IT Act, 2000: Key Provisions
The Information Technology Act, 2000 is India’s main law for electronic records, digital signatures, cyber offences and online transactions. It gives legal backing to e-governance, supports secure digital commerce and defines penalties for a range of computer-related crimes.
Core purpose and legal recognition
- Electronic records: The Act gives legal recognition to electronic documents and records for use in law and administration.
- Digital filings: It permits electronic submission of documents to government agencies, supporting e-governance.
- Electronic contracts: Contracts formed through electronic means are recognised under the Act.
- Digital communication: It provides statutory backing to electronic communication in commercial and administrative systems.
Digital signatures and certifying authorities
- Digital signatures: The Act recognises digital signatures based on asymmetric cryptosystems for authentication of electronic documents.
- Controller of Certifying Authorities: This authority regulates the issuance of digital signature certificates.
- Licensing of certifying authorities: Certifying authorities function under strict licensing rules to verify the identity of digital key holders.
- Trust framework: The system is designed to ensure trust and validity in electronic communication across financial and administrative networks.
Key cyber offences and penalties
| Section | Offence | Penalty |
| Section 43 | Unauthorized access, data downloading and malware introduction | Compensation up to one crore rupees for affected parties |
| Section 66 | Hacking, data destruction and computer-related fraud | Imprisonment up to three years or fine up to five lakh rupees |
| Section 66C | Identity theft using electronic signatures, passwords or unique identifiers | Imprisonment up to three years and fine up to one lakh rupees |
| Section 66E | Violation of privacy by capturing and transmitting images of private areas | Imprisonment up to three years or fine up to two lakh rupees |
| Section 67 | Publishing or transmitting obscene material in electronic form | Imprisonment up to five years and fine up to ten lakh rupees |
- Section 43: Covers unauthorised access, data theft, downloading and malware-related damage, with compensation liability.
- Section 66: Deals with hacking and computer-related fraud.
- Section 66C: Covers identity theft involving passwords, e-signatures and unique identifiers.
- Section 66E: Protects privacy against unlawful capture and transmission of private images.
- Section 67: Punishes obscene publication or transmission in electronic form.
Data protection and intermediary liability
- Section 72: Penalises persons who gain access to electronic records, books or correspondence and disclose them without consent.
- Section 72A: Holds service providers and intermediaries liable if they disclose personal information obtained under a lawful contract with intent to cause injury.
- Section 79: Provides safe harbour protection to intermediaries for third-party information, subject to due diligence requirements.
- Practical significance: These provisions are important for privacy, platform responsibility and online service regulation.
Critical information infrastructure and cyber response
- Section 70: Empowers the central government to declare any computer resource critical to national security or public infrastructure as Critical Information Infrastructure.
- Section 70A: Establishes the National Critical Information Infrastructure Protection Centre to safeguard strategic networks from cyber threats.
- Section 70B: Designates the Indian Computer Emergency Response Team as the national nodal agency for cyber incident response, threat analysis and advisories.
- Cyber security role: These provisions are meant to protect vital digital systems and coordinate response to cyber emergencies.
Major amendment and evolution
- Information Technology Amendment Act, 2008: Strengthened the law to address emerging cyber risks and digital crimes.
- Section 66F: Introduced provisions on cyber terrorism, with punishment up to life imprisonment.
- Electronic signatures: Replaced the narrower reference to digital signatures to widen cryptographic authentication methods.
- Newer offences: The amendment strengthened provisions relating to child pornography, cyber stalking and data privacy breaches.
- Enforcement: It also supported specialised cyber crime cells and investigative units.
Key prelims takeaways
- Enactment: The IT Act, 2000 is India’s principal law for cybercrime, e-commerce and digital transactions.
- International basis: It was enacted based on the model law on electronic commerce adopted by the United Nations Commission on International Trade Law.
- Safe harbour: Section 79 gives intermediaries protection from liability for third-party content, subject to due diligence.
- Privacy provisions: Sections 72 and 72A deal with wrongful disclosure of electronic records and personal information.
- Critical infrastructure: Sections 70, 70A and 70B relate to critical information infrastructure and cyber response.
- Supreme Court ruling: Section 66A was struck down in the Shreya Singhal case for violating freedom of speech and expression.
- Cyber agencies: Indian Computer Emergency Response Team functions under the Ministry of Electronics and Information Technology, while Cyber Swachhta Kendra works as a botnet cleaning and malware analysis centre.
Exam fact: Section 66A was struck down by the Supreme Court in Shreya Singhal.
Originally written on
June 11, 2026
and last modified on
September 6, 2026.