Indian Laws and Policies on Cybersecurity, Intermediary Liability and Internet Regulation

India governs its digital realm through a combination of statutory legislation, executive guidelines, and specialized regulatory agencies. The legal architecture addresses computer-related crimes, protects national critical infrastructure, regulates digital intermediaries, and safeguards personal data. Administered primarily by the Ministry of Electronics and Information Technology alongside the Ministry of Home Affairs, this framework balances national security interests, user safety, and digital economic growth.

Primary Statutory Architecture

Information Technology Act, 2000 (IT Act)
  • Foundational Statute: Enacted in May 2000 and amended in 2008, the IT Act provides legal recognition for electronic commerce, digital signatures, and electronic records.
  • Extraterritorial Jurisdiction: Applies to any offense or contravention committed outside India by any person, provided the computer system or network involved is located within Indian territory.
  • Cyber Offenses and Penalties: Section 66 covers computer-related crimes like hacking, identity theft (Section 66C), and cheating by personation (Section 66D). Section 66F specifically criminalizes cyber terrorism with punishment up to life imprisonment.
  • Content Restriction and Blocking: Section 69 empowers central and state authorities to intercept, monitor, or decrypt digital information. Section 69A authorizes the Central Government to issue blocking orders to restrict public access to online content in the interest of national sovereignty, defense, security, friendly foreign relations, or public order.
  • Critical Infrastructure Protection: Section 70 allows the government to declare any computer resource affecting national security or public finance as a “Protected System.”

Intermediary Liability and the Safe Harbour Regime

Section 79 of the IT Act
  • Grant conditional immunity (“safe harbour”) to digital intermediaries from third-party data or communication hosted on their platforms.
  • Mandates that intermediaries must not initiate the transmission, select the receiver, or modify the contained information to claim exemption from liability.
  • Operates under the principle of “due diligence,” requiring platforms to promptly remove unlawful content upon receiving actual knowledge via court orders or government notifications.
Information Technology Rules, 2021
  • Promulgated in February 2021 to replace the 2011 guidelines, establishing a three-tier grievance redressal structure for social media platforms, digital news publishers, and OTT content providers.
  • Categorizes social media entities into basic intermediaries and higher-tier social media platforms based on a threshold of 50 lakh registered users.
  • Mandates higher-tier platforms to appoint three resident officers: a Chief Compliance Officer, a Nodal Contact Person for round-the-clock coordination, and a Resident Grievance Officer.
  • Requires messaging platforms offering primary services to enable the identification of the first originator of information when directed by a court or competent authority.
  • Established Grievance Appellate Committees (GAC) to allow users to appeal against decisions taken by social media grievance officers.

Institutional Framework and Cyber Enforcement Agencies

Computer Emergency Response Team (CERT-In)
  • Functioning under Section 70B of the IT Act since 2004 as the national nodal agency for collecting, analyzing, and disseminating cyber threat intelligence.
  • Mandates all service providers, data centers, intermediaries, and corporate entities to report mandatory cyber security incidents within six hours of detection.
  • Issues technical advisories, coordinates emergency response actions, and conducts vulnerability assessments across public and private systems.
National Critical Information Infrastructure Protection Centre (NCIIPC)
  • Created under Section 70A of the IT Act in January 2014 as a unit of the National Technical Research Organisation (NTRO).
  • Designates and monitors Critical Information Infrastructure (CII) across critical sectors: Banking, Financial Services and Insurance (BFSI), Power and Energy, Telecom, Transport, Information and Communication Technology, and Strategic Enterprises.
  • Formulates guidelines to shield national protected systems from cyber attacks and espionage.
Indian Cyber Crime Coordination Centre (I4C)
  • Established under the Ministry of Home Affairs to provide a framework for law enforcement agencies to tackle cybercrimes in a coordinated manner.
  • Manages the National Cyber Crime Reporting Portal to enable citizens to report online financial frauds and cyber crimes.
  • Operates the Citizen Financial Cyber Fraud Reporting and Management System to freeze stolen funds immediately through real-time coordination with commercial banks.

Data Protection and Digital Privacy Architecture

Digital Personal Data Protection Act, 2023 (DPDP Act)
  • Establishes a framework governing the processing of digital personal data while recognizing individual rights to data privacy and lawful operational needs.
  • Defines core roles including “Data Principal” (the individual whose data is processed) and “Data Fiduciary” (the entity determining the purpose and means of data processing).
  • Mandates that processing of personal data requires free, informed, specific, unconditional, and unambiguous consent accompanied by a clear affirmative action.
  • Creates the Data Protection Board of India (DPBI) as an independent administrative body to adjudicate complaints, order investigations, and impose financial penalties up to ₹250 crore for major data breaches.
  • Places specialized obligations on data processing involving children, prohibiting behavioral tracking or targeted advertising directed at minors.
Sectoral Internet Regulation and Telecom Rules
  • Telecommunications Act, 2023: Replaced the Indian Telegraph Act, 1885, and the Indian Wireless Telegraphy Act, 1933, updating spectrum allocation rules, authorization frameworks, and emergency interception measures.
  • OTT Regulation: Digital media and over-the-top streaming platforms fall under Part III of the IT Rules, 2021, requiring self-classification of content into age-based ratings (U, U/A 7+, U/A 13+, U/A 16+, and A).

Summary of Key Statutes, Provisions, and Regulatory Bodies

Legislative Statute / Policy Key Section / Provision Nodal Authority Primary Governance Scope
IT Act, 2000 Section 66F Ministry of Electronics & IT (MeitY) Defines and penalizes cyber terrorism
IT Act, 2000 Section 69A Central Government / MeitY Powers to block public access to digital content
IT Act, 2000 Section 70B CERT-In Mandatory reporting of cyber incidents within 6 hours
IT Act, 2000 Section 79 Intermediaries / Platforms Safe harbour immunity subject to due diligence compliance
IT Rules, 2021 Rule 3 & 4 MeitY & Ministry of I&B Due diligence for social media and grievance redressal
DPDP Act, 2023 Section 18 Data Protection Board of India Adjudication of personal data breaches and compliance
Telecommunications Act, 2023 Section 3–5 Department of Telecommunications Telecommunications authorization, spectrum, and security

Key Facts and Data Highlights

  • The Supreme Court of India struck down Section 66A of the IT Act in the landmark Shreya Singhal v. Union of India case (2015), ruling that it violated freedom of speech under Article 19(1)(a).
  • In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge Supreme Court bench declared the right to privacy a fundamental right under Article 21.
  • CERT-In operates as the national agency for cyber incident response under the Information Technology (Indian Computer Emergency Response Team) Rules, 2013.
  • The IT Rules, 2021 require higher-tier social media platforms to publish monthly compliance reports detailing user complaints received and action taken.
  • The Data Protection Board of India functions as a digital office, handling proceedings and complaints through online mechanisms.
  • The Telecommunications Act, 2023 allows the government to take temporary possession of telecom networks during public emergencies or in the interest of public safety.
  • NCIIPC classifies any computer system whose destruction could severely impact national security, economy, or public health as Critical Information Infrastructure.
Originally written on November 4, 2015 and last modified on August 10, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *