Modern Indian Cyber Laws and Technology-Based Justice: Can Digital Crimes Be Punished Faster and More Effectively?

I. Introduction 

India’s tryst with cyber legislation is now a quarter-century old. Yet, the gap between the  volume of digital offending and the system’s capacity to punish it has arguably never been  wider. The Indian Cyber Crime Coordination Centre recorded 15,96,679 cybercrime-related  complaints on the National Cyber Crime Reporting Portal in 2023, rising to 22,68,346 in 2024  -a year-on-year increase of over 42 per cent, with reported financial losses climbing from  ₹2,290.24 crore in 2022 to ₹22,845.73 crore in 2024.¹ Against this arithmetic of scale stands a  strikingly modest conviction record: a Right to Information-based analysis of police data from  twenty-eight states found that of roughly 1.67 lakh cybercrime cases registered between 2020  and 2022, only 2,706 persons were convicted, a conviction rate hovering between 0.93 per cent  and 2 per cent across the three years.² The question this paper poses whether digital crime in  India can be punished faster and more effectively is therefore not rhetorical. It is a live  administrative and constitutional problem, and the answer depends on disentangling three  distinct things that are often spoken of as one: the substantive statutory framework, the  institutional machinery that operationalises it, and the technological tools now being deployed  to compress the distance between offence and outcome. This paper proceeds in four parts. It first traces the evolution of the statutory architecture from  the Information Technology Act 2000 (IT Act) through its 2008 amendment to the cyber relevant provisions of the Bharatiya Nyaya Sanhita 2023 and the Digital Personal Data  Protection Act 2023. It then examines the enforcement and adjudicatory architecture -police  cyber cells, the I4C ecosystem, the moribund Cyber Appellate Tribunal, and the courts – before  turning to the “digital arrest” phenomenon as a case study in the law’s reactive posture. It  concludes that speed and effectiveness in India’s cyber-justice system are being pursued chiefly  through pre-emptive, technology-driven fraud interdiction rather than through the criminal trial  process, and that this bifurcation, while pragmatic, raises its own accountability concerns. 

II. The Statutory Architecture: From the IT Act 2000 to the BNS 

The IT Act 2000 was drafted principally to give legal recognition to electronic records and  digital signatures in line with the UNCITRAL Model Law on Electronic Commerce, and its  penal provisions were, in this sense, an afterthought bolted onto a facilitative statute. ³ Chapter XI of the original Act criminalised a narrow band of conduct: tampering with computer source  documents (section 65), hacking (the original section 66), and publishing obscene material in  electronic form (section 67). Civil liability for unauthorised access, data theft, and the  introduction of viruses was addressed separately under section 43, with adjudication entrusted  to an “Adjudicating Officer” under section 46, whose orders were appealable to a Cyber  Appellate Tribunal under section 48.⁴ The Information Technology (Amendment) Act 2008, passed in the aftermath of the 26/11  Mumbai attacks and following extensive industry lobbying after the Bazee.com controversy,  substantially rewrote the penal architecture.⁵ It introduced section 66A, criminalising the  sending of “grossly offensive” or “menacing” information by means of a computer resource;  sections 66B to 66F, covering receipt of stolen computer resources, identity theft, cheating by  personation, violation of privacy, and cyber-terrorism respectively; sections 67A and 67B on  sexually explicit and child sexual abuse material; and a broadened section 69, empowering the  government to intercept, monitor, or decrypt information without the “public emergency”  precondition that governs telephonic interception under the Indian Telegraph Act 1885.⁶ It was  this 2008 amendment, debated in Parliament for barely a few hours, that gave the Act both its  enforcement teeth and its most notorious constitutional liability. 

That liability crystallised in Shreya Singhal v Union of India, in which the Supreme Court, in  a judgment delivered by Nariman J on 24 March 2015, struck down section 66A in its entirety  as unconstitutionally vague and over-broad, holding that its terms were incapable of being  narrowly construed to fall within the reasonable restrictions permitted under Article 19(2) of  the Constitution and that its chilling effect on protected speech under Article 19(1)(a) could not  be cured by assurances of restrained executive application.⁷ The Court preserved sections 69A  and 79 with the intermediary “safe harbour” rules read down but excised 66A completely — and yet, as subsequent research by the Internet Freedom Foundation and reporting before the  Supreme Court in People’s Union for Civil Liberties v Union of India has shown, first  information reports continued to be registered under the dead provision for years afterward,  prompting the Court in 2019 to direct state police forces and the National Crime Records  Bureau (NCRB) to purge and prevent further prosecutions under it.⁸ The episode is instructive:  it demonstrates that a statute’s formal invalidation does not, on its own, alter enforcement  practice at the police-station level, a theme that recurs throughout the effectiveness question  this paper examines.

The passage of the Bharatiya Nyaya Sanhita 2023, replacing the Indian Penal Code 1860 with  effect from 1 July 2024, has layered a second stratum of cyber-relevant offences onto the IT  Act rather than displacing it. Cheating, including online and UPI-based fraud, is now addressed  under section 318 BNS (replacing IPC section 420); cheating by personation- the provision  most directly applicable to fake profiles and impersonation frauds -is dealt with under section  319 (replacing IPC section 419); forgery of electronic records falls within sections 335, 336  and 338; and stalking, including cyberstalking through monitoring of a woman’s use of the  internet, email, or other electronic communication, is retained under section 78, mirroring the  erstwhile IPC section 354D.⁹ The result is a dual-track regime in which a single act of online  fraud may attract simultaneous liability under the IT Act (say, section 66C or 66D) and the  BNS (section 318 or 319), a structural overlap that complicates charge-framing and has  generated inconsistent police practice as to which statute is invoked, or whether both are. A further, distinct layer arrived with the Digital Personal Data Protection Act 2023, India’s first  cross-sectoral data protection statute, which received presidential assent in August 2023 but  whose substantive provisions await full notification pending the operationalisation of the  Digital Personal Data Protection Rules 2025.¹⁰ The DPDPA establishes obligations on “Data  Fiduciaries” to process personal data only for lawful purposes with consent or specified  legitimate uses, mandates breach notification, and creates a Data Protection Board with the  power to impose penalties running up to ₹250 crore for significant non-compliance.¹¹ It is,  however, a civil-regulatory instrument rather than a criminal one; it does not create new  offences of the kind found in the IT Act, and its Board is not a court of criminal jurisdiction.  Its relevance to the “faster justice” question is therefore indirect: it may improve the traceability  and accountability of entities that hold breached data, but it does nothing to accelerate the  prosecution of the individual fraudster who exploits that data. 

III. Institutional Architecture and the Speed Problem 

If the substantive law has multiplied, the institutional capacity to enforce it has not kept pace,  and it is at this institutional layer that the “faster and more effective” question is really decided.  Three features of the architecture are worth isolating.

First, adjudication under the IT Act’s civil track has effectively collapsed. The Cyber Appellate  Tribunal, established in New Delhi under section 48, functioned only fitfully: the Centre for  Internet and Society’s review of its record found that the Tribunal delivered a mere seventeen  judgments before its Chairperson’s post fell vacant in 2011 upon the incumbent’s retirement,  after which it could not lawfully hold hearings at all, since the presiding officer’s presence was  a statutory precondition.¹² The vacancy persisted for years despite a writ petition before the  Karnataka High Court and government assurances of appointment “within six months.” The  Finance Act 2017 ultimately abolished the CAT altogether, along with several other sector specific tribunals, transferring its residual jurisdiction to the Telecom Disputes Settlement and  Appellate Tribunal as part of a broader tribunal-rationalisation exercise.¹³ A specialised cyber adjudication forum conceived in 2000 to give victims a speedy, technically competent civil  remedy had, within a decade, ceased to function in any meaningful sense – a cautionary  illustration of how institutional design failures can nullify sound statutory intent. 

Second, criminal enforcement remains overwhelmingly a police function exercised through  general-purpose cybercrime cells that are unevenly resourced across states, and the NCRB’s  Crime in India 2022 report – the most recent published in full – records 65,893 cybercrime cases  registered under the IT Act and related sections that year, a 24.4 per cent increase over 2021’s  52,974, with cyber fraud alone accounting for 64.8 per cent of registrations, followed by  extortion (5.5 per cent) and sexual exploitation (5.2 per cent).¹⁴ Notably, the NCRB’s published  tables report registration and disposal figures for the criminal justice system as a whole but do  not break out cybercrime-specific conviction rates, a gap that state-level RTI disclosures have  had to fill; it is those disclosures that produced the sub-2-per-cent conviction figures cited at  the outset.¹⁵ The reasons commonly advanced for this attrition – jurisdictional confusion where  offender, victim, server, and payment gateway sit in different states or countries; the technical  demands of digital forensics on an under-trained investigating cadre; the absence, in most  districts, of dedicated cyber forensic laboratories; and the sheer delay in obtaining data from  foreign platforms under mutual legal assistance treaties – are structural rather than doctrinal,  meaning that no amount of statutory redrafting alone will cure them. 

Third, and most significant for the “faster” half of the question, the Union government has  invested its energy not in accelerating trials but in building a pre-emptive interdiction layer that  operates largely outside the criminal process. The I4C’s Citizen Financial Cyber Fraud  Reporting and Management System, accessible via the 1930 helpline and the National Cyber  Crime Reporting Portal, allows victims to trigger an immediate freeze request to banks and payment intermediaries. Government data placed before the Lok Sabha records that more than  ₹7,130 crore has been saved across over 23.02 lakh complaints since the system’s 2021 launch,  that the Suspect Registry launched in September 2024 has enabled banks to decline transactions  worth ₹8,031.56 crore by cross-referencing 18.43 lakh suspect identifiers and 24.67 lakh mule  accounts, that the Samanvaya coordination platform has facilitated the arrest of 16,840 accused  persons, and that over 11.14 lakh SIM cards and 2.96 lakh IMEIs linked to fraud have been  blocked.¹⁶ This is, in effect, a parallel system of technologically mediated restitution and  disruption that operates at a speed no criminal trial could match – freezing funds within hours  rather than years- but it substitutes financial recovery and network disruption for the due process guarantees, evidentiary standards, and punitive function of a criminal conviction. It is  fast, but it is not “punishment” in the doctrinal sense contemplated by the IT Act or the BNS. 

IV. The Digital Arrest Phenomenon as a Case Study 

The rise of “digital arrest” scams since 2023–24 crystallises the tension between statutory  adequacy and enforcement capacity. In this modus operandi, fraudsters impersonating officers  of the Central Bureau of Investigation, the Enforcement Directorate, or local police contact  victims by video call, allege their involvement in offences such as money laundering or parcel  trafficking, and coerce them -through fabricated arrest warrants and threats of “digital custody”  – into transferring funds. Losses of ₹120.30 crore were reported in just the first four months of  2024, and individual cases involving losses in the range of ₹30 lakh to over ₹7 crore have been  documented, including one incident in Agra where a woman reportedly suffered a fatal cardiac  event after being falsely accused of involvement in human trafficking during such a call.¹⁷  Every element of a “digital arrest” scam is already an offence under existing law — impersonation of a public servant under section 204 BNS, cheating by personation under  section 319 BNS, cheating under section 318 BNS, and offences under sections 66C and 66D  of the IT Act for identity theft and cheating by personation using a computer resource — so the  phenomenon is not evidence of a legislative lacuna.¹⁸ It is evidence that detection, attribution  across international VoIP and messaging infrastructure (I4C has reported blocking over a  thousand Skype IDs linked to such scams), and cross-border enforcement against operations  frequently traced to Southeast Asian scam compounds remain the binding constraints,  prompting the Union Home Ministry to constitute an inter-ministerial committee in May 2024  specifically to address transnational cyber-fraud networks.¹⁹ In November 2024, the Supreme  Court itself intervened, directing the Reserve Bank of India, state governments, and banks to  frame urgent standard operating procedures for fund freezing and restoration in digital-arrest cases, effectively judicially endorsing the pre-emptive, technology-based interdiction model  discussed above as the practically available remedy where criminal prosecution is unlikely to  be swift.²⁰ 

V. Assessment: Faster, But Not Yet More Effective 

Drawing these threads together, the honest answer to whether Indian digital crime can be  punished “faster and more effectively” is asymmetric. On speed, the answer is qualifiedly yes,  but the acceleration has occurred almost entirely in the administrative and financial-interdiction  space – helpline-triggered freezes, SIM and IMEI blocking, suspect registries – rather than in  the judicial process of investigation, charge-sheeting, trial, and sentencing, which remains as  slow and forensically under-resourced as ever, as the sub-2-per-cent conviction rate attests. On  effectiveness, understood as the law’s capacity to secure accountability through conviction and  deterrence, the record is weak, and the weakness is institutional rather than textual: India does  not obviously lack criminal provisions covering hacking, identity theft, cyber-fraud, obscenity,  or stalking, but it lacks a functioning specialised adjudicatory forum (the CAT experiment  failed and was formally abandoned), a sufficiently trained investigative cadre at the district  level, forensic infrastructure proportionate to caseload, and a settled jurisdictional protocol for  offences that are inherently multi-state or transnational. The DPDPA, when fully operational,  may improve upstream data governance and breach accountability but will not itself accelerate  criminal disposal. A coherent reform agenda would therefore need to run on two tracks  simultaneously: consolidating the fragmented dual-track liability under the IT Act and BNS  into clearer charging guidance, and – more urgently – reviving genuine judicial or quasi-judicial  capacity, whether through dedicated cyber courts on the model recommended intermittently by  law commissions and bar bodies, or through properly resourced forensic and investigative  units, so that the considerable technological gains already achieved in fraud interdiction are  eventually matched by gains in the courtroom itself.

REFERENCES 

1. Ministry of Home Affairs, Lok Sabha Unstarred Question No 432 (2 December 2025)  https://www.mha.gov.in/MHA1/Par2017/pdfs/par2025-pdfs/LS02122025/432.pdf accessed 30 August 2026. 

2. ‘Only 1.6% Conviction Rate in 2 yrs Amid Surge in Cybercrime Cases’ The Tribune (Delhi, 2024) https://www.tribuneindia.com/news/delhi/only-1-6-conviction-rate-in-2-yrs-amid-surge-in-cybercrime-cases accessed 30 August 2026. 

3. Information Technology Act 2000, Preamble; Debarati Halder and K Jaishankar, Cyber  Crime and the Victimization of Women: Laws, Rights and Regulations (IGI Global  2012) ch 2. 

4. Information Technology Act 2000, ss 43, 46, 48 (as originally enacted). 5. Information Technology (Amendment) Act 2008. 

6. Information Technology Act 2000, ss 66A–66F, 67A, 67B, 69 (as inserted/amended by  the Information Technology (Amendment) Act 2008); Indian Telegraph Act 1885, s  5(2). 

7. Shreya Singhal v Union of India AIR 2015 SC 1523. 

8. People’s Union for Civil Liberties v Union of India, Writ Petition (Criminal) No 199 of  2013, Supreme Court of India, order dated 5 February 2019; Internet Freedom  Foundation, ‘SC Direction: Stop Prosecuting People Under S.66A’ (Internet Freedom  Foundation, 2019) https://internetfreedom.in/sc-direction-stop-prosecuting-people-under-the-unconstitutional-s-66a/ accessed 30 August 2026. 

9. Bharatiya Nyaya Sanhita 2023, ss 78, 318, 319, 335, 336, 338. 

10. Digital Personal Data Protection Act 2023 (No 22 of 2023); Digital Personal Data  Protection Rules 2025. 

11. Digital Personal Data Protection Act 2023, ss 8, 25, 27, sch (penalty schedule). 

12. Centre for Internet and Society, ‘A Review of the Functioning of the Cyber Appellate  Tribunal and Adjudicatory Officers under the IT Act’ (CIS-India) https://cis-india.org/internet-governance/blog/review-of-functioning-of-cyber-appellate-tribunal-and-adjudicatory-officers-under-it-act accessed 30 August 2026.

13. Finance Act 2017, s 183 and Part XIV (Eighth Schedule); Telecom Disputes Settlement  and Appellate Tribunal, ‘Introduction’  https://tdsat.gov.in/admin/introduction/uploads/TDSAT%20INTRO.pdf accessed 30  August 2026. 

14. National Crime Records Bureau, Crime in India 2022 (Ministry of Home Affairs 2023);  summarised in ‘NCRB’s Crime in India 2022 Report’ (Drishti IAS, 2023)  https://www.drishtiias.com/daily-updates/daily-news-analysis/ncrbs-crime-in-india-2022-report accessed 30 August 2026. 

15. The Tribune (n 2). 

16. Ministry of Home Affairs (n 1); ‘Over Rs 7,000 Crore Saved Through Citizen Financial  Cyber Fraud Reporting and Management System’ (News on Air, 17 December 2025)  https://www.newsonair.gov.in/over-rs-7000-crore-saved-through-citizen-financial-cyber-fraud-reporting-and-management-system/ accessed 30 August 2026. 

17. Vivekananda International Foundation, ‘The Growing Problem of Digital Arrest Scams  in Bharat’ (VIF, 26 November 2024)  https://www.vifindia.org/article/2024/november/26/The-Growing-Problem-of-Digital-Arrest-Scams-in-Bharat accessed 30 August 2026. 

18. Bharatiya Nyaya Sanhita 2023, ss 204, 318, 319; Information Technology Act 2000, ss  66C, 66D. 

19. Deccan Herald, ‘Amid Rise in Digital Arrest Cases, Indian Cyber Crime Coordination  Centre Issues Advisory for Citizens’ (2024) https://www.deccanherald.com/india/amid-rise-in-digital-arrest-cases-indian-cyber-crime-coordination-centre-issues-advisory-for-citizens-3221509 accessed 30 August 2026. 

20. ‘Breaking: Supreme Court Directs RBI, States & Banks to Implement Urgent SOPs and  Money Restoration Measures to Tackle “Digital Arrest” Scams’ (Verdictum, 2024)  https://www.verdictum.in/amp/supreme-court/digital-arrest-scams-interim-directions-rbi-1619172 accessed 30 August 2026.

Scroll to Top
Consent Preferences