Complete guide to the legal framework and statutes governing cyber crime, digital evidence, and online rights in India
India has developed a robust legal framework to combat cyber crime and protect digital rights. Understanding these laws is crucial for anyone facing a cyber crime issue — whether it's a frozen bank account, data breach, sextortion, or online fraud. This page breaks down the key statutes that govern cyber law in India, their provisions, and how they apply to real cases.
The IT Act 2000 is the foundational legislation governing cyber law in India. Originally enacted to provide legal recognition for electronic transactions and digital signatures, it has been substantially amended — most significantly by the IT (Amendment) Act, 2008 — to address the growing menace of cyber crime. Today, the IT Act is the primary tool for prosecuting cyber criminals and regulating online conduct in India.
Deals with unauthorised access to computer systems, data theft, introduction of viruses, damage to systems, and denial of service. Relevance: Applicable in hacking cases, data breaches, and system intrusions. Provides for compensation claims up to ?5 crore.
If a person dishonestly or fraudulently does any act under Section 43, they are punishable under Section 66. Relevance: Covers hacking, data theft with dishonest intent, and unauthorized access for fraudulent purposes. Punishable with up to 3 years imprisonment and/or fine up to ?5 lakh.
Punishes anyone who dishonestly receives or retains any stolen computer resource or communication device. Relevance: Used in mobile theft cases and recovery of stolen digital devices. Punishable with up to 3 years imprisonment and/or fine up to ?1 lakh.
Punishes fraudulent use of another person's electronic signature, password, or other unique identification feature. Relevance: Critical for identity theft, SIM swap fraud, social media account takeover, and phishing cases. Punishable with up to 3 years imprisonment and/or fine up to ?1 lakh.
Punishes cheating by personation through any communication device or computer resource. Relevance: The go-to section for online dating scams, social media impersonation, catfishing, and investment fraud conducted via digital platforms. Punishable with up to 3 years imprisonment and/or fine up to ?1 lakh.
Punishes anyone who intentionally captures, publishes, or transmits images of a person's private areas without consent. Relevance: Used in revenge porn, MMS scandals, voyeurism, and sextortion cases involving intimate images. Punishable with up to 3 years imprisonment and/or fine up to ?2 lakh.
Punishes electronic publication or transmission of obscene material. Relevance: Applies to pornography, obscene content on social media, and sexually explicit material. Punishable with up to 3 years imprisonment and fine up to ?5 lakh.
Specifically targets electronic publication of sexually explicit material. Relevance: Heavier penalties for sexually explicit content (as opposed to merely obscene). Punishable with up to 5 years imprisonment and fine up to ?10 lakh.
Punishes electronic publication, browsing, or downloading of child pornography. Relevance: Strictest provisions for child sexual abuse material. Punishable with up to 5 years imprisonment and fine up to ?10 lakh on first conviction; up to 7 years on second conviction.
Empowers the government to intercept, monitor, or decrypt any information through computer resources for national security. Relevance: Provides legal basis for lawful interception and surveillance by authorized agencies.
Punishes disclosure of information without consent by a person who obtained it under a contractual or legal obligation. Relevance: Used against employees, service providers, and intermediaries who leak personal data. Punishable with up to 2 years imprisonment and/or fine up to ?1 lakh.
Provides safe harbour protection to intermediaries (social media platforms, ISPs, etc.) from liability for third-party content, provided they comply with due diligence requirements under the IT Rules. Relevance: Critical for understanding platform accountability and the legal process for content takedown under the IT (Intermediary Guidelines) Rules, 2021.
Empowers police officers (not below Inspector rank) to enter any public place and search, arrest without warrant for cyber crime offences. Relevance: Enables swift police action in cyber crime cases without requiring a warrant.
Practical Tip: Most cyber crime FIRs are filed under multiple sections of the IT Act 2000 combined with relevant provisions of the BNS 2023. For example, a sextortion case would typically involve Sections 66C, 66D, 66E, and 67A of the IT Act along with relevant BNS sections for criminal intimidation and extortion.
The Bharatiya Nagarik Suraksha Sanhita (BNSS) 2023 replaced the Code of Criminal Procedure (CrPC), 1973, effective July 1, 2024. It modernizes criminal procedure and contains provisions critical for cyber crime cases — most notably Section 102 which deals with freezing of property and bank accounts.
This is arguably the most relevant section for bank account freezing cases in India. Section 102 BNSS empowers any police officer conducting an investigation to seize any property or bank account that is alleged or suspected to be the proceeds of crime, or which may be evidence in the criminal case.
Key provisions of Section 102 BNSS:
Our bank account unfreezing process involves: (1) Reviewing the freezing order for legal validity; (2) Preparing a detailed representation demonstrating the legitimate source of funds; (3) Filing an application for defreezing before the Magistrate or Sessions Court; (4) Negotiating with the investigating agency for speedy release; (5) Obtaining court orders for defreezing and ensuring bank compliance. We have successfully unfrozen hundreds of accounts across India under Section 102 BNSS.
Mandates completion of investigation within 60–90 days. In cyber crime cases with voluminous digital evidence, courts have granted extensions but subject to strict timelines.
Provides for disposal of property at conclusion of trial — relevant for returning frozen accounts and digital assets after case disposal.
The Bharatiya Nyaya Sanhita (BNS) 2023 replaced the Indian Penal Code (IPC), 1860, effective July 1, 2024. While the IPC was the primary criminal code for over 160 years, the BNS modernizes criminal law and contains expanded provisions relevant to cyber crime. Many cyber crime FIRs now cite BNS sections alongside IT Act provisions for a comprehensive legal approach.
Punishes cheating, including digital cheating conducted through online platforms, email, SMS, or social media. Relevance: The most commonly invoked BNS section for cyber fraud, online scam, investment fraud, and payment gateway fraud cases. Punishable with up to 7 years imprisonment.
Punishes cheating by personation, specifically including personation through digital means. Relevance: Used for fake social media profiles, impersonation scams, job fraud through fake recruitment portals, and KYC fraud cases.
Punishes criminal intimidation, including threats communicated through electronic means. Relevance: Applied in sextortion cases where threats are delivered via WhatsApp, email, or social media; online harassment and stalking with threats of harm.
Punishes extortion, including digital extortion and ransom demands made electronically. Relevance: Used in ransomware cases, sextortion demands, and cases where perpetrators demand money under threat of releasing compromising information.
Punishes defamation, including defamation through digital publications and social media posts. Relevance: Critical for online defamation cases, fake news, character assassination through social media, and reputational harm caused by digital content.
A new provision specifically targeting organized crime syndicates, including cyber crime networks operating in a structured manner. Relevance: Used against organized cyber crime rings, coordinated phishing operations, and multi-level fraud networks.
Note: The BNS 2023 introduces enhanced penalties for digital offences and explicitly recognizes cyber crime as a distinct category of criminal conduct, reflecting the modern reality that most crimes today have a digital component.
The Digital Personal Data Protection Act (DPDP Act) 2023 is India's first comprehensive data privacy legislation, replacing the outdated Section 43A of the IT Act. It establishes a robust framework for the protection of personal data and imposes significant obligations on entities that collect, process, or store personal data of Indian citizens.
Data Fiduciaries must obtain explicit, informed consent before processing personal data. Consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. Relevance: Websites, apps, and platforms must redesign their consent mechanisms. Violations can result in penalties up to ?250 crore.
Individuals have the right to: access their data, correction and erasure, grievance redressal, nomination, and withdrawal of consent. Relevance: If your personal data has been misused or leaked, the DPDP Act provides a direct legal remedy against the data fiduciary responsible.
Data Fiduciaries must immediately notify the DPBI and affected Data Principals in case of a personal data breach. Relevance: Companies experiencing data breaches (hacks, leaks, ransomware) must disclose them promptly — failure to do so invites significant penalties.
Penalties for non-compliance can reach up to ?250 crore (approximately $30 million). The DPBI has powers to investigate, adjudicate, and impose penalties. Relevance: This creates strong incentives for companies to implement robust data protection measures.
The DPDP Act 2023 is relevant in: Data breach litigation — holding companies accountable for leaking customer data; Privacy violation cases — where personal data is accessed or shared without consent; Right to be forgotten — seeking removal of personal data from platforms; Corporate compliance — advising businesses on DPDP Act compliance to avoid regulatory action. CyberWakil provides comprehensive DPDP Act advisory and representation for both individuals and businesses.
Evidence law is critical in cyber crime cases because most evidence is electronic and digital. The Bharatiya Sakshya Adhiniyam (BSA) 2023 replaced the Indian Evidence Act, 1872, effective July 1, 2024, with significantly expanded provisions for digital evidence. Understanding how electronic evidence is treated in Indian courts is essential for building a winning cyber crime case.
Electronic records are now treated as primary evidence (not secondary) if they are created and maintained in the ordinary course of business. Previously, under the old Evidence Act, electronic evidence was treated as secondary evidence requiring certification under Section 65B. The BSA 2023 simplifies and strengthens the admissibility framework for digital evidence.
All electronic records — including emails, WhatsApp messages, SMS, social media posts, call records, bank statements, CCTV footage, and server logs — are admissible as documentary evidence provided they meet the authenticity requirements. Practical tip: Screenshots alone may not be sufficient — certified copies, metadata, and preservation of original digital records strengthen admissibility.
Courts can issue orders for preservation of electronic evidence to prevent spoliation. This is critical in cyber crime cases where evidence can be deleted remotely. Our lawyers routinely file applications for interim preservation orders under BSA 2023.
Digital forensic analysis — including metadata analysis, device forensics, network forensics, and data recovery — is admissible through expert testimony under the BSA. CyberWakil works with certified digital forensic experts to ensure evidence meets judicial standards.
Digital forensics plays a pivotal role in establishing the evidentiary chain: Email forensics can trace the origin of phishing emails; Mobile forensics can recover deleted WhatsApp messages; Blockchain forensics can track crypto transactions; Bank statement analysis can map fraudulent transaction trails. All of this evidence must be collected and preserved in a forensically sound manner to be admissible in court — which is exactly what our legal process ensures.
Beyond the primary statutes, India has established a comprehensive institutional framework for cyber crime prevention, investigation, and prosecution. Understanding this framework helps victims navigate the system effectively.
The Ministry of Home Affairs operates a centralized portal where citizens can report cyber crimes online. This platform — administered by the Indian Cyber Crime Coordination Centre (I4C) — accepts complaints for cyber fraud, online harassment, sextortion, and other cyber offences. Complaints filed here are automatically routed to the relevant state cyber cell.
The national cyber crime helpline number 1930 is a toll-free number for immediate reporting of cyber financial fraud. Once a call is made, the complaint is registered and flagged to the concerned bank's nodal officer for transaction reversal or account freezing. This is often the first and most critical step in cyber fraud recovery.
Every state in India has a dedicated Cyber Crime Police Station or Cyber Cell with specialized investigators trained in digital forensics, cyber law, and evidence handling. Major cities like Delhi, Mumbai, Bangalore, Hyderabad, and Pune have advanced cyber labs with forensic capabilities.
These rules under the IT Act 2000 impose due diligence obligations on social media platforms, messaging apps, and other intermediaries. Key requirements include: appointment of a Grievance Officer; timely removal of unlawful content (within 24 hours for content involving sexual violence); traceability of messages; and monthly compliance reports. Relevance: Victims can file grievances directly with platforms for content takedown under these rules.
The Reserve Bank of India has issued comprehensive guidelines on: UPI transaction limits, mandate of banks to implement fraud risk management, zero liability for customers in case of third-party fraud if reported within 3 days, and mandatory reporting of cyber fraud to RBI by banks. Relevance: In cyber fraud cases, these guidelines can be leveraged to claim reversal of fraudulent transactions from banks.
Use unique, complex passwords with 2FA for all accounts
Never share OTP, PIN, or passwords with unknown callers
Call 1930 or file complaint within 3 days for zero liability
Save all screenshots, emails, and transaction records immediately
| Law / Statute | Year | Key Provisions for Cyber Crime | When It Applies |
|---|---|---|---|
| IT Act 2000 | 2000 | Sections 43, 66–72 — hacking, identity theft, data theft, privacy violation, obscenity | All cyber crimes involving computer systems, digital data, and online platforms |
| BNSS 2023 | 2023 | Section 102 — freezing of bank accounts and property suspected as proceeds of crime | Bank account freezes, property attachment, criminal investigation procedure |
| BNS 2023 | 2023 | Sections 318, 319, 127, 128, 352 — cheating, extortion, criminal intimidation, defamation | Cyber fraud, sextortion, online harassment, defamation, impersonation |
| DPDP Act 2023 | 2023 | Consent framework, data breach notification, Data Principal rights, penalties up to ?250 crore | Data breaches, privacy violations, corporate data compliance |
| BSA 2023 | 2023 | Section 63 — admissibility of electronic records as primary evidence | Digital evidence, forensic reports, electronic records in court proceedings |
| IT Rules 2021 | 2021 | Intermediary due diligence, grievance redressal, content takedown timelines | Content removal from platforms, social media complaints |
Cyber crime in India is primarily governed by the Information Technology (IT) Act, 2000 (as amended in 2008), along with the Bharatiya Nyaya Sanhita (BNS) 2023 for criminal offences, the Bharatiya Nagarik Suraksha Sanhita (BNSS) 2023 for procedural matters, and the Bharatiya Sakshya Adhiniyam (BSA) 2023 for electronic evidence. The Digital Personal Data Protection (DPDP) Act, 2023 governs data privacy. Most cyber crime FIRs cite provisions from multiple statutes.
Section 102 of BNSS 2023 (formerly Section 102 CrPC) empowers police to freeze bank accounts, property, or assets that are suspected to be proceeds of crime or evidence in a criminal case. If your account is frozen under this section, the police must report the seizure to a Magistrate immediately. You have the right to apply for defreezing. CyberWakil has successfully assisted hundreds of clients in getting their accounts unfrozen through legal representation before Magistrates and Sessions Courts.
Under the Bharatiya Sakshya Adhiniyam (BSA) 2023, electronic records are admissible as primary evidence (not secondary as under the old law). This includes emails, WhatsApp messages, SMS, social media content, bank statements, CCTV footage, and server logs — provided they meet authenticity standards. Certified copies and digital forensic reports strengthen admissibility. Screenshots alone may be challenged; we always ensure evidence is preserved in a forensically sound and legally admissible format.
Yes, absolutely. Most comprehensive cyber crime FIRs cite multiple legal provisions simultaneously. For example, a sextortion case may invoke Sections 66C, 66D, 66E, and 67A of the IT Act along with Sections 127 (criminal intimidation) and 128 (extortion) of the BNS 2023. Filing under multiple provisions ensures that all aspects of the crime are covered and increases the legal options available to the investigating agency and prosecution.
The Digital Personal Data Protection (DPDP) Act, 2023 is India's comprehensive data privacy law. It requires companies to obtain explicit consent before processing your personal data, grants you the right to access, correct, and erase your data, mandates breach notification within defined timelines, and imposes penalties of up to ?250 crore for violations. If a company mishandles your data, you have direct remedies under this Act through the Data Protection Board of India.
Yes, online defamation is covered under Section 352 of BNS 2023 (replacing IPC 500) read with the IT Act provisions. Defamatory content posted on social media, blogs, websites, or messaging platforms is actionable. Remedies include: filing a criminal complaint, sending legal notices for content removal, filing a civil defamation suit for damages, and seeking injunctions from the court to restrain further publication. We have successfully handled numerous online defamation cases for individuals and businesses.
You can report cyber crime by: (1) Calling 1930 for immediate financial fraud reporting; (2) Filing a complaint on cybercrime.gov.in; (3) Visiting your nearest Cyber Crime Police Station; or (4) Contacting CyberWakil for end-to-end legal assistance. The laws invoked will depend on the nature of the crime — the IT Act 2000 for technology-specific offences, BNS 2023 for cheating/extortion, and BNSS 2023 for procedural actions like account freezing.
Our senior cyber law attorneys can explain how these laws apply to your specific case. Get a free consultation today.
100% confidential | PAN-India service | Emergency: 24/7