IT Ethics and CybersecurityUnit 914 min read
E-Transactions Act, Cyber Law & Nepal’s Digital Governance
Unit 9 of IT Ethics and Cybersecurity explores Nepal’s Electronic Transactions Act 2063, its legal framework for digital contracts, cybercrime penalties, and e-signatures, alongside Cyber Law in Nepal, including data breach rules, online fraud cases, and how platforms like eSewa/Khalti enforce compliance. It contrasts
TAKEAWAYS:
- Nepal’s Electronic Transactions Act 2063 legally validates digital signatures, contracts, and records, mirroring the UNCITRAL Model Law but with local adaptations (e.g., e-signature authentication via NID or bank OTP).
- Cyber Law in Nepal criminalizes offenses like hacking (up to 15 years imprisonment), cyber fraud (up to NPR 5 million fines), and child pornography (mandatory reporting to Nepal Police Cyber Crime Unit).
- eSewa/Khalti use 3D Secure (3DS) authentication and Aadhaar-linked e-signatures to comply with the Act, while Nepal Rastra Bank (NRB) mandates PCI-DSS compliance for all online payment gateways.
- Digital Evidence Rules 2075 require timestamps, non-repudiation, and secure storage (e.g., Nepal Government’s e-Dhoka portal for official documents).
- Comparisons: Nepal’s Cyber Security Strategy 2076 aligns with EU’s NIS2 Directive but lacks a data protection authority like GDPR’s EDPS.
- Emerging Challenges: Deepfake fraud (e.g., 2022 Khalti scams via cloned voices) and AI-generated misinformation (e.g., 2023 NEPSE stock manipulation rumors) highlight gaps in Nepal’s cyber laws.
Core Concepts & Legal Framework
classDiagram
class User {
+name: String
+NID: String
+biometric: Fingerprint/FaceID
+OTP: String
}
class DigitalSignature {
<<enumeration>>
TYPE_A
TYPE_B
TYPE_C
}
class eSewa {
+generateTransactionID(): String
+validateOTP(): Boolean
+storeLog(): ElectronicRecord
}
class Court {
+acceptEvidence(record: ElectronicRecord): Boolean
}
User --> DigitalSignature : "uses"
DigitalSignature --> eSewa : "authenticates"
eSewa --> Court : "provides logs"
note for User "Example: Khalti user with NID + OTP"
note for DigitalSignature "Type A: OTP\nType B: Biometric + OTP\nType C: Cryptographic"Class diagram showing how digital signatures (Types A, B, C) authenticate users in eSewa/Khalti transactions1. Electronic Transactions Act 2063: The Backbone of Digital Trust
The Electronic Transactions Act 2063 (2008) is Nepal’s primary law governing digital transactions, modeled after the UN Model Law on Electronic Signatures (UNCITRAL). It ensures that:
- Digital signatures (e.g., OTP-based, biometric, or cryptographic) are legally binding if they meet non-repudiation, authentication, and integrity standards.
- Electronic records (e.g., eSewa receipts, Daraz order confirmations) are admissible in court if time-stamped and unaltered.
- Online contracts (e.g., Pathao ride bookings, Daraz purchases) are enforceable if parties consent digitally (e.g., via checkbox or voice confirmation).
How It Works:
flowchart TD
A["User Action\n(e.g., Khalti payment)"] -->|"Digital Signature<br/>(OTP/biometric)"| B["Electronic Record\n(eSewa transaction log)"]
B -->|"Non-repudiation<br/>(Cryptographic hash)"| C["Legal Validity\n(Court-admissible)"]
C -->|"Dispute<br/>(e.g., fraud claim)"| D["Cyber Crime Unit\n(Nepal Police)"]Real Example: eSewa’s Compliance
- Process: When you pay via eSewa, the app generates a transaction ID + OTP, which acts as your digital signature.
- Legal Weight: If disputed, eSewa submits the time-stamped transaction log (stored on Nepal Data Center) to prove the payment.
- Why It Matters: Without this Act, digital payments could be easily denied in court.
2. Cyber Law in Nepal: Crimes, Penalties, and Enforcement
Nepal’s Cyber Crime Act 2074 and Digital Evidence Rules 2075 define offenses and penalties. Key provisions:
| Offense | Penalty | Real-World Example |
|---|---|---|
| Hacking (unauthorized access) | Up to 15 years imprisonment | 2021 NTC website breach (data of 1M users leaked) |
| Cyber Fraud | Up to NPR 5 million fine | 2023 Khalti scam (cloned app stole NPR 20M) |
| Child Pornography | Mandatory reporting to police | 2022 Facebook case (Nepali pedophile ring busted) |
| Defamation via IT | NPR 100K–1M fine | 2021 Twitter fake news (accused MP of corruption) |
| Data Theft | 3–7 years jail | 2020 Daraz vendor database leak (sold to competitors) |
How Enforcement Works:
- Reporting: Victims file complaints at Cyber Crime Unit (Nepal Police) or Nepal Computer Emergency Response Team (NeCERT).
- Investigation: Police trace IP addresses via NTC/NTT logs or bank transaction trails.
- Prosecution: Cases go to Cyber Crime Court (Kathmandu) under Special Act 2074.
3. Digital Signatures: From OTPs to Blockchain
The Act recognizes three types of digital signatures:
- Type A (Simple): OTP, PIN, or checkbox (e.g., Daraz checkout).
- Type B (Medium): Biometric (fingerprint/face ID) + OTP (e.g., Khalti app).
- Type C (Advanced): Cryptographic (private key + certificate) (e.g., Nepal Government’s e-Dhoka portal).
Worked Example: Ncell’s e-SIM Activation
- Process:
- User requests e-SIM via Ncell app.
- System sends OTP to registered number (Type A signature).
- OTP submission + biometric verification (Type B) activates the e-SIM.
- Legal Validity: If disputed, Ncell provides server logs + timestamp to prove activation.
Comparison Table: Signature Types
| Type | Method | Use Case | Security Level | Legal Weight |
|---|---|---|---|---|
| A | OTP/PIN | Daraz checkout, Pathao rides | Low | Basic |
| B | Biometric + OTP | Khalti payments, Ncell e-SIM | Medium | Strong |
| C | Cryptographic (PKI) | Government tenders, NEPSE trades | High | Highest |
4. Electronic Evidence: What Courts Accept
The Digital Evidence Rules 2075 state that electronic evidence must be:
- Original: Unaltered (e.g., unedited WhatsApp chat logs).
- Authenticated: Sourced from a reliable system (e.g., bank server, NTC records).
- Time-Stamped: Proven via blockchain or government-certified timestamps (e.g., e-Dhoka portal).
Real Example: 2022 NEPSE Fraud Case
- Scenario: A trader claimed his NEPSE account was hacked to sell shares.
- Evidence Submitted:
- Transaction logs from NEPSE’s server (time-stamped).
- IP address trace linked to a cybercafé in Thapathali.
- Outcome: Court ruled in favor of NEPSE because the logs were unaltered and time-stamped.
5. Online Dispute Resolution (ODR) in Nepal
Nepal’s Alternative Dispute Resolution (ADR) Act 2075 includes Online Dispute Resolution (ODR) for digital conflicts. Platforms like:
- eSewa’s Grievance Portal: Handles payment disputes via chatbot + human review.
- Daraz’s Customer Care: Uses AI chatbots to verify order details before escalating.
- Nepal Bankers’ Association (NBA): Mediates inter-bank digital fraud cases.
Process Flow:
flowchart LR
A["User Complaint\n(e.g., Khalti refund delay)"] --> B["AI Triage\n(Chatbot checks logs)"]
B -->|"Valid Issue"| C["Human Review\n(Customer Support)"]
C -->|"Escalated"| D["ODR Panel\n(NBA/eSewa)"]
D -->|"Settled"| E["Court\n(If unresolved)"]6. Compliance for Businesses: What eSewa, Khalti, and Banks Must Do
| Requirement | eSewa/Khalti | Banks (NMB, Global IME) | E-Commerce (Daraz, Sastodeal) |
|---|---|---|---|
| Data Encryption | AES-256 for transactions | PCI-DSS Level 1 compliant | TLS 1.3 for checkout |
| User Authentication | Biometric + OTP | Aadhaar + OTP | Email + OTP |
| Audit Logs | 90-day retention on secure servers | 5-year retention (NRB mandate) | 30-day retention |
| Fraud Monitoring | AI-based anomaly detection | Real-time transaction alerts | Chargeback dispute system |
| Consumer Protection | NPR 100K insurance per transaction | Deposit Insurance Fund (DIF) coverage | 7-day return policy |
Real Example: NMB Bank’s PCI-DSS Compliance
- Why? To process online loans (e.g., NMB’s "Digital Loan").
- Steps:
- Encrypts all card data (AES-256).
- Tokens customer data (never stores full CVV).
- Submits to NRB audits quarterly.
- Outcome: Reduces fraud by 40% (per NMB’s 2023 report).
7. Challenges & Gaps in Nepal’s Cyber Laws
| Issue | Example | Solution Needed |
|---|---|---|
| Lack of Data Protection Authority | No GDPR-like body to enforce privacy rules | Establish a "Nepal Data Protection Commission" |
| Weak AI Regulation | Deepfake scams (e.g., 2023 Khalti voice cloning) | Amend Cyber Crime Act to cover AI-generated fraud |
| Slow Court Proceedings | 2021 NTC hack case took 3 years to resolve | Dedicated Cyber Courts with faster trials |
| Low Awareness | 60% of SMEs don’t know about e-signature laws | NRB/Nepal Police workshops for businesses |
In the Real World
eSewa/Khalti’s OTP System
- Idea Used: Type B digital signatures (biometric + OTP).
- How It Works: When you pay via Khalti, the app combines fingerprint scan + OTP to create a legally binding signature. If you dispute a payment, Khalti submits server logs + timestamp to prove authenticity.
- Why It Matters: Without this, NPR 50 billion/year in digital transactions could be disputed fraudulently.
Ncell’s e-SIM Activation
- Idea Used: Type B digital signature (biometric + OTP).
- Real Process:
- User requests e-SIM via app.
- System sends OTP to registered number.
- User verifies via fingerprint/face ID.
- Legal Protection: If Ncell denies activation, the OTP logs + biometric match prove the user’s consent.
Daraz’s Fraud Detection
- Idea Used: AI + Digital Evidence Rules.
- How It Works: Daraz’s system flags unusual orders (e.g., same IP buying 100 phones in 1 hour) and blocks them. If a user disputes a chargeback, Daraz provides:
- Transaction timestamp (from their server).
- IP address trace (via NTC logs).
- Outcome: Reduced fraudulent returns by 30% (Daraz’s 2023 report).
Nepal Rastra Bank’s Loan Scams
- Idea Used: Cyber Fraud Penalties (NPR 5M fine).
- Case Study: In 2022, a scammer cloned Global IME’s loan app and tricked users into "pre-approving" loans. When victims reported it:
- Police traced the fake app’s IP to India.
- Global IME submitted server logs showing no real approval.
- Scammer was fined NPR 2M under Cyber Crime Act 2074.
Exam Tip
This unit is heavily tested in TU/PU exams via:
Case Studies (30%):
- Example Question: "A user claims their Khalti payment was unauthorized. How would you verify this using Nepal’s Electronic Transactions Act?"
- Answer Structure:
- Step 1: Check transaction logs (must be time-stamped).
- Step 2: Verify OTP + biometric match (Type B signature).
- Step 3: Cross-check with NTC/IP logs if IP is suspicious.
- Step 4: Escalate to Cyber Crime Unit if fraud is confirmed.
Comparison Tables (25%):
- Example Question: "Compare Type A, B, and C digital signatures with examples from eSewa and Ncell."
- Must Include:
- Method (OTP vs. biometric vs. PKI).
- Use Case (eSewa checkout vs. Ncell e-SIM).
- Security Level (Low/Medium/High).
- Legal Weight (Basic/Strong/Highest).
Short-Answer Definitions (20%):
- Key Terms to Memorize:
- Non-repudiation: Ensures a party cannot deny an action (e.g., eSewa payment logs).
- Digital Evidence Rules 2075: Govern admissibility of electronic records in court.
- Cyber Crime Unit: Nepal Police’s dedicated team for digital offenses.
- Key Terms to Memorize:
Scenario-Based Questions (15%):
- Example Question: "A Daraz seller accuses a buyer of fake returns. How would you resolve this using Nepal’s laws?"
- Answer Steps:
- Check Daraz’s order timestamp (must match user’s claim).
- Verify payment reversal logs (must comply with Digital Evidence Rules).
- If buyer is fraudulent, report to Cyber Crime Unit under Cyber Fraud Act.
Real-World Applications (10%):
- Example Question: "How does Khalti’s OTP system comply with the Electronic Transactions Act?"
- Must Mention:
- Type B signature (biometric + OTP).
- Non-repudiation (logs stored securely).
- Legal recourse (disputes go to ODR panel).
Pro Tip: Always relate answers to real platforms (eSewa, Khalti, Ncell, Daraz). Examiners love when you use local examples like:
- *"Like in the 2023 Khalti scam, where cloned apps used Type A signatures (OTP only), leading to NPR 20M losses."*
In the real world
- eSewa/Khalti payments use Type B digital signatures (biometric + OTP) to comply with the Electronic Transactions Act 2063, ensuring legal validity for disputes (e.g., refund claims).
- NEPSE stock trading requires Type C signatures (cryptographic) for high-value transactions, aligning with the Act’s non-repudiation standards.
- Ncell’s e-SIM activation demonstrates Type A (OTP) + Type B (biometric) authentication, with server logs serving as admissible digital evidence in court.
Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 9.
Discussion
Loading…