21 Nov 2015

Online Card Games Websites May Be Legally Risky If Not Properly Drafted And Managed

At Perry4Law we are frequently approached by online cards and non cards games providers to ascertain the legality of their business models. We guide them as per their business models and requirements but there cannot be a single solution for various gaming stakeholders. This is because different states have different laws regarding online gaming and gambling in India.

Some stakeholders have already approached the Supreme Court of India to get clarity on the legality of online games like rummy, poker, etc. In response of the same, the Supreme Court asked the opinion of Central Government in this regard but the same has been informally denied by the Central Government.  This means that till the time Supreme Court actually says that online rummy, online poker and online card games are legal in India, majority of these gaming stakeholders may be exposing themselves to legal risks and civil and criminal liabilities.

Another problem related to this litigation is that this is an issued between parties to the litigation alone and other cannot derive benefit out of this litigation even if the ultimate decision allows online poker and rummy in India. This is the reason that many gaming companies have approached the Supreme Court to implead them as necessary party to this litigation. While this may be beneficial to clarify the position regarding these additional parties as well yet it would also make them bound the decision of Supreme Court. If an adverse decision is given by the Supreme Court, that would be binding on them as well.

Another related problem with the proceedings taking place at the Supreme Court is that till the time Supreme Court decides this issue, various High Courts would not touch the games with stakes issue at all. This is more so regarding online poker and rummy legal issues as the matter is pending before the Supreme Court.

This is exactly what is happening in India as on date. It has been reported that the Hyderabad High Court has refused to grant relief to clubs in the city who wanted the Hyderabad police prevented from interfering or obstructing in any manner from running card rooms on club premises where members and guests are allowed to play rummy with stakes.

Justice Vilas V. Afzulpurkar was dealing with a petition by the managements of Chiran Fort Club and nine others challenging the action of the police in closing their card rooms. The petitioners contended that in view of the declaration of the Supreme Court in the case of Kishan Chander versus state of Madhya Pradesh, the game of Rummy is not entirely a game of chance and is a game of skill. So the closure of card rooms by the police was illegal.

While refusing interim relief, the judge said in view of new findings in a similar case by the SC and the Madras HC, the case needs a detailed examination to determine whether playing Rummy with stakes will attract provisions under the Gambling Act or not. This is a logical conclusion as the issue of playing poker or rummy with stakes is still not clear despite the contrary beliefs. It is certainly very risky when it comes to online poker and online rummy in India.

Online card games websites may be legally risky if not properly drafted and managed. In fact a majority of online poker and rummy websites are flouting laws of India and they can be punished any time by the Government.

Perry4Law strongly recommends that till the time Indian Supreme Court or Central Government clarifies the legal position regarding online gaming in India, the online gaming/gambling stakeholders must comply with existing and applicable techno legal requirements of Indian laws.

20 Nov 2015

Google Services Temporarily Cut Off Due To Hathway’s Incorrect Traffic Routing

The original design of Internet and its protocols presupposes existence of mutual trust and this at times also cause troubles. In the initial age of Internet, there were very few Internet protocol addresses and they use to communicate with each other directly. There was little reason for abuse or distrust among these IP addresses and their owners. There were also no fears of impersonation and IP spoofing as well.

However, as the Internet and these protocols grew, they became more unstable and untrustworthy. Now if we send something in plain text, chances are great that such plain text information maybe intercepted and misused. Nevertheless, networks and systems still need to trust each other to make the Internet function in a speedier manner. If one system or service provider falters, the services of other may be hampered.

In one such incidence, users around the world were not able to access Google’s service for a short period of time due to a technical glitch. Users were cut off due to the routing leak from Indian broadband Internet provider Hathway. The leak is similar to a 2012 incident caused by an Indonesian ISP, which took Google offline for 30 minutes worldwide.

Routing leaks occur when a network provider broadcasts all or part of its internal routing table to one or more peered networks via the Border Gateway Protocol (BGP) causing network traffic to be routed incorrectly. In the present case Hathway’s boundary router incorrectly announced routing data for over 300 network prefixes belonging to Google to the Internet backbone via its provider Bharti Airtel. Bharti in turn announced these routes to the rest of the world and a number of international ISPs accepted these routes.

Now why would Google rely upon Hathway for its services? This is because Hathway peers with Google to provide better speed to Google’s cloud, directing traffic to the closest Google data centers. That peering is a private network connection. As a result, when the routing table was accidentally broadcast to the world instead of just to Hathway’s customers, much of the world was trying to access Google via Mumbai, through Hathway, instead of over the public Internet.

By design users cannot access Google services with incorrect route information till it is rectified or routed correctly.

2 Nov 2015

RBI Decides To Set Up An IT Subsidiary To Deal With Cyber Crimes And Cyber Security Related Issues

India is treading on the digital highway and very soon most of the public services would be delivered through use of information and communication technologies (ICT). This is clear from the enthusiastic implementation of Digital India project that needs some fine tuning to get the best results. Nevertheless there is no escape from the reality that Digital India would be the face of Indian economy and culture very soon.

With this increased and omnipresent digital culture, cyber crimes and cyber security breaches would be the norm in future. This is the reason why the Delhi Police has decided to launch a mobile application that would help in filing of online FIR for economic frauds and cyber crimes. Now the Reserve Bank of India (RBI) has also showed its commitment to fight against cyber crimes and financial frauds by declaring that an information technology driven subsidiary would be established by it to deal with cyber nuisances. This IT subsidiary of RBI would also deal with cyber security and related issues with a special focus upon banking related technology issues. The IT subsidiary of RBI would also evaluate the technical capabilities of banks that is almost missing as on date.

We at Perry4Law Organisation (P4LO) welcome this move of RBI and extend our full techno legal support and expertise in this regard. As per the cyber security trends of India 2015 by P4LO cyber security related issues must be taken care of by various stakeholders including banks in India. Although RBI has announced many effective cyber security related initiatives for banks in India yet cyber security for banks in India is still not in good shape. Some of the initiatives already undertaken by RBI in this direction include formulation and implementation of Internet banking guidelines, formation of a RBI Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds, RBI Recommendation on Information Security and its implementation in India, etc.

RBI has also prescribed establishment of Steering Committees on Information Security by Banks in India and appointment of Chief Information Officers (CIOs) for all banks in India.  However, banks in India have failed to comply with the directions of RBI so far. As on date there is neither a legal framework nor any compulsion to ensure cyber security of banks in India. This gives little incentive to the banks to ensure cyber security of online banking system of India. On top of it, banks in India are not following cyber security due diligence and cyber law due diligence (PDF) despite RBI’s directions.

If we take the example of western countries, sophisticated malware are targeting banks of these countries. These countries are heavily relying upon ICT for their functioning and this makes them vulnerable to cyber crimes and cyber attacks. India has not faced this heat so far because till now India did not adopt technology to that extent. However, after the adoption of Digital India, cyber security and cyber crimes investigation would become major issues for not only the law enforcement agencies but also banks of India. RBI seems to be aware of this reality and has taken a good step by deciding to establish an IT subsidiary that would take care of all these issues. However, we at P4LO believe that this IT subsidiary of RBI should not be a mere paper tiger but must actually work towards establishing a robust and resilient cyber security environment for banks of India.

Sophisticated botnet and malware like Dump Memory Grabber has been targeting Indian banks and POS Terminals. Similarly, the Gameover Zeus or GOZ botnet is also capable of stealing sensitive banking and financial information and details. Recently, the US Justice Department even charged a Russian national for creation of Gameover Zeus (GOZ) Botnet.

In these circumstances we must consider the proposal of India to adopt and use mobile banking, Internet banking and other online banking and financial transactions methods. So far India and RBI has not considered the issues of mobile banking cyber security, internet banking cyber security, legal aspects of Internet banking, cyber security of e-governance services, etc. In these circumstances, Indian online banking transactions are vulnerable to cyber attacks.

The cyber security for banking and financial sectors of India must be ensured as soon as possible. Online payment market of India and e-commerce and online business legal compliances have further increased the requirements of banking cyber security in India. Similarly, cyber due diligence for Paypal and online payment transferors of India must also be ensured by these stakeholders. These are some of the suggestions that P4LO has shared with Indian Government and RBI through this platform. More detailed suggestions would also be shared by P4LO at appropriate stage and platform.

22 Dec 2013

Corporate Governance Laws In India

Perry4Law and Perry4Law’s Techno Legal Base (PTLB) thank their viewers and readers for their continued support and commitment.

In order to provide more comprehensive and holistic views and opinions about the corporate laws of India, we have shifted this platform to another platform titled Corporate Governance Laws in India.

This is also an attempt to discuss the provisions of Indian Companies Act 2013 in a holistic and techno legal manner.

We have also added additional fields like e-discovery, cyber forensics, cyber security, cyber crimes investigation, etc to the new platforms so that techno legal analysis of the corporate environment is possible.

Perry4Law and PTLB hope that our readers would find the new platform worth reading and enjoying.

18 Mar 2013

Finance Ministry And RBI Investigating Money Laundering Accusations Against ICICI, HDFC And Axis Bank

Banking frauds in India have crossed all the limits and there is an urgent need on the part of Reserve Bank of India and Finance Ministry of India to take strict penal action against the offending banks.

RBI has in the past imposed penalties upon many banks for failure to comply with various laws and regulations. RBI is also investigating the cyber fraud happened at YES Bank.

Now it has been reported by media that ICICI, HDFC and Axis Banks have been accused of indulging in money laundering and benami transactions.

Reacting to this gross and poor state of banking industry of India, the Reserve Bank of India (RBI) and Finance Ministry of India have decided to investigate the money laundering allegations against ICICI, HDFC and Axis banks.

We would share the result of the investigation the moment it would be made public by Finance Ministry and RBI.

Banking Frauds In India Have Increased And RBI Is Sleeping

Banking frauds in India have increased tremendously. This is partly due to lack of stringent banking fraud laws in India and partly because the Reserve Bank of India (RBI) has failed to do the needful in this regard.

ATM frauds, Internet banking frauds, online banking frauds, RTGS frauds, money laundering offences, etc are on rise and all this is happening right under the nose of RBI.

In the absence of any deterrent punishment, Indian banks and their official are openly flouting the rules and regulations applicable to them. They are also flouting the bank's code of conduct and ethical standards.

Banks of India are also not following cyber law due diligence in India.

Banks of India have also failed to appoint chief information officers (CIOs) and adopt cyber security requirements as prescribed by the Reserve Bank of India (RBI).


At Perry4Law and Perry4Law’s Techno Legal Base (PTLB) we strongly believe that the regulatory environment for banks in India needs a rejuvenation that must bring transparency, accountability and responsibility among banks of India.

ICICI, HDFC And Axis Banks Alleged To Be Indulging In Money Laundering And Benami Transactions

Banking frauds in India have reached a level where if immediate action is not taken then public would loose faith in the banking industry of India.

As per media reports, it has been alleged that senior executive of private banks like ICICI, HDFC and Axis Banks have agreed to receive unverified sums of cash and put them in their investment schemes and benami accounts in violation of anti-money laundering laws of India.

These allegations are serious in nature and a thorough investigation must be conducted by enforcement officials, serious fraud investigation office (SFIO) and Reserve Bank of India (RBI).

If found guilt, strict legal and administrative actions must be taken against the guilty banks and their officials.

The banking license of banks repeatedly violating rules and regulations applicable in India must also be cancelled by the RBI.

Further, it is also high time to formulate phishing laws and regulations for banks and financial institutions of India as well as complaint against more and more banks are filed these days.

At Perry4Law and Perry4Law’s Techno Legal Base (PTLB) we strongly believe that the regulatory environment for banks in India needs a rejuvenation that must bring transparency, accountability and responsibility among banks of India.

The sooner this is done the better it would be for the larger interest of all stakeholders.