Mon–Sat 9AM–8PM 24/7 Emergency

Cyber Laws in India

Complete guide to the legal framework and statutes governing cyber crime, digital evidence, and online rights in India

India has developed a robust legal framework to combat cyber crime and protect digital rights. Understanding these laws is crucial for anyone facing a cyber crime issue — whether it's a frozen bank account, data breach, sextortion, or online fraud. This page breaks down the key statutes that govern cyber law in India, their provisions, and how they apply to real cases.

Information Technology Act, 2000 (IT Act)

Primary Cyber Law

The IT Act 2000 is the foundational legislation governing cyber law in India. Originally enacted to provide legal recognition for electronic transactions and digital signatures, it has been substantially amended — most significantly by the IT (Amendment) Act, 2008 — to address the growing menace of cyber crime. Today, the IT Act is the primary tool for prosecuting cyber criminals and regulating online conduct in India.

Key Sections & Their Relevance

Section 43 — Penalty for Unauthorised Access

Deals with unauthorised access to computer systems, data theft, introduction of viruses, damage to systems, and denial of service. Relevance: Applicable in hacking cases, data breaches, and system intrusions. Provides for compensation claims up to ?5 crore.

Section 66 — Computer Related Offences

If a person dishonestly or fraudulently does any act under Section 43, they are punishable under Section 66. Relevance: Covers hacking, data theft with dishonest intent, and unauthorized access for fraudulent purposes. Punishable with up to 3 years imprisonment and/or fine up to ?5 lakh.

Section 66B — Receiving Stolen Computer Resources

Punishes anyone who dishonestly receives or retains any stolen computer resource or communication device. Relevance: Used in mobile theft cases and recovery of stolen digital devices. Punishable with up to 3 years imprisonment and/or fine up to ?1 lakh.

Section 66C — Identity Theft

Punishes fraudulent use of another person's electronic signature, password, or other unique identification feature. Relevance: Critical for identity theft, SIM swap fraud, social media account takeover, and phishing cases. Punishable with up to 3 years imprisonment and/or fine up to ?1 lakh.

Section 66D — Cheating by Personation Using Computer

Punishes cheating by personation through any communication device or computer resource. Relevance: The go-to section for online dating scams, social media impersonation, catfishing, and investment fraud conducted via digital platforms. Punishable with up to 3 years imprisonment and/or fine up to ?1 lakh.

Section 66E — Violation of Privacy

Punishes anyone who intentionally captures, publishes, or transmits images of a person's private areas without consent. Relevance: Used in revenge porn, MMS scandals, voyeurism, and sextortion cases involving intimate images. Punishable with up to 3 years imprisonment and/or fine up to ?2 lakh.

Section 67 — Publishing Obscene Material Electronically

Punishes electronic publication or transmission of obscene material. Relevance: Applies to pornography, obscene content on social media, and sexually explicit material. Punishable with up to 3 years imprisonment and fine up to ?5 lakh.

Section 67A — Sexually Explicit Material

Specifically targets electronic publication of sexually explicit material. Relevance: Heavier penalties for sexually explicit content (as opposed to merely obscene). Punishable with up to 5 years imprisonment and fine up to ?10 lakh.

Section 67B — Child Pornography

Punishes electronic publication, browsing, or downloading of child pornography. Relevance: Strictest provisions for child sexual abuse material. Punishable with up to 5 years imprisonment and fine up to ?10 lakh on first conviction; up to 7 years on second conviction.

Section 69 — Decryption of Information

Empowers the government to intercept, monitor, or decrypt any information through computer resources for national security. Relevance: Provides legal basis for lawful interception and surveillance by authorized agencies.

Section 72 — Breach of Confidentiality & Privacy

Punishes disclosure of information without consent by a person who obtained it under a contractual or legal obligation. Relevance: Used against employees, service providers, and intermediaries who leak personal data. Punishable with up to 2 years imprisonment and/or fine up to ?1 lakh.

Section 79 — Intermediary Liability (Safe Harbor)

Provides safe harbour protection to intermediaries (social media platforms, ISPs, etc.) from liability for third-party content, provided they comply with due diligence requirements under the IT Rules. Relevance: Critical for understanding platform accountability and the legal process for content takedown under the IT (Intermediary Guidelines) Rules, 2021.

Section 80 — Power of Police to Enter & Search

Empowers police officers (not below Inspector rank) to enter any public place and search, arrest without warrant for cyber crime offences. Relevance: Enables swift police action in cyber crime cases without requiring a warrant.

Practical Tip: Most cyber crime FIRs are filed under multiple sections of the IT Act 2000 combined with relevant provisions of the BNS 2023. For example, a sextortion case would typically involve Sections 66C, 66D, 66E, and 67A of the IT Act along with relevant BNS sections for criminal intimidation and extortion.

Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS)

Criminal Procedure Code Replacement

The Bharatiya Nagarik Suraksha Sanhita (BNSS) 2023 replaced the Code of Criminal Procedure (CrPC), 1973, effective July 1, 2024. It modernizes criminal procedure and contains provisions critical for cyber crime cases — most notably Section 102 which deals with freezing of property and bank accounts.

Section 102 BNSS — Power to Freeze Property & Bank Accounts

This is arguably the most relevant section for bank account freezing cases in India. Section 102 BNSS empowers any police officer conducting an investigation to seize any property or bank account that is alleged or suspected to be the proceeds of crime, or which may be evidence in the criminal case.

Key provisions of Section 102 BNSS:

  • The officer must immediately report the seizure to the Magistrate having jurisdiction
  • The seizure must be based on reasonable suspicion that the property is connected to the offence
  • Accounts frozen under Section 102 BNSS must be reviewed periodically — they cannot remain frozen indefinitely
  • The account holder has the right to apply for defreezing before the Magistrate or Sessions Court
  • Courts have held that blanket freezing of all accounts without nexus to the alleged crime is impermissible

Common Grounds for Account Freezing Under Section 102 BNSS

  • Suspected money laundering through bank accounts
  • Cyberspace fraud involving UPI, NEFT, or RTGS transactions
  • Accounts receiving stolen funds from phishing or vishing scams
  • Business accounts caught in fraudulent transaction chains
  • Accounts used for crypto-to-fiat conversions in suspected fraud cases

How CyberWakil Handles Section 102 BNSS Cases

Our bank account unfreezing process involves: (1) Reviewing the freezing order for legal validity; (2) Preparing a detailed representation demonstrating the legitimate source of funds; (3) Filing an application for defreezing before the Magistrate or Sessions Court; (4) Negotiating with the investigating agency for speedy release; (5) Obtaining court orders for defreezing and ensuring bank compliance. We have successfully unfrozen hundreds of accounts across India under Section 102 BNSS.

Other Relevant BNSS Provisions

Section 173 — Report of Investigation (Charge Sheet)

Mandates completion of investigation within 60–90 days. In cyber crime cases with voluminous digital evidence, courts have granted extensions but subject to strict timelines.

Section 452 — Destruction of Records

Provides for disposal of property at conclusion of trial — relevant for returning frozen accounts and digital assets after case disposal.

Bharatiya Nyaya Sanhita, 2023 (BNS)

IPC Replacement

The Bharatiya Nyaya Sanhita (BNS) 2023 replaced the Indian Penal Code (IPC), 1860, effective July 1, 2024. While the IPC was the primary criminal code for over 160 years, the BNS modernizes criminal law and contains expanded provisions relevant to cyber crime. Many cyber crime FIRs now cite BNS sections alongside IT Act provisions for a comprehensive legal approach.

Key BNS Sections Relevant to Cyber Crime

Section 318 — Cheating (Replacing IPC 420)

Punishes cheating, including digital cheating conducted through online platforms, email, SMS, or social media. Relevance: The most commonly invoked BNS section for cyber fraud, online scam, investment fraud, and payment gateway fraud cases. Punishable with up to 7 years imprisonment.

Section 319 — Cheating by Personation (Replacing IPC 419)

Punishes cheating by personation, specifically including personation through digital means. Relevance: Used for fake social media profiles, impersonation scams, job fraud through fake recruitment portals, and KYC fraud cases.

Section 127 — Criminal Intimidation (Replacing IPC 506)

Punishes criminal intimidation, including threats communicated through electronic means. Relevance: Applied in sextortion cases where threats are delivered via WhatsApp, email, or social media; online harassment and stalking with threats of harm.

Section 128 — Extortion (Replacing IPC 383–389)

Punishes extortion, including digital extortion and ransom demands made electronically. Relevance: Used in ransomware cases, sextortion demands, and cases where perpetrators demand money under threat of releasing compromising information.

Section 352 — Defamation (Replacing IPC 500)

Punishes defamation, including defamation through digital publications and social media posts. Relevance: Critical for online defamation cases, fake news, character assassination through social media, and reputational harm caused by digital content.

Section 111 — Organized Crime

A new provision specifically targeting organized crime syndicates, including cyber crime networks operating in a structured manner. Relevance: Used against organized cyber crime rings, coordinated phishing operations, and multi-level fraud networks.

Note: The BNS 2023 introduces enhanced penalties for digital offences and explicitly recognizes cyber crime as a distinct category of criminal conduct, reflecting the modern reality that most crimes today have a digital component.

Digital Personal Data Protection Act, 2023 (DPDP Act)

Data Privacy Law

The Digital Personal Data Protection Act (DPDP Act) 2023 is India's first comprehensive data privacy legislation, replacing the outdated Section 43A of the IT Act. It establishes a robust framework for the protection of personal data and imposes significant obligations on entities that collect, process, or store personal data of Indian citizens.

Scope & Applicability

  • Applies to all entities processing personal data of individuals in India (Data Principals)
  • Applies extraterritorially to entities outside India processing data of Indian citizens
  • Covers personal data (not anonymized or aggregated data)
  • Establishes the Data Protection Board of India (DPBI) as the enforcement authority

Key Provisions

Consent Framework

Data Fiduciaries must obtain explicit, informed consent before processing personal data. Consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. Relevance: Websites, apps, and platforms must redesign their consent mechanisms. Violations can result in penalties up to ?250 crore.

Data Principal Rights

Individuals have the right to: access their data, correction and erasure, grievance redressal, nomination, and withdrawal of consent. Relevance: If your personal data has been misused or leaked, the DPDP Act provides a direct legal remedy against the data fiduciary responsible.

Data Breach Notification

Data Fiduciaries must immediately notify the DPBI and affected Data Principals in case of a personal data breach. Relevance: Companies experiencing data breaches (hacks, leaks, ransomware) must disclose them promptly — failure to do so invites significant penalties.

Penalties & Enforcement

Penalties for non-compliance can reach up to ?250 crore (approximately $30 million). The DPBI has powers to investigate, adjudicate, and impose penalties. Relevance: This creates strong incentives for companies to implement robust data protection measures.

Relevance to Cyber Crime Cases

The DPDP Act 2023 is relevant in: Data breach litigation — holding companies accountable for leaking customer data; Privacy violation cases — where personal data is accessed or shared without consent; Right to be forgotten — seeking removal of personal data from platforms; Corporate compliance — advising businesses on DPDP Act compliance to avoid regulatory action. CyberWakil provides comprehensive DPDP Act advisory and representation for both individuals and businesses.

Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023

Digital Evidence Law

Evidence law is critical in cyber crime cases because most evidence is electronic and digital. The Bharatiya Sakshya Adhiniyam (BSA) 2023 replaced the Indian Evidence Act, 1872, effective July 1, 2024, with significantly expanded provisions for digital evidence. Understanding how electronic evidence is treated in Indian courts is essential for building a winning cyber crime case.

Key Provisions for Digital Evidence

Section 63 BSA — Admissibility of Electronic Records

Electronic records are now treated as primary evidence (not secondary) if they are created and maintained in the ordinary course of business. Previously, under the old Evidence Act, electronic evidence was treated as secondary evidence requiring certification under Section 65B. The BSA 2023 simplifies and strengthens the admissibility framework for digital evidence.

Electronic Records as Documentary Evidence

All electronic records — including emails, WhatsApp messages, SMS, social media posts, call records, bank statements, CCTV footage, and server logs — are admissible as documentary evidence provided they meet the authenticity requirements. Practical tip: Screenshots alone may not be sufficient — certified copies, metadata, and preservation of original digital records strengthen admissibility.

Preservation of Digital Evidence

Courts can issue orders for preservation of electronic evidence to prevent spoliation. This is critical in cyber crime cases where evidence can be deleted remotely. Our lawyers routinely file applications for interim preservation orders under BSA 2023.

Forensic Evidence & Expert Testimony

Digital forensic analysis — including metadata analysis, device forensics, network forensics, and data recovery — is admissible through expert testimony under the BSA. CyberWakil works with certified digital forensic experts to ensure evidence meets judicial standards.

Role of Digital Forensics in Cyber Crime Cases

Digital forensics plays a pivotal role in establishing the evidentiary chain: Email forensics can trace the origin of phishing emails; Mobile forensics can recover deleted WhatsApp messages; Blockchain forensics can track crypto transactions; Bank statement analysis can map fraudulent transaction trails. All of this evidence must be collected and preserved in a forensically sound manner to be admissible in court — which is exactly what our legal process ensures.

Cyber Crime Prevention in India

Regulatory Framework

Beyond the primary statutes, India has established a comprehensive institutional framework for cyber crime prevention, investigation, and prosecution. Understanding this framework helps victims navigate the system effectively.

Key Institutions & Mechanisms

National Cyber Crime Reporting Portal (cybercrime.gov.in)

The Ministry of Home Affairs operates a centralized portal where citizens can report cyber crimes online. This platform — administered by the Indian Cyber Crime Coordination Centre (I4C) — accepts complaints for cyber fraud, online harassment, sextortion, and other cyber offences. Complaints filed here are automatically routed to the relevant state cyber cell.

1930 Helpline

The national cyber crime helpline number 1930 is a toll-free number for immediate reporting of cyber financial fraud. Once a call is made, the complaint is registered and flagged to the concerned bank's nodal officer for transaction reversal or account freezing. This is often the first and most critical step in cyber fraud recovery.

State Cyber Cells

Every state in India has a dedicated Cyber Crime Police Station or Cyber Cell with specialized investigators trained in digital forensics, cyber law, and evidence handling. Major cities like Delhi, Mumbai, Bangalore, Hyderabad, and Pune have advanced cyber labs with forensic capabilities.

IT (Intermediary Guidelines) Rules, 2021

These rules under the IT Act 2000 impose due diligence obligations on social media platforms, messaging apps, and other intermediaries. Key requirements include: appointment of a Grievance Officer; timely removal of unlawful content (within 24 hours for content involving sexual violence); traceability of messages; and monthly compliance reports. Relevance: Victims can file grievances directly with platforms for content takedown under these rules.

RBI Guidelines on Digital Transactions

The Reserve Bank of India has issued comprehensive guidelines on: UPI transaction limits, mandate of banks to implement fraud risk management, zero liability for customers in case of third-party fraud if reported within 3 days, and mandatory reporting of cyber fraud to RBI by banks. Relevance: In cyber fraud cases, these guidelines can be leveraged to claim reversal of fraudulent transactions from banks.

Prevention Best Practices

Strong Passwords

Use unique, complex passwords with 2FA for all accounts

Verify Before Trusting

Never share OTP, PIN, or passwords with unknown callers

Report Immediately

Call 1930 or file complaint within 3 days for zero liability

Preserve Evidence

Save all screenshots, emails, and transaction records immediately

Indian Cyber Laws Quick Reference

Law / Statute Year Key Provisions for Cyber Crime When It Applies
IT Act 2000 2000 Sections 43, 66–72 — hacking, identity theft, data theft, privacy violation, obscenity All cyber crimes involving computer systems, digital data, and online platforms
BNSS 2023 2023 Section 102 — freezing of bank accounts and property suspected as proceeds of crime Bank account freezes, property attachment, criminal investigation procedure
BNS 2023 2023 Sections 318, 319, 127, 128, 352 — cheating, extortion, criminal intimidation, defamation Cyber fraud, sextortion, online harassment, defamation, impersonation
DPDP Act 2023 2023 Consent framework, data breach notification, Data Principal rights, penalties up to ?250 crore Data breaches, privacy violations, corporate data compliance
BSA 2023 2023 Section 63 — admissibility of electronic records as primary evidence Digital evidence, forensic reports, electronic records in court proceedings
IT Rules 2021 2021 Intermediary due diligence, grievance redressal, content takedown timelines Content removal from platforms, social media complaints

Need Help Understanding Your Legal Rights?

Our senior cyber law attorneys can explain how these laws apply to your specific case. Get a free consultation today.

Call +91-9007000603 Free Consultation

100% confidential | PAN-India service | Emergency: 24/7