Revision summary
The 2018 Srikrishna Committee drafted a Personal Data Protection Bill after the Puttaswamy privacy judgment. Strengths are fiduciary duties, consent and purpose limits, user rights, a DPA with penalties, and a localisation push for enforcement. Weaknesses are broad State exemptions, weak real consent, start-up costs of localisation, and an incomplete surveillance reform. A DPA that is not independent cannot police either Big Tech or the government. Cyberspace protection needs the State under the same law as the company.
Model answer
Flow diagram
flowchart TD P[Puttaswamy privacy] --> R[Srikrishna Report 2018] R --> RG[User rights consent fiduciary] R --> DPA[Data Protection Authority] R --> W[State exemptions localisation gaps] RG --> PROT[Personal data in cyberspace] DPA --> PROT W --> PROT
Conclusion
- Pass a data law whose State exemptions are narrow, listed, and reviewable, not a second Official Secrets net.
- Pair it with surveillance and encryption rules that a court can test.
- Make the DPA as independent as a regulator that can fine a ministry’s vendor, not only a start-up.
- Use localisation only for truly critical data, with security investment, not as a slogan.
- Treat consent plus duty of care (fiduciary fairness) as the daily tool against cyber misuse.
The Srikrishna Report’s strength is a rights-based fiduciary statute, a regulator, and a serious draft after Puttaswamy. Its weakness is a State that can step outside those rights, an unfinished surveillance debate, and localisation that may cost more than it protects. Personal data in cyberspace will be safer when the law binds government as tightly as it binds the platform.
Quick related
Students also ask
-
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks).
Next question on this syllabus topic (2018 · Q20). View answer →
-
Did the 2018 report become the law as written?
No. It was a draft and a policy map. Later bills and the 2023 Act changed many balances. The question is about the report’s own strengths and gaps.
-
Is localisation the same as privacy?
No. Keeping a copy in India can help a summons. It does not by itself stop misuse by an Indian fiduciary or a breach of an Indian server.
PYQ trend
When UPSC asked this
Related PYQs from other years, newest first. Open a question to read it.
-
2021 · Q9 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels. -
2021 · Q10 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks. -
2020 · Q9 · GS III · 10 marks
Discuss different types of cybercrimes and measures required to be taken to fight the menace. -
2019 · Q10 · GS III · 10 marks
What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India. -
2018 · Q20 · GS III · 15 marks
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks). -
2017 · Q9 · GS III · 10 marks
Discuss the potential threats of Cyber attack and the security framework to prevent it. -
2015 · Q18 · GS III · 12 marks
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country. -
2015 · Q20 · GS III · 12 marks
Considering the threats cyberspace poses for the country, India needs a "Digital Armed Forces" to prevent crimes. Critically evaluate the National Cyber Security Policy, 2013 outlining the challenges perceived in its effective implementation.
More from this topic
Q19 · UPSC Mains 2022 · GS III · 15 marks
What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
Cyber Security and Money Laundering
Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.
Q10 · UPSC Mains 2021 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.
Cyber Security and Money Laundering
Cross-border cyber operations can stall critical infrastructure, rob finance, and steal state data without a kinetic raid. Attribution problems let states and proxies hide behind criminal malware. CERT-In, NCIIPC, Defence Cyber Agency, sector CERTs, and the IT Act are the Indian defensive core. Segmentation, backups, vendor control, and phishing defence are the practical layer. Resilience and international CERT cooperation matter more than a claim of perfect security.
Q9 · UPSC Mains 2021 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.
Cyber Security and Money Laundering
Global trade, hawala, shells, and now crypto and mule rails turn criminal cash into apparently clean assets. PMLA, FIU-IND, and regulator KYC are the core national tools. FATF, Egmont, and UN conventions organise the international chase and asset return. Technology also helps investigators if travel rules and chain analysis are funded. Beneficial ownership and virtual assets remain the soft spots.
Toppers' copies
Toppers' copies for this question will be uploaded soon.