Section 75 of the Information Technology Act, 2000 gives Indian courts extraterritorial jurisdiction over cyber offences and contraventions committed outside India by any person, regardless of nationality. This extraterritorial mandate applies whenever the underlying unlawful act or conduct involves a computer, computer system, or computer network located in India.
Scope of Extraterritorial Jurisdiction Under Section 75 Information Technology Act
Cyberspace operates without geographic borders, allowing foreign actors to target domestic computer systems from remote physical locations across the globe. Recognizing this technological reality, the Parliament incorporated Section 75 to ensure that geographical boundaries and foreign citizenship do not shield cyber criminals from Indian prosecution. Section 75(1) establishes the universal reach of the statute, while Section 75(2) defines the jurisdictional nexus required to trigger statutory enforcement.
Unlike conventional criminal statutes that historically relied on territorial presence or citizenship, Section 75 establishes an effects-based jurisdiction. As long as the target infrastructure resides on Indian soil, Indian courts retain legal authority to adjudicate the offence. Policy guidelines, cybersecurity circulars, and regulatory directions issued by the Ministry of Electronics and Information Technology reinforce this cross-border enforcement posture.
The Territorial Nexus: Target Systems Located in India
The foundational condition for invoking Section 75 is establishing that the prohibited conduct involved a computer system or network located in India. This nexus manifests in several common operational structures across the digital economy:
- Domestic Data Centres and Cloud Hosting: Foreign threat actors launching ransomware or unauthorized intrusion against servers physically hosted in Mumbai, Bengaluru, or Delhi fall squarely within Indian jurisdiction.
- Critical Financial Infrastructure: Attacks originating overseas that target Indian payment gateways, the Unified Payments Interface (UPI), or core banking networks operated by domestic financial institutions satisfy the statutory requirement.
- Compromised Local Endpoints: Distributed denial of service (DDoS) botnets or phishing operations that manipulate Indian subscriber computers create an actionable statutory nexus.
- Government and Defense Portals: Foreign cyber espionage targeting Indian administrative databases or public sector utilities triggers both Section 75 and cyber terrorism provisions under Section 66F.
Investigative Realities and Cross-Border Cyber Crimes in India
While extraterritorial jurisdiction under IT Act grants substantive legal power, practical enforcement against cross-border actors presents complex procedural challenges. Investigating agencies must navigate international legal assistance channels to collect foreign server logs, IP address allocations, and international financial trails.
Key mechanisms utilized by Indian law enforcement when investigating a cyber offence committed outside India include:
- Mutual Legal Assistance Treaties (MLAT): Bilateral agreements allowing Indian authorities to request digital evidence, server logs, and witness depositions from foreign law enforcement agencies.
- Letters Rogatory (LR): Formal judicial requests issued by Indian trial courts to foreign judiciaries seeking assistance in obtaining overseas records.
- Interpol Notices: Red Corner Notices and cyber crime alerts issued through the National Central Bureau to locate, detain, and extradite fugitive hackers.
- G7 24/7 Cybercrime Network: Rapid preservation channels designed to freeze overseas server logs before electronic evidence is purged by hosting providers.
International Precedents and the Effects Doctrine in Cyber Law
The statutory principle embedded within Section 75 reflects the internationally recognized effects doctrine established in transnational criminal law. Under this doctrine, a sovereign state asserts criminal jurisdiction over extra-territorial conduct when the injurious effects of that conduct materialize directly within its territory. Indian courts apply this standard to cyber attacks because data packets originating from overseas servers produce tangible legal harm upon Indian servers, financial networks, and corporate databases.
Comparative legal frameworks, such as the United States Computer Fraud and Abuse Act and the Council of Europe Convention on Cybercrime, incorporate similar extraterritorial reach. While India is not a formal signatory to the Budapest Convention, Section 75 provides Indian law enforcement and judicial authorities with statutory parity to investigate foreign cyber syndicates, ransomware operators, and illegal botnet controllers.
Procedural Prerequisites and Electronic Evidence Rules
Prosecuting an overseas perpetrator in an Indian court requires adherence to specific statutory safeguards under general criminal law. Under Section 188 of the Code of Criminal Procedure, 1973, when an offence is committed outside India by a citizen or non-citizen, previous sanction of the Central Government is required before trial proceedings can commence.
Furthermore, digital records extracted across international borders must satisfy strict admissibility standards. Authenticating foreign digital records requires compliance with The Indian Evidence Act, 1872, particularly regarding Section 65B certifications and chain of custody documentation. Corporate victims of international data breaches should conduct a thorough cyber law compliance audit to identify vulnerability vectors and preserve tamper-evident forensic images.
Extradition and Cross-Border Legal Obstacles
Enforcing court judgments and securing the physical custody of overseas offenders remains a complex procedural hurdle under Section 75. India has executed bilateral extradition treaties with numerous nations, but extradition in cyber crime cases requires establishing dual criminality. The underlying conduct must be recognized as an offence punishable under the penal laws of both India and the foreign sanctuary state. Where extradition is unfeasible, Indian authorities utilize red notices, bank account freezes through international financial task forces, and diplomatic channels to curtail foreign cyber threat actors.
Strategic Implications for Global and Domestic Enterprises
Section 75 holds substantial implications for multinational technology companies, cloud providers, and global service vendors operating in the Indian market. Any foreign entity whose offshore personnel engage in unauthorized data access, theft of trade secrets, or service disruption against Indian clients faces potential criminal liability in India. Domestic enterprises must ensure that cross-border cloud contracts include explicit cooperation clauses for digital evidence production, ensuring rapid response when offshore attacks compromise Indian computer resources.
By maintaining strong contractual standards and forensic logging capabilities, Indian businesses can effectively assist law enforcement agencies in establishing the required statutory nexus when confronting cross-border cyber threats.
