Indian Cybersecurity and Data Protection Laws
India’s cyber safety and data privacy framework rests on a combination of statutory law, regulatory directions and specialised response agencies. Together, these provisions address cybercrime, critical infrastructure protection, electronic transactions and the protection of personal data.
Information Technology Act, 2000
The Information Technology Act, 2000 is the principal law for electronic governance, cybercrime prevention and electronic commerce in India. It gives legal recognition to electronic records and digital transactions while also creating offences related to misuse of computer systems and online content.
- Section 43: Penalises unauthorised access, data extraction and introduction of malicious computer contaminants into any computer network.
- Section 66: Prescribes punishment for computer-related offences such as hacking, identity theft and cheating by personation using computer resources.
- Section 66E: Punishes capture, publication or transmission of images of private areas of individuals without consent.
- Section 67: Deals with transmission of obscene material in electronic form.
Critical Infrastructure and Cyber Response Bodies
The Act also contains institutional provisions aimed at securing essential digital systems and responding to cyber incidents. These provisions are important for protecting national security and public infrastructure.
- Section 70: Empowers the Central Government to declare any computer resource critical to national security or public infrastructure as Critical Information Infrastructure.
- Section 70A: Provides for the establishment of the National Critical Information Infrastructure Protection Centre to safeguard vital networks.
- Section 70B: Designates Indian Computer Emergency Response Team (CERT-In) as the national nodal agency for incident response, threat analysis and cyber security advisories.
Exam focus: CERT-In works under the administrative control of the Ministry of Electronics and Information Technology.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 creates a dedicated legal regime for the processing and protection of digital personal data. It sets out key definitions, obligations for data-handling entities and rights for individuals whose data is processed.
- Data Principal: The individual to whom the personal data relates.
- Data Fiduciary: Any person or entity that determines the purpose and means of processing personal data.
- Data Processor: Any entity that processes personal data on behalf of a data fiduciary.
- Rights of data principals: Access information about processing, seek correction or erasure of data, and use grievance redressal mechanisms.
- Obligations of data fiduciaries: Implement technical security safeguards to prevent personal data breaches and notify the regulatory board upon occurrence.
- Enforcement body: The Act establishes the Data Protection Board of India to adjudicate non-compliance and enforce statutory provisions.
Policies, Directions and Operational Requirements
Along with primary legislation, India uses policy instruments and operational directives to strengthen cybersecurity compliance across government systems, enterprises and intermediaries.
- CERT-In Directions (2022): Require mandatory reporting of cyber incidents within six hours of notice.
- National Cyber Security Policy: Focuses on infrastructure security, protection of national cyberspace assets and capacity building.
- Intermediary Guidelines and Due Diligence: Place compliance obligations on social media platforms and online intermediaries.
Important Supporting Institutions and Facts
- Puttaswamy judgment (2017): The Supreme Court declared the right to privacy a fundamental right under Article 21 of the Constitution.
- Cyber Swachhta Kendra: Functions as a botnet cleaning and malware analysis centre for individual and organisational users.
- NCIIPC: Protects critical sectors including power, telecom, banking and transport.
- IT Act, 2000: Enacted to give legal recognition to electronic transactions and facilitate e-commerce.
- Cybersecurity governance: India’s framework combines legislation, regulatory directions and specialised agencies rather than relying on a single law alone.
Key Prelims Takeaways
- IT Act, 2000 is the main law for cybercrime, e-governance and e-commerce.
- Section 43 covers unauthorised access, data extraction and malicious contamination.
- Section 66 deals with hacking, identity theft and cheating by personation through computer resources.
- Section 66E protects privacy against unauthorised capture or transmission of private images.
- Section 70A establishes NCIIPC for critical information infrastructure protection.
- Section 70B designates CERT-In as the national nodal agency for cyber incident response.
- DPDP Act, 2023 introduces the legal framework for digital personal data, with the Data Protection Board of India as the enforcement body.