Jio Data Leak Increases Calls for Data Protection Laws in India

Advertisement
By Reuters | Updated: 17 July 2017 09:53 IST
Highlights
  • Jio data breach compromised data of over 100 million customers
  • Companies in India do not have to disclose data breaches to clients
  • In May alone, there were two data security incidents in India

Indian telecom upstart Reliance Jio suffered a major data breach, compromising the personal data of over 100 million customers, have prompted calls for India to adopt more robust laws to protect consumers.

Jio has repeatedly denied any breach took place and said that names, telephone numbers and email addresses of Jio users on a website called "Magicapk" appeared to be "unauthentic." The website was later shut down.

The company, part of conglomerate Reliance Industries, said on Monday that its subscriber data was safe and protected by the highest levels of security.

Advertisement

However, Jio filed a complaint the same day alleging unlawful access to its systems, police have told Reuters.

Advertisement

Jio did not respond to requests for comment.

In contrast to companies in the European Union, which has stringent data protection standards, companies in India do not have to disclose data breaches to clients, information security professionals said.

Advertisement

"It raises questions of security and accountability," said Pranesh Prakash, policy director at the Centre for Internet and Society (CIS), a research organisation.

People complained on Twitter about personal information of Jio users being available on the Magicapk site. Several local news outlets said their checks had led them to believe a leak had occurred.

Advertisement

"A rule to report breaches exists, but it is unenforceable," says Prakash. "It says you're not liable if you're following reasonable security practices. What 'reasonable' means is not defined."

Advocates of stronger laws in India say a data breach in countries with more stringent cyber laws, such as Britain or the United States, would prompt an inquiry by regulators.

After reports of a data leak at Verizon earlier this week, for example, the US telecom firm quickly responded with an explanation of what had occurred, how it had happened and the extent of the problem.

"India is at a nascent stage. For good norms in Asia, look to Singapore. It's been praised for not having cyber security issues by the UN," Srinivas Kodali, an independent security researcher, said.

Not a priority
"We don't have full-menu data protection laws," said Apar Gupta, a Supreme Court lawyer working on data privacy issues. "We don't even have an institutional framework or expert body to implement the limited data protection regulations that do exist. It's so limited it's more accurate to say no law exists."

In May alone, there were two data security incidents in India.

The records of 17 million customers of Zomato, a popular food-delivery app, were put on sale online. Zomato initially advised customers that their passwords were secure, but later advised users to change them.

Separately, a CIS report said the Aadhaar numbers of as many as 135 million Indians had leaked from government databases and could be found online.

The number, similar to a US social security number, is unique to each Indian citizen and the Aadhaar database also stores a user's biometric data. The government is pushing for Aadhaar numbers to be used in everything from opening bank accounts to filing tax returns.

For India, data privacy is not a priority, said Amry Junaideen, a risk advisor at audit firm Deloitte.

"From an organisational perspective there's really no incentive other than being a good corporate citizen, to report a breach," he said, noting that in the European Union and United States the regulatory framework is basically for the good of the consumer, but that this is not the case in India.

India, home to the back offices of many large multinationals and outsourcing companies, has also unsuccessfully sought "data-secure" status from the European Union since 2012.

The status is vital for information sharing between entities in the EU and India, because it means the EU is satisfied that data protection rules in a country meet its standards, so data of EU citizens can be sent to that jurisdiction.

Raman Chima, policy director at Access Now, which advocates stronger digital rights, says weak data privacy laws are likely the main stumbling block to "data-secure" status.

In 2010, a European Union study of data protection in India noted there were "no aspects of India's data protection which would unequivocally be regarded as 'adequate' by European Union standards as yet".

© Thomson Reuters 2017

We discussed the Reliance Jio data leak, new Reliance Jio plans, and JioFiber's impending launch in India on our weekly technology podcast Orbital, which you can subscribe to via Apple Podcasts or RSS or just listen to this episode by hitting the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  2. AI Impact Summit: From Registration to Schedule, All You Need to Know
  3. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  4. Oppo Find X10 Series Could Debut This Year With This iPhone-Like Feature
  5. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  6. Xiaomi Civi 6 Could Launch in China Soon With Customisable AI Shortcut Key
  7. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  8. Google Reveals When You Can Expect Android 17 to Arrive on Your Pixel Phone
  9. Tecno Spark 50 4G Launch Timeline, Design, Colourways, Key Features Leaked
  10. OpenClaw Founder Joins OpenAI, Says AI Agent Will Remain Open-Source
  1. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  2. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
  3. Tecno Spark 50 4G Tipped to Launch Globally Soon; Design, Colourways, Key Features Leaked
  4. Lava Bold N2 India Launch Date Revealed; Will Be Exclusively Available via Amazon
  5. Government Green Lights Rs. 10,000 Crore Fund of Funds 2.0 Under the Startup India Mission
  6. Samsung’s 'Wide' Galaxy Z Fold Design Revealed via Leaked One UI 9 Animations
  7. Realme P4 Lite India Launch Date Announced; Design, Colour Options, Key Features Revealed
  8. Kingdom Come: Deliverance's Free Next-Gen Update on PS5, Xbox Series S/X Is Now Out
  9. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications; Charging Specifications Revealed Ahead of Launch
  10. Oppo K14x 5G With 6,500mAh Battery, 50-Megapixel Camera Goes on Sale in India: Price, Offers
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.