IT Act, 2000: Key Provisions

IT Act, 2000: Key Provisions

The Information Technology Act, 2000 is India’s main law for electronic records, digital signatures, cyber offences and online transactions. It gives legal backing to e-governance, supports secure digital commerce and defines penalties for a range of computer-related crimes.

Core purpose and legal recognition

  • Electronic records: The Act gives legal recognition to electronic documents and records for use in law and administration.
  • Digital filings: It permits electronic submission of documents to government agencies, supporting e-governance.
  • Electronic contracts: Contracts formed through electronic means are recognised under the Act.
  • Digital communication: It provides statutory backing to electronic communication in commercial and administrative systems.

Digital signatures and certifying authorities

  • Digital signatures: The Act recognises digital signatures based on asymmetric cryptosystems for authentication of electronic documents.
  • Controller of Certifying Authorities: This authority regulates the issuance of digital signature certificates.
  • Licensing of certifying authorities: Certifying authorities function under strict licensing rules to verify the identity of digital key holders.
  • Trust framework: The system is designed to ensure trust and validity in electronic communication across financial and administrative networks.

Key cyber offences and penalties

Section Offence Penalty
Section 43 Unauthorized access, data downloading and malware introduction Compensation up to one crore rupees for affected parties
Section 66 Hacking, data destruction and computer-related fraud Imprisonment up to three years or fine up to five lakh rupees
Section 66C Identity theft using electronic signatures, passwords or unique identifiers Imprisonment up to three years and fine up to one lakh rupees
Section 66E Violation of privacy by capturing and transmitting images of private areas Imprisonment up to three years or fine up to two lakh rupees
Section 67 Publishing or transmitting obscene material in electronic form Imprisonment up to five years and fine up to ten lakh rupees
  • Section 43: Covers unauthorised access, data theft, downloading and malware-related damage, with compensation liability.
  • Section 66: Deals with hacking and computer-related fraud.
  • Section 66C: Covers identity theft involving passwords, e-signatures and unique identifiers.
  • Section 66E: Protects privacy against unlawful capture and transmission of private images.
  • Section 67: Punishes obscene publication or transmission in electronic form.

Data protection and intermediary liability

  • Section 72: Penalises persons who gain access to electronic records, books or correspondence and disclose them without consent.
  • Section 72A: Holds service providers and intermediaries liable if they disclose personal information obtained under a lawful contract with intent to cause injury.
  • Section 79: Provides safe harbour protection to intermediaries for third-party information, subject to due diligence requirements.
  • Practical significance: These provisions are important for privacy, platform responsibility and online service regulation.

Critical information infrastructure and cyber response

  • Section 70: Empowers the central government to declare any computer resource critical to national security or public infrastructure as Critical Information Infrastructure.
  • Section 70A: Establishes the National Critical Information Infrastructure Protection Centre to safeguard strategic networks from cyber threats.
  • Section 70B: Designates the Indian Computer Emergency Response Team as the national nodal agency for cyber incident response, threat analysis and advisories.
  • Cyber security role: These provisions are meant to protect vital digital systems and coordinate response to cyber emergencies.

Major amendment and evolution

  • Information Technology Amendment Act, 2008: Strengthened the law to address emerging cyber risks and digital crimes.
  • Section 66F: Introduced provisions on cyber terrorism, with punishment up to life imprisonment.
  • Electronic signatures: Replaced the narrower reference to digital signatures to widen cryptographic authentication methods.
  • Newer offences: The amendment strengthened provisions relating to child pornography, cyber stalking and data privacy breaches.
  • Enforcement: It also supported specialised cyber crime cells and investigative units.

Key prelims takeaways

  • Enactment: The IT Act, 2000 is India’s principal law for cybercrime, e-commerce and digital transactions.
  • International basis: It was enacted based on the model law on electronic commerce adopted by the United Nations Commission on International Trade Law.
  • Safe harbour: Section 79 gives intermediaries protection from liability for third-party content, subject to due diligence.
  • Privacy provisions: Sections 72 and 72A deal with wrongful disclosure of electronic records and personal information.
  • Critical infrastructure: Sections 70, 70A and 70B relate to critical information infrastructure and cyber response.
  • Supreme Court ruling: Section 66A was struck down in the Shreya Singhal case for violating freedom of speech and expression.
  • Cyber agencies: Indian Computer Emergency Response Team functions under the Ministry of Electronics and Information Technology, while Cyber Swachhta Kendra works as a botnet cleaning and malware analysis centre.

Exam fact: Section 66A was struck down by the Supreme Court in Shreya Singhal.

Originally written on June 11, 2026 and last modified on September 6, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *