FDPPI to adopt “LedgerMail” a unique Secure E Mail System

 

 

FDPPI signed an MOU today with LedgerFi IT solutions for a LedgerMail corporate Secure E Mail solution.

LedgerFi is a UAE based company with a development center in Bangalore which has developed a unique blockchain based e-mail solution which does not use the insecure SMTP protocol.

The system provides end to end encryption with a PKI based digital signature system with the private key being in the control of the user.

The solution comes with two versions. In one version (B2C version) the e-mail server works on distributed systems which consists of a public blockchain and public decentralised storage.

In the other version (B2B version) the server is maintained by the corporate entity (on premise or private cloud). The system comes with an admin level control for decryption in case of law enforcement requirements. Hence the solution meets the requirements of security envisaged under the Indian law enforcement requirements and the CERT In regulations.

The solution can be used by a company or a Government department for internal e-mails where the users are on-boarded to the system as members of a closed community.

In the event e-mails are to be sent and received to or from persons outside the closed system, an invitation to be onboarded can be sent and the outsider can be brought into the system.

The system can be configured to use the current e-mail ID of a user such as xyz@gmail.com and hence the user who is onboarded onto the system does not have to make any change of identity with his contacts. All the contacts who are in the LedgerMail system can use the ID xyz@gmail.com to send and receive the e-mails through the system from or to other persons within the system.

The system is likely to be a big boon to Banks to prevent phishing if they onboard all their customers as a part of their account opening process. Similarly the Government of India which has been trying to move people out of Gmail can also use this system with an inhouse server which is secure and free from SMTP protocol deficiencies.

FDPPI expects this system to catch on with Privacy Conscious but Cyber Law Compliant users. FDPPI is proud to be the first Indian Corporate to adopt the system.

 

Naavi
Posted in Cyber Law | Leave a comment

Pensioners… Beware of Jeevanpramaan clones

The Government of India has introduced a scheme for simplifying the issue of life certificates for pensioners through an online service through the website www.jeevanpramaan.gov.in.

However there are  many clones of “Jeevan Praman”  that have  come online and pensioners have to be wary of them. They may either be an unfair exploitation of pensioners or a major scam.

Look at the following two web pages.

The one on the left side is the Government website and the second on the right side belongs to some Noida organization which uses the domain name jeevanpraman.online and the same pictures used by the Government website. It offers similar service but at a price.

This service involves providing aadhaar number and uses face recognition so that vital biometrics have to be provided for using the services offered. Most customers would do so thinking that this is a Government website.

This underscores the responsibility of organizations to guard against  a “Confusingly similar Website”  operating  in violation of trademark rights and causing a potential fraud risk to the community.

Not taking remedial action to bring down such  sites could be an abetment of any crime that may be committed by the alternate website using the similar domain name.

We recall the case of www.cgtmse-govt.in which was a fraudulent website which impersonated www.cgtmse.in which belonged to the Government. This fraud was brought to the notice of the public in 2013 but no action was taken by the authorities till in 2016 an adjudicator of Chattisgarh gave an award of compensation in a fraud case.

While it is open for any private sector company to offer a service to enable a citizen to make use of the Government service and also charge a reasonable fee, there should be clear indications that the company is not to be confused with the Government department.

A mere disclaimer at the bottom of the page that stating “Please be informed that this site serves content solely for knowledge purposes and is not affiliated with any pension agency or state institution. Your interaction with this site is subject to our terms of services, privacy, refunds and grievance policy. “For any questions, please email us at info@jeevanpraman.online.” in small print is not sufficient.

It should carry a bold visible mark “This is not a Government Website” or something similar.

Naavi introduced the service under “lookalikes.in” precisely for this purpose where a third party certified disclaimer can be visibly posted on the website.

This system will be effective if both websites post that he information that they are not related to the other.  At present the other  companies who are using the “Naavi” in their domain names have not yet posted the disclaimers on their websites.

I hope that such disclaimers are an obligation to the society and is a measure to ensure that regulatory authorities donot confuse one for the other.

It is time that such disclaimers are made part of the “Due Diligence” under Section 79 of ITA 2000.

Naavi

 

 

 

Also refer:

Domain Name Regulation in ITA 2000..to be amended

 

Posted in Cyber Law | Leave a comment

Emotional Analysis Techniques pose a Profiling Risk

Emotional Analysis Techniques are a new age techniques used in Data Analytics  to process data such as gaze tracking, sentiment analysis, facial movements, gait analysis, heartbeats, facial expressions and skin moisture. Emotion analysis can also be applied to the use of textual data.

Other examples include monitoring the physical health of workers by offering wearable screening tools or using visual and behavioural methods including body position, speech, eyes and head movements to register students for exams.

Emotions are also gathered and analysed using EEG signals and sub conscious data which falls in the Neuro Rights domain.

These techniques are also related to Sentiment analysis or Opinion Mining which is a Machine learning and NLP technique used by some survey agents to assess the feedback on goods and services. The data gathered in this process is used for marketing.

These techniques have now attracted attention of ICO-UK, which has warned that “Immature biometric technologies could be discriminating against people”

The UK Commissioner has stated that a “Biometric guidance” may be released by the ICO-UK in the next year. For the time being the ICO-UK (Stephen Bonner) has said that  they  are concerned that incorrect analysis of data could result in assumptions and judgements about a person that are inaccurate and lead to discrimination.

It is recognized that the inability of algorithms which are not sufficiently developed to detect emotional cues, means there’s a risk of systemic bias, inaccuracy and even discrimination.

ICO has noted that the technique may be used along with many face recognition technologies used by Financial Companies who analyse photo IDs and Selfies, airports where passengers are scanned by facial recognition and use of voice recognition for access.

In view of the above all organizations who are using biometrics may come under a special watch to understand if they are using emotional analysis and if so responsibly.

Naavi

 

Posted in Cyber Law | Leave a comment

Life Imprisonment under ITA 2000/8

In a first occurrence of its kind, a person was convicted by the Mumbai sessions court for life under Section 66F of ITA 2000/8.

The accused, one Anees Ansari had been arrested in October 2014 and was planning to attack an American school in Bandra with a thermite bomb.

Refer here

Naavi

 

 

 

Posted in Cyber Law | Leave a comment

Amendment to Schedule I of ITA 2000 -Conflicts with NI Act and New Fraud Risks

At a time there are discussions about ITA 2000 being revamped and replaced with a new version of a Digital India Act, a major amendment has been made to the ITA 2000 through a Gazette Notification

Though this appears to be a small notification, it significantly expands the applicability of the ITA 2000.

Presently Schedule I of ITA 2000 lists the following 5 types of documents to which the act does not apply:

  1. A Negotiable Instrument (Other than a cheque) as defined in Section 13 of the Negotiable Instruments Act 1881 (26 of 1881
  2.   A Power of Attorney as defined in section 1A of the Power of Attorney Act 1882 (7 of 1882)
  3. A trust as defined in section 3 of the Indian Trusts Act, 1882 (2 of 1882)
  4.  A will as defined in clause (h) of section 2 of the Indian Succession Act, 1925 (39 of 1925) including any testamentary deposition whatever name called
  5. Any contract for the sale or conveyance of immovable property or any interest in such property

The Modified Schedule I states as follows:

  1. A negotiable instrument (other than a cheque, a Demand Promissory Note or a Bill of Exchange issued in favour of or endorsed by an entity regulated by the Reserve Bank of India, National Housing Bank, Securities and Exchange Board of India, Insurance Regulatory and Development Authority of India and Pension Fund Regulatory and Development Authority) as defined in section 13 of the Negotiable Instrument Act, 1881 (26 of 1881).”
  2. A Power of Attorney as defined in section 1A of the Power of Attorney Act 1882 (7 of 1882), “but excluding those power of attorney that empower an entity regulated by the Reserve Bank of India, National Housing Bank, Securities and Exchange Board of India, Insurance Regulatory and Development Authority of India and Pension Fund Regulatory and Development Authority to act for, on behalf of, and in the name of the person executing them.”
  3. A trust as defined in section 3 of the Indian Trusts Act, 1882 (2 of 1882)
  4.  A will as defined in clause (h) of section 2 of the Indian Succession Act, 1925 (39 of 1925) including any testamentary deposition whatever name called
  5. (Omitted)

Implications

The type of documents mentioned in this schedule are excluded from the applicability of the Act. Since the Act includes section 4 on  “Recognition ” of documents as equivalent to paper documents, those documents omitted from the Act through this schedule have no legal recognition in electronic form.

The documents which are “Excluded” from Schedule I are within the provisions of the Act and will carry legal recognition.

Hence when Schedule I stated “Negotiable Instrument” as an excluded item in the original ITA 2000, it meant that Cheque, Bill of Exchange and Promissory Note in electronic form were not recognised in law. In February 2003, Negotiable Instruments Act 1881 was amended to introduce Truncated Cheques and Cheques in Electronic form. Simultaneously the Schedule I of ITA 2000 had been amended to include the words (Other than the cheque) in item 1. Hence Cheques in electronic form and Truncated cheques (scanned form of written cheques) were considered legally equivalent to  the corresponding physical instruments.

With this amendment, a class of one class of Demand Promissory Notes and Bill of Exchange namely those

Issued in favour  of ” or  “Endorsed by”

an entity regulated by” RBI, NHB, SEBI, IRDAI, Pension Fund Regulatory and Development Authority (PFRDA)

have been brought into the category of legally valid electronic documents.

However, Demand Promissory Notes and Bills of Exchange issued or endorsed by other entities still remain outside the Act. Similarly a Promissory Note which is not a “Demand Promissory Note” (Payable after a date of maturity) could be considered as not a “Demand Promissory Note under this schedule” (Subject to interpretation).

If an instrument (Bill of Exchange or Promissory Note has been issued by an entity other than the privileged entities mentioned in the schedule, if “Endorsed” by a privileged entity (RBI, SEBI, NHB, IRDAI, PFRDA etc) becomes legally recognized.

This part of the impact of this amendment (A Midas touch !) appears to be legally debatable and provides an authority to these agencies to give a “recognition as a negotiable instrument” to an instrument which was earlier not a negotiable instrument (A document which by wording was a promissory note or bill of exchange but expressed as an electronic document).

This notification requires an amendment of NI Act to introduce a new category of instruments as Negotiable Instruments under Section 13 of NI Act.

We must remember that the Negotiable Instruments Act does not end with the definition of Promissory Note, Bill of Exchange and Cheque under Sections 4, 5 and 6 read with Section 13.

A Negotiable Instrument is characterised by the property of being able to create a “Holder in Due Course” which incorporates the principles of “Indorsement” and “Delivery”. It involves “Possession” of the instrument,  and transfer of possession with an intention to make the transferee, owner there of. The definition of an “Indorsement” under Section 15 of NI act itself is dependent on “Signing on the back of the cheque or on a piece attached thereto (allonge)”.

Concept of “Endorsement” of an Electronic Promissory Note or Bill of Exchange (as per the schedule I) is therefore  inconsistent with NI Act.

Further Bills of Exchange  are documents which are compulsorily required to be stamped and an instrument in electronic form but considered as Bill of Exchange needs further changes in other laws.

A Bill of exchange is also associated with concepts of  “Presentment” and “Acceptance” to determine the due date and “Presentment” involves “Delivery” and hence in an electronic  form, there are several other issues which need to be taken together to interpret an electronic negotiable instrument and how it can be used.

“Holder’s Right to a duplicate Bill” also may create a conflict when electronic copies may be available of the Bill.

The Government appears to have not considered the impact of this notification on Negotiable Instruments Act and whether a new class of negotiable instruments can be created through a notification under ITA 2000 instead of an amendment to NI Act.

In other words, it can be argued that this notification is ultra vires the NI Act

Again, the amendment to the notification regarding Power of Attorney creates a category of Powers of Attorney that empower the privileged entities namely the RBI, NHB, SEBI ,IRDAI and PFRDA.

This could have been better addressed through an amendment of the Power of Attorney Act.

It is also surprising that TRAI (which may be replaced by a new Telecom Regulator) is missing from the list of privileged institutions.

The removal of serial item number 5 opens up the use of electronic documents in transactions involving immovable properties and transfer of interest there-in. This introduces a serious element of Fraud risks in registration of property documents since many of the practices used by the Registration department donot meet the security and legal requirements of authentication and evidentiary recording of the transactions.

In summary it appears that the Notification has not taken into consideration the legal validity of the notification and the new risks that will introduce on the community.

Criminals will now focus on how to get properties transferred in the Registrar’s office without a genuine authentication from the erstwhile owners and there will be a chaos in the real estate market bigger than the Telgi Scam.

I wish the Government re-thinks on this notification to avoid the complications.

Naavi

Posted in Cyber Law | Leave a comment

Digital Society Day 2022 celebrated

FDPPI and Naavi.org successfully celebrated the virtual event to celebrate the Digital Society Day 2022, on October 17, 2022. A Brief report of the event is presented below.

The event started with a brief welcome from T C Manju, Consultant Operations, FDPPI. This was followed by Naavi introducing the importance of the day and also introducing the FDPPI and its activities briefly.

This was followed by a talk from Mr Rakesh Maheshwari, Senior Director, MeitY on his experiences regarding ITA 2000 particularly in the implementation of the Intermediary guidelines.

This was followed by Dr (Advocate) Pavan Duggal who shared his reminiscences on ITA 2000. Dr  (Advocate) Prashant Mali followed with his views and suggestions on ITA 2000.

This was followed by a brief presentation by Naavi on the concept of Compliance Management Rating (CMR) for CERT-IN and ITA 2000 compliance.

There after a panel consisting of Commander Mukesh Saini, Dr A Nagarathana, Dr Mahendra Limaye and Advocate M G Kodandaram discussed the relevance of ITA 2000 in the current regulatory scenario.

In the valedictory session, Commander Rajeev Seoni, presented a summary and his views on the proceedings. A Lucky draw was held for the participants who attended the program and three persons were chosen by a spinning wheel draw and they will be sent FDPPI T-Shirts.

Vote of Thanks was provided by Ashok Kini, Co-Founder Klickstart.

Some of the pictures captured during the event are provided below.

 

 

 

We thank all those who made the event a success.

A link to the recording is available here.

Naavi

 

 

 

Posted in Cyber Law | 1 Comment