0% found this document useful (0 votes)
16 views3 pages

Tokenisation Strategy for IRC Bank

The document discusses issues related to IRC Bank's tokenization initiative and legal matters that have arisen. IRC Bank aims to be the first bank to tokenize sensitive customer data and integrate third party applications via API. The document seeks advice on API licensing terms, applicable security standards, extending tokenization to IoT, and legal recourse against defamatory social media posts regarding a fraudulent transaction.

Uploaded by

Antra Azad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views3 pages

Tokenisation Strategy for IRC Bank

The document discusses issues related to IRC Bank's tokenization initiative and legal matters that have arisen. IRC Bank aims to be the first bank to tokenize sensitive customer data and integrate third party applications via API. The document seeks advice on API licensing terms, applicable security standards, extending tokenization to IoT, and legal recourse against defamatory social media posts regarding a fraudulent transaction.

Uploaded by

Antra Azad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

BEAT THE CURVE 3.

0
Problem Statement

Indian Retail and Commercial Bank (“IRC Bank”) is a scheduled commercial bank
incorporated under the Companies Act, 2013 and licensed under the Banking Regulation
Act, 1949. IRC Bank is a dynamic institution that has been at the forefront of various fintech
initiatives and is constantly collaborating with entities around the globe, with the
endeavour to provide the most cutting edge solutions to its customers.

IRC Bank, being a pioneer in upholding principles of personal data protection, has been
collaborating with various global conglomerates for storing and backing up data in servers
situated within the jurisdiction of India.

Part-I
Year - 2019

As a part of its new process, IRC Bank is planning to be the first bank to substitute sensitive
identifiers such as card numbers and other sensitive personal data or information (“SPDI”
as defined under the Information Technology (Reasonable Security Practices and
Procedures and Sensitive Personal Data or Information) Rules 2011) with a non-sensitive
equivalent (i.e., a “token”) that has no extrinsic or exploitable meaning or value. The said
process, coined as “Tokenisation” would replace the card data with a unique randomly
generated token that can be used to represent the card data in transactions but does not
reveal the original card data. This technology would involve integration of platforms that
want to leverage such tokens (For Eg: E-Commerce Applications) through an Application
Program Interface (“API”) for which certain API nodes have been made available. This
would mean that the number of systems with access to the original card data is
dramatically reduced, and with it the risk of fraud should a system become compromised.

Issues-

1) IRC Bank wants to draft standard API licensing terms that can be agreed to by these
applications, to leverage the “Tokenisation” feature. What should be the features of
such licensing terms?
Note: A Broad Template for an API Licensing Agreement is attached herewith as
Annexure-A.

[Please limit the draft agreement to 7500 words only.]

2) What are the security standards that are applicable under Indian law for the purpose
of this feature? Provide the business team with the legal risks, its mitigants and
contractual safeguards to ensure IRC Bank’s interests are saefguarded to the extent
possible, throughout the entire process of Tokenisation.

[Please limit your response to 2000 words only.]


In order to take giant leaps in term of personal data protection, IRC Bank intends to offer
Tokenisation to all of its existing and prospective customers, within the purview of the
extant regulatory and statutory framework.

Year 2021

The Financing Technology Solutions Group of IRC Bank has intended to extend the usage
of Tokenisation transactions to Internet of Thing Devices (“IoT”) as well, and has
approached the Corporate Legal Group and as a member of the Corporate Legal Group
you need to guide them on the below mentioned queries:

a. Highlight the regulatory compliances and the related internal framework, that IRC
Bank shall have to ensure before offering Tokenisation as an IoT Product to its
customers.

[Please limit your response to 2000 words only.]

Part- II

August 2021

IRC Bank now faces a new challenge in respect of its drive towards tokenisation. In the
month of July 2021, 150 customers across India reported complaints of unauthorised/
fraudulent banking transactions. In all these cases, there was a breach of security protocol
attributable to third-party fraudsters. In almost all cases, unique reference codes that ought
to have been known only to the customer were auto-generated by hackers.

Ms. Michelle, a fashion influencer, was also among those customers whose token details
were compromised by this third-party hack. She has filed a consumer complaint before
the DCDRF, Kolkata and the matter is presently sub-judice. She has taken to her YouTube
channel to air her grievances against IRC Bank – the title of these videos are mostly
sensational such as “FRAUD BY IRC GROUP – DO NOT BANK WITH THEM!” or “MY
TRAUMATIC EXPERIENCE WITH IRC BANK TOKENS”. In the videos, Ms. Michelle narrates
her version of the fraudulent transactions and urges her 5 million subscribers to boycott
IRC Bank, whose logo is prominently featured. She has also taken to other social media
platforms such as Instagram and Twitter to promote these videos. Currently, the videos
have been viewed 15 million times.

IRC Bank has reached out to Ms. Michelle to resolve her grievances through the judicial
process and otherwise as part of its customer servicing functions. Ms. Michelle has taken
the opportunity to make exaggerated claims and false allegations against senior
management of IRC Bank.

In view of the considerable damage to goodwill and defamatory antics of Ms. Michelle,
IRC Bank now seeks to pursue legal recourse against Ms. Michelle.

Please examine the Information Technology (Intermediary Guidelines and Digital Media
Ethics Code) Rules, 2021 and advise on steps that may be taken by the Bank thereunder in
combination with other civil/ criminal remedies. The response should touch upon
substantive and procedural laws under the said IT Rules 2021, CPC and/or CrPC, while also
bearing in mind the consumer matter is sub-judice. Reliance may be placed on judicial
precedents.

Assumptions:

1. You may presume all social media platforms mentioned in the problem have been
specified as “significant social media intermediaries” under the Information
Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

2. YouTube India Private Limited is a wholly owned subsidiary of Google LLC, USA,
who owns the global YouTube platform.

[Please limit your draft agreement to 4000 words only.]

Common questions

Powered by AI

IRC Bank can enhance its tokenisation process by incorporating multi-factor authentication, employing advanced encryption techniques, and setting up real-time monitoring systems to detect anomalies. Regular updates to the API nodes and conducting security audits would also ensure that potential vulnerabilities are identified and patched in a timely manner .

Under the IT Rules, 2021, IRC Bank should utilize the issuance of takedown notices and request expedited review processes as procedural tools to manage defamatory content. They need to coordinate with significant social media intermediaries to ensure compliance with intermediary obligations, and follow up using injunctions or content removal processes under CPC and CrPC .

IRC Bank can issue a takedown notice to the social media platforms under the IT Rules, 2021 to remove the defamatory content and can pursue further action through civil or criminal defamation suits under the IPC and CPC. They should substantiate claims with evidence to comply with procedural laws, while considering the judicial precedents to strengthen their case, especially since the consumer matter is sub judice .

IRC Bank should strengthen its fraud detection and response systems, enhance encryption methods for token security, and regularly audit third-party systems to prevent unauthorized access. Educating customers about safe practices for managing unique reference codes could also help in reducing fraud incidents caused by third-party breaches .

Prior to offering Tokenisation as an IoT product, IRC Bank must adhere to regulations regarding data storage and processing under the Information Technology Act and ensure that data is processed within the jurisdiction of India. Compliance with IoT-specific standards on data protection and interoperability should also be ensured to manage data privacy risks associated with IoT devices .

Data localization laws require IRC Bank to store and process customer data within India, reducing cross-border data transfer risks and enhancing data sovereignty. By storing data domestically, IRC Bank can ensure adherence to local data protection regulations, thereby minimizing legal risk and enhancing data security and customer trust .

IRC Bank can balance fintech innovations with legal requirements by adopting a compliance-first approach during their technological development cycles. Regular consultations with legal and regulatory experts can ensure all innovations remain within legal frameworks. Developing strategic partnerships with compliant tech providers and conducting risk assessments can facilitate compliance while promoting innovation .

IRC Bank can employ a multi-pronged approach including issuing public statements clarifying the incidents, engaging in active customer service to address concerned clients, and showcasing any security improvements made since the incident. They can also focus on corporate social responsibility initiatives to rebuild goodwill and consider litigation through proper channels to manage the reputation impact professionally .

The legal risks associated with the implementation of Tokenisation include potential breaches of sensitive personal data, non-compliance with data protection regulations, and liability for unauthorized transactions. These risks can be mitigated by implementing robust security protocols, ensuring compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, and incorporating contractual safeguards that limit liability and ensure adherence to security protocols .

When drafting API licensing terms for Tokenisation, IRC Bank should consider including security standards for data protection, specifying the limits of data access to ensure security, and enforcing compliance with regulatory requirements under Indian law. These measures are crucial to minimize legal risks and fraud potential, ensure the integrity and security of customer data, and meet legal obligations under the Information Technology Act .

You might also like