
The Ministry of Electronics and Information Technology (MeitY) has issued blocking orders for some websites that are found to be exposing sensitive personal identifiable information including Aadhaar and PAN Card details of Indian citizens.
The action was taken after concerns raised by internet users on social media, who claimed that a basic online search of Aadhaar details was revealing personally identifiable information (PII) of many Indians from specific websites.
The Unique Identification Authority of India (UIDAI) has lodged a complaint with the police authorities concerned for violation of the prohibition under section 29(4) of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 on public display of Aadhaar information.
The analysis of these websites by the Indian Computer Emergency Response Team (CERT-In) has shown some security flaws in these websites. The concerned websites owners have been provided guidance about the actions to be taken at their end for hardening the ICT infrastructures and fixing the vulnerabilities.
CERT-In has issued “Guidelines for Secure Application Design, Development, Implementation & Operations” for all entities using IT applications. CERT-In has also given directions under the Information Technology Act, 2000, (“IT Act”) relating to information security practices, procedure, prevention, response and reporting of cyber incidents.
MeitY has notified the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which provide for non-publication and non-disclosure of sensitive personal data. Any adversely affected party can approach the Adjudicating Officer under section 46 of the IT Act for filing a complaint and seeking compensation. The IT Secretaries of the States are empowered as Adjudicating Officers under the IT Act.
Further, the Digital Personal Data Protection Act, 2023 has already been enacted and the Rules under this Act are in the advanced stage of drafting. With the aim of sensitizing the Government, the industry and the citizens about its impact, an awareness programme has also been initiated. This will help in creating a nationwide awareness and understanding among diverse stakeholders about responsible use and proactive measures which will curb unnecessary exposure of personal data by various entities.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.