Information Technology Act, 2000 and Amendments
Introduction
India’s cyber law framework gives legal recognition to electronic transactions, sets rules for digital governance, and prescribes penalties for online offences. It also covers privacy, cyber security, incident response, and protection of personal data through a combination of the Information Technology Act and later amendments.
Information Technology Act, 2000
The Information Technology Act, 2000 is the principal law for cyber regulation in India. It was enacted to provide legal recognition to electronic commerce, electronic communication, digital records and online dealings with government authorities.
- Electronic records: Gives legal validity to electronic documents and digital filings.
- Electronic governance: Supports online filing, issue and retention of documents in electronic form.
- Digital signatures: Recognizes digital signatures based on asymmetric cryptosystems for authentication of electronic records.
- Controller of Certifying Authorities: Empowers the Controller to license and regulate certifying authorities that issue digital certificates.
- Model law basis: The Act was based on the Model Law on Electronic Commerce adopted by the United Nations Commission on International Trade Law.
Major Cyber Offences and Penalties
The Act prescribes penalties for unauthorized access, hacking, identity theft, privacy violations and publication of obscene electronic material.
| Section | Offence | Penalty |
| Section 43 | Unauthorized access, data downloading and introduction of malware | Compensation up to one crore rupees to the affected party |
| Section 66 | Hacking and intentional destruction of data | Imprisonment up to three years or fine up to five lakh rupees |
| Section 66C | Identity theft using passwords, signatures or unique identifiers | Imprisonment up to three years and fine up to one lakh rupees |
| Section 66E | Violation of privacy by capturing or transmitting images of private areas | Imprisonment up to three years or fine up to two lakh rupees |
| Section 67 | Publishing or transmitting obscene material in electronic form | Imprisonment up to five years and fine up to ten lakh rupees |
Information Technology Amendment Act, 2008
The Information Technology Amendment Act, 2008 strengthened cyber enforcement and widened the scope of the original law.
- Section 66F: Introduced punishment for cyber terrorism, including imprisonment up to life.
- Electronic signatures: Replaced the narrower emphasis on digital signatures with broader electronic signature methodologies.
- Section 43A: Made corporate entities liable for failing to implement reasonable security practices for sensitive personal data.
- Section 72A: Penalized disclosure of personal information obtained under a lawful contract without the consent of the user.
Critical Infrastructure and Cyber Incident Response
The Act also provides for protection of important digital systems and coordination in cyber emergencies.
- Section 70: Empowers the central government to declare computer resources vital to national security as Critical Information Infrastructure.
- NCIIPC: The National Critical Information Infrastructure Protection Centre protects strategic networks such as power, transport and finance.
- Section 70B: Designates Indian Computer Emergency Response Team (CERT-In) as the national nodal agency for cyber incident response and threat analysis.
- CERT-In directions: Mandate reporting of cyber incidents within six hours of notice.
- Cyber Swachhta Kendra: Works as a national botnet cleaning and malware analysis centre for individual and organisational users.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 creates a separate legal regime for processing and protecting digital personal data in India.
- Data Principal: The individual to whom the personal data relates.
- Data Fiduciary: Any entity that determines the purpose and means of processing personal data.
- Data Processor: An intermediary that processes personal data on behalf of a data fiduciary.
- Consent Manager: A registered single point of contact that helps users manage and withdraw consent.
- Rights of individuals: Includes access to information, correction or erasure of data, and grievance redressal.
- Obligations of fiduciaries: Require technical safeguards, clear privacy notices and breach reporting to authorities.
- Children’s data: Prohibits tracking or behavioural monitoring of children and requires verifiable parental consent for processing minor data.
- Data Protection Board of India: Adjudicates non-compliance and can levy financial penalties up to two hundred fifty crore rupees for security breaches.
Important Judicial and Exam Facts
Section 66A of the IT Act was struck down by the Supreme Court in the Shreya Singhal case (2015) for violating freedom of speech.
The right to privacy was declared a fundamental right under Article 21 in the Puttaswamy judgment (2017).
- Constitutional relevance: Privacy protection under Article 21 is a major basis for modern data protection law.
- UN basis: The IT Act draws support from international electronic commerce principles.
Key Prelims Takeaways
- Primary cyber law: The Information Technology Act, 2000 is the main statute for cyber regulation in India.
- Digital recognition: It gives legal validity to electronic records, online filings and digital signatures.
- Section 43: Deals with unauthorized access and related computer misuse, with compensation up to one crore rupees.
- Section 66F: Introduced by the 2008 amendment to deal with cyber terrorism.
- Section 43A: Makes companies liable for failure to protect sensitive personal data.
- CERT-In: The national nodal agency for cyber incident response under Section 70B.
- DPDP Act, 2023: Introduces Data Principal, Data Fiduciary, Data Processor and Consent Manager.