Information Technology Act, 2000

IT Act and E-Commerce: Legal Framework for Online Transactions

Topic 4 mapped the legal issues raised by e-commerce and how they shaped cyber law. This note takes a practical angle: it follows a single online purchase from the moment a user signs up to the moment a dispute is resolved, and shows which provision of the IT Act, and which companion law, governs each step. It then examines when a marketplace can shelter behind Section 79, and what remedies a buyer or seller has against online fraud.

1. Following One Order

Priya signs up on a marketplace, verifies her phone number, buys a pair of shoes from a third-party seller, pays by card, receives an order confirmation email, and later finds the shoes are counterfeit. Five legal moments pass in a few days: onboarding, contract, payment, delivery and records, and resolution. At each one, the IT Act supplies part of the answer.

Five stages of an online transaction and the governing provisions

Figure 1: Five stages of an online transaction and the governing provisions

2. Stage 1: Onboarding

  • Identity. Regulated entities such as banks and payment firms may verify customers through Aadhaar e-KYC, and sellers may execute agreements with the platform by electronic signature or e-Sign under Sections 3A and 5.
  • User terms. Rule 3(1)(a) of the IT Rules, 2021 requires intermediaries to publish their rules, privacy policy and user agreement, and to inform users of content they must not host.
  • Personal data. Under the SPDI Rules, 2011, a platform collecting sensitive personal data such as card details must publish a privacy policy and obtain consent. From May 2027, the DPDP Act will require notice and consent for all digital personal data, with verifiable parental consent for users under 18 (ss.5, 6 and 9)

3. Stage 2: Forming the Contract

  • Validity (s.10A). The click that places an order is an acceptance in electronic form, and the contract is not unenforceable merely because of that form. The Contract Act still governs consent, consideration and capacity.
  • Automated systems (s.11). A record sent by an information system programmed by or for the originator is attributed to the originator, so an automated order confirmation binds the platform or seller that set up the system.
  • Acknowledgment (s.12). An order confirmation email is an acknowledgment of receipt. If the originator has made the contract conditional on acknowledgment, the record is treated as never sent until it is received.
  • Time and place (s.13). The acceptance is deemed received at the addressee's place of business, which matters for jurisdiction (see Topic 4 on Bhagwandas Kedia and Trimex)
  • Terms. Click-wrap terms that the user must accept are generally enforceable; browse-wrap terms hidden behind a link are the weakest. Unfair terms may be challenged under the Consumer Protection Act, 2019.
  • Arbitration clauses. An arbitration agreement may be contained in an exchange of communications through electronic means (s.7(4)(b), Arbitration and Conciliation Act, 1996)
  • Limits. Documents in the First Schedule, such as wills, trusts and most powers of attorney, cannot be executed electronically under the Act. Contracts for immovable property were removed from the Schedule in 2022, though registration laws may still require physical formalities.

4. Stage 3: Payment

  • Authentication. Online card payments require additional factor authentication under RBI rules, the practical counterpart of the IT Act's concern with secure authentication.
  • Bank and platform liability. A bank or payment firm that fails to protect a customer's account may be liable for compensation under Section 43 read with Section 85, or under Section 43A for negligence in securing sensitive financial data (Umashankar Sivasubramanian v. ICICI Bank, Adjudicating Officer, Tamil Nadu, 2010)
  • RBI liability framework. Under the RBI circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions, a customer bears no loss where the bank is at fault, or where a third-party breach is reported within three working days.
  • Payment regulation. Payment aggregators and gateways are regulated by the RBI under the Payment and Settlement Systems Act, 2007, and payment data must be stored in India under the RBI's 2018 directive.

Who bears the loss in an unauthorised electronic transaction (RBI, 2017)

Figure 2: Who bears the loss in an unauthorised electronic transaction (RBI, 2017)

5. Stage 4: Delivery and Records

  • Electronic records. Invoices, order histories and delivery confirmations satisfy writing requirements (s.4), and may be retained electronically if they remain accessible, in an accurate format, with origin and time details (s.7)
  • Disclosure duties. The E-Commerce Rules, 2020 require platforms to display seller details, total price, return and refund terms and, for inventory sellers, country of origin.
  • Logs. CERT-In's 2022 Directions require logs to be kept in India for 180 days, which helps trace fraudulent transactions.
  • Proof. Order records and emails are proved under Section 63 BSA with the required certificate, and an electronic agreement bearing electronic signatures is presumed concluded by affixing them (s.85 BSA)

6. Stage 5: Resolving Disputes

  • Grievance officer. Platforms must appoint a grievance officer under the IT Rules, 2021 and the E-Commerce Rules, 2020. As amended in 2026, user grievances under the IT Rules must be resolved within seven days.
  • Consumer commission. The buyer may file a complaint where she resides or works (s.34(2)(d) CPA), including online through the e-Daakhil portal.
  • Notice and takedown. A brand owner may notify the platform of counterfeit listings; a protected intermediary must act on specific knowledge.
  • IT Act adjudication. Claims for compensation for unauthorised access, data theft or negligent data security go to the adjudicating officer under Section 46, up to ₹5 crore.
  • Criminal complaint. Fraud involving impersonation or stolen credentials may be reported under Sections 66C and 66D, and through the national cybercrime reporting portal and helpline 1930.

7. When Is a Marketplace Protected by Section 79?

Marketplace liability under Section 79

Figure 3: Marketplace liability under Section 79

📖 Christian Louboutin SAS v. Nakul Bajaj (Delhi High Court, 2018)

Facts: A luxury brand sued an e-commerce website that sold goods bearing its marks, using its name and images to promote them. The website claimed protection as an intermediary.

Held: Whether a platform is a mere intermediary depends on its actual role. The Court listed activities, such as verifying and storing goods, packaging them in its own name, guaranteeing authenticity and promoting products, that show active participation. A platform that goes beyond a passive conduit, or that conspires or aids in infringement, cannot claim Section 79. It must also observe due diligence and disclose seller details.

Significance: The leading case on when marketplace platforms fall outside the safe harbour.

  • Kent RO Systems Ltd. v. Amit Kotak (Delhi High Court, 2017). An intermediary is not required to screen every listing in advance for possible IP infringement; its obligation arises on receiving specific knowledge.
  • MySpace Inc. v. Super Cassettes Industries Ltd. (Delhi High Court, Division Bench, 2016). Specific, not general, knowledge of infringing content triggers the intermediary's duty to act.
  • Regulatory duties regardless. Even a protected intermediary must comply with the E-Commerce Rules, 2020, including grievance redressal, disclosure of seller information and not manipulating prices.

8. Online Fraud and Remedies

Common e-commerce frauds and the provisions that apply

Figure 4: Common e-commerce frauds and the provisions that apply

⚠ Exam trap

When answering a problem question on an online purchase, do not stop at Section 10A. Work through the stages: validity and formation (ss.10A to 13), authentication and payment security (ss.3A, 43, 43A, 66C, 66D), records and proof (s.4, s.7, BSA s.63), and platform liability (s.79 with Louboutin), then add consumer law for the buyer's remedy.

9. Quick Revision and Memory Aids

  • 'Onboard, contract, pay, record, resolve'. The five stages.
  • 'Click is acceptance (10A); bot binds its master (11)'. Formation and attribution.
  • 'Confirmation email = acknowledgment (12)'. Receipt.
  • 'Three days, zero loss'. RBI liability framework.
  • 'Louboutin: active is not intermediary'. Marketplace liability.
  • 'Kent RO: no duty to pre-screen'. Notice-based obligation.

10. Frequently Asked Questions

Is an automated order confirmation binding on the seller?

Yes. Under Section 11, an electronic record sent by an information system programmed by or on behalf of the originator is attributed to the originator, so the platform or seller is bound by its automated confirmation.

Can an e-commerce marketplace claim immunity for counterfeit goods sold by third parties?

Only if it acts as a passive intermediary, observes due diligence and removes listings on specific knowledge. A platform actively involved in storing, packaging or promoting the goods cannot claim Section 79 (Christian Louboutin v. Nakul Bajaj, 2018).

What remedy does a customer have if money is lost to an unauthorised online transaction?

Under the RBI's 2017 framework, no liability if the bank was at fault or a third-party breach was reported within three working days; a claim for compensation under Sections 43 and 43A before the adjudicating officer; and a criminal complaint under Sections 66C and 66D.

11. Related Topics

  • Topic 4: Electronic Commerce and Development of Cyber Law. Models, FDI and e-contract cases.
  • Topic 7: Intermediary Liability. Section 79 and the IT Rules in detail.