IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 39 min read

Privacy & Data Protection: Laws, Risks & Safeguards

Unit 3 of IT Ethics and Cybersecurity explores the principles of privacy, data protection laws (including Nepal’s PDPA 2018), types of personal data, risks of data breaches, and best practices for secure data handling—with real-world examples from eSewa, Ncell, and global tech giants.

TAKEAWAYS:

  • Privacy vs. Data Protection: Privacy is the right to control personal information, while data protection is the practice of safeguarding that data (e.g., encryption, access controls).
  • Nepal’s PDPA 2018: Mandates consent, transparency, and data minimization—fines up to ₹5 million or 2% of annual revenue for violations (applies to eSewa, banks, and even government databases).
  • Types of Personal Data: Sensitive data (biometrics, health records) requires stricter protection than non-sensitive data (name, email).
  • Data Breach Risks: Phishing (e.g., fake Ncell OTP scams), ransomware (e.g., Daraz supplier databases), and insider threats (e.g., Khalti employee leaks).
  • GDPR vs. PDPA: GDPR (EU) gives users right to be forgotten; PDPA focuses on consent and data localization (storing data within Nepal).
  • Ethical Safeguards: Anonymization, pseudonymization, and data minimization (collecting only what’s necessary) reduce exposure.

1. Definitions: Privacy vs. Data Protection

Privacy is a human right (Article 17 of the Universal Declaration of Human Rights), while data protection is a technical and legal framework to enforce it. In IT, privacy protects individuals from unauthorized access to their data, whereas data protection ensures that data is handled securely and lawfully.

Definition: Right to control personal information (e.g., optHuman Right (UDHR Article 17)PrivacyDefinition: Technical/legal safeguards (e.g., eSewa’s encrypKey Difference: Ethical/Legal (Privacy) vs. Technical/Legal Data ProtectionPrivacy & Data Protection
Hierarchical comparison of Privacy vs. Data Protection with real-world examples

2. Nepal’s Personal Data Protection Act (PDPA) 2018

Nepal’s PDPA 2018 is modeled after the EU’s GDPR but with local adaptations. Key provisions:

  • Consent: Explicit, informed, and revocable (e.g., eSewa’s terms of service).
  • Data Minimization: Collect only what’s necessary (e.g., banks asking for Aadhaar but not caste).
  • Data Localization: Sensitive data must be stored within Nepal (e.g., Ncell’s customer databases).
  • Breach Notification: Must report breaches within 72 hours (e.g., if a Daraz supplier’s data is hacked).
  • Penalties: Up to ₹5 million or 2% of annual revenue (whichever is higher).
2018 ADPDPA 2018 enacted(Nepal)2018 ADData Controllerregistration required2020 ADFirst breachnotification rules2023 ADGDPR-like consentrequirements
Key milestones in Nepal’s data protection legal framework

Worked Example: eSewa’s Compliance eSewa processes millions of transactions daily. Under PDPA:

  1. Consent: Users must opt-in to share financial data.
  2. Encryption: Transaction records are encrypted (AES-256).
  3. Breach Plan: If hacked, eSewa must notify users and the Office of the Data Protection Officer (DPO) within 72 hours.

3. Types of Personal Data (and Their Risks)

Data is classified into three tiers based on sensitivity:

Tier Examples Protection Level Risk if Exposed
Basic Name, email, phone number Low Identity theft, spam
Sensitive Biometrics (fingerprint), health data High Blackmail, insurance fraud
Financial Bank details, transaction history Critical Theft, money laundering (e.g., Ncell wallet hacks)

Real-World Example: Ncell’s SIM Registration Leak (2021)

  • Data Exposed: Names, addresses, and NID numbers of 21 million users.
  • Impact: Scammers used NID data to apply for loans (via banks like NMB).
  • Violation: Ncell failed data minimization (stored unnecessary details) and breach notification.

4. Common Data Breach Methods (and How to Prevent Them)

Breach Type How It Happens Prevention Nepal Example
Phishing Fake emails (e.g., "Your Khalti account is locked") Multi-factor authentication (MFA) Ncell’s 2020 OTP phishing scam
Ransomware Malware encrypts data (e.g., Daraz suppliers) Regular backups + employee training 2022 ransomware attack on a Kathmandu hospital
Insider Threat Employees leaking data (e.g., Khalti staff) Access controls + audits 2021 leak of 50,000 Khalti user records
Weak Encryption Poorly secured databases Use AES-256 or higher 2020 NTA exam result database hack
Phishing Attacks (35%)Weak Passwords (25%)Insider Threats (20%)Malware (15%)Physical Theft (5%)
Data breach causes in Nepal (2022-23 reports)

Worked Example: Daraz Supplier Database Breach

  1. Attack: Hackers exploited a weak API in Daraz’s supplier portal.
  2. Data Stolen: Product details + payment gateways (credit card info).
  3. Impact: Fake orders and chargebacks.
  4. Fix: Daraz implemented tokenization (replacing card numbers with tokens).

5. Ethical Safeguards for Data Protection

Even with laws, ethical practices reduce risks:

Safeguard How It Works Example
Anonymization Remove identifiers (e.g., replacing names with IDs) NTC’s traffic data analysis (without personal details)
Pseudonymization Replace names with codes (e.g., "User123") eSewa’s transaction logs
Data Minimization Collect only what’s needed Banks asking for Aadhaar but not religion
End-to-End Encryption Data encrypted in transit and at rest WhatsApp messages (E2EE)

Mermaid Diagram: Data Lifecycle with Safeguards

flowchart TD
    A["Data Collection"] -->|"Consent"| B["Storage"]
    B -->|"Encryption"| C["Processing"]
    C -->|"Anonymization"| D["Sharing"]
    D -->|"Access Controls"| E["Destruction"]
    E -->|"Secure Deletion"| F["Compliance Audit"]

6. Global vs. Nepal’s Approach: GDPR vs. PDPA

Feature GDPR (EU) PDPA (Nepal)
Right to Erasure Yes ("Right to be forgotten") No (but can request deletion)
Data Localization No (can store anywhere) Yes (sensitive data must stay in Nepal)
Fines Up to 4% of global revenue Up to ₹5M or 2% of annual revenue
Breach Notification 72 hours 72 hours (same as GDPR)

Why PDPA’s Localization Matters for Nepal

  • Example: If a Kathmandu hospital uses a foreign cloud server (e.g., AWS in the US), it violates PDPA.
  • Solution: Use local data centers (e.g., NTA’s servers in Nepal).

## In the Real World

  1. eSewa’s Transaction Security

    • Idea Used: End-to-end encryption and tokenization (replacing card numbers with tokens).
    • How: When you pay via eSewa, your bank details are never stored—only a one-time token is used.
    • Risk Averted: Even if eSewa’s database is hacked, credit card numbers remain safe.
  2. Ncell’s SIM Registration Database Leak (2021)

    • Idea Violated: Data minimization and secure storage.
    • Impact: Scammers used NID numbers to apply for loans under other people’s names.
    • Lesson: Storing only essential data (e.g., phone number + NID) would have limited damage.
  3. Pathao Driver Data Breach (2020)

    • Idea Used: Weak access controls (employees could view all driver data).
    • Fix: Pathao implemented role-based access (only HR can see personal details).

## Exam Tip

  1. Memorize PDPA 2018 Key Points:

    • Consent is mandatory (no pre-ticked boxes).
    • Sensitive data must be localized (stored in Nepal).
    • Breaches must be reported in 72 hours.
  2. Compare GDPR vs. PDPA:

    • GDPR = More user rights (e.g., "right to be forgotten").
    • PDPA = Stricter on local storage but fewer erasure rights.
  3. Case Study Questions:

    • Expect scenario-based questions (e.g., "How would you secure eSewa’s data?").
    • Structure your answer:
      1. Identify the risk (e.g., phishing).
      2. Suggest technical controls (e.g., MFA).
      3. Mention legal compliance (e.g., PDPA’s 72-hour rule).
  4. Visuals in Exams:

    • Flowcharts (e.g., data lifecycle) and comparison tables (GDPR vs. PDPA) often fetch marks.
    • Label diagrams (e.g., "This is anonymization vs. pseudonymization").
  5. Common Pitfalls:

    • ❌ Saying "GDPR applies in Nepal" (it doesn’t—PDPA does).
    • ❌ Ignoring data localization (a major focus in Nepal’s law).
    • ❌ Forgetting real-world examples (eSewa, Ncell, Daraz are safe bets).

Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 3.

Discussion

Loading…