Report an IncidentTalk to Sales

Cybersecurity Laws in India: IT Act 2000 and DPDP Act Explained

Reviewed By: Rahul Katiyar
Updated on: September 18, 2026
Reading Time: 13 Min
Published: 
September 17, 2026

India’s cyber legal framework now extends beyond tackling unauthorised access and cyber offences to governing how organisations collect, process, and protect personal data. The IT Act, 2000 and DPDP Act, 2023 address different aspects of India’s cyber law, alongside supporting rules and directions. This article examines their provisions, penalties, enforcement, applicability, and transition timeline. 

Key Takeaways

  • India’s cybersecurity framework is broader than one law: The IT Act, DPDP Act, BNS, BSA, CERT-In Directions, and applicable IT Rules address different aspects of cyber activity, data protection, criminal conduct, and digital evidence.
  • The IT Act remains central to cyber-related matters: It covers electronic records, specified cyber offences, intermediary liability and other technology-related provisions, while Sections such as 66, 66C, 66D, 66E and 66F prescribe consequences for specific offences.
  • The DPDP Act focuses on digital personal data: It establishes rights for Data Principals and obligations for Data Fiduciaries covering areas such as consent, security safeguards, breach notification and grievance redressal, with penalties for specified breaches.
  • Cybersecurity responsibilities are shared across different authorities: CERT-In handles national cybersecurity incident response, I4C supports coordinated action against cybercrime, and the Data Protection Board performs functions assigned under the DPDP Act.
  • The DPDP framework is being implemented in phases: The IT Act continues to apply within its scope, while the DPDP Act follows a staged commencement schedule, with core operational provisions scheduled to take effect on 13 May 2027. Organisations handling digital personal data should prepare their processes, safeguards, and governance before then.

What Are Cybersecurity Laws in India?

Cybersecurity laws in India set legal requirements for digital activities, electronic records, cyber offences, and personal data protection. Rather than relying on one law, India’s cyber legal framework combines technology-specific legislation with broader criminal and evidence laws.

Key Laws in India's Cyber Legal Framework: IT Act, DPDP Act, BNS and BSA

India’s cyber legal framework combines technology-specific legislation with broader laws governing criminal conduct and digital evidence. The four key laws serve different purposes:

  • IT Act, 2000: Covers electronic records, cyber offences, intermediary liability and related technology matters.
  • DPDP Act, 2023: Regulates the processing and protection of digital personal data.
  • BNS, 2023: Provides the broader criminal law framework applicable to relevant cyber-related offences.
  • BSA, 2023: Governs evidence, including electronic and digital records, in legal proceedings.

What Is the Information Technology Act, 2000?

The Information Technology Act, 2000 is India’s foundational law for electronic records, electronic transactions, and several offences involving computer systems and digital technologies. It provides the legal framework for areas such as electronic signatures, cyber offences, intermediary liability, and specified government powers concerning digital information.

Objectives and Scope of the IT Act

The IT Act was enacted to provide legal recognition to electronic records and electronic transactions and establish a framework for addressing the misuse of information technology. Its scope extends across:

  • Electronic records and signatures: Provides legal recognition to electronic records and electronic signatures for specified purposes.
  • Cyber offences: Establishes provisions addressing unauthorised access, damage to computer resources and other specified offences.
  • Intermediaries: Sets out conditions under which intermediaries may receive protection from liability for third-party information.
  • Government powers: Provides specified powers relating to interception, monitoring, decryption and blocking of information, subject to the Act and applicable rules.

Key Amendments and the Shreya Singhal Judgment

The IT Act has evolved through amendments and judicial interpretation as digital technologies and online activities have changed. A significant development was the Shreya Singhal v. Union of India judgment in 2015.

The Supreme Court struck down Section 66A, finding that it was unconstitutional for violating freedom of speech and expression. The judgment also considered Section 69A, concerning blocking of online information, and Section 79, concerning intermediary liability. These provisions remain relevant to understanding the IT Act today.

What Are the Key Sections and Penalties Under the IT Act?

The IT Act contains provisions addressing computer-related offences, privacy violations, intermediary liability, and certain government powers concerning online information. Depending on the provision involved, a violation may result in imprisonment, a fine, compensation, or other legal consequences.

Types of Cybercrimes and Their Punishments

The Act covers several offences involving computer resources, electronic information and digital communications. Some commonly referenced provisions include:

Section Provision Punishment
66 Computer-related offences involving the acts specified under Section 43, when committed dishonestly or fraudulently Up to 3 years' imprisonment, or fine up to ₹5 lakh, or both
66C Identity theft Up to 3 years' imprisonment and fine up to ₹1 lakh
66D Cheating by personation using a computer resource or communication device Up to 3 years' imprisonment and fine up to ₹1 lakh
66E Violation of privacy Up to 3 years' imprisonment, or fine up to ₹2 lakh, or both
66F Cyber terrorism Imprisonment which may extend to life
67 Publishing or transmitting obscene material in electronic form Up to 3 years' imprisonment and fine up to ₹5 lakh for a first conviction, with severer punishment for subsequent convictions

These are only selected provisions and do not represent the full range of offences under the Act. Section 66A should not be included as a current offence, as the Supreme Court struck it down in Shreya Singhal v. Union of India in 2015.

Data Privacy Provisions Under Sections 43A, 72 and 72A

The IT Act contains specific provisions concerning the protection, confidentiality, and disclosure of information. Their scope differs from the broader personal data framework established under the Digital Personal Data Protection Act (DPDP) Act:

  • Section 43A: Provides for compensation where a body corporate handling sensitive personal data or information is negligent in maintaining reasonable security practices, resulting in wrongful loss or wrongful gain.
  • Section 72: Provides a penalty for breach of confidentiality and privacy by a person who has secured access to information under a power conferred by the IT Act.
  • Section 72A: Addresses disclosure of information in breach of a lawful contract, where the statutory conditions relating to wrongful loss or wrongful gain are met.

These provisions should not be treated as equivalent to the comprehensive obligations introduced by the DPDP Act. The relationship between Section 43A and the DPDP Act also needs to be considered in light of the DPDP Act's phased commencement.

Also Read: How DPDPA 2025 Makes SOC Monitoring Non-Negotiable for Indian Businesses

Intermediary Liability and Blocking Powers Under Sections 79 and 69A

Sections 79 and 69A deal with different aspects of online regulation:

  • Section 79: Provides a conditional exemption from liability for an intermediary in relation to third-party information, subject to the requirements and conditions specified in the Act.
  • Section 69A: Provides the Central Government with the power to direct an intermediary to block public access to information through a computer resource in specified circumstances and subject to the prescribed procedure and safeguards.

The Supreme Court considered both provisions in Shreya Singhal v. Union of India. It upheld Section 69A and the associated blocking procedure, while examining the operation of Section 79 in the context of intermediary liability.

Organisations dealing with cyber threats also need ongoing visibility into security activity and a process for investigating and responding to incidents. Eventus Security provides 24/7 Managed SOC services with security monitoring, threat detection, threat hunting, incident investigation, and response supported by security analysts. This type of managed security operation can help organisations maintain continuous oversight of their security environment and respond to potential incidents.

What Is the Digital Personal Data Protection Act, 2023?

The Digital Personal Data Protection Act, 2023 establishes a legal framework for processing digital personal data in India. It defines the responsibilities of Data Fiduciaries and the rights and duties of Data Principals, while setting requirements for consent, security safeguards, personal data breaches, and grievance redressal. Its provisions are being implemented in phases.

Scope and Applicability of the DPDP Act

The DPDP Act applies to the processing of digital personal data within India where the data is collected digitally or collected in non-digital form and subsequently digitised. It can also apply to processing outside India when such processing is connected with offering goods or services to Data Principals in India, subject to the Act's provisions and exclusions.

Rights of Data Principals

The Act gives Data Principals, meaning individuals to whom personal data relates, specific rights concerning their personal data. These include:

  • Access: Obtain information about personal data and its processing.
  • Correction and erasure: Request correction, completion, updating or erasure, subject to the Act.
  • Grievance redressal: Seek redressal for a grievance relating to the processing of personal data.
  • Nomination: Nominate another individual to exercise specified rights in the event of death or incapacity.

The Act also provides for withdrawal of consent where consent is the basis for processing.

Consent, Breach Notification and Other Obligations of Data Fiduciaries

A Data Fiduciary determines the purpose and means of processing personal data. Where consent is the basis for processing, the Act requires it to be free, specific, informed and unambiguous, with clear affirmative action. Data Fiduciaries also have obligations relating to notice, reasonable security safeguards, personal data breach notification, grievance redressal, and other requirements specified under the Act and applicable Rules.

Penalties Under the DPDP Act

The DPDP Act provides financial penalties for specified breaches. The maximum penalty prescribed under the Act is up to ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach. Other contraventions carry penalties specified separately in the Act, depending on the nature of the breach.

Keep Security Operations Running 24/7
Monitor threats and investigate suspicious activity with Eventus Security.

Explore our Managed SOC Service

Which Cybersecurity Rules Must Organisations Follow Beyond These Acts?

India’s cyber legal framework is supported by rules and directions issued under the IT Act. These instruments address specific areas such as cyber incident reporting, information security practices and intermediary obligations. Their requirements depend on the type of organisation, service or activity involved.

CERT-In Directions, 2022

The CERT-In Directions, 2022 were issued under Section 70B of the IT Act and address information security practices, prevention, response and reporting of cyber incidents. Covered entities must report specified cyber incidents to CERT-In within the prescribed timeframe and comply with requirements relating to maintaining logs and providing information when required.

IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

The IT Rules, 2021 prescribe due diligence and other obligations for intermediaries. They also contain additional requirements for certain categories of intermediaries and a Digital Media Ethics Code covering specified publishers of news and current affairs content and providers of online curated content. The applicable requirements therefore depend on the entity's classification and activities. The Rules have also been amended over time.

Also Read: CERT-In Compliance in India: What Your SOC Must Do to Meet the 2025 Audit Guidelines

Who Enforces Cybersecurity Laws in India?

Cybersecurity enforcement in India is distributed across specialised institutions rather than handled by a single authority. CERT-In deals with national cybersecurity incident response, I4C supports coordinated action against cybercrime, and the Data Protection Board handles matters assigned to it under the DPDP Act. Law enforcement agencies also investigate and prosecute cyber offences under applicable laws.

Role of CERT-In, I4C and the Data Protection Board of India

The responsibilities of these institutions differ according to the type of incident or legal issue involved:

  • CERT-In: Serves as India’s national agency for responding to cybersecurity incidents and performs functions assigned under Section 70B of the IT Act.
  • I4C: Coordinates efforts to address cybercrime across law enforcement agencies and supports the national cybercrime response framework.
  • Data Protection Board of India: Performs functions assigned under the DPDP Act, including examining specified breaches and determining penalties under the Act.

This division means that a cybersecurity incident, a cybercrime complaint, and a personal data protection matter may involve different authorities.

How to Report a Cybercrime in India

Cybercrime can be reported through the National Cybercrime Reporting Portal, which allows individuals to submit complaints online for cyber offences. For financial cyber fraud, reporting promptly through the 1930 helpline can help initiate the response process. Complaints can also be made to the relevant local police or law enforcement authority where appropriate.

When reporting an incident, retain relevant evidence such as transaction records, emails, messages, screenshots, phone numbers, URLs, and other details that can help investigators establish what happened.

Need Help Responding to a Cyber Incident?

Get expert incident response support from Eventus Security. 

Which Law Applies Today: The IT Act or the DPDP Act?

The IT Act and DPDP Act serve different purposes and are not interchangeable. The IT Act continues to apply within its existing scope, while the DPDP Act is being introduced through a phased commencement schedule.

DPDP Act Phased Rollout Timeline (2025–2027)

The DPDP framework is being implemented in stages:

Date Key development
13 November 2025 Initial provisions came into force.
13 November 2026 Further provisions relating to Consent Managers take effect.
13 May 2027 Core operational provisions are scheduled to commence.

Therefore, the DPDP Act is not simply a future law. Different provisions apply at different stages. 

IT Act vs DPDP Act: Side-by-Side Comparison

IT Act, 2000 DPDP Act, 2023
Covers electronic records and specified cyber offences Governs digital personal data processing
Includes intermediary-related provisions Establishes Data Principal rights
Contains specified government powers Establishes Data Fiduciary obligations
Applies within its statutory scope Applies according to its provisions and commencement schedule

The DPDP Act does not replace the IT Act as a whole. Each law addresses a different part of India’s digital legal framework.

What Businesses Should Do Before May 2027

Organisations handling digital personal data should use the transition period to map personal data, review processing practices, assess consent and notice mechanisms, strengthen safeguards, review third-party processing, and prepare processes for applicable Data Principal requests and grievances.

How Can Eventus Security Support Cybersecurity Operations?

Meeting cybersecurity responsibilities requires more than understanding applicable laws and regulations. Organisations also need the operational capability to continuously monitor their environments, identify suspicious activity, investigate potential incidents, and respond appropriately. Eventus Security provides 24/7 Managed SOC services supported by security monitoring, threat detection, investigation, threat hunting, and incident response capabilities.

Eventus Security’s Key Cybersecurity Operations Capabilities:

  • 24/7 Security Monitoring: Eventus Security continuously monitors networks, systems, and applications for security events and anomalies.
  • Threat Detection and Investigation: Its SOC collects and analyses security data from different sources to identify and investigate potential threats.
  • Threat Hunting: Eventus Security supports proactive threat hunting using methods such as IOC sweeping and MITRE ATT&CK TTP mapping.
  • Incident Response: Eventus Security supports incident triage, investigation, containment, remediation, and recovery as part of its incident response capabilities.
  • Incident Readiness: Eventus Security also supports incident response planning, playbooks, security-gap assessment, and related readiness activities.

Contact Eventus Security to discuss your organisation’s cybersecurity monitoring and incident response requirements.

FAQs

1. What is the way forward for cybersecurity laws in India?

India’s cybersecurity framework is expected to continue evolving as digital services, cyber threats, and data processing expand. The phased implementation of the DPDP Act, along with updates to related rules and directions, will require organisations to keep reviewing their cybersecurity and data protection practices.

2. Does the DPDP Act replace the IT Act?

No. The two laws serve different purposes. The IT Act addresses electronic records, specified cyber offences, and other technology-related matters, while the DPDP Act establishes a framework for processing digital personal data. The DPDP Act does not replace the IT Act as a whole.

3. Which cybersecurity laws apply to businesses in India?

The applicable requirements depend on the organisation’s activities, the type of data it handles, and the digital services it provides. Depending on these factors, businesses may need to consider the IT Act, DPDP Act, CERT-In Directions, and other applicable rules or sector-specific requirements.

4. What should businesses do before the DPDP Act takes full effect?

Businesses handling digital personal data should use the transition period to map their data, review processing practices, assess consent and notice mechanisms, strengthen security safeguards, review third-party processing, and prepare processes for applicable Data Principal rights and grievances.

Mohd Kaif Idrisi
Mohd Kaif Idrisi is a cybersecurity and GRC professional with experience in information security governance, risk management, compliance, and internal and external audits. He is a Certified ISO 27001:2022 Lead Auditor with experience across ISO 27001, ISO 9001, ISO 27035, SOC 2 Type II, Saudi NCA ECC, Qatar NIA, GDPR, DPDP, and PDPA.

Report an Incident

Report an Incident - Blog

free consultation

Our team of expert is available 24x7 to help any organization experiencing an active breach.

More Topics

crossmenuchevron-down
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram