Alterations in Personal Data Protection Bill
Introduction
The appeal is to be heard by the TDSAT (telecommunication dispute settlement & appellate tribunal) regarding several changes under Digital personal data protection. The Changes should be a removal of the deemed consent, a change in appellate mechanism, No change in delegation legislation, and under data breach. And there are some following other changes in the bill, and the digital personal data protection bill 2023 will now provide a negative list of countries that cannot transfer the data.
New Version of the DPDP Bill
The Digital Personal Data Protection Bill has a new version. There are three major changes in the 2022 draft of the digital personal data protection bill. The changes are as follows: The new version proposes changes that there shall be no deemed consent under the bill and that the personal data processing should be for limited uses only. By giving the deemed consent, there shall be consent for the processing of data for any purposes. That is why there shall be no deemed consent.
- In the interest of the sovereignty
- The integrity of India and the National Security
- For the issue of subsidies, benefits, services, certificates, licenses, permits, etc
- To comply with any judgment or order under the law
- To protect, assist, or provide service in a medical or health emergency, a disaster situation, or to maintain public order
- In relation to an employee and his/her rights
The 2023 version now includes an appeals mechanism
It states that the Board will have the authority to issue directives for data breach remediation or mitigation, investigate data breaches and complaints, and levy financial penalties. It would be authorised to submit complaints to alternative dispute resolution, accept voluntary undertakings from data fiduciaries, and advise the government to prohibit a data fiduciary’s website, app, or other online presence if the terms of the law were regularly violated. The Telecom Disputes Settlement and Appellate Tribunal will hear any appeals.
The other change is in delegated legislation, as one of the criticisms of the 2022 version bill was that it gave the government extensive rule-making powers. The committee also raised the same concern with the ministry. The committed wants that the provisions that cannot be fully defined within the scope of the bill can be addressed.
The other major change raised in the new version bill is regarding the data breach; there will be no compensation for the data breach. This raises a significant concern for the victims, If the victims suffer a data breach and he approaches the relevant court or authority, he will not be awarded compensation for the loss he has suffered due to the data breach.
Need of changes under DPDP
There is a need for changes in digital personal data protection as we talk about the deemed consent so simply speaking, by ‘deeming’ consent for subsequent uses, your data may be used for purposes other than what it has been provided for and, as there is no provision for to be informed of this through mandatory notice, there may never even come to know about it.
Conclusion
The bill requires changes to meet the need of evolving digital landscape in the digital personal data protection 2022 draft. The removal of deemed consent will ultimately protect the data of the data principal. And the data of the data principal will be used or processed only for the purpose for which the consent is given. The change in the appellate mechanism is also crucial as it meets the requirements of addressing appeals. However, the no compensation for a data breach is derogatory to the interest of the victim who has suffered a data breach.
Related Blogs
.webp)
Smart Wearable devices are designed to track several activities in defined parameters and are increasingly becoming a part of everyday life. According to Markets and Markets Report, the global wearable tech market is projected to reach a staggering USD 256.4 billion by 2026. One of the main areas of use of wearable devices is health, including biomedical research, health care, personal health practices and tracking, technology development, and engineering. These wearable devices often include digital health technologies such as consumer smartwatches that monitor an individual's heart rate and step count, and other body-worn sensors like those that continuously monitor blood glucose concentration.
Wearable devices used by the general population are getting increasingly popular. Health devices like fitness trackers and smartwatches enable continuous monitoring of personal health. Privacy is an emerging concern due to the real-time collection of sensitive data. Vulnerabilities due to unauthorised access or discrimination in case of information being revealed without consent are the primary concerns with these devices. While these concerns are present a lot of related misinformation is emerging due to the same.
While wearable devices typically come with terms of use that outline how data is collected and used, and there are regulations in place such as EU Law GDPR, such regulations largely govern the regulatory compliances on the handling of personal data, however, the implementation and compliances by the manufacturer is a one another aspect which might present the question on privacy protection. In addition, beyond the challenge of regulatory compliance, the rise of myths and misinformation surrounding wearable tech presents a separate issue.
Common Misconceptions About Privacy with Wearable Tech
- With the rapid development and growth of wearable technology their use has been subject to countless rumours which fuel misinformation narratives in the minds of general public. Addressing these misconceptions and privacy concerns requires targeted strategies.
- A prevalent misconception is that they are constantly spying on users. While wearable devices collect users’ data in real time, their vulnerability to unauthorised access is similar to that of a non-wearable device. The issue is of consent when it comes to wearable technology because it gives the ability to record. If permissions are not asked when a person is being recorded then the data is accessible to external entities.
- There is a common myth that wearable tech is surveillance tool. This is entirely a conjecture. These devices collect the user data with their prior consent and have been created to provide them with real-time information, most commonly physical health information. Since users choose the information shared, the idea of wearable tech serving as a surveillance tool is unfounded.
- Another misconception about wearable tech is that it can diagnose medical conditions. These devices collect real-time health data, such as heart rate or activity levels, they are not designed for medical diagnosis. The data collected may not always be accurate or reliable for clinical use to be interpreted by a healthcare professional. This is mainly because the makers of these devices are not held to the safety and liability standards that medical providers are.
- A prevalent misconception is that wearable tech can cure health issues, which is simply untrue. Wearable tech devices are essentially tracking the health parameters that a user sets. It in no way is a cure for any health issue that one suffers from. A user can manage their health based on the parameters they set on the device such as the number of steps that they walk, check on the heart rate and other metrics for their mental satisfaction but they are not a cure to treat diseases. Wearable tech acts as alerts, notifying users of important health metrics and encouraging proactive health management.
Addressing Privacy and Health Concerns in Wearable Tech
Wearable technology raises concerns for privacy and health due to the colossal amount of personal data collected. To address these, strong data protection measures are essential, ensuring that sensitive health information is securely stored and shared only with consent. Providing users with control over their data is one of the ways to build user trust. It includes enabling them to opt in, access, or delete the data in question. Regulators should establish clear guidelines, ensuring wearables ensure the compliances with data protection regulations like HIPPA, GDPR or DPDP Act, whichever is applicable as per the jurisdiction. Furthermore, global standards for data encryption, device security, and user privacy should be implemented to mitigate risks. Transparency in data usage and consistent updates to software security are also crucial for protecting users' privacy and health while promoting the responsible use of wearable tech.
CyberPeace Insights
- Making informed decisions about wearable tech starts with thorough research. Start by reading reviews and comparing products to assess their features, compatibility, and security standards.
- Investigate the manufacturer’s reputation for data protection and device longevity. Understanding device capabilities is crucial. One should evaluate whether the wearable meets their needs, such as fitness tracking, health monitoring, or communication features. Consider software security and updates, and data accuracy when comparing options. Opt for devices that offer two-factor authentication for an additional layer of security.
- Check the permissions requested by the accompanying app; only grant access to data that is necessary for the device's functionality. Always read the terms of use to understand your rights and responsibilities regarding the use of the device. Review and customize data-sharing settings for better control to prevent unauthorised access.
- Staying updated on the tech is equally important. A user should follow the advancements in wearable technology be it regular security updates, or regulatory changes that may affect privacy and usability. This ensures getting tech that aligns with user lifestyle while meeting privacy and security expectations.
Conclusion
Privacy and Misinformation are key concerns that emerge due to the use of wearable tech designed to offer benefits such as health monitoring, fitness tracking, and personal convenience. It requires a combination of informed decision-making by users and stringent regulatory oversight to overcome the issues that emerge due to misinformation about these devices. Users must ensure they understand the capabilities and limitations of their devices, from data accuracy to privacy risks. Additionally, manufacturers and regulators need to prioritise transparency, data protection, and compliance with global standards like GDPR or DPDP to build trust. As wearable tech continues to evolve, a balanced approach to innovation and privacy will be essential in fostering its responsible and beneficial use for all.
References
- https://thehealthcaretechnologyreport.com/privacy-data-security-concerns-rise-as-healthcare-wearables-gain-popularity/
- https://journals.plos.org/digitalhealth/article?id=10.1371/journal.pdig.0000104
- https://www.marketsandmarkets.com/Market-Reports/wearable-electronics-market-983.html?gclid=Cj0KCQjwgMqSBhDCARIsAIIVN1V0sqrk6SpYSga3rcDtWcwh8npZ08L0_s4X91gh7yPAa6QmsctB-lMaAlpqEALw_wcB
- https://www.cambridge.org/core/journals/legal-information-management/article/health-data-on-the-go-navigating-privacy-concerns-with-wearable-technologies/05DAF11EFA807051362BB39260C4814C

Introduction
For two decades, cybercrime enforcement was built around a simple assumption: criminals hide behind screens, but they still operate mostly within reachable borders. That assumption has collapsed. Today's fraud economy runs through industrial-scale scam compounds in Myanmar and Cambodia, laundering networks spanning a dozen jurisdictions, and trafficked labour forced to defraud victims thousands of miles away. INTERPOL's own trend reporting has tracked victims from more than 60 countries pulled into scam operations that now stretch well beyond Southeast Asia into Africa, the Gulf, and Latin America. Global losses from this activity are estimated in the hundreds of billions of dollars annually, and the networks rebuild faster than any single government can dismantle them.
A Threat That Outran the Old Playbook
The mismatch is the real story behind a wave of policy moves in 2025 and 2026. The August 12, 2026 U.S. National Security Presidential Memorandum authorising vetted private companies to conduct government-supervised offensive cyber operations against transnational criminal organisations is one data point in that wave, not the whole story. Washington's move sits alongside a broader, still-unfinished experiment: can the international system build cooperative machinery fast enough to match a threat that treats borders as an inconvenience rather than a barrier?
Three Tracks of International Response
Three distinct but overlapping tracks have emerged.
The treaty: The most consequential recent development is the UN Convention against Cybercrime, adopted by the General Assembly in December 2024 and opened for signature in Hanoi in October 2025, where 71 states and the EU signed on. It is the first comprehensive global treaty addressing cybercrime and cross-border evidence sharing, building on the older Budapest Convention framework that has anchored cooperation since 2004. The Hanoi Convention needs 40 ratifications to enter into force; as of mid-2026, only three states (Qatar, Azerbaijan, and Vietnam) had ratified it, and human rights groups continue to warn that its broad scope could be used by authoritarian governments to justify surveillance and cross-border data requests dressed up as cybercrime cooperation. The treaty's fate will hinge on a Conference of States Parties process now being negotiated, where democracies are pushing for genuine multi-stakeholder oversight rather than a rubber stamp.
The operational track: While treaty diplomacy moves slowly, police-to-police cooperation has scaled up dramatically. INTERPOL's Operation First Light, now an annual standing initiative, illustrates the trajectory: its 2026 iteration spanned January to April, generated over 5,800 arrests and roughly $293 million in intercepted funds, and made heavy use of the Global Rapid Intervention of Payments mechanism to freeze illicit transfers before they disappeared into crypto wallets. A parallel operation led by Dubai Police with the FBI and Chinese authorities dismantled nine pig-butchering compounds across Myanmar, Indonesia, Cambodia, and Thailand, seizing more than $701 million. In Europe, Europol's EMPACT framework has entered a new 2026–2029 cycle, deepening ties with Frontex, Eurojust, and regional partners like Ameripol and the EL PACTTO programme in Latin America, effectively building a lattice of standing coordination bodies rather than one-off task forces. These operations demonstrate real capacity, but they also expose the "whack-a-mole" problem: raided compounds in Myanmar's Myawaddy region simply relocated, reconnected via satellite internet, and resumed operations within weeks, according to regional reporting.
The public-private track: This is where the U.S. memorandum fits into a genuinely global pattern rather than standing alone. The United Kingdom's 2026–2029 Fraud Strategy centres on a £31 million Online Crime Centre, opening in 2026, that fuses data from the National Crime Agency, the intelligence community, and private partners across banking, telecoms, and technology into a single coordination hub building on existing arrangements like Stop Scams UK, where telecom operators and banks already share suspicious SIM and account data in near real time. In the U.S., a June 2026 joint action involving the Justice Department, Meta, Microsoft, Google, Apple, and Coinbase froze $3.8 billion in cryptocurrency and disrupted 1.4 million fraud-linked accounts, showing that platform cooperation can move faster than formal treaty processes. Singapore has positioned itself as a hub for this model too, anchoring the Global Anti-Scam Alliance, which now includes ASEAN's own foundation as a member, bringing governments, banks, and tech platforms into shared intelligence loops. What distinguishes the U.S. memorandum is that it goes a step further than data-sharing: it authorises companies to take disruptive technical action, not just contribute intelligence, under a legal theory that folds them into the government's own authority under the Computer Fraud and Abuse Act's law-enforcement exception.
Where the System Still Breaks Down
Despite this activity, structural gaps, like jurisdiction, are the deepest ones. Scam compounds deliberately locate in special economic zones and border regions precisely because territorial control there is contested or weak, leaving no single government with clean authority to act. ASEAN's own policy work acknowledges that nearly every stage of the regional scam value chain crosses at least one border, which is why the bloc has shifted toward standing coordination bodies like its Working Group on Anti-Online Scams rather than relying on bilateral requests.
Attribution and accountability lag behind operational tempo. Financial intelligence and blockchain analytics have improved enforcement precision, but identifying the human traffickers and financiers sitting above front-line scam operators remains slow, uneven, and dependent on political will in host countries.
Governance of the newer public-private authorities is also unsettled. Human rights advocates flag that expanding both the Hanoi Convention's surveillance-adjacent powers and unilateral hack-back authorities like the U.S. memorandum could, without careful oversight, blur the line between fighting organised fraud and enabling broader digital overreach. The U.S. memorandum's own guardrails, which are a ban on operations causing serious injury or rising to a use of force, mandatory federal sign-off, and a $1 million forfeitable bond, reflect an awareness of that risk, but its implementing procedures remain classified, and comparable transparency gaps exist in several other national programs.
The Emerging Consensus
What's notable is not any single instrument but the convergence: nearly every serious national or regional response now combines the same three ingredients deeper platform and financial-sector data sharing, standing multilateral operational coordination, and a cautious expansion of what non-state actors are permitted to do. The countries and blocs making the fastest progress, from the UK's Online Crime Centre to INTERPOL's payment-interdiction tools to ASEAN's regional information-sharing arrangement, are the ones treating cyber-enabled transnational crime as a persistent infrastructure problem rather than a series of discrete crimes to be prosecuted after the fact. Whether that convergence produces durable results or simply better-coordinated whack-a-mole will depend on the unglamorous work still ahead: ratifying treaties, writing classified rulebooks, and building the cross-border trust that lets financial and technical data move as fast as the criminals do.
Conclusion
Transnational cybercrime has outgrown fragmented national enforcement. The emerging combination of international treaties, operational cooperation, and public-private partnerships offers a stronger response, but serious gaps in jurisdiction, accountability, and oversight remain. Ultimately, success will depend on whether states can build cooperation and safeguards capable of matching criminals’ speed, adaptability, and global reach.
Sources
- Presidential Memorandum: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime — The White House
- United Nations Convention against Cybercrime — UNODC
- The Promise and Peril of the U.N. Convention Against Cybercrime — Just Security
- Moving Forward with the United Nations Convention against Cybercrime — ICCLR
- Growing threat of transnational scam centres highlighted at INTERPOL General Assembly
- Over 5,800 arrests, USD 293 million intercepted in global fraud bust — INTERPOL
- Operation First Light 2026: 276 Arrested, $701M Seized — Breached.Company

Introduction
For more than 10 years, WhatsApp has been designed around one seemingly trivial but impactful idea: your phone number is your digital identity. This concept offered simplicity in terms of contact discovery and onboard- ing but inevitably exposed users to fraud, spam and the everyday necessity of sharing personal phone numbers with complete strangers in group chats and conversations. On June 29th Meta finally revealed a major move: you’ll now be able to choose and reservate a WhatsApp username and communicate without sharing your phone number.
This shift to a username based identity marks the company catching up to platforms like Telegram and Signal, which have utilized this functionality for years.
However, while presented as a push towards greater privacy for the millions using its platform, this new change has already created some alarm around impersonation, cybersquatting, and identity theft. The issues became amplified when, according to reports, the Indian Ministry of Electronics and Information Technology advised WhatsApp to halt the implementation of the new features while it clarifies details, shifting a mundane app update into a high-stakes discussion on digital privacy, platform responsibility, and government regulation.
How does the mechanism work?
“WhatsApp’s username is an added pseudonym layer on its current phone number architecture, not a replacement,” Meta said in a statement on Thursday, as reported by TechCrunch. A WhatsApp username is a three to 35-character name containing lower case letters, numbers, periods and underscores that must contain at least one letter and “should not look like a website address.” The feature will allow you to “reserve a unique identifier that you can share as an alternative to your phone number in WhatsApp Settings - Accounts - Username.”
It said the usernames will work in parallel with a username key which can serve as a passphrase to initiate conversation “with a recipient before sending a message for the first time.”
“The change - which will have some additional, protective measures like reserving usernames for people of public interest or those that would cause impersonation, and rate limits on claiming names - can help maintain phone number protection, while offering people more choices,” Meta said. WhatsApp said usernames will replace phone numbers as the primary way to initiate new chats, but will not be publicly searchable: “Anyone you message would need your exact username, and would still need you to respond.”
The Genuine Privacy Case
The upside is real. Phone numbers double as keys to two-factor authentication, banking apps and SIM-swap fraud, so handing one to a new acquaintance, a group chat of strangers or a customer-support bot has always carried quiet risk. Numbers harvested from public groups already fuel spam and scam campaigns, and a username-first model narrows that exposure considerably.
For journalists, small business owners and anyone who fields messages from people they've never met, decoupling identity from a number that also unlocks their bank account is a meaningful, overdue shift – and one that WhatsApp's closest competitors adopted years ago without major incident.
The Scammer's Paradise Scenario
The trouble lies in what a username removes. A phone number was never just an identifier; it was also a rough verification signal and, for law enforcement, a traceable data point. Security reporters testing the reservation system found that lookalike handles mimicking prominent Indian politicians, film stars and the Reserve Bank of India remained available to claim. Crypto executive Changpeng Zhao's own failed bid to capture his desired handle highlighted the first-come, first-served danger of the rollout and led researchers to advise people to manually activate the optional username key that Meta leaves disabled by default.
The Mozilla Foundation was unvarnished about the tradeoff, noting that impersonation from fake accounts and scams are an “inevitable consequence” of a design that abandons the “implicit signal of authenticity” that comes from owning a phone number.
Indian entrepreneur Ankur Warikoo called the rollout a potential “disaster” if robust enforcement against fraud isn’t immediately applied because scammers could register handles a few characters removed from a popular brand or public figure to launch investment and payment schemes, a concern mirrored by cyber security researchers who observed that many users neglect to check verification badges before trusting an account.
India's Regulatory Scrutiny of WhatsApp's Username Feature
So far the strongest reaction comes from New Delhi. The Ministry of Electronics and Information Technology (MeitY) issued an official notice to Meta's compliance office that it should “temporarily suspend the feature” in the country pending further consultations and “provided an explanation in three days”. The cited concerns involve “digital arrest” fraud, a rapid boom category that involves crooks impersonating investigators like those with India's CBI, judges or customs agents to extort victims, in addition to standard concerns around phishing and bank or government impersonation.
A subtler concern, for India’s government anyway, is “traceability.”
At present, say officials, an Indian mobile number is a launching pad to determine whether a given suspect is a domestic or international actor, while a username and foreign SIM would leave authorities nowhere to begin. The Department of Telecommunications independently voiced concerns over how the change intersects with its SIM-binding regulations and over WhatsApp's lag time for such requests. The MeitY notice, the legal basis for which, incidentally, is in contention with some digital rights groups, specifically invokes Section 79 of the IT Act and various IT Rules from 2021 and provisions on identity theft and impersonation that target individual criminals rather than the tech tools. Not everyone, however, shares MeitY’s reading of the legal ground: the Internet Freedom Foundation says that Section 79 “deal with liability of intermediary” and “does not confer on the government power to license the features of a product,” while arguing the relevant criminal statutes were designed to criminalize impersonators, not tech platforms whose services are misused, echoing concerns that killed a similar government advisement about AI models last spring.
In the meantime, Meta says usernames are unavailable in the country for now and the multilayered safeguards it designed were always intended for exactly this level of risk.
Conclusion
WhatsApp's username feature is neither a total privacy upgrade nor a major security problem; instead, it reallocates risk, reducing phone number exposure while adding a risk of identity spoofing and misuse. Whether it pays off will hinge on the strength of Meta's crackdown on fraudulent usernames, the uptake of extra security features like the username key and whether the company can adequately satisfy regulatory concerns about traceability and user safety. Until all those questions are fully settled, users may want to use the feature tentatively, secure a desired username, enable any other protections and be watchful about new contacts.
References
- https://blog.whatsapp.com/its-time-to-reserve-your-whatsapp-username
- https://www.businesstoday.in/technology/news/story/whatsapp-usernames-why-indias-top-creators-fear-scams-impersonation-and-identity-theft-540359-2026-07-02
- https://www.outlookindia.com/national/outlook-explains-why-is-the-indian-government-worried-about-whatsapp-usernames
- https://techcrunch.com/2026/06/29/whatsapp-now-lets-you-reserve-usernames/
- https://bestmediainfo.com/mediainfo/mediainfo-digital/whatsapp-says-username-feature-not-live-yet-after-meity-asks-meta-to-pause-rollout-12124813