India’s government has granted immunity from public information requests to its Computer Emergency Response Team, CERT-In, effectively shielding the cybersecurity authority from transparency obligations. This decision follows criticism of a controversial mandate requiring rapid reporting of cyber incidents, which many argued was impractical and overly burdensome for businesses. By excluding CERT-In from the Right to Information Act, the state prioritizes operational secrecy over public accountability, raising concerns about how such significant cybersecurity mandates are monitored and enforced without external scrutiny. The move is particularly contentious given the sheer volume of reported cyber threats and the lack of clarity regarding how CERT-In processes this data. Activists argue that shielding a body responsible for national cyber defense from public inquiry undermines democratic principles, especially when dealing with sensitive issues like state-sponsored attacks and data breaches. Without the ability to question CERT-In’s methods or effectiveness, citizens and organizations lose a vital mechanism for ensuring that cybersecurity measures serve the public interest rather than opaque governmental agendas. This shift is highly relevant to open data discussions as it represents a significant retreat from transparency in critical infrastructure management. Open data relies on the principle that government-held information, particularly regarding public safety and security, should be accessible to foster trust and informed civic engagement. Removing a key agency from freedom of information laws sets a dangerous precedent, potentially allowing other security bodies to operate without oversight. It highlights the tension between national security needs and the open society’s demand for accountability, suggesting that future open data initiatives must explicitly protect against such exclusions to maintain public trust.

Source:
Published on 2023-11-29