All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

IT Act, 2000: Legislative History and Original Framework

Much of what is taught about the IT Act describes it as amended in 2008. But exam questions often ask what the Act looked like when it was enacted, and why it had to change. This note reconstructs the Act of 2000: how it was conceived and passed, what it set out to achieve, how it was organised, how it recognised electronic records, digital signatures and e-governance, what penalties and offences it contained, and how the law developed through rules, institutions and cases in the years before the 2008 amendment. Topic 27 gave the whole amendment history in outline; this note goes deeper into the first chapter of that story.

1. The First Floor of a Building

The Act of 2000 was the first floor of a building designed to grow. It laid the foundation, legal recognition of electronic records and signatures, and built the rooms needed at the time: a system of Certifying Authorities, a few penalties and offences, and an appellate tribunal. It did not anticipate social media, smartphones or data-driven platforms, which is why a second floor was added in 2008. To understand the building, start with the ground plan.

2. Legislative History

From the Model Law to commencement

Figure 1: From the Model Law to commencement

  • International impulse. The UNCITRAL Model Law on Electronic Commerce, 1996, commended by the UN General Assembly, invited States to give legal effect to electronic communications (see Topic 3)
  • Domestic push. The Prime Minister's National Task Force on Information Technology and Software Development, set up in 1998, recommended a legal framework for electronic commerce as part of making India an IT power.
  • The Bill. The Information Technology Bill, 1999 was introduced in the Lok Sabha on 16 December 1999 and examined by the Parliamentary Standing Committee on Information Technology.
  • Passage. The Bill was debated and passed by Parliament in May 2000.
  • Enactment. The President assented on 9 June 2000, and it became Act 21 of 2000.
  • Commencement. Most provisions were brought into force on 17 October 2000 by notification under Section 1(3)

3. Objectives of the Original Act

Five objectives drawn from the Preamble

Figure 2: Five objectives drawn from the Preamble

  • Primary aim. The Preamble described the Act as one to provide legal recognition for transactions carried out by electronic data interchange and other electronic communication, commonly referred to as electronic commerce, and to facilitate electronic filing of documents with government agencies.
  • A commerce statute. The Act was designed chiefly to enable trade and government to go paperless. Its criminal provisions were secondary and limited.
  • Consequential amendments. It amended the IPC, the Evidence Act, the Bankers' Books Evidence Act and the RBI Act so that the general law could accommodate electronic records.

4. Structure of the Original Act

The thirteen chapters of the Act as enacted

Figure 3: The thirteen chapters of the Act as enacted

  • Size. 94 sections in 13 chapters, with 4 Schedules.
  • Key definitions (s.2). Among others: computer, electronic record, digital signature, asymmetric crypto system, key pair, private key, public key, secure system, subscriber and intermediary. 'Intermediary' was defined narrowly in relation to a particular electronic message: any person who on behalf of another receives, stores or transmits that message or provides a service with respect to it.
  • Exclusions. Section 1(4) itself listed the documents to which the Act did not apply.

Original exclusions and Schedules

Figure 4: Original exclusions and Schedules

5. Recognition of Electronic Records, Digital Signatures and E-Governance

  • Digital signature (s.3). A subscriber could authenticate an electronic record only by affixing a digital signature, using an asymmetric crypto system and hash function. No other technique was recognised.
  • Electronic records (s.4). A legal requirement of writing was satisfied by information in electronic form accessible for later reference, the same text that survives today.
  • Digital signatures (s.5). A legal requirement of signature was satisfied by a digital signature affixed in the prescribed manner.
  • E-governance (ss.6 to 10). Electronic filing, issue of licences and payments (s.6), retention of electronic records (s.7), the Electronic Gazette (s.8), no right to insist on the electronic form (s.9), and rules on digital signatures (s.10). There was no provision on service providers (later s.6A) or audit (later s.7A)
  • Contracts. The original Act had no provision on electronic contracts; their validity rested on Section 4 and the Contract Act until Section 10A was added in 2008.
  • Attribution and secure records. Chapters IV and V dealt with attribution, acknowledgment and despatch (ss.11 to 13), and secure electronic records and secure digital signatures (ss.14 to 16)

The Certifying Authority Regime

  • Controller (ss.17 to 20). The Controller of Certifying Authorities licensed and supervised Certifying Authorities, recognised foreign ones, and under the original Section 20 acted as the repository of all digital signature certificates, a function later omitted.
  • Licensing and duties (ss.21 to 34). Licensing of Certifying Authorities, suspension and revocation, and duties to use secure systems and make disclosures.
  • Certificates and subscribers (ss.35 to 42). Issue, suspension and revocation of digital signature certificates, and the subscriber's duties, including control of the private key.

6. The Original Penalty and Offence Framework

Civil Penalties (Chapter IX)

  • Section 43. Unauthorised access, downloading, introducing viruses, damage, disruption, denial of access, assisting unauthorised access, and charging services to another's account (clauses (a) to (h)), with compensation not exceeding ₹1 crore.
  • Sections 44 and 45. Penalties for failure to furnish information or maintain records, and a residuary penalty of up to ₹25,000.
  • Adjudication (ss.46 and 47). Adjudicating officers of the rank of Director to the Government of India or equivalent decided claims, considering gain, loss and repetition. The ₹5 crore ceiling on their jurisdiction came only in 2008.

Offences (Chapter XI)

The offences in the Act as enacted

Figure 5: The offences in the Act as enacted

  • Hacking (s.66). Defined as destroying, deleting or altering information in a computer resource, or diminishing its value or utility, with intent or knowledge that wrongful loss or damage is likely. The word 'hacking' disappeared in 2008.
  • Obscenity (s.67). The only content offence, with punishment of up to five years and fine up to ₹1 lakh on first conviction, heavier than the three years introduced in 2008.
  • Controller's powers (ss.68 and 69). The Controller could issue directions to Certifying Authorities, and could direct agencies to intercept information and require subscribers to assist decryption, on grounds of sovereignty, security, public order or preventing incitement.
  • Classification. The Act did not classify its offences itself, so the CrPC's rule for offences under other laws applied: offences punishable with three years or more were cognizable and non-bailable. The 2008 Amendment made three-year offences bailable.
  • Procedure. Investigation by an officer not below the rank of Deputy Superintendent of Police (s.78), who could also search public places without warrant (s.80); extra-territorial application (s.75); and liability of companies (s.85)

Network Service Providers (s.79)

  • The original shield. A network service provider, meaning an intermediary, was not liable for third-party information or data made available by it if it proved that the offence or contravention was committed without its knowledge or that it had exercised all due diligence to prevent it.
  • The weakness. The burden was on the provider, the protection was limited to offences and contraventions 'under this Act', and 'due diligence' was undefined. The Bazee.com prosecutions of 2004 exposed these gaps.

7. Development before the 2008 Amendment

Rules, institutions and cases, 2000 to 2006

Figure 6: Rules, institutions and cases, 2000 to 2006

  • Rules. The Information Technology (Certifying Authorities) Rules, 2000, the Cyber Regulations Appellate Tribunal (Procedure) Rules, 2000, and the IT (Use of Electronic Records and Digital Signatures) Rules, 2004.
  • Institutions. The Controller of Certifying Authorities began licensing Certifying Authorities, with the Root Certifying Authority of India at the top of the chain; the first dedicated cyber crime police station opened in Bengaluru in 2001; and CERT-In began operating in 2004 as an administrative body.
  • Related legislation. The Negotiable Instruments (Amendment and Miscellaneous Provisions) Act, 2002 recognised cheques in electronic form and truncated cheques, extending the digital move to banking.
  • SMC Pneumatics (India) Pvt. Ltd. v. Jogesh Kwatra (Delhi High Court, 2001). An employee was restrained from sending defamatory emails about his employer, often cited as India's first cyber defamation case.
  • State of Tamil Nadu v. Suhas Katti (2004). One of the earliest convictions under Section 67, for posting obscene and defamatory messages about a woman in an online group.
  • NASSCOM v. Ajay Sood (Delhi High Court, 2005). Phishing, sending emails in another's name to obtain personal data, was held actionable as passing off, filling a gap the Act did not cover.
  • Syed Asifuddin v. State of A.P. (Andhra Pradesh High Court, 2005). Reprogramming locked mobile handsets was tampering with source code under Section 65.
  • Review. An Expert Committee constituted in 2005 recommended amendments, leading to the Amendment Bill of 2006 and the 2008 Act (see Topic 29)

8. Assessment of the Original Act

  • Achievements. It gave electronic records and signatures legal validity, created a trust infrastructure, enabled e-filing, and made India one of the early adopters of the UNCITRAL model.
  • Gaps. A technology-specific signature; no data protection duty; offences limited to hacking, source code and obscenity, with nothing on identity theft, phishing, voyeurism, child abuse material or cyber terrorism; an uncertain intermediary shield; and a high investigating rank that slowed enforcement.

⚠ Exam trap

Do not attribute 2008 provisions to the original Act. The Act of 2000 had no electronic signature, no Section 10A, no Section 43A, no Sections 66A to 66F or 67A to 67C, no blocking power under Section 69A, no CERT-In or NCIIPC, and no Examiner of Electronic Evidence. It also had a ₹1 crore cap in Section 43 and an offence called 'hacking' in Section 66.

9. Quick Revision and Memory Aids

  • 'First floor of the building'. The 2000 Act as a foundation.
  • '16 Dec 1999, May 2000, 9 June, 17 October'. Bill, passage, assent, commencement.
  • '94, 13, 4'. Sections, chapters, Schedules.
  • 'Hack, source, obscene'. The core original offences.
  • 'One crore, DSP, network provider'. Original s.43 cap, s.78 rank, s.79 shield.
  • 'Ajay Sood filled the phishing gap'. Courts before 2008.

10. Frequently Asked Questions

What was the original framework of the IT Act, 2000?

An e-commerce and e-governance statute of 94 sections in 13 chapters and 4 Schedules, recognising electronic records and digital signatures, regulating Certifying Authorities, providing civil penalties up to ₹1 crore and a limited set of offences (source code tampering, hacking, obscenity and related offences), with a Cyber Regulations Appellate Tribunal.

11. Related Topics

  • Topic 29: The 2008 Amendment. How the framework was rebuilt.
  • Topic 30: Appellate and Institutional Changes. The tribunal's journey to TDSAT.