Cyber Law Questions and Answers in India
Cyber matters in India are governed by the Information Technology Act, 2000, the criminal code provisions on cheating and forgery, and the Digital Personal Data Protection Act, 2023 for personal data.
People ask about online financial fraud and UPI scams and how to report them, identity theft and fake profiles, online harassment, stalking and non-consensual images, defamatory posts and takedown, data breaches by companies holding their information, and ransomware or hacking affecting a business.
For fraud, there are two parallel steps and both matter. Report on the National Cyber Crime Reporting Portal or the 1930 helpline, which can trigger a hold on funds still in the chain, and report in writing to your bank. RBI's directions on unauthorised electronic transactions limit a customer's liability substantially where the report is prompt and the fault does not lie with the customer, so the written record of when you reported is the evidence that decides liability.
For harassment and non-consensual content, the IT Act read with the Intermediary Guidelines requires platforms to remove flagged content within specified timelines, and a grievance officer must be reachable. Escalation runs from the platform's grievance officer to the Grievance Appellate Committee, alongside any police complaint.
Businesses face a different set of obligations. The Digital Personal Data Protection Act, 2023 requires notice and consent for processing personal data, purpose limitation, and breach notification, with significant penalties for failure to protect data. Ransomware incidents additionally attract CERT-In's directions on incident reporting within a short window and on log retention.
For online financial fraud, speed matters more than anything else. Report to the National Cyber Crime Reporting Portal and to your bank within the golden hour, because recovery becomes considerably harder once funds are layered onward.