Home > Resources > Cyber Offences & Digital Safety FAQs > IT Act, Cyber Offences & Platform Compliance FAQs
IT Act, Cyber Offences & Platform Compliance FAQs
This page explains selected Information Technology Act cyber-offence provisions, intermediary safe harbour, current platform grievance and compliance rules, cybercrime reporting, CERT-In obligations and electronic-evidence issues in India.
Important scope note. This resource provides general information on selected cyber-law and platform-compliance issues. It does not replace emergency safety action, a criminal complaint, platform-specific advice or a fact-specific legal opinion. Statutory provisions, notified rules, official portals and platform processes can change and should be verified before action.
A. Cyber Offences: Core IT Act Distinctions
No. Online conduct may engage the Information Technology Act, Bharatiya Nyaya Sanhita, privacy or data law, intellectual-property law, contract, consumer law or civil remedies, and some platform-policy violations may not be offences at all. The complaint should identify the actual conduct and match it to the legal ingredients instead of treating “cybercrime” as one generic offence.
Section 43 addresses specified unauthorised acts involving computer resources, including access, copying, introducing contaminants, disruption, denial of access and certain damage to information. Section 66 criminalises acts referred to in Section 43 when they are done dishonestly or fraudulently. A technical incident does not automatically become a Section 66 offence without the required mental element.
Potentially. The analysis should identify what resource was accessed, whether access was without permission or exceeded permission, what data was copied or altered, and whether the conduct was dishonest or fraudulent. Account-sharing history, employee authority and prior permissions can materially affect the assessment.
Section 66C concerns fraudulent or dishonest use of another person’s electronic signature, password or other unique identification feature. It should not be invoked automatically merely because someone created a similar display name or copied a profile photograph. The complaint should identify the particular identification feature and the fraudulent or dishonest use.
Section 66D concerns cheating by personation using a communication device or computer resource. It can apply to phishing, fake customer-care accounts, impersonation scams and similar conduct where personation is used to cheat. Mere parody, criticism or an obviously unofficial fan account should not be described as Section 66D cheating without the necessary deception and cheating ingredients.
Section 66E is a specific bodily-privacy offence concerning intentional or knowing capture, publication or transmission of an image of a person’s private area without consent under circumstances violating that person’s privacy. It is not a general criminal provision for every leaked message, address, telephone number or personal-data disclosure.
No. The Supreme Court struck down Section 66A in Shreya Singhal v. Union of India in 2015, and the current Information Technology Act text records Section 66A as omitted. Threats, cheating, stalking, defamation, obscenity, impersonation or other harmful online conduct must therefore be examined under provisions that remain in force rather than by invoking Section 66A.
Section 65 addresses knowing or intentional concealment, destruction or alteration of computer source code when that source code is required by law to be kept or maintained. It should not be treated as a general offence for every software dispute or disagreement over source-code ownership.
Section 66B concerns dishonest receipt or retention of a stolen computer resource or communication device where the recipient knows or has reason to believe it is stolen. The factual basis for both the stolen resource and the recipient’s state of knowledge should be identified.
Yes, Section 75 gives the Act extra-territorial reach in specified circumstances where conduct outside India involves a computer, computer system or computer network located in India. Jurisdiction, investigation, service and enforcement can still require separate practical analysis.
B. Obscenity, Intimate Content, Privacy, Personal Information and Synthetic Media
They are distinct provisions. Section 67 addresses obscene material in electronic form; Section 67A addresses material containing sexually explicit acts or conduct; and Section 67B deals with child-related sexually explicit material and specified associated conduct. The exact content, age of the person depicted and manner of publication, transmission, collection or access matter.
No. Unnecessary circulation can itself create serious legal and safety problems. Preserve the minimum evidence needed to identify the content, account and location, avoid redistributing illegal or intimate material, and use lawful platform, police or cybercrime reporting channels.
Yes. Depending on the facts, IT Act provisions such as Sections 66E, 67 or 67A can overlap with BNS offences concerning voyeurism, stalking, intimidation or other conduct. The legal classification should be based on what was captured, created, shared, threatened or published and whether consent existed.
No. Consent to creation and consent to dissemination are separate questions. An image can have been captured consensually while later circulation is unauthorised and unlawful. The chronology and scope of consent should be preserved carefully.
No. Section 72 concerns disclosure of information obtained through powers conferred under the IT Act in circumstances covered by that provision. A private leak can instead raise confidentiality, contract, privacy, defamation, data-protection or other legal issues without necessarily fitting Section 72.
Section 72A applies where a person, including an intermediary, while providing services under a lawful contract has obtained personal information and discloses it without consent or in breach of that contract with the intent to cause, or knowledge that the disclosure is likely to cause, wrongful loss or wrongful gain. The Jan Vishwas amendments, effective from 30 November 2023, replaced the former imprisonment-and-fine formulation with a monetary penalty that may extend to ₹25 lakh.
No. The Digital Personal Data Protection Act, 2023 is being commenced in stages. The November 2025 commencement notification brought specified institutional and miscellaneous provisions, including Sections 18 to 26, into force immediately; a limited further set is scheduled one year after publication, and most core processing, rights and obligations provisions are scheduled eighteen months after publication. As of 12 September 2026, those later core provisions are therefore not yet generally in force. Constitutional privacy, contract, confidentiality, the IT Act, current intermediary rules and sector-specific duties can still apply in the meantime.
The current IT Rules define synthetically generated information to cover specified audio, visual or audio-visual information that is artificially or algorithmically created, generated, modified or altered so that it appears real or authentic and depicts an individual or event in a manner likely to be perceived as indistinguishable from reality. The definition contains specified exclusions for certain good-faith editing, accessibility, document and technical uses, so the exact rule should be checked where classification is disputed.
Under the 2026 IT Rules amendment, an intermediary that offers a computer resource enabling or facilitating creation, generation, modification or alteration of synthetically generated information must ensure that such information carries the prescribed prominent label or permanent unique metadata or identifier and must not enable suppression or removal of that marker. Significant social-media intermediaries have additional declaration, verification and labelling duties for synthetic information uploaded or published by users. The precise obligation depends on the intermediary function involved.
No. Labelling addresses transparency, not underlying legality. A labelled deepfake can still violate privacy, defamation, impersonation, consumer-protection, intellectual-property or criminal law depending on its content and use.
C. Intermediary Safe Harbour, Actual Knowledge and Record Preservation
Section 79 provides conditional protection from liability for third-party information where the intermediary satisfies the statutory conditions, maintains a limited intermediary role and observes prescribed due diligence. Safe harbour is not blanket immunity and can be affected by participation in unlawful conduct or failure to comply with legally valid obligations.
No. The current Rule 3 actual-knowledge route should be distinguished from an ordinary private complaint. A platform may voluntarily act under its policies or grievance framework, but the statutory actual-knowledge mechanism is tied to the legally specified court or authorised-government route.
For the Rule 3(1)(d) takedown route, actual knowledge arises through an order of a court of competent jurisdiction or a reasoned written intimation issued through the authorised government route specified in the rule. The order or intimation must identify the legal basis, the unlawful act and the specific URL, identifier or electronic location required to be removed or disabled. An ordinary private complaint is not the same statutory trigger.
Under the 2026 amendment to the IT Rules, an intermediary must remove or disable access to the specified information within three hours of receiving valid actual knowledge through the prescribed court-order or authorised-government route. This three-hour rule should not be confused with the separate grievance-officer timelines for ordinary user complaints.
The rules clarify that voluntary removal or disabling of access to information violating the prohibited-content framework, and action taken through the grievance process, does not by itself violate the specified Section 79 safe-harbour conditions. Voluntary moderation is therefore not the same as a judicial determination of illegality.
The current IT Rules require an intermediary to preserve removed information and associated records, without vitiating the evidence, for one hundred and eighty days for investigation purposes, or for a longer period where lawfully required by a court or government agency.
Where an intermediary collects information from a user for registration, the current IT Rules require that information to be retained for one hundred and eighty days after cancellation or withdrawal of the registration, subject to other applicable legal retention requirements.
Yes. Section 67C requires intermediaries to preserve and retain information for the duration, manner and format prescribed by the Central Government. After the Jan Vishwas amendments, intentional or knowing contravention of Section 67C(1) attracts a monetary penalty that may extend to ₹25 lakh; older summaries describing the former imprisonment provision are outdated.
Yes, where the request is lawfully authorised and satisfies the applicable rule. Under the current intermediary rules, specified information or assistance must generally be provided within seventy-two hours after receipt of a written order that clearly states the purpose, subject to any more specific rule that applies to the service or request. This is distinct from a private user asking a platform to reveal another user’s information.
Not merely by asking. Platforms generally require an appropriate legal basis before disclosing another user’s identifying information. In suitable proceedings, a court or lawfully authorised agency may seek targeted information subject to the governing legal tests.
D. Grievance Timelines, GAC and Account Actions
Under the current IT Rules, the Grievance Officer must acknowledge a qualifying complaint within twenty-four hours and ordinarily resolve it within seven days from receipt. Resolution does not mean that every grievance must result in removal; the intermediary must decide the complaint under the applicable rule, law and policy.
For certain complaints seeking removal of information covered by Rule 3(1)(b), the current proviso requires expeditious action and resolution within thirty-six hours. The proviso expressly excludes specified sub-clauses, so the thirty-six-hour period is not a universal takedown deadline.
No. The proviso to Rule 3(2)(a)(i) excludes Rule 3(1)(b)(iv), the proprietary-rights category covering patent, trademark, copyright and other proprietary rights, from the thirty-six-hour route. Intellectual-property complaints may still proceed through the general grievance process, platform-specific IP channels, copyright-specific mechanisms or court orders depending on the case.
Within two hours of a qualifying complaint by an individual, or a person acting on that individual’s behalf, the intermediary must take reasonable and practicable measures to remove or disable access to content that prima facie exposes the individual’s private area, depicts full or partial nudity or a sexual act, or is electronic impersonation including artificially morphed images. This is a specific victim-protection grievance route, not a universal content-removal period.
No. The special wording concerns specified content involving an individual. A fake corporate page, trademark misuse, counterfeit listing or ordinary account-confusion complaint can require a different grievance, IP, fraud or court route.
The Grievance Appellate Committee (GAC) is the statutory appellate mechanism under Rule 3A of the IT Rules for specified grievances against intermediary decisions. It provides an online appeal route but is not a substitute for urgent police, court or safety action where those remedies are needed.
A person aggrieved by a Grievance Officer’s decision may prefer an appeal to the GAC within thirty days from receipt of the communication. The Committee is required to deal with the appeal expeditiously and endeavours to resolve it finally within thirty calendar days from receipt. The statutory endeavour period should not be represented as a guaranteed outcome date in every case.
No. Eligibility, the nature of the intermediary decision, the platform terms, facts and relief requested matter. A GAC appeal is not a guarantee of restoration and is not a substitute for urgent court, police or safety action where those routes are necessary.
E. Significant Social-Media Intermediaries and Platform Compliance
The current rules require specified additional compliance roles including a resident Chief Compliance Officer, a resident nodal contact person for round-the-clock law-enforcement coordination and a Resident Grievance Officer. The detailed eligibility and role requirements should be checked in the current rules.
Yes. The rules require periodic monthly compliance reports describing grievances received and action taken, along with specified information concerning removals or disabling of access and proactive monitoring where applicable.
A significant social-media intermediary that enables users to display, upload or publish information must require users to declare whether the information is synthetically generated, deploy appropriate technical measures to verify the accuracy of that declaration, and prominently label information confirmed to be synthetic. The rules also require reasonable and proportionate technical measures so that synthetic information is not published without the required declaration or label.
The current rules contain a first-originator provision for significant social-media intermediaries primarily providing messaging services, but only through the specified judicial or Section 69 order route and for the serious offence categories stated in the rule. The rule also contains necessity and less-intrusive-means safeguards and does not create a general private right to trace another user.
No. A consultation draft or proposed amendment is not the same as a notified rule in force. Compliance decisions should distinguish current notified and consolidated rules from proposals that remain under consultation, and should be updated only when a later amendment is formally notified and commenced.
No. Removal, non-removal, account suspension or reinstatement is generally a policy or contractual decision. It can form part of the evidence history, but it is not a criminal conviction or final civil adjudication.
F. Cybercrime Reporting, CERT-In and Electronic Evidence
Preserve full URLs, account and user identifiers, complete screenshots and screen recordings, original messages and files, email headers where available, dates, time and time zone, device information, payment or transaction references, bank or wallet details, platform ticket IDs and prior communications. Avoid altering original files or relying only on cropped screenshots.
No. A screenshot may be useful but can omit metadata, source, account attribution, surrounding context and integrity information. Native files, exports, device or system records, platform responses, transaction records and other corroborating evidence may be necessary depending on the dispute.
Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 governs admissibility of specified electronic records and computer outputs. Section 63(4)(c) uses the prescribed Schedule certificate; the Schedule contains Part A for the party producing the electronic record and Part B for an expert, and records hash values and the applicable algorithm. Whether the certificate route is required for a particular record depends on how the electronic evidence is produced and proved, so source material, device information and integrity records should be preserved rather than relying on a generic certificate.
Hashing can be useful to demonstrate that a preserved electronic file has remained unchanged after collection. It should be combined with a dated collection log, source information and custody record. A hash does not itself prove who created the file, who posted it or whether an offence occurred.
Use the Portal where the facts involve an actual cybercrime or suspected cyber offence, including online financial fraud, account compromise, phishing, impersonation scams, certain intimate-content offences and other reportable cyber incidents. A purely contractual or civil reputation dispute may require a different or additional route.
Preserve the fraud messages, beneficiary and account details, transaction references and payment records; contact the bank, wallet or payment service immediately; and report the incident through the National Cyber Crime Reporting Portal. Helpline 1930 is the official immediate reporting route for online financial fraud, and speed can matter for financial-fraud response.
Not necessarily. Where there is immediate safety risk, financial fraud, non-consensual intimate imagery, child-related material, stalking, account takeover or an active scam, platform and law-enforcement routes may need to be used in parallel. Evidence preservation should occur first where doing so is safe.
CERT-In is the national agency for cyber-incident response under Section 70B of the IT Act. Its functions include collecting and analysing cyber-incident information, issuing alerts and advisories, coordinating incident response and issuing directions relating to cyber-security practices, reporting and assistance. Organisational CERT-In compliance is distinct from an individual victim’s ordinary platform complaint.
Yes. CERT-In’s directions require covered entities to report specified cyber incidents within six hours of noticing the incident or being brought to notice about it. CERT-In’s official FAQs state that available information may be supplied initially and supplemented later, and identify reportable categories including severe cyber incidents, data breaches or leaks, large-scale or frequent incidents and incidents affecting human safety. Organisations should maintain an incident-response plan aligned with the current directions.
Containment may be urgent, but evidence should be preserved before destructive remediation where practicable and safe. Logs, volatile data, images, indicators of compromise and relevant credentials may be important for investigation, regulatory reporting and recovery. Incident-response and forensic steps should be coordinated rather than improvised.
G. Practical Boundaries, Compliance Controls and Common Mistakes
No. A fake profile may involve impersonation, fraud, passing off, defamation, privacy or platform-policy issues, but Section 66C has specific statutory ingredients involving another person’s electronic signature, password or unique identification feature. Section 66D separately requires cheating by personation.
No. Section 72A has specific ingredients: personal information must have been obtained while providing services under a lawful contract and then disclosed without consent or in breach of that contract with the intent to cause, or knowledge that the disclosure is likely to cause, wrongful loss or wrongful gain. Other privacy, confidentiality, contractual or data-protection routes may apply where those ingredients are absent.
Security containment and evidence preservation usually come first. Reset compromised credentials, secure connected systems, preserve login and change-history records, use the platform’s recovery process and consider cybercrime reporting where appropriate. A legal notice should not delay immediate technical protection.
Common mistakes include invoking struck-down Section 66A; treating Sections 66C and 66D as generic fake-account provisions; treating Section 66E as a general privacy offence; assuming every private complaint creates statutory actual knowledge; using old fifteen-day, seventy-two-hour or twenty-four-hour grievance timelines after the 2026 amendments; confusing the three-hour actual-knowledge route with the thirty-six-hour grievance route; overlooking the two-hour intimate-content or impersonation mechanism; treating draft rules as law; failing to preserve platform and electronic evidence; and using criminal allegations to pressure an ordinary commercial dispute.
Maintain clear terms and prohibited-content rules; publish the required grievance mechanism; map current response timelines; maintain escalation paths for safety, intellectual property, fraud and government or court orders; preserve required records; control law-enforcement requests; document account-action decisions; implement cyber-incident reporting and retention processes; monitor current IT Rules amendments; and train relevant staff to distinguish policy breaches from legal offences.
Identify the exact online act; preserve full electronic evidence; determine whether the issue is unauthorised access, identity theft, personation, intimate content, obscenity, financial fraud, data disclosure, defamation, IP infringement or only a policy dispute; identify the precise statutory ingredients; check the current intermediary timeline and platform route; assess urgent safety and financial risk; consider cybercrime or CERT-In reporting where applicable; preserve limitation and litigation options; and define the actual remedy sought before sending notices or making allegations.
If you have a live cyber complaint, platform action, legal notice or electronic evidence requiring matter-specific review, you may send a preliminary enquiry.
Subject to conflict check, scope confirmation, professional terms and express acceptance by the responsible Advocate.
Last reviewed: 12 September 2026