Cybersecurity Law for Indian Practitioners

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 26, 2026
4 min read
Read as

Last updated: April 29, 2026

IT Act, BNS/BSA replacement of IPC/Evidence Act, DPDP Act 2023, sectoral regulations (RBI/SEBI/IRDAI), CERT-In directions, evidence handling — a practitioner map of Indian cyber law.

A Hyderabad fintech CTO discovered an employee was running a parallel side-business using customer data. He confronted the employee, terminated employment, and considered the matter closed. Six months later, the company faced a Section 72A IT Act prosecution because they hadn’t reported the breach to CERT-In and hadn’t notified the affected customers. The technical incident was real; the legal failure was worse. This module covers Indian cybersecurity law for practitioners.

The legal stack

Cybersecurity in India is governed by overlapping statutes:

  • Information Technology Act 2000 (amended 2008) — primary statute for cyber offences and electronic records
  • Indian Penal Code (IPC) — traditional criminal offences extended to digital context
  • Bharatiya Nyaya Sanhita (BNS) 2023 — replaces IPC; some IT-relevant provisions
  • Digital Personal Data Protection Act 2023 — privacy / data protection
  • SPDI Rules 2011 (under §43A) — sensitive personal data, transitional
  • CERT-In Direction 28 April 2022 — incident reporting obligations
  • Sectoral regulators — RBI, SEBI, IRDAI, NPCI cyber guidelines

The IT Act sections that matter

Section What it covers
§43 Penalty for damage to computer system; civil liability
§43A Body corporate liable for negligence in handling sensitive personal data
§65 Tampering with source code; criminal
§66 Computer-related offences (combined version of various)
§66B Receiving stolen computer resource
§66C Identity theft
§66D Cheating by personation using computer resource
§66E Privacy violation (capturing private images)
§66F Cyber terrorism
§67 Obscene material
§69 Government interception powers
§70 Protected systems (CII)
§70B CERT-In; designated as national agency for incident response
§70B(7) Penalty for non-compliance with CERT-In direction
§72A Disclosure of information in breach of lawful contract; criminal

The Hyderabad fintech case — what went wrong

Employee accessed customer database beyond authorised scope and used data for side-business. The CTO’s response addressed the HR / employment dimension but missed the legal dimensions:

  • §72A IT Act — employee disclosed information in breach of lawful contract; criminal liability for the employee, possible §43A liability for the company for failing to prevent
  • §43A SPDI Rules — body corporate negligent in handling sensitive personal data; civil liability + customer right to seek compensation
  • CERT-In Direction — data breach is a reportable incident; 6-hour notification obligation missed
  • Customer notification — under DPDP §8(6) (when Rules notified) and contractual obligation, affected customers must be notified
  • Police complaint — for the employee’s offences, under §72A and §66 IT Act + relevant IPC sections

The DPDP Act 2023 — the new layer

DPDP, when fully operationalised, adds:

  • Up to ₹250 crore penalty for failure to prevent personal data breach
  • Data Principal rights — access, correction, erasure, withdraw consent
  • Significant Data Fiduciary obligations (DPO, DPIA)
  • Cross-border transfer restrictions
  • 72-hour breach notification to Data Protection Board
  • Children’s data special protections

DPDP overrides §43A / SPDI Rules for personal-data matters once Rules notified.

The CERT-In Direction (April 2022)

Mandatory for every body corporate, intermediary, data centre, VPN/cloud provider:

  • Cyber-incident reporting to CERT-In within 6 hours of detection
  • 180-day log retention in India
  • NTP synchronisation to NIC / NPL
  • 5-year KYC retention for VPN / VPS / VASP
  • Designated point-of-contact for CERT-In

Non-compliance under §70B(7): up to 1 year imprisonment + ₹1 lakh fine + reputation / contract impact.

Key cases / precedents (anonymised landmark patterns)

  • Customer-data theft cases — multiple §43A actions in Tier-1 cities since 2018
  • BFSI compliance fines — RBI has imposed multi-crore penalties for cyber-framework non-compliance
  • Aadhaar exposure cases — UIDAI enforcement under Aadhaar Act
  • Ransomware notification failures — CERT-In / sectoral CERT enforcement growing

The practitioner playbook

When an incident occurs:

  1. Engage CISO + GC + senior counsel within 1 hour
  2. Determine if reportable incident (per CERT-In Annexure I)
  3. If yes, prepare CERT-In notification; meet 6-hour window
  4. If personal data affected, prepare DPB notification (when operational); 72-hour window
  5. If sectoral (RBI / SEBI / IRDAI / NPCI), additional sector-specific reporting
  6. If contractual obligation to customers / partners, notify per contract
  7. Police complaint where criminal offence (employee theft, external attack, data exfiltration)
  8. Internal investigation with documented evidence preservation
  9. Post-incident review to risk register + corrective actions

Common mistakes

  • Treating cyber incident as IT problem rather than legal-and-IT
  • Missing CERT-In window because investigation was “incomplete”
  • Not notifying affected customers, hoping for quiet resolution
  • Internal investigation without legal counsel guidance (waiver of privilege)
  • Insufficient evidence preservation (logs deleted, devices wiped)
  • Concluding incident before regulatory engagement complete

Try this in your organisation

  1. Find your incident response runbook. Does it include legal-counsel engagement triggers?
  2. Does it have CERT-In notification template ready to send?
  3. Does it preserve evidence in a manner admissible (chain of custody)?
  4. If a §43A liability claim were filed today, would your records demonstrate “reasonable security practices”?
  5. Run a tabletop exercise that includes legal counsel; the gaps surface fast.

Cyber law in India is layered, evolving, and increasingly enforced. Practitioners who know the IT Act, DPDP, CERT-In direction, and sectoral overlays operate with confidence; those who don’t react to incidents technically while leaking legal liability. Build the legal chops alongside the technical ones.

🧠
Check your understanding

Module Quiz · 6 questions

Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.

DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants