The WhatsApp snooping row that involves privacy infringement of 121 Indian users out of 1,400 globally via third-party Israeli Pegasus spyware is now witnessing serious questions on the part of the government in handling such a crucial matter in the absence of a robust digital legal framework.
In a legal memorandum sent to IT and Telecom Minister Ravi Shankar Prasad, the petitioner KN Govindacharya, founder of Rashtriya Swabhimaan Aandolan, said that the Minister’s statement in the Rajya Sabha last week on WhatsApp-Pegasus snooping matter did not reveal the complete truth.
Reacting to the Minister’s claim that no complaint has been made in the IT Ministry till date by anyone in the WhatsApp spyware case, the memorandum said that a petition filed on behalf of Govindacharya by advocate Virag Gupta in Supreme Court on November 2 clearly sought an NIA investigation into the WhatsApp-NSO data Leak and perjury proceedings against WhatsApp and Facebook.
“In earlier such matter of Cambridge Analytica, public data was compromised and the government on its own directed for an investigation by the Central Bureau of Investigation (CBI). However, in the present case, no such action has been taken,” said the petition.
Prasad told the Rajya Sabha that WhatsApp has even established its office in India.
The petitioner argued that WhatsApp Inc is a company registered in the US and has been doing business in India for the last 10 years.
“Till date, WhatsApp does not have an office in India. WhatsApp Application Services Private Limited is an Indian subsidiary, which has a separate corporate personality and has no control over WhatsApp app being used by over 40 crore users in India,” said the RSS ideologue Govindacharya in his petition.
A third key point that Prasad raised in the Rajya Sabha was that WhatsApp has appointed a Grievance Officer in India to take care of users’ complaints.
The petitioner categorically stated that the so-called Grievance Officer has been appointed in the US and not in India as stated by the minister.
After being pulled up by the Supreme Court for not appointing a Grievance Officer and complying with other laws of India, WhatsApp in September last year appointed Komal Lahiri as the Grievance Officer for the country.
Based out of WhatsApp’s headquarters in Menlo Park, California, Lahiri can only be contacted via email and general post.
“India with the biggest user base in the world has become a data colony as all our users’ data is going abroad,” said the petition.
The writ petition filed by Govindacharya in the WhatsApp-NSO Group snooping case is set to be heard in the Supreme Court on December 2.
“In the absence of a robust digital law framework, multinational companies like WhatsApp and its parent company Facebook are misusing the date of 40 crore Indian users. Internet giants have lobbied against data protection laws for long in the country. India should promptly enact data protection law and notify IT Intermediary Rules,” Gupta told IANS.
The Computer Emergency Response Team (CERT-In) had published a vulnerability note on May 17 advising countermeasures to users about a vulnerability in WhatsApp, according to an earlier statement from Prasad.
WhatsApp reported an incident to the CERT-In on May 20, the Minister said.
The Minister added that WhatsApp wrote to CERT-In again on September 5 mentioning an update to the security incident reported in May 2019, that while the full extent of this attack may never be known, WhatsApp continued to review the available information.
According to the petition, to come up for hearing on December 2, “it is clear that WhatsApp misled this Hon’ble Court into believing that its systems were safe. WhatsApp deliberately did not disclose the NSO hacking during proceedings before the Hon’ble Supreme Court, and thus has committed perjury.”
“India is WhatsApp’s biggest market with more than 40 crore users. WhatsApp is owned by Facebook, which also owns Instagram. Facebook has around 30 crore Indian users while Instagram has about 6.9 crore users.”
“Thus, it is clear that data of Indians, including governmental data is being stored in systems, that have already been compromised, which endangers national security.”
NSO Group has stated that it sells its technologies only to government agencies, it added.