the DPA right. Failure to follow due process in enforcement would be damaging to the ease of doing business, to the digital and start-up ecosystem and damage India's chances of dominance in these spheres. More importantly, such failures will have adverse consequences on the justice and dignity of the regulated entities.

In a new working paper, Towards better enforcement by regulatory agencies, we study the gaps in enforcement at the Securities Exchange Board of India (SEBI) and the Competition Commission of India (CCI). The gaps pertain to whether processes of natural justice have been adhered to during the conduct of enforcement activities. We reflect on the lessons this might have for the DPA.

In India, there exists a small literature on the problems with the legislative functions (some examples include Burman and Zaveri, 2018; Bhandari and Sane, 2019), and the judicial functions (see Datta et. al., 2019). In this paper we focus on the executive, or the enforcement, functions of a regulator. Our paper also connects to a larger literature across the world on the dilution of accountability at the 'new administrative state'. Administrative agencies are increasingly built with legislative, executive and judicial mandates. Such agencies are expected to draft subordinate legislation, be responsible for licensing and enforcement actions, and also adjudicate on investigations usually carried out by itself. Questions on checks and balances and due process that were reasonably settled in liberal democracies when it came to government functioning are now being debated once again w.r.t regulators.

Why SEBI and CCI?

Before we discuss questions on natural justice, a word on why we chose to study SEBI and CCI. The Justice Srikrishna Committee Report on data protection suggests that the DPA will be modeled along the lines of other Indian regulators such as TRAI, SEBI, CCI etc. Among the regulators discussed in the report, we found that SEBI has been considered the most effective, as far as its enforcement actions are concerned. CCI is relevant as it is a more recently established regulator. A study of CCI comes at an interesting checkpoint in the development of regulatory governance. As the DPA will be modeled on these regulators, it is important to understand how enforcement is currently taking place and whether there is an inherent problem in the structure of enforcement. For example, Roy, Shah, Srikrishna, and Sundaresan (2019) argue that Indian regulators have too often veered into controlling as opposed to regulating, and that enforcement has been selective and weak, and failed to adequately follow the rule of law, especially on due process. State capacity is known to be weak in India, suggesting the need to move beyond existing models of regulatory design.

Three elements of natural justice

Natural justice is a vast area. We focus on the three most basic elements of natural justice - how are notices served, whether parties are allowed to examine material and cross-examine witnesses, and whether there is separation of powers, especially between the investigation and adjudication functions.

Procedural failures at SEBI and CCI

In the case of SEBI, we studied orders of the Securities Appellate Tribunal (SAT) for a six month period (October, 2019 to March, 2020) where we found that 33% of SEBI orders were over-ruled on failure to adhere to principles of natural justice. Of the cases over-ruled, 86% were related to issues of notice and 14% to issues of examination of materials. SEBI fares poorly on separation of powers. With respect to CCI, a survey of appellate orders passed by the Competition Appellate Tribunal and the Supreme Court, pointed to the lack of due process being ingrained in enforcement procedures. However, CCI maintains separation of powers with a far greater degree as compared to SEBI. The design of the enforcement structure also allows for application of mind by the Commission at multiple stages - at the time of formation of prima facie opinion, at the time of issuance of direction for investigation and lastly, at the time of penalty proceedings.

Importance of codification

Why is it that there are such procedural failures? Legislation in India confers certain powers of a civil court to a regulatory agency, and expects that the regulator will comply with the principles of natural justice. There is, however, no guidance on how regulators should comply with these principles (Burman & Krishnan, 2019; Sundaresan, 2018). Common law in India has held the view that principles of natural justice are not considered embodied rules -their application has been made dependent on a variety of factors such as the nature of the tribunal in question, the controversy in question and the facts and circumstances at hand. As a result, the development around principles of natural justice in administrative law has been in an ad hoc manner. There is very little by way of standardised procedures that an administrative body can source from common law.

What would improve these processes? We look at the structure of regulators in other countries - namely the US and the UK. We find that the processes that Indian law just assumes will be followed, are actually codified in laws, regulations and process manuals in these countries. Codification is important as a study of CCI also shows - while the CCI does better in terms of structural separation, issues of due process continue to remain due to scanty guidance available in the Competition Commission of India (General) Regulations, 2009 on other aspects. Codification of processes on legislative powers, such as having more prescriptive rules on the requirements of consultation, have led to better regulation making processes (Burman & Zaveri, 2018).

Lessons for the DPA

We have the following recommendations for the DPA. The objective is to provide adequate guidance to the regulator as it discharges the enforcement function, as well as to the broader community as it continuously evaluates the performance of the regulator on these counts.

  1. There should be an inclusion of the procedural rights in the statute itself. These provisions would specify a detailed outline of the show cause notice, the scope of the right of examination of materials, the procedure to be followed in case of ex-parte orders and the timelines of providing representation against each of the processes where such representation can be made.

  2. Further, regulations should include the manner in which notice is to be served, the manner of providing opportunity of hearing (written submissions), the form in which materials are to be submitted to the regulated entity under its right of examination of materials etc.

  3. The law, regulations, as well as detailed manuals should be available in the public domain.

  4. At the very least, there should be a cadre of administrative law officers who would not be engaged in any functions of the regulator except performing the quasi judicial functions. There should be an Administrative Law Member in the Board of the agency whose specific task would be to manage the cadre of administrative law officers. This would lead to the insulation of quasi judicial functions of the regulator from executive, investigation and inspection functions.

Conclusion

The concerns raised by us have begun to get recognised in India. For example, in 2011, the Financial Sector Legislative Reforms Commission (FSLRC) Report laid out a regulatory framework imbibing the principles of natural justice. More recently, in 2019, the Report of the Competition Law Review Committee, reviewed the enforcement processes in the CCI. Similarly, the Sahoo Committee Report set up to examine development and regulation of valuation professionals, while laying out the regulatory design for the said purpose, emphasised the need of principles of separation of powers, reasoned orders, independence and accountability. The follow through on the recommendations, however, has been scarce. We think that a statutory formulation of the administrative law requirements would strengthen the rule of law in enforcement actions.

References

Bhandari, V., and Sane, R. (2019) A Critique of the Aadhaar Legal Framework. 31 NSLIR Rev 1-23.

Burman, A., & Krishnan, K. (2019). Statutory regulatory authorities: Evolution and impact.

Burman, A., & Zaveri, B. (2018). Regulatory responsiveness in India: A normative and empirical framework for assessment William & Mary Policy Review , 9 (2), 1-26.

Datta et. al. (2019), How to Modernise the Working of Courts and Tribunals in India. NIPFP Working paper 258.

Roy, S., Shah, A., Srikrishna, B. N., & Sundaresan, S. (2019). Building state capacity for regulation in India. Devesh Kapur and Madhav Khosla (eds.), Regulation in India: Design, Capacity, Performance, Oxford: Hart Publishing.

Sundaresan, S. (2018). Capacity building is imperative. Column titled Without Contempt in the editions of Business Standard dated August 2, 2018.


The authors are researchers at NIPFP. This paper was produced as part of the Data Governance Network. We thank Somasekhar Sundaresan for useful discussions.

Tuesday, September 22, 2020

Improving internet connectivity during the COVID-19 pandemic

by Vrinda Bhandari.

Introduction

The Covid-19 pandemic has forced all of us to live, work, learn, and communicate online. This has led to an increase in the demand for reliable, efficient, and speedy internet access during the pandemic. However, those who are already disadvantaged are suffering greater digital exclusion during this time, in the form of inadequate internet connectivity. Thus, countries, especially developing countries have been presented with an opportunity to deploy different regulatory and policy tools to improve internet access and provide meaningful internet connectivity to their citizens.

In my recently published paper for the Digital Pathways at Oxford Paper Series, I try and understand how Covid-19 has served as a catalyst for positive regulation in improving internet connectivity through the discussion of initiatives taken by four governments - Panama, South Africa, Kenya, and the State of Kerala (in India). Specifically, I ask two questions:

  • What regulatory and policy steps were taken by governments and regulators to meet the increased demand for access to the internet during the Covid-19 pandemic?
  • What changes in regulation are necessary to nudge mobile network operators (MNOs) to work with governments to ensure continued and affordable access to the internet?

The paper examines the different approaches that have met with some success in the four countries and provides various policy options for governments to maintain and improve internet connectivity during the pandemic. In this blog post, I will be summarising the various policy options that are available to governments.

Temporary allocation of spectrum by regulators

Low spectrum allocation adversely impacts network infrastructure and performance; reduces the reliability and quality of mobile broadband services; and can affect the future deployment of mobile broadband technologies. Thus, one option available with governments to maintain efficient and reliable internet connectivity during a crisis is to temporarily allocate unassigned spectrum to MNOs in a fair and non-discriminatory manner. Through the four cases discussed, the paper found that spectrum allocation is a viable option during an emergency only in cases where the total (permanent) allocation of spectrum to MNOs has been inefficient. Thus, while this option was expressly considered/offered by all four countries, there was uptake only in Panama and South Africa. Despite the opportunity cost to allocating spectrum free of charge (in terms of foregone revenue from auction proceeds), both these countries pursued this method in view of the insufficient existing spectrum allocation and by attaching certain conditions to the allocation of spectrum.

The regulators in Panama and South Africa temporarily allocated spectrum to MNOs through the passage of emergency resolutions and regulations, which set out:

  • The frequency of spectrum that was open for temporary allocation;
  • The duration of the temporary allocation;
  • The application procedure and the requirements that needed to be met by applicants, such as demonstrating network performance (as in South Africa);
  • Whether the temporary allocation was free of charge or not - in both Panama and South Africa the allocation was free of charge; and
  • The conditions or expectations that were tied to the allocation of spectrum, in the form of reduced data costs or network expansion that could benefit the users.

While allocating spectrum during an emergency, countries should take care to ensure that such spectrum allocation does not become permanent; affect the long-tem spectrum allocation plan of the regulator; and does not reduce the overall competitiveness of the sector, by entrenching the dominance of a few players. The paper also briefly discusses alternative innovative approaches to spectrum management that could have been employed by the regulators.

Temporary freeze on internet and mobile payments

The COVID-19 pandemic has forced people to stay at home. This has meant that people are even more reliant on the internet to work from home, to study, to have any medical consultation, to stay in touch with friends and family, or to consume online entertainment. At the same time, the impact of the pandemic has been the hardest on the marginalised sections of society, who may find it difficult to keep up payments on their internet or mobile bills.

In such a situation, another policy option that can be considered by governments is to put in a place a temporary freeze on internet and mobile payments for a certain period of time, as was done in Panama. Drawing from the Panamanian example, any government considering such a temporary freeze can use a legal instrument that clearly defines:

  • The duration of the temporary freeze on payments, i.e. the time period for which payment of any internet or mobile bill can be suspended and deferred;
  • The criteria for intended beneficiaries, depending on whether the benefit is expected to be universally applied or restricted to a smaller identified class (as in Panama);
  • The method of repayment, specifying the time period over which the pending bills have to be paid, the number of instalments, and whether the repayment is interest free;
  • Whether there is any impact on the credit history of an individual if they avail of this measure - In Panama, the government clarified that there would be no impact on credit history or the quality of services offered by MNOs.

Having a clear narrowly tailored legal instrument that lays down the obligations of the MNOs, avoids a situation as in India, where the industry body, the Cellular Operators Association of India and the regulator, TRAI were at loggerheads about the nature of the obligation placed on MNOs. TRAI had wanted the MNOs to ensure continued service to all prepaid SIM card owners during the period of the lockdown, whereas the MNOs wanted to restrict it only to the "underprivileged and needy customers", so as to avoid an unjustified subsidy for a larger customer basis.

Prohibition on price increase

Similar to the temporary freeze on internet payments, where MNOs are required to continue service for a limited duration, even in cases of non-payment by users (albeit with an obligation to pay back), this regulatory measure prohibits a price increase in the data plans during the period of the emergency/pandemic. Such a measure was put in place in South Africa through the Electronic Communications, Postal, and Broadcasting (ECPB)Directions in March, although the ECPB Directions were amended in May 2020 to remove such restrictions.

Implementation of tax measures

In order to encourage MNOs to pass on certain benefits to consumers, in the form of reduced data costs, governments can implement various tax measures, such as reducing Value Added Tax, as in Kenya, where the VAT was reduced across the board from 16% to 14% with effect from 01 April 2020. In Panama, the government introduced a "Solidarity Plan" or "Plan Solidario" as a temporary support program to mitigate the economic impact of COVID-19. As part of this Plan, the government offered MNOs income tax deduction on any contributions in cash or kind or any other services towards the government's crisis efforts. Partially in response to this, all the MNOs in Panama came together to announce a "Solidarity Mobile Plan", which was a free basic package for accessing the internet.

Support to telecom infrastructure service providers

Another option available with governments, while not directly regulatory in nature, involves coordination and cooperation with the telecom infrastructure service providers to ensure uninterrupted internet service during a lockdown. This is because practical problems such as inadequate/interrupted power supply, or the necessary municipal officials not being available may affect the service providers.

The State of Kerala in India was unique amongst the cases discussed in the paper in that the Kerala State IT Department worked with the Kerala State Electricity Board in identifying the mobile towers that were exclusively reliant on Diesel Generator (DG) sets, and monitoring the regular supply of diesel to these towers during the national lockdown. This was done to prevent major power outages that could disrupt cell service. In South Africa, to support the legal obligation for continued service by ISPs and MNOs, the telecom infrastructure providers were given regulatory support, in the form of prioritised infrastructure approvals, postponement on license fee renewals, and temporary deferment of wayleaves.

Utilisation of the un-utilised money in the Universal Access Fund

Countries such as Kenya and India have a form of a universal access fund, which comprises of mandatory contributions by MNOs. For instance, in India, a universal access levy is statutorily levied on MNOs to contribute towards the "Universal Service Obligation Fund", which is aimed at ensuring widespread, non-discriminatory, and universal access to ICT services in India. A large amount of money is lying un-utilised in the funds in both these countries (estimated to be INR 51,500 crore in India) and this money can potentially be re-directed by the government towards specific connectivity measures during an emergency, such as reducing data costs or improving network resilience. Alternatively, as in Colombia, governments can temporarily suspend the payment obligations into these universal access funds for MNOs, so that the savings can be passed on to the users.

Provision of zero-rated access to specific websites

In some countries, such as in South Africa, data costs are fairly high, leading to real concerns about affordability and accessibility to the internet during a pandemic. In such a situation, providing zero-rated access, i.e. free access, to certain important health and education websites, may help keep citizens up to date about the latest medical information and research about the virus; as also help students access online educational resources. Consequently, the South African government passed a law requiring MNOs to provide zero-rated access to certain government and local educational websites. Currently, over 1000 health and education websites are offering zero-rated (i.e. free) access to their content.

However, it is worth bearing in mind that zero-rating is a complex issue, especially as the debate in India demonstrates. Hence, any government adopting such a policy should consider the following factors:

  • Zero-rating is often technically complex to implement, since ISPs may not have the technical architecture to distinguish amongst the websites visited by a particular user; and hence, will be unable to determine whether the user is accessing a COVID-19 zero-rated website or a regular website;
  • A zero-rating pandemic policy may limit the zero-rated websites to health and educational websites. However, as a matter of practice, with many websites, notably YouTube, it is difficult to distinguish between the educational and entertainment value of the website;
  • Any requirement, as imposed in South Africa, that the zero-rated website must be a "local" educational content website, may run into the problem that even "local" websites host third party non-local content in the form of embedded videos and text or store the content on a foreign cloud server. Theoretically, access to these websites will not be "local", and hence, they will fall outside the intended benefit of the government's zero-rating policy;
  • Finally, and perhaps most importantly, zero-rating inherently involves privileging certain websites and content over the other, whether the decision is being taken by the government or MNOs or both. In the long run, this can threaten and potentially undermine net neutrality.

Regular monitoring of network capacity

Maintaining reliable and uninterrupted access to the internet also involves ensuring that the back end of the entire telecom infrastructure service system works. Thus, governments can coordinate with MNOs to regularly monitor network performance to assess whether there is sufficient network capacity to meet the increased demand for internet access during a pandemic. Collecting the requisite data will help the government form empirically sound policy. For instance, in Kerala, much before the national lockdown was announced, the State IT Secretary held a meeting with the Telecommunication Department and and all the MNOs in the Kerala Circle to understand internet consumption pattern, bandwidth utilisation, and network capacity in the state. The MNOs had agreed to increase network capacity by 30-40% if required. However, as it turned out, based on the periodic reports that were submitted by MNOs, the government and the MNOs realised that there was no need to increase server capacity or allocate additional spectrum. Similarly, in April, the Kerala State IT Department issued a government order approving the upgradation of networks from 3G to 4G by MNOs in specific tower locations, which had otherwise been delayed.

Conclusion

By examining the regulatory response in Panama, South Africa, Kenya, and India (specifically Kerala), the paper presents various policy options that can be used by a government to improve maintain and improve internet connectivity during a pandemic. Although the paper is situated within the COVID-19 pandemic response, the policy options can be used in any emergency situation that creates additional stress on the existing digital divide and infrastructure. It is worth noting that the paper only focuses on temporary regulatory measures that are intended to maintain and improve internet connectivity during the period of an emergency, although these may have medium to long-term benefits as well.

However, any regulatory measure undertaken by a government to improve internet connectivity during an emergency should be capable of having a tangible impact in the short-term, apart from/ in addition to any medium or long-term benefits. This is because in an emergency such as the COVID-19 pandemic, any increase in the demand for the internet or reduced capacity to afford continued internet services requires immediate and urgent policy intervention. For instance, in Kenya, the pandemic expedited the approval of the innovative Loon Project, that is aimed at using the high altitude internet balloons to bring 4G coverage to underserved and remote areas of Kenya. While this is certainly an innovative example of positive regulation, it may not have the desired short-term effects given the complexity and scale of the project. The Kenyan government also constituted a COVID-19 ICT Advisory Committee that was commissioned to submit a report on the methods of improving "universally affordable connectivity" within six months. However, there is an opportunity cost of establishing a Committee in the middle of a pandemic, in that the government's time and money could have been better spent in pursuing other positive regulations.

References

AA4I (2020): Alliance for Affordable Internet, Meaningful connectivity: A new standard to raise the bar for internet access.

Bhandari(2020): Vrinda Bhandari, Improving internet connectivity during COVID-19, Digital Pathways at Oxford Paper Series No. 4, Oxford, United Kingdom.

European Commission (2017): European Commission, Zero-rating practices in broadband markets.

GSMA (2020): GSMA, Keeping the world connected: Development challenges in times of COVID-19.

Hadzik (2019): Senka Hadzic, A global south perspective on alternative spectrum policy, Research ICT Africa Policy Brief 1: December 2019.

ISPA (2020): ISPA, COVID-19: Most frequently asked questions for ISPs.

ITU (2020): International Telecommunications Union, Pandemic in the internet age: Communications, industry responses.

Vrinda Bhandari is a practicing advocate in Delhi.

Monday, May 25, 2020

Constitutionalism During a Crisis: The Case of Aarogya Setu

by Vrinda Bhandari and Faiza Rahman.

The Aarogya Setu app

Aarogya Setu is a contact tracing app that was launched by the government on April 2, 2020, as a tool to combat the COVID-19 crisis. Although initially meant to be voluntary, some government organisations, state governments, and eventually the Ministry of Home Affairs ("MHA") began mandating the installation and use of the Aarogya Setu app for their employees soon after. In a welcome move, on May 17, 2020, when the MHA issued fresh lockdown guidelines, it changed the directive for downloading the app from mandatory to a "best effort basis". However, there is still some uncertainty about the meaning of these guidelines, since the Indian Railways, and the Delhi Metro continue to require residents to download the app in order to use their services. Recent reports also indicate that the installation of Aarogya Setu will be compulsory for all air passengers above the age of 14 years. Therefore only time will tell as to whether downloading the app will de facto become mandatory. The Aarogya Setu app provides a good practical framing, to think deeply about coercion in a liberal democracy during a crisis.

There are four interesting aspects about the Aarogya Setu app.

  1. The use of state coercion. The level of coercion in play has been significantly diluted by the latest MHA guidelines where the softer words "best effort" are used. However in the case of air and rail travel, there is uncertainty about whether passengers will be prohibited from travelling, if they have not downloaded the app.
  2. The problem of privacy and security. The issues have been been discussed extensively in the Indian discourse [privacy, security].
  3. The lack of legislative foundations. A clear and specific legal basis for deploying and using the app - an anchoring legislation, with proper safeguards - would have helped allay some of the privacy and security concerns, and would have provided a proper avenue for grievance redress.
  4. Practical governance considerations. Governance related issues with the design and roll out of the app have come to the fore, especially the problems of lack of post-facto consultation, transparency, and accountability.

The first two problems (state coercion, privacy and security) have been extensively analysed by researchers in recent months. In this article, we focus on the latter two issues, aiming to obtain clarity on the issues and offer constructive policy proposals for the way ahead.

Underpinning all four issues, however, is the foundational problem of executive discretion in a crisis. While it true that the executive arm of the government has a greater ability to take emergency measures during a pandemic, it does not mean that the role of judicial review is or should be reduced to nought. We start by exploring these foundations.

Principles of evaluating executive action during a crisis

We are in the middle of a COVID-19 pandemic, which is one of the worst global health crises in a century. More than 60 countries have responded by invoking some form of emergency powers to deal with the crisis. These emergency responses have resulted in hitherto unacceptable restrictions on freedoms and civil liberties and a curtailment of the right to privacy. In India, we have witnessed among other things, the deployment of drones to monitor people's movements, the publication of the names of individuals on quarantine lists, and the roll out of a centralised contact tracing app. When government actions have been challenged in court, the courts have generally taken the view that "extraordinary situations call for extraordinary measures". This reflects the general belief that the executive should be given more leeway during a crisis.

As plausible as that argument sounds, it is not entirely correct. As Wiley and Vladeck (2020) explain, COVID-19 reinforces the case for "regular" judicial review, and not a suspension of civil liberties in times of crisis. This is for three reasons. First, emergency powers are supposed to be exercised for a crisis that is finite and limited in duration (such as the Tsunami that led to the enactment of the Disaster Management Act, 2005 in India). By its very nature, the COVID-19 crisis, with fears of a second wave, does not lend itself to a near end-point, at least not till a vaccine is developed. A prolonged use of emergency powers risks normalising the centralisation of power and potentially damages the fabric of our democracy in the long run.

Second, there is an assumption (or fear) that if courts were to perform their role of judicially reviewing government action, they would easily strike down executive orders, thus impeding the government's fight against COVID. In a sound liberal democracy, this is not the case. The doctrine of proportionality requires the government to demonstrate, rather than simply cite, its compliance with the four prongs of (a) legality: existence of a law; (b) suitability: rational connection between the government measure and the aim to prevent the spread of COVID; (c) necessity: was there a less restrictive measure the government could have employed; and (d) balancing the public interest with the loss of liberty. In times of a public health crisis, a government may well be able to satisfy these tests for the unusual actions that it takes. But in a well functioning liberal democracy, it does need to provide adequate evidence and justification for its actions. Proportionality, and judicial review, thus only ensure that we do not cut a blank cheque to the government.

The judiciary is the only branch of the Indian state that has the structural power and institutional credibility to protect the Constitution, especially in times of crisis. A robust judicial response can lead to better governmental action and protection of democracy in the long run. For example, after the Kerala High Court stayed a government orders on the deferral of salary payment, the Kerala State government brought an ordinance -- thus achieving the same result, but through a better process.

Absence of a clear and specific law

Our analysis of the Puttaswamy (2017) verdict describes how any valid restriction on the fundamental right to privacy has to satisfy the four-pronged test of legality, legitimate aim, proportionality and procedural safeguards. The first prong of legality demands that any restriction on the right to privacy must be prescribed by a publicly available law. The principle of legality, however, does not mean the mere existence of a law. Especially, in the context of communications surveillance, the principle demands that this law ought to meet a standard of clarity and specificity that is sufficient to guarantee that individuals have advance notice of and can foresee the manner in which it will be implemented.

While the issue of mandatory download of the app is behind us, many statutory agencies and private organisations continue to coerce their users or employees to install the app. Hence, the need for a law remains. The collection of personal data of an individual, without their informed consent, undermines the principles of privacy, autonomy, and informational self determination, that have been emphasised in Puttaswamy. The various privacy and security concerns associated with the Aarogya Setu app, have been well documented, including by former intelligence officials. Consequently, any direction to mandatorily install the Aarogya Setu app in order to access any service, when it is known that the app continuously collects personal information such as location data through GPS and bluetooth, has to be traced to a valid law, if it is to satisfy the proportionality test.

Drawing a parallel with the Aadhaar experience is useful. Although initially set up on the basis of an executive notification passed by the Planning Commission, the UIDAI was eventually given a statutory basis through the passage of the Aadhaar Act in 2016. The enactment of the Aadhaar Act represents an implied, if belated, admission on the part of the government that citizens' privacy cannot be violated without an enabling legislative framework. At the same time, there is a precedent, in the Aadhaar story, of making Aadhaar de facto mandatory, even though the Aadhaar Act was clear that it was voluntary.

At present, the only possible legal basis for the Aarogya Setu app could come from the issuance of MHA Guidelines under the Disaster Management Act, 2005 or the issuance of an order under Section 144, Cr.P.C. (as in Noida) However, both these provisions are inadequate and unsatisfactory as legal foundations for the app. Let us analyse each of these.

Is the Disaster Management Act an adequate legal foundation for the app?

The MHA Guidelines draw their authority from Section 10 (2) (l) of the Disaster Management Act, 2005. However, this provision cannot satisfy the legality requirement since it is a broad, omnibus provision that simply gives the power to the government to "lay down guidelines for, or give directions to, the concerned Ministries or Departments of the Government of India, the State Governments and the State Authorities regarding measures to be taken by them in response to any threatening disaster situation or disaster." As the sentence shows, the law gives the power to coerce arms of the government, and not private actors.

The restriction of fundamental rights must be grounded in a specific legal provision that specifies the conditions under which the right can be infringed and sets out the procedural and substantive safeguards to protect privacy. As Justice Srikrishna has observed, the National Executive Committee set up under Disaster Management Act, that issued the May 1, 2020 Guidelines directing the installation of Aarogya Setu, is not a statutory body. In the present case, there is no evidence of any specific parliamentary approval having been sought for directing the mandatory installation of the Aarogya Setu app by all smartphone holders (apart from the fact that there is a lot of ambiguity around how these mandates will apply to the majority of Indians who do not own a smartphone).

The issue regarding the lack of legislative basis arose in another context before the Kerala High Court last month. In light of the COVID-19 pandemic, the Kerala Government had issued an executive order deducting the salaries of government employees. When the order was challenged on the ground of legality, the State Government tried to rely on the Disaster Management Act, 2005 as well as the Kerala Ordinance amending the Epidemic Disease Act, 1897 as providing adequate legislative basis for the government order. However, the High Court rejected the government's contention on the ground that, " the provisions that were read out, specifically Sections 38 and 39 of the Disaster Management Act 2005, do not specify or confer any power upon any Government to defer the salary due to its employees during any kind of disaster. Prima facie, I feel that law is found wanting to justify the issuance of [the order]." The government eventually passed an ordinance to achieve its intended aim.

There is also the issue of excessive delegation. Section 10 (2) (l) of the Disaster Management Act does not delegate the power to the National Executive Council to create a data collecting app, nor does it provide any guidance on the exercise of powers. For instance, in United Kingdom v. Malone, the European Court of Human Rights ("ECHR") held that the secret and opaque nature of communications surveillance meant that "it would be contrary to the rule of law for the legal discretion granted to the executive to be expressed in terms of an unfettered power". Consequently, the ECHR held that in order to satisfy the principle of legality, the law must indicate the scope of any such discretion conferred on the competent authorities and the manner of its exercise with sufficient clarity, having regard to the legitimate aim of the measure in question, to give the individual adequate protection against arbitrary interference.

On May 11, 2020, the government released the Aarogya Setu Data Access and Knowledge Sharing Protocol, 2020 ("Protocol") for the "effective implementation" of the MHA Guidelines. This Protocol lays down certain principles regarding the collection, processing, and sharing of personal data. However, the Protocol does not have the status of law, nor can it derive any statutory backing from the Disaster Management Act, 2005. More importantly, it does not seek to confer any legal status to the app itself. There is no mechanism to verify that the app actually works as stated, and nothing prevents a change in the working of the app under conditions of non-transparency. Hence, the release of the Protocol cannot be seen as providing legal foundations for the use and deployment of the Aarogya Setu app.

Is Section 144, Cr.P.C., an adequate foundation for the app?

As an example, the Gautam Budh Nagar (Noida) administration in Uttar Pradesh had earlier passed an order under Section 144 of the Code of Criminal Procedure ("Cr.P.C."), mandating the installation of the Aarogya Setu app for residents of the entire district, under the threat of criminal sanction. In another welcome move, the orders under Section 144, Cr.P.C eventually lapsed.

It is an interesting intellectual puzzle, to analyse the ability of the executive to coerce private persons through this route. Section 144 of the Cr.P.C authorises the Magistrate to issue an order in urgent cases of nuisance of apprehended danger directing "any person to abstain from a certain act" or to take certain order with respect to certain property in his possession or under his management. The Calcutta High Court, in a series of decisions in the early 1930s, interpreted this provision to mean that a Magistrate is only entitled to make a restrictive order preventing the opposite party from doing an act. It does not enable him to make a mandatory positive order directing an individual to do a particular act. For instance, in Kusum Kumari Debi (1933), an order by the Magistrate directing the Petitioner to fill up an excavation at her own cost was held to be beyond the remit of Section 144, Cr.P.C, and the subsequent proceedings initiated under Section 188, I.P.C were quashed. Similarly, in B.N. Sasmal (1930), the Magistrate's direction under Section 144, Cr.P.C directing Sasmal to leave the Midnapur District for two months was quashed since it "was in effect not a direction to abstain from doing anything, but a direction upon a person to remove him self from the district." These judgments have subsequently been cited with approval by various High Courts (Ramanlal Patel (1971), Muzaffarpur Electric (1973).) Thus, any order passed by a Magistrate under Section 144, insofar as it directs individuals to download the Aarogya Setu app falls foul of the law.

The importance of a law and the process of legislation

In a constitutional democracy, the authority to coerce private individuals can only flow from a law that has been vetted and approved by democratically elected representatives of the people. While the executive is often charged with filling out the details missing in parliamentary legislations through rules and regulations, the democratic deficit of these instruments is undeniable i.e., these instruments are drafted and approved by members of the executive, bureaucrats or regulators, and not directly by representatives of the people. In contrast, legislations are often preceded by important deliberations, where elected representatives discuss competing policy choices to decide the best course of action, and negotiate middle roads based on the interests of different social groups.

A contact tracing law would regulate (a) the collection, storage, and use of personal data collected by the app; (b) serve as a check on governmental power; (c) enshrine critical privacy protections; (d) create mechanisms for independent oversight of the functioning of the app; and (e) provide a legislative basis for grievance redressal avenues. These elements are particularly important in India given the absence of a general data protection law. For instance, the Protocol states that any violation "may" lead to prosecution under the Disaster Management Act. However, it does not specify the conditions under which prosecution can take place; nor does it actually set up a complaint mechanism to provide an appropriate forum for grievance redressal (leaving aside the vexed question of how the Disaster Management Act will be used to prosecute privacy violations). Even the privacy policy only designates the Deputy Director General at the National Informatics Centre (NIC) as a grievance officer, without providing any further details or powers. Currently, the privacy protections guaranteed to citizens are based exclusively on the privacy policy, the terms of service of the app, and the new "Protocol", which add up to inadequate protections, which can be unilaterally changed by the executive, and lack mechanisms to ensure compliance by the state. This is incompatible with the protection of fundamental rights and the rule of law.

The need for a specific enabling legislative framework for contact tracing has also been reiterated in other countries. In Israel, the Supreme Court recently held that the Israeli Security Agency, the Shin Bet, required a law to continue using emergency powers (granted by the Cabinet) that allowed it to deploy phone location tracking and electronic contact tracing. In reaching its decision, the Court recognised that the State was monitoring individuals, without their consent, without any legislative framework in place.

Similarly, in the UK, the Parliamentary Joint Committee on Human Rights (2020) released a report stating that a contact tracing app should not be rolled out nationally "unless the Government is prepared to enshrine [intended privacy] protections in law", in the form of primary legislation. Legislative backing was deemed essential for the contact tracing app so as to provide the requisite "legal clarity and certainty" regarding the collection, storage, and use of personal data; whilst simultaneously increasing confidence and trust in the app; and an increase in uptake, which could improve the efficacy of the app. Notably, this demand to legislate specifically for contact tracing comes despite the U.K having a comprehensive data protection legislation.

One way forward: An ordinance

Given that the Parliament is not currently in session, the ongoing national lockdown and the urgency of the COVID-19 crisis, the Central Government should have used the ordinance making power under the Constitution, which is precisely provided for such occasions, to set out a legislative framework for the operationalisation of Aarogya Setu app in India. This would have ensured that ordinance either received the scrutiny and approval of the Parliament when it reconvened, or ensured that the ordinance lapsed if it was not approved by the Parliament. Various states like Uttar Pradesh and Kerala have been taking the ordinance route to address legislative lacunae during the COVID-19 crisis.

Addressing the procedural irregularities and governance related issues

Apart from the legal issues highlighted above, the operationalisation process exhibits a number of procedural irregularities and governance related issues. These can be addressed through the following steps:

  1. Need for public consultation: The conceptualisation, design, and implementation of the Aarogya Setu app was not preceded by public consultation. Given the urgent nature of the COVID-19 crisis, it is understandable that the Central Government was not in a position to hold detailed public consultations before designing and rolling out the app. However, the the government should still initiate a formal post facto consultation process to seek comments from civil society, technical experts and other stakeholders regarding, inter alia, the technical and legal framework, and deployment issues with the app. Given low state capacity in India, such consultation processes are particularly valuable in identifying errors and offering solutions.
  2. Enhancing transparency regarding design and deployment choices: So far the Aarogya Setu app has been accompanied only by (a) terms of service (b) privacy policy and (c) the Aarogya Setu Protocol. There is a foundational problem, located in health policy: What is the overall plan for contact tracing, and what is the role that the app will play in this? Can the complex problem, of public administration and state capacity for contact tracing in an epidemic, be short-circuited by using an app? How do we know that there are commensurate benefits, for contact tracing, in return for intruding into the lives of private persons? It is not obvious that the app will help improve public health, and the case needs to be made for it, where an intelligent balance is struck between cost and benefit. There is a `technology theatre' streak in Indian public policy, where solving complex problems is avoided by building and exhibiting a piece of software.

    For instance, it is unclear why the makers of Aarogya Setu chose to collect location data through both GPS and bluetooth when similar apps, built by some of the best technologists in the world, are choosing to use only Bluetooth signals from phones to detect encounters and do not use or store GPS location data. An explanatory memorandum detailing the reasoning behind the various design choices could go a long way in increasing trust in the app and consequently enhancing its uptake.

    A similar trust building measure, that will show the extent to which the actual operations of the app are aligned with the claims made in documents, will be the release of source code. In fact, even with the latest revision to its privacy policy, the source code has not been released. As an example, contact tracing apps being designed by the U.K and Singapore have made their source code public, thereby enabling greater scrutiny from the technical community, and building confidence that the high level documents are being adhered to in the implementation.

    Confidence would be enhanced if small pilots were rolled out prior to large scale deployment, with extensive involvement of researchers in public health, computer engineering, and civil liberty. As an example the NHS contact tracing app being proposed in the U.K is first being trialled in Isle of Wight on a purely voluntary basis. This has helped identify significant glitches with the app.

  3. Setting in place an open and transparent audit mechanism: Confidence will be enhanced by releasing periodic audit reports detailing key insights obtained from analysis of the data collected by the app. For instance, it will be useful for the public and technologists to know details such as the total number of COVID-19 positive cases detected with the help of the app, the number of false positives or false negatives thrown up by the app, the number and nature of user complaints received etc. Publicly available periodic audit reports of this nature will increase confidence in the operation of the app, ensure transparency in its governance, and help evaluate success or failure of the app.

Conclusion

Courts of law are more deferential to the executive in an emergencies. However, it is also widely known that "temporary" leeways granted to the executive during emergencies have a tendency to transform into permanent fixtures that last long beyond the actual duration of the crises (Harari, 2020). This is because governments often use crises as an opportunity to expand and further centralise their powers. Interestingly, while the Aarogya Setu protocol has a sunset date, which is subject to extensions, there is no clarity on how long the app itself will remain operational. The Union Minister for Information and Broadcasting has also indicated that the app may continue to function for one or two years. Dangerous precedents occur in dangerous times.

On May 5, 2020, a writ petition was filed before the Kerala High Court challenging the MHA directive mandating the use of Aarogya Setu by public and private employees on the grounds that it was violative of the right to privacy and personal autonomy. In response, while the Kerala High Court declined to grant any interim relief on the plea, it directed the Central Government to file a statement on the measures taken to protect the privacy of person's whose data is collected by the app. While the new MHA guidelines have since moved away from making the app mandatory, news reports suggest that the access to important services is increasingly being made contigent on the mandatory installation of the app by users.

When faced with a war, a terrorist attack, or a pandemic, there is an instinctive response in India to be deferential to the executive. However, the founders of the Republic did not intend for colonial rule to be replaced by the rule of officials. The Constitution of India does not see liberal democracy as a luxury to be enjoyed in good times. Apart from freedom being valuable in and of itself, there is also a strong pragmatic value in emphasising checks and balances. Under conditions of low state capacity, unchecked power leads to more mistakes. The quality of work in public policy goes up through the operations of checks and balances, and this is even more valuable in difficult times.

References

Paul Daly, The Covid-19 Pandemic and Proportionality: A Framework, Administrative Law Matters (2020).

Sidharth Deb, Privacy prescriptions for technology interventions on Covid-19 in India, IFF Working Paper No. 3/2020 (2020).

Tom Ginsburg and Mila Versteeg, State of Emergencies, Part II, Harvard Law Review Blog (2020).

Oren Gross, Emergency Powers in the Time of Coronavirus ... and Beyond, Just Security (2020).

Yuval Noah Harari, The World After Coronavirus, Financial Times (2020).

Joint Committee on Human Rights, Human Rights and the Government's Response to Covid-19: Digital Contact Tracing United Kingdom Parliament (2020).

SFLC.in, Our concerns with the Aarogya Setu App (2020).

Joelle Grogan, COVID-19 and States of Emergency: Introduction and List of Countries Verfassungsblog (2020).

Lindsay Wiley and Steve Vladeck, COVID-19 Reinforces the Argument for "Regular" Judicial Review-Not Suspension of Civil Liberties-In Times of Crisis, Harvard Law Review Blog (2020).

Emperor v. B.N. Sasmal (B.N. Sasmal), ILR (1930) 58 Cal 1037.

Kusum Kumari Debi v. Hem Nalini Debi (Kusum Kumari Debi), AIR 1933 Cal 724.

Muzaffarpur Electric Supply Co. v. State of Bihar (Muzaffarpur Electric), 1973 Crl. L.J. 143 (Patna).

Justice K.S. Puttaswamy v. Union of India (Puttaswamy), 2017 (10) SCC 1.

Ramanlal Bhogilal Patel v. N.H. Sethna (Ramanlal Patel), 1971 Crl. L.J. 435 (Guj).

Malone v. The United Kingdom (Malone), [1984] ECHR 10.

The International Principles on the Application of Human Rights to Communications Surveillance ("the Necessary & Proportionate Principles") (2013).

 

Vrinda Bhandari is a practicing advocate in Delhi. She is involved in the legal challenge to the app before the Kerala High Court. Faiza Rahman is a researcher in the technology policy team at the National Institute of Public Finance & Policy. We thank Ajay Shah, Renuka Sane, and Smriti Parsheera for useful comments.