Cyber Laws in India: IT Act 2000, Amendments & Cybercrime Penalties
Cyber laws in India are governed primarily by the Information Technology Act 2000 (amended 2008), the Digital Personal Data Protection Act 2023, and the Bharatiya Nyaya Sanhita 2023. These statutes cover unauthorised access, data theft, identity fraud, cyberterrorism, and data privacy, forming India’s core cybersecurity legal framework.
- Key Takeaway 1: The IT Act 2000 is still valid and actively enforced, supplemented by BNS 2023 and DPDP Act 2023.
- Key Takeaway 2: Section 66 and its sub-sections (66C, 66D) carry criminal penalties including imprisonment up to three years and fines up to Rs 1 lakh.
- Key Takeaway 3: Section 66A was struck down by the Supreme Court in 2015 (Shreya Singhal v. Union of India) but still appears in FIRs, so knowing its status matters.
- Key Takeaway 4: India’s cybercrime portal (cybercrime.gov.in) received over 1.5 million complaints in 2023 alone, according to the Ministry of Home Affairs.
- Key Takeaway 5: Understanding cyber law is a genuine career differentiator for roles in GRC, digital forensics, legal-tech, and compliance.
What the IT Act 2000 Actually Covers: Key Cyber Crime Laws in India
The IT Act 2000 was India’s first legislation to give legal recognition to electronic records and digital signatures. It has been the backbone of cyber crime laws in India for over two decades. The 2008 amendment was the major overhaul, adding offences that the original act simply did not anticipate.
Most people only hear about the controversial sections. But the act is far broader. It covers electronic contracts, certifying authorities, adjudication of disputes, and the powers of CERT-In (the Indian Computer Emergency Response Team). CERT-In operates under the Ministry of Electronics and Information Technology and is the nodal agency for cybersecurity incident response in India.
Section 43: Civil Liability for Unauthorised Access
Section 43 is the civil remedy section. If someone accesses your computer system without permission, downloads data, introduces a virus, or disrupts service, they are liable to pay compensation. There is no upper cap on the compensation amount, which makes it a genuinely powerful provision for businesses and individuals.
This section does not require criminal intent, which is important. Even negligent unauthorised access can trigger liability here. It is the section most relevant to corporate data breach disputes.
Section 66: The Criminal Counterpart
Section 66 criminalises the acts described in Section 43 when done with dishonest or fraudulent intent. The punishment is imprisonment up to three years, or a fine up to Rs 5 lakh, or both. This is the section that gets invoked in most hacking-related FIRs filed across India.
The 2008 amendment added several sub-sections under Section 66 that address specific modern offences. These are worth knowing individually.
Section 66C and 66D: Identity Theft and Cheating by Impersonation
Section 66C targets identity theft. Using someone else’s password, digital signature, or any other unique identification feature dishonestly carries imprisonment up to three years and a fine up to Rs 1 lakh. Phishing attacks that harvest login credentials fall squarely under this section.
Section 66D addresses cheating by impersonation using a computer resource. Think of someone posing as a bank’s customer service on a fake website. Punishment mirrors Section 66C: up to three years imprisonment and a fine up to Rs 1 lakh. These two sections together cover a large share of India’s financial cybercrime cases.
What Happened to Section 66A?
Section 66A originally penalised sending “offensive” or “menacing” messages online. The Supreme Court struck it down entirely in March 2015 in Shreya Singhal v. Union of India, ruling it unconstitutional for violating Article 19(1)(a) (freedom of speech). The court found the terms “grossly offensive” and “menacing” were too vague and prone to misuse.
Despite this, a 2021 PUCL study found that police in multiple states were still filing cases under Section 66A after it was struck down. If you ever see an FIR citing this section, the charge is legally invalid and challengeable.
Sections 67, 67A, 67B: Obscene and Child Sexual Abuse Content
Section 67 punishes publishing or transmitting obscene material in electronic form with up to three years imprisonment and a fine up to Rs 5 lakh for a first conviction. Section 67A covers sexually explicit material (up to five years, Rs 10 lakh fine). Section 67B specifically addresses child sexual abuse material (CSAM), with penalties up to five years and Rs 10 lakh for first offences, higher for repeat offenders.
For a broader view of how cybersecurity threats intersect with real-world harm, the cybersecurity in the digital era guide on 3.0 University covers the technical and human dimensions in depth.
Cyber Laws in India: Key Sections, Penalties and Offences at a Glance
The table below consolidates the most commonly invoked sections under the IT Act 2000 (as amended in 2008), with their offence descriptions and penalty ranges. These are the sections that law enforcement, legal professionals, and compliance officers work with day-to-day.
| Section | Offence | Maximum Imprisonment | Maximum Fine | Nature |
|---|---|---|---|---|
| Section 43 | Unauthorised access, data theft, virus introduction | None (civil) | No upper cap (compensation) | Civil |
| Section 66 | Computer-related offences with fraudulent intent | 3 years | Rs 5 lakh | Criminal |
| Section 66B | Receiving stolen computer resource or communication device | 3 years | Rs 1 lakh | Criminal |
| Section 66C | Identity theft | 3 years | Rs 1 lakh | Criminal |
| Section 66D | Cheating by impersonation using computer | 3 years | Rs 1 lakh | Criminal |
| Section 66E | Violation of privacy (capturing/publishing private images) | 3 years | Rs 2 lakh | Criminal |
| Section 66F | Cyberterrorism | Life imprisonment | Court discretion | Criminal |
| Section 67 | Publishing obscene material electronically | 3 years (first offence) | Rs 5 lakh | Criminal |
| Section 67B | Child sexual abuse material online | 5 years (first offence) | Rs 10 lakh | Criminal |
| Section 72 | Breach of confidentiality and privacy by intermediary | 2 years | Rs 1 lakh | Criminal |
According to the National Crime Records Bureau (NCRB) Crime in India Report 2022, a total of 65,893 cybercrime cases were registered across India, up from 52,974 in 2021. That is a 24.4% year-on-year increase. The states reporting the highest volumes were Telangana, Uttar Pradesh, and Karnataka.
The Ministry of Home Affairs Annual Report 2023-24 noted that the Indian Cyber Crime Coordination Centre (I4C) had blocked over 1,700 Skype IDs and 59,000 WhatsApp accounts linked to cybercrime syndicates. These are not abstract enforcement statistics; they reflect active use of the legal framework.
The BNS 2023 and IT Act: How They Interact
The Bharatiya Nyaya Sanhita 2023 replaced the Indian Penal Code from July 2024. Several IPC sections used alongside the IT Act (like Section 420 for cheating and Section 468 for forgery) now have BNS equivalents. Prosecutors can charge accused persons under both the IT Act and the BNS for the same incident where the facts support it.
This dual-track approach is common in cases involving online financial fraud. The IT Act handles the cyber-specific offence; the BNS handles the underlying fraud or cheating charge. Defence lawyers and compliance officers both need to track both statutes.
IT Act vs DPDP Act: Different Problems, Different Laws
The Digital Personal Data Protection Act 2023 (DPDP Act) is not a replacement for the IT Act. It specifically governs how organisations collect, process, and store personal data of Indian citizens. Penalties under the DPDP Act can reach Rs 250 crore per violation for significant data fiduciaries who fail to implement adequate security safeguards, according to the act’s penalty schedule.
Consider this distinction: if a hacker breaks into a company’s server, the IT Act governs the criminal offence. If the company failed to protect that data adequately in the first place, the DPDP Act governs the company’s liability to its users. Both can apply to the same incident from different angles.
If you work in a sector that handles large volumes of user data, understanding both frameworks is non-negotiable. Roles in GRC (Governance, Risk and Compliance) are growing specifically because organisations need people who can map operations to both statutes simultaneously.
How to Report a Cybercrime in India: The Actual Process
India’s primary cybercrime reporting mechanism is the National Cyber Crime Reporting Portal at cybercrime.gov.in, operated by the Ministry of Home Affairs. It has been operational since 2019 and handles both financial crimes and content-related offences (like CSAM and online harassment).
Step-by-Step: Filing a Complaint
- Visit cybercrime.gov.in and click “Report Cyber Crime.” You can report anonymously for certain categories like CSAM.
- Select the crime category: financial fraud, social media crime, online harassment, hacking, etc. The categorisation matters because it routes your complaint to the right cell.
- Provide evidence: screenshots, transaction IDs, email headers, URLs, phone numbers. The more specific, the faster the response.
- Note your complaint ID. You will need it to track status or escalate.
- For financial fraud, call 1930 immediately. This is the national cybercrime helpline. Early reporting (within the first few hours) significantly increases the chance of freezing fraudulent transactions before funds are moved.
- File an FIR at your local police station if the portal complaint does not result in action within a reasonable timeframe, or if the matter is serious enough to require immediate investigation.
According to the MHA’s 2023 data, the cybercrime portal had received over 15.56 lakh (1.556 million) complaints cumulatively since its launch, with financial fraud dominating the complaint categories at over 67% of total volume.
Seniors are disproportionately targeted in financial cybercrime cases. The 3.0 University guide on protecting seniors from online scams covers the specific tactics used and how families can help. Crypto-related fraud is also rising fast. Our piece on crypto crime detection with blockchain forensics explains how investigators trace illicit transactions.
CERT-In’s Role in Incident Reporting
CERT-In (Indian Computer Emergency Response Team) is the government’s technical arm for cybersecurity. Under the IT (Amendment) Rules 2022, organisations in critical sectors are required to report cybersecurity incidents to CERT-In within six hours of detection. This is one of the strictest mandatory reporting timelines globally.
The six-hour rule applies to data breaches, ransomware attacks, identity theft incidents, and several other defined categories. Non-compliance can result in penalties under the IT Act and regulatory action from sector-specific regulators like RBI or SEBI.
IT Rules 2021 and Intermediary Liability
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 placed significant obligations on social media platforms and OTT providers. Significant social media intermediaries (those with over 5 million registered users in India) must appoint a resident grievance officer, a compliance officer, and a nodal contact person, all based in India.
Non-compliance strips them of the “safe harbour” protection under Section 79 of the IT Act, meaning they can be held liable for third-party content hosted on their platforms. This has been a point of ongoing legal contestation between the government and major platforms.
Frequently Asked Questions About Cyber Laws in India
What are the cyber laws in India?
India’s cyber laws are primarily the Information Technology Act 2000 (amended 2008), the IT Rules 2021, and the Digital Personal Data Protection Act 2023. The Bharatiya Nyaya Sanhita 2023 also covers cyber-enabled offences like fraud and forgery. Together, these statutes govern digital offences, data protection, intermediary obligations, and cybersecurity incident reporting across the country.
What is Section 66A of the IT Act?
Section 66A originally penalised sending offensive or menacing messages online. The Supreme Court of India struck it down in March 2015 in the landmark Shreya Singhal v. Union of India case, ruling it unconstitutional for violating freedom of speech under Article 19(1)(a). The section no longer has legal force, though police have incorrectly invoked it in FIRs after the ruling.
What is the punishment for hacking in India?
Hacking with fraudulent or dishonest intent is punishable under Section 66 of the IT Act with up to three years’ imprisonment and a fine up to Rs 5 lakh. If the act also constitutes cyberterrorism under Section 66F, the punishment can extend to life imprisonment. Civil compensation under Section 43 can be claimed separately with no upper cap on the amount.
How do I report cybercrime in India?
File a complaint at cybercrime.gov.in, India’s official National Cyber Crime Reporting Portal. For financial fraud, call the helpline 1930 immediately as early reporting can help freeze fraudulent transactions. Retain all evidence including screenshots, transaction IDs, and call logs. You can also file an FIR at your nearest police station if online reporting does not result in timely action.
Is the IT Act 2000 still valid?
Yes, the IT Act 2000 is still valid and actively enforced. It was significantly amended in 2008 and is supplemented by rules including the IT Rules 2021 and CERT-In directions 2022. The DPDP Act 2023 and BNS 2023 work alongside it rather than replacing it. Courts across India continue to apply its provisions in cybercrime prosecutions and civil disputes involving digital offences.
Understanding cyber laws in India is not just useful for lawyers. If you are building a career in cybersecurity, digital forensics, compliance, or legal-tech, this knowledge sets you apart. Employers in GRC roles increasingly expect candidates to understand not just the technical controls but the legal consequences of security failures.
The best professionals in this space know how to connect a technical incident to its legal implications and communicate both clearly. That combination is rare and genuinely valued. Start building it by exploring 3.0 University’s cybersecurity learning resources where technical skills and real-world context come together.
Last updated: January 2025. Reviewed by the 3University editorial team.


