Information Technology Act, 2000
Cyber Contraventions, Offences, Intermediary Liability and CII under the IT Act
Once the IT Act made electronic activity legally effective, it had to protect that activity from misuse. It does so through five sets of provisions: civil contraventions that lead to compensation, criminal offences that lead to punishment, a conditional safe harbour for intermediaries, a cybersecurity framework built around CERT-In and the State's interception and blocking powers, and special protection for critical information infrastructure. This note explains each in turn and how they fit together.
1. Traffic Challans, Criminal Cases, Toll Operators and Highway Police
Think of the road system again. A minor violation earns a challan and compensation for the damage caused; that is a cyber contravention. Driving dishonestly to cause harm is a criminal case; that is a cyber offence. The toll operator who lets vehicles pass is not blamed for a smuggler's cargo unless it knew and did nothing; that is the intermediary safe harbour. Highway patrols monitor traffic and respond to accidents; that is CERT-In and cybersecurity. And some roads, such as those to airports and power stations, are specially guarded; those are protected systems of critical information infrastructure.
Figure 1: The five enforcement pillars of the IT Act
2. Cyber Contraventions (Chapter IX, Sections 43 to 47)
Figure 2: The ten acts listed in Section 43
- Section 43. If any person, without permission of the owner or person in charge of a computer, computer system or network, does any of the acts in clauses (a) to (j), he is liable to pay damages by way of compensation to the person affected. The 2008 Amendment removed the earlier cap of ₹1 crore and added clauses (i) and (j)
- No mental element. Section 43 needs no dishonest or fraudulent intention. Doing the act without permission is enough, which makes it a civil wrong of near strict liability.
- Section 43A. Compensation where a body corporate handling sensitive personal data is negligent in maintaining reasonable security practices (see Topic 8)
- Section 44. Penalties for failure to furnish information, returns or documents to the Controller or a Certifying Authority, or to maintain books.
- Section 45. A residuary penalty for contravention of rules or regulations for which no separate penalty is provided: compensation up to ₹25,000 as enacted.
- Adjudication (s.46). An adjudicating officer, not below the rank of Director to the Government of India or an equivalent State officer, decides claims where the injury or damage claimed does not exceed ₹5 crore; above that, the competent court decides. The officer has powers of a civil court. In practice, State IT Secretaries act as adjudicating officers.
- Factors (s.47). The amount of gain or unfair advantage, the loss caused, and the repetitive nature of the default.
- Appeals. To the Appellate Tribunal within 45 days (s.57); since the Finance Act, 2017 the Telecom Disputes Settlement and Appellate Tribunal performs this role. A further appeal lies to the High Court within 60 days on any question of fact or law (s.62)
- Civil court bar (s.61). No civil court may entertain a matter which an adjudicating officer or the Tribunal is empowered to decide, but the proviso preserves the court's jurisdiction where the claim exceeds ₹5 crore.
📖 Umashankar Sivasubramanian v. ICICI Bank (Adjudicating Officer, Tamil Nadu, 2010) Facts: A customer lost money from his account after responding to a phishing email. He claimed compensation from the bank under Section 43 read with Section 85. Held: The bank had failed to exercise due diligence to prevent unauthorised access to the account, and was directed to pay compensation to the customer. Significance: One of the first awards by an adjudicating officer, showing that Chapter IX can make an institution liable for failing to prevent a contravention on its system. |
Figure 3: The same act as a contravention and as an offence
3. Cyber Offences (Chapter XI, Sections 65 to 78)
Figure 4: Principal offences and punishments after the 2008 Amendment
- Section 66: the bridge. Any act in Section 43, done dishonestly or fraudulently, is an offence. 'Dishonestly' and 'fraudulently' carry their meaning in the penal code, now Sections 2(7) and 2(9) of the BNS.
- Section 66A: struck down. The offence of sending offensive messages was declared unconstitutional in Shreya Singhal v. Union of India, (2015) 5 SCC 1, and no prosecution can be launched under it.
- Identity theft and personation (ss.66C and 66D). Fraudulent use of another's password, electronic signature or unique identification feature; and cheating by personation through a computer resource, the provision most used against online fraud.
- Cyber terrorism (s.66F). Denying access, penetrating a system without authorisation or introducing a contaminant with intent to threaten the unity, integrity, security or sovereignty of India or strike terror, causing or likely to cause death, injury, damage to property, disruption of essential supplies, or an adverse effect on critical information infrastructure; or knowingly accessing restricted information that may be used against the security of the State.
- Obscene and sexual material (ss.67 to 67B). Publishing or transmitting obscene material, sexually explicit material and child sexual abuse material in electronic form, with higher punishment on a second conviction. Section 67B also covers browsing, downloading and online grooming.
- Offences by persons with duties. Failure to comply with interception or blocking orders (ss.69 and 69A), traffic data orders (s.69B: up to one year or fine up to ₹1 crore) or CERT-In directions (s.70B(7): up to one year or fine up to ₹1 crore); and misrepresentation or false certificates (ss.71, 73 and 74). Non-compliance with the Controller (s.68), breach of confidentiality (s.72), disclosure in breach of contract (s.72A) and failure to preserve information (s.67C) have been civil penalties since 2023.
- Abetment and attempt. Abetment is punishable as the offence (s.84B), and an attempt with up to half the longest term (s.84C). Companies and their officers are liable under Section 85.
Procedure
- Compounding (s.77A). Offences other than those punishable with life imprisonment or imprisonment for more than three years may be compounded by a competent court, except where the accused is liable to enhanced punishment for a previous conviction, or the offence affects the socio-economic conditions of the country or is committed against a child below 18 or a woman.
- Cognizance and bail (s.77B). Offences punishable with three years or more are cognizable; offences punishable with three years are bailable.
- Investigation (s.78). By a police officer not below the rank of Inspector, who may also enter a public place and search and arrest without warrant under Section 80.
- Extraterritorial reach (s.75). The Act applies to offences committed outside India involving a computer system or network located in India.
- Interplay with the BNS. Where the IT Act specifically covers the conduct, it prevails as the special law (Sharat Babu Digumarti, (2017) 2 SCC 18; Gagan Harsh Sharma v. State of Maharashtra, Bombay High Court, 2018, quashing IPC charges of theft for data theft covered by ss.43 and 66). The BNS still applies to conduct the IT Act does not cover, such as voyeurism and stalking by electronic monitoring (ss.77 and 78 BNS) and organised cyber crime (s.111 BNS)
- Syed Asifuddin v. State of Andhra Pradesh (Andhra Pradesh High Court, 2005). Reprogramming mobile handsets locked to one network so that they could be used on another was held to be tampering with source code under Section 65.
- Just Rights for Children Alliance v. S. Harish (Supreme Court, 2024). Storing or viewing child sexual abuse material can be an offence under Section 15 of the POCSO Act and Section 67B of the IT Act, even without further transmission. The Court recommended the term 'child sexual exploitative and abuse material' in place of 'child pornography'.
⚠ Jan Vishwas Act, 2023 From 30 November 2023 (notification S.O. 4745(E)), the Jan Vishwas (Amendment of Provisions) Act, 2023 omitted Section 66A and converted Sections 33, 67C, 68, 72 and 72A from offences into civil penalties (up to ₹5 lakh for ss.33 and 72, and up to ₹25 lakh for ss.67C, 68 and 72A), raised the penalties in Sections 44 and 45, extended the adjudicating officer's jurisdiction under Section 46 to the whole Act, and changed the punishment under Sections 69B(4) and 70B(7) to up to one year or fine up to ₹1 crore or both (see Topic 40). |
4. Intermediary Liability (Chapter XII, Section 79)
- Intermediary (s.2(1)(w)). Any person who, on behalf of another, receives, stores or transmits an electronic record or provides a service with respect to it, including telecom and internet service providers, web hosts, search engines, online payment, auction and market places, and cyber cafes.
- Safe harbour (s.79(1)). Notwithstanding any other law, an intermediary is not liable for third-party information, data or communication link made available or hosted by it.
- Conditions (s.79(2)). Its function is limited to providing access to a communication system; it does not initiate the transmission, select the receiver or select or modify the information; and it observes due diligence and government guidelines.
- Loss of protection (s.79(3)). If it conspired, abetted, aided or induced the unlawful act, or if, on receiving actual knowledge or government notice that its resource is being used for an unlawful act, it fails to expeditiously remove or disable access.
Figure 5: Does the safe harbour apply?
The Intermediary Guidelines and Digital Media Ethics Code Rules, 2021
- Due diligence (Rule 3). Publish rules and a privacy policy, inform users not to host prohibited content, remove content on a court order or a reasoned intimation from an authorised officer of the appropriate Government, retain information for investigation, and run a grievance mechanism. As amended in February 2026, orders under Rule 3(1)(d) must be acted on within three hours and user grievances resolved within seven days, and synthetically generated content must be labelled and carry provenance metadata.
- Significant social media intermediaries (Rule 4). Platforms above the notified user threshold of 50 lakh registered users must appoint a Chief Compliance Officer, a nodal contact person and a Resident Grievance Officer in India, publish compliance reports, and, for messaging services, enable identification of the first originator on a court or government order, a requirement under challenge.
- Grievance Appellate Committees. Added in 2022 to hear appeals from users against decisions of grievance officers.
- Consequence (Rule 7). An intermediary that fails to observe the Rules loses the protection of Section 79.
- Fact check unit. The 2023 amendment enabling a government fact check unit was struck down by the Bombay High Court in Kunal Kamra v. Union of India (2024)
📖 Shreya Singhal v. Union of India, (2015) 5 SCC 1 (on Section 79) Issue: Whether an intermediary must judge for itself the lawfulness of content complained of by private parties, on pain of losing the safe harbour. Held: Section 79(3)(b) and the corresponding rule were read down: 'actual knowledge' means knowledge through a court order, or notification by the government, and the unlawful act must relate to the grounds in Article 19(2). Significance: Intermediaries are not required to adjudicate private complaints; a court or government order triggers the duty to remove. |
- Avnish Bajaj and Sharat Babu Digumarti (Bazee.com). Prosecutions over an obscene clip listed on an auction site tested director and platform liability; the Supreme Court held in 2017 that where the IT Act covers the conduct the accused cannot be separately prosecuted under the general obscenity provision.
- MySpace Inc. v. Super Cassettes Industries Ltd. (Delhi High Court, Division Bench, 2016). For copyright infringement by users, an intermediary is liable only on specific knowledge of infringing content; a general awareness is not enough, and the safe harbour applies to copyright claims too.
- Christian Louboutin SAS v. Nakul Bajaj (Delhi High Court, 2018). An e-commerce platform that actively participates in selling, by storing, packaging and promoting goods, is not a passive intermediary and cannot claim Section 79.
- Google India Pvt. Ltd. v. Visaka Industries, (2020) 2 SCC 726. The unamended Section 79, before 27 October 2009, did not protect an intermediary against criminal defamation.
- X Corp v. Union of India (Karnataka High Court, 2023). A challenge to blocking orders under Section 69A was dismissed, with costs of ₹50 lakh.
5. Cybersecurity under the IT Act
- Definition (s.2(1)(nb)). Protecting information, equipment, devices, computers, computer resources, communication devices and stored information from unauthorised access, use, disclosure, disruption, modification or destruction.
- CERT-In (s.70B). The Indian Computer Emergency Response Team is the national agency for incident response. It collects, analyses and disseminates information on cyber incidents, issues forecasts and alerts, takes emergency measures, coordinates response, and issues guidelines and advisories. It may call for information and give directions (s.70B(6)); non-compliance is punishable under s.70B(7)
- CERT-In Directions of 28 April 2022. Report specified cyber incidents within six hours of noticing them, maintain logs for 180 days within India, synchronise system clocks with national time servers, and, for VPN, cloud and data centre providers, retain subscriber information for five years.
- Interception (s.69). The Central or State Government may direct interception, monitoring or decryption of information in the interest of sovereignty, integrity, defence, security of the State, friendly relations, public order, preventing incitement to a cognizable offence, or investigation of any offence, with reasons recorded and subject to the 2009 Rules and review committee.
- Blocking (s.69A). Public access to information may be blocked on similar grounds, under the Blocking Rules, 2009. Shreya Singhal upheld the provision because of its narrow grounds, reasoned orders and hearing safeguards.
- Traffic data (s.69B). The Central Government may authorise monitoring and collection of traffic data to enhance cyber security and to identify, analyse and prevent intrusions.
- Reasonable security practices. Section 43A and the SPDI Rules, 2011, under which ISO/IEC 27001 is a recognised standard; Section 84A for prescribed modes of encryption.
Figure 6: Institutions and powers of the cybersecurity framework
6. Critical Information Infrastructure (Sections 70 and 70A)
Figure 7: From definition to protection
Section 70(1) and Explanation, Information Technology Act, 2000 The appropriate Government may, by notification in the Official Gazette, declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure, to be a protected system. Explanation. For the purposes of this section, 'Critical Information Infrastructure' means the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety. |
- Authorisation (s.70(2)). The appropriate Government may, by written order, authorise persons to access protected systems.
- Offence (s.70(3)). Securing or attempting to secure access to a protected system in contravention of the section: imprisonment up to ten years and fine.
- Security practices (s.70(4)). The Central Government prescribes information security practices, now in the Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018, which require an information security management system, a Chief Information Security Officer and reporting to the nodal agency.
- Nodal agency (s.70A). The Central Government may designate an organisation as the national nodal agency for CII protection. The National Critical Information Infrastructure Protection Centre, under the National Technical Research Organisation, was designated in January 2014.
- Link to cyber terrorism. An attack likely to adversely affect CII specified under Section 70 is expressly covered by Section 66F.
Figure 8: NCIIPC and CERT-In: two agencies, two roles
⚠ Exam trap NCIIPC and CERT-In are often confused. NCIIPC (s.70A), under NTRO, protects critical information infrastructure in advance. CERT-In (s.70B), under MeitY, responds to cyber incidents across all systems. Likewise, keep Section 43 (civil, no intention needed) apart from Section 66 (criminal, dishonest or fraudulent intention). |
7. Quick Revision and Memory Aids
- 'Challan, case, toll, patrol, guarded road'. Contravention, offence, intermediary, cybersecurity, CII.
- '43 + dishonest = 66'. The link between civil and criminal liability.
- 'Five crore divides forum'. Adjudicating officer up to ₹5 crore; civil court above.
- 'Conduit, diligence, takedown'. The three conditions of the safe harbour.
- 'Shreya: court or government order'. Meaning of actual knowledge.
- 'Six hours, 180 days, five years'. CERT-In Directions of 2022.
- '70 guards, 70A plans, 70B responds'. Protected systems, NCIIPC, CERT-In.
8. Frequently Asked Questions
What is the difference between Section 43 and Section 66 of the IT Act?
Section 43 is a civil contravention requiring no mental element and leading to compensation decided by an adjudicating officer. Section 66 makes the same acts an offence when done dishonestly or fraudulently, punishable with up to three years or fine up to ₹5 lakh or both.
When does an intermediary lose the safe harbour under Section 79?
When it goes beyond a passive role, fails to observe due diligence under the 2021 Rules, conspires in or abets the unlawful act, or fails to remove content expeditiously after actual knowledge through a court order or government notification.
What is critical information infrastructure?
Under the Explanation to Section 70(1), a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. The Government may declare it a protected system, and unauthorised access is punishable with up to ten years.
9. Related Topics
- Topic 8: Privacy and Data Protection. Sections 43A, 66E, 72 and 72A and the DPDP Act.
- Topic 9: Electronic Evidence. Proving cyber offences in court.