PRIVACY IN THE AGE OF CYBERCRIME: CONSTITUTIONAL PROTECTION AND CRIMINAL INVESTIGATION IN INDIA : AUTHOR: Yumnam Soviet Ningthoucha
The growth of cybercrime has made access to digital information an important part of criminal investigation. A mobile phone, computer or cloud account can contain evidence of an offence, but it can also reveal a much wider range of private information. This creates a constitutional problem: how can the State investigate cybercrime effectively without allowing investigative access to become unnecessarily intrusive? This article examines that question through Article 21 of the Constitution, the Supreme Court's privacy jurisprudence, the Information Technology Act, 2000, the Bharatiya Nagarik Suraksha Sanhita, 2023 and the Digital Personal Data Protection Act, 2023.
ARTICLE


ABSTRACT
The growth of cybercrime has made access to digital information an important part of criminal investigation. A mobile phone, computer or cloud account can contain evidence of an offence, but it can also reveal a much wider range of private information. This creates a constitutional problem: how can the State investigate cybercrime effectively without allowing investigative access to become unnecessarily intrusive? This article examines that question through Article 21 of the Constitution, the Supreme Court's privacy jurisprudence, the Information Technology Act, 2000, the Bharatiya Nagarik Suraksha Sanhita, 2023 and the Digital Personal Data Protection Act, 2023. It also considers recent Supreme Court developments, particularly the 2025 judgment concerning digital devices and privileged lawyer-client communications and the Court's directions in the digital-arrest cybercrime proceedings. The article argues that effective investigation and privacy protection are compatible when digital searches are supported by law, connected to a legitimate investigative purpose and controlled by safeguards concerning scope, access and retention.
Keywords: Right to Privacy, Cybercrime, Article 21, Digital Evidence, Criminal Investigation, Proportionality, Digital Devices, Data Protection
1. INTRODUCTION
Cybercrime has changed the nature of criminal evidence. Fraud, identity theft, unauthorised access, online cheating and other offences may leave evidence in mobile phones, computers, email accounts, cloud storage and online platforms. Investigators therefore need digital information to identify offenders and reconstruct events. The difficulty is that digital devices contain far more than evidence of a particular offence. A smartphone may hold private messages, photographs, banking information, location history, documents and information about third persons. A lawful seizure can therefore lead to an investigation that reaches well beyond the original allegation. The real concern is not whether the State has the power to investigate crime, but whether the methods it uses to obtain digital information remain within the limits set by the Constitution and the law.
2. CONSTITUTIONAL RIGHT TO PRIVACY
In K.S. Puttaswamy (Retd.) v. Union of India, a nine-judge Bench recognised privacy as a constitutionally protected fundamental right connected with liberty, dignity and autonomy.[1] The Court also made clear that privacy is not absolute. An interference must have a legal basis and pursue a legitimate State aim. The later proportionality decision explained that restrictions must satisfy a structured test, including suitability, necessity and balancing.[2]
Criminal investigation is plainly a legitimate State function. But a legitimate objective does not automatically validate every means of pursuing it. When an investigator examines a person's complete digital history, the constitutional question becomes whether the extent of access is reasonably connected with the offence and whether less intrusive methods could achieve the same purpose.
3. DIGITAL DEVICES AND THE PROBLEM OF OVER-ACCESS
The difference between seizure and examination is important. A device may be lawfully seized because it is capable of containing relevant evidence. That does not mean every file, photograph or conversation on it is automatically relevant. For example, in an online banking-fraud case, transaction records and related communications may be directly relevant, while unrelated family conversations may have no evidentiary value.
The Supreme Court's 2025 judgment in Suo Motu Writ Petition (Criminal) No. 2 of 2025 is relevant to this problem because it expressly addressed the protection of confidential information contained in digital devices. The Court stated that, where examination of an advocate's digital device is permitted, care must be taken not to impair confidentiality relating to other clients and the examination should be confined to the material sought by the investigating officer.[3] Although the case concerned advocate-client privilege, its reasoning illustrates a broader point: access to a digital device should not become unrestricted access to everything stored on it.
This principle is particularly significant because modern devices frequently contain information belonging to people other than the device owner. Digital investigation therefore requires attention not only to the privacy of an accused or suspect but also to the privacy and confidentiality of third parties.
4. STATUTORY FRAMEWORK
The Information Technology Act, 2000 remains an important part of India's cybercrime framework. Section 66E addresses specified violations of privacy, while Section 69 provides a statutory mechanism for interception, monitoring or decryption of information through a computer resource in specified circumstances and subject to prescribed safeguards.[4] These powers support investigation, but statutory authority must still operate consistently with constitutional rights.
The Bharatiya Nagarik Suraksha Sanhita, 2023 governs criminal procedure. It came into force on 1 July 2024. Section 105 requires the process of search and seizure to be recorded through audio-video electronic means, while Section 106 concerns seizure of property by police officers.[5] These provisions are relevant to digital evidence because the manner in which evidence is collected affects both accountability and reliability.
The Digital Personal Data Protection Act, 2023 is part of India's wider data-protection framework. Its provisions and exemptions must be read carefully when considering State functions. The existence of a data-protection statute does not mean that every police investigation is governed in exactly the same way as private-sector processing of personal data.[6]
5. RECENT JUDICIAL DEVELOPMENTS
Recent Supreme Court proceedings show that the privacy-investigation relationship is no longer a purely theoretical issue. In the October 2025 judgment in Suo Motu Writ Petition (Criminal) No. 2 of 2025, the Court considered the relationship between criminal investigation, professional privilege and information contained in digital devices. The Court preserved the investigating agency's ability to investigate a lawyer where there is credible material of criminal involvement, while recognising the statutory protection of privileged communications.[7] The decision is useful for the present topic because it demonstrates that digital evidence may require a process that separates relevant material from protected or unrelated information.
The Court's December 2025 directions in proceedings concerning digital-arrest cybercrime also illustrate the investigative side of the balance. The Court directed intermediaries to cooperate with the CBI and provide traffic and content data when sought for the investigation of digital-arrest cases, and directed coordination among investigative agencies and telecom providers.[8] These directions show why investigators need access to digital information, but they also underline the importance of clearly defined legal authority and controlled access when large quantities of personal and communications data are involved.
Together, these developments suggest that the future of privacy law will not be decided simply by asking whether digital information can be obtained. The more difficult question will be how the information is selected, accessed, used and protected after it is obtained.
6. PROPORTIONALITY AND DIGITAL SEARCHES
Proportionality provides a useful constitutional framework. First, there must be legal authority for the interference. Second, the investigation must pursue a legitimate objective. Third, the measure should have a rational connection with that objective. Fourth, the interference should not be excessive when compared with the purpose it seeks to achieve.
In practice, this supports targeted digital searches where feasible. If an investigation concerns a specific financial transaction, relevant messages, account records and transaction files may be searched without treating the entire digital life of the individual as evidence. Technical methods such as filtering and targeted extraction may also reduce unnecessary exposure.
Retention is equally important. Data that is irrelevant to the investigation may nevertheless remain in copied forensic material. Clear rules should therefore address who may access extracted data, how access is recorded, how long information is retained and when unnecessary material should be deleted or isolated.
7. THE WAY FORWARD
India does not have to choose between protecting privacy and conducting effective cybercrime investigations. What is needed is a fair and practical procedure that allows investigators to obtain relevant evidence while avoiding unnecessary intrusion into personal information. This is particularly important where the information of a third party is found on a device or account connected to the suspect, even though that third party has no involvement in the alleged offence. Where searches or warrants are required, they should clearly state the purpose and reasonable limits of the digital examination. Investigators should, wherever possible, use methods that are proportionate to the investigation, while access to sensitive information should be properly controlled and recorded through appropriate audit mechanisms.
Judicial oversight is also important where an investigative technique creates a serious privacy intrusion. The courts can ensure that statutory powers are not treated as unlimited permissions to examine every aspect of a person's digital life. At the same time, safeguards should not be designed so broadly that they prevent legitimate investigation of serious cybercrime.
8. CONCLUSION
The digital age has made privacy and criminal investigation closely connected. A mobile phone or cloud account may contain evidence capable of solving a crime, but the same source may contain years of unrelated private information. The constitutional right to privacy therefore requires attention to the scope and manner of digital investigation.
The recent Supreme Court developments reinforce this need. The 2025 digital-device judgment demonstrates the importance of protecting confidential and unrelated information during examination, while the digital-arrest proceedings demonstrate the practical need for investigators to obtain digital data in serious cybercrime cases. The balance should be achieved through legality, legitimate purpose, proportionality, minimisation and oversight.
The central principle should be simple: the State may obtain digital information when the law permits it and the information is genuinely connected to a legitimate investigation, but investigative access should not become a general license to examine a person's entire private life. Clearer standards on digital searches, access, retention and accountability can protect constitutional privacy without weakening the fight against cybercrime.
REFERENCES
Constitution of India, art. 21.
Bharatiya Nagarik Suraksha Sanhita, 2023.
Bharatiya Sakshya Adhiniyam, 2023, ss. 132–134.
Digital Personal Data Protection Act, 2023.
Information Technology Act, 2000.
Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009.
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1.
People's Union for Civil Liberties (PUCL) v. Union of India, (1997) 1 SCC 301.
Suo Motu Writ Petition (Crl.) No. 2 of 2025 & Ors., 2025 INSC 1275 (Supreme Court of India, 31 Oct. 2025).
Supreme Court of India, order dated 1 Dec. 2025 in the digital-arrest cybercrime proceedings.
[1] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[2] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1, especially para 325.
[3] Suo Motu Writ Petition (Crl.) No. 2 of 2025 & Ors., 2025 INSC 1275 (Supreme Court of India, 31 Oct. 2025), judgment at pp. 76–77 (directions concerning examination of digital devices and protection of confidentiality of other clients).
[4] Information Technology Act, 2000, ss. 66E, 69; Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009.
[5] Bharatiya Nagarik Suraksha Sanhita, 2023, ss. 105, 106; see also notification bringing the Sanhita into force from 1 July 2024.
[6] Digital Personal Data Protection Act, 2023, long title and s. 17.
[7] Suo Motu Writ Petition (Crl.) No. 2 of 2025 & Ors., 2025 INSC 1275, especially discussion of Sections 132–134 of the Bharatiya Sakshya Adhiniyam, 2023 and limits on summoning advocates in their professional capacity.
[8] Supreme Court of India, order dated 1 Dec. 2025 in the digital-arrest cybercrime proceedings (Suo Motu Writ Petition/connected proceedings), directing intermediaries to cooperate with the CBI and provide traffic and content data as sought for investigation.
