ICT Governance in India
ICT Laws in India
Infrastructure without law is chaos. India has built a progressively sophisticated legal framework to govern its digital infrastructure. Here are the most important laws — their purpose, key provisions, and criticisms.
Information Technology Act, 2000
The IT Act, 2000 is India’s foundational cyber law — enacted when the internet was just arriving in homes and offices. It was the first law to give legal recognition to electronic records and digital signatures, and to define what constitutes a crime in cyberspace.
Key Provisions
- Legal recognition: Electronic records and digital/electronic signatures have the same status as physical documents and handwritten signatures.
- e-Governance enablement: Government departments can accept electronic filings and issue digital approvals.
- Cyber offences: Defines unauthorised access, hacking, identity theft, online fraud, data theft, and cyber terrorism.
- Intermediary liability: Defines the role of ISPs and online platforms; provides safe harbour protection subject to due diligence.
- Government powers: Empowers government to block websites, intercept communications, and protect Critical Information Infrastructure.
- Extra-territorial jurisdiction: Applies to offences committed anywhere in the world if they involve Indian computer systems.
- CERT-In: Designated as the nodal agency for cybersecurity incident management.
Key Sections — The IT Act Reference Chart
| Section | Subject Matter |
| Section 43 & 66 | Computer-related offences — unauthorised access, data theft, virus introduction (civil + criminal liability) |
| Section 66B | Dishonestly receiving stolen computer resource |
| Section 66C | Identity theft — misuse of password, digital signature |
| Section 66D | Cheating by impersonation using a computer — online fraud |
| Section 66E | Violation of privacy — capturing/transmitting private images without consent |
| Section 66F | Cyber terrorism — attacks threatening national security or critical infrastructure |
| Section 70 | Critical Information Infrastructure — declaration as Protected Systems; strict penalties for unauthorised access |
| Section 70B | Statutory establishment of CERT-In as the national cybersecurity nodal agency |
IT (Amendment) Act, 2008 — Key Updates
- Technology-neutral: Recognised electronic signatures alongside digital signatures — allowing biometric eSign.
- New cyber offences: Added cyber terrorism, identity theft, online impersonation, privacy violation.
- Data protection: Mandated that body corporates handling sensitive personal data must implement security practices — failing which they are liable for compensation.
- CERT-In: Granted statutory status under the Amendment.
- Section 66A (struck down): Penalised sending ‘offensive’ electronic messages — struck down by the Supreme Court in Shreya Singhal Case (2015) as unconstitutional for violating free speech.
Digital Personal Data Protection (DPDP) Act, 2023
The DPDP Act, 2023 is India’s comprehensive data protection law — the result of years of debate following the Puttaswamy judgment (2017) that established privacy as a fundamental right. It applies to personal data in digital form processed in India or related to offering services to individuals in India.
Key Concepts
- Data Principal: The individual whose personal data is being processed — i.e., you and me.
- Data Fiduciary: The entity that determines the purpose and means of processing personal data (e.g., Facebook, HDFC Bank, a government ministry).
- Significant Data Fiduciaries (SDFs): High-risk entities handling large or sensitive data — enhanced compliance, audits, and mandatory Data Protection Officer.
- Consent Managers: Intermediaries helping individuals manage, review, and withdraw consent in a standardised, interoperable manner.
Rights of Data Principals
- Right to access: Know what personal data is held and how it is being processed.
- Right to correction and erasure: Correct inaccurate data; erase data once purpose is fulfilled.
- Right to nominate: Nominate a person to exercise data rights in case of death or incapacity.
- Grievance redressal: First to the Data Fiduciary, then escalate to the Data Protection Board.
Other Key Features
- Consent framework: Consent must be free, specific, informed, unconditional, unambiguous, and revocable.
- Legitimate uses: Non-consensual processing allowed for state functions, legal obligations, medical emergencies, disaster response.
- Children’s data: Verifiable parental consent required; harmful processing of children’s data prohibited.
- Cross-border transfers: Permitted to countries notified by GoI — no blanket data localisation mandate.
- Penalties: Civil monetary penalties — focused on deterrence and compliance, not criminalisation.
- Data Protection Board of India: Statutory, quasi-judicial enforcement body.
IT (Reasonable Security Practices & SPDI) Rules, 2011
Framed under IT Act 2000, these rules provided India’s first statutory data protection framework before the DPDP Act, focusing on Sensitive Personal Data or Information (SPDI): passwords, financial information, medical records, biometric data, and sexual orientation.
- ISO/IEC 27001 security practices and regular audits mandatory for body corporates.
- Consent-based collection: SPDI may only be collected, used, or disclosed with prior consent.
- Privacy policy: Body corporates must publish a clear privacy policy.
- Purpose limitation: SPDI used only for its stated purpose; third-party disclosure only with consent.
IT (Intermediary Guidelines & Digital Media Ethics Code) Rules, 2021
The IT Rules 2021 regulate social media platforms, messaging apps, digital news publishers, and OTT platforms. They operationalise the intermediary liability provisions of the IT Act, 2000.
Key Provisions
- Due diligence: Intermediaries must publish rules and privacy policies; remove unlawful content on lawful notice.
- Content removal: Unlawful content within 36 hours of a valid court/government order; non-consensual intimate images within 24 hours.
- Grievance redressal: Acknowledge within 24 hours; resolve within 15 days; Grievance Officer based in India.
- Significant Social Media Intermediaries (SSMIs): Must appoint a Chief Compliance Officer, Nodal Contact Person, and Resident Grievance Officer.
The Traceability Controversy
The most debated provision: messaging platforms must enable identification of the ‘first originator’ of a message for national security cases.
- Government’s stance: Not asking to break encryption; platforms should use alternative technical solutions (e.g., hashing).
- Platform’s stance (WhatsApp, Signal): Any traceability effectively breaks end-to-end encryption (E2EE) — a fundamental privacy tool.
- Legal status: Contested in WhatsApp LLC vs. Union of India — verdict pending.
OTT Regulation — Three-Tier Mechanism
- Self-regulation by publishers (adherence to code of ethics).
- Self-regulatory bodies headed by retired judges or eminent persons.
- Government oversight mechanism — issues directions when necessary.
OTT platforms must also provide content classification (age ratings) and parental controls.
CERT-In Cyber Security Directions, 2022
Issued under Section 70B of IT Act, 2000, applying to all service providers, intermediaries, data centres, body corporates, and government organisations.
| Provision | Requirement |
| Mandatory Incident Reporting | Report specified cyber incidents (data breaches, ransomware, malware, DoS attacks) to CERT-In within 6 hours of detection |
| Log Retention | ICT system logs maintained for at least 180 days, stored within India |
| Time Synchronisation | All ICT systems must sync with NIC or authorised time sources for accurate timestamping |
| KYC and Data Storage | VPN providers, cloud services, and data centres must maintain subscriber/KYC data for 5+ years |
National Cyber Security Policy, 2013
India’s first comprehensive cybersecurity policy framework, introduced by DeitY (now MeitY).
Vision: ‘To build a secure and resilient cyberspace for citizens, businesses, and government.’
- Protection of Critical Information Infrastructure (CII) across power, telecom, banking, transport, defence, and governance.
- CERT-In as nodal agency: Early warning, real-time response, and recovery.
- National cyber coordination: Inter-agency coordination, public-private partnerships, threat intelligence sharing.
- Capacity building: Creating a large pool of cybersecurity professionals through education and training.
Critical Information Infrastructure (CII)
CII refers to computer resources whose incapacitation or destruction would severely impact national security, economic security, public health and safety, or critical public services. The IT Act, 2000 empowers the GoI to declare any such resource a ‘Protected System.’
Nodal agency: National Critical Information Infrastructure Protection Centre (NCIIPC).
CII sectors: Power and energy, banking and finance, telecommunications, transport (railways, aviation, ports), defence, healthcare, and emergency services.
Telecom Laws — Old vs. New
| Aspect | Indian Telegraph Act, 1885 | Telecommunications Act, 2023 |
| Era | Colonial era — originally for telegraph | Modern, technology-neutral for the digital era |
| Status | Replaced by Telecom Act 2023 | Replaces Telegraph Act 1885 and Wireless Telegraphy Act 1933 |
| Licensing | Complex licensing regime | Simplified authorisation and registration framework |
| Spectrum | No structured management | Auction-based assignment; spectrum sharing, trading, and surrender allowed |
| RoW | No specific provisions | Statutory backing for uniform, time-bound RoW permissions |
| Consumer Protection | Minimal provisions | Explicit consumer protection, QoS standards, anti-spam provisions |
| National Security | Interception and suspension powers | Lawful interception, network security standards, emergency powers with safeguards |
| Technology Coverage | Telegraph and telephone | 5G, IoT, satellite, and future technologies — technology-neutral |
Key Institutions for ICT in India
For UPSC, knowing which institution does what is essential. The most common confusion is between MeitY and DoT, and between TRAI and TDSAT. This reference table clarifies all of them:
| Institution | Type | Core Mandate |
| MeitY | Ministry | Nodal ministry for ICT policy, Digital India, e-governance, cyber laws (IT Act, DPDP Act), and MeghRaj |
| DoT | Department under MoC | Telecom policy, licensing, spectrum, broadband (NBM, BharatNet), Telecom Act 2023 |
| TRAI | Statutory Regulator (TRAI Act 1997) | Regulates telecom tariffs and QoS; advises government on spectrum; promotes competition; consumer protection |
| TDSAT | Specialised Tribunal (TRAI Amdt Act 2000) | Adjudicates disputes between DoT and licensees, between operators, and between operators and consumers; hears appeals against TRAI orders |
| NPCI | Not-for-profit company (RBI and IBA promoted) | Operates retail payment systems: UPI, IMPS, RuPay, AePS, FASTag (NETC), BHIM, Bharat QR, NACH |
| CERT-In | Statutory agency under MeitY (IT Act 2000) | National nodal agency for cybersecurity incident response; mandatory incident reporting; cyber threat alerts and advisories |
| NIC | Technology partner under MeitY | ICT backbone for e-governance; develops government portals; operates NICNET; manages National Data Centres; supports MeghRaj |
| UIDAI | Statutory authority under MeitY (Aadhaar Act 2016) | Issues and manages Aadhaar; maintains CIDR; sets data security and authentication standards |
NPCI — The Payments Backbone
NPCI (National Payments Corporation of India) is the not-for-profit organisation promoted by RBI and the Indian Banks’ Association that operates India’s entire retail payment ecosystem. Without NPCI, there would be no UPI, no RuPay, no FASTag, no IMPS, and no AePS.
- Ensures interoperability across banks and payment apps.
- Develops indigenous payment infrastructure — RuPay reduces dependence on Visa and Mastercard.
- Supports government programmes: DBT, toll collection, bill payments.
- Creates open standards and APIs that enable fintech innovation.
CERT-In — India’s Cyber Firefighters
CERT-In (Indian Computer Emergency Response Team) is India’s cyber first-responder — the organisation that responds when the power grid is attacked or a bank suffers ransomware.
- Cyber incident response: Malware, ransomware, data breaches, phishing, DDoS attacks.
- Mandatory incident reporting: 6-hour reporting mandate for all major entities.
- Cyber threat alerts: Real-time advisories warning of emerging threats.
- Coordination: Works with international CERTs, law enforcement, and intelligence agencies.
