Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

ANA Law Group 7th floor, Keshava Bandra Kurla Complex Bandra East Mumbai 400 051 Maharashtra India

Tel: +91 226 112 8484 Fax: +91 226 112 8485 Email: mailbox@anaassociates.com Web: www.anaassociates.com

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy India recognises cybersecurity as a core compo - nent of national security, economic stability and the effective functioning of its digital infrastructure. The recently enacted Digital Personal Data Protection Act, 2023 (DPDPA) and its associated Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”) are a transformative step for India’s cybersecurity and data protection landscape. It establishes a comprehensive framework governing the collection, processing, and protection of personal data, emphasising accountabil - ity, informed user consent, and timely breach notifica - tion. National Cybersecurity Strategy The National Cyber Security Policy, 2013, established by the Ministry of Electronics and Information Tech - nology (MeitY), represents India’s first comprehensive policy framework for securing cyberspace. The policy seeks to build a resilient and digital ecosystem by cre - ating a secure environment for individuals, businesses and government institutions. The National Cyber Security Policy prescribes various objectives, which include the following: • to create a secure cyber ecosystem that fosters trust and confidence in IT systems and digital transactions across all sectors of the economy;

• to establish an assurance framework supporting security-by-design and compliance with global security standards and best practices through conformity assessment of products, processes, technologies and personnel; • to strengthen the regulatory framework governing cybersecurity and cyber risk management; • to establish national and sectoral level 24x7 mech - anisms for obtaining strategic threats information to ICT infrastructure, and for enabling co-ordinated response, resolution and crisis management through predictive, preventive, protective, response and recovery actions; • to enhance the protection and resilience of critical information infrastructure (CII) through the opera - tion of a dedicated national protection centre and the adoption of security practices across the lifecy - cle of information systems; • to improve visibility into the integrity and security of ICT products and services through testing and validation mechanisms; • to safeguard information during processing, storage and transmission to protect citizen data, reduce economic losses from cybercrime and miti - gate data theft; • to enable effective prevention, investigation and prosecution of cybercrime through legislative and institutional strengthening; • to train approximately 500,000 cybersecurity professionals through capacity building and skill development initiatives; and

191 CHAMBERS.COM

Powered by