Indian cybersecurity rules due to come into force later this month will create an "environment of fear rather than trust", a body representing top tech companies has warned the government, calling for a one-year delay before the rules take effect.
The Internet and Mobile Association of India IAMBI, which represents firms including Facebook, Google and Reliance, wrote this week to India's IT ministry criticizing a directive on cybersecurity set out in April.
Among other changes, the directive from the Indian Computer Emergency Response Team (CERT) requires tech companies to report data breaches within six hours of noticing such incidents and to maintain IT and communications logs for six months.
In the letter seen by Reuters, IAMBI proposed to extend the six-hour window, noting the global standard for reporting cyber-security incidents is generally 72 hours.
CERT, which comes under the IT ministry, has also asked cloud service providers such as Amazon and virtual private network (VPN) companies to retain names of their customers and IP addresses for at least five years, even after they stop using the company's services.
The cost of complying with such directives could be "massive", and proposed penalties for violation including prison would lead to "entities ceasing operations in India for fear of running afoul," the IAMBI letter said.
On Thursday, VPN service provider Express VPN removed its servers from India, saying it "refuses to participate in the Indian government's attempts to limit internet freedom".
IAMBI's letter follows one from 11 significant tech-aligned industry associations earlier this week, which said the new requirements made it difficult to do business in India.
India has tightened regulation of big tech firms in recent years, prompting pushback from the industry and in some cases even straining trade ties between New Delhi and Washington.
New Delhi has said the new rules were needed as cybersecurity incidents were reported regularly, but the requisite information needed to investigate them was not always readily available from service providers.
(Reporting by Muncie Vengattil in New Delhi; Editing by David Holmes)
(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)
The Supreme Court Friday extended the time for submitting the report by the apex court-appointed technical and supervisory committees to look into the Pegasus row, saying 29 infected mobile phones are being examined for the spyware and the process should be over in four weeks.
A bench headed by Chief Justice N V Ramada said the technical committee has been examining mobiles for the spyware and has also recorded statements of persons including some journalists and activists.
Standard operating procedure for testing the 'infected devices' will be finalized too, it said, adding the probe by the technical committee may be over by the May end and then the supervisory judge would be making a report for the perusal of the bench.
Referring to the receipt of an interim report, the bench, also comprising justices Surya Kant and Him Kohl, said that the technical committee, which has received 29 mobiles for examining the spyware, has developed its software for this purpose and issued notices to some government agencies and individuals including journalists.
It has prayed for time to submit its report. Now, it is under process. We will give them time, it said.
Preferably, the process by the technical committee should be over in four weeks and the supervisory judge should be informed. The supervisory judge shall submit his report thereafter. List sometime in July, said the bench.
The bench did not pass any order concerning the request made by senior lawyer Kamil Sibyl, who has been appearing for some petitioners, that the interim report be made available to the parties.
Solicitor General Pusher Meh ta, appearing for the Center, said the report being an interim one need not be made public at this stage.
The bench, which on October 27, last year had ordered a probe into the allegations of use of Israeli spyware by government agencies for targeted surveillance of politicians, journalists, and activists, has now fixed the case for further consideration in July.
The panel, which included three experts on cybersecurity, digital forensics, networks, and hardware, was asked to inquire, investigate and determine whether Pegasus spyware was used for snooping on citizens and their probe would be monitored by a former apex court judge R V Ravindra.
The panel members were Naveen Kumar Chaudhary, Prabhakar P, and Ashwin Anil Namaste.
Justice Ravindra, who is heading the monitoring panel, has been assisted by former IPS officer Alok Joshi and Sundeep Oberon, Chairman of Sub Committee in International Organization of Standardization/ International Electromechanical Commission/Joint Technical Committee - in monitoring the inquiry of the technical panel.
The committee is requested to prepare the report after a thorough inquiry and place it expeditiously before the court.
The apex court, in its order, had said that the probe panel would be empowered to inquire and investigate what steps/actions have been taken by the Center after reports were published in 2019 about the hacking of WhatsApp accounts of Indian citizens, using the Pegasus suite of spyware, whether any Pegasus suite was acquired by the Union of India, or any state government, or any central or state agency for use against the citizens of India.
An international media consortium had reported that over 300 verified Indian mobile phone numbers were on the list of potential targets for surveillance using the Pegasus spyware.
You must be logged in to post a comment.