Cybersecurity Laws and Regulations in India
India maintains a multi-layered legal, statutory, and institutional framework to govern digital transactions, protect personal data, prevent cybercrime, and secure critical information infrastructure.
Information Technology Act of 2000
The Information Technology Act of 2000 serves as the primary cyber law in India, providing legal recognition for electronic documents, digital signatures, and e-commerce transactions.
Scope and Key Provisions
- Grants legal validity to electronic records and digital contracts.
- Defines cyber offenses, hacking, data theft, and prescribes penalties for tampering with computer source codes.
- Contains Section 66E for punishing the violation of privacy, Section 66F for cyber terrorism, and Section 67 for publishing obscene material online.
- Outlines the legal liability of intermediaries and network service providers.
Intermediary Guidelines and Digital Ethics
- The Information Technology Rules establish due diligence obligations for social media intermediaries and digital platforms.
- Mandates the removal of unlawful, obscene, or privacy-invading content within stipulated timelines upon receiving a formal grievance or government order.
- Requires large social media platforms to appoint resident grievance officers, chief compliance officers, and nodal contact persons in India.
- Incorporates provisions to restrict the generation, creation, and dissemination of synthetic media and AI-driven deepfakes.
Digital Personal Data Protection Act
The Digital Personal Data Protection Act of 2023 provides a comprehensive legal framework for safeguarding individual privacy and regulating the processing of digital personal data.
Core Principles and Obligations
- Mandates that data fiduciaries collect personal data only for lawful purposes after obtaining explicit, free, unconditional, and informed consent.
- Establishes enforceable rights for individuals, known as data principals, to access personal data summaries, request corrections, and seek data erasure.
- Imposes statutory obligations on entities handling children’s data and defines special protections for vulnerable groups.
- Empowers the Data Protection Board of India to investigate breaches and levy financial penalties for non-compliance.
National Cybersecurity Agencies and Incident Response
India operates dedicated administrative bodies and technical emergency teams to defend national cyberspace and critical infrastructure against malicious attacks.
CERT-In and Sectoral Response Teams
- The Indian Computer Emergency Response Team functions as the national nodal agency for threat monitoring, vulnerability analysis, and cyber incident management.
- Mandates that organizations, companies, and service providers report cyber security incidents and data breaches within a stipulated timeline of six hours.
- Sectoral emergency response teams operate within critical infrastructure domains, including finance, power, and telecommunications, to coordinate targeted defense mechanisms.
National Critical Information Infrastructure Protection Centre
- Operates as the nodal agency for protecting critical information infrastructure across vital sectors such as energy, transport, defense, and telecommunications.
- Formulates security audits, vulnerability assessments, and baseline protection standards for designated vital networks.
Comparative Overview of Cybersecurity Frameworks
| Regulatory Instrument | Governing Authority | Primary Focus Area |
| IT Act, 2000 | Ministry of Electronics and Information Technology | Cybercrime penalization, electronic contracts, and intermediary liability |
| DPDP Act, 2023 | Data Protection Board of India | Personal data privacy, fiduciary obligations, and consent management |
| CERT-In Directives | Ministry of Electronics and Information Technology | Mandatory cyber incident reporting and malware tracking |
| Sectoral Regulations | RBI, SEBI, IRDAI, and CEA | Domain-specific technology risk, resilience, and operational security |
- The National Cyber Crime Reporting Portal allows citizens to report online fraud anonymously, with specialized modules for cyberstalking and financial scams.
- Section 79 of the IT Act provides safe harbor protection to intermediaries, shielding them from third-party liability only if they observe prescribed due diligence rules.
- The Indian Penal Code and the Bharatiya Nagarik Suraksha Sanhita work in tandem with the IT Act to prosecute complex technology-enabled financial frauds and digital identity thefts.
Originally written on
December 15, 2015
and last modified on
August 14, 2026.