Important Indian Laws, Policies and Amendments on Cybersecurity and Data Protection
India manages its digital security and personal privacy through a combination of foundational legislative statutes, regulatory mandates, and specialized operational agencies designed to secure cyberspace and protect citizen data.
Information Technology Act, 2000
The Information Technology Act, 2000 serves as the primary legal framework for electronic governance, cybercrime prevention, and electronic commerce in the country.
Key Provisions and Sections
- Section 43 penalizes unauthorized access, data extraction, and introduction of malicious computer contaminants into any computer network.
- Section 66 prescribes punishments for computer-related offenses such as hacking, identity theft, and cheating by personation using computer resources.
- Section 66E penalizes the capture, publication, or transmission of images of private areas of individuals without consent.
- Section 67 addresses the transmission of obscene material in electronic form.
Institutional Mandates
- Section 70 empowers the central government to declare any computer resource critical to national security or public infrastructure as Critical Information Infrastructure.
- Section 70A provides for the establishment of the National Critical Information Infrastructure Protection Centre to safeguard vital networks.
- Section 70B designates the Indian Computer Emergency Response Team as the national nodal agency for incident response, threat analysis, and issuing cyber security advisories.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 establishes a comprehensive legal regime specifically governing the processing and protection of digital personal data.
Core Concepts and Terms
- Data Principal refers to the individual to whom the personal data relates.
- Data Fiduciary denotes any person or entity that determines the purpose and means of processing personal data.
- Data Processor means any entity that processes personal data on behalf of a data fiduciary.
Rights and Obligations
- Data principals possess the right to access information about processing, seek correction or erasure of data, and utilize grievance redressal mechanisms.
- Data fiduciaries must implement technical security safeguards to prevent personal data breaches and notify the regulatory board upon occurrence.
- The Act establishes the Data Protection Board of India to adjudicate non-compliance and enforce statutory provisions.
National Cybersecurity Policies and Directives
Strategic administrative guidelines and CERT-In directions dictate operational security protocols for enterprises and government entities operating within Indian jurisdiction.
| Policy Instrument | Focus Area | Mandatory Requirement |
| CERT-In Directions (2022) | Incident Reporting | Mandatory reporting of cyber incidents within six hours of notice. |
| National Cyber Security Policy | Infrastructure Security | Protection of national cyberspace assets and capacity building. |
| Intermediary Guidelines | Due Diligence | Strict compliance obligations for social media platforms and online intermediaries. |
Key Facts on Cyber Laws and Protection
- The Information Technology Act, 2000 was enacted to give legal recognition to electronic transactions and facilitate e-commerce.
- The Supreme Court of India in the historic Puttaswamy judgment (2017) declared the right to privacy as a fundamental right under Article 21 of the Constitution.
- The Indian Computer Emergency Response Team functions under the administrative control of the Ministry of Electronics and Information Technology.
- Cyber Swachhta Kendra operates as a botnet cleaning and malware analysis center for individual and organizational users.
- The National Critical Information Infrastructure Protection Centre protects critical sectors including power, telecom, banking, and transport.
Originally written on
December 19, 2015
and last modified on
August 14, 2026.