Major Cybersecurity and Data Privacy Laws in India

Major Cybersecurity and Data Privacy Laws in India

India’s cyber law framework combines criminal penalties, regulatory directions and data protection duties to address hacking, data misuse, privacy violations and threats to critical digital systems. The core statutes and institutional mechanisms are designed to support electronic transactions, secure networks and protect personal data.

Information Technology Act, 2000

The Information Technology Act, 2000 remains the principal legal framework for electronic commerce and cybercrime prevention in India. It gives statutory recognition to electronic records and lays down offences and penalties for misuse of computer systems and digital data.

  • Section 43: Penalises unauthorised access, downloading of data and introduction of malware into any computer network.
  • Section 66: Prescribes imprisonment and fines for computer-related offences such as hacking, identity theft and data destruction.
  • Section 66E: Punishes capturing and transmitting images of a private area of an individual without consent.
  • Section 72A: Penalises service providers and intermediaries for disclosing personal information without user consent.

Critical Infrastructure and Cyber Response

Several provisions of the IT Act deal with the protection of vital digital assets and incident response. These institutions are important for exam purposes because they define India’s official cyber defence architecture.

  • Section 70: Empowers the government to declare vital computer resources as Critical Information Infrastructure.
  • Section 70A: Establishes the National Critical Information Infrastructure Protection Centre to secure strategic networks.
  • Section 70B: Designates the Indian Computer Emergency Response Team (CERT-In) as the national nodal agency for cyber incident response and threat analysis.
  • CERT-In: Functions under the administrative control of the Ministry of Electronics and Information Technology.
  • Cyber Swachhta Kendra: Works as a botnet cleaning and malware analysis centre for individual and organisational users.

Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 governs the processing and protection of digital personal data in India. It introduces a structured compliance regime for entities handling personal information and strengthens accountability in case of breaches.

  • Data Principal: The individual citizen to whom the personal data relates.
  • Data Fiduciary: Any entity that determines the purpose and means of processing personal data.
  • Processing: Includes collection, storage, use and sharing of digital personal data through automated operations.
  • Rights of data principals: Access information about processing, seek correction or erasure, and register grievances.
  • Obligations of data fiduciaries: Put in place technical security safeguards to prevent data breaches and notify authorities when such breaches occur.
  • Data Protection Board of India: Adjudicates non-compliance and enforces provisions under the Act.
  • Penalty: The Act provides financial penalties of up to INR 250 crore for failure to prevent data breaches.

Cybersecurity Directives and Policy Instruments

Along with statutes, India uses directions and policy instruments to improve cyber hygiene, secure platforms and strengthen infrastructure protection. These rules are important because they shape compliance requirements for intermediaries and institutions.

Regulatory Instrument Focus Area Mandate
CERT-In Directions (2022) Incident reporting Mandatory reporting of cyber incidents within six hours of notice
National Cyber Security Policy Infrastructure security Protection of national cyberspace assets and capacity building
Intermediary Guidelines Digital platforms Due diligence obligations for social media platforms and digital intermediaries

Privacy and Constitutional Context

India’s privacy framework is also shaped by constitutional interpretation. The Supreme Court’s Puttaswamy judgment (2017) declared the right to privacy a fundamental right under Article 21. This decision provided the constitutional basis for stronger personal data protection and privacy-oriented regulation.

  • IT Act, 2000: Enacted to provide legal recognition for electronic transactions and to address cyber offences.
  • Privacy right: Recognised by the Supreme Court as part of the fundamental right to life and personal liberty.
  • CERT-In: Serves as the nodal agency for cyber incident response and threat analysis.

Key Prelims Takeaways

  • Information Technology Act, 2000: The principal law for electronic commerce and cybercrime prevention in India.
  • Section 43: Covers unauthorised access, data download and malware-related violations.
  • Section 66: Deals with hacking, identity theft and data destruction.
  • Section 66E: Protects privacy against capture and transmission of private images without consent.
  • Section 72A: Penalises unauthorised disclosure of personal information by intermediaries and service providers.
  • Section 70A and 70B: Create the NCIIPC and designate CERT-In respectively.
  • DPDP Act, 2023: Introduces the terms data principal and data fiduciary and sets out data protection duties.
  • Puttaswamy judgment, 2017: Declared privacy a fundamental right under Article 21.
  • CERT-In Directions (2022): Require cyber incident reporting within six hours of notice.
  • Cyber Swachhta Kendra: Functions as a botnet cleaning and malware analysis centre.
Current General Studies comprises current-affairs-based, General Studies-rich study material on policies, laws, institutions, economy, science, environment, governance, international relations, and other varied but important topics for UPSC and State PSC Prelims examinations. Fortnightly PDF compilations: Available here
Originally written on June 11, 2026 and last modified on September 6, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *