IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 914 min read

E-Transactions Act, Cyber Law & Nepal’s Digital Governance

Unit 9 of IT Ethics and Cybersecurity explores Nepal’s Electronic Transactions Act 2063, its legal framework for digital contracts, cybercrime penalties, and e-signatures, alongside Cyber Law in Nepal, including data breach rules, online fraud cases, and how platforms like eSewa/Khalti enforce compliance. It contrasts

TAKEAWAYS:

  • Nepal’s Electronic Transactions Act 2063 legally validates digital signatures, contracts, and records, mirroring the UNCITRAL Model Law but with local adaptations (e.g., e-signature authentication via NID or bank OTP).
  • Cyber Law in Nepal criminalizes offenses like hacking (up to 15 years imprisonment), cyber fraud (up to NPR 5 million fines), and child pornography (mandatory reporting to Nepal Police Cyber Crime Unit).
  • eSewa/Khalti use 3D Secure (3DS) authentication and Aadhaar-linked e-signatures to comply with the Act, while Nepal Rastra Bank (NRB) mandates PCI-DSS compliance for all online payment gateways.
  • Digital Evidence Rules 2075 require timestamps, non-repudiation, and secure storage (e.g., Nepal Government’s e-Dhoka portal for official documents).
  • Comparisons: Nepal’s Cyber Security Strategy 2076 aligns with EU’s NIS2 Directive but lacks a data protection authority like GDPR’s EDPS.
  • Emerging Challenges: Deepfake fraud (e.g., 2022 Khalti scams via cloned voices) and AI-generated misinformation (e.g., 2023 NEPSE stock manipulation rumors) highlight gaps in Nepal’s cyber laws.

classDiagram
    class User {
        +name: String
        +NID: String
        +biometric: Fingerprint/FaceID
        +OTP: String
    }
    class DigitalSignature {
        <<enumeration>>
        TYPE_A
        TYPE_B
        TYPE_C
    }
    class eSewa {
        +generateTransactionID(): String
        +validateOTP(): Boolean
        +storeLog(): ElectronicRecord
    }
    class Court {
        +acceptEvidence(record: ElectronicRecord): Boolean
    }
    User --> DigitalSignature : "uses"
    DigitalSignature --> eSewa : "authenticates"
    eSewa --> Court : "provides logs"
    note for User "Example: Khalti user with NID + OTP"
    note for DigitalSignature "Type A: OTP\nType B: Biometric + OTP\nType C: Cryptographic"
Class diagram showing how digital signatures (Types A, B, C) authenticate users in eSewa/Khalti transactions
2008 AD (2063 BS)ElectronicTransactions Act 2063 2017 AD (2074 BS)Cyber Crime Act2074 criminalizes hack2020 AD (2077 BS)Digital EvidenceRules 2075 mandate tim2023 AD (2080 BS)Nepal Rastra Bankenforces PCI-DSS compl
Key milestones in Nepal’s digital governance and cyber law evolution

1. Electronic Transactions Act 2063: The Backbone of Digital Trust

The Electronic Transactions Act 2063 (2008) is Nepal’s primary law governing digital transactions, modeled after the UN Model Law on Electronic Signatures (UNCITRAL). It ensures that:

  • Digital signatures (e.g., OTP-based, biometric, or cryptographic) are legally binding if they meet non-repudiation, authentication, and integrity standards.
  • Electronic records (e.g., eSewa receipts, Daraz order confirmations) are admissible in court if time-stamped and unaltered.
  • Online contracts (e.g., Pathao ride bookings, Daraz purchases) are enforceable if parties consent digitally (e.g., via checkbox or voice confirmation).

How It Works:

flowchart TD
    A["User Action\n(e.g., Khalti payment)"] -->|"Digital Signature<br/>(OTP/biometric)"| B["Electronic Record\n(eSewa transaction log)"]
    B -->|"Non-repudiation<br/>(Cryptographic hash)"| C["Legal Validity\n(Court-admissible)"]
    C -->|"Dispute<br/>(e.g., fraud claim)"| D["Cyber Crime Unit\n(Nepal Police)"]

Real Example: eSewa’s Compliance

  • Process: When you pay via eSewa, the app generates a transaction ID + OTP, which acts as your digital signature.
  • Legal Weight: If disputed, eSewa submits the time-stamped transaction log (stored on Nepal Data Center) to prove the payment.
  • Why It Matters: Without this Act, digital payments could be easily denied in court.

2. Cyber Law in Nepal: Crimes, Penalties, and Enforcement

Nepal’s Cyber Crime Act 2074 and Digital Evidence Rules 2075 define offenses and penalties. Key provisions:

Offense Penalty Real-World Example
Hacking (unauthorized access) Up to 15 years imprisonment 2021 NTC website breach (data of 1M users leaked)
Cyber Fraud Up to NPR 5 million fine 2023 Khalti scam (cloned app stole NPR 20M)
Child Pornography Mandatory reporting to police 2022 Facebook case (Nepali pedophile ring busted)
Defamation via IT NPR 100K–1M fine 2021 Twitter fake news (accused MP of corruption)
Data Theft 3–7 years jail 2020 Daraz vendor database leak (sold to competitors)

How Enforcement Works:

  1. Reporting: Victims file complaints at Cyber Crime Unit (Nepal Police) or Nepal Computer Emergency Response Team (NeCERT).
  2. Investigation: Police trace IP addresses via NTC/NTT logs or bank transaction trails.
  3. Prosecution: Cases go to Cyber Crime Court (Kathmandu) under Special Act 2074.

3. Digital Signatures: From OTPs to Blockchain

The Act recognizes three types of digital signatures:

  1. Type A (Simple): OTP, PIN, or checkbox (e.g., Daraz checkout).
  2. Type B (Medium): Biometric (fingerprint/face ID) + OTP (e.g., Khalti app).
  3. Type C (Advanced): Cryptographic (private key + certificate) (e.g., Nepal Government’s e-Dhoka portal).

Worked Example: Ncell’s e-SIM Activation

  • Process:
    1. User requests e-SIM via Ncell app.
    2. System sends OTP to registered number (Type A signature).
    3. OTP submission + biometric verification (Type B) activates the e-SIM.
  • Legal Validity: If disputed, Ncell provides server logs + timestamp to prove activation.

Comparison Table: Signature Types

Type Method Use Case Security Level Legal Weight
A OTP/PIN Daraz checkout, Pathao rides Low Basic
B Biometric + OTP Khalti payments, Ncell e-SIM Medium Strong
C Cryptographic (PKI) Government tenders, NEPSE trades High Highest

4. Electronic Evidence: What Courts Accept

The Digital Evidence Rules 2075 state that electronic evidence must be:

  • Original: Unaltered (e.g., unedited WhatsApp chat logs).
  • Authenticated: Sourced from a reliable system (e.g., bank server, NTC records).
  • Time-Stamped: Proven via blockchain or government-certified timestamps (e.g., e-Dhoka portal).

Real Example: 2022 NEPSE Fraud Case

  • Scenario: A trader claimed his NEPSE account was hacked to sell shares.
  • Evidence Submitted:
    • Transaction logs from NEPSE’s server (time-stamped).
    • IP address trace linked to a cybercafé in Thapathali.
  • Outcome: Court ruled in favor of NEPSE because the logs were unaltered and time-stamped.

5. Online Dispute Resolution (ODR) in Nepal

Nepal’s Alternative Dispute Resolution (ADR) Act 2075 includes Online Dispute Resolution (ODR) for digital conflicts. Platforms like:

  • eSewa’s Grievance Portal: Handles payment disputes via chatbot + human review.
  • Daraz’s Customer Care: Uses AI chatbots to verify order details before escalating.
  • Nepal Bankers’ Association (NBA): Mediates inter-bank digital fraud cases.

Process Flow:

flowchart LR
    A["User Complaint\n(e.g., Khalti refund delay)"] --> B["AI Triage\n(Chatbot checks logs)"]
    B -->|"Valid Issue"| C["Human Review\n(Customer Support)"]
    C -->|"Escalated"| D["ODR Panel\n(NBA/eSewa)"]
    D -->|"Settled"| E["Court\n(If unresolved)"]

6. Compliance for Businesses: What eSewa, Khalti, and Banks Must Do

Requirement eSewa/Khalti Banks (NMB, Global IME) E-Commerce (Daraz, Sastodeal)
Data Encryption AES-256 for transactions PCI-DSS Level 1 compliant TLS 1.3 for checkout
User Authentication Biometric + OTP Aadhaar + OTP Email + OTP
Audit Logs 90-day retention on secure servers 5-year retention (NRB mandate) 30-day retention
Fraud Monitoring AI-based anomaly detection Real-time transaction alerts Chargeback dispute system
Consumer Protection NPR 100K insurance per transaction Deposit Insurance Fund (DIF) coverage 7-day return policy

Real Example: NMB Bank’s PCI-DSS Compliance

  • Why? To process online loans (e.g., NMB’s "Digital Loan").
  • Steps:
    1. Encrypts all card data (AES-256).
    2. Tokens customer data (never stores full CVV).
    3. Submits to NRB audits quarterly.
  • Outcome: Reduces fraud by 40% (per NMB’s 2023 report).

7. Challenges & Gaps in Nepal’s Cyber Laws

Issue Example Solution Needed
Lack of Data Protection Authority No GDPR-like body to enforce privacy rules Establish a "Nepal Data Protection Commission"
Weak AI Regulation Deepfake scams (e.g., 2023 Khalti voice cloning) Amend Cyber Crime Act to cover AI-generated fraud
Slow Court Proceedings 2021 NTC hack case took 3 years to resolve Dedicated Cyber Courts with faster trials
Low Awareness 60% of SMEs don’t know about e-signature laws NRB/Nepal Police workshops for businesses

In the Real World

  1. eSewa/Khalti’s OTP System

    • Idea Used: Type B digital signatures (biometric + OTP).
    • How It Works: When you pay via Khalti, the app combines fingerprint scan + OTP to create a legally binding signature. If you dispute a payment, Khalti submits server logs + timestamp to prove authenticity.
    • Why It Matters: Without this, NPR 50 billion/year in digital transactions could be disputed fraudulently.
  2. Ncell’s e-SIM Activation

    • Idea Used: Type B digital signature (biometric + OTP).
    • Real Process:
      1. User requests e-SIM via app.
      2. System sends OTP to registered number.
      3. User verifies via fingerprint/face ID.
    • Legal Protection: If Ncell denies activation, the OTP logs + biometric match prove the user’s consent.
  3. Daraz’s Fraud Detection

    • Idea Used: AI + Digital Evidence Rules.
    • How It Works: Daraz’s system flags unusual orders (e.g., same IP buying 100 phones in 1 hour) and blocks them. If a user disputes a chargeback, Daraz provides:
      • Transaction timestamp (from their server).
      • IP address trace (via NTC logs).
    • Outcome: Reduced fraudulent returns by 30% (Daraz’s 2023 report).
  4. Nepal Rastra Bank’s Loan Scams

    • Idea Used: Cyber Fraud Penalties (NPR 5M fine).
    • Case Study: In 2022, a scammer cloned Global IME’s loan app and tricked users into "pre-approving" loans. When victims reported it:
      • Police traced the fake app’s IP to India.
      • Global IME submitted server logs showing no real approval.
      • Scammer was fined NPR 2M under Cyber Crime Act 2074.

Exam Tip

This unit is heavily tested in TU/PU exams via:

  1. Case Studies (30%):

    • Example Question: "A user claims their Khalti payment was unauthorized. How would you verify this using Nepal’s Electronic Transactions Act?"
    • Answer Structure:
      • Step 1: Check transaction logs (must be time-stamped).
      • Step 2: Verify OTP + biometric match (Type B signature).
      • Step 3: Cross-check with NTC/IP logs if IP is suspicious.
      • Step 4: Escalate to Cyber Crime Unit if fraud is confirmed.
  2. Comparison Tables (25%):

    • Example Question: "Compare Type A, B, and C digital signatures with examples from eSewa and Ncell."
    • Must Include:
      • Method (OTP vs. biometric vs. PKI).
      • Use Case (eSewa checkout vs. Ncell e-SIM).
      • Security Level (Low/Medium/High).
      • Legal Weight (Basic/Strong/Highest).
  3. Short-Answer Definitions (20%):

    • Key Terms to Memorize:
      • Non-repudiation: Ensures a party cannot deny an action (e.g., eSewa payment logs).
      • Digital Evidence Rules 2075: Govern admissibility of electronic records in court.
      • Cyber Crime Unit: Nepal Police’s dedicated team for digital offenses.
  4. Scenario-Based Questions (15%):

    • Example Question: "A Daraz seller accuses a buyer of fake returns. How would you resolve this using Nepal’s laws?"
    • Answer Steps:
      1. Check Daraz’s order timestamp (must match user’s claim).
      2. Verify payment reversal logs (must comply with Digital Evidence Rules).
      3. If buyer is fraudulent, report to Cyber Crime Unit under Cyber Fraud Act.
  5. Real-World Applications (10%):

    • Example Question: "How does Khalti’s OTP system comply with the Electronic Transactions Act?"
    • Must Mention:
      • Type B signature (biometric + OTP).
      • Non-repudiation (logs stored securely).
      • Legal recourse (disputes go to ODR panel).

Pro Tip: Always relate answers to real platforms (eSewa, Khalti, Ncell, Daraz). Examiners love when you use local examples like:

  • *"Like in the 2023 Khalti scam, where cloned apps used Type A signatures (OTP only), leading to NPR 20M losses."*

In the real world

  • eSewa/Khalti payments use Type B digital signatures (biometric + OTP) to comply with the Electronic Transactions Act 2063, ensuring legal validity for disputes (e.g., refund claims).
  • NEPSE stock trading requires Type C signatures (cryptographic) for high-value transactions, aligning with the Act’s non-repudiation standards.
  • Ncell’s e-SIM activation demonstrates Type A (OTP) + Type B (biometric) authentication, with server logs serving as admissible digital evidence in court.

Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 9.

Discussion

Loading…