Cyber Law & Data Protection
Every organisation that operates digitally carries exposure under India’s cyber law framework. Data breaches, ransomware, business email compromise, unauthorised access, and payment fraud are ordinary operational risks, and they carry legal consequences that arrive quickly — reporting obligations measured in hours, not weeks.
For individuals, the range runs from online harassment and impersonation to financial fraud and coordinated reputational attack. In each of these the first forty-eight hours largely determine what can be recovered and what can be proved.
The firm advises organisations and individuals across this field — on the compliance architecture before an incident, on the response during one, and on civil and criminal proceedings afterwards.
Offences Under the Information Technology Act, 2000
The Act, as amended in 2008, creates offences including unauthorised access and damage to a computer resource (Section 66), identity theft (Section 66C), cheating by personation using a computer resource (Section 66D), violation of privacy (Section 66E), cyber terrorism (Section 66F), and publication or transmission of obscene material in electronic form (Sections 67, 67A and 67B). We act for complainants and for accused persons, including in applications for anticipatory bail under Section 482 BNSS (formerly Section 438 CrPC) and regular bail under Section 483 BNSS (formerly Section 439 CrPC).
Electronic evidence carries its own difficulties. The admissibility of an electronic record depends on compliance with the certification requirement now contained in Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (formerly Section 65B of the Indian Evidence Act, 1872), and a prosecution or a defence that neglects it is exposed. Preservation of the original device and of the chain of custody matters from the first day.
Breach Reporting — What Is Actually in Force
The live obligation today is the CERT-In direction. Under the directions issued in April 2022 under Section 70B(6) of the Information Technology Act, 2000, specified cyber security incidents must be reported to the Indian Computer Emergency Response Team within six hours of being noticed or brought to notice. This applies now, and it is the reporting obligation that an organisation suffering an incident must meet first.
The Digital Personal Data Protection Act, 2023 is being brought into force in stages. The Digital Personal Data Protection Rules were notified on 13 November 2025. The provisions relating to the Data Protection Board of India and appeals commenced on notification; the consent manager provisions commence in November 2026; and the substantive obligations — notice, consent, purpose limitation, security safeguards, retention and erasure, the rights of data principals, the additional duties of significant data fiduciaries, and personal data breach intimation — commence in May 2027.
The practical consequence is that an organisation must comply with the CERT-In six-hour direction today, and should be building its DPDP compliance architecture now against a fixed 2027 date. We advise on both, and on the interaction between them.
Several commercial commentaries currently describe the DPDP seventy-two-hour reporting duty as though it were already enforceable. It is not. The page above states the position correctly. Confirm the commencement dates before publication, as the phasing is by notification and can be altered.
Data Protection Advisory
We advise data fiduciaries on the obligations the Act will impose — the notice and consent architecture, the grounds for processing, purpose limitation and retention, processor contracts, the position on children’s data, cross-border transfer, and the additional obligations that attach to a significant data fiduciary including data protection impact assessment and audit. We also advise on the incident response plan, on the breach intimation content, and on the interaction with sectoral regulation and with contractual data obligations to customers.
Online Fraud
For victims of payment fraud, phishing, investment fraud and account takeover, speed determines recovery. A complaint on the National Cyber Crime Reporting Portal and to the relevant bank should be made immediately, since the prospect of a freeze on the destination account falls away rapidly. We advise on the immediate steps, on the complaint and the FIR, on representations to the bank and to the payment system operator, and on civil proceedings for recovery where the criminal route will not restore the funds.
Online Defamation and Reputational Attack
Civil and criminal remedies for defamatory publication online, including a suit for damages and injunction, a complaint of defamation under Section 356 of the Bharatiya Nyaya Sanhita, 2023 (formerly Section 499 of the Indian Penal Code), and requests for removal or disabling of access directed to the intermediary under the Information Technology Act and the Intermediary Guidelines. Where the attack is coordinated, the strategy has to be sequenced — an ill-judged first step frequently amplifies what it was meant to suppress.
Cross-Border Incidents
Cyber incidents are rarely confined to one jurisdiction. Where evidence, infrastructure or the perpetrator sits abroad, we co-ordinate with independent firms in Dubai, Singapore, the United Kingdom and the United States on evidence preservation requests, mutual legal assistance, and parallel civil proceedings where those are available and worthwhile.
Have questions? talk to our eye specialist.
What must an organisation do immediately after a cyber incident?
Contain the incident, preserve evidence including logs and images of affected systems, notify the insurer, and report to CERT-In within six hours where the incident falls within the specified categories. Take legal advice before any public statement or customer communication. Contractual notification obligations to customers and to regulators in other jurisdictions should be checked at the same time.
Is the seventy-two-hour data breach report to the Data Protection Board in force?
Not yet. The Digital Personal Data Protection Rules were notified in November 2025, but the personal data breach intimation provisions commence in May 2027. The obligation in force today is the CERT-In six-hour direction under the Information Technology Act, 2000.
Can money lost to online fraud be recovered?
Sometimes, and almost always only if action is immediate. Prompt reporting on the National Cyber Crime Reporting Portal and to the bank allows an attempt to freeze the destination account before the funds are layered away. Recovery prospects fall sharply with delay. Separate questions of the bank’s liability may also arise depending on the circumstances of the transaction.
Is online defamation a criminal offence?
Yes. Defamation is an offence under Section 356 of the Bharatiya Nyaya Sanhita, 2023, and publication in electronic form may attract additional liability. A civil suit for damages and injunction may be brought at the same time, and in most cases the civil route is the one that actually removes the material.
This page is provided for general information about the firm’s areas of practice. It is not legal advice, and no advocate–client relationship arises from reading it or from an enquiry. The law stated is current as at the date of publication and may change.

