India: Cybersecurity

Subscribe
Accounting law and audit law thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics such as FinTech, marketing, media, new technology, security.
Article
How Do The DPDP Rules Interact With The IT Act And Intermediary Guidelines?
India’s digital regulatory framework is multi-layered. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) sit alongside the long-standing Information Technology Act, 2000 (“IT Act”) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Guidelines” or “IT Rules, 2021”).
India Privacy
KS
King, Stubb & Kasiva
Article
Can Employers Monitor Employee Devices, Emails And Communications Under India’s DPDP Act?
The increasing use of remote working, Bring Your Own Device (“BYOD”) arrangements, cloud-based platforms and workplace monitoring software has made employee privacy an important consideration for employers in India. Organisations routinely collect and process employee data through access-control systems, company email accounts, endpoint security tools, attendance systems, CCTV, location services, and cybersecurity platforms.
India Privacy
KS
King, Stubb & Kasiva
Article
CERT-In’s New AI-Vulnerability Guidelines: A Quick-Reference For OEMs, Tech Vendors And In-House Counsel
Cybersecurity regulation in India has, until now, largely spoken to the entity that suffers the breach. The 2022 CERT-In Directions issued under Section 70B of the Information Technology Act, 2000 fixed a six-hour reporting clock on the organisation that detects an incident. The new Guidelines flip the lens onto the entity upstream of that breach, the OEM or technology provider that built the product in the first place. For the first time, vendors supplying software, firmware, cloud platforms, or APIs into India carry direct, time-bound, and independently verifiable obligations of their own and not obligations that are merely passed through a customer contract, but obligations CERT-In itself may enforce.
India Technology
SR
S.S. Rana & Co. Advocates
Article
MNRE Has Issued Compliance Guidelines Regarding Inverter-level Generation Data And Storage Of Inverter-level Data Of Rooftop Solar Systems
The Ministry of New and Renewable Enegery (“MNRE”) vide its office memorandum dated 17.08.2026 (“OM”) has issued directions regarding compliance with guidelines on inverter-level generation data and storage of inverter-level data of Rooftop Solar systems (“RTS”) installed under PM Surya Ghar: Muft Bijli Yojana (“PMSG: MBY”). This OM is issued in continuation of the earlier guidelines issued by MNRE from time to time on secure communication of generation data and the compliance requirements for inverters and communication devices used under PMSG: MBY.
India Energy
Sagus Legal
Article
Signal In The Machine- Evolving Regulatory Landscape On Telemetry Data And Connected Vehicles
Connected vehicles increasingly resemble computers on wheels. They rely on continuous data flows for safe operation, navigation, infotainment and driver-assistance features. This data - called telemetry-travels through Machine-to-Machine SIM cards (M2M SIMs), embedded SIMs (eSIMs), dedicated short-range communication (DSRC), cellular vehicle-to-everything(C-V2X) and cloud platforms. In India, each of these building blocks is regulated, but through separate legal framework rather than a unified regulation.
India Privacy
La
Luthra and Luthra Law Offices India
Article
Who Bears The Loss? Re-thinking Liability In India’s Digital Banking Ecosystem
India's digital payments ecosystem has transformed financial accessibility, but it has also created new vulnerabilities through SIM swap fraud, phishing, and social engineering attacks. Recent High Court decisions are reshaping how liability is allocated among banks, telecom providers, and customers when unauthorized electronic banking transactions occur, establishing that responsibility increasingly rests with whichever participant first compromised the digital authentication process.
India Privacy
HS
Hammurabi & Solomon
Article
Data Embassies: A Strategic Tool for Preserving Sovereignty and Digital Continuity
Data embassies represent a groundbreaking evolution in digital sovereignty, allowing states to extend diplomatic protections to critical infrastructure and data hosted in foreign territories. As global geopolitics becomes increasingly volatile and cyber threats intensify, how are nations leveraging this innovative concept to ensure governmental continuity and protect their most sensitive information beyond their borders?
India Government
I
CMS INDUSLAW
Article
From Cybersquatting To Cyber Fraud: Delhi High Court Rewrites The Rules In Dabur Case
On December 24, 2025, the Hon'ble Delhi High Court passed a judgement in Dabur India Limited v. Ashok Kumar & Ors. [CS (COMM) 135/2022] delivered by Hon'ble Justice Prathiba M. Singh, which has set new precedents governing the liability of domain name registrars and related digital service providers as well as treats large scale misuse of well-known marks in domain names as a systemic cyber fraud.
India Criminal
SR
S.S. Rana & Co. Advocates
See more