Project AASHVAST: Cyber Safety, Tech Policing and Privacy
How Gujarat's pioneering cyber defense model balances real-time fraud interception with constitutional privacy limits under the DPDP Act and Puttaswamy test.
Sep, 2026
•9 min read
Overview
Project Cyber AASHVAST represents a pioneering transition from post-incident criminal investigation to proactive digital threat deterrence in India, illustrating how state-level technological integration can modernize policing while exposing critical constitutional tensions between law enforcement surveillance and the fundamental right to privacy. Inaugurated on 11 January 2020 in Gandhinagar by the Government of Gujarat, the initiative established India's first dedicated state-level cybercrime prevention and victim assistance unit. By combining real-time financial fraud interception, citizen-facing device hygiene kiosks, and institutional integration with physical surveillance grids, the project created an operational blueprint that prefigured national mechanisms under the Ministry of Home Affairs. This case study evaluates the institutional architecture of Cyber AASHVAST, examines its statutory friction with the Digital Personal Data Protection Act, 2023, and outlines how federal policing models must reconcile rapid technological deterrence with fundamental civil liberty safeguards.
Why in the News: From Gujarat's Pioneer Lab to National Cyber Defense
Project Cyber AASHVAST serves as the foundational operational model for state-level cyber prevention hubs across India as digital fraud networks rapidly expand in scale and sophistication. As of June 2026, the Ministry of Home Affairs reported that the national Citizen Financial Cyber Fraud Reporting and Management System alongside Helpline 1930 had saved over Rs 11,158 crore across more than 32.80 lakh complaints nationwide, scaling an interception model originally piloted in Gandhinagar.
Under the Seventh Schedule of the Constitution of India, 'Police' (Entry 2) and 'Public Order' (Entry 1) fall squarely within List II (State List), placing primary statutory responsibility for cybercrime investigation on State Law Enforcement Agencies. Consequently, state-level innovations remain critical for translating central reporting mechanisms into localized field enforcement and timely forensic recovery.
Discuss with Superkalam
Which operational arm of Cyber AASHVAST provides public kiosks for malware auditing on personal devices?
Ask NowWhat is Project Cyber AASHVAST and How Does It Function?
Project Cyber AASHVAST (Assured Assistance Service Helpful for Victims At Shortest Time) operates as a specialized techno-policing framework designed to minimize response latency in cyber offences. Developed by the Gujarat Police, the initiative was conceptualized to address the structural lag between online crime commission and conventional First Information Report (FIR) registration.
The system functions through a synchronized multi-tier architecture that receives distress calls, freezes illicit financial flows within the banking ecosystem, and provides technical assistance to citizens. Instead of requiring victims to navigate complex procedural channels during an ongoing incident, the platform initiates immediate administrative countermeasures to secure digital assets and preserve volatile electronic evidence.
Key Pillars: Incident Response, Digital Forensics, and Citizen Helplines
Project Cyber AASHVAST is organized into four specialized operational arms that handle specific vectors of the digital threat environment. According to the Gujarat Police Cyber Crime Cell Official Framework, these four pillars ensure comprehensive coverage from immediate triage to long-term digital hygiene:
- Incident Response Unit (IRU): Operates on a continuous 24x7 basis to intercept fraudulent online financial transactions and freeze illicit fund transfers across banking channels in real time, mitigating financial losses before fraudsters siphon capital through mule accounts.
- Cyber Anti-Bullying Unit: Provides dedicated psychological counseling, grievance redressal, and identity protection for vulnerable citizens facing online harassment, cyberstalking, and non-consensual image morphing.
- Cyber Suraksha Lab: Manages public-facing digital kiosks enabling citizens to audit personal electronic devices for malware, spyware, and unauthorized access, fostering preventive digital hygiene.
- Cyber Crime Prevention Unit: Conducts community outreach, analyses emerging modus operandi, and disseminates targeted advisories to inoculate citizens against evolving phishing and social engineering tactics.
How AASHVAST Integrates with VISWAS and NETRANG Security Grids
Project Cyber AASHVAST achieves heightened operational capability by integrating with Gujarat's statewide physical surveillance infrastructure. The platform links directly with Project VISWAS (Video Integration and State Wide Advanced Security), which centralizes video feeds from over 7,000 CCTV cameras deployed across 34 district headquarters.
Project NETRANG reinforces this infrastructure by establishing district-level Command and Control Rooms, termed Netram, across all districts of Gujarat. These district hubs feed surveillance streams into the state-level Trinetra integrated command center, allowing law enforcement to cross-reference digital transaction trails with real-time physical telemetry.
+-------------------------------------------------------------------------+
| TRINETRA INTEGRATED COMMAND HUB |
| (State-Level Convergence) |
+------------------------------------+------------------------------------+
|
+-------------------------+-------------------------+
| |
+----------v-----------+ +---------v----------+
| PROJECT VISWAS | | PROJECT NETRANG |
| (Over 7,000 CCTVs | | (District Netram |
| Across 34 Districts) | | Control Rooms) |
+----------+-----------+ +---------+----------+
| |
+-------------------------+-------------------------+
|
+------------------------------------v------------------------------------+
| PROJECT CYBER AASHVAST |
| [Incident Response] [Anti-Bullying] [Suraksha Lab] [Crime Prevention] |
+-------------------------------------------------------------------------+
Discuss with Superkalam
How does real-time transaction freezing by the Incident Response Unit overcome the structural delays of conventional FIR registration?
Ask NowComparative Breakdown: Project AASHVAST vs National Cyber Crime Ecosystem (I4C)
The Indian Cyber Crime Coordination Centre (I4C) operates as a federal nodal agency under the Ministry of Home Affairs to coordinate national anti-cybercrime initiatives. While I4C provides the overarching federal framework through the National Cyber Crime Reporting Portal (NCRP), Project AASHVAST exemplifies a sub-national operational delivery model.
| Feature / Dimension | Project Cyber AASHVAST (Gujarat Model) | Indian Cyber Crime Coordination Centre (I4C) |
|---|---|---|
| Constitutional Basis | Seventh Schedule, List II, Entry 2 (State Police powers) | Seventh Schedule, List I / Executive mandate via Ministry of Home Affairs |
| Primary Scope | State-level rapid intervention, citizen kiosks, and direct counseling | National policy coordination, inter-state operational synergy, and threat intelligence |
| Financial Fraud Mechanism | Dedicated state-level Incident Response Unit (IRU) | Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS / Helpline 1930) |
| Citizen Touchpoints | Physical Cyber Suraksha Labs, district Netram hubs, and localized portals | Centralized National Cyber Crime Reporting Portal (NCRP) |
| Physical Grid Synergy | Direct integration with VISWAS (over 7,000 CCTVs) and NETRANG | Coordinated data sharing with central intelligence agencies and state police nodes |
Discuss with Superkalam
How can a state police force apply the Trinetra command model to track suspects across both digital and physical domains?
Ask NowThe Efficacy Debate: Proactive Deterrence vs Mass Surveillance Risks
Technological policing introduces a structural tension between proactive crime prevention and civil liberties. Proponents argue that the velocity of digital transactions makes post-facto investigation obsolete, requiring law enforcement to deploy automated fraud interception, continuous digital footprint monitoring, and unified command centers to protect public savings.
Critics contend that combining digital financial tracking with extensive public CCTV networks creates an architecture of persistent state surveillance. When algorithmic tools operate without independent civilian oversight, law enforcement risks engaging in bulk metadata aggregation, predictive policing biases, and unwarranted intrusions into individual associations.
Discuss with Superkalam
How do the exemptions under Sections 17 and 36 of the DPDP Act, 2023 challenge the necessity standard of the Puttaswamy proportionality test?
Ask NowThe Data Privacy Challenge: DPDP Act 2023 and the Puttaswamy Doctrine
The Supreme Court of India in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) established that the right to privacy is a fundamental right protected under Article 21 of the Constitution. The nine-judge bench ruled that any state intrusion into personal privacy must pass the fourfold proportionality test:
- Legality: The action must possess a clear statutory backing.
- Legitimate State Aim: It must pursue a valid public purpose, such as national security or crime prevention.
- Suitability: The means adopted must be rationally connected to achieving the intended purpose.
- Necessity: The measure must be the least intrusive option available, avoiding excessive encroachment.
The Digital Personal Data Protection (DPDP) Act, 2023 introduces broad statutory exemptions for law enforcement that test this constitutional threshold. Section 17(1)(c) of the DPDP Act, 2023 exempts personal data processing from core obligations where processing is deemed necessary for the prevention, detection, investigation, or prosecution of any offence.
Furthermore, Section 17(2)(a) empowers the Central Government to exempt notified State instrumentalities entirely from the Act in the interests of sovereignty, integrity, state security, or public order, while Section 36 authorizes the executive to call for data directly from fiduciaries. Without statutory requirements for prior judicial warrants, proactive techno-policing architectures risk overstepping the strict necessity standard established in Puttaswamy.
Institutional Bottlenecks in Scaling State Cyber Models Pan-India
Replicating advanced integrated cyber models across all Indian states faces severe operational bottlenecks. Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, electronic records are admissible as primary evidence subject to stringent certification and verified chain of custody. Inexperienced first responders often compromise digital evidence integrity at the scene of seizure, leading to acquittals during judicial trial.
State Forensic Science Laboratories (SFSLs) face persistent case backlogs due to acute shortages of certified digital forensic examiners, licensed extraction suites, and specialized hardware decrypters. Furthermore, cross-jurisdictional investigations encounter structural friction when pursuing overseas cyber syndicates, as obtaining data from foreign-hosted cloud infrastructure requires protracted processing of Letters Rogatory and Mutual Legal Assistance Treaties (MLAT).
Discuss with Superkalam
Weigh the trade-offs between proactive techno-policing deterrence and the risks of mass algorithmic surveillance in a constitutional democracy.
Ask NowWay Forward: Balancing Smart Tech-Policing with Civil Liberty Safeguards
Establishing an effective cyber security framework requires balancing operational agility with constitutional safeguards. State police modernization initiatives must move beyond ad-hoc executive notifications and anchor digital surveillance mechanisms within explicit statutory charters that define clear thresholds for data access and storage limits.
Independent judicial oversight should be instituted for automated data interception and facial recognition integration, ensuring that police access to centralized video grids satisfies the Puttaswamy necessity test. Simultaneously, the Union Government must accelerate capacity-building grants under the Modernisation of Police Forces (MPF) scheme to equip district units with accredited digital forensic extraction tools, institutionalizing standardized evidence collection under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023.
Key Takeaways
- Project Cyber AASHVAST was launched on 11 January 2020 in Gandhinagar, Gujarat, establishing India's first dedicated state-level cybercrime prevention and victim assistance unit.
- The project's four operational arms comprise the Incident Response Unit (IRU), Cyber Anti-Bullying Unit, Cyber Suraksha Lab, and Cyber Crime Prevention Unit.
- AASHVAST integrates with Gujarat's physical security grid via Project VISWAS (centralizing over 7,000 CCTVs) and Project NETRANG's district command rooms feeding into the Trinetra hub.
- As of June 2026, the national Helpline 1930 and CFCFRMS under the Indian Cyber Crime Coordination Centre (I4C) have saved over Rs 11,158 crore across 32.80 lakh complaints nationwide.
- Digital policing must align with the Supreme Court's fourfold proportionality test (Puttaswamy, 2017) to prevent exemptions under Section 17 of the DPDP Act, 2023 from turning into mass surveillance.
- Operationalization across states requires clearing forensic backlogs at State Forensic Science Laboratories and mastering electronic evidence procedures under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023.
Mains Question
"Techno-policing models that converge digital financial fraud interception with physical CCTV surveillance grids create structural friction with constitutional privacy standards." In light of Project Cyber AASHVAST and the Digital Personal Data Protection (DPDP) Act, 2023, critically examine this statement. (15 Marks)
Evaluate NowMains Question
Evaluate the role of state-level initiatives like Project Cyber AASHVAST in strengthening India's federal cybercrime architecture alongside the Indian Cyber Crime Coordination Centre (I4C). (10 Marks)
Evaluate NowPractice MCQs
QUESTION 1
With reference to Project Cyber AASHVAST and the policing architecture in India, consider the following statements:
- Project Cyber AASHVAST was conceptualized to address the structural lag between online crime commission and conventional FIR registration.
- Under the Seventh Schedule of the Constitution of India, 'Police' is listed under Entry 2 of List II (State List).
- The project is an initiative launched directly by the Indian Cyber Crime Coordination Centre (I4C) under the Union Ministry of Home Affairs. Which of the statements given above are correct?
QUESTION 2
Consider the following pairs regarding the four operational arms of Project Cyber AASHVAST:
- Incident Response Unit (IRU) — Real-time freezing of fraudulent financial transactions across banking channels
- Cyber Anti-Bullying Unit — Psychological counseling and protection against online harassment
- Cyber Suraksha Lab — Public kiosks for auditing personal electronic devices for malware and spyware Which of the pairs given above is/are correctly matched?
QUESTION 3
Regarding the integration of Gujarat's surveillance and cyber frameworks, consider the following statements:
- Project VISWAS centralizes video streams from over 7,000 CCTV cameras across 34 district headquarters.
- Project NETRANG establishes district-level Command and Control Rooms termed 'Netram'.
- District surveillance streams are integrated at the state level through the 'Trinetra' command hub. Which of the statements given above are correct?
QUESTION 4
With reference to the Supreme Court's ruling in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), which of the following is NOT one of the components of the fourfold proportionality test for state intrusion into personal privacy?
QUESTION 5
Consider the following statements regarding the statutory provisions under the Digital Personal Data Protection (DPDP) Act, 2023 discussed in the context of law enforcement:
- Section 17(1)(c) exempts personal data processing necessary for the prevention, detection, investigation, or prosecution of any offence.
- Section 17(2)(a) empowers the Central Government to exempt notified State instrumentalities in the interests of sovereignty, state security, or public order.
- Section 36 prohibits the executive from calling for data directly from data fiduciaries without a prior judicial warrant. Which of the statements given above is/are correct?



