Information Technology Act, 2000

March 6, 2017

The Information Technology Act 2000 defines cyber offences, establishes civil compensation mechanisms for unauthorized data access, prescribes criminal penalties for digital fraud, and sets out the statutory intermediary liability framework in India.

Civil Penalties and Corporate Data Protection Under Section 43

Chapter IX of the Information Technology Act creates a specialized civil liability regime designed to remedy financial harm caused by unauthorized computer interference. Under Section 43, any person who accesses, downloads, copies, extracts, introduces computer contaminants, damages data, or denies access to authorized users without permission is liable to pay damages by way of compensation to the affected party.

Unlike ordinary tort claims that require lengthy civil litigation, Section 43 claims are adjudicated through dedicated administrative forums. The section covers a wide range of unauthorized electronic acts, including disrupting computer networks, stealing computer source code, and deleting sensitive operational databases.

Following the 2008 statutory amendments, Section 43A was introduced to impose strict corporate data privacy obligations. Under Section 43A, body corporates possessing, dealing, or handling sensitive personal data or information (SPDI) in a computer resource that are negligent in implementing reasonable security practices, resulting in wrongful loss or wrongful gain, are liable to pay compensation to affected individuals without any upper statutory cap.

Cyber Offences and Criminal Sanctions Under Chapter XI

Chapter XI establishes dedicated criminal provisions punishing intentional digital misconduct. Unlike general criminal law under the Indian Penal Code, these provisions directly target computer-enabled offences and digital fraud:

  • Hacking and Computer Data Tampering (Section 66): Concealing, destroying, or altering computer source code intentionally, as well as committing computer-related offences dishonestly or fraudulently, is punishable with imprisonment up to three years or fine up to five lakh rupees.
  • Identity Theft and Digital Impersonation (Sections 66C and 66D): Fraudulently using electronic signatures, passwords, or biometric features of others, as well as cheating by personation using computer resources, carries imprisonment up to three years and fines.
  • Violation of Bodily Privacy and Voyeurism (Section 66E): Intentionally capturing, transmitting, or publishing images of private areas of an individual without consent constitutes a serious criminal offence.
  • Cyber Terrorism (Section 66F): Acts threatening the unity, integrity, security, or sovereignty of India through computer networks or denying authorized access to critical infrastructure carry penalties extending to life imprisonment.
  • Source Code Alteration (Section 65): Knowingly concealing, destroying, or altering computer source code required by law to be maintained attracts imprisonment up to three years.
  • Tampering with Electronic Documents (Section 73): Publishing fake digital signature certificates or making fraudulent representations to certifying authorities is punishable with criminal sanctions.
  • Breach of Confidentiality and Privacy (Section 72): Disclosing secured electronic records, books, or correspondence without the consent of the concerned person is punishable with imprisonment.

Constitutional review has continuously shaped these provisions, as demonstrated by the landmark invalidation of vague speech restrictions analyzed in constitutional limits in Section 66A of IT Law. Meanwhile, fraudulent digital certifications face specific penalties discussed in penal consequences in Publication for fraudulent purpose - Sec.74.

Intermediary Liability and Safe Harbour Protections (Section 79)

Section 79 establishes a statutory safe harbour protecting online intermediaries, including internet service providers, telecom operators, web hosts, social media platforms, and cloud service providers, from third-party liability. An intermediary is not liable for third-party information, data, or communication links hosted by it, provided specific statutory criteria are satisfied.

To maintain safe harbour protection, the intermediary must satisfy four fundamental conditions:

  • Passive Function: The function of the intermediary must be limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored.
  • No Active Involvement: The intermediary must not initiate the transmission, select the receiver of the transmission, or select or modify the information contained in the transmission.
  • Observance of Due Diligence: The intermediary must observe statutory due diligence requirements, publish privacy policies, and maintain user terms of service.
  • Expeditious Takedown: Upon receiving actual knowledge through a court order or government notification that unlawful content is hosted, the intermediary must expeditiously remove or disable access to the material.

Adjudication Mechanism and Appellate Remedies

To adjudicate civil contraventions under Chapter IX, state IT secretaries are appointed as Adjudicating Officers under Section 46. These officers hold powers equivalent to civil courts, conducting summary inquiries to determine damages and award compensation to victims of unauthorized access or data theft.

Appeals against orders of Adjudicating Officers lie before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which exercises cyber appellate jurisdiction under Chapter X. TDSAT hears appeals regarding jurisdictional errors, compensation awards, and regulatory directives issued under the Act.

Proceedings before Adjudicating Officers follow principles of natural justice and summary inquiry procedures, enabling fast monetary compensation without the complex technicalities of plenary civil trials.

Strategic Compliance for Corporate Entities

Understanding this enforcement apparatus is critical for internet enterprises, security professionals, and corporate legal teams. By combining specialized civil adjudication with criminal deterrence, the Information Technology Act maintains operational security and legal remedies across India's digital ecosystem.

Enterprises handling consumer data must establish internal data protection policies, appoint grievance officers as mandated by intermediary rules, and maintain cyber incident response protocols to avoid liability under Section 43A and Section 79.

Routine compliance audits and rigorous access control logging safeguard digital enterprises against regulatory penalties and criminal prosecution under Chapter XI.

Found this helpful?

Share this page with others