The Government of India is committed to have an open, safe & trusted and accountable internet. It has come to the notice of the Ministry of Electronics and Information Technology (MeitY) that some websites were exposing sensitive personal identifiable information including Aadhaar and PAN Card details of Indian citizens.
This has been taken up seriously as the Government accords highest priority to safe cyber security practices and protection of personal data. In line with this, prompt action has been taken to block these websites.
The Unique Identification Authority of India (UIDAI) has lodged a complaint with the police authorities concerned for violation of the prohibition under section 29(4) of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 on public display of Aadhaar information.
The analysis of these websites by the Indian Computer Emergency Response Team (CERT-In) has shown some security flaws in these websites. The concerned websites owners have been provided guidance about the actions to be taken at their end for hardening the ICT infrastructures and fixing the vulnerabilities.
CERT-In has issued “Guidelines for Secure Application Design, Development, Implementation & Operations” for all entities using IT applications. CERT-In has also given directions under the Information Technology Act, 2000, (“IT Act”) relating to information security practices, procedure, prevention, response and reporting of cyber incidents.
MeitY has notified the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which provide for non-publication and non-disclosure of sensitive personal data. Any adversely affected party can approach the Adjudicating Officer under section 46 of the IT Act for filing a complaint and seeking compensation. The IT Secretaries of the States are empowered as Adjudicating Officers under the IT Act.
Further, the Digital Personal Data Protection Act, 2023 has already been enacted and the Rules under this Act are in the advanced stage of drafting. With the aim of sensitizing the Government, the industry and the citizens about its impact, an awareness programme has also been initiated. This will help in creating a nationwide awareness and understanding among diverse stakeholders about responsible use and proactive measures which will curb unnecessary exposure of personal data by various entities.