Cybersecurity Laws and Regulations in India - July 2026 

Author: Adv (Dr.) Prashant Mali, | Date : 22/07/2027

India Does Not Have A Cybersecurity Law. It Has a Federation of Them.

Salus populi suprema lex esto. - Cicero, De Legibus, III.3.8

Every few weeks a founder or a CXO tells me, with the serenity of a man who has never been audited: “Sir, we are ISO 27001 certified, so we are compliant.”

I have learned to pause before replying. Because the honest answer is that in India, cybersecurity compliance is not a certificate. It is a standing committee of regulators, none of whom have met, all of whom have jurisdiction over you, and each of whom has a different clock.

Here is the map I wish someone had handed me twenty years ago..


I. The Spine: Constitution, Statute, Evidence

Everything begins at Article 21. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 made informational privacy a fundamental right and gave us the four-part proportionality test that every surveillance measure, every data mandate, every takedown must now survive. It is the grundnorm of Indian cyber law and, incidentally, the reason India could not simply legislate its way to a surveillance state.

The Information Technology Act, 2000 remains the workhorse: Section 43 (unauthorised access), Section 66 (computer-related offences), Sections 66C and 66D (identity theft, cheating by personation the statutory home of the “digital arrest” racket), Section 66F (cyber terrorism), Sections 69, 69A and 69B (interception, blocking, traffic-data monitoring), Section 70 (protected systems), Section 70A (NCIIPC), Section 70B (CERT-In), Sections 72 and 72A (breach of confidentiality), Section 79 (safe harbour), and Section 85 (officer-in-default liability - the provision your board should actually be reading).

Note one quiet demolition: the DPDP Act omitted Section 43A. The old civil compensation route for negligent handling of sensitive personal data is gone, replaced by a regulator led penalty model. Whether that trade private remedy for public fine  is progress or loss is a genuinely interesting jurisprudential question. Ask me over coffee.


Layered on top: the Bharatiya Nyaya Sanhita, 2023 (organised cyber-enabled crime,

cheating, forgery), the Bharatiya Nagarik Suraksha Sanhita, 2023, and the Bharatiya Sakshya Adhiniyam, 2023, whose Section 63 carries forward the electronic-evidence certificate regime built by Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473 and Arjun  panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1. Half the cyber prosecutions I see collapse not on facts but on that certificate. And one statute that almost never appears on cybersecurity slides but plainly belongs there: the Copyright Act, 1957. Section 65A criminalises circumvention of technological protection measures - India’s answer to DMCA S1201 - and Section 65B protects rights management information. These are access-control and metadata- integrity provisions that happen to live in an IP statute. Add Section 63 (cognizable, and the workhorse of every source-code-theft FIR against a departing engineer, usually pleaded alongside Sections 43 and 66 of the IT Act and the relevant BNS provisions), and the point is unavoidable: if CERT-In can compel you to produce an SBOM, the licence obligations that SBOM exposes are Copyright Act obligations. And Shreya Singhal v. Union of India, (2015) 5 SCC 1 - which struck down Section 66A and read down Section 69A - remains the case the government must argue around, not through.


II. The Horizontal Layer: MeitY and CERT-In

CERT-In Directions of 28 April 2022, issued under Section 70B(6), are still the most operationally brutal instrument in Indian cyber law: Six hours to report a notifiable incident. 180 days of ICT logs, maintained within India. NTP synchronisation to NIC/NPL time servers. Five years of KYC retention for VPS, cloud and VPN providers. Six hours. Not six business hours. Your SOC lead discovering ransomware at 2 a.m. onDiwali does not get a grace period for sentiment.

CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines (25 July 2025) then changed what an “audit” means. The scope now runs to twenty-six-plus categories- cloud, OT/ICS, IoT, source code review, red teaming, blockchain, AI system audits, and SBOM/QBOM/AIBOM verification. Crucially, tool-only, checklist-driven testing is expressly discouraged, and OWASP Top 10 is declared not a comprehensive standard. If your VAPT report is a Nessus export with a cover page, you are no longer audited. You are decorated. Add the SPDI Rules, 2011, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the sharpest recent development: Then, in quick succession, two amendments. The IT Amendment Rules, 2025 (notified 22 October 2025, effective 1 November 2025) tightened Rule 3(1)(d) itself, requiring that takedown intimations issued from a sufficiently senior authorised officer rather than from anyone with a government email address - a procedural safeguard that reads as a direct response to the criticism levelled at the Sahyog architecture.

And then the sharpest development of all:

The IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 - notified 10 February 2026, in force 20 February 2026. They introduce “synthetically generated information” (SGI), compress the takedown clock from 36 hours to three hours, mandate prominent labelling of AI-generated audio-visual content, require embedded provenance metadata where feasible, prohibit the removal of those labels, and impose proactive technical verification duties on significant social media intermediaries. Safe harbour is the collateral.

Which brings us to X Corp v. Union of India (Karnataka HC, 24 September 2025, W.P. 7405/2025). Nagaprasanna J., across 351 pages, upheld the Sahyog portal as an instrument of public good, held that Section 79(3)(b) read with Rule 3(1)(d) supports

takedown obligations independent of Section 69A, and held that a foreign company cannot invoke Article 19. An appeal was filed in November 2025. Watch that space - it is the most consequential intermediary-liability litigation since Shreya Singhal.

III. The Data Layer: DPDP Act and Rules

The Digital Personal Data Protection Act, 2023, finally became operational when the

DPDP Rules, 2025 were notified on 13–14 November 2025. The rollout is phased: Immediately (Nov 2025): definitions, and the Data Protection Board of India. 13 November 2026: the Consent Manager regime. 13 May 2027: the substantive obligations notice, security safeguards, breach notification, retention, cross-border conditions, Significant Data Fiduciary duties, and data-principal rights.

Penalties: up to ₹250 crore for failure of reasonable security safeguards, ₹200 crorefor failure to notify a breach or for children’s-data violations, ₹50 crore residual. Per

violation. Now hold that against CERT-In. A single incident triggers a six-hour clock to CERT-In and a separate breach-notification clock to the Board. Your breach, in other words, has a connecting flight - and if it misses the first leg, the second one does not wait.

IV. The Sectoral Swarm

This is where “one law” becomes a polite fiction.

RBI - and the statute everyone forgets. Before the circulars, there is the Payment and Settlement Systems Act, 2007. Almost every payments-security obligation in India is an exercise of power under it, and almost nobody cites it. Section 4 makes operating a payment system without RBI authorisation unlawful. Section 10(2) - the power to determine standards - is the provision under which the

RBI issued its Storage of Payment System Data directive of 6 April 2018, the origin of India’s payments data-localisation regime. Sections 17 and 18 carry the directions power that the cyber and security circulars actually rest on. Section 21 imposes duties on system providers; Section 22 requires a system provider to keep documents and information confidential - a pre-DPDP confidentiality obligation with teeth, since Section 26(4) makes wrongful disclosure punishable with imprisonment up to six months or a fine up to ₹5 lakh (or twice the damage caused, whichever is higher). Section 26(5) attaches imprisonment of up to ten years and fines up to ₹1 crore, with a daily continuing fine, where an RBI direction is not complied with. Section 27 extends liability to directors and officers, Section 30 empowers the RBI to impose fines directly,

and Section 32 gives the Act overriding effect. Read that list again. A payments company that shrugs at an RBI security direction is not risking a “compliance observation” - it is standing in front of a statute with a custodial provision and an override clause. This is the sharpest enforcement edge in Indian cyber regulation, and it predates the DPDP Act by sixteen years.

Built on that foundation: the Cyber Security Framework for Banks (2016); the Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023); the Master Direction on Digital Payment Security Controls (2021); the Cyber Resilience and Digital Payment Security Controls Directions for non-bank PSOs (2024); Master Directions on Fraud Risk Management (2024); Master Directions on Payment Aggregators (September 2025); the digital banking channel authorisation regime effective 1 January 2026; and the SOP of 2 January 2026 permitting temporary debit holds against cyber-enabledfraud. Also the FREE-AI Committee report, from which the national AI “sutras” were borrowed.


SEBI - the Cybersecurity and Cyber Resilience Framework (CSCRF), Circular

SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024: a five-tier classification across twenty-two entity types, Cyber Capability Index scoring, SOC/M- SOC onboarding, HSM mandates for MIIs, and cyber audits by CERT-In-empanelled auditors. Implementation landed 31 August 2025 for most REs; the live obligation now is the recurring audit cycle. The August 2025 clarifications also gave us the Principle of Exclusivity and Equivalence - dual-regulated entities may satisfy CSCRF through an equivalent framework. A rare and welcome outbreak of regulatory mercy.


IRDAI - the Information and Cyber Security Guidelines, 2026, issued 6 April 2026, replacing the 2023 guidelines. The headline is structural, not technical: the CISO shall not report to the Head of IT and shall not carry business targets; the ISRMC must meet quarterly; supply-chain and third-party controls tighten; incidents still route to CERT-In within six hours. If your CISO’s bonus depends on shipping the product they are meant to block, IRDAI has now made that a compliance defect rather than an org-chart quirk.


DoT / MoC - the Telecommunications Act, 2023; the Telecommunications (Telecom Cyber Security) Rules, 2024 (21 November 2024); and the Amendment Rules, 2025 (22 October 2025), which created the category of Telecommunication Identifier User Entities (TIUEs) - every bank, fintech, e-commerce platform and OTT that uses a mobile number as an identifier - mandated interfacing with the Mobile Number Validation (MNV) platform, and built a central IMEI blacklist with scrubbing duties o resellers. Congratulations: your food-delivery app is now a telecom-security compliance entit.

CCPA - the regulator that governs your consent screen. The Consumer Protection Act, 2019 is not usually filed under “cybersecurity,” and that is precisely why it keeps catching companies off guard. Section 10 constitutes the Central Consumer Protection Authority; Section 18(2)(l) gives it the power to issue guidelines; Sections 20 and 21 let it order discontinuance of unfair practices, recall, and reimbursement; Section 88 attaches imprisonment up to six months or a fine up to ₹20 lakh for non-compliance with its directions.

Under that power, the CCPA notified the Guidelines for Prevention and Regulation of Dark Patterns, 2023 on 30 November 2023 - the first time Indian law named deceptive interface design as a legal wrong. Thirteen patterns are specified: false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised advertisement, nagging, trickwording, SaaS billing, and rogue malware. That last one deserves attention from security counsel: scareware and fake-alert interstitials are now not merely an IT Act offence but a consumer-protection contravention, prosecutable by an entirely different regulator on an entirely different standard of proof.

And the Guidelines do not stand alone. The Consumer Protection (E-Commerce) Rules, 2020 impose their own quasi-security architecture: every e-commerce entity must appoint a grievance officer with published contact details and a 48-hour acknowledgement plus one-month resolution clock (Rule 4(4)-(5)); a nodal contact person for law-enforcement compliance (Rule 4(2)); and, under Rule 4(9), consent through express and affirmative action, with the pre-ticked box expressly out of bounds. Marketplace entities must additionally disclose seller identity and grievance details under Rule 5. Read together with Rule 3 of the IT Rules, 2021, an Indian platform is now running two parallel grievance regimes under two ministries - and being judged on both.

Then came the CCPA Advisory of 5 June 2025 under Section 18(1), directing every e-commerce platform and online service provider to complete a self-audit within three months and eliminate dark patterns, with self-declarations encouraged. By 20 November 2025, twenty-six leading platforms had filed declarations. The Advisory expressly invokes Rule 4(9) - and singles out the pre-ticked checkbox.

Is a “guideline” binding? Yes, and we now have authority. In National Restaurant Association of India v. Union of India [2025:DHC:2084], decided 28 March 2025,

Prathiba M. Singh J. held that the CCPA is not a merely recommendatory body, that guidelines under Section 18(2)(l) carry statutory force, and dismissed the challenge with costs. Anyone still treating the Dark Patterns Guidelines as aspirational should read paragraphs 66 to 73 before the next board meeting.

Here is the convergence that matters. A single pre-ticked consent box on an Indian checkout page simultaneously (a) breaches the Dark Patterns Guidelines as forced action or interface interference, (b) violates Rule 4(9) of the E-Commerce Rules, and (c) vitiates consent under Section 6(1) of the DPDP Act, which demands consent that is free, specific, informed, unconditional and unambiguous by clear affirmative action. Three regulators, one checkbox, and none of them will accept “the UX team owned that flow.”

The instruments nobody indexes. Below the headline frameworks sits a stratum of obligations that surface only when someone is already in trouble. Online gaming. The Promotion and Regulation of Online Gaming Act, 2025 (August 2025) and the PROG Rules, 2026 - notified 22 April 2026, in force 1 May2026 - ban online money games, create the Online Gaming Authority of India, mandate broad “user safety features” covering security-related harms, and require

traffic data and metadata to be retained on computer resources located in India. A localisation mandate in a gaming statute. Nobody’s compliance matrix had that column. Matrimonial platforms. The MeitY (then DeitY) advisory of 6 June 2016 treats matrimonial websites as intermediaries and expects verification of user identity and address proof, mobile verification, and log retention. It is soft law - but it feeds directly into the Section 79 due-diligence standard, which is how soft law in India acquires teeth. Every romance-fraud matter I have handled turns on whether the platform did what that advisory said. Telecom equipment. The National Security Directive on the Telecommunication Sector, operative since June 2021, requires licensees to

procure only from sources designated “trusted” by the National Cyber Security Coordinator, through the Trusted Telecom Portal. Supply-chain security, enacted quietly, years before anyone in India said “SBOM.” Power. The CEA (Cyber Security in Power Sector) Guidelines, 2021, with their own CISO, ISAC-Power reporting and trusted-vendor requirements for a sector

where an outage is not a data breach but a blackout.

Aadhaar. UIDAI’s requirement that requesting entities hold Aadhaar numbers in an Aadhaar Data Vault, referenced by tokens, with keys in an HSM - the most prescriptive cryptographic mandate in Indian law, and one that appears in no statute. Health. The ABDM Health Data Management Policy, still filling the gap left by the never-enacted DISHA Bill.

Government websites. GIGW compliance and the security-audit prerequisite before any government site goes live. MeitY advisories. The SOP on non-consensual intimate imagery (October 2025) and the mature-content advisory of 29 December 2025 - advisory in name,

evidentiary in effect, because the first question in any safe-harbour dispute is what

the intermediary did after MeitY told it what to do.

And the rest of the room: NCIIPC for critical information infrastructure under Section

70A; MHA and I4C (Sahyog, cybercrime.gov.in, Chakshu); TRAI under TCCCPR; NPCI

scheme rules; PFRDA; and MCA’s audit-trail mandate under the Companies (Accounts)

Rules - the edit-log requirement that quietly made every ERP a forensic artefact.V. One Login Screen, Eight Regulators

A concrete example, because abstraction is where compliance goes to die.

A digital lending app asks for a mobile number and an OTP. That single screen engages: DoT (MNV validation, TIUE obligations), RBI under the PSS Act (authorisation, payment-data storage, DPSC controls, authentication standards), DPDP (notice, consent, purpose limitation, retention), CERT-In (log retention, time sync, six-hour reporting), MeitY (intermediary due diligence if there is any user content), and UIDAI if Aadhaar-based KYC is anywhere in the flow.

Six regulators. One text box.

And if that screen carries a pre-ticked “I agree to marketing communications,” add the CCPA and, for the SMS that follows, TRAI under TCCCPR. Eight regulators. Still one text box.

VI. The Judicial Turn

The courts are no longer waiting for the legislature.

On 9 February 2026, a Bench of Chief Justice Surya Kant with Bagchi and Anjaria JJ., in

the suo motu digital-arrest proceedings, described losses exceeding ₹52,000 crore as

robbery and dacoity, flagged the complicity of bank officials, directed the MHA to adopt

the RBI’s SOP nationally, ordered CBI mapping of cases, pressed MeitY on time-bound

intermediary compliance, and moved towards a national victim-compensation

framework. Read alongside the December 2025 order for a pan-India CBI probe, this is

the Court doing regulatory design from the Bench. And in May 2026, the Delhi High Court (Sachin Datta, J.) grounded the right to be forgotten squarely in Puttaswamy’s informational privacy - holding that acquittals and exonerations must mean something in the digital record, not merely in the physical one. Anyone who has litigated de-indexing knows precisely how much that judgment was needed.

VII. Why It Looks Like Chaos (And Mostly Isn’t)

Some scholarship worth carrying into the boardroom:

Julia Black, Decentring Regulation (2001) - polycentric regulation is not a failurestate; it is what happens when no single actor holds the relevant knowledge. India’s

regulatory swarm is Black’s thesis in Devanagari.

Ayres & Braithwaite, Responsive Regulation (Oxford, 1992) - the enforcement

pyramid. India has built the pyramid; we are still arguing about the base.

Ross Anderson & Tyler Moore, The Economics of Information Security, 314

Science 610 (2006) - security fails from misaligned incentives, not missing

technology. IRDAI’s CISO-independence mandate is this paper turned into law.

Mathur et al., Dark Patterns at Scale: Findings from a Crawl of 11K Shopping

Websites, 3 Proc. ACM Hum.-Comput. Interact. (CSCW) 81 (2019) - the empirical

study that turned an anecdote into a taxonomy, and which the CCPA’s thirteen

categories visibly echo.

Cass Sunstein, Sludge and Ordeals, 68 Duke L.J. 1843 (2019), read against Thaler

& Sunstein, Nudge (2008) - a dark pattern is simply a nudge that has stopped

serving the person being nudged. Kant would have called it treating the consumer as

a means. The CCPA calls it confirm shaming. Same objection, different register.

Helen Nissenbaum, Privacy as Contextual Integrity, 79 Wash. L. Rev. 119 (2004) -

why “the data was already public” has never been a defence.

Daniel Solove, A Taxonomy of Privacy, 154 U. Pa. L. Rev. 477 (2006) - still the

sharpest vocabulary we have for harms our statutes under-describe.

Lawrence Lessig, Code v2 (2006) - architecture regulates. The IT Amendment

Rules, 2026, mandating embedded provenance metadata, are Lessig’s “code is law”

enacted verbatim.

Ulrich Beck, Risk Society (1992) - modern law increasingly governs probabilities

rather than acts. That is the entire logic of a six-hour reporting rule.

Kautilya wrote in the Arthashastra that the security of the realm rests on vigilance rather

than on walls. Two thousand years later, our regulators have simply given vigilance a

reporting format, an empanelled auditor, and a deadline.

VIII. The Counter-Offensive: What You Sue With

Every framework above answers the same question - what the State may demand of you. Almost nobody maps the other column: what the law lends you when you are the one being attacked. Hohfeld would have called this the difference between a duty and a power (Some Fundamental Legal Conceptions as Applied in Judicial Reasoning, 23 YaleL.J. 16 (1913)), and the distinction is not academic. Compliance is defensive posture.


Enforcement is manoeuvre.

Trade Marks Act, 1999. Phishing domains, typosquatting, cloned payment pages, fake

franchise portals and impersonation apps are prosecuted under the IT Act — but they

are stopped under trademark law, because an injunction moves in days and a

chargesheet moves in years. Satyam Infoway Ltd. v. Sifynet Solutions, (2004) 6 SCC 145

brought domain names within passing-off. Christian Louboutin v. Nakul Bajaj (Delhi HC,

2018) showed how active involvement costs an intermediary its safe harbour.

And then the decision that changes the practice. In Dabur India Ltd. v. Ashok Kumar

[CS(COMM) 135/2022], decided 30 December 2025, and the connected Colgate

Palmolive Co. v. NIXI, Prathiba M. Singh J. - across roughly 250 pages - treated

anonymous domain registration as systemic cyber fraud rather than routine

infringement. Domain name registrars offering services in India must implement

mandatory e-KYC of registrants; privacy and identity-masking may no longer be the

default; IP logs and timestamps must be retained; registrant data must be disclosed to

investigating authorities within 72 hours of request; registry operators must prevent

re-registration of infringing domains; NIXI is contemplated as a national repository; and

a non-compliant registrar may forfeit safe harbour and face liability as an infringer, with

Section 69A blocking available against it. The relief runs as a dynamic+ injunction,

covering domains that do not yet exist.

Read that as a cybersecurity practitioner, not an IP lawyer. A commercial court has just

imposed KYC, log-retention, and 72-hour law-enforcement disclosure obligations on a

class of intermediaries that no regulator had reached. That is regulation by injunction -

and it is now the fastest anti-phishing remedy available in India.

Copyright Act, 1957 supplies the rest: Section 63 for source-code theft and pirated

deployments, Sections 65A and 65B where protection measures were circumvented,

and John Doe orders where the defendant is a username.

BNS, 2023 completes the set for the criminal track, and the Section 65 BSA/Section 63

certificate determines whether any of it survives cross-examination. One caution on scope. India’s Semiconductor Integrated Circuits Layout-Design Act, 2000 is sometimes offered as part of this landscape. I would leave it out. It is a

TRIPS-compliance registration statute with famously thin uptake and thinner case law,

and it imposes no duty to secure anything. The real hardware-security conversation -

counterfeit chips, hardware trojans, trusted foundries, an HBOM to sit beside the SBOM

- is happening in CERT-In’s audit guidelines, the National Security Directive on

Telecom, and the DoT’s IMEI provisions. Protecting a mask work is not securing a supplychain, any more than registering a trademark secures a login. When the India

Semiconductor Mission acquires a security mandate rather than a funding mandate, that

column will need writing. It does not exist yet.

IX. What I Actually Tell Boards

1. Build one control set, mapped to many regulators. Not five programmes.

2. Run a dual-clock incident playbook: CERT-In first, sectoral regulator and DPB

next.

3. Move the CISO out of the IT reporting line. IRDAI mandated it; every other sector

should read the room.

4. Treat SBOM, AIBOM and provenance metadata as a 2026 deliverable, not a 2028

aspiration.

5. Put your consent and checkout screens through legal review, not just design

review. Dark-pattern exposure sits at the intersection of CCPA, the E-Commerce

Rules and DPDP consent validity - and it is the cheapest of all these risks to fix.

6. Put Section 85 of the IT Act on the board agenda. Personal liability concentrates

attention beautifully.

7. Preserve logs like they are evidence. Because under Section 63 BSA, they are.

Compliance is not a certificate on a wall. It is a habit with an audit trail.

Ubi jus ibi remedium - but only, these days, if you kept the logs.


Adv. (Dr.) Prashant Mali Advocate, Supreme Court of India & Bombay High Court |

Cyber Law, Cyber Security, AI & Data Protection Expert

Which of these frameworks is causing your organisation the most pain right now? I

would genuinely like to know - the gap between what regulators drafted and what

compliance teams can execute is where the next five years of Indian cyber

jurisprudence will be written.

#CyberLaw #DPDPA #CyberSecurity #CERTIn #SEBICSCRF #RBI #IRDAI

#DataProtection #AIGovernance #IndiaLaw