including where these are regular citizens or notfor-profits rather than commercial entities, arguably affecting their freedom of speech and expression. Without going as far as to provide a definitive list of characteristics which justify regulation of private commercial entities, the explanatory memorandum to the TRAI regulation notes that changes to business models and commercial arrangements should pay heed to the unique architecture of the internet, including its “end-to-end design principle”, according to which features specific to an application reside in the communicating end nodes, rather than in the intermediary nodes of the network. This principle is central to net neutrality. The internet has become the most active public square, where political speech is discussed, and public opinion mobilised. The state has a role to play in ensuring that such a space is not unduly controlled by gatekeepers. As private players mediate access to a public good, the internet, they have an obligation to ensure that there is no discrimination on the grounds of who the service is being offered to. As observed in several submissions to the above-mentioned consultation, the Supreme Court has previously held that when private parties discharge what amounts to a public function, they must be held to a public law standard.135 Consultations on a broader framework for net neutrality, with similar potential ramifications for the right to freedom of expression online, have also been held by TRAI since then, as well as by the Department of Telecommunications. The outcome of these consultations is awaited. Surveillance It has been established by courts136 as well as by research137 that mass surveillance has a chilling effect on speech and expression. In India, such concerns have arisen especially in the context of mass surveillance programmes. Some of these, such as the Central Monitoring System (CMS) and National Intelligence Grid (NATGRID), have been designed for the specific purpose of mass communications surveillance; others, such as the Unique Identity Project (Aadhaar) and the seeding of Aadhaar numbers in other databases, have tremendous potential for mass surveillance but were not developed explicitly for this purpose. The CMS has been operationalised through a mere executive order. In addition, the licence terms of 135 Unnikrishnan v. State of Andhra Pradesh, 1993 SCC (1) 645. 136 Shreya Singhal v. Union of India, AIR 2015 SC 1523. 137 Penney, J. (2016). Chilling Effects: Online Surveillance and Wikipedia Use. Berkeley Technology Law Journal, 31(1). https:// www.papers.ssrn.com/sol3/papers.cfm?abstract_id=2769645 Unified Access Services (UAS) Licensees and Unified Service Licensees were amended in 2013 to require the setting up of interception store and forward (ISF) servers and integration with the Lawful Interception Systems at the licensee’s premises.138 These servers were to be connected to Regional Monitoring Centres, which are in turn connected to the CMS. The CMS infrastructure, operated by Telecom Enforcement Resource and Monitoring (TERM) cells, enables interception of all communications over the networks in a systematic way such that authorities do not have to interface with the nodal officers of telecom service providers for interception requests. As per section 4 of the Telegraph Act, all ISPs and telecom companies require a licence from the central government to do business. While licences contain a number of clauses requiring ISPs to safeguard the privacy and confidentiality of the information of their customers, they also require ISPs to maintain extensive logs of user activity, which need to be available in real time to the telecom authority, and to cooperate with government agencies when required to do so. In practice, however, ISPs only kept a log of customers’ internet protocol addresses, as well as selectively monitoring specific users’ activity at the government’s request.139 With the establishment of the CMS, the government now no longer needs to rely on telecom companies’ cooperation. NATGRID is an initiative of the Ministry of Home Affairs. According to the Ministry’s website, NATGRID “has been conceived to develop a cutting edge framework to enhance India’s counter-terror capabilities.” The project, started in 2011, seeks to connect 21 databases held by different agencies of the government like the Customs Department, Income Tax Department, etc., through agreements. The Central Board of Direct Taxes issued a notification earlier this year to share “bulk information” including Permanent Account Numbers (PAN), taxpayers’ names and demographic and biometric details like photographs and thumbprints with NATGRID.140 Such all-round access by intelligence agencies to 138 Ministry of Telecommunications and Information Technology. (2013, 11 October). Amendment 2 of 13. www.dot.gov.in/sites/ default/files/DOC231013.pdf?download=1 139 Philip, J. T. (2010, 30 December). Intelligence bureau wants ISPs to log all customer details. Economic Times. https:// economictimes.indiatimes.com/tech/internet/intelligence-bureauwants-isps-to-log-all-customer-details/articleshow/7187899. cms?intenttarget=no 140 Central Board of Direct Taxes, Department of Revenue, Ministry of Finance. (2017, 21 June). Notification 54 of 2017. www.incometaxindia.gov.in/communications/notification/ notification54_2017.pdf; Press Trust of India. (2017, 22 June). NATGRID to get PAN, taxpayer data access. Economic Times. www. economictimes.indiatimes.com/news/economy/policy/natgrid-toget-pan-taxpayer-data-access/articleshow/59270998.cms 78 / Unshackling Expression

Select target paragraph3