Police complaints for data theft

1. Meaning

A police complaint for data theft arises when a person unlawfully accesses, copies, downloads, transfers, obtains, or uses computer data or confidential digital information belonging to another person or organisation. The stolen information may include customer databases, employee records, passwords, trade secrets, source code, financial information, personal data, or business documents.

In India, such conduct may attract provisions of the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 (BNS), contractual obligations, and other applicable laws depending upon the facts.

A complaint may be made by the affected individual, company, employer, data owner, or an authorised representative.

2. Contents of a Police Complaint

A well-drafted complaint should clearly identify:

  • Name and address of the complainant.
  • Name and details of the suspected person, if known.
  • Date and approximate time of the incident.
  • Computer, laptop, server, cloud account, email account, or other system involved.
  • Nature of the data allegedly stolen.
  • How the complainant discovered the theft.
  • Whether the accused had authorised access initially and subsequently exceeded that authority.
  • Approximate quantity or value of the data involved.
  • Evidence supporting the allegation.
  • Financial, operational, reputational, or privacy-related consequences.
  • Request for registration of an FIR/investigation where a cognizable offence is disclosed.
  • Request for preservation and forensic examination of relevant electronic evidence.

3. Evidence That Can Be Attached

The complainant should preserve evidence in its original form wherever possible. Relevant evidence may include:

  1. Server and access logs.
  2. Login/logout records.
  3. Email correspondence.
  4. CCTV footage.
  5. Computer or mobile-device images.
  6. USB/device connection records.
  7. Cloud access logs.
  8. Screenshots.
  9. Database download records.
  10. Audit trails.
  11. Employment agreements and confidentiality clauses.
  12. IT policies and access-control records.
  13. Hash values of relevant electronic files.
  14. Statements of employees or other witnesses.
  15. Evidence showing subsequent use or disclosure of the stolen information.

Electronic evidence should be preserved carefully because alteration of the original material can affect its evidentiary value.

4. Role of the Police and Cyber-Crime Authorities

The police may investigate the complaint by:

  • Recording statements of witnesses.
  • Obtaining relevant electronic records.
  • Examining computers and storage devices.
  • Obtaining information from internet-service providers or platforms through lawful process.
  • Conducting forensic examination.
  • Tracing IP addresses and login activity.
  • Examining email and cloud accounts.
  • Seizing relevant devices where legally justified.
  • Identifying the person who accessed or transferred the information.
  • Investigating whether other offences were committed along with the data theft.

For cyber-related incidents, complaints can also be made through the appropriate cyber-crime police machinery.

5. Data Theft by Employees

A common situation involves an employee who has legitimate access to company information but allegedly copies it before resignation or termination.

The distinction between authorised access and unauthorised use can become important. Merely possessing information during employment does not automatically establish criminal data theft. The prosecution generally needs evidence connecting the accused with unlawful access, copying, extraction, transfer, or use.

For example, downloading a customer database to a personal device immediately before leaving employment may become significant when combined with access logs, device records, emails, or evidence that the database was subsequently provided to a competitor.

6. Civil and Criminal Remedies Can Coexist

Data theft can give rise to both:

Criminal remedies

  • Police complaint/FIR.
  • Cyber-crime investigation.
  • Criminal prosecution where statutory ingredients are established.

Civil remedies

  • Injunction against use or disclosure.
  • Protection of confidential information and trade secrets.
  • Damages where legally recoverable.
  • Enforcement of contractual confidentiality obligations.

Therefore, a company does not necessarily have to choose between criminal proceedings and civil proceedings; the appropriate remedies depend on the facts and applicable law.

Important Case Laws

1. Shreya Singhal v. Union of India (2015)

The Supreme Court examined provisions of the Information Technology Act and emphasised the constitutional framework governing restrictions on online speech. The case is important when considering the limits of criminal provisions involving internet activity and demonstrates that offences under cyber legislation must satisfy statutory and constitutional requirements.

Relevance: A police complaint concerning online activity must identify the precise statutory offence rather than relying on broad allegations.

2. Anvar P.V. v. P.K. Basheer (2014)

The Supreme Court laid down important principles concerning the admissibility of electronic records under the Indian Evidence Act.

Relevance to data theft: Electronic evidence such as emails, computer records, and digital files must be properly proved in accordance with the applicable evidentiary requirements.

3. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020)

The Supreme Court further clarified the law concerning electronic evidence and certificates relating to electronic records.

Relevance: Where a data-theft prosecution depends upon computer-generated records, proper handling and authentication of those records can become crucial.

4. State of Tamil Nadu v. Suhas Katti (2004)

This is one of India's early convictions involving offences under the Information Technology Act. The case demonstrated the practical use of electronic evidence, including computer records and other digital material, in a cybercrime prosecution.

Relevance: It illustrates how digital evidence can support criminal proceedings concerning unlawful online activity.

5. Trimex International FZE Ltd. v. Vedanta Aluminium Ltd. (2010)

The Supreme Court recognised that contractual arrangements can, in appropriate circumstances, be established through electronic communications.

Relevance: In employment-related data theft disputes, emails and electronic communications may have significance in establishing contractual obligations, including confidentiality arrangements.

6. RMC Readymix (India) Pvt. Ltd. v. Aegis Employees Union — principles concerning confidential business information

Indian courts have recognised the importance of contractual confidentiality and protection of legitimate business interests in employment relationships.

Relevance: Where an employee allegedly removes confidential business information, the employer may rely upon contractual confidentiality provisions in addition to pursuing appropriate statutory remedies.

7. American Express Bank Ltd. v. Priya Puri (2006)

The Delhi High Court considered an employment dispute involving confidential information and customer-related information. The Court distinguished between information that could legitimately be protected as confidential and information that an employee could use as part of ordinary professional knowledge.

Relevance: This is particularly important in employee data-theft cases because an employer must establish that the information claimed to be confidential actually warrants protection.

8. Diljeet Titus v. Alfred A. Adebare (2006)

The Delhi High Court dealt with protection of confidential information and copyright-related material in a professional context.

Relevance: The decision illustrates the importance of protecting confidential digital/business material and demonstrates that misuse of information can potentially lead to civil protective remedies in addition to other legal proceedings.

7. What the Complaint Should Establish

A strong data-theft complaint should establish four basic elements:

Access → Unauthorised conduct → Data extraction/use → Evidence

For example:

The employee had access to the company's customer database for employment purposes. On a particular date, the employee accessed and downloaded the database to an unauthorised personal device. Server logs establish the download, and subsequent records indicate that the information was transferred to a third party.

This is considerably stronger than merely stating:

"The employee stole our data."

The complaint should therefore provide specific dates, systems, files, access records, and supporting evidence.

8. Special Importance of Digital Forensics

Data theft investigations can become difficult because deleted files may be recoverable, metadata may reveal the history of a document, and access logs can establish when an account was used.

The complainant should therefore avoid:

  • Editing original files.
  • Deleting potentially relevant logs.
  • Resetting or wiping the suspected device without preserving evidence.
  • Relying exclusively on screenshots.
  • Making unsupported accusations.
  • Altering timestamps or metadata.

Maintaining a documented chain of custody for important electronic evidence can strengthen the investigation.

9. Conclusion

A police complaint for data theft should be fact-specific and evidence-based. It should identify the data, explain the accused person's authority or lack of authority, describe the alleged unauthorised activity, identify the applicable legal provisions where possible, and preserve the electronic evidence capable of proving the allegation.

In employment situations, particular attention should be given to access permissions, confidentiality agreements, download logs, email records, USB activity, cloud transfers, and evidence of subsequent disclosure or use. Civil injunctions and contractual remedies may operate alongside criminal proceedings where the facts justify them.

 

 

LEAVE A COMMENT