New Delhi: One year after a parliamentary panel recommended amendments to the Delhi Special Police Establishment Act, 1946, allowing the Central Bureau of Investigation (CBI) to probe cybercrime cases across the country without the need for general consent from state governments, the Director of CBI has requested the Chief Secretaries of 14 states for the issuance of consent, the parliamentary committee noted in its report tabled on Friday.
The Department-related Parliamentary Standing Committee on Home Affairs has been authorised by the Parliamentary Committee to submit the report on its behalf. The report pertains to action taken by the government on the recommendations and observations contained in the ‘254th report of the Committee on Cybercrime— Ramifications, Protection and Prevention’.
The Standing Committee on Home Affairs based its recommendation on the submission that the need to obtain general consent from the state before launching an investigation hinders the early detection of leads in cybercrime cases and compromises the quality of the probe.
The committee, in CBI’s reply, had said that certain states have withdrawn general consent required under the Delhi Special Police Establishment Act, 1946 (DSPE Act). It creates a major hurdle in the seamless investigation of cybercrime, and asking for specific consent on a case-to-case basis is time-consuming, creates stress on resources and manpower, can hamper the quality of investigation and is detrimental to timely and prompt investigation, it states.
Presenting its case before the panel, CBI said at least eight states have withdrawn general consent for cybercrime probes in their jurisdictions—which is mandated under Sections 5 and 6 of the DSPE Act. Meanwhile, eight more state governments have extended their specific consents; and Arunachal Pradesh, Assam, Chhattisgarh, Gujarat, Haryana, Odisha have issued General Consent for all offences including IT Act.
It has been notified that the Director, CBI, on 8 July 2025, requested the Chief Secretaries of the remaining 14 states for consent for investigation by CBI under Information Technology Act, 2000, as notified by the Government of India under Section 3 of the DSPE Act within the territory of the respective states, the committee noted in its report tabled in Rajya Sabha.
The 14 states are: Bihar, Karnataka, Kerala, Maharashtra, Meghalaya, Madhya Pradesh, Punjab, Rajasthan, Jharkhand, Tamil Nadu, Telangana, Tripura, Uttarakhand, and West Bengal.
Regulation of online gaming
The Parliamentary Committee observed that at present, regulation of online gaming in India is overseen by various ministries and state governments, resulting in a fragmented and, at times, inconsistent approach to enforcement and consumer protection.
“Recognising these challenges, the committee recommends the Central Government the establishment of a dedicated ecosystem for online gaming in the country through a comprehensive consultative process. The committee is of the view that this system should not only oversee the sector to address concerns related to real money/betting apps but also foster the development of a vibrant multimedia, animation, gaming ecosystem within the country,” the recommendations noted.
Regarding the action taken, it said the Promotion and Regulation of Online Gaming Act, 2025 (PROG Act), MeitY, has published the Draft Promotion and Regulation of Online Gaming Rules, 2025, on its website on 2 October 2025, for public consultation.
The action taken report also said, the public consultation process has been completed, and MeitY, after “due consideration of stakeholder inputs”, has initiated the process of finalisation of the rules. The ministry is concurrently undertaking necessary steps to operationalise the provisions of the Act, including the establishment of the authority mandated under the Act, along with the creation of its administrative and technical infrastructure, the report added.
VoIP calls, bulk SMS
Another issue the committee noted was that the regulatory frameworks governing the use of telecom channels such as automatic calls, bulk SMSs and Voice over Internet Protocol (VoIP) be strengthened in order to prevent misuse of these services for phishing campaigns.
The committee recommended continued investment in indigenous AI technologies like artificial intelligence and facial recognition powered solution for Telecom SIM Subscriber Verification (ASTR) to ensure SIM card issuance with a focus on preventing identity fraud at the point of issue.
Regarding this, the Department of Telecommunications has stated that it has been continuously strengthening and refining its regulatory framework to prevent the misuse of telecom resources.
In this context, the Telecom Cyber Security Rules, 2024, were notified on 21 November 2024, providing a comprehensive legal framework to address and curb such misuse. Further, draft amendments to the Telecom Cyber Security Rules, 2024, were published for public consultation on 24 June 2025.
“DoT uses the Artificial Intelligence and Telecom Subscriber Reverification (ASTR) mechanism on a regular basis for the identification of suspected mobile connections and their subsequent disconnection after due reverification,” the action taken report adds.
Further, in line with the recommendations of the committee, the Detailed Project Report (DPR) for Phase-II of the Digital Intelligence Unit (DIU) project has been “accorded approval to enable further investment and advancement in indigenous artificial intelligence technologies, thereby strengthening the security and integrity of the telecom ecosystem”.
The mobile number and fraud problem
Considering the importance of public awareness in cybercrime prevention, the committee observed that sustained multilingual and cross-platform campaigns should be intensified, particularly in regional and rural areas, so that more citizens know how to report fraud and reclaim control over their mobile credentials.
The committee recommended that it would be valuable to take the Mobile Number Validation Service (MNVS) beyond the current stage and implement it nationwide in collaboration with banks, NBFCs and fintech platforms to limit the use of mobile numbers in fraudulent or mule accounts, the recommendations noted.
Regarding this, the Department of Telecommunications (DoT) has stated that the DoT has been consistently undertaking citizen outreach initiatives to enhance awareness regarding telecom-related fraud and to inform the public about the latest measures for ensuring telecom safety.
As part of these initiatives, sustained efforts have been made to promote the adoption and use of the ‘Sanchar Saathi’ portal and mobile application, a flagship citizen-centric platform that enables users to report suspected fraudulent communications. The ‘Sanchar Saathi’ portal and mobile app are available in multiple regional languages for inclusion. There also exist citizen engagement and awareness activities.
Additionally, under the Sanchar Mitra Volunteer Programme, student volunteers from universities across the country are actively assisting in educating citizens on digital safety, fraud prevention and the effective use of ‘Sanchar Saathi’.
“In order to strengthen the regulatory framework, DoT has notified the amendment to the Telecom Cyber Security Rules, 2024; these amendments provide the necessary legal underpinnings for the implementation of the Mobile Number Validation Service (MNVS),” the committee notified.
(Edited by Viny Mishra)
Also read: ‘Krrish’ unmasked: How CBI trapped the ghost who ‘lured Indians to Myanmar cyber scam farms’

