Cyber & IT Law in Pune
Cybercrime cases turn on two things most criminal lawyers never formally study: how the Information Technology Act, 2000 actually applies to a given fact pattern, and how digital material becomes admissible evidence in an Indian courtroom. Advocate Akash R. Chikate holds an LL.M in Science & Technology Laws (First Class Distinction) from Savitribai Phule Pune University and a Diploma in Cyber Laws, in addition to practicing criminal defence before the Pune Sessions Court and the Bombay High Court since 2021. That combination — a formal, examined qualification in this specific subject alongside active criminal trial practice — is uncommon in Pune's criminal defence bar, where cyber matters are usually handled as an extension of general criminal work rather than as a specialisation in their own right.
This page covers the IT Act offences that generate the bulk of cybercrime FIRs, how the 2023 evidence law recodification changed the rules for admitting electronic material, and what actually matters when building a defence once a device has been seized.
Identity Theft and Impersonation — Section 66C, IT Act
Section 66C punishes fraudulent or dishonest use of another person's electronic signature, password, or any other unique identification feature — the provision typically invoked when someone's Aadhaar details, login credentials, digital signature, or biometric identifiers are misused to impersonate them online. Conviction carries imprisonment up to three years and a fine up to ₹1 lakh. In practice, S.66C is frequently charged alongside cheating provisions under the Bharatiya Nyaya Sanhita, since the identity theft is rarely the end goal — it is the mechanism for a further fraud.
Cheating by Personation Using a Computer Resource — Section 66D, IT Act
Section 66D is the single most commonly invoked cybercrime section in Pune FIRs today, because it covers the fact pattern behind the overwhelming majority of digital fraud complaints: UPI fraud, fake customer-care calls, OTP-based bank fraud, fraudulent loan or investment apps, and impersonation on messaging platforms to extract money. The section punishes cheating by personation by means of any communication device or computer resource, with imprisonment up to three years and a fine up to ₹1 lakh. Because it is the default charging section for almost any digital fraud, S.66D FIRs range enormously in seriousness and quality of evidence — from cases with a clear, traceable money trail to cases built on a complainant's assumption of who was on the other end of a call or chat, with the actual identification evidence thin. That distinction is exactly where a defence is built or lost.
Violation of Privacy — Section 66E, IT Act
Section 66E addresses intentional capture, publication, or transmission of an image of a person's private area without their consent, in circumstances violating privacy — imprisonment up to three years or a fine up to ₹2 lakh, or both. This section is fact-specific and consent-dependent, and cases frequently turn on what was actually captured, whether consent existed and to what scope, and whether the accused was the person who transmitted or published the material versus merely possessed it.
Obscene and Sexually Explicit Content — Sections 67 and 67A, IT Act
Section 67 punishes publishing or transmitting obscene material in electronic form; Section 67A carries enhanced punishment where the material contains a sexually explicit act. These are among the more severely punished IT Act offences — S.67 carries up to three years and a fine up to ₹5 lakh on first conviction (five years and ₹10 lakh on a subsequent conviction), with S.67A carrying up to five years and a fine up to ₹10 lakh on first conviction (seven years on a subsequent one). Where a minor is involved, these sections operate alongside — not instead of — the POCSO Act, which materially changes both the forum and the stakes. Given the severity and the frequent involvement of forwarded or third-party content, the question of who actually authored, uploaded, or knowingly forwarded material — versus who merely received it — is often the entire case.
Digital Evidence Admissibility Under BSA 2023
Every cybercrime prosecution eventually reduces to a single question: is the electronic material the prosecution is relying on actually admissible? Since 1 July 2024, this is governed by Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which replaced Section 65B of the Indian Evidence Act, 1872. The core requirement is unchanged in principle — electronic records (call data, chat logs, CCTV footage, server logs, forensic images of a device) are not automatically admissible; they require a certificate confirming how the record was produced and that the device was functioning properly at the relevant time. What changed under S.63 BSA is the certificate itself: it now requires dual certification — one from the person in charge of the device or computer system, and a second, independent certification, structured in the specific Part A / Part B format set out in the BSA's Schedule. A certificate that meets the old S.65B standard but not the new dual-certification structure is a live admissibility issue, and prosecutions built on evidence gathered before the transition need careful scrutiny of which framework actually governs the certificate produced.
This is not a technicality that only matters to specialists — it is frequently the difference between a chat log or call record being read into evidence at all.
Building a Defence: Seizure, Forensics, and Chain of Custody
Once a device — a phone, laptop, or storage medium — is seized in connection with a cybercrime investigation, several practical issues routinely decide whether the resulting evidence stands up:
- Seizure documentation. Was the seizure memo properly prepared, witnessed, and does it accurately describe what was taken, including make, model, and any identifying marks or hash values recorded at the time of seizure? Investigating officers can compel production of documents and digital data under Section 94 of the Bharatiya Nagarik Suraksha Sanhita, 2023 (which replaced Section 91 CrPC and explicitly extends to digital material) — whether that power was exercised and documented correctly is often the first thing worth examining.
- Chain of custody. Between seizure and forensic examination, was the device secured against tampering, and can the prosecution account for every hand it passed through? A gap or an unexplained handling event in the custody chain is one of the most reliable grounds for challenging the reliability of what a forensic report later claims to have found.
- Forensic imaging integrity. Was a proper forensic (bit-by-bit) image taken before analysis, with hash values recorded and matched, or was the original device itself examined and potentially altered in the process?
- Certificate compliance. Does the S.63 BSA certificate actually meet the dual-certification requirement described above, in the prescribed format, for every piece of electronic evidence the prosecution intends to rely on?
- Attribution. Even where a message, transaction, or upload is genuine, is there actual evidence the accused — specifically — was the person who sent it, versus evidence only that it originated from a device, SIM, or account that could have been accessed by others?
None of these points, on their own, guarantee an outcome — but a defence that is built around the actual evidentiary record, rather than a general denial, is the difference between a filing that gets taken seriously and one that does not.
What Clients Say About Cybercrime & IT Law Cases
A recent cybercrime matter, in the client’s own words.
"Our company faced a serious cybercrime complaint and we had no idea how to handle it. Adv. Akash’s knowledge of the IT Act and cyber law was exceptional. He resolved the matter efficiently and professionally."