Concept Page
Information Technology Act 2000
The Information Technology Act 2000 is a law regulating cyber activities in India. It signifies the government's effort to address cybercrime. The Act amended the Indian Penal Code and Indian Evidence Act.
The Information Technology Act 2000 (IT Act) is India’s primary legislation governing electronic commerce, digital signatures, and cyber‑related offences. Enacted on 9 June 2000 and brought into force on 17 October 2000, it created a legal framework that recognised electronic records and signatures as equivalent to paper documents, thereby enabling the rapid growth of e‑business, online banking, and government‑to‑citizen services. By amending the Indian Penal Code (IPC) and the Indian Evidence Act, the Act filled a statutory vacuum that had left cyber‑crimes unaddressed and provided the state with tools to combat hacking, phishing, and other forms of digital misconduct.
Historical Background
The IT Act emerged from a series of government committees in the late 1990s, notably the 1997 “Committee on Information Technology” chaired by Justice B.N. Srikrishna, which recommended statutory recognition of electronic contracts. The legislation was introduced under the Ministry of Communications and Information Technology (later merged into the Ministry of Electronics and Information Technology, MeitY) to align India with the United Nations’ “Model Law on Electronic Commerce” of 1996. Its passage coincided with a 300 percent increase in internet users between 1998 and 2000, prompting Parliament to act swiftly to protect both consumers and service providers in the nascent digital economy.
Key Provisions
Section 43 imposes civil liability for damage caused by unauthorized access to computer systems, prescribing compensation ranging from ₹5,000 to ₹250,000 per incident. Section 66 criminalises hacking, with penalties of up to three years’ imprisonment and a fine of ₹5 lakh, while Section 66A—introduced in the 2008 amendment to penalise “grossly offensive” online content—was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015). Section 67 bans the transmission of obscene material, prescribing up to three years’ imprisonment and a fine of ₹5 lakh. Sections 69 and 69A empower the government to intercept, monitor, and block public access to electronic information in the interest of sovereignty, security, or public order, with the latter requiring a procedural order from the Secretary‑in‑Charge of the Ministry.
Mechanism and Institutional Framework
The Act’s definition of “electronic record” under Section 5, coupled with Section 65’s provision that such records are admissible in court without the need for physical evidence, transformed judicial practice. Digital signatures, validated by Certifying Authorities (CAs) licensed by the Controller of Certifying Authorities (CCA), acquire legal effect under Section 5(2), enabling secure online transactions for entities ranging from the Income Tax Department to private e‑retail platforms. Dispute resolution is overseen by the now‑defunct Cyber Appellate Tribunal (established in 2000, dissolved in 2012), whose jurisdiction was transferred to the High Courts, ensuring that cyber‑related appeals receive specialised judicial scrutiny.
Amendments and Evolution
The Information Technology (Amendment) Act 2008 introduced Sections 66B‑66F to address identity theft, phishing, and cyber‑terrorism, expanding punishments to up to ten years’ imprisonment for offences involving critical infrastructure. It also created Section 79, granting “intermediary immunity” to platforms that act as mere conduits, provided they observe due diligence—a provision that underpins the liability framework for social media giants such as Facebook and Twitter. The 2015 Supreme Court judgment invalidated Section 66A, prompting a legislative review that led to the 2021 draft Personal Data Protection Bill, which, while separate, builds on the IT Act’s data‑security foundations.
Current Implementation and Significance
As of 2023, MeitY reports over 1,200 registered Certifying Authorities and more than 2 million digital signatures issued, facilitating the e‑filing of income tax returns for roughly 80 percent of Indian taxpayers. The Ministry’s Cyber Crime Investigation Cell recorded 1.2 million cyber‑crime complaints in 2022, a 28 percent rise from the previous year, reflecting both increased reporting and the Act’s expanding scope. Critics argue that the Act’s procedural safeguards for interception (Section 69) lack transparent oversight, while the absence of a comprehensive data‑protection regime leaves personal information vulnerable. Nonetheless, the IT Act remains the legal backbone of India’s digital transformation, underpinning everything from the Election Commission’s electronic voting infrastructure to the AI‑powered cyber‑war rooms being set up by state police forces.
Articles that reference this concept
The NEET Leak: A Test of Institutional Accountability
Read →SIET Launches Digital Content Platform to Preserve Indian Arts and Boost Classroom Learning
Read →**What Happened and Why It Matters**
Read →How UPI Works: The Technical Backbone
Read →Cybercrime Impersonation Case and Political Corruption Allegations: Legal Frameworks Under Scrutiny
Read →