IT Ethics and CybersecurityUnit 310 min read
Privacy, Data Protection Laws & Digital Rights
Unit 3 of IT Ethics and Cybersecurity explores the core principles of privacy, data protection laws (including Nepal’s PDPA 2018), types of personal data, rights of data subjects, and real-world breaches—with case studies from Nepali apps like eSewa and global platforms like Facebook.
Core Concepts
What is Privacy?
Privacy is the right to control how your personal information is collected, used, and shared. It ensures individuals can decide who accesses their data and for what purpose.
Types of Personal Data (Nepal’s PDPA 2018)
Nepal’s Personal Data Protection Act (PDPA) 2018 defines 10 categories of sensitive personal data that require extra protection:
| Category | Examples | Protection Level |
|---|---|---|
| Biometric Data | Fingerprints, facial recognition | High (requires explicit consent) |
| Financial Data | Bank details, transaction history | High |
| Health Data | Medical records, prescriptions | Highest (strict anonymization) |
| Location Data | GPS coordinates, IP addresses | Medium (with user awareness) |
| Genetic Data | DNA sequences | Highest |
| Racial/Ethnic Data | Caste, ethnicity | High (anti-discrimination) |
| Political Opinions | Voting records, activism data | High (no profiling) |
| Religious Beliefs | Prayer history, temple visits | High |
| Sexual Orientation | Dating app data, LGBTQ+ profiles | Highest |
| Criminal Records | Court cases, police files | Highest (access restricted) |
Worked Example: eSewa’s Data Handling When you pay bills via eSewa, your:
- Biometric data (fingerprint) is encrypted and never stored long-term.
- Financial data (bank details) is tokenized (replaced with random codes).
- Location data (if shared) is deleted after transaction completion. Violation Risk: If eSewa sold your transaction history to a third party without consent, it would breach Section 12 (Data Processing Principles) of PDPA 2018.
Key Principles of Data Protection
The PDPA 2018 and global laws (e.g., GDPR) enforce 8 core principles:
Lawfulness, Fairness, and Transparency
- Data must be processed legally and fairly.
- Example: Facebook’s Cambridge Analytica scandal (2018) violated this by secretly harvesting user data for political profiling.
Purpose Limitation
- Data must be collected only for declared purposes.
- Example: Nepal’s NID card collects biometric data for ID verification, not for selling to advertisers.
Data Minimization
- Collect only what is necessary.
- Example: Pathao asks for your phone number and location (for ride tracking) but not your salary or political views.
Accuracy
- Data must be kept up-to-date.
- Example: Ncell’s customer database updates contact details when you change your number.
Storage Limitation
- Data must be deleted when no longer needed.
- Example: Daraz’s order history deletes old purchases after 2 years (unless you’re a premium user).
Integrity and Confidentiality
- Data must be protected from breaches.
- Example: Nepal Rastra Bank’s cybersecurity encrypts all financial transactions to prevent fraud.
Accountability
- Organizations must prove compliance.
- Example: Google’s Data Protection Officer (DPO) reports annually on GDPR compliance.
Individual Rights
- Users can access, correct, or delete their data.
- Example: WhatsApp’s "Delete My Account" feature lets users erase chat history.
Rights of Data Subjects (PDPA 2018)
Under Nepal’s law, you have 6 key rights over your data:
| Right | What It Means | Example in Nepal |
|---|---|---|
| Right to Access | Request a copy of your stored data. | Asking NTC for your call logs. |
| Right to Correction | Fix errors in your data. | Updating your NID card address. |
| Right to Erasure | Delete data no longer needed. | Requesting eSewa to delete old transactions. |
| Right to Restrict | Limit how data is used. | Blocking Facebook from tracking your offline activity. |
| Right to Data Portability | Move your data to another service. | Exporting your Khalti transaction history to Excel. |
| Right to Object | Opt out of profiling (e.g., ads). | Unsubscribing from Daraz’s email marketing. |
Worked Example: Kathmandu Traffic Routes & Privacy Imagine Kathmandu Metropolitan City (KMC) installs AI cameras to monitor traffic. Under PDPA 2018:
- Allowed: Using anonymous license plate data to optimize traffic lights.
- Not Allowed: Selling individual driver records (name + route history) to insurance companies. Legal Basis: Section 15 (Data Subject Rights).
Data Protection Laws: Nepal vs. Global Standards
Compare Nepal’s PDPA 2018 with global laws like GDPR (EU) and CCPA (USA):
| Feature | PDPA 2018 (Nepal) | GDPR (EU) | CCPA (USA) |
|---|---|---|---|
| Scope | Applies to Nepali citizens + data collected in Nepal. | Applies to any company processing EU citizens’ data. | Applies to California residents. |
| Fines for Violations | Up to 5 million NPR or 2% of annual revenue. | Up to €20 million or 4% of global revenue. | Up to $7,500 per violation. |
| Data Subject Rights | 6 rights (access, correction, erasure, etc.). | 8 rights (including "right to be forgotten"). | 5 rights (access, deletion, opt-out of sales). |
| Consent Requirements | Explicit for sensitive data (e.g., biometrics). | Explicit for all data (opt-in). | Opt-out (default is allowed). |
| Data Protection Authority (DPA) | Office of the Data Protection Authority (ODPA). | European Data Protection Board (EDPB). | California Privacy Protection Agency (CPPA). |
Common Data Breaches and How to Prevent Them
Real-World Example: Facebook’s 2018 Breach
- What Happened: 50 million Facebook users’ data was harvested via a third-party app (Cambridge Analytica).
- How It Violated Privacy:
- No explicit consent for political profiling.
- Data was shared without user knowledge.
- Nepal’s Lesson: Under PDPA 2018, apps like eSewa must:
- Disclose data-sharing partners.
- Get explicit consent for sensitive data.
- Encrypt data in transit (e.g., HTTPS for all transactions).
Prevention Checklist for Nepali Companies:
In the Real World
eSewa’s Biometric Payments
- Idea Used: Biometric data protection (fingerprint encryption).
- How It Works: When you pay via fingerprint, eSewa never stores your actual biometric template—only a hashed version (like a password hash). If hacked, thieves can’t replicate your fingerprint.
- PDPA Link: Section 9 (Data Processing Principles) requires such safeguards.
Ncell’s Customer Data Leak (2020)
- Idea Used: Unauthorized data access.
- What Happened: An Ncell employee sold 1.2 million customers’ data (names, phone numbers, SIM details) to a third party.
- Legal Outcome: Ncell was fined ₹500,000 under PDPA 2018’s Section 38 (Penalties).
- Lesson: Companies must audit employee access to sensitive data.
Nepal Rastra Bank’s Cybersecurity Framework
- Idea Used: Data integrity and confidentiality.
- How It Works: All online banking transactions use 256-bit encryption (like WhatsApp calls). Even if a hacker intercepts data, they can’t read it without the private key.
- PDPA Link: Section 11 (Security Safeguards) mandates such measures.
Exam Tip
How This Unit is Tested
Short Questions (5-10 marks)
- Define privacy vs. data protection.
- List 3 rights of data subjects under PDPA 2018.
- Compare PDPA 2018 and GDPR in a bullet-point table.
Long Questions (15-20 marks)
- Case Study Analysis: Given a scenario (e.g., Daraz selling user data), explain:
- Which PDPA principle was violated?
- What rights were breached?
- How would you remedy the situation?
- Worked Example: Calculate storage limits for a company’s customer data (e.g., "How long can NTC store your call logs?" → Answer: 6 months, per PDPA’s Section 14).
- Case Study Analysis: Given a scenario (e.g., Daraz selling user data), explain:
True/False + Justification
- Example:
- "Under PDPA 2018, companies can sell user data if they inform customers afterward."
- False (Violates Section 12: Purpose Limitation—consent must be prior).
- Example:
Diagram-Based Questions
- Draw a flowchart of how eSewa processes your biometric data (steps: collection → encryption → storage → deletion).
- Label a Venn diagram comparing PDPA 2018 and CCPA (e.g., "Both require consent" vs. "Only GDPR has 'right to be forgotten'").
Pro Tip:
- Memorize the 8 principles of data protection—examiners love testing them in match-the-following questions.
- Relate every answer to Nepal (e.g., "Like NID cards, biometric data must be protected under Section 9 of PDPA 2018").
- Practice with real apps: Analyze Khalti’s privacy policy or NTC’s data retention rules for exam-style questions.
Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 3.
Discussion
Loading…