Major Cybersecurity and Data Privacy Laws in India
India regulates its digital space through legislative acts and regulatory guidelines designed to prevent cybercrime, protect personal data, and secure critical infrastructure.
Information Technology Act, 2000
The Information Technology Act, 2000 serves as the principal legal framework for electronic commerce and cybercrime prevention in the country.
Key Provisions and Penalties
- Section 43 penalizes unauthorized access, downloading of data, and introduction of malware into any computer network.
- Section 66 prescribes imprisonment and fines for computer-related offenses such as hacking, identity theft, and data destruction.
- Section 66E punishes the capture and transmission of images of private areas of individuals without consent.
- Section 72A penalizes service providers and intermediaries for disclosing personal information without user consent.
Institutional Framework
- Section 70 empowers the government to declare vital computer resources as Critical Information Infrastructure.
- Section 70A establishes the National Critical Information Infrastructure Protection Centre to secure strategic networks.
- Section 70B designates the Indian Computer Emergency Response Team as the national nodal agency for cyber incident response and threat analysis.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 governs the processing and protection of digital personal data within the country.
Core Definitions and Concepts
- Data Principal refers to the individual citizen to whom the personal data relates.
- Data Fiduciary denotes any entity that determines the purpose and means of processing personal data.
- Processing includes any automated operation performed on digital personal data such as collection, storage, use, and sharing.
Rights and Obligations
- Data principals possess the right to access information about data processing, seek correction or erasure, and register grievances.
- Data fiduciaries must implement technical security safeguards to prevent data breaches and notify authorities upon occurrence.
- The Data Protection Board of India adjudicates non-compliance and enforces statutory provisions under the framework.
Cybersecurity Directives and Policy Instruments
| Regulatory Instrument | Focus Area | Mandate |
| CERT-In Directions (2022) | Incident Reporting | Mandatory reporting of cyber incidents within six hours of notice. |
| National Cyber Security Policy | Infrastructure Security | Protection of national cyberspace assets and capacity building. |
| Intermediary Guidelines | Digital Platforms | Due diligence obligations for social media platforms and digital intermediaries. |
Key Facts on Cybersecurity and Data Privacy
- The Information Technology Act was enacted in the year 2000 to provide legal recognition for electronic transactions.
- The Supreme Court in the historic Puttaswamy judgment of 2017 declared the right to privacy as a fundamental right under Article 21.
- The Indian Computer Emergency Response Team functions under the administrative control of the Ministry of Electronics and Information Technology.
- Cyber Swachhta Kendra operates as a botnet cleaning and malware analysis center for individual and organizational users.
- The Digital Personal Data Protection Act relies on financial penalties of up to two hundred fifty crore rupees for failure to prevent data breaches.
Originally written on
December 19, 2015
and last modified on
August 14, 2026.