When a hacker in one country breaks into a bank server located in another and transfers funds to a third nation, which court has the authority to prosecute? This scenario illustrates the fundamental challenge that defines jurisdiction in cyberspace. Unlike physical crimes bound by geographical borders, cybercrimes transcend national boundaries with a single keystroke, creating complex questions about legal authority and enforcement.

Table of Contents

Why jurisdiction matters in the digital age

Cyberspace has no physical boundaries. A person sitting anywhere in the world can access systems, commit fraud, or spread harmful content across multiple countries simultaneously. When such offenses occur, law enforcement and courts face a critical question: who has the authority to investigate, prosecute, and punish the offender?

Jurisdiction refers to the power of courts to hear cases and take cognizance of matters brought before them. In cyberspace, determining jurisdiction becomes challenging because the act, the perpetrator, and the victim may all be in different locations. This borderless nature of the Internet necessitates clear legal frameworks to establish which courts can adjudicate cyber offenses.

Traditional jurisdictional theories applied to cyberspace

International law recognizes several principles that help determine jurisdiction. These traditional theories, developed for physical crimes, are now being adapted to address digital offenses.

Subjective and objective territoriality

The territorial principle enables a sovereign state to exercise exclusive jurisdiction over individuals and acts within its territory. This principle operates in two forms when applied to cyberspace.

Subjective territoriality applies when an offense begins within a state’s territory. For instance, if a cybercriminal initiates an attack from within India, Indian courts can claim jurisdiction regardless of where the effects are felt. This principle is by far the most important basis for jurisdiction, as most criminal legislation operates on the theory that activities within a territory can be regulated by that territory’s laws.

Objective territoriality or the effects doctrine extends jurisdiction to acts initiated outside a state’s borders but producing substantial effects within that state. This principle allows states to exercise jurisdiction when a constitutive element of the conduct occurred in their territory, even if the perpetrator was physically located elsewhere.

Section 199 of the Nagarik Suraksha Sanhita, 2023 reflects this principle in Indian law. It states that an offense may be tried by a court in whose jurisdiction either the act was done or the consequence ensued. In the landmark case Ajay Aggarwal v. Union of India, the Supreme Court held that a Dubai-based individual who defrauded an Indian bank could be prosecuted in India because although the offense was committed in Dubai, the consequence occurred in India.

Nationality principle

The nationality principle provides a basis for jurisdiction where a state’s citizen is either a victim or a perpetrator. This principle operates in two forms: active personality and passive personality.

Active personality allows states to prosecute their nationals for crimes committed anywhere in the world. Section 1(5) of the Nyaya Sanhita, 2023 incorporates this principle by stating that provisions apply to offenses committed by any citizen of India in any place outside India. This means an Indian citizen who commits a cybercrime while abroad can still be prosecuted under Indian law.

Passive personality permits states to claim jurisdiction when their nationals are victims of crimes committed abroad. This principle allows states to try foreign nationals for offenses committed abroad that affect their own citizens, though its application remains somewhat controversial in international law.

Protective principle

The protective principle allows states to assert jurisdiction over foreign conduct that threatens their national security, sovereignty, or governmental functions. This principle proves particularly relevant for cybercrimes targeting critical infrastructure, government systems, or defense networks.

Under this principle, India could prosecute foreign hackers who attempt to breach Indian government computers or attack essential national systems, even if the perpetrators never set foot in India. The principle recognizes that states have a fundamental right to protect themselves from external threats, regardless of where those threats originate.

Universal jurisdiction

Universal jurisdiction applies to crimes considered so heinous that any nation may prosecute offenders regardless of where the crime occurred. Traditionally reserved for international crimes like piracy, genocide, and crimes against humanity, this principle’s application to cybercrimes remains limited and controversial.

While some states have claimed universal jurisdiction over certain cybercrimes like child pornography, such claims remain controversial due to the lack of consensus on specific definitions of these offenses globally. The borderless nature of cyber activity makes universal jurisdiction both potentially useful and practically challenging.

India’s approach to cyber jurisdiction

The Information Technology Act of 2000 provides the legal framework for regulating electronic transactions and establishing jurisdiction over cybercrimes in India. Section 75 of the IT Act states that the Act applies to offenses committed outside India if the act involves a computer, computer system, or computer network located in India.

This extraterritorial application is broader than the nationality-based provision in the Nyaya Sanhita. It means that anyone, regardless of nationality or location, who commits an offense involving Indian computer resources can be prosecuted under Indian law. However, enforcement remains challenging when the perpetrator is located in a country that does not recognize this jurisdictional claim or lacks an extradition treaty with India.

For civil disputes arising in cyberspace, jurisdiction is determined under the Code of Civil Procedure, 1908. Section 20 provides that suits should be instituted where the defendant resides or where the cause of action arises. In e-commerce disputes, determining where the cause of action arises can be complex, particularly when contracts are formed through electronic communications and services are delivered digitally across borders.

Challenges in establishing cyber jurisdiction

The application of traditional jurisdictional theories to cyberspace faces several obstacles. First, the intangible nature of cyberspace makes it difficult to determine where an offense actually occurred. Cloud computing and distributed networks create a loss of location problem, where data and activities occur simultaneously across multiple jurisdictions.

Second, the ease with which cybercriminals can mask their location through proxy servers and anonymization tools complicates enforcement. Even when jurisdiction can be established legally, identifying and locating the perpetrator remains a technical challenge.

Third, conflicting jurisdictional claims arise when multiple states can legitimately assert authority over the same conduct. A single cybercrime may involve servers in one country, perpetrators in another, victims in several others, and effects felt globally. Jurisdiction is primarily determined by the location of offenders, victims, and impacts of cybercrime, but when all these elements span multiple nations, determining which court should hear the case becomes contentious.

International cooperation and the way forward

The borderless nature of cybercrimes necessitates international cooperation. The Budapest Convention on Cybercrime, adopted in 2001, represents the first international treaty addressing Internet crimes. It sets common minimum standards for relevant offenses and establishes procedures for collecting electronic evidence and mutual legal assistance.

However, India has not signed the Budapest Convention, citing concerns about lack of participation in its drafting. The convention requires parties to establish jurisdiction based on territoriality, nationality, and flag principles, but its regional origins and limited acceptance restrict its effectiveness as a global standard.

The United Nations has been working toward a comprehensive international convention on cybercrime that would provide globally binding frameworks for cooperation. Such efforts aim to balance state sovereignty with the practical need for transnational collaboration in combating cybercrimes that affect multiple jurisdictions simultaneously.

What do you think? Should India join existing international conventions like the Budapest Convention to strengthen cross-border cooperation in prosecuting cybercrimes? How can jurisdictional frameworks evolve to keep pace with rapidly changing technologies that further blur geographical boundaries?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.legalserviceindia.com/legal/article-3329-analysis-of-cyber-jurisdiction-in-india.html
  2. https://en.wikipedia.org/wiki/Territorial_principle
  3. https://www.respicio.ph/bar/2025/political-law-and-public-international-law/public-international-law/jurisdiction-of-states/basis-of-jurisdiction/territoriality-principle
  4. https://www.asil.org/sites/default/files/benchbook/jurisdiction.pdf
  5. https://www.scconline.com/blog/post/2024/03/24/jurisdiction-in-cybercrimes-and-civil-disputes/
  6. https://classic.austlii.edu.au/au/journals/MelbJIL/2012/5.html
  7. https://www.britannica.com/topic/international-law/Jurisdiction
  8. https://www.diplomacyandlaw.com/post/principles-of-jurisdiction-in-international-law
  9. https://law2021.wordpress.com/2025/10/09/international-law-jurisdiction-over-cybercrimes/
  10. https://www.linkedin.com/pulse/issues-concerns-cyberspace-jurisdiction-india-kirtika-sarangi-vk6qc
  11. https://www.unodc.org/e4j/en/cybercrime/module-7/key-issues/sovereignty-and-jurisdiction.html

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Regulation of Cyberspace

1 Domestic Laws- Backgrounder

  1. Challenges to Laws
  2. Information Technology Act 2000
  3. Critiques of the I.T. Act
  4. Proposed Amendments to the I.T. Act

2 Information Technology Act โ€“ Part-I

  1. Statement of Objects and Reasons
  2. Application of the Act โ€“ The Extra-Territorial Effect
  3. Digital Signatures
  4. E-governance

3 Information Technology Act โ€“ Part-II

  1. Adjudication (Chapter IX)
  2. Penalties and Offences (Chapter IX & XI)
  3. Network Service Provider Liability (Chapter XII)
  4. Amendments to Certain Statutes

4 International Treaties, Conventions and Protocols Concerning Cyberspace

  1. United Nations Commission on International Trade Law
  2. World Summit on Information Society
  3. United Nations Commission on Trade and Development
  4. Council of Europe
  5. World Trade Organization
  6. World Intellectual Property Organization

5 Guidelines Issued by Various Ministries

  1. Broadband Policy 2004
  2. .IN Internet Domain Name โ€“ Policy Framework
  3. Draft Policy Guidelines on Web-site Development Hosting and Maintenance
  4. New Telecom Policy 1999 (NTP 1999)
  5. Information Technology Security Guidelines
  6. SEBI Guidelines on Internet-based Trading and Services
  7. Guidelines for Setting up of International Gateways for Internet

6 Introduction to Computer Wrongs

  1. Computer Wrongs
  2. Classification of Computer Crimes
  3. Technology-neutral and Technology-based Laws
  4. Regulation Versus Freedom on the Internet
  5. Information Technology Act 2000
  6. Convention on Cyber Crime โ€“ Council of Europe

7 Conventional Crimes Through Computer

  1. Cyber Defamation
  2. Digital Forgery
  3. Cyber Pornography
  4. Cyber Stalking/Harassment
  5. Online Gambling
  6. Online Sale of Illegal Articles

8 Crimes and Torts Committed on a Computer Network and Relating to Electronic Mail

  1. Hacking/Unauthorized Access
  2. Denial of Service
  3. Crimes Relating to Electronic Mail: E-mail Spamming/E-mail Bombing
  4. Crimes Relating to Electronic Mail: E-mail Spoofing

9 Crimes Relating to Data Alteration/Destruction

  1. Internet Fraud and Financial Crimes
  2. Virus Worms Trojan Horses and Logic Bombs
  3. Theft of Internet Hours
  4. Salami Attacks
  5. Data Diddling
  6. Steganography

10 Issues of Jurisdiction and Applicable Law in Cyberspace

  1. Jurisdiction in Cyberspace
  2. Theories of Jurisdiction in Criminal Cases
  3. General Jurisdiction in Computer Crimes
  4. Application of โ€˜Effectsโ€™ Doctrine in Computer Crimes
  5. Convention on Cyber Crime โ€“ Council of Europe
  6. Applicable Law in Computer Crimes

11 Enforcement Issues in Cyberspace

  1. Prevention
  2. Detection of Crime
  3. Use of Cyber Forensics
  4. On-going Efforts in India

12 Online Dispute Resolution

  1. Internet Fraud and Financial Crimes
  2. Theories of Jurisdiction in Criminal Cases
  3. Prevention
  4. Online Dispute Resolution (ODR)