India’s digital landscape has transformed dramatically over the past two decades. From early attempts at regulating online transactions to today’s comprehensive data protection regime, the country’s IT laws have evolved to address everything from cybercrime and electronic commerce to privacy and AI governance. At the heart of this legal ecosystem is the Information Technology Act, 2000 – India’s foundational cyber law – along with its amendments, subordinate rules, and the recently enacted Digital Personal Data Protection Act, 2023.

Table of Contents

The Information Technology Act, 2000: India’s foundational cyber law

The Information Technology Act, 2000 (IT Act) was notified on 17 October 2000, making India the 12th country in the world to enact dedicated legislation for cybercrimes and electronic commerce. The Act was modelled on the UNCITRAL Model Law on Electronic Commerce (1996), which called on all nations to develop their own legal frameworks for digital transactions.

The IT Act originally contained 94 sections spread across 13 chapters and 4 schedules. Its core objectives include giving legal recognition to electronic records and digital signatures, defining cybercrimes and prescribing penalties, securing electronic governance processes, and regulating certifying authorities for digital signatures.

Key provisions of the IT Act

The IT Act covers a wide range of digital activities. Section 3 grants legal validity to electronic records and digital signatures, treating them on par with paper documents and handwritten signatures. Sections 43 and 66 deal with unauthorised access to computer systems, data theft, and hacking, with prescribed penalties including imprisonment and fines. Section 65 addresses tampering with computer source documents, while Section 67 penalises the publication of obscene material in electronic form.

The Act also established important institutional mechanisms. It created the office of the Controller of Certifying Authorities to regulate the issuance of digital signatures. An adjudicating officer framework was set up to handle compensation claims related to cyber contraventions. Originally, the Act also created the Cyber Appellate Tribunal, which was later merged with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) following the Finance Act of 2017.

The 2008 amendment: expanding the scope

As technology evolved rapidly in the 2000s, the Indian Parliament recognised that the original IT Act needed significant updates. A major amendment was passed in December 2008 and signed into law by President Pratibha Patil on 5 February 2009. This amendment introduced several new provisions that significantly expanded the Act’s coverage.

The 2008 amendment introduced Sections 66A through 66F, covering new categories of offences. Section 66A dealt with sending offensive messages electronically – though this later became deeply controversial. Other notable additions included provisions on identity theft (Section 66C), cheating by impersonation using computers (Section 66D), violation of privacy (Section 66E), and cyber terrorism (Section 66F). The amendment also introduced provisions addressing child pornography and voyeurism.

Section 69 was another significant addition, granting government authorities the power to intercept, monitor, or decrypt information transmitted through any computer resource in the interest of national security. Section 69A empowered the government to block public access to websites for reasons related to sovereignty, integrity, or public order.

The amendment also introduced the concept of electronic signatures (Section 3A), broadening the earlier framework that only recognised digital signatures. This made it possible to incorporate newer authentication technologies as they emerged. Additionally, the amendment established that contracts formed through electronic means are legally valid and introduced Section 43A, making companies liable for negligent handling of sensitive personal data.

The Shreya Singhal case and Section 66A

Section 66A became one of the most debated provisions in Indian digital law. It penalised the sending of offensive or menacing messages electronically, but the section never clearly defined what constituted “offensive” content. This vagueness led to several controversial arrests. In March 2015, the Supreme Court of India struck down Section 66A in the landmark Shreya Singhal v. Union of India case, ruling that it disproportionately restricted the fundamental right to free speech under Article 19(1) of the Constitution. However, the Court upheld Sections 69A and 79, which deal with website blocking and intermediary liability respectively.

The IT Rules: intermediary guidelines and digital media ethics

Beyond the IT Act itself, the government has framed several subordinate rules that shape day-to-day digital regulation. The Information Technology (Intermediary Guidelines) Rules, 2011 initially laid down the obligations of online platforms. These were substantially replaced by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which made social media platforms, news portals, and other digital intermediaries far more accountable for the content published on their platforms.

Further updates through the IT Amendment Rules, 2023 introduced guidelines for online gaming platforms and established requirements around fact-checking of government-related information. Online gaming platforms were required to register with a Self-Regulatory Body (SRB) to ensure compliance with legal standards and the exclusion of gambling elements.

MeitY: the engine behind India’s IT policy

The Ministry of Electronics and Information Technology (MeitY) is India’s nodal agency for formulating and implementing national policies related to electronics, IT, and cybersecurity. It functions as a promoter, facilitator, and regulator of the country’s digital ecosystem.

Key roles and initiatives

MeitY’s mandate covers a broad spectrum. It oversees the implementation of the IT Act and its subordinate rules, drives the Digital India programme, promotes e-governance, and supports the development of emerging technologies including AI, blockchain, and the Internet of Things.

Some of MeitY’s most impactful initiatives include the following. The Digital India programme has been transformative, with platforms like Aadhaar (over 138 crore numbers generated), UPI (facilitating over 24,100 crore financial transactions as of mid-2024), and DigiLocker (over 37 crore registered users) forming the backbone of India’s digital public infrastructure. The Common Services Centres (CSCs), numbering over 5.84 lakh across the country, deliver more than 800 government services to rural areas, bridging the digital divide at the grassroots level.

In cybersecurity, MeitY runs the Cyber Surakshit Bharat initiative to train Chief Information Security Officers (CISOs) and government IT officials. In 2024 alone, over 250 officials participated in CISO training programmes, and a dedicated workshop in Kerala trained more than 100 state officials. MeitY also notified 15 forensic laboratories as official examiners of electronic evidence under Section 79A of the IT Act.

The Indian Computer Emergency Response Team (CERT-In), designated under the 2008 amendment, serves as the national agency for cybersecurity incident response. It issues guidelines, tracks threats, and coordinates responses to cyber incidents across sectors.

E-governance and digital infrastructure

MeitY’s push for e-governance is backed by substantial digital infrastructure. The National Informatics Centre (NIC) operates data centres in cities like Delhi, Pune, Bhubaneswar, and Hyderabad, with storage capacity exceeding 100 petabytes. The GI Cloud (MeghRaj) initiative provides cloud services to over 300 government departments, while API Setu has facilitated more than 312 crore transactions through over 6,000 government APIs. A new Tier-III data centre in Guwahati is being set up to strengthen digital resilience in India’s northeastern region.

Platforms like UMANG (serving over 7.12 crore users with 2,077 government services across 32 states), e-Hastakshar (issuing over 81.97 crore digital signatures), and MyGov (with over 4.89 crore registered users) reflect MeitY’s commitment to citizen-centric digital governance.

The Digital Personal Data Protection Act, 2023

For years, India lacked a standalone data protection law. The IT Act’s Section 43A and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 provided limited protections but were widely considered insufficient for a country with over 850 million internet users.

The journey towards a comprehensive data protection law began in earnest in 2017, when the Supreme Court of India, in Justice K.S. Puttaswamy v. Union of India, affirmed that privacy is a fundamental right under Article 21 of the Constitution. This landmark ruling catalysed the legislative process.

From committee reports to legislation

Following the Puttaswamy judgment, the government constituted the Justice B.N. Srikrishna Committee to study data protection issues. The committee submitted its report in July 2018, leading to the Personal Data Protection Bill, 2019. After being referred to a Joint Parliamentary Committee and receiving extensive criticism, the 2019 Bill was withdrawn in August 2022. A fresh draft was released for public consultation in November 2022, and the revised Digital Personal Data Protection Bill, 2023 was introduced in Parliament in August 2023. It was passed by both houses and received presidential assent on 11 August 2023.

Key features of the DPDP Act

The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to digital personal data collected online within India, as well as offline data that is subsequently digitised. It also has extra-territorial applicability for entities offering goods or services to individuals in India.

The Act revolves around two key concepts. Data Principals are individuals whose personal data is being processed, while Data Fiduciaries are entities (including companies and government bodies) that determine the purpose and means of processing. Data Fiduciaries must obtain informed consent before collecting personal data, maintain data accuracy, implement reasonable security safeguards, report breaches to the Data Protection Board of India within 72 hours, and delete personal data once its purpose is fulfilled.

Data Principals have the right to access information about how their data is processed, seek correction and erasure of personal data, nominate a person to exercise their data rights, and file grievances with the Data Protection Board. Penalties under the Act are significant – up to Rs 250 crore for failure to implement adequate security measures and up to Rs 200 crore for violations involving children’s data.

The DPDP Rules, 2025 and phased implementation

On 13 November 2025, MeitY notified the Digital Personal Data Protection Rules, 2025, which operationalise the DPDP Act. The rules are being implemented in phases over a 12-18 month timeline. Until the core provisions of the DPDP Act are fully operational (expected by May 2027), the older IT Act privacy rules will continue to apply in parallel. The DPDP Act replaces Section 43A of the IT Act and the 2011 Privacy Rules, marking India’s transition to a modern, consent-driven data protection regime.

One notable difference from the EU’s GDPR is that the DPDP Act applies exclusively to digital personal data and does not create a separate category for sensitive personal data. The Act also allows cross-border data transfers except to countries specifically restricted by the central government – an approach that differs from the GDPR’s adequacy-based framework.

Emerging challenges in India’s cybersecurity landscape

Despite the robust legal framework, India faces several ongoing challenges in the digital space.

Rising cybercrime

India has witnessed a sharp rise in cybercrimes including phishing, ransomware attacks, identity theft, and financial fraud. As digital transactions grow – UPI alone processes billions of transactions – the attack surface for cybercriminals expands proportionally. The government’s response includes CERT-In’s expanded mandate, the Cyber Surakshit Bharat initiative, and the notification of forensic labs for electronic evidence examination.

AI governance

In November 2025, MeitY unveiled AI Governance Guidelines under the IndiaAI mission, adopting a sectoral regulatory approach rather than a single umbrella law. This means regulators like the RBI, SEBI, and IRDAI will frame AI-specific rules for their respective sectors. While this approach encourages innovation, questions remain about how existing legal definitions under the IT Act (such as “intermediary” and “computer system”) will apply to AI-specific entities like developers, deployers, and autonomous systems.

Data localisation and cross-border transfers

The DPDP Act’s permissive stance on international data transfers – allowing transfers to all countries except those explicitly restricted – continues to generate debate. Critics argue that without a rigorous adequacy assessment mechanism, personal data of Indian citizens transferred abroad may not receive equivalent protection. The government is expected to issue further notifications on restricted countries and on the designation of Significant Data Fiduciaries who will face enhanced compliance obligations.

Balancing surveillance and privacy

Sections 69 and 69A of the IT Act grant the government broad powers to intercept communications and block websites. While these provisions were upheld by the Supreme Court in the Shreya Singhal case, the absence of a separate law governing bulk surveillance – unlike countries such as the UK, which has the Investigatory Powers Act – remains a concern among privacy advocates. The exemptions granted to government agencies under the DPDP Act for national security purposes add another layer to this ongoing debate.

Looking ahead

India’s IT legal framework has come a long way from the IT Act of 2000. The enactment of the DPDP Act, 2023 and notification of the DPDP Rules in 2025 represent a significant milestone – India now has a dedicated, consent-driven data protection regime aligned with global standards. MeitY’s expanding role in promoting AI governance, strengthening cybersecurity infrastructure, and enabling digital public services ensures that the regulatory framework keeps pace with technological change.

However, the real test lies in implementation. The phased rollout of the DPDP Act, the evolving nature of AI regulation, and the persistent challenges of cybercrime and digital surveillance will shape how effectively India’s IT laws protect citizens while fostering innovation.

What do you think? As India implements the DPDP Act in phases, do you believe the current framework adequately balances individual privacy rights with the government’s need for data access in the interest of national security? And with AI regulation being left to individual sector regulators, will a decentralised approach work effectively, or does India eventually need a unified AI law?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
  2. https://uncitral.un.org/en/texts/ecommerce/modellaw/electronic_commerce
  3. https://www.meity.gov.in/content/information-technology-act-2000
  4. https://blog.ipleaders.in/information-technology-act-2000/
  5. https://en.wikipedia.org/wiki/Information_Technology_Act,_2000
  6. https://vajiramandravi.com/upsc-exam/information-technology-act-2000/
  7. https://www.digitalindia.gov.in/
  8. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2088990
  9. https://en.wikipedia.org/wiki/Digital_Personal_Data_Protection_Act,_2023
  10. https://prsindia.org/billtrack/digital-personal-data-protection-bill-2023
  11. https://www.hoganlovells.com/en/publications/indias-digital-personal-data-protection-act-2023-brought-into-force-
  12. https://chambers.com/articles/meity-unveils-india-s-approach-towards-regulating-artificial-intelligence
  13. https://www.dlapiperdataprotection.com/?t=law&c=IN

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Digital Media

1 Internet as a Medium

  1. Internet as a Medium of Communication
  2. Conceptual Framework of Cyberspace
  3. Functional Dimensions of Cyberspace
  4. Characteristics of Cyberspace
  5. Types of Internet-Based Communication
  6. Dynamics of Communication Process in CMC
  7. Forms of Computer-Mediated Communication
  8. Virtual Communities

2 Digital Media and Society

  1. Digital Media in Society
  2. Understanding Digital Media
  3. Evolution and Development of Digital Media
  4. Concepts and Theories of Digital Media
  5. Medium Specific Trends
  6. Revolution within the Media Landscape
  7. Effects of Digital Media

3 Issues of Access and Participation

  1. Digital (In)Equality: Conceptual Framework
  2. Evolution and Development of ICT
  3. Growth and Diffusion of ICT
  4. Digital Divide
  5. Initiatives to Bridge the Digital Divide in India

4 Policy Framework and Regulation

  1. Digital Media Framework in India
  2. ICT Policies of India
  3. Regulatory Body
  4. IT Laws and Rules
  5. Agencies Involved in Cyber Security
  6. Social Media Guidelines

5 Spectrum of Social Media

  1. Understanding Social Media
  2. Social Media in India
  3. Social Media Etiquettes
  4. Uses of Social Media
  5. Socio Cultural and Economic Impact of Social Media

6 Online News Sharing

  1. Social Media and Interactivity
  2. Content Sharing
  3. Social Media Tools and Engagement
  4. Impact of News Sharing on Mainstream Media
  5. Fake News on Social Media

7 Social Media Audience

  1. Audience – The Term and Concept
  2. Social Media Audience
  3. Theories of Audience
  4. Marketing and Social Media Audience

8 Applications of Social Media

  1. Social Media and Governance
  2. Social Media and Business Organisations
  3. Social Media Politics and Development
  4. Social Media Arts Culture and Education

9 Internet and Marginalised sections

  1. Understanding Marginalisation and the Marginalised
  2. Digital Media Platforms: Conceptual Understanding
  3. Representations and Presentations
  4. Internet and Marginalised Sections: Case Studies

10 Praticipatory Online Media

  1. Approaches to Participation
  2. Online Participation and Engagement
  3. Youth Participatory Culture and Media Literacy
  4. Digital Media and Empowerment
  5. Role of Social Media in Online Participatory Communication
  6. Experiments/Stories from India

11 Online Activism

  1. Understanding Online Activism
  2. Activism and Social Movements
  3. Technology and Activism/Social Movements
  4. Characteristics of Online Activism
  5. Online Activism and Social Change

12 Democracy and Digital Media

  1. Understanding Concepts of Democracy
  2. Linkages between Democracy and Digital Media
  3. Avenues of Linkages
  4. Citizen Journalism and Social Change
  5. Experiences of Interplay

13 ICT for Education

  1. Scope of ICT in Education
  2. ICT in Education: Major Requirements
  3. ICT in Education: Indian Scenario
  4. Integration of ICT in Education: Issues and Challenges

14 Health and ICT

  1. Health Sector and ICT
  2. Health Information Online
  3. Strategies for Health Communication
  4. Skill Acquisition in Health-Theory and Models
  5. Barriers to Health Information Literacy

15 E-Goverance

  1. Concept of E-governance
  2. Stages of E-governance
  3. Models of E-governance
  4. Legal and Policy Framework
  5. Significance of E-governance
  6. Challenges and Opportunities

16 Entrepreneurship and Digital Media

  1. Entrepreneurship
  2. Digital Media
  3. Opportunities and Challenges for a Media Student
  4. Critique of Technology Aided Business Model