Why in news?
External Affairs Minister S. Jaishankar signed the United Nations Convention against Cybercrime for India on 25 September in New York. The agreement seeks to help countries investigate technology-related offences and obtain electronic evidence across borders. Such evidence may be held outside the country where victims or investigators are located, making cooperation essential. India's signature is recorded in the United Nations treaty register, but it is not ratification. The convention also remains outside force: its legal threshold requires ratifications or equivalent instruments, not merely signatures. The development therefore signals India's participation in a proposed global cooperation framework, while leaving further legal and implementation steps ahead.
The problem behind the agreement
A criminal investigation can involve several jurisdictions even when the victim never leaves home. An account may be operated from one country, with relevant records held by a service provider elsewhere. Investigators then need a lawful way to preserve and obtain that evidence. The fact that information travels quickly does not remove the legal boundaries governing access to it.
The convention addresses this mismatch between cross-border activity and nationally organised criminal justice systems. It combines provisions on offences, investigative powers and cooperation. It also includes technical assistance and capacity building. The aim is not to create a single worldwide police force. National authorities would continue to act through domestic law and the treaty's agreed procedures.
Adoption, signature and ratification
The United Nations General Assembly adopted the convention on 24 December 2024 through resolution 79/243. It opened for signature in Hanoi on 25–26 October 2025, followed by signature at United Nations Headquarters. These events explain why it is also associated with Hanoi. Adoption settled the treaty text; opening for signature allowed eligible participants to begin joining the framework.
Signature and ratification serve different purposes. A signature does not, by itself, make India a party bound by all the convention's operational obligations. The treaty provides for ratification, acceptance or approval, with instruments deposited with the United Nations Secretary-General. It also allows accession. India's depositary entry records the signature of 25 September, not a completed ratification.
Entry into force requires the fortieth qualifying instrument, followed by 90 days. Article 65 specifies instruments of ratification, acceptance, approval or accession. Counting signatures instead gives the wrong legal result. The depositary's status record confirms that the convention is not yet in force. A report describing it as already operational from 2025 should therefore not override the treaty text and register.
What conduct and evidence does it cover?
The criminalisation chapter includes unlawful access, unlawful interception and interference with electronic data or systems. Other provisions address technology-enabled fraud and certain forms of online exploitation. These provisions require national legal measures rather than automatically replacing domestic criminal codes. Their precise elements and permitted qualifications matter when countries translate treaty commitments into enforceable offences.
The cooperation framework also reaches beyond offences committed entirely online. Article 35 covers electronic evidence relating to serious crime. Article 2 defines that category by a maximum possible custodial penalty of at least four years, or a more serious penalty. This is a threshold based on the offence's legal punishment, not the sentence actually imposed in a particular case.
Preserving evidence is not the same as disclosing it
Electronic records may be altered or deleted before a formal request is completed. Article 25 therefore provides for expedited preservation of specified stored data. Preservation protects material while authorities pursue the next lawful step; it does not mean that every preserved record is immediately handed over. Keeping those stages separate helps explain both the investigative purpose and the need for controls.
The text also provides for production orders, searches of stored data and certain real-time collection powers. These are subject to the convention's conditions and domestic legal safeguards. Article 41 calls for a contact point available around the clock to support immediate assistance. A readily available contact can speed communication, but it does not erase the legal requirements attached to the requested action.
Rights and sovereignty remain central
Article 6 requires implementation consistent with international human-rights obligations. It also rejects interpretations permitting suppression of protected freedoms. Article 24 adds proportionality and domestic safeguards for investigative powers. These include, where appropriate, judicial or other independent review, effective remedies, justified grounds and limits on scope and duration. The protections are part of the legal framework, not optional additions to it.
The convention also respects the territorial authority of states. It does not authorise one country to perform another country's reserved official functions on foreign territory. Cross-border cooperation therefore remains a legal process between authorities, rather than a general permission to search systems anywhere. Effective implementation will depend on how requests, review mechanisms and accountability work in practice.
Conclusion
India's signature advances its involvement in a global framework for cybercrime investigations and electronic evidence. The immediate change is diplomatic and legal participation, not the instant activation of every treaty power. Ratification, the convention's entry into force and domestic implementation remain separate milestones. The framework's eventual effectiveness will depend on obtaining useful evidence while preserving lawful authority, proportionality and meaningful protection of rights.