The IT Act 2000 is sometimes a complex document to understand. The original legislation was passed by the parliament in a hurry without enough public debate. This may have led to limitations creeping into the Act. Many problems of the act were amended by the amended act of 2008. Conviction in cases of cybercrime in India continues to be abysmally low. One other impediment to the enforcement of cybercrime laws is the nature of evidence available in the custody of prosecution and the admissibility of same, during the course trial of cybercriminals. Cyber law proceedings require parties to meet different burdens of proof, the typical examples being beyond a reasonable doubt, clear and convincing evidence, and preponderance of the evidence. The limitations in cyberlaws and legal issues to prove cybercrime related evidences are enumerated below
- Anonymous
nature of the identity of cybercriminals
Cyber laws were principally enacted to prosecute
cybercriminals, so, if the criminals are not identifiable, the law become a
misnomer. The Internet is free and there is no perquisite that needs to be
fulfilled, before a user can login to connect with anywhere and anyone across
the globe. Digital technologies such as VPN, TOR, etc. provide ample
opportunities for impersonation by way of identity disguise so as make it
difficult if not impossible to ascertain who the perpetrator of cybercrimes is.
Anonymization and IP spoofing is well advanced and cyber criminals can forgo
identity easily. Further if the IP address is traced to a location, the next
hurdle cannot be scaled as the identity of a cybercriminal is undisclosed to
the owner or operator of Internet service provider. Communication are often
routed via many servers which further compounds the possibility of
cybercriminals being traced.
- Jurisdictional challenges and lack
of Uniform Global law
Cybercrimes span the global cyber space; by so doing, the extant laws
and policies which are fragmented, national, regional or quasi international
cannot possibly cope with the problems engendered by cybercrimes Location of
the cybercrime may cross borders and hence local laws of the land may lead to
limitation in application of law in India. Cybercrime is a global phenomenon
and therefore the initiative to fight it should come from the same level. Each
nation-state of the world has the authority to make laws binding on things and
all persons within its geographical entity. Since multiple nation-states are
enacting Cyber Crime laws on the same matter for different jurisdictions,
conflict of laws is unavoidable. The extant laws also are not punitive enough
when it comes to extent of the fine/incarceration for cybercrime acts. Hence
even if the extant laws are enforced, it would make little or no impact on the
cybercriminals as the laws cannot possibly deter criminals from their illegal
acts. A cybercriminal may sit in the comfort of his home, office, café or
wherever he chooses, with a desktop, laptop, tablet or phone connected to the
Internet and carry out his illegal activities, that may impact a different
geography and jurisdiction.
- Extradition challenges for
international cybercrime
Cyber Crimes can span extra-territorial and
intra-territorial situations. A court may lack the geographical jurisdiction.
Even if a cybercriminal is clearly identified but he is situated in another
country aside from where the victim is domiciled, the court of the forum cannot
effectively try such a criminal as the court lacks jurisdiction geographically.
Extradition of criminals to bring them within jurisdiction is also fraught with
its own challenges. This includes challenges such as the double criminality
requirement and extradition treaty between countries. Multiple countries such
as Austria, Brazil, Japan, France, etc. have in their laws, jurisdiction to
conduct trials over their nationals for offences committed abroad. Further
processes of returning criminals are overly cumbersome, time consuming and
costly.
·
Multiple enactments
covering Cybercrime
Information Technology Act (IT Act), 2000 is not the singular enactment
covering cybercrime in India. The Indian Penal Code (IPC) could also relied
upon for cybercrimes related prosecution.: hacking, data theft, virus attacks,
denial of service attacks, illegal tampering with source codes including
ransomware attacks could be prosecuted under S.66 r/w S.43 of the IT Act covers
DDOS, Data Theft, Hacking, Virus and ransomware. Cases of SIM card cloning or
Bank Card duplication with intent to cause wrongful loss or wrongful gain can
be prosecuted under IPC provisions (S.463 to S.471 IPC, as applicable). IPC
also have overlap for cases against identity theft (IT Act 2008 - S.66C) or
cheating by impersonating online (IT Act 2008 - S.66D). Similar there are other
overlapping laws for example S.67A and S.67B also provide for prosecution of
pornography and child pornography respectively. In case of the latter, the
provisions of the Prevention of Children from Sexual Offences Act, 2012 (POCSO)
may also be invoked. These multiple enactments have varying levels of
prosecution and applying the wrong section/law can lead to limitations.
·
Hesitation to report
offenses
One fatal drawbacks of the Act have been the cases going unreported.
Cases reported have long closure lifetimes and there have been reported cases
where police have wielding the rod and harassed innocents, preventing them from
going about their normal cyber business. There is also a lack of awareness
related to cybercrimes amongst the masses and hence people do not report
offenses. Companies to evade possibilities of liabilities and public exposure
and reputational impacts also tend to underreport cybercrimes. If only the people are vigilant about their
rights, can the law protect their rights.
- Trained Police Force
The present form of police system and many police officials are not
familiar with the cybercrimes and they need training to be familiar with the
“Modus operandi” of cybercrimes. Though the existing relevant act is
comprehensive legislation but from the practical point of view there are some
shortcomings in the errant form of the act. At times
it becomes difficult to test the veracity of electronic evidences. For
‘electronic evidence’ to be admissible, it must comply with the ‘best evidence
rule’ and ‘chain of custody’ must be so that rules out any tampering. Doing
this at ground level where police may not have the resources is difficult.
There is a lack of standard documented
procedures for searching, seizing of digital evidence and standard operating
procedures for forensic examination of digital evidence and this contributes to
fewer convictions in cybercrimes.
- Secondary electronic evidence
Electronic Evidence under
Indian Evidence Act, 1872 allows for
electronic evidence as primary method for evidence if the
electronic records are certified by a person occupying a responsible
official position. However there are few gaps which are still unresolved as
what would be the fate of the secondary electronic evidence seized from the
accused wherein, the certificate u/s 65B of Evidence Act cannot be taken and
the accused cannot be made witness against himself as it would be violative of
the Article 19 of the Constitution of India.
- Challenge regarding the nature of
evidence
Unlike in terrestrial crimes where physical evidence could be presented
to the court with the view of securing conviction of the accused, physical
evidence is rare in cybercrime prosecution. Digital logs and evidence are footprints
on the computers used by the criminals and traces left on the Internet; the
nature of these proofs may have little evidential value. Mere examination by
inexperienced investigators may contaminate or out rightly damage digital evidence

No comments:
Post a Comment