What is digital identity and why do we need to protect it, in Pakistan of all the places? With globalization and outsourcing on the rise privacy and Identity theft is fast
becoming a global problem. Here are a few reasons for concern regarding
privacy and data protection in Pakistan: rise in banking and consumer
credit industry, surging number of telecom subscribers, outsourced
data processing and grwoth of E-commerce transactions. I’ll provide
some background, discuss the existing rules and provide recommendations
for business organizations.

The…

" />

Privacy and Identity Protection in Pakistan

March 15, 2007 10:15 am 0 comments

Share this Article

Author:

This post was originally published by Babar Bhatti in the TelecomPK blog, and it is being cross-posted here.

—-

What is digital identity and why do we need to protect it, in Pakistan of all the places? With globalization and outsourcing on the rise privacy and Identity theft is fast
becoming a global problem. Here are a few reasons for concern regarding
privacy and data protection in Pakistan: rise in banking and consumer
credit industry, surging number of telecom subscribers, outsourced
data processing and grwoth of E-commerce transactions. I’ll provide
some background, discuss the existing rules and provide recommendations
for business organizations.

The question is: do we have adequate identity and privacy protection
in Pakistan? Are banks and telecom companies doing enough to keep your
personal information safe? As one example, I was sent phone bills of
someone else via e-mail and even after reporting the issue there was no
followup. Probably similar incidents have happened with others in
Pakistan as well, though statistics are not readily available.

My prediction is that gradually Asian societies (Pakistan, China, India etc) will become more sensitive to data protection and privacy issues. Now is a good time to demand good security practices to safeguard our data.

As a related item I’ll mention theITU Internet Report entitled “digital.life” (in pdf), which was prepared for ITU TELECOM World 2006 . The report examines how innovation in digital technology is radically changing individual and societal lifestyles.

Chapter four, identity.digital,
explores the changing nature of the digital individual and the need for
greater emphasis on the creation and management of digital identity.
Individuals today spend more and more time using digital means to
communicate and transact, be that sending and receiving e-mail, talking
on a mobile phone, participating in a social networking site, buying
music, booking vacations over the internet, or playing an online
game. The complexity of the interaction between technology, personal
consumption and the construction of identity in the virtual space is a
growing area of research. Users of digital technologies have a wide
scope for constructing their virtual identity.

What are the laws for data and privacy protection in Pakistan? I found a final draft of the Electronic Data Protection Act 2005 at Pakistan Software Export Board [PSEB] website.
It is a relatively short and simple document which provides very
basic rules over data collection, processing and handling. The
Act tries to solve two problems: a) provide guidelines for outsourced
data processing and b) data collection regulation in Pakistan. To give
you a flavour of this Act here are 2 definitions from it:

“Sensitive Data” means data revealing
racial or ethnic origin, religious, philosophical or other beliefs,
political opinions, membership in political parties, trade unions,
organizations and associations with a religious, philosophical,
political or trade-union, or provide information as to the health or
sexual life of an individual and financial, or proprietary confidential
corporate data.

Electronic data security. Electronic data that is
subject to data processing shall be kept under custody, controlled or
processed in such a way as to minimize the risks of its destruction or
loss, even accidental, unauthorized access, unlawful processing or
processing for purposes other than those for which the electronic data
were collected, by means of appropriate precautionary security measures.

I would like to hear more from those who are involved in data
processing in Pakistan and get some stats about security breaches and
their resolution. A few years ago there was some uproar in the US about
a data processing company in Pakistan but that issue was settled.
Perhaps that incident also contributed to the implementation of
Electronic Data Protection Act 2005.

What is the situation in the developed (or G7) world? European
Union has stricter standards than US, where laws vary from state to
state. The privacy legislation in California is worth mentioning here.
State of California is considered by many to be the most strict
regarding privacy and identity issues. California has setup a privacy office for this purpose and you can find the legislature details here .

Based on California’s laws Forrester Research recommends the
following practices for Business organizations – these recommendations
can be applied to any organization:

Pick a framework. The establishment of reasonable
security is best built on a foundation that is recognized and accepted.
ISO17799 is currently the leading and most accepted framework to build
an information security program around. The framework provides a
standard architecture to document controls and make sure that
everything is covered.

Identify and classify information. The focus of
reasonable security is around personal California resident data.
Security is first established by classifying this data — define it,
assign information owners, establish controls —and identifying where in
the organization this information resides. Personal data may be
classified into subcategories such as employee data and customer/client
data.

Determine business partners that touch your data.
Identify which business partner relationships touch and store personal
data; this is a critical element that is directly addressed in the
legislation. Your organization’s liability does not stop with
organizational boundaries — you are required to see adequate security
is established in third-party relationships.

Document controls. Utilizing the framework as a
structure, the next step is to document the detailed controls in place
to line up with the framework. This gets into the depth of defining
your policy, operational, contractual, and technical controls in place
to protect personal information.

Validate controls. Establishing reasonable security
does not stop with documenting controls. In fact, documenting controls
that you do not have in place may only open the doors of liability
wider. It is necessary to demonstrate that controls are implemented and
working as defined in your security control architecture.

A few words about outsourcing and data security. As more firms enter
into outsourcing agreements, liability coverage especially for data
security and protection becomes more critical. While outsourcers are
unlikely to accept unlimited liability, customer organizations can
insert limits of liability into their contracts and receive cost
reimbursement for any incidents that the outsourcer is responsible for,
if they are willing to aggressively negotiate. However, customers must
be aware of the real consequences and costs associated with enforcing
these clauses or they may find that these clauses have very little real
impact. Customers need to protect themselves in outsourcing agreements,
but they must balance those needs with realistic expectations from
their vendor.

Share :
  • Print
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • email
  • Twitter

Facebook comments:

Leave a Reply


*

Recent Posts

  • General Business Incubation: False Hopes and Shattered Dreams…

    Business Incubation: False Hopes and Shattered Dreams…

    When a 19th century romantic French writer by the name of Victor Hugo said “Nothing is as powerful as an idea whose time has come” he obviously could not envision Pakistani bureaucracy. Not only can it reduce an idea to nothing more than its meager skeletal remains squirming in its own vile, it too often does.

    Come 2004, the IT bubble is about to burst in a military run, democratic, American influenced politically independent subcontinent country by the name of Pakistan. It is here in our story that along comes an idea. It is a simple idea yet revolutionary in every way, the idea to prepare this country for the…

    Read more →
  • Events General Home & Cars Expo 2012

    Home & Cars Expo 2012

    The past whole week I was really excited about going to the exhibition on 5th and 6th at expo center Lahore since the theme read “home expo and super car expo”. I was counting on seeing some innovative home solutions, fancy cars and a lot of appliances for both. As I entered the arena, an ear piercing heavy bike engine race greeted me. Oh wow nice, we have bikes here too… and lots of them, but let’s see if we have the actual products that are expected.

    First cars!! Honda Launched its new City Aspire at the event. This attracted a lot of young crowd who wanted to check it…

    Read more →
  • General Rock the ball with Pepsi

    Rock the ball with Pepsi

       NOTE: This is a sponsored post

    Football. The most popular sport in the world. That may be hard to believe, we being a die-hard cricket nation, but there are many amongst us who get their blood pumping whenever our favorite team kicks some balls (pun intended).  There’s excitement in the air, and the airwaves for that matter, when Spanish rivals Real Madrid and Barcelona are about to have a face-off on the field. Manchester United or Chelsea? The answer could incite either jeers or cheers, depending on who you’re surrounded by. It feels like you belong to an exclusive club really, not to mention how convenient it is to…

    Read more →
  • Coffee Session General Another SHAM ICT Funding Project

    Another SHAM ICT Funding Project

    There are two main things that are currently causing out growth in ICT to stall. One is the lack of original ideas, so most of the entrepreneurs either copy what is already around internationally or locally (same ideas of online shopping, online bidding) we still have not hit the jackpot with someone creating some thing like instagram or drawsomething and being acquired by one of the big names.

    The second issue always lamented by entrepreneurs is lack of any funding sources in Pakistan. Over the years we have seen efforts being made to create funds which would help but what ended happening that most of these funds either did…

    Read more →
  • Coffee Session General 8th Layer of Networking

    8th Layer of Networking

    We all know about the 7 layers of the OSI model. This is the framework by which computer networks are defined. Starting with the physical layer, going through the transport layer and finally culminating in the application layer where end user applications reside. I believe that this should be redefined to include and additional layer – the Social Layer. From the current vantage point, the Social Layer lies right above the Application layer – hence it is served by the Application layer.

    The 90s witnessed a boom in what is now referred to as web 1.0. This consisted of static applications hosted over the web. Static applications meant that…

    Read more →
  • General Mobile Apps Software & I.T. Pakistani IT company TenPearls launches car racing game with a bang

    Pakistani IT company TenPearls launches car racing game with a bang

    Pakistani IT industry has been progressing rapidly over the last few years. It is heartening to see that the industry players are innovating and working in different areas to establish their expertise.

    Recently, TenPearls, one of the leading IT companies of Pakistan, launched “Carumba!”, a 3D car racing game for iPhone and iPad. Carumba! has been designed and developed by TenPearls’ innovation labs. Launched as a free game, Carumba! allows users to earn coins during the race, and redeem them to unlock other cars and tracks or to get additional nitro boosts. It has also been integrated with Apple’s Game Center.

    The game has received very good response from…

    Read more →
  • Events General TEDx Event 2012

    TEDx Event 2012

    ‘Rethinking Pakistan’ [and my expression goes LOL and I will explain why] was the theme of the conference which took place at margalla hills Islamabad on March 31st 2011 organized by TEDx, lets just summarize here what TEDx is; before we further dig into the “theme” and happenings of this conference.

    TED (Technology, Entertainment and Design) and ’x’ denotes the independently organized events under the TED umbrella, mission is “Ideas worth spreading” and this events basically brings together individuals, communities and organizations with the opportunity to excite dialogue through TED-like experiences at the local level (geographically). The programs combine live presenters, performers and pre-recorded talks from some of the most brilliant…

    Read more →
  • Announcements Events General ICT Funds Final Projects

    ICT Funds Final Projects

      ICT R&D Fund aims to provide graduating students a chance to really make their final projects counts. I have always felt that students in their final year some times product excellent products which due to lack of any infrastructure and proper guidance plus funding just go in the Universities Libraries.

    Seems ICT R & D fund is giving these students a chance to take their projects to the next level by acquiring funding, if you are a final year student doing a project all you need is to get this form filled and submitted through your head of department .
    Last date for submission for forms is 31st

    Read more →
  • Coffee Session General Thiel Fellowship: right idea, wrong approach

    Thiel Fellowship: right idea, wrong approach

    I wanted to discuss the Thiel Fellowship and sort of run the idea among our readership to figure out if it was justified or not. Bay Area hedge fund manager Peter Thiel started a Fellowship program in his name about a year ago trying to capitalize not on start ups, but the smart kids who may actually come up with the next billion dollar idea.

    Let there be no mistake. Innovation solves problems. Bankers, lawyers and hot shot executives are good for only one thing: managing an existing infrastructure. It is the innovators who turn existing ideas on to their heads and enable breakthroughs. Considering the point above, it…

    Read more →