The Ministry of Road Transport (MoRTH) and Highways have released a Bulk Data Sharing Policy & Procedure wherein it states who should buy bulk automobile statistics of Registration Certificates (RCs) and Driving Licenses (DLs), what it may do with it and how much the information will fee. MoRTH says that it stocks information with enforcement groups, automobile industries, banks, finance agencies, etc. at distinct charges for each statistics set.
Note that the ministry did not maintain any public consultations before releasing this policy, neither does it move into precise information about the need for it, the call for, or how it will make sure that the privacy of people is conserved.
On the need for the policy, MoRTH says that “It is diagnosed that sharing these records for other purposes, in a controlled manner, can assist the shipping and vehicle industry… help in provider improvements… gain us of an economic system. (sic) There has been developing a call to share the records for wider blessings.” (Note: does now not specify the ‘wider advantages.’)
However, it also adds that the ministry isn’t always in a role to “make sure the sanctity of the records which could be made available on “as-is-in which-is” basis” because of to the digital and analog divide of the to be had data.
Who is eligible to buy bulk facts
The employer must be India registered with at the least 50% Indian resident or Indian company possession
All bulk statistics it accesses must be processed, saved in data centers and servers in India, and can not be transferred to servers outside India
The Analytics company (uncertain if MoRTH method the same “business enterprise” shopping for the majority statistics or otherwise) “must post a safety pre-audit document from Cert-In empaneled safety auditor. The record needs to ensure that:
(i) Proper get entry to manipulate mechanism is in the vicinity. Information is maintained about any individuals having access to the statistics. (Note: The Ministry does no longer specify how this must be done.)
(ii) Audit logging of all get right of entry to of the data is maintained.
(iii) All statistics are kept in the primary region in a relaxed way and is accessed thru a software over LAN or WAN over the informal channel.
(iv) The application shall be free from the top 10 OWASP vulnerability.
(v) Data Loss prevention mechanism shall make sure the following:
Monitor and block statistics transfers – Monitor, control and block any touchy facts being moved from the records processing employer network. This includes e-mails, documents, browser any utility, etc. This is to be finished through content material & context conscious protection.
Cross-Platform protection – Through regulations to be ensured that touchy data is not living in computers walking over Windows, Linux or Mac OS. Discover this sort of information, which will be deleted or encrypted.
End Point Protection – Protection of facts in all forms of giving up-factors either desktops, laptops, cell devices against loss and robbery.
Device Control – Through policies control and set rights for detachable gadgets and ports on the endpoints.
Audit path & hobby logger – Maintain pastime record to make sure that files aren’t always being leaked.
The DLP shall be done via deployment of proper solution (software & hardware) in the company while managing the records. All touchy statistics to be in encrypted layout while saved in a disk and best to be decrypted even as accessed via the right mechanism.”
The fee of bulk data
Companies can purchase statistics for one calendar yr at any time – this data could be furnished in 4 facts dumps on 1st January, 1st April, 1st July and 1st October of each calendar 12 months. These dumps may have facts up to the ultimate day of the preceding month.
Bulk statistics will price Rs 3 crore for FY 2019-20.
“Educational institutions can use this statistics simplest for research purposes for internal use only and would be furnished the majority statistics one time on a charge of an amount of Rs 5 lakh best for the FY 2019-20.”
Educational & Research institutions the usage of the records for any technical functions pays Rs three crore for FY 2019-20.
“There will be an annual boom of 5% from the FY 2020-21 onwards.”
How the data might be provided
“Data in bulk will be launched in an encrypted layout. With the public key of the nodal person of the buying organization who will control the records securely.
Data could be supplied on as-is-in which-is foundation. No claims can be entertained in case some facts/data is found to be missing.”
Companies looking at the information will provide a “protection audit document.” The business enterprise has to “ensure the integrity of the information and security of information is included. Correct use of information, including regulations on de-anonymizing, is precisely enforced through proper get admission to control.” “Any non-compliance of Data Loss prevention or dealing with of sensitive statistics will result in termination of the contract.”
“The 2nd quarter of information may be supplied after receipt of protection audit compliance report for the beyond records.
All Data furnished might be non-transferable and cannot be re-sold on as-is or file foundation. However, the employer can promote analytics reviews, forecasting, every other review based totally in these records.