The Punjab and Haryana High Court in Amrik Singh Juneja v State of Punjab and another (CRM-M No. 23026 of 2012) quashed criminal proceedings instituted under Sections 43 and 66 of the Information Technology Act, 2000, establishing that penal amendments introduced by Act 10 of 2009 cannot be applied retrospectively to acts committed prior to 27 October 2009. Justice Sabina held that an act committed in February 2008, which attracted only civil compensation under Section 43 at the time of its occurrence, cannot be converted into a punishable offence under amended Section 66 without violating the constitutional prohibition against ex post facto criminal liability under Article 20(1) of the Constitution of India.
Procedural History and Factual Matrix
The petitioner, Amrik Singh Juneja, approached the High Court under Section 482 of the Code of Criminal Procedure, 1973 seeking the quashing of First Information Report No. 130 registered on 10 June 2010 at Police Station Civil Lines, Patiala, District Patiala. The FIR alleged offences under Sections 43 and 66 of the Information Technology Act, 2000. In addition, the petition challenged the order dated 10 July 2012 passed by the Judicial Magistrate First Class, Patiala, which had dismissed the petitioner application for dropping the criminal proceedings after the filing of the police challan.
The dispute arose out of a letter allegedly drafted and issued by the petitioner on 29 February 2008. The complainant, respondent No. 2, who was the son-in-law of the petitioner, lodged a police complaint on 14 March 2008 alleging unauthorized electronic access and misuse of information. The underlying dispute was rooted in ongoing matrimonial litigation between respondent No. 2 and the daughter of the petitioner.
Following the initial complaint, the matter was investigated by senior police authorities. The Superintendent of Police conducted a detailed inquiry and concluded that the allegations levelled by respondent No. 2 were unsubstantiated. The Senior Superintendent of Police subsequently endorsed that inquiry report and forwarded it to the Inspector General of Police with a formal recommendation that no criminal offence was made out against the petitioner. Despite these findings, the formal FIR was registered on 10 June 2010 and a challan was presented before the trial court, leading the petitioner to seek quashing cyber crime FIR Section 482 CrPC protection.
Legislative Evolution of Sections 43 and 66 of the IT Act
To determine whether criminal liability could attach to the petitioner conduct, the High Court analyzed the statutory structure of the Information Technology Act, 2000 prior to and following the Information Technology (Amendment) Act, 2008 (Act 10 of 2009), which came into force on 27 October 2009.
The Original Statutory Scheme (Prior to 27 October 2009)
Under the unamended Information Technology Act, 2000, the statute maintained a sharp divide between civil contraventions and criminal offences:
- Section 43 (Civil Liability): Titled Penalty and compensation for damage to computer, computer system, etc., this section provided civil redress. If any person without permission of the owner or person in charge accessed, downloaded, copied, introduced contaminants, damaged, or disrupted a computer system, they were liable to pay damages by way of compensation to the affected person. The remedy was adjudicated through the Adjudicating Officer appointed under Section 46 of the Act.
- Original Section 66 (Hacking): Titled Hacking with computer system, the original section was narrowly circumscribed. It made hacking punishable with imprisonment up to three years or fine up to two lakh rupees only if a person caused wrongful loss or damage to the public or any person by destroying, deleting, or altering information in a computer resource or diminishing its utility.
The 2008 Amendment (Effective 27 October 2009)
Act 10 of 2009 fundamentally overhauled Chapter XI of the Act. The legislature substituted Section 66 with a broad provision titled computer related offences under IT Act 2000. The amended Section 66 provided that if any person, dishonestly or fraudulently, does any act referred to in Section 43, they shall be punishable with imprisonment for a term which may extend to three years or with fine up to five lakh rupees, or with both.
The amendment effectively criminalized conduct covered under Section 43 that had previously attracted only civil compensation, provided the requisite mental elements (dishonestly under Section 24 IPC or fraudulently under Section 25 IPC) were present.
Complete Statutory Provisions Analyzed by the Court
Justice Sabina examined the full statutory text of Section 43 and amended Section 66 to evaluate the legislative boundaries. Section 43 of the Act stipulates:
"43. Penalty and compensation for damage to computer, computer system, etc. If any person without permission of the owner or any other person who is incharge of a computer, computer system or computer network,
- (a) accesses or secures access to such computer, computer system or computer network or computer resource;
- (b) downloads, copies or extracts any data, computer data base or information from such computer, computer system or computer network including information or data held or stored in any removable storage medium;
- (c) introduces or causes to be introduced any computer contaminant or computer virus into any computer, computer system or computer network;
- (d) damages or causes to be damaged any computer, computer system or computer network, data, computer data base or any other programmes residing in such computer, computer system or computer network;
- (e) disrupts or causes disruption of any computer, computer system or computer network;
- (f) denies or causes the denial of access to any person authorised to access any computer, computer system or computer network by any means;
- (g) provides any assistance to any person to facilitate access to a computer, computer system or computer network in contravention of the provisions of this Act, rules or regulations made thereunder;
- (h) charges the services availed of by a person to the account of another person by tampering with or manipulating any computer, computer system, or computer network;
- (i) destroys, deletes or alters any information residing in a computer resource or diminishes its value or utility or affects it injuriously by any means;
- (j) steals, conceals, destroys or alters or causes any person to steal, conceal, destroy or alter any computer source code used for a computer resource with an intention to cause damage;
he shall be liable to pay damages by way of compensation to the person so affected."
The amended Section 66 reads:
"66. Computer related offences. If any person, dishonestly or fraudulently, does any act referred to in section 43, he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both.
Explanation. For the purposes of this section, (a) the word 'dishonestly' shall have the meaning assigned to it in Section 24 of the Indian Penal Code; (b) the word 'fraudulently' shall have the meaning assigned to it in Section 25 of the Indian Penal Code."
Constitutional Bar on Retrospective Criminal Law (Article 20(1))
The core legal determination turned upon whether penal liability under amended Section 66 could attach to an event that occurred on 29 February 2008. The High Court affirmed that penal statutes operate prospectively unless the legislature explicitly provides otherwise within constitutional bounds.
Under Article 20(1) of the Constitution of India, no person can be convicted of any offence except for violation of a law in force at the time of the commission of the act charged, nor can they be subjected to a penalty greater than that which might have been inflicted under the law in force at the time of the commission of the offence. This principle prohibits ex post facto criminal liability cyber law applications.
Because the alleged communication was issued in February 2008 and the police complaint was filed in March 2008, the conduct was governed exclusively by the unamended 2000 Act. Under that statutory framework, an act falling within Section 43 Information Technology Act entitled an aggrieved party to pursue civil damages before the Adjudicating Officer, but did not constitute an offence punishable under Section 66. To apply the 2009 penal amendment to a 2008 event would constitute an unlawful retrospective criminalization of past conduct.
Judicial Findings and Quashing of Proceedings
Justice Sabina delivered a clear finding that at the time when the petitioner allegedly issued the letter in question, no criminal offence under Section 66 or Section 66-A had been committed. The complainant remedy, if any, lay solely in claiming compensation under Section 43.
The High Court held that prosecuting the petitioner under amended penal provisions that took effect over eighteen months after the alleged act was an abuse of the process of law. Consequently, the High Court allowed the petition, quashed FIR No. 130 dated 10 June 2010 registered at Police Station Civil Lines, Patiala, and set aside the trial court order dated 10 July 2012 refusing discharge.
Significance for Cyber Law and Technology Compliance
The ruling in Amrik Singh Juneja v State of Punjab establishes key precedents for cyber law enforcement and corporate IT management:
- Temporal Application of Penal Provisions: Enforcement agencies cannot invoke post-2009 penal sanctions under Section 66 for electronic actions that transpired prior to the effective date of Act 10 of 2009. This underscores the rule against Section 66 IT Act retrospective application.
- Distinction Between Civil and Criminal Redress: Section 43 remains primarily a civil compensation mechanism; criminal prosecution requires proving specific mental elements under Section 66 alongside an established contravention of Section 43.
- Importance of Compliance Verification: Organizations auditing digital systems and electronic communications benefit from establishing structured protocols through regular cyber law compliance audit and statutory guidelines to differentiate regulatory breaches from criminal misconduct.
- Protection of Intellectual and Computer Assets: Clear internal policies governing computer resource access and software licensing regulations ensure that employee access disputes are addressed through proper civil and administrative mechanisms rather than unwarranted criminal complaints.
