Q19 · UPSC Civil Services Mains 2018 · GS III · 15 marks · 4 min read

← Q10 Q20 →

Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks).

Topic: Cyber Security and Money Laundering. Syllabus: Challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security; money-laundering and its prevention. Same official PYQ from year-wise 2018 and Cyber Security and Money Laundering.

Revision summary

The 2018 Srikrishna Committee drafted a Personal Data Protection Bill after the Puttaswamy privacy judgment. Strengths are fiduciary duties, consent and purpose limits, user rights, a DPA with penalties, and a localisation push for enforcement. Weaknesses are broad State exemptions, weak real consent, start-up costs of localisation, and an incomplete surveillance reform. A DPA that is not independent cannot police either Big Tech or the government. Cyberspace protection needs the State under the same law as the company.

Model answer

Copper italics in this answer — like this — are the key facts. Each one is unpacked in the Facts & figures rail.

Introduction

In a digitised India, Aadhaar, phones, banks, and platforms hold intimate personal data, and cyber-crime feeds on leaks. The Justice B. N. Srikrishna Committee (report and draft Personal Data Protection Bill, 2018) tried to give Indians rights and the State a Data Protection Authority. The report is strong on a fiduciary model and consent. It is weak where the State exempts itself and where localisation and surveillance sit in tension with privacy.

Body

What the report set out to do

  • It treated privacy as a fundamental interest after the Supreme Court’s Puttaswamy (2017) judgment, and it drafted a law rather than only a lecture.
  • It defined personal data, sensitive personal data, and data fiduciaries (those who decide why data is processed), with duties of fair and reasonable processing.
  • It proposed a Data Protection Authority of India with codes, inquiries, and penalties that could hurt a firm’s turnover, which is a real deterrent on paper.

Strengths for personal data in cyberspace

  • Rights bundle: confirmation, access, correction, data portability, and a right to be forgotten (with a balancing test) give the user tools against a platform, not only a grievance tweet.
  • Consent is meant to be free, informed, specific, and capable of withdrawal; purpose limitation and collection limitation fight the silent vacuum-cleaner of apps.
  • Data localisation: at least one serving copy of personal data in India, and critical personal data only in India, was meant to help enforcement and sovereignty against a server in another country.
  • Children’s data, health and finance as sensitive classes, and privacy by design duties on fiduciaries match the way cyber-crime actually harvests lives.
  • Fiduciary–processor split and data audits / data protection officers for significant fiduciaries copy a GDPR-like professionalism that Indian IT rules (2000/2011) never fully built.
  • The report saw Aadhaar and State data as needing a statute, not only a contract, which is a strength after years of executive collection.

Weaknesses

  • Wide State exemptions for security, legal process, and some government processing can hollow out the same rights the report gives against a private app; cyberspace harm is often a State or police database as well as a company.
  • Consent in Indian markets is still a tick-box; the report under-weighted dark patterns and the poverty of real choice when a service is a monopoly.
  • Data localisation raises cost for start-ups, may not stop foreign intelligence, and can centralise a honeypot for attackers if Indian security is weak.
  • The Authority’s independence (appointments, funds, directions) was not fortress-strong; a weak DPA cannot police either Big Tech or the Union.
  • Surveillance reform (legal interception, judicial warrant) was not fully joined to the data Bill; personal data protection without a surveillance law is half a shield.
  • Non-personal and anonymised data, later a separate political fight, was thin; re-identification is a cyber risk the 2018 text did not finish.
  • Criminal cyber-crime procedure (investigation copies of phones and clouds) can clash with the rights chapter unless the two codes are read together.

Way forward

  • Pass a data law whose State exemptions are narrow, listed, and reviewable, not a second Official Secrets net.
  • Pair it with surveillance and encryption rules that a court can test.
  • Make the DPA as independent as a regulator that can fine a ministry’s vendor, not only a start-up.
  • Use localisation only for truly critical data, with security investment, not as a slogan.
  • Treat consent plus duty of care (fiduciary fairness) as the daily tool against cyber misuse.

Flow diagram

flowchart TD
  P[Puttaswamy privacy] --> R[Srikrishna Report 2018]
  R --> RG[User rights consent fiduciary]
  R --> DPA[Data Protection Authority]
  R --> W[State exemptions localisation gaps]
  RG --> PROT[Personal data in cyberspace]
  DPA[DPA] --> PROT[PROT]
  W[W] --> PROT[PROT]

Conclusion

The Srikrishna Report’s strength is a rights-based fiduciary statute, a regulator, and a serious draft after Puttaswamy. Its weakness is a State that can step outside those rights, an unfinished surveillance debate, and localisation that may cost more than it protects. Personal data in cyberspace will be safer when the law binds government as tightly as it binds the platform.

Quick related

Students also ask

Same topic · past papers

UPSC has asked this before

These previous-year questions sit on the same topic. Open one to practise the earlier ask.

  1. 2024 · Q10 · GS III · 10 marks

    Describe the context and salient feature of Digital Personal Data Protection Act 2023.

    View answer →

More from this topic

Q20 · UPSC Mains 2026 · GS III · 15 marks · Solution

Discuss counterfeit currency and money laundering as major sources of terror funding in India. State the actions being taken at International level to check these menaces. Highlight the role of Financial Action Task Force (FATF) and methods of compliance by its member states in preventing terror funding.

Cyber Security and Money Laundering

Counterfeit currency and money laundering are primary conduits for financing terrorism in India, exploiting porous borders and digital vulnerabilities. Internationally, multilateral conventions, UN resolutions, and intelligence-sharing networks operate to disrupt illicit financial flows. The Financial Action Task Force (FATF) sets global standards through its recommendations, compelling member states to implement strict legal, regulatory, and institutional frameworks. Compliance requires robust domestic anti-money laundering laws, designated non-financial businesses regulation, and suspicious transaction reporting. Strengthening public-private partnerships and cross-border cooperation remains vital for choking terror supply lines.

Q9 · UPSC Mains 2026 · GS III · 10 marks · Solution

Explain how fake news and disinformation pose threat to Internal Security and Public Order in Indian context? In this regard, discuss salient features of amendments in respect of Information Technology (Intermediatory Guidelines and Digital Media Ethics Code) Rules 2021.

Cyber Security and Money Laundering

• Fake news fuels communal riots, radicalizes youth through encrypted apps, and destabilizes democratic trust. • Cross-border adversaries weaponize disinformation as an asymmetric threat against India's internal security. • The 2021 IT Rules amendments mandate India-based key officers: Chief Compliance, Grievance, and Nodal Contact. • Intermediaries must use automated tools for due diligence and remove unlawful content within strict timelines. • Designated government bodies are empowered to flag and remove fake news related to central government business. • Effective mitigation requires balancing strict regulatory oversight and traceability with the protection of fundamental rights.

Q19 · UPSC Mains 2022 · GS III · 15 marks · Solution

What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

Cyber Security and Money Laundering

Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.

PDF