Business Standard

Aadhaar isn’t progress — it’s dystopian

India should pause its further roll-out until a comprehens­ive law protecting individual security and privacy is passed

- MITCHELL BAKER & ANKIT GADGIL

Imagine your government required you to consent to ubiquitous stalking in order to participat­e in society -- to do things such as log into a WiFi hotspot, register a SIM card, get your pension, or even obtain a food ration of rice. Imagine your government was doing this in ways your Supreme Court had indicated were illegal.

This isn’t some dystopian future, this is happening in India right now. The government of India is pushing relentless­ly to roll out a national biometric identity database called Aadhaar, which it wants India’s billion-plus population to use for virtually all transactio­ns and interactio­ns with government services.

The Indian Supreme Court has directed that Aadhaar is only legal if it’s voluntary and restricted to a limited number of schemes. Seemingly disregardi­ng this directive, Prime Minister Narendra Modi’s government has made verificati­on through Aadhaar mandatory for a wide range of government services, including vital subsidies that some of India’s poorest citizens rely on to survive. Vital subsidies aren’t voluntary.

Even worse, the government of India is selling access to this database to private companies to use and combine with other datasets as they wish. This would allow companies to have access to some of your most intimate details and create detailed profiles of you, in ways you can’t necessaril­y see or control. The government can also share user data “in the interest of national security,” a term that remains dangerousl­y undefined. There are little to no protection­s on how Aadhaar data is used, and certainly no meaningful user consent. Individual privacy and security cannot be adequately protected and users cannot have trust in systems when they do not have transparen­cy or a choice in how their private informatio­n will be used.

This is all possible because India currently does not have any comprehens­ive national law protecting personal security through privacy. India’s Attorney General has recently cast doubt on whether a right to privacy exists in arguments before the Supreme Court, and has not addressed how individual citizens can enjoy personal security without privacy.

We have long argued that enacting a comprehens­ive privacy and data protection law should be a national policy priority for India. While it is encouragin­g to see the Attorney General also indicate to the Supreme Court in a separate case that the government of India intends to develop a privacy and data protection law by Diwali, it is not at all clear that the draft law the government will put forward will contain the robust protection­s needed to ensure the security and privacy of individual­s in India. At the same time, the government of India is still exploiting this vacuum in legal protection­s by continuing to push ahead with a massive initiative that systematic­ally threatens individual­s’ security and privacy. The world is looking to India to be a leader on internet policy, but it is unclear if Prime Minister Modi’s government will seize this opportunit­y and responsibi­lity for India to take its place as a global leader in protecting individual security and privacy.

The protection of individual security and privacy is critical to building safe online systems. It is the lifeblood of the online ecosystem, without which online efforts such as Aadhaar and Digital India are likely to fail or become deeply dangerous.

One of Mozilla’s founding principles is the idea that security and privacy on the internet are fundamenta­l and must not be treated as optional. This core value underlines and guides all of Mozilla’s work on online privacy and security issues—including our product developmen­t and design decisions and policies, and our public policy and advocacy work. The Mozilla Community in India has also long sought to empower Indians to protect their privacy themselves including through national campaigns with privacy tips and tools. Yet, we also need the government to do its part to protect individual security and privacy.

The Mozilla Community in India has further been active in promoting the use, developmen­t, and adoption of open source software. Aadhaar fails here as well.

The government of India has sought to soften the image of Aadhaar by wrapping it in the veneer of open source. It refers to the Aadhaar API as an “Open API” and its corporate partners as “volunteers.” As executive chairwoman and one of the leading contributo­rs to Mozilla, one of the largest open source projects in the world, let us be unequivoca­lly clear: There’s nothing open about this. The developmen­t was not open, the source code is not open, and companies that pay to get a license to access this biometric identity database are not volunteers. Moreover, requiring Indians to use Aadhaar to access so many services dangerousl­y intensifie­s the already worrying trend toward centralisa­tion of the internet. This is disappoint­ing given the government of India’s previous championin­g of open source technologi­es and the open internet.

Prime Minister Modi and the government of India should pause the further roll out of Aadhaar until a strong, comprehens­ive law protecting individual security and privacy is passed. We further urge a thorough and open public process around these much-needed protection­s, India’s privacy law should not be passed in a rushed manner in the dead of night as the original Aadhaar Act was. As an additional act of openness and transparen­cy and to enable an informed debate, the government of India should make Aadhaar actually open source rather than use the language of open source for an initiative that has little if anything “open” about it. We hope India will take this opportunit­y to be a beacon to the world on how citizens should be protected.

 ?? ILLUSTRATI­ON BY BINAY SINHA ??
ILLUSTRATI­ON BY BINAY SINHA
 ??  ??

Newspapers in English

Newspapers from India