Current Affairs · · GS2 · International Relations

India signs the first global treaty against cybercrime

External Affairs Minister S. Jaishankar signed the UN Convention against Cybercrime in New York on 25 September 2026, on the sidelines of the General Assembly. It is the first comprehensive global treaty on cybercrime. Signing is not the final step: the treaty needs ratifications before it binds a State.

Event date:

REq1

The brief in 6 cards

  1. Context1 / 6

    On 25 September 2026, External Affairs Minister S. Jaishankar signed the United Nations Convention against Cybercrime at UN Headquarters in New York, on the sidelines of the 81st session of the UN General Assembly. The UN General Assembly adopted the convention on 24 December 2024 through Resolution 79/243, after around five years of negotiations. The UN Office on Drugs and Crime (UNODC) served as secretariat for the negotiations. The convention's full title is the United Nations Convention against Cybercrime: Strengthening International Cooperation for Combating Certain Crimes Committed by Means of Information and Communications Technology Systems and for the Sharing of Evidence in Electronic Form of Serious Crimes.

  2. Key highlights2 / 6

    Offences covered: The convention sets legal standards for offences such as illegal access to systems, illegal interception, cyber fraud and online child sexual exploitation.

    Electronic evidence: It also addresses collection and sharing of electronic evidence in serious crimes generally, whether or not those crimes were committed online.

    Cooperation: It facilitates cross-border electronic-evidence sharing and provides for a 24/7 cooperation network among States.

    Asset recovery and capacity: It provides for recovery of proceeds of cybercrime and includes capacity-building support, particularly for developing countries.

    Signature window: It opened for signature in Hanoi on 25 October 2025 and remains open for signature at UN Headquarters until 31 December 2026. This is why it is often called the Hanoi Convention. The UN Treaty Collection recorded India's signature on 25 September 2026.

  3. Key concepts3 / 6

    1. The life cycle of a UN treaty

    • Negotiation: States discuss and draft provisions.
    • Adoption: The text is finalised, here by the UN General Assembly by consensus. Adoption does not make any State a party.
    • Signature: A State indicates its intention to become a party. Signature generally creates an obligation not to defeat the treaty's object and purpose, but does not by itself bind the State to the treaty's substantive provisions.
    • Ratification, acceptance, approval or accession: The State completes its domestic process and formally consents to be legally bound.
    • Entry into force: The convention enters into force 90 days after deposit of the 40th instrument of ratification, acceptance, approval or accession.

    Adoption is not signature; signature is not ratification. The entry-into-force threshold counts instruments of consent to be bound, not signatures. The UN Treaty Collection records India as having signed on 25 September 2026; its current treaty record should be checked again before publication for any later change in status.

    2. Cybercrime and electronic evidence

    Cybercrime includes offences where a computer system is the target, such as hacking or ransomware, and offences where technology is the means, such as online fraud. Electronic evidence is information stored or transmitted digitally that may be relevant to an investigation, such as server logs, communications data or stored files. Such evidence may be held in a country different from the crime scene or victim's location. Mutual Legal Assistance Treaties (MLATs) provide a formal route for seeking evidence across jurisdictions; the 24/7 network is intended to help urgent preservation and requests move faster.

    3. The debate

    Supporters argue that cross-border cybercrime needs a global framework, that existing instruments such as the Council of Europe's Budapest Convention have limited membership, and that a UN instrument gives developing countries a role and includes capacity-building. Critics, including human-rights organisations, technology companies and digital-rights groups, have raised concerns about the convention's scope for sharing electronic evidence in serious crimes generally and the strength and consistent application of human-rights safeguards. Its effects will depend substantially on domestic implementation and safeguards.

    4. Consensus adoption

    Adoption by consensus means the resolution passed without a vote because no member formally objected. It indicates broad acceptability of the text, not equal support for every provision or an assurance that all States will sign or ratify. The convention is not yet in force according to the UN Treaty Collection; entry into force depends on 40 instruments of consent to be bound, not signatures.

  4. Way forward4 / 6

    Complete the domestic process: India must complete its constitutional and legal process before ratification and before it is bound by the convention's substantive provisions.

    Align domestic law: Examine how the obligations interact with the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and the Digital Personal Data Protection Act, 2023.

    Build safeguards: Ensure cross-border data-sharing mechanisms include clear procedures, judicial oversight and privacy protections, in line with the Puttaswamy judgment's recognition of privacy as a fundamental right.

    Strengthen capacity: Invest in cyber forensics, trained investigators and prosecution capacity so domestic institutions can act on international cooperation.

    Engage on capacity-building: Use the convention's capacity-building provisions both to benefit from and contribute to support for developing countries.

  5. Note5 / 6

    Why this matters for India

    India has one of the world's largest internet user bases and has seen growth in reported cyber fraud, particularly financial fraud. Cybercrime affecting Indians may originate abroad, while evidence may sit on servers in another jurisdiction; without a cooperation framework, investigations can stall. India's digital payment and identity systems raise the stakes for both security and privacy.

    India already operates the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs and CERT-In under MeitY. A treaty framework can complement, not replace, these institutions. India's signature is notable given that it has not joined the Budapest Convention. India's data-protection framework and constitutional right to privacy will shape how cross-border data requests are handled in practice.

  6. Note6 / 6
    REq1

Sources

Syllabus

PaperSubjectSub-topic
GS2International RelationsImportant International institutions, agencies and fora, their structure and mandate; bilateral, regional and global groupings and agreements involving India. Prelims and Mains.
GS3Internal SecurityBasics of cyber security; challenges to internal security through communication networks. Prelims and Mains.
EssayPolity—

Topics

International Relations and Current AffairsGovernanceHigher Judiciary (SC and HC)Information and Communication Technology

Related previous-year questions

Asked in earlier UPSC Prelims papers on this topic. Answer, then check.

  1. UPSC Prelims 2017 · Science and Technology · Information and Communication Technology

    In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data centres 3. Body corporate Select the correct answer using the code given below:

    1. 1 only
    2. 1 and 2 only
    3. 3 only
    4. 1, 2 and 3
    Show answer

    Answer: D. VERDICT: The answer is 1, 2 and 3. Service providers, data centres and body corporates are all legally required to report cyber security incidents. ANALYSIS: Under the information technology framework, the Indian Computer Emergency Response Team serves as the national nodal agency for cyber security, collecting, analysing and disseminating information on cyber incidents, issuing forecasts and alerts, and coordinating incident response. The rules made under the Act make mandatory reporting of cyber security incidents applicable to service providers, intermediaries, data centres and body corporates alike, so all three categories in the question are covered. SOURCE: Press Information Bureau release and the Information Technology Act framework. Source type RR. HOW TO CRACK IT: Reason from the purpose of a national incident response agency. Such a body can only function if it receives reports from every entity that holds or moves data, so a reporting duty confined to one category would defeat the design. Where a regulatory obligation exists to build a national picture, expect the obligation to be broad rather than narrow, and expect the inclusive option. Keep CERT-In tagged as the nodal agency, since that single fact anchors the whole topic.

    Difficulty: hard · statement

    Open this question on its own page, with the full explanation →

Practice questions

  1. With reference to the process by which a State becomes party to a UN treaty, consider the following statements: 1. Adoption of a treaty text by the UN General Assembly automatically makes all UN member States parties to it. 2. Signature indicates a State's intention to become a party but does not by itself make it legally bound by the treaty's substantive obligations. 3. Ratification involves a State completing its domestic process and formally consenting to be legally bound. Which of the statements given above is/are correct?

    1. 2 and 3 only
    2. 1 and 2 only
    3. 1 and 3 only
    4. 1, 2 and 3
    Show answer

    Answer: A. Statements 2 and 3 are correct. Adoption finalises the text but does not make a State a party; each State separately consents to be bound through the applicable treaty process.

    Difficulty: medium · statement

  2. With reference to the United Nations Convention against Cybercrime, consider the following statements: 1. It was adopted by the UN General Assembly in December 2024. 2. The UN Office on Drugs and Crime served as secretariat for the negotiations. 3. Its scope is limited strictly to cyber offences and does not extend to electronic evidence in other serious crimes. Which of the statements given above is/are correct?

    1. 1 and 2 only
    2. 2 and 3 only
    3. 1 and 3 only
    4. 1, 2 and 3
    Show answer

    Answer: A. Statements 1 and 2 are correct. The convention also covers collection and sharing of electronic evidence in serious crimes generally.

    Difficulty: medium · statement

  3. Consider the following statements regarding international instruments on cybercrime: 1. The Budapest Convention on Cybercrime was developed under the Council of Europe. 2. India is a party to the Budapest Convention. 3. A Mutual Legal Assistance Treaty is a formal mechanism through which States seek evidence located in another jurisdiction. Which of the statements given above is/are correct?

    1. 1 and 3 only
    2. 2 and 3 only
    3. 1 and 2 only
    4. 1, 2 and 3
    Show answer

    Answer: A. Statements 1 and 3 are correct. India is not a party to the Budapest Convention.

    Difficulty: medium · statement

Mains practice

Answer-writing practice on this article. Attempt it first, then open the hints.

  1. GS2 · 250 words

    The UN Convention against Cybercrime is the first global treaty of its kind. Examine its significance for India, and discuss the concerns that have been raised about it. (250 words)

    Show hints
    1. Explain the gap it fills: cybercrime is cross-border, while existing instruments have limited membership.
    2. Discuss India's position: it is not a party to the Budapest Convention and has signed the UN instrument.
    3. Cover offence definitions, the 24/7 cooperation network, electronic-evidence sharing, asset recovery and capacity-building.
    4. Address concerns about broad electronic-evidence provisions, surveillance risk and human-rights safeguards.
    5. Discuss domestic alignment with India's IT Act, data-protection law and constitutional right to privacy.
  2. Essay · 250 words

    A crime without borders demands cooperation without borders, but cooperation must not become a doorway to overreach.

    Show hints
    1. Explain why cybercrime requires international cooperation.
    2. Discuss practical difficulties such as evidence held in other jurisdictions and slow formal processes.
    3. Examine the tension between rapid cooperation and procedural safeguards.
    4. Consider the risk that cooperation frameworks may be used beyond their stated purpose.
    5. Explain the role of domestic safeguards, judicial oversight and privacy protections in legitimate cooperation.