India asks WhatsApp to withdraw new privacy policy over ‘grave concerns’
techcrunch.com
techcrunch.com
It’s not unusual for shops to demand a telephone number during even small purchases, and your number will be spammed with SMS ads shortly thereafter. Also email spam if they somehow get your email.
Chat archives (possibly backups?) of people under investigation have been leaked to the media with no consequence to the leaker.
Essentially it’s an extreme “laissez-faire” environment, one almost out of a textbook example of what happens in the absence of any regulation whatsoever.
The above doesn’t have anything to do with Facebook or WhatsApp (except tangentially), it’s just to note that privacy legislation would be a very helpful quality of life improvement for many Indians.
Perhaps someone on HN who knows more about this can share why the efforts to have privacy legislation in India have so far been unsuccessful.
This ruling was one the the landmark rulings in recent times, and a true David vs Goliath story - where a small group of privacy activists won against mandatory Aadhaar.
While it is true that right to privacy implementation remains patchy, there is growing awareness around privacy - both from government, and against large corporations. For example, half of my contact list is now on Signal and last week I had more chats on Signal than on WA.
On that note, a pro tip for anyone incorporating a company in India. Give a separate email id, phone number when you incorporate because as soon as its available on the MCA(Ministry of Corporate Affairs) database the brokers buy it for (~ INR 100/ ~1.37 USD) legally and put it out for sale to the spammers/scammers often displaying the email id publicly.
It will feel intuitive to give your personal phone, email in the forms when starting a company but you'll regret it. I'm waiting for the Data-Privacy legislation to be passed, so I can sue the X out of these brokers; Until then I'm creating an account with these brokers to delete my own details and if not possible then updating it with fake data.
In section titled "Part 3: Becoming Data Rich" of the above article, they talk about the privacy protection legislations that are going to be implemented in India. Adding the part that caught my attention below:
___
Data Empowerment and Protection Architecture (DEPA) is a policy framework that defines how the economic primitive of data can be freed up so that individuals and businesses can choose how to best protect it and use it for their own gain. This innovation, which is presently being rolled out in the financial services industry, has its philosophical roots in a piece of impending legislation known as the Personal Data Protection Bill (PDP).
According to this bill, Indians will (for the first time) get a litany of new rights pertaining to their data. Specifically, they will get the following rights:
The right to data confirmation: The right to know what data is being stored about them, how it has been processed, and who else it might have been shared with
The right to data correction or erasure: The right to update their data stored with a service provider, in order to make corrections, edits, and omissions of data that is no longer relevant
The right to be forgotten: The right to have their data deleted from a service provider’s database should they withdraw their consent to its continued storage
The right to data portability: The right to obtain and share their data in a structured and machine-readable format
It exempts government and give them more power over data held by the private companies in later amendments.
Proper enforcement capacity is also needed otherwise it will be abused to selectively target companies and startups but make little difference in privacy.
Most Indians are not rich enough to afford paying for multiple software subscriptions monthly. They give away privacy as a substitute for that. Market forces at play.
Whenever that rule gets passed it's going to put a real squeeze on a lot of mid-large sized companies that have been playing fast and loose for a while. Facebook would definitely be violating many different parts of the law
Ah india also has anti piracy laws but that's a story for another time
[1] https://internetfreedom.in/why-is-porn-being-blocked-in-indi...
In India, WhatsApp is much more ubiquitous than any other platform and penetrates even the lesser developed regions - if one has a smartphone in India, it almost always has WhatsApp on it. It is even available on some feature phones in the country. "Texting" in India means sending a WhatsApp message.
Additionally, WhatsApp also acts as a mobile payments platform in India. Although not very popular yet, it is increasingly becoming a significant sales and support platform for many businesses.
I had no idea. Not something that’s in U.K. yet.
See the official stats here: https://www.npci.org.in/what-we-do/upi/upi-ecosystem-statist...
"The sanctity of personal communications needs to be maintained.."
LOL. Seems govt IT cell has freaked out seeing one of their propped journalist whatsapp chat leaked.
WhatsApp admins are made to "register" their groups with local police station and I have a relative who manages one group. Had to frequently visit the police because of his "posts" which are only news forwards but they want their views put to public. I read on twitter the police install that WhatsApp malware on their phones so it can propagate through these news groups. No confirmation on this but just saying.
Then you have this crackdown on dissent whereby forwards and messages and statuses crticial to govt are arrested and literally tortured. I know because friends have taken a beating on more than one occasion.
This is damage control by govt on behalf of the company because that allows their users to not jump ship and govt can maintain surveillance
Edit1:
https://www.financialexpress.com/india-news/big-crackdown-ag... Edit 2:
http://thekashmiriyat.co.uk/after-facebook-now-whatsapp-star...
https://kashmirlife.net/youth-arrested-for-misusing-social-m...
> “He has been also found involved in misusing of social media platform by creating fake accounts and posting seditious and provocative posts for antinational activities which are highly prejudicial in maintaining law and order,” he added.
So speak anything critical to govt means antinational and sedition and that needs arrests?
https://www.aa.com.tr/en/asia-pacific/india-launches-fresh-c...
This one while not directly related to WhatsApp does makes a point to explain how the govt is using social media in most productive manner which is benefical to the society.
The central government in India has no interest in the privacy of residents or citizens. This government argued in the Supreme Court that Indians do not have the right to privacy in the constitutional case about it a few years ago (fortunately, the Supreme Court disagreed and declared that privacy as a fundamental right is read in/through a few articles in the constitution). This government also sold vehicle registration and related data to several entities for money.
It has pushed the poorly designed and poorly implemented Aadhaar biometric identity for residents for almost everything, resulting in denial of service and also deaths (including starvation deaths of kids) due to people not getting their entitlements.
This government hurriedly got a couple of private companies (Make My Trip and 1mg) to develop a “contact tracing app” called Aarogya Setu for COVID-19 that requires 24/7 location access and Bluetooth to be on as well. The data from the apps is stored in central servers that these private companies have access to (a right to information request showed that the government isn’t really aware who engaged the companies or what the relationship with the government is). The application was declared to be open source but the sources have been old versions released a long time after, and have little bearing to what’s in the app stores.
India still doesn’t have a privacy law (personal data protection law). It has been in the works for a very long time, though broad reasoning in the draft gives the government the power to compel anyone to provide data.
The recent suspensions of prominent politicians in the U.S. by major tech companies has triggered the ruling party and the central government to worry about the “control” that these companies wield. The government is worried that its own propaganda troll armies (called “IT cell” locally) will start facing such issues.
The ministry that wrote to WhatsApp to not implement the new policy wouldn’t even know that WhatsApp has been sharing information with Facebook since 2016 (when it temporarily allowed some users to opt out, which most didn’t because they didn’t understand or care about the implications).
The government, faced with farmers agitating against recent laws and unwilling to accept anything but a repeal of those, seems to consider this as a time to gather some goodwill by making WhatsApp kneel to show who’s the boss in the country (both the carrot and the stick here are WhatsApp Pay’s sustainability and future).
P.S.: I haven’t listed sources for the claims made above, because all of them, except for the personal speculation about why the government is doing this, can be verified from authentic news sources online.
https://www.notion.so/UrbanNazi-com-Uncovering-the-Nexus-of-...
The BJP IT cell is bigger, better and more organized. It's India's state of the art. Dismissing the work being done here is a bit insulting to people working very hard to make it seem they do no work at all.
n for bjp accounts analyzed = 2,71,579 accounts
n for congress = 1,22,023 accounts.
Its fascinating stuff.
Also what you find is that internet forums usually get the people who are unhappy. The happy people aren't online. During the congress' tenure you had EVERYONE crying against the congress and everyone was a BJP supporter.
Today the roles have reversed. I bet it switches if the BJP drops from power.
so it can either be that it is a fundamental right, in which case my rights have been trampled and there is no recourse or it is not a fundamental right, and i can go fuck myself for being born here because i have to suffer because the govt gets a boner talking about the land because it gets them votes.
unbelievable
search for "temporary". this is from the govt. What fearmongering is this?
students have been unable to attend schools since 5 august 2019 and you make 8 million humans suffer because of a boogeyman which doesnt exist? hasn't the recent arnab leaks suggested that pulwama was a false flag along with arnab getting prior info about something like balakot? if this is true and factually it does look like it, so who is the boogeyman? if allegedly india did pulwama attack on its own people and blamed kashmiri militants for it and pakistan for aiding them which has led to the crackdown on militancy in kashmir and this supposedly "anti-national" elements which in reality don't exist so why are we suffering?
if modi wants to fuck himself over the blood of indians to stay in power, do it but why am i suffering?
How does this work if someone outside of the EU is in the same group or private chats as an EU user?
Surely by sharing information about those chats they would be breaking the GDPR if that's the case.
(I assume they have or will come up with a work-around, as far as legally possible)
Chat messages in themselves are not necessarily PII, but then again WhatsApp isn't claiming to freely read the messages. I suppose the messages in the chat could be mined for keywords to give ads to the non-EU/EEA persons.
The same is not true for all the metadata.
No. In law, EU GDPR absolutely does not cover EU citizens who are physically outside the EU.
GDPR makes no reference to citizens or residents and is understood to apply to any person whenever they are physically present in the EU, and to data which is created/located physically inside the EU's borders (and to data which has crossed the border within the rules).
Citation e.g. first search result https://www.hipaajournal.com/does-gdpr-apply-to-eu-citizens-... which suggests only that businesses might find it easier to give GDPR protections more widely. I would not expect that advice to be taken by Facebook.
The user’s phone number is a unique ID as far as WhatsApp is concerned, so any metadata related to phone numbers in the “European region” (eg numbers starting with +33, +44, +49, etc) would be treated as if the 2020-era privacy policy applies.
That was my case until recently, and of many other expats I know.
I know looking at a phone number’s country code is imperfect, but pretty much every other method is problematic too.
* the most explicit would be for EU residents to contact WhatsApp with proof of residency. Unfortunately it creates a vast bureaucracy and most people should be wary of sharing scans of their documents, with Facebook of all companies.
* The WhatsApp app could look at which network the phone it’s on is connected to. If it’s a EU network (say connected to a EU network for 6+ months to filter out tourists), protections could apply, but I this would probably adversely impact EU nationals in non-EU countries.
So yes, a number of options are possible, each have pros and cons. How far Facebook would go would depend on regulatory direction, almost certainly.
https://iapp.org/news/a/indias-data-privacy-bill-under-commi...
PDPB bill itself: https://iapp.org/media/pdf/resource_center/India_Draft_Perso...