The Ministry of Road Transport (MoRTH) and Highways have released a Bulk Data Sharing Policy & Procedure wherein it states who should buy bulk automobile statistics of Registration Certificates (RCs) and Driving Licenses (DLs), what it may do with it, and how much the information will fee. MoRTH says that it stocks information with enforcement groups, automobile industries, banks, finance agencies, etc., at distinct charges for each statistics set.
Note that the ministry did not maintain any public consultations before releasing this policy. Neither does it move into precise information about the need for it, the call for, or how it will ensure that people’s privacy is conserved.
On the need for the policy, MoRTH says that “It is diagnosed that sharing these records for other purposes, in a controlled manner, can assist the shipping and vehicle industry… help in provider improvements… gain us of an economic system. (sic) There has been developing a call to share the records for wider blessings.” (Note: does now not specify the ‘wider advantages.’)
However, it also adds that the ministry isn’t always in a role to “make sure the sanctity of the records could be made available on “as-is-in which-is” basis” because of the digital and analog divide of the to be had data.
Who is eligible to buy bulk facts
The employer must be India registered with at the least 50% Indian resident or Indian company possession
All bulk statistics it accesses must be processed, saved in data centers and servers in India, and can not be transferred to servers outside India.
The Analytics company (uncertain if MoRTH method the same “business enterprise” shopping for the majority statistics or otherwise) “must post a safety pre-audit document from Cert-In empaneled safety auditor. The record needs to ensure that:
(i) Proper get entry to manipulate mechanism is in the vicinity. Information is maintained about any individuals having access to the statistics. (Note: The Ministry does no longer specify how this must be done.)
(ii) Audit logging of all get right of entry to of the data is maintained.
(iii) All statistics are kept in the primary region in a relaxed way and are accessed thru software over LAN or WAN over the informal channel.
(iv) The application shall be free from the top 10 OWASP vulnerabilities.
(v) Data Loss prevention mechanism shall make sure the following:
Monitor and block statistics transfers – Monitor, control, and block any touchy facts being moved from the records processing employer network. This includes e-mails, documents, browser, any utility, etc. This is to be finished through content material & context conscious protection.
Cross-Platform protection – Through regulations to be ensured that touchy data is not living in computers walking over Windows, Linux, or Mac OS. Discover this sort of information, which will be deleted or encrypted.
End Point Protection – Protection of facts in all forms of giving up-factors, either desktops, laptops, cell devices, against loss and robbery.
Device Control – Through policies, control and set rights for detachable gadgets and ports on the endpoints.
Audit path & hobby logger – Maintain pastime records to ensure that files aren’t always leaked.
The DLP shall be done via the deployment of proper solutions (software & hardware) while managing the records. All touchy statistics to be in encrypted layout while saved in a disk and best to be decrypted even as accessed via the right mechanism.”
The fee of bulk data
Companies can purchase statistics for one calendar yr at any time – this data could be furnished in 4 facts dumps on 1st January, 1st April, 1st July and 1st October of each calendar 12 months. These dumps may have facts up to the ultimate day of the preceding month.
Bulk statistics will price Rs 3 crore for FY 2019-20.
“Educational institutions can use this statistics simplest for research purposes for internal use only and would be furnished the majority statistics one time on a charge of an amount of Rs 5 lakh best for the FY 2019-20.”
Educational & Research institutions using the records for any technical functions pay Rs three crore for FY 2019-20.
“There will be an annual boom of 5% from the FY 2020-21 onwards.”
How the data might be provided
“Data in bulk will be launched in an encrypted layout, with the public key of the nodal person of the buying organization who will control the records securely.
Data could be supplied on as-is-in which-is foundation. No claims can be entertained in case some facts/data is found to be missing.”
Companies looking at the information will provide a “protection audit document.” The business enterprise has to “ensure the integrity of the information and security of information is included. Correct use of information, including regulations on de-anonymizing, is precisely enforced through proper get admission to control.” “Any non-compliance of Data Loss prevention or dealing with of sensitive statistics will result in termination of the contract.”
“The 2nd quarter of information may be supplied after receipt of protection audit compliance report for the beyond records.
All Data furnished might be non-transferable and cannot be re-sold on an as-is or file foundation. However, the employer can promote analytics reviews, forecasting, every other review based totally on these records.