INTRODUCTION
Someone’s home address, phone number and daily routine are, right now, sitting in a public post they never agreed to share. That is doxxing, and India has no law naming it a distinct offence, though existing provisions apply to it indirectly. The Delhi High Court has observed that doxing “hasn’t been defined in the Indian legal landscape, nor has it been made a statutory offence in India,” while holding that aggrieved persons can still seek relief through the law of torts and privacy.[1] This piece argues that the patchwork of privacy, harassment and intimidation law currently applied to doxxing addresses its consequences, not the act itself, and that Parliament should give it a home of its own.
WHAT DOXXING ACTUALLY IS
Doxxing means collecting and publishing someone’s private identifying information, address, phone number, workplace, family details, without consent, usually so others can find, threaten or harass them. The discloser may never send a threatening message themselves; once information is published, others often act on it independently, which is what makes doxxing hard to prosecute under existing law.
TWO INCIDENTS THAT SHOW THE GAP
The ‘Sulli Deals’ and ‘Bulli Bai’ apps illustrate the pattern. In 2021 and 2022, unidentified users built apps that lifted photographs of Muslim women from social media and listed them for mock ‘auction’ with identifying details, without consent.[2] Delhi Police filed chargesheets under sections 153A and 153B of the Indian Penal Code (communal enmity) and section 354A(3) (sexual harassment), read with sections 66 and 67 of the Information Technology Act, 2000.[3] None of these was written for identity-assembly itself; they applied only because the doxxing carried religiously targeted, sexualised commentary, and a comparable app without that commentary would likely have found no provision to invoke at all.
The ‘Bois Locker Room’ case is similar. In 2020, a private Instagram group shared photographs of minor girls, some morphed, with names, schools and explicit commentary. Delhi Police registered an FIR under the forgery provisions and section 509 of the Indian Penal Code, read with sections 67 and 67A of the Information Technology Act, and the Protection of Children from Sexual Offences Act 2012 applied because minors were involved.[4] Again, the charges tracked forgery, obscenity and modesty, not the underlying act of exposing the girls to a hostile audience. Doxxing also happens in smaller ways daily, a journalist’s number posted after an article, an activist’s address shared in an argument, each ending in harassment from strangers triggered by information someone else made public.
WHY EXISTING LAW DOES NOT COVER IT
India’s privacy jurisprudence, anchored in Justice K.S. Puttaswamy v Union of India, protects individuals against intrusion into personal life, but was built around informational self-determination and data protection, not the act of assembling an identity and handing it to a hostile crowd.[5] The Digital Personal Data Protection Act, 2023 regulates ‘data fiduciaries’, those who determine the purpose and means of processing personal data, but an individual doxxer republishing scraped information falls outside that framework.[6]
Cyber harassment provisions, stalking under the Bharatiya Nyaya Sanhita and obscenity under sections 67 and 67A of the Information Technology Act, generally require repeated contact, sexual content or direct communication.[7] Doxxing needs none of that: a single post can trigger harm sustained by hundreds acting independently, not by the original poster.
Criminal intimidation under section 351 of the Bharatiya Nyaya Sanhita requires a threat communicated with intent to cause alarm.[8] The person who first publishes an address rarely threatens anything themselves; the alarm that follows comes from third parties acting independently, so the provision does not plainly extend to the discloser. This is a structural limitation in the drafting rather than a settled judicial finding, no reported decision has tested it, and the provision should not have to be stretched to fit at all.
DOXXING AS ITS OWN CATEGORY OF HARM
Together these gaps show a pattern: doxxing is not simply privacy violation, harassment or intimidation, since weaponised disclosure rests on neither repeated contact nor a threat from an identifiable person. It is a distinct harm: converting a private life into a public target and letting others do the harming.
WHY A STANDALONE OFFENCE RATHER THAN AMENDING EXISTING LAW
An objection follows: why not simply amend section 351, widen the stalking provision, or extend the Digital Personal Data Protection Act to individual disclosers? Three reasons favour a standalone offence. First, each existing provision has a definitional core, threat, repeated contact, fiduciary processing, that does not match doxxing’s real conduct element, disclosure itself, regardless of what follows; stretching those definitions risks diluting the original offence or leaving gaps. Second, a standalone offence lets the mental element be calibrated to doxxing’s actual dynamics, where the defence is almost always that the discloser only wanted to ‘expose’, not harm. Third, a named offence gives cyber cells a specific head for registering complaints, avoiding the classification delay behind under-registration.[9] Existing provisions are not worthless; they should keep applying where facts independently satisfy them, but doxxing should also have a legal home of its own.
WHAT A STANDALONE OFFENCE SHOULD LOOK LIKE
Parliament should define doxxing as the unauthorised publication of a person’s private identifying information, address, contact details, workplace, family details or real-time location, without consent, where the discloser knows or ought reasonably to know that publication is likely to expose the person to harassment, threats or harm.
‘Private identifying information’ should be defined narrowly enough to survive scrutiny: information that allows a person to be located or contacted, which they have not themselves made public. This distinction already exists in practice; commentary on a Delhi High Court ruling notes that sharing already-public information was treated as distinct from doxxing.[10] A statutory offence should adopt this expressly, so republishing an already-public professional address is not, by itself, an offence.
The offence must also carve out journalism, whistleblowing and public-interest disclosure, or it risks an Article 19(1)(a) challenge, since publishing an official’s address while exposing corruption is different in kind from exposing an ordinary citizen for a pile-on, even though the conduct looks similar on paper. An explicit public-interest defence is needed, or the offence risks the vagueness that led the Supreme Court to strike down section 66A of the Information Technology Act in Shreya Singhal v Union of India, where an undefined offence was found to chill speech disproportionately.[11] The mental element should require only knowledge or reckless disregard, not intent to harm, since doxxers typically claim they only wanted to ‘expose’ someone; that permissiveness is exactly why the definitional and public-interest limits above matter, without them, the offence could be used against reporters publishing identifying information about powerful people for legitimate reasons.
PENALTIES, TAKEDOWN AND THE RISK OF MISUSE
Penalties should be tiered: up to two years for straightforward doxxing, rising to five where it targets someone based on gender, religion, caste or sexual orientation, or leads to physical harm or further exploitation, tracking Sulli Deals and Bulli Bai.
A takedown obligation raises design questions of its own. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 already require intermediaries to preserve removed content for 180 days once they act on a complaint.[12] A doxxing-specific obligation could build on this rather than create a parallel one. The risk with any platform-driven takedown power is over-removal: a platform facing liability for delay may remove first and evaluate later, the dynamic Shreya Singhal flagged when it required actual knowledge through a court or government order rather than a private complaint alone.[13] Any takedown duty should route disputed cases through a defined verification step rather than a bare allegation, and a civil right to compensation, independent of any criminal proceeding, should also exist, since criminal cases take years while information stays online.
WHAT ELSE NEEDS TO CHANGE
A new offence needs supporting changes. Cyber cells need a named intake category for doxxing complaints, rather than folding them into general cybercrime registration where they get misclassified. Platforms should preserve doxxing-related content the moment a complaint is filed, alongside their existing 180-day duty under the Intermediary Guidelines Rules.[14] Courts should grant urgent interim relief modelled on the ex parte injunctions already used to protect personality rights against anonymous infringers, so takedown need not wait for trial, a mechanism built for a different problem, unauthorised commercial use of a person’s likeness, but whose core feature, binding unidentified defendants, is close to what a doxxing victim needs.[15]
CONCLUSION
Doxxing is not a footnote to privacy, harassment or intimidation law; it is what happens right before all three. Two women listed for auction online, schoolgirls catalogued without their knowledge, and ordinary people whose numbers circulate in group chats they never joined, all point to the same gap. Closing it requires careful drafting around what counts as private information, how public information is treated, and how journalism is protected. Parliament should give this harm a name, a bounded definition, and a punishment of its own.
Author(s) Name: Shakshi (Campus Law Centre, University of Delhi)
References:
[1] Shaviya Sharma v Quint Neon, 2024 SCC OnLine Del 1445 (Delhi High Court, 22 February 2024), quoting the Court’s observation that doxing “hasn’t been defined in the Indian legal landscape, nor has it been made a statutory offence in India,” while holding that aggrieved persons are not without remedy under the law of torts and privacy.
[2] ‘Delhi Police File Chargesheets in ‘Bulli Bai’, ‘Sulli Deals’ Cases’ (National Herald, 9 March 2022) <https://www.nationalheraldindia.com/national/delhi-police-file-chargesheets-in-bulli-bai-sulli-deals-cases> accessed 20 July 2026.
[3] Indian Penal Code 1860, ss 153A, 153B, 354A(3); Information Technology Act 2000, ss 66, 67; ‘Charge Sheets Filed Against Prime Accused in Bulli Bai, Sulli Deals App Cases’ (ANI, 9 March 2022) <https://www.aninews.in/news/national/general-news/charge-sheets-filed-against-prime-accused-in-bulli-bai-sulli-deals-app-cases20220309081907/> accessed 20 July 2026.
[4] Indian Penal Code 1860, ss 465, 469, 471, 509; Information Technology Act 2000, ss 67, 67A; Protection of Children from Sexual Offences Act 2012; ‘Instagram Bois Locker Room Case Tests India’s Group Chat, Privacy Laws’ (Inc42, 9 May 2020) <https://inc42.com/buzz/instagram-bois-locker-room-case-tests-indias-chat-privacy-social-media-safe-harbour-laws/> accessed 20 July 2026.
[5] Justice K.S. Puttaswamy v Union of India (2017) 10 SCC 1.
[6] Digital Personal Data Protection Act 2023, s 2(i).
[7] Bharatiya Nyaya Sanhita 2023, s 78; Information Technology Act 2000, ss 67, 67A.
[8] Bharatiya Nyaya Sanhita 2023, s 351.
[9] Hamiya M Sagith, ‘Legal Gaps in Addressing Doxxing in India’ (2024) 4 International Journal of Criminal, Common and Statutory Law 34; Internet Freedom Foundation, ‘Why Doxxing Remains a Legal Grey Area: Navigating the Legal Uncertainty of Online Exposure’ <https://internetfreedom.in/why-doxxing-remains-a-legal-grey-area-navigating-the-legal-uncertainty-of-online-exposure/> accessed 20 July 2026.
[10] ‘Sharing Publicly Available Information Not Doxing: Delhi High Court’ (MediaNama, 7 March 2024) <https://www.medianama.com/2024/03/223-sharing-publicly-available-information-not-doxing-delhi-high-court/> accessed 20 July 2026, discussing the Delhi High Court’s observations in Shaviya Sharma v Quint Neon (n 1).
[11] Constitution of India, art 19(1)(a); Shreya Singhal v Union of India (2015) 5 SCC 1.
[12] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, r 3(1)(g).
[13] Shreya Singhal v Union of India (2015) 5 SCC 1 (n 11).
[14] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, r 3(1)(g) (n 12).
[15] Anil Kapoor v Simply Life India, 2023 SCC OnLine Del 6914.

