Information Technology Act, 2000
Section-Wise Structure of the IT Act, 2000: Chapters, Sections and Schedules
Judiciary papers often ask for the substance of a named section, or test whether a candidate knows where a provision sits in the Act. This note is a complete section-wise guide to the Information Technology Act, 2000 as it stands today, after the 2008 Amendment, the Finance Act, 2017 and the 2022 Schedule notification. Each chapter is introduced, and every section is explained in a line or two, with cross-references to the topics that treat it in depth. Changes provided for by the Jan Vishwas Act, 2023 and the DPDP Act, 2023 are flagged where relevant.
1. Reading the Act Like a Map
A city map is easier to use once you know the districts: the old town, the business district, the courts, the police lines. The IT Act has six districts. Chapters I to V lay the foundation of recognition; Chapters VI to VIII build the trust infrastructure of signatures; Chapters IX and X provide civil enforcement; Chapter XI is the criminal quarter; Chapters XII and XIIA deal with platforms and evidence; and Chapter XIII with the Schedules holds the general provisions. Learn the districts first, then the streets.
Figure 1: Six districts of the IT Act
Figure 2: The chapters of the Act as it stands today
2. Chapter I: Preliminary (Sections 1 and 2)
- Section 1: short title, extent, commencement and application. The Act extends to the whole of India and, save as otherwise provided, applies to offences or contraventions committed outside India by any person (s.1(2)); comes into force on notified dates (s.1(3)); does not apply to documents or transactions in the First Schedule, which the Central Government may amend by notification (s.1(4)); and every such notification is laid before Parliament (s.1(5))
- Section 2: definitions. Section 2(1) defines over forty terms, from 'access' to 'verify'. Section 2(2) provides that references to an enactment not in force in an area are to be read as references to the corresponding law in force there.
Figure 3: Twelve definitions every candidate should know
- Other definitions to note. Adjudicating officer (c), appropriate Government (e), asymmetric crypto system (f), Certifying Authority (g), certification practice statement (h), computer network (j), computer system (l), Controller (m), Appellate Tribunal (n), cyber cafe (na), digital signature (p), electronic form (r), Electronic Gazette (s), Electronic Signature Certificate (tb), Indian Computer Emergency Response Team (ua), key pair (x), private and public key (zc, zd), secure system (ze), security procedure (zf) and subscriber (zg)
3. Chapter II: Digital Signature and Electronic Signature (Sections 3 and 3A)
- Section 3: authentication of electronic records. A subscriber may authenticate an electronic record by affixing a digital signature (s.3(1)), effected by an asymmetric crypto system and hash function (s.3(2)); anyone can verify it using the subscriber's public key (s.3(3)); and the private and public keys are unique to the subscriber and form a functioning key pair (s.3(4))
- Section 3A: electronic signature. A subscriber may authenticate by any electronic signature or authentication technique that is reliable and specified in the Second Schedule (s.3A(1)); reliability depends on the five conditions in s.3A(2); the Central Government may prescribe how to ascertain whose signature it is (s.3A(3)), and add or omit techniques from the Second Schedule (s.3A(4)), laying the notification before Parliament (s.3A(5)). See Topics 6 and 13.
4. Chapter III: Electronic Governance (Sections 4 to 10A)
- Section 4: legal recognition of electronic records. A legal requirement of writing is satisfied by information in electronic form that is accessible for subsequent reference.
- Section 5: legal recognition of electronic signatures. A legal requirement of signature is satisfied by an electronic signature affixed in the prescribed manner.
- Section 6: use in Government. Filing of forms, issue of licences and permits, and receipt and payment of money may be done electronically in the prescribed manner.
- Section 6A: delivery of services by service provider. The appropriate Government may authorise service providers to deliver e-services and collect service charges on a specified scale.
- Section 7: retention of electronic records. Retention requirements are met by electronic records that remain accessible, are kept in an accurate format and carry origin, destination and time details.
- Section 7A: audit of documents maintained electronically. Laws providing for audit apply equally to electronic records.
- Section 8: publication in Electronic Gazette. Publication in the Electronic Gazette satisfies a requirement to publish in the Official Gazette; the date of first publication in either is the date of publication.
- Section 9: no right to insist. Sections 6, 7 and 8 confer no right to insist that any authority accept, issue, retain or pay in electronic form.
- Section 10: rules regarding electronic signature. The Central Government may prescribe the type of signature, manner and format of affixing, identification procedures, and controls ensuring integrity, security and confidentiality.
- Section 10A: validity of contracts formed through electronic means. A contract is not unenforceable merely because the proposal, acceptance or revocation was expressed electronically. See Topics 6 and 16.
Figure 4: The e-governance provisions at a glance
5. Chapter IV: Attribution, Acknowledgment and Despatch (Sections 11 to 13)
- Section 11: attribution of electronic records. A record is attributed to the originator if sent by the originator, by a person authorised to act for the originator, or by an information system programmed by or for the originator to operate automatically.
- Section 12: acknowledgment of receipt. If no form is stipulated, any communication or conduct indicating receipt is enough; if the originator made the record binding only on acknowledgment, it is deemed never sent until acknowledgment is received; otherwise the originator may give notice and treat the record as not sent if acknowledgment does not come within the time allowed.
- Section 13: time and place of despatch and receipt. Despatch occurs when the record enters a computer resource outside the originator's control; receipt depends on whether a computer resource was designated; the record is deemed despatched at the originator's place of business and received at the addressee's place of business, with rules for principal place of business and usual residence. See Topics 4 and 15.
6. Chapter V: Secure Electronic Records and Secure Electronic Signatures (Sections 14 to 16)
- Section 14: secure electronic record. Where a security procedure has been applied to an electronic record at a specific point of time, the record is deemed secure from that time to the time of verification.
- Section 15: secure electronic signature. An electronic signature is deemed secure if the signature creation data was, at the time of affixing, under the exclusive control of the signatory, and was stored and affixed in the prescribed exclusive manner; for a digital signature, the signature creation data is the private key.
- Section 16: security procedures and practices. The Central Government may prescribe security procedures for Sections 14 and 15, having regard to commercial circumstances and the nature of transactions. Secure records and signatures carry presumptions under Sections 86 and 87 of the BSA.
7. Chapter VI: Regulation of Certifying Authorities (Sections 17 to 34)
Figure 5: The chain of trust
- Section 17: Controller and other officers. Appointment of the Controller of Certifying Authorities and Deputy and Assistant Controllers by the Central Government.
- Section 18: functions of Controller. Supervising Certifying Authorities, certifying their public keys, laying down standards and conditions, specifying certificate contents, resolving conflicts and maintaining a disclosure database.
- Section 19: recognition of foreign Certifying Authorities. With Central Government approval, by notification, revocable for breach of conditions.
- Section 20. Omitted in 2008 (formerly, the Controller as repository of signatures)
- Sections 21 to 24: licence. Licence required to issue electronic signature certificates (s.21); application (s.22); renewal (s.23); grant or rejection only after a reasonable opportunity of being heard (s.24)
- Sections 25 and 26: suspension and revocation. Revocation for false statements, breach of licence conditions, failure to maintain procedures or contravention of the Act, after inquiry, with suspension of up to ten days pending inquiry (s.25); publication of the suspension or revocation in the Controller's database (s.26)
- Section 27: power to delegate. The Controller may delegate powers to Deputy or Assistant Controllers or officers.
- Sections 28 and 29: investigation and access. Power to investigate contraventions (s.28) and to access any computer system and data where there is reasonable cause to suspect a contravention of the Chapter (s.29)
- Sections 30 to 34: duties of Certifying Authorities. Follow secure procedures and ensure secrecy and privacy of signatures (s.30); ensure compliance by employees (s.31); display the licence (s.32); surrender a suspended or revoked licence (s.33); and disclose certificates, practice statements and material adverse facts (s.34)
8. Chapter VII: Electronic Signature Certificates (Sections 35 to 39)
- Section 35: issue of certificate. Any person may apply with a fee (up to ₹25,000) and a practice statement; the Certifying Authority may grant or, after a hearing and with reasons, reject.
- Section 36: representations upon issuance. The Certifying Authority represents that it has complied with the Act, that the subscriber holds the private key corresponding to the public key, that the keys form a functioning pair, and that the information in the certificate is accurate.
- Section 37: suspension. On the subscriber's request or in the public interest, for up to 15 days without a hearing.
- Section 38: revocation. On the subscriber's request, death or dissolution, or where a material fact was misrepresented, a requirement was not met, or the private key or system was compromised.
- Section 39: notice of suspension or revocation. Publication in the repository specified in the certificate.
9. Chapter VIII: Duties of Subscribers (Sections 40 to 42)
- Section 40: generating key pair. The subscriber must generate the key pair by applying the security procedure.
- Section 40A: duties of subscriber of electronic signature certificate. Inserted in 2008: perform duties as prescribed.
- Section 41: acceptance of certificate. By publishing or authorising publication of the certificate, the subscriber certifies that they hold the private key and that the information and representations are true.
- Section 42: control of private key. The subscriber must take reasonable care to retain control of the private key, communicate any compromise to the Certifying Authority without delay, and remains liable until then.
10. Chapter IX: Penalties, Compensation and Adjudication (Sections 43 to 47)
- Section 43: penalty and compensation for damage to computer. Unauthorised access, downloading, viruses, damage, disruption, denial of access, assistance, charging services to another, destroying or altering information, and stealing source code (clauses (a) to (j)), with compensation to the person affected; explanations define computer contaminant, computer database, computer virus, damage and computer source code.
- Section 43A: compensation for failure to protect data. Body corporate negligent in maintaining reasonable security practices for sensitive personal data; to be omitted by the DPDP Act, scheduled for May 2027.
- Section 44: failure to furnish information. Penalties for failure to furnish documents or returns to the Controller or a Certifying Authority, or to maintain books or records.
- Section 45: residuary penalty. For contraventions with no separate penalty: since 2023, a penalty of up to ₹1 lakh plus compensation of up to ₹10 lakh (intermediaries, companies) or ₹1 lakh (others)
- Section 46: power to adjudicate. Adjudicating officers of the rank of Director to the Government of India or equivalent, with experience in information technology and legal or judicial matters, decide claims up to ₹5 crore after a hearing, with powers of a civil court.
- Section 47: factors. Gain or unfair advantage, loss caused, and repetitive nature of the default. See Topics 7 and 12.
11. Chapter X: The Appellate Tribunal (Sections 48 to 64)
- Section 48: Appellate Tribunal. TDSAT is the Appellate Tribunal from 26 May 2017 (Finance Act, 2017)
- Sections 49 to 54 and 56. Omitted in 2017 (composition, qualifications, term, salary, superintendence, business, transfer, majority, vacancies, removal, staff)
- Section 55. Orders constituting the Appellate Tribunal are final and do not invalidate its proceedings.
- Section 57: appeal. From the Controller or an adjudicating officer within 45 days; not from consent orders; to be decided, if possible, within six months.
- Section 58: procedure and powers. Guided by natural justice, not bound by the CPC, with civil court powers including review.
- Section 59: legal representation. Appearance in person or through legal practitioners or officers.
- Section 60: limitation. The Limitation Act, 1963 applies to appeals.
- Section 61: civil court not to have jurisdiction. Barred for matters within the officer's or tribunal's jurisdiction, and no injunction against action under the Act, except for claims above ₹5 crore.
- Section 62: appeal to High Court. Within 60 days on any question of fact or law, extendable by 60 days.
- Section 63: compounding of contraventions. By the Controller, an authorised officer or the adjudicating officer, but not for a repeat within three years.
- Section 64: recovery. As arrears of land revenue, with suspension of the licence or certificate until payment. See Topic 30.
Figure 6: How disputes move through Chapters IX and X
12. Chapter XI: Offences (Sections 65 to 78)
Figure 7: The principal offences and their punishments
- Section 65: tampering with computer source documents. Concealing, destroying or altering source code required to be kept by law.
- Section 66: computer related offences. Any Section 43 act done dishonestly or fraudulently.
- Section 66A: offensive messages. Struck down in Shreya Singhal (2015); omitted by the Jan Vishwas Act, 2023.
- Sections 66B to 66F. Receiving stolen computer resource (66B); identity theft (66C); cheating by personation using computer resource (66D); violation of privacy (66E); cyber terrorism (66F)
- Sections 67 to 67C. Obscene material (67); sexually explicit material (67A); child sexual abuse material (67B); preservation and retention by intermediaries (67C, penalty up to ₹25 lakh since 2023)
- Section 68: Controller's directions. Power of the Controller to direct a Certifying Authority; non-compliance attracts a penalty of up to ₹25 lakh since 2023.
- Sections 69, 69A and 69B. Interception, monitoring and decryption (69); blocking of public access (69A); monitoring and collection of traffic data (69B)
- Sections 70, 70A and 70B. Protected systems and critical information infrastructure (70); national nodal agency, NCIIPC (70A); CERT-In (70B)
- Sections 71 to 74. Misrepresentation (71); breach of confidentiality and privacy by persons acting under the Act (72, penalty up to ₹5 lakh since 2023); disclosure in breach of lawful contract (72A, penalty up to ₹25 lakh since 2023); publishing false certificates (73); publication for fraudulent purpose (74)
- Sections 75 to 78: application and procedure. Offences committed outside India (75); confiscation (76); compensation and penalties not to interfere with other punishment (77); compounding (77A); cognizable and bailable offences (77B); investigation by an Inspector (78). See Topics 7 and 10.
13. Chapters XII and XIIA: Intermediaries and the Examiner of Electronic Evidence
- Section 79: exemption from liability of intermediary. No liability for third-party information (s.79(1)) if the intermediary only provides access, does not initiate, select the receiver or modify, and observes due diligence (s.79(2)); protection lost for conspiracy, abetment or failure to remove on actual knowledge or government notification (s.79(3)). See Topics 7, 17 and 22.
- Section 79A: Examiner of Electronic Evidence. The Central Government may notify any department, body or agency as an Examiner of Electronic Evidence to give expert opinion before courts and authorities. See Topics 9 and 24.
Figure 8: The Section 79 safe harbour
14. Chapter XIII: Miscellaneous (Sections 80 to 90)
Figure 9: The miscellaneous provisions
- Section 80. A police officer not below the rank of Inspector, or an authorised officer, may enter a public place, search and arrest without warrant any person reasonably suspected of an offence under the Act.
- Section 81. Overriding effect, with a proviso preserving rights under the Copyright and Patents Acts, to which the DPDP Act will add itself.
- Section 81A. The Act applies to electronic cheques and truncated cheques, with modifications notified by the Central Government in consultation with the RBI.
- Sections 82 to 84. Tribunal members, adjudicating officers, the Controller and their staff are public servants (82); the Central Government may give directions to State Governments (83); and action in good faith is protected (84)
- Sections 84A to 84C. Modes of encryption (84A); abetment (84B); attempt, punishable with up to half the longest term (84C)
- Section 85. Offences by companies: persons in charge of and responsible for the company's business are liable, unless they prove lack of knowledge or due diligence.
- Section 86. Removal of difficulties by order, within two years of commencement.
- Sections 87 to 90. Central rule-making power, including clause (ob) for Section 43A, to be omitted by the DPDP Act (87); the Cyber Regulations Advisory Committee (88); regulations by the Controller (89); and State rule-making power for Section 6 (90)
- Sections 91 to 94. Omitted. They amended the IPC, the Evidence Act, the Bankers' Books Evidence Act and the RBI Act; those amendments survive in the amended Acts under Section 6A of the General Clauses Act.
15. The Schedules
Figure 10: The First, Second and omitted Third and Fourth Schedules
- First Schedule. Documents to which the Act does not apply, narrowed by the 2022 notification (see Topic 27)
- Second Schedule. Recognised electronic signature and authentication techniques, including Aadhaar-based e-authentication since 2015.
- Third and Fourth Schedules. Omitted; they contained the original amendments to the Bankers' Books Evidence Act and the RBI Act.
⚠ Exam traps Section numbers are often confused. Remember: 43 is civil, 66 is criminal; 43A is data protection, 72A is disclosure in breach of contract; 69 is interception, 69A blocking, 69B traffic data; 70A is NCIIPC, 70B is CERT-In; 79 is the safe harbour, 79A the Examiner of Electronic Evidence; 81 is overriding effect, 81A electronic cheques. Chapter X no longer establishes its own tribunal; Section 48 designates TDSAT and Sections 49 to 54 and 56 are omitted. |
16. Quick Revision and Memory Aids
- 'Six districts'. Foundation, trust, civil, criminal, platforms and evidence, general.
- '4 writes, 5 signs, 10A binds'. Recognition sections.
- '11 attributes, 12 acknowledges, 13 locates'. Chapter IV.
- '17 appoints, 18 functions, 19 foreign, 21 licenses'. Chapter VI.
- '35 issues, 37 suspends, 38 revokes'. Chapter VII.
- '57 to TDSAT in 45, 62 to High Court in 60'. Chapter X.
- '80 to 90, then 91 to 94 gone'. Chapter XIII.
17. Frequently Asked Questions
How many chapters does the IT Act have today?
Fourteen, counting Chapter XIIA on the Examiner of Electronic Evidence: Chapters I to XIII, with XIIA inserted in 2008, plus the First and Second Schedules.
What does Section 81A provide?
That the Act applies to electronic cheques and truncated cheques, subject to such modifications as the Central Government, in consultation with the RBI, may notify.
18. Related Topics
- Topic 1: Introduction, Object and Scope. The Act in outline.
- Topic 27: Amendment History. How the sections came to read as they do.