Sample Read
© All rights reserved Price : ` 625 First Published : August 2026 Published by : Taxmann Publications (P.) Ltd. Sales & Marketing : 59/32, New Rohtak Road, New Delhi-110 005 India Phone : +91-11-45562222 Website : www.taxmann.com E-mail : sales@taxmann.com Regd. Office : 21/35, West Punjabi Bagh, New Delhi-110 026 India Printed at : Tan Prints (India) Pvt. Ltd. 44 Km. Mile Stone, National Highway, Rohtak Road Village Rohad, Distt. Jhajjar (Haryana) India E-mail : sales@tanprints.com Disclaimer Every effort has been made to avoid errors or omissions in this publication. In spite of this, errors may creep in. Any mistake, error or discrepancy noted may be brought to our notice which shall be taken care of in the next edition. It is notified that neither the publisher nor the author or seller will be responsible for any damage or loss of action to any one, of any kind, in any manner, therefrom. It is suggested that to avoid any doubt the reader should cross-check all the facts, law and contents of the publication with original Government publication or notifications. No part of this book may be reproduced or copied in any form or by any means [graphic, electronic or mechanical, including photocopying, recording, taping, or information retrieval systems] or reproduced on any disc, tape, perforated media or other information storage device, etc., without the written permission of the publishers. Breach of this condition is liable for legal action. For binding mistake, misprints or for missing pages, etc., the publisher’s liability is limited to replacement within seven days of purchase by similar edition. All expenses in this connection are to be borne by the purchaser. All disputes are subject to Delhi jurisdiction only.
Contents
PAGE
About the Author
I-5
Preface
I-9
Acknowledgement
I-11
List of Cases
I-23
Abbreviations
I-27
CHAPTER 1 INTRODUCTION
Introduction
1
CHAPTER 2 INFORMATION TECHNOLOGY ACT - ITS EVOLUTION AND AMENDMENTS 2.1
Introduction
9
2.2
UNCITRAL Model Law on E-Commerce
9
2.3
The Information Technology Act, 2000
11
2.4
Laws amended through the Information Technology Act, 2000
11
2.5
Amendments to Information Technology Act, 2000
15
2.6
Digital India Act – An incomplete attempt to change the law
21
2.7
Conclusion
22
CHAPTER 3 E-COMMERCE, E-GOVERNANCE AND THE INFORMATION TECHNOLOGY ACT, 2000 3.1
Introduction
23 I-13
I-14
CONTENTS
PAGE
3.2
Conceptual Analysis
24
3.3
Electronic Commerce [E-Commerce]
24
3.4
Electronic Governance [E-Governance]
25
3.5
Electronic Record [E-Records]
25
3.6
Electronic Signature [E-Signature]
26
3.7
Digital Signature
26
3.8
Electronic Contract [E-Contract]
27
3.9
Relevant Provisions of IT Act, 2000
27
3.10
E-commerce Guidelines
36
3.11
Conclusion
37
CHAPTER 4 UNDERSTANDING CYBER CRIMES 4.1
Introduction
38
4.2
Concept of Cybercrimes
39
4.3
Salient Features of Cybercrimes
39
4.4
Classification of Cybercrimes
41
4.5
Forms of Cybercrimes
43
4.6
Cybercrimes vis-à-vis Conventional Crimes
50
4.7
Cybercrimes under other Special Laws
50
4.8
Conclusion
51
4.9
References
51
CHAPTER 5 CYBER CIVIL WRONGS AND THE INFORMATION TECHNOLOGY ACT, 2000 5.1
Introduction
53
5.2
Cyber Civil Wrongs under the Information Technology Act, 2000
53
5.3
Conclusion
64
CONTENTS
I-15 PAGE
CHAPTER 6 ADJUDICATION OF CIVIL CASES UNDER INFORMATION TECHNOLOGY ACT, 2000 6.1
Introduction
65
6.2
Adjudication of cases under Information Technology Act, 2000
65
6.3
Factors to be considered in fixing the amount of compensation or damages
67
6.4
Appeals
67
6.5
Compounding of the Offences
68
6.6
Adjudication process under Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023 – The intersection
68
6.7
Conclusion
71
CHAPTER 7 REGULATION OF CYBERCRIMES IN INDIA THROUGH SUBSTANTIVE LEGAL PROVISIONS 7.1
Introduction
72
7.2
Indian Approach of Regulation of Cybercrimes
73
7.3
Provisions from the Information Technology Act, 2000
73
7.4
Corporate Criminal Liability under Information Technology Act, 2000
95
7.5
Liability of Internet Intermediaries
96
7.6
Cyber Crimes under Bharatiya Nyaya Sanhita, 2023
97
7.7
Surge of Cases of Digital Arrest and the Intervention of Supreme Court through Recent Orders
111
7.8
Conclusion
114
7.9
References
114
CHAPTER 8 CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS 8.1
Introduction
116
I-16
CONTENTS
PAGE
8.2
Nature of Offences
116
8.3
Procedure of Investigation of Cybercrimes
121
8.4
Other Mandatory Rules under the Information Technology Act, 2000
140
8.5
Conclusion
141
CHAPTER 9 INSTITUTIONAL FRAMEWORK AND THE INFORMATION TECHNOLOGY ACT, 2000 9.1
Introduction
142
9.2
Institutions through which Cyber Civil Wrongs are Adjudicated
142
9.3
Appeals from the Orders of the Adjudicating Authority under Information Technology Act, 2000
143
9.4
Section 43A of the Information Technology Act, 2000 vis-avis Digital Personal Data Protection Act, 2023 – The Interface
144
9.5
Appeals from the Data Protection Board of India under Digital Personal Data Protection Act, 2023
146
9.6
Institutions through which Cyber Crimes are Investigated
147
9.7
Cyber Forensics Labs
151
9.8
Other Institutions to ensure Cyber Security in the Country
155
9.9
Conclusion
158
CHAPTER 10 GOVERNMENT’S SPECIAL POWERS TO SAFEGUARD CYBER SPACE UNDER INFORMATION TECHNOLOGY ACT, 2000 10.1
Introduction
159
10.2
Section 69: Government’s Power to Conduct E-Surveillance and Seek for Decryption
159
10.3
Section 69A: Power to block/remove illegal contents from online platforms
169
10.4
Section 69B: Information Technology Act, 2000
178
10.5
Conclusion
183
CONTENTS
I-17 PAGE
CHAPTER 11 CYBERCRIME INVESTIGATION AND THE INDIAN LEGAL PROVISIONS RELATING TO JURISDICTION 11.1
Introduction
185
11.2
Important Basis for Invoking Jurisdiction and Related Principles
189
11.3
Conclusion
195
CHAPTER 12 INTERNET INTERMEDIARY - OBLIGATION AND LIABILITY 12.1
Introduction
197
12.2
Definition of Internet Intermediary
198
12.3
Section 79 of the Information Technology Act, 2000
199
12.4
Important Amendments made to the Intermediary Rules
203
12.5
Due diligence by intermediary - An analysis of the current regulatory framework
211
12.6
Extension of Application of Rule 4
239
12.7
Legal Consequence of not Complying with ‘Due Diligence’ Requirements or not Complying with Intermediary Regulations
240
12.8
Other Duties of Internet Intermediary under the Information Technology Act, 2000 and Related Liability
241
12.9
Other MEITY’s Advisories Imposing Obligations upon Intermediaries
244
12.10
Conclusion
244
CHAPTER 13 UNDERSTANDING DIGITAL EVIDENCE AND DIGITAL FORENSIC – FROM LEGAL PERSPECTIVE 13.1
Introduction
246
13.2
Few Prescribed Legal and Forensic Process as Per Some SOPs/Guidelines/Manuals and Related Legal Provisions
249
13.3
Recent Legal Changes
251
13.4
Conclusion
265
I-18
CONTENTS
PAGE
CHAPTER 14 DATA PROTECTION AND INFORMATION TECHNOLOGY ACT, 2000 14.1
Introduction
266
14.2
Definition of ‘Data’
268
14.3
Classification of Data
269
14.4
The Information Technology Act, 2000 and Data Protection
269
14.5
Conclusion
272
CHAPTER 15 PERSONAL DATA PROTECTION AND RELATED LEGAL PROVISIONS FROM THE INFORMATION TECHNOLOGY ACT, 2000 15.1
Introduction
274
15.2
Importance of Right to Privacy
275
15.3
Right to Privacy as a Fundamental Right
275
15.4
Concept of ‘Personal Data’
276
15.5
Personal Data and the Information Technology Act, 2000
276
15.6
Conclusion
284
CHAPTER 16 DIGITAL PERSONAL DATA PROTECTION ACT, 2023 AND RULES – AN OVERVIEW 16.1
Introduction
285
16.2
Aim and Objective
286
16.3
Scope and Ambit
286
16.4
Important Concepts and their Definitions
287
16.5
Some Important Provisions
289
16.6
Exceptions to Rules Restricting Data Processing & Data Processing by State and its Instrumentalities
294
16.7
Rights of Data Principal
298
16.8
Other Obligations of the data Fiduciary
302
16.9
Additional Obligations of Significant Data Fiduciary
305
CONTENTS
I-19 PAGE
16.10
Data Erasion v. Data Retention & Production
307
16.11
Data Privacy of Children or a person with disabilities
309
16.12
Data Transfer Beyond India
311
16.13
Data Protection Board of India
312
16.14
Date of Implementation
317
16.15
Conclusion
319
CHAPTER 17 A GLIMPSE INTO THE PROMOTION AND REGULATION OF ONLINE GAMING ACT, 2025 17.1
Introduction
320
17.2
Promotion and Regulation of Online Gaming Act, 2025 (“PROG ACT”)
320
17.3
Important Definitions
321
17.4
Important Provisions of the Act and the Rules
321
17.5
Conclusion
326
CHAPTER 18 CROSS-BORDER MEASURES REGULATING CYBER CRIMES AND ENSURING CYBER SECURITY – AN OVERVIEW 18.1
Introduction
327
18.2
Budapest Convention on Cyber Crime
328
18.3
UN Cybercrime Convention
334
18.4
G7 [Group of 7] 24/7 Cybercrime Network
344
18.5
BRICS and India
346
18.6
G20 – India and Cyber Security
352
18.7
ASEAN – India and Cyber Security Strategies
354
18.8
SAARC – India and Cyber Security
357
18.9
India’s Bilateral Arrangements
358
18.10
India and MLAT Agreements
361
18.11
India and Extradition Agreements
362
18.12
Conclusion
362
I-20
CONTENTS
PAGE
CHAPTER 19 EMERGING FORMS OF CYBER TECHNOLOGY AND CHALLENGES TO LEGAL REGULATORY FRAMEWORK 19.1
Introduction
364
19.2
Novel forms of technology and the challenges they pose to regulatory framework
365
19.3
Conclusion
383
Annexure 1
Resolution adopted by the general assembly [on the report of the sixth committee (A/51/628)] 51/162 model law on electronic commerce adopted by the united nations commission on international trade law
389
Annexure 2
MEITY’S notification of appointment of Adjudicating Authority under Information Technology Act, 2000
391
Annexure 3
The Information Technology (Qualification and Experience of Adjudicating Officers and Manner of Holding Enquiry) Rules, 2003
392
Annexure 4
MEITY’S notification on amendment to the information technology (Qualification and Experience of Adjudicating Officers and Manner of Holding Enquiry) Rules, 2003
398
Annexure 5
Bharatiya Sakshya Adhiniym, section 63 - Certificate Format
399
Annexure 6
Bharatiya Sakshya Adhiniyam –Prescribed format of the second certificate under section 63 to be issued by the expert
401
Annexure 7
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
402
Annexure 8
Ministry of Electronics and Information Technology Notification on Information Technology (InterMediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2023
419
Annexure 9
Ministry of Electronics and Information Technology Notification on commencement of the DPDP Act, 2023
427
CONTENTS
I-21 PAGE
Annexure 10 The Information Technology (National Critical Information Infrastructure Protection Centre and Manner of Performing Functions and Duties) Rules, 2013
428
Annexure 11 The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
433
SUBJECT INDEX
439
CHAPTER CYBERCRIME INVESTIGATION
8
AND INDIAN PROCEDURAL LEGAL PROVISIONS
SYNOPSIS 8.1 Introduction 8.2 Nature of Offences 8.3 Procedure of Investigation of Cybercrimes 8.4 Other Mandatory Rules under the Information Technology Act, 2000
8.5 Conclusion
8.1 INTRODUCTION Cybercrime involves various forms of offences, some falling under the ambit of Information Technology Act, 2000 while some falling under the ambit of other laws including the Bharatiya Nyaya Sanhita, 2023 as well as under some special laws such as Protection of Children from Sexual Offences Act, 2012. While Bharatiya Nagarik Suraksha Sanhita prescribes rules of procedure related to a crime covered under Bharatiya Nyaya Sanhita, other special laws may lay down their own rules of procedure to be followed while conducting investigation, inquiry and trial of crimes covered under their framework. Wherever special laws are silent about a process, the procedure laid down under Bharatiya Nagarik Suraksha Sanhita of 2023 must be followed. This chapter explains the process laid down in relation to investigation of cybercrimes with reference to the Bharatiya Nagarik Suraksha Sanhita and the Information Technology Act, 2000.1
8.2 NATURE OF OFFENCES Even though the Information Technology Act, 2000 does not lay down detailed rules related to the procedure to be followed while investigating cybercrimes, yet there are provisions indicating to certain extent the
1. Note that some procedures may be different in relation to offences covered under Protection of Children from Sexual Offences Act, 2012.
116
CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS
117
procedural rules to be adhered to while dealing with offences covered under the Act. According to Section 77B of the Information Technology Act, 2000 “Notwithstanding anything contained in the Code of Criminal Procedure, 1973, the offence punishable with imprisonment of three years and above shall be cognizable and the offence punishable with imprisonment of three years shall be bailable.” Recognising an offence as a cognizable offence indicates that the offence is of complex nature and serious form. In comparison to the non-cognizable offence, cognizable offences are usually subjected to severe punishment. They are seen as offences against State and hence their investigations are conducted by the State police or other investigation agencies. An investigation police officer hence is empowered to investigate cognizable offences without any order of investigation by a Magistrate. While on the other hand, a police officer cannot investigate a non-cognizable offence unless there is an order to investigate issued to him by a Magistrate. Note that all the crimes covered under the Information Technology Act, 2000 are cognizable offences. Prior to the amendments made to the Act, through the Jan Vishwas Act, Section 72 was a non-cognizable offence but it is now decriminalised and is subjected to penalty. Hence as on today most of the cybercrimes under Information Technology Act, 2000 are cognizable in nature and must be investigated by police. ILLUSTRATIONS (a) A hacks B’s Computer System. B files a FIR against A. Since this is an offence under Section 66 of the IT Act, 2000 it must be investigated by the police. (b) X has published a defamatory post against Y on a social media platform. Here even though defamation is a crime under Section 356 of BNS, yet since it is not a cognizable offence, it cannot be investigated by the police. As an aggrieved person, Y can however file a private criminal compliant against X.
Section 77B of the Information Technology Act, 2000 makes all the offences punishable with imprisonment upto three years as bailable offence. This means that unless the offence is punishable with more than 3 years, they are bailable in nature. Hence if a person is arrested during investigation of a bailable offence, he must be immediately released on bail. While on the other hand, if a person is arrested in relation to a non-bailable offence, that is, in relation to a cybercrime which is punishable with more than 3 years of imprisonment, he may or may not be released on bail, since the offence is non-bailable in nature. In a non-bailable case, the bail is granted subject to the discretionary power of the court, while in a bailable offence, bail is a matter of right of the accused. There are however guidelines laid down by courts which must be considered while deciding on bail applications in non-bailable offences.
118
CYBER LAWS
ILLUSTRATION (i) X is arrested in relation to a case of cheating by impersonation, which is an offence under Section 66C of the Information Technology Act, 2000. This being an offence punishable with imprisonment up to 3 years is a bailable offence. X, hence, if is arrested must be released on bail as soon as he furnishes bail. (ii) Y is arrested for the offence of hacking a Protected System under Section 70 of the Information Technology Act, 2000. Since the term of imprisonment under Section 70 can extend up to 10 years it is a non-bailable offence. Hence during investigation Y may or may not be released on bail and the decision to release him on bail will be that of the court which will be based on various criterias and as per the guidelines laid down in this regard by several courts. Y here has no right to be released on bail unlike in a case of bailable offence.
The following table indicates the nature of offences: COGNIZABLE OR NON-COGNIZABLE
BAILABLE OR NON-BAILABLE
PROVISION FROM THE IT ACT, 2000
OFFENCE COVERED
EXTENT OF PUNISHMENT
Section 65
Tampering with computer source documents
with imprisonment up to Cognizable three years, or with fine which may extend up to two lakh rupees, or with both.
Bailable
Section 66
Computer related offences
with imprisonment for a Cognizable term which may extend to three years or with fine which may extend to five lakh rupees or with both.
Bailable
Section 66B
Punishment for dishonestly receiving stolen computer resource or communication device
with imprisonment of ei- Cognizable ther description for a term which may extend to three years or with fine which may extend to rupees one lakh or with both.
Bailable
Section 66C
Punishment for identity theft
with imprisonment of ei- Cognizable ther description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.
Bailable
Section 66D
Punishment for cheating by personation by using computer resource
with imprisonment of ei- Cognizable ther description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees.
Bailable
CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS COGNIZABLE OR NON-COGNIZABLE
119
PROVISION FROM THE IT ACT, 2000
OFFENCE COVERED
EXTENT OF PUNISHMENT
BAILABLE OR NON-BAILABLE
Section 66E
Punishment for violation of privacy
with imprisonment which Cognizable may extend to three years or with fine not exceeding two lakh rupees, or with both.
Bailable
Section 66F
Punishment for cyber terrorism
with imprisonment which Cognizable may extend to imprisonment for life
Non-Bailable
Section 67
Punishment for publishing or transmitting obscene material in electronic form
shall be punished on first Cognizable conviction with imprisonment of either description for a term which may extend to three years and with fine which may extend to five lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to five years and also with fine which may extend to ten lakh rupees
First time offence – Bailable
Section 67A
Punishment for publishing or transmitting of material containing sexually explicit act, etc. in electronic form
shall be punished on first Cognizable conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to ten lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to seven years and also with fine which may extend to ten lakh rupees.
Non-Bailable
Section 67B
Punishment for publishing or transmitting of material depicting children in sexually explicit act, etc. in electronic form
shall be punished on first Cognizable conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to ten lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term.
Non-Bailable
Second or subsequent time offence – non-Bailable
120 PROVISION FROM THE IT ACT, 2000
CYBER LAWS OFFENCE COVERED
EXTENT OF PUNISHMENT
COGNIZABLE OR NON-COGNIZABLE
BAILABLE OR NON-BAILABLE
which may extend to seven years and also with fine which may extend to ten lakh rupees Section 68
Power of Controller to give directions
for a term not exceeding Non – Cognizable two years or a fine not exceeding one lakh rupees or with both.
Bailable
Section 69
Power to issue directions for interception or monitoring or decryption of any information through any computer resource
(4) The subscriber or inter- Cognizable mediary or any person who fails to assist the agency referred to in sub-section (3) shall be punished with imprisonment for a term which may extend to seven years and shall also be liable to fine.
Non- Bailable
Section 69A
Power to issue directions for blocking for public access of any information through any computer resource
(3) The intermediary who Cognizable fails to comply with the direction issued under sub-section (1) shall be punished with an imprisonment for a term which may extend to seven years and also be liable to fine.
Non- Bailable
Section 69B
Power to authorise to monitor and collect traffic data or information through any computer resource for cyber security
(4) Any intermediary who Non- Cognizable intentionally or knowingly contravenes the provisions of sub-section (2) shall be punished with an imprisonment for a term which any extend to one year or shall be liable to fine which may extend to one crore rupees, or with both
Bailable
Section 70
Protected system
(3) Any person who secures Cognizable access or attempts to secure access to a protected system in contravention of the provisions of this section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.
Non- Bailable
CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS PROVISION FROM THE IT ACT, 2000
OFFENCE COVERED
EXTENT OF PUNISHMENT
COGNIZABLE OR NON-COGNIZABLE
Section 70B
Indian Computer Emergency Response Team to serve as national agency for incident response.
(7) Any service provider, Non-cognizable intermediaries, data centres, body corporate or person who fails to provide the information called for or comply with the direction under sub-section (6), shall be punishable with imprisonment for a term which may extend to one year or with fine which may extend to one crore rupees or with both.
Bailable
Section 71
Penalty for misrepresentation.
imprisonment for a term Non-cognizable which may extend to two years, or with fine which may extend to one lakh rupees, or with both.
Bailable
Section 73
Penalty for publishing electronic signature Certificate false in certain particulars
with imprisonment for a Non-cognizable term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.
Bailable
Section 74
Publication for fraudulent purpose.
with imprisonment for a Non-cognizable term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.
Bailable
121
BAILABLE OR NON-BAILABLE
As indicated in the above table, most of the offences under Information Technology Act, 2000 are cognizable in nature. They hence must be investigated by police.
8.3 PROCEDURE OF INVESTIGATION OF CYBERCRIMES As mentioned earlier, a police officer is empowered to investigate a cognizable offence without an order by the magistrate. He is also obliged to investigate a non-cognizable offence provided he is ordered to do so through an order of a Magistrate. In both cases, he has the same power of investigation except that in a non-cognizable case, when he is investigating a case based on a Magistrate’s order, he cannot arrest the accused unless with a Magistrate’s order to arrest. Hence, he requires an arrest warrant to arrest an accused during investigation of a non-cognizable offence.
122
CYBER LAWS
Bharatiya Nagarik Suraksha Sanhita along with the Information Technology Act, 2000 lays down rules of procedure in relation to investigation of cybercrimes. Since the provisions relating to investigation of cybercrimes are not exhaustively laid down under the Information Technology Act, 2000, the provisions from BNSS must be adhered to when a cybercrime is investigated. Investigation of cybercrime must be conducted as per below explained procedure prescribed by BNSS.
Registration of FIR Registration of FIR marks the beginning of investigation of a crime. It is mandatory on the part of the police officer to register FIR if he receives information related to a cognizable offence. Earlier police used to insist for concerned police station’s jurisdiction for both registration of FIR as well as investigation of a case based on such FIR. However, courts through their judicial decisions had persistently insisted for immediate registration of FIR upon receipt of information related to a cognizable offence. The courts even insisted for registration of Zero FIR, meaning an FIR without number being assigned or specified on it. This would mean that the FIR at least could be registered based on the information received and later such FIR could be transferred to police stations having jurisdiction.2 Despite court’s efforts in mandating registration of FIR, there were many incidences when registration was not done. Hence, there was a need to make necessary amendments to law to mandate registration of FIR. BNSS has to some extent revised law relating to registration of FIR. The provision – that is - Section 173 of BNSS provides as follows: “(1) Every information relating to the commission of a cognizable offence, irrespective of the area where the offence is committed, may be given orally or by electronic communication to an officer in charge of a police station, and if given— (i) orally, it shall be reduced to writing by him or under his direction, and be read over to the informant; and every such information, whether given in writing or reduced to writing as aforesaid, shall be signed by the person giving it; (ii) by electronic communication, it shall be taken on record by him on being signed within three days by the person giving it, and the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may by rules prescribe in this behalf: Provided that if the information is given by the woman against whom an offence under section 64, section 65, section 66, section 67, section 68, section 69, section 70, section 71, section 74, section 75, section 76, section 77, section 78, section 79 or section 124 of the Bharatiya Nyaya Sanhita, 2023 is alleged to have been
2. Law relating to jurisdiction is discussed in detail in Chapter 11 of this book
CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS
123
committed or attempted, then such information shall be recorded, by a woman police officer or any woman officer: Provided further that— (a) in the event that the person against whom an offence under section 64, section 65, section 66, section 67, section 68, section 69, section 70, section 71, section 74, section 75, section 76, section 77, section 78, section 79 or section 124 of the Bharatiya Nyaya Sanhita, 2023 is alleged to have been committed or attempted, is temporarily or permanently mentally or physically disabled, then such information shall be recorded by a police officer, at the residence of the person seeking to report such offence or at a convenient place of such person’s choice, in the presence of an interpreter or a special educator, as the case may be; (b) the recording of such information shall be videographed;
(c) the police officer shall get the statement of the person recorded by a Magistrate under clause (a) of sub-section (6) of section 183 as soon as possible. (2) A copy of the information as recorded under sub-section (1) shall be given forthwith, free of cost, to the informant or the victim. (3) Without prejudice to the provisions contained in section 175, on receipt of information relating to the commission of any cognizable offence, which is made punishable for three years or more but less than seven years, the officer in charge of the police station may with the prior permission from an officer not below the rank of Deputy Superintendent of Police, considering the nature and gravity of the offence, — (i) proceed to conduct preliminary enquiry to ascertain whether there exists a prima facie case for proceeding in the matter within a period of fourteen days; or
(ii) proceed with investigation when there exists a prima facie case. (4) Any person aggrieved by a refusal on the part of an officer-in-charge of a police station to record the information referred to in sub-section (1), may send the substance of such information, in writing and by post, to the Superintendent of Police concerned who, if satisfied that such information discloses the commission of a cognizable offence, shall either investigate the case himself or direct an investigation to be made by any police officer subordinate to him, in the manner provided by this Sanhita, and such officer shall have all the powers of an officer-in-charge of the police station in relation to that offence failing which such aggrieved person may make an application to the Magistrate.”
According to Section 173 of the Bharatiya Nagarik Suraksha Sanhita [BNSS], an informer or a victim of crime, can get a FIR registered by giving information about the cognizable offence either orally to the police or in writing. If it is given orally the same will be reduced into writing. As per the revised provision in BNSS, FIR can also be registered by using electronic communication mode. Hence the use of the term E-FIR. In this
124
CYBER LAWS
case, the informer can get his information registered by using electronic modes of communication such as through a phone call or an email or a messenger platform, etc. Section 2(i) of BNSS defines “electronic communication” as “the communication of any written, verbal, pictorial information or video content transmitted or transferred (whether from one person to another or from one device to another or from a person to a device or from a device to a person) by means of an electronic device including a telephone, mobile phone, or other wireless telecommunication device, or a computer, or audio-video player or camera or any other electronic device or electronic form as may be specified by notification, by the Central Government.” While in a case of FIR being registered orally the informer must sign on the report and thereby authenticate the contents of it. When a FIR is registered through online modes or through phone calls, it is important to ensure that such FIR is not a false information or a vexatious report. To ensure that the information received is authentic and the person making it takes up the responsibility for getting such registration done, BNSS states that the person registering an E-FIR should sign on the registered FIR within 3 days from the date of providing such information. Today information relating to cybercrimes can be shared with the police by using the helpline number. That is, via number 1930 in India. While the helpline helps victims of cybercrimes report their cases at the earliest time possible it is mandated to be transformed into a regular registered FIR later, i.e., within 3 days. This initial reporting through helplines are crucial since emergency actions can be immediately taken based on the information shared, such as freezing bank accounts from where and to where unauthorised money has been transferred, getting illegal and abusive contents removed from the online platforms etc. Sharing of information via helpline till registration of FIR provides “golden time” to prevent loss/harm, thereby necessitating immediate actions by the police and other authorities without waiting for formal registration of a case. Once a police officer receives information related to a crime, as far as that information indicates commission of a cognizable offence, he has no other option but to register a FIR. Use of the word “shall” in Section 154(1)3 of the earlier Criminal Procedure Code clearly
3. According to Section 154, CRPC: “Every information relating to the commission of a cognisable offence, if given orally to an officer-in-charge of a police station, shall be reduced to writing by him or under his direction, and be read over to the informant; and every such information, whether given in writing or reduced to writing as aforesaid, shall be signed by the person giving it, and the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may prescribe in this behalf.”
CYBERCRIME INVESTIGATION AND INDIAN PROCEDURAL LEGAL PROVISIONS
125
shows the legislative intent, i.e., it is mandatory to register a FIR if the information given to the police discloses the commission of a cognizable offence.4 Courts too have through their judicial decisions insisted upon compulsory registration of FIRs based on such information. Hence whenever police receive information about a cognizable offence, they must register First Information Report.5 Thus, FIR is nothing but the FIRST INFORMATION REPORT. It is a book or a register maintained by the police at the police station in which information related to cognizable offences are entered. According to Section 154(1) of CRPC once information related to a cognizable offence reaches the police, they must enter such information in a book specifically kept in prescribed format for this purpose. This book or register is nothing but the FIR – i.e. – the First Information Report. Section 173(1) of BNSS too continues to use similar words, that is, “the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may by rules prescribe in this behalf.” Procedurally registration of FIR marks the beginning of the crime investigation. It is from here that the investigation of crime starts.
Meaning of the term ‘Investigation’ Investigation refers to “collection of evidence.” According to Section 2(l) of BNSS “investigation” “includes all the proceedings under this Sanhita for the collection of evidence conducted by a police officer or by any person (other than a Magistrate) who is authorised by a Magistrate in this behalf.” Usually investigation of crimes is conducted by the police officers unless it is entrusted to be done by others through an order of the Magistrate. Since “collection of evidence” also refers to a very comprehensive process, what evidences needs to be collected for what case depends upon the nature of such case. For example: in a case of cybercrime of hacking, the investigation may involve collection of log in details, details of the computer system that was hacked, the digital devices or other tools through which hacking was done, etc. On the other hand, investigation of a crime of murder may require collection of evidences like the tool or weapon used to commit the offence, post mortem report, that is, the medical evidence, etc. 4. According to Section 154, CRPC: “Every information relating to the commission of a cognisable offence, if given orally to an officer-in-charge of a police station, shall be reduced to writing by him or under his direction, and be read over to the informant; and every such information, whether given in writing or reduced to writing as aforesaid, shall be signed by the person giving it, and the substance thereof shall be entered in a book to be kept by such officer in such form as the State Government may prescribe in this behalf.” 5. State of Andra Pradesh v. Punati Ramube, 1993 CR L J 3684 (SC), also see: Lalita Kumari v. Govt. of U.P. (2014) 2 SCC 1
Cyber Laws AUTHOR : PUBLISHER : DATE OF PUBLICATION : EDITION : ISBN NO : No. of Pages : BINDING TYPE :
Nagarathna Annappa Taxmann July 2026 2026 Edition 9789375615248 480 Paperback
Rs. 625 DESCRIPTION Cyber Laws is a comprehensive, analytically driven textbook on India’s cyber-law regime. It traces the framework from the Information Technology Act 2000—India’s first cyber legislation, modelled on the UNCITRAL Model Law on E-Commerce— through its successive amendments (notably 2008) to the newest statutes reshaping the field: the Digital Personal Data Protection Act 2023 and the DPDP Rules, the Promotion and Regulation of Online Gaming Act 2025, and the cyber-relevant provisions of the Bharatiya Nyaya Sanhita, Bharatiya Nagarik Suraksha Sanhita, and Bharatiya Sakshya Adhiniyam 2023. Its centre of gravity is the regulation of cybercrime—both substantive (what conduct is prohibited and what civil or criminal liability attaches) and procedural (investigation, jurisdiction, adjudication, appeals, and digital evidence)—around which it builds the connected themes of modern cyber law: e-commerce and e-governance, cyber civil wrongs, intermediary liability, digital evidence and cyber forensics, data protection and privacy, the State’s surveillance and content-blocking powers, cross-border cooperation, and emerging technologies. Treating cyber law as an inherently ‘techno-legal’ subject, the author explains the underlying technology before mapping it onto statute and case law, in a lucid, illustration-rich and unusually current style. The book is written for a broad, multidisciplinary readership, and its dual substantive/procedural structure lets each group use it differently: • Students of Law, Cyber Law, and Cyber Forensics • Academicians and Researchers • Legal Practitioners • Law Enforcement Officers, Investigators, and Prosecutors • Compliance, Data-protection, and Technology Professionals • The Judiciary and Adjudicating Authorities The Present Publication is the 1st Edition, authored by Dr Nagarathna Annappa, with the following noteworthy features: • [Complete Legislative Evolution] Traces Indian cyber law from the IT Act 2000 to the DPDP Act 2023, showing how an e-commerce statute became the country’s principal cybercrime and cyber-security law • [Comprehensive Thematic Coverage] Dedicated treatment of intermediary liability, e-commerce, e-governance, privacy, data protection, and online gaming • [Civil Wrongs and Cybercrimes Distinguished] Separates the civil-liability regime (Sections 43, 43A, 44, 45) from the criminal regime (Sections 65–85 and beyond) • [Substantive and Procedural Focus] Investigation, jurisdiction, adjudication, appeals, and enforcement given weight comparable to the offences • [Digital Evidence and Cyber Forensics] A specialised, techno-legal treatment, including the Bharatiya Sakshya Adhiniyam 2023 and the Section 63 certificate regime • [Fully Updated (2024–2026)] Reflects the latest statutes, rules, and judicial pronouncements • [Illustrations and Landmark Cases] Worked hypotheticals plus decisions such as Shreya Singhal, the Puttaswamy privacy rulings, Anvar P.V. v. P.K. Basheer, ICICI Bank v. Uma Shankar, Kunal Kamra, and X Corp (Twitter) v. Union of India • [Concept-based, ‘Techno-Legal’ Approach] Explains the technology before the law for readers without a technical background • [Cross-audience Utility] Useful to students, academicians, researchers, practitioners, and law-enforcement personnel alike
Buy Now