{"id":18940,"date":"2022-05-04T10:45:05","date_gmt":"2022-05-04T18:45:05","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/05\/04\/news-12673\/"},"modified":"2022-05-04T10:45:05","modified_gmt":"2022-05-04T18:45:05","slug":"news-12673","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/05\/04\/news-12673\/","title":{"rendered":"India\u2019s New Super App Has a Privacy Problem"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/6271744df2e5a2b3f2ddf349\/master\/pass\/India-Privacy-Tata-App-Security-GettyImages-981948872.jpg\"\/><\/p>\n<p><strong>Credit to Author: Varsha Bansal| Date: Wed, 04 May 2022 11:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/varsha-bansal\">Varsha Bansal<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">On April 7,<\/span> Ranendra Ojha, a marketing professional in the eastern Indian city of Kolkata was looking forward to installing and using the new super app, Tata Neu. Super apps are umbrella mobile applications under which companies offer a bunch of services. But as soon as Ojha installed and signed up for Tata Neu on his phone number, he was appalled to see that this newly launched app already had three of his old addresses along with his full name\u2014details he never shared with the app.<\/p>\n<p class=\"paywall\">As he dug further, Ojha realized that the app seemed to have pulled data from the grocery app Big Basket, which Ojha uses frequently. Like Big Basket, Tata Neu is owned by the almost 155-year-old Tata Group. One of India\u2019s largest conglomerates and a household name, the Tata Group sells everything from salt to software and recently forayed into the world of consumer tech through a slew of <a data-offer-url=\"https:\/\/economictimes.indiatimes.com\/tech\/startups\/tata-digital-to-acquire-majority-stake-in-1mg\/articleshow\/83393293.cms?from=mdr\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/economictimes.indiatimes.com\/tech\/startups\/tata-digital-to-acquire-majority-stake-in-1mg\/articleshow\/83393293.cms?from=mdr&quot;}\" href=\"https:\/\/economictimes.indiatimes.com\/tech\/startups\/tata-digital-to-acquire-majority-stake-in-1mg\/articleshow\/83393293.cms?from=mdr\" rel=\"nofollow noopener\" target=\"_blank\">acquisitions<\/a>.<\/p>\n<p class=\"paywall\">\u201cFrankly, I was quite shocked that Tata had picked up my personal details from one of the apps they owned and used it for this new app,\u201d Ojha says. \u201cIn effect they have shared my personal details with the whole Tata Group companies without my permission.\u201d<\/p>\n<p class=\"paywall\">Another user based in the southern Indian city of Bangalore was equally shocked when he saw multiple addresses (including the address of his old home, where he doesn\u2019t live anymore) and his date of birth already preloaded on Tata Neu when he signed up for it using his phone number and a one-time password. What he found more perplexing was that his wife\u2019s Tata Neu also had her old office address, which he says they never used for any purpose. \u201cPersonally I am a very big fan of Tata Group, and there is trust when it comes to the Tata brand,\u201d says Naren, who requested to be quoted under a pseudonym, fearing backlash from the company. \u201cBut that trust is lost when they do these sorts of sneaky things under the name of user experience.\u201d<\/p>\n<p class=\"paywall\">Tata Neu was launched in the first week of April and has had at least <a data-offer-url=\"https:\/\/www.thehindubusinessline.com\/info-tech\/tata-neu-records-22-million-downloads-bets-big-on-financial-services\/article65321593.ece\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.thehindubusinessline.com\/info-tech\/tata-neu-records-22-million-downloads-bets-big-on-financial-services\/article65321593.ece&quot;}\" href=\"https:\/\/www.thehindubusinessline.com\/info-tech\/tata-neu-records-22-million-downloads-bets-big-on-financial-services\/article65321593.ece\" rel=\"nofollow noopener\" target=\"_blank\">2.2 million downloads<\/a>. The app houses all of the company\u2019s brands ranging across industries such as ecommerce, financial services, airline tickets, grocery, medicines, and hotels. But the inclusion of preloaded personal data in a new app means that the Tata Group has managed to save customer data across its online and offline companies and create their profiles. According to privacy advocates, this is problematic because it happened without users giving explicit consent and in the absence of a comprehensive data-protection law in India.<\/p>\n<p class=\"paywall\">The Tatas, with a market cap of <a data-offer-url=\"https:\/\/www.moneycontrol.com\/news\/business\/markets\/tata-group-stocks-market-value-triples-under-chandrasekarans-reign-8081121.html\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.moneycontrol.com\/news\/business\/markets\/tata-group-stocks-market-value-triples-under-chandrasekarans-reign-8081121.html&quot;}\" href=\"https:\/\/www.moneycontrol.com\/news\/business\/markets\/tata-group-stocks-market-value-triples-under-chandrasekarans-reign-8081121.html\" rel=\"nofollow noopener\" target=\"_blank\">over $300 billion<\/a> at current exchange rates, have had a strong offline presence across a wide range of sectors. But, until relatively recently, consumer tech remained an untapped market. So a few years ago, in a bid to compete with tech biggies like Amazon and Walmart-owned Flipkart, Tata started building its digital profile by acquiring startups like Alibaba-backed online grocery firm Big Basket and medicine delivery startup 1mg, along with an investment in health-and-fitness startup Cult.Fit.<\/p>\n<p class=\"paywall\">Some customers of these startups acquired by Tata received an email with updated terms and conditions. Others, including the author of this piece, received no email and are unaware of any other form of notice. And while previous privacy policies of these apps vaguely said that they may share customer data with partner companies or other third parties in the event of an acquisition, experts say it\u2019s the lack of explicit consumer consent coupled with the fact that this is data collected from acquired companies which, according to long-time privacy advocate Nikhil Pahwa, makes it \u201can ethical failure on the part of the Tata Group.\u201d<\/p>\n<p class=\"paywall\">\u201cAll super apps already do this [data sharing] but the difference for Tata Neu is the fact that they have acquired companies and then connected all of this data together,\u201d says Pahwa, founder of digital media portal <a data-offer-url=\"https:\/\/www.medianama.com\/2022\/04\/223-tata-brands-data-sharing-privacy-concerns\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.medianama.com\/2022\/04\/223-tata-brands-data-sharing-privacy-concerns\/&quot;}\" href=\"https:\/\/www.medianama.com\/2022\/04\/223-tata-brands-data-sharing-privacy-concerns\/\" rel=\"nofollow noopener\" target=\"_blank\">Medianama<\/a>. \u201cThere is a different threshold of accountability for them, because customers who were using an app or service before acquisition naturally didn\u2019t expect that the data would be linked to data from multiple different apps when an acquisition takes place.\u201d<\/p>\n<p class=\"paywall\">In response to queries sent by WIRED, a Tata spokesperson defended the company\u2019s business practices and asserted that it is committed to user privacy and security.<\/p>\n<p class=\"paywall\">\u201cRespecting and safeguarding our customers&#x27; privacy is vital to our business at Tata Digital. We take great care to maintain the confidentiality of their information,\u201d the spokesperson said. \u201cTata Digital complies with, and will continue to comply with, applicable data regulations, both in letter and spirit.\u201d<\/p>\n<p class=\"paywall\">Last year, WhatsApp\u2014for which India is the <a data-offer-url=\"https:\/\/backlinko.com\/whatsapp-users#whatsapp-statistics\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/backlinko.com\/whatsapp-users#whatsapp-statistics&quot;}\" href=\"https:\/\/backlinko.com\/whatsapp-users#whatsapp-statistics\" rel=\"nofollow noopener\" target=\"_blank\">largest<\/a> market\u2014<a data-offer-url=\"https:\/\/faq.whatsapp.com\/general\/security-and-privacy\/answering-your-questions-about-whatsapps-privacy-policy\/?lang=en\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/faq.whatsapp.com\/general\/security-and-privacy\/answering-your-questions-about-whatsapps-privacy-policy\/?lang=en&quot;}\" href=\"https:\/\/faq.whatsapp.com\/general\/security-and-privacy\/answering-your-questions-about-whatsapps-privacy-policy\/?lang=en\" rel=\"nofollow noopener\" target=\"_blank\">updated<\/a> its privacy policy to require users to accept sharing their data with its parent company, Facebook (now known as Meta). This led to an outrage among its users, many of whom <a data-offer-url=\"https:\/\/restofworld.org\/2021\/whatsapp-risks-losing-its-loyal-customers\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/restofworld.org\/2021\/whatsapp-risks-losing-its-loyal-customers\/&quot;}\" href=\"https:\/\/restofworld.org\/2021\/whatsapp-risks-losing-its-loyal-customers\/\" rel=\"nofollow noopener\" target=\"_blank\">abandoned<\/a> WhatsApp (if only temporarily) and moved en masse to other messaging apps like Signal and Telegram.<\/p>\n<p class=\"paywall\">The Competition Commission of India, India\u2019s antitrust agency, soon <a data-offer-url=\"https:\/\/www.business-standard.com\/article\/companies\/delhi-hc-grants-whatsapp-facebook-time-to-respond-to-cci-probe-122010300381_1.html\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.business-standard.com\/article\/companies\/delhi-hc-grants-whatsapp-facebook-time-to-respond-to-cci-probe-122010300381_1.html&quot;}\" href=\"https:\/\/www.business-standard.com\/article\/companies\/delhi-hc-grants-whatsapp-facebook-time-to-respond-to-cci-probe-122010300381_1.html\" rel=\"nofollow noopener\" target=\"_blank\">initiated regulatory action<\/a> against WhatsApp for the unilateral changes to its privacy policy on the grounds of abuse of dominance. But antitrust and privacy lawyers say it may be difficult to make the argument of unfair policy terms as a form of abuse of dominance in the case of a new entrant like Neu, because it has a relatively small market share so far. \u201cHowever, if any of the Tata affiliates hold a clear dominance in the markets that they operate in, then any sort of coercive data sharing with Neu could potentially raise competition law issues for that entity,\u201d says Smriti Parsheera, a tech policy researcher with the think tank National Institute of Public Finance and Policy.<\/p>\n<p class=\"paywall\">Tata\u2019s data sharing stands against the void of a lack of a comprehensive data protection law in India. The closest thing the country has is now a <a data-offer-url=\"https:\/\/trilegal.com\/knowledge_repository\/the-data-protection-bill-2021\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/trilegal.com\/knowledge_repository\/the-data-protection-bill-2021\/&quot;}\" href=\"https:\/\/trilegal.com\/knowledge_repository\/the-data-protection-bill-2021\/\" rel=\"nofollow noopener\" target=\"_blank\">finalized<\/a> Data Protection Bill, 2021. But the legislation hasn&#x27;t been passed and relies on \u201cinformed\u201d consent as one of the main grounds of data processing\u2014meaning companies could still bury alerts about how their data could be used under a mountain of legalese while giving people no opt-out beyond not using the service.<\/p>\n<p class=\"paywall\">\u201cMerely having the new law would not completely solve the problem,\u201d says Parsheera. \u201cBut it will create a framework of accountability where the new regulator can take actions, and consumers can seek redress.\u201d The new regulator would also be expected to frame regulations around the tools that can be used to make privacy policies more understandable to users.<\/p>\n<p class=\"paywall\">Ojha, for one, is not waiting for the Indian government to bring a legal framework for data protection. He decided to delete the app the same day it first resided on his phone\u2019s home screen. \u201cI found it very cumbersome and absolutely zero value addition to me,\u201d he says. \u201cAlso, I was uncomfortable that they were using my personal information without my explicit permission.\u201d<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/india-tata-super-app-privacy\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/6271744df2e5a2b3f2ddf349\/master\/pass\/India-Privacy-Tata-App-Security-GettyImages-981948872.jpg\"\/><\/p>\n<p><strong>Credit to Author: Varsha Bansal| Date: Wed, 04 May 2022 11:00:00 +0000<\/strong><\/p>\n<p>Tata Neu is the country\u2019s latest do-everything app. When users signed up, their personal information was already there.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-18940","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18940"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18940\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18940"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}