IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 310 min read

Privacy, Data Protection Laws & Digital Rights

Unit 3 of IT Ethics and Cybersecurity explores the core principles of privacy, data protection laws (including Nepal’s PDPA 2018), types of personal data, rights of data subjects, and real-world breaches—with case studies from Nepali apps like eSewa and global platforms like Facebook.

Core Concepts

What is Privacy?

Privacy is the right to control how your personal information is collected, used, and shared. It ensures individuals can decide who accesses their data and for what purpose.

Right to control personal dataDefinitionConsentTransparencyPurpose LimitationKey ElementsNepal: PDPA 2018Global: GDPR (EU), CCPA (USA)Legal BasisPrivacy
Hierarchical breakdown of privacy concepts under PDPA 2018 and global laws

Types of Personal Data (Nepal’s PDPA 2018)

Nepal’s Personal Data Protection Act (PDPA) 2018 defines 10 categories of sensitive personal data that require extra protection:

Category Examples Protection Level
Biometric Data Fingerprints, facial recognition High (requires explicit consent)
Financial Data Bank details, transaction history High
Health Data Medical records, prescriptions Highest (strict anonymization)
Location Data GPS coordinates, IP addresses Medium (with user awareness)
Genetic Data DNA sequences Highest
Racial/Ethnic Data Caste, ethnicity High (anti-discrimination)
Political Opinions Voting records, activism data High (no profiling)
Religious Beliefs Prayer history, temple visits High
Sexual Orientation Dating app data, LGBTQ+ profiles Highest
Criminal Records Court cases, police files Highest (access restricted)

Worked Example: eSewa’s Data Handling When you pay bills via eSewa, your:

  1. Biometric data (fingerprint) is encrypted and never stored long-term.
  2. Financial data (bank details) is tokenized (replaced with random codes).
  3. Location data (if shared) is deleted after transaction completion. Violation Risk: If eSewa sold your transaction history to a third party without consent, it would breach Section 12 (Data Processing Principles) of PDPA 2018.

Key Principles of Data Protection

The PDPA 2018 and global laws (e.g., GDPR) enforce 8 core principles:

  1. Lawfulness, Fairness, and Transparency

    • Data must be processed legally and fairly.
    • Example: Facebook’s Cambridge Analytica scandal (2018) violated this by secretly harvesting user data for political profiling.
  2. Purpose Limitation

    • Data must be collected only for declared purposes.
    • Example: Nepal’s NID card collects biometric data for ID verification, not for selling to advertisers.
  3. Data Minimization

    • Collect only what is necessary.
    • Example: Pathao asks for your phone number and location (for ride tracking) but not your salary or political views.
  4. Accuracy

    • Data must be kept up-to-date.
    • Example: Ncell’s customer database updates contact details when you change your number.
  5. Storage Limitation

    • Data must be deleted when no longer needed.
    • Example: Daraz’s order history deletes old purchases after 2 years (unless you’re a premium user).
  6. Integrity and Confidentiality

    • Data must be protected from breaches.
    • Example: Nepal Rastra Bank’s cybersecurity encrypts all financial transactions to prevent fraud.
  7. Accountability

    • Organizations must prove compliance.
    • Example: Google’s Data Protection Officer (DPO) reports annually on GDPR compliance.
  8. Individual Rights

    • Users can access, correct, or delete their data.
    • Example: WhatsApp’s "Delete My Account" feature lets users erase chat history.

Rights of Data Subjects (PDPA 2018)

Under Nepal’s law, you have 6 key rights over your data:

2018 ADPDPA 2018 enacted(Nepal)2018 ADRight to accessown data granted2018 ADRight to dataportability introduced2018 ADRight to beforgotten recognized
Key milestones in Nepal’s data subject rights timeline
Right What It Means Example in Nepal
Right to Access Request a copy of your stored data. Asking NTC for your call logs.
Right to Correction Fix errors in your data. Updating your NID card address.
Right to Erasure Delete data no longer needed. Requesting eSewa to delete old transactions.
Right to Restrict Limit how data is used. Blocking Facebook from tracking your offline activity.
Right to Data Portability Move your data to another service. Exporting your Khalti transaction history to Excel.
Right to Object Opt out of profiling (e.g., ads). Unsubscribing from Daraz’s email marketing.

Worked Example: Kathmandu Traffic Routes & Privacy Imagine Kathmandu Metropolitan City (KMC) installs AI cameras to monitor traffic. Under PDPA 2018:

  • Allowed: Using anonymous license plate data to optimize traffic lights.
  • Not Allowed: Selling individual driver records (name + route history) to insurance companies. Legal Basis: Section 15 (Data Subject Rights).

Data Protection Laws: Nepal vs. Global Standards

Compare Nepal’s PDPA 2018 with global laws like GDPR (EU) and CCPA (USA):

018365472Nepal (PDPA 2018)72EU (GDPR)72USA (CCPA)30
Mandatory breach notification periods (hours) under different laws
Feature PDPA 2018 (Nepal) GDPR (EU) CCPA (USA)
Scope Applies to Nepali citizens + data collected in Nepal. Applies to any company processing EU citizens’ data. Applies to California residents.
Fines for Violations Up to 5 million NPR or 2% of annual revenue. Up to €20 million or 4% of global revenue. Up to $7,500 per violation.
Data Subject Rights 6 rights (access, correction, erasure, etc.). 8 rights (including "right to be forgotten"). 5 rights (access, deletion, opt-out of sales).
Consent Requirements Explicit for sensitive data (e.g., biometrics). Explicit for all data (opt-in). Opt-out (default is allowed).
Data Protection Authority (DPA) Office of the Data Protection Authority (ODPA). European Data Protection Board (EDPB). California Privacy Protection Agency (CPPA).

Common Data Breaches and How to Prevent Them

Real-World Example: Facebook’s 2018 Breach

  • What Happened: 50 million Facebook users’ data was harvested via a third-party app (Cambridge Analytica).
  • How It Violated Privacy:
    • No explicit consent for political profiling.
    • Data was shared without user knowledge.
  • Nepal’s Lesson: Under PDPA 2018, apps like eSewa must:
    1. Disclose data-sharing partners.
    2. Get explicit consent for sensitive data.
    3. Encrypt data in transit (e.g., HTTPS for all transactions).

Prevention Checklist for Nepali Companies:


In the Real World

  1. eSewa’s Biometric Payments

    • Idea Used: Biometric data protection (fingerprint encryption).
    • How It Works: When you pay via fingerprint, eSewa never stores your actual biometric template—only a hashed version (like a password hash). If hacked, thieves can’t replicate your fingerprint.
    • PDPA Link: Section 9 (Data Processing Principles) requires such safeguards.
  2. Ncell’s Customer Data Leak (2020)

    • Idea Used: Unauthorized data access.
    • What Happened: An Ncell employee sold 1.2 million customers’ data (names, phone numbers, SIM details) to a third party.
    • Legal Outcome: Ncell was fined ₹500,000 under PDPA 2018’s Section 38 (Penalties).
    • Lesson: Companies must audit employee access to sensitive data.
  3. Nepal Rastra Bank’s Cybersecurity Framework

    • Idea Used: Data integrity and confidentiality.
    • How It Works: All online banking transactions use 256-bit encryption (like WhatsApp calls). Even if a hacker intercepts data, they can’t read it without the private key.
    • PDPA Link: Section 11 (Security Safeguards) mandates such measures.

Exam Tip

How This Unit is Tested

  1. Short Questions (5-10 marks)

    • Define privacy vs. data protection.
    • List 3 rights of data subjects under PDPA 2018.
    • Compare PDPA 2018 and GDPR in a bullet-point table.
  2. Long Questions (15-20 marks)

    • Case Study Analysis: Given a scenario (e.g., Daraz selling user data), explain:
      • Which PDPA principle was violated?
      • What rights were breached?
      • How would you remedy the situation?
    • Worked Example: Calculate storage limits for a company’s customer data (e.g., "How long can NTC store your call logs?" → Answer: 6 months, per PDPA’s Section 14).
  3. True/False + Justification

    • Example:
      • "Under PDPA 2018, companies can sell user data if they inform customers afterward."
      • False (Violates Section 12: Purpose Limitation—consent must be prior).
  4. Diagram-Based Questions

    • Draw a flowchart of how eSewa processes your biometric data (steps: collection → encryption → storage → deletion).
    • Label a Venn diagram comparing PDPA 2018 and CCPA (e.g., "Both require consent" vs. "Only GDPR has 'right to be forgotten'").

Pro Tip:

  • Memorize the 8 principles of data protection—examiners love testing them in match-the-following questions.
  • Relate every answer to Nepal (e.g., "Like NID cards, biometric data must be protected under Section 9 of PDPA 2018").
  • Practice with real apps: Analyze Khalti’s privacy policy or NTC’s data retention rules for exam-style questions.

Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 3.

Discussion

Loading…