cloud consultation

Vickram Crishna <v1clist-/[email protected]> Sun, 12 Jun 2016 10:44:09 +0000 (UTC)
Newsgroups gmane.org.telecom.india-gii
Message-ID <[email protected]>
--===============4606538937097138201==
Content-Type: multipart/alternative; 
	boundary="----=_Part_2677641_1344402165.1465728249721"
Content-Length: 29896

------=_Part_2677641_1344402165.1465728249721
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable


An assessment (The Wire):
http://thewire.in/2016/06/11/cross-border-data-flows-debate-hits-india-as-t=
rai-issues-paper-on-cloud-services-42300/





Cross-Border Data Flows Debate Hits India as TRAI Issues Paper on Cloud Ser=
vices
BY=C2=A0ANUJ SRIVAS=C2=A0ON=C2=A011/06/2016=C2=A0
Clocking in at a whopping 119 pages and a little over 20 questions, this is=
 one of TRAI=E2=80=99s most broadly-focused and comprehensive consultations=
 in recent times.

Data centres are the new battleground of regulation when it comes to privac=
y and data protection. Credit: Sean Ellis, Flickr CC BY 2.0

New Delhi:=C2=A0With a=C2=A0new consultation paper=C2=A0on cloud computing,=
 the Telecom Regulatory Authority of India (TRAI) is looking to continue it=
s trend of tackling the biggest and most burning digital issues that face I=
ndia=E2=80=99s government.

This time around, the telecom regulator is looking to kick-start debate ove=
r the challenges that arise in regulating the flow of data through the nume=
rous cloud-based platforms that underpin our digital life.

Questions of cross-border flow of data, licensing of cloud-based services a=
nd best practices on how to successfully carry out law-enforcement requests=
 are a few examples. Clocking in at a whopping 119 pages and a little over =
20 questions, this is one of TRAI=E2=80=99s most broadly-focused and compre=
hensive consultations in recent times.

While the paper addresses everything from how to increase implementation of=
 government cloud services to interoperability and security issues, the por=
tion concerning the legal and regulatory framework for domestic and foreign=
 cloud services is likely to be the focus of debate and discussion in the c=
oming weeks.

=E2=80=9CRegulations should be put in place to protect the interests of bot=
h cloud services providers and the consumers.Regulations are also required =
for standardization of technical parameters associated with cloud computing=
 networks. Legal framework under which the cloud operates becomes very impo=
rtant..,=E2=80=9D the regulator says in the paper=E2=80=99s introductory se=
ction.

The rest of the paper is divided into six broad sections: cloud security, q=
uality of service, interoperability, legal framework for jurisdictions, cos=
t benefit analysis and incentivising the implementation of cloud services i=
n governments.=C2=A0The Wire=C2=A0breaks down the most crucial portions bel=
ow, with examples of the problems that India is currently undergoing=E2=80=
=A6

Security and=C2=A0cross-border =E2=80=93 where, when and why?

In a sub-section on =E2=80=98Cross Border or Data Location Security Issues=
=E2=80=99, TRAI implicitly references=C2=A0the global debate=C2=A0on what r=
estrictions should be applied to the free flow of data by detailing how var=
ious European Union States have dealt with the issue.

=E2=80=9COne of the top security concerns=E2=80=A6 is the physical location=
 of the data especially if they are located in another country because the =
laws of the host country apply to the machine and data residing on it=E2=80=
=A6As an example, the data protection laws of the European Union member sta=
tes are extremely complex. The transfer of personal data outside these regi=
ons needs to be handled in very specific way,=E2=80=9D the paper states.

The problem that confronts and concerns the privacy of India=E2=80=99s resi=
dents, that TRAI is looking to gain more information on, is this: Should In=
ternet services be, at minimum, required to inform you that your data is be=
ing sent and processed outside India?=C2=A0 Building on this principle, in =
a more extreme measure, if data is sent outside India should a data control=
ler in India ensure that specific conditions surrounding the privacy and se=
curity of that data are met?

The issues surrounding the security of every jurisdiction that is part of t=
he cross-border data flow process are addressed in questions 10 and 11 of t=
he consultation paper:

Question 10- Enumerate in detail with justification, the provisions that ne=
ed to be put in place to ensure that the cloud services being offered are s=
ecure.

Question 11 =E2=80=93 What are the termination or exit provisions that need=
 to be defined for ensuring security of data or information over cloud?

Whither regulatory framework?

In the opening parts of the section on what legal and regulatory frameworks=
 could be applied to cloud computing and data sovereignty in India, TRAI ex=
amines currently existing legislation and how it could be applied to the pr=
oblem at hand.

The regulator starts from the Indian Telegraph Act of 1885 and goes up to t=
he much-criticized Information Technology Act =E2=80=93 2000 & Information =
Technology Rules 2011. Most significantly, TRAI notes that the =E2=80=9Cwid=
e-reaching jurisdiction conferred by the IT Act=E2=80=9D with regard to dat=
a ownership/privacy/security=E2=80=9D could lay the groundwork for imposing=
 =C2=A0Indian jurisdiction on issues =E2=80=9Carising from the use of cloud=
 services by Indian persons=E2=80=9D.

While the idea of using Indian jurisdiction and legal justification for Ind=
ian users of foreign services isn=E2=80=99t new in other industries, this i=
s the first proper articulation of a similar approach for the digital spher=
e. Ultimately, however, TRAI dismisses existing legislation as =E2=80=9Cthe=
y don=E2=80=99t contemplate the scope of cloud computing services and the r=
esultant magnification of the issues..=E2=80=9D. Consequently, it calls for=
 the birth of new and =E2=80=9Cspecific regulation whereby any emergent iss=
ues can be dealt with directly and effectively.=E2=80=9D

What should this regulatory framework deal with? The consultation paper poi=
nts in a few directions, all of which are hotly contested in legal-technolo=
gy-policy circles and even amongst various Western governments.

Law enforcement

The framework, as TRAI spells out, should ideally deal with =E2=80=9Cregula=
tion of investigatory powers, regulation on stored communication, mandatory=
 guidelines for national security, state privacy laws=E2=80=9D.

However, the paper itself devotes good chunk of attention towards law enfor=
cement. TRAI starts from a basic assumption, that the Internet and digital =
ICTs has hobbled the practice of law enforcement; a phenomenon that most re=
cently manifested in the showdown between Apple and the FBI.

The consultation paper helpfully points out that =E2=80=9Cmachines and data=
 are no longer physically in one place or national boundary=E2=80=9D and th=
at today=E2=80=99s =E2=80=9Cencryption and security of data are far stronge=
r and of industrial grade.=E2=80=9D Consequently,=C2=A0Question 15=C2=A0ask=
s: =E2=80=9CWhat polices [sic], systems and processes are required to be de=
fined for information governance framework in Cloud, from lawful intercepti=
on point of view and particularly if it is hosted in a different country?=
=E2=80=9D

One solution that TRAI offers to the problem of law enforcement is a rather=
 blatant reference to the concept of data localisation =E2=80=94 where the =
data of Indian users would remain on Indian soil. =E2=80=9CTo overcome the =
problem of multiple jurisdictions, one of the possibilities may be to manda=
te the cloud service providers to host the data centres only in India,=E2=
=80=9D the paper says.

Other less controversial examples include bringing about a US regime on dat=
a, where critical information such as health records, financial transaction=
s and tax returns would come with specific restrictions if transferred acro=
ss different countries. For instance, in this case, the medical or health d=
ata of Indian residents would not be sent to countries that India deems uns=
afe or lacking in data protection laws.

Unfortunately, it appears that in order to strictly regulate foreign and do=
mestic cloud companies, TRAI falls back on a much-criticized example: a lic=
ence regime.=C2=A0Question 16=C2=A0of the consultation paper asks: =E2=80=
=9CWhat shall be the scope of cloud computing services in law? What is your=
 view on providing licence or registration to cloud service providers so as=
 to subject them to the obligations thereunder?=E2=80=9D

The idea of a licence regime for technology companies is not new: China, an=
d to a lesser extent Russia, have perfected this model. If companies like U=
ber for instance wish to operate in either China or Russia they are require=
d to open local data centres where the data of the company=E2=80=99s Russia=
n and Chinese users must be stored. Closer to home, TRAI=E2=80=99s last con=
sultation paper on OTT (over-the-top) applications also hinted at whether a=
 licence regime would be necessary to help regulate instant messaging compa=
nies such as WhatsApp.

On the other hand, TRAI still appears to be open to other solutions to how =
to more effectively enforce law-enforcement in the time of Facebook and Goo=
gle. The=C2=A0issue of prodding=C2=A0Silicon Valley-based companies into he=
lping out Indian security agencies such as CBI assumed centre-stage during =
Prime Minister Modi=E2=80=99s recent to the US. Both governments=C2=A0relea=
sed=C2=A0a =E2=80=9Cframework for US-India Cyber Relationship=E2=80=9D, one=
 point in which expresses =E2=80=9C a commitment to promote closer cooperat=
ion among law enforcement agencies to combat cybercrime=E2=80=9D.

TRAI, and consequently the Department of Telecommunications, appear to be i=
nterested in this as well.=C2=A0Question 17=C2=A0of the paper asks the publ=
ic =E2=80=9Cwhat protocol for cloud service providers to submit to the terr=
itorial jurisdiction of India for the purpose of lawful access of informati=
on?=E2=80=9D

Carrot and the stick

The final section of the TRAI consultation paper, mostly because in additio=
n to the stick of forcing companies to open data centres in India, it also =
seems open to receiving feedback on how market incentives can accelerate cl=
oud adoption in government services and encourage domestic cloud services.

The regulator correctly notes that in countries such as India (and even Bra=
zil to a lesser extent) physical factors such as the lack of a reliable pow=
er supply, road infrastructure as well as network stability have resulted i=
n an environment that doesn=E2=80=99t encourage local or domestic data cent=
res.

It also notes that in order to make up for these disadvantages, it=E2=80=99=
s possible that a new tax regime is necessary. =E2=80=9CIt is to be conside=
red as to what tax regime should be employed for cloud service providers in=
 india and whether tax benefits shall be given to them, for promoting the a=
doption of cloud services in the country,=E2=80=9D the paper says.

Questions=C2=A018-21 address this: Should tax subsidies be given? What step=
s can be taken to promote establishment centres of data centres in India? S=
hould there be a dedicated cloud for government applications?

Simply put, TRAI, who after this round of consultations will submit a set o=
f recommendations to the Department of Telecommunications, is looking to ta=
me the Wild Wild West that is cloud services in India today. How should dat=
a that is created by Indians, in India, on foreign technology platforms be =
governed? How should that data be treated? Is it even possible without nati=
onal privacy and data protection legislation? How can the long arm of law e=
nforcement be restored?

TRAI hopes to answer these questions and in the process, shape the digital =
future of India.

Sent from Yahoo Mail on Android
------=_Part_2677641_1344402165.1465728249721
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div><br></div><div id=3D"message" class=3D"mail-message-content " style=3D=
"font-family: sans-serif; font-size: 28.16px; zoom: 1.86335;"><div dir=3D"l=
tr"><div class=3D"gmail_quote" style=3D"clear: both;"><div dir=3D"ltr"><div=
 id=3D"yMail_cursorElementTracker_0.2612860649741797">An assessment (The Wi=
re):</div><div><br></div><div><a href=3D"http://thewire.in/2016/06/11/cross=
-border-data-flows-debate-hits-india-as-trai-issues-paper-on-cloud-services=
-42300/" target=3D"_blank" data-saferedirecturl=3D"https://www.google.com/u=
rl?q=3Dhttp://thewire.in/2016/06/11/cross-border-data-flows-debate-hits-ind=
ia-as-trai-issues-paper-on-cloud-services-42300/&amp;source=3Dgmail&amp;ust=
=3D1465797490324000&amp;usg=3DAFQjCNEcyizK-gmn-kYY2qLWVuzm3KdDOA">http://th=
ewire.in/2016/06/11/<wbr>cross-border-data-flows-<wbr>debate-hits-india-as-=
trai-<wbr>issues-paper-on-cloud-<wbr>services-42300/</a><br></div><div><br>=
</div><div><br></div><div><br></div><div><br></div><div><h1 style=3D"font-s=
ize: 56.7182px; margin: 0px 0px 5px; color: rgb(26, 26, 26); font-family: L=
ato, Arial, sans-serif; line-height: 1.1667;">Cross-Border Data Flows Debat=
e Hits India as TRAI Issues Paper on Cloud Services</h1><div style=3D"font-=
size: 0.75em; color: rgb(153, 153, 153); margin: 5px 0px 30px 1px; text-tra=
nsform: uppercase; letter-spacing: 1px; font-family: 'Noto Serif', Georgia,=
 serif;">BY&nbsp;<a href=3D"http://thewire.in/author/asrivas/" title=3D"Vie=
w all posts by Anuj Srivas" rel=3D"author" target=3D"_blank" data-saferedir=
ecturl=3D"https://www.google.com/url?q=3Dhttp://thewire.in/author/asrivas/&=
amp;source=3Dgmail&amp;ust=3D1465797490324000&amp;usg=3DAFQjCNHARHwe7VbJ092=
mxm0aav1n7_Zt6Q" style=3D"color: rgb(214, 85, 72); text-decoration: none;">=
ANUJ SRIVAS</a>&nbsp;ON&nbsp;<a href=3D"http://thewire.in/2016/06/11/cross-=
border-data-flows-debate-hits-india-as-trai-issues-paper-on-cloud-services-=
42300/" title=3D"4:30 pm" rel=3D"bookmark" target=3D"_blank" data-saferedir=
ecturl=3D"https://www.google.com/url?q=3Dhttp://thewire.in/2016/06/11/cross=
-border-data-flows-debate-hits-india-as-trai-issues-paper-on-cloud-services=
-42300/&amp;source=3Dgmail&amp;ust=3D1465797490324000&amp;usg=3DAFQjCNEcyiz=
K-gmn-kYY2qLWVuzm3KdDOA" style=3D"color: rgb(214, 85, 72); text-decoration:=
 none;">11/06/2016</a>&nbsp;</div><div style=3D"clear: both;"><div style=3D=
"padding: 15px 0px 10px; border-color: rgba(0, 0, 0, 0.0470588);"><div></di=
v><div></div></div></div><h3 style=3D"font-size: 22.6869px; margin-bottom: =
15px; color: rgb(26, 26, 26); font-family: Lato, Arial, sans-serif; line-he=
ight: 1.1667; margin-top: 0px; font-weight: normal;">Clocking in at a whopp=
ing 119 pages and a little over 20 questions, this is one of TRAI=E2=80=99s=
 most broadly-focused and comprehensive consultations in recent times.</h3>=
<div data-width=3D"917px" data-minwidth=3D"" data-maxwidth=3D"100%" style=
=3D"padding: 5px; text-align: center; margin: 10px auto 15px; max-width: 10=
0%; clear: both; width: 917px; background: rgb(242, 242, 242);"><p style=3D=
"margin: 0px; padding: 0px; color: rgb(128, 128, 128); font-size: 0.8em;">D=
ata centres are the new battleground of regulation when it comes to privacy=
 and data protection. Credit: Sean Ellis, Flickr CC BY 2.0</p></div><p styl=
e=3D"margin: 0px 0px 30px;"><b>New Delhi:</b>&nbsp;With a&nbsp;<a href=3D"h=
ttp://www.trai.gov.in/WriteReaddata/ConsultationPaper/Document/Cloud_Comput=
ing_Consultation_paper_10_june_2016.pdf" target=3D"_blank" data-saferedirec=
turl=3D"https://www.google.com/url?q=3Dhttp://www.trai.gov.in/WriteReaddata=
/ConsultationPaper/Document/Cloud_Computing_Consultation_paper_10_june_2016=
.pdf&amp;source=3Dgmail&amp;ust=3D1465797490324000&amp;usg=3DAFQjCNGRZBOGIM=
bsg4EGNMrG04ckLG4GSw" style=3D"color: rgb(192, 57, 43); text-decoration: no=
ne;">new consultation paper&nbsp;</a>on cloud computing, the Telecom Regula=
tory Authority of India (TRAI) is looking to continue its trend of tackling=
 the biggest and most burning digital issues that face India=E2=80=99s gove=
rnment.</p><p style=3D"margin: 0px 0px 30px;">This time around, the telecom=
 regulator is looking to kick-start debate over the challenges that arise i=
n regulating the flow of data through the numerous cloud-based platforms th=
at underpin our digital life.</p><p style=3D"margin: 0px 0px 30px;">Questio=
ns of cross-border flow of data, licensing of cloud-based services and best=
 practices on how to successfully carry out law-enforcement requests are a =
few examples. Clocking in at a whopping 119 pages and a little over 20 ques=
tions, this is one of TRAI=E2=80=99s most broadly-focused and comprehensive=
 consultations in recent times.</p><p style=3D"margin: 0px 0px 30px;">While=
 the paper addresses everything from how to increase implementation of gove=
rnment cloud services to interoperability and security issues, the portion =
concerning the legal and regulatory framework for domestic and foreign clou=
d services is likely to be the focus of debate and discussion in the coming=
 weeks.</p><p style=3D"margin: 0px 0px 30px;">=E2=80=9CRegulations should b=
e put in place to protect the interests of both cloud services providers an=
d the consumers.Regulations are also required for standardization of techni=
cal parameters associated with cloud computing networks. Legal framework un=
der which the cloud operates becomes very important..,=E2=80=9D the regulat=
or says in the paper=E2=80=99s introductory section.</p><p style=3D"margin:=
 0px 0px 30px;">The rest of the paper is divided into six broad sections: c=
loud security, quality of service, interoperability, legal framework for ju=
risdictions, cost benefit analysis and incentivising the implementation of =
cloud services in governments.&nbsp;<i>The Wire</i>&nbsp;breaks down the mo=
st crucial portions below, with examples of the problems that India is curr=
ently undergoing=E2=80=A6</p><p style=3D"margin: 0px 0px 30px;"><b>Security=
 and&nbsp;cross-border =E2=80=93 where, when and why?</b></p><p style=3D"ma=
rgin: 0px 0px 30px;">In a sub-section on =E2=80=98Cross Border or Data Loca=
tion Security Issues=E2=80=99, TRAI implicitly references&nbsp;<a href=3D"h=
ttps://www.washingtonpost.com/news/monkey-cage/wp/2016/06/02/the-u-s-wants-=
to-maintain-cross-border-data-flows-that-may-be-tough/" target=3D"_blank" d=
ata-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://www.washingto=
npost.com/news/monkey-cage/wp/2016/06/02/the-u-s-wants-to-maintain-cross-bo=
rder-data-flows-that-may-be-tough/&amp;source=3Dgmail&amp;ust=3D14657974903=
24000&amp;usg=3DAFQjCNHjuapC_xh7T9x9mfYsVUZYkCZ_og" style=3D"color: rgb(192=
, 57, 43); text-decoration: none;">the global debate</a>&nbsp;on what restr=
ictions should be applied to the free flow of data by detailing how various=
 European Union States have dealt with the issue.</p><p style=3D"margin: 0p=
x 0px 30px;">=E2=80=9COne of the top security concerns=E2=80=A6 is the phys=
ical location of the data especially if they are located in another country=
 because the laws of the host country apply to the machine and data residin=
g on it=E2=80=A6As an example, the data protection laws of the European Uni=
on member states are extremely complex. The transfer of personal data outsi=
de these regions needs to be handled in very specific way,=E2=80=9D the pap=
er states.</p><p style=3D"margin: 0px 0px 30px;">The problem that confronts=
 and concerns the privacy of India=E2=80=99s residents, that TRAI is lookin=
g to gain more information on, is this: Should Internet services be, at min=
imum, required to inform you that your data is being sent and processed out=
side India?&nbsp; Building on this principle, in a more extreme measure, if=
 data is sent outside India should a data controller in India ensure that s=
pecific conditions surrounding the privacy and security of that data are me=
t?</p><p style=3D"margin: 0px 0px 30px;">The issues surrounding the securit=
y of every jurisdiction that is part of the cross-border data flow process =
are addressed in questions 10 and 11 of the consultation paper:</p><p style=
=3D"margin: 0px 0px 30px;"><i>Question 10- Enumerate in detail with justifi=
cation, the provisions that need to be put in place to ensure that the clou=
d services being offered are secure.</i></p><p style=3D"margin: 0px 0px 30p=
x;"><i>Question 11 =E2=80=93 What are the termination or exit provisions th=
at need to be defined for ensuring security of data or information over clo=
ud?</i></p><p style=3D"margin: 0px 0px 30px;"><b>Whither regulatory framewo=
rk?</b></p><p style=3D"margin: 0px 0px 30px;">In the opening parts of the s=
ection on what legal and regulatory frameworks could be applied to cloud co=
mputing and data sovereignty in India, TRAI examines currently existing leg=
islation and how it could be applied to the problem at hand.</p><p style=3D=
"margin: 0px 0px 30px;">The regulator starts from the Indian Telegraph Act =
of 1885 and goes up to the much-criticized Information Technology Act =E2=
=80=93 2000 &amp; Information Technology Rules 2011. Most significantly, TR=
AI notes that the =E2=80=9Cwide-reaching jurisdiction conferred by the IT A=
ct=E2=80=9D with regard to data ownership/privacy/security=E2=80=9D could l=
ay the groundwork for imposing &nbsp;Indian jurisdiction on issues =E2=80=
=9Carising from the use of cloud services by Indian persons=E2=80=9D.</p><p=
 style=3D"margin: 0px 0px 30px;">While the idea of using Indian jurisdictio=
n and legal justification for Indian users of foreign services isn=E2=80=99=
t new in other industries, this is the first proper articulation of a simil=
ar approach for the digital sphere. Ultimately, however, TRAI dismisses exi=
sting legislation as =E2=80=9Cthey don=E2=80=99t contemplate the scope of c=
loud computing services and the resultant magnification of the issues..=E2=
=80=9D. Consequently, it calls for the birth of new and =E2=80=9Cspecific r=
egulation whereby any emergent issues can be dealt with directly and effect=
ively.=E2=80=9D</p><p style=3D"margin: 0px 0px 30px;">What should this regu=
latory framework deal with? The consultation paper points in a few directio=
ns, all of which are hotly contested in legal-technology-policy circles and=
 even amongst various Western governments.</p><p style=3D"margin: 0px 0px 3=
0px;"><b>Law enforcement</b></p><p style=3D"margin: 0px 0px 30px;">The fram=
ework, as TRAI spells out, should ideally deal with =E2=80=9Cregulation of =
investigatory powers, regulation on stored communication, mandatory guideli=
nes for national security, state privacy laws=E2=80=9D.</p><p style=3D"marg=
in: 0px 0px 30px;">However, the paper itself devotes good chunk of attentio=
n towards law enforcement. TRAI starts from a basic assumption, that the In=
ternet and digital ICTs has hobbled the practice of law enforcement; a phen=
omenon that most recently manifested in the showdown between Apple and the =
FBI.</p><p style=3D"margin: 0px 0px 30px;">The consultation paper helpfully=
 points out that =E2=80=9Cmachines and data are no longer physically in one=
 place or national boundary=E2=80=9D and that today=E2=80=99s =E2=80=9Cencr=
yption and security of data are far stronger and of industrial grade.=E2=80=
=9D Consequently,&nbsp;<i>Question 15</i>&nbsp;asks: =E2=80=9CWhat polices =
[sic], systems and processes are required to be defined for information gov=
ernance framework in Cloud, from lawful interception point of view and part=
icularly if it is hosted in a different country?=E2=80=9D</p><p style=3D"ma=
rgin: 0px 0px 30px;">One solution that TRAI offers to the problem of law en=
forcement is a rather blatant reference to the concept of data localisation=
 =E2=80=94 where the data of Indian users would remain on Indian soil. =E2=
=80=9CTo overcome the problem of multiple jurisdictions, one of the possibi=
lities may be to mandate the cloud service providers to host the data centr=
es only in India,=E2=80=9D the paper says.</p><p style=3D"margin: 0px 0px 3=
0px;">Other less controversial examples include bringing about a US regime =
on data, where critical information such as health records, financial trans=
actions and tax returns would come with specific restrictions if transferre=
d across different countries. For instance, in this case, the medical or he=
alth data of Indian residents would not be sent to countries that India dee=
ms unsafe or lacking in data protection laws.</p><p style=3D"margin: 0px 0p=
x 30px;">Unfortunately, it appears that in order to strictly regulate forei=
gn and domestic cloud companies, TRAI falls back on a much-criticized examp=
le: a licence regime.&nbsp;<i>Question 16</i>&nbsp;of the consultation pape=
r asks: =E2=80=9CWhat shall be the scope of cloud computing services in law=
? What is your view on providing licence or registration to cloud service p=
roviders so as to subject them to the obligations thereunder?=E2=80=9D</p><=
p style=3D"margin: 0px 0px 30px;">The idea of a licence regime for technolo=
gy companies is not new: China, and to a lesser extent Russia, have perfect=
ed this model. If companies like Uber for instance wish to operate in eithe=
r China or Russia they are required to open local data centres where the da=
ta of the company=E2=80=99s Russian and Chinese users must be stored. Close=
r to home, TRAI=E2=80=99s last consultation paper on OTT (over-the-top) app=
lications also hinted at whether a licence regime would be necessary to hel=
p regulate instant messaging companies such as WhatsApp.</p><p style=3D"mar=
gin: 0px 0px 30px;">On the other hand, TRAI still appears to be open to oth=
er solutions to how to more effectively enforce law-enforcement in the time=
 of Facebook and Google. The&nbsp;<a href=3D"http://www.thehindu.com/opinio=
n/op-ed/what-apple-versus-fbi-means-for-india/article8272521.ece" target=3D=
"_blank" data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttp://www.=
thehindu.com/opinion/op-ed/what-apple-versus-fbi-means-for-india/article827=
2521.ece&amp;source=3Dgmail&amp;ust=3D1465797490324000&amp;usg=3DAFQjCNHB_B=
mBV_8x2hcuKGFY0EmV1mGq-Q" style=3D"color: rgb(192, 57, 43); text-decoration=
: none;">issue of prodding</a>&nbsp;Silicon Valley-based companies into hel=
ping out Indian security agencies such as CBI assumed centre-stage during P=
rime Minister Modi=E2=80=99s recent to the US. Both governments&nbsp;<a hre=
f=3D"https://www.whitehouse.gov/the-press-office/2016/06/07/fact-sheet-fram=
ework-us-india-cyber-relationship" target=3D"_blank" data-saferedirecturl=
=3D"https://www.google.com/url?q=3Dhttps://www.whitehouse.gov/the-press-off=
ice/2016/06/07/fact-sheet-framework-us-india-cyber-relationship&amp;source=
=3Dgmail&amp;ust=3D1465797490324000&amp;usg=3DAFQjCNH_k80veYr93rrtNbDZvVT-A=
HJ-bQ" style=3D"color: rgb(192, 57, 43); text-decoration: none;">released</=
a>&nbsp;a =E2=80=9Cframework for US-India Cyber Relationship=E2=80=9D, one =
point in which expresses =E2=80=9C a commitment to promote closer cooperati=
on among law enforcement agencies to combat cybercrime=E2=80=9D.</p><p styl=
e=3D"margin: 0px 0px 30px;">TRAI, and consequently the Department of Teleco=
mmunications, appear to be interested in this as well.&nbsp;<i>Question 17<=
/i>&nbsp;of the paper asks the public =E2=80=9Cwhat protocol for cloud serv=
ice providers to submit to the territorial jurisdiction of India for the pu=
rpose of lawful access of information?=E2=80=9D</p><p style=3D"margin: 0px =
0px 30px;"><b>Carrot and the stick</b></p><p style=3D"margin: 0px 0px 30px;=
">The final section of the TRAI consultation paper, mostly because in addit=
ion to the stick of forcing companies to open data centres in India, it als=
o seems open to receiving feedback on how market incentives can accelerate =
cloud adoption in government services and encourage domestic cloud services=
.</p><p style=3D"margin: 0px 0px 30px;">The regulator correctly notes that =
in countries such as India (and even Brazil to a lesser extent) physical fa=
ctors such as the lack of a reliable power supply, road infrastructure as w=
ell as network stability have resulted in an environment that doesn=E2=80=
=99t encourage local or domestic data centres.</p><p style=3D"margin: 0px 0=
px 30px;">It also notes that in order to make up for these disadvantages, i=
t=E2=80=99s possible that a new tax regime is necessary. =E2=80=9CIt is to =
be considered as to what tax regime should be employed for cloud service pr=
oviders in india and whether tax benefits shall be given to them, for promo=
ting the adoption of cloud services in the country,=E2=80=9D the paper says=
.</p><p style=3D"margin: 0px 0px 30px;"><i>Questions</i>&nbsp;18-21 address=
 this: Should tax subsidies be given? What steps can be taken to promote es=
tablishment centres of data centres in India? Should there be a dedicated c=
loud for government applications?</p><p style=3D"margin: 0px 0px 30px;">Sim=
ply put, TRAI, who after this round of consultations will submit a set of r=
ecommendations to the Department of Telecommunications, is looking to tame =
the Wild Wild West that is cloud services in India today. How should data t=
hat is created by Indians, in India, on foreign technology platforms be gov=
erned? How should that data be treated? Is it even possible without nationa=
l privacy and data protection legislation? How can the long arm of law enfo=
rcement be restored?</p><p style=3D"margin: 0px 0px 30px;" id=3D"yMail_curs=
orElementTracker_0.4675873653569407">TRAI hopes to answer these questions a=
nd in the process, shape the digital future of India.</p></div></div></div>=
</div></div><div id=3D"pinch-jank-hack" style=3D"font-family: sans-serif; f=
ont-size: 28.16px; line-height: 39.424px; height: 100px;"></div><br><div id=
=3D"ymail_android_signature"><a href=3D"https://overview.mail.yahoo.com/mob=
ile/?.src=3DAndroid">Sent from Yahoo Mail on Android</a></div>
------=_Part_2677641_1344402165.1465728249721--


--===============4606538937097138201==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KSW5kaWEtZ2lp
IG1haWxpbmcgbGlzdApJbmRpYS1naWlAbGlzdHMuaW5kaWEtZ2lpLm9yZwpodHRwczovL2xpc3Rz
LmluZGlhLWdpaS5vcmcvbWFpbG1hbi9saXN0aW5mby9pbmRpYS1naWkK

--===============4606538937097138201==--