All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

IT (Amendment) Act, 2008: Reasons and Major Changes

The Information Technology (Amendment) Act, 2008 is the most important change ever made to the IT Act. It turned an e-commerce statute into a general cyber law: technology-neutral signatures, data protection duties, a wide range of new offences, powers to block and monitor, statutory bodies for cyber security, and a new safe harbour for intermediaries. Topic 27 summarised it within the whole amendment history. This note examines the 2008 Amendment in depth: its passage, the reasons behind it, each group of changes with the punishments it introduced, the rules that followed, and an assessment of what it achieved and where it fell short.

1. Rebuilding While the House Is Occupied

By 2006, the house built in 2000 was full: new kinds of visitors, new kinds of burglars, and valuables the builders had never imagined. The 2008 Amendment was a rebuilding while the family still lived inside. The foundation, legal recognition of electronic records, stayed. Almost everything above it was renovated: new locks (offences), new guards (CERT-In, NCIIPC), new house rules for tenants (intermediaries), and new keys (electronic signatures).

2. Passage of the Amendment

From Expert Committee to commencement

Figure 1: From Expert Committee to commencement

  • Expert Committee (2005). Constituted by the Ministry to review the Act in the light of experience and international developments.
  • The Bill (2006). The Information Technology (Amendment) Bill, 2006 was introduced in the Lok Sabha in December 2006 and referred to the Standing Committee on Information Technology, which reported in 2007.
  • Passage (December 2008). Revised and passed by both Houses in December 2008, weeks after the Mumbai terror attacks, with almost no debate.
  • Enactment and commencement. Assent on 5 February 2009 as Act 10 of 2009; brought into force on 27 October 2009.

3. Reasons for the Amendment

Six reasons behind the 2008 Amendment

Figure 2: Six reasons behind the 2008 Amendment

  • Technology neutrality. The digital signature tied the law to one technology; the UNCITRAL Model Law on Electronic Signatures, 2001 had adopted a neutral approach.
  • New forms of cybercrime. The Statement of Objects and Reasons referred to publishing sexually explicit material, video voyeurism, breach of confidentiality and leakage of data by intermediaries, e-commerce frauds like phishing, identity theft and offensive messages through communication services.
  • Data security. India's outsourcing industry needed a legal duty to protect customer data, after incidents of data theft by call centre employees.
  • Intermediary liability. The Bazee.com prosecutions showed that the original Section 79 left platforms exposed and uncertain.
  • National security. The need for statutory institutions for incident response and critical infrastructure, and for clear powers of interception and blocking, a need felt sharply after November 2008.

4. The Major Changes

Ten areas changed by the 2008 Amendment

Figure 3: Ten areas changed by the 2008 Amendment

New and Revised Definitions

Definitions added or revised in Section 2

Figure 4: Definitions added or revised in Section 2

Introduction of Electronic Signatures

  • Section 3A. A subscriber may authenticate an electronic record by any electronic signature or electronic authentication technique that is reliable and specified in the Second Schedule, with reliability tested under Section 3A(2)
  • Terminology. 'Digital signature' was replaced by 'electronic signature' throughout the Act, and Chapter II retitled 'Digital Signature and Electronic Signature'; digital signatures remain one kind of electronic signature.
  • Schedules. Section 1(4) was substituted to refer to a new First Schedule of excluded documents, now listing negotiable instruments other than cheques, and a new Second Schedule of signature techniques, both amendable by notification.
  • Related additions. Service providers for e-governance (s.6A), audit of electronic documents (s.7A) and validity of electronic contracts (s.10A); Section 20, making the Controller the repository of signatures, was omitted.

Civil Liability and Data Protection

  • Section 43. The ₹1 crore cap was removed and clauses (i) (destroying, deleting or altering information) and (j) (stealing or altering source code) were added.
  • Section 43A. Compensation where a body corporate is negligent in maintaining reasonable security practices for sensitive personal data.
  • Section 46. Adjudicating officers limited to claims up to ₹5 crore, with larger claims going to the civil court.
  • Section 72A. Offence of disclosing personal information obtained under a lawful contract without consent, intending or knowing it would cause wrongful loss or gain.

Expansion of Cyber Offences

Offences added or recast by the 2008 Amendment, as enacted; Sections 67C and 72A were decriminalised and Section 69B revised by the Jan Vishwas Act from 30 November 2023 (see Topic 40)

Figure 5: Offences added or recast by the 2008 Amendment, as enacted; Sections 67C and 72A were decriminalised and Section 69B revised by the Jan Vishwas Act from 30 November 2023 (see Topic 40)

  • Section 66 recast. 'Hacking' was replaced by computer related offences: any Section 43 act done dishonestly or fraudulently. This linked civil and criminal liability in a single test.
  • Sections 66B to 66F. Receiving stolen computer resources (66B), identity theft (66C), cheating by personation (66D), violation of privacy through images of private areas (66E), and cyber terrorism (66F), which covers denial of access, unauthorised penetration or introducing contaminants with intent to threaten India's unity, integrity, security or sovereignty or strike terror, and knowingly accessing restricted information that may be used against the State.
  • Section 66A. Offensive messages, later struck down in Shreya Singhal (2015)
  • Section 67 and Sections 67A to 67C. Punishment under Section 67 reduced to three years and fine up to ₹5 lakh on first conviction; new offences of sexually explicit material (67A) and child sexual abuse material, including browsing, downloading and online grooming (67B); and a duty on intermediaries to preserve and retain information (67C)

Powers of Interception, Blocking and Monitoring: Sections 69, 69A and 69B

  • Section 69 recast. The Controller's decryption power was replaced by a power of the Central or State Government to direct interception, monitoring or decryption of any information on grounds including sovereignty, security of the State, public order, preventing incitement and investigation of any offence.
  • Section 69A inserted. Power of the Central Government to block public access to information on similar grounds, with an intermediary's failure to comply punishable with up to seven years.
  • Section 69B inserted. Power to authorise monitoring and collection of traffic data to enhance cyber security.

Critical Information Infrastructure: Sections 70, 70A and 70B

  • Section 70 recast. Protected systems linked to critical information infrastructure, defined as computer resources whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety; power to prescribe information security practices (s.70(4))
  • Section 70A inserted. National nodal agency for critical information infrastructure protection, later NCIIPC (designated in 2014)
  • Section 70B inserted. CERT-In as the national agency for incident response, with power to call for information and issue directions, and punishment for non-compliance (s.70B(7))

Revised Intermediary Safe Harbour: Section 79

  • New structure. Section 79(1) grants immunity for third-party information, notwithstanding any other law; Section 79(2) sets the conditions of a passive role and due diligence; Section 79(3) removes protection for conspiracy, abetment or inducement, and for failure to remove content on actual knowledge or government notification.
  • Change from 2000. From a defence that the provider had to prove, limited to offences under the Act, to a general conditional immunity for all intermediaries under any law, with a new, wider definition of intermediary.
  • Later interpretation. Due diligence was elaborated by the Intermediary Guidelines of 2011 and 2021, and 'actual knowledge' was read down in Shreya Singhal (2015)

Evidence, Encryption and Procedure

  • Section 79A. The Central Government may notify any department, body or agency as an Examiner of Electronic Evidence to give expert opinion before courts and authorities; a corresponding Section 45A was inserted in the Evidence Act.
  • Section 84A. The Central Government may prescribe modes or methods of encryption for secure use of the electronic medium and promotion of e-governance and e-commerce.
  • Section 84B. Abetment of any offence under the Act is punishable with the punishment for the offence if the act is committed in consequence of the abetment.
  • Section 84C. Attempt to commit an offence is punishable with up to half of the longest term of imprisonment, or fine, or both.
  • Sections 77A and 77B. Compounding by a competent court of offences punishable with up to three years, with exclusions; offences punishable with three years or more made cognizable, and offences punishable with three years made bailable.
  • Sections 78 and 80. Investigating and search powers given to an Inspector instead of a Deputy Superintendent of Police.
  • Section 81. A proviso preserved rights under the Copyright Act, 1957 and the Patents Act, 1970.
  • Other laws. Clause (3) was added to Section 4 of the IPC for offences targeting computer resources in India, and the Evidence Act was amended accordingly.
  • Tribunal. The Cyber Regulations Appellate Tribunal was renamed the Cyber Appellate Tribunal and given a Chairperson and members (see Topic 30)

5. Rules That Followed

  • 2009. Rules on interception, monitoring and decryption (s.69), blocking (s.69A) and traffic data (s.69B)
  • 2011. The SPDI Rules (s.43A), the first Intermediary Guidelines (s.79) and rules for cyber cafes.
  • 2013 and after. Rules for CERT-In and NCIIPC, the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021, and the CERT-In Directions of 2022.

6. The IT Act Before and After 2008

Key provisions before and after the 2008 Amendment

Figure 6: Key provisions before and after the 2008 Amendment

7. Assessment

Achievements and criticisms

Figure 7: Achievements and criticisms

⚠ Exam trap

Two common mistakes. First, writing that the 2008 Amendment increased every punishment: it created many new offences but reduced the punishment for obscenity under Section 67 and made most offences bailable under Section 77B. Secondly, dating it wrongly: passed in December 2008, Act 10 of 2009, assent 5 February 2009, in force 27 October 2009.

8. Quick Revision and Memory Aids

  • 'Rebuilding while occupied'. The foundation stayed, the rest was renovated.
  • '66 B-C-D-E-F: stolen, identity, disguise, exposure, fear'. The new offences.
  • '67 A-B-C: adult, boy or girl, cache'. Explicit material, child abuse material, retention.
  • '69 listens, 69A blocks, 69B counts traffic'. State powers.
  • '70 guards, 70A plans, 70B responds'. CII, NCIIPC, CERT-In.
  • '79 from defence to shield'. The intermediary change.
  • '84 A-B-C: algorithm, abettor, attempt'. Encryption, abetment, attempt.

9. Frequently Asked Questions

Why was the IT Act amended in 2008?

To make signatures technology-neutral, to address new forms of cybercrime such as identity theft, phishing, voyeurism, child abuse material and cyber terrorism, to impose data protection duties, to clarify intermediary liability, and to create statutory bodies and powers for cyber security.

10. Related Topics

  • Topic 28: Legislative History and Original Framework. What the Act looked like before 2008.
  • Topic 7: Enforcement under the IT Act. How the 2008 provisions work today.