Last updated: April 29, 2026
A Hyderabad fintech CTO discovered an employee was running a parallel side-business using customer data. He confronted the employee, terminated employment, and considered the matter closed. Six months later, the company faced a Section 72A IT Act prosecution because they hadn’t reported the breach to CERT-In and hadn’t notified the affected customers. The technical incident was real; the legal failure was worse. This module covers Indian cybersecurity law for practitioners.
The legal stack
Cybersecurity in India is governed by overlapping statutes:
- Information Technology Act 2000 (amended 2008) — primary statute for cyber offences and electronic records
- Indian Penal Code (IPC) — traditional criminal offences extended to digital context
- Bharatiya Nyaya Sanhita (BNS) 2023 — replaces IPC; some IT-relevant provisions
- Digital Personal Data Protection Act 2023 — privacy / data protection
- SPDI Rules 2011 (under §43A) — sensitive personal data, transitional
- CERT-In Direction 28 April 2022 — incident reporting obligations
- Sectoral regulators — RBI, SEBI, IRDAI, NPCI cyber guidelines
The IT Act sections that matter
| Section | What it covers |
|---|---|
| §43 | Penalty for damage to computer system; civil liability |
| §43A | Body corporate liable for negligence in handling sensitive personal data |
| §65 | Tampering with source code; criminal |
| §66 | Computer-related offences (combined version of various) |
| §66B | Receiving stolen computer resource |
| §66C | Identity theft |
| §66D | Cheating by personation using computer resource |
| §66E | Privacy violation (capturing private images) |
| §66F | Cyber terrorism |
| §67 | Obscene material |
| §69 | Government interception powers |
| §70 | Protected systems (CII) |
| §70B | CERT-In; designated as national agency for incident response |
| §70B(7) | Penalty for non-compliance with CERT-In direction |
| §72A | Disclosure of information in breach of lawful contract; criminal |
The Hyderabad fintech case — what went wrong
Employee accessed customer database beyond authorised scope and used data for side-business. The CTO’s response addressed the HR / employment dimension but missed the legal dimensions:
- §72A IT Act — employee disclosed information in breach of lawful contract; criminal liability for the employee, possible §43A liability for the company for failing to prevent
- §43A SPDI Rules — body corporate negligent in handling sensitive personal data; civil liability + customer right to seek compensation
- CERT-In Direction — data breach is a reportable incident; 6-hour notification obligation missed
- Customer notification — under DPDP §8(6) (when Rules notified) and contractual obligation, affected customers must be notified
- Police complaint — for the employee’s offences, under §72A and §66 IT Act + relevant IPC sections
The DPDP Act 2023 — the new layer
DPDP, when fully operationalised, adds:
- Up to ₹250 crore penalty for failure to prevent personal data breach
- Data Principal rights — access, correction, erasure, withdraw consent
- Significant Data Fiduciary obligations (DPO, DPIA)
- Cross-border transfer restrictions
- 72-hour breach notification to Data Protection Board
- Children’s data special protections
DPDP overrides §43A / SPDI Rules for personal-data matters once Rules notified.
The CERT-In Direction (April 2022)
Mandatory for every body corporate, intermediary, data centre, VPN/cloud provider:
- Cyber-incident reporting to CERT-In within 6 hours of detection
- 180-day log retention in India
- NTP synchronisation to NIC / NPL
- 5-year KYC retention for VPN / VPS / VASP
- Designated point-of-contact for CERT-In
Non-compliance under §70B(7): up to 1 year imprisonment + ₹1 lakh fine + reputation / contract impact.
Key cases / precedents (anonymised landmark patterns)
- Customer-data theft cases — multiple §43A actions in Tier-1 cities since 2018
- BFSI compliance fines — RBI has imposed multi-crore penalties for cyber-framework non-compliance
- Aadhaar exposure cases — UIDAI enforcement under Aadhaar Act
- Ransomware notification failures — CERT-In / sectoral CERT enforcement growing
The practitioner playbook
When an incident occurs:
- Engage CISO + GC + senior counsel within 1 hour
- Determine if reportable incident (per CERT-In Annexure I)
- If yes, prepare CERT-In notification; meet 6-hour window
- If personal data affected, prepare DPB notification (when operational); 72-hour window
- If sectoral (RBI / SEBI / IRDAI / NPCI), additional sector-specific reporting
- If contractual obligation to customers / partners, notify per contract
- Police complaint where criminal offence (employee theft, external attack, data exfiltration)
- Internal investigation with documented evidence preservation
- Post-incident review to risk register + corrective actions
Common mistakes
- Treating cyber incident as IT problem rather than legal-and-IT
- Missing CERT-In window because investigation was “incomplete”
- Not notifying affected customers, hoping for quiet resolution
- Internal investigation without legal counsel guidance (waiver of privilege)
- Insufficient evidence preservation (logs deleted, devices wiped)
- Concluding incident before regulatory engagement complete
Try this in your organisation
- Find your incident response runbook. Does it include legal-counsel engagement triggers?
- Does it have CERT-In notification template ready to send?
- Does it preserve evidence in a manner admissible (chain of custody)?
- If a §43A liability claim were filed today, would your records demonstrate “reasonable security practices”?
- Run a tabletop exercise that includes legal counsel; the gaps surface fast.
Cyber law in India is layered, evolving, and increasingly enforced. Practitioners who know the IT Act, DPDP, CERT-In direction, and sectoral overlays operate with confidence; those who don’t react to incidents technically while leaking legal liability. Build the legal chops alongside the technical ones.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.