All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Sections 71 to 74 IT Act: Misrepresentation, Confidentiality and Certificate Offences

Sections 71 to 74 protect the honesty of the electronic signature and data ecosystem from four directions: lies told to the regulator to obtain a licence or certificate (s.71), secrets disclosed by those who obtained access under the Act's own powers (s.72), personal information disclosed by service providers in breach of contract (s.72A), and false or fraudulent certificates put into circulation (ss.73, 74). Two of the four, Sections 72 and 72A, were converted into civil penalties by the Jan Vishwas Act from 30 November 2023, so precision about their current character matters. This note covers each provision, the current sanctions, and the comparisons that separate the overlapping data provisions.

1. The Four Provisions in One View

Sections 71 to 74 at a glance

Figure 1: Sections 71 to 74 at a glance

  • What joins them. Each guards a different point of trust: the regulator's records (s.71), the State's handling of what it collects (s.72), the service provider's handling of what customers entrust (s.72A), and the certificates on which relying parties act (ss.73, 74)
  • Current character. Sections 71, 73 and 74 remain offences punishable with up to two years or ₹1 lakh or both; Sections 72 and 72A are civil penalties since 30 November 2023, adjudicated under Section 46.

2. Section 71: Misrepresentation

Section 71, Information Technology Act, 2000

Whoever makes any misrepresentation to, or suppresses any material fact from, the Controller or the Certifying Authority for obtaining any licence or Electronic Signature Certificate, as the case may be, shall be punished with imprisonment for a term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.

The elements of Section 71

Figure 2: The elements of Section 71

  • Misrepresentation to the Controller. False statements in a licence application under Section 21 or its renewal: inflated net worth, non-existent infrastructure, concealed disqualifications. A licence so obtained is also revocable under Section 25(1)(a)
  • Misrepresentation to a Certifying Authority. False particulars in a certificate application under Section 35: another person's identity documents, a forged authorisation, a fake organisational letter. The certificate is revocable under Section 38(2)(a), and the misrepresentation is separately punishable here.
  • Suppression of material fact. The provision expressly covers silence: withholding a fact that would have influenced the grant is as culpable as stating a falsehood. Materiality is judged by whether the Controller or CA would have acted differently had it known.
  • Positioning. Section 71 punishes lies at the point of entry; Sections 73 and 74 punish false certificates in circulation; and identity theft in the application process can add Section 66C where another's identity features are used.

3. Section 72: Breach of Confidentiality and Privacy

Section 72, Information Technology Act, 2000 (sanction as amended in 2023)

Save as otherwise provided in this Act or any other law for the time being in force, any person who, in pursuance of any of the powers conferred under this Act, rules or regulations made thereunder, has secured access to any electronic record, book, register, correspondence, information, document or other material without the consent of the person concerned discloses such electronic record, book, register, correspondence, information, document or other material to any other person shall be liable to a penalty which may extend to five lakh rupees.

  • Access obtained under the powers of the Act. The provision binds those who see private material because the Act let them: the Controller and his officers, adjudicating officers, investigators exercising s.29 access, CERT-In personnel handling incident data, Certifying Authority staff, and interception personnel. It does not reach a hacker, whose access was never in pursuance of any power.
  • Disclosure without consent. The wrong is complete on disclosure of the material to any other person without the consent of the person concerned; no wrongful intent is required, and no harm need be shown.
  • Section 72 and privacy. For years this was the Act's only general confidentiality guarantee, the assurance that surveillance, adjudication and regulation would not become leakage. The saving clause preserves disclosures the Act or another law itself authorises, such as reports to CERT-In or evidence produced in proceedings.
  • The sanction today. Formerly up to two years or ₹1 lakh or both; since 30 November 2023 a civil penalty of up to ₹5 lakh, adjudicated under Section 46 with appeal to TDSAT.

4. Section 72A: Disclosure in Breach of Lawful Contract

Section 72A, Information Technology Act, 2000 (sanction as amended in 2023)

Any person including an intermediary who, while providing services under the terms of lawful contract, has secured access to any material containing personal information about another person, with the intent to cause or knowing that he is likely to cause wrongful loss or wrongful gain discloses, without the consent of the person concerned, or in breach of a lawful contract, such material to any other person, shall be liable to a penalty which may extend to twenty-five lakh rupees.

  • Personal information under a lawful contract. Inserted in 2008 for the outsourcing economy: the call centre agent, the payroll processor, the app with access to contacts, the hospital billing vendor, each holds personal information only because a services contract gave access.
  • The mental element. Intent to cause, or knowledge of the likelihood of, wrongful loss or wrongful gain, carrying the penal code meanings. An accidental leak is not a s.72A contravention, though it may engage s.43A against the employer.
  • Two modes of wrong. Disclosure without the consent of the person concerned, or disclosure in breach of the lawful contract; either suffices once the mental element is present.
  • Unauthorised disclosure by service providers. The typical cases: an employee selling customer databases, a banking correspondent passing account details to fraudsters, an app transferring personal data against its own terms.
  • The sanction today. Formerly up to three years or ₹5 lakh or both; since 30 November 2023 a civil penalty of up to ₹25 lakh. The decriminalisation is the standing criticism of the Jan Vishwas changes, since the individual victim has lost the criminal complaint route (Topic 40)

Sections 72 and 72A compared

Figure 3: Sections 72 and 72A compared

Section 72A beside Section 43A and the DPDP Act

Figure 4: Section 72A beside Section 43A and the DPDP Act

  • Section 72 vs Section 72A. Different actors (those empowered by the Act against those contracted for services), different material (any accessed material against personal information), different mental elements (none against intent or knowledge), and different amounts (₹5 lakh against ₹25 lakh)
  • Section 72A vs Section 43A. 72A pursues the person who deliberately disclosed; 43A extracts compensation from the body corporate whose negligent security allowed the loss. One leak can engage both, against different defendants (Topic 54)
  • Section 72A vs the DPDP Act. 72A is a one-clause wrong with a penalty for the discloser; the DPDP Act imposes a full duty structure on the Data Fiduciary with Board penalties up to ₹250 crore, but no compensation and no offence. After full commencement the two operate side by side: the employer answers to the Board, the disclosing individual under s.72A.

5. Sections 73 and 74: The Certificate Offences

The two certificate offences

Figure 5: The two certificate offences

  • Publishing a false certificate (s.73). Publishing an Electronic Signature Certificate, or making it available to any other person, knowing that the Certifying Authority listed in it has not issued it, or the subscriber listed has not accepted it, or it has been suspended or revoked. Each limb attacks a different falsehood: a forged issuance, a certificate the subscriber never stood behind, and a dead certificate presented as alive.
  • The saving. Publication for the purpose of verifying a signature created before the suspension or revocation remains lawful, which protects archives and long-term validation (Topic 41)
  • Publication for fraudulent purpose (s.74). Knowingly creating, publishing or otherwise making available a certificate for any fraudulent or unlawful purpose. Unlike s.73, it covers creation itself, so the maker of a fake certificate is caught even before anyone relies on it.
  • Punishment and setting. Each carries up to two years, or fine up to ₹1 lakh, or both. They protect the reliance chain of Sections 35 to 39 and 41: a relying party checks a certificate precisely because the law polices its truth (Topics 51, 52). Where the fake certificate is used to cheat or forge, ss.66C, 66D and the BNS forgery provisions stack on.

⚠ Exam trap

Dates and character first: Sections 72 and 72A are civil penalties of ₹5 lakh and ₹25 lakh since 30 November 2023, while Sections 71, 73 and 74 remain offences at two years or ₹1 lakh. Keep the actors straight: s.72 binds those who gained access under the Act's powers, s.72A those who gained it under a services contract; and remember that s.72A, unlike s.72, demands intent or knowledge of wrongful loss or gain.

6. Frequently Asked Questions

What is the difference between Section 72 and Section 72A?

Section 72 applies to any person who secured access to records or information in pursuance of powers under the Act and disclosed the material without the consent of the person concerned; no wrongful intent is required, and the penalty is up to ₹5 lakh. Section 72A applies to any person, including an intermediary, who obtained access to personal information while providing services under a lawful contract and disclosed it without consent or in breach of the contract, with intent to cause or knowledge of likely wrongful loss or gain; the penalty is up to ₹25 lakh. Both became civil penalties on 30 November 2023.

When is publishing an Electronic Signature Certificate an offence?

Under Section 73, when it is published or made available with knowledge that the listed Certifying Authority did not issue it, the listed subscriber did not accept it, or it stands suspended or revoked, except publication to verify a signature created before the suspension or revocation. Under Section 74, knowingly creating, publishing or making available a certificate for any fraudulent or unlawful purpose is an offence. Each is punishable with up to two years, or fine up to ₹1 lakh, or both.

7. Related Topics

  • Topic 54: Section 43A and the SPDI Rules. The negligence-based companion to Section 72A.
  • Topic 51: Electronic Signature Certificates. The certificates Sections 73 and 74 protect.