Information Technology Act, 2000
The Information Technology Act, 2000 serves as the primary legislation in India dealing with cybercrime and electronic commerce. The statute aims to provide legal recognition for transactions carried out by means of electronic data interchange and other means of electronic communication. This legislation facilitates electronic filing of documents with government agencies and addresses security practices for digital records.
Objectives and Scope
The legislation regulates digital signatures, establishes cyber offenses, and sets penalties for violations. The law extends across the entire territory of India and applies to any offense or contravention committed outside India by any person regardless of their nationality, if the act involves a computer system located in India.
Key Provisions of the Original Act
The enactment laid down the foundation for electronic governance and legal validity of digital records.
- Electronic Records: Grants legal recognition to electronic records and digital signatures.
- Certifying Authorities: Establishes the Controller of Certifying Authorities to regulate the issuance of digital signature certificates.
- Cyber Appellate Tribunal: Creates an appellate framework to resolve disputes arising from directions of the Controller or adjudicating officers.
- Cyber Offenses: Defines penalties for hacking, data theft, tampering with computer source code, and unauthorized access to computer systems.
The 2008 Amendment Act
Parliament enacted major amendments in 2008 to address emerging forms of cybercrimes and technological advancements. The modification shifted focus towards data protection, intermediary liability, and national security.
- Section 66A: Criminalized the sending of offensive messages through communication services. The Supreme Court later struck down this section in the landmark Shreya Singhal v. Union of India case for violating freedom of speech.
- Section 66E: Penalized the violation of privacy by capturing, publishing, or transmitting images of a private area of any person without consent.
- Section 67: Prescribed punishment for publishing or transmitting obscene material in electronic form.
- Section 43A: Introduced provisions for compensation to be paid by bodies corporate for failure to protect sensitive personal data or information due to negligence.
Intermediary Guidelines and Digital Rules
The legal framework empowers the central government to issue guidelines for intermediaries such as internet service providers, social media platforms, and search engines.
- Due Diligence: Intermediaries must publish privacy policies and terms of use for users.
- Grievance Redressal: Platforms must appoint a grievance officer in India to address complaints within specified timelines.
- Law Enforcement Cooperation: Intermediaries are required to assist government agencies in cyber security incidents and lawful interception of communications.
Key Sections at a Glance
| Section | Subject Matter | Penalty Provisions |
| Section 43 | Damage to computer systems and data | Compensation up to one crore rupees |
| Section 66 | Computer related offenses (hacking) | Imprisonment up to three years or fine up to five lakh rupees |
| Section 67 | Publishing obscene material in electronic form | Imprisonment up to five years and fine up to ten lakh rupees |
| Section 72 | Breach of confidentiality and privacy | Imprisonment up to two years or fine up to one lakh rupees |
Challenges and Subsequent Developments
The rapid evolution of artificial intelligence, cryptocurrency transactions, and cloud computing created new regulatory demands. The legislation faces criticism regarding state surveillance powers, data localization norms, and the balance between online safety and freedom of expression. To address modern data protection needs, Parliament enacted the Digital Personal Data Protection Act, 2023, which operates alongside the core provisions of the information technology framework.
Important Facts
The Information Technology Act received the assent of the President on June 9, 2000. The statute came into force on October 17, 2000. India enacted this law in pursuance of the model law on electronic commerce adopted by the United Nations Commission on International Trade Law. The Department of Electronics and Information Technology administers the implementation of the act alongside the Indian Computer Emergency Response Team, which handles cyber security incidents at the national level.