Act to apply for cyber offence or cyber contraventions committed outside India – Sec.75

July 23, 2017

Under Section 75 Information Technology Act, 2000, Indian courts and law enforcement authorities possess extra-territorial jurisdiction cyber offence authority over acts committed outside Indian territory by any individual regardless of nationality. This statutory provision applies whenever the conduct involves a computer, computer system, or computer network located in India, creating a direct legal basis for prosecuting transnational digital infractions.

Statutory Framework of Section 75 Information Technology Act

The Information Technology Act, 2000 was enacted to provide legal recognition for electronic transactions, facilitate e-governance, and penalize computer-related offences. Recognizing that digital crime respects no geographic boundaries, the Indian Parliament incorporated explicit extra-territorial provisions to protect national digital assets from external threats.

Section 75 of the Act reads as follows:

  • Sub-section (1): Subject to the provisions of sub-section (2), the provisions of this Act shall apply also to any cyber offence or cyber contravention committed outside India by any person irrespective of his nationality.
  • Sub-section (2): For the purposes of sub-section (1), this Act shall apply to an offence or contravention committed outside India by any person if the act or conduct constituting the offence or contravention involves a computer, computer system or computer network located in India.

Scope of Extra-Territorial Jurisdiction for Cyber Offence Cases

Traditional criminal law is primarily territorial, meaning a state exercises penal jurisdiction over offences committed within its physical borders. However, in the internet domain, an attacker sitting thousands of miles away in a foreign country can launch malware, execute unauthorized database access, or orchestrate distributed denial-of-service attacks against critical infrastructure.

Section 75 creates a statutory bridge that eliminates geographic immunity. By stating that the law applies to any person irrespective of nationality, the provision ensures that foreign nationals cannot escape Indian penal provisions simply because the malicious code was launched from foreign soil. To understand the broader statutory architecture governing digital evidence and cyber liability, consult Cyber Laws in India.

The Nexus Requirement: Computer Network Located in India

While Section 75 confers broad extra-territorial jurisdiction, sub-section (2) establishes an essential jurisdictional test: the physical or virtual target must be linked to India. The act or omission must directly involve a computer, computer system, computer network, or data repository situated within the geographical territory of India.

This nexus requirement ensures that:

  • The computer resource targeted or manipulated must be physically located within India at the time of the incident.
  • Data servers, cloud nodes, or telecommunication gateways hosted in Indian data centers provide the necessary territorial anchor.
  • Casual transiting of data packets through international fiber lines without impacting an Indian system is insufficient to invoke jurisdiction.

Application to Cyber Contraventions Committed Outside India

An important feature of Section 75 is that it covers both criminal cyber offences (punishable with imprisonment and fines under Chapter XI) and civil cyber contraventions committed outside India (punishable with financial compensation and penalties under Chapter IX).

Consequently, Section 75 empowers the Adjudicating Officer appointed under Section 46 of the IT Act to hear compensation claims against overseas entities for unauthorized access, data theft, virus introduction, and denial of access under Section 43. When enterprise networks suffer data breaches from overseas actors, engaging a Cyber Security, Data Protection & Data Privacy Lawyer is critical for initiating statutory complaint mechanisms.

Application of Effects Doctrine in Indian Cyber Law

The principle embedded in Section 75 reflects the internationally recognized effects doctrine Indian cyber law application. Under the effects doctrine, a sovereign state has legislative and adjudicative jurisdiction over foreign conduct when that conduct produces direct, substantial, and foreseeable harmful effects within its territory.

Indian courts interpret Section 75 in harmony with Section 1(2) of the IT Act and Section 4 of the Indian Penal Code, 1860 (and corresponding provisions in Bharatiya Nyaya Sanhita). Together, these provisions affirm that the location of the impact establishes the jurisdiction of the investigating agencies and the competent court of trial.

Evidentiary Standards and Electronic Records in Cross-Border Cases

Prosecuting cross-border digital offences requires strict adherence to statutory rules regarding electronic evidence. Under Section 65B of the Indian Evidence Act, 1872 (and Section 63 of Bharatiya Sakshya Adhiniyam, 2023), electronic records, server logs, IP routing tables, and cryptographic hashes must be accompanied by lawful certificates of authenticity. When digital evidence originates from foreign cloud service providers or international server farms, Indian investigators must obtain chain-of-custody documentation that meets judicial scrutiny.

Judicial Interpretation and Practical Enforcement in Cross-Border Matters

Indian judicial forums have consistently affirmed the broad reach of Section 75 in cases involving online defamation, corporate data exfiltration, intellectual property piracy, and unauthorized domain hijacking. In civil suits seeking anti-suit injunctions or takedown orders against foreign hosting services, High Courts regularly rely on Section 75 to assert subject-matter jurisdiction over foreign entities whose websites target Indian consumers or process Indian data.

While establishing cross-border cyber crime jurisdiction on paper is straightforward, practical enforcement involves complex international cooperation protocols. Indian law enforcement agencies utilize multiple instruments to investigate and prosecute foreign-based cyber criminals:

  • Mutual Legal Assistance Treaties (MLAT): Bilateral agreements used to request electronic evidence, server logs, subscriber identity records, and bank transaction details from foreign law enforcement bodies.
  • Letters Rogatory (LR): Formal judicial requests issued by an Indian magistrate to a foreign court seeking investigative assistance and preservation of digital evidence.
  • Interpol Red Notices and Extradition: Seeking the arrest and extradition of accused individuals under bilateral extradition treaties for grave cyber offences.
  • Cyber Forensics Preservation: Prompt preservation of volatile network logs and header records under Section 91 CrPC and international preservation frameworks.

In summary, Section 75 provides the indispensable statutory bedrock that allows Indian investigative bodies to reach beyond physical frontiers and defend national cyberspace against global cyber threats.

Found this helpful?

Share this page with others