India’s digital landscape has transformed dramatically over the past two decades. From early attempts at regulating online transactions to today’s comprehensive data protection regime, the country’s IT laws have evolved to address everything from cybercrime and electronic commerce to privacy and AI governance. At the heart of this legal ecosystem is the Information Technology Act, 2000 – India’s foundational cyber law – along with its amendments, subordinate rules, and the recently enacted Digital Personal Data Protection Act, 2023.
Table of Contents
- The Information Technology Act, 2000: India’s foundational cyber law
- Key provisions of the IT Act
- The 2008 amendment: expanding the scope
- The Shreya Singhal case and Section 66A
- The IT Rules: intermediary guidelines and digital media ethics
- MeitY: the engine behind India’s IT policy
- Key roles and initiatives
- E-governance and digital infrastructure
- The Digital Personal Data Protection Act, 2023
- From committee reports to legislation
- Key features of the DPDP Act
- The DPDP Rules, 2025 and phased implementation
- Emerging challenges in India’s cybersecurity landscape
- Rising cybercrime
- AI governance
- Data localisation and cross-border transfers
- Balancing surveillance and privacy
- Looking ahead
The Information Technology Act, 2000: India’s foundational cyber law
The Information Technology Act, 2000 (IT Act) was notified on 17 October 2000, making India the 12th country in the world to enact dedicated legislation for cybercrimes and electronic commerce. The Act was modelled on the UNCITRAL Model Law on Electronic Commerce (1996), which called on all nations to develop their own legal frameworks for digital transactions.
The IT Act originally contained 94 sections spread across 13 chapters and 4 schedules. Its core objectives include giving legal recognition to electronic records and digital signatures, defining cybercrimes and prescribing penalties, securing electronic governance processes, and regulating certifying authorities for digital signatures.
Key provisions of the IT Act
The IT Act covers a wide range of digital activities. Section 3 grants legal validity to electronic records and digital signatures, treating them on par with paper documents and handwritten signatures. Sections 43 and 66 deal with unauthorised access to computer systems, data theft, and hacking, with prescribed penalties including imprisonment and fines. Section 65 addresses tampering with computer source documents, while Section 67 penalises the publication of obscene material in electronic form.
The Act also established important institutional mechanisms. It created the office of the Controller of Certifying Authorities to regulate the issuance of digital signatures. An adjudicating officer framework was set up to handle compensation claims related to cyber contraventions. Originally, the Act also created the Cyber Appellate Tribunal, which was later merged with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) following the Finance Act of 2017.
The 2008 amendment: expanding the scope
As technology evolved rapidly in the 2000s, the Indian Parliament recognised that the original IT Act needed significant updates. A major amendment was passed in December 2008 and signed into law by President Pratibha Patil on 5 February 2009. This amendment introduced several new provisions that significantly expanded the Act’s coverage.
The 2008 amendment introduced Sections 66A through 66F, covering new categories of offences. Section 66A dealt with sending offensive messages electronically – though this later became deeply controversial. Other notable additions included provisions on identity theft (Section 66C), cheating by impersonation using computers (Section 66D), violation of privacy (Section 66E), and cyber terrorism (Section 66F). The amendment also introduced provisions addressing child pornography and voyeurism.
Section 69 was another significant addition, granting government authorities the power to intercept, monitor, or decrypt information transmitted through any computer resource in the interest of national security. Section 69A empowered the government to block public access to websites for reasons related to sovereignty, integrity, or public order.
The amendment also introduced the concept of electronic signatures (Section 3A), broadening the earlier framework that only recognised digital signatures. This made it possible to incorporate newer authentication technologies as they emerged. Additionally, the amendment established that contracts formed through electronic means are legally valid and introduced Section 43A, making companies liable for negligent handling of sensitive personal data.
The Shreya Singhal case and Section 66A
Section 66A became one of the most debated provisions in Indian digital law. It penalised the sending of offensive or menacing messages electronically, but the section never clearly defined what constituted “offensive” content. This vagueness led to several controversial arrests. In March 2015, the Supreme Court of India struck down Section 66A in the landmark Shreya Singhal v. Union of India case, ruling that it disproportionately restricted the fundamental right to free speech under Article 19(1) of the Constitution. However, the Court upheld Sections 69A and 79, which deal with website blocking and intermediary liability respectively.
The IT Rules: intermediary guidelines and digital media ethics
Beyond the IT Act itself, the government has framed several subordinate rules that shape day-to-day digital regulation. The Information Technology (Intermediary Guidelines) Rules, 2011 initially laid down the obligations of online platforms. These were substantially replaced by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which made social media platforms, news portals, and other digital intermediaries far more accountable for the content published on their platforms.
Further updates through the IT Amendment Rules, 2023 introduced guidelines for online gaming platforms and established requirements around fact-checking of government-related information. Online gaming platforms were required to register with a Self-Regulatory Body (SRB) to ensure compliance with legal standards and the exclusion of gambling elements.
MeitY: the engine behind India’s IT policy
The Ministry of Electronics and Information Technology (MeitY) is India’s nodal agency for formulating and implementing national policies related to electronics, IT, and cybersecurity. It functions as a promoter, facilitator, and regulator of the country’s digital ecosystem.
Key roles and initiatives
MeitY’s mandate covers a broad spectrum. It oversees the implementation of the IT Act and its subordinate rules, drives the Digital India programme, promotes e-governance, and supports the development of emerging technologies including AI, blockchain, and the Internet of Things.
Some of MeitY’s most impactful initiatives include the following. The Digital India programme has been transformative, with platforms like Aadhaar (over 138 crore numbers generated), UPI (facilitating over 24,100 crore financial transactions as of mid-2024), and DigiLocker (over 37 crore registered users) forming the backbone of India’s digital public infrastructure. The Common Services Centres (CSCs), numbering over 5.84 lakh across the country, deliver more than 800 government services to rural areas, bridging the digital divide at the grassroots level.
In cybersecurity, MeitY runs the Cyber Surakshit Bharat initiative to train Chief Information Security Officers (CISOs) and government IT officials. In 2024 alone, over 250 officials participated in CISO training programmes, and a dedicated workshop in Kerala trained more than 100 state officials. MeitY also notified 15 forensic laboratories as official examiners of electronic evidence under Section 79A of the IT Act.
The Indian Computer Emergency Response Team (CERT-In), designated under the 2008 amendment, serves as the national agency for cybersecurity incident response. It issues guidelines, tracks threats, and coordinates responses to cyber incidents across sectors.
E-governance and digital infrastructure
MeitY’s push for e-governance is backed by substantial digital infrastructure. The National Informatics Centre (NIC) operates data centres in cities like Delhi, Pune, Bhubaneswar, and Hyderabad, with storage capacity exceeding 100 petabytes. The GI Cloud (MeghRaj) initiative provides cloud services to over 300 government departments, while API Setu has facilitated more than 312 crore transactions through over 6,000 government APIs. A new Tier-III data centre in Guwahati is being set up to strengthen digital resilience in India’s northeastern region.
Platforms like UMANG (serving over 7.12 crore users with 2,077 government services across 32 states), e-Hastakshar (issuing over 81.97 crore digital signatures), and MyGov (with over 4.89 crore registered users) reflect MeitY’s commitment to citizen-centric digital governance.
The Digital Personal Data Protection Act, 2023
For years, India lacked a standalone data protection law. The IT Act’s Section 43A and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 provided limited protections but were widely considered insufficient for a country with over 850 million internet users.
The journey towards a comprehensive data protection law began in earnest in 2017, when the Supreme Court of India, in Justice K.S. Puttaswamy v. Union of India, affirmed that privacy is a fundamental right under Article 21 of the Constitution. This landmark ruling catalysed the legislative process.
From committee reports to legislation
Following the Puttaswamy judgment, the government constituted the Justice B.N. Srikrishna Committee to study data protection issues. The committee submitted its report in July 2018, leading to the Personal Data Protection Bill, 2019. After being referred to a Joint Parliamentary Committee and receiving extensive criticism, the 2019 Bill was withdrawn in August 2022. A fresh draft was released for public consultation in November 2022, and the revised Digital Personal Data Protection Bill, 2023 was introduced in Parliament in August 2023. It was passed by both houses and received presidential assent on 11 August 2023.
Key features of the DPDP Act
The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to digital personal data collected online within India, as well as offline data that is subsequently digitised. It also has extra-territorial applicability for entities offering goods or services to individuals in India.
The Act revolves around two key concepts. Data Principals are individuals whose personal data is being processed, while Data Fiduciaries are entities (including companies and government bodies) that determine the purpose and means of processing. Data Fiduciaries must obtain informed consent before collecting personal data, maintain data accuracy, implement reasonable security safeguards, report breaches to the Data Protection Board of India within 72 hours, and delete personal data once its purpose is fulfilled.
Data Principals have the right to access information about how their data is processed, seek correction and erasure of personal data, nominate a person to exercise their data rights, and file grievances with the Data Protection Board. Penalties under the Act are significant – up to Rs 250 crore for failure to implement adequate security measures and up to Rs 200 crore for violations involving children’s data.
The DPDP Rules, 2025 and phased implementation
On 13 November 2025, MeitY notified the Digital Personal Data Protection Rules, 2025, which operationalise the DPDP Act. The rules are being implemented in phases over a 12-18 month timeline. Until the core provisions of the DPDP Act are fully operational (expected by May 2027), the older IT Act privacy rules will continue to apply in parallel. The DPDP Act replaces Section 43A of the IT Act and the 2011 Privacy Rules, marking India’s transition to a modern, consent-driven data protection regime.
One notable difference from the EU’s GDPR is that the DPDP Act applies exclusively to digital personal data and does not create a separate category for sensitive personal data. The Act also allows cross-border data transfers except to countries specifically restricted by the central government – an approach that differs from the GDPR’s adequacy-based framework.
Emerging challenges in India’s cybersecurity landscape
Despite the robust legal framework, India faces several ongoing challenges in the digital space.
Rising cybercrime
India has witnessed a sharp rise in cybercrimes including phishing, ransomware attacks, identity theft, and financial fraud. As digital transactions grow – UPI alone processes billions of transactions – the attack surface for cybercriminals expands proportionally. The government’s response includes CERT-In’s expanded mandate, the Cyber Surakshit Bharat initiative, and the notification of forensic labs for electronic evidence examination.
AI governance
In November 2025, MeitY unveiled AI Governance Guidelines under the IndiaAI mission, adopting a sectoral regulatory approach rather than a single umbrella law. This means regulators like the RBI, SEBI, and IRDAI will frame AI-specific rules for their respective sectors. While this approach encourages innovation, questions remain about how existing legal definitions under the IT Act (such as “intermediary” and “computer system”) will apply to AI-specific entities like developers, deployers, and autonomous systems.
Data localisation and cross-border transfers
The DPDP Act’s permissive stance on international data transfers – allowing transfers to all countries except those explicitly restricted – continues to generate debate. Critics argue that without a rigorous adequacy assessment mechanism, personal data of Indian citizens transferred abroad may not receive equivalent protection. The government is expected to issue further notifications on restricted countries and on the designation of Significant Data Fiduciaries who will face enhanced compliance obligations.
Balancing surveillance and privacy
Sections 69 and 69A of the IT Act grant the government broad powers to intercept communications and block websites. While these provisions were upheld by the Supreme Court in the Shreya Singhal case, the absence of a separate law governing bulk surveillance – unlike countries such as the UK, which has the Investigatory Powers Act – remains a concern among privacy advocates. The exemptions granted to government agencies under the DPDP Act for national security purposes add another layer to this ongoing debate.
Looking ahead
India’s IT legal framework has come a long way from the IT Act of 2000. The enactment of the DPDP Act, 2023 and notification of the DPDP Rules in 2025 represent a significant milestone – India now has a dedicated, consent-driven data protection regime aligned with global standards. MeitY’s expanding role in promoting AI governance, strengthening cybersecurity infrastructure, and enabling digital public services ensures that the regulatory framework keeps pace with technological change.
However, the real test lies in implementation. The phased rollout of the DPDP Act, the evolving nature of AI regulation, and the persistent challenges of cybercrime and digital surveillance will shape how effectively India’s IT laws protect citizens while fostering innovation.
What do you think? As India implements the DPDP Act in phases, do you believe the current framework adequately balances individual privacy rights with the government’s need for data access in the interest of national security? And with AI regulation being left to individual sector regulators, will a decentralised approach work effectively, or does India eventually need a unified AI law?
References
- https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
- https://uncitral.un.org/en/texts/ecommerce/modellaw/electronic_commerce
- https://www.meity.gov.in/content/information-technology-act-2000
- https://blog.ipleaders.in/information-technology-act-2000/
- https://en.wikipedia.org/wiki/Information_Technology_Act,_2000
- https://vajiramandravi.com/upsc-exam/information-technology-act-2000/
- https://www.digitalindia.gov.in/
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2088990
- https://en.wikipedia.org/wiki/Digital_Personal_Data_Protection_Act,_2023
- https://prsindia.org/billtrack/digital-personal-data-protection-bill-2023
- https://www.hoganlovells.com/en/publications/indias-digital-personal-data-protection-act-2023-brought-into-force-
- https://chambers.com/articles/meity-unveils-india-s-approach-towards-regulating-artificial-intelligence
- https://www.dlapiperdataprotection.com/?t=law&c=IN
Leave a Reply