By B.V.S. Aditya Santosh and Siddhant Tomar

INTRODUCTION
The Union Ministry of Home Affairs’ terse Statutory Order dated December 20, 2018 (SO) garnered sharp reactions from the political community, cyber security experts and advocates of internet freedom, against what they perceived was an attempt at mass surveillance. The SO cemented the ideology that it provides a “legal basis” for non-consensual access to sensitive, personal data under the garb of national security.
The Statutory Order drew its legitimacy from Section 69(1) of the Information Technology Act, 2000, in conjunction with Rule 4 of the Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009. The Order issued by the Cyber and Information Security Division authorized ten intelligence and security agencies, viz. (Intelligence Bureau, Central Bureau of Investigation, National Investigation Agency etc.) to intercept, monitor and decrypt any information received, transmitted, or generated, stored in any computer resource under the Act.
The term “computer resource” connotes wide implications and endows astounding powers to intelligence agencies, as its definition under Section 2(k) was amended to include communication devices in 2008. In comparison, the original definition was limited to computer, computer network, computer database, data and software and therefore the possibility of misuse cannot be understated.
SAFEGUARDS
Every single case of interception, decryption and monitoring is to be ratified by the competent authority, which in this case is the Union Home Secretary. Pursuant to section 69(1) of the Act, where the central government or the respective state government is satisfied that it is expedient to do so in the interest of the sovereignty, integrity or defense of India, or for ensuring security of the state and securing friendly relations with foreign states, or in the interest of public order or to prevent incitement to the commission of any cognizable offence relating to the above or for the investigation of any offence, it may, subject to the provisions of 69(2), for reasons to be recorded in writing, direct any of its agencies to intercept, decrypt and monitor any information transmitted, received or stored through any computer resource.
The prescribed procedure and safeguards under the aforementioned section are tenuous, therefore in 2009, IT Rules were promulgated as an additional bulwark, particularly rule 22 which envisages that all surveillance requests have to be placed before a review committee chaired by the cabinet secretary, which shall meet at least once in two months to review such cases. In the case of state governments, a committee headed by the chief secretary concerned will carry out the review.
EFFICACY OF CURRENT SAFEGUARDS
In the light of a recent Right to Information application to the Home ministry, it was divulged that the review committee approves 7500-9000 surveillance requests every month. The review committee, which is convened every two months, has the unrealistic task of reviewing 15,000 to 18,000 interception orders in every meeting, which points towards the blatant arbitrariness that is present. Additionally, the BN Sri Krishna Committee, while reviewing Section 5 of the Telegraph Act and Sections 69 and 69B of the IT Act, noted that the existing mechanism is lopsided and enabled unfair surveillance practices by the license agreements entered into by telecom service operators with the government. For example, such agreements can mandate low encryption standards. This poses a threat to the safety and security of the personal data of data principals (individual whose data is being collected) and data fiduciaries (entities which collect data.)
SIGNIFICANCE OF SAFEGUARDS
Effective safeguards can only be guaranteed by a comprehensive data protection law, despite a draft bill having been recommended by an expert committee headed by the former Supreme Court Justice Hon’ble BN Sri Krishna, the enactment is pending in Parliament. The committee observed, “Surveillance should not be carried out without a degree of transparency that can pass the threshold of the Puttaswamy test of necessity, proportionality and due process. This can be accomplished through various forms, including judicial oversight and information provided to the public. This would ensure scrutiny over the working of such agencies and infuse public accountability.”
The prospective data protection law must make it obligatory for law enforcement agencies to ensure that the processing of sensitive personal data of individuals is actually necessary and proportionate to their purpose. For example, mass DNA profiling, i.e. the maintenance of DNA database of all citizens, some of whom may be innocent, to track crime, without legal sanction, would be a disproportionate law enforcement measure. A similar framework was standardized in the United Kingdom, where the government later had to delete the records of more than a million innocent adults and children after the enactment of the Protection of Freedoms Act, 2012, which inter alia regulates the collection, retention, destruction of biometric data, surveillance mechanisms, etc.
Recourse can be drawn from the proposed Section 42(1) of the Personal Data Protection Bill, 2018, which states that processing of personal data in the interests of the security of the state shall not be permitted unless it is authorized pursuant to a law and is in accordance with the procedure established by such law made by Parliament and is necessary for, and proportionate to, such interests being achieved.
THE GARB OF NATIONAL SECURITY
Indian Courts have conventionally deferred to the executive’s prerogative on national security grounds. The consequential question is this that how much actual security would such a measure provide.
Scholars such as Jennifer Chandler argue that heightened surveillance often leads to less rather than more security since these measures have been known to disproportionately affect racial and religious minorities. She also argues that the traditional debate on privacy versus security always ends in favor of security before we can fully examine the impact that a given reduction of privacy will have.
These overarching mechanisms instituted by the Current S.O seem to increase feelings of security but do not translate into an actual increase in physical safety. This phenomenon famously referred in the Stasi Commission (secret police of East Germany) era as a “security theatre” where the mental aspect of “feeling secure” is given greater importance than actual physical safety.
Justice Kaul dealt with profiling in his concurring judgment in the Puttaswamy case. He referred to the European Union regulation of 2016 on data privacy, which defines profiling as any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements. Such profiling, Justice Kaul said, could result in discrimination based on religion, ethnicity and caste. However, he added, that profiling could be used to further the public interest and for the benefit of national security.
The security environment, not only in India but throughout the world, makes the safety of persons and the state a matter to be balanced against the right to privacy, he observed. But then he warned: “Knowledge about a person gives a power over that person. The personal data collected is capable of effecting representations, influencing decision-making processes and shaping behavior. It can be used as a tool to exercise control over us like the ‘Big Brother’ state exercised. This can have a stultifying effect on the expression of dissent and difference of opinion, which no democracy can afford.” Even as the Union government seeks to acquire the power of surveillance in the name of national security, it is apt to read what Justice Kaul said in the Puttaswamy judgment on the right to privacy with regard to the role of privacy in preventing awkward social situations and reducing social friction.
CONCLUSION
The lapse of the Intelligence Services (Powers and Regulation) Bill, to regulate the functioning of Indian intelligence agencies and to institute an oversight mechanism lapse creates a legislative vacuum for unfettered state surveillance in direct abhorrence of the Right to Privacy judgment. More importantly, if national security was the objective, it is unclear why organizations aiming to detect financial and narcotics-related offences have been empowered. The NCB and the CBDT pursue objectives other than national security. Justice DY Chandrachud while expressing concern over ‘social media communication hub’ proposed by the government to collect and analyze social media citizens of data, termed the practice as Surveillance State.
From a global standpoint, the Jamaican Supreme Court very recently struck down the Jamaican National Identification Registration Act, (law mandating the collection of biometric information) placing substantial reliance on the Justice DY Chandrachud’s dissenting view in the Aadhaar judgment. The proliferation of a social credit system in totalitarian countries like China begs the importance of having adequate oversight over the mass monitoring of citizens personal data.
The authors endorse the creation of an autonomous Data Protection Authority to authorize the interception, decryption and monitoring approvals of sensitive personal data of citizens and timely expunction of such data after the cessation of suspicion. In the light of the aforementioned, the December 20 Statutory Order fails the test of proportionality as laid down by the Supreme Court in several cases and is liable to be struck down in limine.
(The authors are fourth year students, currently pursuing B.B.A. LL.B. (Hons.) at ICFAI Law School, Dehradun).
