Legal Aspects of Business and TechnologyUnit 1011 min read
Cyber Law & Data Privacy: Acts, Crimes, Rights & Compliance
Unit 10 of Legal Aspects of Business and Technology covers Nepal’s Electronic Transactions Act 2063, Cyber Security Act 2075, and Data Privacy Laws, explaining cybercrimes (hacking, fraud, identity theft), user rights (privacy, anonymity), and compliance for businesses (KYC, GDPR-like rules). Includes real-world cases
Core Concepts & Definitions
1. What is Cyber Law?
Cyber law is the legal framework governing digital transactions, cybercrimes, and data protection. It bridges:
- Technology (e.g., encryption, blockchain)
- Law (e.g., contracts, intellectual property)
- Ethics (e.g., privacy, transparency)
Why it matters in Nepal? Nepal’s Electronic Transactions Act 2063 (amended 2075) and Cyber Security Act 2075 make digital agreements legally binding and criminalize cybercrimes like:
- Unauthorized access to systems (hacking)
- Fraudulent transactions (e.g., fake eSewa payments)
- Cyberstalking or harassment
2. Key Acts in Nepal
| Act | Year | Key Provisions | Penalty for Violation |
|---|---|---|---|
| Electronic Transactions Act | 2063 (amended 2075) | Legal validity of digital signatures, e-contracts, and e-documents. | Fine up to NPR 10 lakh or imprisonment (3 years). |
| Cyber Security Act | 2075 | Mandates data localization, cybersecurity audits for critical infrastructure (banks, telecom). | Fine up to NPR 1 crore or imprisonment (5 years). |
| Data Privacy Act | (Draft, 2023) | Proposed GDPR-like rules for data collection, consent, and breach notifications. | Not yet enforced (but expected soon). |
Cybercrimes & Offenses
1. Common Cybercrimes in Nepal
mindmap
root((Cybercrimes in Nepal))
Hacking["Unauthorized access to systems (e.g., Ncell databases)"]
Fraud["Fake eSewa/Khalti payments (NPR 50M+ lost annually)"]
Identity Theft["Stealing Aadhaar/eID data to open bank accounts"]
Cyberstalking["Harassment via social media (e.g., Facebook, Pathao driver apps)"]
Data Breach["Leaking customer data (e.g., Daraz supplier databases)"]
Cyber Defamation["Spreading false info online (e.g., fake news on Twitter)"]Worked Example: eSewa Data Breach (2021)
- Crime: Unauthorized access to 1.2 million user records (names, phone numbers, transaction history).
- Legal Violation:
- Cyber Security Act 2075 (Section 18: Unauthorized data access).
- Electronic Transactions Act (Section 12: Fraudulent digital transactions).
- Outcome:
- eSewa fined NPR 50 lakh by the National Payment System Board.
- Users offered free credit monitoring for 1 year.
2. How Cybercrimes Happen: A Trace
Real-World Link: Pathao Driver Scams
- Crime: Fake "Pathao support" calls trick drivers into sharing OTP codes for cash withdrawals.
- Legal Basis:
- Cyber Security Act 2075 (Section 20: Fraud via digital means).
- Telecom Act 2018 (Section 35: Misuse of telecom services).
Data Privacy & User Rights
1. What is Data Privacy?
Data privacy is the right to control how your personal data is collected, stored, and used. Key principles:
- Consent: Users must explicitly agree to data collection (e.g., Daraz checkout terms).
- Transparency: Companies must disclose what data they collect (e.g., Facebook’s privacy policy).
- Security: Data must be encrypted and protected (e.g., Ncell’s SIM registration rules).
Comparison: Offline vs. Digital Data Privacy
| Aspect | Offline (Traditional) | Digital (Cyber Law) |
|---|---|---|
| Data Collection | Paper forms (e.g., bank loan apps) | Cookies, GPS, purchase history (e.g., Daraz). |
| Consent | Signed physical forms | Clicking "Agree" buttons (must be informed). |
| Breach Response | Limited (e.g., lost files) | Mandatory reporting (e.g., Ncell must notify users within 72 hours). |
| Enforcement | Civil lawsuits | Cyber Bureau + fines (e.g., NPR 1 crore). |
2. User Rights Under Cyber Law
Worked Example: Ncell SIM Data Leak (2022)
- Issue: Ncell’s third-party vendor leaked 10M SIM records to a marketing firm.
- User Rights Violated:
- Right to Privacy (data shared without consent).
- Right to Grievance (users could file complaints with Nepal Telecom Authority).
- Legal Action:
- Ncell fined NPR 20 lakh under Cyber Security Act 2075.
- Users offered free SIM re-registration.
Compliance for Businesses
1. What Companies Must Do
| Requirement | Example for Nepali Businesses | Penalty for Non-Compliance |
|---|---|---|
| Data Localization | Store customer data on Nepal-based servers (not AWS US). | Fine up to NPR 50 lakh (Cyber Security Act). |
| KYC (Know Your Customer) | Verify users via Aadhaar/eID before opening accounts (e.g., Khalti). | Imprisonment (3 years) if fraud enabled. |
| Data Encryption | Use SSL certificates for websites (e.g., Daraz checkout). | NPR 1 crore fine if data breached. |
| Breach Notification | Inform users within 72 hours if data is leaked (e.g., eSewa 2021). | NPR 10 lakh/day until fixed. |
| Age Verification | Block under-18 users (e.g., YouTube, Facebook). | NPR 5 lakh fine per violation. |
2. Case Study: Daraz Nepal’s Compliance
Challenge: Daraz (Alibaba-owned) faced data localization issues in Nepal. Solution:
- Stored user data on servers in Nepal (complying with Cyber Security Act 2075).
- Implemented two-factor authentication (2FA) for payments.
- Published a privacy policy in Nepali (translated from global version). Outcome:
- Avoids NPR 50 lakh fines for non-compliance.
- Builds trust with Nepali users (critical for e-commerce).
In the Real World
eSewa & Khalti (Digital Payments)
- Idea Used: Electronic Transactions Act 2063 (legal validity of digital signatures).
- How? When you pay via eSewa, the digital signature is legally binding—just like a handwritten check.
- Risk: If a hacker steals your OTP, they can file a fraud complaint under Section 19 of the Cyber Security Act.
Ncell & NTC (Telecom Data Privacy)
- Idea Used: Data Localization + KYC Rules.
- How? Ncell must:
- Store all SIM data on Nepal servers.
- Verify Aadhaar/eID before issuing new SIMs (to prevent fraud).
- Real Example: In 2023, NTC blocked 50,000 fake SIMs using AI + KYC checks.
Daraz & Pathao (Cyber Fraud Prevention)
- Idea Used: Cyber Security Act 2075 (Section 20: Fraud Prevention).
- How?
- Daraz: Uses AI to detect fake reviews (cyber defamation).
- Pathao: Driver verification via Nepal Police clearance (prevents scams).
Exam Tip
How This Unit is Tested in PU Exams
Short Questions (2-5 marks)
- Define: Cybercrime, Data Localization, Digital Signature.
- Example:
"Explain the difference between cyber defamation and cyberstalking with examples."
Case Studies (10-15 marks)
- Format: Given a scenario (e.g., "A user’s eSewa account was hacked"), you must:
- Identify the cybercrime (e.g., unauthorized access).
- State the relevant act/section (e.g., Cyber Security Act 2075, Section 18).
- Suggest legal remedies (e.g., file complaint with Cyber Bureau, demand data deletion).
- Example Question:
"Nabil Bank’s online portal was hacked, and 50,000 customers’ data was leaked. What legal actions can the bank take? What penalties might the hacker face?"
- Format: Given a scenario (e.g., "A user’s eSewa account was hacked"), you must:
Comparisons (5-10 marks)
- Compare offline vs. digital contracts, GDPR vs. Nepal’s Data Privacy Act, or hacking vs. cyberstalking.
- Example Table to Memorize:
Offline Contract Digital Contract (e-Contract) Handwritten/signed Digital signature or OTP confirmation Physical storage Cloud/encrypted databases Dispute: Civil Court Dispute: Cyber Bureau or District Court Example: Loan agreement Example: Daraz order confirmation email
True/False + Justification (3-5 marks)
- Example:
"Digital signatures are legally invalid in Nepal." Answer: False. The Electronic Transactions Act 2063 makes them valid if:
- The signer’s Aadhaar/eID is verified.
- The signature is encrypted and tamper-proof.
- Example:
Top 5 Exam Strategies
Memorize Key Sections:
- Cyber Security Act 2075: Sections 18 (Unauthorized Access), 19 (Fraud), 20 (Cyber Defamation).
- Electronic Transactions Act 2063: Sections 5 (Digital Signature), 12 (Fraudulent Transactions).
Use Real Examples:
- Always tie answers to eSewa, Ncell, Daraz, or Nabil Bank (examiners love this).
Draw Flowcharts for Cases:
- For case studies, map out steps like this:
Hacker → Phishing Email → Victim Clicks → Data Stolen → Cyber Bureau Complaint → Police Arrest
- For case studies, map out steps like this:
Practice Past Papers:
- PU often asks about:
- Data breach responses (72-hour rule).
- KYC compliance (Aadhaar/eID verification).
- Penalties for cybercrimes (fines + imprisonment).
- PU often asks about:
Watch for Tricks:
- Distinguish between:
- Cybercrime (illegal act, e.g., hacking) vs. Cyber Law (legal rules).
- Data Privacy (user rights) vs. Data Security (protection from breaches).
- Distinguish between:
Based on the PU BBA (PU) syllabus for Legal Aspects of Business and Technology, unit 10.
Discussion
Loading…