Offences by Companies - Sec.85 - Information Technology Act

May 27, 2024

Section 85 of the Information Technology Act 2000 establishes corporate liability for cyber contraventions, holding both the company entity and key individuals in charge of business conduct personally accountable. Directors, managers, and officers avoid liability only by proving that the violation occurred without their knowledge or despite exercising all due diligence.

Vicarious Liability Structure Under Section 85 of the IT Act

Section 85 of the IT Act 2000 outlines the statutory mechanism for prosecuting corporate entities and their key personnel when cyber offences occur. Under Section 85(1), when a company violates provisions of the IT Act or rules made thereunder, every person who was in charge of and responsible to the company for conducting its business at the time of contravention is deemed guilty along with the corporate entity itself.

Section 85(2) expands personal liability further. If an offence by a company is proved to have taken place with the consent, connivance, or neglect of any director, manager, secretary, or other corporate officer, such individual is held personally guilty and subject to prosecution and punishment. The legal explanation clarifies that company includes body corporate, partnership firms, and associations of individuals.

The Statutory Proviso and Due Diligence Defence Mechanisms

The proviso to Section 85(1) provides a vital legal protection for corporate management. An officer in charge will not face personal criminal punishment if they demonstrate two essential statutory defences: first, that the contravention occurred without their knowledge, or second, that they exercised all due diligence to prevent the commission of such contravention.

Establishing due diligence requires corporate management to implement proactive cybersecurity policies, maintain technical access controls, perform periodic vulnerability assessments, and enforce employee compliance standards. Documented administrative diligence serves as primary evidence to rebut legal presumption of negligence during judicial proceedings.

Judicial Interpretation and Procedural Safeguards in Corporate Cyber Prosecutions

Indian courts interpret Section 85 strictly, requiring investigating authorities to establish a specific nexus between the alleged contravention and the officer sought to be held vicariously liable. Vicarious criminal liability cannot be automatically imputed to non-executive directors without explicit pleadings detailing their operational role in the commission of the offence.

Courts apply criminal procedure safeguards when evaluating corporate officer prosecutions, examining precedents such as judicial precedents on official sanction requirements and related Bombay High Court criminal procedure rulings to ensure proper legal procedure is followed before issuing summons against corporate executives.

Practical Compliance Recommendations for Corporate Officers

To mitigate risk under Section 85, corporate organizations should implement cybersecurity governance frameworks. Boards must approve explicit data security policies, designate qualified Chief Information Security Officers, maintain audit logs, and conduct regular compliance reviews.

By institutionalizing due diligence and immediate incident response protocols, corporate officers protect the enterprise while maintaining effective legal protection against vicarious liability.

Found this helpful?

Share this page with others