Skip to main content

Making e-transactions safer.

SAYAN GHOSAL
The government’s recent demonetisation scheme has given a fillip to digital transactions in the traditionally cash-based economy. Amid the changing times and the plethora of conveniences associated with e-payments, experts have again highlighted the lack of a comprehensive data protection and privacy framework.

The Nilson Report, a trade newsletter covering the card and mobile payment segments, estimates fraud losses incurred by banks and merchants in electronic transactions reached the equivalent of $21.8 billion in 2015. This figure is expected to grow as more and more transactions go cashless. India’s recent brush with transactional fraud, involving 3.2 million debit cards, have highlighted the growing necessity of ensuring safety and security in the digital payment space. Advent of an e-payment regime now places a greater responsibility on the government, corporate entities and citizens alike to spread awareness about the associated risks, to ensure a well-protected financial environment.

India’s data protection scenario is highly decentralised. It is governed primarily through a series of sector-specific laws in individual regulatory spaces. Introduction of a comprehensive law on data protection has been in the pipeline since 2010, without much progress on the ground. A glimpse of a generic data security scheme can be found in certain provisions of the Information Technology Act. Sections 43 and 66C outline criminal provisions dealing with cases of extraction of data without permission and identity theft. Sections 43A and 72A provide for compensation and punishment for disclosures in breach of lawful contracts.

According to Stephen Mathias, partner, Kochhar & Co, though the amount of compensation payable under Section 43A is unlimited, it fails to cover cases involving the government. As a large majority of banking institutions are part of the public sector, the provision seems feeble in protecting the rapidly evolving transactional space.

Section 72A makes the disclosure culpable only when there is an intention to cause wrongful loss or gain. However, such intent is hard to prove, often allowing companies to escape prosecution.

To modernise the regulatory framework in the transactional space, the government introduced the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, laying down guidelines for the collection, possession, storage and dissemination of personal data. These Rules also promote reasonable security practices and require annual due-diligence and audit exercises to ensure conformity.

Additionally, the Banking Codes and Standards Board of India lays down further safeguards on handling of personal data in financial transactions.

However, many of these requirements are optional in nature. One may contractually opt out of these, undermining the effectiveness.

“Till the Reserve Bank of India (RBI) starts penalising banks for non-adherence, its efforts are sure to be lacklustre. Some banks are yet to comply with even the old guidelines and the whole of the cooperative sector is outside the clutches of the regulator,” says Prashant Mali, president, Cyber Law Consulting.

He says RBI should also have separate guidelines for mobile payments. At present, the regulation of these platforms is weak. India’s tryst with encryption standards has further complicated the issue of data security. According to Salman Waris, founder partner, TechLegis, there exists a practical dichotomy between the RBI-mandated minimum standards (128-bit) and the maximum permissible encryption levels (40-bit), allowed by the department of telecommunications (DoT). “This often requires banks to obtain permissions and provide encryption keys to DoT, creating a hurdle in Ease of Doing Business for these entities," he says.

Introduction of a two-factor authentication for online transactions does go a long way in securing digital payments. However, further guidelines on protecting original data sources in banking databases is a must for smooth transition into acashless system. “The government may consider protecting personally identifiable information such as spending patterns, in addition to the current protection awarded to sensitive data. And, an enhanced security framework should always be promoted," says Vaibhav Parikh, partner, Nishith Desai Associates.

According to Sunil Abraham, executive director, Centre for Internet and Society, apart from legislating on an omnibus data protection law, introduction of data protection officers to regulate the market and respond to changes will build confidence and promote a culture of digital payment. Consolidating the multi-layered Know Your Customer (KYC) requirements and proper implementation of the e-KYC system, alongside the development of a secured central digital database, such as Aadhaar, will also give a boost to e-transactions.

“The lack of adoption of electronic payments by merchants is another hurdle to achieving a digital payment regime,” says Rahul Matthan, partner, Trilegal. Under the present system, sellers have to bear several associated costs. These are disincentives for transitioning into a cashless economy. “The government must come up with innovative solutions to encourage vendors to adopt these alternative modes of payment," says Matthan. LAWS APPLICABLE TO E-TRANSACTIONS

28TH NOVEMBER, 2016, THE BUSINESS STANDARD, NEW DELHI

Comments

Popular posts from this blog

New income tax slab and rates for new tax regime FY 2023-24 (AY 2024-25) announced in Budget 2023

  Basic exemption limit has been hiked to Rs.3 lakh from Rs 2.5 currently under the new income tax regime in Budget 2023. Further, the income tax slabs in the new tax regime has been changed. According to the announcement, 5 income tax slabs will be there in FY 2023-24, from 6 income tax slabs currently. A rebate under Section 87A has been enhanced under the new tax regime; from the current income level of Rs.5 lakh to Rs.7 lakh. Thus, individuals opting for the new income tax regime and having an income up to Rs.7 lakh will not pay any taxes   The income tax slabs under the new income tax regime will now be as follows: Rs 0 to Rs 3 lakh - 0% tax rate Rs 3 lakh to 6 lakh - 5% Rs 6 lakh to 9 lakh - 10% Rs 9 lakh to Rs 12 lakh - 15% Rs 12 lakh to Rs 15 lakh - 20% Above Rs 15 lakh - 30%   The revised Income tax slabs under new tax regime for FY 2023-24 (AY 2024-25)   Income tax slabs under new tax regime Income tax rates under new tax regime O to Rs 3 lakh 0 Rs 3 lakh to Rs 6 lakh 5% Rs 6

Jaitley plans to cut MSME tax rate to 25%

Income tax for companies with annual turnover up to ?50 crore has been reduced to 25% from 30% in order to make Micro, Small and Medium Enterprises (MSME) companies more viable and also to encourage firms to migrate to a company format. This move will benefit 96% or 6.67 lakh of the 6.94 lakh companies filing returns of lower taxation and make MSME sector more competitive as compared with large companies. However, bigger firms have shown their disappointment since the proposal for reducing tax rates was to make Indian firms competitive globally and it is the large firms that are competing globally. The Finance Minister foregone revenue estimate of Rs 7,200 crore per annum for this for this measure. Besides, the Finance Minister refrained from removing or reducing Minimum Alternate Tax (MAT), a popular demand from India Inc., but provided a higher period of 15 years for carry forward of future credit claims, instead of the existing 10-year period. “It is not practical to rem

Don't forget to verify your income tax return in August: Here's the process

  An ITR return needs to be verified within 120 days of filing of tax return. Now that you have filed your income tax return, remember to verify it because your return filing process is not complete unless you do so. The CBDT has reduced the time limit of ITR verification to 30 days (from 120 days) from the date of return submission. The new rule is applicable for the returns filed online on or after 1st August 2022. E-verification is the most convenient and instant method for verifying your ITR. However, if you prefer not to e-verify, you have the option to verify it by sending a physical copy of the ITR-V. Taxpayers who filed returns by July 31, 2023 but forget to verify their tax returns, will get the following email from the tax department, as per ClearTax. If your ITR is not verified within 30 days of e-filing, it will be considered invalid, and may be liable to pay a Late Fee. Aadhaar OTP | EVC through bank account | EVC through Demat account | Sending duly signed ITR-V through s