CYBERCRIME AND DATA PROTECTION LAWS IN INDIA: EMERGING LEGAL CHALLENGES
Main Article Content
Abstract
The digitization of governance, business, banking and social interaction in India has been happening at an unprecedented speed and with it, the rise of the cybercrime and the need for a robust data protection law. This paper explores the statutory landscape of cyberspace in India over the past two decades, first the Information Technology Act, 2000 and then the Information Technology (Amendment) Act, 2008, until the Digital Personal Data Protection Act, 2023, the country's first comprehensive personal-data law, was enacted. The paper is divided into five thematic sections, respectively addressing the statutory framework of cyber law, the data protection regime, cybercrimes against individuals, cybercrimes against property and the State and new challenges created by artificial intelligence, cross-border data flows and cloud jurisdiction. A separate chapter then examines key court rulings such as that in Shreya Singhal v. Union of India, Justice K.S. Puttaswamy's decision in its favour and other privacy, intermediary liability and electronic evidence cases, that have influenced the application of these laws. The paper states that while India has constructed a reasonably developed legal structure, there are still several areas of enforcement, cooperation, victim redressal and regulation of emerging technologies which remain unaddressed. Finally, it provides recommendations on the strengthening of the institutional capacity, harmonisation of the Digital Personal Data Protection Act with sectoral regulation and reform of criminal procedure in order to address the challenges posed by the fast-changing digital environment.
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
References
The Information Technology Act, 2000 (Act No. 21 of 2000).
The Information Technology (Amendment) Act, 2008 (Act No. 10 of 2009).
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.