IT Ethics and CybersecurityUnit 39 min read
Privacy & Data Protection: Laws, Risks & Safeguards
Unit 3 of IT Ethics and Cybersecurity explores the principles of privacy, data protection laws (including Nepal’s PDPA 2018), types of personal data, risks of data breaches, and best practices for secure data handling—with real-world examples from eSewa, Ncell, and global tech giants.
TAKEAWAYS:
- Privacy vs. Data Protection: Privacy is the right to control personal information, while data protection is the practice of safeguarding that data (e.g., encryption, access controls).
- Nepal’s PDPA 2018: Mandates consent, transparency, and data minimization—fines up to ₹5 million or 2% of annual revenue for violations (applies to eSewa, banks, and even government databases).
- Types of Personal Data: Sensitive data (biometrics, health records) requires stricter protection than non-sensitive data (name, email).
- Data Breach Risks: Phishing (e.g., fake Ncell OTP scams), ransomware (e.g., Daraz supplier databases), and insider threats (e.g., Khalti employee leaks).
- GDPR vs. PDPA: GDPR (EU) gives users right to be forgotten; PDPA focuses on consent and data localization (storing data within Nepal).
- Ethical Safeguards: Anonymization, pseudonymization, and data minimization (collecting only what’s necessary) reduce exposure.
1. Definitions: Privacy vs. Data Protection
Privacy is a human right (Article 17 of the Universal Declaration of Human Rights), while data protection is a technical and legal framework to enforce it. In IT, privacy protects individuals from unauthorized access to their data, whereas data protection ensures that data is handled securely and lawfully.
2. Nepal’s Personal Data Protection Act (PDPA) 2018
Nepal’s PDPA 2018 is modeled after the EU’s GDPR but with local adaptations. Key provisions:
- Consent: Explicit, informed, and revocable (e.g., eSewa’s terms of service).
- Data Minimization: Collect only what’s necessary (e.g., banks asking for Aadhaar but not caste).
- Data Localization: Sensitive data must be stored within Nepal (e.g., Ncell’s customer databases).
- Breach Notification: Must report breaches within 72 hours (e.g., if a Daraz supplier’s data is hacked).
- Penalties: Up to ₹5 million or 2% of annual revenue (whichever is higher).
Worked Example: eSewa’s Compliance eSewa processes millions of transactions daily. Under PDPA:
- Consent: Users must opt-in to share financial data.
- Encryption: Transaction records are encrypted (AES-256).
- Breach Plan: If hacked, eSewa must notify users and the Office of the Data Protection Officer (DPO) within 72 hours.
3. Types of Personal Data (and Their Risks)
Data is classified into three tiers based on sensitivity:
| Tier | Examples | Protection Level | Risk if Exposed |
|---|---|---|---|
| Basic | Name, email, phone number | Low | Identity theft, spam |
| Sensitive | Biometrics (fingerprint), health data | High | Blackmail, insurance fraud |
| Financial | Bank details, transaction history | Critical | Theft, money laundering (e.g., Ncell wallet hacks) |
Real-World Example: Ncell’s SIM Registration Leak (2021)
- Data Exposed: Names, addresses, and NID numbers of 21 million users.
- Impact: Scammers used NID data to apply for loans (via banks like NMB).
- Violation: Ncell failed data minimization (stored unnecessary details) and breach notification.
4. Common Data Breach Methods (and How to Prevent Them)
| Breach Type | How It Happens | Prevention | Nepal Example |
|---|---|---|---|
| Phishing | Fake emails (e.g., "Your Khalti account is locked") | Multi-factor authentication (MFA) | Ncell’s 2020 OTP phishing scam |
| Ransomware | Malware encrypts data (e.g., Daraz suppliers) | Regular backups + employee training | 2022 ransomware attack on a Kathmandu hospital |
| Insider Threat | Employees leaking data (e.g., Khalti staff) | Access controls + audits | 2021 leak of 50,000 Khalti user records |
| Weak Encryption | Poorly secured databases | Use AES-256 or higher | 2020 NTA exam result database hack |
Worked Example: Daraz Supplier Database Breach
- Attack: Hackers exploited a weak API in Daraz’s supplier portal.
- Data Stolen: Product details + payment gateways (credit card info).
- Impact: Fake orders and chargebacks.
- Fix: Daraz implemented tokenization (replacing card numbers with tokens).
5. Ethical Safeguards for Data Protection
Even with laws, ethical practices reduce risks:
| Safeguard | How It Works | Example |
|---|---|---|
| Anonymization | Remove identifiers (e.g., replacing names with IDs) | NTC’s traffic data analysis (without personal details) |
| Pseudonymization | Replace names with codes (e.g., "User123") | eSewa’s transaction logs |
| Data Minimization | Collect only what’s needed | Banks asking for Aadhaar but not religion |
| End-to-End Encryption | Data encrypted in transit and at rest | WhatsApp messages (E2EE) |
Mermaid Diagram: Data Lifecycle with Safeguards
flowchart TD
A["Data Collection"] -->|"Consent"| B["Storage"]
B -->|"Encryption"| C["Processing"]
C -->|"Anonymization"| D["Sharing"]
D -->|"Access Controls"| E["Destruction"]
E -->|"Secure Deletion"| F["Compliance Audit"]6. Global vs. Nepal’s Approach: GDPR vs. PDPA
| Feature | GDPR (EU) | PDPA (Nepal) |
|---|---|---|
| Right to Erasure | Yes ("Right to be forgotten") | No (but can request deletion) |
| Data Localization | No (can store anywhere) | Yes (sensitive data must stay in Nepal) |
| Fines | Up to 4% of global revenue | Up to ₹5M or 2% of annual revenue |
| Breach Notification | 72 hours | 72 hours (same as GDPR) |
Why PDPA’s Localization Matters for Nepal
- Example: If a Kathmandu hospital uses a foreign cloud server (e.g., AWS in the US), it violates PDPA.
- Solution: Use local data centers (e.g., NTA’s servers in Nepal).
## In the Real World
eSewa’s Transaction Security
- Idea Used: End-to-end encryption and tokenization (replacing card numbers with tokens).
- How: When you pay via eSewa, your bank details are never stored—only a one-time token is used.
- Risk Averted: Even if eSewa’s database is hacked, credit card numbers remain safe.
Ncell’s SIM Registration Database Leak (2021)
- Idea Violated: Data minimization and secure storage.
- Impact: Scammers used NID numbers to apply for loans under other people’s names.
- Lesson: Storing only essential data (e.g., phone number + NID) would have limited damage.
Pathao Driver Data Breach (2020)
- Idea Used: Weak access controls (employees could view all driver data).
- Fix: Pathao implemented role-based access (only HR can see personal details).
## Exam Tip
Memorize PDPA 2018 Key Points:
- Consent is mandatory (no pre-ticked boxes).
- Sensitive data must be localized (stored in Nepal).
- Breaches must be reported in 72 hours.
Compare GDPR vs. PDPA:
- GDPR = More user rights (e.g., "right to be forgotten").
- PDPA = Stricter on local storage but fewer erasure rights.
Case Study Questions:
- Expect scenario-based questions (e.g., "How would you secure eSewa’s data?").
- Structure your answer:
- Identify the risk (e.g., phishing).
- Suggest technical controls (e.g., MFA).
- Mention legal compliance (e.g., PDPA’s 72-hour rule).
Visuals in Exams:
- Flowcharts (e.g., data lifecycle) and comparison tables (GDPR vs. PDPA) often fetch marks.
- Label diagrams (e.g., "This is anonymization vs. pseudonymization").
Common Pitfalls:
- ❌ Saying "GDPR applies in Nepal" (it doesn’t—PDPA does).
- ❌ Ignoring data localization (a major focus in Nepal’s law).
- ❌ Forgetting real-world examples (eSewa, Ncell, Daraz are safe bets).
Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 3.
Discussion
Loading…