Showing posts with label Internet Service Providers. Show all posts
Showing posts with label Internet Service Providers. Show all posts

Friday, September 6, 2019

Creating a new legal regime for ‘platforms’

Source: Hindustan Times dated 06.09.2019

By Ananth Padmanabhan (Visiting fellow with the Centre for Policy Research, New Delhi)

The idea of safe harbours was meant to protect digital intermediaries. It is time to now find a new balance


In 2010, professor Tarleton Gillespie called out the astuteness behind YouTube’s appropriation of the term “platform” to reference its activities. As Gillespie rightly noted in an article in New Media & Society, multiple meanings of this word conveniently served to assume the status of champions of user expression while, in parallel, escaping liability for such expression.
In its oldest sense, this term stood for an architectural feature – a raised level surface on which people could stand. But this feature also lent the term a more figurative meaning with time, symbolising the reliance on something to achieve a higher goal. The term has also acquired a computational meaning as being a neutral technical infrastructure that supports various applications. But, in polar opposition to this, are the political connotations of this term when used to signify issues endorsed by a political leader or party.
Gillespie’s attempts at unravelling the multiple meanings of the term “platform” are not only of exceptional academic rigor but also deep practical relevance. Technology companies have used these multiple meanings to lobby for reduced liability for activities on the “platform.” In the online context, policymakers in both the United States and the European Union bought in to this metaphor. Thus, “safe harbours” were crafted to protect digital intermediaries against defamation and other torts and crimes. They were, after all, the engines of free expression and its unhindered transmitters, rather than curators of opinion and content. This placed them in direct contrast with the traditional media industry that invested, and continues to invest, significant resources in their editorial function and ironically, attracts tortious and criminal liability.
The legal position has evolved in India in very different ways though. Starting with the Avnish Bajaj case where a senior official at Baazee.com faced criminal liability for an unfortunate video clip that went up for sale, there was considerable confusion about the extent to which the Information Technology Act, 2000 would rescue the intermediary model. This was later put to test when questions of liability for copyright infringement came up before the Delhi High Court.
In a litigation initiated by T-Series against MySpace, a single judge of the high court found the latter liable for facilitating the upload of the former’s copyrighted content by primary infringers who were subscribers of the digital platform.
The division bench of the Delhi High Court subsequently overturned this verdict and, while doing so, offered policy reasons in support of a more relaxed liability regime. Echoing the policy choices in the United States when “safe harbours” were originally introduced, the bench observed that imposing such great liability on intermediaries would “not only discourage investment, research and development in the Internet sector but also in turn harm the digital economy.” Though considered a progressive verdict that supported the platform model, its effect is largely confined to the Intellectual Property Rights context.
Indian courts, including the Madurai bench of the Madras High Court and multiple benches of the Supreme Court of India, have intervened in situations ranging from TikTok to prenatal diagnostic technique advertisements, to impose strictures and positive obligations on social media platforms and search engines. In December 2018, the ministry of electronics and information technology also proposed amending the intermediary guidelines and rules under the IT Act to mandate automated tools for filtering undesirable content. It is worth noting here that copyright rules in EU have similarly embraced proactive filtering. Subsequently, the Indian debate has also taken the undesirable turn of questioning the need for encryption technologies, with experts arrayed from either side to attack or defend the anonymity of private conversations.
But the drive to generally regulate social media platforms for the content they carry, whether through judicial or executive action, misses the forest for the trees. Moreover, these interventions have rightly attracted criticism on the ground that they are overboard and represent a form of impermissible State-sanctioned restriction against free speech and expression.
What is needed instead is a compensatory regime that addresses grievances of individuals whose reputations are permanently damaged on account of “viral and trending.” Here, platforms are not neutral observers, rather lending the power of the algorithm to multiply manifold the damage of a one-off slur. If traditional media, with its exacting editorial standards, is put to a low threshold for liability, there is no reason to exempt advertising companies that deploy algorithms to gain maximum eyeballs merely for their reliance on the “platform” metaphor.
New legal tests must be devised to hold these platforms liable, including an assessment of how news spreads and the role of the respective platform in assisting with the same, regardless of facial neutrality and their distancing from the actual content. This must necessarily happen on a case-by-case basis. However, we must bear in mind that the business or technology models of today are a far cry, at least from the lens of scale, from what the “safe harbours” were meant to protect.
The occasion is therefore ripe to create new harbours for the models that exist today wherein individuals can anchor their rights and be suitably compensated.

Tuesday, April 16, 2019

To preserve freedoms online, amend the IT Act

Source: Hindustan Times dated 16.04.2019

  • GURSHABAD GROVER (Gurshabad Grover is senior policy officer, the Centre for Internet and Society)

Look into the mechanisms that allow the government and ISPs to carry out online censorship without accountability

The issue of blocking of websites and online services in India has gained traction after internet users reported that services like Reddit and Telegram were inaccessible on certain Internet Service Providers (ISPs). The befuddlement of users calls for a look into the mechanisms that allow the government and ISPs to carry out online censorship without accountability.
Among other things, Section 69A of the Information Technology (IT) Act, which regulates takedown and blocking of online content, allows both government departments and courts to issue directions to ISPs to block websites. Since court orders are in the public domain, it is possible to know this set of blocked websites and URLs. However, the process is much more opaque when it comes to government orders.
The Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009, issued under the Act, detail a process entirely driven through decisions made by executive-appointed officers. Although some scrutiny of such orders is required normally, it can be waived in cases of emergencies. The process does not require judicial sanction, and does not present an opportunity of a fair hearing to the website owner. Notably, the rules also mandate ISPs to maintain all such government requests as confidential, thus making the process and complete list of blocked websites unavailable to the general public.
In the absence of transparency, we have to rely on a mix of user reports and media reports that carry leaked government documents to get a glimpse into what websites the government is blocking. Civil society efforts to get the entire list of blocked websites have repeatedly failed. In response to the Right to Information (RTI) request filed by the Software Freedom Law Centre India in August 2017, the ministry of electronics and information technology refused to provide the entire of list of blocked websites citing national security and public order, but only revealed the number of blocked websites: 11,422.
Unsurprisingly, ISPs do not share this information because of the confidentiality provision in the rules. A 2017 study by the Centre for Internet and Society (CIS) found all five ISPs surveyed refused to share information about website blocking requests. In July 2018, the Bharat Sanchar Nagam Limited rejected the RTI request by CIS which asked for the list of blocked websites.
The lack of transparency, clear guidelines, and a monitoring mechanism means that there are various forms of arbitrary behaviour by ISPs. First and most importantly, there is no way to ascertain whether a website block has legal backing through a government order because of the aforementioned confidentiality clause. Second, the rules define no technical method for the ISPs to follow to block the website. This results in some ISPs suppressing Domain Name System queries (which translate human-parseable addresses like ‘example.com’ to their network address, ‘93.184.216.34’), or using the Hypertext Transfer Protocol (HTTP) headers to block requests. Third, as has been made clear with recent user reports, users in different regions and telecom circles, but serviced by the same ISP, may be facing a different list of blocked websites. Fourth, when blocking orders are rescinded, there is no way to make sure that ISPs have unblocked the websites. These factors mean that two Indians can have wildly different experiences with online censorship.
Organisations like the Internet Freedom Foundation have also been pointing out how, if ISPs block websites in a non-transparent way (for example, when there is no information page mentioning a government order presented to users when they attempt to access a blocked website), it constitutes a violation of the net neutrality rules that ISPs are bound to since July 2018.

Friday, January 4, 2019

Move Fast And Break Things: Government’s new rules on internet regulation could kill innovation and privacy

Source: Times of India dated 04.01.2019

“Move fast and break things” is the now infamous mantra associated with the Silicon Valley internet giants. It’s an approach that prioritised speed of creation, even if mistakes were made on that dizzy path. As it turned out, their blunders were to have a serious impact on society, elections and democracy globally.
Now the Indian government risks falling into the same trap. Last week, it hurriedly revealed proposals to radically change the “Intermediary Liability” rules for internet companies, effectively requiring all internet services to actively censor “unlawful” user content or else face liability for such content.
The aim of holding large social platforms to higher standards of transparency and accountability is a valid one. But the proposals ask internet users to put even more trust into these companies, to decide what content is appropriate and what isn’t, and they haven’t earned that trust yet. Beyond large social media companies, the rules create an existential threat to the many other services they apply to. Perhaps it is the government’s turn to slow down now.
If the internet has been characterised by permission-less innovation and communication, this can be credited in large part to the very rules that are today under threat. The new rules are proposed under Section 79 of the Information Technology Act, which, like its global counterparts, currently ensures that companies generally have no obligations to actively censor content.
Until they know about them, the platforms have only limited liability for the illegal activities and postings of their users. In 2015, the Supreme Court clarified that companies would only be expected to remove user content if they are directed by a court to do so. The new rules turn this logic on its head and propose a zero-tolerance approach to “unlawful content”, where services must “proactively” purge their platforms of such content or else potentially face criminal or civil liability.
The term “unlawful” is not defined, but would likely include all content that is illegal under various laws in India. This ranges from child sexual abuse and videos of rape, to hateful speech against particular religious, caste or other groups, to content that is defamatory or infringes copyright.
Each of these involve legal standards that are vastly different, as is the surrounding context that determines their legality. Take for example, whether a video of a provocative speech was simply a case of advocacy or an incitement to violence. These are complex inquiries, and must be steeped in factual, social and political context.
Social media companies have been in the spotlight recently over controversial decisions to remove content that did not meet their own content guidelines, leading to calls for greater transparency. With the proposed rules, however, they will be further incentivised to “take down first, think later”, or prevent such content from surfacing at all.
Presumably to address the practical questions of scale, the draft rules require companies to deploy “automated tools to filter content”. Rather than creating more transparency about – or fairness in – platforms’ content moderation policies, this will only encourage a black box approach that is bound to lead to inaccurate and opaque decisions on content.
In encouraging automated tools the government is giving primacy to the speed and quantity, rather than the quality, of content removals. These are crude and inappropriate metrics of success where critical fundamental rights are at stake.
Even as the public outcry around unchecked government surveillance is growing, the draft rules also take another step backwards on the question of privacy. The rules also require these services to make available information about the creators or senders of content to government agencies. For end-to-end encrypted messaging platforms like WhatsApp and Signal, this could mean companies will be expected to intentionally store records of who sent messages to whom, with the sole purpose being government surveillance.
The government has justified these moves by invoking “instances of misuse of social media by criminals and anti-national elements”, but the rules they propose go far beyond the handful of companies they refer to. For small and medium-sized online services, as well as start-ups, for example, these content control obligations will be a disproportionate burden.
And the expansive definition of “intermediaries” in these rules would even include internet service providers, browsers and operating systems. For such entities, content control obligations seem entirely misplaced and inapplicable, and yet they create a legal risk that can’t be ignored.
In the full glare of media attention, the government has invited feedback. What this proposal needs, however, is a complete rethink. Building a rights protective framework for tackling illegal content on the internet is a challenging task. But any way you look at it, undermining encryption and outsourcing content regulation to companies are blunt and disproportionate tools.
For better or worse, our fundamental freedoms and rights online are intertwined with the laws that apply to the mediums we use to communicate. This is not about the concerns of a handful of companies alone. Rather than see this move through the trope of big tech versus big brother, we must understand that it is, above all, a threat to internet users.
The writer is a lawyer and public policy adviser at Mozilla