Information Technology Act, 2000

Amendment History of the IT Act, 2000: From 2008 to 2023

The IT Act of today is very different from the Act that came into force in October 2000. It has been reshaped by one major overhaul in 2008, a tribunal reform in 2017, notifications amending its Schedules in 2015 and 2022, a decriminalisation exercise in 2023, and the data protection law of 2023. This note traces that history amendment by amendment: what the original Act contained, why and how it was changed in 2008, how the appellate tribunal was folded into TDSAT, how the Schedules widened the reach of electronic transactions, what the Jan Vishwas Act changed, and how the DPDP Act is set to amend the IT Act. It ends with before and after comparisons for quick revision.

1. A House Renovated over Twenty-Five Years

Think of a house built in 2000 for a small family. In 2008 it was rebuilt to add rooms and locks as the family grew and the neighbourhood became less safe. In 2017 the old guardroom was shut and the guard moved to a larger building next door. In 2022 two locked doors were opened to let more visitors in. In 2023 some harsh punishments for minor breaches of house rules were replaced with fines, and a new wing for personal data was planned. Knowing when each change happened is the key to answering questions on the Act.

Milestones in the life of the IT Act

Figure 1: Milestones in the life of the IT Act

2. Legislative History at a Glance

  • Origins. The UNCITRAL Model Law on Electronic Commerce, 1996 and the recommendations of the Prime Minister's IT Task Force in 1998 led to the Information Technology Bill, 1999, introduced in December 1999.
  • Enactment. Act 21 of 2000; passed in May 2000; President's assent on 9 June 2000; in force on 17 October 2000.
  • The 2008 overhaul. The Information Technology (Amendment) Act, 2008 (Act 10 of 2009), assent 5 February 2009, in force 27 October 2009.
  • Tribunal reform. The Finance Act, 2017 made TDSAT the Appellate Tribunal from 26 May 2017.
  • Schedule notifications. The Second Schedule was amended in 2015 to add Aadhaar-based e-authentication; the First Schedule was amended by a notification dated 26 September 2022, published on 6 October 2022.
  • 2023. The Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023) and the Digital Personal Data Protection Act, 2023 (Act 22 of 2023), both receiving assent on 11 August 2023.

3. The Original Framework of 2000

The 2000 Act and its gaps

Figure 2: The 2000 Act and its gaps

  • Purpose. Primarily an e-commerce and e-governance statute: legal recognition of electronic records and digital signatures, a regulatory framework for Certifying Authorities, and a limited set of penalties and offences.
  • Structure. 94 sections in 13 chapters and 4 Schedules. Sections 91 to 94 and the Schedules amended the IPC, the Evidence Act, the Bankers' Books Evidence Act and the RBI Act. The excluded documents were listed in Section 1(4) itself.
  • Civil side. Section 43 provided compensation of up to ₹1 crore for unauthorised access and damage, decided by adjudicating officers.
  • Offences. Tampering with source code (s.65), hacking (s.66), obscenity (s.67), non-compliance with the Controller's directions (ss.68 and 69), access to protected systems (s.70), misrepresentation, breach of confidentiality and false certificates (ss.71 to 74)
  • Institutions. The Controller of Certifying Authorities and the Cyber Regulations Appellate Tribunal; investigation by a Deputy Superintendent of Police.

4. The Information Technology (Amendment) Act, 2008

From review to commencement

Figure 3: From review to commencement

  • Journey. An Expert Committee constituted by the Ministry reviewed the Act in 2005; the Amendment Bill was introduced in the Lok Sabha in December 2006 and examined by the Parliamentary Standing Committee, which reported in 2007. Both Houses passed the Bill in December 2008, shortly after the Mumbai terror attacks of November 2008, with little debate.

Reasons for the 2008 Amendment

  • Technology neutrality. To move from the technology-specific digital signature to the electronic signature, in line with the UNCITRAL Model Law on Electronic Signatures, 2001.
  • New cybercrimes. The Statement of Objects and Reasons pointed to new forms of crime such as publishing sexually explicit material, video voyeurism, breach of confidentiality and leakage of data by intermediaries, e-commerce frauds such as phishing, identity theft and offensive messages.
  • Data protection. The growth of outsourcing and incidents of data theft called for a duty on companies to protect personal data.
  • Intermediary liability. The Bazee.com prosecutions of 2004 showed that the original Section 79 gave uncertain protection to platforms.
  • National security. The need for statutory bodies for incident response and critical infrastructure protection, and for clearer powers of interception and blocking.

Major Changes

Ten areas changed by the 2008 Amendment

Figure 4: Ten areas changed by the 2008 Amendment

  • Electronic signature. New definitions of electronic signature and electronic signature certificate (s.2(1)(ta) and (tb)); Section 3A recognising any reliable technique in the Second Schedule; 'digital signature' replaced by 'electronic signature' throughout; and new definitions of communication device, cyber cafe and cyber security (s.2(1)(ha), (na) and (nb)), with a revised definition of intermediary (s.2(1)(w))
  • E-governance and contracts. Section 6A (service providers), Section 7A (audit of electronic documents) and Section 10A (validity of contracts formed electronically)
  • Civil liability and data protection. The ₹1 crore cap in Section 43 removed, clauses (i) and (j) added, Section 43A inserted, and adjudicating officers limited to claims up to ₹5 crore (s.46)
  • Schedules. Section 1(4) substituted to refer to a new First Schedule of excluded documents, and a new Second Schedule of electronic signature techniques created, both amendable by notification.

Expansion of Cyber Offences: Sections 66 and 66A to 66F

  • Section 66 recast. The offence of 'hacking' was replaced by 'computer related offences': any act in Section 43 done dishonestly or fraudulently, punishable with up to three years or fine up to ₹5 lakh or both.
  • Section 66A. Sending offensive messages through communication services; struck down in Shreya Singhal (2015)
  • Section 66B. Dishonestly receiving or retaining a stolen computer resource or communication device.
  • Section 66C. Identity theft: fraudulent or dishonest use of another's electronic signature, password or unique identification feature.
  • Section 66D. Cheating by personation using a computer resource.
  • Section 66E. Violation of privacy: capturing, publishing or transmitting images of a person's private area without consent.
  • Section 66F. Cyber terrorism, punishable with imprisonment which may extend to life.

Obscenity: Section 67 and Sections 67A to 67C

  • Section 67 revised. Punishment for a first conviction changed from up to five years and fine up to ₹1 lakh to up to three years and fine up to ₹5 lakh, with higher punishment on a second conviction.
  • Section 67A. Publishing or transmitting sexually explicit material in electronic form.
  • Section 67B. Child sexual abuse material, covering creation, collection, browsing, downloading, advertising and distribution, and online grooming of children, with an exception for bona fide works of science, literature, art or heritage.
  • Section 67C. Intermediaries to preserve and retain information as prescribed.

State Powers: Sections 69, 69A and 69B

  • Section 69 recast. Originally a power of the Controller to direct decryption; now a power of the Central or State Government to direct interception, monitoring or decryption on stated grounds, with procedure prescribed by rules.
  • Section 69A. Power of the Central Government to block public access to information, upheld in Shreya Singhal.
  • Section 69B. Power to authorise monitoring and collection of traffic data for cyber security.

Critical Information Infrastructure: Sections 70, 70A and 70B

  • Section 70 recast. Protected systems linked to critical information infrastructure, defined in the Explanation as a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety; and power to prescribe information security practices.
  • Section 70A. National nodal agency for CII protection, later NCIIPC.
  • Section 70B. CERT-In as the national agency for incident response, with power to call for information and give directions.

Intermediaries, Evidence and Other Changes

  • Section 79. The narrow protection for 'network service providers' was replaced by a conditional safe harbour for all intermediaries: no liability for third-party information if the intermediary plays a passive role and observes due diligence, but loss of protection if it conspires or aids, or fails to remove content on actual knowledge or government notice.
  • Section 79A. The Central Government may notify Examiners of Electronic Evidence to give expert opinion in courts and other authorities.
  • Sections 84A to 84C. Power to prescribe modes of encryption (s.84A); abetment punishable as the offence (s.84B); and attempt punishable with up to half the longest term (s.84C)
  • Other new sections. Section 72A (disclosure of personal information in breach of lawful contract), Section 77A (compounding), Section 77B (offences punishable with three years or more cognizable; three-year offences bailable), and Section 78 (investigation by an Inspector instead of a Deputy Superintendent)
  • Consequential changes. The IPC and the Evidence Act were amended, including by inserting clause (3) in Section 4 of the IPC on offences targeting computers in India, and Section 45A of the Evidence Act on the opinion of the Examiner of Electronic Evidence.

The IT Act before and after the 2008 Amendment

Figure 5: The IT Act before and after the 2008 Amendment

5. The Finance Act, 2017 and TDSAT

The appellate tribunal over time

Figure 6: The appellate tribunal over time

  • Tribunal rationalisation. The Finance Act, 2017 merged several tribunals to reduce their number. The Cyber Appellate Tribunal, which had long functioned without a chairperson, was merged into the Telecom Disputes Settlement and Appellate Tribunal.
  • Section 48 substituted. TDSAT, established under Section 14 of the TRAI Act, 1997, is the Appellate Tribunal under the IT Act from the commencement of the relevant part of the Finance Act, 2017 on 26 May 2017, and exercises the jurisdiction, powers and authority conferred by the IT Act.
  • Sections 49 to 54 and 56 omitted. The provisions on the composition of the Cyber Appellate Tribunal, qualifications, term, salary, superintendence, distribution of business, transfer of cases, decision by majority, vacancies, resignation and removal, and staff were omitted, since TDSAT's own statute governs these matters.
  • What remains. Appeals from the Controller and adjudicating officers still lie to the Appellate Tribunal under Section 57 within 45 days, now to TDSAT, and from there to the High Court under Section 62 within 60 days.

6. The Schedule Amendments

  • Second Schedule, 2015. Added e-authentication using Aadhaar or other e-KYC services as a recognised electronic signature technique, enabling the e-Sign service without any amendment to the Act itself.
  • First Schedule, 2022. By a notification dated 26 September 2022, published on 6 October 2022, the Central Government narrowed the list of documents excluded from the Act.

The First Schedule before and after the 2022 notification

Figure 7: The First Schedule before and after the 2022 notification

  • Negotiable instruments. Demand promissory notes and bills of exchange issued in favour of or endorsed by entities regulated by the RBI, NHB, SEBI, IRDAI or PFRDA are no longer excluded.
  • Powers of attorney. Powers of attorney empowering such regulated entities to act for the executant are no longer excluded.
  • Immovable property. The entry excluding contracts for sale or conveyance of immovable property was omitted altogether.
  • Electronic transactions expanded. Banks and other regulated lenders can now execute loan documents, demand promissory notes, powers of attorney and property-related agreements such as memoranda of deposit of title deeds electronically, with e-signatures and e-stamping. Trusts and wills remain excluded, and registration and stamp laws still apply.

7. The Jan Vishwas (Amendment of Provisions) Act, 2023

  • Purpose. To promote ease of living and doing business by decriminalising or rationalising minor offences across 42 central Acts, replacing imprisonment for technical or procedural defaults with monetary penalties.
  • Omission of Section 66A. The Act omits Section 66A from the statutory text. The provision had been void since Shreya Singhal (2015), but its continued presence in the text had led police to register cases under it. Omission removes it from the statute book.
  • Decriminalisation. Defaults such as failure to surrender a suspended or revoked licence (s.33), failure to preserve and retain information (s.67C), non-compliance with the Controller's orders (s.68) and disclosure in breach of confidentiality or contract (ss.72 and 72A) are converted from offences into contraventions attracting monetary penalties.
  • Rationalisation. Penalties under Section 44 were raised tenfold (to ₹15 lakh per failure, and ₹50,000 and ₹1 lakh per day); the residuary penalty in Section 45 became a penalty of up to ₹1 lakh plus compensation of up to ₹10 lakh (intermediaries, companies, bodies corporate) or ₹1 lakh (others); and Sections 69B(4) and 70B(7) now provide up to one year or fine up to ₹1 crore or both.
  • Adjudication. Section 46 is amended so that adjudicating officers can impose the new penalties across the Act, not only under Chapter IX.
  • Commencement. The IT Act amendments were brought into force from 30 November 2023 by notification S.O. 4745(E) dated 31 October 2023 (see Topic 40)

The IT Act before and after the Jan Vishwas amendments

Figure 8: The IT Act before and after the Jan Vishwas amendments

8. The DPDP Act, 2023 Amendments

Section 44(2) of the DPDP Act

Figure 9: Section 44(2) of the DPDP Act

  • Future omission of Section 43A. The compensation remedy for negligent handling of sensitive personal data will be omitted, and replaced by the DPDP Act's duties and penalties.
  • Section 81 amendment. The proviso to the overriding clause will preserve rights under the DPDP Act, alongside the Copyright and Patents Acts.
  • Section 87(2)(ob) omission. The rule-making power supporting Section 43A and the SPDI Rules will go.
  • Transition. The DPDP Rules, 2025 were notified on 13 November 2025; the substantive provisions, and with them Section 44(2), are scheduled to take effect in May 2027. Until then, Section 43A and the SPDI Rules continue, and claims arising earlier should survive under Section 6 of the General Clauses Act (see Topic 25)

⚠ Exam traps

First, date the 2008 Amendment correctly: passed in December 2008, Act 10 of 2009, assent 5 February 2009, in force 27 October 2009.

Secondly, Section 66A was inserted in 2008, struck down in 2015 and omitted from the text by the Jan Vishwas Act, 2023. Striking down and omission are different events.

Thirdly, immovable property contracts have not been excluded from the Act since the 2022 notification.

Fourthly, Section 43A is not yet omitted; the DPDP amendment is scheduled for May 2027.

9. Quick Revision and Memory Aids

  • '2000 built, 2008 rebuilt, 2017 guard moved, 2022 doors opened, 2023 fines and a new wing'. The whole history.
  • '10 of 2009, 5 Feb, 27 Oct'. The 2008 Amendment.
  • '66 B-C-D-E-F: stolen, identity, personation, exposure, fear'. The new offences.
  • '67 A-B-C: adult, boy or girl, cache'. Sexually explicit, child abuse material, retention.
  • '69A blocks, 69B watches traffic'. State powers.
  • '70A plans, 70B responds'. NCIIPC and CERT-In.
  • '48 to TDSAT; 49 to 54 and 56 gone'. Finance Act, 2017.
  • '2022: promissory notes, powers of attorney, property'. First Schedule changes.
  • '44(2): 43A, 81, 87(2)(ob)'. DPDP amendments.

10. Frequently Asked Questions

What were the major changes made by the IT (Amendment) Act, 2008?

The technology-neutral electronic signature (s.3A), data protection duties (ss.43A and 72A), new offences (ss.66A to 66F, 67A to 67C), blocking, interception and traffic data powers (ss.69 to 69B), CII protection and CERT-In (ss.70 to 70B), a revised intermediary safe harbour (s.79), the Examiner of Electronic Evidence (s.79A), and encryption, abetment and attempt provisions (ss.84A to 84C).

Which body is now the Appellate Tribunal under the IT Act?

The Telecom Disputes Settlement and Appellate Tribunal, under Section 48 as substituted by the Finance Act, 2017, from 26 May 2017.

11. Related Topics

  • Topic 40: Jan Vishwas Act and the IT Act. The 2023 amendments section by section.
  • Topic 25: IT Act and Data Protection. The DPDP transition in detail.