-Advocate Suraksha Acharya

Cyber law is a relatively new legal area in Nepal that covers a broad range of topics with an emphasis on cyber security and data privacy. The law is extended to the devices used to access the internet, including computers, cell phones, email, websites, data storage devices, software, and hardware. It regulates the communications, privacy, freedom of expression, and intellectual property of internet users. These laws protect individuals and businesses that use the internet and establish penalties for people and groups that commit cybercrime.
Data security is the practice of safeguarding digital information from unauthorized access, accidental loss, disclosure and modification, manipulation or corruption throughout its entire lifecycle, from creation to destruction. This practice is key to maintaining the confidentiality, integrity and availability of an organization's data. Confidentiality refers to keeping data private, integrity to ensuring data is complete and trustworthy, and availability to providing access to authorized entities.
Scope of cyber law and data security
Cyber Law:
1. Security and Privacy of Data: Cyber law establishes the laws that regulations for the collection, storage, processing, and sharing of personal and sensitive data. Laws like GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and various national laws define rights of individuals and responsibilities of organizations regarding data protection.
2. Electronic Transactions: It governs various aspects of contracts, agreements, and transactions conducted electronically. This includes issues such as electronic signatures, contract formation, and consumer protection in e-commerce.
3. Intellectual Property Rights (IPRS): Cyber law regulates digital content, trademarks, copyrights, and patents in the digital world. It addresses issues like online piracy, digital rights management (DRM), and domain name disputes.
4. Defines Legal Frameworks: Cyber law defines the rules and regulations governing the use of digital technology, the internet, and cyberspace. It includes laws related to electronic commerce, data protection, privacy, intellectual property, cybercrimes, and cyber warfare.
5. Regulates Cybercrimes: Cyber law addresses offenses committed using digital means, such as hacking, malware distribution, identity theft, cyber bullying, phishing, and fraud. It specifies legal penalties and procedures for prosecuting offenders.
Data Security:
1. Management of Risk: It involves assessing, identifying, and mitigating risks to data security. This involves conducting risk assessments, developing security policies and procedures, and ensuring compliance with regulatory requirements.
2. Meeting of Standards: Data security is related with industry standards and regulatory requirements for protecting specific types of data for example. Healthcare data and financial data. Compliance ensures organizations meet the required legal obligations and industry best practices.
3. Awareness and Training: Data security efforts include educating employees and users about best practices for safeguarding data, recognizing phishing attempts, and understanding their roles in maintaining security.
4. Response to Incident: Data security includes plans and procedures for responding to data breaches, cyber attacks, or other security incidents. This involves containment, investigation, notification, and recovery processes to minimize harm and prevent future incidents.
5. Protection Measures: Data security involves implementing technical, administrative, and physical controls to protect data from unauthorized access, alteration, or destruction. This includes encryption, access controls, firewalls, antivirus software, and intrusion detection systems.
Historical Development of cyber law and data security in Nepal
The development of cyber law and data security in Nepal has followed by technological advancements, legal reforms, and the increasing rate of digitalization in Nepalese society. Here are key time period in the historical development of cyber law and data security in Nepal:
1. Early Years (Pre-2000s):
o In this period Nepal initially did not have specific legislation related to cybercrime and data security
o The focus was only on traditional laws related to crimes like fraud, defamation, and intellectual property violations, which were sometimes applied to cyber activities.
2. Emergence of Cybercrime (Early 2000s):
o With the growth of internet usage and advanced technology adoption in Nepal in the early 2000s, incidents of cybercrime such as hacking and online fraud started to emerge.
o The absence of specific laws and regulations addressing these crimes led to challenges in data security and digital world.
3. Legal Framework Development (Mid-2000s to 2010s):
o In response to increasing cyber threats and challenges and the need for legal framework, Nepal began developing its cyber law framework.
o The Electronic Transactions Act (ETA) 2063 (2008) was a significant law that recognized electronic records and digital signatures, providing a foundation for e-commerce and online transactions.
o The ETA also included provisions related to cybercrime, defining offenses such as unauthorized access to computer systems and data, hacking, and computer data security.
4. Data Protection and Privacy (2010 s onwards):
o Concerns over data protection and privacy grew with the increase of internet usage and online platforms became more popular in Nepal.
o In 2019, Nepal introduced the Information Technology Bill, which aimed to update and consolidate existing laws related to information technology, including provisions for data protection and cyber security.
o The bill includes measures for protecting personal data and outlines responsibilities for handling such data.
5. Current Trends and Challenges:
o Nepal continues to cope with challenges and focus on capacity building in cyber law enforcement, ensuring meeting international standards, and addressing cyber threats effectively.
o There is ongoing development regarding additional legislation and regulatory frameworks to address emerging issues such as social media regulation, cyber security standards and protection against online harassment.
Importance of cyber law and data security
• Regulation of Internet Use: Cyber laws data security practices regulates internet use, including online content, electronic contracts, digital signatures, and electronic communication. These regulations ensure that the internet remains a safe and reliable platform for global internet communication and commerce
• Promotion of Trust: Cyber laws and data security practices foster trust between businesses and consumers. When individuals feel confident that their data is safe, they are more likely to engage in online transactions and share information with individuals and organizations.
• Promotion of International Cooperation: Cyber laws and data security promotes international cooperation and collaboration to fight against cyber crimes that span across borders. They provide a framework for countries to work together in investigating and prosecuting offenders.
• Protection of Personal Information: Cyber laws and data security ensure that ith increasing digital transactions and data sharing, personal information such as financial details, medical records, and identity information are protected from unauthorized access, theft, and misuse.
• Prevention of Cybercrimes: Cyber laws and data security establish guidelines and penalties for various cybercrimes such as hacking, phishing, identity theft, and cyber bullying. They help in deterring criminals and prosecuting those who commit such offenses.
• Cyber security Preparedness: Cyber laws and data security laws often require organizations to implement cyber security measures and protocols to protect against potential threats. This proactive approach helps in minimizing the risk of data breaches and cyber-attacks.
• Business Security: Cyber laws and data security laws and regulations ensure that businesses implement measures to protect sensitive company and customer information. This includes safeguarding financial records, trade secrets, and proprietary information from breaches and theft.
• Legal Framework:, Cyber laws and data security provide a legal framework for their development, deployment, and use while ensuring they are secure and do not infringe on individual rights as new technologies such as artificial intelligence(AI)
Types of cyber crimes
• Hacking: It is an unauthorized access to computer systems or networks with the intent to steal data, disrupt operations, or cause damage.
• Identity Theft: It refers to using someone else's personal information, such as Social Security numbers or credit card details, without their permission to commit fraud or other crimes.
• Cyber bullying: Misuse of the digital platforms to threaten, harass, or intimidate individuals, often through social media, email, or messaging apps.
• Phishing: Attempt to obtain sensitive information such as usernames, passwords, and credit card details showing trustworthy entity in electronic communications.
• Malware: Software designed to disrupt, damage, or gain unauthorized access to computer systems. Examples include viruses, worms, ransom ware, and spyware.
• Child Exploitation: Exploiting children for sexual purposes by using the internet, including producing, distributing, or accessing child pornography.
• Online Scams: Schemes conducted online to deceive individuals for providing money, sensitive information, or personal details. Examples include lottery scams, romance scams, and fraudulent investment schemes.
• Cyber Espionage: Accessing and stealing confidential information illegally from governments, companies, or individuals to gain a competitive advantage or for political purposes.
• Denial-of-Service (DoS) Attacks: Overloading a computer system or network with excessive requests, causing it to become slow, crash, or be temporarily unavailable to users.
• Cyber Espionage: Illegally accessing and stealing confidential information from governments, companies, or individuals to gain a competitive advantage or for political purposes.
• Data Breaches: Unauthorized access to sensitive or confidential data stored electronically, often resulting in theft or exposure of personal information.
• Cyber Espionage: Illegally accessing and stealing confidential information from governments, companies, or individuals to gain a competitive advantage or for political purposes.
• Denial-of-Service (DoS) Attacks: Overloading a computer system or network with excessive requests, causing it to become slow, crash, or be temporarily unavailable to users.
• Intellectual Property related crimes: Unauthorized copying or distribution of copyrighted materials, such as software, movies, music, or books, over the internet.
Cyber law and data security practices in Nepal
• Data Protection and Privacy:
• Individuals and organizations are encouraged to implement measures to protect personal data and ensure confidentiality, though specific regulations and enforcement of the law
• Nepal does not have a specific data protection law similar to GDPR (General Data Protection Regulation) which are practiced in abroad. However, the Electronic Transactions Act (ETA) includes provisions related to the protection of personal information and data privacy.
• Cyber crime Prevention and Enforcement:
• The IT Act punishes various cybercrimes, including unauthorized access to computer systems, data breaches, hacking, and cyber fraud.
• Law enforcement agencies are responsible for investigating and prosecuting cybercrimes, with penalties prescribed for offenders.
• Cyber security Measures:
Individuals and Organizations are encouraged to implement cyber security best practices such as access controls, regular security audits, encryption, and incident response planning.
• The Computer Incident Response Team (CIRT Nepal) is used for coordinating responses to cyber security incidents, providing advice on cyber security issues, and promoting cyber security awareness and education.
• Awareness and Capacity Building:
• Efforts are made to raise awareness among individuals, businesses, and government agencies about cyber security risks, best practices, and legal obligations.
• Capacity building includes many aspects like training programs, workshops, and collaboration with international organizations to strengthen Nepal's cyber security capabilities.
• Challenges and Considerations:
• Limitation in the resources and technical expertise pose challenges to effective implementation and enforcement of cyber law and data security practices.
• Continuous updates and amendments to existing laws and regulations are needed to control the information technology and emerging cyber threats.
• Legal Frameworks:
• Information Technology (IT) Act: The broader aspects of information technology, includes electronic transactions, cybercrimes, data protection, and the establishment of the Computer Incident Response Team (CIRT) for handling cyber security incidents
• Electronic Transactions Act (ETA): This law provides legal recognition and validity to electronic records and digital signatures. It regulates electronic transactions and sets out provisions for data protection, cyber security, and cybercrimes.
Challenges in Cyber law and data security practices in Nepal
• Awareness and Education:
• There is a general lack of awareness among the public, businesses, and government officials about cyber law and data security risks, and legal obligations.It is required to promote cyber security awareness through education programs, training workshops, and public awareness campaigns
• Technologies and Security Risks:
• The rapid adoption of emerging technologies such as artificial intelligence (AI), cloud computing, Internet of Things (IoT), and block chain introduces new cyber law and data security risks. Addressing security challenges associated with IT requires proactive measures and adaptation of new laws and regulations.
• Capacity Building and Institutional Framework:
• Building capacity and institutional frameworks, such as national cyber and data security strategies, and cyber and data security training centers, requires sustained investment and commitment. Strengthening public-private partnerships and collaboration with educational institution and civil society can foster innovation and capacity building in cyber security.
• Legal Harmonization:
• It is essential yet challenging to ensure co-ordination and consistency between different legal frameworks related to cyber issues, including criminal law, electronic transactions, intellectual property, and privacy. However balancing regulations with international standards and best practices can facilitate international cooperation and enhance legal certainty for businesses and stakeholders.
• International Cooperation and Cyber Diplomacy:
• In this age of globalization cyber threats can go beyond national borders, which requires international cooperation and collaboration in cyber law enforcement, information sharing, and policy development. Such cyber diplomacy efforts and active participation in international forums and agreements that can enhance Nepal's cyber security and response capabilities.
• Limited Enforcement Capacity:
• There is lack the technical expertise, resources, and training in law enforcement agencies in Nepal that is necessary to effectively investigate and prosecute cybercrimes.There is a gap in digital capabilities and cybercrime activities, which affect on timely and effective responses to cyber incidents.
• Lack of Comprehensive Legislation:
• Nepal's existing cyber laws, such as the Electronic Transactions Act (ETA) and the Information Technology (IT) Act, cannot fully address modern cyber threats, data protection issues, and international cybercrime co-operation. There is a need for updated legislation that covers emerging IT, cyber security standards, threats and data privacy in electronic transactions.
Immerging technologies in Cyber law and data security practices to cope above challenges in Nepal
• Biometrics and Authentication Technologies:
• Biometric authentication methods, such as fingerprint scanning and facial recognition, are being adopted for security in digital transactions and access control systems.Privacy laws and regulations governing the collection, storage, and use of biometric data are essential to protect individuals' privacy rights.
• Artificial Intelligence (AI):
• AI can be used for threat detection, anomaly detection in network traffic, and improving incident response times. Here accountability for AI-driven decisions, data privacy implications of AI algorithms, and regulatory frameworks for AI technologies are evolving areas.
• Internet of Things (IoT):
• IoT devices are increasingly used in Nepal, from individual to organizations, which reduces attack for cyber threats. Ensuring IoT device security, data encryption, and protection against unauthorized access are critical issues addressed through cyber security regulations.
• Blockchain Technology:
• Block chain can be used for secure transactions, smart contracts, and decentralized data storage, enhancing data integrity and reducing the risk of fraud. Blockchain applications may influence how data is stored and verified, potentially impacting data protection laws and regulations in Nepal
• Cloud Computing:
• Cloud services are gaining popularity among businesses and government agencies in Nepal for data storage, processing, and collaboration. Regulations and contracts governing data sovereignty, data residency requirements, and data access controls are essential for ensuring data security in cloud environments.
• Education and Awareness:
• Efforts are made to enhance cyber security skills and awareness among stakeholders, including government officials, businesses, and the general public. programs on emerging technologies and their cyber security implications help in preparing professionals to address evolving cyber threats effectively.
• Cyber Law and Policy Development:
• Nepal is working towards updating its cyber laws and policies to address emerging technologies' challenges and opportunities. For this collaboration with international organizations and regional partners helps in adopting best practices and standards in cyber security and data protection.
Author
LLB, MBS, MA(TU Topper)
Resunga Law Firm, Notary Public, Butwal
9847255329
नागरिक अनलाइनमा प्रकाशित कुनैपनि सामग्रीबारे गुनासो,सूचना तथा सुझाव भए हामीलाई nagarikonlinenews@gmail.com मा पठाउनुहोला।)