All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

History of Cyber Law in India and the Need for the IT Act, 2000

India's cyber law did not arrive fully formed. It began in 2000 as a statute mainly concerned with making electronic commerce and e-governance legally possible, and it grew, through a major amendment in 2008, a series of rules, and landmark judgments, into the general law of cyberspace. This note explains why the law was needed, what the legal position was before it, how the Act was passed, how it was transformed in 2008, which cases shaped it, and how later statutes such as the Digital Personal Data Protection Act and the new criminal laws fit around it.

1. Roads before Traffic Rules

When motor cars first appeared, there were roads but no traffic rules written for cars. Early drivers and courts had to stretch laws made for horse carts. India in the late 1990s was in the same position with computers: businesses were exchanging electronic data, banks were computerising, and the internet was arriving, but every relevant law was written for paper. The IT Act was the first set of traffic rules for this new road.

Six gaps that created the need for the IT Act

Figure 1: Six gaps that created the need for the IT Act

2. The Legal Position before 2000

  • Contract law. The Indian Contract Act, 1872 did not forbid electronic contracts, but it said nothing about when an electronic offer or acceptance was communicated, leaving uncertainty.
  • Evidence law. The Indian Evidence Act, 1872 was built around documents and their originals. Computer printouts and stored data had no clear route to admissibility.
  • Signatures and formalities. Many statutes required documents to be 'signed' or 'in writing', which was understood as ink on paper.
  • Criminal law. The Indian Penal Code defined offences in terms of physical property and documents. There was no offence of hacking, unauthorised access or data theft as such.
  • Government processes. There was no legal basis for accepting applications, payments or filings electronically, or for publishing the Gazette online.

3. The Passage of the Act

From the Model Law to the 2008 Amendment

Figure 2: From the Model Law to the 2008 Amendment

  • International model. In 1996 UNCITRAL adopted its Model Law on Electronic Commerce, and the UN General Assembly recommended that States give it favourable consideration (see Topic 3)
  • Policy push. In 1998 the Prime Minister's National Task Force on Information Technology and Software Development made recommendations that included a legal framework for electronic commerce.
  • The Bill. The Information Technology Bill, 1999 was introduced in the Lok Sabha in December 1999 and examined by a Parliamentary Standing Committee.
  • Enactment. Parliament passed the Bill in May 2000; the President assented on 9 June 2000; the Act came into force on 17 October 2000.
  • Early implementation. Rules on Certifying Authorities followed, and licensed Certifying Authorities began issuing digital signature certificates in the early 2000s.

4. The Four Phases of Development

How India's cyber law grew

Figure 3: How India's cyber law grew

  • Phase 1: the 2000 Act. An e-commerce and e-governance statute with a limited list of offences, a technology-specific digital signature and a Cyber Regulations Appellate Tribunal.
  • Phase 2: the 2008 Amendment. After an expert committee reviewed the Act, the Information Technology (Amendment) Act, 2008 was passed in December 2008, received assent on 5 February 2009 and came into force on 27 October 2009. It introduced the technology-neutral 'electronic signature', data protection duties (Section 43A), new offences including identity theft, privacy violation and cyber terrorism (Sections 66B to 66F), sexually explicit and child sexual abuse material (Sections 67A and 67B), blocking and monitoring powers (Sections 69A and 69B), CERT-In and NCIIPC (Sections 70A and 70B), and a revised intermediary safe harbour (Section 79)
  • Phase 3: rules and constitutional review, 2011 to 2021. Rules on reasonable security practices and intermediary guidelines were notified in 2011; the Supreme Court reviewed the Act against fundamental rights in Shreya Singhal (2015); and new Intermediary Guidelines and Digital Media Ethics Code Rules were notified in 2021.
  • Phase 4: security, data and new codes, 2022 onwards. CERT-In directions of April 2022 required reporting of cyber incidents within six hours; the Digital Personal Data Protection Act, 2023 created a separate data protection law; and the BNS and BSA replaced the IPC and the Evidence Act from 1 July 2024.

5. Cases That Shaped the Law

Rules, judgments and statutes since 2011

Figure 4: Rules, judgments and statutes since 2011

  • SMC Pneumatics (India) Pvt. Ltd. v. Jogesh Kwatra (Delhi High Court, 2001). Often cited as India's first cyber defamation case, in which the Court restrained an employee from sending defamatory emails about his employer.
  • State of Tamil Nadu v. Suhas Katti (Chief Metropolitan Magistrate, Egmore, 2004). One of the earliest convictions under Section 67 of the Act, for posting obscene and defamatory messages about a woman in an online group.
  • Avnish Bajaj and Sharat Babu Digumarti (the Bazee.com case). The listing of an obscene video on an auction website in 2004 led to prosecutions that tested intermediary liability. In Sharat Babu Digumarti v. Government of NCT of Delhi, (2017) 2 SCC 18, the Supreme Court held that where the IT Act specifically covers the conduct, the accused cannot be separately prosecuted for the same act under the general obscenity provision of the IPC.
  • Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473. Electronic records are admissible as secondary evidence only with the certificate required by Section 65B of the Evidence Act, affirmed by a larger Bench in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.
  • Shreya Singhal v. Union of India, (2015) 5 SCC 1. Section 66A was struck down as vague and overbroad; Section 79 was read down so that 'actual knowledge' means a court order or government notification; the blocking power in Section 69A was upheld with its safeguards.
  • Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. A nine-judge Bench held privacy to be a fundamental right, which shaped the later data protection law.

📖 Shreya Singhal v. Union of India, (2015) 5 SCC 1

Facts: Arrests of persons for social media posts under Section 66A, which punished sending 'grossly offensive' or 'menacing' information or information causing 'annoyance' or 'inconvenience', led to a batch of writ petitions.

Held: Section 66A was struck down in its entirety as violating Article 19(1)(a) and not saved by Article 19(2): its terms were vague and it swept in protected speech. Section 79(3)(b) was read down to require actual knowledge through a court order or government notification. Section 69A and the blocking rules were upheld.

Significance: The defining constitutional judgment on the IT Act, balancing free speech against regulation of online content.

6. Where Cyber Law Stands Now

  • The IT Act remains the core. It continues to govern electronic records, signatures, cyber contraventions and offences, intermediaries and cyber security.
  • Around it. The DPDP Act, 2023 for personal data; the Telecommunications Act, 2023 for telecom; the BNS for general offences committed through computers; and the BSA for electronic evidence.
  • Looking ahead. A Digital India Act to replace the IT Act has been proposed and publicly discussed, but it had not been enacted at the time of writing.

⚠ Exam trap

Answers often describe the 2000 Act as if it already contained the 2008 provisions. Keep the phases distinct: identity theft, cyber terrorism, Section 43A, CERT-In and the electronic signature all came with the 2008 Amendment, in force from 27 October 2009.

7. Quick Revision and Memory Aids

  • 'Roads before traffic rules'. Why the Act was needed.
  • '96 model, 99 Bill, 2000 Act, 2008 overhaul'. The legislative journey.
  • 'Four phases'. 2000 Act; 2008 Amendment; rules and review; security, data and new codes.
  • 'Shreya Singhal: strike, read down, uphold'. Sections 66A, 79 and 69A.
  • 'Anvar and Khotkar: certificate'. Electronic evidence.

8. Frequently Asked Questions

Why was the Information Technology Act, 2000 needed?

Because existing laws on contracts, evidence, signatures, crime and government procedure assumed paper, leaving electronic transactions without legal certainty, and because India wished to give effect to the UNCITRAL Model Law on Electronic Commerce.

What were the major changes made by the 2008 Amendment?

The technology-neutral electronic signature, Section 43A on data protection, new offences including identity theft and cyber terrorism, blocking and monitoring powers, CERT-In and NCIIPC, and a revised intermediary safe harbour.

Which case struck down Section 66A?

Shreya Singhal v. Union of India, (2015) 5 SCC 1.

9. Related Topics

  • Topic 1: Introduction, Object and Scope. The Act in outline.
  • Topic 3: UNCITRAL Model Law. The international model.