Digital Safety & Online Privacy
Before you start: no prior technical background is needed. (Note: legal section details β IT Act sections, penalties, DPDP Act specifics β reflect India law as of authoring; verify current provisions before relying on them for anything legal, as laws and amendments change.)
Why This Exists (The Hook)
A phishing email doesn't need to fool a security expert β it only needs to fool one tired, distracted person for ten seconds, out of thousands of attempts. Attackers exploit exactly that asymmetry: they only need to succeed once, while you need to be careful every single time. Digital safety exists to shrink that asymmetry back in your favor β recognizing the small number of attack patterns (urgency, impersonation, requests for OTP/passwords) that cover the overwhelming majority of real attacks, so you can catch them reflexively instead of needing to analyze every message from scratch.
Analogy β Think of digital safety like locking your car and not leaving valuables visible, not building a bunker. Most car break-ins are opportunistic β an unlocked door or a visible laptop on the seat, not a determined thief defeating a serious security system. Removing the easy opportunity (locking doors, hiding valuables) stops the overwhelming majority of real-world attempts, even though a truly determined, resourced attacker could theoretically still get in. Strong unique passwords, 2FA, and recognizing phishing are your "locked doors" β they don't make you invincible, but they stop the vast majority of real attacks, which are opportunistic, not targeted.
Try it (2 minutes) β Reason through why "no legitimate organisation asks for your OTP, password, or CVV" is treated as an absolute rule rather than a rule of thumb, without looking anything up: an OTP exists specifically to prove that a request is coming from you, the account owner, at the moment of a legitimate transaction you initiated. If someone calling and claiming to be from your bank asks you to read them the OTP that just arrived, what are they actually trying to do with it β and why would a genuine bank employee, who already has access to your account internally, have no legitimate reason to need a code that exists purely to prove YOUR identity to THEM?
Most Common Online Threats
Phishing
Fake emails/messages impersonating trusted entities (bank, UIDAI, IRCTC, IT Department) to steal credentials.
Spotting phishing:
Phishing variants:
Social Engineering
Manipulating people rather than systems. Common scenarios:
Password Attacks
Malware
Malicious software that damages or steals from your device:
Protective Measures
Passwords & Authentication
- Authenticator app (Google Authenticator, Authy) β better than SMS OTP
- Hardware key (YubiKey) β strongest
- SMS OTP β better than nothing, but vulnerable to SIM swap attacks
Device Security
Network Security
India-Specific Digital Laws
IT Act 2000 & Amendments
Sec 43: Damage to computer system β civil penalty up to βΉ1 crore
Sec 66: Computer related offences β imprisonment up to 3 years and/or fine
Sec 66A (struck down): Offensive online communication β removed by Supreme Court in Shreya Singhal (2015)
Sec 66C: Identity theft β imprisonment up to 3 years, fine βΉ1 lakh
Sec 66D: Cheating by personation using computer β same penalties
Sec 66E: Violation of privacy (capturing/transmitting private images without consent) β imprisonment up to 3 years
Sec 67: Obscene material online β imprisonment up to 5 years
Sec 69: Government power to intercept/monitor β requires Home Secretary order
Sec 79: Safe harbour for intermediaries β platforms not liable for user content if they comply with takedown notices
DPDP Act 2023 (Digital Personal Data Protection)
How to Report Cybercrime in India
Cybercrime Portal: cybercrime.gov.in
Cyber Helpline: 1930 (national helpline for financial fraud β report within 24 hours to block money)
Local police: File FIR at nearest police station. Cyber cells in major cities.
Golden rule for financial fraud: If money has been transferred fraudulently, call 1930 IMMEDIATELY. Banks can flag and hold fraudulent transactions if reported within a few hours.
Privacy Settings β Quick Actions
Google Account: myaccount.google.com β Data & Privacy β review what's saved
Facebook: Settings β Privacy β restrict post visibility, disable location
WhatsApp: Settings β Privacy β Who can see last seen, profile photo, status β set to Contacts only
Instagram: Settings β Privacy β Private Account β approve followers
LinkedIn: Settings β Privacy β restrict who sees your connections, activity
App permissions (Android/iOS): Settings β Apps β review camera, microphone, location permissions. Revoke any app that doesn't need them.

