DBT Bureau
Pune, 27 Sep 2024
The Government of India is dedicated to ensuring a safe and trustworthy internet. Recently, the Ministry of Electronics and Information Technology (MeitY) discovered that some websites were leaking sensitive personal information, including Aadhaar and PAN Card details of Indian citizens. The government is treating this issue seriously, as it prioritizes cybersecurity and the protection of personal data. As a result, immediate action has been taken to block these websites.
The Unique Identification Authority of India (UIDAI) has lodged a complaint with the police authorities concerned for violation of the prohibition under section 29(4) of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 on public display of Aadhaar information.
The analysis of these websites by the Indian Computer Emergency Response Team (CERT-In) has shown some security flaws in these websites. The concerned website owners have been guided on the actions to be taken at their end for hardening the ICT infrastructures and fixing the vulnerabilities.
CERT-In has issued “Guidelines for Secure Application Design, Development, Implementation & Operations” for all entities using IT applications. CERT-In has also given directions under the Information Technology Act, 2000, (“IT Act”) relating to information security practices, procedures, prevention, response and reporting of cyber incidents.
MeitY has notified the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which provide for non-publication and non-disclosure of sensitive personal data. Any adversely affected party can approach the Adjudicating Officer under section 46 of the IT Act to file a complaint and seek compensation. The IT Secretaries of the States are empowered as Adjudicating Officers under the IT Act.
Further, the Digital Personal Data Protection Act, 2023 has already been enacted and the Rules under this Act are in the advanced stage of drafting. To sensitize the Government, the industry and the citizens about its impact, an awareness programme has also been initiated. This will help in creating a nationwide awareness and understanding among diverse stakeholders about responsible use and proactive measures that will curb unnecessary exposure of personal data by various entities.