This is an archive article published on June 13, 2023
Premium

Apar Gupta writes on CoWIN breach, Jack Dorsey claims: Digital India is not built on the Constitution

In Digital India, individual harms are left unaddressed and the creation of regulatory and institutional frameworks is rejected to favour the mirage of innovation

jack dorseyAs news media and Twitter trended the CoWIN data breach, later in the day former Twitter CEO Jack Dorsey stated that the Indian government coerced Twitter with censorship directions regarding the farmers' protest with threats to the platform's continued operations and staff safety in India. (File/PTI)
Written by: Apar Gupta
7 min readJun 14, 2023 10:05 AM IST First published on: Jun 13, 2023 at 06:22 PM IST

On June 12, three events occurred that demonstrate a gulf between the rhetoric and reality of Digital India. In the morning readers of the Malayala Manorama were greeted with the front page news of a data breach on the CoWIN platform (first reported on the online portal, “The Fourth”). Sensitive personal details including date and place of vaccination, with Aadhaar, PAN, Passport, Voter ID, & Mobile numbers were circulating on the internet-based messaging platform Telegram. Though details of the breach were established by many, the Union Government responded with denials. This was first done by the Ministry of Health and Family Welfare which termed the reports, “mischievous”, while Rajeev Chandrasekhar, Minister of State, Ministry of Electronics and IT (MEITY) tweeted that sensitive information had emerged from, “previously stolen data”. Towards the evening an extensive statement was made through the Press Information Bureau (PIB) which claimed that, “Co-WIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy.”

Such self-serving statements are by now a template for public officials that rely on bluster to overcome a media maelstrom. After all, there have been denials and opacity in the investigations of previous data breaches in the public sector – these include the Employees’ Provident Fund Organisation (EPFO) breach in August 2022 and the ransomware attack on the All-India Institute of Medical Sciences (AIIMS) in November 2022. The Computer Emergency Response Team (CERT-In), which is tasked with such investigations, has often maintained silence and not made any of its technical findings public. This has eroded citizens’ trust. All this is compounded by the lack of a National Cyber Security Strategy — a draft put to public consultation in December 2019 awaits finalisation. Also, India does not have any data protection law requiring breach notifications to impacted users. Even the proposed Draft Digital Personal Data Protection Bill, 2022, being mooted by MeitY would by notification exempt government entities from compliance. Without any legal accountability, repeated data breaches now occur within the same entity or platform such as the RailYatri portal that has reportedly been breached in 2020, 2022 and 2023.

Latest Comment
Post Comment
Read Comments