In this Article, We will be covering Indian laws and provisions applicable to cybersecurity, categorized by acts and sections:
1. Information Technology Act, 2000 (IT Act)
- Section 43: Penalty and compensation for unauthorized access to computer systems.
- Section 43A: Compensation for failure to protect data.
- Section 66: Hacking with computer systems.
- Section 66A: (Now repealed) Initially for sending offensive messages through communication services.
- Section 66B: Punishment for dishonestly receiving stolen computer resources.
- Section 66C: Identity theft.
- Section 66D: Cheating by personation through computer resource.
- Section 66E: Violation of privacy.
- Section 66F: Cyber terrorism.
- Section 67: Publishing or transmitting obscene material in electronic form.
- Section 67A: Publishing or transmitting sexually explicit content.
- Section 67B: Publishing or transmitting child pornographic material.
- Section 69: Powers to issue directions for interception or monitoring of information.
- Section 69A: Power to block public access to any information.
- Section 69B: Power to monitor and collect traffic data for cyber security.
- Section 70: Protection of critical information infrastructure.
- Section 70A: National nodal agency for critical information infrastructure protection.
- Section 70B: Establishment of the Indian Computer Emergency Response Team (CERT-In).
- Section 72: Breach of confidentiality and privacy.
- Section 72A: Punishment for disclosure of information in breach of lawful contract.
2. Indian Penal Code, 1860 (IPC)
- Section 379: Theft, relevant for cybercrime involving data theft.
- Section 403: Dishonest misappropriation of property, including data.
- Section 405 & 406: Criminal breach of trust, including cases where employees misuse company data.
- Section 408 & 409: Criminal breach of trust by employees and public servants.
- Section 415 & 420: Cheating and fraud.
- Section 463 & 465: Forgery, applicable to digital forgeries and document tampering.
- Section 468 & 469: Forgery for cheating and harming reputation, often applicable in cybercrime.
- Section 499 & 500: Defamation, relevant for online defamation cases.
3. Companies Act, 2013
- Section 206: Powers to inspect books and conduct inquiries, applicable to cybersecurity in company data.
- Section 207: Power to enter and search companies, including digital records.
- Section 447: Punishment for fraud, relevant in cyber fraud cases.
- Section 448: False statements, applicable to cyber reports and declarations.
- Section 449: Punishment for false evidence, related to digital documentation.
4. Payment and Settlement Systems Act, 2007
- Section 23: Offenses related to operating payment systems without authorization.
- Section 26: Punishment for fraud, embezzlement, or misrepresentation within digital payment systems.
5. Banking Regulation Act, 1949
- Section 35A: Power of RBI to issue directions, used for cybersecurity guidelines in the banking sector.
- Section 46: Penalties for violating RBI guidelines, which include cybersecurity measures.
6. The Indian Evidence Act, 1872
- Section 65B: Admissibility of electronic records as evidence in court.
- Section 67A: Proof of digital signatures.
7. Telegraph Act, 1885
- Section 5: Power of government to intercept communications for security purposes.
8. The Consumer Protection Act, 2019
- Section 2(47): Defines “unfair trade practices,” applicable in cases of misleading information online.
- Section 10: Establishes the Central Consumer Protection Authority (CCPA), responsible for handling consumer complaints, including those online.
9. Indian Contract Act, 1872
- Section 10: Validity of contracts, applicable in online contracts and click-wrap agreements.
- Section 17: Fraud in contracts, relevant to cases of digital fraud.
- Section 73: Compensation for breach of contract, applicable to cyber contracts and e-commerce.
10. Right to Information Act, 2005
- Section 8(1)(j): Exemption for personal information, ensuring privacy and data protection.
- Section 11: Protection of confidential information from third parties.
11. Public Financial Institutions Act, 1983
- Governs protection measures within financial institutions, relevant in cases of cybersecurity breaches in public financial bodies.
12. Personal Data Protection Bill (Draft)
- This is not yet law, but it’s intended to address protection, collection, and processing of personal data in India.
13. Reserve Bank of India (RBI) Guidelines on Cyber Security Framework, 2016
- These guidelines mandate a comprehensive cyber security policy, controls, and audit requirements in the banking sector.
- Guideline 6: Customer awareness and training on cybersecurity.
14. The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits, and Services) Act, 2016
- Section 29: Restrictions on sharing and usage of Aadhaar information.
- Section 30: Defines biometric information and establishes protection protocols.
15. Telecom Regulatory Authority of India (TRAI) Act, 1997
- Section 12: TRAI’s authority to issue guidelines, including cybersecurity standards for telecom services.
16. Criminal Procedure Code (CrPC), 1973
- Section 91: Summons to produce documents or electronic records.
- Section 161: Powers of the police to examine witnesses, including obtaining digital evidence.
- Section 165: Search and seizure powers applicable to digital devices.
17. Public Records Act, 1993
- Governs the management and protection of government records, including digitized formats.
18. Competition Act, 2002
- Section 3: Prohibits anti-competitive agreements, relevant for online marketplaces and cybersecurity practices.
- Section 4: Prohibits abuse of dominant position, often relevant in the tech sector.
19. Central Vigilance Commission Act, 2003
- Governs protection against corruption and misuse, including in cyber contexts.
20. Intellectual Property Rights (IPR)
- Copyright Act, 1957 (Sections 51 and 63): Governs digital piracy and unauthorized use of copyrighted content.
- Patents Act, 1970 (Sections 48 and 66): Governs patent rights infringement online.
- Trademark Act, 1999 (Sections 29 and 107): Protects online trademark violations.
21. Credit Information Companies (Regulation) Act, 2005
- Section 19: Protection of credit information data against unauthorized access.
22. National Security Act, 1980
- Governs actions against threats to national security, which includes cybersecurity threats.
23. Disaster Management Act, 2005
- Section 69: Provides for dealing with cyber-related disasters and crisis response measures.
24. Cyber Swachhta Kendra (Cyber Hygiene Centre) Regulations
- An initiative under CERT-In, Cyber Swachhta Kendra aims to ensure cybersecurity hygiene and awareness.
25. Unlawful Activities Prevention Act (UAPA), 1967
- Governs cybersecurity measures in counter-terrorism, especially in digital spaces.
26. Prevention of Money Laundering Act, 2002 (PMLA)
- Governs the use of digital channels for money laundering and mandates cybersecurity measures.
27. National Investigation Agency Act, 2008
- Section 6: Powers of NIA to investigate cyber-terrorism cases.
28. Protection of Children from Sexual Offences Act (POCSO), 2012
- Section 14 & 15: Criminalizes possession and distribution of child pornography.
29. Medical Council of India Guidelines (Telemedicine)
- Governs confidentiality and cybersecurity in telemedicine services.
30. Indian Post Office Act, 1898
- Section 20: Protects the confidentiality of letters, including emails sent via government networks.
31. Prevention of Insults to National Honour Act, 1971
- Governs restrictions on sharing content online that could insult the nation’s honor.
32. Cinematograph Act, 1952
- Regulates the digital distribution of movies and other copyrighted cinematic content.
33. National Digital Health Mission (NDHM) Policy
- Governs data security standards for healthcare records in digital platforms.
34. Maternity Benefit (Amendment) Act, 2017
- Mandates data protection for health records, especially on digital platforms.
35. Juvenile Justice (Care and Protection of Children) Act, 2015
- Governs privacy protection for children’s digital data in juvenile justice cases.
36. Insurance Regulatory and Development Authority of India (IRDAI) Cyber Security Guidelines
- Mandates cybersecurity for insurance companies, including secure handling of sensitive information.
37. Merchant Shipping Act, 1958
- Governs cybersecurity protocols for digital transactions in maritime trade.
38. Biological Diversity Act, 2002
- Governs data protection related to biodiversity information in digital platforms.
39. Arms Act, 1959
- Regulates digital data protection related to arms and ammunitions records.
40. Public Gambling Act, 1867
- Governs online gaming and gambling regulations, addressing cybersecurity standards in gaming applications.
41. Indian Wireless Telegraphy Act, 1933
- Governs the possession of wireless telegraphy apparatus and is relevant in cases of cyber espionage and wireless hacking.
42. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
- Rule 3(1): Due diligence by intermediaries in user data protection.
- Rule 4: Significant social media intermediaries to appoint grievance officers and comply with cybersecurity standards.
43. National Cyber Security Policy, 2013
- Provides a framework for cybersecurity initiatives in government and critical sectors.
44. The Foreign Exchange Management Act (FEMA), 1999
- Section 13: Cybersecurity measures for cross-border transactions and controls on digital currency exchanges.
45. The Public Liability Insurance Act, 1991
- Governs cybersecurity insurance for damages caused by data breaches in hazardous industries.
46. The Essential Commodities Act, 1955
- Governs digital records for essential commodities, especially relevant to e-commerce and online supply chains.
47. The Cinematograph (Certification) Rules, 1983
- Governs online distribution and sharing of cinematographic content with cybersecurity implications for copyright.
48. The Cable Television Networks (Regulation) Act, 1995
- Section 5: Regulates digital cable networks and prohibits broadcasting offensive content online.
49. Protection of Plant Varieties and Farmers’ Rights Act, 2001
- Governs data security for information related to agricultural varieties and farmers’ data.
50. The Electricity Act, 2003
- Section 68: Protection against cyber threats to electricity grids and other critical infrastructure.
51. National Digital Communications Policy, 2018
- Sets policies for secure and resilient digital communications infrastructure in India.
52. Indian Ports Act, 1908
- Governs the protection of digital systems and cybersecurity measures in port operations and logistics.
53. The Telecom Commercial Communications Customer Preference Regulations, 2018 (TRAI)
- Section 4: Regulations for controlling spam and phishing through digital communications.
54. Income Tax Act, 1961
- Section 139A: Secure handling of Permanent Account Numbers (PAN) in digital records and prevention of data leaks.
55. The Right to Privacy (Judicial Precedent, Puttaswamy Judgement, 2017)
- Established the right to privacy as a fundamental right, impacting all data protection and cybersecurity laws in India.
56. Broadcasting Content Complaint Council Guidelines
- Provides ethical guidelines for digital content and addresses cybersecurity for streaming services.
57. Biotechnology Regulatory Authority of India Bill (Draft)
- Proposed regulations for cybersecurity in biotechnology data and digital health records.
58. Industrial Disputes Act, 1947
- Protects against cyber-related industrial espionage and digital record tampering in employment disputes.
59. Indian Trusts Act, 1882
- Governs data management in trust assets, including protection against digital fraud.
60. The Legal Metrology Act, 2009
- Governs data protection in digital transactions involving weights and measures.
61. The Securities and Exchange Board of India (SEBI) Cyber Security and Cyber Resilience Framework
- Mandates cybersecurity protocols for stock exchanges, brokers, and other participants in the securities market.
62. Mines and Minerals (Development and Regulation) Act, 1957
- Governs cybersecurity measures for data in digital mining licenses and permits.
63. The Collection of Statistics Act, 2008
- Governs data security in the collection and processing of statistical information by government agencies.
64. Motor Vehicles Act, 1988
- Section 2(19): Protection of data collected through automated driving and licensing systems.
65. The Employment Exchanges (Compulsory Notification of Vacancies) Act, 1959
- Governs secure handling of employment data on government portals.
66. Department of Telecom (DoT) Internet Services Rules
- Regulates cybersecurity standards for ISPs in India, including data protection protocols.
67. The Prohibition of Benami Property Transactions Act, 1988
- Governs secure handling of property data and prevention of digital manipulation.
68. The Plant Quarantine (Regulation of Import into India) Order, 2003
- Regulates digital records for plant imports, applicable to cybersecurity in customs data.
69. The Foreign Contribution (Regulation) Act, 2010
- Section 11: Regulates secure digital records of foreign contributions to NGOs.
70. Official Secrets Act, 1923
- Governs cybersecurity for sensitive government data, especially in cases of espionage.
71. The Payment of Wages Act, 1936
- Governs the secure handling of digital wage payments and personal financial data of employees.
72. Digital Locker Authority Regulations, 2016
- Sets guidelines for secure access, storage, and retrieval of documents in Digital Lockers.
73. The Drug and Cosmetics Act, 1940
- Governs digital records for drug licensing and clinical trials, with cybersecurity implications.
74. Standards of Weights and Measures Act, 1976
- Governs cybersecurity in the digital handling of weights and measures in trade and commerce.
75. The Railways Act, 1989
- Section 145: Governs cybersecurity measures for online booking and ticketing systems.
76. Apprentices Act, 1961
- Governs secure handling of apprentice records and training data.
77. The Public Servants (Inquiries) Act, 1850
- Governs secure handling of inquiry records and digital evidence for public servants.
78. Postal and Telegraphic Communication Regulations
- Governs cybersecurity measures for online postal services, including secure transmission of messages.
79. The Aircraft Act, 1934
- Governs cybersecurity for data handling in air traffic control and airline data management systems.
80. The Carriage by Air Act, 1972
- Governs digital data protection and cybersecurity measures in air freight and passenger data.
81. Electronic Waste (Management) Rules, 2016
- Governs secure disposal of electronic data and digital devices.
82. Environmental Protection Act, 1986
- Governs cybersecurity measures for data handling in environmental monitoring systems.
83. The Consumer Protection (E-Commerce) Rules, 2020
- Sets standards for cybersecurity, user data protection, and grievance redressal for e-commerce platforms.
84. Data Privacy Guidelines by Ministry of Electronics and Information Technology (MeitY)
- Guidelines for data privacy and cybersecurity across sectors involving personal information.
85. Intelligence Bureau (IB) and National Technical Research Organization (NTRO) Security Protocols
- Guidelines for handling cybersecurity in intelligence and technical research.
86. Narcotic Drugs and Psychotropic Substances (NDPS) Act, 1985
- Governs secure handling of digital records and cybersecurity for information on narcotics.
87. Central Board of Direct Taxes (CBDT) Guidelines on Data Privacy and Security
- Guidelines to secure handling of taxpayer information and cybersecurity in tax records.
88. Real Estate (Regulation and Development) Act, 2016 (RERA)
- Governs secure handling of real estate transaction data on digital platforms.
89. Model Shops and Establishments Act, 2016
- Governs data protection in digital records of establishments under state jurisdiction.
90. Special Marriage Act, 1954
- Governs the protection of digital marriage records and personal data.
India’s cybersecurity landscape across sectors, covering various aspects from data privacy to digital transactions, government data, corporate records, and personal information.

