Search interesting materials

Showing posts with label technology policy. Show all posts
Showing posts with label technology policy. Show all posts

Sunday, December 14, 2025

Can technology augment order writing capacity at regulators?

by Natasha Aggarwal, Satyavrat Bondre, Amrutha Desikan, Bhavin Patel and Dipyaman Sanyal.

Indian regulators have extensive quasi-judicial powers that they express through adjudicatory orders. It is critical that these powers are exercised in a proportionate, legitimate, and well-reasoned manner, as they not only impact the persons directly involved, but also the wider ecosystem in which they operate. Arbitrary actions, unsubstantiated by clearly articulated reasoning, can raise serious concerns around the legitimacy of regulatory actions and lead to a loss of confidence in the regulator. Such actions may also be set aside by appellate and review fora. Clearly written, well-researched, and reasoned orders help provide clarity, predictability, and knowability of the law, which are key indicators of a rule of law system (Aggarwal, Patel and Singh, 2025). Our study of the state of Indian regulatory order writing shows there is room for improvement in this regard.

We notice a growing interest in the use of Generative Artificial Intelligence (Gen AI) to resolve procedural inefficiencies at quasi-judicial and judicial authorities in India (Supreme Court Committee on AI, 2025; Kerala High Court, 2025), coupled with concerns around the potential dangers of using such technologies without adequate safeguards. Against this background, in a new working paper titled, 'Can technology augment order writing capacity at regulators?' we critically examine the opportunities and challenges of using technology, in particular Large Language Models (LLMs), to assist regulatory order writing in quasi-judicial settings.

The paper proposes augmenting rather than replacing human decision-makers, aiming to improve regulatory order writing practice through responsible use of LLMs. It identifies the core principles of administrative law that must be upheld in these settings - such as application of mind, reasoned orders, non-arbitrariness, rules against bias, and transparency - and analyses how inherent limitations of LLMs, including their probabilistic reasoning, opacity, potential for bias, confabulation, and lack of metacognition, may undermine these principles.

While the available Indian literature on the topic focuses largely on these limitations, and on critiquing proposals based on an over-reliance on technocratic means to improve state capacity, this paper's contribution lies in its integrative work: we draw upon the design principles articulated in frameworks developed in other jurisdictions and relate them to the applicable principles of Indian administrative law. We use this synthesis to develop a Problem-Solution-Evaluation (PSE) framework that is attentive to international practice, the legal principles underpinning quasi-judicial decision-making in India, and problems and limitations inherent to GenAI and LLMs.

The PSE framework proposed in the paper maps specific technical, design, and systemic solutions to each identified risk, and outlines evaluation strategies - end-to-end, component-wise, human-in-the-loop, and automated - to ensure ongoing alignment with legal standards. An overview of the framework is set out in the table below:

Table 1: Applying the Problem-Solution-Evaluation framework. This table illustrates how the PSE framework can be operationalised to align the design, development and use of LLMs for order writing assistance with the requirements of Applicable Law.
Problem Applicable law Solution Evaluation
Non-application of mind Non-application of mind; Failure to provide reasons; Arbitrariness Interface Checkpoints; Confidence Score Display; Dual-Prompt Pipelines; Functionality Limitation; Constraint Enforcement; Workflow Design for; Review Role-Based Access Edit Rate; Turnaround Time (TAT); Prompt Divergence Rate; Coherence Score
Black-box problem Failure to provide reasons; Transparency Chain-of-thought prompting; Input Token Influence Identification Symbolic Reasoning Systems Traceability tools; Visualisation; Simplified model explanations Clarity rating; Audit Trail Incidence Document Traceability Rate
Potential for bias Rules against bias; Arbitrariness Data Preprocessing; Bias penalisation; Domain-specific content filters; Automated Bias Flagging Tools; Establishment of Legal Fairness Criteria; Mandatory Periodic Benchmarking Bias Flag Rate Override Percentage; Fairness Benchmark Scores
Confabulation problem Non-application of mind; Failure to provide reasons; Arbitrariness Retrieval Augmented Generation; Post-Generation Verification; Legal Knowledge Graph Integration; Mandatory reviewer verification; Watermarking for traceability; Communicate technical limitations Secondary LLM ''Judge'' for Fact-Checking; End-to-End Evaluation Tools Hallucination Rate; Retrieval Precision@k/ MRR NLI Coherence Checks; Self-Consistency Rate
Lack of metacognition Non-application of mind; Arbitrariness Prompt engineering; LLM as a judge; Iterative improvement from feedback Closeness Metric; Human evaluation on overconfidence in output
Training corpus NA Adaptive Scraping Frameworks; Sector-specific pre-training; Structured Entity; Extraction and Legal Knowledge Graphs; Isolated Model Containers; Source inclusion; Perplexity tracking; Legal Retrieval Benchmarking; Curate sector-specific legal databases Crawl coverage; OCR Error Reduction; Validation perplexity; Retrieval lift
Data security and privacy NA Stringent access control; Synthetic supervision-based PII detectors; NLP filters for information masking; Isolated Model Containers; On-premise infrastructure Unauthorised access attempts; Mean Time To Remediation (MTTR); Penetration Test Pass Rate; PII Detection Accuracy

By itself the framework may be insufficient. It must be supplemented with systemic measures taken at the regulatory level. We offer stage-wise recommendations on how LLM-based order review tools can be built for and used in regulatory adjudication.

References

Natasha Aggarwal, Bhavin Patel, and Karan Singh, "A Guide to Writing Good Regulatory Orders" [2025] Trustbridge Rule of Law Foundation Working Papers.

Anurag Bhaskar and others, "White Paper on Artificial Intelligence and Judiciary" Centre for Research and Planning, Supreme Court of India, 2025.

High Court of Kerala, "Policy Regarding the Use of Artificial Intelligence (AI) Tools in District Judiciary" Official Memorandum HCKL/7490/2025-DI-3-HC Kerala, 2025.


Natasha Aggarwal, Amrutha Desikan and Bhavin Patel are researchers at the TrustBridge Rule of Law Foundation. Satyavrat Bondre and Dipyaman Sanyal work on AI and technology at dōnō consulting.

Monday, September 01, 2025

Powering AI with Reliable Grids and Networks

by Renuka Sane.

There is much action and anticipation related to the AI decade, and especially about the potential of building large data centres, in India. As of April 2025, at least five hyperscale data centres were in the works. It is expected that India's data centre capacity will surpass 4,500 MW by 2030, backed by $25 billion in investments. Recently, OpenAI has indicated its interest in setting up a data center in India. Before we celebrate these investments, we should ask if the economics of locating them in India adds up? Even leaving aside issues such as land and taxes, do power prices, network quality, and the reliability of both electricity and the internet make us globally competitive? Some investment will come anyway because of data-localisation rules. But that is compulsion, not strategy. Real scale will only occur when a rational firm would choose India even without a localisation mandate, because the numbers and the policy risk both make sense. The AI story has two prerequisites: abundant, reliable electricity and reliable connectivity.

Reliable electricity

Let's start with electricity consumption. A small data center requires about 1-5 MW of power, while a "hyperscale" data centre draws about 100 MW of power at full load. Assuming a power usage effectiveness (PUE) of a data center of 1.2, one hyperscale data center will require 100 MW * 1.2 * 8,760 h = 1.0512 TWh. over a year.

Where is this power going to be sourced from, and how much will it cost? There are three supply options: (1) grid supply,(2) round-the-clock renewable energy plus storage (RTC-RE+storage) contracted from a developer under green open access or (3) a captive plant powering the data centre.

  1. Grid supply: If we assume an industrial tariff of Rs. 7.5 per kWh (which is close to the tariffs in Maharashtra and Tamil Nadu,the two states at the forefront of the data center business), the electricity bill for uninterrupted grid power is roughly Rs. 7.9 billion (US$ 90 million) per year. Except that power supply is not guaranteed, and significant power outages imply that data centres have to build alternatives to ride through grid outages. At Rs. 25-30/kWh, diesel generators routinely cost an order of magnitude more to almost US 236-300 million.

  2. Round-the-clock renewables with storage (RTC-RE + storage) via green open access: Here we have to consider three cost items. The first is the cost of the RTC power purchase agreement (PPA), which will be higher than plain solar/wind because it includes storage and portfolio diversity. The second are the network charges and losses that include intra-state transmission, wheeling (distribution) charges, and transmission + wheeling losses before it reaches the meter. If this is inter-state then one has to start considering the prevailing ISTS regime. The third is the cross-subsidy surcharge (CSS) and additional surcharge (AS) to the DISCOM. In Maharashtra, for example, these are quite high, potentially making the final price above the grid, even if the landed cost of the RTC PPA is significantly lower than the grid price. An approx overall price of Rs.9/kWh hour, gives us a total cost of around US$110 million.

  3. Group-captive RTC: In this case, CSS and AS charges wouldn't apply and the price may come close to (or be lower than) the grid price. The data centre, however, would need to hold the required equity and off-take, and would have its own governance challenges. It is these that can become the binding constraints, not just price. A group-captive cost of Rs.7/kWh leads to a cost of US$83 million.

How do these numbers compare to say the US or Germany? The table below gives some indicative answers.

Country Unit cost (US$) Annual costs (US$)
India (grid average) 0.085 89.4 m
India (RTC, group captive) 0.076-0.080 80-85m
India, (RTC, third-party) 0.104-0.112 109-118 m
Germany, (grid average) 0.196 205.5 m
United Kingdom (grid average) 0.249 261.6 m
US, (grid average) 0.0886 93.1 m
US (Texas) 0.063 66.6m

As the table shows, despite the difficulties in India, it remains competitive vis-a-vis countries such as Germany and the UK as far as electricity prices are considered. However, India is not competitive vis-a-vis the US, where prices in places such as Texas and Virginia (US$0.091) are lower than the third-party open access option in India. The economics of electricity will further change based on the amount of cooling required, which will be relatively higher in India, requiring more energy than in countries with ambient temperatures much lower than India.

Reliable connectivity

There is much more awareness regarding the impediments of the electricity sector for our AI ambition. The issue of reliability of connectivity is less talked about - reliability that gets compromised because of our world-leading record of internet shutdowns. India sees routine network blackouts for reasons related to mobile data bans during exams, to internet suspensions in conflict for months on end. In 2024 India accounted for 28% of all government ordered shutdowns globally - the highest by any country. There have already been 28 shutdowns in 2025. One study estimates the economic cost of shutdowns to the Indian economy at $968 million.

One could argue that data centres used leased lines, and a mobile only shutdown would not matter much. Except that mobile only bans knock out end-user access potentially affecting any product whose customers are on these networks. Shutdowns can affect logistics, field engineering, and remote operations. A shutdown freezes the demand for AI inference in that region. Such vanishing demand equals loss of demand of electricity, leading to idle capacity, another indirect cost for an entrepreneur to handle. One could also argue that shutdowns primarily occur in conflict zones, or districts that are on the periphery of economic activity, and therefore not likely to materially affect the AI story. While that may be true at the moment, routine ad-hoc shutdowns undermine trust in India as a location for latency-critical workloads and cross-border data partnerships. They can lead to a sovereign reliability discount, raising the hurdle rate for capital. Even without shutdowns, India routinely has to deal with connectivity problems owing to frequent power cuts causing internet outages.

Way forward

There are two ways to look at the issue of data centres. The first is whether India can become the regional hub and service clients across Asia and the Middle East. On this question, the answer is clear. Firms will make rational decisions - unless it makes economics sense, firms will prefer to rent equipment or make API calls to the cheapest data centres elsewhere in the world. The second is what it costs firms in India to be forced to place data centres here owing to data localisation mandates. If the cost of training and inference is lower in the US (or other overseas markets) than in India, then firms in India will be at a considerable disadvantage if forced to use local facilities.

Blackouts and shutdowns are not compatible with the way in which AI services evolve and deploy. Foundation models, hyperscale data centres, and exportable AI services demand 24x7 supply and connectivity. India needs to get its grid electricity to world-class levels. It needs to reform its charge structure that makes firm green more expensive than grid making exit difficult. While nuclear energy remains an option, there is no clarity yet on the resolution of supplier-liability laws, making its future still uncertain. Additionally, India needs a radical overhaul of its policy on shutdowns. They should be the absolute last instrument; a rule-of-law state first exhausts narrower tools such as content take-downs, site-specific throttling, geofenced blocks, and targeted law enforcement, and only then even contemplates turning off the network. Our AI strategy should focus on building on two pillars: dependable power and dependable networks.


The author is a researcher at the TrustBridge Rule of Law Foundation. I thank Ajay Shah and Anand Venkatanarayanan for useful comments.

Monday, December 23, 2024

Digital transformation and the paradox of financial inclusion in India

by Suyash Rai.

India has made great strides in digital technology, becoming a leading exporter of digitally delivered services to the global economy. These capabilities with computer technology fuelled hopes that digital transformation could yield gains for the Indian state that are comparable to those seen in the private sector. The `Digital Public Infrastructure (DPI)' approach, with India's Aadhaar digital ID system as a prime example, is presented as a path to higher GDP growth for developing countries. There is an emerging debate on the role of the state in shaping the development and deployment of DPIs.

Two key pillars of the Indian story with DPIs are identity services ("Aadhaar") and their impact on financial inclusion. In a new working paper, Economic development and digital transformation: Learning from the experience of Aadhaar and financial inclusion in India, I critically examine the Indian progress on financial inclusion between 2011 and 2021, revealing a paradox: while account ownership surged, account usage remained low.

The facts

The paper analyses India's performance compared to other lower middle-income and middle-income countries. The evidence shows:

  • Impressive account opening: India witnessed remarkable progress in account penetration, surpassing the average improvement in middle-income countries.
  • High inactivity: A significant percentage of accounts in India were inactive, far exceeding the average for middle-income countries.
  • Low account usage: India lagged behind in account usage for both consumption smoothing (regular deposits and withdrawals) and digital payments, indicating a gap between account ownership and actual financial inclusion.

The role of government mandates and Aadhaar

We argue that the rapid scale of account opening was caused by a series of government and Reserve Bank of India (RBI)mandates, particularly the Pradhan Mantri Jan Dhan Yojana (PMJDY). While Aadhaar played a role, it was primarily used as a physical ID for KYC, rather than as a digital ID through e-KYC. The gains in account opening may have a lot to do with state coercion and less to do with DPI.

The primary objective driving these initiatives was to facilitate direct benefit transfers (DBT) for welfare schemes. The government's focus on DBT aimed to reduce leakages and improve attribution for its welfare programs in the eyes of voters.

Why did this approach yield disappointing results?

The paper explores several reasons for the limited account usage despite the increase in account ownership:

  • The lack of a viable business model: No-frills accounts, with zero minimum balance and free transactions, are commercially unattractive for banks.
  • Mismatch between the solution and the problem: The focus on account opening for DBT didn't necessarily translate into accounts that address the richness and complexity of finance for the poor, of meeting the diverse needs of users for consumption smoothing and payments.

Lessons

The top-down approach, with a readiness to utilise the coercive power of the state, has limitations. While the government achieved its objective of scaling up DBT, this came at the cost of genuine financial inclusion and limited the potential uses of Aadhaar as a DPI.

We highlight the need for a more balanced approach, considering market forces and user needs, so as to obtain better outcomes with DPIs. We stress the importance of political creativity, institutional reforms, and a broader understanding of public value, beyond narrow fiscal objectives, when designing and implementing DPIs.

We offers insights into the complexities of digital transformation and financial inclusion, challenging the simplistic narrative of Aadhaar's success. These experiences invite us to rethink the role of the state in shaping DPIs and consider alternative approaches that can truly leverage technology for inclusive and sustainable development.


Suyash Rai is a Fellow at Carnegie India and a Visiting Research Fellow at the xKDR Forum

.

Wednesday, January 10, 2024

Evaluating capital market responses to cybersecurity incidents in Indian listed companies

by Sayan Dasgupta, Renuka Sane and Karthik Suresh.

In a previous report on the Information Technology Act, 2000 we described the infirmities in the laws and institutions that govern cybersecurity threat detection and response in India. However, two questions persist. Firstly, what is the true scale of the cybersecurity problem among Indian firms? Secondly, what are the financial and reputational consequences of a cybersecurity breach at an Indian firm?

It is difficult to find answers to the first question in the public domain. But when it comes to the second question, we can gain some insights by looking at how investors respond to the news of cybersecurity incidents whenever such details are made public. In the United States, the results of these studies range from a slightly negative effect on stock prices following the announcement of an incident (e.g. Cavusoglu et al, 2004 estimated an average 2.1% loss in the first two days after disclosure) to no significant effects (e.g. Kannan et al, 2007). Amir et al (2018) however observed that there is a significant difference between the fall in stock prices for firms that disclosed the cybersecurity incident (0.7% decline in one month) vs. firms that withheld this information (3.6% decline in one month).

It is important and interesting to understand the current state of play. How many Indian listed companies made public disclosures of cybersecurity incidents? How did investors in these companies respond to this news given the limited information they had? We attempt to provide some insights into this question by conducting an event study of stock price movements that follow cybersecurity incidents in Indian listed companies. We found that there was a significant negative effect on stock prices given the prior system of disclosures.

Why is it important to make disclosures of cybersecurity incidents?

A cybersecurity incident can be a costly negative externality. In 2022, IBM surveyed 49 Indian companies and estimated the loss they suffered from a single data breach to be USD 2.32 million (INR 184.5 million). A firm suffers direct costs (e.g. costs of data recovery) as well as indirect costs (e.g. loss of trust and goodwill) due to a cybersecurity incident. These costs, along with the reluctance to divulge details about its vulnerabilities to competitors, mean that firms are not incentivized to share information on their cybersecurity incidents.

There are two reasons why firms should make disclosures about cybersecurity incidents. Firstly, consumers have a reasonable expectation of privacy. In India, the Supreme Court in the Puttaswamy decision traced this expectation of privacy to one's right to life and personal liberty. On these grounds, data privacy legislations, such as Article 34 of the EU General Data Protection Regulation and Section 8 of the Digital Personal Data Protection Act, 2023 require firms to disclose details of data breaches to their users. Secondly, securities laws are concerned with whether cybersecurity risks are "material information" that should be disclosed to investors. The concept originated in the United States --- the US Supreme Court in TSC Industries v. Northway held that a given piece of information is "material" if there is "a substantial likelihood that a reasonable shareholder would consider it important in deciding how to vote".

Specifically on materiality, the US Securities and Exchanges Commission (SEC) issued non-binding guidance in 2011 and 2018 which provided the format in which a listed entity or market participant should report on cybersecurity risks. However, in March 2023, the SEC proposed a framework for compulsory disclosures of cybersecurity risk and preparedness. In India, SEBI's general disclosure requirements on materiality are found in Regulation 30 read with Schedule III of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 ("LODR Regulations"). Sub-part B, no. 6 requires the listed entity to report "disruption of operations of any one or more units or division ... due to natural calamity (earthquake, flood, fire etc.), force majeure or events such as strikes, lockouts etc." While it was not explicitly mentioned that cybersecurity risks are to be reported, many listed companies (example) made such disclosures anyway. In June 2023, specific reporting requirements for cybersecurity incidents were added to the LODR regulations which we describe in the discussion section.

Data

Our list of cybersecurity incidents comes from two datasets that provide firm-specific incident information. The first dataset --- the "CISSM Cyber Attacks Database" --- is based on the work of Harry and Gallagher (2018). It is hosted by the University of Maryland (UoM). It has a set of 285 incidents that took place in India between 2014 and 2023. Of these, 45 incidents took place in companies listed in India. This dataset includes detailed information on the type of data that was compromised, the method of attack, and the responses of the affected companies. This data was collected by deploying a customised script that queries a list of news websites for articles or news items on cybersecurity incidents which are collected, sorted and stored. Another script then categorizes these incidents into various types.

The other dataset, called the Data Breach Investigations Report (DBIR), is hosted by Verizon. It has information on the type of breach (e.g., malware, hacking, social engineering), the target of the breach (e.g., government, enterprise, small business), the method of attack (e.g., phishing, spear phishing, watering hole attack) and the impact of the breach (e.g., data loss, financial loss, reputational damage). The DBIR dataset accepts information from a broad set of user-reported sources which are manually sorted by varying levels of confidence. The dataset has 83 incidents that took place in India between 2009 and 2017, of which 11 incidents took place in Indian-listed companies. 8 of the 11 incidents are already mentioned in the UoM database, so we are left with 3 unique entries in the DBIR. We manually categorized these three incidents based on the typology provided by Harry and Gallagher (2018).

The distribution of the different types of cybersecurity incidents is as follows:

Type Description No. of incidents
Data attack This type of attack covers the manipulation, destruction, or encryption of data in the target network. 7
Exploitation of application server This type of attack uses a misconfiguration or vulnerability to gain access to data in a server-side application (e.g. a database) or the server itself. 27
Exploitation of network infrastructure This type of attack covers the theft of data through direct access to network infrastructure such as routers, switches and modems. 1
Denial of service This type of attack is meant to degrade or deny access to other parts of the firm's network. 3
Message manipulation This type of attack covers interferences with the target's ability to accurately communicate information to its customers. 3
Combination of methods 5
Undetermined 2
Total 48

In total, our dataset has 40 unique companies and 48 incidents that took place between June 2013 and March 2023.

For stock prices, we retrieved the NSE daily closing prices for all the affected companies from CMIE Prowess for the period between 1 March 2013 to 31 July 2023.

Methodology

The event study methodology (ESM) is commonly used to measure stock price reactions to certain events (Fama et al, 969). We use the ESM to analyze the stock price consequences of cybersecurity incidents. Price reactions are represented by abnormal returns, which are stock returns adjusted for the normal daily stock price and market. We use the eventstudies package developed by Anand et al (2014) for our analysis.

This methodology involves the following steps:

  1. Identifying the event date: The event dates are the dates on which each of the cybersecurity incidents were made public i.e. the date of the news article.
  2. Calculating the abnormal returns: The abnormal returns for the affected companies are calculated on the event date and 45 days before and after the event. Abnormal returns are the difference between the actual returns of the affected companies and the expected returns of the market. The expected returns are calculated using the market model.
  3. Statistical tests: They help us determine whether the abnormal returns are statistically significant. The abnormal returns are used to test whether the cybersecurity incidents had a significant impact on the stock prices of the affected companies. The statistical tests are conducted using a variety of methods such as the t-test and the Wilcoxon signed-rank test.
  4. Analyzing the results: The results of the event study are analyzed to determine (i) the magnitude of the impact of cybersecurity incidents on stock prices, (ii) the factors that influence the impact of cybersecurity incidents on stock prices, and (iii) the implications of the results for investors, companies, and regulators.

Results

Event study results covering all incidents

Fig 1: Event study results for all 48 incidents.

We observe a significant decrease in the cumulative abnormal return (CAR) after the event date. The average decrease in the first month after the event was 3.48%. At its lowest, the CAR was -8.06%. However, with a widening 95% confidence interval, there is some uncertainty about the true effect of the cybersecurity incident on the stock prices of the companies. The sample size is low and the information available regarding the nature and magnitude of the incident is limited.

Event study covering incidents of the type "exploitation of application server"

Fig 2: Event study results for 27 incidents which were of the type "exploitation of application server".

The majority of the cybersecurity incidents were of the type "exploitation of application server". We conducted another event study on this set of incidents. However, we do not see significant results. In the first month after the event, the CAR increased by an average of 9.79%.

Limitations

Our list of 48 incidents is certainly not exhaustive. Many cybersecurity incidents may not have been reported. Given that the majority of our data comes from news sources, some disclosures may have been made long past the incident date.

Discussion

We began by asking about the financial and reputational consequences of a cybersecurity breach in a listed Indian firm. The trends in our analysis show that investors do tend to react negatively to the news of a cybersecurity incident.

As time progresses, we may be able to find more conclusive answers to both questions. This is thanks to some recent changes in the disclosure regime which will give us the true picture of cybersecurity incidents at Indian listed companies. In November 2022, SEBI in its consultation paper proposed amendments to these regulations. The consultation paper notes that cybersecurity incidents "may impact the operations and/or performance of the listed entity" but also recognizes that the "immediate disclosure of such events may not be desired since the entity may be vulnerable to further attacks". SEBI therefore proposed that the disclosures be made on a quarterly basis in the corporate governance report where the listed entity mentions the root cause of the incident as well as the remedial measures that they undertook. In June 2023, these proposals were adopted by amending Regulation 27(2) of the LODR regulations. Given the recent amendments to the SEBI LODR regulations, the quality of information on cybersecurity incidents could become richer. This could inform further studies which could deploy more sophisticated methodologies that control for other factors that could affect stock prices and remove the variation caused by them before performing the event study.

References

Chirag Anand, Vimal Balasubramaniam, Vikram Bahure and Ajay Shah, eventstudies: an R package for conducting event studies and a platform for methodological research on event studies, NIPFP Macro/Finance group, 2014.

Hassan Cavusoglu, B. K. Mishra, and S. Raghunathan, The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers, International Journal of Electronic Commerce, Vol. 9 (2004), no. 104, pp. 70--104.

Karthik Kannan, Jackie Rees and Sanjay Sridhar, Market Reactions to Information Security Breach Announcements: An Empirical Analysis, International Journal of Electronic Commerce, Vol. 12 (2007), no. 1, pp. 69--91.

Eli Amir, Shai Levi and Tsafrir Livne, Do Firms Underreport Information on Cyber-Attacks? Evidence from Capital Markets, Review of Accounting Studies, Vol. 23 (2018), issue 3, no. 11, pp. 1177-1206.

Charles Harry and Nancy Gallagher, Classifying cyber events: a proposed taxonomy, Journal of Information Warfare, Vol. 17 (Summer 2018), no. 3, pp. 17-31.

Eugene F. Fama, Lawrence Fisher, Michael C. Jensen and Richard Roll, The Adjustment of Stock Prices to New Information, International Economic Review, Vol. 10, no. 1, pp. 1--21.


Sayan Dasgupta and Karthik Suresh are researchers at XKDR Forum. Renuka Sane is a researcher at TrustBridge. We thank Ajay Shah, Geetika Palta and Siddhant Bharti for their useful comments.

Tuesday, April 04, 2023

Revising the Information Technology Act, 2000

by Rishab Bailey, Vrinda Bhandari, Renuka Sane and Karthik Suresh.

The Information Technology Act, 2000 ('IT Act') is a comprehensive law enacted to build trust in the digital ecosystem by regulating e-commerce, e-filing of documents, and by creating criminal offences applicable to the digital ecosystem. Despite amendments in 2009, it is widely considered that the IT Act is outdated, not least due to the proliferation of the Internet and a range of new technologies (e.g. Bahl, Rahman and Bailey 2020; Nappinai 2017; Nigam et al 2020). Recently, the government has proposed replacing the IT Act with a new legislation known as the 'Digital India Act'.

In a new report, Revisiting the Information Technology Act, 2000, we attempt to contribute to the process of revision of the IT Act, by examining four critical issues pertaining to the online ecosystem. These are:

  1. Censorship: The provisions in the IT Act pertaining to censorship and blocking were framed in an era when the digital ecosystem was not as pervasive as today and before the use of social media platforms exploded. The provisions in the IT Act that empower the government to block content from public access are largely based on Article 19(2) of the Constitution. However, the institutional framework for carrying out blocking suffers from significant lacunae, including a lack of accountability of the relevant oversight institutions. We recommend that appropriate procedural safeguards be introduced through statute, to ensure greater transparency and neutrality in the blocking processes.
  2. Intermediary liability: The IT Act protects intermediaries from prosecution for content posted or transmitted by third parties upon the following three conditions: (a) that they act as passive agents (or distributors) of content, (b) they disable access to unlawful content upon receiving 'actual knowledge' thereof, and (c) they observe 'due diligence' conditions laid down by the government. The 'safe harbour'' provision was introduced at a time when the digital ecosystem was still nascent. The variety of online harms that have since proliferated raise questions about whether such a system is required. We find that there is value in retaining a safe harbour for intermediaries in contexts where they have played a passive role in the ecosystem. Removing safe harbour is likely to incentivise greater private censorship, a role that intermediaries are not well positioned to undertake. However, this does not mean that intermediaries should not be responsible for ensuring the safety of the digital ecosystem. Any further obligations (such as greater transparency, the introduction of grievance redress mechanisms, etc.) ought to be implemented outside the safe harbour framework and certainly not as part of amorphous 'due diligence' obligations. We point to how new intermediary rules introduced in 2021 and 2022 have imposed a variety of new and onerous obligations on intermediaries. Many of these obligations, such as the obligation to enable traceability of the originator of information on messaging platforms and the obligation or the need to practically police a host of proscribed content, should be done away with. Any new obligations must be introduced based on evidence of harm in a proportionate manner.
  3. Surveillance: The current framework pertaining to interception and monitoring of digital communications was established before the seminal decision of the Supreme Court in Justice K Puttaswamy vs. Union of India which recognized privacy as a fundamental right. Our report builds on the literature on surveillance reform in India to suggest that significant revision is required in our legal framework. Currently, the executive is provided extremely broad powers with insufficient safeguards to mitigate abuse. Certain surveillance programs such as the Centralised Monitoring System are per se disproportionate as they conduct mass surveillance. Our primary recommendation is therefore to enact a new stand-alone surveillance-related legislation, which could harmonise surveillance processes while ensuring that appropriate procedural and institutional safeguards are implemented. In the alternative, the revised IT Act should narrow the scope of powers given to the executive, while also implementing workable oversight and accountability mechanisms, not least ensuring judicial review, legislative oversight, and greater accountability of relevant bodies involved in the surveillance apparatus.
  4. Cybersecurity: While the IT Act lays down various offences pertaining to cybersecurity that are broadly in accordance with international standards, we find that there is a significant need for reform of the institutional mechanisms that manage incident reporting and response. We recommend that the revised IT Act clarify the role and powers of CERT-in and NCIIPC --- the two primar cybersecurity-related agencies in India. In particular, their rule-making powers should be clarified/limited. The law should also avoid duplicating functions of each agency while limiting incident reporting requirements to large and systemically important systems and entities --- this avoids imposing disproportionate costs.

As we move towards an economy that is ever more dependent on the digital ecosystem, it is vital that the law promotes trust in the online ecosystem. This involves finding an appropriate balance between a range of competing interests --- national security and public order, the need to protect fundamental rights, and the need to promote innovation in and development of the digital ecosystem. Finding such a balance will require the government to take a considered stance on several thorny issues. Carrying out detailed and inclusive consultations will also be a vital part of the process towards establishing the digital ecosystem on a sound legal footing.

References

Varun Sen Bahl, Faiza Rahman and Rishab Bailey, Internet intermediaries and online harms: Regulatory Responses in India, Data Governance Network Working Paper no. 6, March 2020.

N S Napinnai, Cyber security and challenges: Why India needs to change IT Act, February 2017.

Aniruddh Nigam, Kadambari Agarwal, Trishi Jindal, Jaai Vipra, Primer for an Information Technology Framework Law, Vidhi Center for Legal Policy, September 2020.

Rishab Bailey, Vrinda Bhandari, Renuka Sane, Karthik Suresh, Revisiting the Information Technology Act, 2000, XKDR Forum, March 2023.


Rishab Bailey and Karthik Suresh are researchers at XKDR Forum. Vrinda Bhandari is a practising advocate. Renuka Sane is a researcher at TrustBridge.

Monday, May 10, 2021

Backdoors to Encryption: Analysing an Intermediary's Duty to Provide 'Technical Assistance'

by Rishab Bailey, Vrinda Bhandari, and Faiza Rahman.

The rising use of encryption is often said to be problematic for law enforcement agencies (LEAs) in that it directly impacts their ability to collect data required to prosecute online offences. While certainly not a novel issue, the matter has risen to global prominence over the last four or five years, possibly due to the increased usage of privacy enhancing technologies across the digital ecosystem.

While there have been a number of policy proposals that seek to address this perceived impasse, no globally accepted best practice or standard has been evolved thus far. In India (as in many other jurisdictions), the government has increasingly sought to regulate the use of encryption. For instance, the recently announced Intermediary Guidelines under the Information Technology Act, 2000, seek to extend the "technical assistance" mandate of certain intermediaries to ensure traceability, by enabling identification of the first originator of the information on a computer resource. The scope of the term "technical assistance" has not been clearly defined. However, the provision appears to go well beyond existing mandates in the law that require holders of encryption keys to provide decryption assistance, when called upon to do so, in accordance with due process, and based on their capability of decrypting the encrypted information. Courts have also weighed in on this debate, with the Madras High Court and the Supreme Court hearing petitions that seek to create mechanisms whereby LEAs could gain access to content protected by end-to-end encryption (E2E), thereby enabling access to user conversations on popular platforms such as WhatsApp. A Rajya Sabha Ad-hoc Committee Report released in 2020 has also recommended that LEAs be permitted to break or weaken E2E to trace distributors of illegal child sexual abuse content.

Against this background, our recently released paper examines the scope of the obligations that ought to be imposed on intermediaries to provide "technical assistance" to LEAs, and whether that should extend to weakening standards of encryption, for instance, through the creation of backdoors. Broadly speaking the term "backdoors" refers to covert methods of circumventing encryption systems, without the consent of the owner or the user. The paper also evaluates, in brief, proposals for alternatives, such as the use of escrow mechanisms and ghost protocols.

We argue that the government should not impose a general mandate for intermediaries to either weaken encryption standards or create backdoors in their products/platforms. This can significantly affect the privacy of individuals and would constitute a disproportionate infringement into the right to privacy. Such a mandate will also likely fail a cost-benefit analysis, not least in view of the possible effects on network security as well as broader considerations such as growth of the Indian market in securities products, geopolitical considerations, etc. This however, does not mean that the law enforcement agencies have no options when faced with the prospect of having to access encrypted digital data. A first step in this regard would be to implement rights-respecting processes to enable law enforcement to access data collected by intermediaries in a timely manner. In addition, there should be greater focus on enhancing government and law enforcement capacities, including by developing hacking capabilities, with sufficient oversight and due process checks and greater funding to research and development efforts in the cybersecurity and crypto spaces.

This post seeks to throw light on the key issues around the encryption debate, and summarises our main arguments and suggestions on how India should address them.

Understanding the encryption debate

Encryption is the process of using a mathematical algorithm to render plain, understandable text into unreadable letters and numbers (Gill, 2018). Typically, an encryption key is used to carry out this conversion. Reconverting the encrypted text back to plain-text also requires an encryption key. Depending on the manner of encryption, the same encryption key can be used to encrypt or decrypt information, or alternatively, one may require different encryption and decryption keys. Encryption therefore ensures that the message can only be read by the person who has the appropriate decryption key, particularly as newer forms of encryption make it inefficient, if not impossible, to reverse the encryption process (Gill, 2018).

Encryption essentially improves the security of information. It secures information against unwarranted access and ensures the confidentiality and integrity of data, thereby fostering trust in the digital ecosystem and protecting the private information of citizens and businesses alike.

However, the use of encryption can also enable criminals to "go dark", making it difficult for LEAs to carry out their functions. For instance, it is estimated that upwards of 22 percent of global communication traffic uses end-to-end encryption (Lewis et al, 2017). This puts a quarter of communications virtually out of reach for LEAs, not least as the use of modern encryption systems makes it harder for LEAs to use the traditional "brute force" method to access encrypted data (Haunts, 2019). LEAs therefore have increasingly called for limitations to be placed on the use of encryption so as to enable them to have access to information they require to pursue their law enforcement functions. They point to the need to ensure accountability for online harms, and therefore argue that intermediaries must provide them with all data relevant to an investigation.

The concerns with the use of encryption are driven by a number of factors such as the growing instances of cybercrime, the use of data minimisation practices such as disappearing messages and the use of encryption by default in various technology products. For instance, WhatsApp and Signal automatically encrypt communications in transit and also give users the option of automatically deleting their messages. Similarly, Apple uses encryption based authentication on its iPhones (which render the content accessible only if an appropriate passcode is provided. If not, the content on the phone could even be deleted after a certain number of failed attempts) (Lewis et. al, 2017).

These concerns have led to calls for Internet intermediaries to weaken encryption standards or create backdoors in their products/services. These demands are not new. Notably, the 1990s saw the issue being debated in the United States, with the FBI proposing the use of the "Clipper Chip", a mechanism whereby decryption keys would be copied from the devices of users and sent to a trusted third party, where they could be accessed on appropriate authorisation by LEAs. More recently, the FBI has been involved in face-offs with technology companies such as Apple, when it refused to provide exceptional access to an iPhone linked to a terrorist. In India too, the government has encountered similar issues - notably forcing Blackberry manufacturers to relocate their servers to India and hand over plain text of communications. The government also circulated a draft National Encryption Policy in 2015, which sought to implement obligations involving registration of encryption software vendors, and the need for intermediaries to store plain text of user data. The draft was however withdrawn after much criticism.

In response to such proposals, security researchers, cryptographers and service providers, have been near unanimous in pointing out that the creation of backdoors is likely to lead to significant costs to the entire digital ecosystem, especially as it leads to the entire population being exposed to vulnerabilities and security threats. Indeed, the need for stronger encryption and other security standards to protect user data is only heightened by the numerous and frequent data breaches that have been reported in India. Interestingly, even the Telecom Regulatory Authority of India has adopted a similar position in its Recommendations on Regulatory Framework for OTT Communication Services of 2020.

Even two commonly discussed methods of a "balanced solution" to the problem - the use of escrow mechanisms and ghosting protocols - have faced significant criticism. For instance, the use of escrow mechanisms (which, as with the Clipper Chip system described above, involve storage of the decryption key with a trusted third-party, who can then provide the same to LEAs when called upon to do so) is likely to lead to significant vulnerabilities being created in computer systems. Not only will such a system require faith in the integrity of the entity holding the decryption key, such an entity would constitute a single point of failure, which is poor system design (Kaye, 2015). Deployment of complex key recovery infrastructure is also likely to impose huge costs on the ecosystem (Abelson et al., 1997). Similarly, suggestions for using ghost protocols (which would require service providers to secretly add an extra LEA participant to private communications) have also faced significant criticism (Levy and Robinson, 2018). Given that this system would essentially require service providers to convert a private conversation between two individuals into a group chat, with a hidden third participant, critics have argued that it is just another form of a backdoor. It would erode trust between consumers and service providers, and provide for a "dormant wiretap in every user's pocket" that can be activated at will. This would also require fundamental changes in system architecture, thereby introducing vulnerabilities that can create threats for all users on platforms (Access Now et al., 2019).

Thus, while the use of such methods can enable LEAs to access user data more quickly than is currently possible, there are numerous concerns - from a civil liberties, economic and technical perspective. We outline the key concerns in this regard below.

Concerns with mandating backdoors

  • Privacy: In view of the recognition of privacy as a fundamental right, private thoughts and communications are protected from government intrusion subject to satisfaction of tests of necessity and proportionality. Mass surveillance can be considered to be per se disproportionate. It is recognised that government surveillance can lead to unwanted behavioural changes, and create a chilling effect. Encryption therefore serves as a method to protect individual privacy, particularly from government excesses.
  • Security: Creating backdoors can weaken network security as a whole since it can be exploited by governments and hackers alike (Abelson et al., 2015). Backdoors can also lead to increased complexity in systems, which can make them more vulnerable to attack (Abelson et al., 2015).
  • Right against self-incrimination: Mandating decryption of data can arguably also be seen as violating an individual's right against self-incrimination (Gripman, 1999; ACLU and EFF, 2015).
  • Due process requirements: Criminal investigation in general and surveillance in particular is not meant to be a frictionless process. Introducing inefficiencies in the functioning of LEAs is what separates a police state from a democracy (Richards, 2013; Hartzog and Selinger, 2013). As is the case of due process requirements, encryption creates procedural hurdles, ensuring some checks and balances over the functioning of LEAs and the possibility of mass surveillance. It therefore helps re-balance the asymmetric power distribution between the State and citizen.

Scope of "technical assistance": Should it extend to creating backdoors?

Given the aforementioned concerns, the question arises, should the duty of "technical assistance" that intermediaries are required to provide to LEAs, extend to the creation of backdoors or otherwise weakening encryption systems?

We argue that as far as recoverable encryption is concerned, i.e. encryption where a service provider already has a decryption key in the normal course of service provision, there is no requirement for such a mandate. Indian law already requires service providers to decrypt data in such cases, in addition to providing various other forms of assistance. Here, the need is to focus on implementing proper oversight and other procedural frameworks to ensure that LEAs exercise their powers of surveillance or decryption in an appropriate manner. We find however, that the Indian framework is lacking in this regard. There is no judicial oversight of decryption requests, no proportionality requirements in the law, and no meaningful checks and balances over decryption processes at all. We therefore proposed various changes in order to improve the transparency and accountability of the system. Further, research indicates that the primary problem of LEAs in India may relate to the relatively old and slow processes that must be used by LEAs when accessing data held by intermediaries, particularly those based outside India. This points more to the need for LEA data access processes to be revised/streamlined in accordance with modern needs.

As far as unrecoverable encryption is concerned, i.e. encryption where even the service provider cannot access the content (such as with E2E) as it does not have access to the decryption key, which is retained by the user, the situation is undoubtedly more complex. However, even in such instances, for the reasons elaborated above, we believe that mandating backdoors or weakening encryption is not an appropriate solution.

Moreover, LEAs already have multiple alternatives to collect information, including by accessing metadata and unencrypted backups of encrypted communications. They can also use targeted surveillance methods to conduct investigations (National Academy of Science, Engineering and Medicine, 2018). Indeed, the current Indian framework - governing telecom service providers in particular, but also other intermediaries - already gives significant and arguably excessive powers to the State. It should also be noted that LEAs in India are already using spying technology, as we saw in the Pegasus case. LEAs also have other covert methods of gathering data - from key-stroke logging programmes to exploiting weaknesses in implementation of encryption systems. While one cannot argue against the use of such systems in appropriate cases, it is clear that such powers must only be exercised through institutionalised processes, and importantly, subject to appropriate regulatory oversight. There is therefore a case for formulating a legal framework in India, along the lines of the US vulnerabilities equities process, to ensure due process even when the government resorts to exploitation of vulnerabilities within information systems for national security and law enforcement purposes.

Accordingly, we point to the need to carry out a more detailed cost-benefit analysis before deciding on the need to implement such a mandate (which unfortunately, has not been done in the case of the recent Intermediary Guidelines Rules). We point to how such a cost-benefit analysis should consider:

  • Whether the use of unrecoverable encryption is indeed a significant hurdle for LEAs in collecting relevant information. While no data is available in this context in India, data from the US in the period 2012-2015 indicates that of the 14,500 wiretaps ordered under the Communications Assistance for Law Enforcement Act, only about 0.2 percent of wiretaps encountered unrecoverable encryption (Lewis et al., 2017). While this share has likely increased in view of the greater use of unrecoverable encryption in the ecosystem, a similar empirical analysis must be conducted in India to understand the impact of such types of encryption.
  • The cost to intermediaries in changing their platform architecture are unlikely to be insignificant. It is also worth keeping in mind that often intermediaries will avoid using certain types of encryption purely to keep in the good books of LEAs in a form of "weakness by design". Notably, companies such as Apple and WhatsApp have dropped plans to encrypt user back-ups stored in the cloud. Such data can therefore be accessed by LEAs without compromising encryption.
  • The risk of such laws getting caught up in global geopolitics. This has been the case for example, with Huawei and ZTE, who have faced significant international pressure in view of the Chinese government's purported ability to access data flowing through their networks.
  • The possible effectiveness of such laws, considering that many criminals may use open source encryption or encryption from platforms that are not amenable to Indian jurisdiction. Further, the pace of technical development is difficult to keep up with from a regulatory perspective. Notably, institutions such as Europol and Interpol are increasingly concerned about the use of steganography (the technique of hiding the very existence of a message) and open source encryption by international criminals and terrorist groups. Therefore, even if there is a bar on using strong encryption, those who want to break this law, will continue to do so.

We therefore argue that while a mandate for targeted decryption or technical assistance may be constitutional if backed by a law with sufficient safeguards, a general mandate for the creation of backdoors (or an interpretation of the Intermediary Guidelines requirement to provide "technical assistance" to extend to such generic obligations) is unlikely to pass constitutional muster, assuming a high intensity of proportionality review is applied. A higher intensity of review will have to look at not just whether the proposed intervention would substantially improve national security, but would also need to engage with the fact that it would (a) compromise the privacy and security of individuals at all times, regardless of whether there is any evidence of illegal activity on their party, and (b) the existence of alternative means that are available to LEAs to carry out their investigations. Thus, we believe that a general mandate for creating backdoors will not be the least restrictive measure available.

Conclusions and Recommendations

We argue that a general mandate that requires Internet intermediaries to break encryption, use poor quality encryption, or create backdoors in encryption is not a proportionate policy response given the significant privacy and security concerns, and the relatively less harmful alternatives available to LEAs. Instead, the Indian government should support the development and use of strong encryption systems.

Rather than limiting the use of certain technologies, or mandating significant changes in platform/network architecture of intermediaries that compromises encryption, the government ought to take a more rights-preserving and long-term view of the issue. This will enable a more holistic consideration of interests involved, avoid unintended consequences, and limit costs that come with excessive government interference in the technology space. The focus of the government must be on achieving optimal policy results, while reducing costs to the ecosystem as a whole (including privacy and security costs). A substantive mandate to limit the use of strong encryption would increase costs for the entire ecosystem, without commensurate benefits as far as state security is concerned.

The tussle between LEAs and criminal actors has always been an arms race. Rather than adopting steps that may have significant negative effects on the digital ecosystem, the government could learn from the policies adopted by countries such as Germany, Israel and the USA. This would involve interventions along two axes - legal changes and measures to enhance state capacity.

Legal changes that the government must consider implementing, include:

  • Reforming surveillance and decryption processes, to clarify the powers of LEAs, and ensure appropriate transparency, oversight and review. It is also essential to standardise and improve current methods of information access by LEAs at both domestic and international levels. There must be greater transparency in the entire surveillance and information access apparatus, including by casting obligations on intermediaries and the State to make relevant disclosures to the public.
  • Adoption of a Vulnerabilities Equities Process, such as that adopted in the United States, which could enable reasoned decisions to be made by the government about the disclosure of software/network vulnerabilities (thereby allowing these to be patched, in circumstances where this would not significantly affect security interests of the State). Such a process, while not without critics, does chart a path forward and must become central to the Indian conversation around due process in LEA access to personal data.
  • Amending telecom licenses, which currently give excessive leeway for exercise of executive authority, without sufficient checks or safeguards.

Rather than implement ill-thought out policy solutions that would significantly harm the digital ecosystem and user rights, the government could also focus on enhancing its own capacities. This can include measures such as:

  • Developing and enhancing covert hacking capacities (though these must be implemented only subject to appropriate oversight and review processes). To this end, there must be appropriate funding of LEAs, including by hiring security and technical researchers.
  • Investing in academic and industry research into cryptography and allied areas. The government should also aid the development of domestic entities who can participate in the global market for data security related products. Enhancing coordination between industry, academia and the State is essential.
  • Increasing participation in international standard setting and technical development processes.

To conclude, the crux of this issue can be understood using an analogy. Would it be prudent for a government, engaged in a fight against black money, to require all banks to deposit a key to their customer's safe deposit boxes with it? One would venture that this would be an unworkable proposition in a democracy. It would lead to people looking for alternatives to the use of safe-deposit boxes due to the lack of trust such a system will create. Innocent people will be exposed to increased risks. A preferable solution may be for the government to develop the ability to break into a specific safe deposit box, upon learning of its illegal contents, and subsequent to following due process. This would enable more targeted interventions, that would also preserve the broader privacy interests of innocent customers while protecting banks from increased costs (or loss of business).

References

Gill, 2018: L Gill, Law, Metaphor and the Encrypted Machine, Osgoode Hall L.J. 55(2) 2018, 440-477.

Lewis et al., 2017: James Lewis, Denise Zheng and William Carter, The Effect of Encryption on Lawful Access to Communications and Data, Center for Strategic and International Studies, February 2017.

Haunts, 2019: Stephen Haunts, Applied Cryptography in .Net and Azure Key Vault: A Practical Guide to Encryption in .Net and .Net Core, APress, February 2019.

Kaye, 2015: David Kaye, Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, United Nations, Human Rights Council, May 2015.

Abelson et al., 1997: Hal Abelson, Ross Anderson, Steven Bellovin, Josh Benaloh, Matt Blaze, Whitfield Diffie, John Gilmore, Peter Neumann, Ronald Rivest, Jeffrey Schiller, and Bruce Schneier, The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption, May 27, 1997.

Levy and Robinson, 2018: Ian Levy and Crispin Robinson, Principles for a More Informed Exceptional Access Debate, LawFare Blog, November 29, 2018.

Cardozo, 2019: Nate Cardozo, Give Up the Ghost: A Backdoor by Another Nam et al.e, Electronic Frontier Foundation, January 7, 2019.

Access Now et al., 2019: Access Now, Big Brother Watch, Center for Democracy and Technology, et al., Open Letter to GCHQ, May 22, 2019.

Harold Abelson et al., 2015: Harold Abelson, Ross Anderson, Steven Bellovin, Josh Benaloh, et al., Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications, MIT-CSAIL Technical Report, July 6, 2015.

Gripman, 1999: David Gripman, Electronic Document Certification: A Primer on the Technology Behind Digital Signatures, 17 J. Marshall J. Computer and Info. L. 769 (1999).

ACLU and EFF, 2015: American Civil Liberties Foundation of Massachusetts, the American Civil Liberties Union Foundation, and Electronic Frontier Foundation, Brief for Amici Curiae in Support of the Defendant-Appellee in Commonwealth of Massachusetts v. Leon Gelfgatt, 2015

Richards, 2013: Neil Richards, Don't Let US Government Read Your E-Mail, CNN, August 18, 2013.

Hartzog and Selinger, 2013: Woodrow Hartzog and Evan Selinger, Surveillance as Loss of Obscurity, Washington and Lee L.R. 72(3), 2015.

National Academy of Science, Engineering and Medicine, 2018: National Academy of Science, Engineering and Medicine, Decrypting the Encryption Debate: A Framework for Decision Makers, National Academies Press, Washington DC.


Rishab Bailey is a researcher at NIPFP. Vrinda Bhandari is a practising advocate. Faiza Rahman is a PhD candidate at the University of Melbourne.

Wednesday, April 14, 2021

Online dispute resolution in India: Looking beyond the window of opportunity

by Rashika Narain and Smriti Parsheera.

Online dispute resolution (ODR) refers to the use of electronic communications and other information and communication technology for dispute resolution (UNCITRAL, 2016). Its objective being to bring the gains of efficiency, reach, cost-effectiveness, and convenience that technology has brought to so many sectors into the domains of redress, resolution and justice delivery. Some of the use cases of ODR include internal dispute management systems of businesses, electronic forms of alternative dispute resolution (often referred to as e-ADR), and operation of online courts.

India has seen a spate of recent developments in this space. There has been a rise in the number of ODR startups and businesses that are willing to experiment with ODR as an alternative to the traditional forms of dispute resolution. On the institutional side, COVID-19 induced pressures forced courts and Lok Adalats to switch to an online mode, the Reserve Bank of India directed payment systems operators to adopt ODR for failed payment disputes and the NITI Aayog put out a draft ODR Policy Plan.

Collectively, these developments signal the intersection of the problem, policy and politics streams to create a window of opportunity (Kingdon, 2013) for ODR in India. However, alongside the many benefits and opportunities of ODR lie a few areas of caution. First, the push toward ODR should account for the country's narrowing yet persistent digital divide. ODR solutions must, therefore, be designed in a manner that avoids extending digital exclusions into the domains of justice delivery and redress. Second, the immediate focus needs to be on building trust in the ODR sector though an emphasis on competence, accountability, equity, and transparency. These priorities should emerge from within the ODR ecosystem rather than being imposed through external forces. Lastly, the ecosystem should remain wary of any kind of central planning, particularly in terms of technical design. While controlled technical standardisation may seem attractive for initial adoption, it could result in the locking in of specific technologies and standards in the long run.

In this article we describe the meaning and evolution of ODR, explain the state of adoption in India, and introduce the Handbook on Online Dispute Resolution (ODR Handbook, 2021) created by a group of nine institutions that was recently launched by Justice D.Y. Chandrachud at a virtual event. The Handbook serves as an invitation to businesses to adopt and mainstream ODR solutions in India. While sharing the optimism generated by recent advancements in this space, we emphasise certain areas of caution and desirable practices for ODR to succeed beyond the current window of opportunity.

What is ODR?

ODR refers to the use of technology for enabling more accessible and efficient dispute resolution. Its genesis is often traced to the growth of Internet-based businesses and the resulting search for mechanisms to deal with online disputes and their accompanying jurisdictional uncertainties (Katsh, 2012). eBay and its payments arm PayPal are recognised to be among the early adopters of tech-enabled solutions for resolving cases arising on their platform (Rule, 2008). Similar tech-mediated systems for grievance redress are now commonplace across online businesses. Examples include the order returns management policies of e-commerce companies, feedback mechanisms of ride hailing companies and content reporting systems of social media firms. Beyond grievance management, e-ADR processes like mediation and arbitration are another popular use case.

The factors responsible for the growth of ODR include its efficiency, reach, cost-effectiveness, and the ability to improve business intelligence through data about dispute management. The possibility of asynchronous communication in many ODR models, which allows parties to respond at their own convenience, is another significant draw. Globally, ODR's reach has expanded to a range of sectors, such as property matters, family settlements, domain name disputes and financial matters (Kinhal et al, 2020). Further, tech solutions have also permeated into different layers of the dispute management process. For instance, negotiation tools like Cybersettle guide parties in making financial settlement bids and communication tools like Our Family Wizard are being used by courts to monitor parental custody settlements.

There are also many cases of institutional adoption of ODR in the public justice delivery system. Notable examples include Canada's British Columbia Civil Resolution Tribunal that uses ODR to handle condominium property claims, small claims, and motor vehicle injury cases, Hong Kong's ODR scheme for COVID-19 related cases, Mexico's Concilianet platform for consumer dispute resolution, and various small value claims courts in the United States (NITI Aayog, 2020).

State of play in India

The ODR industry in India has seen significant movement in the last few years although it still remains in the early stages of development. As per the ODR Handbook, the number of ODR start-ups has grown from 3 in 2018 to 13 by mid 2020. This includes operators like Presolv360, Centre for Online Resolution of Disputes (CORD) and SAMA that are directly involved in delivering online arbitration and mediation services as well as platforms like CREK ODR and Resolve Disputes Online that specialise in offering technology solutions to others.

A pilot project initiated by ICICI Bank in collaboration with SAMA presents one of the early examples of ODR adoption in India. As per the ODR Handbook, this mechanism was used for the resolution of 200 loan repayment related disputes before the introduction of the COVID-19 related loan moratorium. This reportedly led to significant cost and time savings for the bank -- its resolution effort went down from six person-days per case to only half a day (ODR Handbook, p. 61). In another example, SAMA recently organised an e-conciliation camp, called Suljhav Manch, which saw participation from companies like Udaan, Snapdeal and ICICI Housing Finance. An aggregate of over 8,000 loan and customer disputes were recorded for online resolution, of which 1,860 disputes have already been settled.

The COVID-19 situation has also created an impetus for institutional adoption through online filings, electronic court hearings and organisation of e-Lok Adalats in several states (Nair, 2020). Further, in line with RBI's directions for adoption of ODR by payment operators, the National Payments Corporation of India (NPCI) recently went live with its online resolution system for BHIM UPI app users. Others in the payment space are expected to shortly follow suit. The Income Tax Department has also introduced a Faceless Assessment Scheme that is meant to offer greater convenience and transparency in the assessment process.

In another interesting development, last year, the Supreme Court declared that the sole appointment of an arbitrator by a party interested in the dispute would be unlawful, even if previously agreed by the parties (Mehta et al, 2020). This may shift the standard practice of consumer facing companies appointing arbitrators en masse for low value, high volume disputes in favour of the incorporation of ODR clauses in commercial agreements.

Some areas of caution

While the developments above are cited as victories for ODR, the long term trajectory of tech-enabled dispute resolution will depend on a number of factors. First, there is the reality of India's digital divide, which spans across issues of connectivity, device ownership, digital literacy and skills, and social norms. A combination of these factors ends up generating varying levels of digital adoption across demographic groups. While sectors such as digital payments and e-commerce, which cater to an already digital population, are more conducive for ODR adoption, a broader policy push towards mandatory ODR could end up disenfranchising several sections of the population. For instance, the Tax Department's faceless assessment scheme has drawn criticism for the lack of opportunity for individuals to explain their case in person and limitations in technical skills and infrastructural facilities required to comply with the online processes (Chatterji, 2020).

Possible ways to minimise the harms of digital exclusion include keeping ODR adoption voluntary in most circumstances, investing in training and capacity building of intended users, and allowing them to opt for a combination of online and offline interactions. The emergence of a hybrid model where an intermediary can step in to facilitate the engagement between the parities and the technological requirements of the ODR system is another interesting solution. This is illustrated in the work being done by the Aajeevika Bureau to help migrant workers claim unpaid compensation from employers using an ODR process (ODR Handbook, p. 71-72).

Second, there is also the question of how to build trust in the ODR ecosystem in order to facilitate its adoption by businesses and individuals. There are some who argue that a certain level of government intervention and control is a necessary part of trust building (Schluz, 2004) while others have discussed interventions such as increasing knowledge about the process, certification of neutrals, and the existence of a code of ethics as mechanisms to bolster trust (Abedi et al, 2019). This points to the need for a discussion on the role of voluntary codes of conduct in building trust in ODR systems. We discuss this in the next section.

The third area of caution would be to avoid the creation of monolithic technical architectures in the ODR space. All too often in India, there is a temptation to create a state-mandated monopoly in a field, with government controlled technological standards (e.g. the Unified Payments Interface (UPI)) and a government controlled monopoly vendor (e.g. the NPCI). The NITI Aayog's draft report suggests a similar path for the ODR sector. It makes a case for the government's role in developing a 'scalable platform using technology' that will allow for the development of private sector services relying on government-led free and open source software (NITI Aayog, 2020, p. 96-97).

This is a less efficient path for several reasons. Government-mandated engineering designs tend to stagnate over time, and fall out of touch with the requirements of the people and of the technological possibilities. India is highly heterogeneous, and even if an efficient state-run planning process is able to emerge with a sound design for a modal use case, that may only cover a small fraction of the situations in the field. Further, despite being labeled as 'open', such solutions are often designed in a closed environment, with consultations being used as a tool for information dissemination rather than technical collaboration.

Providers and adopters of ODR have the incentives to understand opportunities, customer needs, and figure out innovative solutions. It would, therefore, be more efficient to allow a diverse set of actors to develop technology, protocols and standards in this space. Notably, ODR initiatives would also be bound by existing legal frameworks, such as the rights to data access and portability proposed under the draft Personal Data Protection Bill, 2019 and the safeguards available under competition law. Accordingly, government-backed technical standards are neither the only, nor the most efficient, path to achieving data access, portability, interoperability, and empowerment in this field.

A voluntary code for the ODR ecosystem

While resisting the push for government-backed standards and protocols, we recognise that a sound governance framework could be one of the ways to engender trust in the ODR ecosystem. There are several examples of non-binding ODR principles that have emerged globally. For instance, the International Council for Online Dispute Resolution (ICODR) is a US-based non profit that has put out a set of open standards on ODR. This includes requirements that the ODR programs must be accessible, accountable, competent, confidential, equal, neutral and impartial, legal, secure and transparent. Similar standards and guidelines have also been put out by other institutions such as the UNCITRAL's Technical Notes on ODR and the National Center for Technology and Dispute Resolution's Ethical Principles for ODR. The overlap in the principles outlined in these documents indicates a convergence of ideas on the basic requirements of a well functioning ODR system. Many ODR providers in India have also voluntarily adopted different international standards.

Given the current stage of development of India's ODR system, having mandatory standards or strict legal requirements could impede innovation and create entry barriers (ODR Handbook, p.51). However, this does not preclude the adoption of voluntary codes of conduct that are developed and operationalised by ODR players themselves. This could be done by having a basic set of good practices (see table below for the principles suggested in the ODR Handbook) that may be agreed to among the service providers in an open, inclusive and collaborative manner. Further, voluntary mechanisms such as peer review, ratings and accreditations can be used to verify the extent to which each platform is complying with these principles.


Principle Description
Accessibility Ensuring ODR platforms can be used across devices and by different demographic groups, accounting for the diversity of Indian languages and the ability to engage with technology.
Competence and neutrality Neutrals should possess substantive knowledge and understanding of processes and must be free of conflicts of interest.
Accountability and fairness Adherence to due process standards. Remain mindful of the possibility of unequal bargaining powers between parties.
Information and transparency Proactive disclosure of conflict of interest, risks, and benefits to enable informed consent. Anonymised data on ODR trends and statistics can help in building trust.
Confidentiality and robust data security Adherence to data protection norms, including safe storage and established protocols to deal with breaches, cyber attacks, and disasters.

Besides such voluntary adoption, providers of e-ADR are also bound by the existing laws and principles applicable to ADR processes. However, in many cases, these principles might need to be reframed to account for the impact of technology on ADR processes and the responsibility of ODR platforms and third parties neutrals conducing the mediation or arbitration processes (Rainey, 2014). For instance, use of the online medium might impose additional requirements of how confidentiality in mediation needs to be enforced in practice. This is because the mediator's ability to ensure confidentiality in ODR depends both on their own conduct as well as the design of the ODR platform. The ODR principle for confidentiality must, therefore, account for appropriate technical standards to ensure that the information transmitted on the platform remains confidential and secure. The practitioner also bears the responsibility to convey the risks of online communications to the parties (Rainey, 2014).

Conclusion

Developments in the past year or two have opened a window of opportunity for the adoption of ODR systems in India. As policymakers and private actors start warming up to the benefits of tech-enabled dispute resolution, the immediate goal should be to demonstrate capacity and build trust in ODR systems. This includes the realisation that not all sectors and user groups are equally equipped to immediately transition to ODR. Any kind of mandatory adoption should, therefore, be carefully considered so as to avoid extending digital exclusions into the domains of justice delivery and redress. An emphasis on hybrid models of ODR, both in terms of the choice between offline and online interactions and emergence of intermediaries who can help users in bridging the technological gap, would be useful.

Creating digital trust requires a framework that incorporates accountability, equity, ethics and auditability in its functioning. Thus, another priority at this stage should be to pursue the adoption of a voluntary code of conduct that is conducive to building trust in the ecosystem. Such a code of conduct should emerge, and be implemented, from within the ODR ecosystem rather than being enforced through State coercion. In addition to concerns of stifling innovation through over-regulation, it is also important to avoid excessive central planning in the technical design of ODR systems. This could result in the locking in of specific technologies and standards, hampering the long term prospects of the ODR sector.

References

Chatterji, 2020: B.M. Chatterji, Faceless Assessment: Concerns & Recommendations for Seamless Digital Integration, Tax Guru, 28 November 2020.

Katsh, 2012: Ethan Katsh, ODR: A Look at History, Online Dispute Resolution: Theory and Practice, Mohamed Abdel Wahab, Ethan Katsh & Daniel Rainey (Eds.), Eleven International Publishing, 2012.

Kelkar & Shah, 2019: Vijay Kelkar and Ajay Shah, In service of the republic: The art and science of economic policy, Penguin Allen Lane, 2019.

Kingdon, 2013: John W. Kingdon, Agendas, Alternatives and Public Policies. 2nd ed., Pearson, 2013.

Kinhal et al, 2020: Deepika Kinhal, Tarika Jain, Vaidehi Misra & Aditya Ranjan, ODR: The Future of Dispute Resolution in India, Vidhi Cenre for Legal Policy, July 2020.

Lederer, 2018: Nadine Lederer, The UNCITRAL Technical Notes on Online Dispute Resolution - Paper Tiger or Game Changer?, Kluwer Arbitration Blog, January 2018.

Mehta et al, 2020: Ankoosh Mehta, Maitrayi Jain & Anushka Shah, SC refuses unilateral appointment of single arbitrator, Indian Corporate Law, A Cyril Amarchand Mangaldas Blog, May 2020.

Nair, 2020: Ria Nair, E-Lok Adalats In India, August, 2020.

NITI Aayog, 2020: The NITI Aayog Expert Committee on ODR, Designing the Future of Dispute Resolution: The ODR Policy Plan for India, October, 2020.

ODR Handbook, 2021: NITI Aayog, Agami, Omidyar Network India, Ashoka, ICICI Bank, Trilegal, Dalberg, Dvara Research, NIPFP and Cracker & Rush, Online Dispute Resolution: Shifting from Disputes to Resolutions, April, 2021.

Rainey, 2014: Daniel Rainey, Third-Party Ethics in the Age of the Fourth Party, 2014.

Rule, 2008: Colin Rule, Making Peace on eBay: Resolving Disputes in the World's Largest Marketplace, ACResolution Magazine, Fall 2008.

Schluz 2004: Thomas Schulz, Does Online Dispute Resolution Need Governmental Intervention - The Case for Architectures of Control and Trust, 6 N.C.J.L. & Tech. 71 (2004).

UNCITRAL, 2016: UNCITRAL Technical Notes on Online Dispute Resolution, 2016.


Rashika Narain is lawyer and mediator associated with SAMA and the Centre for Mediation and Arbitration, Mumbai. Smriti Parsheera is a Fellow with the CyberBRICS Project and was previously a researcher with the National Institute of Public Finance & Policy (NIPFP). NIPFP was one of the contributors to the ODR Handbook. The authors would like to thank Vimal Balasubramaniam, Keerthana Medarametla, Renuka Sane and Ajay Shah for valuable inputs.