Breach of confidentiality and privacy - Sec.72 - Information Technology Act

July 20, 2017

Section 72 of the Information Technology Act, 2000 imposes criminal penalties for the breach of confidentiality and privacy by persons who disclose electronic records without the consent of the affected party. This statutory protection applies strictly to individuals who secure access to electronic records, books, registers, correspondence, or documents in pursuant of powers conferred under the IT Act or its rules. A conviction under Section 72 carries imprisonment for a term of up to two years, a fine extending to one lakh rupees, or both.

Statutory Construct of Section 72 Information Technology Act

The legislative foundation of the Section 72 Information Technology Act provision is rooted in safeguarding sensitive information handled during statutory processes. When regulatory officials, system auditors, digital investigators, or administrative officers exercise powers under the Act, they frequently gain access to proprietary correspondence, confidential business records, and private personal communications. Section 72 acts as a statutory check against abuse of power, ensuring that official access is not converted into unauthorized public dissemination.

The provision begins with the non-obstante clause "Save as otherwise provided in this Act or any other law for the time being in force," creating a clear boundary where lawful disclosures required by court orders or statutory duties remain protected, while unauthorized disclosures are strictly penalized.

Essential Elements of Breach of Confidentiality and Privacy under IT Act

Establishing criminal liability for breach of confidentiality and privacy under IT Act requires fulfilling specific statutory conditions:

  • Conferment of Statutory Power: The accused person must have secured access to the electronic material in pursuant of powers conferred under the Information Technology Act, rules, or regulations.
  • Nature of Electronic Material: The accessed data must constitute an electronic record, book, register, correspondence, information, document, or related digital material.
  • Absence of Consent: The disclosure must occur without the express or implied consent of the person concerned.
  • Unauthorized Disclosure: The accused must have disclosed such electronic material to any other third party without lawful statutory authority.

Access Conferred Pursuant to Statutory Powers

A critical nuance of Section 72 is its limited application to persons acting pursuant to statutory powers. Unlike general corporate privacy breaches, Section 72 specifically targets authorized officers, adjudicating officers, cyber controllers, network inspectors, and technical custodians who obtain access during official audits, investigations, or regulatory filings. A private employee who steals company files without statutory authority is generally prosecuted under Section 43 or Section 66, whereas an officer abusing statutory access falls under Section 72.

The Prohibition of Unauthorized Disclosure of Electronic Records

The prohibition against unauthorized disclosure of electronic records prevents leaking sensitive data obtained during official inquiries. Examples of prohibited disclosures include:

  • A technical auditor disclosing proprietary source code discovered during an official intermediary compliance audit.
  • An investigating officer leaking private emails or WhatsApp correspondence obtained during forensic seizure to media outlets.
  • A regulatory official disclosing confidential financial records submitted as part of a Certifying Authority licensing application.
  • A network administrator sharing subscriber traffic metadata obtained during a lawful government monitoring process with private commercial entities.

Difference Between Section 72 and Section 72A

Legal practitioners and corporate entities frequently examine the difference between Section 72 and Section 72A to determine appropriate legal remedies:

  • Section 72: Applies strictly to individuals who secure access pursuant to statutory powers under the IT Act. It carries up to two years imprisonment and fines up to one lakh rupees, without requiring proof of wrongful loss or intent to cause injury.
  • Section 72A: Applies broadly to any person (including IT service providers, telecom companies, call centers, and intermediaries) who discloses personal information in breach of a lawful contract, with intent to cause wrongful loss or wrongful gain. It carries higher penalties of up to three years imprisonment and fines up to five lakh rupees.

Penalties for Privacy Breach in India and Interaction with the DPDP Act

The structured penalties for privacy breach in India under Section 72 comprise imprisonment of either description for a term extending up to two years, a fine extending up to one lakh rupees, or both. The offence is non-cognizable and bailable, requiring a formal complaint or magistrate direction to initiate criminal proceedings.

In the evolving regulatory environment, Section 72 operates alongside the Digital Personal Data Protection (DPDP) Act, 2023. While the DPDP Act focuses on civil monetary penalties administered by the Data Protection Board for data fiduciary non-compliance, Section 72 retains criminal sanctions for statutory officials and custodians who betray confidentiality obligations. Official policies established by the Ministry of Electronics and Information Technology emphasize strict accountability across all public digital services.

Statutory Defenses and Procedural Protections

Individuals facing prosecution under Section 72 may raise valid statutory defenses. Legitimate defenses include demonstrating that the disclosure was made in good faith pursuant to a court order, under statutory reporting requirements, or with the prior written consent of the affected individual. In situations involving contested allegations, understanding how to file pre-arrest bail before High Court and leveraging precedents such as Pramod Jain Vs. Securities and Exchange Board of India help safeguard individual procedural rights during investigative inquiries.

Corporate Governance and Information Security Protocols

Public agencies and private entities handling regulatory electronic records must implement institutional safeguards to prevent unauthorized data leaks:

  • Enforce role-based access controls (RBAC) ensuring that statutory data is accessible only to authorized personnel on a need-to-know basis.
  • Maintain immutable digital audit logs tracking every view, download, export, and transfer of confidential electronic records.
  • Implement data loss prevention (DLP) solutions and cryptographic controls on systems storing regulatory submissions.
  • Conduct periodic confidentiality training for officers, auditors, and technical staff handling sensitive citizen data.

Section 72 remains a critical safeguard for digital privacy and official accountability in India. By imposing strict criminal penalties for unauthorized disclosures made by persons exercising statutory powers, the Information Technology Act ensures that citizen trust and business confidentiality are preserved across digital governance systems.

Found this helpful?

Share this page with others