My data was leaked after a laptop or phone repair in India. What should I do?
Act in this order. Do not confront the shop or delete anything yet: keep the device as it is, and take screenshots of every message, post or link that shows your data, with dates. Keep the job sheet, the bill and any chat with the shop. Report it on the National Cyber Crime Reporting Portal, cybercrime.gov.in, or call the 1930 helpline; the portal has a separate section for crimes against women and children, including sexually explicit content, and you can ask platforms to take material down. Change your passwords from a different device and tell your bank if financial details were exposed. Then consider a police complaint and legal advice.
Why the order matters
The instinct is to call the shop and demand answers. It is usually the worst first move: it warns whoever did it to delete copies and clean up, and it gives you nothing you can use later. Evidence is strongest when it is collected before anyone knows you are looking.
Cases like this are not rare. In 2025 a phone repair worker in Kolkata was accused of leaking a customer's private videos, and a similar case surfaced in Thiruvananthapuram. In the University of Guelph's controlled study, technicians copied customer data to external devices in two of 16 repair visits.
Which laws may apply
Under the Information Technology Act, 2000, copying data from a computer without the owner's permission can lead to compensation under Section 43 and, when done dishonestly, to prosecution under Section 66. Capturing or publishing images of a person's private areas is an offence under Section 66E, and disclosing personal information obtained while providing a service, without consent, can fall under Section 72A. Voyeurism is also an offence under Section 77 of the Bharatiya Nyaya Sanhita, 2023.
Which of these applies depends on the facts, and the police or a lawyer will decide. This page is general information, not legal advice.
What makes a complaint stronger
Dates and times. When the device was handed over and returned, from the job sheet and bill. When the data first appeared, from screenshots. Anything that ties the two together, such as a record from the device itself showing files opened or copied during the service window, turns a suspicion into something an investigator can act on.
The first 48 hours
- 01
Keep the device as it is
Do not reset it, clean it or reinstall anything. Whatever is on it now may be evidence.
- 02
Capture what you can see
Screenshots of posts, messages and links, with the date and the URL visible. Save copies somewhere the other side cannot reach.
- 03
Gather the paperwork
Job sheet, bill, warranty card, chats and call logs with the shop, and the names of anyone you dealt with.
- 04
Report it
cybercrime.gov.in, or call 1930. Ask the platforms where the material appeared to remove it; most have a dedicated form for private images.
- 05
Secure your accounts
Change passwords from a different device, sign out of all sessions, and alert your bank if financial details were on the device.
Rashnova cannot help with a repair that has already happened: it only records while it is running. It is worth knowing about for next time. It is a free Windows app; with Repair Mode on during a repair, its sealed report shows which files were opened, what was copied to USB drives and when, which is exactly the kind of record a complaint needs.
