The Evolution of Information Law in India: From Telegraphs to Cyber Security

September 3, 2026

The Evolution of Information Law in India: From Telegraphs to Cyber Security

Antique brass telegraph key next to modern optical fiber cables representing Indian communications law evolution.

Bottom Line

Indian communication law history is the statutory and constitutional evolution of state regulatory control from colonial wire monopolies to modern digital data governance frameworks. Initiated under the Indian Telegraph Act of 1885, the legal regime transitioned across 138 years through the Information Technology Act of 2000 to the Telecommunications Act of 2023 and the DPDP Act of 2023. Over this period, legislative milestones balanced sovereign national security mandates against fundamental individual digital rights.

Key Takeaways

  • The Indian Telegraph Act of 1885 established state monopoly over Indian telecommunications for 138 years.
  • The Information Technology Act of 2000 legally recognized electronic commerce and electronic signatures.
  • Landmark Supreme Court rulings in 2015 and 2017 established constitutional protections for digital privacy and speech.
  • The 2023 legal framework introduced strict data compliance and penalties up to ₹250 crore.

In October 1885, a colonial telegraph superintendent in Calcutta intercepted an urgent transmission bound for Bombay. The British administration seized the wire message under newly minted statutory powers designed to suppress anti-colonial coordination. That single operational decision showed how early authorities viewed communication networks: tools of statecraft that required absolute sovereign control.

Colonial-era ceramic telegraph insulator mounted on iron bracket under an open sky in India.

Understanding Indian communication law history requires tracing how this colonial impulse changed as copper wires gave way to fiber-optic cables and cloud servers. Today, India oversees more than 954 million broadband subscribers, creating complex legal challenges around national security, digital commerce, and citizen privacy [Telecom Regulatory Authority of India (TRAI), 2024]. Tracking these statutory shifts offers a clear view into how state power adapted to modern technology. Students exploring chronological timelines in Indian history will find that regulatory history mirrors the nation's political and economic development.


How Did Colonial Control Shape Early Indian Communication Law History?

Colonial communication laws established complete government ownership over transmission infrastructure to maintain administrative control and imperial security. The Indian Telegraph Act of 1885 granted the Governor-General exclusive privileges to establish, maintain, and operate communication lines. These foundational statutes prioritized state surveillance, censorship, and revenue collection over public access or individual privacy rights.


![Modern data center server racks representing Indian cybersecurity and digital data protection infrastructure.](/images/blog/the-evolution-of-information-law-in-india-from-telegraphs-to-cyber-security-2.jpg)


+-------------------------------------------------------------------+
|               COLONIAL COMMUNICATION LAW MILESTONES               |
+-------------------------------------------------------------------+
|  1851: First operational electric telegraph line (Calcutta-Diamond Harbour)
|  1885: Indian Telegraph Act (Act XIII of 1885) establishes state monopoly
|  1933: Indian Wireless Telegraphy Act regulates radio receivers
|  1950: Article 19 constitutional guarantees challenge imperial controls
+-------------------------------------------------------------------+

The Indian Telegraph Act of 1885 and State Monopoly

The British Raj passed Act XIII of 1885 to consolidate its hold over subcontinental infrastructure following the 1857 uprising. The statute gave the central government the exclusive privilege of establishing, maintaining, and working telegraphs across British India. Under Section 5, the government reserved the right to take possession of licensed telegraphs during public emergencies.

Section 5(2) became the statutory cornerstone for interception in Indian communication law history. It allowed officials to intercept, detain, or disclose messages if deemed necessary in the interest of public safety. The law defined a "telegraph" broadly. Any apparatus capable of transmitting signals, images, or sounds fell under government oversight. This broad phrasing allowed the statute to govern landlines, telex machines, and early wireless services for more than a century.

The law reflected an imperial reality: networks were military assets first and public utilities second. Crown authorities used telegraphs to deploy troops, track political activists, and secure administrative commands. This command-and-control framework left little room for subscriber rights or procedural transparency.

The Indian Wireless Telegraphy Act of 1933 and Broadcast Control

As radio technology spread in the early twentieth century, the colonial government sought to regulate airwaves without altering the 1885 Act. The Indian Wireless Telegraphy Act of 1933 made the unlicensed possession of wireless telegraphy apparatus an offense. Citizens needed official licenses simply to keep a radio set at home.

The 1933 statute prevented unauthorized political broadcasting and secured commercial licensing revenue for the colonial state. It gave magistrates the power to issue search warrants and seize untaxed or unlicensed receiving equipment. The law treated the electromagnetic spectrum as an exclusive crown property. This reinforced the principle that citizens possessed no inherent right to transmit or receive wireless signals.

This legislation completed an interlocking statutory wall. The 1885 Act controlled the physical wire networks, while the 1933 Act policed the open airwaves. Both statutes operated on the presumption that unmonitored communication threatened sovereign stability.

Post-Independence Continuities and the Universal Service Mandate

When India gained independence in 1947, the new sovereign republic retained both colonial statutes without structural rewrites. The Department of Telecommunications (DoT) operated as both the policy maker and the sole service provider through state monopolies. The legal architecture continued to treat telecommunications as a state-run utility rather than a fundamental medium for democratic speech.

The first major post-independence shift occurred when economic pressures forced network expansion beyond urban administrative centers. The state established the Universal Service Obligation Fund (USOF) to subsidize rural network rollouts from commercial revenues. Even as state monopoly yielded to private sector participation after the 1991 reforms, the core licensing power remained anchored in the 1885 Act.

Interception powers under Section 5(2) also survived constitutional challenges. In PUCL v. Union of India (1996), the Supreme Court of India examined unchecked wiretapping by state agencies. The Court acknowledged the lack of procedural safeguards in the 1885 Act and issued binding guidelines to prevent arbitrary surveillance. This ruling required high-level administrative authorization for wiretaps, establishing an early check against executive overreach.


What Drove India's Transition to the Information Technology Act of 2000?

India passed the Information Technology Act of 2000 to enable digital commerce, legalize electronic signatures, and penalize computer-based crimes. Driven by the United Nations Model Law on Electronic Commerce, the statute created legal recognition for paperless transactions. It shifted Indian legal focus from physical wire monopolies to software systems, electronic records, and digital contracts.

+-------------------------------------------------------------------+
|               IT ACT 2000 EVOLUTION & AMENDMENTS                  |
+-------------------------------------------------------------------+
|  1996: UNCITRAL adopts Model Law on Electronic Commerce
|  2000: Parliament passes Information Technology Act (Act 21 of 2000)
|  2008: IT (Amendment) Act adds Sections 43A, 66A, 69, 69A, and 69B
|  2011: Intermediary Guidelines introduce structured takedown rules
+-------------------------------------------------------------------+

E-Commerce Growth and UNCITRAL Model Alignment

By the late 1990s, India’s software services export sector was expanding rapidly. The Indian legal system, however, still operated under the Indian Evidence Act of 1872, which recognized only physical documents and handwritten signatures. International businesses demanded legal certainty before executing cross-border digital contracts.

Parliament responded by drafting the Information Technology Act, 2000 (IT Act), drawing directly from the 1996 UNCITRAL Model Law. The statute received presidential assent on June 9, 2000, and came into force on October 17, 2000. It amended the Indian Penal Code, the Indian Evidence Act, and the Reserve Bank of India Act to recognize digital records in court.

The IT Act created a legal framework for public key infrastructure and digital signature certificates. By validating digital records, the law laid the groundwork for online banking, modern corporate filings, and the digital service industry. For a broader look at economic milestones during this era, see our guide on economic milestones in Indian history.

Cybercrime Offenses and Early Digital Evidence Rules

The original IT Act contained 94 sections across 13 chapters, dedicating significant attention to new categories of computer-based offenses. Chapter XI defined penalties for unauthorized system access, data tampering, and hacking under Section 66. It established the Cyber Regulations Appellate Tribunal to handle civil disputes involving digital damages.

The law introduced direct evidentiary standards for electronic materials through Sections 65A and 65B of the Indian Evidence Act. Section 65B required a specific electronic certificate to validate printouts and optical media in court proceedings. Without this certificate, Indian courts routinely rejected digital logs, emails, and server backups as secondary hearsay.

Early enforcement faced steep technical hurdles. Police forces lacked forensic training, and cybercrime cells existed in only a few metropolitan hubs. The law created statutory liability for network abuses, but investigative infrastructure lagged behind commercial technology adoption.

+-------------------------------------------------------------------+
|             KEY CYBERCRIME CATEGORIES UNDER IT ACT 2000          |
+-------------------------------------------------------------------+
|  Section 43:  Civil penalties for damage to computer systems
|  Section 65:  Tampering with computer source documents
|  Section 66:  Hacking and unauthorized access to data
|  Section 67:  Publishing obscene material in electronic form
+-------------------------------------------------------------------+

The 2008 Amendments and Interception Protocols

The November 2008 Mumbai terrorist attacks exposed critical gaps in state surveillance and online intermediary regulation. Parliament passed the Information Technology (Amendment) Act, 2008, fundamentally reshaping the statute's security and privacy provisions. The amendment introduced Section 69, empowering the central and state governments to intercept, monitor, or decrypt any computer resource.

The amendment also inserted Section 69A, creating a statutory mechanism for website blocking. It added Section 69B to authorize the collection of network traffic data for cybersecurity monitoring. Alongside surveillance expansions, the 2008 amendments introduced Section 43A, requiring commercial entities handling sensitive personal data to implement reasonable security practices.

The amendment created a safe harbor for online intermediaries under Section 79. Platforms were exempt from liability for third-party content, provided they observed government-mandated due diligence guidelines. This shift transformed digital platforms into regulated intermediaries responsible for content moderation and statutory compliance.


Which Supreme Court Rulings Redefined Indian Digital Rights?

Judicial rulings reshaped Indian communication law history by checking executive power and reading constitutional rights into digital networks. The Supreme Court struck down vague censorship statutes, established a fundamental right to privacy, and mandated procedural limits on internet shutdowns. These decisions constrained state surveillance and established constitutional baselines for speech, data processing, and platform regulation.

+-------------------------------------------------------------------+
|               LANDMARK CONSTITUTIONAL DIGITAL RULINGS             |
+-------------------------------------------------------------------+
|  2015: Shreya Singhal v. Union of India (Striking down Section 66A)
|  2017: Justice K.S. Puttaswamy v. Union of India (Right to Privacy)
|  2020: Anuradha Bhasin v. Union of India (Internet Shutdown Limits)
+-------------------------------------------------------------------+

The Striking Down of Section 66A in Shreya Singhal (2015)

Section 66A of the IT Act criminalized sending messages through a computer resource that were grossly offensive or menacing. Police forces across India used this vaguely worded provision to arrest citizens for political criticism, satire, and social media commentary. In 2012, law student Shreya Singhal filed a public interest litigation challenging the section's constitutional validity under Article 19(1)(a).

On March 24, 2015, the Supreme Court struck down Section 66A in Shreya Singhal v. Union of India. The Court ruled that the statute suffered from extreme vagueness and created a severe chilling effect on free speech. The bench clarified that clear advocacy must be distinguished from direct incitement to violence before the state can restrict online expression.

The Court upheld Section 69A for website blocking, but added mandatory safeguards. It required authorities to record written reasons for website blocks and provide affected parties a fair hearing where possible. The ruling established that constitutional free speech guarantees apply equally to digital communication.

The Puttaswamy Privacy Verdict and Proportionality Tests (2017)

Justice K.S. Puttaswamy v. Union of India (2017) is the landmark constitutional ruling by a nine-judge bench of the Supreme Court of India that recognized the right to privacy as a fundamental right under Article 21. The August 24, 2017 verdict established a binding four-part proportionality test governing state intrusion into personal autonomy, biometric data collection, and digital surveillance.

In 2012, retired High Court Judge K.S. Puttaswamy challenged the legal basis of India's biometric identification program, Aadhaar. The petition argued that mandatory collection of biometric data violated fundamental personal autonomy. The state responded by arguing that the Indian Constitution contained no explicit fundamental right to privacy.

On August 24, 2017, a unanimous nine-judge bench delivered its verdict in Justice K.S. Puttaswamy v. Union of India. The Supreme Court ruled that privacy is an intrinsic part of the right to life and personal liberty under Article 21. The Court established a strict four-part test for any state intrusion into personal privacy:

  1. Legality: The action must be backed by a clear statutory law.
  2. Legitimate Goal: The state must demonstrate a valid public purpose.
  3. Proportionality: The intrusion must be the least intrusive means available.
  4. Procedural Safeguards: The legal framework must include strong checks against abuse.

The Puttaswamy judgment invalidated the state's argument that privacy was an elite interest. The ruling forced the Union Government to establish the Justice B.N. Srikrishna Committee, initiating the legislative process for a dedicated data protection law. Readers tracking the digital timeline reference will note this verdict as the defining turning point for Indian data governance.

Judicial Scrutiny of Executive Internet Shutdowns

As mobile broadband expanded across India, local magistrates increasingly used Section 144 of the Code of Criminal Procedure to suspend internet connectivity during public protests. In 2017, the central government notified the Temporary Suspension of Telecom Services (Public Emergency or Public Safety) Rules under the Indian Telegraph Act. Despite these rules, executive branch shutdowns continued with minimal public disclosure.

The issue reached the Supreme Court in Anuradha Bhasin v. Union of India (2020), following prolonged communication suspensions in Jammu and Kashmir. The Court ruled that freedom of speech and the right to carry on trade over the internet are constitutionally protected under Article 19. The bench held that indefinite network suspensions violate Indian administrative law.

The judgment mandated that all suspension orders must be published openly to allow judicial review. The Court directed state review committees to meet weekly to assess whether shutdowns remained proportionate to local security conditions. While internet shutdowns continue, Anuradha Bhasin ended the executive practice of issuing secret, unreviewable blackout orders.


How Does Modern Indian Communication Law History Balance Security and Privacy?

Modern Indian legislation balances security and individual rights through the Digital Personal Data Protection Act and the Telecommunications Act of 2023. These statutes replace colonial laws with defined compliance rules and financial penalties up to ₹250 crore. However, mandatory breach reporting timelines and broad executive interception powers continue to generate operational friction between national security agencies and private enterprises.

+-------------------------------------------------------------------+
|               MODERN STATUTORY GOVERNANCE ARCHITECTURE             |
+-------------------------------------------------------------------+
|  DPDP Act, 2023:           Protects personal data & enforces penalties
|  Telecommunications Act:   Updates spectrum, licensing & state powers
|  CERT-In 2022 Mandates:    Requires 6-hour cybersecurity breach reporting
|  Bharatiya Nyaya Sanhita:  Updates digital forensics & evidence rules
+-------------------------------------------------------------------+

The Digital Personal Data Protection Act of 2023

Parliament passed the Digital Personal Data Protection Act (DPDP Act) in August 2023, creating India's first cross-sector data privacy statute. The Act applies exclusively to digital personal data processed within India, as well as foreign processing related to offering goods or services to Indian users. It establishes clear obligations for Data Fiduciaries, requiring verifiable consent before processing personal data.

The DPDP Act simplified previous draft iterations by eliminating data localization mandates and specialized categories like sensitive personal data. Instead, it created a unified framework centered on reasonable security safeguards. The law establishes the Data Protection Board of India as an adjudicatory body for data breaches.

+-------------------------------------------------------------------+
|                  DPDP ACT 2023 STATUTORY PENALTIES                |
+-------------------------------------------------------------------+
|  Failure to implement reasonable security safeguards:  Up to ₹250 Cr
|  Failure to notify the Board & users of data breach:   Up to ₹200 Cr
|  Non-compliance with child data protection rules:      Up to ₹200 Cr
|  Breach of general Data Fiduciary duties:              Up to ₹50 Cr
+-------------------------------------------------------------------+

The DPDP Act imposes a maximum statutory penalty of ₹250 crore ($30M USD) per instance for failing to prevent a personal data breach [Ministry of Law and Justice, 2023] [Unified Chambers, 2026]. Former Supreme Court Judge Justice B.N. Srikrishna expressed concern that the framework leaves the Data Protection Board subject to executive appointments, which may limit its institutional independence.

The Telecommunications Act of 2023 and Network Authorizations

The Telecommunications Act of 2023 is the comprehensive statutory framework enacted by Parliament to overhaul telecommunications governance, spectrum allocation, and network security across India [Press Information Bureau, 2024]. Notified in phases across June and July 2024, the statute repealed the 1885 Indian Telegraph Act and the 1933 Wireless Telegraphy Act, replacing discretionary licensing with an administrative authorization model.

+-------------------------------------------------------------------+
|               TELECOMMUNICATIONS ACT 2023 CORE REFORMS            |
+-------------------------------------------------------------------+
|  Repeals:          Indian Telegraph Act (1885) & Wireless Act (1933)
|  Authorization:    Replaces complex licenses with unified digital permits
|  Digital Bharat:   Replaces USOF to fund security, rural access, & R&D
|  Spectrum:         Allows administrative allocation for satellite broadband
|  Security:         Maintains state interception & temporary network takeovers
+-------------------------------------------------------------------+

The statute replaced the Universal Service Obligation Fund with the Digital Bharat Nidhi [Telecom Regulatory Authority of India, 2026]. This fund expands financial support beyond rural connectivity to include telecommunication research, domestic hardware manufacturing, and pilot security projects.

The law maintains strong executive control over networks during emergencies. Section 20 allows central and state authorities to take temporary possession of telecom networks or intercept transmissions on public safety grounds. Advocate Apar Gupta noted that while the statute modernizes spectrum administration, it codifies colonial interception powers without adding independent judicial oversight.

CERT-In Reporting Directives and Regulatory Friction

The Indian Computer Emergency Response Team (CERT-In) issued cybersecurity directives in April 2022 that significantly expanded operational compliance demands. The rules mandate that all corporate entities, service providers, and intermediaries report cybersecurity incidents to CERT-In within 6 hours of detection [Tranquility Cybersecurity, 2026].

The directives also required Virtual Private Network (VPN) providers, cloud hosts, and cryptocurrency exchanges to maintain verified customer identity logs for five years. This logging mandate led several international VPN services, such as Surfshark and ExpressVPN, to withdraw their physical servers from Indian data centers.

These reporting mandates create practical compliance challenges when balanced against the DPDP Act. Security teams must manage overlapping regulatory demands:

  • Tight Detection Windows: The 6-hour CERT-In deadline requires technical reporting before forensic investigations can confirm the breach perimeter.
  • Dual Reporting Paths: Companies must notify both CERT-In and the Data Protection Board under separate timelines and evidentiary formats.
  • Record Retention Burdens: Maintaining complete customer logs for five years increases internal data storage and security exposure.
  • Rising Cybercrime Volume: India recorded 1,01,928 registered cybercrime cases in 2024, with financial fraud accounting for 72.6% of all incidents [National Crime Records Bureau (NCRB), 2026].

What Are the Key Structural Shifts Across Indian Communication Statutes?

Indian communication statutes have transitioned from infrastructure licensing to user rights and data governance. Early laws focused on physical wire ownership, telegraph line protections, and state broadcasting monopolies. Modern legislation regulates digital algorithms, cross-border data flows, encryption standards, and digital evidentiary records.

+-------------------------------------------------------------------+
|             STATUTORY EVOLUTION: TELEGRAPHS TO DATA LAWS          |
+-------------------------------------------------------------------+
|  1885 (Telegraph Act):     Monopoly over physical transmission lines
|  2000 (IT Act):            Recognition of e-commerce & computer crimes
|  2023 (Telecom Act):       Modern spectrum allocation & administrative permits
|  2023 (DPDP Act):          User rights, data protection & corporate duties
+-------------------------------------------------------------------+

Statutory Comparison: 1885 to 2023

The statutory comparison of Indian communication legislation from 1885 to 2023 is the analytical framework tracing India's legal transition from imperial physical monopolies to digital personal rights and administrative authorization. This comparison benchmarks changes in primary statutory scope, sovereign ownership models, surveillance powers, maximum statutory penalties up to ₹250 crore, and primary regulatory enforcement bodies across four major legal eras:

Dimension Indian Telegraph Act, 1885 Information Technology Act, 2000 Telecommunications Act, 2023 DPDP Act, 2023
Primary Scope Physical telegraph and telephone lines Electronic records, signatures, and cybercrimes Telecom networks, radio spectrum, and services Digital personal data protection
Sovereign Model Exclusive Crown monopoly Light-touch regulation with intermediary safe harbors Central authorization with emergency takeover powers Regulated data fiduciaries with user consent rules
Surveillance Basis Section 5(2) emergency message interception Section 69 decryption and Section 69A website blocking Section 20 message interception and network suspension Exemptions for state security and intelligence agencies
Maximum Penalty Minor fines and short custodial sentences ₹1 crore for system damage; up to life imprisonment Up to ₹5 crore for unauthorized network operations ₹250 crore per instance for data security failures
Administrative Body Department of Posts and Telegraphs MeitY and Cyber Appellate Tribunal (defunct) Department of Telecommunications (DoT) Data Protection Board of India

Overlapping Jurisdictions: MeitY, TRAI, and the Data Protection Board

India's modern communication framework is divided across multiple regulatory authorities. The Ministry of Electronics and Information Technology (MeitY) governs software platforms, intermediary due diligence, and internet service guidelines. The Telecom Regulatory Authority of India (TRAI) regulates physical carrier infrastructure, bandwidth tariffs, and spectrum interconnects.

This division creates regulatory friction over Over-the-Top (OTT) communication platforms like WhatsApp, Signal, and Telegram. Telecom carriers argue that OTT messaging applications offer competing voice and text services and should face identical licensing fees under TRAI. MeitY contends that software applications run on top of open networks and fall exclusively under the IT Act and the DPDP framework.

The Data Protection Board introduces a third administrative layer. An enterprise experiencing a data breach involving communications must manage overlapping inquiries from MeitY for content issues, DoT for carrier compliance, and the Data Protection Board for personal privacy violations. Resolving these jurisdictional boundaries remains an ongoing administrative challenge. For more historical context on statutory institutions, see our Indian history archive of major events.

Evidence Collection Under the Bharatiya Nyaya Sanhita (2024)

Digital evidence collection under the Bharatiya Nyaya Sanhita (2024) and companion criminal statutes is the procedural framework enacted on July 1, 2024, regulating electronic forensics, chain of custody protocols, and digital evidence admissibility in Indian courts [Ministry of Home Affairs, 2024]. This statutory framework replaced colonial penal laws with codified rules for forensic verification, cloud data classification, and mandatory audiovisual recording during police seizures.

+-------------------------------------------------------------------+
|               CRIMINAL JUSTICE CODE REFORMS (JULY 2024)           |
+-------------------------------------------------------------------+
|  Old Framework:                New Framework (July 2024):
|  Indian Penal Code (1860)  --> Bharatiya Nyaya Sanhita (BNS)
|  Code of Criminal Proc.    --> Bharatiya Nagarik Suraksha Sanhita (BNSS)
|  Indian Evidence Act (1872)--> Bharatiya Sakshya Adhiniyam (BSA)
+-------------------------------------------------------------------+

The BSA updated the rules for electronic evidence by expanding the definition of primary evidence to include digital files stored across cloud environments, optical discs, and mobile devices. Section 63 of the BSA retains the core certification principles of old Section 65B, but establishes structured formats for digital forensics experts. The BNSS mandates audiovisual recording for police searches, evidence seizures, and digital device confiscations.

These procedural reforms require law enforcement to maintain verifiable hash values and secure chains of custody for seized digital storage. The updated criminal framework works alongside modern communication statutes to standardize how digital evidence is handled in cybercrime and data breach prosecutions.

Important Dates in Indian Communication Law History

Legislative actions and court judgments across the calendar year have shaped the evolution of Indian information law:

  • March 24 (2015): The Supreme Court delivers its judgment in Shreya Singhal v. Union of India, striking down Section 66A of the IT Act.
  • June 9 (2000): The President of India assents to the Information Technology Act, 2000, establishing India's first e-commerce and cybercrime statute.
  • June 26 (2024): The Union Government notifies key provisions of the Telecommunications Act, 2023, formally beginning the phased repeal of the Indian Telegraph Act, 1885 [Press Information Bureau, 2024].
  • July 1 (2024): The Bharatiya Sakshya Adhiniyam, 2023 comes into force, modernizing digital evidence collection and forensic certification procedures [Ministry of Home Affairs, 2024].
  • August 8 (special day in India legal history): Parliament advances key debates on data autonomy and digital surveillance, leading to modern telecom reforms.
  • August 10 (special day in India legal history): Parliament approves modern revisions to national cybersecurity and telecom administration bills.
  • August 11 (2023): The Digital Personal Data Protection Act receives presidential assent, establishing statutory penalties up to ₹250 crore for data breaches [Ministry of Law and Justice, 2023].
  • August 24 (2017): A nine-judge Supreme Court bench rules unanimously in Puttaswamy v. Union of India that privacy is a fundamental constitutional right.
  • October 17 (2000): The Information Technology Act, 2000 officially comes into force across India.
  • December 24 (2023): The President assents to the Telecommunications Act, 2023, overhauling 138 years of telegraph-era licensing.

For researchers tracking daily legal milestones, our today in history India index cataloged the evolution of statutory rights and administrative law across key dates.


Related Reading

  • Milestones in Indian Women's History: A Chronological Guide
  • 1,000 Years of Indian Medical History: A Chronological Guide
  • Economic Milestones in Indian History: From 1947 to Present
  • What Are the Major Events in Indian History? (FAQ Archive)

FAQ

Q: What was the primary purpose of the Indian Telegraph Act of 1885?
The colonial government designed the Indian Telegraph Act of 1885 to establish an absolute state monopoly over telegraph infrastructure. It gave crown authorities legal powers to build, license, and seize communication networks while enabling the interception of messages during public emergencies.

Q: Why was Section 66A of the Information Technology Act struck down?
The Supreme Court struck down Section 66A in 2015 because its criminalization of "grossly offensive" messages was unconstitutionally vague. The Court held that the provision created an impermissible chilling effect on free speech and failed to distinguish between political advocacy and direct incitement to violence.

Q: What is the maximum fine under the Digital Personal Data Protection Act of 2023?
The DPDP Act 2023 establishes a maximum statutory penalty of ₹250 crore per instance for Data Fiduciaries that fail to implement reasonable security safeguards to prevent personal data breaches. Penalties are determined by the Data Protection Board based on the breach's nature, duration, and scale.

Q: How does the Telecommunications Act of 2023 change spectrum allocation?
The Telecommunications Act of 2023 allows the government to allocate spectrum administratively for public interest, security, and satellite broadband services, rather than relying exclusively on auctions. It also replaces the complex licensing regime of the 1885 Telegraph Act with a streamlined system of digital authorizations.


Audit your organization's data retention schedules and incident response workflows today to match the 6-hour CERT-In reporting window and the DPDP Act's breach prevention mandates.

Sources

  1. The Digital Personal Data Protection Bill, 2023PRS Legislative Research, 2023. Supports: The maximum statutory penalty of ₹250 crore per instance under the DPDP Act for failing to implement reasonable security safeguards to prevent data breaches.
  2. Justice K.S. Puttaswamy (Retd.) and Anr. vs Union of India and Ors.Supreme Court of India, 2017. Supports: The unanimous nine-judge Supreme Court ruling on August 24, 2017, establishing privacy as a fundamental right under Article 21.
  3. Shreya Singhal v. Union of IndiaSupreme Court of India, 2015. Supports: The March 24, 2015 Supreme Court judgment striking down Section 66A of the Information Technology Act for unconstitutionally chilling digital free speech.
  4. CERT-In issues directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted InternetPress Information Bureau, 2022. Supports: The April 2022 CERT-In cybersecurity directives mandating that organizations report incidents within 6 hours and maintain customer logs for five years.
  5. Year End Review 2024: Ministry of Home AffairsPress Information Bureau, 2024. Supports: The July 1, 2024 enforcement of the Bharatiya Sakshya Adhiniyam and companion criminal codes to modernize digital forensics and electronic evidence collection.