In 2023, India recorded over 1.3 million cybersecurity incidents – many of them orchestrated by individuals sitting thousands of kilometres outside Indian borders. A phishing site targeting Indian bank customers can be operated from Eastern Europe. Ransomware crippling a Mumbai hospital’s servers can be deployed from Southeast Asia. The criminal is physically absent; the damage is very much present. This raises a critical legal question: can India’s law reach beyond its borders to hold such offenders accountable? The answer lies in two provisions of the Information Technology Act, 2000 – Section 1(2) and Section 75 – which together give India’s cyber law an extra-territorial arm.
Table of Contents
- Applicability across India and beyond
- The nexus with Indian computer resources: understanding Section 75
- How the Indian nexus works in practice
- Prescriptive jurisdiction vs. enforcement jurisdiction
- Addressing borderless cybercrime: why this provision exists
- The challenge of enforcement in practice
- The deterrence value of extra-territorial law
Applicability across India and beyond
The foundation of the IT Act’s geographic reach is established right at the start of the statute. Section 1(2) of the IT Act, 2000 states that the Act extends to the whole of India and also applies to any offence or contravention committed outside India by any person. This is not just domestic housekeeping – it is a deliberate legislative signal that India’s cyber law is designed to function in a world without digital borders.
The critical phrase here is “any person”. The Act does not restrict its scope to Indian citizens. A foreign national – a hacker in Russia, a fraudster in Nigeria, a data thief in Romania – can all fall within the purview of the IT Act if the right conditions are met. Legal analysts note that the nationality of the offender is entirely irrelevant; what matters is the nature and location of the digital harm caused.
This approach marks a significant departure from the classical principle of territorial jurisdiction, where a state’s laws were assumed to govern only what happened within its physical borders. Cyberspace, by its very nature, makes that principle inadequate. The IT Act’s framers understood this and built in an explicit extra-territorial mechanism from the outset.
The nexus with Indian computer resources: understanding Section 75
The extra-territorial reach of the IT Act is not a blanket power. It is governed by a specific condition, and that condition is spelled out in Section 75 of the IT Act. The provision reads that the Act shall apply to an offence or contravention committed outside India if the act or conduct constituting the offence or contravention involves a computer, computer system or computer network located in India.
This is the legal test – the “Indian nexus”. The law is not concerned with where the offender is sitting. It is concerned with where the targeted digital infrastructure is located. If a computer, server, or network physically situated in India is involved in the commission of the offence, Indian courts acquire jurisdiction, regardless of the offender’s nationality or location.
How the Indian nexus works in practice
Consider a few concrete scenarios to understand how this plays out. A cybercriminal group operating from abroad launches an attack on the customer database of a major Indian bank. The bank’s servers are housed in a data centre in Hyderabad. Even though the criminals never set foot in India, the attack involves a computer system located in India – Section 75 applies. Or consider a former employee who relocates abroad but uses retained login credentials to access their old company’s cloud infrastructure, which is managed from India. The physical act of unauthorised access happened outside India, but the network involved is located in India. Again, Section 75 is triggered.
According to Baker McKenzie’s Global Data and Cyber Handbook, the provisions of the IT Act extend to any offence committed outside India by any person, irrespective of nationality, as long as the conduct involves a computer or computer system located in India. This “location of the digital victim” test is what makes the provision both precise and powerful.
It is also worth noting that legal commentary by Khaitan & Co published on Lexology points out that Section 75 is broader in scope than the corresponding provision under the Indian Penal Code (Section 4(3)), because it grants jurisdiction not just where a computer resource is targeted, but wherever the conduct involves a computer or network in India – a meaningfully wider formulation.
Prescriptive jurisdiction vs. enforcement jurisdiction
It is important to be clear-eyed about what Section 75 actually does – and what it does not do. Legal scholars draw a distinction between prescriptive jurisdiction (the authority to make a law that applies to certain conduct) and enforcement jurisdiction (the physical ability to arrest, prosecute, and punish an offender). Section 75 grants India the former. It does not – and cannot – grant the latter unilaterally.
Indian police cannot cross into another country’s territory to arrest a foreign national. That would violate the other nation’s sovereignty. What Section 75 does instead is give India a credible legal basis to engage diplomatically. When Indian agencies like the CBI identify a foreign-based suspect, they can approach that country’s authorities and demonstrate that the suspect has violated a specific provision of Indian law – one that India has explicit legislative authority to apply. From there, mechanisms like Mutual Legal Assistance Treaties (MLATs) come into play.
Bhatt & Joshi Associates note that India has signed MLATs with over 40 countries, including the United States, the United Kingdom, Canada, and Australia. Through these treaties, Indian law enforcement can formally request foreign authorities to share digital evidence, preserve data, or initiate extradition proceedings. Section 75 is the domestic legal anchor that makes those international requests legitimate.
Addressing borderless cybercrime: why this provision exists
The rationale behind Section 75 is rooted in a basic technological reality: the internet has no borders, but its consequences do. A cyberattack can originate anywhere and land anywhere. Ransomware deployed from one continent can encrypt hospital records on another. A fraudulent e-commerce site hosted abroad can siphon money from Indian consumers without ever being physically present in the country.
As a study published in the International Journal of Innovative Research in International Law observes, the borderless nature of cyberspace often conflicts with the territorial jurisdiction of law enforcement agencies, creating delays and jurisdictional disputes. This mismatch is particularly sharp when the perpetrator, the victim, and the digital infrastructure are each located in different countries. Without a provision like Section 75, a foreign national committing cybercrimes against Indian systems from abroad would effectively be immune from Indian law – a legally untenable and practically dangerous situation.
The provision also reflects the “effects doctrine” – a principle in international law that holds a state may claim jurisdiction over acts committed abroad when those acts produce harmful effects within its territory. Section 75 codifies this doctrine specifically for cyberspace, anchoring it to the concrete and verifiable criterion of where the affected computer resource is physically located.
The challenge of enforcement in practice
Despite the clear legal logic of Section 75, its real-world application faces persistent hurdles. Legal researchers have flagged that enforcement challenges remain significant, particularly due to cross-border complexities, inconsistent international cooperation, and the reluctance of some global technology companies to comply promptly with Indian law enforcement requests.
MLATs, while useful, are often slow. The Centre for Internet and Society has documented that MLAT processes can take upwards of ten months to yield results, by which time critical digital evidence may have been deleted, overwritten, or moved. Cybercriminals routinely use VPNs, the dark web, and proxy servers to obscure their location, further complicating the identification and attribution process.
India is also not a signatory to the Budapest Convention on Cybercrime – the primary international treaty on the subject, adopted by the Council of Europe in 2001 and now joined by dozens of nations including the US, UK, Japan, and most EU members. This limits India’s ability to engage in the streamlined, multilateral cooperation that signatories enjoy, forcing it to rely on bilateral arrangements that vary widely in speed and effectiveness.
The deterrence value of extra-territorial law
Even with these enforcement limitations, Section 75 serves a meaningful deterrent function. The knowledge that a foreign offender can be identified, named, and legally pursued under Indian law – and that India has formal channels to seek their prosecution abroad – introduces a non-trivial legal risk for would-be cybercriminals. Legal analysts at TheLaw.Institute note that while enforcement challenges exist, the possibility of prosecution under Indian law may discourage some cybercriminals from targeting Indian systems in the first place. This deterrence effect works alongside technical cybersecurity measures to create a multi-layered national defence.
As India’s digital economy continues to expand – with millions of new internet users, expanding fintech infrastructure, and increasing volumes of sensitive data stored on Indian servers – the relevance of Section 75 will only grow. The provision represents India’s assertion that its digital sovereignty does not stop at the airport. Where Indian computer resources are involved, Indian law follows.
What do you think? As cyberattacks increasingly originate from foreign soil, should India consider joining the Budapest Convention to strengthen its cross-border enforcement capabilities? And is anchoring jurisdiction to the physical location of a server still a practical standard in an era of cloud computing, where data is distributed across dozens of locations simultaneously?
References
- https://www.cert-in.org.in/
- https://indiankanoon.org/doc/1354589/
- https://www.legalserviceindia.com/legal/article-3329-analysis-of-cyber-jurisdiction-in-india.html
- https://indiankanoon.org/doc/576992/
- https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/asia-pacific/india/topics/territorial-scope
- https://www.lexology.com/library/detail.aspx?g=9fa6c473-904f-4fa6-8890-a28fc846edc8
- https://bhattandjoshiassociates.com/cybercrime-jurisdiction-issues-challenges-in-prosecuting-cross-border-cybercrimes-in-india/
- https://ijirl.com/wp-content/uploads/2025/03/ADJUDICATING-AND-INVESTIGATING-CROSS-BORDER-CYBERCRIMES-A-STUDY-OF-INDIAS-JURISDICTIONAL-FRAMEWORK.pdf
- https://drbtaneja.com/jurisdiction-under-the-information-technology-it-act-2000/
- https://cis-india.org/internet-governance/blog/cross-border-cooperation-on-criminal-matters
- https://www.coe.int/en/web/cybercrime/the-budapest-convention
- https://thelaw.institute/regulation-of-cyberspace/it-act-extra-territorial-application-reach-borders/
Leave a Reply