Skip to main content

Taxmann's Cyber Laws

Page 1

Sample Read


© All rights reserved Price : ` 625 First Published : August 2026 Published by : Taxmann Publications (P.) Ltd. Sales & Marketing : 59/32, New Rohtak Road, New Delhi-110 005 India Phone : +91-11-45562222 Website : www.taxmann.com E-mail : sales@taxmann.com Regd. Office : 21/35, West Punjabi Bagh, New Delhi-110 026 India Printed at : Tan Prints (India) Pvt. Ltd. 44 Km. Mile Stone, National Highway, Rohtak Road Village Rohad, Distt. Jhajjar (Haryana) India E-mail : sales@tanprints.com Disclaimer Every effort has been made to avoid errors or omissions in this publication. In spite of this, errors may creep in. Any mistake, error or discrepancy noted may be brought to our notice which shall be taken care of in the next edition. It is notified that neither the publisher nor the author or seller will be responsible for any damage or loss of action to any one, of any kind, in any manner, therefrom. It is suggested that to avoid any doubt the reader should cross-check all the facts, law and contents of the publication with original Government publication or notifications. No part of this book may be reproduced or copied in any form or by any means [graphic, electronic or mechanical, including photocopying, recording, taping, or information retrieval systems] or reproduced on any disc, tape, perforated media or other information storage device, etc., without the written permission of the publishers. Breach of this condition is liable for legal action. For binding mistake, misprints or for missing pages, etc., the publisher’s liability is limited to replacement within seven days of purchase by similar edition. All expenses in this connection are to be borne by the purchaser. All disputes are subject to Delhi jurisdiction only.


Contents

PAGE

About the Author

I-5

Preface

I-9

Acknowledgement

I-11

List of Cases

I-23

Abbreviations

I-27

CHAPTER 1 INTRODUCTION

Introduction

1

CHAPTER 2 INFORMATION TECHNOLOGY ACT - ITS EVOLUTION AND AMENDMENTS 2.1

Introduction

9

2.2

UNCITRAL Model Law on E-Commerce

9

2.3

The Information Technology Act, 2000

11

2.4

Laws amended through the Information Technology Act, 2000

11

2.5

Amendments to Information Technology Act, 2000

15

2.6

Digital India Act – An incomplete attempt to change the law

21

2.7

Conclusion

22

CHAPTER 3 E-COMMERCE, E-GOVERNANCE AND THE INFORMATION TECHNOLOGY ACT, 2000 3.1

Introduction

23 I-13


I-14

CONTENTS

PAGE

3.2

Conceptual Analysis

24

3.3

Electronic Commerce [E-Commerce]

24

3.4

Electronic Governance [E-Governance]

25

3.5

Electronic Record [E-Records]

25

3.6

Electronic Signature [E-Signature]

26

3.7

Digital Signature

26

3.8

Electronic Contract [E-Contract]

27

3.9

Relevant Provisions of IT Act, 2000

27

3.10

E-commerce Guidelines

36

3.11

Conclusion

37

CHAPTER 4 UNDERSTANDING CYBER CRIMES 4.1

Introduction

38

4.2

Concept of Cybercrimes

39

4.3

Salient Features of Cybercrimes

39

4.4

Classification of Cybercrimes

41

4.5

Forms of Cybercrimes

43

4.6

Cybercrimes vis-à-vis Conventional Crimes

50

4.7

Cybercrimes under other Special Laws

50

4.8

Conclusion

51

4.9

References

51

CHAPTER 5 CYBER CIVIL WRONGS AND THE INFORMATION TECHNOLOGY ACT, 2000 5.1

Introduction

53

5.2

Cyber Civil Wrongs under the Information Technology Act, 2000

53

5.3

Conclusion

64


CONTENTS

I-15 PAGE

CHAPTER 6 ADJUDICATION OF CIVIL CASES UNDER INFORMATION TECHNOLOGY ACT, 2000 6.1

Introduction

65

6.2

Adjudication of cases under Information Technology Act, 2000

65

6.3

Factors to be considered in fixing the amount of compensation or damages

67

6.4

Appeals

67

6.5

Compounding of the Offences

68

6.6

Adjudication process under Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023 – The intersection

68

6.7

Conclusion

71

CHAPTER 7 REGULATION OF CYBERCRIMES IN INDIA THROUGH SUBSTANTIVE LEGAL PROVISIONS 7.1

Introduction

72

7.2

Indian Approach of Regulation of Cybercrimes

73

7.3

Provisions from the Information Technology Act, 2000

73

7.4

Corporate Criminal Liability under Information Technology Act, 2000

95

7.5

Liability of Internet Intermediaries

96

7.6

Cyber Crimes under Bharatiya Nyaya Sanhita, 2023

97

7.7

Surge of Cases of Digital Arrest and the Intervention of Supreme Court through Recent Orders

111

7.8

Conclusion

114

7.9

References

114

CHAPTER 8 CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS 8.1

Introduction

116


I-16

CONTENTS

PAGE

8.2

Nature of Offences

116

8.3

Procedure of Investigation of Cybercrimes

121

8.4

Other Mandatory Rules under the Information Technology Act, 2000

140

8.5

Conclusion

141

CHAPTER 9 INSTITUTIONAL FRAMEWORK AND THE INFORMATION TECHNOLOGY ACT, 2000 9.1

Introduction

142

9.2

Institutions through which Cyber Civil Wrongs are Adjudicated

142

9.3

Appeals from the Orders of the Adjudicating Authority under Information Technology Act, 2000

143

9.4

Section 43A of the Information Technology Act, 2000 vis-avis Digital Personal Data Protection Act, 2023 – The Interface

144

9.5

Appeals from the Data Protection Board of India under Digital Personal Data Protection Act, 2023

146

9.6

Institutions through which Cyber Crimes are Investigated

147

9.7

Cyber Forensics Labs

151

9.8

Other Institutions to ensure Cyber Security in the Country

155

9.9

Conclusion

158

CHAPTER 10 GOVERNMENT’S SPECIAL POWERS TO SAFEGUARD CYBER SPACE UNDER INFORMATION TECHNOLOGY ACT, 2000 10.1

Introduction

159

10.2

Section 69: Government’s Power to Conduct E-Surveillance and Seek for Decryption

159

10.3

Section 69A: Power to block/remove illegal contents from online platforms

169

10.4

Section 69B: Information Technology Act, 2000

178

10.5

Conclusion

183


CONTENTS

I-17 PAGE

CHAPTER 11 CYBERCRIME INVESTIGATION AND THE INDIAN LEGAL PROVISIONS RELATING TO JURISDICTION 11.1

Introduction

185

11.2

Important Basis for Invoking Jurisdiction and Related Principles

189

11.3

Conclusion

195

CHAPTER 12 INTERNET INTERMEDIARY - OBLIGATION AND LIABILITY 12.1

Introduction

197

12.2

Definition of Internet Intermediary

198

12.3

Section 79 of the Information Technology Act, 2000

199

12.4

Important Amendments made to the Intermediary Rules

203

12.5

Due diligence by intermediary - An analysis of the current regulatory framework

211

12.6

Extension of Application of Rule 4

239

12.7

Legal Consequence of not Complying with ‘Due Diligence’ Requirements or not Complying with Intermediary Regulations

240

12.8

Other Duties of Internet Intermediary under the Information Technology Act, 2000 and Related Liability

241

12.9

Other MEITY’s Advisories Imposing Obligations upon Intermediaries

244

12.10

Conclusion

244

CHAPTER 13 UNDERSTANDING DIGITAL EVIDENCE AND DIGITAL FORENSIC – FROM LEGAL PERSPECTIVE 13.1

Introduction

246

13.2

Few Prescribed Legal and Forensic Process as Per Some SOPs/Guidelines/Manuals and Related Legal Provisions

249

13.3

Recent Legal Changes

251

13.4

Conclusion

265


I-18

CONTENTS

PAGE

CHAPTER 14 DATA PROTECTION AND INFORMATION TECHNOLOGY ACT, 2000 14.1

Introduction

266

14.2

Definition of ‘Data’

268

14.3

Classification of Data

269

14.4

The Information Technology Act, 2000 and Data Protection

269

14.5

Conclusion

272

CHAPTER 15 PERSONAL DATA PROTECTION AND RELATED LEGAL PROVISIONS FROM THE INFORMATION TECHNOLOGY ACT, 2000 15.1

Introduction

274

15.2

Importance of Right to Privacy

275

15.3

Right to Privacy as a Fundamental Right

275

15.4

Concept of ‘Personal Data’

276

15.5

Personal Data and the Information Technology Act, 2000

276

15.6

Conclusion

284

CHAPTER 16 DIGITAL PERSONAL DATA PROTECTION ACT, 2023 AND RULES – AN OVERVIEW 16.1

Introduction

285

16.2

Aim and Objective

286

16.3

Scope and Ambit

286

16.4

Important Concepts and their Definitions

287

16.5

Some Important Provisions

289

16.6

Exceptions to Rules Restricting Data Processing & Data Processing by State and its Instrumentalities

294

16.7

Rights of Data Principal

298

16.8

Other Obligations of the data Fiduciary

302

16.9

Additional Obligations of Significant Data Fiduciary

305


CONTENTS

I-19 PAGE

16.10

Data Erasion v. Data Retention & Production

307

16.11

Data Privacy of Children or a person with disabilities

309

16.12

Data Transfer Beyond India

311

16.13

Data Protection Board of India

312

16.14

Date of Implementation

317

16.15

Conclusion

319

CHAPTER 17 A GLIMPSE INTO THE PROMOTION AND REGULATION OF ONLINE GAMING ACT, 2025 17.1

Introduction

320

17.2

Promotion and Regulation of Online Gaming Act, 2025 (“PROG ACT”)

320

17.3

Important Definitions

321

17.4

Important Provisions of the Act and the Rules

321

17.5

Conclusion

326

CHAPTER 18 CROSS-BORDER MEASURES REGULATING CYBER CRIMES AND ENSURING CYBER SECURITY – AN OVERVIEW 18.1

Introduction

327

18.2

Budapest Convention on Cyber Crime

328

18.3

UN Cybercrime Convention

334

18.4

G7 [Group of 7] 24/7 Cybercrime Network

344

18.5

BRICS and India

346

18.6

G20 – India and Cyber Security

352

18.7

ASEAN – India and Cyber Security Strategies

354

18.8

SAARC – India and Cyber Security

357

18.9

India’s Bilateral Arrangements

358

18.10

India and MLAT Agreements

361

18.11

India and Extradition Agreements

362

18.12

Conclusion

362


I-20

CONTENTS

PAGE

CHAPTER 19 EMERGING FORMS OF CYBER TECHNOLOGY AND CHALLENGES TO LEGAL REGULATORY FRAMEWORK 19.1

Introduction

364

19.2

Novel forms of technology and the challenges they pose to regulatory framework

365

19.3

Conclusion

383

Annexure 1

Resolution adopted by the general assembly [on the report of the sixth committee (A/51/628)] 51/162 model law on electronic commerce adopted by the united nations commission on international trade law

389

Annexure 2

MEITY’S notification of appointment of Adjudicating Authority under Information Technology Act, 2000

391

Annexure 3

The Information Technology (Qualification and Experience of Adjudicating Officers and Manner of Holding Enquiry) Rules, 2003

392

Annexure 4

MEITY’S notification on amendment to the information technology (Qualification and Experience of Adjudicating Officers and Manner of Holding Enquiry) Rules, 2003

398

Annexure 5

Bharatiya Sakshya Adhiniym, section 63 - Certificate Format

399

Annexure 6

Bharatiya Sakshya Adhiniyam –Prescribed format of the second certificate under section 63 to be issued by the expert

401

Annexure 7

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

402

Annexure 8

Ministry of Electronics and Information Technology Notification on Information Technology (InterMediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2023

419

Annexure 9

Ministry of Electronics and Information Technology Notification on commencement of the DPDP Act, 2023

427


CONTENTS

I-21 PAGE

Annexure 10 The Information Technology (National Critical Information Infrastructure Protection Centre and Manner of Performing Functions and Duties) Rules, 2013

428

Annexure 11 The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

433

SUBJECT INDEX

439


CHAPTER CYBERCRIME INVESTIGATION

8

AND INDIAN PROCEDURAL LEGAL PROVISIONS

SYNOPSIS 8.1 Introduction 8.2 Nature of Offences 8.3 Procedure of Investigation of Cybercrimes 8.4 Other Mandatory Rules under the Information Technology Act, 2000

8.5 Conclusion

8.1 INTRODUCTION Cybercrime involves various forms of offences, some falling under the ambit of Information Technology Act, 2000 while some falling under the ambit of other laws including the Bharatiya Nyaya Sanhita, 2023 as well as under some special laws such as Protection of Children from Sexual Offences Act, 2012. While Bharatiya Nagarik Suraksha Sanhita prescribes rules of procedure related to a crime covered under Bharatiya Nyaya Sanhita, other special laws may lay down their own rules of procedure to be followed while conducting investigation, inquiry and trial of crimes covered under their framework. Wherever special laws are silent about a process, the procedure laid down under Bharatiya Nagarik Suraksha Sanhita of 2023 must be followed. This chapter explains the process laid down in relation to investigation of cybercrimes with reference to the Bharatiya Nagarik Suraksha Sanhita and the Information Technology Act, 2000.1

8.2 NATURE OF OFFENCES Even though the Information Technology Act, 2000 does not lay down detailed rules related to the procedure to be followed while investigating cybercrimes, yet there are provisions indicating to certain extent the

1. Note that some procedures may be different in relation to offences covered under Protection of Children from Sexual Offences Act, 2012.

116


CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS

117

procedural rules to be adhered to while dealing with offences covered under the Act. According to Section 77B of the Information Technology Act, 2000 “Notwithstanding anything contained in the Code of Criminal Procedure, 1973, the offence punishable with imprisonment of three years and above shall be cognizable and the offence punishable with imprisonment of three years shall be bailable.” Recognising an offence as a cognizable offence indicates that the offence is of complex nature and serious form. In comparison to the non-cognizable offence, cognizable offences are usually subjected to severe punishment. They are seen as offences against State and hence their investigations are conducted by the State police or other investigation agencies. An investigation police officer hence is empowered to investigate cognizable offences without any order of investigation by a Magistrate. While on the other hand, a police officer cannot investigate a non-cognizable offence unless there is an order to investigate issued to him by a Magistrate. Note that all the crimes covered under the Information Technology Act, 2000 are cognizable offences. Prior to the amendments made to the Act, through the Jan Vishwas Act, Section 72 was a non-cognizable offence but it is now decriminalised and is subjected to penalty. Hence as on today most of the cybercrimes under Information Technology Act, 2000 are cognizable in nature and must be investigated by police. ILLUSTRATIONS (a) A hacks B’s Computer System. B files a FIR against A. Since this is an offence under Section 66 of the IT Act, 2000 it must be investigated by the police. (b) X has published a defamatory post against Y on a social media platform. Here even though defamation is a crime under Section 356 of BNS, yet since it is not a cognizable offence, it cannot be investigated by the police. As an aggrieved person, Y can however file a private criminal compliant against X.

Section 77B of the Information Technology Act, 2000 makes all the offences punishable with imprisonment upto three years as bailable offence. This means that unless the offence is punishable with more than 3 years, they are bailable in nature. Hence if a person is arrested during investigation of a bailable offence, he must be immediately released on bail. While on the other hand, if a person is arrested in relation to a non-bailable offence, that is, in relation to a cybercrime which is punishable with more than 3 years of imprisonment, he may or may not be released on bail, since the offence is non-bailable in nature. In a non-bailable case, the bail is granted subject to the discretionary power of the court, while in a bailable offence, bail is a matter of right of the accused. There are however guidelines laid down by courts which must be considered while deciding on bail applications in non-bailable offences.


118

CYBER LAWS

ILLUSTRATION (i) X is arrested in relation to a case of cheating by impersonation, which is an offence under Section 66C of the Information Technology Act, 2000. This being an offence punishable with imprisonment up to 3 years is a bailable offence. X, hence, if is arrested must be released on bail as soon as he furnishes bail. (ii) Y is arrested for the offence of hacking a Protected System under Section 70 of the Information Technology Act, 2000. Since the term of imprisonment under Section 70 can extend up to 10 years it is a non-bailable offence. Hence during investigation Y may or may not be released on bail and the decision to release him on bail will be that of the court which will be based on various criterias and as per the guidelines laid down in this regard by several courts. Y here has no right to be released on bail unlike in a case of bailable offence.

The following table indicates the nature of offences: COGNIZABLE OR NON-COGNIZABLE

BAILABLE OR NON-BAILABLE

PROVISION FROM THE IT ACT, 2000

OFFENCE COVERED

EXTENT OF PUNISHMENT

Section 65

Tampering with computer source documents

with imprisonment up to Cognizable three years, or with fine which may extend up to two lakh rupees, or with both.

Bailable

Section 66

Computer related offences

with imprisonment for a Cognizable term which may extend to three years or with fine which may extend to five lakh rupees or with both.

Bailable

Section 66B

Punishment for dishonestly receiving stolen computer resource or communication device

with imprisonment of ei- Cognizable ther description for a term which may extend to three years or with fine which may extend to rupees one lakh or with both.

Bailable

Section 66C

Punishment for identity theft

with imprisonment of ei- Cognizable ther description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.

Bailable

Section 66D

Punishment for cheating by personation by using computer resource

with imprisonment of ei- Cognizable ther description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees.

Bailable


CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS COGNIZABLE OR NON-COGNIZABLE

119

PROVISION FROM THE IT ACT, 2000

OFFENCE COVERED

EXTENT OF PUNISHMENT

BAILABLE OR NON-BAILABLE

Section 66E

Punishment for violation of privacy

with imprisonment which Cognizable may extend to three years or with fine not exceeding two lakh rupees, or with both.

Bailable

Section 66F

Punishment for cyber terrorism

with imprisonment which Cognizable may extend to imprisonment for life

Non-Bailable

Section 67

Punishment for publishing or transmitting obscene material in electronic form

shall be punished on first Cognizable conviction with imprisonment of either description for a term which may extend to three years and with fine which may extend to five lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to five years and also with fine which may extend to ten lakh rupees

First time offence – Bailable

Section 67A

Punishment for publishing or transmitting of material containing sexually explicit act, etc. in electronic form

shall be punished on first Cognizable conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to ten lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to seven years and also with fine which may extend to ten lakh rupees.

Non-Bailable

Section 67B

Punishment for publishing or transmitting of material depicting children in sexually explicit act, etc. in electronic form

shall be punished on first Cognizable conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to ten lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term.

Non-Bailable

Second or subsequent time offence – non-Bailable


120 PROVISION FROM THE IT ACT, 2000

CYBER LAWS OFFENCE COVERED

EXTENT OF PUNISHMENT

COGNIZABLE OR NON-COGNIZABLE

BAILABLE OR NON-BAILABLE

which may extend to seven years and also with fine which may extend to ten lakh rupees Section 68

Power of Controller to give directions

for a term not exceeding Non – Cognizable two years or a fine not exceeding one lakh rupees or with both.

Bailable

Section 69

Power to issue directions for interception or monitoring or decryption of any information through any computer resource

(4) The subscriber or inter- Cognizable mediary or any person who fails to assist the agency referred to in sub-section (3) shall be punished with imprisonment for a term which may extend to seven years and shall also be liable to fine.

Non- Bailable

Section 69A

Power to issue directions for blocking for public access of any information through any computer resource

(3) The intermediary who Cognizable fails to comply with the direction issued under sub-section (1) shall be punished with an imprisonment for a term which may extend to seven years and also be liable to fine.

Non- Bailable

Section 69B

Power to authorise to monitor and collect traffic data or information through any computer resource for cyber security

(4) Any intermediary who Non- Cognizable intentionally or knowingly contravenes the provisions of sub-section (2) shall be punished with an imprisonment for a term which any extend to one year or shall be liable to fine which may extend to one crore rupees, or with both

Bailable

Section 70

Protected system

(3) Any person who secures Cognizable access or attempts to secure access to a protected system in contravention of the provisions of this section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.

Non- Bailable


CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS PROVISION FROM THE IT ACT, 2000

OFFENCE COVERED

EXTENT OF PUNISHMENT

COGNIZABLE OR NON-COGNIZABLE

Section 70B

Indian Computer Emergency Response Team to serve as national agency for incident response.

(7) Any service provider, Non-cognizable intermediaries, data centres, body corporate or person who fails to provide the information called for or comply with the direction under sub-section (6), shall be punishable with imprisonment for a term which may extend to one year or with fine which may extend to one crore rupees or with both.

Bailable

Section 71

Penalty for misrepresentation.

imprisonment for a term Non-cognizable which may extend to two years, or with fine which may extend to one lakh rupees, or with both.

Bailable

Section 73

Penalty for publishing electronic signature Certificate false in certain particulars

with imprisonment for a Non-cognizable term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.

Bailable

Section 74

Publication for fraudulent purpose.

with imprisonment for a Non-cognizable term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.

Bailable

121

BAILABLE OR NON-BAILABLE

As indicated in the above table, most of the offences under Information Technology Act, 2000 are cognizable in nature. They hence must be investigated by police.

8.3 PROCEDURE OF INVESTIGATION OF CYBERCRIMES As mentioned earlier, a police officer is empowered to investigate a cognizable offence without an order by the magistrate. He is also obliged to investigate a non-cognizable offence provided he is ordered to do so through an order of a Magistrate. In both cases, he has the same power of investigation except that in a non-cognizable case, when he is investigating a case based on a Magistrate’s order, he cannot arrest the accused unless with a Magistrate’s order to arrest. Hence, he requires an arrest warrant to arrest an accused during investigation of a non-cognizable offence.


122

CYBER LAWS

Bharatiya Nagarik Suraksha Sanhita along with the Information Technology Act, 2000 lays down rules of procedure in relation to investigation of cybercrimes. Since the provisions relating to investigation of cybercrimes are not exhaustively laid down under the Information Technology Act, 2000, the provisions from BNSS must be adhered to when a cybercrime is investigated. Investigation of cybercrime must be conducted as per below explained procedure prescribed by BNSS.

Registration of FIR Registration of FIR marks the beginning of investigation of a crime. It is mandatory on the part of the police officer to register FIR if he receives information related to a cognizable offence. Earlier police used to insist for concerned police station’s jurisdiction for both registration of FIR as well as investigation of a case based on such FIR. However, courts through their judicial decisions had persistently insisted for immediate registration of FIR upon receipt of information related to a cognizable offence. The courts even insisted for registration of Zero FIR, meaning an FIR without number being assigned or specified on it. This would mean that the FIR at least could be registered based on the information received and later such FIR could be transferred to police stations having jurisdiction.2 Despite court’s efforts in mandating registration of FIR, there were many incidences when registration was not done. Hence, there was a need to make necessary amendments to law to mandate registration of FIR. BNSS has to some extent revised law relating to registration of FIR. The provision – that is - Section 173 of BNSS provides as follows: “(1) Every information relating to the commission of a cognizable offence, irrespective of the area where the offence is committed, may be given orally or by electronic communication to an officer in charge of a police station, and if given— (i) orally, it shall be reduced to writing by him or under his direction, and be read over to the informant; and every such information, whether given in writing or reduced to writing as aforesaid, shall be signed by the person giving it; (ii) by electronic communication, it shall be taken on record by him on being signed within three days by the person giving it, and the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may by rules prescribe in this behalf: Provided that if the information is given by the woman against whom an offence under section 64, section 65, section 66, section 67, section 68, section 69, section 70, section 71, section 74, section 75, section 76, section 77, section 78, section 79 or section 124 of the Bharatiya Nyaya Sanhita, 2023 is alleged to have been

2. Law relating to jurisdiction is discussed in detail in Chapter 11 of this book


CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS

123

committed or attempted, then such information shall be recorded, by a woman police officer or any woman officer: Provided further that— (a) in the event that the person against whom an offence under section 64, section 65, section 66, section 67, section 68, section 69, section 70, section 71, section 74, section 75, section 76, section 77, section 78, section 79 or section 124 of the Bharatiya Nyaya Sanhita, 2023 is alleged to have been committed or attempted, is temporarily or permanently mentally or physically disabled, then such information shall be recorded by a police officer, at the residence of the person seeking to report such offence or at a convenient place of such person’s choice, in the presence of an interpreter or a special educator, as the case may be; (b) the recording of such information shall be videographed;

(c) the police officer shall get the statement of the person recorded by a Magistrate under clause (a) of sub-section (6) of section 183 as soon as possible. (2) A copy of the information as recorded under sub-section (1) shall be given forthwith, free of cost, to the informant or the victim. (3) Without prejudice to the provisions contained in section 175, on receipt of information relating to the commission of any cognizable offence, which is made punishable for three years or more but less than seven years, the officer in charge of the police station may with the prior permission from an officer not below the rank of Deputy Superintendent of Police, considering the nature and gravity of the offence, — (i) proceed to conduct preliminary enquiry to ascertain whether there exists a prima facie case for proceeding in the matter within a period of fourteen days; or

(ii) proceed with investigation when there exists a prima facie case. (4) Any person aggrieved by a refusal on the part of an officer-in-charge of a police station to record the information referred to in sub-section (1), may send the substance of such information, in writing and by post, to the Superintendent of Police concerned who, if satisfied that such information discloses the commission of a cognizable offence, shall either investigate the case himself or direct an investigation to be made by any police officer subordinate to him, in the manner provided by this Sanhita, and such officer shall have all the powers of an officer-in-charge of the police station in relation to that offence failing which such aggrieved person may make an application to the Magistrate.”

According to Section 173 of the Bharatiya Nagarik Suraksha Sanhita [BNSS], an informer or a victim of crime, can get a FIR registered by giving information about the cognizable offence either orally to the police or in writing. If it is given orally the same will be reduced into writing. As per the revised provision in BNSS, FIR can also be registered by using electronic communication mode. Hence the use of the term E-FIR. In this


124

CYBER LAWS

case, the informer can get his information registered by using electronic modes of communication such as through a phone call or an email or a messenger platform, etc. Section 2(i) of BNSS defines “electronic communication” as “the communication of any written, verbal, pictorial information or video content transmitted or transferred (whether from one person to another or from one device to another or from a person to a device or from a device to a person) by means of an electronic device including a telephone, mobile phone, or other wireless telecommunication device, or a computer, or audio-video player or camera or any other electronic device or electronic form as may be specified by notification, by the Central Government.” While in a case of FIR being registered orally the informer must sign on the report and thereby authenticate the contents of it. When a FIR is registered through online modes or through phone calls, it is important to ensure that such FIR is not a false information or a vexatious report. To ensure that the information received is authentic and the person making it takes up the responsibility for getting such registration done, BNSS states that the person registering an E-FIR should sign on the registered FIR within 3 days from the date of providing such information. Today information relating to cybercrimes can be shared with the police by using the helpline number. That is, via number 1930 in India. While the helpline helps victims of cybercrimes report their cases at the earliest time possible it is mandated to be transformed into a regular registered FIR later, i.e., within 3 days. This initial reporting through helplines are crucial since emergency actions can be immediately taken based on the information shared, such as freezing bank accounts from where and to where unauthorised money has been transferred, getting illegal and abusive contents removed from the online platforms etc. Sharing of information via helpline till registration of FIR provides “golden time” to prevent loss/harm, thereby necessitating immediate actions by the police and other authorities without waiting for formal registration of a case. Once a police officer receives information related to a crime, as far as that information indicates commission of a cognizable offence, he has no other option but to register a FIR. Use of the word “shall” in Section 154(1)3 of the earlier Criminal Procedure Code clearly

3. According to Section 154, CRPC: “Every information relating to the commission of a cognisable offence, if given orally to an officer-in-charge of a police station, shall be reduced to writing by him or under his direction, and be read over to the informant; and every such information, whether given in writing or reduced to writing as aforesaid, shall be signed by the person giving it, and the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may prescribe in this behalf.”


CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS

125

shows the legislative intent, i.e., it is mandatory to register a FIR if the information given to the police discloses the commission of a cognizable offence.4 Courts too have through their judicial decisions insisted upon compulsory registration of FIRs based on such information. Hence whenever police receive information about a cognizable offence, they must register First Information Report.5 Thus, FIR is nothing but the FIRST INFORMATION REPORT. It is a book or a register maintained by the police at the police station in which information related to cognizable offences are entered. According to Section 154(1) of CRPC once information related to a cognizable offence reaches the police, they must enter such information in a book specifically kept in prescribed format for this purpose. This book or register is nothing but the FIR – i.e. – the First Information Report. Section 173(1) of BNSS too continues to use similar words, that is, “the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may by rules prescribe in this behalf.” Procedurally registration of FIR marks the beginning of the crime investigation. It is from here that the investigation of crime starts.

Meaning of the term ‘Investigation’ Investigation refers to “collection of evidence.” According to Section 2(l) of BNSS “investigation” “includes all the proceedings under this Sanhita for the collection of evidence conducted by a police officer or by any person (other than a Magistrate) who is authorised by a Magistrate in this behalf.” Usually investigation of crimes is conducted by the police officers unless it is entrusted to be done by others through an order of the Magistrate. Since “collection of evidence” also refers to a very comprehensive process, what evidences needs to be collected for what case depends upon the nature of such case. For example: in a case of cybercrime of hacking, the investigation may involve collection of log in details, details of the computer system that was hacked, the digital devices or other tools through which hacking was done, etc. On the other hand, investigation of a crime of murder may require collection of evidences like the tool or weapon used to commit the offence, post mortem report, that is, the medical evidence, etc. 4. According to Section 154, CRPC: “Every information relating to the commission of a cognisable offence, if given orally to an officer-in-charge of a police station, shall be reduced to writing by him or under his direction, and be read over to the informant; and every such information, whether given in writing or reduced to writing as aforesaid, shall be signed by the person giving it, and the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may prescribe in this behalf.” 5. State of Andra Pradesh v. Punati Ramube, 1993 CR L J 3684 (SC), also see: Lalita Kumari v. Govt. of U.P. (2014) 2 SCC 1


Cyber Laws AUTHOR : PUBLISHER : DATE OF PUBLICATION : EDITION : ISBN NO : No. of Pages : BINDING TYPE :

Nagarathna Annappa Taxmann July 2026 2026 Edition 9789375615248 480 Paperback

Rs. 625 DESCRIPTION Cyber Laws is a comprehensive, analytically driven textbook on India’s cyber-law regime. It traces the framework from the Information Technology Act 2000—India’s first cyber legislation, modelled on the UNCITRAL Model Law on E-Commerce— through its successive amendments (notably 2008) to the newest statutes reshaping the field: the Digital Personal Data Protection Act 2023 and the DPDP Rules, the Promotion and Regulation of Online Gaming Act 2025, and the cyber-relevant provisions of the Bharatiya Nyaya Sanhita, Bharatiya Nagarik Suraksha Sanhita, and Bharatiya Sakshya Adhiniyam 2023. Its centre of gravity is the regulation of cybercrime—both substantive (what conduct is prohibited and what civil or criminal liability attaches) and procedural (investigation, jurisdiction, adjudication, appeals, and digital evidence)—around which it builds the connected themes of modern cyber law: e-commerce and e-governance, cyber civil wrongs, intermediary liability, digital evidence and cyber forensics, data protection and privacy, the State’s surveillance and content-blocking powers, cross-border cooperation, and emerging technologies. Treating cyber law as an inherently ‘techno-legal’ subject, the author explains the underlying technology before mapping it onto statute and case law, in a lucid, illustration-rich and unusually current style. The book is written for a broad, multidisciplinary readership, and its dual substantive/procedural structure lets each group use it differently: • Students of Law, Cyber Law, and Cyber Forensics • Academicians and Researchers • Legal Practitioners • Law Enforcement Officers, Investigators, and Prosecutors • Compliance, Data-protection, and Technology Professionals • The Judiciary and Adjudicating Authorities The Present Publication is the 1st Edition, authored by Dr Nagarathna Annappa, with the following noteworthy features: • [Complete Legislative Evolution] Traces Indian cyber law from the IT Act 2000 to the DPDP Act 2023, showing how an e-commerce statute became the country’s principal cybercrime and cyber-security law • [Comprehensive Thematic Coverage] Dedicated treatment of intermediary liability, e-commerce, e-governance, privacy, data protection, and online gaming • [Civil Wrongs and Cybercrimes Distinguished] Separates the civil-liability regime (Sections 43, 43A, 44, 45) from the criminal regime (Sections 65–85 and beyond) • [Substantive and Procedural Focus] Investigation, jurisdiction, adjudication, appeals, and enforcement given weight comparable to the offences • [Digital Evidence and Cyber Forensics] A specialised, techno-legal treatment, including the Bharatiya Sakshya Adhiniyam 2023 and the Section 63 certificate regime • [Fully Updated (2024–2026)] Reflects the latest statutes, rules, and judicial pronouncements • [Illustrations and Landmark Cases] Worked hypotheticals plus decisions such as Shreya Singhal, the Puttaswamy privacy rulings, Anvar P.V. v. P.K. Basheer, ICICI Bank v. Uma Shankar, Kunal Kamra, and X Corp (Twitter) v. Union of India • [Concept-based, ‘Techno-Legal’ Approach] Explains the technology before the law for readers without a technical background • [Cross-audience Utility] Useful to students, academicians, researchers, practitioners, and law-enforcement personnel alike

Buy Now


Turn static files into dynamic content formats.

Create a flipbook
Taxmann's Cyber Laws by Taxmann - Issuu