INFORMATION TECHNOLOGY ACT, 2000
(With special reference to Information Technology Amendment Act, 2008)
Introduction
With the rise of:
computers
internet
e-commerce
online banking
email communication
electronic governance
traditional laws became insufficient to regulate online transactions and cyber crimes.
India therefore enacted the Information Technology Act, 2000, which came into force on 17
October 2000.
It was based on the UNCITRAL Model Law on Electronic Commerce, 1996.
Purpose of the Act:
Legal recognition to electronic records
Legal recognition to digital signatures
Facilitate e-commerce
Promote e-governance
Prevent cyber crimes
Regulate digital communication
Objectives of IT Act, 2000
1. To provide legal recognition to electronic records
2. To recognize digital signatures
3. To facilitate electronic commerce
4. To encourage e-governance
5. To prevent cyber crimes
6. To provide legal framework for electronic contracts
7. To protect digital data and computer systems
Scope of the Act
The Act extends to:
✔ Whole of India
✔ Also applies outside India if a computer resource located in India is affected.
Important Section: Section 75 – Extra Territorial Jurisdiction
If a hacker sitting in another country hacks an Indian bank server → Indian law can still
apply.
Example:
A hacker in Russia hacks SBI servers in India → he may be prosecuted under Indian law.
Salient Features of Information Technology Act, 2000 (Detailed Explanation)
The Information Technology Act, 2000 was India’s first comprehensive cyber law enacted to
regulate electronic transactions, provide legal recognition to digital communication, and deal
with cyber offences.
It came into force on 17 October 2000 and was based on the UNCITRAL Model Law on
Electronic Commerce, 1996.
The following are the major salient features of the original IT Act, 2000:
1. Legal Recognition of Electronic Records
Section 4
Before this Act, legal documents were generally required to be in:
written form
printed form
paper format
This created problems for online transactions because emails, online forms, and electronic
documents had no legal recognition.
Section 4 solved this issue by stating that where any law requires information to be in writing
or printed form, such requirement shall be fulfilled if the information is available in
electronic form and remains accessible for future reference.
Importance:
This provision became the foundation of paperless transactions in India.
Example:
If a company sends invoices through email instead of physical paper bills, those invoices are
legally valid.
Another example:
University admission forms submitted online are legally recognized.
2. Legal Recognition of Digital Signatures
Sections 3 and 5
In physical transactions, handwritten signatures prove authenticity.
Similarly, online transactions require a mechanism to verify:
identity of sender
authenticity of documents
prevention of fraud
The Act legally recognized digital signatures.
Digital signatures operate through:
asymmetric cryptography
public key infrastructure
hash functions
They ensure:
authentication
integrity
non-repudiation
Importance:
This made secure online transactions possible.
Example:
Filing income tax returns using digital signature certificates.
3. Facilitation of Electronic Governance (E-Governance)
Sections 6, 7, and 8
This feature enabled government departments to shift from manual paperwork to electronic
governance.
Government authorities can now:
receive applications electronically
issue licenses electronically
maintain digital records
accept online filing
Importance:
It promoted efficiency and transparency in administration.
Example:
Online passport application portal
Online filing of GST returns
DigiLocker services
4. Legal Recognition of Electronic Contracts
Section 10A
Traditional contract law required offer and acceptance through physical communication.
With rise of e-commerce, contracts began taking place through:
emails
websites
online platforms
Section 10A provides that a contract cannot be declared invalid merely because it was formed
electronically.
Importance:
It gave legal validity to online business transactions.
Example:
When you book a ticket on IRCTC, a valid electronic contract is created.
When you click "I Agree" on Amazon terms and conditions, it becomes enforceable.
5. Establishment of Controller of Certifying Authorities (CCA)
The Act created the office of Controller of Certifying Authorities.
Its functions include:
regulating certifying authorities
granting licenses
supervising digital signature framework
Importance:
Ensures reliability of digital signatures.
Example:
Entities issuing digital signature certificates require government approval.
6. Regulation of Certifying Authorities
The Act introduced licensed Certifying Authorities that issue Digital Signature Certificates
(DSCs).
These authorities verify identity before issuing certificates.
Importance:
Prevents fraud in digital signatures.
Example:
A company director obtains DSC for MCA filings.
7. Retention of Electronic Records
Section 7
Businesses and government departments often need to preserve records.
This provision allows records to be stored electronically instead of physically.
Conditions:
records should remain accessible
records should retain original format details
Importance:
Reduces paperwork and storage costs.
Example:
Banks storing customer statements digitally.
8. Rules Regarding Attribution and Acknowledgment of Electronic Records
Sections 11–13
These sections determine:
when an electronic message is considered sent
when it is considered received
who sent it
These rules help resolve disputes.
Example:
An online purchase confirmation email proves that order was accepted.
9. Penalties for Unauthorized Access and Damage
Section 43
This section imposes civil liability for:
unauthorized access
downloading data
introducing viruses
disrupting systems
damaging networks
Importance:
Protects computer systems from misuse.
Example:
An employee copies confidential company files without permission.
Compensation can be awarded.
10. Punishment for Tampering with Computer Source Documents
Section 65
This provision punishes persons who intentionally:
destroy
alter
conceal computer source code
Importance:
Protects software integrity.
Example:
An employee deletes source code of a company software project.
Punishment:
up to 3 years imprisonment
OR
fine up to ₹2 lakh
11. Punishment for Hacking
Section 66
Hacking involves unauthorized access done dishonestly or fraudulently.
This section criminalizes hacking activities.
Example:
Breaking into another person's social media account.
Punishment:
up to 3 years imprisonment
OR
fine up to ₹5 lakh
12. Punishment for Publishing Obscene Material Online
Section 67
This provision criminalizes publishing or transmitting obscene material electronically.
Importance:
Protects morality and public decency.
Example:
Uploading obscene videos online.
13. Adjudication Mechanism
Section 46
The Act provides appointment of Adjudicating Officers.
They hear disputes involving compensation claims.
They possess powers similar to civil courts.
Importance:
Provides speedy resolution of cyber disputes.
Example:
A victim claiming compensation for hacked business data.
14. Cyber Regulations Appellate Tribunal
The Act established the Cyber Appellate Tribunal to hear appeals against decisions of
adjudicating officers.
Importance:
Provides appellate remedy.
Example:
If a party is dissatisfied with compensation awarded, they may appeal.
(Now appeals lie before TDSAT.)
15. Extra-Territorial Jurisdiction
Section 75
Cyber crimes often cross borders.
This section provides that the Act applies even to offences committed outside India if the
affected computer system is located in India.
Importance:
Addresses international cyber crimes.
Example:
A hacker sitting in another country attacks Indian banking servers.
Indian authorities may still take action.
Conclusion
The original IT Act, 2000 mainly focused on:
legal recognition of electronic transactions
promotion of e-commerce
digital governance
digital authentication
basic cyber crime regulation
It laid the foundation of India’s cyber law system, which was later expanded through the
2008 Amendment to address modern cyber threats like identity theft, cyber terrorism, and
privacy violations.
Now let’s cover the salient features of the Information Technology (Amendment) Act,
2008 in the same detailed, explanatory, exam-friendly format.
Information Technology (Amendment) Act, 2008 – Detailed Salient Features
Introduction
The original Information Technology Act, 2000 mainly focused on:
e-commerce
digital signatures
e-governance
basic cyber offences
However, after 2000, technology evolved rapidly and new cyber threats emerged such as:
phishing
identity theft
online banking fraud
cyber terrorism
privacy violations
child pornography
data breaches
misuse of social media platforms
The original law was insufficient to deal with these new challenges.
Therefore, Parliament passed the Information Technology (Amendment) Act, 2008, which
came into force in 2009.
The amendment significantly expanded India’s cyber law framework.
1. Introduction of Electronic Signature
Section 3A
Under the original Act, only digital signatures were legally recognized.
This became outdated because technology developed new authentication methods.
The amendment introduced the broader concept of electronic signatures.
This includes:
biometric authentication
OTP verification
electronic authentication tools
other reliable technologies
Why needed?
To ensure technological flexibility.
Example:
Aadhaar-based e-sign system.
2. Expansion of Definitions under Section 2
The amendment added and expanded several important definitions such as:
communication device
intermediary
cyber café
electronic signature
computer resource
Why important?
Technology had expanded beyond computers to:
mobile phones
tablets
digital devices
Example:
Cyber offences committed through mobile phones now clearly fall under the Act.
3. Section 66A – Offensive Messages Through Communication Services
(Now struck down)
This section punished sending messages that were:
offensive
annoying
inconvenient
menacing
through electronic communication.
Problem:
The terms were vague and misused by authorities.
People were arrested for harmless social media posts.
Landmark Case:
Shreya Singhal v. Union of India (2015)
Supreme Court declared Section 66A unconstitutional for violating freedom of speech under
Article 19(1)(a).
Example:
People were arrested for critical Facebook posts.
4. Section 66B – Receiving Stolen Computer Resource
This section punishes dishonestly receiving:
stolen computer devices
stolen computer resources
stolen communication devices
Example:
Buying a stolen laptop knowing it contains stolen corporate information.
5. Section 66C – Identity Theft
One of the most important additions.
This section punishes fraudulent use of:
passwords
digital signatures
biometric data
personal identification details
Example:
Using another person's debit card password.
Using someone’s Aadhaar details for fraud.
Importance:
Addresses modern digital fraud.
6. Section 66D – Cheating by Personation Using Computer Resources
This punishes online cheating by impersonating another person.
Example:
Creating fake bank websites to steal OTPs.
Fake job portals collecting money.
Phishing scams.
This section directly addresses online frauds.
7. Section 66E – Violation of Privacy
This section punishes capturing, publishing, or transmitting images of a person’s private parts
without consent.
Example:
Sharing private images online without permission.
Secretly recording someone in private spaces.
Importance:
Protects digital privacy and dignity.
8. Section 66F – Cyber Terrorism
One of the most serious additions.
This section covers acts intended to:
threaten sovereignty of India
create panic among people
attack national security systems
damage critical infrastructure
access restricted government information
Example:
Hacking defense systems.
Attacking power grids.
Punishment:
Imprisonment for life
This reflects seriousness of cyber terrorism.
9. Section 67A – Sexually Explicit Material
This section specifically punishes publishing sexually explicit content online.
This is more serious than ordinary obscenity under Section 67.
Example:
Uploading pornographic videos.
10. Section 67B – Child Pornography
This section punishes:
child sexual abuse content
browsing child pornography
distributing such material
Example:
Sharing exploitative child content online.
Importance:
Protects children from online exploitation.
11. Section 43A – Compensation for Failure to Protect Data
A major step toward data protection law.
If a company handling sensitive personal data fails to maintain reasonable security and causes
loss:
→ compensation may be awarded.
Example:
A company leaks customer credit card details due to poor security systems.
12. Section 72A – Punishment for Disclosure of Information
This section punishes disclosure of personal information obtained through lawful contract
without consent.
Example:
A telecom company sells user data to advertisers.
13. Section 69 – Government Power to Intercept, Monitor, Decrypt
Government may intercept or monitor online communications for:
national security
sovereignty
public order
prevention of crime
Example:
Monitoring suspected terrorist communication.
14. Section 69A – Power to Block Websites
Government may block public access to online content.
Example:
Blocking apps/websites threatening national security.
Landmark Case:
Shreya Singhal v. Union of India
Supreme Court upheld Section 69A because procedural safeguards existed.
15. Section 69B – Monitoring Traffic Data
Government can monitor internet traffic data for cyber security purposes.
Example:
Tracking suspicious malware attacks.
16. Protection of Critical Information Infrastructure
Section 70A
The amendment introduced institutional protection for critical systems such as:
banking systems
electricity grids
defense networks
telecom systems
Example:
Protection of RBI payment infrastructure.
17. Establishment of CERT-In
Section 70B
The amendment formally recognized:
Indian Computer Emergency Response Team (CERT-In)
Functions:
respond to cyber incidents
issue alerts
coordinate cyber security responses
vulnerability reporting
Example:
CERT-In issuing ransomware warnings.
18. Intermediary Liability Reform
Section 79
This section was significantly modified.
Intermediaries such as:
Facebook
YouTube
Instagram
ISPs
e-commerce websites
receive safe harbour protection if:
they act as intermediaries only
follow due diligence
do not knowingly assist illegal acts
Example:
If a user uploads illegal content, platform may avoid liability if proper action is taken.
19. Examiner of Electronic Evidence
Section 79A
Government may appoint experts to verify electronic evidence.
Importance:
Helps courts determine authenticity of digital evidence.
Example:
Verification of hacked email records.
20. Strengthening National Cyber Security Framework
The amendment strengthened institutional cyber security by:
protecting critical infrastructure
creating response agencies
enabling monitoring mechanisms
This reflected growing concerns about cyber warfare.
Why the 2008 Amendment Was Important
It transformed Indian cyber law from a law focused mainly on e-commerce into a law
dealing with:
cyber crime
privacy
terrorism
online fraud
child protection
data security
intermediary regulation
Criticism of the Amendment
1. Section 66A misuse
Used to suppress online speech.
2. Surveillance concerns
Sections 69 and 69B may threaten privacy.
3. Weak data protection framework
Section 43A was limited.
4. Overbroad censorship concerns
Section 69A criticized by some.
Conclusion
The Information Technology (Amendment) Act, 2008 modernized India’s cyber law
framework by addressing emerging digital crimes and national security threats.
It introduced provisions relating to:
identity theft
phishing
privacy
cyber terrorism
child pornography
intermediary liability
data protection
Thus, it made the original IT Act far more relevant to the realities of the digital age.
Here’s a systematic chart/memory table to quickly revise both the IT Act, 2000 and the IT
Amendment Act, 2008.
This format is very useful before exams because you can revise all sections in 2–3 minutes.
CHART 1: Information Technology Act, 2000 (Original Act)
Important
[Link] Salient Feature What it Deals With Example
Section
Legal recognition of Gives legal validity to
1 Sec. 4 Email invoice
electronic records electronic documents
Legal recognition of Validates digital Digital filing of
2 Secs. 3 & 5
digital signatures signatures ITR
Online interaction with Online passport
3 E-Governance Secs. 6, 7, 8
government application
Validity of online
4 Electronic contracts Sec. 10A Amazon purchase
contracts
Controller of Certifying Regulates digital signature
5 Secs. 17–20 DSC regulation
Authorities system
Issue Digital Signature
6 Certifying Authorities Secs. 21–34 MCA filings
Certificates
Important
[Link] Salient Feature What it Deals With Example
Section
Retention of electronic Storage of records Digital bank
7 Sec. 7
records electronically statements
Attribution &
Determines Order confirmation
8 acknowledgment of e- Secs. 11–13
sender/receiver/time email
records
Unauthorized
9 access/damage Sec. 43 Civil liability for damage Data theft
compensation
Tampering with source Punishes source code Deleting company
10 Sec. 65
code destruction code
Hacking/computer Hacking Facebook
11 Sec. 66 Criminal hacking offences
offences account
Publishing obscene Uploading obscene
12 Obscene content online Sec. 67
material video
Cyber
Decide compensation
13 Adjudicating officers Sec. 46 compensation
disputes
claims
Appeal against
14 Cyber Appellate Tribunal Secs. 48–64 Appeals mechanism
adjudication
Extra-territorial Foreign hacker
15 Sec. 75 Applies outside India too
jurisdiction attacks Indian bank
Memory Trick for IT Act, 2000
"Recognition → Governance → Regulation → Cyber Crimes → Remedies →
Jurisdiction"
Recognition
Sec 4
Sec 3/5
Sec 10A
Governance
Sec 6–8
Sec 7
Sec 11–13
Regulation
Sec 17–34
Cyber Crimes
Sec 43
Sec 65
Sec 66
Sec 67
Remedies
Sec 46
Sec 48–64
Jurisdiction
Sec 75
CHART 2: Information Technology (Amendment) Act, 2008
[Link] Salient Feature Section What it Deals With Example
Broader authentication
1 Electronic signatures Sec. 3A Aadhaar e-sign
methods
Sec. 2 Added cyber Mobile device
2 Expanded definitions
amendments café/intermediary etc. crimes
Offensive messages Facebook post
3 Sec. 66A Offensive communication
(struck down) arrest
Receiving stolen Receiving stolen Buying stolen
4 Sec. 66B
computer resource devices/data laptop
5 Identity theft Sec. 66C Password misuse Using stolen OTP
[Link] Salient Feature Section What it Deals With Example
Cheating by Fake banking
6 Sec. 66D Phishing/fake identity
personation website
7 Violation of privacy Sec. 66E Sharing private images Revenge porn
Attacks on Hacking defense
8 Cyber terrorism Sec. 66F
sovereignty/security servers
Sexually explicit Uploading explicit
9 Sec. 67A Online pornography
content videos
Sharing child
10 Child pornography Sec. 67B Child sexual content
abuse material
Failure to protect sensitive
11 Data protection Sec. 43A Company data leak
data
Disclosure of personal Unauthorized sharing of
12 Sec. 72A Selling user data
information data
Monitoring/decryption Terror
13 Interception powers Sec. 69
powers investigation
14 Website blocking Sec. 69A Blocking online content App ban
15 Traffic monitoring Sec. 69B Cyber security monitoring Malware tracking
Critical infrastructure Power grid
16 Sec. 70A Protects essential systems
protection protection
National cyber response
17 CERT-In Sec. 70B Ransomware alert
agency
Social media
18 Intermediary liability Sec. 79 Safe harbour protection
liability
Electronic evidence Authentication of e-
19 Sec. 79A Email verification
examiner evidence
Stronger cyber Combined National cyber
20 Cyber defense
security framework effect preparedness
Memory Trick for 2008 Amendment
"Identity → Privacy → Security → Regulation"
Identity Crimes
66A
66B
66C
66D
Privacy Crimes
66E
67A
67B
72A
43A
National Security
66F
69
69A
69B
70A
70B
Platform Regulation
79
79A
Super Quick Revision Formula
IT Act 2000 =
Recognition + E-commerce + Basic Cyber Crime
IT Amendment 2008 =
Identity Theft + Privacy + Cyber Terrorism + Data Protection + Intermediary
Regulation
This chart is usually enough to revise the entire topic one night before exams.