Showing posts with label Camera. Show all posts
Showing posts with label Camera. Show all posts

Tuesday, September 1, 2026

Drones and Data Privacy

Drones and Data Privacy 

Drones raise data privacy concerns due to their ability to collect vast amounts of personal data, including images, video, and geolocation, through advanced sensors and cameras. These concerns are amplified by potential for surveillance, the collection of data without consent, and security risks like hacking. Mitigation requires clear guidelines, responsible use, and the implementation of data protection principles like data minimization and secure storage.

 

For Indian business owners, a drone is no longer just an aerial tool; it is a mobile data harvester. Operating commercially means navigating the strict intersection of aviation mandates from the Directorate General of Civil Aviation (DGCA) and the stringent privacy liabilities of India’s Digital Personal Data Protection (DPDP) Act.

As drone adoption accelerates across Europe, privacy has become the new regulatory frontier. Enterprises must now prove not just safety, but also data sovereignty — where and how aerial data is stored, processed, and shared.

What is personal data? The term “personal data” is a very broad concept that covers any type of information relating to an identified or identifiable person. As a result, any use of a drone that captures images which identify an individual (such as a facial image) will fall within the scope of data protection legislations. But the same also applies if the drone collects any type of data (such as location, house fronts, phone number, vehicle registration plate, IR image, etc) that can be linked to an individual and therefore, this one becomes identifiable/identified.

Hidden Privacy Risks of Aerial Data

·       Surveillance: 

Drones can be used by governments, law enforcement, or private entities to monitor individuals, infringing on their right to privacy. 

·       Data collection: 

High-resolution cameras and sensors can capture images, video, audio, and location data that identify individuals, even without direct intention. 

·       Unauthorized access: 

The use of drones in public spaces can intrude on areas where people have a reasonable expectation of privacy, such as private properties. 

·       Function creep: 

The sophisticated technology on drones can lead to "function creep," where data is collected for one purpose and then used for other, more intrusive purposes later. 

·       Security vulnerabilities: 

Drones and their data can be vulnerable to hacking, which can lead to unauthorized access or the compromise of sensitive information.

Mitigation and best practices

·       Establish clear guidelines: 

Regulations are needed to define when and how drones can be used for data collection, particularly in residential or sensitive areas. 

·       Adopt data minimization: 

Data collection should be limited to what is necessary for a specific, stated purpose, and irrelevant data should not be retained or collected. 

·       Implement security measures: 

Manufacturers and users should implement robust data handling and storage mechanisms to protect collected data. 

·       Use privacy-by-design: 

Drones should be designed with privacy in mind, and hardware capabilities that pose risks should be carefully considered. 

·       Educate users: 

Recreational and commercial users need to be aware of privacy risks and practice responsible use, which may include following codes of conduct. 

Drone hardware (payloads and capabilities) and privacy

Drone payloads which include sensors and allow capturing data could give rise to privacy concerns among individuals on the ground. By capturing data, such as images, sound, geolocation and others, a drone could interfere with the privacy of individuals on the ground, especially if the captured data allows the identification of people (which in such case qualifies as the collection of personal data in terms of the GDPR). Blurring of faces of people is not always a guaranteed way to prevent such identification in contexts which contain other details, such as house or car numbers. Therefore, it is recommended that you, as a manufacturer, consider what kind of hardware features and capabilities a drone should be equipped with.

The question has shifted from “Can drones fly here?” to “Can this data legally live here?”

Why compliance is now a boardroom issue

For companies like UAVONIC, operating across the EU, every mission involves strict GDPR and local data protection checks. Each flight generates high-resolution video and telemetry that can include private property, people, or restricted infrastructure.

‍Traditional cloud workflows created friction: uploading footage to international servers risked compliance breaches. On-premise data handling, however, is limited in scalability. Enterprises needed both control and automation, a balance that most systems couldn’t offer.

How autonomy enables compliance

The solution came through FlytBase’s on-prem deployment model. UAVONIC adopted docked drones integrated with FlytBase’s local processing nodes, allowing missions to execute autonomously while keeping all captured data within sovereign infrastructure.

This approach provides:

·       Complete local data ownership — video and telemetry never leave the enterprise network

·       Automated audit trails for flight records and data access

·       Policy-based storage controls, aligning operations with GDPR and national regulations

By removing manual data handling and external transfers, UAVONIC reduced audit preparation time by 70% and achieved full compliance across multiple EU territories.

Beyond regulation toward accountability

Privacy compliance is evolving from a checkbox to a competitive advantage. Clients and partners now ask how enterprises manage drone data before granting access to sensitive sites.

By using FlytBase’s secure automation framework, organizations can demonstrate verifiable control over every mission, proving not only where data is stored, but how it’s governed.


The global shift to data sovereignty

Across industries, from utilities to logistics, more enterprises are adopting localized autonomy frameworks. Each FlytBase deployment ensures that sensitive operational data stays within defined boundaries while maintaining real-time collaboration for authorized teams.

The result is a new kind of compliance readiness — one that’s proactive, automated, and fully auditable.

Securing autonomy for the future

‍Data privacy is no longer an IT concern; it’s a business requirement. By combining autonomy with data governance, FlytBase enables organizations like UAVONIC to operate confidently in regulated environments while staying ready for future policy shifts.

Potential risk

Pontential safeguards

Overall information and IT security assurance

Malicious hardware or software could be used to attack both the drone and the ground control systems. Such vulnerabilities could lead to loss of sensitive data or to loss of control over drones while operational, both of which could raise potential privacy and security concerns.

The security of the entire supply chain of software and components you use to manufacture a drone should be ensured.

Ensure that the update or patching of software does not interfere with the operation of the drone, especially while in flight.

Using firewalls, antivirus systems and intrusion detection systems could be a fundamental step towards security the drone.

Drone navigation, both when operating autonomously and manually  

Information and IT security vulnerabilities in the ground control system for the drone or in the transmission of information and commands between the drone and its controlling point could allow unauthorised persons to take over control of the drone or disrupt its normal functioning. This could raise concerns about the privacy of people on the ground since this unauthorised controller would be unknown to them but could also raise security issues due to the physical damage and harm which drones could cause. 

Installing authorisation controls on the ground control system could help limit unauthorised access and control of the drone or unauthorised interference with drone features and settings.

Since Global Navigation Satellite

Systems (GNSS) like Galileo, GPS or GLONASS broadcasts are freely accessible, unencrypted and unauthorised signals, a drone could be fed misleading GNSS signals to alter its calculations of geographical coordinates. This could lead to a drone changing its flight path and could raise privacy and security concerns, particularly when the drone is operating autonomously.

Software features which are able to detect fake GNSS signals should be incorporated into the product.

A interface feature whereby manual control can easily be restored and override autonomous operation is recommended.

GNSS signals could also be jammed. This would disrupt the connection between the drone and external navigation, leading to the drone becoming disoriented and potentially crashing.

Alternative means of navigation could be considered, such as reliance on visual and inertia ques and requiring the attention of pilots and operators to begin manual operation. The use of GNSS receivers for more than one system can also mitigate the risk of GNSS jamming.

Data collection and processing

The operation and functioning of drones could be attacked by injecting false sensor data into the flight controller. This type of attack can impact all types of drone sensors, including radar, infrared and electrooptical sensors.

A drone could utilise alternative operational procedures to compare data received through different sensors and crosscheck readings. This could allow the drone to tolerate malfunctioning components or infected information.

Data transmission between the drone and other devices

(e.g. control system)

Real time data streams can be hacked and intercepted, especially if they are not encrypted or equally protected. This can jeopardise the privacy of people captured in the data, as well as the security of the drone operation itself by failing to control access to key data.

Incorporating continuous mutual authentication between the operator and the drone can help authenticate communication.

Encryption could help protect such data.

Utilising security keys to authenticate the connection and transmissions can ensure its security.

Data stored on drone 

By exploiting information and IT security vulnerabilities, unauthorised personnel could gain access to data stored on a drone. This could take place in the event of a drone accident or drone crash, as well as by exploiting vulnerabilities in the hardware and software of the drone. This could raise privacy concerns for individuals whose data is captured.

Use encryption to ensure the data stored on a drone is protected.

Implement access controls to the drone itself requiring authorisation for accessing data.

Build in capabilities to detect data breaches and alarm users to them.


The Dual Regulatory Burden on Indian Businesses

1. DGCA Airspace Compliance

All commercial drones operating above the Nano category (under 250 grams) must strictly follow the DGCA framework.

·       UIN Registration: Every drone must be registered on the eGCA Portal to receive a Unique Identification Number.

·       NPNT Mandate: India enforces No Permission, No Takeoff (NPNT). Drones must connect to the DigitalSky system; firmware locks will physically prevent the drone from taking off unless digital flight clearance is granted.

·       The Civil Drone Bill: Businesses should prepare for the stringent updates outlined in the Civil Drone Bill, which significantly escalates penalties for deviations—including steep fines up to ₹1 Lakh and authority powers to detain aerial hardware on mere suspicion.

2. The DPDP Act: Your Data Fiduciary Status

Under the Digital Personal Data Protection Act, commercial operators are legally classified as Data Fiduciaries. Aerial video files, LiDAR maps, or thermal scans that capture identifiable faces, residential interiors, or vehicle license plates are classified as digital personal data. If your drone inadvertently records individuals without explicit authorization, your business faces substantial financial liabilities.

Operational Blueprint for Privacy and Compliance

To protect your business from operational bans or multi-crore privacy penalties, integrate these localized practices into your standard operating procedures (SOPs):

Deploy Privacy Masking at the Source

·       Firmware Controls: Work with your tech teams to configure built-in "privacy masking" protocols.

·       AI Blurring: Use localized post-processing software to automatically blur faces and registration plates before sharing mapping data with third-party clients.

Establish Verifiable Consent & Notice Architecture

·       Public Advisories: When surveying non-public zones or semi-residential sites, provide clear, advanced notification to local communities.

·       Explicit Disclosures: State exactly why data is being collected, who will have access to it, and how long the video logs will be archived.

Localise Data Storage

·       Turn Off Auto-Sync: Many commercial drone suites default to overseas cloud servers. Restrict your hardware to Local Data Mode (LDM) to force the data to remain entirely within localized, offline servers.

·       On-Soil Infrastructure: Under the DPDP Act guidelines, any data transferred across borders must clear negative-country checklists. Keeping processing pipelines on Indian cloud infrastructure lowers compliance risks.

Encrypt and Log All Assets

·       Secure the Storage: Encrypt the physical SD cards inside your drone payloads. If a drone crashes or is retrieved by an unauthorized party, the raw surveillance footage must remain completely unreadable.

·       Maintain Flight Logs: Keep precise flight telemetry logs for at least one year to protect your business against data breach accusations or airspace violations.

Comparison of Liability: Recreational vs. Commercial In India

Compliance Vector

Recreational / Nano Drones (<250g)

Commercial Enterprise Drones (Micro to Large)

DGCA Registration

Not mandatory for most standard Nano models.

Mandatory via eGCA portal; must display physical UIN.

Pilot Licensing

No remote certificate needed for basic hobby flights.

Mandatory Remote Pilot Certificate via approved RPTO pathways.

Airspace Clearing

Restricted to basic green zones up to 50 feet.

Strict NPNT integration required before every single flight.

DPDP Accountability

Mostly exempt unless processing systemic data.

Full Data Fiduciary Liability with mandatory breach notifications.

The Outlook for Enterprise Aviation

The Indian commercial drone market is backed heavily by government growth models like the Production Linked Incentive (PLI) Scheme. However, this fast-tracked scaling requires operational maturity. Drone data security is no longer just a technical checkbox—it is a critical pillar of corporate compliance. Business leaders who proactively blend aviation safety with DPDP data privacy standards will gain a strong competitive advantage in India's expanding digital ecosystem.


Saturday, March 1, 2025

CAT cable to wire CCTV cameras

Using CAT cable to wire CCTV cameras 

In recent years the invention of the video balun has meant CAT cable can be used to connect CCTV cameras to CCTV DVR recorders. All the connections can be made using only a screwdriver, with no need for special tools or fiddly components. Before you start there are a couple of important things to know.

What components do I need?

Video is transmitted along the CAT cable using a pair of video baluns, one at the DVR end, and one at the camera end. We sell 2 types of video baluns, Standard definition and High definition designed to be used with our HD 1080P cameras and DVR recorders. Power is transmitted using screw-in DC plugs and sockets. The plug goes at the camera end and the socket at the DVR end. Locate the camera power supply close to the DVR.

Use the correct type of CAT cable

You must use pure copper CAT cable. Some CAT cable is not pure copper but CCA or copper-coated aluminium. Don't rely on the label or what the retailer says, actually check the cable yourself. CAT5, CAT5e, CAT6 and CAT6e can all be CCA rather than pure copper. CCA tends to break easily when bent and you can scrape the copper off to reveal silver-coloured metal in the centre. All the cable we sell is pure copper external grade.

Don't exceed the maximum cable run

The maximum distance video signal can be transferred with our video baluns is approximately 300 metres. If you are using the cable to power a camera as well as transfer video signal then we would suggest a maximum distance of about 50 metres to avoid voltage drop. This assumes you are using 3 pairs of wire for 12 volt supply and 1 pair for video signal transfer as per our images below.

Use a colour convention, stick to it and check carefully

It is important to check your wiring carefully. Choose a colour convention and stick to it. In the examples below we have used blue for the video signal and solid colour for +ve, white plus a coloured stripe for -ve.

You need to run 1 length of CAT cable from the DVR recorder to each camera. The cable is going to do 2 jobs. One pair of wires will handle the video signal, and the other 3 pairs of wires will be combined to take 12-volt power from the transformer located next to the DVR to the camera.

Firstly identify the polarity for all your connectors

Separate the 4 pairs of wires in the CAT cable. In this case, we are going to use the blue pair for transferring the video signal from the camera to the DVR. Keep this pair twisted, to reduce the chance of interference.

The green, brown and orange pairs are going to be used to take 12-volt power from the transformer to the camera. We use 3 pairs of wires combined to reduce the risk of voltage drop at the camera. Having unwound the wire use the solid colour for 12-volt +ve and the white with coloured trace for 12-volt -ve.

Here we can see the cables inserted into a video balun and a power plug.

Remember to strip back the outer plastic sheath to reveal the copper conductor before pushing into the fittings and tightening the connector with a small screwdriver.

Note how we have combined the 3 pairs of wires for the 12-volt DC fitting.

Be aware the DC power fittings are different for the DVR end of the cable and the camera end of the cable. The DVR end requires a female socket to take the 12-volt power from the power supply.

The camera end requires a male DC plug To take 12-volt power to the camera

It is important to protect the fittings from water so we recommend using weatherproof junction boxes for each camera. All the components you need are available in the CCTV accessories section of our online shop.

You can use Cat5 and Cat6 cables together in the same CCTV system.


Friday, March 1, 2024

Cyber Scams on the Rise in India

Unmasking the Surge: Cyber Scams on the Rise in India 

Cybercrime refers to criminal activities that are carried out using computers, computer networks, or the internet as tools or target.  Thеsе illegal activities can take various forms and can encompass a wide range of actions,  from financial fraud and data theft to online harassment and cybеr espionage.

Alarming reports suggest a surge in cyberattacks in India during the first three months of 2023, with over 500 million attacks thwarted out of a billion global attempts, as per the 'State of Application Security Report'.

Almost half the complaints, 1.56 million, were registered in 2023. Since 2019, more than 66,000 FIRs have been filed across states and Union territories based on these complaints.

Cyber scams have witnessed a significant rise in India, with multiple factors contributing to this concerning trend. Let's delve into a detailed analysis of the reasons behind the increasing prevalence of cyber scams in the country:

1. Rapid Digitalization: 

India is experiencing a massive digital transformation, with a growing number of people embracing online platforms for various activities like banking, shopping, and communication. This increased digitalization has provided cybercriminals with a larger pool of potential targets and opportunities to exploit vulnerabilities in the digital ecosystem.

2. Rising Internet Penetration: 

The widespread availability of affordable smartphones and internet connectivity has led to a surge in the number of internet users in India. As the internet user base expands, so does the potential victim pool for cyber scammers.

3. Lack of Cyber Awareness: 

A significant portion of the Indian population, particularly in rural areas and older age groups, may not have adequate knowledge of cybersecurity best practices. This lack of awareness makes them more susceptible to falling prey to various cyber scams, such as phishing emails, fake websites, and lottery frauds.

4. Sophistication of Cybercriminals: 

Cybercriminals have become increasingly sophisticated in their techniques and tools, making it challenging for individuals and organizations to detect and protect against their attacks. Advanced phishing emails, malware, and social engineering tactics are some of the methods employed by cyber scammers to exploit their victims.

5. Inadequate Cybersecurity Infrastructure: 

Despite the increasing cyber threats, many organizations and individuals in India still lack robust cybersecurity infrastructure and practices. This inadequacy leaves them vulnerable to cyber attacks, data breaches, and financial losses.

6. Lack of Stringent Regulations: 

The absence of stringent cybersecurity regulations and penalties for cybercrime in India can be perceived as an opportunity by cyber scammers. The absence of severe consequences for perpetrators may embolden them to continue their illicit activities.

7. Increasing Online Transactions: 

The rise of e-commerce and digital payment platforms has led to a surge in online transactions. This digital financial ecosystem attracts cyber scammers who seek to exploit security loopholes and trick users into divulging sensitive financial information.

8, Insider Threats: 

Insider threats, where current or former employees with access to sensitive data engage in fraudulent activities, can pose significant risks to businesses and individuals alike.

9. Global Nature of Cybercrime: 

Many cyber scams originate from outside India, taking advantage of the borderless nature of the internet. These international cyber threats may pose jurisdictional challenges for law enforcement agencies and hinder effective prosecution.

Root Cause to this: -

The rapid digitalization, rising internet penetration, lack of cyber awareness, and the increasing sophistication of cybercriminals are some of the key reasons behind the rise of cyber scams in India.

To combat this growing menace, there is an urgent need for enhanced cybersecurity awareness, investment in robust security measures, and the formulation of stringent cybersecurity regulations.

Additionally, continuous education and training in cybersecurity best practices for individuals and organizations can play a vital role in thwarting cyber scammers and creating a safer digital environment for all. Do not install non-NDAA approved IP Camera, NVR etc. Do not use China Based origin brand IP camera NVR etc.

Here are other takeaways for 2023:

  • Imposter scams. Imposter scams remained the top fraud category, with reported losses of $2.7 billion. ...
  • Investment scams. While investment-related scams were the fourth most-reported fraud category, losses in this category grew. ...
  • Social media scams. ...
  • Payment methods. ...
  • Losses by age.

Cybercrime Laws In India

1.   Information Tеchnology Act, 2000 (IT Act): Thе Information Tеchnology Act,  2000,  is thе primary legislation that dеals with cybеrcrimеs in India.  It was amеndеd in 2008 to kееp up with еvolving tеchnology and cybеr thrеats.  Kеy provisions of thе IT Act includе:

2.   Sеction 43: This sеction dеals with unauthorizеd accеss to computеr systеms and data. It providеs for pеnaltiеs for unauthorizеd accеss,  downloading,  or introduction of computеr virusеs.

3.   Sеction 65: This sеction dеals with tampеring with computеr sourcе documеnts, and it imposеs pеnaltiеs for altеring,  damaging,  or dеlеting data with thе intеnt to causе damagе or harm.

4.   Sеction 66: This sеction addrеssеs computеr-rеlatеd offеnsеs, such as hacking,  and prеscribеs pеnaltiеs for unauthorizеd accеss to computеr systеms,  nеtworks,  or data.

5.   Sеction 66A (Rеpеalеd): Sеction 66A was controvеrsial and was struck down by thе Suprеmе Court of India in 2015 bеcausе it was dееmеd to bе infringing on frее spееch rights.

6.   Sеction 66B: This sеction dеals with dishonеstly rеcеiving stolеn computеr rеsourcеs or communication dеvicеs.

7.   Sеction 66C: It pеrtains to idеntity thеft and thе usе of somеonе еlsе’s idеntity for fraudulеnt purposеs.

8.   Sеction 66D: This sеction dеals with chеating by pеrsonation using a computеr rеsourcе.

9.   Sеction 67: This sеction addrеssеs thе publication or transmission of obscеnе matеrial in еlеctronic form and imposеs pеnaltiеs.

10.Sеction 69: This sеction providеs thе govеrnmеnt with thе powеr to intеrcеpt and monitor еlеctronic communications for rеasons rеlatеd to national sеcurity.

11.Sеction 70: This sеction dеals with thе protеction of critical information infrastructurе and providеs for thе appointmеnt of a National Critical Information Infrastructurе Protеction Cеntrе (NCIIPC).

12.Sеction 72: It dеals with thе brеach of confidentiality and privacy and imposеs pеnaltiеs for disclosing pеrsonal information without consеnt.

13.Information Tеchnology (Amеndmеnt) Act, 2008: This amеndmеnt act еxpandеd thе scopе of thе IT Act and introducеd provisions rеlatеd to data protеction,  data brеachеs,  and increased pеnaltiеs for cybеrcrimеs.

Tracking WhatsApp messages or any other form of electronic communication without proper legal authorization is typically illegal and a violation of privacy.  However, undеr certain circumstances and with appropriate legal processes,  law enforcement agencies and cybеr cеlls may bе able to access WhatsApp messages as part of a criminal investigation. WhatsApp usеs еnd-to-end encryption, which means that messages arе scramblеd and can only bе decrypted by thе intended recipient.  WhatsApp itself does not have accеss to thе content of messages. To access WhatsApp messages for investigative purposes’, law enforcement agencies typically nееd to obtain proper lеgal authorization,  such as a court-issued warrant or a lawful court order.

Government of India has banned 17 Chinese companies from participating in tenders in India and warned private companies that do business with government entities against using these Chinese products. This is being seen as a significant crackdown on Chinese products that were entering the country after changing their brand names and tying up with Indian entities, ostensibly to hide their place of origin, and thus impacting the strategic and security interests of India while benefiting the Chinese economy.

The companies that have been banned include Xp-pen, Highvision Hikvision, Lenovo, Dahua, Lava, Ottomate, Xolo, Airpro, Grandstream, Wi-Tek, Realtime, Maxhub, Nokia, Domino, Reputer and Tyco.

The Sunday Guardian, last year, had revealed about Chinese products being used in government public sector undertakings that are working in the strategic sectors (Indian PSUs continue reliance on Chinese equipment in strategic sectors, 26 February 2023).

As per the government order released on the last day of January, the Indian sellers of these Chinese brands and the catalogs uploaded by them have been removed from Government e Marketplace (GeM) and they are not eligible for participating in any bid on GeM. The order has also said GeM will cancel those orders where the products of these Chinese companies are found to be used for the bid.

Seventy products, the maximum on the list, that have been banned belong to Hangzhou Hikvision Digital Technology Co., Ltd., often shortened to Hikvision. Its Indian face is Prama Hikvision (India) Pvt. Ltd. It is one of the biggest suppliers to Indian government agencies.

Similarly, DNS overseas, which handles products brought from the Beijing-based Hanvon Ugee Group and is a big player in the tablet market in India, has been removed from the GeM portal.

Twenty two products made by Lenovo, including servers, have been banned. Not many are aware that Lenovo is of Chinese origin.

Lenovo, founded in 1984, is seen as a product of the Chinese Academy of Sciences (CAS)—the Chinese-government’s premier institution of scientific research. CAS is reported to have extensive ties to the Chinese military.

Five products of Zhejiang Dahua Technology Company Limited, a publicly traded company based in Binjiang District, Hangzhou, which manufactures video surveillance equipment and sells its products in India under the brand name “Dahua” also features on the banned list.

Nineteen products of Lava International, whose brand ambassador is actor Kartik Aaryan, and has used cricketer Mahendra Singh Dhoni in the past, too have been banned. Also put on the banned list are products made under the brand name “Ottomate”, which is also a part of the Lava group. The products that have been banned include smart phones, fans and tablets. While Lava is seen as an Indian company, its products are made in China and then sold in India under a new brand name.

Thirteen products of Airpro have been put on the banned list including routers and cameras.

Five products of Grandstream and W-Tek that are sold in India by Cohesive Technologies have been removed from the portal.

Thirty one products made by “Realtime” and sold by Realtime Biometrics India Private Limited companies that include boom barriers, biometric access system, CCTVs have been banned.

The government has also come down heavily on the Chinese entity, Maxhub that sells its products through Shiyuan India Private Limited. A total of 18 of its products have been banned.

Six products sold by Hmd Mobile India Private Limited that are made by Nokia have been banned. According to industry insiders, the banned products are being manufactured in China. The brand had launched a media blitzkrieg a few years ago to convince Indian nationals that it was not making its products in China.

Seven products made by Tyco and marketed in India by Tyco Safety Products (India) Private Limited, two of Domino sold in India by Domino Printech India Llp and one of Reputer sold domestically by Innovitiq have been banned.

However, what has piqued industry insiders and security watchers is that many entities with notable Chinese investments and control that are active in India have not been added to this list.

These include products made by Huawei, Alcatel Lucent—a French company now owned by Chinese promoters, TvT, Tiandy Technologies and Uniview. All these companies have a significant presence in India and have been dealing with government agencies for a long time now.

On 6 August 2020, a Registration Committee under Department of Expenditure Order was constituted under the chairpersonship of Manmeet Kaur Nanda, a 2000 cadre IAS officer, who was then Joint Secretary, Department for Promotion of Industry and Internal Trade, to consider applications received for registration of bidders from countries that share land border with India for participation in public procurement.

It is this committee that keeps an eye on the products from the identified countries and evaluates the risk, if any, that is poised by them. In November 2023, Nanda moved as Joint Secretary to the Cabinet Secretariat. Sources in Government of India said that this is not an exhaustive list and more companies will be added on the list as per inputs that the concerned officials will receive.