Prevention of Electronic Crimes Act, 2016

Prevention of Electronic Crimes Act, 2016 — Section 35: Powers of an authorized officer

35. Powers of an authorized officer.— (1) Subject to provisions of this Act, an authorized officer shall have the powers to

(a)have access to and inspect the operation of any specified information system;

(b)use or cause to be used any specified information system to search any specified data contained in or available to such system;

(c)obtain and copy only relevant data, use equipment to make copies and obtain an intelligible output from an information system;

(d)have access to or demand any information in readable and comprehensible format or plain version;

(e)require any person by whom or on whose behalf, the authorized officer has reasonable cause to believe, any information system has been used to grant access to any data within an information system within the control of such person;

(f)require any person having charge of or otherwise concerned with the operation of any information system to provide him reasonable technical and other assistance as the authorized officer may require for investigation of an offence under this Act; and

(g)require any person who is in possession of decryption information of an information system, device or data under investigation to grant him access to such data, device or information system in unencrypted or decrypted intelligible format for the purpose of investigating any such offence: Explanation.—Decryption information means information or technology that enables a person to readily retransform or unscramble encrypted data from its unreadable form and from ciphered data to intelligible data.

(2)In exercise of the power of search and seizure of any information system, program or data the authorized officer at all times shall,

(a)act with proportionality;

(b)take all precautions to maintain integrity and secrecy of the information system and data in respect of which a warrant for search or seizure has been issued;

(c)not disrupt or interfere with the integrity or running and operation of any information system or data that is not the subject of the offences identified in the application for which a warrant for search or seizure has been issued;

(d)avoid disruption to the continued legitimate business operations and the premises subjected to search or seizure under this Act; and

(e)avoid disruption to any information system, program or data not connected with the information system that is not the subject of the offences identified in the application for which a warrant has been issued or is not necessary for the investigation of the specified offence in respect of which a warrant has been issued.

(3)When seizing or securing any data or information system, the authorized officer shall make all efforts to use technical measures to maintain its integrity and chain of custody. The authorized officer shall seize an information system, data, device or articles, in part or in whole, as a last resort only in the event where it is not possible under the circumstances to use such technical measures or where use of such technical measures by themselves shall not be sufficient to maintain the integrity and chain of custody of the data or information system being seized.

(4)Where an authorized officer seizes or secures any data or information system, the authorized officer shall ensure that data or information system while in the possession or in the access of the authorized officer is not released to any other person including competitors or public at large and details including log of any action performed on the information system or data is maintained in a manner prescribed under this Act.

This is the text of the provision as enacted. It is legal information, not legal advice, and it cannot account for the facts of your own matter. For advice on your situation, consult a verified advocate.