⚖️SECURITY ISSUES IN E-
COMMERCE: PRIVACY, DATA
PROTECTION AND AUTHENTICATION
IN INDIA
1. Introduction: E-Commerce and Legal Security
Concerns
Electronic commerce (e-commerce) has revolutionized business transactions by allowing
goods, services, and financial payments to be exchanged digitally across borders. However, it
also exposes consumers and businesses to serious security risks, such as data breaches,
identity theft, payment fraud, hacking, and privacy violations. The digital environment
lacks the physical safeguards of traditional transactions, making legal mechanisms essential
to ensure trust, accountability, and consumer protection.
In India, the Information Technology Act, 2000 (IT Act) serves as the primary legislation
governing electronic transactions, cybersecurity, and data protection. Supplementing this are
the Information Technology (Reasonable Security Practices and Procedures and
Sensitive Personal Data or Information) Rules, 2011, various RBI guidelines, and the
evolving framework under the Digital Personal Data Protection Act, 2023 (DPDPA).
Together, these address the triad of e-commerce security issues — privacy, data
protection, and authentication.
2. Privacy in E-Commerce Transactions
(a) Nature of the Privacy Concern
In e-commerce, privacy involves an individual’s control over personal data — such as
name, contact details, financial information, browsing behaviour, and purchase history —
that is collected, stored, or processed by online platforms. Businesses often use this data for
targeted advertising, analytics, or profiling, leading to potential misuse or unauthorized
disclosure.
(b) Constitutional Foundation
The right to privacy is a fundamental right under Article 21 of the Constitution,
recognized in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1.
The Supreme Court held that informational privacy is an intrinsic part of personal liberty, and
the State (and private actors) must ensure data is collected and processed only with informed
consent and for legitimate purposes.
This judgment laid the constitutional foundation for privacy regulation in digital commerce
and directly influenced the Digital Personal Data Protection Act, 2023.
(c) Statutory Provisions
Under Section 43A of the IT Act, any body corporate that handles personal data negligently
and causes wrongful loss or gain is liable to pay damages by way of compensation.
Further, the IT Rules, 2011, define sensitive personal data to include financial details,
passwords, health conditions, and biometric information. Companies must:
Obtain consent before collection,
Use data only for lawful, necessary purposes,
Provide a mechanism for review and withdrawal of consent,
Maintain reasonable security practices (ISO 27001 standard).
With the Digital Personal Data Protection Act, 2023 (DPDPA), India now has a
comprehensive legal framework imposing duties on “Data Fiduciaries” and rights on “Data
Principals” — including notice, correction, grievance redressal, and the right to erasure. The
Act applies to both government and private entities processing data digitally.
3. Data Protection in E-Commerce
(a) Importance and Risks
E-commerce platforms routinely collect and process vast volumes of personal and financial
data. Data protection ensures that such information is accurate, lawfully processed, stored
securely, and not misused. Data breaches — such as those suffered by Zomato, BigBasket,
or Juspay — expose millions of consumers to fraud and identity theft, revealing the urgent
need for robust data governance.
(b) Legal Framework under the IT Act and Rules
Section 72A of the IT Act criminalizes the disclosure of personal information by
service providers without consent, punishable with imprisonment up to three years
and fine up to ₹5 lakh.
The 2011 Rules require data controllers to implement “reasonable security
practices” and hold them accountable for any loss caused by negligence.
These provisions create a quasi-contractual obligation between e-commerce entities and
users — breach of which leads to civil liability under Section 43A and criminal liability
under Section 72A.
(c) The Digital Personal Data Protection Act, 2023
This new Act modernizes India’s data law to align with global standards like the EU’s
General Data Protection Regulation (GDPR).
Key features include:
1. Consent-Based Processing – No data processing without user consent.
2. Notice Requirement – Users must be informed about the purpose of collection.
3. Data Fiduciary Obligations – Entities must implement security safeguards and
report breaches.
4. Cross-Border Transfers – Permitted only to countries notified by the Central
Government.
5. Data Protection Board of India – Established for adjudication and enforcement.
Penalties for non-compliance can reach ₹250 crore, making this Act a strong deterrent
against data negligence in e-commerce.
(d) Comparative Insight
The European Union’s GDPR (2018) is considered the global benchmark, emphasizing:
Lawful, fair, and transparent processing;
Data minimization and purpose limitation;
Explicit consent and right to be forgotten.
India’s DPDPA borrows heavily from GDPR but with greater flexibility for state
processing and fewer cross-border restrictions.
In contrast, the United States follows a sectoral approach, with laws like the
Gramm-Leach-Bliley Act (financial data) and HIPAA (health data), leaving much
of e-commerce regulation to state law and self-regulation.
4. Authentication and Security in E-Commerce
(a) Meaning and Importance
Authentication is the process of verifying the identity of parties in an online transaction to
ensure that communication originates from a genuine source and remains unaltered.
Security refers to the broader technical and legal framework that safeguards confidentiality,
integrity, and availability of data.
In e-commerce, both concepts are vital for ensuring non-repudiation, preventing phishing,
spoofing, and hacking, and maintaining consumer confidence in digital payments.
(b) Legal Recognition of Electronic Authentication
The Information Technology Act, 2000 gives legal validity to electronic authentication
through digital signatures and electronic signatures.
Sections 3–3A: Recognize digital signatures and electronic signatures as legally
valid, provided they are based on asymmetric cryptosystems and hash functions.
Section 5: Grants equivalence between electronic authentication and handwritten
signatures.
Section 10A: Recognizes validity of e-contracts formed through electronic
communication, ensuring enforceability of online transactions.
Thus, authentication under the IT Act serves as the legal guarantee of trust in e-commerce
agreements.
(c) Certification and Trust Infrastructure
The Controller of Certifying Authorities (CCA), under Chapter VI of the IT Act, issues
licenses to Certifying Authorities (CAs) such as NIC, e-Mudhra, and IDRBT, who provide
Digital Signature Certificates (DSCs).
These certificates authenticate the identity of users, ensure message integrity, and prevent
repudiation of online transactions.
The Indian IT (Certifying Authority) Rules, 2000 prescribe procedures for key
management, encryption standards, and public key infrastructure (PKI).
This forms the legal trust backbone of India’s e-commerce ecosystem, used in GST filings,
MCA filings, and online banking transactions.
(d) Cybersecurity Provisions under IT Act
Section 43 & 66: Impose civil and criminal liability for unauthorized access, hacking,
or data theft.
Section 66C & 66D: Penalize identity theft and cheating by impersonation using
computer resources.
Section 70: Protects “critical information infrastructure” relating to banking and
payment systems.
Section 79: Provides “safe harbour” to intermediaries (like Amazon or Flipkart),
provided they observe due diligence and remove unlawful content upon notice.
These provisions ensure that authentication and security are not only technical but also
legal duties of e-commerce entities.
5. Payment Authentication and RBI Framework
Given the prevalence of online payments, the Reserve Bank of India (RBI) plays a critical
role in regulating e-commerce payment authentication:
RBI Master Directions on Digital Payment Security Controls (2021) mandate
multi-factor authentication for all digital transactions.
Card-on-File Tokenization (2022) protects consumer data by substituting card
details with encrypted tokens.
The Payment and Settlement Systems Act, 2007 gives RBI power to regulate
payment intermediaries like Paytm, Razorpay, and UPI platforms.
Collectively, these measures ensure that payment authentication complies with both IT law
and financial regulation, bridging the gap between cybersecurity and banking law.
6. Case Laws Illustrating E-Commerce Security Issues
1. Trimex International FZE v. Vedanta Aluminium Ltd., (2010) 3 SCC 1 –
Supreme Court recognized validity of e-contracts concluded via email
communication.
2. Avnish Bajaj v. State ([Link] case), 150 (2008) DLT 769 – Intermediary
liability under S.79 IT Act; reinforced duty of e-commerce platforms to ensure due
diligence.
3. Google India (P) Ltd. v. Visaka Industries Ltd., (2020) 4 SCC 162 – Clarified
intermediary liability and safe harbour applicability.
4. Shreya Singhal v. Union of India, (2015) 5 SCC 1 – Upheld online free speech but
imposed responsibility on intermediaries to act on valid legal notices.
5. K.S. Puttaswamy v. Union of India, (2017) – Recognized privacy and data
protection as fundamental rights, binding on both State and private actors.
These judgments collectively strengthen the legal foundations of e-commerce trust by
balancing innovation, freedom, and accountability.
7. Comparative Insights: Global Best Practices
Jurisdiction Framework Key Features
Strong consent-based data processing;
European
GDPR (2018), eIDAS Regulation electronic ID and signature recognition
Union
across EU.
Sectoral laws – FTC Act, Focus on consumer protection through
United States Gramm-Leach-Bliley, CCPA enforcement by Federal Trade
(California) Commission.
Personal Data Protection Act, Explicit data protection and cybersecurity
Singapore
2012 framework for digital businesses.
Hybrid model combining data protection,
India IT Act, 2000 + DPDPA, 2023
authentication, and cybercrime provisions.
India’s approach, while still evolving, is increasingly rights-based and harmonized with
global norms, marking a transition from reactive regulation to preventive digital governance.