PG Diploma Cyber Law semester 2 class notes on cyber crimes and the law examine the statutory, procedural, and judicial principles governing computer-related offences in India and international jurisdictions. The syllabus covers the conceptual definitions of cyber offences, the adaptation of actus reus and mens rea in digital environments, civil contraventions versus criminal penalties, electronic evidence admissibility, and the statutory framework under the Information Technology Act, 2000. This cyber crimes and the law study guide provides law students and digital forensics professionals with an in-depth curricular reference across all five prescribed syllabus units.
Unit I: Conceptual Foundations of Cyber Crime and Criminal Jurisprudence
Cyber crime refers to any unlawful activity wherein a computer, computer system, computer network, or communication device acts either as a tool, a target, or a repository of criminal conduct. Unlike traditional physical crimes bounded by geographic frontiers, cyber offences occur in borderless electronic domains, creating unique evidentiary and jurisdictional complexities.
Criminal law establishes culpability on the foundational legal maxim actus non facit reum nisi mens sit rea, meaning an act does not make a person guilty unless the mind is also guilty. Applying actus reus and mens rea in cyber crimes requires specialized legal interpretation:
- Actus Reus (The Prohibited Physical Act): In cyberspace, the wrongful act consists of unauthorized digital access, code execution, downloading confidential data without permission, introducing malware, or sending menacing electronic transmissions. The physical act is manifested through electronic keystrokes and data packets traversing network routers.
- Mens Rea (The Culpable Mental State): Proving malicious intent, knowledge, or dishonesty in cyber prosecutions is challenging due to automation, remote execution, and identity obfuscation (such as proxy chains or spoofed headers). Indian cyber legislation addresses this by embedding intentionality requirements directly into penal definitions through terms such as dishonest, fraudulent, or intentional tampering.
These principles integrate directly with the wider cyber laws in India legal framework, harmonizing technical definitions with constitutional guarantees of due process.
Unit II: Classification and Modus Operandi of Digital Offences
Modern cyber offences exhibit diverse operational techniques targeting individuals, commercial corporations, and sovereign state systems. The syllabus categorizes digital crimes according to their primary targets and execution methods:
- Hacking and Unauthorized Access (Section 43 & 66): Breaching computer firewalls, accessing restricted databases, and altering access control permissions without owner authorization.
- Data Theft and Industrial Espionage: Stealing intellectual property, customer databases, proprietary source code, or personal data for commercial extortion or competitive advantage.
- Cyber Fraud and Financial Scams: Electronic banking fraud, phishing attacks, unauthorized electronic fund transfers, and fraudulent online lottery schemes designed to deceive victims.
- Cyber Stalking and Online Harassment: Persistent electronic surveillance, threatening communications, morphing digital photographs, and violating personal privacy through social platforms.
- Malicious Code and Ransomware: Designing and disseminating computer viruses, worms, Trojan horses, spyware, and ransomware payloads that encrypt institutional assets.
- Cyber Terrorism (Section 66F IT Act): Attacking national critical information infrastructure, disrupting essential public utility systems, or compromising national security through computer networks.
- Identity Theft (Section 66C): Fraudulent appropriation of digital signatures, passwords, biometric markers, or electronic identifiers to execute unauthorized transactions.
Unit III: Civil Wrongs, Tortious Liabilities, and Defective Software
The law distinguishes between penal offences punishable by imprisonment and civil wrongs giving rise to monetary compensation. In cyberspace, civil contraventions protect private economic interests against digital damage:
The statutory concept of tortious liability and defective software in cyber law establishes accountability for software developers and service providers whose negligence causes financial harm or data leakage. Key liability considerations include:
- Civil Contraventions under Section 43 IT Act: Imposing statutory compensation (up to specified caps) for unauthorized copying, virus introduction, denial-of-service disruptions, or data destruction, adjudicated by designated Adjudicating Officers.
- Product Liability for Software Flaws: Determining whether software creators owe a duty of care to commercial users when severe security vulnerabilities or unpatched coding defects expose user networks to breaches.
- Remedies and Damages: Calculating compensatory, exemplary, and restitutionary damages for business interruption, reputation harm, and intellectual property compromise.
Unit IV: Electronic Evidence, Digital Forensics, and Investigation
The investigation and prosecution of computer offences depend on forensically sound collection and presentation of electronic records. Because digital data is volatile and easily altered, statutory evidentiary procedures must be strictly observed.
1. Electronic Evidence Admissibility
Under Section 65B of the Indian Evidence Act, 1872 (and corresponding provisions of the Bharatiya Sakshya Adhiniyam), electronic records such as server logs, email communications, database entries, and mobile extractions require statutory certification by persons responsible for device operation. Courts strictly require procedural compliance to prevent fabricated digital submissions.
2. Cyber Police Infrastructure and Digital Surveillance
Specialized cyber crime police stations, forensic laboratories, and lawful interception mechanisms under Section 69 and 69B of the IT Act enable law enforcement agencies to monitor traffic data, seize digital media, and preserve chain of custody for courtroom presentation.
3. Comparative Cyber Law Frameworks
Evaluating electronic evidence admissibility and investigation across international jurisdictions reveals distinct statutory approaches:
- India: Governed primarily by the Information Technology Act, 2000 and procedural evidence codes.
- United Kingdom: Regulated under the Computer Misuse Act 1990 and the Police and Criminal Evidence Act (PACE) 1984.
- United States: Governed by the Computer Fraud and Abuse Act (CFAA), the Electronic Communications Privacy Act (ECPA), and Federal Rules of Evidence.
Unit V: Criminal Penalties under the IT Act 2000 and Indian Penal Code
The statutory enforcement of cyber offences operates through the dual application of the Information Technology Act 2000 cyber offences and traditional criminal statutes:
- Section 65 IT Act: Tampering with computer source documents, punishable with imprisonment up to three years or fine.
- Section 66 IT Act: Computer related offences committed dishonestly or fraudulently, punishable with imprisonment up to three years.
- Section 66E IT Act: Punishment for violation of privacy, penalizing intentional capturing or publishing of private images without consent.
- Interplay with General Criminal Law: Offences involving extortion, cheating, forgery, criminal conspiracy, and defamation executed via electronic systems are simultaneously prosecuted under the Indian Penal Code (IPC) and Bharatiya Nyaya Sanhita (BNS).
- Extraterritorial Jurisdiction (Section 75 IT Act): Extending statutory reach to offences committed outside India if the computer or computer network involved is located within Indian territory.
Students preparing for academic examinations should consult the detailed PGD Cyber Law Exam Guide to review model questions, statutory amendments, and leading judicial precedents governing cyberspace dispute resolution.
