Business Regulations (COM3CJ201) — Module 4: Cyber Law & Information Technology Act, 2000
Lecture Notes • Complete Study Material
- MODULE IV: CYBER LAW & INFORMATION TECHNOLOGY ACT, 2000 Genesis, International Origins & Objectives of Cyber Law Cyber law is the field of law dealing with the legal issues related to the use of networked information technology, computers, cyberspace, software, and electronic communications. In India, cyber jurisprudence is primarily codified in the Information Technology Act, 2000 (Act No. 21 of 2000), which received Presidential assent on June 9, 2000, and came into force on October 17, 2000. The Act was enacted pursuant to Resolution A/RES/51/162 adopted by the General Assembly of the United Nations on January 30, 1997, which commended the adoption of the UNCITRAL Model Law on Electronic Commerce (1996) to ensure global legal uniformity. The Act was substantially overhauled by the Information Technology (Amendment) Act, 2008 (Act No. 10 of 2009) to incorporate technology-neutral electronic signatures, address sophisticated cybercrimes, data privacy, and intermediary liabilities.
1. Objectives, Scope and Extraterritorial Jurisdiction of the IT Act, 2000 The preamble of the Information Technology Act, 2000 outlines its fundamental objectives:
To grant legal recognition for transactions carried out by means of electronic data interchange and other means of electronic communication (commonly referred to as "Electronic Commerce").
To substitute paper-based methods of communication and storage of information with electronic alternatives, facilitating electronic filing of documents with government agencies (E-Governance).
To amend the Indian Penal Code, 1860, the Indian Evidence Act, 1872, the Bankers' Books Evidence Act, 1891, and the Reserve Bank of India Act, 1934 to harmonize general law with electronic evidence and fund transfers.
To prevent, regulate, and penalize computer-related offences, data theft, and unauthorized network intrusions.
TERRITORIAL SCOPE AND EXTRATERRITORIAL APPLICATION (SECTIONS 1 & 75) Jurisdictional Mandate Territorial Jurisdiction (Section 1(2)) The Act extends to the whole of India and also applies to any offence or contravention committed outside India by any person irrespective of his nationality, subject to Section 75.
Extraterritorial Jurisdiction (Section 75) The provisions of this Act apply to any offence or contravention committed outside India by any person, regardless of his nationality, if the act or conduct constituting the offence involves a computer, computer system, or computer network located within India.
Documents and Transactions Excluded from the IT Act (First Schedule) Under Section 1(4), the Information Technology Act does not apply to the following documents and instruments:
1. A negotiable instrument (other than a cheque) as defined in Section 13 of the Negotiable Instruments Act, 1881.
- A power-of-attorney as defined in: Section 1A of the Powers-of-Attorney Act, 1882.
- A trust as defined in: Section 3 of the Indian Trusts Act, 1882.
- A will as defined in clause (h) of: Section 2 of the Indian Succession Act, 1925, including any other testamentary disposition.
5. Any contract for the sale or conveyance of immovable property or any interest in such property.
- Fundamental: Statutory Definitions (Section 2) The IT Act, 2000 provides precise statutory definitions for critical technical constructs under Section 2:
Computer & Computer System (Sec 2(1)(i) & (l)) "Computer" means any electronic, magnetic, optical or other high-speed data processing device or system which performs logical, arithmetic, and memory functions by manipulations of electronic, magnetic or optical impulses, and includes all input, output, processing, storage, computer software, or communication facilities. "Computer System" means a device or collection of devices, including input and output support devices and excluding calculators which are not programmable and capable of being used in conjunction with external files, which contain computer programmes, electronic instructions, input data and output data.
Computer Network (Section 2(1)(j)) Means the interconnection of one or more computers or computer systems through:
The use of satellite, microwave, terrestrial line or other communication media; and Terminals or a complex consisting of two or more interconnected computers whether or not the interconnection is continuously maintained.
Electronic Record (Section 2(1)(t)) Means data, record or data generated, image or sound stored, received or sent in an electronic form or micro film or computer generated micro fiche.
Includes emails, digital databases, web files, log files, and multimedia recordings.
Intermediary (Section 2(1)(w)) With respect to any particular electronic records, means any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record; includes telecom service providers, network providers, ISPs, web-hosting service providers, search engines, online payment sites, online auction sites, and online marketplaces.
- Electronic: Governance (E-Governance: Sections 4 to 10) The Act provides functional equivalence to electronic communications and records, effectively placing paper documents and digital records on the same statutory footing:
Legal Recognition of Electronic Records (Section 4): Where any law provides that information shall be in writing, typewritten or printed, such requirement is deemed satisfied if rendered in an electronic form accessible so as to be usable for subsequent reference.
Legal Recognition of Electronic Signatures (Section 5): Where any law requires an individual signature, that requirement is deemed satisfied if authenticated by an electronic signature affixed in an approved statutory manner.
Use of Electronic Records and Signatures in Government Agencies (Section 6): Permits electronic filing of forms, applications, issue of licenses, sanctions, approvals, and receipt or payment of money through designated electronic portals.
Retention of Electronic Records (Section 7): Prescribes that statutory document retention requirements are satisfied if the electronic record remains accessible, is preserved in its original format, and retains transmission details (origin, destination, time of dispatch).
Audit of Documents Kept in Electronic Form (Section 7A): Recognizes statutory audit of accounts and documents maintained in digital systems.
Legal Recognition of Electronic Contracts (Section 10A): Validates agreements formed through electronic communications; contracts shall not be unenforceable solely because electronic forms or records were utilized.
- Cryptographic: Foundations: Digital Signatures vs. Electronic Signatures Authentication of electronic records is achieved through mathematical cryptography and public key infrastructure (PKI). The original IT Act 2000 recognized only asymmetric digital signatures; the 2008 Amendment adopted the broader, technology-neutral concept of Electronic Signatures (Section 3A).
ASYMMETRIC CRYPTOGRAPHY & PUBLIC KEY INFRASTRUCTURE (PKI) WORKFLOW ======================================================================================== [SENDER / SIGNER] [RECIPIENT / VERIFIER] Electronic Document Electronic Document | | v v +------------------+ +------------------+ | One-Way Hash | ====> Hash Value (Message Digest) | One-Way Hash | ====> Computed Hash | Function (SHA-2) | | Function (SHA-2) | +------------------+ +------------------+ | | v | Hash Value + Signer's PRIVATE KEY | | | v | [DIGITAL SIGNATURE CREATED] ========================================> [SIGNATURE VERIFIED] (Transmitted over Network) | v Signature + Signer's PUBLIC KEY | v Decrypted Original Hash | v [COMPARE]: Does Decrypted Hash == Computed Hash?
- IF YES: Authenticity & Integrity Proven!
- IF NO: Document Altered or Forged! ======================================================================================== Feature Digital Signature (Section 3) Electronic Signature (Section 3A) Technological Framework Strictly based on Asymmetric Cryptosystem and one-way Hash function (PKI technology).
Technology-neutral; includes PKI digital signatures as well as Aadhaar e-Sign, biometric, and cryptographic tokens listed in the Second Schedule.
Statutory Scope A specific species under the broader genus of electronic signatures.
The comprehensive statutory umbrella term under Section 3A (introduced in 2008).
Key Infrastructure Mandates a mathematical Key Pair:
Private Key (for signing) and Public Key (for verification).
May rely on key pairs, Aadhaar-linked OTP verification, or trusted authentication service providers.
Certification Requirement Issued exclusively by a licensed Certifying Authority (CA) under the Controller of Certifying Authorities (CCA).
May be authenticated through designated electronic signature service providers recognized by the Central Government.
Evidentiary Status Presumption of authenticity under Section 85B of the Indian Evidence Act, 1872.
Presumption of authenticity applies if the e-signature complies with statutory security procedures (Section 85B).
5. Attribution, Acknowledgment and Despatch of Electronic Records (Sections 11 to 13) Attribution of Electronic Records (Section 11) An electronic record is legally attributed to the originator if it was sent:
By the originator himself; By a person authorized to act on behalf of the originator; or By an information system programmed by or on behalf of the originator to operate automatically.
Acknowledgment of Receipt (Section 12) Where the originator has requested or agreed that receipt be acknowledged:
Any communication by addressee, automated or manual, or conduct indicating receipt, constitutes valid acknowledgment.
If originator specified acknowledgment as a condition precedent, record is treated as never sent until acknowledged.
If no time fixed, within a reasonable time. Time and Place of Despatch and Receipt (Section 13) Section 13 resolves the legal complexity of determining where and when an electronic contract is concluded:
Time of Despatch (Sec 13(1)): Occurs when the electronic record enters a computer resource outside the control of the originator.
Time of Receipt (Sec 13(2)): If addressee has designated a computer resource: (i) Occurs when record enters the designated computer resource; or (ii) If sent to a non-designated resource, when retrieved by addressee.
If addressee has not designated a computer resource: Occurs when record enters any computer resource of the addressee.
Place of Despatch & Receipt (Sec 13(3)): Electronic record is deemed despatched at the originator's principal place of business, and deemed received at the addressee's principal place of business, regardless of where the computer server is physically located.
- Regulatory: Architecture: Controller of Certifying Authorities (CCA) & CAs Chapter VI of the IT Act (Sections 17 to 34) establishes the regulatory oversight for digital trust. The Central Government appoints a Controller of Certifying Authorities (CCA) to supervise Certifying Authorities (CAs).
Functions of the Controller (Section 18) Exercising supervision over the activities of Certifying Authorities.
Certifying public keys of Certifying Authorities. Laying down standards and operational codes of practice for CAs.
Specifying qualification and experience requirements for CA personnel.
Specifying the terms and conditions for grant of CA licenses.
Maintaining a National Repository of Digital Certificates.
- Role of Certifying Authorities (CAs: Sections 21–24) Any person can apply to the CCA for a license to issue Digital Signature Certificates (DSC).
- Licensed CAs in India include: e-Mudhra, NIC, IDRBT, SafeScrypt, NSDL, CDAC.
CAs verify identity and issue Class 1, Class 2, or Class 3 DSCs to subscribers.
CAs must maintain Certificate Revocation Lists (CRL) and publish public keys.
- Electronic: Contracts: Types, Validity & Enforceability Under Section 10A (inserted by the 2008 Amendment), where in a contract formation, the communication of proposals, acceptance of proposals, the revocation of proposals and acceptances are expressed in electronic form or by means of an electronic record, such contract shall not be deemed to be unenforceable solely on the ground that such electronic form or means was used and for that purpose the provisions of Section 10A shall apply.
- Click-Wrap: Agreements Agreements where the user manifests assent to the contractual terms by clicking an "I Agree", "Accept", or "Submit" button before software installation, account creation, or digital checkout. Widely upheld as legally binding if terms are visible.
- Shrink-Wrap: Agreements Terms and conditions printed on the physical packaging of software disks or tech products.
Opening the plastic shrink-wrap film or tearing the seal is legally construed as constructive acceptance of the license terms.
- Browse-Wrap: Agreements Terms linked via a hyperlink at the bottom of a website. User is purported to accept terms simply by browsing or utilizing website services. Enforceability requires clear, prominent notice to the visitor.
8. Cyberspace, Cyber Crimes & Typology Cyberspace is the virtual, interconnected digital environment where communications over computer networks occur. A Cyber Crime is an unlawful act wherein a computer is either a tool, a target, or both.
COMPREHENSIVE TAXONOMY OF CYBER CRIMES Threat Landscape Crimes Against Individuals
- Cyber Stalking: Repeated electronic monitoring, harassment, and threatening communications online.
- Identity Theft: Fraudulent appropriation of another individual's personal identifiable information (PAN, Aadhaar, credit cards).
- Phishing & Vishing: Deceptive emails and counterfeit web portals designed to harvest banking credentials.
- Cyber Defamation: Publishing defamatory statements against individuals across social networks and blogs.
Crimes Against Property & Organizations
- Hacking & Data Theft: Unauthorized intrusion into server databases and exfiltration of proprietary trade secrets.
- Denial of Service (DoS / DDoS): Overwhelming a target web server with automated traffic requests to render it inaccessible.
- Ransomware & Malware: Malicious encryption of victim's databases followed by extortion demands in cryptocurrency.
- Online Financial Fraud: Unauthorized electronic fund transfers, ATM skimming,
UPI payment frauds. Crimes Against Society & State Cyber Terrorism (Section 66F): Digital attacks threatening the unity, integrity, security, or sovereignty of India.
Child Sexual Abuse Material (CSAM / Sec 67B): Publishing, generating, transmitting, or browsing online child exploitation material.
- Cyber Warfare: State-sponsored espionage targeting critical national infrastructure (power grids, nuclear systems, air traffic).
Digital Intellectual Property Infringements
- Cybersquatting: Bad-faith registration of established corporate trademarks as internet domain names.
- Digital Piracy: Unauthorized peer-topeer downloading, torrent distribution, and streaming of copyrighted films and software.
- Meta-Tag Infringement: Embedding rival trademarks into web source code to divert search engine traffic.
9. Penalties, Compensation and Adjudication (Chapter IX: Sections 43 to 47) Chapter IX of the Act deals with civil contraventions where the remedy is primarily monetary compensation to the victim, distinct from criminal imprisonment.
Civil Liability for Damage to Computer System (Section 43) If any person without permission of the owner or person in charge of a computer: (a) Accesses or secures access to such computer, computer system or computer network; (b) Downloads, copies, or extracts any data, computer database or information; (c) Introduces or causes to be introduced any computer contaminant or computer virus; (d) Damages or causes to be damaged any computer, computer database, or other programmes; (e) Disrupts or causes disruption of any computer, computer system or computer network; (f) Denies or causes the denial of access to any person authorized to access the computer; (g) Provides assistance to any person to facilitate unauthorized access; (h) Charges the services availed of by a person to the account of another person; (i) Destroys, deletes or alters any information residing in a computer resource; (j) Steals, conceals, destroys or alters any computer source code;
He shall be liable to pay compensation to the person so affected (up to several crores depending on actual loss assessed by the Adjudicating Officer).
Corporate Responsibility for Data Protection (Section 43A) Introduced by the 2008 Amendment, Section 43A holds a body corporate possessing, dealing, or handling any Sensitive Personal Data or Information (SPDI) strictly liable to pay compensation if it is negligent in implementing and maintaining reasonable security practices and procedures, thereby causing wrongful loss or wrongful gain to any person.
Adjudicating Officer (Section 46) The Central Government appoints an officer not below the rank of Director to the Government of India or an equivalent state government officer (often the State IT Secretary) as an Adjudicating Officer. He has the powers of a civil court to summon witnesses, discover documents, and adjudicate claims for compensation under Chapter IX.
- Appellate Jurisdiction: TDSAT (Section 48 to 64) Originally, appeals lay to the Cyber Appellate Tribunal (CyAT). Under the Finance Act 2017 amendments, all powers and jurisdiction of the Cyber Appellate Tribunal were merged into the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). Any person aggrieved by an order of the Adjudicating Officer may file an appeal before TDSAT within 45 days. Appeals against TDSAT lie before the High Court (Section 62). 10. Offences, Criminal Liabilities & Punishments (Chapter XI) Chapter XI (Sections 65 to 78) details statutory criminal offences under the IT Act, investigated by specialized cyber police cells and tried before criminal courts.
Section Offence Description Statutory Ingredients Maximum Punishment Sec 65 Tampering with Computer Source Documents Knowingly or intentionally concealing, destroying, or altering computer source code required to be kept by law.
Imprisonment up to 3 years and/or fine up to INR 2,00,000.
Sec 66 Computer Related Offences (Hacking) Committing any act referred to in Section 43 dishonestly or fraudulently.
Imprisonment up to 3 years and/or fine up to INR 5,00,000.
Sec 66B Receiving Stolen Computer Resource / Data Dishonestly receiving or retaining any stolen computer resource or communication device.
Imprisonment up to 3 years and/or fine up to INR 1,00,000.
Sec 66C Identity Theft Fraudulently or dishonestly making use of electronic signature, password or unique identification feature of another person.
Imprisonment up to 3 years and fine up to INR 1,00,000.
Sec 66D Cheating by Personation using Computer Cheating by personating someone through any computer resource or communication device.
Imprisonment up to 3 years and fine up to INR 1,00,000.
Sec 66E Violation of Privacy Intentionally capturing, publishing, or transmitting images of private area of an individual without consent.
Imprisonment up to 3 years and/or fine up to INR 2,00,000.
Sec 66F Cyber Terrorism Attacking computer systems with intent to threaten the unity, integrity, security, or sovereignty of India or strike terror.
Imprisonment for Life. Sec 67 Publishing Obscene Material in Electronic Form Transmitting or publishing lascivious material or material appealing to prurient interests. 1st conviction: 3 yrs + INR 5L; 2nd conviction: 5 yrs + INR 10L.
Sec 67A Publishing Material with Sexually Explicit Act Publishing or transmitting electronic material containing sexually explicit act or conduct. 1st conviction: 5 yrs + INR 10L; 2nd conviction: 7 yrs + INR 10L.
Sec 67B Child Sexual Abuse Material (CSAM) Publishing, transmitting, collecting, or searching child pornography or depiction of children in sexually explicit acts. 1st conviction: 5 yrs + INR 10L; 2nd conviction: 7 yrs + INR 10L.
Sec 72 Breach of Confidentiality & Privacy Any person securing access to electronic records disclosing them without consent of the person concerned.
Imprisonment up to 2 years and/or fine up to INR 1,00,000.
Section Offence Description Statutory Ingredients Maximum Punishment Sec 72A Disclosure of Information in Breach of Contract Intermediary or service provider disclosing personal info in breach of lawful contract with intent to cause wrongful loss.
Imprisonment up to 3 years and/or fine up to INR 5,00,000.
- Landmark Constitutional Jurisprudence: The Demise of Section 66A Shreya Singhal v. Union of India (AIR 2015 SC 1523): Section 66A penalized sending "offensive" or "menacing" messages through communication devices with up to 3 years imprisonment. The Supreme Court struck down Section 66A in its entirety as unconstitutional, ruling that it violated the fundamental right to freedom of speech and expression under Article 19(1)(a) of the Constitution of India.
The Court held that the section suffered from the vices of vagueness and overbreadth, failed to distinguish between mere advocacy and incitement to violence, had a chilling effect on legitimate speech, and was not saved by reasonable restrictions under Article 19(2). 11. Intermediary Liability and Safe Harbour Provisions (Section 79) Section 79 provides a Safe Harbour immunity protecting internet intermediaries (like social media networks, cloud platforms, e-commerce marketplaces) from third-party liabilities, provided they comply with statutory prerequisites:
The function of the intermediary is limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored;
The intermediary does not initiate the transmission, select the receiver of the transmission, or select/modify the information contained in the transmission;
The intermediary observes due diligence while discharging its duties under the Act and complies with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
Upon receiving "actual knowledge" (a court order or government takedown notice), the intermediary must expeditiously remove or disable access to unlawful content (as settled in Shreya Singhal v. Union of India). 12. Intellectual Property Rights (IPR) in Cyberspace Cyberspace introduces novel and complex challenges to the protection and enforcement of intellectual property rights:
- Copyright: Issues in Cyberspace
- Computer Software: Computer source code and object code are protected as "literary works" under Section 2(o) of the Indian Copyright Act, 1957.
- Digital Piracy: Unauthorized copying, peerto-peer sharing, and unauthorized downloading constitute copyright infringement under Section 51.
- Website Content: Text, UI design, photographs, graphics, and digital architecture are copyrighted works.
- Anti-Circumvention: Sections 65A and 65B of the Copyright Act prohibit circumventing Technological Protection Measures (TPM) and altering Rights Management Information (RMI).
- Trademark: Issues & Domain Name Disputes
- Domain Names as Trademarks: A domain name serves not merely as an internet address but as a commercial business identifier equivalent to a trademark.
- Cybersquatting: Registering well-known trademarks as domain names in bad faith to sell them at exorbitant prices to the rightful owner.
- Dispute Resolution: Resolved globally through ICANN's Uniform Domain-Name Dispute-Resolution Policy (UDRP) and domestically through the .IN Dispute Resolution Policy (INDRP) under NIXI.
- Landmark: Cyber Law Precedent Matrix Case Name & Citation Facts & Substantive Legal Issue Judicial Holding & Legal Ratio State of Tamil Nadu v.
Suhas Katti (2004 CMM Court, Chennai) Accused posted defamatory, obscene messages regarding a divorced woman in a Yahoo group, soliciting obscene phone calls to her.
First conviction in India under Section 67 of the IT Act, 2000. Accused convicted and sentenced to 2 years rigorous imprisonment and fine within 7 months of filing chargesheet.
Yahoo! Inc. v. Akash Arora (1999 FSR 249 Del HC) Defendant registered the domain name 'YahooIndia.com' to offer internet directory services similar to plaintiff's 'Yahoo.com'.
Delhi High Court held that a domain name performs the same function as a trademark. Passing off injunction granted; bad faith imitation of domain name restrained.
Christian Louboutin SAS v. Nakul Bajaj (2018 Del HC) E-commerce website 'darveys.com' sold luxury footwear bearing plaintiff's trademark without authorization.
Delhi High Court delineated boundary of Section 79 Intermediary Safe Harbour:
Active participants that promote, package, or guarantee authenticity cannot claim passive intermediary immunity.
Avnish Bajaj v. State (Bazee.com Case) (2005 116 DLT 427 Del HC) Obscene video clip was listed for auction by a third-party user on Bazee.com. CEO Avnish Bajaj was arrested under Sec 67.
Led to Parliament enacting the 2008 Amendment to insert Section 79 (Safe Harbour) and Section 43A, distinguishing corporate platform liability from usergenerated content crimes. 14. Investigation, Search, Seizure and Police Powers (Section 78) Special Procedural Safeguards in Cybercrime Investigation Under Section 78 of the Act (as amended in 2008), notwithstanding anything contained in the Code of Criminal Procedure, 1973, a police officer not below the rank of Inspector shall investigate any offence under this Act.
Section 80 empowers any police officer, not below the rank of Inspector, to enter any public place, search and arrest without warrant any person who is reasonably suspected of having committed or being about to commit any offence under the Act. Section 69 empowers the Central or State Government to issue directions for the interception, monitoring, or decryption of any information through any computer resource in the interest of sovereignty, security, public order, or investigation of offences.
Download Module 4 Notes (PDF)
Calicut University • FYUGP 2024 Syllabus
Finished this module?
Continue reading the next module or return to the subject overview.