Indian trade body sets up data protection group
DSCI founded to counter privacy criticism
Posted in Enterprise Security, 15th June 2007 09:31 GMT
Free Download - Security Web 2.0
An IT industry trade body is setting up a data privacy watchdog in India. The Data Security Council of India will not have legal powers, but will certify companies' data security.
Following a number of media exposes of data security breaches in India, IT industry trade body Nasscom is establishing the DSCI to counter criticism that outsourcing to India threatens privacy.
Channel 4 and The Sun newspaper have both conducted investigations in which poor privacy and data security were exposed in outsourcing agreements to Indian companies. A reporter for Channel 4's Dispatches programme was offered hundreds of thousands of banking and financial profiles for sale after investigating India's call centre industry.
Nasscom (the National Association of Software and Services Companies) will be able to refer breaches to the police and will offer certification of privacy policies to companies.
While the new body may refer cases to the police, as may anyone, there is still doubt about the strength of data protection laws in India. Though the Government amended the Information Technology Act (ITA) late last year to punish data theft, there is still no single piece of data protection legislation in India to compare with that in the UK.
The legal changes last year included creating fines of up to $1m for companies or people who fail to stop data theft or leakage. The move was in response to significant concerns over the reputation of the massive Indian outsourcing industry.
Nasscom had previously made recommendations to the Indian government about changes to the ITA. It said last October that the changes made then met most of their concerns.
Copyright © 2007, OUT-LAW.com
OUT-LAW.COM is part of international law firm Pinsent Masons.

Implementing Energy Efficient Data Centers [WP114]
An Improved Architecture for High-Efficiency, High-Density Data Centers [WP126]
Web application security [3-2APYM3X]
Securing your Online Data Transfer with SSL
The Register Guide to Extended Validation

Inmate hacked prison network, broke into employee database
Miscreants hijacking machines via (freshly patched) Adobe flaw
Martial law planned for Craigslist's red-light district
Cocaine addicted IT manager hacks ex-employer's mail servers