Collection of personal data of cell phone users
THE telecoms regulator has collected sensitive personal data of about seven crore cell phone users without their consent and shared those with another government agency for a ghost survey just weeks before the Parliamentary Elections. Four mobile operators were at first reluctant to hand over the information but eventually gave in to the demand of the BTRC (Bangladesh Telecommunication Regulatory Commission) in a breach of customers’ trust. Under the existing laws, mobile companies cannot share subscribers’ information unless there is a court order or an issue of national security and public order.
Most strangely, the BTRC gave two different versions, in a span of two days, about which government agency took the data. On Tuesday, BTRC said the dataset was handed over to the Ministry of Power and Energy for a survey, then on Thursday said Bangladesh Bureau of Statistics (BBS) took the dataset. In contrast, State Minister Nasrul Hamid flatly denied collecting users’ data from the BTRC while the BBS categorically denied having any dataset from the BTRC in recent days. The lack of transparency in safeguarding the users’ data is a breach of customers’ trust and public safety and security.
However, Power and Energy Adviser Tawfiq-e-Elahi Chowdhury confirmed that he collected the data from the BTRC and handed it over to the BBS for a survey. According to the list attached with the BTRC letter, personal data of all the mobile users in 184 Upazilas from all Divisions were collected in the process. This is for the first time the telecoms regulator has collected such a huge volume of user data of certain locations, and suspicions deepened as it coincides with the run-up to the National Election.
Collecting customers’ information without their consent is a direct violation of the Telecommunication Act-2001. If the bulk data are somehow obtained by an unscrupulous person or party, the data leak may cause huge damage. Mobile operators said they spend crores of taka every year for safeguarding users’ data but everything is now at stake because of this breach. The authorities must make it clear why the dataset was collected and reassure the users about the safeguard of the data.
