Cyber Laws Regarding Unauthorized Data Access and Hacking in India

Updated: July 15, 2026
Published: July 13, 2026

Quick Answer

Unauthorized data access and hacking are punishable by up to three years in prison under Section 66 of the IT Act. Victims can pursue criminal charges against the hacker while simultaneously claiming heavy civil compensation under Section 43 of the IT Act for data theft or system damage.

Key Takeaways

  • Section 66 of the IT Act criminalizes hacking, carrying up to 3 years imprisonment and a ₹5 lakh fine.
  • Section 43 provides a civil remedy, allowing victims to claim compensation for unauthorized access and data extraction.
  • Corporate entities must report hacking incidents to CERT-In within 6 hours of detection.
  • Under the DPDPA 2023, companies failing to secure personal data from hackers face penalties up to ₹250 crore.

Introduction

Data is the most valuable asset in the modern digital economy, making it a prime target for cybercriminals. Unauthorized access—commonly known as hacking—involves breaching a computer system, network, or database without the owner's permission to steal, alter, or destroy information. The Indian legal framework heavily penalizes hacking, offering victims a dual approach: criminal prosecution to jail the perpetrators under the Information Technology (IT) Act, 2000, and civil remedies to recover financial damages.

When a system is compromised, the law distinguishes between penalizing the hacker and compensating the victim.

1. Criminal Remedies (Punishing the Hacker)

  • Section 66 (IT Act): This is the primary criminal provision for hacking. If a person dishonestly or fraudulently commits any act referred to in Section 43 (such as unauthorized access, introducing viruses, or downloading data), they are punishable with imprisonment of up to three years, a fine up to ₹5 lakh, or both.
  • Section 66F (IT Act): If the unauthorized access threatens the unity, integrity, or security of India, or involves penetrating critical information infrastructure, it is classified as Cyber Terrorism, punishable by life imprisonment.
  • Bharatiya Nyaya Sanhita (BNS), 2023: If the hacked data is subsequently used to commit financial fraud, extortion, or corporate cheating, provisions like Section 318 (Cheating) and Section 308 (Extortion) of the BNS are invoked alongside the IT Act.
  • Bharatiya Sakshya Adhiniyam (BSA), 2023: To convict a hacker, digital evidence such as server access logs, IP addresses, and firewall breach reports must be strictly certified under the BSA (Section 63) before presentation in court.

2. Civil Remedies (Compensation and Corporate Liability)

  • Section 43 (IT Act): This provision allows victims to file a civil claim for damages before the state's Adjudicating Officer. If someone accesses a computer without permission and extracts data, the victim can claim substantial financial compensation (up to ₹5 crore) directly from the offender or the negligent entity hosting the data.
  • CERT-In Directions: Under the Ministry of Electronics and Information Technology (MeitY), corporations and intermediaries must report unauthorized access and data breaches to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of noticing the incident. Failure to comply attracts severe penalties.
  • DPDPA 2023: If a corporate entity's weak cybersecurity allows hackers to access users' personal data, the Digital Personal Data Protection Act imposes massive penalties up to ₹250 crore on the company for failing to implement reasonable security safeguards.

Time Limits

  • CERT-In 6-Hour Rule: Corporate entities, data centers, and service providers have exactly 6 hours to report severe cyber incidents (including unauthorized access) to CERT-In.
  • The Golden Hour: If hacking leads to immediate financial loss from a bank account, individual victims must call the 1930 National Cyber Crime Helpline within 2 to 24 hours to freeze the stolen funds.

Practical Tips

  • Preserve Digital Evidence: Do not immediately wipe or reset compromised servers or devices. Isolate the affected systems and preserve the IP logs, access timestamps, and malware signatures. Obtaining a forensic image certified under the BSA is crucial.
  • Where to File Complaints:
    • Individuals should report hacking incidents immediately on the National Cyber Crime Reporting Portal (cybercrime.gov.in).
    • Businesses must formally report the breach to CERT-In via their incident reporting portal.
    • File an FIR at the specialized District Cyber Crime Police Station.
  • Escalation Remedies: To recover financial losses resulting from corporate negligence or insider data theft, victims can file a formal compensation petition before the IT Act Adjudicating Officer of their respective state.

When Should You Consult a Cyber Lawyer?

  • Filing Compensation Claims: Approaching the Adjudicating Officer requires drafting complex civil petitions quantifying the exact financial loss caused by the data breach. A cyber lawyer ensures your claim is legally sound.
  • Corporate Defense: If your company is hacked and customer data is leaked, you need immediate legal counsel to navigate CERT-In reporting obligations, DPDPA 2023 compliance, and defend against consumer class-action lawsuits.
  • Securing Anticipatory Bail: If an employee or IT contractor is falsely accused of unauthorized access due to a misunderstanding of their access privileges, a defense lawyer is essential to prevent arbitrary arrest under Section 66.

Conclusion

Unauthorized data access is a severe violation that triggers both criminal penalties and hefty civil liabilities. While Section 66 of the IT Act ensures hackers face imprisonment, provisions like Section 43 and the DPDPA 2023 empower victims to aggressively pursue financial compensation. By preserving pristine digital evidence and acting swiftly within the mandatory reporting windows, victims can mitigate damage and hold both hackers and negligent data custodians fully accountable.

Frequently Asked Questions

Q: What is the punishment for hacking a computer in India?

A: Hacking or unauthorized access is punishable under Section 66 of the IT Act with imprisonment up to three years, a fine up to ₹5 lakh, or both.

Q: Can I claim compensation if someone steals my data?

A: Yes. Under Section 43 of the IT Act, you can file a civil claim before the Adjudicating Officer to seek financial compensation from the person who accessed and stole your data without permission.

Q: Do companies have to report hacking incidents to the government?

A: Yes. Corporate entities and intermediaries are legally mandated by CERT-In directions to report severe cyber incidents, including unauthorized access and data breaches, within 6 hours of noticing them.

Need personalized legal help?

Find advocates on JurisOS and send an enquiry.

Find Cyber Law Lawyers