Cybersecurity Laws and Regulations in India

Cybersecurity Laws and Regulations in India

India’s cybersecurity framework is built on a combination of law, rules, regulatory directions and specialised institutions. It covers electronic transactions, personal data protection, cybercrime enforcement and the security of critical information infrastructure.

For Prelims revision, the most important parts are the IT Act, 2000, the Digital Personal Data Protection Act, 2023, CERT-In directions, intermediary rules and sector-specific cyber regulations.

Information Technology Act, 2000

The Information Technology Act, 2000 is the primary cyber law in India. It gives legal recognition to electronic records, digital signatures and e-commerce transactions, while also defining offences and penalties linked to computer misuse.

  • Legal validity: Recognises electronic records and digital contracts.
  • Cyber offences: Covers hacking, data theft and tampering with computer source code.
  • Privacy violation: Section 66E punishes violation of privacy.
  • Cyber terrorism: Section 66F deals with cyber terrorism.
  • Obscene content: Section 67 punishes publishing obscene material online.
  • Intermediary liability: Lays down the legal framework for liability of intermediaries and network service providers.
  • Safe harbour: Section 79 provides protection to intermediaries if they follow prescribed due diligence norms.

Intermediary Rules and Digital Ethics

The Information Technology Rules impose due diligence obligations on social media intermediaries and digital platforms. These rules are aimed at quicker grievance redressal and removal of unlawful content.

  • Content removal: Platforms must remove unlawful, obscene or privacy-invading content within stipulated timelines after a formal grievance or government order.
  • Compliance officers: Large social media platforms must appoint a resident grievance officer, a chief compliance officer and a nodal contact person in India.
  • Digital responsibility: The rules also address the generation, creation and dissemination of synthetic media and AI-driven deepfakes.
  • Due diligence: Intermediaries must follow prescribed procedures to retain safe harbour protection under the IT Act.

Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 provides a legal framework for safeguarding personal data and regulating its processing in digital form. It is centered on consent, user rights and compliance duties for data-handling entities.

  • Lawful processing: Data fiduciaries can collect personal data only for lawful purposes and with explicit, free, unconditional and informed consent.
  • Data principal rights: Individuals can seek access to personal data summaries, correction and erasure.
  • Children’s data: The Act imposes special obligations while handling children’s data.
  • Vulnerable groups: It provides additional protections for vulnerable groups.
  • Penalty mechanism: The Data Protection Board of India can investigate breaches and impose financial penalties for non-compliance.

Cyber Incident Reporting and National Response

India has dedicated institutions for cyber incident monitoring, threat analysis and emergency response. These bodies support both national defence and operational security across sectors.

  • CERT-In: The Indian Computer Emergency Response Team is the national nodal agency for threat monitoring, vulnerability analysis and cyber incident management.
  • Mandatory reporting: Organisations, companies and service providers must report cyber security incidents and data breaches within a stipulated timeline of six hours.
  • Sectoral response teams: Sector-specific emergency response teams operate in critical infrastructure domains such as finance, power and telecommunications.
  • National Cyber Crime Reporting Portal: Citizens can report online fraud anonymously, with specialised modules for cyberstalking and financial scams.

Protection of Critical Information Infrastructure

Critical information infrastructure refers to systems whose disruption can seriously affect national security, public services and economic stability. India has separate arrangements to protect these vital networks.

  • Node for protection: The National Critical Information Infrastructure Protection Centre is the nodal agency for protecting critical information infrastructure.
  • Coverage: It works across sectors such as energy, transport, defence and telecommunications.
  • Security standards: It formulates security audits, vulnerability assessments and baseline protection standards for designated vital networks.

Sector-Specific Cyber Regulations

In addition to general cyber law, sector regulators issue domain-specific rules to address technology risk, resilience and operational security.

  • RBI: Regulates cyber risk and resilience in the financial sector.
  • SEBI: Issues cybersecurity directions for market infrastructure and securities entities.
  • IRDAI: Covers cyber risk standards for insurance entities.
  • CEA: Addresses technology and security concerns in the power sector.
Regulatory Instrument Governing Authority Primary Focus Area
IT Act, 2000 Ministry of Electronics and Information Technology Cybercrime penalisation, electronic contracts and intermediary liability
DPDP Act, 2023 Data Protection Board of India Personal data privacy, fiduciary obligations and consent management
CERT-In Directives Ministry of Electronics and Information Technology Mandatory cyber incident reporting and malware tracking
Sectoral Regulations RBI, SEBI, IRDAI and CEA Domain-specific technology risk, resilience and operational security

Key Prelims Takeaways

  • IT Act, 2000: The core cyber law for electronic records, digital signatures and cyber offences.
  • Section 79: Safe harbour for intermediaries applies only with due diligence compliance.
  • Section 66E: Deals with violation of privacy.
  • Section 66F: Covers cyber terrorism.
  • DPDP Act, 2023: Focuses on lawful processing of personal data and user rights.
  • CERT-In: National nodal agency for incident response and vulnerability analysis.
  • Critical infrastructure protection: NCIIPC safeguards vital networks in sectors like energy, transport, defence and telecommunications.
Current General Studies comprises current-affairs-based, General Studies-rich study material on policies, laws, institutions, economy, science, environment, governance, international relations, and other varied but important topics for UPSC and State PSC Prelims examinations. Fortnightly PDF compilations: Available here
Originally written on May 30, 2026 and last modified on September 6, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *