By Dattatray Mahajan –
1st year – Government Law College, Mumbai
– Legal Intern @Singhania & Co

In the fast-digitising Indian society, the correlation between data privacy and criminal law has acquired formal prominence never before. With the continued use of digital platforms in the conduct of governance, commerce, finance, as well as personal communication, the abuse of information has been discovered to be not only a regulatory issue but also a criminal threat. The cases of identity theft, online financial fraud, unauthorised surveillance, and massive data breaches illustrate that informational harm is now potentially as harmful as physical or financial damage. This is a change that requires re-assessment of the capability of the criminal justice system in India to properly deal with the infringement of data privacy.
Informational privacy was well established in the constitutional basis of the case of Justice K.S. Puttaswamy v Union of India when the Supreme Court acknowledged the recognising privacy as a fundamental right in Article 21 of the constitution. The Court underscored the fact that human dignity entails informational self-determination and personal data control. This ruling changed the discussion to constitutional compulsion, where the State should come up with proper legal safeguards.
And on this constitutional requirement, Indian data protection regime was intellectually anchored based on the recommendations of the Justice B.N. Srikrishna Committee that appeared in its report titled A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians (2018). One of the legislative solutions to these issues is the introduction of the Digital Personal Data Protection Act, 2023 that introduces the consent-based framework and regulatory penalties to misuse data. Criminal provisions of cyber misconduct remain at the same time, Information Technology Act, 2000 and general penal provisions under the Bharatiya Nyaya Sanhita, 2023.
The changing aspects of privacy and criminal liability have also been discussed on academic platforms. Other researchers like Gautam Bhatia in his article titled Privacy in the Age of Surveillance have suggested that informational privacy must be legally safeguarded at a structural level that is not in line with the traditional criminal doctrines. Likewise, legal analysis of cyber law in India underline that the traditional notions of mens rea, jurisdiction and evidentiary provisions were constructed around physical harms and might not fit into the digital misconduct across boundaries.

It is on this basis that it is not necessarily the case, irrespective of whether India has passed data protection laws, but the structure of India criminal law, conceptually and institutionally, is geared to respond to the complex and technology-based privacy intrusions. This paper discusses whether the current criminal provisions are sufficient to address data based offences and determines whether more structural change is required to provide any meaningful protection in the digital age.
Constitutional Foundation of Data Privacy
In India, data privacy is constitutional based on the provisions of Article 21 of the Constitution under which right to life and personal liberty is enshrined. Privacy is not raised in the Constitution, but unfortunately judicial interpretation has broadened Article 21 to encompass safeguarding of personal autonomy and dignity.

Another significant advancement was in Justice K.S. Puttaswamy v Union of India where the Supreme Court identified the right to privacy unanimously as a fundamental right. In particular, the Court recognized informational privacy, which states that people should have a right to regulate the utilization and sharing of their personal information. It also established the test of legality, legitimate aim, and proportionality of any action of the State that invaded privacy.
The Court brought the protections of unreasonable surveillance and the necessity to create a balance between the power of the State and individual privacy in earlier, in the case People Union of Civil Liberties v Union of India.

In this way, data privacy has a solid normative basis in the Constitution. Nevertheless, the key to meaningful protection lies in the way the criminal law can implement this constitutional assurance in form of enforceable protection against the misuse of data.
Legislative Framework Governing Data Privacy
1. Digital Personal Data Protection Act, 2023
The purpose of the Digital Personal Data Protection Act, 2023 is the center of the Indian data privacy legislation. It allows handling of digital personal information within the legal scope (Section 4) mostly on the basis of consent (Section 6), and gives the individual rights and security and report-of-breach obligations to Data Fiduciaries (Sections 19 and 8).
The enforcement is regulatory by the Data Protection Board of India (Section 18) where hefty financial fines are imposed by the Schedule. There is not a criminalisation of data misuse in the Act, and penalties are mostly left to the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023.
2. Information Technology Act, 2000
The Information Technology Act, 2000 is still the most relevant criminal law regulating cyber offences in India. The IT Act is a direct criminal offence on unauthorised data access and misuse compared to the regulatory approach of the DPDP Act. Section 43 holds the offenders liable to unauthorized access, downloading or extraction of data, whereas Section 66 transforms such activities into criminal offences through penile actions of dishonesty or fraud.
The Act also criminalises identity theft (Section 66C), cheating by means of a personation using computer resources (Section 66D) and breach of confidentiality or privacy (Sections 72 and 72A). These measures offer jails and fines and they are the main punishment to the data theft and online fraud.
The IT Act, therefore, plays the role of the main connection between data abuse and criminal prosecution in the framework of preparedness and replaces the regulatory framework developed under the DPDP Act.
3. Bharatiya Nyaya Sanhita, 2023
The Bharatiya Nyaya Sanhita, 2023 does not directly deal with the issue of data privacy but it is important when prosecuting data-related crimes. Cheating, electronic records forgery, impersonation, criminal breach of trust are among the acts that are likely to be invoked in cases of misuse of personal data.
The Sanhita, therefore, complements the specialised cyber laws offering the general criminal foundation upon which digital misconduct is to be prosecuted..
Key Challenges in Criminal Enforcement
1. Jurisdictional Complexities
The information is often kept on the servers which are not in India. Cybercrimes have been characterized by cross-border players who utilize VPNs and encrypted networks. Even though in some instances Indian law offers extra-territorial jurisdiction it is often reliant on the cooperation of the countries in real practice.
2. Investigative Capacity
Criminal enforcement cannot be good without the specialised cyber forensic skills. A number of law enforcement agencies are constrained with resources and training as well as technological gaps. Consequently, prosecution and investigation of data-related crimes can be tedious and ignoble.
3. Corporate Liability
It is difficult to establish the criminal liability in issues of corporate data breaches. Whether the breach came as a result of a deliberate act of misconduct, carelessness, or structural weakness is hard to establish. To prove the personal liability of individual directors, it is necessary to demonstrate knowledge and involvement, which is not easy to do.
4. Intangible Nature of Harm
The common law in criminal cases safeguards against harm of the body or money. The misuse of data, though, can often lead to immaterial harm like loss of reputation, profiling, or mental torture. It is hard to quantify such harm in order to prosecute a criminal.
Are We Prepared?
In India, the country has a multi-layered legal framework to tackle data misuse, namely regulatory protection of law through Digital Personal Data Protection Act, 2023, cyber offences laws through Information Technology Act, 2000, and general criminal liability in the Bharatiya Nyaya Sanhita, 2023. The structure seems all inclusive on paper.
Nonetheless, the readiness is not evaluated only by the presence of statutes. There are continuing issues in enforcement capacity, technical competence in investigative agencies, digital forensic infrastructure and liaisons between regulatory agencies and criminal courts. The DPDP Act goes with a regulatory, penalty-oriented framework whereas criminal prosecution remains based on the provisions of cyber-crimes that were developed long ago and do not match the size of data-driven crimes of the modern world.
Thus, India is legally prepared although effective preparedness is institutional preparedness, timely investigative action, judicial effectiveness, and the capacity to respond to the fast-changing technological threats.
Conclusion
India has come up with an overlapping system of securing data privacy including constitutional and statutory safeguards under the Digital Personal Data Protection Act, 2023 and criminal law under the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023. On paper, the structure is seemingly sufficient.
However, effective enforcement, technical capacity, and the capacity of criminal law to respond to changing harms that are driven by technology will render preparation true. The legal basis is there, although its success will be determined in the end by the institutional availability and constant adjustment in the digital age.
References:
Justice K.S. Puttaswamy (Retd.) & Anr. vs. Union of India
https://api.sci.gov.in/supremecourt/2012/35071/35071_2012_Judgement_24-Aug-2017.pdf
Digital Personal Data Protection Act, 2023 (DPDP Act)
https://www.indiacode.nic.in/bitstream/123456789/22037/1/a2023-22.pdf
Srikrishna Committee Report – A Free and Fair Digital Economy
Discussion on People’s Union for Civil Liberties v. Union of India (1997)
The Bharatiya Nyaya Sanhita, 2023
https://www.indiacode.nic.in/bitstream/123456789/20062/1/a202345.pdf

