All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Information Technology Act, 2000: Introduction, Objects, Structure and Scope

The Information Technology Act, 2000 is India's foundational cyber law. It was enacted to give electronic records and electronic signatures the same legal footing as paper documents and handwritten signatures, so that commerce and government could move online, and it also created a framework of penalties and offences for misuse of computers and data. This note introduces the Act: its preamble and objects, how it is organised, how far it reaches, what it excludes, the definitions that run through it, the authorities it creates, and how it sits alongside the BNS, the BSA and the data protection law.

1. A Bridge between Paper Law and the Digital World

Before 2000, Indian law assumed that important things happen on paper: contracts are signed in ink, records are kept in files, evidence is a document that can be held. The IT Act works like a bridge. It does not rewrite the Contract Act or the law of evidence; instead, it declares that where those laws ask for writing, a signature or a record, the electronic version counts. Over that bridge it then places guardrails: rules for Certifying Authorities, penalties for unauthorised access, offences for serious misuse, and duties for the intermediaries that carry online traffic.

Preamble, Information Technology Act, 2000 (extract)

An Act to provide legal recognition for transactions carried out by means of electronic data interchange and other means of electronic communication, commonly referred to as 'electronic commerce', which involve the use of alternatives to paper-based methods of communication and storage of information, to facilitate electronic filing of documents with the Government agencies and further to amend the Indian Penal Code, the Indian Evidence Act, 1872, the Bankers' Books Evidence Act, 1891 and the Reserve Bank of India Act, 1934 and for matters connected therewith or incidental thereto.

WHEREAS the General Assembly of the United Nations by resolution A/RES/51/162, dated the 30th January, 1997 has adopted the Model Law on Electronic Commerce adopted by the United Nations Commission on International Trade Law; ... AND WHEREAS it is considered necessary to give effect to the said resolution and to promote efficient delivery of Government services by means of reliable electronic records.

  • Act number and dates. Act No. 21 of 2000; passed by Parliament in May 2000; President's assent on 9 June 2000; brought into force on 17 October 2000.
  • Major amendment. The Information Technology (Amendment) Act, 2008 (Act 10 of 2009), in force from 27 October 2009, widened the Act from an e-commerce statute into a general cyber law.
  • Nodal ministry. The Ministry of Electronics and Information Technology (MeitY) administers the Act and frames most rules under it.

2. The Objects of the Act

The seven pillars of the IT Act

Figure 1: The seven pillars of the IT Act

  • Legal recognition of electronic records. Where a law requires writing, the requirement is met by information in electronic form that is accessible for later reference (Section 4)
  • Legal recognition of electronic signatures. A signature requirement is met by an electronic signature affixed in the prescribed manner (Sections 3, 3A and 5)
  • Electronic governance. Filing, issue of licences, receipts and payments, retention of records and publication in an electronic Gazette (Sections 6 to 10A)
  • Trust infrastructure. A Controller of Certifying Authorities licenses and regulates the authorities that issue electronic signature certificates (Sections 17 to 34)
  • Civil remedies. Penalties and compensation for unauthorised access, data damage and similar contraventions, decided by adjudicating officers (Sections 43 to 47)
  • Criminal law of cyberspace. Offences such as tampering with source code, computer-related offences, identity theft, cheating by personation, violation of privacy, cyber terrorism and obscene or sexually explicit material (Sections 65 to 78)
  • Intermediary framework. Conditional safe harbour for intermediaries that observe due diligence (Section 79), with blocking and monitoring powers in Sections 69 to 69B.

3. Structure of the Act

The chapters of the IT Act and their sections

Figure 2: The chapters of the IT Act and their sections

  • As enacted. 94 sections in 13 chapters, with 4 Schedules. Sections 91 to 94 and the Third and Fourth Schedules amended the IPC, the Evidence Act, the Bankers' Books Evidence Act and the RBI Act; those amending provisions have since been omitted.
  • Added in 2008. Among others, Sections 3A (electronic signature), 10A (electronic contracts), 43A (compensation for failure to protect data), 66A to 66F (new offences, including cyber terrorism), 67A and 67B (sexually explicit material and child sexual abuse material), 69A and 69B (blocking and traffic data), 70A and 70B (NCIIPC and CERT-In), 72A (disclosure in breach of contract), 77A and 77B (compounding and cognizability), 79A (examiner of electronic evidence) and 84A to 84C (encryption, abetment and attempt)
  • Struck down. Section 66A was declared unconstitutional in Shreya Singhal v. Union of India, (2015) 5 SCC 1.

4. Territorial Scope and Excluded Documents

How far the Act reaches and what it leaves out

Figure 3: How far the Act reaches and what it leaves out

  • Whole of India. Section 1(2) extends the Act to the whole of India.
  • Extraterritorial reach. Section 1(2) also applies the Act to any offence or contravention committed outside India by any person, and Section 75 makes it apply to such an act if it involves a computer, computer system or computer network located in India, irrespective of the offender's nationality.
  • Commencement. Section 1(3) allowed the Act to be brought into force by notification, with different dates for different provisions.
  • First Schedule exclusions. Under Section 1(4), the Act does not apply to the documents in the First Schedule: negotiable instruments other than cheques, powers of attorney, trusts, and wills and other testamentary dispositions. Since a notification of September 2022, demand promissory notes and bills of exchange issued in favour of or endorsed by entities regulated by the RBI, NHB, SEBI, IRDAI or PFRDA, and powers of attorney empowering such entities, are no longer excluded, and the entry on contracts for sale or conveyance of immovable property has been omitted. The Central Government may amend the Schedule by notification.
  • Why these exclusions. These are documents where the law traditionally insists on formality, registration or witnesses, and where the risks of fraud are high.

5. Key Definitions (Section 2)

  • Computer (s.2(1)(i)). Any electronic, magnetic, optical or other high-speed data processing device or system which performs logical, arithmetic and memory functions by manipulations of electronic, magnetic or optical impulses, including connected input, output, storage and communication facilities.
  • Electronic record (s.2(1)(t)). Data, record or data generated, image or sound stored, received or sent in an electronic form, or micro film or computer generated micro fiche.
  • Electronic signature (s.2(1)(ta)). Authentication of an electronic record by a subscriber by means of the electronic technique specified in the Second Schedule, and includes a digital signature.
  • Intermediary (s.2(1)(w)). Any person who, on behalf of another, receives, stores or transmits an electronic record or provides a service with respect to it, including telecom and internet service providers, web hosts, search engines, online payment, auction and market places, and cyber cafes.
  • Cyber security (s.2(1)(nb)). Protecting information, equipment, devices, computers, computer resources, communication devices and stored information from unauthorised access, use, disclosure, disruption, modification or destruction.

6. Authorities under the Act

  • Controller of Certifying Authorities (s.17). Licenses and supervises Certifying Authorities and maintains the national repository of electronic signature certificates.
  • Adjudicating Officers (s.46). Decide claims for penalty and compensation under Chapter IX, up to a prescribed monetary limit; beyond that, the competent court decides.
  • Appellate Tribunal (s.48). Hears appeals from the Controller and adjudicating officers. Since the Finance Act, 2017, the Telecom Disputes Settlement and Appellate Tribunal performs this function in place of the former Cyber Appellate Tribunal.
  • CERT-In (s.70B). The national agency for incident response, which can issue directions on cyber security.
  • NCIIPC (s.70A). The national nodal agency for the protection of critical information infrastructure.

7. Overriding Effect and Relationship with Other Laws

  • Section 81. The Act has effect notwithstanding anything inconsistent in any other law. A proviso added in 2008 preserves the rights conferred by the Copyright Act, 1957 and the Patents Act, 1970.
  • Bharatiya Nyaya Sanhita, 2023. General offences such as cheating, forgery and defamation committed through computers may attract the BNS as well as the IT Act. Where the IT Act specifically covers the conduct, it has been treated as the special law (Sharat Babu Digumarti v. Government of NCT of Delhi, (2017) 2 SCC 18)
  • Bharatiya Sakshya Adhiniyam, 2023. Admissibility of electronic records, formerly under Sections 65A and 65B of the Evidence Act, is now governed by Sections 61 to 63 of the BSA.
  • Digital Personal Data Protection Act, 2023. A separate statute for personal data. It provides for the omission of Section 43A of the IT Act, subject to its commencement.

⚠ Common confusions

First, treating the IT Act as only a cybercrime law; its first purpose was to validate electronic commerce and e-governance. Secondly, using 'digital signature' and 'electronic signature' interchangeably; since 2008 the Act uses the wider, technology-neutral 'electronic signature', of which a digital signature is one kind. Thirdly, forgetting the First Schedule: a will or a trust cannot be executed electronically under the Act, though contracts for immovable property have been outside the exclusion since 2022.

8. Quick Revision and Memory Aids

  • '21 of 2000; 9 June; 17 October'. Act number, assent and commencement.
  • 'R-S-G-C-P-O-I'. Records, Signatures, Governance, Certifying Authorities, Penalties, Offences, Intermediaries.
  • 'N-P-T-W'. First Schedule: Negotiable instruments (not cheques), Powers of attorney, Trusts, Wills; immovable property contracts dropped in 2022.
  • '1(2) and 75 reach abroad'. Extraterritorial application.
  • '2008 made it a cyber law'. The Amendment Act in force from 27 October 2009.

9. Frequently Asked Questions

What is the main object of the Information Technology Act, 2000?

To give legal recognition to electronic records and electronic signatures so that electronic commerce and e-governance can operate, and to provide penalties and offences for misuse of computers and data.

Does the IT Act apply to acts committed outside India?

Yes, under Sections 1(2) and 75, if the act involves a computer, computer system or computer network located in India.

Which documents are excluded from the IT Act?

Under the First Schedule, negotiable instruments other than cheques, powers of attorney, trusts, and wills and other testamentary dispositions, subject to the 2022 exceptions for instruments and powers of attorney involving regulated financial entities. Immovable property contracts ceased to be excluded in 2022.

When did the IT Act come into force?

On 17 October 2000.

10. Related Topics

  • Topic 2: History and Development of Cyber Law. How the Act came about and evolved.
  • Topic 3: UNCITRAL Model Law. The international model behind the Act.