Preparing your learning space...
67% through Cyber Laws tutorials
Before India had cyber-specific laws, crimes committed using computers were prosecuted under traditional laws like the Indian Penal Code (IPC), 1860. However, these were inadequate for the digital age.
The Information Technology Act, 2000 (IT Act, 2000) was enacted by the Indian Parliament to provide a legal framework for electronic transactions, digital signatures, and cyber crimes.
It came into effect on October 17, 2000.
| Need | Explanation |
|---|---|
| Legal recognition of electronic records | Papers documents were the only legally valid format |
| Enable e-commerce and e-governance | Digital contracts and signatures needed legal validity |
| Penalise cyber crimes | Old laws couldn't handle computer-specific crimes |
| Comply with UN Model Law | UN's Model Law on Electronic Commerce (1996) |
| Regulate digital signatures | Authentication in a digital world |
| Establish cyber appellate tribunal | For dispute resolution |
The Act has 13 chapters and 90+ sections. Key highlights:
These are civil (not criminal) offences — punishable by compensation rather than imprisonment.
| Section | Offence | Penalty |
|---|---|---|
| 43 | Unauthorised access, downloading, or introducing viruses | Compensation up to ₹5 Crore |
| 43A | Failure to protect personal data leading to wrongful loss | Compensation up to ₹5 Crore (added by 2008 amendment) |
| 44 | Failure to furnish documents or return information | Penalty up to ₹1.5 Lakh |
| 45 | Residual penalty for offences not covered elsewhere | Up to ₹25,000 |
Section 43A is especially important — it was the first data protection provision in Indian law, holding companies liable for mishandling "sensitive personal data."
These are criminal offences — punishable by imprisonment + fine.
| Section | Offence | Punishment |
|---|---|---|
| 65 | Tampering with computer source documents | Imprisonment up to 3 years + fine up to ₹2 Lakh |
| 66 | Hacking with dishonest intent | Imprisonment up to 3 years + fine up to ₹5 Lakh |
| 66B | Receiving stolen computer resources | Imprisonment up to 3 years + fine up to ₹1 Lakh |
| 66C | Identity theft (using someone else's password/signature) | Imprisonment up to 3 years + fine up to ₹1 Lakh |
| 66D | Cheating by impersonation using a computer | Imprisonment up to 3 years + fine up to ₹1 Lakh |
| 66E | Publishing private images without consent | Imprisonment up to 3 years + fine up to ₹2 Lakh |
| 66F | Cyber terrorism | Imprisonment for life |
| 67 | Publishing obscene material electronically | Imprisonment up to 5 years + fine up to ₹10 Lakh (first conviction) |
| 67A | Publishing sexually explicit material | Imprisonment up to 7 years + fine up to ₹10 Lakh |
| 67B | Child pornography (publishing/browsing/collecting) | Imprisonment up to 7 years + fine up to ₹10 Lakh |
| 67C | Intermediary failing to preserve/retain information | Imprisonment up to 3 years + fine |
| 70 | Unauthorised access to protected systems | Imprisonment up to 10 years |
| 72 | Breach of confidentiality and privacy | Imprisonment up to 2 years + fine up to ₹1 Lakh |
The original 2000 Act was amended in 2008 with major changes taking effect on October 27, 2009.
| Change | Detail |
|---|---|
| Section 66A introduced | Punishment for sending offensive messages — later struck down by Supreme Court (2015) as unconstitutional |
| Section 69 introduced | Government's power to intercept, monitor, and decrypt any computer resource (in the interest of national security) |
| Section 69A | Government's power to block websites/public content |
| Section 69B | Government's power to monitor traffic data |
| Vishing & Phishing | Covered under cheating/impersonation |
| Cyber Terrorism | Defined and made punishable (Section 66F) |
| Intermediary Liability | Intermediaries (ISPs, social media) must act within 36 hours on government directions |
One of the most important provisions of the IT Act:
Section 79 — Intermediaries (ISPs, social media platforms, e-commerce sites) are not liable for third-party content posted on their platform IF they:
This is similar to Section 230 of the US Communications Decency Act — the legal foundation that protects platforms like YouTube, Facebook, and Twitter from being sued for user-generated content.
IT Rules, 2021 imposed additional due diligence:
The IT Act establishes a tiered dispute resolution system:
| Body | Role |
|---|---|
| Adjudicating Officer (AO) | Hears cases where compensation/penalty ≤ ₹5 Crore (appointed by MeitY) |
| Cyber Appellate Tribunal (CyAT) | Appeals against AO decisions; headed by a retired High Court judge |
| High Court | Appeals against CyAT decisions |
For criminal offences (Sections 65–74), cases go directly to the regular criminal courts under the CrPC / BNSS.
| IPC Section | Covers |
|---|---|
| 378–382 | Theft (includes digital theft) |
| 403–404 | Dishonest misappropriation of property |
| 415–420 | Cheating (includes online fraud) |
| 463–477A | Forgery (includes digital documents) |
| 499–502 | Defamation (includes cyber defamation) |
| 503–506 | Criminal intimidation (includes cyber stalking) |
| 507 | Anonymous criminal intimidation |
| 509 | Insulting modesty of a woman (includes online harassment) |
(Covered in detail in Tutorial 3)
CERT-In is the national nodal agency for:
It functions under the Ministry of Electronics & Information Technology (MeitY).
| Development | Detail |
|---|---|
| DPDP Act, 2023 | Digital Personal Data Protection Act — India's comprehensive data privacy law |
| IT Rules, 2021 | Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules — tighter social media regulation |
| SOP for intermediaries | Standard Operating Procedures for grievance redressal |
| VPN & Data Localisation | Increased emphasis on data storage within India |
Save your progress and earn XP for completing tutorials.
Keep learning
Technology
Cyber Security & Networking
Lesson group
Cyber Laws
Progress
67% complete