[] Tampering with computer source Documents – Sec.65 (IT Act)

July 3, 2017

Section 65 Information Technology Act establishes criminal liability for knowingly or intentionally concealing, destroying, or altering any computer source code used for a computer, computer programme, computer system, or computer network when such code is required by law to be kept or maintained. Designed to protect the intellectual property, operational integrity, and technological architecture of software systems in India, this provision penalizes unauthorized tampering with computer source documents with imprisonment of up to three years, a fine of up to two lakh rupees, or both.

Statutory Definition and Legal Scope of Section 65

The text of Section 65 forms a cornerstone of Indian cyber jurisprudence concerning intellectual property and source code security. The statute explicitly penalizes intentional acts aimed at compromising vital software instructions.

Under the statutory explanation, the computer source code legal definition encompasses the complete listing of programmes, computer commands, design and layout, and programme analysis of a computer resource in any form. This expansive definition covers human-readable source code, compiled machine instructions, architectural software documentation, database schemas, and configuration scripts essential for system execution.

A critical statutory requirement under Section 65 is that the source code in question must be one that is required to be kept or maintained by law for the time being in force. This includes source codes preserved under statutory accounting mandates, regulatory compliance rules for banking or telecommunications, intellectual property escrow agreements, or corporate governance statutes.

Essential Ingredients for Prosecuting Section 65 Offences

To establish an offence under Section 65 before a criminal court, the prosecution must satisfy several essential ingredients beyond reasonable doubt:

  1. Deliberate Mens Rea: The accused must have acted knowingly or intentionally. Accidental system errors, unintended compilation glitches, or bona fide debugging activities lacking malicious intent fall outside the scope of criminal liability.
  2. Act of Tampering: The accused must have concealed, destroyed, or altered the computer source code, or intentionally caused another individual to execute such alterations.
  3. Target Classification: The material subject to interference must qualify as computer source code under the statutory definition.
  4. Legal Requirement of Retention: The affected source code must be subject to an existing legal or regulatory obligation requiring its retention and maintenance.

When these ingredients are present, actions involving unauthorized repository modifications, deliberate code obfuscation, or deletion of legal audit scripts trigger cyber crime source document concealment charges.

Distinction Between Source Tampering and General Computer Offences

The Information Technology Act maintains clear distinctions between specialized source code tampering under Section 65 and general hacking offences under Section 66. While Section 66 addresses unauthorized system access, data deletion, or service disruptions causing wrongful loss, Section 65 specifically penalizes the intentional manipulation of underlying programmatic architecture and formal records required by law.

In commercial and employment settings, disputes frequently arise when departing software developers alter access permissions, delete proprietary source repositories, or modify underlying application routines. Such actions intersect with contract law and corporate asset security, reflecting broader issues in corporate governance and service contracts examined in commercial litigation such as Bakshi Security And Personnel Services Pvt. Ltd. Vs. Devkishan Computed Pvt. Ltd. [Supreme Court of India, 26-07-2016].

Similarly, unauthorized modification of intellectual property in collaborative technical environments can lead to civil actions for damages under Section 43 alongside criminal complaints under Section 65.

Judicial Interpretations and Key Precedents

Indian courts have interpreted Section 65 to protect technological assets across diverse electronic platforms. In the landmark decision of Syed Asifuddin and Others v. State of Andhra Pradesh, the court examined whether reprogramming mobile handset Electronic Serial Numbers (ESNs) constituted tampering with computer source code. The High Court held that mobile phones constitute computers under the IT Act and that altering embedded firmware instructions fell squarely within the penal scope of Section 65.

Judicial precedent also underscores the importance of proper jurisdictional and procedural compliance when initiating prosecutions under cyber statutes, as reflected in cases addressing criminal procedure and statutory oversight like Vineet Mittal v State of Uttar Pradesh. IT Act Section 65 judicial precedents affirm that forensic code comparison, version control records, and expert witness testimony are necessary to substantiate claims of unauthorized alteration in judicial proceedings.

Courts have clarified that where source code is maintained pursuant to license conditions, regulatory compliance rules, or contractual escrow obligations enforced by statute, unauthorized deletion constitutes a cognizable offence requiring technical forensic verification.

Penalties and Corporate Compliance Measures

The statutory punishment for altering source code under Section 65 involves imprisonment of either description for a term extending up to three years, a fine extending up to two lakh rupees, or both. Under Section 77B of the IT Act, offences punishable with imprisonment of up to three years are categorized as bailable and cognizable, permitting police investigation upon registration of a formal First Information Report (FIR).

Enterprises and technology organizations should institute preventive governance measures to protect source code assets:

  • Version Control Logging: Enforcing cryptographic commit signing and immutable version control audit logs across all production software repositories.
  • Granular Access Controls: Restricting administrative code modification rights based on the principle of least privilege, preventing unilateral alteration or deletion.
  • Automated Backup Redundancy: Maintaining offsite, write-once-read-many (WORM) storage for critical source code required under statutory or regulatory frameworks.
  • Employment Covenants: Implementing clear intellectual property assignment agreements and technological handover protocols for engineering personnel.
  • Forensic Readiness Plans: Establishing digital forensic preservation protocols to isolate modified codebases and maintain hash verification trails during dispute resolution.

These compliance measures protect software developers and corporate entities against internal sabotage while ensuring complete alignment with statutory requirements under Indian cyber law.

Found this helpful?

Share this page with others