munotes®

Information Technology Cyber Laws Notes | LL.M. Semester 3 | Mumbai University | munotes

Official Notes munotes.in

Information Technology Cyber Laws

LL.M. · SEMESTER 3

Strictly as per the University of Mumbai LL.M. syllabus in force, with every provision read from the Act, the Rules and the Gazette as amended to 10-02-2026

For LL.M. students of the University of Mumbai and all its affiliated law colleges

Open the book ↓

munotes.in Group 3 Law of Intellectual Property and Information Technology

Information Technology Cyber Laws

Copyright © 2026 munotes.in. All rights reserved.

Written and first published by munotes.in, 2026.

This book is free for individual students to read at munotes.in. No part of it may be reproduced, distributed, stored, translated or used for institutional or classroom purposes in any form without a prior written licence from munotes.in.

Licensing and permissions: contact@munotes.in

The text of statutes and of judgments reproduced in this book is in the public domain under section 52(1)(q) of the Copyright Act 1957. The commentary, arrangement, examples and questions are the original work of munotes.in.

munotes.in is an independent study resource for MU students. It is not affiliated with, endorsed by, or officially connected to the University of Mumbai. Course names and university references describe the students and syllabus the material relates to.

munotes.in

Contents

Module I

  1. What Information Technology Is 1
  2. How a Computer Holds Information 7
  3. How the Internet Works 12
  4. Cyberspace, and the Trouble with Territory 17
  5. How India Came to Have an Information Technology Act 21
  6. The UNCITRAL Model Law on Electronic Commerce 26
  7. The Functional Equivalent Approach 32
  8. The Model Law on the Communication of Data Messages 39
  9. The Model Law on Carriage of Goods 46
  10. The UNCITRAL Model Law on Electronic Signatures 51
  11. How India Enacted the Model Law 59
  12. The Scheme of the Information Technology Act 66
  13. Short Title, Extent and Application 72
  14. The First Schedule: What the Act Does Not Touch 76
  15. The Definitions, Part One: the Machine 81
  16. The Definitions, Part Two: the People and the Transaction 88
  17. The Objects of the Act, and What Each Part Does 95
  18. The Information Technology (Amendment) Act, 2008 100
  19. What Has Changed Since 2008 105
  20. What Information Security Means 111
  21. Threats, Attacks and How They Work 116
  22. Secure Electronic Records and Secure Signatures 121
  23. Reasonable Security Practices and the SPDI Rules 126
  24. Using the Act in Practice 134

Module II

  1. What a Signature Does 139
  2. Cryptography for Lawyers 144
  3. The Hash Function and the Hash Value 150
  4. Authentication of Electronic Records: Section 3 155
  5. Electronic Signature and the Second Schedule 160
  6. Legal Recognition of Electronic Records and Signatures 167
  7. Digital Signature Against Electronic Signature 173
  8. The Electronic Signature Certificate 178
  9. Suspension and Revocation of a Certificate 184
  10. The Duties of a Subscriber 190
  11. What Electronic Governance Is 196
  12. Electronic Records in Government: Sections 6 to 9 201
  13. Delivery of Services by a Service Provider 207
  14. E-Governance in Practice: DigiLocker and e-KYC 213
  15. The Power to Make Rules on Electronic Signature 219
  16. The Controller of Certifying Authorities 222
  17. The Controller's Powers of Investigation 227
  18. Recognition of Foreign Certifying Authorities 233
  19. Licensing a Certifying Authority 238
  20. Suspension and Revocation of a Licence 245
  21. The Duties of a Certifying Authority 251
  22. The Certifying Authorities Rules in Outline 258
  23. Why Software Is Hard to Protect 263
  24. Copyright in a Computer Programme 269
  25. Who Owns the Software, and For How Long 275
  26. Infringement of Software Copyright, and the Exceptions 281
  27. Software Patents in India 288
  28. Trade Secrets and the Employment Contract 294
  29. Semiconductor Layout Designs 300
  30. Licensing Software: Proprietary and Open Source 306
  31. Software Piracy and Its Enforcement 312

Module III

  1. Why Compare Cyber Laws 318
  2. Three Models of Regulating the Network 324
  3. The United Nations and Cyber Law 329
  4. The Budapest Convention: the Offences 335
  5. The Budapest Convention: Procedure and Co-operation 343
  6. India in Comparison 351
  7. The United States: the Constitutional Frame 357
  8. The Computer Fraud and Abuse Act 363
  9. Section 230 and the American Safe Harbour 369
  10. The DMCA: Notice and Takedown 375
  11. Europe: the e-Commerce Directive 381
  12. The General Data Protection Regulation: the Scheme 387
  13. The GDPR: Rights and the Controller's Duties 395
  14. The GDPR: Transfers and Enforcement 404
  15. eIDAS and Electronic Signatures in Europe 415
  16. The Digital Services Act 423
  17. China: the Cybersecurity Law 434
  18. China: Data Security and Personal Information 444
  19. The Five Systems Side by Side 455
  20. What Cyber Security Means in Law 462
  21. CERT-In and Incident Reporting 468
  22. The CERT-In Directions of 2022 475
  23. Protected Systems and Critical Information Infrastructure 482
  24. The National Cyber Security Policy, and After 490
  25. Interception, Monitoring and Decryption 496
  26. Blocking Public Access to Information 505
  27. Monitoring Traffic Data for Cyber Security 513
  28. Encryption and the Law 521
  29. Jurisdiction: the Five Bases 527
  30. The Act Reaching Outside India 532
  31. Civil Jurisdiction Over an Internet Dispute 538
  32. Where an Electronic Contract Is Made 544
  33. Getting Evidence from Abroad 550
  34. Conflicting Orders and the Global Takedown 557
  35. Data Localisation and Cross-Border Data Flows 564

Module IV

  1. What an Electronic Contract Is 571
  2. Offer and Acceptance Online 577
  3. The Validity of an Electronic Contract: Section 10A 584
  4. Attribution of an Electronic Record 590
  5. Acknowledgment of Receipt 596
  6. Enforcing an Electronic Contract 601
  7. Consumer Protection in Electronic Commerce 608
  8. Electronic Payments and Their Law 615
  9. Artificial Intelligence and the 2026 Amendment 622
  10. Deepfakes, Labelling and Provenance 629
  11. Cryptocurrency and Virtual Digital Assets 637
  12. Blockchain and the Smart Contract 644
  13. Cloud Computing and the Internet of Things 651
  14. Privacy After Puttaswamy 657
  15. The Digital Personal Data Protection Act, 2023 664
  16. The Data Protection Board and Enforcement 674
  17. Domain Names and Cybersquatting 684
  18. Internet Shutdowns and Access to the Internet 692
  19. What a Cyber Crime Is 699
  20. Penalty and Compensation: Section 43 705
  21. The Residuary Penalties 711
  22. Adjudication Under the Act 717
  23. Compounding and Recovery 725
  24. The Appellate Tribunal Today 731
  25. The Cyber Appellate Tribunal, and What Happened to It 739
  26. Appeals to the Tribunal, and Beyond 746
  27. Tampering with Computer Source Documents 753
  28. Computer Related Offences: Section 66 760
  29. Section 66A, and Shreya Singhal 766
  30. Receiving a Stolen Computer Resource, and Identity Theft 773
  31. Cheating by Personation, and Violation of Privacy 778
  32. Obscenity in Electronic Form 786
  33. Material Depicting Children 794
  34. Preservation and Retention by Intermediaries 800
  35. Breach of Confidentiality and Privacy 806
  36. Investigating a Cyber Offence 813
  37. Proving a Cyber Offence: Electronic Evidence 820
  38. The IT Act and the General Penal Law 830
  39. Confiscation, Abetment, Attempt and Companies 839
  40. Compounding, Bail and the Shape of a Prosecution 846
  41. What Cyber Terrorism Is 852
  42. Section 66F Broken Down 858
  43. Cyber Terrorism Beside the UAPA and the Sanhita 865
  44. Modes of Cyber Terrorism, and the Response 872
  45. Social Media in Law 879
  46. Intermediary Liability and the Safe Harbour 889
  47. The Code of Ethics and the Three-Tier Mechanism 898
  48. Crimes Committed Through Social Media 907
  49. Non-Consensual Images, Morphing and Revenge Pornography 913
  50. Fake News, Misinformation and the Fact Check Unit 919
  51. Grievance Redress and Reporting a Cyber Crime 926
  52. The Closing Provisions of the Act 932
  53. Cyber Cafes as a Worked Example of Due Diligence 940
munotes.in

Module I

munotes.in

Chapter One

What Information Technology Is

Syllabus topic 1.1, "Introduction to Information Technology"

In one line

Information technology is the use of computers and networks to create, store, move and use information.

In the wording a student can write in an exam: information technology is the set of techniques by which information is captured, represented in a form a machine can process, stored, transmitted over a network and presented back to a human being, together with the hardware and software that do the work.

Why a lawyer has to know this

You cannot apply a statute to a machine you cannot describe. The Information Technology Act, 2000 does not talk about computers loosely. It defines a computer, a computer system, a computer network and a computer resource as four different things, gives each a different definition in section 2, and then attaches different consequences to each. Section 43 penalises access to a computer, computer system or computer network. Section 66F speaks of a computer resource. If you cannot tell those apart, you cannot say which offence a set of facts discloses.

The University asks this directly. The 2024-25 paper set a short note on the distinction between "computer", "computer system" and "computer network". The 2016 paper asked what the term information technology means and what the benefits of its application are. Neither can be answered by a student who has only read about law.

And the whole of Module III depends on it. Jurisdiction over a transnational cyber crime turns on where a server sits, whose network the traffic crossed and which country's law reached the machine. That is a technical question before it is a legal one.

The four things a computer does

Every computer, from a phone to a data centre, does four things. It takes in data, which is the input. It performs arithmetic and logic on that data, which is the processing. It keeps data for later, which is the storage. It gives results back, which is the output. Everything else is detail.

The Act's own definition follows exactly that shape. Section 2(1)(i) defines a computer as any electronic, magnetic, optical or other high-speed data processing device or system which performs logical, arithmetic, and memory functions by manipulations of electronic, magnetic or optical impulses, and includes all input, output, processing, storage, computer software or communication facilities which are connected or related to the computer in a computer system or computer network.

Notice three things about that definition. It is technology neutral: it says electronic, magnetic, optical or other, so a technology invented tomorrow is inside it. It is functional: the test is whether the device performs logic, arithmetic and memory functions, not what it looks like. And it is inclusive: the input and output devices, the storage and the software are all part of the computer, so seizing a computer means seizing the keyboard, the monitor and the hard disk too.

munotes.in1

What Information Technology Is

A smartphone is a computer under this definition, and so is the electronic control unit in a modern car, a smart television, and the card reader at a shop counter. Anything that processes data at high speed by manipulating impulses qualifies. Section 2(1)(ha) separately defines a communication device to mean cell phones, personal digital assistance or a combination of both or any other device used to communicate, send or transmit any text, video, audio or image, so a phone is both.

Hardware

Hardware is the physical part: the machine you could drop on your foot. Four pieces matter for law.

The processor, often called the CPU or central processing unit, is the part that actually performs the arithmetic and logic. It holds no data of its own for more than an instant. Nothing useful for an investigation survives in it once the power goes off.

Memory, usually called RAM or random access memory, is the working space. It is fast, it is where a running program and its current data sit, and it is volatile: switch the machine off and its contents are gone. That single fact drives a rule of digital forensics, that a live machine at a crime scene should be imaged before it is switched off, because what is in memory at that moment includes decryption keys and open network connections that will never be recovered afterwards.

Storage, the hard disk or solid state drive, is where data survives a power cut. It is what is seized, imaged and examined. It matters legally that deleting a file usually does not erase the data: it marks the space as reusable, so the content remains until it is overwritten, which is why a deleted file is often recoverable and why an accused cannot assume that pressing delete has ended the matter.

Input and output devices are the keyboard, the mouse, the camera, the screen, the printer and the network card. Section 2(1)(l) expressly includes input and output support devices in the definition of a computer system.

Software

Software is the set of instructions that tells the hardware what to do. It is not a physical thing. It is a sequence of instructions, written by a human being in a language a human being can read and then translated into a form the machine executes.

Source code is the human-readable version. A programmer writes lines that another programmer can read and change. Object code, or machine code, is the version the processor executes, and it is unreadable to a person. The translation from one to the other is done by a program called a compiler.

munotes.in2

What Information Technology Is

That distinction carries a whole section of the Act. Section 65 makes it an offence to knowingly or intentionally conceal, destroy or alter computer source code, and its Explanation defines computer source code to mean the listing of programmes, computer commands, design and layout and programme analysis of computer resource in any form. Source code is what a business actually owns and what a departing employee can take. Chapter 1170 works section 65 in full.

Software divides into two kinds. System software runs the machine itself: the operating system, such as Windows, Android, macOS or a Linux distribution, and the drivers that let it speak to hardware. Application software does a job for the user: a browser, a spreadsheet, a banking app. Malware is application software written to do harm, and chapter 210 works its varieties.

Data, and the difference between data and information

Data is raw. Information is data that means something. The number 9820044556 is data. The statement that it is Meera's mobile number is information.

The Act keeps the two apart and defines each separately, which is unusual and deliberate. Section 2(1)(o) defines data as a representation of information, knowledge, facts, concepts or instructions which are being prepared or have been prepared in a formalised manner, and is intended to be processed, is being processed or has been processed in a computer system or computer network, and may be in any form, including computer printouts and magnetic or optical storage media, or stored internally in the memory of the computer.

Section 2(1)(v) defines information to include data, message, text, images, sound, voice, codes, computer programmes, software and data bases or micro film or computer generated micro fiche.

So under the Act, information is the wider word and data is inside it. A printout is data, because the definition says so in terms. That matters: a person who steals a printed report has taken data within the meaning of section 43(b), even though nothing electronic was touched at the moment of taking.

Networks

A network is two or more computers connected so that they can exchange data. Section 2(1)(j) defines a computer network as the inter-connection of one or more computers or computer systems or communication devices through the use of satellite, microwave, terrestrial line, wire, wireless or other communication media, and terminals or a complex consisting of two or more interconnected computers or communication devices, whether or not the inter-connection is continuously maintained.

The last nine words carry weight. "Whether or not the inter-connection is continuously maintained" means a network exists even when the connection is intermittent. A phone that connects to a server only when the user opens an app is still part of a computer network for the purposes of the Act.

munotes.in3

What Information Technology Is

Chapter 30 works out how the internet, the largest network there is, actually moves data, because every jurisdictional question in Module III depends on it.

The four words the Act uses, side by side

TermSectionWhat it coversThe point of it
Computer2(1)(i)One high-speed data processing device, with its input, output, storage, software and communication facilitiesThe individual machine
Computer system2(1)(l)A device or collection of devices, including input and output support devices, containing programmes, instructions and data, that performs logic, arithmetic, storage, retrieval and communication control. Excludes a calculator that is not programmableThe machine plus everything it needs to work as a unit
Computer network2(1)(j)The interconnection of computers, computer systems or communication devices by any mediumTwo or more machines joined
Computer resource2(1)(k)Computer, computer system, computer network, data, computer data base or softwareThe widest word: it reaches the data and the software as well as the machines

Computer resource is the widest of the four and the one to watch. It is the only one that includes data, a database and software, so an offence framed in terms of a computer resource reaches things that are not machines at all. Sections 66F, 69, 69A, 69B and 79 are all drafted using it.

A worked example

Meera runs a small logistics business in Vashi. She keeps her consignment records in a spreadsheet on a desktop computer in her office. The desktop is connected by cable to a printer and to a second machine used by her accountant, and both connect through a router to the internet, where she uses a cloud service to back the spreadsheet up each night.

Rohit, a former employee, uses a password he still knows to log in from home and delete three months of records.

Now apply the vocabulary. The desktop is a computer under section 2(1)(i). The desktop together with its keyboard, monitor and printer is a computer system under section 2(1)(l). The desktop, the accountant's machine, the router and the cloud server are together a computer network under section 2(1)(j), and the interconnection is not continuous, which the definition says does not matter. The spreadsheet file is data under section 2(1)(o) and also information under section 2(1)(v). All of it is a computer resource under section 2(1)(k).

Rohit has gained entry into the memory function resources of a computer, which is access as defined in section 2(1)(a), and he has done so without Meera's permission. That engages section 43. Because he did it dishonestly, it also engages section 66. Chapters 1100 and 1180 work those two sections in full; the point here is that not one of those conclusions can be reached without the vocabulary.

munotes.in4

What Information Technology Is

What this does NOT mean

It does not mean the Act only applies to the internet. Nothing in the definitions requires a network at all. A standalone machine with no connection is a computer, and altering data on it is caught by section 43(i) exactly as if it were online.

It does not mean a calculator is a computer system. Section 2(1)(l) expressly excludes calculators which are not programmable and capable of being used in conjunction with external files. A programmable one is not excluded.

It does not mean information technology law is only the IT Act. The Act is the centre of it, but copyright in software is in the Copyright Act 1957, the general offences that a cyber crime also discloses are in the Bharatiya Nyaya Sanhita 2023, the proof of an electronic record is in the Bharatiya Sakshya Adhiniyam 2023, and personal data will be governed by the Digital Personal Data Protection Act 2023. Chapter 120 maps the whole field.

Quick revision

  • Information technology: capturing, representing, storing, transmitting and presenting information by machine, with the hardware and software that do it.
  • Four functions: input, processing, storage, output. The Act's definition of a computer follows exactly that shape.
  • Section 2(1)(i) computer: high-speed data processing device performing logic, arithmetic and memory functions, including its input, output, storage, software and communication facilities.
  • Section 2(1)(l) computer system: device or collection of devices, excluding a non-programmable calculator.
  • Section 2(1)(j) computer network: interconnection by any medium, whether or not continuously maintained.
  • Section 2(1)(k) computer resource: the widest term. Computer, computer system, computer network, data, database or software.
  • Section 2(1)(o) data against section 2(1)(v) information: information is the wider word and includes data.
  • Source code is human-readable; object code is what the machine runs. Section 65 protects source code.
  • RAM is volatile; storage is not. Deleting a file usually does not erase it.

Test yourself

1. Give the statutory definition of a computer and say what three features it has. Section 2(1)(i): any electronic, magnetic, optical or other high-speed data processing device or system which performs logical, arithmetic and memory functions by manipulations of impulses, including its input, output, processing, storage, software and communication facilities. It is technology neutral, functional rather than descriptive, and inclusive of the peripherals and the software.

2. Ravi photographs a printed customer list belonging to his employer and sells it. Has he taken "data"? Yes. Section 2(1)(o) says data may be in any form "including computer printouts", so a printout of processed data is data. Whether an offence under the Act is made out depends on the other sections, but the object taken is data.

munotes.in5

What Information Technology Is

3. Which of the four terms is the widest, and why does it matter? Computer resource, in section 2(1)(k), because it alone includes data, a computer database and software as well as the machines. It matters because the sections dealing with cyber terrorism, interception, blocking and intermediary liability are all drafted around it, so their reach is not limited to hardware.

4. Is an unconnected laptop outside the Act? No. The definitions do not require connectivity. A standalone machine is a computer and a computer system, and offences such as those in section 43 and section 66 apply to it.

5. Why does the distinction between source code and object code matter in law? Because section 65 makes it an offence to conceal, destroy or alter computer source code required to be kept by law, and because copyright litigation over software usually turns on access to and comparison of source code, which the object code does not reveal.

Contents This chapter on its own page

munotes.in6

Chapter Two

How a Computer Holds Information

Syllabus topic 1.1, "Introduction to Information Technology"

In one line

A computer holds everything as numbers, and the law's problems with electronic records all follow from that one fact.

In the wording a student can write in an exam: a computer represents all information, whether text, image, sound or instruction, as sequences of binary digits, organised into files and described by metadata, and stored on media from which it can be copied perfectly and altered without visible trace.

Why this matters to a lawyer

Three of the hardest questions in this subject are consequences of how storage works. Why does an electronic record need a certificate before a court will look at it? Because a copy is indistinguishable from the original, so the law needs some other assurance that it has not been altered. Why does the law speak of preserving and retaining information rather than of keeping documents? Because the thing to be preserved has no physical existence and will be overwritten unless somebody stops it. Why is a deleted file recoverable? Because deletion usually removes the pointer, not the content.

A student who does not know this can memorise section 63 of the Bharatiya Sakshya Adhiniyam and still not know why it exists. The whole of chapter 1270 depends on the paragraphs below.

Bits, bytes and why everything is a number

A bit is a single binary digit: it is either 0 or 1. That is the smallest thing a computer can hold, because the underlying hardware can reliably distinguish only two states, such as charged and not charged, or magnetised one way and the other.

Eight bits make a byte, and a byte can hold 256 different values. Everything else is a convention about what those values mean.

Text is a number by agreement. The letter A is stored as the number 65 under a standard called ASCII, and the standard now in general use, Unicode, extends the same idea to every writing system, so that Devanagari, Tamil and emoji all have their own numbers. There is nothing about the stored byte that says "this is a letter". The interpretation is supplied by the software.

An image is a grid of numbers. Each picture element, or pixel, is stored as three numbers giving the intensity of red, green and blue. A photograph two thousand pixels wide and fifteen hundred high is three million pixels, each with three numbers.

Sound is a series of numbers too, being the height of the sound wave measured many thousand times a second.

Two consequences follow, and both are legal. First, a copy is exact. Copying a file copies the numbers, and the copy is not a degraded reproduction like a photocopy; it is identical. Second, an alteration leaves no visible trace. Changing one number in a document changes the document, and nothing about the file announces that it happened. The whole apparatus of digital signatures in Chapter II of the Act exists to answer that second point, and chapter 280 works the mechanism.

munotes.in7

How a Computer Holds Information

Files, folders and file systems

A file is a named block of data that the operating system keeps track of. The file system is the index: it records where on the disk each file's data physically sits, what it is called, when it was created, when it was last modified, and who may read it.

Deleting a file usually removes the index entry, not the data. The operating system marks the space as available for reuse and stops showing the file. Until something else is written over that space, the content is still there, and forensic software recovers it by reading the disk directly instead of asking the file system. This is why an investigator images a disk rather than browsing it, and why an accused who deleted a file has not necessarily destroyed the evidence.

Overwriting is different from deleting. Software that writes random data over the space repeatedly does destroy the content. Deliberate overwriting after an investigation begins is the electronic equivalent of destroying a document, and section 65 of the Act makes the destruction of source code required to be maintained by law an offence in its own right.

Metadata

Metadata is data about the data. A photograph taken on a phone carries, inside the same file, the date and time it was taken, the make and model of the phone, the camera settings and, if location services were on, the latitude and longitude. A word processing document carries the author's name, the times of creation and last modification, and often a record of earlier edits.

Metadata is frequently the most useful evidence in the file, and it is also the least considered. A defence that a photograph was taken in one place is answered by the coordinates inside it. A claim that a document was drafted before a certain date is answered by its creation timestamp.

It is also fragile. Sending a photograph through some messaging applications strips the metadata, uploading it to some websites strips it, and opening and saving a document changes the modification time. That is why the rule in forensics is to work on an image of the original medium, and why a copy forwarded by WhatsApp is a much weaker exhibit than the file taken off the device.

The hash: a fingerprint for data

A hash function takes any amount of data and produces a short fixed-length number from it. Feed it a one-page letter or a two-hour film and you get, in the widely used SHA-256 function, the same 256 bits out.

munotes.in8

How a Computer Holds Information

Three properties make it useful in law. It is deterministic: the same input always gives the same output. It is one way: from the output you cannot work back to the input. And it is collision resistant: it is not practically possible to find two different inputs that produce the same output.

So the hash behaves as a fingerprint for a body of data. Change one character anywhere in a ten thousand page file and the hash changes completely. Two files with the same hash are, for practical purposes, the same file.

This is used at three points in this subject. It is how a digital signature works, because what is actually signed is the hash rather than the document, and chapter 280 works that in detail. It is how a forensic image is proved to be a true copy: the examiner records the hash of the original medium and of the image, and if the two match, the image is unaltered. And it is how a court can be shown that an exhibit produced at trial is the same file that was seized months earlier.

The University set a short note on "the importance of Hash Value" on the 2024-25 paper, and the three properties above are the answer.

Logs

A log is a file in which a system records what happened, with times. A web server logs each request with the requesting address and the time. An operating system logs each login. A bank logs each transaction. A router may log which internal device used which external address.

Logs are the ordinary evidence of a cyber offence, because the offence usually leaves no other trace. They are also the reason the law imposes retention duties on people who did nothing wrong: rule 3(1)(g) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires an intermediary to preserve information for one hundred and eighty days, section 67C of the Act requires intermediaries to preserve and retain information as prescribed, and the CERT-In directions of 28 April 2022 require logs to be maintained for one hundred and eighty days within India. Chapter 1240 owns section 67C and the retention rules, and chapter 770 owns the CERT-In directions.

Logs are also easy to lose. Many systems overwrite them after days. That is the practical reason a complaint made a week after an incident often cannot be investigated at all, and it is the reason the Budapest Convention has an article devoted to expedited preservation.

Encoding, encryption and compression, which are three different things

What it doesIs it secret?Undone by
EncodingRepresents data in a particular format, such as Unicode text or Base64No, and it is not meant to beAnyone who knows the format
CompressionMakes data smaller by removing redundancy, as in a ZIP fileNoAnyone with the software
EncryptionTransforms data so it is unreadable without a keyYes, that is its whole purposeOnly the holder of the key
munotes.in9

How a Computer Holds Information

Students routinely call an encoded file encrypted. They are not the same and the legal consequences differ sharply. Section 69 of the Act gives a power to require decryption assistance and section 84A empowers the Central Government to prescribe modes and methods of encryption. Neither has anything to say about encoding. Chapters 800 and 830 own those two.

A worked example

Arjun, an auditor, is asked to prove that a spreadsheet produced by a company in 2026 is the same one it produced to him in 2024.

He compares hashes. In 2024 he recorded the SHA-256 hash of the file he received. In 2026 he computes the hash of the file produced. If the two are identical, the file is byte for byte the same and nothing has been altered. If they differ, something changed, though the hash does not tell him what.

He looks at metadata. The 2026 file shows a modification timestamp in March 2025, which is after the 2024 delivery. That alone suggests alteration, although a timestamp can be changed by someone who sets out to change it, so it corroborates the hash comparison rather than replacing it.

He asks for the logs. The company's document management system logs each save with the user account. Those entries, if kept, name the person and the time.

None of the three is a legal conclusion, but between them they turn "the file looks different" into evidence that a court can act on. Chapter 1270 works how such evidence is actually admitted.

What this does NOT mean

It does not mean a hash proves who made a change. It proves only that a change was made. Attributing it to a person needs logs, metadata or a signature.

It does not mean deleted data is always recoverable. Solid state drives reorganise themselves and may erase deleted blocks quickly, encrypted storage becomes unreadable once the key is gone, and deliberate overwriting destroys content. Recoverability is a question of fact for the examiner, not a rule of law.

It does not mean metadata is conclusive. It can be edited, and a court treats it as evidence to be weighed and not as an incontrovertible fact.

Quick revision

  • Bit is one binary digit; eight bits are a byte. Text, images and sound are all numbers by convention.
  • A copy is exact, and an alteration leaves no visible trace. Chapter II of the Act exists because of that.
  • Deleting removes the pointer, not the data. Overwriting removes the data.
  • Metadata is data about the data: author, timestamps, device, location. Powerful and fragile.
  • A hash is a short fixed-length fingerprint. Deterministic, one way, collision resistant. Used for digital signatures, forensic imaging, and proving an exhibit is unchanged. Asked as a short note in 2024-25.
  • Logs record what happened and when, are the ordinary evidence of a cyber offence, and are subject to retention duties under section 67C, rule 3(1)(g) and the CERT-In directions.
  • Encoding, compression and encryption are three different things. Only encryption is meant to keep a secret.
munotes.in10

How a Computer Holds Information

Test yourself

1. Why does the law need a special rule for proving an electronic record when it has no such rule for a letter? Because an electronic copy is identical to its source and an alteration leaves no physical trace, so the ordinary reasons for trusting a document, its handwriting, its paper and its wear, do not exist. Section 63 of the Bharatiya Sakshya Adhiniyam supplies a substitute assurance.

2. State the three properties of a hash function and give one legal use of each. Deterministic, so the same file always yields the same value and an exhibit can be matched to a seized original. One way, so publishing the hash of a document does not disclose the document. Collision resistant, so a party cannot produce a different document with the same value, which is what makes a digital signature meaningful.

3. A witness says he deleted the file, so nothing can be recovered. Is he right? Not necessarily. Deletion normally removes the file system's index entry while leaving the content on the medium until it is overwritten, so the data is often recoverable by imaging the disk. Whether it is recoverable in the particular case is a question for the examiner.

4. Distinguish encoding from encryption. Encoding represents data in an agreed format and is undone by anyone who knows the format; it keeps no secret. Encryption transforms data so that it can be read only with a key. Section 69 of the Act deals with decryption; encoding is not addressed at all.

5. Why do retention obligations exist for intermediaries who have done nothing wrong? Because the evidence of an offence exists only in logs and records that systems overwrite in the ordinary course, and by the time a complaint is investigated it would otherwise be gone. Hence section 67C, rule 3(1)(g) of the 2021 Rules and the CERT-In direction on one hundred and eighty day log retention.

Contents This chapter on its own page

munotes.in11

Chapter Three

How the Internet Works

Syllabus topic 1.1, "Introduction to Information Technology"

In one line

The internet is a network of networks that moves data by breaking it into numbered packets and letting independent machines forward each one towards its destination.

In the wording a student can write in an exam: the internet is a decentralised global system of interconnected computer networks that communicate using a common set of protocols, chiefly the Transmission Control Protocol and the Internet Protocol, under which information is divided into packets that are routed independently between numerically addressed machines and reassembled at the receiving end.

Why a lawyer must know how it works

Every jurisdictional problem in this subject is a consequence of the design. A message from Mumbai to Mumbai may cross three countries. The person who sent it, the machine that stored it and the machine that displayed it may be in three different jurisdictions. No single body owns the network or can switch it off. Those are not opinions; they are consequences of the architecture, and a student who does not know the architecture is reduced to repeating that the internet is borderless without being able to say why.

And the statutory categories track the architecture. The definition of an intermediary in section 2(1)(w) of the Act lists telecom service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes. That is a list of the different roles a machine can play in moving or holding a message, and it makes sense only if you know what those roles are.

Packet switching

The old telephone network worked by circuit switching. When you called somebody, the exchange built a physical path from your handset to theirs and reserved it for the whole call. It was dedicated, it was in order, and if any link in it failed the call dropped.

The internet works the other way. Your message is cut into small pieces called packets. Each packet carries the address it is going to, the address it came from, and a sequence number saying where it belongs in the message. Each packet is then handed to the next machine along, which decides for itself where to send it next. Different packets of the same message may take different routes and arrive out of order, and the receiving machine puts them back in order using the sequence numbers.

Three legal consequences follow immediately. First, there is no single path to intercept, which is why interception under section 69 is done at the service provider rather than on the wire. Second, a message routinely crosses jurisdictions that neither party chose or knows about. Third, the network is robust: designed to survive the loss of links, it cannot be switched off centrally, which is why blocking under section 69A operates on intermediaries rather than on the network.

munotes.in12

How the Internet Works

Protocols and the layers

A protocol is an agreed set of rules for how machines talk. The internet works because everybody uses the same ones. Four matter for law.

The Internet Protocol, IP, does addressing and routing. It gives each machine an address and gets packets from one address to another. It makes no promise that they will arrive.

The Transmission Control Protocol, TCP, makes the connection reliable. It numbers the packets, notices which did not arrive, asks for them again, and puts them in order. Together these two are usually written TCP/IP.

The HyperText Transfer Protocol, HTTP, is what browsers and websites speak. Its secure form, HTTPS, wraps the conversation in encryption so that the intermediaries carrying it can see who is talking to whom but not what is said. That single fact is the reason a great deal of modern interception is about metadata rather than content.

The Domain Name System, DNS, translates names into addresses, and it is dealt with below.

IP addresses

Every machine on the internet has a numerical address. In the older and still dominant version, IPv4, it is four numbers from 0 to 255, written as 203.0.113.45. There are about four billion such addresses, which ran out, so a newer version, IPv6, provides a vastly larger space and is written as eight groups of hexadecimal digits.

An address usually identifies a connection, not a person, and often not even a device. Three mechanisms break the link that students assume.

Addresses are usually shared. A home or office router holds one public address and uses network address translation to let every device behind it share that address. So an address identifies the household, not the person at the keyboard.

Addresses are usually temporary. An internet service provider allocates an address to a subscriber for a period and reallocates it afterwards. To connect an address to a subscriber you need the address and the exact time, and you need the provider's logs, which is why the retention obligations in chapter 1230 matter and why a complaint made too late cannot be investigated.

Addresses can be deliberately hidden. A virtual private network, or VPN, routes the traffic through an intermediate server so that the destination sees the VPN's address; a proxy does the same; the Tor network chains several such hops with layered encryption so that no single machine knows both ends.

So an IP address is a starting point for an investigation and never a conclusion. Courts have had to be told this repeatedly, and it is the honest answer to an examination problem that supplies an address and asks who is liable.

munotes.in13

How the Internet Works

The Domain Name System

People use names and machines use numbers, and the DNS is the translation. When a browser is given munotes.in it asks a DNS resolver for the corresponding address and then connects to that address.

The name space is hierarchical and it is administered. At the top are the root servers. Below them are the top level domains: generic ones such as .com and .org, and country code ones such as .in for India. Under each, a registry keeps the register and accredited registrars sell registrations to the public. The global coordination of names and numbers is done by the Internet Corporation for Assigned Names and Numbers, ICANN, and .in is administered by the National Internet Exchange of India, NIXI.

That administration is why domain names, alone among internet resources, have a working dispute resolution system. ICANN's Uniform Domain-Name Dispute-Resolution Policy and NIXI's .IN Domain Name Dispute Resolution Policy are contractual conditions of registration, and they allow a trade mark owner to have a name transferred without going to court. Chapter 1070 owns domain names and cybersquatting.

Who does what: the roles in section 2(1)(w)

RoleWhat the machine actually doesWhere it appears in the Act
Internet service providerConnects a subscriber to the network and allocates the addressNamed in the section 2(1)(w) list; the entity served with a section 69A blocking direction
Telecom or network service providerCarries traffic between networksNamed in the list; the licensee under the Telegraph Act whose licence carries interception conditions
Web hosting service providerKeeps the files that make up a site and serves them on requestNamed in the list; the typical defendant in a takedown
Search engineIndexes what it finds and returns linksNamed in the list; the respondent in Sabu Mathew George and in the right to be forgotten cases
Online market place or auction siteLets third parties list and sellNamed in the list; the defendant in the Bazee.com prosecution and in Christian Louboutin
Cyber cafeOffers public access; separately defined in section 2(1)(na)Governed by its own rules, worked in chapter 1430

Nothing in that list is about ownership of content. Every one of them is a description of a service performed on somebody else's message, which is precisely why the safe harbour in section 79 is available to all of them and why chapter 1360 has to work out its conditions carefully.

Client, server and the cloud

A server is a machine that waits for requests and answers them; a client is the machine that asks. Your phone is the client, the machine holding the website is the server.

munotes.in14

How the Internet Works

Cloud computing means renting somebody else's servers, so the data of an Indian business may sit on machines in Singapore owned by a company in the United States and operated by staff in Ireland. That single arrangement produces most of the hard questions in chapter 1030 and in chapter 880 on getting evidence from abroad.

A worked example: what happens when Priya opens a website

Priya, in Thane, types munotes.in into her browser.

Her computer asks a DNS resolver, usually run by her internet service provider, for the address matching that name. The resolver answers with an IP address.

Her computer opens a TCP connection to that address and sends an HTTPS request for the page. The request leaves her laptop, goes to her router, which replaces her private address with the household's public address, then to her internet service provider, then across one or more networks, possibly through a submarine cable and a different country, to the machine that hosts the site.

The server answers with the page, cut into packets, which return by whatever route is available and are reassembled by her machine.

Now ask the legal questions. Whose computer resource was used? Hers, her provider's, several carriers' and the host's. Where did the transaction happen? In at least two countries. Who is an intermediary here? Her internet service provider, every carrier in between, and the web host. What could each of them see? Her provider saw that she connected to that address at that time; because the connection was encrypted, it did not see what she read. Which of them could be ordered to block the page? Her provider, under section 69A, and the host, under the same power or under rule 3(1)(d) of the 2021 Rules.

Every one of those answers is worked in a later chapter. The point here is that all of them are questions about the mechanics.

What this does NOT mean

It does not mean nobody governs the internet. ICANN administers names and numbers, the Internet Engineering Task Force sets the protocols, the regional registries allocate addresses, and every national government regulates the providers within its territory. There is no single owner, which is a different thing.

It does not mean traffic between two Indian users stays in India. It often does not, because routing follows commercial and technical convenience, and because the service may be hosted abroad.

It does not mean an IP address identifies a person. It identifies a connection at a time, and only the provider's logs link that to a subscriber, who may not be the user.

It does not mean encryption defeats all investigation. Encryption of the content leaves the metadata visible: who connected to whom, when, and how much passed. Section 69B and the traffic data rules exist for exactly that layer, and chapter 820 owns them.

munotes.in15

How the Internet Works

Quick revision

  • Packet switching: the message is cut into numbered packets, routed independently and reassembled. Hence no single path, routine crossing of borders, and no central switch.
  • TCP/IP: IP addresses and routes, TCP makes it reliable. HTTPS encrypts the content but not the fact of the connection. DNS turns names into numbers.
  • An IP address is shared, temporary and maskable. It needs the provider's log plus the exact time to reach a subscriber, and the subscriber is not necessarily the user.
  • DNS is administered, by ICANN globally and NIXI for .in, which is why domain names have the UDRP and INDRP.
  • Section 2(1)(w) lists intermediaries by the role they play in moving or holding somebody else's message. Section 2(1)(na) separately defines a cyber cafe.
  • Cloud computing means the data is on rented servers, often abroad, which produces the jurisdiction and evidence problems of Module III.

Test yourself

1. Explain packet switching and give two legal consequences. The message is divided into packets, each carrying source, destination and sequence number, and each routed independently to be reassembled at the far end. Consequences: there is no single path to intercept, so interception is done at the service provider under section 69 rather than on the wire; and packets routinely cross States neither party chose, which is the root of the jurisdiction problem in topic 3.4.

2. A complainant gives the police an IP address. What else does an investigator need before anybody can be identified? The exact date and time of the connection, because addresses are reallocated; the internet service provider's subscriber logs for that period, which are retained only for a limited time; and evidence connecting the subscriber's connection to the individual, because a household address is shared and may be behind a VPN or proxy.

3. What is DNS and why does it matter legally? It is the hierarchical system translating domain names into IP addresses. It matters because it is administered rather than anarchic, which is what makes the UDRP and INDRP dispute policies possible and what makes DNS-level blocking technically feasible.

4. Why does the definition of intermediary in section 2(1)(w) list so many different businesses? Because each is a different role performed on somebody else's electronic record: carrying it, storing it, indexing it, or providing a place for it. The safe harbour in section 79 turns on the service performed rather than on the kind of company, so the list describes functions.

5. If a page is served over HTTPS, what can the internet service provider see? That the subscriber's connection contacted a particular address at a particular time and how much data passed, which is traffic data. It cannot ordinarily read the content. This is why section 69B and the Monitoring and Collecting Traffic Data Rules 2009 address the metadata layer separately from section 69.

Contents This chapter on its own page

munotes.in16

Chapter Four

Cyberspace, and the Trouble with Territory

Syllabus topic 1.1, "Introduction to Information Technology"

In one line

Law is organised around territory and the network is not, and almost every difficulty in this subject is a version of that mismatch.

In the wording a student can write in an exam: cyberspace is the notional space constituted by interconnected computer networks in which communication and transactions occur without regard to the physical location of the participants, and the central problem of information technology law is that legal systems derive their authority from territory while conduct in cyberspace is simultaneously connected to many territories and located in none.

Why the law has this problem at all

Every legal system rests on territory. A State makes law for its territory, its courts try what happens there, its police act there, and its judgments are enforced against people and property there. That arrangement is so basic that statutes rarely bother to state it: section 1(2) of the Information Technology Act says the Act extends to the whole of India, and the reader is expected to understand what that means.

Territory works because ordinary conduct has a place. A theft happens somewhere. A contract is made somewhere. A defamatory pamphlet is published somewhere. There may be arguments at the edges, but the question has an answer.

A network transaction resists the question. Consider a single act: a person in Pune uploads a photograph to a service whose company is registered in the United States, whose servers are in Singapore, and it is seen by a person in Nagpur. Where did the publication occur? Every answer has a case for it and none is obviously right. Multiply that by the fact that neither the uploader nor the viewer knew or could have known where the servers were, and the difficulty is plain.

The four features that cause the trouble

Cyberspace has no natural borders. The cost of sending data to the next street and to the next continent is effectively the same, and neither the sender nor the network treats the border as an event. A rule that applies at a border cannot easily be applied where the border is not crossed at any identifiable moment.

Location is contingent and often unknown. Where a service physically stores data is a commercial decision that may change weekly, may be split across several countries, and is not disclosed to the user. Attaching legal consequences to that location makes the law depend on a fact nobody knows.

Identity is not fixed to a body. The same person may hold many accounts, an account may be shared, an account may be run by somebody who is not its named holder, and the connection may be routed to conceal its origin. Chapter 30 explains why an address identifies a connection rather than a person.

munotes.in17

Cyberspace, and the Trouble with Territory

Everything happens through an intermediary. In the physical world most wrongs are done directly by the wrongdoer. Online, the message reaches its audience only because a series of businesses carried, stored, indexed or displayed it. That single fact is why a whole branch of this subject is about the liability of people who did not write the words.

The four answers legal systems have tried

The first answer was that cyberspace is a separate place that ordinary law should leave alone. This was argued seriously in the 1990s: that the network is a jurisdiction of its own, governed by its own norms, and that a State claiming to regulate it is over-reaching. It has not survived, for the reason that the people using the network live in territories, own property in territories, and can be reached there. It is worth knowing because examination questions still describe cyberspace as a borderless realm, and the honest answer is that it is borderless technically and thoroughly bordered legally.

The second answer is to extend the territory. A State says that its law reaches conduct abroad which affects it. Section 1(2) of the Act does this in terms: the Act applies also to any offence or contravention committed outside India by any person. Section 75 then supplies the limit, that the act must involve a computer, computer system or computer network located in India. Chapter 850 works both. The difficulty is that if every State does this, the same conduct is lawful and unlawful at once, and the person concerned cannot comply with everything.

The third answer is to regulate the intermediary. A State cannot reach a person abroad but can reach the business that serves its market, and can require that business to remove material, to block access, to retain records or to identify a user. This is the dominant answer everywhere, and it is what sections 69A and 79 of the Act, the 2021 Rules, the European Digital Services Act and section 230 of the American Communications Decency Act are all about. Its difficulty is that it makes private companies the decision makers about lawfulness.

The fourth answer is to co-operate. States agree on common offences and on procedures for helping each other, as in the Budapest Convention of 2001. Chapters 590 and 600 work it. Its difficulty is that co-operation is slow, and chapter 880 shows how slow.

The three questions that recur

Prescriptive jurisdiction: whose law applies? May India apply its law to a website hosted abroad which Indian users read?

Adjudicative jurisdiction: which court may decide? May a court in Mumbai entertain a suit against a company with no presence in Maharashtra whose site is accessible there?

munotes.in18

Cyberspace, and the Trouble with Territory

Enforcement jurisdiction: can the order be given effect? A decree against a foreign defendant with no assets in India is a piece of paper unless a foreign court will enforce it or an intermediary will act on it.

Keep those three apart. Students routinely answer the first when asked the second. A court can have the power to apply Indian law and still lack territorial jurisdiction over the defendant, and it can have both and still be unable to enforce. Chapters 840 to 900 take them in turn.

A worked example

Karan, in Nashik, runs a blog. He writes that a Bengaluru company's product is dangerous. The blog is hosted on a platform incorporated in Delaware, whose servers for the region are in Singapore. A reader in Dubai forwards the post; a distributor in Nagpur cancels its order.

Ask the three questions.

Whose law? India's, because the writer, the company and the loss are in India, and because the material was published to readers in India. But Singapore's law applies to the copy on the machines there, and the platform's contract with Karan probably applies Californian law.

Which court? The company will sue in Bengaluru or Nagpur, where it carries on business and where the loss was felt. Whether the platform can be joined depends on whether it carries on business in India, which is the question chapter 860 works with Banyan Tree and World Wrestling Entertainment.

Enforcement? A decree against Karan is straightforward. An order against the platform is worth what the platform's willingness or its Indian presence makes it worth, which is why litigants now ask for orders against intermediaries under the 2021 Rules rather than only for damages.

Nothing in that example is unusual. It is the ordinary shape of an internet dispute, and the point is that the mismatch between law and network is not an exotic problem at the edge of the subject. It is the subject.

What this does NOT mean

It does not mean cyberspace is a legal vacuum. Every act done online is done by a person somewhere and touches property and reputation somewhere. The problem is an excess of applicable laws, not an absence.

It does not mean the location of a server settles anything. It is one connecting factor among several, and both Indian and foreign courts have refused to make it decisive, because it would let a party choose its law by choosing a data centre.

It does not mean that "the internet is borderless" is an answer to an examination question. It is the beginning of one. The marks are in showing which of the four responses the law has adopted for the particular problem and what the response costs.

munotes.in19

Cyberspace, and the Trouble with Territory

Quick revision

  • Cyberspace: the notional space constituted by interconnected networks, in which conduct is connected to many territories and located in none.
  • Law is territorial; section 1(2) of the Act extends to the whole of India and then reaches conduct abroad, with section 75 supplying the limit.
  • Four causes: no natural borders, contingent and unknown location, identity not fixed to a body, and everything mediated.
  • Four responses: leave it alone (abandoned), extend the territory, regulate the intermediary (dominant), co-operate between States.
  • Three questions, kept apart: whose law (prescriptive), which court (adjudicative), can it be enforced (enforcement).
  • Regulating the intermediary is dominant because it is the only response a single State can make effective on its own, and its cost is that private companies decide what is lawful.

Test yourself

1. Why does the territorial basis of law fit the network badly? Because a State's authority comes from territory, while a single network transaction is simultaneously connected to several territories through the sender, the recipient, the servers and the carriers, and is not located in any of them in the way a physical act is. Neither the participants nor the network treat a border as an event.

2. Distinguish prescriptive, adjudicative and enforcement jurisdiction with one internet example each. Prescriptive: whether Indian law governs a foreign-hosted site read in India. Adjudicative: whether a court in Mumbai may entertain the suit against the foreign host. Enforcement: whether a decree obtained against that host can be given effect, which usually depends on its Indian presence or on a foreign court recognising the decree.

3. Name the four responses legal systems have made and give one instrument for each. Leave it alone, now abandoned. Extend the territory: section 1(2) with section 75 of the IT Act. Regulate the intermediary: section 79 and the Intermediary Guidelines Rules 2021, and the European Digital Services Act. Co-operate: the Budapest Convention on Cybercrime, 2001.

4. What is the cost of the intermediary-regulation response? It puts the decision whether material is unlawful into the hands of private companies acting on notice and under threat of losing an immunity, which produces over-removal, and it makes the extent of a State's reach depend on whether the company has assets or staff in that State.

5. Why is the physical location of a server not decisive? Because it is a commercial decision unknown to the parties, it may be split or changed at will, and making it decisive would let a service choose the law applying to it by choosing a data centre, which would defeat the regulation of every market it serves.

Contents This chapter on its own page

munotes.in20

Chapter Five

How India Came to Have an Information Technology Act

Syllabus topic 1.1, "Introduction to Information Technology"

In one line

India had no law for electronic transactions until 2000, and the Act it then passed was a United Nations model translated into Indian statutory form.

In the wording a student can write in an exam: before the Information Technology Act, 2000, Indian law recognised neither electronic records nor electronic signatures and contained no offence directed at conduct done through a computer; the Act was enacted to give effect to General Assembly resolution A/RES/51/162 recommending that States give favourable consideration to the UNCITRAL Model Law on Electronic Commerce, and it was substantially rewritten by the Information Technology (Amendment) Act, 2008.

The problem before 2000

Four Indian statutes stood in the way of doing business electronically, and each did so without ever mentioning computers.

Writing. A great many legal obligations require something to be "in writing". Section 3(65) of the General Clauses Act, 1897 defines writing by reference to words printed, lithographed or photographed, which is a list of ways of putting marks on a surface. Nothing on a screen is obviously inside it.

Signature. Section 3(56) of the General Clauses Act defines "sign" with reference to a mark made by a person who cannot write. The idea it embodies is of a physical mark on a physical document.

Evidence. The Indian Evidence Act, 1872 divided evidence into oral and documentary, defined a document by reference to matter expressed on a substance by letters, figures or marks, and required primary evidence, meaning the document itself. A printout of a database entry is not the document itself in any obvious sense, and there was no rule for admitting the record inside the machine.

Offences. The Indian Penal Code, 1860 punished theft of movable property, mischief causing destruction, and forgery of a document. None of them obviously reached copying a file without removing it, corrupting data on a disk, or fabricating an electronic record.

So the position in 1999 was not that electronic commerce was unlawful. It was that nobody could be sure it was effective, and there was no answer at all when it went wrong.

The United Nations answer

On 16 December 1996 the General Assembly adopted the UNCITRAL Model Law on Electronic Commerce. UNCITRAL is the United Nations Commission on International Trade Law, the body the General Assembly created in 1966 to reduce the obstacles that differing national laws put in the way of international trade. A Model Law is a text a legislature may enact as it stands or with modification; it binds nobody and it becomes law only when a State passes it.

The resolution the Act's own preamble recites is A/RES/51/162. The preamble records that the General Assembly by that resolution adopted the Model Law, that the resolution recommends that all States give favourable consideration to it when they enact or revise their laws in view of the need for uniformity of the law applicable to alternatives to paper-based methods of communication and storage of information, and that it is considered necessary to give effect to the said resolution.

munotes.in21

How India Came to Have an Information Technology Act

The Model Law's method is worked in chapters 60 to 90, and its central idea, the functional equivalent approach, is the single most useful thing in Module I.

What India did

The Bill was introduced in 1999 and the Act received the President's assent on 9 June 2000. It was brought into force on 17 October 2000.

The Statement of Objects and Reasons sets out four purposes, and they map on to the Act's structure exactly.

To give legal recognition to transactions carried out by electronic data interchange and other means of electronic communication, commonly referred to as electronic commerce, which involve the use of alternatives to paper-based methods of communication and storage of information. That is Chapters II to IV of the Act, sections 3 to 13.

To facilitate electronic filing of documents with Government agencies. That is Chapter III, sections 6 to 9.

To amend the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934. That was done by sections 91 to 94 and the four Schedules, all since omitted as spent, and it is how section 65B came into the Evidence Act.

And, added by the Act itself rather than by the Model Law, to create offences and a regulatory machinery. That is Chapters VI to XI.

Two of those four purposes have no counterpart in the Model Law at all. The Model Law is about commerce. It says nothing about licensing certifying authorities, nothing about hacking, and nothing about obscenity. India built a regulatory and penal statute on a commercial foundation, and a good deal of the criticism of the Act is that the two halves do not sit comfortably together.

The three phases of the Act's life

Phase one, 2000 to 2009: the commerce statute. The Act as passed recognised electronic records and digital signatures, set up the Controller of Certifying Authorities and a licensing regime, created a Cyber Regulations Appellate Tribunal, and provided a short list of offences of which the best known was section 66, then headed "hacking with computer system".

Phase two, 2009 onwards: the amended Act. The Information Technology (Amendment) Act, 2008 came into force on 27 October 2009 and rewrote the statute. It replaced digital signature with the wider electronic signature, inserted sections 43A, 66A to 66F, 67A to 67C, 69A, 69B, 70A, 70B, 72A, 79 in its present form, 84A to 84C, and much else. Chapter 180 works it in full. Almost everything a student meets in Modules III and IV was put there in 2008.

munotes.in22

How India Came to Have an Information Technology Act

Phase three, 2017 onwards: the Act as amended by other Acts and filled out by rules. The Finance Act 2017 abolished the Cyber Appellate Tribunal and made the Telecom Disputes Settlement and Appellate Tribunal the appellate forum. The Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 replaced the 2011 intermediary rules and added a code for digital media. The Digital Personal Data Protection Act, 2023 will remove section 43A when its section 44(2) comes into force. The amendment of 10 February 2026 brought synthetically generated information into the Rules. Chapter 190 works this phase.

A short chronology

DateWhat happened
16 December 1996General Assembly resolution A/RES/51/162 adopts the UNCITRAL Model Law on Electronic Commerce
9 June 2000The Information Technology Act, 2000 receives the President's assent, Act 21 of 2000
17 October 2000The Act is brought into force, together with the Certifying Authorities Rules 2000
5 July 2001The UNCITRAL Model Law on Electronic Signatures is adopted
2008The Information Technology (Amendment) Act, 2008 is passed
27 October 2009The 2008 amendment, and the Interception, Blocking and Traffic Data Rules, come into force
11 April 2011The SPDI Rules, the Intermediaries Guidelines Rules and the Cyber Cafe Rules are notified
24 March 2015Section 66A is struck down in Shreya Singhal v. Union of India
26 May 2017Part XIV of Chapter VI of the Finance Act 2017 merges the Cyber Appellate Tribunal into the TDSAT
25 February 2021The Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 are notified
11 August 2023The Digital Personal Data Protection Act, 2023 receives assent
13 November 2025G.S.R. 843(E) brings parts of the DPDP Act into force in three stages
20 February 2026G.S.R. 120(E) of 10 February 2026, the synthetically generated information amendment, comes into force

A worked example

Take one dispute and ask what a court could have done with it in 1998, in 2002, in 2012 and today. Nalini Sridhar orders goods by email from Vipul Shah, he denies the order and she produces a printout.

In 1998, before the Act. The printout is a document only if the Evidence Act, 1872, treats it as one, and section 3 as it then stood spoke of matter recorded upon a substance by letters, figures or marks. There is no provision making an electronic record admissible, no rule attributing it to a sender, and no way to satisfy a statute that requires a signature. Nalini's difficulty is not that she will lose; it is that nobody knows what the answer is.

munotes.in23

How India Came to Have an Information Technology Act

In 2002, under the Act as enacted. Section 4 gives legal recognition to an electronic record where a law requires writing. Section 5 gives legal recognition to a digital signature where a law requires a signature. Section 11 attributes the record to the originator. Section 13 fixes when and where it was sent and received. And section 92 of this Act with the Second Schedule has inserted sections 65A and 65B into the Evidence Act, so the printout is admissible with a certificate. Everything Nalini needed has arrived at once, and that is what the Act was for.

In 2012, after the amendment of 2008. The same answers, plus section 10A, which puts beyond argument that a contract is not unenforceable merely because it was made electronically, and section 3A, which widens signature recognition beyond digital signatures to any technique in the Second Schedule. If Vipul now says his account was compromised, section 11 still does not help him or her, because it attributes only in three cases and none of them is the stolen password.

Today. The Evidence Act is repealed; section 61 of the Bharatiya Sakshya Adhiniyam, 2023, forbids denial of admissibility on the ground that the record is electronic, section 57 may make the file itself primary evidence, and section 63 carries the old section 65B certificate with the added requirement of an expert's signature. Chapter 1270.

And the shape the example shows. The Act's first phase, from 2000, was about recognition; the second, from 2008, added crime, security and intermediaries; and the third, from 2021, is rules rather than statute. The chronology below is that story with dates on it.

What this does NOT mean

It does not mean India copied the Model Law. India enacted its substance for electronic records and signatures and then added a licensing regime, an offence chapter and a State powers chapter that the Model Law never contemplated. Chapter 110 compares the two clause by clause, which is a question the University has set three times.

It does not mean the Act repealed the older statutes. It amended four of them and otherwise left the general law standing, which is why section 81 was needed to say which prevails and why chapter 1280 has to work out how the Act and the Bharatiya Nyaya Sanhita apply together.

It does not mean the Act was drafted for the internet we have. It was drafted for electronic data interchange between businesses. Social media, cloud computing, smartphones and machine-generated content all arrived afterwards, and the strain shows.

Quick revision

  • Before 2000: writing and signature were defined physically in the General Clauses Act 1897; the Evidence Act 1872 had no rule for records inside a machine; the Penal Code 1860 reached none of the new conduct.
  • UNCITRAL is the United Nations Commission on International Trade Law. A Model Law binds nobody until enacted.
  • Resolution A/RES/51/162, 16 December 1996, adopted the Model Law on Electronic Commerce and is recited in the Act's own preamble.
  • Assent 9 June 2000, Act 21 of 2000, in force 17 October 2000.
  • Four objects: recognise electronic transactions; facilitate electronic filing with Government; amend four statutes; and, added by India, create offences and a regulator.
  • Three phases: the commerce statute to 2009; the amended Act from 27 October 2009; and the Act as reshaped by the Finance Act 2017, the 2021 Rules, the DPDP Act 2023 and the amendment of February 2026.
munotes.in24

How India Came to Have an Information Technology Act

Test yourself

1. State three obstacles in Indian law before 2000 to doing business electronically. The definitions of writing and of signature in the General Clauses Act, 1897 assumed marks on a physical surface. The Indian Evidence Act, 1872 had no rule for admitting a record held inside a computer and required primary evidence of a document. The Indian Penal Code, 1860 did not reach copying data without removing it, corrupting data, or fabricating an electronic record.

2. What is a Model Law, and which one does the Act's preamble recite? A text prepared for legislatures to enact with or without modification, binding on nobody until enacted. The preamble recites the UNCITRAL Model Law on Electronic Commerce, adopted by General Assembly resolution A/RES/51/162 dated 30 January 1997 as the Act prints it, and recommends favourable consideration in the interests of uniformity.

3. Which two of the Act's purposes have no counterpart in the Model Law? The regulatory purpose, meaning the licensing and supervision of Certifying Authorities in Chapters VI and VII, and the penal purpose, meaning the offences in Chapter XI. The Model Law is a commercial instrument and contains neither.

4. Give the date the Act came into force and the date the 2008 amendment came into force, and say why the second matters more. The Act came into force on 17 October 2000; the 2008 amendment on 27 October 2009. The second matters more because almost every provision a student meets in Modules III and IV, sections 43A, 66A to 66F, 67A to 67C, 69A, 69B, 70A, 70B, 72A, the present section 79 and sections 84A to 84C, was inserted by it.

5. Why is it wrong to say the Act is simply the Model Law in Indian form? Because the Model Law supplied only the recognition provisions on electronic records, signatures, attribution, acknowledgment and the time and place of despatch and receipt. The Certifying Authority regime, the offences, the State powers of interception and blocking, and the intermediary provisions are Indian additions with no Model Law counterpart.

Contents This chapter on its own page

munotes.in25

Chapter Six

The UNCITRAL Model Law on Electronic Commerce

Syllabus topic 1.2, "UNCITRAL Model Law"

In one line

The Model Law on Electronic Commerce is a text the United Nations wrote for legislatures to copy, so that the law of electronic trade would be the same everywhere.

In the wording a student can write in an exam: the UNCITRAL Model Law on Electronic Commerce, adopted by the General Assembly on 16 December 1996, is a non-binding legislative text prepared by the United Nations Commission on International Trade Law which States may enact with or without modification, and which removes the obstacles that paper-based legal requirements place in the way of electronic commerce by providing that a data message is not to be denied legal effect merely because it is electronic.

Why the United Nations wrote it

Trade is international and law is national, and that is the problem UNCITRAL exists to reduce. The Commission was created by the General Assembly in 1966 to promote the progressive harmonisation and unification of the law of international trade. Its instruments include conventions, such as the Convention on Contracts for the International Sale of Goods, and model laws, such as the Model Law on International Commercial Arbitration.

By the early 1990s electronic data interchange was in ordinary commercial use and no legal system had a rule for it. Businesses exchanged purchase orders and invoices between computers, and nobody could say with confidence whether the resulting exchange was a contract, whether it satisfied a statutory requirement of writing, or whether a court would look at it. Parties papered over the gap with interchange agreements, which worked only between people who had signed them.

Two answers were possible and UNCITRAL chose the second. One was to write a convention, which binds States that ratify it and which nobody has to accept. The other was to write a model law, which binds nobody but which every legislature can adopt at its own pace. Given how fast the technology was moving, a text that could be amended by each State without renegotiating a treaty was the practical choice.

What a Model Law is

A model law is a draft statute. It is not a treaty. Nothing in it applies in any country until that country's legislature passes it, and a legislature may pass it whole, in part, or with changes. The Model Law on Electronic Commerce is drafted to be enacted, which is why it reads like a statute and not like a treaty.

It comes with a Guide to Enactment, which is the Commission's own commentary explaining what each article is for and what a legislature should consider. The Guide is not law either, but it is the best evidence of what the articles mean and courts refer to it.

munotes.in26

The UNCITRAL Model Law on Electronic Commerce

India enacted its substance. Chapter 110 compares the two clause by clause, which is a comparison the University has set three times, in 2015, 2016 and 2025-26. The short point is that sections 4, 5, 7, 11, 12 and 13 of the Information Technology Act are recognisably articles 6, 7, 10, 13, 14 and 15 of the Model Law.

The structure of the Model Law

It has two parts and seventeen articles.

Part one, electronic commerce in general, contains articles 1 to 15 in three chapters. Chapter I is general provisions, articles 1 to 4. Chapter II applies legal requirements to data messages, articles 5 to 10, and includes article 5 bis, which was added by the Commission in June 1998. Chapter III deals with the communication of data messages, articles 11 to 15.

Part two, electronic commerce in specific areas, contains articles 16 and 17 on the carriage of goods. Chapter 90 owns those.

Article 1: the sphere of application

"This Law applies to any kind of information in the form of a data message used in the context of commercial activities."

Three things about that sentence matter.

It applies to information, not to documents or transactions. The unit is the data message, which article 2 defines.

It is limited to commercial activities, and a footnote directs that the term commercial be given a wide interpretation covering all relationships of a commercial nature, whether contractual or not, and lists supply and exchange of goods or services, distribution, agency, factoring, leasing, construction, consulting, engineering, licensing, investment, financing, banking, insurance, concession, joint venture and carriage of goods or passengers by any mode.

A footnote records that the Law does not override any rule of law intended for the protection of consumers. UNCITRAL was writing for business to business trade, and left consumer protection to each State.

The Commission offers two alternative texts in footnotes, one for a State that wishes to limit the Law to international data messages, and one for a State that wishes to extend it beyond commerce by listing exceptions instead. India took the second route: the Act applies generally and section 1(4) with the First Schedule lists what it does not touch. Chapter 140 owns the First Schedule.

Article 2: the five definitions that carry the whole subject

Article 2(a): a data message means information generated, sent, received or stored by electronic, optical or similar means including, but not limited to, electronic data interchange, electronic mail, telegram, telex or telecopy.

Notice that the definition includes a telegram, a telex and a telecopy, which is a fax. The Model Law is not about the internet. It is about any means of communication that is not paper, and that deliberate width is what has let it survive thirty years of new technology.

munotes.in27

The UNCITRAL Model Law on Electronic Commerce

Article 2(b): electronic data interchange means the electronic transfer from computer to computer of information using an agreed standard to structure the information. This was the dominant commercial technology of the time.

Article 2(c): the originator of a data message means a person by whom, or on whose behalf, the data message purports to have been sent or generated prior to storage, if any, but does not include a person acting as an intermediary with respect to that data message.

Article 2(d): the addressee means a person who is intended by the originator to receive the data message, but does not include a person acting as an intermediary.

Article 2(e): an intermediary, with respect to a particular data message, means a person who, on behalf of another person, sends, receives or stores that data message or provides other services with respect to it.

Compare those three with sections 2(1)(za), 2(1)(b) and 2(1)(w) of the Indian Act. The originator and the addressee are taken over almost word for word, each carrying the same express exclusion of an intermediary. The Indian definition of intermediary keeps the same core, "on behalf of another person receives, stores or transmits that record or provides any service with respect to that record", and then adds the long list of businesses that chapter 30 sets out. Chapter 160 owns the Indian definitions.

Article 2(f) defines an information system as a system for generating, sending, receiving, storing or otherwise processing data messages. India did not enact this one, which is why section 13 of the Act speaks of a computer resource where article 15 speaks of an information system.

Article 3: interpretation

Article 3(1) requires that in interpreting the Law regard is to be had to its international origin and to the need to promote uniformity in its application and the observance of good faith.

Article 3(2) provides that questions concerning matters governed by the Law which are not expressly settled in it are to be settled in conformity with the general principles on which the Law is based.

This is a standard UNCITRAL article and it does real work. It tells a court not to read the enacted text as though it were purely domestic, and it supplies a method for a gap: reason from the principles of the instrument rather than from local doctrine. India did not enact article 3, and that omission has a cost, because an Indian court construing section 13 has no direction to consult the Model Law or the decisions of other enacting States.

Article 4: variation by agreement

Article 4(1) provides that as between parties involved in generating, sending, receiving, storing or otherwise processing data messages, and except as otherwise provided, the provisions of chapter III may be varied by agreement.

munotes.in28

The UNCITRAL Model Law on Electronic Commerce

Article 4(2) provides that this does not affect any right that may exist to modify by agreement any rule of law referred to in chapter II.

So the Model Law divides itself in two. Chapter III, the communication rules on attribution, acknowledgment and the time and place of despatch and receipt, is default law: it applies unless the parties have agreed otherwise, exactly as much of the law of contract does. Chapter II, the rules about writing, signature and originality, is not in the parties' gift in the same way, because those are requirements imposed by other law for reasons of their own, and two parties cannot agree that a statutory requirement of writing is satisfied.

India enacted this distinction in substance without enacting article 4 as a section. Sections 11, 12 and 13 all open with words that give way to a contrary agreement: section 11 attributes a record in the circumstances stated, section 12 applies "where the originator has not agreed with the addressee", and section 13 applies "unless otherwise agreed between the originator and the addressee". Chapters 940, 950 and 870 own those three.

A worked example

Sunrise Textiles in Bhiwandi sells cotton to Meridian Trading in Colombo. They exchange purchase orders and confirmations by email, using a standard message format, and never sign anything on paper.

Under article 1, this is information in the form of a data message used in the context of a commercial activity, so the Model Law applies to it in any State that has enacted it. The exchange is a trade transaction for the supply of goods, which is the first item in the footnote's list.

Under article 2(a), each email is a data message. Under article 2(c), Sunrise is the originator of the purchase confirmation. Under article 2(d), Meridian is the addressee. Under article 2(e), the mail service that carried the message is an intermediary, and it is neither originator nor addressee, which is what stops the carrier being treated as a party to the exchange.

Under article 4, if the two companies have a trading agreement providing that no message is effective until acknowledged, that agreement displaces article 14. If they have agreed that email will do instead of a signed order, that agreement is good between them but does not by itself satisfy a statutory requirement of signature imposed by Sri Lankan or Indian law, because article 4(2) keeps chapter II out of their hands.

The rest of the exchange is worked in the next three chapters, which take chapter II and chapter III in turn.

munotes.in29

The UNCITRAL Model Law on Electronic Commerce

What this does NOT mean

It does not mean the Model Law is in force anywhere as the Model Law. It is in force as the enacting State's own statute, in whatever form that State passed it. When an Indian court applies section 13 it applies section 13, not article 15.

It does not mean every State enacted the same text. More than eighty jurisdictions have legislation based on it, and they differ. Comparing those differences is what topic 3.1 asks for.

It does not mean the Model Law settles what a contract is. It removes obstacles arising from the electronic form and does nothing else. Whether there was an offer, an acceptance and consideration remains a question for the ordinary law of contract, which is why chapter 920 has to work offer and acceptance separately.

Quick revision

  • UNCITRAL: the United Nations Commission on International Trade Law, created 1966 to harmonise the law of international trade.
  • A model law binds nobody until a legislature enacts it. It comes with a Guide to Enactment, which is the Commission's own commentary.
  • Adopted 16 December 1996; article 5 bis added June 1998. Seventeen articles in two parts.
  • Article 1: any kind of information in the form of a data message used in the context of commercial activities; "commercial" to be read widely; the Law does not override consumer protection law.
  • Article 2: data message, electronic data interchange, originator, addressee, intermediary, information system. The originator and the addressee both exclude an intermediary.
  • Article 3: interpret with regard to the international origin, the need for uniformity and good faith; fill gaps from the Law's own principles. India did not enact it.
  • Article 4: chapter III may be varied by agreement; chapter II may not be varied in the same way. India enacted the distinction inside sections 11, 12 and 13 instead.

Test yourself

1. What is a model law, and how does it differ from a convention? A model law is a draft statute prepared for legislatures to enact with or without modification; it has no legal force until enacted, and each State may adapt it. A convention is a treaty binding the States that ratify it, in the terms ratified, and cannot be adapted unilaterally. UNCITRAL chose a model law here because the technology was moving too fast for a treaty.

2. Define a data message and say why the definition mentions telegrams. Article 2(a): information generated, sent, received or stored by electronic, optical or similar means, including but not limited to electronic data interchange, electronic mail, telegram, telex or telecopy. It mentions telegrams because the Law is about non-paper communication generally rather than about any one technology, and that width is why it has survived the arrival of technologies nobody had in 1996.

munotes.in30

The UNCITRAL Model Law on Electronic Commerce

3. Why do the definitions of originator and addressee both exclude an intermediary? Because the intermediary handles the message on somebody else's behalf and has no interest in its content, so treating it as a party would attach to it the consequences of a communication it did not make. The same exclusion appears in sections 2(1)(za) and 2(1)(b) of the Indian Act and is the foundation of the intermediary liability chapters.

4. Explain the difference article 4 draws between chapter II and chapter III. Chapter III, the communication rules, is default law that parties may vary by agreement. Chapter II, the rules on writing, signature, original, admissibility and retention, addresses requirements imposed by other law for public reasons, so article 4(2) preserves whatever right to modify those rules exists independently and does not itself confer one.

5. India did not enact article 3. What is the consequence? An Indian court construing the enacted provisions has no statutory direction to have regard to the Model Law's international origin, to uniformity of application, or to the general principles of the instrument when filling a gap. The result is that Indian interpretation of these provisions is not formally tied to the interpretation given in other enacting States.

Contents This chapter on its own page

munotes.in31

Chapter Seven

The Functional Equivalent Approach

Syllabus topic 1.2, "UNCITRAL Model Law"

In one line

Do not ask whether an electronic record is a document. Ask what the law wanted a document for, and whether the electronic record does that job.

In the wording a student can write in an exam: the functional equivalent approach is the method of the UNCITRAL Model Law on Electronic Commerce, under which a paper-based legal requirement is analysed to identify the purposes and functions it serves, and an electronic communication is treated as satisfying the requirement if it fulfils those functions to an equivalent standard of reliability, rather than by extending the definition of paper concepts to cover electronic ones.

Why the law needed a method at all

Two obvious approaches were tried first and both fail.

The first is to redefine the old words. Amend the definition of "writing" to include electronic records, amend "signature" to include electronic signatures, and so on. It fails because those words appear in hundreds of statutes, each with its own purpose, and a single new definition either sweeps in things it should not or misses things it should catch. It also has to be done again for every new word: original, document, record, sealed, delivered, produced.

The second is to require the electronic thing to look like the paper thing. Insist on a scanned image of a signed page. It fails because it throws away everything electronic communication is good for, and because a scanned signature is far easier to forge than the original.

The Model Law's method is different and it is stated in the Guide to Enactment. Take the paper requirement. Ask what functions paper performs in that context. Then ask what an electronic communication must do to perform the same functions. Then write a rule saying that a data message satisfying those criteria satisfies the requirement.

Notice what this achieves. It does not say electronic is as good as paper, which would be untrue in some contexts. It says an electronic record satisfies a particular requirement when it does the particular job that requirement exists for. Different requirements yield different criteria, which is why articles 6, 7 and 8 look different from one another.

Article 5: the base rule

"Information shall not be denied legal effect, validity or enforceability solely on the grounds that it is in the form of a data message."

Every other rule in chapter II is a working out of that sentence. It is drafted as a prohibition on a reason for refusal, not as a positive grant of validity, and the word "solely" is doing the work. A data message may be denied effect for any ordinary reason: it was unauthorised, it was procured by fraud, the contract was void. What it may not be denied effect for is being electronic and nothing more.

munotes.in32

The Functional Equivalent Approach

Section 4 of the Indian Act enacts the same idea in positive form for the writing requirement, and section 5 does it for signature. Chapter 300 owns both.

Article 5 bis: incorporation by reference

"Information shall not be denied legal effect, validity or enforceability solely on the grounds that it is not contained in the data message purporting to give rise to such legal effect, but is merely referred to in that data message."

This article was added by the Commission in June 1998, two years after the rest, and it addresses the ordinary web practice of putting the terms behind a link rather than in the message.

It is drafted in exactly the same negative form as article 5, and for the same reason. It does not say that a linked term is incorporated. It says that the mere fact of being linked rather than included is not a ground for denying effect, leaving the ordinary law of incorporation, and questions of notice and assent, to do the rest.

India did not enact article 5 bis, and the point is not academic: the enforceability of a browse-wrap term behind a link is decided in India by ordinary contract principles of notice, without any statutory starting point. Chapter 960 works that out.

Article 6: writing

Article 6(1): where the law requires information to be in writing, that requirement is met by a data message if the information contained therein is accessible so as to be usable for subsequent reference.

Article 6(2): paragraph (1) applies whether the requirement is in the form of an obligation or whether the law simply provides consequences for the information not being in writing.

Work through the method. What is writing for? Chiefly, that the information can be read again later. Paper does that by lasting and staying legible. So the criterion is accessibility for subsequent reference, and that is the whole test. It says nothing about permanence, nothing about format, and nothing about who can read it.

Article 6(2) covers both kinds of statute: those that say a thing must be in writing, and those that merely attach a consequence to its not being, such as unenforceability.

Section 4 of the Indian Act is article 6, and its wording is close: where any law provides that information or any other matter shall be in writing or in the typewritten or printed form, then that requirement shall be deemed to have been satisfied if such information or matter is rendered or made available in an electronic form and accessible so as to be usable for a subsequent reference.

munotes.in33

The Functional Equivalent Approach

Article 7: signature

Article 7(1): where the law requires a signature of a person, that requirement is met in relation to a data message if (a) a method is used to identify that person and to indicate that person's approval of the information contained in the data message, and (b) that method is as reliable as was appropriate for the purpose for which the data message was generated or communicated, in the light of all the circumstances, including any relevant agreement.

Ask the same question. What is a signature for? Two things: it identifies the signer, and it shows that the signer approved the content. Those are the two limbs of article 7(1)(a), and they are the functional part.

Article 7(1)(b) adds a reliability standard, and it is deliberately relative. The method must be as reliable as was appropriate for the purpose, in the light of all the circumstances. A typed name at the foot of an email may be appropriate for confirming a delivery date and plainly inappropriate for executing a mortgage. That relativity is the difference between article 7 and the Indian provision.

Section 5 of the Indian Act is narrower. It provides that where any law requires a signature, that requirement is satisfied if the information is authenticated by means of an electronic signature affixed in the manner prescribed by the Central Government. India chose a prescribed method rather than a reliability standard, so an Indian statutory signature requirement is met by the techniques in the Second Schedule and not by any method that happens to be appropriate. Chapters 300 and 310 work the difference, which is the most important single divergence between the Model Law and the Act.

Article 8: original

Article 8(1): where the law requires information to be presented or retained in its original form, that requirement is met by a data message if (a) there exists a reliable assurance as to the integrity of the information from the time when it was first generated in its final form, and (b) where presentation is required, the information is capable of being displayed to the person to whom it is to be presented.

Article 8(3)(a) supplies the test of integrity: whether the information has remained complete and unaltered, apart from the addition of any endorsement and any change which arises in the normal course of communication, storage and display.

Article 8(3)(b) makes the standard of reliability relative to the purpose for which the information was generated and to all the relevant circumstances.

This is the hardest of the three and the most instructive. What is an original for? Not that it is the first copy, because for a data message that is a meaningless idea; every copy is identical. An original is required because it is the version that has not been tampered with. So the criterion is integrity, and the exceptions in article 8(3)(a) are exactly the changes that do not touch integrity: an endorsement added on the way, and the format changes that happen in transmission and display.

munotes.in34

The Functional Equivalent Approach

India enacted this in section 7A and, more importantly, in the electronic evidence provisions, and the integrity idea is what section 63 of the Bharatiya Sakshya Adhiniyam is testing when it requires a certificate. Chapter 1270 owns that.

Article 9: admissibility and evidential weight

Article 9(1): nothing in the application of the rules of evidence shall apply so as to deny the admissibility of a data message in evidence on the sole ground that it is a data message, or, if it is the best evidence that the person adducing it could reasonably be expected to obtain, on the ground that it is not in its original form.

Article 9(2): information in the form of a data message shall be given due evidential weight, and in assessing that weight regard shall be had to the reliability of the manner in which the data message was generated, stored or communicated, to the reliability of the manner in which the integrity of the information was maintained, to the manner in which its originator was identified, and to any other relevant factor.

Two ideas are kept apart here, and they are the two ideas Indian courts have struggled with. Admissibility is a threshold: the record comes in. Weight is what the court makes of it afterwards. Article 9 says the electronic form is no answer to admissibility, and lists the factors that go to weight.

India took a different route, requiring a certificate as a condition of admissibility rather than treating reliability purely as a matter of weight. That choice is why Anvar P.V. and Arjun Panditrao were needed at all, and chapter 1270 works both.

Article 10: retention

Article 10(1): where the law requires that documents, records or information be retained, that requirement is met by retaining data messages provided that (a) the information is accessible so as to be usable for subsequent reference; (b) the data message is retained in the format in which it was generated, sent or received, or in a format which can be demonstrated to represent accurately the information generated, sent or received; and (c) such information, if any, is retained as enables the identification of the origin and destination of a data message and the date and time when it was sent or received.

Condition (c) is the one students miss. It is not enough to keep the message. You must keep enough to say who sent it, to whom, and when. That is the metadata, and chapter 20 explains why it is fragile.

munotes.in35

The Functional Equivalent Approach

Section 7 of the Indian Act is article 10 almost word for word, with the same three conditions, and section 7(2) adds that the section does not apply to information automatically generated solely for the purpose of enabling a message to be sent or received. Chapter 360 owns it.

The five requirements and their criteria, side by side

Paper requirementWhat it is forModel Law criterionIndian provision
Writing, art. 6Being able to read it againAccessible so as to be usable for subsequent references.4
Signature, art. 7Identifying the signer and showing approvalA method that identifies and indicates approval, as reliable as appropriates.5, but by prescribed method instead
Original, art. 8Assurance that it has not been alteredReliable assurance of integrity, and capable of displayss.7A and 14; and s.63 of the BSA 2023
Evidence, art. 9Letting the court see it and weigh itNo denial of admissibility for electronic form; weight by reliability factorss.63 BSA, but as a condition of admissibility
Retention, art. 10Having it later, with its contextAccessible, in an accurate format, plus origin, destination, date and times.7

A worked example

Nandini sells industrial valves. Her customer sends a purchase order by email; she replies "Confirmed, Nandini Rao" and ships. The customer refuses to pay and says there was no contract in writing signed by the seller.

Writing, article 6. The emails are stored in both mailboxes and can be opened and read. They are accessible so as to be usable for subsequent reference. The writing requirement is met.

Signature, article 7 as the Model Law has it. The typed name at the foot, together with the fact that the message came from her business account, is a method that identifies her and indicates approval. Is it as reliable as appropriate? For a routine order of this size, between parties who have traded this way for two years, plainly yes. So the signature requirement is met.

Signature, section 5 as India has it. The typed name is not an electronic signature affixed in the prescribed manner, so section 5 is not satisfied. That does not end the matter, because section 5 is engaged only where a law requires a signature, and the general law of contract does not require one for a sale of goods. Chapter 930 works out what section 10A then does.

Original, article 8. If the customer produces a version of the confirmation with different terms, the question is integrity: which version has a reliable assurance that it has not been altered since it was first generated in final form. That is the practical reason the mail server logs and the message headers matter more than the printout.

munotes.in36

The Functional Equivalent Approach

Retention, article 10. Nandini keeps the emails with their headers, which show sender, recipient and time. Had she copied the text into a word processing file and deleted the mail, she would have kept the content and lost condition (c).

What this does NOT mean

It does not mean electronic always equals paper. The approach is requirement by requirement. A record can satisfy the writing requirement and fail the signature requirement, as the worked example shows.

It does not mean the Model Law makes anything valid. Article 5 removes one reason for refusal. Everything else that could make the transaction bad still can.

It does not mean India adopted the approach wholesale. It adopted it for writing and retention, narrowed it sharply for signature, and departed from it for evidence. Those three divergences are the substance of chapter 110.

Quick revision

  • The method: identify the function the paper requirement serves, then set criteria an electronic record must meet to serve it. Not redefinition, not imitation.
  • Article 5: information is not to be denied legal effect solely because it is a data message. Article 5 bis, added 1998, does the same for information merely referred to. India did not enact 5 bis.
  • Article 6, writing: accessible so as to be usable for subsequent reference. Indian section 4.
  • Article 7, signature: a method that identifies and indicates approval, and is as reliable as appropriate in the circumstances. Indian section 5 requires a prescribed method instead. This is the main divergence.
  • Article 8, original: reliable assurance of integrity from the time it was first generated in final form, plus capability of display. Integrity means complete and unaltered apart from endorsements and normal changes in communication, storage and display.
  • Article 9, evidence: no denial of admissibility for electronic form; the reliability factors go to weight. India made reliability a condition of admissibility.
  • Article 10, retention: accessible, accurate format, and origin, destination, date and time. Indian section 7.

Test yourself

1. State the functional equivalent approach and say what two alternatives it rejects. Identify the functions a paper-based requirement serves, then treat a data message as satisfying the requirement if it performs those functions to an appropriate standard of reliability. It rejects redefining paper words to include electronic ones, which either over-includes or under-includes across hundreds of statutes, and it rejects requiring the electronic record to imitate paper, which discards the advantages of the medium.

2. Why is the criterion for writing different from the criterion for original? Because the two requirements exist for different reasons. Writing exists so the information can be read again, so the criterion is accessibility for subsequent reference. An original is required because it is the untampered version, so the criterion is a reliable assurance of integrity. Applying one criterion to the other requirement would satisfy neither.

munotes.in37

The Functional Equivalent Approach

3. How does section 5 of the Indian Act differ from article 7, and what turns on it? Article 7 accepts any method that identifies the person and indicates approval and is as reliable as appropriate in the circumstances. Section 5 requires an electronic signature affixed in the manner prescribed by the Central Government. India therefore has a closed list of acceptable techniques where the Model Law has an open reliability standard, so a typed name or a scanned signature can never satisfy an Indian statutory signature requirement however appropriate it is.

4. What are the three conditions in article 10 and which is most often overlooked? Accessibility for subsequent reference; retention in the format generated, sent or received or one demonstrably accurate; and retention of information enabling identification of origin, destination, date and time. The third is the one overlooked, because it requires keeping the metadata and not only the content.

5. Why is article 5 drafted as a prohibition rather than as a grant of validity? Because it is not trying to make electronic communications valid; validity depends on the ordinary law. It removes one specific ground of objection, that the communication is electronic, and the word "solely" preserves every other ground. Drafting it as a grant would have made electronic records effective in circumstances where a paper record would not have been.

Contents This chapter on its own page

munotes.in38

Chapter Eight

The Model Law on the Communication of Data Messages

Syllabus topic 1.2, "UNCITRAL Model Law"

In one line

Chapter III of the Model Law answers the four questions that arise once two people are actually exchanging messages: is a contract made this way good, whose message is it, must receipt be acknowledged, and when and where did it happen?

In the wording a student can write in an exam: articles 11 to 15 of the UNCITRAL Model Law on Electronic Commerce govern the communication of data messages, providing that a contract may be formed by data messages, that a declaration of will expressed by a data message is not to be denied effect for that reason, when a data message is to be attributed to the originator, the effect of a stipulation for acknowledgment of receipt, and the time and place at which a data message is despatched and received.

Why these five articles exist

Chapter II removed the paper obstacles. Chapter III supplies the rules that paper never needed.

With paper, whose document it is is usually obvious, because it is signed and it arrived in an envelope. With a data message, the sender's name in the header is written by software and is trivially faked, so a rule about attribution is needed.

With paper, the post office rule and the receipt rule between them settle when a communication takes effect, and the cases go back to 1818. With a data message the sequence is different: it may sit unread on a server for a week, or be delivered instantly to a device nobody is holding.

And with paper, place is where the letter is. With a data message, the server may be anywhere, so a rule is needed that does not depend on the location of hardware.

Article 4 makes this whole chapter default law, variable by agreement between the parties, and chapter 60 explains why chapter II is treated differently.

Article 11: formation and validity of contracts

Article 11(1): in the context of contract formation, unless otherwise agreed by the parties, an offer and the acceptance of an offer may be expressed by means of data messages. Where a data message is used in the formation of a contract, that contract shall not be denied validity or enforceability on the sole ground that a data message was used for that purpose.

Article 11(2) provides that the article does not apply to the categories a State chooses to exclude.

Notice the two halves and the difference between them. The first is permissive: offer and acceptance may be expressed by data message. The second is the familiar negative form: the contract is not to be denied validity on the sole ground that a data message was used.

Section 10A of the Indian Act is this article, and it was not in the Act as passed. It was inserted by the 2008 amendment, so between October 2000 and October 2009 India had recognition of electronic records but no express provision that a contract could be made by them. Chapter 930 works section 10A and what filled the gap before it.

munotes.in39

The Model Law on the Communication of Data Messages

Article 12: recognition by parties of data messages

Article 12(1): as between the originator and the addressee of a data message, a declaration of will or other statement shall not be denied legal effect, validity or enforceability solely on the grounds that it is in the form of a data message.

This is article 5 applied to a declaration of will rather than to information generally, and it exists because a great deal of legally significant conduct is not the making of a contract at all. A notice terminating a lease, an election under a policy, a waiver, a consent, a revocation of an offer: each is a declaration of will and none of them is a contract.

India did not enact article 12 as a separate section, relying on the width of sections 4 and 10A. In practice the gap is small, but it is a real one for a unilateral notice where no contract is being formed.

Article 13: attribution of data messages

This is the longest article in the chapter and it has five paragraphs.

Article 13(1): a data message is that of the originator if it was sent by the originator itself.

Article 13(2): as between the originator and the addressee, a data message is deemed to be that of the originator if it was sent (a) by a person who had the authority to act on behalf of the originator in respect of that data message; or (b) by an information system programmed by or on behalf of the originator to operate automatically.

Article 13(2)(b) is the article that keeps the Model Law modern. A message sent automatically by a machine set up by the originator is the originator's message, which is what makes automated ordering systems, and today's automated agents, work at all.

Article 13(3): as between the originator and the addressee, the addressee is entitled to regard a data message as being that of the originator and to act on that assumption if (a) in order to ascertain whether the data message was that of the originator, the addressee properly applied a procedure previously agreed to by the originator for that purpose; or (b) the data message as received by the addressee resulted from the actions of a person whose relationship with the originator or with any agent of the originator enabled that person to gain access to a method used by the originator to identify data messages as its own.

munotes.in40

The Model Law on the Communication of Data Messages

Article 13(3)(b) puts the risk of a leaked credential on the originator, and it does so on the ground of relationship rather than fault: if the person who misused the method got access through a relationship with the originator or its agent, the addressee may still act on the message. The employee who takes the password is the paradigm case.

Article 13(4) takes that entitlement away in two situations: where the addressee had received notice from the originator that the data message was not the originator's and had reasonable time to act accordingly, and, in a case falling within 13(3)(b), at any time when the addressee knew or should have known, had it exercised reasonable care or used any agreed procedure, that the data message was not that of the originator.

Article 13(5) deals with the content: where a data message is that of the originator or is deemed to be so, the addressee is entitled to regard it as what the originator intended to send and to act on that assumption, except where the addressee knew or should have known that transmission resulted in an error.

Section 11 of the Indian Act enacts article 13(1) and (2) and stops. It provides that an electronic record shall be attributed to the originator if it was sent by the originator himself, by a person who had the authority to act on behalf of the originator, or by an information system programmed by or on behalf of the originator to operate automatically. India left out paragraphs (3), (4) and (5) altogether, which is the largest single omission from the Model Law and the one with the most practical consequence: the Indian Act says nothing about when an addressee may rely on a message that turns out not to be the originator's. Chapter 940 works out what fills the gap.

Article 14: acknowledgement of receipt

Article 14(1): where the originator has requested or agreed with the addressee that receipt be acknowledged, paragraphs (2) to (4) apply.

Article 14(2): where the originator has not agreed with the addressee that the acknowledgement be given in a particular form or by a particular method, an acknowledgement may be given by any communication by the addressee, automated or otherwise, or any conduct of the addressee, sufficient to indicate to the originator that the data message has been received.

Article 14(3): where the originator has stated that the data message is conditional on receipt of the acknowledgement, the data message is treated as though it has never been sent until the acknowledgement is received.

Article 14(4): where the originator has not so stated, and the acknowledgement has not been received within the time specified or agreed or, if none, within a reasonable time, the originator may give notice to the addressee stating that no acknowledgement has been received and specifying a reasonable time by which it must be received; and if it is not received within that time the originator may, on notice to the addressee, treat the data message as though it had never been sent, or exercise any other rights it may have.

munotes.in41

The Model Law on the Communication of Data Messages

Article 14(5) and (6) keep two things apart. Receipt of an acknowledgement is not, of itself, evidence that the message as received corresponds to the message as sent; and, except to the extent that it establishes receipt, article 14 is not concerned with the legal consequences that may flow either from the data message or from the acknowledgement.

Section 12 of the Indian Act is article 14(1) to (4) in almost the same words, and India did enact the equivalent of 14(3) and 14(4), including the two-stage notice procedure. Chapter 950 owns it.

Article 15: time and place of despatch and receipt

This is the article with the greatest practical importance in the whole Model Law, and section 13 of the Indian Act follows it closely.

Article 15(1): unless otherwise agreed, the despatch of a data message occurs when it enters an information system outside the control of the originator or of the person who sent the data message on behalf of the originator.

The test is loss of control. Not when the sender pressed send, and not when it arrived: when it passed out of the sender's hands. That is the electronic equivalent of putting the letter in the post box.

Article 15(2) deals with receipt and distinguishes two cases. If the addressee has designated an information system for the purpose, receipt occurs when the data message enters that designated system, or, if the message is sent to a different system of the addressee, when it is retrieved by the addressee. If the addressee has not designated a system, receipt occurs when the data message enters an information system of the addressee.

So a designated address gets a delivery rule and an undesignated one gets a retrieval rule, which is fair: a person who publishes an address for a purpose can be taken to look at it, and a person who is written to at some other address cannot.

Article 15(3): the data message is deemed to be despatched at the place where the originator has its place of business and to be received at the place where the addressee has its place of business.

That is the crucial deeming, and its purpose is to keep the location of hardware out of the question. Article 15(4) supplies the rules for a party with more than one place of business, the place with the closest relationship to the underlying transaction, or failing that the principal place of business, and for a party with none, its habitual residence. Article 15(5) states that paragraph (3) applies notwithstanding that the place where the information system is located may be different from the place where the data message is deemed to be received.

munotes.in42

The Model Law on the Communication of Data Messages

Section 13 of the Indian Act is article 15, and chapter 870 works it in full with P.R. Transport Agency, the Indian case that decided a writ petition's territorial jurisdiction on it.

The five articles and their Indian counterparts

Model LawSubjectIndian sectionEnacted?
Article 11Contract may be formed by data messagess.10AYes, but only from 27 October 2009
Article 12Declaration of will not denied effectnoneNo; sections 4 and 10A relied on
Article 13(1) and (2)Attribution: sent by, authorised by, or automated system of the originators.11Yes
Article 13(3), (4) and (5)When the addressee may rely; when it may not; error in transmissionnoneNo. The largest omission
Article 14Acknowledgement of receipts.12Yes
Article 15Time and place of despatch and receipts.13Yes

A worked example

Deepak Enterprises in Surat and Ganesh Chemicals in Pune trade by email. Deepak's purchasing manager, Farid, has authority to place orders. Deepak publishes orders@deepak.example as the address for confirmations.

Farid places an order. Under article 13(2)(a) the order is Deepak's, because Farid had authority in respect of it.

Ganesh's order-processing system sends an automated confirmation. Under article 13(2)(b) the confirmation is Ganesh's, because the system was programmed by Ganesh to operate automatically.

The confirmation is despatched under article 15(1) when it leaves Ganesh's control and enters a system outside it, and it is received under article 15(2)(a) when it enters orders@deepak.example, because that address was designated. Had Ganesh sent it to Farid's personal address instead, receipt would have occurred only when Farid actually retrieved it.

It is deemed despatched in Pune and received in Surat under article 15(3), whichever data centres the two mail systems actually use.

Now change the facts. A former employee of Deepak, who still has Farid's password, sends an order for goods Deepak does not want. Under article 13(3)(b) Ganesh is entitled to regard the order as Deepak's, because the sender's relationship with Deepak enabled him to gain access to the method Deepak used to identify its own messages. Under article 13(4)(a) that entitlement stops if Deepak had already notified Ganesh, with time to act.

Under Indian law, section 11 answers the first part and nothing answers the second. That is the practical shape of the omission, and chapter 940 works it.

munotes.in43

The Model Law on the Communication of Data Messages

What this does NOT mean

It does not mean article 15 decides jurisdiction. It decides where a message is deemed despatched and received. Whether that gives a particular court territorial jurisdiction is a question under the local procedural law, and chapter 860 keeps the two apart.

It does not mean an acknowledgement proves the content. Article 14(5) says so in terms: acknowledgement establishes receipt and nothing about correspondence between what was sent and what arrived.

It does not mean attribution decides liability. Article 13 says whose message it is as between originator and addressee. Whether the originator is bound by it is a question of contract and agency.

Quick revision

  • Chapter III is default law, variable by agreement under article 4.
  • Article 11: offer and acceptance may be expressed by data message; a contract is not invalid solely because one was used. Indian section 10A, inserted 2008.
  • Article 12: a declaration of will is not denied effect for being a data message. Not enacted in India.
  • Article 13: attribution. (1) sent by the originator; (2) sent by an authorised person or by an automated system of the originator; (3) when the addressee may rely, including where a relationship gave access to the originator's method; (4) when it may not; (5) errors in transmission. India enacted only (1) and (2), in section 11.
  • Article 14: acknowledgement. Any sufficient communication or conduct; if the originator made the message conditional, it is treated as never sent until acknowledgement; otherwise the two-stage notice procedure. Indian section 12.
  • Article 15: despatch when it leaves the originator's control; receipt when it enters a designated system, or on retrieval if sent elsewhere, or when it enters any system of the addressee if none was designated; deemed despatched and received at the parties' places of business regardless of where the hardware is. Indian section 13.

Test yourself

1. State the test for despatch and the two tests for receipt under article 15. Despatch occurs when the message enters an information system outside the control of the originator or of the person who sent it on the originator's behalf. If the addressee designated a system, receipt occurs when the message enters that system, or on retrieval if it was sent to a different system of the addressee. If no system was designated, receipt occurs when the message enters any information system of the addressee.

2. Why does article 15(3) deem the place of receipt to be the addressee's place of business? Because the location of the server is a commercial and technical accident, unknown to the parties and changeable at will, and making it decisive would let a party choose the applicable rules by choosing a data centre. Article 15(5) says the deeming applies notwithstanding that the system is elsewhere.

munotes.in44

The Model Law on the Communication of Data Messages

3. Which parts of article 13 did India not enact, and why does it matter? Paragraphs (3), (4) and (5). It matters because they are the parts that say when an addressee is entitled to rely on a message that was not in fact the originator's, when that entitlement is lost, and what happens where transmission produced an error. Section 11 attributes messages actually sent or authorised, and leaves the compromised-credential case to the general law.

4. A supplier stipulates that its quotation is conditional on acknowledgement of receipt, and no acknowledgement comes. What is the position under article 14? Under article 14(3) the data message is treated as though it had never been sent until the acknowledgement is received. The supplier does not need to give notice or wait; the condition does the work. Article 14(4)'s two-stage notice procedure applies only where the originator did not make the message conditional.

5. Does an acknowledgement of receipt prove that what arrived is what was sent? No. Article 14(5) provides that receipt of an acknowledgement is not of itself evidence that the data message received corresponds to the message sent. Correspondence is a question of integrity, addressed by article 8 and by the evidence provisions.

Contents This chapter on its own page

munotes.in45

Chapter Nine

The Model Law on Carriage of Goods

Syllabus topic 1.2, "UNCITRAL Model Law"

In one line

Part two of the Model Law deals with the one commercial document that cannot simply be copied, the bill of lading, and it solves the problem by requiring a reliable method of making a data message unique.

In the wording a student can write in an exam: articles 16 and 17 constitute part two of the UNCITRAL Model Law on Electronic Commerce and apply the Law to actions in connection with a contract of carriage of goods, providing that a requirement of writing or of a paper document for such an action is met by one or more data messages, and that where a right or obligation must be conveyed to one person and no other by the transfer of a paper document, that requirement is met by data messages provided a reliable method is used to render them unique.

Why carriage of goods needed its own chapter

Almost every paper requirement in commerce is about recording something. One is not.

A bill of lading is a document of title. The carrier issues it to the shipper, and whoever holds it is entitled to demand the goods at the other end. It is transferred by endorsement and delivery while the ship is at sea, so the cargo can be sold two or three times in transit without anything physical moving. The reason the system works is that there is exactly one bill of lading in existence at a time, and the person holding it holds the goods.

Everything about a data message defeats that. A data message can be copied perfectly, instantly, and without limit. Chapter 20 explains why. If a bill of lading were an ordinary email, the shipper could send the same email to three buyers and each would present it at the port.

So the functional analysis produces a different criterion here. The function of the paper bill of lading is not to record, and not to be signed, and not to be original in the article 8 sense. Its function is to be the only one. The criterion therefore has to be a method that guarantees singularity, and article 17(3) is the only place in the Model Law where such a criterion appears.

Article 16: what part two applies to

Article 16 opens by saying that, without derogating from the provisions of part one, this chapter applies to any action in connection with, or in pursuance of, a contract of carriage of goods. It then lists, expressly without limitation, seven groups of actions.

Group (a) is about the goods themselves: furnishing the marks, number, quantity or weight of goods; stating or declaring their nature or value; issuing a receipt for goods; and confirming that goods have been loaded.

munotes.in46

The Model Law on Carriage of Goods

Group (b) is about the contract and the carrier: notifying a person of terms and conditions of the contract, and giving instructions to a carrier.

Group (c) is about delivery: claiming delivery of goods, authorising release of goods, and giving notice of loss of or damage to goods.

Group (d) is any other notice or statement in connection with the performance of the contract.

Group (e) is undertaking to deliver goods to a named person or a person authorised to claim delivery.

Group (f) is granting, acquiring, renouncing, surrendering, transferring or negotiating rights in goods.

Group (g) is acquiring or transferring rights and obligations under the contract.

Groups (e), (f) and (g) are the ones that matter, because they are the ones a document of title performs. The first four groups could have been handled by article 6 alone.

Article 17: transport documents

Article 17(1): subject to paragraph (3), where the law requires that any action referred to in article 16 be carried out in writing or by using a paper document, that requirement is met if the action is carried out by using one or more data messages.

Article 17(2) makes it apply whether the requirement is an obligation or merely attracts a consequence, in the same terms as articles 6(2), 7(2) and 8(2).

Article 17(3) is the provision worth learning by heart. If a right is to be granted to, or an obligation is to be acquired by, one person and no other person, and if the law requires that, in order to effect this, the right or obligation must be conveyed to that person by the transfer, or use of, a paper document, that requirement is met if the right or obligation is conveyed by using one or more data messages, provided that a reliable method is used to render such data message or messages unique.

Article 17(4) makes the standard of reliability relative, assessed in the light of the purpose for which the right or obligation was conveyed and all the circumstances including any relevant agreement, exactly as articles 7(1)(b) and 8(3)(b) do.

Articles 17(5) to (7) deal with the consequences. Where a right is conveyed by data messages instead of by a paper document, no paper document used to effect any such action is valid unless the use of data messages has been terminated and replaced by paper documents; a paper document issued in those circumstances must contain a statement of the termination; and the rules of law applicable to a contract of carriage evidenced by a paper document are not to be denied application merely because the contract is evidenced by data messages instead.

munotes.in47

The Model Law on Carriage of Goods

The uniqueness requirement, and why nobody could deliver it for twenty years

Article 17(3) states a criterion and deliberately does not say how to meet it. The Model Law is a framework text and leaves technique to technical regulation and to contract, which is what the Guide to Enactment says of the whole instrument.

Meeting it in practice proved very hard. The commercial answer for two decades was a closed system: a registry, run by a service provider, which recorded who held the electronic bill and transferred it on instruction. It works, but only for members of the registry who have contracted into its rules, and it is not the same thing as a negotiable instrument good against the world.

The problem was eventually addressed by a different UNCITRAL instrument. The Model Law on Electronic Transferable Records, adopted in 2017, is built around the idea of control of an electronic record standing in place of possession of a paper one, with singularity, integrity and identifiability as its requirements. That is beyond this syllabus, but a student who mentions it in an answer on part two has shown where the story went.

What India did with part two

India did not enact part two, and it did not have to.

Section 1(4) of the Act, with the First Schedule, excludes from the Act's application a bill of exchange, a power of attorney, a trust, a will, and any contract for the sale or conveyance of immovable property. Chapter 140 owns that Schedule in full.

A bill of lading is not in the First Schedule, so the Act's general provisions can apply to it. What India did not enact is any equivalent of article 17(3), so Indian law has no statutory criterion for making an electronic transferable record unique.

The practical consequence is that an electronic bill of lading in India works by contract. Parties adopt a registry's rulebook and bind themselves to treat the registry's record as determinative. That is enforceable between them and says nothing about a third party who never joined.

A worked example

Konkan Exports ships a container of cashew from Mangaluru to Rotterdam on a vessel operated by Baltic Line.

Under article 16(a)(iii) and (iv), the receipt for the goods and the confirmation that they have been loaded are actions in connection with a contract of carriage, so under article 17(1) they may be done by data message wherever the law required paper.

Under article 16(f) and (g), the transfer of rights in the goods and of rights under the contract while the vessel is at sea is also within the chapter. But that is a transfer of a right to one person and no other, so article 17(3), not 17(1), is the provision that governs it, and it is satisfied only if a reliable method renders the message unique.

munotes.in48

The Model Law on Carriage of Goods

Konkan sells the cargo to a trader in Antwerp, who sells it on to a refiner in Hamburg. Each transfer must leave exactly one person entitled to demand the container. If the electronic record can be duplicated, two buyers can present it and the carrier cannot know which to obey.

Under a registry system, all four parties and the carrier are members. The registry records Konkan as holder, then the trader, then the refiner, and the carrier delivers to whoever the registry names. Under article 17(5), no paper bill may be used unless the electronic system is terminated and replaced, and under 17(6) any paper bill then issued must say so, which is what stops the same cargo being claimed twice, once on paper and once electronically.

Under Indian law the same commercial result is reached by contract, and only as against the people who agreed to it.

What this does NOT mean

It does not mean part two is unimportant because India did not enact it. The syllabus prints "UNCITRAL Model Law" without qualification, and a comparative question about what India took and what it left is precisely where part two belongs.

It does not mean article 17(1) is the same rule as article 6. Article 6 makes a data message satisfy a requirement of writing. Article 17(1) makes it satisfy a requirement of writing or of using a paper document, which is wider, and it does so for the actions article 16 lists rather than generally.

It does not mean a bill of lading is excluded from the Indian Act. The First Schedule excludes a negotiable instrument as defined in section 13 of the Negotiable Instruments Act, 1881, which means a promissory note, a bill of exchange or a cheque. A bill of lading is a document of title to goods and is not a negotiable instrument in that sense.

Quick revision

  • Part two is articles 16 and 17, and it exists for one reason: a document of title must be unique, and a data message is trivially copyable.
  • Article 16 lists seven groups of actions in connection with a contract of carriage, expressly without limitation. Groups (e), (f) and (g), undertaking to deliver, transferring rights in goods, and transferring rights under the contract, are the ones that need special treatment.
  • Article 17(1): a requirement of writing or of a paper document for an article 16 action is met by one or more data messages.
  • Article 17(3): where a right must be conveyed to one person and no other by transfer of a paper document, data messages will do provided a reliable method is used to render them unique. Article 17(4) makes reliability relative.
  • Articles 17(5) to (7): once the electronic route is used, no paper document is valid until the electronic use is terminated and replaced, and the replacement paper must say so.
  • India enacted none of part two. A bill of lading is not in the First Schedule, so the Act's general provisions can reach it, but there is no Indian statutory criterion of uniqueness, and electronic bills of lading operate by contract through registry rulebooks.
  • The UNCITRAL Model Law on Electronic Transferable Records, 2017, is where the uniqueness problem was eventually addressed, through control, singularity, integrity and identifiability.
munotes.in49

The Model Law on Carriage of Goods

Test yourself

1. Why did carriage of goods need a chapter of its own? Because a bill of lading is a document of title whose function is to be the only one in existence, so that the holder is entitled to the goods. Every other paper requirement addressed by the Model Law is about recording, signing or preserving, and can be satisfied by a data message; uniqueness cannot, because a data message can be copied perfectly and without limit.

2. State article 17(3) and identify its criterion. Where a right is to be granted to, or an obligation acquired by, one person and no other, and the law requires it to be conveyed by the transfer or use of a paper document, that requirement is met by one or more data messages provided a reliable method is used to render the data message or messages unique. The criterion is uniqueness, assessed by a standard of reliability that article 17(4) makes relative to the purpose and the circumstances.

3. What do articles 17(5) and 17(6) prevent? The same cargo being claimed twice, once electronically and once on paper. Once rights are conveyed by data messages, no paper document used for the same action is valid unless the electronic use has been terminated and replaced, and any paper document then issued must contain a statement of that termination.

4. Is a bill of lading excluded from the Indian Act by the First Schedule? No. The Schedule excludes a negotiable instrument as defined in section 13 of the Negotiable Instruments Act, 1881, namely a promissory note, bill of exchange or cheque, together with a power of attorney, a trust, a will and a contract for the sale or conveyance of immovable property. A bill of lading is a document of title to goods and is not within that list.

5. How does an electronic bill of lading work in India in the absence of an enacted article 17(3)? By contract. The parties and the carrier join a registry whose rulebook they agree to be bound by, and the registry's record of who holds the electronic bill is treated as determinative between them. It binds only those who joined, which is the difference between a contractual arrangement and a document of title good against the world.

Contents This chapter on its own page

munotes.in50

Chapter Ten

The UNCITRAL Model Law on Electronic Signatures

Syllabus topic 1.2, "UNCITRAL Model Law"

In one line

The 2001 Model Law takes article 7 of the 1996 Model Law and builds a whole statute on it, saying what makes an electronic signature reliable and what the signer, the certifier and the person relying on it each owe.

In the wording a student can write in an exam: the UNCITRAL Model Law on Electronic Signatures, adopted by the General Assembly by resolution 56/80 of 12 December 2001, elaborates the signature provision of the 1996 Model Law by supplying a technology-neutral test of reliability, presumptive criteria that a reliable signature satisfies, and rules of conduct for the signatory, the certification service provider and the relying party, together with a rule for the recognition of foreign certificates and signatures.

Why a second Model Law was needed

Article 7 of the 1996 Model Law states a standard and nothing more. A signature requirement is satisfied by a method that identifies the person and indicates approval, and that is as reliable as appropriate in the circumstances. Chapter 70 works it.

That is exactly right as a principle and useless to a business deciding what to install. A company that has to sign a thousand orders a month cannot litigate the appropriateness of its method each time. It needs to know in advance which methods will be accepted.

Meanwhile legislatures were solving the problem badly. Several States, and the European Union in its first electronic signatures directive of 1999, wrote rules around one technology, public key cryptography, and thereby froze it into law. Chapter 260 explains what that technology is. Freezing a technology into a statute is a mistake that becomes visible only when the technology is superseded.

So the Commission set out to do two things at once, and the tension between them is the whole design of this instrument: to give businesses certainty about which signatures will be accepted, without naming a technology.

Articles 1 and 4: the reach of the Law and how to read it

Article 1, sphere of application. The Law applies where electronic signatures are used in the context of commercial activities, and it does not override any rule of law intended for the protection of consumers.

Both halves of that sentence matter. The Model Law is a commercial instrument, so a State enacting it is not being asked to settle how a consumer contract is signed, and the consumer saving means a national consumer statute survives enactment intact. The Indian Act took the opposite course and made no such distinction: section 1(4) excludes documents by their type, not transactions by whether they are commercial, which is why a negotiable instrument and a power of attorney are outside the Indian Act whoever signs them. Chapters 130 and 140.

munotes.in51

The UNCITRAL Model Law on Electronic Signatures

Article 4, interpretation, and it is the article that keeps the Law uniform. In interpreting the Law regard is to be had to its international origin and to the need to promote uniformity in its application and the observance of good faith. Questions the Law governs but does not expressly settle are to be settled in conformity with the general principles on which the Law is based.

Why an article about interpretation is worth an examination paragraph. A model law that each State reads through its own doctrines produces forty different laws with one text. Article 4(1) tells a national court not to do that, and article 4(2) fills gaps from the instrument's own principles rather than from domestic law. It is the same technique as article 7 of the Vienna Sales Convention, and the Indian Act has no equivalent provision at all.

The solution: a general rule with a presumptive list

Article 6(1) restates article 7 of the 1996 Law. Where the law requires a signature of a person, that requirement is met in relation to a data message if an electronic signature is used that is as reliable as was appropriate for the purpose for which the data message was generated or communicated, in the light of all the circumstances, including any relevant agreement. Article 6(2) applies it to both kinds of statute, as before.

Article 6(3) is the innovation. An electronic signature is considered to be reliable for the purpose of satisfying that requirement if four conditions are met.

(a) The signature creation data are, within the context in which they are used, linked to the signatory and to no other person.

(b) The signature creation data were, at the time of signing, under the control of the signatory and of no other person.

(c) Any alteration to the electronic signature, made after the time of signing, is detectable.

(d) Where a purpose of the legal requirement for a signature is to provide assurance as to the integrity of the information to which it relates, any alteration made to that information after the time of signing is detectable.

Read those four again and notice what they do not say. They do not name public key cryptography, or a hash function, or a certificate. They describe what a technology must achieve: unique linkage, sole control, tamper-evidence of the signature, and tamper-evidence of the document. A digital signature satisfies all four, which is why digital signatures were the technology of the day, but so would anything else that achieved the same results.

Article 6(4) keeps the list from becoming a closed one. Paragraph 3 does not limit the ability of any person to establish the reliability of an electronic signature in any other way, or to adduce evidence of non-reliability. So the four conditions are a safe harbour, not a definition: meet them and reliability is established, fail them and you may still prove it another way.

munotes.in52

The UNCITRAL Model Law on Electronic Signatures

Article 3 states the same principle as a prohibition: nothing in the Law, except article 5, is to be applied so as to exclude, restrict or deprive of legal effect any method of creating an electronic signature that satisfies article 6(1) or otherwise meets the requirements of applicable law. That is the equal treatment of signature technologies, and it is the headline principle of the instrument.

Article 2: the vocabulary Module II uses

Article 2(a): an electronic signature means data in electronic form in, affixed to or logically associated with, a data message, which may be used to identify the signatory in relation to the data message and to indicate the signatory's approval of the information contained in the data message.

Article 2(b): a certificate means a data message or other record confirming the link between a signatory and signature creation data.

Article 2(d): a signatory means a person that holds signature creation data and acts either on its own behalf or on behalf of the person it represents.

Article 2(e): a certification service provider means a person that issues certificates and may provide other services related to electronic signatures.

Article 2(f): a relying party means a person that may act on the basis of a certificate or an electronic signature.

Those five words map onto the Indian Act almost exactly. The Indian subscriber in section 2(1)(zg) is the signatory; the Indian Certifying Authority in section 2(1)(g) is the certification service provider; the Indian Electronic Signature Certificate in section 2(1)(tb) is the certificate. India has no term for the relying party, which is a real gap and one chapter 450 has to work around.

Notice also that "signature creation data" is what India calls the private key, and the Model Law deliberately avoids the cryptographic word.

Articles 8 to 11: three sets of duties

This is the part of the instrument that has no Indian counterpart in the same form, and it is worth learning as a set.

Article 8, the conduct of the signatory. Where signature creation data can be used to create a signature that has legal effect, each signatory shall exercise reasonable care to avoid unauthorised use of its signature creation data; shall without undue delay notify any person that may reasonably be expected to rely on or provide services in support of the signature if the signatory knows the data have been compromised, or if the circumstances known to the signatory give rise to a substantial risk that they may have been; and shall, where a certificate is used, exercise reasonable care to ensure the accuracy and completeness of all material representations made by the signatory that are relevant to the certificate throughout its life cycle. Article 8(2): a signatory shall bear the legal consequences of its failure to satisfy those requirements.

munotes.in53

The UNCITRAL Model Law on Electronic Signatures

Article 9, the conduct of the certification service provider. It shall act in accordance with its own representations about its policies and practices; exercise reasonable care as to the accuracy and completeness of its material representations relevant to the certificate; provide reasonably accessible means enabling a relying party to ascertain from the certificate the identity of the provider, that the signatory identified had control of the signature creation data when the certificate was issued, and that the data were valid at or before that time; provide reasonably accessible means enabling a relying party to ascertain the method used to identify the signatory, any limitation on purpose or value, that the data are valid and uncompromised, any limitation on the provider's liability, whether means exist for the signatory to give notice under article 8, and whether a timely revocation service is offered; where those services are offered, actually provide them; and utilise trustworthy systems, procedures and human resources. Article 9(2) again attaches the legal consequences of failure.

Article 10 says how trustworthiness is assessed, and lists seven factors: financial and human resources including the existence of assets; quality of hardware and software systems; procedures for processing certificates and applications and for retaining records; availability of information to signatories and potential relying parties; regularity and extent of audit by an independent body; the existence of a declaration by the State, an accreditation body or the provider regarding compliance; and any other relevant factor.

Article 11, the conduct of the relying party. A relying party shall bear the legal consequences of its failure to take reasonable steps to verify the reliability of an electronic signature, or, where the signature is supported by a certificate, to take reasonable steps to verify the validity, suspension or revocation of the certificate and to observe any limitation with respect to it.

Article 11 is the shortest article and the most neglected. It puts a burden on the person who relies. A party that acts on a certificate without checking whether it has been revoked, or that ignores a stated limit on the value of transactions the certificate covers, bears the consequence. The Indian Act has no equivalent provision at all, and chapter 340 has to reason from section 42 and general principle instead.

Article 7: who decides

Article 7(1) leaves a blank for the enacting State: any person, organ or authority, whether public or private, specified by the enacting State as competent, may determine which electronic signatures satisfy article 6.

munotes.in54

The UNCITRAL Model Law on Electronic Signatures

Article 7(2) requires any such determination to be consistent with recognised international standards, and article 7(3) preserves the rules of private international law.

India filled that blank with the Central Government and the Second Schedule. Section 3A of the Act provides that a subscriber may authenticate an electronic record by an electronic signature or authentication technique which is considered reliable and specified in the Second Schedule, and section 3A(2) lists the factors the technique must satisfy, which are recognisably article 6(3). Chapter 290 owns section 3A and the Second Schedule.

Article 12: foreign certificates and signatures

Article 12(1): in determining whether or to what extent a certificate or an electronic signature is legally effective, no regard shall be had to the geographic location where the certificate is issued or the signature created or used, or to the geographic location of the place of business of the issuer or signatory.

Article 12(2) and (3): a certificate issued outside the enacting State, and a signature created or used outside it, have the same legal effect as a domestic one if they offer a substantially equivalent level of reliability.

Article 12(4) directs regard to recognised international standards and any other relevant factors in assessing equivalence.

Article 12(5) preserves party autonomy: where parties agree between themselves to the use of certain types of electronic signatures or certificates, that agreement is to be recognised as sufficient for cross-border recognition, unless it would not be valid or effective under applicable law.

Section 19 of the Indian Act is a narrower answer. It empowers the Controller, with the previous approval of the Central Government and by notification, to recognise a foreign Certifying Authority, subject to conditions. So India requires an act of recognition where article 12 requires an assessment of equivalence. Chapter 420 owns section 19.

The two Model Laws compared

1996, Electronic Commerce2001, Electronic Signatures
Adopted16 December 1996, resolution 51/16212 December 2001, resolution 56/80
Articles17, in two parts12
SubjectData messages generally: writing, signature, original, evidence, retention, attribution, acknowledgment, despatch and receiptElectronic signatures only
The signature ruleArticle 7: a method that identifies and indicates approval, as reliable as appropriateArticle 6: the same, plus four presumptive criteria in 6(3)
Duties of partiesNoneArticles 8, 9 and 11 on the signatory, the certification service provider and the relying party
Foreign recognitionNot addressedArticle 12: no regard to geography, equivalence of reliability, party agreement
Enacted in IndiaSubstantially, in sections 4, 5, 7, 11, 12 and 13The reliability criteria, in section 3A(2). Not the duties, and not article 12
munotes.in55

The UNCITRAL Model Law on Electronic Signatures

A worked example

Vikram, a director of a Nagpur company, holds an Electronic Signature Certificate and uses it to sign a supply agreement with a buyer in Colombo.

Under article 6(3), the signature is reliable if the signature creation data are linked to Vikram and to no other person, were under his sole control at the moment of signing, and if any later alteration to the signature or to the agreement is detectable. A digital signature achieves all four, so the requirement in article 6(1) is satisfied without any inquiry into what was appropriate.

Under article 8, Vikram must take reasonable care to stop anybody else using the data, and if he learns his private key has been copied, or learns facts giving rise to a substantial risk that it has, he must notify without undue delay both his certification service provider and anybody who may reasonably be expected to rely. Under article 8(2) he bears the consequences of not doing so.

Under article 9, his provider must operate trustworthy systems, must let the Colombo buyer check the certificate's validity and any limit on its use, and must run a timely revocation service if it has said it does.

Under article 11, the buyer must take reasonable steps to check that the certificate has not been suspended or revoked and to observe any limitation on it. If the certificate says it covers transactions up to fifty lakh rupees and the agreement is for two crore, the buyer that ignores the limit bears the consequence.

Under article 12, the fact that the certificate was issued in India and the buyer is in Sri Lanka is irrelevant, and the certificate has the same effect there as a Sri Lankan one if it offers a substantially equivalent level of reliability.

Under Indian law, article 6(3) is section 3A(2), and articles 8, 9, 11 and 12 have no direct counterpart. The signatory's duty is in section 42, the Certifying Authority's obligations are in sections 30 to 34 and the Certifying Authorities Rules 2000, there is nothing on the relying party, and foreign recognition is by notification under section 19.

What this does NOT mean

It does not mean the 2001 Law replaces the 1996 Law. The Guide to Enactment says the new Model Law is a separate legal instrument, fully consistent with the 1996 Law and building on its article 7. A State may enact either or both.

It does not mean article 6(3) defines an electronic signature. It states when one is considered reliable, and article 6(4) preserves the ability to prove reliability otherwise or to disprove it.

munotes.in56

The UNCITRAL Model Law on Electronic Signatures

It does not mean India enacted this Model Law. It enacted its reliability criteria into section 3A(2), and the 2008 amendment's shift from digital signature to electronic signature follows its philosophy. The duty articles and article 12 were not taken.

Quick revision

  • Adopted 12 December 2001 by resolution 56/80. Twelve articles. Builds on article 7 of the 1996 Model Law.
  • Article 3, equal treatment of signature technologies: no method that meets article 6(1) or applicable law is to be excluded or restricted.
  • Article 6(1): as reliable as appropriate in the circumstances. Article 6(3): four presumptive criteria. Signature creation data linked to the signatory alone; under the signatory's sole control at signing; any later alteration to the signature detectable; any later alteration to the information detectable where the requirement exists to assure integrity.
  • Article 6(4): the four criteria are a safe harbour, not a definition. Reliability may be proved otherwise, and non-reliability may be proved.
  • Article 7: the enacting State names who may determine which signatures satisfy article 6, consistently with recognised international standards. India named the Central Government and the Second Schedule, in section 3A.
  • Articles 8, 9 and 11: duties of the signatory (care, notify on compromise, accurate representations), the certification service provider (act on its own representations, enable verification, trustworthy systems), and the relying party (verify reliability, check revocation, observe limitations). Each bears the consequences of failure.
  • Article 10: seven factors for trustworthiness, including independent audit.
  • Article 12: no regard to geography; a foreign certificate or signature has the same effect if substantially equivalent in reliability; party agreement suffices for cross-border recognition. India instead requires recognition by notification under section 19.

Test yourself

1. State the four criteria in article 6(3) and explain why none of them names a technology. Signature creation data linked to the signatory and to no other person in the context of use; under the signatory's control and no other person's at the time of signing; any later alteration to the signature detectable; and, where the requirement exists to assure integrity, any later alteration to the information detectable. They name results rather than techniques because naming a technology in a statute freezes it, which is the error the first European directive made, and because article 3 requires equal treatment of signature technologies.

2. What is the effect of article 6(4)? It makes article 6(3) a safe harbour rather than a definition: a person may establish the reliability of a signature that does not meet the four criteria in any other way, and a person may adduce evidence that a signature meeting them is in fact unreliable. Without it, the four criteria would have become an exclusive test and the equal treatment principle would have been defeated.

munotes.in57

The UNCITRAL Model Law on Electronic Signatures

3. Set out the duty of the relying party and say why it matters. Article 11: a relying party bears the legal consequences of failing to take reasonable steps to verify the reliability of the signature and, where a certificate supports it, to verify the certificate's validity, suspension or revocation and to observe any limitation on it. It matters because it places part of the risk on the person who chose to act, so a party who ignores a revocation list or a stated value limit cannot complain, and because the Indian Act contains no equivalent.

4. How does India's answer to article 7 differ from India's answer to article 12? For article 7, India named a competent authority and a method: section 3A makes the Central Government and the Second Schedule the determinants, and section 3A(2) reproduces the reliability criteria. For article 12, India did not adopt the equivalence test at all; section 19 requires the Controller, with the previous approval of the Central Government, to recognise a foreign Certifying Authority by notification, so recognition is an administrative act rather than an assessment made case by case.

5. Why did the Commission write a second Model Law instead of amending the first? Because article 7 of the 1996 Law stated a correct principle that gave businesses no advance certainty about which methods would be accepted, while several legislatures were supplying certainty by writing one technology into their statutes. A separate instrument could add presumptive criteria and rules of conduct without disturbing the 1996 text, and could be enacted by States that had already enacted the first.

Contents This chapter on its own page

munotes.in58

Chapter Eleven

How India Enacted the Model Law

Syllabus topic 1.2, "UNCITRAL Model Law"

In one line

India took the Model Law's recognition provisions almost word for word, narrowed its signature rule, left out four articles altogether, and added two chapters the Model Law never contemplated.

In the wording a student can write in an exam: the Information Technology Act, 2000 gives effect to the UNCITRAL Model Law on Electronic Commerce by enacting its functional equivalence provisions on writing, retention, attribution, acknowledgment and the time and place of despatch and receipt in substantially the Model Law's terms, but it departs from the Model Law by substituting a prescribed-method rule for the reliability standard on signatures, by omitting articles 3, 5 bis, 12 and 13(3) to (5), and by adding a licensing regime, an offence chapter and a chapter of State powers which have no counterpart in the Model Law at all.

Why harmonisation was the point

The Model Law's own object is uniformity, and the resolution says so. General Assembly resolution 51/162 recommends that all States give favourable consideration to the Model Law when they enact or revise their laws, in view of the need for uniformity of the law applicable to alternatives to paper-based methods of communication and storage of information. The Act's preamble recites that recommendation.

Uniformity matters commercially because the parties are in different States. If India says an emailed order is not writing and Singapore says it is, the parties cannot know what they have. If both enact the same rule, they can. That is the whole argument, and it is what an examination question about harmonisation is asking for.

Harmonisation by model law works differently from harmonisation by treaty. A treaty produces one text binding on the ratifying States. A model law produces many texts, each the enacting State's own, resembling one another to the extent each State chose. So the harmonisation achieved is a question of fact about what each State enacted, and that is exactly why this comparison is worth making.

What India enacted, provision by provision

Model LawIndian provisionHow close
Art. 1, sphere of applications.1(2) and s.1(4) with the First ScheduleIndia took the alternative text the Commission offered: general application with a list of exclusions, rather than limitation to commerce
Art. 2, definitionss.2(1), especially (za) originator, (b) addressee, (w) intermediary, (t) electronic recordOriginator and addressee almost word for word, each excluding an intermediary. India added a long list to intermediary and did not enact "information system"
Art. 3, interpretationnoneNot enacted
Art. 4, variation by agreementinside ss.11, 12 and 13Enacted in substance, not as a section
Art. 5, legal recognitionss.4 and 5Enacted, but in positive form rather than as a prohibition
Art. 5 bis, incorporation by referencenoneNot enacted
Art. 6, writings.4Very close: "accessible so as to be usable for a subsequent reference"
Art. 7, signatures.5 with s.3 and s.3ASubstantially different. Prescribed method, not a reliability standard
Art. 8, originalss.7A and 14Partially, and the integrity idea reappears in s.63 of the Bharatiya Sakshya Adhiniyam
Art. 9, admissibility and weights.65B of the Evidence Act 1872, inserted by s.92 and the Second Schedule; now s.63 BSA 2023Different in kind. India made reliability a condition of admissibility, not a factor going to weight
Art. 10, retentions.7Almost word for word, with the same three conditions
Art. 11, formation of contractss.10AEnacted, but only from 27 October 2009
Art. 12, declaration of willnoneNot enacted
Art. 13, attributions.11Only paragraphs (1) and (2). Paragraphs (3), (4) and (5) not enacted
Art. 14, acknowledgments.12Close, including the conditional-message rule and the two-stage notice
Art. 15, despatch and receipts.13Close, including the deeming of place to the place of business
Arts. 16 and 17, carriage of goodsnoneNot enacted
MLES 2001 art. 6(3)s.3A(2)The four reliability criteria, enacted in 2008
MLES 2001 arts. 8, 9, 11, 12none in that formDuties of the signatory and the Certifying Authority appear in ss.30 to 42 and the CA Rules; nothing on the relying party
munotes.in59

How India Enacted the Model Law

The four things India took, and took well

Writing, in section 4. Where any law provides that information or any other matter shall be in writing or in the typewritten or printed form, that requirement shall be deemed to have been satisfied if such information or matter is rendered or made available in an electronic form and accessible so as to be usable for a subsequent reference. That is article 6 with the criterion intact.

Retention, in section 7. The three conditions of article 10 are all there: accessibility for subsequent reference, retention in the format generated, sent or received or a format that can be demonstrated to represent it accurately, and retention of details enabling identification of the origin, destination, date and time of despatch or receipt. Section 7(2) adds a sensible exception for information automatically generated solely to enable a message to be sent or received.

Acknowledgment, in section 12. Article 14's structure survives: any communication or conduct sufficient to indicate receipt where no form was agreed; the message treated as never sent where the originator stipulated that it was conditional on acknowledgment; and the two-stage notice where it did not.

Despatch and receipt, in section 13. Despatch when the record enters a computer resource outside the originator's control. Receipt at the designated computer resource, or on retrieval if sent elsewhere, or on entry into any computer resource of the addressee where none was designated. And the deeming in section 13(3): the record is deemed despatched at the place where the originator has his place of business and received where the addressee has his, with section 13(5) defining place of business for parties with more than one or none. Chapter 870 works it with P.R. Transport Agency.

munotes.in60

How India Enacted the Model Law

On these four, harmonisation was achieved. An Indian court and a Singaporean court applying their respective enactments would reach the same result on the same facts.

The one big divergence: signature

This is the answer to the critical half of the 2025-26 question, and it should be the centre of any answer on how far the Act incorporates the Model Law's principles.

Article 7 is a standard. Any method that identifies the person and indicates approval will do, if it is as reliable as appropriate in the circumstances. The circumstances include the value of the transaction, the practice between the parties and any agreement. A typed name may be enough for one purpose and not for another.

Section 5 is a rule. Where any law provides that information or any matter shall be authenticated by affixing the signature, that requirement shall be deemed satisfied if such information or matter is authenticated by means of an electronic signature affixed in such manner as may be prescribed by the Central Government.

Four consequences follow, and they are examinable.

First, certainty is gained. A business knows in advance that a digital signature from a licensed Certifying Authority, or the Aadhaar-based e-authentication technique in the Second Schedule, will satisfy any statutory signature requirement.

Second, flexibility is lost. A method that plainly identifies the signer and shows approval, and is entirely appropriate for the transaction, does not satisfy section 5 unless it is prescribed. A scanned signature, a typed name and a one-time password sent to a registered mobile number are all outside it.

Third, India built an institution the Model Law never needed. Because the acceptable methods are prescribed, somebody has to license and supervise the people who supply them, which is Chapters VI and VII of the Act and the whole of Module II topic 2.3.

Fourth, the technology neutrality of article 3 of the 2001 Model Law is achieved only formally. Section 3A does allow the Second Schedule to be amended, and section 3A(2) reproduces the article 6(3) criteria, so a new technique can be added. But it must be added, by the Central Government, before anyone may use it.

Two honest points on the other side. India was legislating in 1999 into a system with no history of accepting anything but a wet signature, and a prescribed method was the safer choice. And section 5 bites only where a law requires a signature, which most commercial dealing does not, so the practical reach of the divergence is narrower than it first appears. Chapter 930 shows what section 10A then does.

munotes.in61

How India Enacted the Model Law

The four omissions, and what each costs

Article 3, interpretation. Without it, an Indian court construing section 13 has no direction to have regard to the instrument's international origin, to uniformity of application, or to the general principles of the Model Law in filling a gap. The cost is that Indian interpretation is not formally tied to the interpretation given elsewhere, which is a direct loss of the harmonisation the whole exercise was for.

Article 5 bis, incorporation by reference. Without it, the enforceability of terms behind a link is decided by ordinary principles of notice and assent with no statutory starting point. Chapter 960 works the browse-wrap problem that results.

Article 12, declaration of will. Without it, a unilateral electronic notice that is not part of a contract, such as a notice of termination or a revocation, is recognised only through the general width of section 4.

Article 13(3), (4) and (5), reliance on an attributed message. This is the most serious. Section 11 says when a record is the originator's. The Model Law goes on to say when the addressee is entitled to act as though it is, when that entitlement is lost, and what happens when transmission introduced an error. The compromised-password case, which is the commonest fact pattern in practice, is squarely within article 13(3)(b) and is answered in India only by the general law of agency, estoppel and negligence. Chapter 940 works it.

What India added, which the Model Law never had

Chapters VI and VII: the Controller of Certifying Authorities and the licensing regime, sections 17 to 42. The Model Law on Electronic Signatures has duty articles but no regulator, and the 1996 Model Law has neither.

Chapter IX and Chapter XI: penalties, compensation and offences, sections 43 to 47 and 65 to 78. Nothing in either Model Law creates a penalty or an offence. Every one of these is an Indian policy choice.

Chapter X: an appellate tribunal, sections 48 to 64.

The State powers in sections 69, 69A, 69B, 70, 70A and 70B, on interception, blocking, traffic data, protected systems, critical information infrastructure and CERT-In. These are the furthest of all from anything UNCITRAL wrote, and Module III is largely about them.

The intermediary provisions in section 79 and the rules under it. The Model Law defines an intermediary in order to exclude it from being an originator or an addressee. India defines it in order to give it an immunity and then attach conditions to it.

munotes.in62

How India Enacted the Model Law

So the Act is a commercial statute with a regulatory statute and a criminal statute welded on. A critical answer should say so, and should say that the welding shows: the offences chapter uses the definitions written for a chapter about trade, so that section 66 borrows its actus reus from section 43, a civil provision about compensation.

How far was harmonisation achieved? An honest assessment

On the recognition provisions, substantially. Writing, retention, attribution in its basic form, acknowledgment and the rules on despatch and receipt are all recognisably the Model Law, and a foreign lawyer reading them would know where they came from.

On signature, not really. India adopted the objective of article 7 and rejected its method, which means that a signature acceptable in most enacting States is not acceptable in India, and the divergence is at the point where cross-border transactions most often need certainty.

On evidence, not at all. Article 9 keeps admissibility and weight apart and India merged them, which is why the Indian case law on section 65B and now section 63 of the Bharatiya Sakshya Adhiniyam has been so unsettled. Chapter 1270 works it.

And on everything India added, the question does not arise, because there was nothing to harmonise with.

One further point deserves credit. Because the Act took the Model Law's technology-neutral definitions of data, information and electronic record, it has survived twenty-six years of technological change without needing to be redefined, and the 2026 amendment on synthetically generated information was made in rules rather than by amending the Act's vocabulary. That is the Model Law's method working.

A worked example

Alpha Fabrics in Ichalkaranji contracts with Beta Textiles in Dubai by email. The Emirates has legislation based on the Model Law; India has the Act.

Writing. Both satisfied: article 6 in Dubai, section 4 in India, same criterion.

Retention. Both satisfied: article 10 and section 7, same three conditions.

Time and place. Both reach the same answers: despatch on leaving the sender's control, receipt at the designated system, place deemed to be the place of business.

Signature. Alpha's managing director types his name at the foot of the confirmation. In Dubai that may satisfy the signature requirement if it was as reliable as appropriate. In India it does not satisfy section 5, because a typed name is not prescribed. If Indian law requires a signature for this contract, and it generally does not, Alpha has a problem that Beta does not.

Attribution. Beta receives an order from Alpha's account, sent by a dismissed employee. In Dubai, article 13(3)(b) entitles Beta to act on it, subject to article 13(4). In India, section 11 does not attribute it, because the employee had no authority, and Beta must fall back on estoppel or on Alpha's negligence.

munotes.in63

How India Enacted the Model Law

Those last two divergences are precisely the harmonisation gap, and they are what a critical answer should name.

What this does NOT mean

It does not mean the Act failed. It achieved for India what the Model Law was for, and it did it in 2000, ahead of most of the region.

It does not mean the omissions were accidents. India took the alternative texts the Commission itself offered in footnotes to article 1, which shows the drafters were reading closely.

It does not mean the added chapters are a criticism. Every State that enacted the Model Law added a penal and regulatory layer of some kind, because a commerce statute alone leaves the wrongs unaddressed. The criticism is about the joinery, not about the decision to build both.

Quick revision

  • The object is uniformity, and resolution 51/162 says so; the Act's preamble recites it.
  • Taken and taken well: writing (s.4 from art. 6), retention (s.7 from art. 10), acknowledgment (s.12 from art. 14), despatch and receipt (s.13 from art. 15).
  • The big divergence: art. 7 is a reliability standard; s.5 is a prescribed method. Gains certainty, loses flexibility, and forces the whole Certifying Authority regime into existence.
  • Four omissions: art. 3 (interpretation), art. 5 bis (incorporation by reference), art. 12 (declaration of will), and art. 13(3) to (5) (when the addressee may rely). The last is the most serious.
  • Part two, arts. 16 and 17, not enacted, so India has no statutory criterion of uniqueness for an electronic transferable record.
  • India added: the Controller and licensing (Ch. VI and VII), penalties and offences (Ch. IX and XI), a tribunal (Ch. X), the State powers (ss. 69 to 70B) and the intermediary safe harbour (s.79). None has a Model Law counterpart.
  • Assessment: substantial harmonisation on recognition, little on signature, none on evidence, and no question arising on the added chapters.

Test yourself

1. How does a model law harmonise the law, and how does that differ from a treaty? A model law is a text legislatures may enact with or without modification, so harmonisation is achieved to the extent each State adopts it and is a question of fact about each enactment. A treaty produces a single text binding on ratifying States in the terms ratified. UNCITRAL chose a model law because the technology was moving faster than a treaty could be renegotiated.

2. Name four provisions of the Act that follow the Model Law closely, with the article each comes from. Section 4 from article 6 on writing; section 7 from article 10 on retention; section 12 from article 14 on acknowledgment of receipt; section 13 from article 15 on the time and place of despatch and receipt. Section 11 from article 13(1) and (2) on attribution is a fifth, but only in part.

munotes.in64

How India Enacted the Model Law

3. Explain the difference between article 7 and section 5, and give two consequences. Article 7 accepts any method that identifies the signer and indicates approval and is as reliable as appropriate in the circumstances. Section 5 requires an electronic signature affixed in the manner prescribed by the Central Government. Consequences: businesses gain certainty about which methods work but lose the ability to use an appropriate method that has not been prescribed; and India needed a licensing regime for the suppliers of prescribed methods, which is Chapters VI and VII of the Act.

4. Which omission from the Model Law is the most serious in practice, and why? Article 13(3) to (5). Section 11 says when a record is the originator's, but the Act says nothing about when an addressee may act on a message that appears to be from the originator and is not, when that entitlement is lost, or what happens where transmission produced an error. The compromised-credential case is the commonest fact pattern in practice and is left to agency, estoppel and negligence.

5. Assess how far the Act successfully incorporates the Model Law's principles. Substantially on the recognition provisions, where writing, retention, acknowledgment and the rules on despatch and receipt reproduce the Model Law's criteria and would yield the same results in another enacting State. Only formally on signature, where the objective was adopted and the method rejected. Not at all on evidence, where article 9 keeps admissibility and weight apart and Indian law made reliability a condition of admissibility. And not applicable to the licensing, penal, appellate, State powers and intermediary chapters, which India added and which have no Model Law counterpart at all.

Contents This chapter on its own page

munotes.in65

Chapter Twelve

The Scheme of the Information Technology Act

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

The Act has thirteen chapters, and they fall into four blocks: making electronic records work, regulating the people who certify signatures, punishing misuse, and giving the State powers over the network.

In the wording a student can write in an exam: the Information Technology Act, 2000 is arranged in thirteen chapters running from section 1 to section 90, comprising a preliminary chapter, three chapters giving legal effect to electronic records and signatures, a chapter on secure records, two chapters regulating Certifying Authorities and Electronic Signature Certificates, a chapter of subscriber duties, chapters on penalties and adjudication and on appeals, a chapter of offences, a chapter conferring immunity on intermediaries, and a miscellaneous chapter.

Why a student needs the map before the detail

A statute read section by section teaches nothing about why the sections are where they are. The reason section 43 sits next to section 44 is that both are civil penalties. The reason section 66 borrows its conduct from section 43 is that Chapter XI was written later, on top of Chapter IX. The reason section 79 has a chapter to itself is that it was rewritten in 2008 to do a job the original Act had not thought about.

And an examination answer that locates a provision earns marks that one which merely recites it does not. Being able to say that section 69A sits in the offences chapter although it creates no offence, or that section 43A sits in the penalties chapter although it is a compensation provision, shows a reader who has understood the architecture.

The thirteen chapters

ChapterHeadingSectionsWhat it does
IPreliminary1 to 2Extent, application, the First Schedule exclusions, and every definition
IIDigital Signature and Electronic Signature3 to 10AAuthentication, electronic signature, legal recognition of records and signatures
IIIElectronic Governance6 to 9Use in Government, service delivery, retention, audit, Electronic Gazette
IVAttribution, Acknowledgment and Despatch of Electronic Records11 to 13Whose record it is, acknowledgment, time and place
VSecure Electronic Records and Secure Electronic Signatures14 to 16What makes a record or signature secure, and the security procedure
VIRegulation of Certifying Authorities17 to 34The Controller, licensing, and the duties of a Certifying Authority
VIIElectronic Signature Certificates35 to 39Issue, representations, suspension and revocation
VIIIDuties of Subscribers40 to 42The key pair, acceptance, control of the private key
IXPenalties, Compensation and Adjudication43 to 47Civil liability for damage and for failing to protect data, and the adjudicating officer
XThe Appellate Tribunal48 to 64The Tribunal, appeals, compounding and recovery
XIOffences65 to 78The criminal provisions, and the State powers in sections 69 to 70B
XIIIntermediaries Not To Be Liable In Certain Cases79 to 79AThe safe harbour, and the Examiner of Electronic Evidence
XIIIMiscellaneous80 to 90Search, overriding effect, encryption, companies, rule-making
munotes.in66

The Scheme of the Information Technology Act

Two notes on that table, and both are traps.

Chapter II and Chapter III overlap in numbering because section 6A was inserted into Chapter III and sections 10 and 10A into Chapter II, so the section runs are not neatly separated. Read the chapter headings, not the numbers.

The chapter headings themselves have been amended. Chapter II was headed "Digital Signature" until 2008 and is now "Digital Signature and Electronic Signature"; Chapter X was headed "The Cyber Appellate Tribunal" until the Finance Act 2017 and is now "The Appellate Tribunal"; Chapter XII was substituted whole in 2008. A textbook printed before 2009 gives the old headings.

The four blocks

Block one, Chapters I to V, sections 1 to 16: making electronic records work. This is the Model Law. Everything here is about giving an electronic record the legal effect a paper one would have had, and about the mechanical rules that follow once people communicate by machine. If the Act had stopped at section 16 it would have been a faithful enactment of the 1996 Model Law and nothing else.

Block two, Chapters VI to VIII, sections 17 to 42: the trust infrastructure. Because section 5 accepts only a prescribed method, somebody must supply and vouch for that method, and somebody must supervise the suppliers. Chapter VI creates the Controller and the licence; Chapter VII governs the certificate; Chapter VIII binds the subscriber. Chapter 110 explains why India needed this block and the Model Law did not.

Block three, Chapters IX to XI, sections 43 to 78: consequences. Chapter IX is civil: damage, compensation, adjudication by an officer rather than a court. Chapter X is the appeal. Chapter XI is criminal. The sequence is deliberate and useful: the Act tries a civil answer first and reaches for the criminal law afterwards.

Block four, sections 69 to 70B and Chapter XII, and much of Chapter XIII: the State and the network. These sit inside Chapters XI and XIII rather than in a chapter of their own, which is the Act's least tidy feature. Interception, blocking, traffic-data monitoring, protected systems, critical information infrastructure and CERT-In are all in the offences chapter. The intermediary safe harbour has a chapter to itself. Module III is largely block four.

Where to find things: a lookup for the whole subject

Definitions: section 2. Every term. Chapters 150 and 160.

Does the Act apply to this document at all? Section 1(4) and the First Schedule. Chapter 140.

munotes.in67

The Scheme of the Information Technology Act

Is this electronic record as good as writing? Section 4. As good as a signature? Section 5 with sections 3 and 3A.

How long must this be kept, and in what form? Section 7.

Whose message is it? Section 11. When and where was it sent and received? Section 13.

Who licenses the people who issue certificates? Section 17, and the licence is under section 24.

My certificate has been misused. What now? Sections 37 to 39 on suspension and revocation, section 42 on the duty to keep the private key secret, and section 43 or 66 against whoever misused it.

Somebody damaged my data. Section 43 for compensation, section 66 for the offence, section 46 for who adjudicates a claim up to five crore rupees.

Somebody published my private photograph. Section 66E, and section 67 or 67A if it is obscene or sexually explicit, and rule 3(2)(b) of the 2021 Rules for a takedown in twenty-four hours.

The Government wants to read my messages. Section 69 and the Interception Rules 2009.

The Government wants a website blocked. Section 69A and the Blocking Rules 2009.

A platform is refusing to take down defamatory material. Section 79 with the 2021 Rules, and chapter 1360.

A company's server was breached and my data leaked. Section 43A with the SPDI Rules 2011 for compensation, section 72A if there was a service-provider disclosure in breach of contract, and the CERT-In directions for the reporting obligation.

Where does the Act say it prevails over other law? Section 81, with its proviso preserving the Copyright Act and the Patents Act. Chapter 1280.

The rules, and why the Act is unreadable without them

Section 87 empowers the Central Government to make rules, and it is a very long section. Almost every important question in this subject is answered in a rule and not in the Act.

SectionRules made under itChapter
6AElectronic Service Delivery Rules 2011370
10 and 3ACertifying Authorities Rules 2000; the 2016 electronic signature notifications460, 290
43AReasonable Security Practices Rules 2011, the SPDI Rules230
46Adjudicating Officers Rules 20031120
69Interception, Monitoring and Decryption Rules 2009800
69ABlocking for Access of Information by Public Rules 2009810
69BMonitoring and Collecting Traffic Data Rules 2009820
70Information Security Practices for Protected System Rules 2018780
70ANCIIPC Rules 2013780
70BCERT-In Rules 2013, and the Directions of 28 April 2022760, 770
79Intermediary Guidelines and Digital Media Ethics Code Rules 2021, as amended 10 February 20261350, 1360, 1370, 990, 1000
79, cyber cafesGuidelines for Cyber Cafe Rules 20111430

A student who reads the Act and not the rules will know that section 79 confers an immunity and will not know a single thing an intermediary actually has to do.

munotes.in68

The Scheme of the Information Technology Act

The four Schedules

The First Schedule, under section 1(4), lists the documents and transactions the Act does not apply to. Chapter 140 owns it.

The Second Schedule, under section 3A, specifies the electronic signature or electronic authentication techniques. Chapter 290 owns it.

The Third and Fourth Schedules were the amending Schedules, carried by sections 91 to 94, which amended the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934. Sections 91 to 94 were omitted in 2008 as spent, having done their work. What section 92 did to the Evidence Act, inserting the old section 65B, is taught in chapter 1270 as history.

A worked example: finding your way

A client says: "Our accounts clerk received an email that looked like it came from our supplier, changed the bank details, and we paid eighteen lakh rupees to a fraudster. What can we do?"

Start with Chapter I. Is this within the Act at all? Yes: an electronic record, a computer resource, and nothing in the First Schedule excludes it.

Chapter IV. Was the email attributed to the supplier under section 11? No, unless it was sent by the supplier, by somebody authorised, or by the supplier's automated system. So the supplier is not bound by it, and chapter 940 explains what the Act does not say about reliance.

Chapter IX. Section 43 gives a claim for compensation against whoever accessed a computer resource without authorisation or introduced a deceptive record; if the supplier's mail account was compromised and the supplier was negligent in protecting sensitive personal data, section 43A may reach the supplier too, and chapter 230 works the SPDI Rules.

Chapter XI. Section 66 makes the fraudster's conduct an offence; section 66C reaches the use of another's identifying feature; section 66D reaches cheating by personation using a computer resource.

Chapter IX again. Section 46: the claim for eighteen lakh rupees goes to the adjudicating officer, not to a civil court, because it is under five crore rupees.

Chapter XII. Is the email provider liable? Section 79, and almost certainly not.

Outside the Act. Section 318 of the Bharatiya Nyaya Sanhita for cheating, the bank's obligations under the Reserve Bank's directions on unauthorised electronic transactions, and section 63 of the Bharatiya Sakshya Adhiniyam to prove the emails.

Every one of those steps is a chapter of this book, and the map is what let us find them in order.

What this does NOT mean

It does not mean the chapters are watertight. Sections 69 to 70B create no offence in the ordinary sense and sit in the offences chapter; section 43A creates no penalty and sits in the penalties chapter. The headings are a guide, not a classification.

munotes.in69

The Scheme of the Information Technology Act

It does not mean the Act is self-contained. Section 81 gives it overriding effect, but the general criminal law, the law of contract, the law of evidence and the law of copyright all continue to apply, and much of Module IV is about how they fit together.

It does not mean sections 91 to 94 never mattered. They are the reason electronic records are admissible in Indian courts at all, and their omission in 2008 is a tidying up of provisions that had already done their work.

Quick revision

  • Thirteen chapters, sections 1 to 90. Five omitted sections: 20, 91, 92, 93, 94.
  • Four blocks: recognition (I to V, ss.1 to 16); trust infrastructure (VI to VIII, ss.17 to 42); consequences (IX to XI, ss.43 to 78); the State and the network (ss.69 to 70B, XII and parts of XIII).
  • Chapter headings have been amended: Chapter II gained "and Electronic Signature" in 2008; Chapter X lost "Cyber" in 2017; Chapter XII was substituted in 2008.
  • Section 87 is the rule-making power, and almost every operative detail is in a rule, not in the Act.
  • Four Schedules: the First under s.1(4), exclusions; the Second under s.3A, signature techniques; the Third and Fourth, the amending Schedules carried by ss.91 to 94, now omitted as spent.
  • The untidiness worth naming: sections 69 to 70B are State powers sitting in the offences chapter, and section 43A is a compensation provision sitting in the penalties chapter.

Test yourself

1. Name the four blocks of the Act and the sections in each. Recognition, Chapters I to V, sections 1 to 16. The trust infrastructure, Chapters VI to VIII, sections 17 to 42. Consequences, Chapters IX to XI, sections 43 to 78. The State and the network, sections 69 to 70B inside Chapter XI, Chapter XII on intermediaries, and parts of Chapter XIII.

2. Which chapter would you look in for each of: whether an email satisfies a requirement of writing; who licenses a Certifying Authority; whether a marketplace is liable for a seller's listing; and where a claim for four crore rupees is decided? Chapter II, section 4. Chapter VI, sections 17 and 24. Chapter XII, section 79. Chapter IX, section 46, because the claim is under five crore rupees and goes to the adjudicating officer.

3. Why is it a mistake to read the Act without the rules? Because section 87 leaves the operative detail to rules, and the provisions that decide practical questions are in them: what reasonable security practices are, how a blocking direction is made and reviewed, what an intermediary must do to keep its immunity, and how an adjudication proceeds. Section 79 confers an immunity and says nothing about what an intermediary must actually do; the 2021 Rules do.

munotes.in70

The Scheme of the Information Technology Act

4. What did sections 91 to 94 do, and why are they no longer in the Act? They carried the Third and Fourth Schedules, which amended the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934, and it was section 92 with the Second Schedule that inserted the old section 65B into the Evidence Act. They were omitted by the 2008 amendment as spent, the amendments having already taken effect in the amended statutes.

5. Give two places where the Act's chapter headings mislead. Sections 69, 69A, 69B, 70, 70A and 70B confer State powers and sit in Chapter XI, headed "Offences", although the sections themselves create powers rather than offences, with the offences attached as consequences of non-compliance. And section 43A, which creates a right to compensation with no penalty at all, sits in Chapter IX headed "Penalties, Compensation and Adjudication".

Contents This chapter on its own page

munotes.in71

Chapter Thirteen

Short Title, Extent and Application

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

Section 1 says what the Act is called, that it covers the whole of India, that it reaches conduct abroad, and that it does not touch the documents in the First Schedule.

In the wording a student can write in an exam: section 1 of the Information Technology Act, 2000 provides the short title, extends the Act to the whole of India and to any offence or contravention committed outside India by any person, empowers the Central Government to bring different provisions into force on different dates, and excludes from the Act's operation the documents and transactions specified in the First Schedule, which the Central Government may amend by notification laid before each House of Parliament.

Why an extent clause matters here more than usual

In most statutes the extent clause is a formality. In this one it is doing hard work, because the conduct the Act addresses routinely happens outside the country and the person who did it is routinely not Indian.

Section 1(2) makes that claim in the extent clause itself, which is unusual drafting. Most statutes deal with extraterritorial application, if at all, in a separate section. This Act says it in section 1 and then repeats and qualifies it in section 75.

Section 1(1): the short title

"This Act may be called the Information Technology Act, 2000."

The Act was not renamed by the 2008 amendment, although several published copies suggest otherwise. The Information Technology (Amendment) Act, 2008 is a separate amending Act, Act 10 of 2009, and the principal Act remains the Information Technology Act, 2000, Act 21 of 2000. Chapter 180 works the amendment.

Section 1(2): extent, and the reach abroad

"It shall extend to the whole of India and, save as otherwise provided in this Act, it applies also to any offence or contravention thereunder committed outside India by any person."

Three separate propositions are packed into that sentence.

The Act extends to the whole of India. Since the Jammu and Kashmir Reorganisation Act, 2019 there is no State to which it does not apply, and the older textbook qualification that it did not extend to Jammu and Kashmir is out of date.

It applies to an offence or contravention committed outside India. Note the two words: offence, which is the criminal side in Chapter XI, and contravention, which is the civil side in Chapter IX. Both reach abroad.

By any person, and section 75(1) adds "irrespective of his nationality", which puts the matter beyond argument. India does not rely on the nationality principle here; it claims jurisdiction over anyone.

Section 75(2) supplies the limit, and without it section 1(2) would be a claim over the whole world. The Act applies to an offence or contravention committed outside India if the act or conduct constituting the offence or contravention involves a computer, computer system or computer network located in India. Chapter 850 works section 75 in full, and chapter 840 places both in the general law of jurisdiction.

munotes.in72

Short Title, Extent and Application

So the connecting factor India chose is the location of the machine, not the nationality of the offender and not the location of the victim. A person anywhere who attacks a server in Pune is within the Act. A person anywhere who attacks an Indian company's server in Frankfurt is not, on the face of section 75, however Indian the victim.

Section 1(3): commencement

"It shall come into force on such date as the Central Government may, by notification, appoint and different dates may be appointed for different provisions of this Act."

The Act was brought into force on 17 October 2000, and the Information Technology (Amendment) Act, 2008 was brought into force on 27 October 2009. Those two dates matter constantly, because a great many of the provisions a student meets did not exist before the second.

The power to appoint different dates for different provisions is not a formality either. It is the same power the Digital Personal Data Protection Act, 2023 used to stage its own commencement over eighteen months, and chapter 1050 works out what that means for the parts of that Act that are not yet law.

The section closes by providing that a reference in any provision to the commencement of the Act is to be construed as a reference to the commencement of that provision. That is the drafting device that makes staged commencement workable.

Section 1(4) and (5): the First Schedule

"Nothing in this Act shall apply to documents or transactions specified in the First Schedule: Provided that the Central Government may, by notification in the Official Gazette, amend the First Schedule by way of addition or deletion of entries thereto."

"Every notification issued under sub-section (4) shall be laid before each House of Parliament."

Sub-sections (4) and (5) in this form were substituted by the 2008 amendment. The Act as passed had a fixed Schedule; the amendment made it amendable by notification, with the notification laid before Parliament.

Two things follow. The list of exclusions is not in the Act's own text and can change without an amending Act, so it must be checked rather than remembered. And it has in fact changed: chapter 140 works the notification of 26 September 2022 that rewrote it.

The words "save as otherwise provided in this Act"

These words in section 1(2) are the hinge between section 1 and everything else. They mean the extraterritorial claim yields wherever the Act says something different, and section 75(2) is exactly such a provision.

munotes.in73

Short Title, Extent and Application

They also mean that the exclusion in section 1(4) is not affected by section 1(2). A document in the First Schedule is outside the Act whether it is made in India or abroad.

A worked example

Three sets of facts, and the same section decides all three.

A person in Manila breaks into a Mumbai bank's server and moves money. Section 1(2) applies the Act to a contravention committed outside India by any person. Section 75(2) is satisfied because the conduct involves a computer system located in India. So sections 43 and 66 both reach him, and section 75(1) makes his Filipino nationality irrelevant. Whether India can get him is a different question, and chapter 880 works it.

An Indian citizen in Toronto sends a threatening message to another Indian in Toronto, using a service whose servers are in Ireland. Section 1(2) claims application, but section 75(2) is not satisfied: no computer, computer system or computer network located in India was involved. The Act does not apply on its own terms.

A builder in Thane and a buyer in Dombivli make an agreement for the sale of a flat by exchanging signed electronic documents. Before 26 September 2022 this would have been outside the Act under serial number 5 of the First Schedule. Chapter 140 shows why it is not any more, and that change is the single most surprising thing in section 1.

What this does NOT mean

It does not mean the Act applies to everything done abroad. Section 1(2) states the claim and section 75(2) confines it to conduct involving a machine located in India. Reading section 1(2) alone is the commonest mistake made about this section.

It does not mean a person abroad can be tried in India as a matter of course. Applicability of the Act is one question; getting the accused before a court, which needs extradition or presence, is another. Chapter 840 keeps prescriptive and enforcement jurisdiction apart.

It does not mean the First Schedule is fixed. It is amendable by notification under the proviso to section 1(4), and it has been amended.

It does not mean the Act does not apply in Jammu and Kashmir. It extends to the whole of India, and any statement to the contrary reflects the pre-2019 position.

Quick revision

  • Section 1(1): short title. The principal Act is still the Information Technology Act, 2000, Act 21 of 2000, not renamed by the 2008 amendment.
  • Section 1(2): extends to the whole of India and to any offence or contravention committed outside India by any person, save as otherwise provided.
  • Section 75(1) adds "irrespective of his nationality"; section 75(2) supplies the limit: the conduct must involve a computer, computer system or computer network located in India.
  • Section 1(3): commencement by notification, different dates for different provisions. Act in force 17 October 2000; the 2008 amendment in force 27 October 2009.
  • Section 1(4): the Act does not apply to what the First Schedule lists, and the Central Government may amend the Schedule by notification. Section 1(5): every such notification is laid before each House.
  • The connecting factor India chose is the location of the machine, not the nationality of the offender or the location of the victim.
munotes.in74

Short Title, Extent and Application

Test yourself

1. Set out the extraterritorial rule in the Act and state its limit. Section 1(2) applies the Act to any offence or contravention under it committed outside India by any person, and section 75(1) adds that nationality is irrelevant. Section 75(2) limits it: the Act applies to such conduct only if the act or conduct constituting the offence or contravention involves a computer, computer system or computer network located in India.

2. An Indian company's data is stolen from its server in Singapore by a hacker in Brazil. Does the Act apply? Not on the face of section 75(2), because no computer, computer system or computer network located in India was involved in the conduct. Indian ownership of the data and Indian nationality of the victim are not connecting factors under this Act, though the general criminal law and the law of the place of the server may apply.

3. Why does section 1(3) allow different dates for different provisions, and give a current example of the power being used? Because a statute of this kind needs institutions built before its substantive provisions can operate, so the Government stages commencement. The Digital Personal Data Protection Act, 2023 used the same power in section 1(2) of that Act: G.S.R. 843(E) of 13 November 2025 brought its Board provisions into force at once, its consent manager provisions after twelve months, and its substantive sections 3 to 17 after eighteen months.

4. How may the First Schedule be changed, and what safeguard attaches? Under the proviso to section 1(4) the Central Government may amend it by notification in the Official Gazette, by addition or deletion of entries. Section 1(5) requires every such notification to be laid before each House of Parliament, which is the parliamentary control on a power that would otherwise let the executive remove documents from the Act's operation by itself.

5. What do the words "save as otherwise provided in this Act" in section 1(2) do? They subordinate the extraterritorial claim to any contrary provision of the Act, and section 75(2) is the principal such provision, cutting the claim down to conduct involving a machine in India. Without those words section 1(2) and section 75(2) would be in direct conflict.

Contents This chapter on its own page

munotes.in75

Chapter Fourteen

The First Schedule: What the Act Does Not Touch

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

Four kinds of document are outside the Act, and the fifth, which every textbook still lists, was removed in September 2022.

In the wording a student can write in an exam: by section 1(4) of the Information Technology Act, 2000 nothing in the Act applies to the documents or transactions specified in the First Schedule, which as amended by notification S.O. 4720(E) dated 26 September 2022 comprises a negotiable instrument other than a cheque, demand promissory note or bill of exchange issued in favour of or endorsed by a regulated financial entity, a power of attorney other than one empowering such an entity to act for the executant, a trust, and a will or other testamentary disposition.

Why any document is excluded at all

The Act's method is to remove the paper obstacles. For some documents the obstacle is the point.

Four reasons run through the list.

Formality as protection. A will must be signed by the testator and attested by two witnesses who saw him sign, and the formality exists because the testator will not be alive to explain what he meant. Removing it removes the protection.

Uniqueness. A negotiable instrument is transferred by delivery and the holder is entitled to be paid. If it can be copied perfectly there can be many holders. Chapter 90 works the same problem for bills of lading and shows how the Model Law solved it.

Third parties. A trust and a conveyance affect people who were never party to the document and may look at it years later, and they need a public and reliable record.

Institutional readiness. A power of attorney has to be accepted by a registrar, a bank or a court, and in 2000 none of them could verify an electronic one.

None of those reasons is permanent, and the amendment of 2022 is the proof.

The Schedule as it now stands

Sl. No.Description of documents or transactions
1A negotiable instrument (other than a cheque, a Demand Promissory Note or a Bill of Exchange issued in favour of or endorsed by an entity regulated by the Reserve Bank of India, National Housing Bank, Securities and Exchange Board of India, Insurance Regulatory and Development Authority of India and Pension Fund Regulatory and Development Authority) as defined in section 13 of the Negotiable Instruments Act, 1881
2A power-of-attorney as defined in section 1A of the Powers-of-Attorney Act, 1882, but excluding those power-of-attorney that empower an entity regulated by the Reserve Bank of India, National Housing Bank, Securities and Exchange Board of India, Insurance Regulatory and Development Authority of India and Pension Fund Regulatory and Development Authority to act for, on behalf of, and in the name of the person executing them
3A trust as defined in section 3 of the Indian Trusts Act, 1882
4A will as defined in clause (h) of section 2 of the Indian Succession Act, 1925, including any other testamentary disposition by whatever name called
5Omitted
munotes.in76

The First Schedule: What the Act Does Not Touch

Serial number 5 read: "Any contract for the sale or conveyance of immovable property or any interest in such property." It was omitted by S.O. 4720(E), and the omission is the most consequential change to this Act since 2009 that nobody talks about.

The amendment of 26 September 2022

The notification was made under the proviso to section 1(4), and it did three things.

It substituted serial number 1, so that a cheque, a demand promissory note or a bill of exchange is no longer excluded if it is issued in favour of or endorsed by an entity regulated by the Reserve Bank of India, the National Housing Bank, the Securities and Exchange Board of India, the Insurance Regulatory and Development Authority of India or the Pension Fund Regulatory and Development Authority.

It amended serial number 2, so that a power of attorney empowering such a regulated entity to act for, on behalf of, and in the name of the executant is no longer excluded.

It omitted serial number 5 entirely.

The first two changes have a single purpose and it is worth naming. Lending in India is documented by a demand promissory note and a power of attorney, and until 2022 a lender regulated by the Reserve Bank could not take either electronically. The amendment lets a regulated lender complete a loan file without paper. It is deliberately narrow: the exclusion still stands for everybody else, so an ordinary promissory note between two individuals is still outside the Act.

The third change is not narrow at all.

What the omission of serial number 5 means

Since 26 September 2022, a contract for the sale or conveyance of immovable property, or of any interest in it, is within the Act. So sections 4, 5, 7 and 10A apply to it, and an agreement for sale made by electronic record is not outside the Act's recognition provisions.

Three cautions, and a student who gives only the headline will be caught by any of them.

First, the Act's removal of one obstacle does not remove the others. The Registration Act, 1908 requires certain instruments to be registered, and registration requires presentation to the registering officer. The Transfer of Property Act, 1882 requires a sale of tangible immovable property of one hundred rupees and upwards to be made by a registered instrument. Section 1(4) getting out of the way does not make an unregistered electronic conveyance effective; it makes the Act's recognition provisions available to instruments that are otherwise good.

munotes.in77

The First Schedule: What the Act Does Not Touch

Second, stamp duty is untouched. State stamp laws and their machinery for e-stamping operate independently.

Third, the distinction between an agreement for sale and a conveyance matters. An agreement for sale of immovable property does not itself transfer an interest, and section 17 of the Registration Act requires registration of certain agreements in some States and not in others. The omission of serial 5 has its clearest effect on agreements that never needed registration.

So the honest statement is this. The Act no longer stands aside from property transactions, which is a real and current change; the other statutes that govern them still stand where they did.

The exclusions and the reason for each

ExcludedWhyIs the reason still good?
Negotiable instrument, s.13 NI ActTransferred by delivery; the holder is paid; a copyable record would produce many holdersPartly. Since 2022 a regulated entity may take a cheque, demand promissory note or bill of exchange electronically, so the answer for that class is that the reason is manageable
Power of attorney, s.1A Powers-of-Attorney ActConfers authority on which strangers act, and needed institutional acceptancePartly, for the same reason and by the same amendment
Trust, s.3 Indian Trusts ActAffects beneficiaries who are not parties, and lasts a long timeNot yet revisited
Will, s.2(h) Indian Succession ActThe formality exists because the testator cannot be asked; attestation is the protectionStill good, and no jurisdiction has solved the attestation problem convincingly
Contract for sale or conveyance of immovable propertyThird-party effect and the registration systemThe Government decided in 2022 that it was not, and omitted the entry

A worked example

Kirti Housing Finance, a company regulated by the National Housing Bank, lends thirty lakh rupees to Mr and Mrs Salvi against their flat in Kalyan.

The demand promissory note. Before 26 September 2022 this was serial number 1 and could not be electronic. Now, because it is a demand promissory note issued in favour of an entity regulated by the National Housing Bank, it is outside the exclusion, so section 4 makes an electronic note satisfy a requirement of writing and section 5 makes a prescribed electronic signature satisfy a requirement of signature.

The power of attorney in favour of the lender. Before 2022 this was serial number 2. Now, because it empowers a regulated entity to act for, on behalf of, and in the name of the Salvis, it is outside the exclusion.

The loan agreement. Never excluded, and always capable of being electronic.

The mortgage of the flat. Serial number 5 is gone, so the Act does not stand aside. But section 59 of the Transfer of Property Act requires a mortgage other than by deposit of title deeds to be effected by a registered instrument, and the Registration Act requires registration. What has changed is that the Act's recognition provisions are available; what has not changed is the registration requirement.

munotes.in78

The First Schedule: What the Act Does Not Touch

A will the Salvis make leaving the flat to their daughter. Serial number 4 still excludes it, and an electronic will is ineffective in India however carefully it is signed.

What this does NOT mean

It does not mean the excluded documents are unlawful in electronic form. It means the Act's provisions do not apply to them, so the pre-2000 position governs, and under that position a will must be signed and attested and a negotiable instrument must be an instrument.

It does not mean the exclusion of negotiable instruments has gone. Only the three named kinds, and only where a regulated financial entity is the payee or the endorser. A promissory note between two individuals is still excluded.

It does not mean electronic conveyancing is now available in India. The Act's obstacle is gone; the Registration Act, the Transfer of Property Act and the State stamp laws are not.

It does not mean the Schedule can be changed quietly. Section 1(5) requires every notification under section 1(4) to be laid before each House of Parliament.

Quick revision

  • Section 1(4): nothing in the Act applies to what the First Schedule lists. Proviso: the Central Government may amend the Schedule by notification. Section 1(5): every such notification is laid before each House.
  • Four entries survive: negotiable instrument, power of attorney, trust, will.
  • S.O. 4720(E), 26 September 2022, did three things: carved a cheque, demand promissory note and bill of exchange out of serial 1 where a regulated financial entity is payee or endorser; carved out of serial 2 a power of attorney empowering such an entity to act for the executant; and omitted serial number 5 entirely.
  • Serial 5 was "any contract for the sale or conveyance of immovable property or any interest in such property". It is gone.
  • The omission removes the Act's obstacle only. The Registration Act 1908, the Transfer of Property Act 1882 and State stamp laws are untouched.
  • The regulators named are the RBI, the National Housing Bank, SEBI, IRDAI and PFRDA.

Test yourself

1. List the First Schedule as it now stands. A negotiable instrument as defined in section 13 of the Negotiable Instruments Act, 1881, other than a cheque, a demand promissory note or a bill of exchange issued in favour of or endorsed by an entity regulated by the Reserve Bank of India, the National Housing Bank, SEBI, IRDAI or PFRDA; a power of attorney as defined in section 1A of the Powers-of-Attorney Act, 1882, excluding one empowering such a regulated entity to act for, on behalf of and in the name of the executant; a trust as defined in section 3 of the Indian Trusts Act, 1882; and a will as defined in section 2(h) of the Indian Succession Act, 1925, including any other testamentary disposition.

munotes.in79

The First Schedule: What the Act Does Not Touch

2. What was serial number 5, what happened to it, and when? It was "any contract for the sale or conveyance of immovable property or any interest in such property". It was omitted by notification S.O. 4720(E) dated 26 September 2022, made under the proviso to section 1(4).

3. Does that omission make electronic conveyancing possible in India? Not by itself. It removes the Act's own exclusion, so sections 4, 5 and 10A can apply to such a contract. It does not touch section 54 or section 59 of the Transfer of Property Act, 1882, the registration requirements of the Registration Act, 1908, or State stamp legislation, all of which continue to require a registered instrument for a sale or mortgage of immovable property.

4. Why were cheques and demand promissory notes carved out only for regulated entities? Because the purpose was to let regulated lenders complete a loan file electronically, and the risks of a copyable negotiable instrument are containable within a supervised financial system where the payee or endorser is an entity the regulator can hold to account. Between two individuals the risk of multiple holders remains, so the exclusion still applies.

5. Why does a will remain excluded when a conveyance does not? Because the formality that a will requires, signature by the testator attested by two witnesses who saw him sign, exists precisely because the testator cannot be asked what he meant, and there is no accepted electronic equivalent of attestation in the presence of the testator. A conveyance, by contrast, is made between living parties who can be asked, and its third-party protection comes from registration rather than from the medium of the document.

Contents This chapter on its own page

munotes.in80

Chapter Fifteen

The Definitions, Part One: the Machine

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

Section 2 defines the machine in four overlapping ways, and which one a section uses decides how far that section reaches.

In the wording a student can write in an exam: section 2(1) of the Information Technology Act, 2000 defines "computer" in clause (i), "computer network" in clause (j), "computer resource" in clause (k) and "computer system" in clause (l), together with "access" in clause (a), "communication device" in clause (ha), "data" in clause (o), "electronic form" in clause (r), "electronic record" in clause (t), "function" in clause (u) and "information" in clause (v), and the width of a given offence or power is determined by which of these terms the section in question uses.

Why the definitions are worth a chapter of their own

A definition section is not a glossary. It is the operative part of the statute in disguise.

Section 43 penalises a person who does the listed acts to "a computer, computer system or computer network". Section 66F speaks of a "computer resource". Section 69 speaks of "any computer resource". Those are not stylistic variations. Computer resource includes data, a database and software; the other three do not. So a power framed in terms of a computer resource reaches a file, and a penalty framed in terms of a computer does not, except through the acts section 43 separately lists.

The 2024-25 paper set a short note on the distinction between "computer", "computer system" and "computer network". That question is answered from this chapter.

And the definitions were amended in 2008. Clauses (ha) communication device, (na) cyber cafe, (nb) cyber security, (ta) electronic signature, (tb) Electronic Signature Certificate and (ua) Indian Computer Emergency Response Team were all inserted then, and clauses (j) and (w) were substituted. A pre-2009 textbook has a different section 2.

Access: clause (a)

"'Access' with its grammatical variations and cognate expressions means gaining entry into, instructing or communicating with the logical, arithmetical, or memory function resources of a computer, computer system or computer network."

Three separate things are access, and only the first is what a lay reader would call it. Gaining entry. Instructing. And communicating with.

So a person who sends a computer an instruction has accessed it, without ever getting inside anything. That is why a denial of service attack, which merely floods a machine with requests, is access; why sending a malformed request that crashes a server is access; and why the width of this clause carries a great deal of section 43 and section 66.

Notice what the definition attaches to. It is access to the logical, arithmetical or memory function resources, which are the three functions clause (i) says a computer performs. Reading a printout is not access. Photographing a screen is not access.

munotes.in81

The Definitions, Part One: the Machine

Computer: clause (i)

"'Computer' means any electronic, magnetic, optical or other high-speed data processing device or system which performs logical, arithmetic, and memory functions by manipulations of electronic, magnetic or optical impulses, and includes all input, output, processing, storage, computer software or communication facilities which are connected or related to the computer in a computer system or computer network."

Three features, and each does work.

Technology neutral. "Electronic, magnetic, optical or other". A technology that does not yet exist is inside the definition if it processes data at high speed by manipulating impulses.

Functional. The test is performing logical, arithmetic and memory functions. A device is a computer because of what it does, not what it is called.

Inclusive. The keyboard, the monitor, the printer, the disk, the software and the communication facilities connected or related to it are all part of the computer. That matters for search and seizure under section 80 and for confiscation under section 76: seizing a computer means seizing its peripherals.

Computer system: clause (l)

"'Computer system' means a device or collection of devices, including input and output support devices and excluding calculators which are not programmable and capable of being used in conjunction with external files, which contain computer programmes, electronic instructions, input data and output data, that performs logic, arithmetic, data storage and retrieval, communication control and other functions."

The difference from clause (i) is that a computer system may be a collection of devices working as a unit, and that it must contain programmes, instructions and data.

The exclusion is the only express exclusion in the machine definitions. A calculator which is neither programmable nor capable of being used with external files is not a computer system. A programmable one is not excluded, and neither is a scientific calculator that reads a memory card.

Clause (l) also adds two functions to the list: data storage and retrieval, and communication control.

Computer network: clause (j)

"'Computer network' means the inter-connection of one or more computers or computer systems or communication device through (i) the use of satellite, microwave, terrestrial line, wire, wireless or other communication media; and (ii) terminals or a complex consisting of two or more interconnected computers or communication device whether or not the inter-connection is continuously maintained."

This clause was substituted by the 2008 amendment, and two changes matter. The original required two or more computers; the substituted clause says "one or more computers or computer systems or communication device", which brings a phone connected to a server inside it. And the closing words, "whether or not the inter-connection is continuously maintained", put beyond argument that an intermittent connection is a network.

munotes.in82

The Definitions, Part One: the Machine

The list of media is illustrative and closed with "or other communication media", so a technology not listed is inside.

Computer resource: clause (k)

"'Computer resource' means computer, computer system, computer network, data, computer data base or software."

Six words, and three of them are not machines. This is the widest term in the Act and the one to watch. It includes data, a computer database and software.

Which sections use it? Section 43 in some of its clauses, section 66C, 66D, 66E and 66F, sections 69, 69A and 69B, section 70, section 72A, section 79, and the definitions of cyber cafe and cyber security. In short, every provision written or rewritten in 2008 uses computer resource, and the older ones use the narrower terms.

That is the single most useful observation in this chapter, and it explains why the State powers reach a file and a website while section 43's older clauses are written around machines.

Communication device: clause (ha)

"'Communication device' means cell phones, personal digital assistance or combination of both or any other device used to communicate, send or transmit any text, video, audio or image."

Inserted in 2008, and its function is to put a phone inside the Act without argument. A phone is a computer under clause (i) anyway, but in 2008 that was not obvious to everybody, and several offences are framed in terms of "a computer resource or a communication device" precisely to close the point. Section 66C and section 66D are both drafted that way.

Data, information, electronic form and electronic record

"'Data' means a representation of information, knowledge, facts, concepts or instructions which are being prepared or have been prepared in a formalised manner, and is intended to be processed, is being processed or has been processed in a computer system or computer network, and may be in any form (including computer printouts magnetic or optical storage media, punched cards, punched tapes) or stored internally in the memory of the computer." Clause (o).

The words in brackets carry the surprise. A computer printout is data. So a person who takes a printed report has taken data, and the offence or contravention does not fail because nothing electronic was touched at the moment of taking.

"'Information' includes data, message, text, images, sound, voice, codes, computer programmes, software and data bases or micro film or computer generated micro fiche." Clause (v), as amended in 2008 to add "data, message, text".

So information is the wider word and data sits inside it, which is the opposite of the ordinary usage in which data is raw and information is data with meaning. Chapter 20 explains the ordinary usage; the statute reverses it, and an answer must use the statute's.

munotes.in83

The Definitions, Part One: the Machine

"'Electronic form', with reference to information, means any information generated, sent, received or stored in media, magnetic, optical, computer memory, micro film, computer generated micro fiche or similar device." Clause (r).

"'Electronic record' means data, record or data generated, image or sound stored, received or sent in an electronic form or micro film or computer generated micro fiche." Clause (t).

Electronic record is the unit the whole Act operates on. Sections 3, 4, 7, 11, 12, 13, 14, 65 and 67 are all about electronic records, and the term corresponds to the Model Law's "data message", which chapter 60 works.

Function, and secure system

"'Function', in relation to a computer, includes logic, control, arithmetical process, deletion, storage and retrieval and communication or telecommunication from or within a computer." Clause (u). Note that deletion is expressly a function, which matters for section 43(d) and for section 65.

"'Secure system' means computer hardware, software, and procedure that (a) are reasonably secure from unauthorised access and misuse; (b) provide a reasonable level of reliability and correct operation; (c) are reasonably suited to performing the intended functions; and (d) adhere to generally accepted security procedures." Clause (ze). Chapter 220 works secure records and signatures.

"'Security procedure' means the security procedure prescribed under section 16 by the Central Government." Clause (zf).

Cyber cafe and cyber security

"'Cyber cafe' means any facility from where access to the internet is offered by any person in the ordinary course of business to the members of the public." Clause (na), inserted 2008. Chapter 1430 works the Cyber Cafe Rules 2011.

"'Cyber security' means protecting information, equipment, devices, computer, computer resource, communication device and information stored therein from unauthorised access, use, disclosure, disruption, modification or destruction." Clause (nb), inserted 2008.

Clause (nb) is the statutory definition of the phrase MU prints as topic 3.3, and it is worth noticing that it is a definition by reference to six harms: unauthorised access, use, disclosure, disruption, modification and destruction. Chapter 750 builds on it.

The four terms side by side, with what turns on each

TermClauseIncludes machines?Includes data and software?Used by
Computer2(1)(i)One device or system, with peripherals and software connected to itOnly its own software and storagess.43, 65, 66 (via 43), 70, 75
Computer system2(1)(l)A device or collection of devices working as a unitContains programmes and datass.43, 70, 75
Computer network2(1)(j)Interconnected computers, systems or communication devicesNoss.43, 70, 75
Computer resource2(1)(k)All three of the aboveYes: data, computer database and softwaress.66C to 66F, 69, 69A, 69B, 72A, 79, and 2(1)(na), (nb)
munotes.in84

The Definitions, Part One: the Machine

A worked example

Nikhil, who works for a Pune analytics firm, copies a client database to a personal drive on his last day and emails a summary to a competitor.

Was there access? Yes, under clause (a): he communicated with and instructed the memory function resources of his employer's computer system. It does not matter that he was authorised to be at the keyboard; authorisation to use is not authorisation to copy, and section 43 turns on whether the act was without permission of the owner.

What did he take? The database is data under clause (o) and a computer data base, so it is also a computer resource under clause (k). The summary email is an electronic record under clause (t).

Which sections reach it? Section 43(b) covers downloading, copying or extracting data from a computer, computer system or computer network. Section 66 makes the same act an offence if done dishonestly or fraudulently. Section 72A may reach him if he was a person providing services under a contract who disclosed personal information in breach of it, because that section is drafted around a computer resource. Chapters 1100, 1180 and 1250 own those three.

Change one fact. Suppose he printed the database and carried out the paper. There is now no access under clause (a), because he did not gain entry into, instruct or communicate with anything after the printing. But the printout is still data under clause (o), so his employer's remedies under the general law and any offence of criminal breach of trust remain, and the point is that the Act's reach turned on the definition and not on the wrongfulness of what he did.

What this does NOT mean

It does not mean the four machine terms are interchangeable. Reading "computer resource" into a section that says "computer" widens the section beyond what Parliament wrote, and reading "computer" into a section that says "computer resource" narrows it.

It does not mean the section 2 definitions govern other statutes. They apply "in this Act, unless the context otherwise requires". Where the Bharatiya Sakshya Adhiniyam or the Copyright Act uses similar words it has its own definitions, and chapter 480 shows how differently the Copyright Act defines a computer programme.

It does not mean information means what it means in ordinary speech. In the Act, information includes data, which is the reverse of the usual relationship.

It does not mean everything in section 2 is here. The definitions about people and transactions, originator, addressee, intermediary, subscriber, Certifying Authority, key pair and the rest, are in chapter 160.

Quick revision

  • Access, 2(1)(a): gaining entry into, instructing or communicating with the logical, arithmetical or memory function resources. Instruction alone is access.
  • Computer, 2(1)(i): technology neutral, functional, and inclusive of peripherals, storage, software and communication facilities.
  • Computer system, 2(1)(l): a device or collection of devices; excludes a calculator that is not programmable and cannot use external files.
  • Computer network, 2(1)(j): substituted in 2008; one or more computers, systems or communication devices; whether or not the interconnection is continuously maintained.
  • Computer resource, 2(1)(k): the widest. Computer, computer system, computer network, data, computer data base or software. Every provision written in 2008 uses it.
  • Data, 2(1)(o): includes a computer printout. Information, 2(1)(v): includes data, so information is the wider word.
  • Electronic record, 2(1)(t): the unit the Act operates on; the Model Law's data message.
  • Communication device, 2(1)(ha), cyber cafe, 2(1)(na), cyber security, 2(1)(nb), electronic signature, 2(1)(ta) and Electronic Signature Certificate, 2(1)(tb): all inserted in 2008.
munotes.in85

The Definitions, Part One: the Machine

Test yourself

1. Distinguish computer, computer system and computer network. A computer, section 2(1)(i), is a high-speed data processing device performing logical, arithmetic and memory functions, including its input, output, storage, software and communication facilities. A computer system, section 2(1)(l), is a device or collection of devices including input and output support devices, containing programmes, instructions and data, that performs logic, arithmetic, storage and retrieval and communication control, expressly excluding a calculator that is not programmable and cannot use external files. A computer network, section 2(1)(j), is the interconnection of one or more computers, computer systems or communication devices by any medium, whether or not the interconnection is continuously maintained.

2. Why does it matter that section 69 uses "computer resource" and section 43 in part uses "computer, computer system or computer network"? Because computer resource, section 2(1)(k), additionally includes data, a computer database and software, while the other three are machines. A power framed around a computer resource therefore reaches a file, a database or a program directly, whereas a provision framed around the machines reaches data only through the specific acts the provision lists.

3. A person floods a website with automated requests until it stops responding. Has he accessed it? Yes. Section 2(1)(a) makes instructing or communicating with the logical, arithmetical or memory function resources of a computer, computer system or computer network access, so entry is not required. That is why a denial of service attack is within section 43(f), which covers denying or causing the denial of access to any person authorised to access.

4. Is a printout data? Yes. Section 2(1)(o) provides that data may be in any form, "including computer printouts, magnetic or optical storage media, punched cards, punched tapes", so a printed representation of processed information is data within the Act.

munotes.in86

The Definitions, Part One: the Machine

5. Which definitions were inserted or substituted by the 2008 amendment, and why does it matter? Inserted: communication device, clause (ha); cyber cafe, (na); cyber security, (nb); electronic signature, (ta); Electronic Signature Certificate, (tb); and Indian Computer Emergency Response Team, (ua). Substituted: computer network, clause (j), and intermediary, clause (w). It matters because a book or a judgment predating 27 October 2009 works from a materially different section 2, and because every provision the amendment inserted is drafted using the vocabulary it inserted with them.

Contents This chapter on its own page

munotes.in87

Chapter Sixteen

The Definitions, Part Two: the People and the Transaction

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

The other half of section 2 names the people: who sends, who receives, who carries in between, who signs, who certifies, and who holds the keys.

In the wording a student can write in an exam: section 2(1) of the Information Technology Act, 2000 further defines "addressee" in clause (b), "originator" in clause (za), "intermediary" in clause (w), "subscriber" in clause (zg), "Certifying Authority" in clause (g), "Controller" in clause (m), "asymmetric crypto system" in clause (f), "key pair" in clause (x), "private key" in clause (zc), "public key" in clause (zd), "digital signature" in clause (p), "electronic signature" in clause (ta) and "verify" in clause (zh), and these terms between them describe every party to an electronic transaction under the Act.

Why these definitions are grouped together

Chapter 150 dealt with the machine. This one deals with the people, and the two halves answer different questions. The machine definitions decide how far a provision reaches. The people definitions decide who is liable, who is protected and who owes a duty.

Three of them carry whole chapters of this book. Intermediary carries Module IV topics 4.2 and 4.7. Certifying Authority carries the whole of Module II topic 2.3. And subscriber carries Chapter VIII of the Act.

Originator and addressee, and the exclusion both carry

"'Originator' means a person who sends, generates, stores or transmits any electronic message or causes any electronic message to be sent, generated, stored or transmitted to any other person but does not include an intermediary." Clause (za).

"'Addressee' means a person who is intended by the originator to receive the electronic record but does not include any intermediary." Clause (b).

Both are taken from the Model Law almost word for word, and both carry its express exclusion of an intermediary. Chapter 60 explains why: the intermediary handles somebody else's message and has no interest in its content, so treating it as a party would attach to it the consequences of a communication it never made.

Three points repay attention.

The originator need not have composed anything. A person who "causes" a message to be sent is an originator, so the person who configures an automated system is the originator of what it sends, which is what section 11(c) then confirms.

Storing is enough. The definition includes a person who stores an electronic message, which is wider than the Model Law's "sends or generates".

The addressee is defined by the originator's intention, not by who actually received it. A message that goes to the wrong person does not make that person an addressee.

Intermediary: clause (w)

"'Intermediary', with respect to any particular electronic records, means any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record and includes telecom service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes."

munotes.in88

The Definitions, Part Two: the People and the Transaction

This clause was substituted by the 2008 amendment, which added the list. The original definition was the bare functional test.

Four things about it decide most of Module IV.

It is defined with respect to a particular electronic record. The same company may be an intermediary in relation to one record and not another. A platform that carries a user's post is an intermediary as to that post; the same platform's own advertisement for itself is its own content and it is not an intermediary as to that.

The functional test is four-limbed: on behalf of another person, receives, stores or transmits that record, or provides any service with respect to that record. The last limb is very wide, and it is what brings a search engine, which neither receives, stores nor transmits the underlying page, inside the definition.

The list is inclusive, not exhaustive. "Includes" means a business not on the list is an intermediary if it satisfies the functional test.

A cyber cafe is expressly on the list, and separately defined in clause (na), which is why the Cyber Cafe Rules 2011 exist and why chapter 1430 uses them as the clearest worked example of due diligence.

The consequence is section 79, the safe harbour, and chapter 1360 works it. Being an intermediary is not a liability; it is the gateway to an immunity, subject to conditions.

Subscriber: clause (zg)

"'Subscriber' means a person in whose name the electronic signature Certificate is issued."

Short and consequential. The subscriber is the person the certificate names, and Chapter VIII of the Act, sections 40 to 42, puts three duties on him: to generate the key pair as prescribed, to accept the certificate in the manner the section requires, and to keep the private key secret. Chapter 340 works them.

Note the mismatch with the Model Law's vocabulary. The 2001 Model Law calls this person the signatory, and defines a relying party as well. India has no term for the relying party, which is a real gap and one chapter 340 has to reason around.

Certifying Authority and Controller

"'Certifying Authority' means a person who has been granted a licence to issue an electronic signature Certificate under section 24." Clause (g).

The definition is by reference to the licence, not to the activity. A person who issues something that looks like a certificate without a licence is not a Certifying Authority under the Act, and commits an offence under section 21(1) read with the penalties.

munotes.in89

The Definitions, Part Two: the People and the Transaction

"'Controller' means the Controller of Certifying Authorities appointed under sub-section (1) of section 17." Clause (m). Chapter 400 works the office.

"'Certification practice statement' means a statement issued by a Certifying Authority to specify the practices that the Certifying Authority employs in issuing electronic signature Certificates." Clause (h). Chapter 450 shows why it matters: it is the document against which the Authority's conduct is judged.

"'Licence' means a licence granted to a Certifying Authority under section 24." Clause (z).

The cryptographic definitions

"'Asymmetric crypto system' means a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature." Clause (f).

"'Key pair', in an asymmetric crypto system, means a private key and its mathematically related public key, which are so related that the public key can verify a digital signature created by the private key." Clause (x).

"'Private key' means the key of a key pair used to create a digital signature." Clause (zc).

"'Public key' means the key of a key pair used to verify a digital signature and listed in the Digital Signature Certificate." Clause (zd).

These four clauses put one technology into the statute, and chapter 260 explains what asymmetric cryptography actually is. The 2008 amendment did not remove them; it added electronic signature alongside, so the Act now contains both a technology-specific vocabulary and a technology-neutral one. Chapter 310 works the resulting distinction.

Digital signature, electronic signature, and the two certificates

"'Digital signature' means authentication of any electronic record by a subscriber by means of an electronic method or procedure in accordance with the provisions of section 3." Clause (p).

"'Electronic signature' means authentication of any electronic record by a subscriber by means of the electronic technique specified in the Second Schedule and includes digital signature." Clause (ta), inserted 2008.

So electronic signature is the wider term and digital signature sits inside it, exactly as information is wider than data. That relationship is the answer to a question set in 2015 and again as a short note in 2025-26.

"'Digital Signature Certificate' means a Digital Signature Certificate issued under sub-section (4) of section 35." Clause (q).

"'Electronic Signature Certificate' means an Electronic Signature Certificate issued under section 35 and includes Digital Signature Certificate." Clause (tb), inserted 2008. Same relationship again.

"'Affixing electronic signature' with its grammatical variations and cognate expressions means adoption of any methodology or procedure by a person for the purpose of authenticating an electronic record by means of digital signature." Clause (d), as amended.

Clause (d) is a drafting untidiness worth noticing. The 2008 amendment substituted "electronic signature" for "digital signature" in the term being defined but left "digital signature" in the definition itself, so "affixing electronic signature" is defined as authenticating by means of a digital signature. Chapter 310 records it.

munotes.in90

The Definitions, Part Two: the People and the Transaction

Verify: clause (zh)

"'Verify', in relation to a digital signature, electronic record or public key, with its grammatical variations and cognate expressions, means to determine whether (a) the initial electronic record was affixed with the digital signature by the use of private key corresponding to the public key of the subscriber; (b) the initial electronic record is retained intact or has been altered since such electronic record was so affixed with the digital signature."

Two questions, and both must be answered before verification succeeds. Was it signed by the private key matching this public key, which is authenticity; and has it changed since, which is integrity. Chapter 280 works how the mathematics answers both at once.

The remaining definitions

"'Adjudicating officer' means an adjudicating officer appointed under sub-section (1) of section 46." Clause (c). Chapter 1120.

"'Appellate Tribunal' means the Appellate Tribunal referred to in sub-section (1) of section 48." Clause (da), inserted 2008. Chapter 1140 shows that what section 48 now refers to is the Telecom Disputes Settlement and Appellate Tribunal.

"'Appropriate Government' means, as respects any matter enumerated in List II of the Seventh Schedule to the Constitution, or relating to any State law enacted under List III, the State Government, and in any other case the Central Government." Clause (e). This is the clause behind section 90, the State rule-making power, and behind the division of function in sections 69 and 69B.

"'Electronic Gazette' means the Official Gazette published in the electronic form." Clause (s). Chapter 360 works section 8.

"'Function', 'law', 'prescribed', 'secure system' and 'security procedure' are in clauses (u), (y), (zb), (ze) and (zf). Clause (y) is worth a glance: "law" includes an Act of Parliament or of a State Legislature, an Ordinance, Regulations made by the President under article 240, a President's Act under article 357(1)(a), and rules, regulations, bye-laws and orders made under any of them. That width is what makes sections 4 and 5 reach subordinate legislation as well as statutes.

"'Indian Computer Emergency Response Team' means an agency established under sub-section (1) of section 70B." Clause (ua), inserted 2008. Chapter 760.

Section 2(2) provides that a reference in the Act to any enactment or provision is, in relation to an area where it is not in force, to be construed as a reference to the corresponding law in force in that area.

The Act's vocabulary against the Model Law's

The ActThe 1996 Model LawThe 2001 Model LawComment
Originator, 2(1)(za)Originator, art. 2(c)Almost identical, both excluding an intermediary
Addressee, 2(1)(b)Addressee, art. 2(d)Almost identical
Intermediary, 2(1)(w)Intermediary, art. 2(e)Same core; India added the list of businesses
Electronic record, 2(1)(t)Data message, art. 2(a)Data message, art. 2(c)Different words, same idea
Subscriber, 2(1)(zg)Signatory, art. 2(d)Same person
Certifying Authority, 2(1)(g)Certification service provider, art. 2(e)India defines by the licence, the Model Law by the activity
Electronic Signature Certificate, 2(1)(tb)Certificate, art. 2(b)Same
noneRelying party, art. 2(f)India has no term and no duty provision
Private key, 2(1)(zc)Signature creation dataIndia names the technology; the Model Law does not
noneInformation system, art. 2(f)India uses computer resource instead
munotes.in91

The Definitions, Part Two: the People and the Transaction

A worked example

Ashwini buys a saree from a marketplace. The seller is a shop in Surat. Payment goes through a payment gateway. The marketplace's servers are rented from a cloud provider.

Who is the originator of the order? Ashwini, under clause (za): she sent it, and she caused it to be transmitted.

Who is the addressee? The seller, if the order was intended for the seller. If the marketplace itself contracts as seller under an inventory model, the marketplace is the addressee. That is a question of fact about the marketplace's own terms, and chapter 970 works the marketplace and inventory models under the E-Commerce Rules 2020.

Who is an intermediary? The marketplace, as to the seller's listing and as to Ashwini's order, because it receives, stores or transmits those records on behalf of another. The payment gateway, expressly on the list as an online payment site. Her internet service provider. The cloud provider, as to the records it stores. Each of them, separately, and each only as to the particular records it handles.

Who is not an intermediary? The marketplace, as to its own advertising, its own product descriptions if it wrote them, and its own terms of service. Section 79 gives it nothing there, and chapter 1360 shows the line the cases have drawn.

Now suppose the saree never arrives and Ashwini alleges the listing was fraudulent. Every question about the marketplace's liability begins by asking whether it was acting as an intermediary in relation to the particular record complained of. The definition is not background; it is the first issue.

What this does NOT mean

It does not mean being an intermediary is a liability. It is the qualification for an immunity under section 79, subject to that section's conditions.

It does not mean the intermediary list is exhaustive. "Includes" makes it illustrative, and any person satisfying the functional test is an intermediary whether or not it is on the list.

It does not mean a Certifying Authority is anyone who certifies. Clause (g) defines it as a person granted a licence under section 24, so the definition is institutional.

munotes.in92

The Definitions, Part Two: the People and the Transaction

It does not mean the Act has a term for the relying party. It does not, and the duty article 11 of the 2001 Model Law puts on that person has no Indian counterpart.

Quick revision

  • Originator, 2(1)(za) and addressee, 2(1)(b): both taken from the Model Law and both expressly exclude an intermediary. The originator includes a person who causes a message to be sent, and one who stores it.
  • Intermediary, 2(1)(w), substituted 2008: with respect to a particular electronic record, a person who on behalf of another receives, stores or transmits it or provides any service with respect to it; the list of businesses is inclusive.
  • Subscriber, 2(1)(zg): the person the certificate names. The Model Law calls him the signatory.
  • Certifying Authority, 2(1)(g): defined by the licence under section 24, not by the activity.
  • Digital signature, 2(1)(p) sits inside electronic signature, 2(1)(ta); Digital Signature Certificate, 2(1)(q) sits inside Electronic Signature Certificate, 2(1)(tb).
  • Verify, 2(1)(zh): two questions, authenticity and integrity.
  • Asymmetric crypto system, key pair, private key, public key, clauses (f), (x), (zc), (zd): one technology written into the statute in 2000 and left there in 2008.
  • India has no definition of a relying party, and no equivalent of article 11 of the 2001 Model Law.

Test yourself

1. Why do the definitions of originator and addressee both exclude an intermediary? Because an intermediary handles the message on behalf of another and has no interest in its content, so treating it as a party would attach to it the legal consequences of a communication it did not make and did not intend to receive. The exclusion is taken from articles 2(c) and 2(d) of the 1996 Model Law.

2. Set out the definition of intermediary and identify its four limbs. Section 2(1)(w): with respect to any particular electronic records, any person who on behalf of another person (i) receives, (ii) stores or (iii) transmits that record, or (iv) provides any service with respect to that record, and includes the businesses listed. The fourth limb is the widest and is what brings a search engine within the definition.

3. Is a company an intermediary in relation to everything on its website? No. The definition operates "with respect to any particular electronic records", so the same company may be an intermediary as to a user's post and not as to its own content, its own advertising, or descriptions it wrote itself. That distinction is the first issue in any question about section 79.

munotes.in93

The Definitions, Part Two: the People and the Transaction

4. Explain the relationship between digital signature and electronic signature under section 2. Section 2(1)(p) defines a digital signature as authentication in accordance with section 3, which is the asymmetric crypto system and hash function route. Section 2(1)(ta), inserted in 2008, defines an electronic signature as authentication by the technique specified in the Second Schedule and expressly includes a digital signature. So electronic signature is the wider term and every digital signature is an electronic signature, but not the reverse.

5. Name two places where the Act's vocabulary has no Model Law counterpart, and one where the Model Law's has no Indian counterpart. The Act's Certifying Authority is defined by a licence, which has no Model Law counterpart because the Model Law regulates conduct rather than status; and the Act's cryptographic definitions in clauses (f), (x), (zc) and (zd) name a technology the Model Laws deliberately avoid. Conversely the 2001 Model Law's "relying party", article 2(f), has no Indian definition, so article 11's duty on that person has no counterpart in the Act.

Contents This chapter on its own page

munotes.in94

Chapter Seventeen

The Objects of the Act, and What Each Part Does

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

The Act says it exists to make electronic commerce work and to let people file things with the Government electronically, and about half of it does something else.

In the wording a student can write in an exam: the preamble to the Information Technology Act, 2000 states its purposes as giving legal recognition to transactions carried out by electronic data interchange and other means of electronic communication commonly referred to as electronic commerce, facilitating electronic filing of documents with Government agencies, and amending the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934; the regulatory and penal chapters that make up much of the Act appear in none of those stated purposes.

Why the purpose of a statute matters

Because a court reads a provision in the light of what the Act was for, and because an examination question asking whether the Act has succeeded needs a standard to measure it against. The preamble supplies that standard in the Act's own words.

And because the mismatch between the stated purposes and the actual contents is the most useful criticism a student can make, and it can be made accurately in three sentences.

The preamble, in the Act's own words

"An Act to provide legal recognition for the transactions carried out by means of electronic data interchange and other means of electronic communication, commonly referred to as 'electronic commerce', which involve the use of alternatives to paper-based methods of communication and storage of information, to facilitate electronic filing of documents with the Government agencies and further to amend the Indian Penal Code, the Indian Evidence Act, 1872, the Bankers' Books Evidence Act, 1891 and the Reserve Bank of India Act, 1934 and for matters connected therewith or incidental thereto."

Then three recitals. That the General Assembly of the United Nations by resolution A/RES/51/162 adopted the Model Law on Electronic Commerce. That the resolution recommends that all States give favourable consideration to the Model Law when they enact or revise their laws, in view of the need for uniformity of the law applicable to alternatives to paper-based methods of communication and storage of information. And that it is considered necessary to give effect to the said resolution and to promote efficient delivery of Government services by means of reliable electronic records.

The four purposes, and what each produced

Purpose one: legal recognition of electronic commerce. This is Chapters II, IV and V, sections 3 to 5, 10A, and 11 to 16. It is the Model Law, and chapter 110 measures how faithfully it was taken.

Purpose two: facilitating electronic filing with Government agencies. This is Chapter III, sections 6 to 9, together with section 6A added in 2008. Chapters 350 to 380 work it, and the last of those shows what it became: DigiLocker, e-KYC and the service delivery machinery.

munotes.in95

The Objects of the Act, and What Each Part Does

Purpose three: amending four statutes. Sections 91 to 94 with the Third and Fourth Schedules, all since omitted as spent. What section 92 did to the Indian Evidence Act, inserting the old section 65B, is the reason electronic records are admissible in Indian courts at all, and chapter 1270 works its successor.

Purpose four, in the third recital: promoting efficient delivery of Government services by means of reliable electronic records. The word reliable is doing quiet work. Reliability is what Chapters VI, VII and VIII are for: a certificate is reliable because a licensed Certifying Authority stands behind it. So the licensing regime is traceable to the preamble, though only through this recital.

What the preamble does not mention

No offence. Chapter XI, sections 65 to 78, creates about twenty offences, and nothing in the preamble announces them.

No State power over the network. Sections 69, 69A, 69B, 70, 70A and 70B give powers of interception, blocking, traffic monitoring, and the machinery of protected systems, critical information infrastructure and CERT-In. The preamble is silent.

No intermediary regime. Section 79 and the rules under it are the most consequential part of the Act in daily life, and the preamble does not hint at them. Section 79 in its present form was inserted in 2008, long after the preamble was written.

No data protection. Section 43A and the SPDI Rules 2011 came in 2008 and 2011.

That is not a defect of drafting; it is the record of what happened. The Act was written as a commerce statute in 1999 and became, by amendment, the principal instrument of internet regulation in India. Chapter 180 works the amendment that did most of it.

Holding the Act against its own purposes

On purpose one it has largely succeeded. Electronic contracting is ordinary in India, the recognition provisions are used without controversy, and the courts have not had to strain them. The one real gap is section 5's prescribed-method rule for signatures, which chapter 110 works.

On purpose two it has succeeded beyond what was expected. Section 6 was drafted for filing forms; what it enabled, with section 6A and the rules of 2011, is a service delivery architecture through which a citizen obtains documents rather than merely submitting them. Chapter 380 works it.

On purpose three it did what it said, and the provisions have been omitted as spent.

On the purposes it never stated, the record is mixed and contested, which is what Modules III and IV are about. Section 66A was struck down. Sections 69A and 79 survived and were read down. The 2021 Rules are the subject of continuing litigation. A student writing a critical answer has plenty to say and should say it about the parts the preamble never claimed.

munotes.in96

The Objects of the Act, and What Each Part Does

A worked example

A court has to decide whether a wholly new kind of electronic instrument, unmentioned in the Act, is within it. Counsel on both sides argue from the preamble. How is the argument run?

Step one, what the preamble says. The Act is to provide legal recognition for transactions carried out by means of electronic data interchange and other means of electronic communication, commonly referred to as electronic commerce, which involve the use of alternatives to paper-based methods of communication and storage of information; to facilitate electronic filing of documents with Government agencies; and to amend the Indian Penal Code, 1860, the Indian Evidence Act, 1872, the Bankers' Books Evidence Act, 1891, and the Reserve Bank of India Act, 1934.

Step two, what a preamble may be used for. It is a key to the intention of the makers and may be used to resolve an ambiguity, but it cannot control clear words. So counsel may argue from it that a doubtful provision should be read to include the new instrument, and may not argue from it that a plain exclusion should be ignored.

Step three, the argument for inclusion. The first purpose is drawn widely, "and other means of electronic communication", and the functional equivalence approach the Act adopts from the Model Law asks what a paper rule is for rather than what form it takes. Chapter 80.

Step four, the argument against, and it is the stronger one. The First Schedule excludes five classes of document by type, not by function, so Parliament has shown that it legislates by naming, and section 1(4) gives that exclusion statutory force. Section 3A requires an electronic signature technique to be specified in the Second Schedule, so recognition is by listing and not by resemblance. Chapters 140 and 250.

Step five, and the point the preamble makes by omission. It says nothing about cyber crime, nothing about cyber security, nothing about privacy or data protection and nothing about intermediaries. Chapters IX and XI, sections 69, 69A, 69B, 70A, 70B, 79 and 43A were all added later or expanded far beyond what the preamble contemplated. A statute whose preamble is about electronic commerce now carries India's interception power, its blocking power and its national incident response agency.

Step six, the conclusion to state. That the Act has succeeded on its first two purposes, spent itself on the third, and grown a fourth body of law its preamble never announced, and that an argument from the preamble is therefore weakest exactly where the modern litigation is. Chapter 1420.

munotes.in97

The Objects of the Act, and What Each Part Does

What this does NOT mean

It does not mean the added chapters are ultra vires. Parliament may legislate on what it chooses, and a preamble does not confine the enacting words. It means only that the Act's stated purpose is a poor description of the Act as it now stands.

It does not mean the preamble is useless. It is the reason the Model Law is a legitimate aid to construing sections 4, 7, 11, 12 and 13, because the Act says on its face that it was enacted to give effect to the resolution adopting it.

It does not mean the Act failed at what it set out to do. On its stated purposes it worked.

Quick revision

  • The preamble names three purposes: legal recognition of electronic commerce; facilitating electronic filing with Government agencies; amending the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934.
  • The recitals name resolution A/RES/51/162, the recommendation of favourable consideration in the interests of uniformity, and the promotion of efficient delivery of Government services by reliable electronic records.
  • The word "reliable" is the only textual hook for Chapters VI to VIII, the licensing regime.
  • Not mentioned: offences, the State powers in sections 69 to 70B, the intermediary safe harbour in section 79, and data protection. All of the last three were inserted in 2008 or later.
  • The preamble legitimises using the Model Law to construe the recognition provisions, because the Act says on its face that it was enacted to give effect to the resolution adopting it.

Test yourself

1. State the purposes the preamble names. To provide legal recognition for transactions carried out by means of electronic data interchange and other means of electronic communication commonly referred to as electronic commerce, involving alternatives to paper-based methods of communication and storage of information; to facilitate electronic filing of documents with Government agencies; and to amend the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934.

2. Which substantial parts of the Act are not traceable to any stated purpose? The offences in Chapter XI; the State powers in sections 69, 69A, 69B, 70, 70A and 70B; the intermediary safe harbour in section 79 and the rules under it; and the data protection provision in section 43A. The licensing regime in Chapters VI to VIII is traceable only through the third recital's reference to reliable electronic records.

munotes.in98

The Objects of the Act, and What Each Part Does

3. What use can be made of the preamble in construing section 13? It records that the Act was enacted to give effect to General Assembly resolution A/RES/51/162 adopting the UNCITRAL Model Law on Electronic Commerce, which makes the Model Law and its Guide to Enactment legitimate aids to construction of the provisions taken from it, of which section 13 is one.

4. Does the mismatch between the preamble and the contents affect the validity of the added chapters? No. A preamble does not confine enacting words, and Parliament's competence to legislate is not measured by the Act's stated purposes. The mismatch is a description of how the statute developed and is material for criticism, not for validity.

Contents This chapter on its own page

munotes.in99

Chapter Eighteen

The Information Technology (Amendment) Act, 2008

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

The 2008 amendment is where the Act a student actually studies came from: almost every provision in Modules III and IV was put there by it.

In the wording a student can write in an exam: the Information Technology (Amendment) Act, 2008, Act 10 of 2009, which came into force on 27 October 2009, substantially rewrote the Information Technology Act, 2000 by replacing digital signature with the technology-neutral concept of electronic signature, inserting a data protection provision, creating a graded set of computer-related offences in place of the single offence of hacking, conferring on the Central Government express powers of interception, blocking and traffic monitoring, creating the institutions of critical information infrastructure protection and computer emergency response, and substituting a conditional safe harbour for intermediaries.

Why the Act had to be amended

Three things had changed between 1999 and 2008.

The technology. The Act was drafted for electronic data interchange between businesses. By 2008 India had a mass internet, mobile phones with cameras, social networking, online marketplaces and online banking.

The case law had shown up the gaps. Two prosecutions in particular. In the Bazee.com matter a chief executive was prosecuted because a user had listed an obscene video for sale on a marketplace, and the Act as it stood had no provision protecting an intermediary that had not itself published anything. And there was no offence at all that fitted publishing a private photograph, or sending a threatening message, or stealing an identity.

And there was a security case. The attacks in Mumbai in November 2008 happened while the Bill was before Parliament, and the Bill was passed on 23 December 2008 with the surveillance provisions in a form that had not been fully debated. The speed of that passage is a standing criticism of the amendment and a fair point in an examination answer.

An Expert Committee had reported in 2005 recommending most of the substantive changes, so the substance was not improvised even if the passage was hurried.

What the amendment inserted

Every lettered section in the Act is a later insertion, and almost all of them are from 2008.

SectionWhat it doesChapter
3AElectronic signature, and the Second Schedule290
6ADelivery of services by a service provider370
7AAudit of documents maintained in electronic form360
10AValidity of contracts formed through electronic means930
40ADuties of a subscriber of an Electronic Signature Certificate340
43ACompensation for failure to protect data1040
52A to 52DPowers of the Chairperson of the Tribunal, distribution of business, transfer, decision by majority1150
66APunishment for sending offensive messages, struck down in 20151190
66BDishonestly receiving a stolen computer resource1200
66CIdentity theft1200
66DCheating by personation using a computer resource1210
66EViolation of privacy1210
66FCyber terrorism1320
67ASexually explicit material1220
67BMaterial depicting children in a sexually explicit act1230
67CPreservation and retention of information by intermediaries1240
69ABlocking public access to information810
69BMonitoring and collecting traffic data for cyber security820
70AThe national nodal agency, now NCIIPC780
70BCERT-In760
72ADisclosure of information in breach of lawful contract1250
77ACompounding of offences1300
77BOffences with three years imprisonment to be bailable1300
79AExaminer of Electronic Evidence1270
84AModes or methods for encryption830
84BPunishment for abetment1290
84CPunishment for attempt1290
munotes.in100

The Information Technology (Amendment) Act, 2008

What the amendment substituted or rewrote

Section 66 was rewritten completely. It had been headed "Hacking with computer system" and had contained its own definition of the conduct. It now reads: if any person, dishonestly or fraudulently, does any act referred to in section 43, he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both. The word hacking left the statute. Chapter 1180 works the consequences, and the point worth noticing here is that a criminal provision now borrows its conduct from a civil one.

Section 43 was widened. The one crore rupee cap on compensation was removed, so compensation is now at large, and the list grew from eight entries to ten: clause (i), destroying, deleting or altering information or diminishing its value or utility, and clause (j), stealing, concealing, destroying or altering computer source code with intent to cause damage, were both inserted.

Section 46 gained sub-section (1A), giving the adjudicating officer jurisdiction where the claim for damage does not exceed five crore rupees and vesting jurisdiction above that in the competent court. Chapter 1120 works it.

Section 69 was substituted. The original section 69 was a decryption power in narrow terms. The new one is a full interception, monitoring and decryption power with five stated grounds, and chapter 800 works it with the 2009 Rules.

Section 79 was substituted whole, and Chapter XII was rewritten around it. The original section 79 gave a network service provider a defence of proving that the contravention was committed without its knowledge or that it had exercised all due diligence. The new section confers an exemption subject to three conditions, and chapter 1360 works it.

Section 2 gained six definitions: communication device, cyber cafe, cyber security, electronic signature, Electronic Signature Certificate and Indian Computer Emergency Response Team; and two were substituted, computer network and intermediary. Chapters 150 and 160 own them.

munotes.in101

The Information Technology (Amendment) Act, 2008

Section 67 was rewritten, and the sentence structure changed: the maximum on first conviction became three years and five lakh rupees, and on second or subsequent conviction five years and ten lakh rupees.

The First and Second Schedules were substituted.

What the amendment omitted

Sections 91 to 94 were omitted as spent, having carried the amendments to the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934.

Section 20 was omitted, which had made the Controller a repository of all Digital Signature Certificates.

The five things the amendment changed in kind

One: from one technology to many. Sections 3A and 15, with the Second Schedule, replaced a statute that recognised only the asymmetric crypto system with one that can recognise any technique the Central Government specifies. Chapter 290 works it. This is the 2001 Model Law's philosophy arriving eight years late.

Two: from one offence to a graded set. The original Act had section 65 and section 66, and the second was headed hacking. The amendment produced sections 66 and 66A to 66F, each with its own conduct and its own sentence, running from three years for computer-related offences to imprisonment for life for cyber terrorism. Chapter 1090 shows the resulting scheme.

Three: from silence to a surveillance code. Sections 69, 69A and 69B, with the three sets of Rules of 2009, are the Indian State's principal powers over the network, and none existed in this form before. Chapters 800 to 820 work them.

Four: from no institutions to three. Section 70A creates the national nodal agency for critical information infrastructure protection, section 70B creates CERT-In as the national agency for incident response, and section 79A provides for notified Examiners of Electronic Evidence. Chapters 780, 760 and 1270.

Five: from a defence to a conditional immunity. The new section 79 is the difference between an intermediary having to prove absence of knowledge and diligence in every case, and having an exemption it keeps by observing due diligence and acting on actual knowledge. Chapter 1360 works it.

A worked example

The same facts under the two versions of the Act.

In 2007, a user of an online marketplace lists an obscene video clip for sale. Another user buys it. The clip is transmitted.

Under the Act as it then stood. The seller has published obscene material in electronic form and is caught by section 67. The marketplace has published nothing and has no exemption designed for it: section 79 as it then read gave a network service provider a defence on proof of no knowledge and all due diligence, and it was arguable whether a marketplace was a network service provider at all. The chief executive was prosecuted. There was no provision at all reaching the buyer's onward transmission by phone.

munotes.in102

The Information Technology (Amendment) Act, 2008

Under the Act as amended. The seller is caught by section 67 and, if the material is sexually explicit, by section 67A. The marketplace is an intermediary within the substituted section 2(1)(w), which now names online-market places expressly, and section 79(1) exempts it from liability for third party information it did not initiate, select the receiver of, or select or modify, provided it observes due diligence and takes down on actual knowledge. Section 79(3)(b), as read down in 2015, makes actual knowledge mean a court order or a government notification. Section 85 governs when an officer of the company is liable. And the buyer's onward transmission by mobile phone is reached because section 67 covers transmitting, and a communication device is now defined.

The comparison is the answer to a question about what the amendment achieved, and it also shows what it cost: section 66A, drafted in the same amendment, was so wide that it was struck down.

What this does NOT mean

It does not mean the Act was renamed. The principal Act is still the Information Technology Act, 2000. The amending Act is Act 10 of 2009, commonly called ITAA 2008 after the year the Bill was passed.

It does not mean everything since 2009 is unchanged. The Finance Act 2017, the Digital Personal Data Protection Act 2023 and the rules of 2021 and 2026 have all changed the Act or the law around it, and chapter 190 works them.

It does not mean the amendment was well received. Section 66A was struck down as unconstitutional. Sections 69 and 69A are criticised as executive powers with no judicial oversight. The manner of passage, without effective debate in December 2008, is a standing complaint. A good answer says all three.

Quick revision

  • Act 10 of 2009, in force 27 October 2009. Bill passed 23 December 2008; the Expert Committee had reported in 2005; the Mumbai attacks of November 2008 are the reason for the manner of passage.
  • Every lettered section is a later insertion, and almost all are from this amendment: 3A, 6A, 7A, 10A, 40A, 43A, 52A to 52D, 66A to 66F, 67A to 67C, 69A, 69B, 70A, 70B, 72A, 77A, 77B, 79A, 84A to 84C.
  • Rewritten: section 66, which now borrows its conduct from section 43 and drops the word hacking; section 43, cap removed and clauses (i) and (j) added; section 69, now a full interception power; section 79, now a conditional immunity; section 67; and section 2, with six new definitions and two substituted.
  • Section 46(1A) gave the adjudicating officer the five crore rupee limit.
  • Omitted: sections 91 to 94 as spent, and section 20.
  • Five changes in kind: one technology to many; one offence to a graded set; silence to a surveillance code; no institutions to three; a defence to a conditional immunity.
munotes.in103

The Information Technology (Amendment) Act, 2008

Test yourself

1. Name six sections inserted by the 2008 amendment and say what each does. Section 43A, compensation for a body corporate's failure to protect sensitive personal data. Section 66C, identity theft. Section 66E, violation of privacy. Section 66F, cyber terrorism. Section 69A, blocking public access to information. Section 70B, CERT-In. Any six of the lettered sections listed above will do, provided the function is stated.

2. How did the amendment change section 66, and why does that matter? It replaced the offence of hacking with a provision punishing any act referred to in section 43 done dishonestly or fraudulently. It matters because a criminal offence now takes its conduct from a civil compensation provision, so the ten clauses of section 43 define the actus reus of section 66, and the entire criminal liability turns on the two mental elements, dishonestly and fraudulently, which the Act borrows from the general penal law.

3. What was the position of an intermediary before 2009 and what is it now? Before, section 79 gave a network service provider a defence if it proved that the contravention was committed without its knowledge or that it had exercised all due diligence, which put the burden on the provider in every case and left it unclear which businesses qualified. Now section 79(1) exempts an intermediary from liability for third party information provided it did not initiate the transmission, select the receiver or select or modify the information, and provided it observes due diligence and acts on actual knowledge under section 79(3)(b).

4. Give three criticisms of the amendment. It was passed on 23 December 2008 in the aftermath of the Mumbai attacks without effective debate. Section 66A was drafted so widely that it was struck down as unconstitutional in 2015. And the surveillance powers in sections 69, 69A and 69B were conferred on the executive with review by a committee of officials rather than any judicial oversight.

5. Why is a book or judgment dated before 27 October 2009 unsafe on this subject? Because the amendment inserted twenty-seven sections, substituted section 66, section 69, section 79 and both Schedules, added six definitions and substituted two more. Almost every provision a student meets in Modules III and IV came from it, and the pre-amendment Act has a different section 66, a different section 79 and no sections 43A, 66A to 66F, 67A to 67C, 69A, 69B, 70A, 70B or 72A at all.

Contents This chapter on its own page

munotes.in104

Chapter Nineteen

What Has Changed Since 2008

Syllabus topic 1.3, "An Overview of the Information Technology Act"

In one line

Since 2009 the Act has been changed by four other statutes and by rules, and three of those changes are more recent than any textbook a student is likely to own.

In the wording a student can write in an exam: since the Information Technology (Amendment) Act, 2008 came into force, the Information Technology Act, 2000 has been altered by the Finance Act, 2017, which abolished the Cyber Appellate Tribunal and made the Telecom Disputes Settlement and Appellate Tribunal the appellate forum; by notification S.O. 4720(E) dated 26 September 2022 amending the First Schedule; and by the Digital Personal Data Protection Act, 2023, whose section 44 is commencing in stages; and the rules under it have been replaced by the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021, themselves amended with effect from 20 February 2026.

Why this chapter exists

Because the Act on a bookshelf is not the Act in force. Four separate instruments have changed it since 2009, and two of them, in 2025 and 2026, are more recent than any commercially published commentary. A student who answers from a textbook printed in 2023 will state at least two propositions that are no longer true and will miss one that is examinable today.

Each change is dated from its own Gazette in this book, and the dates are the answer, so learn them.

2017: the Cyber Appellate Tribunal is abolished

Part XIV of Chapter VI of the Finance Act, 2017 merged a large number of tribunals. The Cyber Appellate Tribunal was one of them.

Section 48 of the Act now reads, in its substituted sub-section (1), that the Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997 shall, on and from the commencement of Part XIV of Chapter VI of the Finance Act, 2017, be the Appellate Tribunal for the purposes of this Act, and shall exercise the jurisdiction, powers and authority conferred on it by or under this Act.

Sections 49 to 54 and section 56 were omitted, being the provisions on the composition of the Cyber Appellate Tribunal, the qualifications and term of its Chairperson and Members, their salaries, the Chairperson's powers of superintendence and the transfer of cases, the filling of vacancies, resignation and removal, and the Tribunal's staff.

Section 52D, decision by majority, survives, as does section 55, which makes orders constituting the Tribunal final.

Two consequences. The Tribunal a student must describe is now constituted by a different Act altogether, so chapter 1140 has to work sections 14 to 19 of the TRAI Act. And MU still prints "Appellate Tribunal" as topic 4.4 and both 2015 papers asked for the establishment, composition, jurisdiction and powers of the Cyber Appellate Tribunal, so chapter 1150 teaches the abolished sections as well.

munotes.in105

What Has Changed Since 2008

2022: the First Schedule loses an entry

Notification S.O. 4720(E) dated 26 September 2022, made under the proviso to section 1(4), did three things: it carved a cheque, demand promissory note and bill of exchange out of serial number 1 where a regulated financial entity is the payee or endorser; it carved a power of attorney empowering such an entity out of serial number 2; and it omitted serial number 5 entirely.

Serial number 5 was "any contract for the sale or conveyance of immovable property or any interest in such property". Chapter 140 works the change and, just as importantly, what it does not do.

2021 and 2026: the rules under section 79 are replaced and then amended

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were notified on 25 February 2021 in supersession of the Information Technology (Intermediaries Guidelines) Rules, 2011. They did three things the 2011 Rules had not: they expanded the due diligence in rule 3; they created a class of significant social media intermediary with additional obligations in rule 4; and they added Part III, a Code of Ethics for publishers of news and current affairs content and of online curated content, with a three-tier grievance mechanism. Chapters 1350, 1360 and 1370 work them.

They were amended in 2022 to add the Grievance Appellate Committees, in 2023 to add online gaming provisions and a fact check unit, and again with effect from 20 February 2026.

G.S.R. 120(E) dated 10 February 2026, in force 20 February 2026, is the most recent change to this subject and the most striking. It inserted into rule 2(1) a definition of audio, visual or audio-visual information, clause (ca), and a definition of synthetically generated information, clause (wa); it inserted rule 3(3), a due diligence regime for synthetically generated information requiring labelling, permanent provenance metadata, a declaration by the user and reasonable technical measures to verify; and it substituted "three hours" for "thirty-six hours" in the removal window in rule 3. Chapters 990 and 1000 work it in full.

A further set of amendments remains a draft. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Second Amendment Rules, 2026 were published for consultation in March and April 2026 and had not been notified when this book was written: the published text carries blanks where the date and the G.S.R. number should be. They are named in this book as a proposal and never taught as law.

munotes.in106

What Has Changed Since 2008

2023 and 2025: the Digital Personal Data Protection Act, commencing in stages

This is the change most likely to be stated wrongly, and the reason is that the Act was passed in 2023 and is coming into force in 2027.

Section 44 of the Digital Personal Data Protection Act, 2023 makes three sets of consequential amendments. Sub-section (1) substitutes clause (c) of section 14 of the TRAI Act, so that the Telecom Disputes Settlement and Appellate Tribunal is the Appellate Tribunal under the Information Technology Act, the Airports Economic Regulatory Authority of India Act and the Digital Personal Data Protection Act. Sub-section (2) amends the Information Technology Act by omitting section 43A, by inserting a reference to the Digital Personal Data Protection Act in the proviso to section 81, and by omitting clause (ob) of section 87(2). Sub-section (3) substitutes clause (j) of section 8(1) of the Right to Information Act, 2005 to read simply "information which relates to personal information".

Notification G.S.R. 843(E) dated 13 November 2025 brought the Act into force in three stages, and which stage a provision is in decides whether it is law today.

FromProvisions in force
13 November 2025Section 1(2), section 2, sections 18 to 26, sections 35, 38, 39, 40, 41, 42, 43, and section 44(1) and 44(3)
13 November 2026Section 6(9) and section 27(1)(d)
13 May 2027Sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 10, sections 11 to 17, section 27 except (1)(d), sections 28 to 34, sections 36 and 37, and section 44(2)

Three propositions follow and each is examinable.

Section 43A of the Information Technology Act is still live law, and so are the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011 made under it, because section 44(2) is in the third stage and does not commence until 13 May 2027. Chapter 230 works the SPDI Rules on that footing and chapter 1040 works section 43A.

Section 8(1)(j) of the Right to Information Act has already been rewritten, from 13 November 2025, because section 44(3) is in the first stage. The exemption now reads "information which relates to personal information" without the qualifications the old clause carried, which is a significant narrowing of the right to information and is not yet in most textbooks.

The substantive data protection scheme is not yet in force. Sections 3 to 17, which contain the grounds for processing, consent, notice, the duties of a Data Fiduciary, the obligations towards children, the Significant Data Fiduciary provisions and the rights of a Data Principal, all commence on 13 May 2027. Chapter 1050 teaches them and says so on the page.

The Data Protection Board of India exists, because sections 18 to 26 commenced on 13 November 2025, and the Digital Personal Data Protection Rules, 2025 were notified the same day with a matching staged application. Chapter 1060 works the Board.

munotes.in107

What Has Changed Since 2008

The state of the law, in one table

InstrumentDateEffectIn force?
IT (Amendment) Act 2008, Act 10 of 200927 October 2009Rewrote the ActYes
IT Rules 2011: SPDI, Intermediaries Guidelines, Cyber Cafe, Electronic Service Delivery11 April 2011Rules under ss.43A, 79, 6ASPDI, Cyber Cafe and ESD yes; the 2011 Intermediaries Guidelines superseded in 2021
Finance Act 2017, Part XIV of Chapter VI2017Abolished the Cyber Appellate Tribunal; TDSAT becomes the Appellate TribunalYes
IT Rules 202125 February 2021Replaced the 2011 intermediary rules; added Part IIIYes, as amended
S.O. 4720(E)26 September 2022Amended the First Schedule; omitted serial 5Yes
CERT-In Directions under s.70B(6)28 April 2022Six-hour incident reporting, 180-day logs in India, KYCYes
DPDP Act 2023, s.44(1) and (3)13 November 2025TRAI Act s.14(c) and RTI Act s.8(1)(j) substitutedYes
DPDP Act 2023, ss.18 to 2613 November 2025Data Protection Board establishedYes
G.S.R. 120(E)20 February 2026Synthetically generated information; three-hour takedownYes
DPDP Act 2023, s.6(9) and s.27(1)(d)13 November 2026Consent managersNot yet
DPDP Act 2023, ss.3 to 17 and s.44(2)13 May 2027The substantive scheme; omission of IT Act s.43ANot yet
IT Second Amendment Rules 2026draftRetention, labelling, compliance with Ministry directionsA draft. Not law

A worked example

A student is asked in an examination: "A company's server is breached and the personal data of two lakh customers is leaked. Advise."

A textbook answer from 2024 would say that section 43A has been repealed by the Digital Personal Data Protection Act and that the customers' remedy lies under that Act.

The correct answer today is different in both halves. Section 43A is in force, because section 44(2) of the DPDP Act does not commence until 13 May 2027, so a customer may claim compensation from the body corporate for negligence in implementing and maintaining reasonable security practices, which the SPDI Rules 2011 define. And the substantive DPDP obligations are not in force either, because sections 3 to 17 commence on the same date, so no claim lies under them.

What is in force from the DPDP Act is the Board, sections 18 to 26, which has been established but whose enforcement powers bite on obligations that do not yet exist.

And what does apply immediately is the CERT-In direction of 28 April 2022, which requires the incident to be reported to CERT-In within six hours of noticing it.

Getting that answer right requires the commencement notification and nothing else, which is why chapter 1050 quotes it.

munotes.in108

What Has Changed Since 2008

What this does NOT mean

It does not mean the Act has been rewritten again. Only section 48 and the First Schedule have been altered in the Act's own text since 2009. Everything else is either in rules or is a change that has not yet commenced.

It does not mean the DPDP Act is a dead letter. It is law, passed and partly commenced, and the compliance timelines run from November 2025 whether or not the obligations bite until 2027.

It does not mean the draft Second Amendment Rules can be ignored. They should be named as a proposal in any answer about the direction of the law, and never stated as law.

It does not mean section 66A is back. It was struck down in 2015 and no amendment has restored it. Chapter 1190 works what happened.

Quick revision

  • Finance Act 2017, Part XIV of Chapter VI: Cyber Appellate Tribunal abolished; TDSAT becomes the Appellate Tribunal under substituted section 48(1); sections 49 to 54 and 56 omitted; 52D and 55 survive.
  • S.O. 4720(E), 26 September 2022: First Schedule amended; serial number 5, contracts for sale or conveyance of immovable property, omitted.
  • IT Rules 2021, 25 February 2021, superseded the 2011 Intermediaries Guidelines and added Part III.
  • G.S.R. 120(E), 10 February 2026, in force 20 February 2026: synthetically generated information defined and regulated; three hours replaces thirty-six.
  • DPDP Act 2023, commenced by G.S.R. 843(E) of 13 November 2025 in three stages: at once, sections 1(2), 2, 18 to 26, 35, 38 to 43, and 44(1) and 44(3); after twelve months, 6(9) and 27(1)(d); after eighteen months, sections 3 to 17 and section 44(2), on 13 May 2027.
  • So today: IT Act section 43A and the SPDI Rules 2011 are LIVE; RTI Act section 8(1)(j) has already been substituted; and the DPDP substantive scheme is not yet in force.
  • The Second Amendment Rules 2026 are a draft, not notified.

Test yourself

1. Which body is the Appellate Tribunal under the Information Technology Act today, and under which statute is it constituted? The Telecom Disputes Settlement and Appellate Tribunal, constituted under section 14 of the Telecom Regulatory Authority of India Act, 1997. Section 48(1) of the Information Technology Act, as substituted, makes it the Appellate Tribunal for the purposes of that Act on and from the commencement of Part XIV of Chapter VI of the Finance Act, 2017.

2. Is section 43A of the Information Technology Act in force? Yes. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 provides for its omission, but notification G.S.R. 843(E) of 13 November 2025 placed section 44(2) in the eighteen-month stage, so it comes into force on 13 May 2027. Until then section 43A and the SPDI Rules 2011 made under it continue to apply.

munotes.in109

What Has Changed Since 2008

3. Which provisions of the DPDP Act are already in force, and what did two of them change outside that Act? Section 1(2), section 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3), all from 13 November 2025. Section 44(1) substituted clause (c) of section 14 of the TRAI Act so that the TDSAT is named as the Appellate Tribunal under the IT Act, the AERA Act and the DPDP Act. Section 44(3) substituted clause (j) of section 8(1) of the Right to Information Act, 2005, which now exempts "information which relates to personal information".

4. What did G.S.R. 120(E) do and when did it take effect? Notified 10 February 2026 and in force from 20 February 2026, it amended the IT Rules 2021 by defining audio, visual or audio-visual information in rule 2(1)(ca) and synthetically generated information in rule 2(1)(wa), by inserting rule 3(3) requiring labelling, permanent provenance metadata, a user declaration and reasonable technical verification measures for synthetically generated information, and by substituting three hours for thirty-six hours in the removal window in rule 3.

5. Why is a commencement notification worth reading in full rather than summarising? Because it is a list, and what it omits is not in force. G.S.R. 843(E) brings section 44(1) and 44(3) into force at once and section 44(2) only after eighteen months, so a summary saying "the DPDP Act came into force in November 2025" produces two wrong answers: that section 43A of the IT Act has gone, and that the consent and rights provisions apply now. Neither is true.

Contents This chapter on its own page

munotes.in110

Chapter Twenty

What Information Security Means

Syllabus topic 1.4, "Information Security"

In one line

Information security is keeping information confidential, unaltered and available, and every provision of this Act about protection is an attack on one of those three.

In the wording a student can write in an exam: information security is the practice of protecting information and the systems that hold it against unauthorised access, use, disclosure, disruption, modification or destruction, and it is conventionally analysed as three objectives, confidentiality, integrity and availability, to which authenticity and non-repudiation are usually added when the subject is electronic transactions.

Why the law needs the vocabulary

Because the Act uses it, and defines only half of it. Section 2(1)(nb), inserted in 2008, defines cyber security as protecting information, equipment, devices, computer, computer resource, communication device and information stored therein from unauthorised access, use, disclosure, disruption, modification or destruction. That is a list of six harms, and the three objectives below are the standard way of organising them.

And because MU prints topic 1.4 as "Information Security" and asks about it: a short note on information security was set in 2015.

The three objectives

Confidentiality: only those who should see it, do. The harms are unauthorised access, use and disclosure. In the Act: section 43(b) on downloading or copying data without permission, section 66E on capturing a private image, section 72 on breach of confidentiality by a person with statutory powers, section 72A on disclosure in breach of a lawful contract, and the whole of section 43A with the SPDI Rules.

Integrity: the information is what it was, and has not been changed. The harms are unauthorised modification and destruction. In the Act: section 43(d) on damaging data, section 43(i) on destroying, deleting or altering information or diminishing its value or utility, section 65 on altering computer source code, and sections 14, 15 and 3 on secure records and signatures. Chapter 220 works those.

Availability: it is there when it is needed. The harm is disruption. In the Act: section 43(e) on disrupting a computer, computer system or computer network, section 43(f) on denying access to an authorised person, and section 66F(1)(A)(i) and (ii), where denying access or attempting to penetrate is the actus reus of cyber terrorism.

The three pull against one another, and that is the practical point. Encrypting everything raises confidentiality and lowers availability, because a lost key is lost data. Keeping many backups raises availability and lowers confidentiality, because each copy is another thing to steal. Security is a set of trade-offs, not a maximum, and section 16 acknowledges this by directing the Central Government to have regard to the commercial circumstances and the nature of transactions when prescribing security procedures.

The two objectives added for transactions

Authenticity: the message is from whom it claims to be from. This is what a digital signature's verification answers first, and chapter 280 works the mechanism. The Act attacks failures of authenticity through section 66C on identity theft, section 66D on cheating by personation, and section 74 on publication for a fraudulent purpose.

munotes.in111

What Information Security Means

Non-repudiation: the sender cannot later deny sending it. This is authenticity looked at from the other end, and it is why the reliability criteria in section 3A(2) require sole control of the signature creation data. If two people could have created the signature, the signer can deny it.

Section 11, attribution, is the Act's answer to a dispute about both, and chapter 940 shows how narrow that answer is.

How the objectives are actually achieved

Four families of control, and the SPDI Rules require a body corporate to have all four.

Administrative controls are policies and people: an information security policy, defined roles, background checks, training, and a process for granting and withdrawing access when somebody joins or leaves. Rule 8(1) of the SPDI Rules calls these managerial controls and requires them to be documented.

Technical controls are the machinery: authentication, access control lists, encryption at rest and in transit, firewalls, intrusion detection, patching and logging.

Operational controls are the routines: backups that are tested, monitoring of logs, incident response, and change management.

Physical controls are locks, access to server rooms, and disposal of old media.

Rule 8(1) requires "managerial, technical, operational and physical security control measures that are commensurate with the information assets being protected with the nature of business", which is those four families in the Rules' own words. Chapter 230 works rule 8 in full.

Two principles a lawyer should be able to state

Defence in depth. No single control is relied on. A firewall, an authentication requirement, encryption and logging each fail sometimes; the point is that they must fail together for the breach to succeed. When an incident is investigated, the question is not whether one control failed but whether the layers were there at all.

Least privilege. A person or a program is given the access needed for the task and no more. This is the control most often missing in practice, and it is why the departing employee in chapter 150's worked example could copy an entire database: he had access he did not need.

Security is not privacy, and the distinction matters legally

Information securityPrivacy
The questionIs the information protected from those who should not have it?Should this information have been collected, and may it be used this way?
Failure looks likeA breach: somebody got inA misuse: the holder did what it should not have done
In the ActSection 43A and the SPDI Rules, sections 14 to 16, section 70Sections 66E and 72A; and the Digital Personal Data Protection Act, 2023
Can you have one without the other?Yes: perfectly secured data collected without consentYes: lawfully collected data, badly protected
munotes.in112

What Information Security Means

A body corporate that encrypts everything and sells the data has perfect security and no privacy. That is why the DPDP Act was needed and why section 43A was never a data protection statute. Chapters 1040 and 1050 work the distinction.

A worked example

Ratnagiri Diagnostics keeps patients' test reports on a server in its clinic.

Confidentiality. Reports contain medical records, which are sensitive personal data or information under rule 3(v) of the SPDI Rules. Access is limited to the doctors and the lab, each with an individual login, and the reports are encrypted on the disk.

Integrity. A report cannot be edited after it is signed off; a correction is made by issuing a new report and the old one is retained. Each report carries a hash recorded in a register, so an altered report is detectable. Chapter 270 explains the mechanism.

Availability. The server is backed up nightly to a second location and the backup is restored to a test machine each month, because a backup that has never been restored is not a backup.

Now the failure. A receptionist's password is written on a note under the keyboard. A visitor uses it and copies four hundred reports.

Which objective failed? Confidentiality, and the cause was administrative rather than technical: the encryption, the access controls and the logging all worked as designed and were defeated by a credential that was not kept secret. That is the ordinary shape of a real breach.

What follows in law? Section 43A gives the patients a claim for compensation if the clinic was negligent in implementing and maintaining reasonable security practices, and rule 8 supplies the standard. Whether the clinic's documented programme covered password handling is the whole question. Section 43(b) and section 66 reach the visitor. And the incident is a cyber incident, reportable to CERT-In within six hours under the direction of 28 April 2022, which chapter 770 works.

What this does NOT mean

It does not mean security is a technical subject that lawyers may leave alone. Section 43A makes the adequacy of security practices a question a court or an adjudicating officer decides, and rule 8 makes it a question about documentation, audit and standards, which is a lawyer's territory.

It does not mean more security is always better. Section 16 requires the Central Government, when prescribing security procedures, to have regard to the commercial circumstances and the nature of transactions, which is a direction to be proportionate.

munotes.in113

What Information Security Means

It does not mean a certificate is a defence. Rule 8(4) deems compliance where IS/ISO/IEC 27001 or approved codes of best practice have been implemented and certified or audited on a regular basis by an approved independent auditor. A certificate obtained once and never audited does not attract the deeming.

It does not mean information security is the same as cyber security. Section 2(1)(nb)'s definition of cyber security is about protecting information and the equipment holding it; information security is the wider practice and covers paper too, which is why data in section 2(1)(o) includes a printout.

Quick revision

  • Section 2(1)(nb) defines cyber security by six harms: unauthorised access, use, disclosure, disruption, modification or destruction.
  • Three objectives: confidentiality (access, use, disclosure), integrity (modification, destruction), availability (disruption).
  • Two more for transactions: authenticity (it is from whom it says) and non-repudiation (the sender cannot deny it).
  • They pull against one another, and section 16's proviso directs regard to commercial circumstances and the nature of transactions.
  • Four families of control: administrative, technical, operational, physical. Rule 8(1) of the SPDI Rules names all four.
  • Two principles: defence in depth and least privilege.
  • Security is not privacy. Security asks whether the information is protected; privacy asks whether it should have been collected and whether this use is permitted.

Test yourself

1. State the three objectives of information security and give one section of the Act attacking a failure of each. Confidentiality, attacked by section 43(b) on downloading or copying data without permission or by section 72A on disclosure in breach of a lawful contract. Integrity, attacked by section 43(i) on destroying, deleting or altering information or diminishing its value or utility, or by section 65 on altering source code. Availability, attacked by section 43(f) on denying access to an authorised person.

2. Why does the Act's definition of cyber security list six harms rather than stating an objective? Because a definition by harms is capable of being applied to conduct, which is what a penal and regulatory statute needs, whereas an objective would state an aspiration. The six, unauthorised access, use, disclosure, disruption, modification and destruction, map onto the three objectives, with the first three going to confidentiality, disruption to availability, and modification and destruction to integrity.

3. Distinguish security from privacy with an example. A hospital that encrypts every record, restricts access and audits its systems has good security; if it then sells those records to an insurer without consent it has no privacy protection at all. Conversely a clinic that collects only what it needs with proper consent has good privacy practice and none of it survives a breach caused by weak passwords. Section 43A addresses the second; the Digital Personal Data Protection Act addresses the first.

munotes.in114

What Information Security Means

4. What does rule 8(1) of the SPDI Rules require, and what does rule 8(4) deem? Rule 8(1) requires implemented security practices and standards with a comprehensive documented information security programme and policies containing managerial, technical, operational and physical control measures commensurate with the information assets and the nature of the business, and requires the body corporate to demonstrate implementation after a breach. Rule 8(4) deems compliance where IS/ISO/IEC 27001 or approved best-practice codes have been implemented, provided they are certified or audited regularly by an approved independent auditor.

5. Explain defence in depth and least privilege, and say which failed in the clinic example. Defence in depth means using layered controls so that a breach requires several to fail together. Least privilege means giving each person or program only the access the task requires. In the clinic example neither principle was breached in design; an administrative control failed, because a credential was written down, and the layers were defeated by a legitimate login. That illustrates why the standard in section 43A is about the documented programme and its implementation, not about the presence of any one technical measure.

Contents This chapter on its own page

munotes.in115

Chapter Twenty-One

Threats, Attacks and How They Work

Syllabus topic 1.4, "Information Security"

In one line

There are about a dozen ways to attack a computer, each of them is simple once described, and each maps onto a provision of this Act.

In the wording a student can write in an exam: attacks on information systems are conventionally classified by the objective they defeat, so that unauthorised access, malicious software and social engineering attack confidentiality and integrity, while denial of service attacks availability, and Indian law addresses them through section 43 as a civil wrong and sections 65, 66, 66B to 66F and 67 as offences.

Why a lawyer must know how the attacks work

Because the offence is defined by conduct, and you cannot match conduct to a section you do not understand. Section 43(c) covers introducing a computer contaminant or computer virus. Section 43(e) covers disrupting a computer, computer system or computer network. Section 43(f) covers denying access to an authorised person. Whether a set of facts is (c), (e) or (f) is a technical question first.

And because the 2016 paper asked for the nature of cyber crimes and a description of at least three types, with the provisions of the Act, the Penal Code and other laws that address them. That is this chapter and chapter 1090 together.

Malware: software written to do harm

Malware is the general word. The Act uses computer contaminant and computer virus, both defined in the Explanation to section 43, and chapter 1100 quotes those definitions in full.

A virus attaches itself to a file or a program and spreads when that file is run. It needs a human being to open something.

A worm spreads by itself across a network, exploiting a weakness in software rather than waiting for a user. That is why a worm can cross the world in hours.

A trojan pretends to be something useful. The user installs it deliberately, believing it to be a game or a utility, and it does something else as well.

Ransomware encrypts the victim's files and demands payment for the key. It attacks availability rather than confidentiality: the data is still there and the owner cannot reach it. It is the commonest serious attack on Indian organisations today, and it engages section 43(d), (e) and (f) at once, section 66, and, where the target is a protected system or critical infrastructure, section 66F.

Spyware watches: keystrokes, screens, cameras, location. A keylogger records everything typed, which is how banking credentials are most often taken.

A rootkit hides. It modifies the operating system so that the other malware does not appear in any list of running programs, which is why forensic examination works on an image of the disk rather than by asking the running machine what is on it.

munotes.in116

Threats, Attacks and How They Work

A botnet is a network of compromised machines under one controller. The owners do not know. Botnets are rented out, and they are what makes a large denial of service attack possible.

Attacks on people: social engineering

The technical controls are usually sound and the person is not, and most successful attacks begin here.

Phishing is a message that pretends to come from somebody trusted and asks for credentials or a payment. The classic is an email that appears to be from a bank with a link to a page that looks like the bank's. It engages section 66C, identity theft, and section 66D, cheating by personation using a computer resource, and chapter 1210 works those.

Spear phishing is phishing aimed at one person, using facts about them, and it is far more effective. Business email compromise is its commercial form: an email that appears to come from a director instructing a payment, or from a supplier changing its bank details, which is the fact pattern chapter 120 works.

Vishing and smishing are the same attack by voice call and by text message.

Pretexting is inventing a situation that makes the request seem normal, such as calling as the information technology helpdesk and asking a new employee to confirm a password.

None of these is a technical failure, which is why rule 8(1) of the SPDI Rules requires managerial and operational controls and not only technical ones. Chapter 230 works it.

Attacks on the machine

Unauthorised access is using a system you are not permitted to use. It may be by a stolen or guessed credential, by an unpatched weakness in the software, or by a configuration mistake such as a database left open to the internet. Section 43(a) covers accessing or securing access without permission; section 66 makes it an offence if done dishonestly or fraudulently.

Exceeding authorised access is being permitted to use a system and doing more with it than permitted. The employee who is allowed to read one customer's file and reads ten thousand is the paradigm. In India section 43 turns on "without the permission of the owner", which covers it. In the United States the same question produced the litigation chapter 630 works.

A brute force attack tries passwords until one works. A dictionary attack tries likely ones. Credential stuffing tries username and password pairs leaked from some other service, which works because people reuse passwords.

Privilege escalation is turning ordinary access into administrator access, usually by exploiting a defect.

Injection attacks send input that the receiving program treats as an instruction. The best known is SQL injection, where text typed into a form is passed to the database as part of a query, so that typing the right characters into a login box can return the entire customer table. It requires no special access at all and is still among the commonest causes of large breaches.

munotes.in117

Threats, Attacks and How They Work

A man in the middle attack sits between two parties, relaying and possibly altering what each sends while both believe they are talking directly. Encrypted connections and certificate checking exist to defeat it, which is the practical reason the certificate machinery of Module II matters.

Attacks on availability

A denial of service attack sends a machine more requests than it can answer, so that legitimate users cannot get through.

A distributed denial of service attack does the same from thousands of machines at once, usually a botnet, which makes it very hard to block because the traffic looks like ordinary users.

Section 43(f) covers denying or causing the denial of access to any person authorised to access, and section 43(e) covers disrupting a computer, computer system or computer network. Against a protected system or critical infrastructure, section 66F(1)(A) makes denial of access an act of cyber terrorism where the intent or knowledge that section requires is present. Chapter 1320 works it.

Attacks on the supply chain and on infrastructure

A supply chain attack compromises a supplier to reach its customers. Software update mechanisms are the usual route, because an update is trusted by definition.

Domain name system attacks send a user to the wrong machine. In pharming, the translation of a name to an address is corrupted so that a correct address in the browser reaches an attacker's server.

Website defacement replaces the content of a page, which is often political rather than acquisitive and engages section 43(i) and section 66, and section 66F where the target and the intent bring it within cyber terrorism.

The attacks and the provisions, side by side

AttackWhat it defeatsCivilCriminalChapter
Unauthorised accessConfidentialitys.43(a)s.661100, 1180
Downloading or copying dataConfidentialitys.43(b)s.661100, 1180
Virus, worm, ransomware, contaminantIntegrity, availabilitys.43(c)s.661100
Damage to data or the systemIntegritys.43(d), (i)s.661100
Denial of serviceAvailabilitys.43(e), (f)s.66; s.66F where the intent is present1100, 1320
Source code theft or alterationIntegritys.43(j)s.651170
Phishing and identity theftAuthenticitys.43(a), (b)ss.66C, 66D1200, 1210
Receiving a stolen device or resources.66B1200
Spyware capturing private imagesConfidentialitys.66E1210
Attack on critical infrastructureAvailability, integritys.66F1320
Publishing obscene materialss.67, 67A, 67B1220, 1230
Breach by a service providerConfidentialitys.43As.72A1040, 1250

A worked example

A distributor in Kolhapur receives an email that appears to be from its regular supplier in Ludhiana, saying the supplier's bank account has changed. The distributor pays twenty-two lakh rupees to the new account. The money is gone.

munotes.in118

Threats, Attacks and How They Work

Step one: what actually happened? Two possibilities, and they have different legal consequences. Either the supplier's mailbox was compromised and the email really came from it, or the email was spoofed and merely looked as though it did. The headers answer this, and chapter 20 explains why they must be preserved before anything else.

If the mailbox was compromised, there was unauthorised access to the supplier's system under section 43(a), probably by phishing or credential stuffing. The supplier may be exposed under section 43A if it held the distributor's information and was negligent about security, and chapter 230 supplies the standard. The fraudster is caught by sections 66, 66C and 66D.

If the email was spoofed, no computer of the supplier was touched at all. The fraudster is still caught by sections 66C and 66D, because he used another person's unique identification feature and cheated by personation using a computer resource. The supplier is not exposed, and the distributor's own verification process becomes the issue.

In both cases the general penal law applies as well, section 318 of the Bharatiya Nyaya Sanhita on cheating, and chapter 1280 shows how the two statutes work together. The money is traced through the banking system, and the Reserve Bank's directions on unauthorised electronic transactions govern the bank's position.

The point of the example is that the legal analysis did not begin with a section. It began with a technical question about which machine was accessed.

What this does NOT mean

It does not mean every attack is an offence under this Act. Section 66 requires the act to be done dishonestly or fraudulently, so a security researcher who accesses a system to report a weakness commits a contravention under section 43 and may not commit the section 66 offence at all. Chapter 1180 works the mental element.

It does not mean the classification decides the section. The names in this chapter are technical usage, not statutory categories. The Act's categories are the ten clauses of section 43 and the offences in Chapter XI, and an answer should reason from those.

It does not mean the attacker is always outside the organisation. Most serious losses involve a person who was given access, which is why least privilege matters and why section 43's test is the owner's permission rather than physical intrusion.

Quick revision

  • Malware: virus (needs a user), worm (spreads itself), trojan (pretends to be useful), ransomware (encrypts and demands payment, attacking availability), spyware and keyloggers, rootkits (hide), botnets (rented networks of compromised machines).
  • Social engineering: phishing, spear phishing and business email compromise, vishing, smishing, pretexting. Most successful attacks begin here, and the failure is administrative rather than technical.
  • On the machine: unauthorised access, exceeding authorised access, brute force, dictionary and credential stuffing, privilege escalation, injection including SQL injection, man in the middle.
  • On availability: denial of service and distributed denial of service.
  • Elsewhere: supply chain attacks, DNS attacks and pharming, defacement.
  • The Act's own words are computer contaminant and computer virus, defined in the Explanation to section 43.
  • Section 66 needs the act to be dishonest or fraudulent; section 43 does not.
munotes.in119

Threats, Attacks and How They Work

Test yourself

1. Distinguish a virus, a worm and a trojan. A virus attaches to a file or program and spreads when that file is executed, so it needs a human act. A worm spreads by itself across a network by exploiting a defect, which is why it propagates so fast. A trojan is installed deliberately by the user because it appears to be something useful, and performs a hidden function as well.

2. Which clauses of section 43 does a ransomware attack engage, and why more than one? Clause (c) if a computer contaminant or virus was introduced; clause (d) for damage to data; clause (e) for disruption of the computer, computer system or computer network; and clause (f) for denial of access to authorised persons. More than one because the single attack simultaneously introduces malicious code, alters the data by encrypting it, disrupts the system's working, and locks out the people entitled to use it.

3. What is SQL injection and why is it a lawyer's concern? Input typed into an ordinary form is passed to the database as part of a query, so that carefully chosen characters cause the database to return or alter data the user was never entitled to. It is a lawyer's concern because it requires no credential and no privileged access, so a breach caused by it is almost always attributable to the defendant's own failure to validate input, which goes directly to the negligence question under section 43A and rule 8.

4. A security researcher accesses a company's server without permission, takes nothing, and reports the weakness. What is the position? He has secured access to a computer resource without the permission of the owner, so section 43(a) is engaged and a contravention has occurred, for which compensation may be claimed if damage is shown. Section 66 requires the act to be done dishonestly or fraudulently, and on those facts neither mental element is present, so the offence is not made out.

5. Why does the analysis of a business email compromise begin with the email headers? Because the legal consequences differ according to whether the supplier's mailbox was actually accessed or the message was merely spoofed. In the first case there was unauthorised access to the supplier's system and the supplier's own security may be in issue under section 43A; in the second no computer of the supplier was touched and only the fraudster is liable. Only the headers, and the mail server logs, distinguish the two, and both are volatile.

Contents This chapter on its own page

munotes.in120

Chapter Twenty-Two

Secure Electronic Records and Secure Signatures

Syllabus topic 1.4, "Information Security"

In one line

Chapter V is three short sections that create a higher class of electronic record and of electronic signature, and it matters because being in that class changes what a court presumes.

In the wording a student can write in an exam: sections 14, 15 and 16 of the Information Technology Act, 2000 provide that an electronic record to which a prescribed security procedure has been applied is deemed to be a secure electronic record from that point to the time of verification, that an electronic signature is deemed to be secure if the signature creation data was under the exclusive control of the signatory and was stored and affixed in the prescribed exclusive manner, and that the Central Government may prescribe security procedures and practices having regard to the commercial circumstances and the nature of transactions.

Why the Act needed a second, higher class

Sections 4 and 5 make an electronic record and an electronic signature good enough. They satisfy the requirements of writing and of signature. Chapter 300 works them.

Chapter V asks a different question: how good? Not every electronic record deserves the same trust. A record produced by a system with proper controls, and a signature whose key was genuinely under one person's control, are more reliable than the same things produced carelessly. Chapter V gives the reliable ones a name.

And the name has a consequence, though not in this Act. It is in the law of evidence: the Bharatiya Sakshya Adhiniyam, like the Indian Evidence Act before it, presumes more in favour of a secure electronic record and a secure electronic signature than of an ordinary one. Chapter 1270 works the presumptions.

So Chapter V is a definition chapter whose payoff lies elsewhere, which is why it is short and why students skip it.

Section 14: secure electronic record

"Where any security procedure has been applied to an electronic record at a specific point of time, then such record shall be deemed to be a secure electronic record from such point of time to the time of verification."

Four things follow from that sentence.

The status is conferred by applying a security procedure, and nothing else. Section 2(1)(zf) defines "security procedure" as the security procedure prescribed under section 16 by the Central Government. So the class is defined by delegated legislation.

It attaches at a specific point of time, and the record is secure from that moment.

It runs to the time of verification. The status is not permanent; it covers the interval between securing and checking. That is the drafting device that ties the section to the way integrity is actually tested: you secure a record, and later you verify that it has not changed since.

munotes.in121

Secure Electronic Records and Secure Signatures

It is a deeming provision. Once the procedure has been applied, the record shall be deemed secure. There is no discretion.

Section 15: secure electronic signature

The section as it now stands was substituted by the 2008 amendment, and the original spoke of a secure digital signature and required verification through the prescribed security procedure. The substituted section reads:

"An electronic signature shall be deemed to be a secure electronic signature if (i) the signature creation data, at the time of affixing signature, was under the exclusive control of signatory and no other person; and (ii) the signature creation data was stored and affixed in such exclusive manner as may be prescribed. Explanation: In case of digital signature, the 'signature creation data' means the private key of the subscriber."

Two conditions, and both must be satisfied.

Exclusive control at the moment of signing. Not before, not afterwards: at the time of affixing. That is the same idea as article 6(3)(b) of the UNCITRAL Model Law on Electronic Signatures, which chapter 100 works, and it is what makes non-repudiation possible. If two people could have made the signature, the signer can deny it.

Storage and affixing in the prescribed exclusive manner. This is where the technical requirements live: in practice, that the private key is held in a device from which it cannot be extracted, and that the signing operation happens inside that device.

The Explanation is the bridge to the older vocabulary. For a digital signature, the signature creation data is the private key of the subscriber, which section 2(1)(zc) defines. For a technique that is not a digital signature, the signature creation data is whatever plays the same part.

Notice how the section changed in 2008 and why. The original was written for one technology and required verification by a security procedure. The substituted section states the two functional conditions, which is the technology-neutral approach the 2001 Model Law asks for, and leaves the technique to what is prescribed.

Section 16: the power to prescribe

"The Central Government may, for the purposes of sections 14 and 15, prescribe the security procedures and practices: Provided that in prescribing such security procedures and practices, the Central Government shall have regard to the commercial circumstances, nature of transactions and such other related factors as it may consider appropriate."

Section 16 was also substituted in 2008. The original listed the factors the Government was to consider: the nature of the transaction, the level of sophistication of the parties, the volume of similar transactions, the availability of alternatives, the cost of alternatives, and the procedures in general use for similar transactions. The substituted section compresses those into "the commercial circumstances, nature of transactions and such other related factors".

munotes.in122

Secure Electronic Records and Secure Signatures

The proviso is a direction to be proportionate, and it is the Act's own acknowledgement that security is a trade-off rather than a maximum. Chapter 200 makes the same point.

What has been prescribed? The Information Technology (Security Procedure) Rules, 2004, made under section 16, provide that a secure digital signature is one created by applying the standards in the Second Schedule and stored in a manner that ensures exclusive control. In practice the operative requirements now sit in the Certifying Authorities Rules 2000 and in the Second Schedule, and chapter 460 works them.

Secure and ordinary, side by side

Ordinary electronic record or signatureSecure electronic record or signature
Created byAny electronic form; any prescribed electronic signature techniqueApplying a prescribed security procedure (s.14); exclusive control plus prescribed storage and affixing (s.15)
Satisfies a legal requirement of writing or signature?Yes, under ss.4 and 5Yes
Duration of the statusNot applicableFrom the point of application to the time of verification
ConsequenceThe requirement is metThe evidentiary presumptions attach
Where the consequence is foundThis ActThe law of evidence, not this Act

That last row is the whole point of the chapter. Sections 14 to 16 say what secure means and confer no advantage of their own. The advantage is that a court presumes things about a secure record and signature that it does not presume about an ordinary one, and chapter 1270 sets out the presumptions in the Bharatiya Sakshya Adhiniyam.

A worked example

Two companies each execute an agreement electronically.

Company A's finance officer holds her private key on a USB cryptographic token issued by a licensed Certifying Authority. The key was generated inside the token, cannot be exported from it, and the signing happens inside the token when she enters a PIN. Section 15(i) is satisfied because the signature creation data was under her exclusive control when she signed; section 15(ii) is satisfied because it was stored and affixed in the prescribed exclusive manner. Her signature is a secure electronic signature.

Company B's finance officer has a signing certificate installed as a file on the office desktop, with the password saved. Three colleagues use that machine. The key is on the disk and could be copied. Section 15(i) is not satisfied: the signature creation data was not under her exclusive control and no other person's. Her signature may still be a valid electronic signature satisfying section 5, if the technique is one specified in the Second Schedule, but it is not secure.

The difference appears when the agreement is disputed. Company A's officer, denying that she signed, faces the presumption the law of evidence attaches to a secure electronic signature. Company B's officer denying it faces no such presumption, and Company B must prove the signature affirmatively, most likely by evidence about the machine, the logs and who had access.

munotes.in123

Secure Electronic Records and Secure Signatures

Neither signature is invalid. The difference is entirely about who has to prove what, which is exactly the sort of difference that decides litigation.

What this does NOT mean

It does not mean an insecure electronic record is inadmissible. Admissibility is governed by the law of evidence, and chapter 1270 works it. Chapter V affects presumptions, not admission.

It does not mean a secure electronic signature cannot be challenged. A presumption may be rebutted. It shifts the burden; it does not close the question.

It does not mean section 14 and section 15 work the same way. Section 14 confers the status by the application of a prescribed security procedure. Section 15 confers it by satisfying two stated conditions, one of which is factual (exclusive control) and one of which refers to what is prescribed. So a record is secure because a procedure was applied; a signature is secure because of a fact about the key plus compliance with what is prescribed.

It does not mean the pre-2009 sections say the same thing. The original section 15 was about a secure digital signature and required verification through a security procedure, and the original section 16 listed six factors. A textbook printed before 27 October 2009 prints both.

Quick revision

  • Section 14: a prescribed security procedure applied to an electronic record at a specific time makes it a secure electronic record from that time to the time of verification. A deeming provision.
  • Section 15, substituted 2008: an electronic signature is deemed secure if (i) the signature creation data was under the exclusive control of the signatory and no other person at the time of affixing, and (ii) it was stored and affixed in the prescribed exclusive manner. The Explanation says that for a digital signature the signature creation data is the private key.
  • Section 16, substituted 2008: the Central Government may prescribe, having regard to the commercial circumstances, the nature of transactions and other related factors. A direction to be proportionate.
  • Section 2(1)(zf) defines security procedure by reference to what is prescribed under section 16.
  • The payoff is in the law of evidence, not in this Act: the presumptions attaching to a secure record and a secure signature.

Test yourself

1. State the two conditions in section 15 and explain why the first is expressed as at the time of affixing. The signature creation data must have been under the exclusive control of the signatory and no other person at the time of affixing the signature, and it must have been stored and affixed in such exclusive manner as may be prescribed. The first is fixed to the moment of signing because that is the only moment at which sole control matters: what happened to the key before or afterwards does not bear on whether this signature could have been made by anyone else.

munotes.in124

Secure Electronic Records and Secure Signatures

2. What does section 14 confer, and for how long? It deems an electronic record to be a secure electronic record from the specific point of time at which a prescribed security procedure was applied to it until the time of verification. The status is therefore an interval and not a permanent attribute, which matches the way integrity is tested: secured at one moment, checked at another.

3. Where is the advantage of being secure actually found? Not in this Act. Chapter V defines the class; the consequence is in the law of evidence, where the presumptions available in respect of a secure electronic record and a secure electronic signature are stronger than those available for ordinary ones. Sections 14 to 16 give no substantive right of their own.

4. Why was section 15 substituted in 2008? Because the original spoke of a secure digital signature and tied the status to verification through a prescribed security procedure, which is technology specific. The substituted section states two functional conditions, exclusive control and prescribed storage and affixing, and leaves the technique to the Second Schedule, which is the technology-neutral method the UNCITRAL Model Law on Electronic Signatures of 2001 asks for.

5. Is a signature that fails section 15 invalid? No. Section 5 asks only whether the record was authenticated by an electronic signature affixed in the prescribed manner, and a signature may satisfy that and still fail section 15 because the key was not under exclusive control. Failing section 15 costs the presumptions; it does not cost validity.

Contents This chapter on its own page

munotes.in125

Chapter Twenty-Three

Reasonable Security Practices and the SPDI Rules

Syllabus topic 1.4, "Information Security"

In one line

Eight rules made in 2011 are still India's operative data protection law, and they say what a company must do with your sensitive personal information and what counts as protecting it properly.

In the wording a student can write in an exam: the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, made under clause (ob) of section 87(2) read with section 43A of the Information Technology Act, 2000, define sensitive personal data or information, require a body corporate handling it to publish a privacy policy, to obtain written consent for a lawful and necessary purpose, to limit retention and use, to permit review and correction, to allow withdrawal of consent, to restrict disclosure and transfer, and to implement documented reasonable security practices of which IS/ISO/IEC 27001 is one recognised standard.

Why these rules still matter

Because section 43A is still in force. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 provides for the omission of section 43A, and notification G.S.R. 843(E) of 13 November 2025 placed section 44(2) in the eighteen-month stage, so it commences on 13 May 2027. Until then section 43A stands and so do these Rules. Chapter 190 sets out the staging.

And because they supply the standard by which section 43A is judged. Section 43A makes a body corporate liable to pay damages by way of compensation where it is negligent in implementing and maintaining reasonable security practices and procedures while possessing, dealing or handling sensitive personal data or information. The Explanation to the section leaves both expressions to be prescribed, and these Rules are what was prescribed. Chapter 1040 works the section.

Rule 1: the instrument and its date

Rule 1 names the Rules and commences them. They are the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, notified as G.S.R. 313(E) on 11 April 2011 under clause (ob) of section 87(2) read with section 43A, and they came into force on the date of their publication in the Official Gazette.

The parent power is worth a sentence of its own. Clause (ob) was inserted by the amendment of 2008 along with section 43A itself, so the Rules are not a general privacy code made under a general power. They exist only to fill the two expressions section 43A left blank, and nothing in them can travel beyond that section.

Three sets were notified on the same day, G.S.R. 313(E) here, G.S.R. 315(E) for cyber cafes and G.S.R. 316(E) for electronic service delivery, with the now superseded intermediaries guidelines as G.S.R. 314(E). Chapters 1430 and 370 take the other two.

munotes.in126

Reasonable Security Practices and the SPDI Rules

Rule 2: the definitions that decide who is covered

Rule 2(1)(c): "body corporate" means the body corporate as defined in clause (i) of the Explanation to section 43A, which is any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities.

That excludes the Government. A Government department is not a body corporate engaged in commercial or professional activities, so section 43A and these Rules do not reach it, which was the largest single gap in Indian data protection law before the DPDP Act.

Rule 2(1)(i): "personal information" means any information that relates to a natural person which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person.

The words "in combination with other information available or likely to be available" are wider than students expect. Information that identifies nobody on its own is personal information if the holder has, or is likely to have, the other pieces.

Rule 2(1)(b) defines biometrics as technologies measuring and analysing human body characteristics, naming fingerprints, eye retinas and irises, voice patterns, facial patterns, hand measurements and DNA, for authentication purposes.

Rule 2(1)(d) defines cyber incidents, and rule 2(1)(h) defines password to include an encryption or decryption key.

Rule 3: sensitive personal data or information

The list is closed and it is short. Sensitive personal data or information means personal information consisting of information relating to:

(i) password; (ii) financial information such as bank account or credit card or debit card or other payment instrument details; (iii) physical, physiological and mental health condition; (iv) sexual orientation; (v) medical records and history; (vi) biometric information; (vii) any detail relating to the above clauses as provided to a body corporate for providing service; and (viii) any of the information received under the above clauses by a body corporate for processing, stored or processed under lawful contract or otherwise.

The proviso is important and often forgotten. Any information that is freely available or accessible in the public domain, or furnished under the Right to Information Act, 2005 or any other law for the time being in force, is not sensitive personal data or information for the purposes of these Rules.

What is not on the list is as instructive as what is. A name, an address, a telephone number, an email address, an identity number, caste, religion, political opinion and criminal record are all personal information and none of them is sensitive under rule 3. So the strict obligations in rules 5 and 6 do not attach to them.

Compare the Digital Personal Data Protection Act 2023, which abandons the sensitive category altogether and applies one set of obligations to all digital personal data. Chapter 1050 works it, and the comparison is a good examination point.

munotes.in127

Reasonable Security Practices and the SPDI Rules

Rule 4: the privacy policy

Rule 4(1) requires the body corporate, or any person collecting on its behalf, to provide a privacy policy for handling of or dealing in personal information including sensitive personal data or information, and to ensure that it is available for view by those who have provided information under a lawful contract.

The policy must be published on the website, and rule 4(2) requires it to provide for: clear and easily accessible statements of its practices and policies; the type of personal or sensitive personal data or information collected; the purpose of collection and usage; disclosure of information including sensitive personal data or information as provided in rule 6; and the reasonable security practices and procedures as provided under rule 8.

Rule 5: collection

This is the longest rule and it contains nine obligations.

Rule 5(1): consent in writing. The body corporate shall obtain consent in writing through letter or fax or email from the provider of the sensitive personal data or information regarding the purpose of usage before collection.

Rule 5(2): lawful purpose and necessity. It shall not collect sensitive personal data or information unless the information is collected for a lawful purpose connected with a function or activity of the body corporate, and the collection is considered necessary for that purpose. Two conditions, both required.

Rule 5(3): notice at collection. While collecting directly from the person, it shall take reasonable steps to ensure the person knows the fact that the information is being collected, the purpose, the intended recipients, and the name and address of the agency collecting it and the agency that will retain it.

Rule 5(4): retention limit. It shall not retain the information for longer than is required for the purposes for which it may lawfully be used or is otherwise required under any other law.

Rule 5(5): purpose limitation. The information shall be used for the purpose for which it has been collected.

Rule 5(6): review and correction. It shall permit the providers, as and when requested, to review the information they provided, and shall ensure that anything found inaccurate or deficient is corrected or amended as feasible. The proviso relieves the body corporate of responsibility for the authenticity of what the provider supplied.

Rule 5(7): the option not to give, and withdrawal. Prior to collection it shall provide an option to the provider not to provide the data sought. The provider shall also have an option, at any time, to withdraw consent given earlier, in writing. Where the provider does not give or later withdraws consent, the body corporate shall have the option not to provide goods or services for which the information was sought.

munotes.in128

Reasonable Security Practices and the SPDI Rules

Rule 5(8): it shall keep the information secure as provided in rule 8.

Rule 5(9): the Grievance Officer. It shall address any discrepancies and grievances of the provider in a time bound manner, and for that purpose shall designate a Grievance Officer and publish his name and contact details on its website. The Grievance Officer shall redress grievances expeditiously but within one month from receipt.

Rule 6: disclosure

Rule 6(1): disclosure to a third party requires prior permission from the provider, unless the disclosure has been agreed to in the contract between them, or the disclosure is necessary for compliance of a legal obligation.

The proviso is the Government exception. Information shall be shared without obtaining prior consent with Government agencies mandated under the law to obtain it for the purpose of verification of identity, or for prevention, detection, investigation including cyber incidents, prosecution, and punishment of offences. The agency shall send a request in writing stating clearly the purpose, and shall also state that the information obtained shall not be published or shared with any other person.

Rule 6(2): notwithstanding sub-rule (1), sensitive personal data or information shall be disclosed to any third party by an order under the law for the time being in force.

Rule 6(3): the body corporate shall not publish the sensitive personal data or information.

Rule 6(4): the third party receiving it shall not disclose it further.

Rule 7: transfer, including outside India

A body corporate may transfer sensitive personal data or information, including any information, to any other body corporate or person in India or located in any other country, that ensures the same level of data protection that is adhered to by the body corporate as provided under these Rules.

The transfer may be allowed only if it is necessary for the performance of the lawful contract between the body corporate and the provider, or where the provider has consented to the transfer.

Two conditions, and both must be met: an equivalent level of protection at the destination, and either necessity for the contract or consent. There is no adequacy list and no approval requirement, which makes rule 7 far lighter than Chapter V of the European General Data Protection Regulation, and chapter 690 draws the comparison.

Rule 8: reasonable security practices

Rule 8(1) states the standard. A body corporate is considered to have complied if it has implemented security practices and standards and has a comprehensive documented information security programme and information security policies containing managerial, technical, operational and physical security control measures commensurate with the information assets being protected with the nature of business. In the event of a breach, it shall be required to demonstrate, as and when called upon by the agency mandated under the law, that it has implemented security control measures as per its documented programme and policies.

munotes.in129

Reasonable Security Practices and the SPDI Rules

Rule 8(2) names a standard: IS/ISO/IEC 27001 on Information Technology, Security Techniques, Information Security Management System, Requirements, is one such standard. It is not the only one, and it is not mandatory.

Rule 8(3) allows an industry association whose members follow other codes of best practice to have those codes approved and notified by the Central Government.

Rule 8(4) is the deeming provision, and it has a condition. A body corporate which has implemented either IS/ISO/IEC 27001 or approved codes shall be deemed to have complied, provided that such standard or codes have been certified or audited on a regular basis by entities through independent auditor duly approved by the Central Government. The audit is to be carried out at least once a year or when the body corporate undertakes a significant upgradation of its process and computer resource.

So a certificate obtained once and never audited does not attract the deeming, and that is the most commonly missed point in the whole of these Rules.

The obligations at a glance

RuleObligationThe trap
4Publish a privacy policy covering practices, types collected, purpose, disclosure and securityMust be available for view by the provider, not merely on file
5(1)Written consent by letter, fax or email, before collectionOral or implied consent is not enough for sensitive data
5(2)Lawful purpose and necessityTwo conditions, not one
5(3)Notice of the fact, purpose, recipients, and the collecting and retaining agenciesThe two agencies must be named separately
5(4), 5(5)Retention limit and purpose limitation
5(6)Review and correction on requestThe body corporate is not responsible for the authenticity of what was supplied
5(7)Option not to provide, and to withdrawOn withdrawal the body corporate may refuse the service
5(9)Grievance Officer named on the website, redress within one monthA named individual, not an address
6Disclosure needs prior permission; the Government exception; no publication; no onward disclosureThe Government must request in writing and must state that it will not publish or share
7Transfer needs equivalent protection and either necessity or consentApplies to transfers within India as well
8Documented programme with four families of control; demonstrate on demandThe deeming in 8(4) needs a regular independent audit

A worked example

Sahyadri Wellness runs a chain of diagnostic clinics and a mobile application.

munotes.in130

Reasonable Security Practices and the SPDI Rules

What it holds. Names, addresses and phone numbers, which are personal information but not sensitive under rule 3. Medical records and test results, which are sensitive under rule 3(iii) and (v). Payment card details, sensitive under rule 3(ii). Fingerprints used to log staff in, sensitive under rule 3(vi).

What rule 5 requires for the sensitive items. Written consent by letter, fax or email before collection, stating the purpose of usage. A lawful purpose connected with its activity, which diagnosis plainly is, and necessity, which is where collecting a patient's sexual orientation for a routine blood test would fail. Notice at collection naming Sahyadri as collector and its cloud provider as the agency that will retain the data. Retention no longer than required. Use only for the stated purpose, so using the records to market a health insurance product is a breach of rule 5(5) unless that purpose was stated and consented to.

A patient asks to see and correct her record. Rule 5(6) requires Sahyadri to permit review and to correct what is inaccurate as feasible.

A patient withdraws consent. Rule 5(7) allows her to do so in writing, and allows Sahyadri to decline to provide the service for which the information was sought.

The police ask for a patient's records. Rule 6's proviso allows disclosure without consent to a Government agency mandated under the law, for one of the listed purposes, on a written request stating the purpose and stating that the information will not be published or shared. A telephone request does not satisfy it.

Sahyadri wants to move its records to a cloud provider in Singapore. Rule 7 permits it if the provider ensures the same level of protection as these Rules require and the transfer is necessary for the performance of the contract with the patient or the patient has consented.

Then the breach. Fourteen thousand records are taken. Section 43A asks whether Sahyadri was negligent in implementing and maintaining reasonable security practices, and rule 8(1) makes that a question about its documented programme and whether it can demonstrate implementation. If it holds a current IS/ISO/IEC 27001 certification that has been audited annually by an approved independent auditor, rule 8(4) deems compliance. If the certification lapsed two years ago, it does not.

What this does NOT mean

It does not mean these Rules apply to the Government. They apply to a body corporate as defined in section 43A, which is an entity engaged in commercial or professional activities.

It does not mean all personal information is protected by rules 5 and 6. Those rules operate on sensitive personal data or information as rule 3 defines it. A name and address are personal information and are not sensitive.

munotes.in131

Reasonable Security Practices and the SPDI Rules

It does not mean an ISO certificate is a complete answer. Rule 8(4) deems compliance only where the standard has been certified or audited regularly by an approved independent auditor.

It does not mean these Rules survive 2027. They are made under section 43A, and when section 44(2) of the DPDP Act commences on 13 May 2027 the parent provision goes. What happens to rules made under a repealed section is a question section 6 of the General Clauses Act, 1897 will have to answer.

Quick revision

  • G.S.R. 313(E), 11 April 2011, made under section 87(2)(ob) read with section 43A. Eight rules. Still in force.
  • Body corporate excludes the Government. Personal information, rule 2(1)(i), includes information identifying a person in combination with other information the body corporate has or is likely to have.
  • Rule 3, sensitive: password; financial information; physical, physiological and mental health condition; sexual orientation; medical records and history; biometrics; details of the above given for a service; and such information received for processing. Proviso: not information freely available in the public domain or furnished under the RTI Act or any other law.
  • Rule 4: privacy policy, published, covering practices, types, purpose, disclosure and security.
  • Rule 5: written consent before collection; lawful purpose and necessity; notice of fact, purpose, recipients and both agencies; retention limit; purpose limitation; review and correction; option not to give and to withdraw, with the right to refuse service; Grievance Officer named on the website, redress within one month.
  • Rule 6: disclosure needs prior permission unless contracted for or legally obliged; Government exception on a written request stating the purpose and a no-publication undertaking; no publication; no onward disclosure.
  • Rule 7: transfer, in India or abroad, needs equivalent protection plus necessity or consent.
  • Rule 8: documented programme with managerial, technical, operational and physical controls, demonstrable on demand; IS/ISO/IEC 27001 is one standard; the deeming in 8(4) requires a regular audit by an approved independent auditor.

Test yourself

1. List the categories of sensitive personal data or information and state the proviso. Password; financial information such as bank account, credit card, debit card or other payment instrument details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; any detail relating to those clauses provided to a body corporate for providing a service; and any such information received by a body corporate for processing, stored or processed under lawful contract or otherwise. The proviso excludes information freely available or accessible in the public domain, or furnished under the Right to Information Act, 2005 or any other law in force.

2. What form must consent take under rule 5(1), and what may the body corporate do if consent is withdrawn? Consent must be in writing through letter, fax or email, obtained from the provider regarding the purpose of usage, before collection. Under rule 5(7) the provider may withdraw consent at any time in writing, and the body corporate then has the option not to provide the goods or services for which the information was sought.

munotes.in132

Reasonable Security Practices and the SPDI Rules

3. On what conditions may a Government agency obtain sensitive personal data without the provider's consent? Under the proviso to rule 6(1) the agency must be mandated under the law to obtain such information, the purpose must be verification of identity or prevention, detection, investigation including cyber incidents, prosecution or punishment of offences, the agency must send a request in writing stating clearly the purpose, and it must also state that the information obtained shall not be published or shared with any other person.

4. When is a body corporate deemed to have complied with reasonable security practices? Under rule 8(4), where it has implemented IS/ISO/IEC 27001 or codes of best practice approved and notified under rule 8(3), provided that the standard or codes have been certified or audited on a regular basis by entities through an independent auditor duly approved by the Central Government. Without that regular independent audit the deeming does not operate and the body corporate must satisfy rule 8(1) on its own terms.

5. Are these Rules still in force, and why is that surprising? Yes. It is surprising because section 44(2)(a) of the Digital Personal Data Protection Act, 2023 provides for the omission of section 43A, the parent provision, and most commentary written since 2023 states that section 43A has gone. Notification G.S.R. 843(E) dated 13 November 2025 placed section 44(2) in the eighteen-month stage, so it comes into force on 13 May 2027, and until then both section 43A and these Rules apply.

Contents This chapter on its own page

munotes.in133

Chapter Twenty-Four

Using the Act in Practice

Syllabus topic 1.5, "5. Application"

In one line

Four questions, asked in order, will get you from a set of facts to the right provision of this Act every time.

In the wording a student can write in an exam: the application of the Information Technology Act, 2000 to any dispute is determined by asking, in order, whether the Act applies at all having regard to section 1(4) and the First Schedule and to sections 1(2) and 75; what the electronic record is and whose it is under sections 2, 11 and 13; whether the transaction satisfies the requirements of writing, signature, retention and evidence under sections 4, 5, 7 and the law of evidence; and what remedy the facts disclose under Chapter IX, Chapter XI and the rules made under section 87.

Why a method is worth a chapter

Because a statute of thirteen chapters and a dozen sets of rules cannot be searched by memory. A reader who knows the Act well still needs a route through it, and a reader meeting it for the first time needs one badly.

And because examination problems in this subject are always the same shape. A set of facts, several parties, and an instruction to advise. The marks are in identifying which provisions are engaged, in the right order, and in noticing the ones a hurried answer misses.

Question one: does the Act apply at all?

Three sub-questions, and each can end the inquiry.

Is the document or transaction in the First Schedule? A negotiable instrument other than the three kinds carved out in 2022; a power of attorney other than the kind carved out in 2022; a trust; a will. If it is, nothing in the Act applies to it. Chapter 140 works the Schedule, including the entry that was removed.

If the conduct was outside India, is section 75(2) satisfied? The Act reaches an offence or contravention committed abroad by any person only if the act or conduct involves a computer, computer system or computer network located in India. Chapters 130 and 850.

Is there an electronic record at all? The Act operates on electronic records, data, information and computer resources as section 2 defines them. A dispute about a paper document with no electronic element is outside it, although chapter 150 shows that a computer printout is still data.

Question two: what is the record, and whose is it?

Identify the record. Which electronic record is in issue: the order, the confirmation, the log, the photograph, the source code? The Act's provisions attach to particular records, and the intermediary definition in section 2(1)(w) operates "with respect to any particular electronic records", so the answer changes with the record.

Identify the originator and the addressee. Sections 2(1)(za) and 2(1)(b), and neither includes an intermediary. Chapter 160.

munotes.in134

Using the Act in Practice

Ask whether the record is attributed to the person said to have sent it. Section 11: sent by him, by a person authorised, or by an automated system he programmed. If none of the three, the Act does not attribute it, and chapter 940 shows what the Act then does not say.

Ask when and where it was despatched and received. Section 13, and chapter 870. This decides the place of the transaction and often the forum.

Ask who the intermediaries are, record by record. Chapter 160 works the definition; chapter 1360 works what follows.

Question three: does the transaction hold up?

Writing. Section 4. Is the information rendered or made available in electronic form and accessible so as to be usable for a subsequent reference? Chapter 300.

Signature. Section 5, with sections 3 and 3A. Was it authenticated by an electronic signature affixed in the prescribed manner? Remember that section 5 bites only where a law requires a signature. Chapters 280, 290 and 300.

Contract. Section 10A, which since 2009 puts the validity of an electronic contract beyond argument. Chapter 930.

Retention. Section 7, and its three conditions including the metadata condition. Chapter 360.

Security. Sections 14 and 15: is the record or the signature secure? That decides the presumptions rather than the validity. Chapter 220.

Proof. Section 63 of the Bharatiya Sakshya Adhiniyam and its certificate. Chapter 1270.

Question four: what remedy do the facts disclose?

Take the civil side first, because it is the one clients usually want.

Section 43 for damage to a computer, computer system, computer network, data or source code: ten clauses, compensation at large. Section 43A where a body corporate was negligent in protecting sensitive personal data. Section 46: the adjudicating officer decides claims up to five crore rupees, the competent court above that. Chapters 1100, 1040 and 1120.

Then the criminal side. Chapter XI, sections 65 to 78, and the mapping table in chapter 210 is the quickest route from conduct to section. Remember section 66 needs dishonestly or fraudulently, and remember that the general penal law applies alongside, with section 81 and Sharat Babu Digumarti deciding which prevails. Chapters 1180 and 1280.

Then the regulatory side, which is where most practical answers now lie. Is there an intermediary who can be required to take the material down, under rule 3 of the IT Rules 2021? Is a blocking direction under section 69A appropriate? Is there a reporting obligation to CERT-In within six hours? Chapters 1360, 810 and 770.

And always ask what the rules add. Chapter 120 lists the twelve sets of rules and which section each is made under. A question about intermediaries answered only from section 79 loses most of the marks.

munotes.in135

Using the Act in Practice

The route in one table

StepAskSectionsChapter
1Is it in the First Schedule?1(4), Sch. I140
2If abroad, is a machine in India involved?1(2), 75130, 850
3What is the electronic record?2(1)(t)150
4Who is the originator, the addressee, the intermediary?2(1)(za), (b), (w)160
5Is the record attributed?11940
6When and where despatched and received?13870
7Writing? Signature? Contract?4, 5, 10A300, 930
8Retention, and its metadata condition?7360
9Secure record, secure signature?14, 15220
10How is it proved?BSA 2023, ss.61, 631270
11Civil claim? Who decides it?43, 43A, 461100, 1040, 1120
12Offence? Which, and with what mental element?65 to 741170 to 1250
13Intermediary takedown? Blocking? Reporting?79 and the 2021 Rules; 69A; 70B1360, 810, 760
14Which other statute applies alongside?811280

A worked example, taking the route in order

Facts. Anaya, in Mumbai, sells handmade jewellery through her own website hosted on a service whose servers are in Ireland. A buyer in Chennai places an order by filling a form and clicking "I agree" to the terms. Anaya ships. The buyer then complains that a photograph of her, taken from her social media account, has been used on Anaya's site without permission, and that her card details, stored by Anaya, have appeared on a fraud forum. Anaya says the order was never placed by that buyer at all.

Step 1. Nothing in the First Schedule. The Act applies.

Step 2. The conduct is in India; the server is not, which does not matter, because the parties and the machines they used are here and section 75 is engaged only for conduct outside India.

Steps 3 and 4. The records in issue are the order, the terms accepted by the click, the photograph on the site, and the stored card details. Anaya is the originator of the terms and of the photograph. The buyer is the originator of the order. The hosting service is an intermediary as to the records it stores, and Anaya is not an intermediary as to her own product photographs.

Step 5. Anaya disputes the order. Section 11 attributes it to the buyer only if she sent it, authorised somebody, or ran an automated system. If a third party used her card details to place it, section 11 does not attribute it and chapter 940 shows that the Act gives Anaya nothing further.

Steps 6 and 7. Section 13 places despatch and receipt at the parties' places of business, Mumbai and Chennai. Section 10A makes the click-wrap contract valid; whether its terms were properly incorporated is a contract question, and chapter 960 works it.

munotes.in136

Using the Act in Practice

Steps 8 to 10. Anaya's records of the order and the logs are what will prove it, subject to the certificate under section 63 of the Bharatiya Sakshya Adhiniyam.

Step 11. The buyer's card details are sensitive personal data or information under rule 3(ii) of the SPDI Rules. If Anaya was negligent in implementing reasonable security practices under rule 8, section 43A gives the buyer compensation, and section 46 sends the claim to the adjudicating officer.

Step 12. Whoever took the card details is caught by sections 43(b) and 66, and by section 66C if they used the buyer's identifying feature. Using the buyer's photograph without consent may engage section 66E if it was taken in circumstances giving rise to a reasonable expectation of privacy, and chapter 1210 works the elements.

Step 13. The buyer can require the hosting service to take the photograph down under rule 3(2)(b) of the IT Rules 2021 if it is a morphed or intimate image, or on a court order under section 79(3)(b) otherwise. Chapter 1360.

Step 14. The photograph is also a copyright question if the buyer took it herself, and section 81's proviso preserves the Copyright Act. Chapter 1280.

Fourteen steps, and not one of them required a memory of a section number, because each step names the question and the chapter that answers it.

What this does NOT mean

It does not mean the order is rigid. A criminal problem starts at step 12 and works backwards. A contract problem may stop at step 7.

It does not mean the Act is the only statute in play. Almost every real problem in this subject also involves the Bharatiya Nyaya Sanhita, the Bharatiya Sakshya Adhiniyam, the Contract Act, the Consumer Protection Act, the Copyright Act or the DPDP Act. Step 14 exists to make sure the question is asked.

It does not mean an answer should recite the route. The route is how you find the provisions. What goes on the paper is the provisions and what they do.

Quick revision

  • Four questions, in order: does the Act apply; what is the record and whose is it; does the transaction hold up; what remedy do the facts disclose.
  • Question one is section 1(4) and the First Schedule, then sections 1(2) and 75 for anything done abroad.
  • Question two is sections 2, 11 and 13, and it identifies every party including the intermediaries, record by record.
  • Question three is sections 4, 5, 10A, 7, 14 and 15, and then section 63 of the Bharatiya Sakshya Adhiniyam for proof.
  • Question four has three limbs: civil under sections 43, 43A and 46; criminal under Chapter XI; and regulatory under section 79 with the IT Rules 2021, section 69A, and section 70B with the CERT-In directions.
  • Always finish with section 81 and the question of what other statute applies alongside.
  • And always ask what the rules add, because most operative detail is in a rule and not in the Act.
munotes.in137

Using the Act in Practice

Test yourself

1. What is the first question to ask of any facts under this Act, and why is it first? Whether the Act applies at all: whether the document or transaction is in the First Schedule under section 1(4), and, for conduct outside India, whether section 75(2) is satisfied by the involvement of a computer, computer system or computer network located in India. It is first because a negative answer ends the inquiry and no other provision needs to be considered.

2. Why must the intermediary question be asked record by record? Because section 2(1)(w) defines an intermediary "with respect to any particular electronic records", so the same person may be an intermediary as to one record and the author of another. A platform is an intermediary as to a user's post and is not an intermediary as to its own advertising, and the availability of section 79 turns on which record is complained of.

3. Where does a claim for three crore rupees under section 43 go, and where does one for seven crore go? Section 46(1A) gives the adjudicating officer jurisdiction where the claim for damage does not exceed five crore rupees, so three crore goes to the adjudicating officer. The proviso vests jurisdiction in respect of a claim exceeding five crore rupees in the competent court, so seven crore goes there.

4. A client asks whether an email exchange made a binding contract. Which steps of the route apply? Steps 3 and 4 to identify the records and the originator and addressee; step 5, section 11, on attribution if either party denies sending; step 6, section 13, for when and where; step 7, sections 4, 5 and 10A, for writing, signature and validity; and step 10, section 63 of the Bharatiya Sakshya Adhiniyam, for how the exchange will be proved. Step 1 should still be asked, because if the contract is one the First Schedule excludes the Act does not touch it at all.

5. Why is an answer built only on the Act likely to be incomplete? Because section 87 leaves the operative detail to rules, so the duties of an intermediary, the standard of reasonable security practices, the procedure for interception or blocking, and the manner of adjudication are all in rules rather than in the Act; and because section 81's overriding effect is qualified, so the Bharatiya Nyaya Sanhita, the Bharatiya Sakshya Adhiniyam, the Contract Act, the Consumer Protection Act and the Copyright Act frequently apply alongside.

Contents This chapter on its own page

munotes.in138

Module II

munotes.in

Chapter Twenty-Five

What a Signature Does

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

A signature does four jobs, and the whole of Chapter II of the Act is an attempt to do those four jobs without paper.

In the wording a student can write in an exam: a signature performs the functions of identifying the signer, evidencing the signer's intention to be bound by or to approve the contents of the document, associating the signer with the document in a way that is difficult to repudiate, and, by the act of signing, bringing home to the signer the seriousness of what is being done; and an electronic method satisfies a legal requirement of signature only if it performs those functions, which is the principle stated in article 7 of the UNCITRAL Model Law on Electronic Commerce.

Why start with the functions

Because the functional equivalent approach cannot be applied to signatures without them. Chapter 70 sets out the method: identify what the paper requirement is for, then ask what an electronic thing must do to serve the same purpose. For writing, the answer was easy, accessibility for subsequent reference. For signature it is harder, because a signature does more than one thing.

And because an examination question about electronic signatures is really a question about these functions. Any answer that begins "a digital signature uses public key cryptography" has started in the middle.

The four functions

Identification. A signature says who. In the paper world it does this badly: a handwritten mark is compared with a specimen, and the comparison is a matter of opinion. It works because forging a particular person's hand consistently is difficult and because most documents are never questioned.

Approval, or animus signandi. A signature says that the signer adopts the contents. This is why a person who writes their name on a page as a heading has not signed it, and why the same mark can be a signature in one place on the page and not in another.

Association with the document. The mark is on the document, so the two cannot be separated. That is why a signed page with a substituted second page is a forgery that people notice, and why each page of an important agreement is initialled.

Ceremony, or the cautionary function. The act of signing marks the transition from negotiating to being bound. It makes the signer pause. The formalities the law imposes on wills and deeds exist largely for this reason, and it is why the Act's First Schedule still excludes a will.

A fifth is often added for commercial documents: the evidentiary function, meaning that the signed document is the record that will be produced later, but that is a consequence of the first three rather than a separate job.

Contents This chapter on its own page

munotes.in139

The rest of this chapter

Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

Notes + Solved papers: ₹798 Already bought it? Sign in

Or notes only: ₹499
Or solved papers only: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

Chapter Twenty-Six

Cryptography for Lawyers

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

There are two kinds of encryption: one where both people share the same secret, and one where each person has a pair of keys, and the second is what makes signatures and certificates possible.

In the wording a student can write in an exam: symmetric or private key cryptography uses a single shared key for both encryption and decryption, which is fast but requires the key to be distributed securely and in advance; asymmetric or public key cryptography uses a mathematically related pair of keys, one published and one kept secret, so that what one encrypts only the other can decrypt, which permits confidential communication between strangers and, in reverse, the creation of digital signatures.

Why a lawyer has to understand this

Because the statute is written in these terms. Section 2(1)(f) defines an asymmetric crypto system, section 2(1)(x) a key pair, section 2(1)(zc) a private key and section 2(1)(zd) a public key. Section 3 tells a subscriber to authenticate by affixing a digital signature effected by the use of an asymmetric crypto system and hash function. A reader who does not know what those are cannot read section 3.

Because the University asks. The 2015 paper: "Explain the difference between public key and private key encryption. What advantages does public key encryption hold over private key encryption?" That is this chapter.

And because the whole of Module II topic 2.3, the Certifying Authority, exists to solve one problem this chapter identifies, and the problem cannot be seen without the mechanism.

Encryption in general

Encryption turns readable text into unreadable text using a key. The readable form is called plaintext and the unreadable form ciphertext. Decryption is the reverse.

The security lies in the key, not in the method. This is Kerckhoffs's principle, stated in the nineteenth century and still the foundation: a system should remain secure even if everything about it except the key is public. A method kept secret is a method nobody has tested.

So when the Act speaks of a security procedure or of encryption, it is speaking about key management, because that is where the security is.

Symmetric cryptography: one shared key

The same key both encrypts and decrypts. Ashok and Bina agree on a key. Ashok encrypts with it, Bina decrypts with it. Anyone without the key sees only ciphertext.

Its advantages are real. It is very fast, so it is what actually protects large volumes of data: the contents of a disk, a database, or a connection between a browser and a website.

It has two failures, and both are fatal on their own.

The key distribution problem. Before Ashok can send Bina anything, they must both have the key, and getting it to her requires a secure channel that does not exist yet. If they had a secure channel they would not need the encryption.

Contents This chapter on its own page

munotes.in144

The rest of this chapter comes with the notes. See the prices

Chapter Twenty-Seven

The Hash Function and the Hash Value

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

A hash function turns any amount of data into a short number that acts as its fingerprint, and it is what makes a digital signature possible.

In the wording a student can write in an exam: a hash function is an algorithm that maps a sequence of bits of any length into another, generally smaller, fixed-length set known as the hash result, such that the same input always yields the same result, that it is computationally infeasible to reconstruct the original from the result, and that it is computationally infeasible for two different inputs to produce the same result; the Explanation to section 3(2) of the Information Technology Act, 2000 adopts precisely that definition.

Why the Act defines it

Because section 3(2) uses it, and the whole mechanism of the digital signature depends on it. Section 3(2) provides that the authentication of the electronic record shall be effected by the use of an asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record.

And because the Act's draftsman knew that the reader would not know what a hash function is, so the Explanation defines it. That is unusual and useful: the statute itself contains a plain statement of the mathematics.

The Act's own definition

"For the purposes of this sub-section, 'hash function' means an algorithm mapping or translation of one sequence of bits into another, generally smaller, set known as 'hash result' such that an electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input making it computationally infeasible (a) to derive or reconstruct the original electronic record from the hash result produced by the algorithm; (b) that two electronic records can produce the same hash result using the algorithm."

Three properties are stated there and they are the three that matter.

Determinism. "An electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input." Same input, same output, always, on any machine, in any year.

Pre-image resistance, which the section calls being computationally infeasible to derive or reconstruct the original. The function runs one way. Knowing the hash tells you nothing about the document.

Collision resistance, which the section states as its being computationally infeasible that two electronic records can produce the same hash result. No two different documents share a hash, as a practical matter.

Note the word the Act uses: infeasible, not impossible. With infinite time both could be done. The security is that the time required exceeds anything anyone has.

What a hash actually looks like

Fixed length, whatever goes in. The function in general use, SHA-256, produces 256 bits, written as sixty-four hexadecimal characters, for any input at all. A one-line email and a two-hour film both produce sixty-four characters.

Contents This chapter on its own page

munotes.in150

The rest of this chapter comes with the notes. See the prices

Chapter Twenty-Eight

Authentication of Electronic Records: Section 3

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

Section 3 is four sub-sections that put the mathematics of the last two chapters into statutory form and make a digital signature an act with legal effect.

In the wording a student can write in an exam: section 3 of the Information Technology Act, 2000 provides that a subscriber may authenticate an electronic record by affixing his digital signature, that the authentication shall be effected by the use of an asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record, that any person may verify the electronic record by the use of the public key of the subscriber, and that the private key and the public key are unique to the subscriber and constitute a functioning key pair.

Why the section is drafted this way

Because the Act of 2000 recognised one technology and had to describe it. Section 5 accepts only a signature affixed in the prescribed manner, so the statute has to say what the manner is. Section 3 says it.

And because the section had to make an act of mathematics into an act in law. Computing a value is not, in itself, a legal act. Section 3(1) makes it one: a subscriber may authenticate an electronic record by affixing his digital signature. Authentication is the legal operation; the rest of the section is how it is done.

Section 3(1): who may do it and to what

"Subject to the provisions of this section any subscriber may authenticate an electronic record by affixing his digital signature."

Three limitations are in that sentence.

Only a subscriber. Section 2(1)(zg) defines a subscriber as a person in whose name the electronic signature Certificate is issued. So the person must hold a certificate, which means a Certifying Authority must have satisfied itself of the person's identity and issued one. Chapter 320 works the issue.

Only an electronic record, as section 2(1)(t) defines it.

Subject to the provisions of this section, which are the three that follow.

Section 3(2): how it is done

"The authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record."

Two techniques are named and both are mandatory. The asymmetric crypto system, defined in section 2(1)(f), and the hash function, defined in the Explanation to this sub-section. Chapters 260 and 270 work them.

The words "envelop and transform the initial electronic record into another electronic record" describe the result. The signature is itself an electronic record, produced from the first one. It is not a mark placed on the document; it is a second record derived from the first.

Contents This chapter on its own page

munotes.in155

The rest of this chapter comes with the notes. See the prices

Chapter Twenty-Nine

Electronic Signature and the Second Schedule

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

Section 3A is the 2008 amendment's answer to the criticism that the Act had written one technology into the statute, and the Second Schedule is the list it produced.

In the wording a student can write in an exam: section 3A of the Information Technology Act, 2000, inserted by the Information Technology (Amendment) Act, 2008, provides that notwithstanding section 3 a subscriber may authenticate any electronic record by an electronic signature or electronic authentication technique which is considered reliable and may be specified in the Second Schedule, states five criteria of reliability, empowers the Central Government to prescribe the procedure for ascertaining whether an electronic signature is that of the person purporting to have affixed it, and empowers it by notification to add to or omit techniques from the Second Schedule provided the technique is reliable, every such notification being laid before each House of Parliament.

Why section 3A was needed

Because the Act of 2000 had made the mistake the 2001 Model Law was written to prevent. Section 3 names the asymmetric crypto system and the hash function, so the statute recognised one family of technique and could recognise nothing else without an amending Act.

Article 3 of the UNCITRAL Model Law on Electronic Signatures, 2001, requires equal treatment of signature technologies. Chapter 100 works it. India's answer, eight years later, was to add section 3A alongside section 3 rather than replacing it, so the Act now contains both a technology-specific route and a technology-neutral one.

The practical driver was different and worth knowing. By 2008 the cost and inconvenience of obtaining a Digital Signature Certificate was keeping electronic signatures out of ordinary use in India: a token, a fee, an in-person verification and an annual renewal for every individual. A route that could accommodate something lighter was needed, and what eventually filled it was Aadhaar-based e-authentication.

Section 3A(1): the route

"Notwithstanding anything contained in section 3, but subject to the provisions of sub-section (2), a subscriber may authenticate any electronic record by such electronic signature or electronic authentication technique which (a) is considered reliable; and (b) may be specified in the Second Schedule."

The non obstante clause makes section 3A a free-standing alternative, not a qualification of section 3.

Two conditions, and both are required. The technique must be considered reliable, which sub-section (2) defines, and it must be specified in the Second Schedule. A technique that is reliable and not specified cannot be used, and the Central Government could not lawfully specify one that is not reliable, because the proviso to sub-section (4) forbids it.

Note the two expressions the sub-section carries: "electronic signature" and "electronic authentication technique". The second is wider. A technique may authenticate a record without producing anything that looks like a signature at all, and section 3A accommodates it.

Contents This chapter on its own page

munotes.in160

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-One

Digital Signature Against Electronic Signature

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

Every digital signature is an electronic signature; not every electronic signature is a digital signature; and the difference is that one names a technology and the other names a result.

In the wording a student can write in an exam: a digital signature is authentication of an electronic record by a subscriber by means of an asymmetric crypto system and hash function in accordance with section 3 of the Information Technology Act, 2000, whereas an electronic signature, defined in section 2(1)(ta) as inserted by the 2008 amendment, is authentication of an electronic record by the electronic technique specified in the Second Schedule and expressly includes a digital signature, so that the second is the genus and the first is a species of it.

Why the Act has both

Because the Act of 2000 recognised one technology and the amendment of 2008 added a category above it rather than replacing it.

Section 3, from 2000, describes a technique. Asymmetric crypto system and hash function. Chapter 280 works it.

Section 3A, from 2008, describes a result. Any technique that is reliable on the four criteria and is specified in the Second Schedule. Chapter 290 works it.

Section 2(1)(ta), also from 2008, ties them together: electronic signature means authentication of any electronic record by a subscriber by means of the electronic technique specified in the Second Schedule and includes digital signature.

So the relationship is one of inclusion, exactly as information includes data in section 2(1)(v), and Electronic Signature Certificate includes Digital Signature Certificate in section 2(1)(tb). Chapter 150 draws the same shape for the machine definitions.

The distinction in a table

Digital signatureElectronic signature
Defined ins.2(1)(p), with s.3s.2(1)(ta)
InsertedOriginal Act, 20002008 amendment
What it namesA technology: asymmetric crypto system and hash functionA result: any technique specified in the Second Schedule
The testCompliance with the technique section 3 describesReliability on the four criteria in s.3A(2), and specification in the Second Schedule
Changed byAn amending Act, because the technique is in the sectionA notification amending the Second Schedule, laid before Parliament under s.3A(5)
CertificateDigital Signature Certificate, s.2(1)(q)Electronic Signature Certificate, s.2(1)(tb), which includes the Digital Signature Certificate
RelationshipA speciesThe genus
Technology neutral?NoYes in form; in substance the Second Schedule's only entry still ends in a digital signature
Practical formA cryptographic token and a PIN, a certificate valid for a year or twoAn Aadhaar or other e-KYC one-time password, a certificate valid for the transaction

The five differences that carry marks

One: the level of abstraction. A digital signature is defined by how it is made. An electronic signature is defined by what it achieves and by whether the Government has listed the technique. That is the difference between a rule that names a technology and one that states a standard, and chapter 100 shows that the 2001 Model Law made exactly this move at the international level.

Contents This chapter on its own page

munotes.in173

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Two

The Electronic Signature Certificate

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

A certificate is a signed statement by a Certifying Authority that a named person holds a particular public key, and section 36 lists what the Authority is taken to have certified by issuing it.

In the wording a student can write in an exam: section 35 of the Information Technology Act, 2000 provides that any person may apply to a Certifying Authority for an Electronic Signature Certificate in the prescribed form with the prescribed fee not exceeding twenty-five thousand rupees and with a certification practice statement, and that the Certifying Authority may grant it after such enquiries as it deems fit or reject the application for reasons recorded in writing after giving the applicant a reasonable opportunity of showing cause; and section 36 sets out the eight representations a Certifying Authority makes by issuing a Digital Signature Certificate.

Why a certificate is needed at all

Because a public key is a number and numbers carry no names. Chapter 260 states the problem: asymmetric cryptography lets anybody verify a signature with a public key, and nothing in the mathematics establishes whose key it is. If a stranger can persuade me that his key is yours, everything you sign can be forged and everything I encrypt to you goes to him.

A certificate is the answer. A third party whom both of us trust examines evidence of who you are, and then issues a data structure containing your name and your public key, signed with the third party's own private key. I check the third party's signature on the certificate, and I then know that the key belongs to you as far as the third party's word goes.

So a certificate is not a technical object at all. It is a statement of fact, in writing, by somebody who is answerable for it. Sections 35 and 36 are about what that statement contains and what the Authority undertakes by making it.

Section 35(1) to (3): the application

"Any person may make an application to the Certifying Authority for the issue of an Electronic Signature Certificate in such form as may be prescribed by the Central Government."

Any person. No qualification, no residence requirement, no minimum age stated in the section.

"Every such application shall be accompanied by such fee not exceeding twenty-five thousand rupees as may be prescribed by the Central Government, to be paid to the Certifying Authority." The proviso permits different fees for different classes of applicant.

Notice that the fee is a statutory ceiling, not a price. Twenty-five thousand rupees is the maximum the Central Government may prescribe; the fees actually prescribed and charged are a small fraction of it.

"Every such application shall be accompanied by a certification practice statement or where there is no such statement, a statement containing such particulars, as may be specified by regulations."

Contents This chapter on its own page

munotes.in178

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Three

Suspension and Revocation of a Certificate

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

A certificate can be put on hold or killed, and the difference matters because one is temporary, limited to fifteen days without a hearing, and reversible, and the other is permanent.

In the wording a student can write in an exam: section 37 of the Information Technology Act, 2000 empowers a Certifying Authority to suspend a Digital Signature Certificate on the request of the subscriber or a person duly authorised on his behalf, or if it is of opinion that suspension is in the public interest, and forbids suspension for a period exceeding fifteen days unless the subscriber has been given an opportunity of being heard; section 38 empowers revocation on request, on the death of the subscriber or the dissolution or winding up of a subscriber firm or company, and on four further grounds subject to the subscriber being given an opportunity of being heard; and section 39 requires notice of any suspension or revocation to be published in every repository specified in the certificate.

Why a certificate must be capable of being killed

Because the private key can be stolen, and because the facts can change.

A certificate is a statement that a named person holds a particular key. If the key is copied, the statement becomes dangerous: anybody with the key can sign in the subscriber's name and every relying party will verify the signature successfully. Nothing in the mathematics detects it.

So the whole system depends on a way of publishing that a certificate can no longer be relied on, and on relying parties actually checking. Chapter 260 explains why the mathematics cannot do this by itself.

And the facts can change without any wrongdoing. A subscriber dies. A company is wound up. An employee leaves and his authority to sign for the company ends. The certificate says what it said and is no longer true.

Section 37: suspension

Section 37(1): "Subject to the provisions of sub-section (2), the Certifying Authority which has issued a Digital Signature Certificate may suspend such Digital Signature Certificate: (a) on receipt of a request to that effect from (i) the subscriber listed in the Digital Signature Certificate; or (ii) any person duly authorised to act on behalf of that subscriber; (b) if it is of opinion that the Digital Signature Certificate should be suspended in public interest."

Two grounds only, and they are very different in character.

Ground (a) is on request, from the subscriber or somebody duly authorised for him. This is the ground a subscriber uses the moment he suspects his key has been compromised, and section 42(2) obliges him to tell the Authority without delay.

Ground (b) is on the Authority's own opinion, in the public interest. No further guidance is given, and the width of the ground is checked only by sub-section (2).

Contents This chapter on its own page

munotes.in184

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Four

The Duties of a Subscriber

Syllabus topic 2.1, "Digital Signatures and Certificates"

In one line

Chapter VIII puts three duties on the person the certificate names: generate the key properly, accept the certificate knowing what acceptance means, and keep the private key to yourself.

In the wording a student can write in an exam: sections 40 to 42 of the Information Technology Act, 2000 require a subscriber who has accepted a Digital Signature Certificate to generate the key pair by applying the security procedure, provide that a subscriber is deemed to have accepted a certificate by publishing it or authorising its publication or otherwise demonstrating approval and that by accepting it he certifies three matters to all who reasonably rely on it, and require every subscriber to exercise reasonable care to retain control of the private key and to communicate any compromise to the Certifying Authority without delay, the Explanation declaring that the subscriber shall be liable until he has so informed the Certifying Authority.

Why the subscriber has duties at all

Because the whole system rests on one person keeping one number secret.

The mathematics is sound and the certificate is reliable, and neither helps if the private key has been copied. Chapter 260 explains why: anybody with the key can produce signatures that verify perfectly. The only defence is that the key never leaves the subscriber's control, and the only person who can secure that is the subscriber.

So Chapter VIII is where the Act allocates the risk, and it allocates almost all of it to the subscriber.

Section 40: generating the key pair

"Where any Digital Signature Certificate, the public key of which corresponds to the private key of that subscriber which is to be listed in the Digital Signature Certificate, has been accepted by a subscriber, the subscriber shall generate that key pair by applying the security procedure."

The section is awkwardly drafted and its point is simple. The subscriber, and not the Certifying Authority, generates the key pair, and he does so by applying the security procedure.

Why the subscriber and not the Authority? Because if the Authority generated the pair it would have held the private key, and the subscriber could then always say that somebody else could have signed. Sole control from the moment of creation is what makes non-repudiation possible, and it is the same idea as section 15(i), worked in chapter 220.

"Security procedure" is defined in section 2(1)(zf) as the procedure prescribed under section 16 by the Central Government. Chapter 220 works section 16.

And note the tension with the Second Schedule's technique. Under the e-authentication procedure the key pair is generated and held by a trusted third party offered by the Certifying Authority, which is the opposite of what section 40 requires. The reconciliation is that section 40 speaks of a Digital Signature Certificate and the Second Schedule operates under section 3A, but the tension is real and chapter 290 states it.

Contents This chapter on its own page

munotes.in190

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Five

What Electronic Governance Is

Syllabus topic 2.2, "Electronic Governance"

In one line

Electronic governance is a government doing its business by machine instead of on paper, and Chapter III of the Act is the four sections that make that lawful.

In the wording a student can write in an exam: electronic governance is the use of information and communication technology by the State to deliver services, to receive and issue documents, to make payments, to publish law and to conduct its internal administration; and Chapter III of the Information Technology Act, 2000, sections 6 to 9 with section 6A inserted in 2008, gives legal effect to filing, issue, grant and payment in electronic form, to retention and audit of electronic records, and to publication in an Electronic Gazette, while expressly conferring no right to insist on any of it.

Why the State needed its own chapter

Because sections 4 and 5 were not enough. Those sections deem the requirements of writing and signature satisfied, and chapter 300 works them. They say nothing about whether a Government office must accept an electronic filing, whether an electronic licence is validly granted, or whether an electronic payment discharges a statutory fee.

And because government forms are made under rules, not under statutes. A great deal of what a citizen has to do is prescribed by a form appended to a rule, and the form assumes paper: an original, in duplicate, with a photograph pasted and a signature across it. Section 4 does nothing about a requirement of that kind, because the requirement is not one of writing.

Section 6 answers all three questions at once, and it does so in the language of what a citizen actually does: filing, issue and grant, and payment.

The four categories of electronic governance

Government to citizen. The delivery of services and the receipt of applications: a driving licence, a passport, a ration card, a certificate of birth. This is what section 6 and section 6A are principally about, and chapter 380 shows what it has become.

Government to business. Company filings, tax returns, licences, the customs single window, and above all electronic procurement. Government tendering in India is now almost entirely electronic, and it is the largest single use of Digital Signature Certificates in the country, which is why chapter 320's worked example is a tender.

Government to government. Between departments and between the Union and the States: land records, treasury systems, and the transfer of files.

Government to employee. Payroll, pensions, service records and the electronic office.

What Chapter III actually does

SectionWhat it makes lawfulChapter
6Filing a form or document, issuing or granting a licence, permit, sanction or approval, and receiving or paying money, in the electronic form the appropriate Government prescribes360
6AAuthorising a service provider to set up and run the facilities, and to collect and keep service charges370
7Retaining records electronically where a law requires retention, on three conditions360
7AApplying an existing audit requirement to records maintained electronically360
8Publishing in the Electronic Gazette instead of the Official Gazette360
9Conferring no right to insist that any of this be done360

Contents This chapter on its own page

munotes.in196

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Six

Electronic Records in Government: Sections 6 to 9

Syllabus topic 2.2, "Electronic Governance"

In one line

Five sections let a Government file, issue, be paid, retain, audit and publish electronically, and the fifth says nobody can make it do any of them.

In the wording a student can write in an exam: section 6 of the Information Technology Act, 2000 deems satisfied a requirement that a form or document be filed, that a licence, permit, sanction or approval be issued or granted, or that money be received or paid in a particular manner, if it is effected in such electronic form as the appropriate Government prescribes; section 7 deems satisfied a requirement of retention on three conditions; section 7A applies existing audit provisions to electronic records; section 8 permits publication in the Electronic Gazette; and section 9 provides that sections 6, 7 and 8 confer no right to insist that a Government body deal electronically.

Section 6: the enabling provision

Section 6(1): "Where any law provides for (a) the filing of any form, application or any other document with any office, authority, body or agency owned or controlled by the appropriate Government in a particular manner; (b) the issue or grant of any licence, permit, sanction or approval by whatever name called in a particular manner; (c) the receipt or payment of money in a particular manner, then, notwithstanding anything contained in any other law for the time being in force, such requirement shall be deemed to have been satisfied if such filing, issue, grant, receipt or payment, as the case may be, is effected by means of such electronic form as may be prescribed by the appropriate Government."

Four features.

Three activities, covering both directions. Clause (a) is the citizen filing something with the Government. Clause (b) is the Government issuing something to the citizen, and the words "by whatever name called" close the argument about what a permit or sanction is. Clause (c) is money, in either direction.

"In a particular manner" is the requirement being displaced. Section 6 is not about writing or signature; it is about the manner a law prescribes, which is where forms, duplicates, attestations and counters live.

A non obstante clause directed at any other law for the time being in force.

The condition is a prescribed electronic form. Not any electronic form: such electronic form as may be prescribed by the appropriate Government. So section 6 does nothing at all until the appropriate Government prescribes, which is what section 6(2) empowers.

Section 6(2): "The appropriate Government may, for the purposes of sub-section (1), by rules, prescribe (a) the manner and format in which such electronic records shall be filed, created or issued; (b) the manner or method of payment of any fee or charges for filing, creation or issue any electronic record under clause (a)."

Contents This chapter on its own page

munotes.in201

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Seven

Delivery of Services by a Service Provider

Syllabus topic 2.2, "Electronic Governance"

In one line

Section 6A lets a Government pay somebody else to run its electronic counters, and lets that person charge the citizen for standing at one.

In the wording a student can write in an exam: section 6A of the Information Technology Act, 2000, inserted by the 2008 amendment, empowers the appropriate Government by order to authorise any service provider to set up, maintain and upgrade computerised facilities and perform such other services as it may specify for the efficient delivery of services to the public through electronic means, to authorise that provider to collect, retain and appropriate prescribed service charges from the person availing the service notwithstanding the absence of any express provision permitting such charges in the Act, rule, regulation or notification under which the service is provided, and requires the appropriate Government to specify the scale of service charges by notification.

Why the section was inserted

Because the Act of 2000 enabled electronic filing and did not say who would run the counter.

Section 6 assumes a Government office receiving an electronic filing. In a country where a great many citizens have no device and no connection, that is not how a service reaches them. It reaches them through an intermediary who has the machine, does the typing, scans the documents and takes the fee.

That intermediary is a private person doing a public function, and by 2008 there were tens of thousands of them. The Act said nothing about them, and in particular said nothing about whether they could charge. Section 6A regularised the arrangement.

Section 6A(1): authorising a service provider

"The appropriate Government may, for the purposes of this Chapter and for efficient delivery of services to the public through electronic means authorise, by order, any service provider to set up, maintain and upgrade the computerised facilities and perform such other services as it may specify, by notification in the Official Gazette."

"Explanation: For the purposes of this section, service provider so authorised includes any individual, private agency, private company, partnership firm, sole proprietor firm or any such other body or agency which has been granted permission by the appropriate Government to offer services through electronic means in accordance with the policy governing such service sector."

Three things to notice.

The class is very wide. An individual is included. So is a sole proprietor firm. This is not a provision about large contractors; it is drafted for the person running a small centre in a district town.

The authorisation is by order and the services are specified by notification. Two instruments, and in practice the distinction is not always observed.

"In accordance with the policy governing such service sector" in the Explanation ties the permission to whatever sectoral policy applies, so a service provider for land records is subject to the land records policy.

Contents This chapter on its own page

munotes.in207

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Eight

E-Governance in Practice: DigiLocker and e-KYC

Syllabus topic 2.2, "Electronic Governance"

In one line

Electronic governance in India runs on three pieces of infrastructure the Act never mentions: a national identity system, a document repository and a payments network.

In the wording a student can write in an exam: the operative machinery of electronic governance in India consists of the Aadhaar identity and authentication system established under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, the DigiLocker repository of electronically signed records created under rule 9A of the Information Technology (Preservation and Retention of Information by Intermediaries Providing Digital Locker Facilities) Rules and rule 5 of the Electronic Service Delivery Rules, 2011, the eSign service operating under section 3A and the Second Schedule, and the electronic payment systems regulated under the Payment and Settlement Systems Act, 2007.

Why this chapter exists

Because the statutory sections are short and the machinery is everything. Sections 6, 6A, 7, 8 and 9 occupy less than a page. What a citizen actually meets is an application on a phone, an identity check by one-time password, a certificate delivered to a locker and a fee paid by a payments interface. None of that is in the Act, and all of it takes its legal effect from the Act.

And because the 2024-25 paper asked for the initiatives taken by the Government to deliver services electronically and the legal challenges associated with them. This chapter is the initiatives; chapters 360 and 370 are the framework; and the legal challenges are set out below.

Aadhaar, and what it does in this subject

Aadhaar is a twelve-digit number issued to a resident, with biometric and demographic information held in a central repository. It is established under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, and the authority that runs it is the Unique Identification Authority of India.

Two things it provides matter here.

Authentication. A person asserts an identity and the system answers yes or no, on a fingerprint, an iris scan or a one-time password sent to a registered mobile number. Section 4 of the Aadhaar Act provides for authentication and section 8 for the process.

Electronic know-your-customer, or e-KYC. Where the holder consents, the system returns a digitally signed set of demographic details. That is the input the Second Schedule's e-authentication technique requires, and chapter 290 works it.

The constitutional history is essential and short. In Justice K.S. Puttaswamy v. Union of India the Supreme Court held that privacy is a fundamental right, and in the later Aadhaar judgment it upheld the scheme for subsidies, benefits and services funded from the Consolidated Fund while striking down its use for private purposes on the footing then before it. Chapter 1040 works the privacy decision.

Contents This chapter on its own page

munotes.in213

The rest of this chapter comes with the notes. See the prices

Chapter Thirty-Nine

The Power to Make Rules on Electronic Signature

Syllabus topic 2.2, "Electronic Governance"

In one line

Section 10 is the power under which the Central Government decides what an electronic signature must be, and it is why section 5 works at all.

In the wording a student can write in an exam: section 10 of the Information Technology Act, 2000 empowers the Central Government, for the purposes of the Act, to make rules prescribing the type of electronic signature, the manner and format in which it shall be affixed, the manner or procedure which facilitates identification of the person affixing it, control processes and procedures to ensure adequate integrity, security and confidentiality of electronic records or payments, and any other matter necessary to give legal effect to electronic signatures.

Why the section is needed

Because section 5 accepts only a signature affixed "in such manner as may be prescribed by the Central Government". Chapter 300 works section 5, and the point is that without a prescription section 5 would be an empty provision: no manner prescribed, no signature capable of satisfying it.

Section 10 is that prescribing power, and the five heads describe what has to be settled before an electronic signature can have legal effect.

The five heads

"(a) the type of electronic signature." Which kinds are acceptable at all. This head and section 3A's Second Schedule cover the same ground from different directions, and chapter 290 works the Schedule.

"(b) the manner and format in which the electronic signature shall be affixed." How the signature is applied to the record and what the result looks like. This is the head section 5 refers to in terms.

"(c) the manner or procedure which facilitates identification of the person affixing the electronic signature." The link between the signature and the person, which is the identification function chapter 250 sets out. In practice this is the certificate machinery of Chapters VI and VII.

"(d) control processes and procedures to ensure adequate integrity, security and confidentiality of electronic records or payments." Note that this head reaches beyond signatures to records and payments, and note the three objectives named: integrity, security and confidentiality, which chapter 200 works.

"(e) any other matter which is necessary to give legal effect to electronic signatures." A residuary head, confined by its own purpose.

What has been made under it

The Information Technology (Certifying Authorities) Rules, 2000 are the principal exercise of the power, made under section 87 read with section 10 among others, and chapter 460 works them.

The Information Technology (Security Procedure) Rules, 2004, made under section 16 with section 10, prescribe the secure digital signature.

The Second Schedule, though amended under section 3A(4) rather than under section 10, is where the acceptable technique now appears.

Contents This chapter on its own page

munotes.in219

The rest of this chapter comes with the notes. See the prices

Chapter Forty

The Controller of Certifying Authorities

Syllabus topic 2.3, "Certifying authority"

In one line

The Controller of Certifying Authorities is the regulator at the top of India's trust chain: it licenses the Authorities, certifies their public keys, and lays down the standards they work to.

In the wording a student can write in an exam: section 17 of the Information Technology Act, 2000 empowers the Central Government by notification to appoint a Controller of Certifying Authorities together with Deputy Controllers, Assistant Controllers, other officers and employees, the Controller discharging his functions subject to the general control and directions of the Central Government; and section 18 lists fourteen functions the Controller may perform, of which supervision of Certifying Authorities, certifying their public keys, laying down standards and maintaining a public database of disclosure records are the principal ones.

Why there is a regulator at all

Because section 5 accepts only a prescribed method, and somebody has to stand behind the method. Chapter 300 works section 5, and chapter 260 explains the problem it leaves: a public key is a number and the certificate binding it to a person is only as good as the person who issued it.

So the Act builds a chain of trust with three links. The subscriber holds a key. A Certifying Authority certifies that the key is the subscriber's. And the Controller certifies that the Certifying Authority is what it says it is, and supervises it.

The Controller sits at the top of that chain and operates the Root Certifying Authority of India. Every licensed Certifying Authority's public key is certified by the Root, so a relying party who trusts the Root can verify any certificate issued in the country.

That is why the office is a regulator and not merely a registrar. It licenses, it standardises, it inspects, and it can shut an Authority down.

Section 17: the office

Section 17(1): "The Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities for the purposes of this Act and may also by the same or subsequent notification appoint such number of Deputy Controllers, Assistant Controllers, other officers and employees as it deems fit."

Section 17(2): "The Controller shall discharge his functions under this Act subject to the general control and directions of the Central Government."

Section 17(3): "The Deputy Controllers and Assistant Controllers shall perform the functions assigned to them by the Controller under the general superintendence and control of the Controller."

Section 17(4) leaves qualifications, experience and terms of service to be prescribed. Section 17(5) provides for a head office and branch offices at places the Central Government specifies. Section 17(6): "There shall be a seal of the Office of the Controller."

Two observations that matter for an answer.

Contents This chapter on its own page

munotes.in222

The rest of this chapter comes with the notes. See the prices

Chapter Forty-One

The Controller's Powers of Investigation

Syllabus topic 2.3, "Certifying authority"

In one line

The Controller can investigate any contravention of the Act with the powers of an income-tax authority, can walk into a computer system on reasonable suspicion, and can order a Certifying Authority to do or stop doing anything the Act requires.

In the wording a student can write in an exam: section 28 of the Information Technology Act, 2000 requires the Controller or an officer authorised by him to take up for investigation any contravention of the Act, rules or regulations and confers on him the powers of income-tax authorities under Chapter XIII of the Income-tax Act, 1961 subject to the limitations of that Act; section 29 gives the Controller or a person authorised by him access to any computer system, apparatus, data or connected material on reasonable cause to suspect a contravention of Chapter VI, and empowers him to direct the person in charge to provide reasonable technical and other assistance; and section 68 empowers the Controller to direct a Certifying Authority or its employee to take measures or cease activities specified in an order, non-compliance being an offence.

Why these powers exist

Because a licence is worth nothing if nobody looks. Chapter 430 works the grant of a licence and chapter 450 the duties that attach to it. Every one of those duties is a statement about how the Authority operates internally, and none of them can be verified from outside.

And because the Controller's supervisory function under section 18(a) needs teeth. A power to supervise without a power to investigate is an exhortation.

Section 28: the power to investigate

Section 28(1): "The Controller or any officer authorised by him in this behalf shall take up for investigation any contravention of the provisions of this Act, rules or regulations made thereunder."

Note "shall", not "may". The section is drafted as a duty to investigate a contravention, not a discretion.

And note the width. Any contravention of the provisions of this Act, not merely of Chapter VI. On its face section 28 is not confined to Certifying Authorities at all, and would reach a contravention of section 43 or section 67. In practice it is exercised in relation to the matters the Controller supervises, but the words are wide and worth noticing.

Section 28(2): "The Controller or any officer authorised by him in this behalf shall exercise the like powers which are conferred on Income-tax authorities under Chapter XIII of the Income-tax Act, 1961, and shall exercise such powers, subject to such limitations laid down under that Act."

This is legislation by reference and it is worth unpacking. Chapter XIII of the Income-tax Act, 1961 confers on income-tax authorities powers of discovery and inspection, of enforcing the attendance of any person and examining him on oath, of compelling the production of books of account and other documents, of issuing commissions, of survey, of calling for information, and, in the specified authorities, of search and seizure.

Contents This chapter on its own page

munotes.in227

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Two

Recognition of Foreign Certifying Authorities

Syllabus topic 2.3, "Certifying authority"

In one line

A foreign Certifying Authority counts in India only if the Controller has recognised it by notification with the previous approval of the Central Government.

In the wording a student can write in an exam: section 19 of the Information Technology Act, 2000 empowers the Controller, subject to such conditions and restrictions as may be specified by regulations and with the previous approval of the Central Government, to recognise any foreign Certifying Authority as a Certifying Authority for the purposes of the Act by notification in the Official Gazette, provides that a certificate issued by an Authority so recognised shall be valid for the purposes of the Act, and empowers the Controller for reasons recorded in writing to revoke that recognition by notification if satisfied that the Authority has contravened the conditions and restrictions of its recognition.

Why the section is needed

Because a certificate is a statement by somebody, and the reason to believe it is the licence behind it. Chapter 320 sets that out. A certificate issued by an Authority licensed under section 24 is trustworthy in India because the Controller licensed and supervises the issuer.

A certificate issued in Singapore or Germany has none of that behind it, so far as Indian law is concerned. Its issuer is licensed by somebody else, to somebody else's standards, and answerable to somebody else.

And cross-border transactions need the problem solved. An Indian company signing with a German counterparty needs each side's signature to be effective at the other end, and neither wants to obtain a certificate in the other's country.

The section

Section 19(1): "Subject to such conditions and restrictions as may be specified by regulations, the Controller may with the previous approval of the Central Government, and by notification in the Official Gazette, recognise any foreign Certifying Authority as a Certifying Authority for the purposes of this Act."

Four requirements, and each is a step. Conditions and restrictions specified by regulations, which are the Controller's own regulations under section 89. The previous approval of the Central Government. A notification in the Official Gazette. And the effect is that the foreign Authority becomes a Certifying Authority for the purposes of this Act.

Section 19(2): "Where any Certifying Authority is recognised under sub-section (1), the Electronic Signature Certificate issued by such Certifying Authority shall be valid for the purposes of this Act."

So recognition attaches to the Authority and the validity flows to its certificates. There is no mechanism for recognising a single certificate or a class of certificates.

Section 19(3): "The Controller may, if he is satisfied that any Certifying Authority has contravened any of the conditions and restrictions subject to which it was granted recognition under sub-section (1), he may, for reasons to be recorded in writing, by notification in the Official Gazette, revoke such recognition."

Contents This chapter on its own page

munotes.in233

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Three

Licensing a Certifying Authority

Syllabus topic 2.3, "Certifying authority"

In one line

Becoming a Certifying Authority takes five crore rupees of capital, fifty crore rupees of net worth, facilities located in India, an audit before you may start, and the Controller's licence.

In the wording a student can write in an exam: section 21 of the Information Technology Act, 2000 permits any person to apply to the Controller for a licence to issue Electronic Signature Certificates but forbids the issue of a licence unless the applicant fulfils the prescribed requirements as to qualification, expertise, manpower, financial resources and other infrastructure facilities, and provides that a licence is valid for the prescribed period, is not transferable or heritable and is subject to the terms and conditions specified by regulations; section 22 prescribes the contents of the application; section 23 governs renewal; and section 24 empowers the Controller to grant or reject after considering the accompanying documents and such other factors as he deems fit, no rejection being made without a reasonable opportunity of presenting the applicant's case.

Why the entry requirements are so heavy

Because the whole of section 5 rests on the certificate, and the certificate rests on the Authority. Chapters 300 and 320 set that out. An Authority that fails takes with it every signature that depends on its certificates.

And because the risk is not confined to its customers. A relying party who accepts a signature has no relationship with the Authority at all, and no way of assessing it. The licensing requirements are the substitute for that assessment.

Section 21: who may hold a licence

Section 21(1): "Subject to the provisions of sub-section (2), any person may make an application, to the Controller, for a licence to issue Electronic Signature Certificates."

Section 21(2): "No licence shall be issued under sub-section (1), unless the applicant fulfils such requirements with respect to qualification, expertise, manpower, financial resources and other infrastructure facilities, which are necessary to issue Electronic Signature Certificates as may be prescribed by the Central Government."

Five heads of requirement: qualification, expertise, manpower, financial resources and other infrastructure facilities. Each is prescribed by the Certifying Authorities Rules 2000.

Section 21(3): "A licence granted under this section shall (a) be valid for such period as may be prescribed by the Central Government; (b) not be transferable or heritable; (c) be subject to such terms and conditions as may be specified by the regulations."

Clause (b) is worth pausing on. A licence is neither transferable nor heritable. So the business of a Certifying Authority cannot be sold with its licence, and the death of an individual licensee ends it. That is a serious constraint on the commercial structure of the industry and explains why licensed Authorities in India are companies rather than individuals.

Contents This chapter on its own page

munotes.in238

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Four

Suspension and Revocation of a Licence

Syllabus topic 2.3, "Certifying authority"

In one line

The Controller can suspend a Certifying Authority's licence for ten days without hearing it, and can revoke it on four grounds after hearing it, and while suspended the Authority may issue nothing.

In the wording a student can write in an exam: section 25 of the Information Technology Act, 2000 empowers the Controller, if satisfied after such inquiry as he thinks fit that a Certifying Authority has made an incorrect or false statement in material particulars in or in relation to its application, has failed to comply with the terms and conditions of its licence, has failed to maintain the procedures and standards specified in section 30, or has contravened the Act, rules, regulations or orders, to revoke the licence after giving a reasonable opportunity of showing cause, and empowers him to suspend the licence pending an enquiry, no suspension exceeding ten days without such an opportunity, an Authority whose licence is suspended being forbidden to issue any Electronic Signature Certificate.

Why the section is drafted around revocation

Read section 25(1) carefully. The marginal note says "Suspension of licence" and the operative verb at the end of sub-section (1) is revoke. Sub-section (2) then provides for suspension pending an enquiry into a ground for revocation.

So the structure is: revocation is the substantive power, and suspension is the interim measure. That is the opposite way round from sections 37 and 38 for a subscriber's certificate, where suspension and revocation are separate powers with different grounds. Chapter 330 works those.

Section 25(1): the four grounds of revocation

"The Controller may, if he is satisfied after making such inquiry, as he may think fit, that a Certifying Authority has:"

(a) made a statement in, or in relation to, the application for the issue or renewal of the licence, which is incorrect or false in material particulars;

(b) failed to comply with the terms and conditions subject to which the licence was granted;

(c) failed to maintain the procedures and standards specified in section 30;

(d) contravened any provisions of this Act, rule, regulation or order made thereunder,

"revoke the licence: Provided that no licence shall be revoked unless the Certifying Authority has been given a reasonable opportunity of showing cause against the proposed revocation."

Clause (c) was substituted by the 2008 amendment. As originally enacted it read that the Authority had failed to maintain the standards specified in section 20(2), which was the repository provision; when section 20 was omitted the reference was moved to section 30, which is the section imposing the Authority's own procedural duties. Chapter 450 works section 30.

Four observations.

Ground (a) reaches statements made "in relation to" the application, not merely in it, so a false statement made in correspondence during the licensing process is caught.

Contents This chapter on its own page

munotes.in245

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Five

The Duties of a Certifying Authority

Syllabus topic 2.3, "Certifying authority"

In one line

A Certifying Authority must run a system secure from intrusion, be reliable, keep signatures secret, be the repository of what it issues, publish its practices and the status of every certificate, and be audited every year.

In the wording a student can write in an exam: section 30 of the Information Technology Act, 2000 requires every Certifying Authority to make use of hardware, software and procedures secure from intrusion and misuse, to provide a reasonable level of reliability in its services reasonably suited to the performance of intended functions, to adhere to security procedures ensuring the secrecy and privacy of electronic signatures, to be the repository of all Electronic Signature Certificates issued under the Act, to publish information regarding its practices, its certificates and their current status, and to observe such other standards as may be specified by regulations; sections 31 to 34 add obligations as to its employees, the display of its licence, surrender and disclosure.

Why the duties are stated so generally

Because the Act states the objective and the rules state the technique. Section 30 is four broad obligations and a residuary head. The Certifying Authorities Rules 2000 then run to thirty-six rules with three schedules of technical requirement.

That division is deliberate and it matters for an answer. A statute that specified the cryptographic standard would be obsolete in five years. A statute that requires hardware, software and procedures "secure from intrusion and misuse" can be met by whatever the current standard is, and the standard lives in the rules and in the Controller's directions under section 18(c).

Section 30: the five duties

"Every Certifying Authority shall:"

(a) make use of hardware, software and procedures that are secure from intrusion and misuse;

(b) provide a reasonable level of reliability in its services which are reasonably suited to the performance of intended functions;

(c) adhere to security procedures to ensure that the secrecy and privacy of the electronic signatures are assured;

(ca) be the repository of all electronic signature Certificates issued under this Act;

(cb) publish information regarding its practices, electronic signature Certificates and current status of such certificates; and

(d) observe such other standards as may be specified by regulations.

Clauses (ca) and (cb) were inserted by the 2008 amendment, and they are the provisions that replaced the omitted section 20. Chapter 400 explains: the repository function moved from the Controller to each Certifying Authority, which is where it belongs, since each Authority knows the status of its own certificates.

Clause (a) is the security obligation and it names three things: hardware, software and procedures. Most failures in practice are procedural rather than technical, and chapter 440's worked example is one.

Contents This chapter on its own page

munotes.in251

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Six

The Certifying Authorities Rules in Outline

Syllabus topic 2.3, "Certifying authority"

In one line

The Certifying Authorities Rules are thirty-six rules and four schedules, and the first six of them define the vocabulary and describe, in a statutory instrument, how a digital signature is made and checked.

In the wording a student can write in an exam: the Information Technology (Certifying Authorities) Rules, 2000, made under section 87 read with sections 10, 16, 17, 21, 22, 25 and 30 of the Information Technology Act, 2000 and effective from 17 October 2000, comprise thirty-six rules with four schedules, of which rules 1 to 7 contain the definitions and the manner of authentication by digital signature, rules 8 to 17 govern licensing, rules 18 to 22 the operation of a Certifying Authority, rules 23 to 30 certificates, and rules 31 to 36 audit, confidentiality and access.

Why the rules matter more than the sections

Because the Act states objectives and the rules state technique. Chapter 450 makes the point about section 30. The same is true throughout Chapter VI: section 21 says the applicant must have prescribed financial resources and the rules say five crore rupees; section 30 says the systems must be secure and the schedules say how.

And because the rules contain things the Act does not mention at all: the classes of certificate, the certificate lifetime, cross certification, the auditor's independence, and the seven year record retention on cessation.

The shape of the set

RulesSubjectChapter
1 to 2Short title, commencement and definitionsThis chapter
3 to 7How a digital signature is created and verified; the standardsThis chapter
8 to 12Eligibility, location, application, fee, cross certification430
13 to 17Validity, suspension, renewal, issuance and refusal of a licence430, 440
18 to 22Governing law, security guidelines, commencement of operation, cessation, the Controller's database450
23 to 30Digital Signature Certificates: generation, issue, lifetime, archival, compromise, revocation, fees320, 330
31 to 36Audit, the auditor's independence, confidential information and access to it450
Schedule IThe application form430
Schedule IIInformation Technology Security Guidelines450
Schedule IIISecurity Guidelines for Certifying Authorities450
Schedule IVForms, including Form C referred to in the Second Schedule to the Act290

Rule 2: the definitions worth knowing

Rule 2(c), "auditor": any internationally accredited computer security professional or agency appointed by the Certifying Authority and recognised by the Controller for conducting technical audit of the operation of a Certifying Authority.

Two requirements, and both matter. The auditor must be internationally accredited, and must be recognised by the Controller. Read with rule 32, which chapter 450 works, the auditor must also be independent and must not be a vendor to the Authority.

Rule 2(f), "information asset": all information resources utilised in the course of any organisation's business, including all information, applications, whether software developed or purchased, and technology, meaning hardware, system software and networks.

Contents This chapter on its own page

munotes.in258

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Seven

Why Software Is Hard to Protect

Syllabus topic 2.4, "Software Protection"

In one line

Software is a text that behaves like a machine, and every branch of intellectual property protects one half of that description and misses the other.

In the wording a student can write in an exam: a computer programme has a dual character, being at once an expression in a language, which is what copyright protects, and a functional artefact producing a technical result, which is what patent law protects; Indian law protects it primarily as a literary work under the Copyright Act, 1957, excludes a computer programme per se from patentability under section 3(k) of the Patents Act, 1970, protects the layout design of an integrated circuit under the Semiconductor Integrated Circuits Layout-Design Act, 2000, and leaves confidential information to contract and equity, there being no trade secrets statute in India.

What a computer programme actually is

Section 2(ffc) of the Copyright Act defines it: a set of instructions expressed in words, codes, schemes or in any other form, including a machine readable medium, capable of causing a computer to perform a particular task or achieve a particular result.

Read that definition and the dual character is on its face. It is expressed in words, codes or schemes, which is the language half. And it is capable of causing a computer to perform a particular task or achieve a particular result, which is the machine half.

A novel does not cause anything to happen. A machine is not written in a language. Software is both, and that is why every branch of intellectual property fits it awkwardly.

Why each branch fits badly

Copyright protects expression and not ideas. So it protects the particular lines a programmer wrote and does not protect what the program does. A competitor who reads the specification and writes his own code from scratch infringes nothing, however identical the behaviour. For a novel that result is correct, because the value of a novel is in its words. For software the value is usually in what it does.

Patents protect function and require an invention. That would fit software well, and section 3(k) of the Patents Act excludes a computer programme per se from being an invention. Chapter 510 works the exclusion and the argument about what "per se" leaves.

Trade marks protect a name and not a thing. They stop somebody selling a different program under your name; they do nothing about somebody copying your program and selling it under theirs.

Designs protect appearance. The Designs Act, 2000 protects features of shape, configuration, pattern or ornament applied to an article, which reaches the visual appearance of an interface in some jurisdictions and sits uneasily with the exclusion of anything that is merely a mode or principle of construction.

Contents This chapter on its own page

munotes.in263

The rest of this chapter comes with the notes. See the prices

Chapter Forty-Nine

Who Owns the Software, and For How Long

Syllabus topic 2.4, "Software Protection"

In one line

The person who wrote the code owns it, unless they wrote it as an employee, in which case the employer does, and a contractor is not an employee.

In the wording a student can write in an exam: section 17 of the Copyright Act, 1957 makes the author of a work the first owner of the copyright, subject to provisos of which clause (c) provides that in the case of a work made in the course of the author's employment under a contract of service or apprenticeship the employer shall, in the absence of any agreement to the contrary, be the first owner; section 22 fixes the term of copyright in a literary work at the author's lifetime plus sixty years from the beginning of the calendar year following his death; and sections 18 and 19 govern assignment, requiring it to be in writing signed by the assignor and to specify the work, the rights, the duration and the territorial extent.

Why ownership is the first question

Because a company that commissioned software and did not take an assignment may not own it, and that discovery is usually made when the company tries to sell the business or sue a competitor.

And because the rule is counter-intuitive. Paying for something does not make you its owner in copyright. Section 17 starts from the author, and money is not one of the exceptions.

Section 17: the author is the first owner

"Subject to the provisions of this Act, the author of a work shall be the first owner of the copyright therein."

Who is the author of a computer programme? Section 2(d)(vi) provides that in relation to any literary, dramatic, musical or artistic work which is computer-generated, the author is the person who causes the work to be created. For a programme written by a human being, section 2(d)(i) applies and the author is the author of the work, meaning the programmer.

Section 2(d)(vi) is worth pausing on, because it is India's answer to the question every jurisdiction is now asking about work produced by a machine. It was inserted long before generative systems existed and it says that where a work is computer-generated, the author is the person who caused it to be created. Chapter 990 works the current problem, and this clause is the starting point for it.

The provisos, and the one that matters

Proviso (a): the journalist's rule. A literary, dramatic or artistic work made by the author in the course of employment by the proprietor of a newspaper, magazine or similar periodical under a contract of service or apprenticeship, for the purpose of publication there, belongs to the proprietor so far as the copyright relates to publication in a periodical or to reproduction for that purpose, and in all other respects the author is the first owner. This is a split ownership rule and it does not apply to software.

Contents This chapter on its own page

munotes.in275

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-One

Software Patents in India

Syllabus topic 2.4, "Software Protection"

In one line

India does not patent computer programmes as such, and the whole argument is about the two words the section adds after them.

In the wording a student can write in an exam: section 3(k) of the Patents Act, 1970 provides that a mathematical or business method or a computer programme per se or algorithms are not inventions within the meaning of the Act, so that a claim to a computer programme as such is excluded from patentability, while the words "per se" leave open the patentability of an invention in which a computer programme produces a technical effect or a technical advance beyond the ordinary working of the computer.

Why the exclusion exists

Because a patent gives a monopoly over a function for twenty years, and copyright already protects the code. Chapter 480 works the copyright route.

Two objections to software patents run through every jurisdiction that has considered them.

The subject matter objection. A patent is for an invention, meaning a technical solution to a technical problem. A program is a set of instructions, and instructions are closer to a mental method or a mathematical formula than to a machine. India excludes all three in section 3, at clauses (k) and (m).

The practical objection. Software is written in layers, each building on thousands of earlier ideas, and a patent on a small step can block an entire field. The examination systems of most patent offices cope badly with prior art in software, because much of it is in products rather than in publications.

India's answer was to exclude, and to leave a qualifier.

Section 2: what an invention is before section 3 takes anything away

Section 2(1)(j): an invention means a new product or process involving an inventive step and capable of industrial application. Three requirements, and all three must be met before section 3 is even reached.

Section 2(1)(ja), inserted in 2005, defines the middle one. An inventive step means a feature of an invention that involves technical advance as compared to the existing knowledge or having economic significance or both, and that makes the invention not obvious to a person skilled in the art.

Read those two definitions before section 3(k) and the shape of the Indian position becomes clear. Section 2(1)(ja) writes technical advance into the definition of an inventive step, so the technical effect the Patent Office looks for in a software claim is not an invention of the guidelines. It is already in the statute. Section 3(k) then removes a category outright, and a claim must clear both: it must be an invention within section 2(1)(j) and (ja), and it must not be a thing section 3 says is not an invention.

Contents This chapter on its own page

munotes.in288

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Two

Trade Secrets and the Employment Contract

Syllabus topic 2.4, "Software Protection"

In one line

India has no trade secrets statute, so confidential information is protected by contract, by the equitable action for breach of confidence, and, in a narrow field, by section 72A of the Information Technology Act.

In the wording a student can write in an exam: there is no legislation in India protecting trade secrets as such, and confidential information is protected by an express or implied contractual obligation of confidence, by the equitable jurisdiction to restrain a breach of confidence, by the employer's remedy against a departing employee subject to section 27 of the Indian Contract Act, 1872 which makes an agreement in restraint of trade void, and by section 72A of the Information Technology Act, 2000 which punishes disclosure of personal information in breach of a lawful contract by a person providing services under it.

Why trade secrecy matters so much for software

Because the most valuable software is never distributed. Chapter 470 makes the point: a service delivered over a network gives the customer no copy to study, so nothing has been published and everything remains secret.

And because copyright leaves the most valuable thing unprotected. A competitor who works out how a system does what it does may write his own, and section 52(1)(ac) expressly permits the observation and study that gets him there. Chapter 500 works it. The only way to stop him is to make sure he cannot find out.

Three categories are typically protected as secrets in software. Source code that is never released. Algorithms, parameters and training data. And commercial information: pricing models, customer lists, roadmaps.

What India does not have

There is no Indian statute on trade secrets. No definition, no registration, no term, no statutory remedy.

That is unusual. The United States has the Defend Trade Secrets Act of 2016 and the state Uniform Trade Secrets Act; the European Union has the Trade Secrets Directive of 2016; China's Anti-Unfair Competition Law protects commercial secrets, and chapter 720 mentions it.

India's obligation under TRIPS is article 39, which requires members to protect undisclosed information against acquisition, disclosure or use contrary to honest commercial practices, where the information is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. India has taken the view that its existing law satisfies article 39.

A National Innovation Bill was drafted in 2008 with a chapter on confidentiality and never enacted, and the Law Commission's report of 2024 on trade secrets recommended a statute. As matters stand there is none, and an answer should say so.

Route one: contract

This is the principal protection and it is the one a lawyer actually drafts.

The non-disclosure agreement. With customers, vendors, contractors and prospective investors. It defines what is confidential, what may be done with it, how long the obligation lasts, and what happens on termination.

Contents This chapter on its own page

munotes.in294

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Three

Semiconductor Layout Designs

Syllabus topic 2.4, "Software Protection"

In one line

The Semiconductor Integrated Circuits Layout-Design Act protects the arrangement of elements on a chip, which is neither a program nor a design nor an invention, and which nothing else protects.

In the wording a student can write in an exam: the Semiconductor Integrated Circuits Layout-Design Act, 2000 gives the registered proprietor of an original layout-design of a semiconductor integrated circuit the exclusive right to its use for ten years, defines a layout-design in section 2(h) as a layout of transistors and other circuitry elements including lead wires connecting them and expressed in any manner in a semiconductor integrated circuit, requires originality and the absence of prior commercial exploitation under section 7, and makes reproduction, importation, sale or distribution for commercial purposes an infringement under section 18, subject to substantial exceptions for scientific evaluation, reverse engineering and independent creation.

Why chips needed their own statute

Because nothing else fitted, and this is a rare case where the gap was real rather than argued.

Not copyright. A layout is a functional arrangement of circuit elements. It is not a literary or artistic work; its value is what it does, and every choice in it is dictated by electrical constraints.

Not patent. The layout is not an invention; it is one physical implementation of a circuit that is often already known. It fails novelty and inventive step routinely.

Not designs. The Designs Act protects features of shape, configuration, pattern or ornament judged solely by the eye, and expressly excludes anything that is a mode or principle of construction. A chip layout is never judged by the eye and is nothing but a principle of construction.

And the copying was trivially easy. A finished chip can be photographed layer by layer and the layout reconstructed, so a design costing years and crores could be copied for the cost of the photography.

So a sui generis right was created internationally, in the Washington Treaty on Intellectual Property in Respect of Integrated Circuits of 1989, and then in the TRIPS Agreement, articles 35 to 38, which obliged members to protect layout-designs. India's Act of 2000 gives effect to that obligation.

What is protected

Section 2(h): "layout-design means a layout of transistors and other circuitry elements and includes lead wires connecting such elements and expressed in any manner in a semiconductor integrated circuit."

Section 2 also defines a semiconductor integrated circuit as a product having transistors and other circuitry elements inseparably formed on a semiconductor material or an insulating material or inside the semiconductor material and designed to perform an electronic circuitry function.

And section 2(e) defines commercial exploitation in relation to a layout-design as to sell, lease, offer or exhibit for sale or otherwise distribute the semiconductor integrated circuit for any commercial purpose.

Contents This chapter on its own page

munotes.in300

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Four

Licensing Software: Proprietary and Open Source

Syllabus topic 2.4, "Software Protection"

In one line

A software licence is a permission not to be sued, and everything about the licensing of software follows from that one fact.

In the wording a student can write in an exam: a software licence is a grant by the owner of copyright in a computer programme, under section 30 of the Copyright Act, 1957, of permission to do acts which would otherwise infringe the exclusive rights conferred by section 14, and it may be proprietary, restricting use, copying, modification and transfer, or free and open source, permitting all of those subject to conditions of which the requirement that derivative works be distributed under the same terms, called copyleft, is the most significant.

Why a licence is not a sale

Because copyright is a bundle of exclusive rights and a licence is permission to do one or more of them.

Section 14 makes reproduction, including storing by electronic means, an exclusive right of the owner. Chapter 480 works it. So loading a program is a reproduction, and without permission it infringes, which is why section 52(1)(aa)(i) exists to make ordinary use lawful for a lawful possessor.

A licence is what makes the possessor lawful, and what defines what "the purpose for which it was supplied" is. Chapter 500 works that exception.

And the distinction from a sale matters. When you buy a book you own the physical copy and may resell it; the copyright owner's rights are exhausted as to that copy. When you take a software licence you usually own nothing: the licence says you are granted a limited, non-exclusive, non-transferable right to use, and everything not granted is reserved. That is a deliberate structure and it is why software is licensed rather than sold.

Section 30 and the form of a licence

Section 30 of the Copyright Act: the owner of the copyright in any work, or the prospective owner of the copyright in any future work, may grant any interest in the right by licence in writing signed by him or by his duly authorised agent.

"In writing signed by him", and the proviso for a future work provides that the licence takes effect when the work comes into existence.

Section 30A applies sections 19 and 19A to licences as they apply to assignments, so the requirements about identifying the work, the rights, the duration and the territorial extent, and about royalty, apply to a licence too. Chapter 490 works section 19, including the five-year default and the India-only presumption.

And section 5 of the Information Technology Act is not engaged, because no law requires a licence of copyright to be signed in the sense section 5 addresses; what section 30 requires is writing and signature, and chapter 300 explains the difference between the two questions.

Contents This chapter on its own page

munotes.in306

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Five

Software Piracy and Its Enforcement

Syllabus topic 2.4, "Software Protection"

In one line

Software piracy is copyright infringement, and the enforcement that works is a civil action with an order to seize the evidence before the defendant knows the case has started.

In the wording a student can write in an exam: software piracy is the unauthorised reproduction, distribution or use of a computer programme, actionable civilly as an infringement of copyright under section 51 of the Copyright Act, 1957 with the remedies of injunction, damages and account of profits under section 55, and punishable under section 63 where the infringement is knowing, with a power of seizure without warrant under section 64; and the same conduct will frequently also be a contravention of section 43 and an offence under section 66 of the Information Technology Act, 2000 where data has been copied from a computer resource without the owner's permission.

The forms piracy takes

End user piracy is the commonest and the least visible: a business with ten licences running the software on forty machines. It is reproduction in contravention of the conditions of a licence under the second limb of section 51(a)(i), and chapter 500 works it.

Hard disk loading is a dealer installing unlicensed software on machines it sells, which is section 51(b)(i), making for sale or selling infringing copies.

Counterfeiting is manufacturing and selling copies presented as genuine, which engages the Copyright Act and, where the packaging carries the owner's mark, the Trade Marks Act, 1999 as well.

Internet piracy is distribution through file-sharing, download sites and streaming, which is section 51(b)(ii) distribution and, for the platform, raises the intermediary question chapter 1360 works.

Client-server overuse is running software on a server accessed by more users than the licence permits.

Key generators and cracks are tools that defeat the licence check, which is section 65A of the Copyright Act, circumventing an effective technological measure with the intention of infringing, and chapter 500 works it.

The civil action, and why it is the real remedy

Section 55(1): where copyright in a work has been infringed, the owner is entitled to all such remedies by way of injunction, damages, accounts and otherwise as are conferred by law for the infringement of a right.

The proviso protects the innocent infringer. If the defendant proves that at the date of the infringement he was not aware and had no reasonable ground for believing that copyright subsisted in the work, the plaintiff is not entitled to any remedy other than an injunction and a decree for the whole or part of the profits made by the defendant. So innocence removes damages and leaves the injunction and an account.

That proviso is almost never available in software cases, because a licence check, a copyright notice and a purchase price make it very difficult to say the defendant had no reasonable ground for believing copyright subsisted.

Contents This chapter on its own page

munotes.in312

The rest of this chapter comes with the notes. See the prices

Module III

munotes.in

Chapter Fifty-Six

Why Compare Cyber Laws

Syllabus topic 3.1, "Comparative Study Relating to Cyber Laws"

In one line

Comparing cyber laws is not listing what each country's statute says; it is asking what problem each is solving and what each answer costs.

In the wording a student can write in an exam: comparative law in this field proceeds by the functional method, which identifies a problem that every legal system faces, asks how each system solves it whatever the doctrinal labels used, and then explains the differences by reference to the constitutional, institutional and economic conditions of each system; and the four problems on which cyber law systems may usefully be compared are liability for content published by another, the protection of personal data, the powers of the State over the network, and the reach of a court over conduct abroad.

Why comparison is worth doing in this subject

Because India borrowed almost everything and a student who does not know the sources cannot see the shape of the Act.

Section 4 is article 6 of a United Nations Model Law. Section 79 answers the same question as the European e-Commerce Directive and the American Communications Decency Act. Section 43A and the SPDI Rules were drafted with the European data protection directive in view. Chapter 610 traces the borrowings.

Because the network is one thing and the laws are many. A dispute in this field routinely engages three legal systems at once, and chapter 40 explains why. A lawyer who knows only Indian law cannot advise on the ordinary case.

And because the University asks. Topic 3.1 is comparative study and topic 3.2 names five systems.

The method

The functional method is the standard tool and it has three steps.

Step one: state the problem in factual terms, not in legal ones. Not "what is the safe harbour in each country", which assumes every country has one, but "when a person publishes something unlawful on a platform, who bears the loss?" Stated factually, every system has an answer, including the answer that the platform bears none.

Step two: find the answer in each system, wherever it lies. It may be in a statute, in case law, in a regulator's practice or in a contract term the market imposes. Comparing statutes alone produces a false picture, because a country with no statute may have a stricter rule than one with a detailed statute nobody enforces.

Step three: explain the differences. This is where the marks are. A difference is explained by something: a constitutional guarantee, an institutional capacity, an economic interest, a political tradition. The United States protects platforms more generously than India because of the First Amendment and because the platforms are American. Europe regulates more heavily than either because it has no large platforms of its own and a strong tradition of rights-based regulation. China is different because sovereignty over the network is a stated policy.

Contents This chapter on its own page

munotes.in318

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Seven

Three Models of Regulating the Network

Syllabus topic 3.1, "Comparative Study Relating to Cyber Laws"

In one line

There are three ways to regulate a network, and a country's choice between them explains almost everything else about its cyber law.

In the wording a student can write in an exam: legal systems regulate information networks on one of three models, namely the single comprehensive code in which one statute governs electronic transactions, offences and State powers together, as in India; the sectoral patchwork in which there is no general statute and particular harms are addressed by particular laws, as in the United States; and the sovereign-control model in which the network is treated as territory over which the State exercises the authority it exercises on the ground, as in China; with the European Union representing a fourth, rights-led variant in which regulation proceeds from a constitutionalised set of individual rights.

Model one: the single comprehensive code

One statute does everything. It gives legal effect to electronic records and signatures, creates the offences, confers the State's powers, and provides for a regulator and an appellate forum.

India is the clearest example. The Information Technology Act, 2000 contains Chapters II to V on recognition, Chapters VI to VIII on the trust infrastructure, Chapters IX to XI on penalties and offences, Chapter XII on intermediaries and, inside Chapter XI, the State powers in sections 69 to 70B. Chapter 120 maps it.

Its advantages. A single place to look. One set of definitions, so "computer resource" means the same thing in section 43 and section 69. And a legislature that can extend the statute as technology changes, which is what happened in 2008.

Its disadvantages, and chapter 170 states them. The statute's stated purposes describe less than half of what it now does. The offences chapter borrows its conduct from a civil compensation provision, which is what section 66 does with section 43. And a statute drafted for electronic data interchange between businesses has had social media, cloud computing and machine-generated content grafted onto it.

Other systems on this model include most of the countries that enacted the UNCITRAL Model Law and then added their own penal and regulatory chapters, which is a very large part of Asia and Africa.

Model two: the sectoral patchwork

No general statute; particular harms addressed by particular laws.

The United States is the example. There is no federal statute corresponding to the Information Technology Act. Instead: the Computer Fraud and Abuse Act for unauthorised access; the Electronic Communications Privacy Act for interception and stored communications; section 230 of the Communications Decency Act for platform liability; section 512 of the Copyright Act for copyright takedown; the Health Insurance Portability and Accountability Act for health data; the Gramm-Leach-Bliley Act for financial data; the Children's Online Privacy Protection Act for children; and, in the absence of a federal data protection law, State statutes such as the California Consumer Privacy Act. Chapters 620 to 650 work the ones this syllabus needs.

Contents This chapter on its own page

munotes.in324

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Eight

The United Nations and Cyber Law

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The United Nations makes model laws for commerce and treaties for crime, and until 2024 it had produced no cybercrime treaty at all.

In the wording a student can write in an exam: the United Nations contributes to cyber law through the United Nations Commission on International Trade Law, which produced the Model Law on Electronic Commerce 1996 and the Model Law on Electronic Signatures 2001, through the United Nations Office on Drugs and Crime, which serviced the negotiation of the United Nations Convention against Cybercrime adopted by General Assembly resolution 79/243 of 24 December 2024 and opened for signature at Hanoi on 25 October 2025, and through the Groups of Governmental Experts and the Open-Ended Working Group on responsible State behaviour in cyberspace, whose output is a set of voluntary non-binding norms rather than law.

What the United Nations can and cannot do

It is not a legislature. It makes nothing that binds anybody by its own act. What it produces is of three kinds, and keeping them apart is the whole of an answer on this topic.

A model law binds nobody until a legislature enacts it, and then what binds is the enacting State's own statute. Chapter 60 works the point.

A convention binds only States that ratify it, and only in the terms ratified. It enters into force when the stated number of ratifications is deposited.

A resolution or a norm binds nobody at all. It states what States have agreed to say is expected of them.

So a question about "the role of the United Nations in cyber law" is answered by distinguishing the three and by naming an instrument in each class.

UNCITRAL: the commercial side

The United Nations Commission on International Trade Law was created by General Assembly resolution 2205 (XXI) of 17 December 1966 with a mandate to further the progressive harmonisation and unification of the law of international trade.

Its three instruments in this field.

The Model Law on Electronic Commerce, 1996, adopted by resolution 51/162 of 16 December 1996, with article 5 bis added in June 1998. Chapters 60 to 90 work it, and the Indian Act's preamble recites the resolution.

The Model Law on Electronic Signatures, 2001, adopted by resolution 56/80 of 12 December 2001. Chapter 100 works it.

The Model Law on Electronic Transferable Records, 2017, which addressed the uniqueness problem that article 17(3) of the 1996 Model Law had stated and not solved. Chapter 90 works the problem.

And one convention. The United Nations Convention on the Use of Electronic Communications in International Contracts, 2005, which puts the Model Law's core rules into treaty form for international contracts. India has not ratified it.

Contents This chapter on its own page

munotes.in329

The rest of this chapter comes with the notes. See the prices

Chapter Fifty-Nine

The Budapest Convention: the Offences

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The Budapest Convention is the template most of the world's cybercrime offences follow, and reading its nine offences against the Indian Act shows exactly where India departed.

In the wording a student can write in an exam: the Convention on Cybercrime, opened for signature at Budapest on 23 November 2001, European Treaty Series No. 185, requires each Party to establish as criminal offences under its domestic law illegal access, illegal interception, data interference, system interference and misuse of devices, computer-related forgery and computer-related fraud, offences related to child pornography, and offences related to infringements of copyright and related rights, together with attempt, aiding and abetting and corporate liability, and to provide for effective, proportionate and dissuasive sanctions.

What the Convention is, and what it is for

It is a treaty of the Council of Europe, open to non-member States, and about seventy States are parties, including the United States, Japan, Canada, Australia, Brazil and a number of African and Latin American States.

Its purpose is stated in its preamble: to pursue a common criminal policy aimed at the protection of society against cybercrime, by adopting appropriate legislation and fostering international co-operation.

Its architecture is three chapters and it is worth learning as a shape. Chapter II section 1 is the substantive criminal law, articles 2 to 13, which this chapter works. Chapter II section 2 is the procedural law, articles 14 to 21, and section 3 is jurisdiction, article 22. Chapter III is international co-operation, articles 23 to 35. Chapter 600 works the second and third.

Two features of its drafting recur and both matter.

Every offence begins "Each Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law". The Convention does not create offences; it obliges Parties to create them. So a Party's law is what applies, and the Convention is the specification.

Every offence requires the conduct to be "without right", and most require it to be "intentional". "Without right" excludes conduct authorised by law, by contract or by the consent of the person entitled, which is what protects a security researcher, an employee doing their job and a person testing their own system.

Article 1: the four definitions the rest of the treaty runs on

A computer system means any device or group of interconnected or related devices, one or more of which, pursuant to a program, performs automatic processing of data.

Computer data means any representation of facts, information or concepts in a form suitable for processing in a computer system, including a program suitable to cause a computer system to perform a function.

Contents This chapter on its own page

munotes.in335

The rest of this chapter comes with the notes. See the prices

Chapter Sixty

The Budapest Convention: Procedure and Co-operation

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The half of the Budapest Convention that matters most is not the offences but the machinery: preserve the evidence in hours, produce it in days, and help each other around the clock.

In the wording a student can write in an exam: Chapter II section 2 of the Convention on Cybercrime requires each Party to establish procedural powers of expedited preservation of stored computer data and of traffic data, production orders, search and seizure of stored computer data, and real-time collection of traffic data and interception of content data, all subject to the conditions and safeguards in articles 14 and 15; article 22 requires jurisdiction over the offences on territorial, flag, registry and nationality bases; and Chapter III requires Parties to co-operate through extradition, mutual assistance including expedited preservation and disclosure, trans-border access to stored data in the two cases article 32 permits, and a 24/7 Network under article 35.

Why the procedural chapter is the important one

Because the offences were the easy part. Every State already had, or could easily enact, offences of unauthorised access and damage to data.

What no State had was procedure that worked at network speed. Chapter 20 explains the problem: logs are overwritten in days, an IP address without a time is useless, and a mutual legal assistance request takes months. By the time an ordinary request is answered the evidence is gone.

So the Convention's real innovation is a set of powers designed for evidence that expires, and article 16 is its centrepiece.

Articles 14 and 15: scope and safeguards

Article 14 applies the procedural powers to the offences the Convention establishes, to other criminal offences committed by means of a computer system, and to the collection of evidence in electronic form of any criminal offence. So the powers are general, not confined to cybercrime.

Article 15 is the safeguards article and it should be quoted in an answer about criticism. Each Party shall ensure that the establishment, implementation and application of the powers are subject to conditions and safeguards provided for under its domestic law, which shall provide for the adequate protection of human rights and liberties, including rights arising under the European Convention on Human Rights, the International Covenant on Civil and Political Rights and other applicable international human rights instruments, and which shall incorporate the principle of proportionality.

Article 15(2) requires such conditions and safeguards to include, as appropriate in view of the nature of the power, judicial or other independent supervision, grounds justifying application, and limitation of the scope and duration.

Article 15(3) requires Parties to consider the impact of the powers on the rights, responsibilities and legitimate interests of third parties.

Contents This chapter on its own page

munotes.in343

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-One

India in Comparison

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

India took its recognition provisions from the United Nations, its intermediary regime from Europe by way of America, its data protection concepts from Europe, and its surveillance architecture from its own Telegraph Act.

In the wording a student can write in an exam: the Indian regime is composite; Chapters II to V of the Information Technology Act, 2000 enact the UNCITRAL Model Law on Electronic Commerce, section 3A adopts the reliability criteria of the Model Law on Electronic Signatures 2001, section 79 and the rules under it follow the conditional immunity of the European e-Commerce Directive with the notice-based mechanics of the American Digital Millennium Copyright Act, section 43A and the SPDI Rules 2011 and now the Digital Personal Data Protection Act, 2023 follow European data protection concepts, and sections 69 to 69B follow the Indian Telegraph Act, 1885 rather than any foreign model.

Why tracing the borrowings is worth doing

Because it explains the shape of the Act. Chapter 120 shows that the statute reads as four blocks welded together, and the reason is that each block came from somewhere different.

And because it answers a question the University sets directly. The 2025-26 paper asked how far the Act gives effect to the UNCITRAL principles and to evaluate the extent critically. Chapter 110 answers it provision by provision against the Model Law; this chapter answers it by naming what came from where.

What came from the United Nations

Chapters II, IV and V, and the recognition provisions. Section 4 is article 6; section 7 is article 10; section 11 is article 13(1) and (2); section 12 is article 14; section 13 is article 15. Chapter 110 sets them out with what was left behind.

Section 3A(2) is article 6(3) of the 2001 Model Law, its four criteria taken almost word for word, with India adding a residuary clause (e) and omitting article 6(4)'s safe harbour formulation. Chapter 290.

What India did not take from the United Nations: article 3 on interpretation, article 5 bis on incorporation by reference, article 12 on declarations of will, article 13(3) to (5) on reliance, part two on carriage of goods, and article 12 of the 2001 Model Law on foreign certificates.

What came from Europe

The structure of section 79. Article 12 of the e-Commerce Directive is mere conduit, article 13 is caching, article 14 is hosting, and article 15 forbids a general obligation to monitor. Chapter 660 works them. Section 79(2) of the Indian Act reproduces the substance: the exemption applies where the function is limited to providing access to a communication system over which information made available by third parties is transmitted, temporarily stored or hosted, or where the intermediary does not initiate the transmission, select the receiver, or select or modify the information.

Contents This chapter on its own page

munotes.in351

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Two

The United States: the Constitutional Frame

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

American cyber law is what is left after the First Amendment has taken most of the regulatory options away.

In the wording a student can write in an exam: the United States has no comprehensive statute corresponding to the Information Technology Act, 2000, and its regulation of the network is shaped by three constitutional and structural features, namely the First Amendment's protection of speech which subjects content regulation to strict scrutiny, the enumerated and limited legislative powers of the federal government which leaves much of the field to the States, and the state action doctrine under which constitutional guarantees bind the government and not private platforms.

The First Amendment

"Congress shall make no law ... abridging the freedom of speech, or of the press."

Three features of American free speech doctrine explain almost every difference from Indian law.

There is no equivalent of article 19(2). The Indian Constitution permits reasonable restrictions on eight enumerated grounds: the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, public order, decency or morality, contempt of court, defamation and incitement to an offence. The First Amendment states no exceptions at all, and the exceptions the courts have recognised are far narrower: incitement to imminent lawless action, true threats, obscenity in a narrow sense, child sexual abuse material, fraud and defamation with a fault requirement.

Content-based regulation attracts strict scrutiny, meaning the government must show a compelling interest and that the law is narrowly tailored to it, a standard almost nothing survives.

And there is no reasonableness standard. Indian courts ask whether a restriction is reasonable in the interests of one of the eight grounds. American courts ask whether the government has met strict scrutiny. Chapter 1190 shows what the Indian test produced in Shreya Singhal.

The consequence for cyber law is that a general statute regulating what may be said or hosted online is very difficult to enact, and the attempts have failed.

In Reno v. American Civil Liberties Union, 521 U.S. 844 (1997), the Supreme Court struck down the indecent transmission and patently offensive display provisions of the Communications Decency Act of 1996, holding that the internet is entitled to the full protection given to print rather than the reduced protection given to broadcasting, and that the provisions were vague and overbroad because they suppressed a large amount of speech adults had a right to receive in order to protect children. That decision is why there is no American statute regulating online indecency, and why what survives of the Communications Decency Act is section 230, which chapter 640 works.

The Indian comparison is exact and worth making. Section 66A of the Indian Act was struck down for vagueness and overbreadth in Shreya Singhal, which cites Reno among other American authority, and the two decisions rest on the same reasoning applied under different constitutional texts.

Contents This chapter on its own page

munotes.in357

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Three

The Computer Fraud and Abuse Act

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The Computer Fraud and Abuse Act is the American section 43 and section 66 in one provision, and its whole difficulty is the words "exceeds authorized access".

In the wording a student can write in an exam: the Computer Fraud and Abuse Act, enacted in 1986 and codified at title 18 United States Code section 1030, creates seven offences turning on accessing a computer without authorisation or exceeding authorised access, or on causing damage or trafficking in passwords or extortion, provides both criminal penalties and, in subsection (g), a civil action for a person who suffers damage or loss, and applies to a "protected computer", a term so widely defined that it now reaches any computer connected to the internet.

What the Act is and where it came from

It began as a narrow statute about government and financial computers in 1984 and 1986, and was widened repeatedly.

Its architecture is a single section. Subsection (a) creates the offences, subsection (b) covers attempt and conspiracy, subsection (c) sets the penalties, subsection (e) contains the definitions, and subsection (g) creates a civil action.

Its Indian analogue is sections 43 and 66 of the Information Technology Act together, and chapters 1100 and 1180 work those. The parallel is close: both statutes attach a civil remedy and a criminal penalty to the same conduct, and both define that conduct as unauthorised access.

The seven offences in subsection (a)

(a)(1): espionage. Having knowingly accessed a computer without authorisation or exceeding authorised access, obtaining classified or restricted national security information, and wilfully communicating or retaining it.

(a)(2): obtaining information. Intentionally accessing a computer without authorisation or exceeding authorised access, and thereby obtaining information from a financial record of a financial institution or card issuer, from any department or agency of the United States, or from any protected computer.

Note how wide the third limb is. Obtaining any information at all from any protected computer. Reading a web page you were not supposed to read is, on the face of the words, within it.

(a)(3): government computers. Intentionally accessing without authorisation a non-public computer of a department or agency of the United States.

(a)(4): fraud. Knowingly and with intent to defraud accessing a protected computer without authorisation or exceeding authorised access, and by means of such conduct furthering the intended fraud and obtaining anything of value.

(a)(5): damage. Three limbs of decreasing gravity. (A) Knowingly causing the transmission of a program, information, code or command and thereby intentionally causing damage without authorisation. (B) Intentionally accessing without authorisation and thereby recklessly causing damage. (C) Intentionally accessing without authorisation and thereby causing damage and loss.

The (a)(5) structure is instructive, because it grades by mental element: intentional damage by transmission; reckless damage on unauthorised access; and damage in fact on unauthorised access.

Contents This chapter on its own page

munotes.in363

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Four

Section 230 and the American Safe Harbour

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

Twenty-six words of American statute say that a platform is not the publisher of what its users say, and the modern internet was built on them.

In the wording a student can write in an exam: section 230 of the Communications Decency Act of 1996, codified at title 47 United States Code section 230, provides in subsection (c)(1) that no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider, and in subsection (c)(2) that no such provider or user shall be held liable on account of any voluntary action taken in good faith to restrict access to material it considers objectionable, so conferring an immunity that is not conditional on ignorance, on notice, on takedown or on compliance with any regulation.

The two cases that made it necessary

In Cubby, Inc. v. CompuServe Inc. (1991) a federal district court held that an online service that exercised no editorial control over a forum was a distributor rather than a publisher, and so was liable only if it knew or had reason to know of the defamatory content.

In Stratton Oakmont, Inc. v. Prodigy Services Co. (1995) a New York court held that a service which did moderate its bulletin boards, and advertised that it did, was a publisher of everything on them, and so was liable for a defamatory posting whether or not it knew of it.

Put the two together and the incentive is perverse. A service that moderates nothing is safe; a service that tries to keep its forums clean becomes liable for everything it fails to catch. The law rewarded doing nothing.

Section 230 was enacted to reverse that, and its title, "Protection for private blocking and screening of offensive material", says so.

Subsection (c)(1): the twenty-six words

"No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider."

Four elements, and each has been litigated.

"Provider or user of an interactive computer service." Defined in subsection (f)(2) to mean any information service, system or access software provider that provides or enables computer access by multiple users to a computer server. It covers platforms, hosts, search engines, forums and, because the word "user" is there, individual people who forward or repost.

"Shall not be treated as the publisher or speaker." The immunity operates by removing a legal characterisation rather than by creating a defence, which is why it can be decided at the outset of a case.

"Any information." Not merely defamatory information. The immunity is not confined to defamation and has been applied to negligence, product liability and consumer protection claims founded on third-party content.

Contents This chapter on its own page

munotes.in369

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Five

The DMCA: Notice and Takedown

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

Section 512 is where notice and takedown was invented, and every removal mechanism in Indian law is a version of it.

In the wording a student can write in an exam: section 512 of title 17 of the United States Code, inserted by the Digital Millennium Copyright Act of 1998, creates four safe harbours limiting the monetary liability of a service provider for copyright infringement, namely transitory digital network communications, system caching, information residing on systems or networks at the direction of users, and information location tools, each conditional on stated requirements, and establishes a notice and counter-notice procedure under which a provider that removes material expeditiously on a compliant notice retains the safe harbour, with liability under subsection (f) for a knowing material misrepresentation in a notice.

Why copyright needed its own regime

Because section 230 does not apply to it. Subsection (e)(2) of section 230 excludes intellectual property law, and chapter 640 records the exclusion. So the platform immunity that answers a defamation claim answers no copyright claim at all.

And because copyright liability in American law is strict as to the primary act and broad as to secondary liability. A service on which users upload infringing files faces contributory liability for knowingly inducing or materially contributing, and vicarious liability where it has the right and ability to supervise and a direct financial interest.

So without section 512 the exposure would have been unlimited, and the compromise reached in 1998 was that the provider gets a safe harbour and the copyright owner gets a fast, cheap removal mechanism.

The four safe harbours

Subsection (a): transitory digital network communications. Transmitting, routing or providing connections for material, or intermediate and transient storage in the course of it, where the transmission was initiated by or at the direction of a person other than the provider; carried out by an automatic technical process without selection of the material; the provider does not select the recipients except as an automatic response; no copy is ordinarily accessible to anyone other than anticipated recipients and none is maintained longer than reasonably necessary; and the material is transmitted without modification of its content.

This is the mere conduit, and article 12 of the European e-Commerce Directive says the same thing in different words. Chapter 660 works it.

Subsection (b): system caching. Intermediate and temporary storage of material made available by another and transmitted at the direction of another, carried out by an automatic technical process for the purpose of making it available to users who subsequently request it, subject to conditions about not modifying the material, complying with refreshing rules, not interfering with technology returning hit information to the originator, honouring conditions on access such as passwords, and removing material on notice where it has been removed at the originating site.

Contents This chapter on its own page

munotes.in375

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Six

Europe: the e-Commerce Directive

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The e-Commerce Directive divided intermediaries into three functions, gave each an immunity, and forbade any general duty to monitor, and every later regime in the world is a variation on it.

In the wording a student can write in an exam: Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the internal market, requires Member States to allow contracts to be concluded by electronic means under article 9, exempts from liability a provider acting as a mere conduit under article 12, a provider engaged in caching under article 13 and a hosting provider under article 14, in each case on stated conditions, and by article 15 forbids Member States from imposing a general obligation to monitor or actively to seek facts indicating illegal activity.

The Directive's place

It is the European counterpart of Chapter III of the UNCITRAL Model Law and of Chapter XII of the Indian Act at once, and it predates section 79 in its present form by eight years.

Its purpose is the internal market, and that shapes it. Recital 8 says the objective is to create a legal framework to ensure the free movement of information society services between Member States, and not to harmonise criminal law as such. So the Directive is about removing obstacles to services crossing borders within the Union, and the intermediary immunities exist because divergent national liability rules were such an obstacle.

Its liability provisions have now been carried into the Digital Services Act, Regulation (EU) 2022/2065, which repeats articles 12 to 15 in its own articles 4 to 8 and adds a great deal. Chapter 710 works it. The Directive's articles are still worth learning because they are the original and because Indian and American law were both built against them.

Article 9: contracts by electronic means

Article 9(1): Member States shall ensure that their legal system allows contracts to be concluded by electronic means, and in particular that the legal requirements applicable to the contractual process neither create obstacles for the use of electronic contracts nor result in such contracts being deprived of legal effectiveness and validity on account of their having been made by electronic means.

This is article 11 of the UNCITRAL Model Law and section 10A of the Indian Act, and chapters 80 and 930 work them.

Article 9(2) permits Member States to exclude four categories: contracts creating or transferring rights in real estate, except rental rights; contracts requiring by law the involvement of courts, public authorities or professions exercising public authority; contracts of suretyship and collateral securities granted by persons acting outside their trade, business or profession; and contracts governed by family law or the law of succession.

Contents This chapter on its own page

munotes.in381

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Seven

The General Data Protection Regulation: the Scheme

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The General Data Protection Regulation says that processing personal data is forbidden unless you have a lawful basis, and everything else follows from that inversion.

In the wording a student can write in an exam: Regulation (EU) 2016/679, in force since 25 May 2018, protects natural persons with regard to the processing of personal data, applies by article 3 to processing in the context of an establishment in the Union regardless of where it takes place and to processing by a controller outside the Union of the data of persons in the Union where it relates to offering them goods or services or monitoring their behaviour, states six principles in article 5, requires one of six lawful bases in article 6, imposes conditions on consent in article 7 and on a child's consent in article 8, and prohibits the processing of special categories of data by article 9 save in the ten cases it lists.

The inversion that defines it

Most legal systems permit conduct unless it is prohibited. The Regulation does the opposite for personal data.

Article 6(1) provides that processing shall be lawful only if and to the extent that at least one of six conditions applies. So processing without a basis is unlawful whether or not anybody is harmed, whether or not the data subject objects, and whether or not the processing is reasonable.

Compare section 43A of the Indian Act, which chapter 1040 works. Section 43A creates a liability for negligence in protecting sensitive personal data. It says nothing about whether the data should have been collected. That is the difference between a security provision and a data protection statute, and chapter 200 makes it.

The Digital Personal Data Protection Act, 2023 adopts the European inversion. Section 4 provides that a person may process personal data only in accordance with the Act and for a lawful purpose for which the Data Principal has given consent or for certain legitimate uses. Chapter 1050 works it, and notes that sections 3 to 17 do not come into force until 13 May 2027.

Articles 1 to 3: scope

Article 1 states the subject matter: rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of such data; and article 1(2) says the Regulation protects fundamental rights and freedoms and in particular the right to the protection of personal data.

Article 2, material scope. It applies to processing wholly or partly by automated means and to non-automated processing of data forming part of a filing system. It does not apply to processing by a natural person in the course of a purely personal or household activity, nor to processing by competent authorities for criminal law purposes, which a separate directive governs.

Contents This chapter on its own page

munotes.in387

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Eight

The GDPR: Rights and the Controller's Duties

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The Regulation gives eight rights to the person and about a dozen duties to the organisation, and the duties are drafted so that compliance has to be documented rather than asserted.

In the wording a student can write in an exam: Chapter III of Regulation (EU) 2016/679 confers on the data subject the rights to transparent information, of access, to rectification, to erasure known as the right to be forgotten, to restriction of processing, to notification of recipients, to data portability, to object, and not to be subject to a decision based solely on automated processing; and Chapter IV imposes on the controller the obligations of responsibility and demonstrable compliance, data protection by design and by default, record-keeping, security of processing, notification of a personal data breach to the supervisory authority within seventy-two hours and to the data subject where the risk is high, a data protection impact assessment where the risk is high, and the designation of a data protection officer in the three cases article 37 states.

The rights: Chapter III

Article 12 is the framing article and it is easy to overlook. The controller must take appropriate measures to provide the information under articles 13 and 14 and any communication under articles 15 to 22 in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for information addressed to a child. It must act on a request without undue delay and in any event within one month, extendable by two further months where necessary. Information and communications are provided free of charge, unless requests are manifestly unfounded or excessive.

Articles 13 and 14: the right to information. Article 13 applies where the data is collected from the data subject and article 14 where it is not. Between them they require the controller to state its identity and contact details, the contact details of any data protection officer, the purposes and the lawful basis, the legitimate interests relied on where article 6(1)(f) is used, the recipients, any intended transfer outside the Union and the safeguards, the retention period or the criteria for determining it, the rights available including the right to withdraw consent and to lodge a complaint, whether provision of the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making with meaningful information about the logic involved.

Article 15: the right of access. Confirmation whether personal data is being processed; access to the data; and the same categories of information as articles 13 and 14, together with, where the data was not collected from the data subject, any available information as to its source. The controller must provide a copy of the data undergoing processing.

Contents This chapter on its own page

munotes.in395

The rest of this chapter comes with the notes. See the prices

Chapter Sixty-Nine

The GDPR: Transfers and Enforcement

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

Chapter V says personal data may leave Europe only if the protection travels with it, and the enforcement chapter puts a percentage of worldwide turnover behind everything else.

In the wording a student can write in an exam: Chapter V of Regulation (EU) 2016/679 permits a transfer of personal data to a third country only on the basis of an adequacy decision under article 45, appropriate safeguards under article 46 with enforceable rights and effective remedies, binding corporate rules under article 47, or one of the derogations in article 49, and article 48 provides that a judgment or decision of a third country authority requiring transfer is not a ground for transfer unless based on an international agreement; Chapter VI establishes independent supervisory authorities with the investigative, corrective and authorisation powers in article 58; and Chapter VIII gives rights to complain, to an effective judicial remedy and to compensation, and empowers administrative fines of up to twenty million euros or four per cent of total worldwide annual turnover, whichever is higher.

Why transfers are regulated at all

Because a right that ends at the border is not a right. If a controller could move data to a State with no protection and process it freely there, Chapter III's rights would be defeated by a routing decision.

So Chapter V does not prohibit transfers; it requires the protection to travel. Article 44 states the general principle: any transfer to a third country or international organisation shall take place only if, subject to the other provisions of the Regulation, the conditions in Chapter V are complied with by the controller and processor, including for onward transfers, and all provisions shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.

Article 45: adequacy

A transfer may take place where the Commission has decided that the third country, a territory or one or more specified sectors within it, or the international organisation, ensures an adequate level of protection. Such a transfer requires no specific authorisation.

Article 45(2) lists what the Commission takes into account: the rule of law, respect for human rights and fundamental freedoms, relevant legislation both general and sectoral including on public security, defence, national security and criminal law and the access of public authorities to personal data, and effective and enforceable data subject rights and effective administrative and judicial redress; the existence and effective functioning of one or more independent supervisory authorities with adequate enforcement powers; and the international commitments the country has entered into.

Article 45(3) requires a periodic review at least every four years, and article 45(5) permits repeal, amendment or suspension where a country no longer ensures adequacy.

Contents This chapter on its own page

munotes.in404

The rest of this chapter comes with the notes. See the prices

Chapter Seventy

eIDAS and Electronic Signatures in Europe

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

Europe has three grades of electronic signature where India has two, and the middle grade is what India does not have.

In the wording a student can write in an exam: Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market, commonly called eIDAS, distinguishes an electronic signature, an advanced electronic signature and a qualified electronic signature, provides by article 25(1) that an electronic signature shall not be denied legal effect and admissibility solely because it is in electronic form or does not meet the requirements for a qualified electronic signature, by article 25(2) that a qualified electronic signature shall have the equivalent legal effect of a handwritten signature, and by article 25(3) that a qualified electronic signature based on a qualified certificate issued in one Member State shall be recognised as such in all others.

Why the three-grade structure exists

Because the two extremes are both unsatisfactory as a single rule.

A pure reliability standard, as in article 7 of the UNCITRAL Model Law, gives no advance certainty, and chapter 70 explains the difficulty.

A single prescribed method, as in section 5 of the Indian Act, gives certainty at the price of excluding everything not prescribed, and chapter 300 explains that.

Europe's answer is to recognise everything and to grade it. Anything counts as an electronic signature; those that meet stated technical criteria are advanced; those made with a qualified device on a qualified certificate are qualified and are equivalent to a handwritten signature by operation of law.

Article 3: the three definitions

Article 3(10), electronic signature: data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.

That is all. A typed name, a scanned image, a click on an "I agree" button: each is an electronic signature within the definition, because each is data in electronic form used by the signatory to sign.

Article 3(11), advanced electronic signature: an electronic signature which meets the requirements set out in article 26.

Article 26 states four requirements. It must be uniquely linked to the signatory; it must be capable of identifying the signatory; it must be created using electronic signature creation data that the signatory can, with a high level of confidence, use under his sole control; and it must be linked to the data signed in such a way that any subsequent change in the data is detectable.

Those four are recognisably section 3A(2) of the Indian Act, which chapter 290 works, and both are article 6(3) of the 2001 UNCITRAL Model Law.

Contents This chapter on its own page

munotes.in415

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-One

The Digital Services Act

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

The Digital Services Act keeps the old immunities and adds a ladder of duties that gets steeper the larger the platform is.

In the wording a student can write in an exam: Regulation (EU) 2022/2065 on a Single Market for Digital Services carries forward the liability exemptions of the e-Commerce Directive in its articles 4 to 6 with the prohibition on general monitoring in article 8, and adds a graduated set of due diligence obligations, the lightest applying to all intermediary services, further obligations to hosting services including the notice and action mechanism in article 16 and the statement of reasons in article 17, further obligations to online platforms including internal complaint handling in article 20 and trusted flaggers in article 22, and the heaviest to very large online platforms and very large online search engines designated under article 33, which must assess systemic risks under article 34 and mitigate them under article 35.

Why the Directive was not enough

Because the Directive answered one question and by 2020 there were four.

The Directive answered: when is a provider liable for content it did not create? Chapter 660 works the answer.

It did not answer: what must a provider do when told about illegal content; what must it tell a user whose content it removes; what recourse does that user have; and what obligations should attach to a platform whose scale makes its design choices a matter of public concern.

The Digital Services Act answers all four, and it does so by a ladder.

Articles 1 to 3: what the Regulation is, whom it binds, and its vocabulary

Article 1, subject matter. The aim is to contribute to the proper functioning of the internal market for intermediary services by setting harmonised rules for a safe, predictable and trusted online environment that facilitates innovation and in which the fundamental rights of the Charter, including consumer protection, are effectively protected. It establishes a framework for the conditional exemption from liability of providers of intermediary services, rules on due diligence obligations tailored to categories of provider, and rules on implementation and enforcement.

Notice the order of those three limbs, because it is the architecture of the whole Regulation and the answer to the question of what the Act is: an immunity, a graded set of duties, and a regulator.

Article 2, scope, and this is the extraterritoriality provision. The Regulation applies to intermediary services offered to recipients who have their place of establishment or are located in the Union, irrespective of where the provider is established. It does not apply to a service that is not an intermediary service, does not affect the E-Commerce Directive, and is without prejudice to other Union acts including the Audiovisual Media Services Directive, Union copyright law and the Terrorist Content Regulation.

Contents This chapter on its own page

munotes.in423

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Two

China: the Cybersecurity Law

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

China's Cybersecurity Law begins by saying that cyberspace has sovereignty, and every other feature of the regime follows from that sentence.

In the wording a student can write in an exam: the Cybersecurity Law of the People's Republic of China, adopted in November 2016 and in force from 1 June 2017, declares in article 1 the purpose of safeguarding cyberspace sovereignty, applies by article 2 to the establishment, operation, maintenance and usage of networks within mainland China, imposes on network operators the multi-level protection duties of article 21 including log retention for at least six months, requires real identity information from users under article 24, creates a category of critical information infrastructure with heightened duties and a data localisation obligation in article 37, regulates the collection and use of personal information in articles 41 to 44, requires operators to manage user-published information and to stop and report prohibited information under article 47, and permits temporary restrictions on network communications in specified areas under article 58.

Article 1: cyberspace sovereignty

"This law is formulated to ensure cybersecurity, to safeguard cyberspace sovereignty, national security, and the societal public interest, to protect the lawful rights and interests of citizens, legal persons, and other organizations, and to promote the healthy development of economic and social informatization."

The phrase "cyberspace sovereignty" is doing all the work, and it is a stated legal position rather than a description.

What it asserts is that the network within a State's territory is subject to that State's authority in the same way as anything else within it, so that regulating what enters, what leaves and what is said is an ordinary exercise of sovereignty rather than an interference with a global commons.

Chapter 40 sets out the competing view, that the network is not territorial and that States regulate it only to the extent they can reach the people and businesses involved. China's position rejects that framing and legislates accordingly.

Article 2 gives the sovereignty claim its scope: the law applies to the establishment, operation, maintenance and usage of networks, and to cybersecurity oversight and management, within the mainland territory. So it is territorial and not extraterritorial, which is the opposite of article 3(2) of the European General Data Protection Regulation and of section 75 of the Indian Act. Chapters 670 and 850 work those.

Articles 4 and 5 turn the claim into a programme. Article 4 requires the State to formulate and continuously improve a cybersecurity strategy, to clarify the fundamental requirements and primary goals of cybersecurity, and to put forward cybersecurity policies, work tasks and procedures for key fields. Article 5 requires the State to take measures for monitoring, preventing and handling cybersecurity risks and threats arising both within and outside the mainland territory, to protect critical information infrastructure against attacks, intrusions, interference and destruction, and to punish unlawful and criminal network activities.

Contents This chapter on its own page

munotes.in434

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Three

China: Data Security and Personal Information

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

China finished its regime in 2021 with two statutes: one grading data by how much its loss would hurt the State, and one that reads like the European data protection regulation.

In the wording a student can write in an exam: the Data Security Law of the People's Republic of China, in force from 1 September 2021, establishes a categorical and hierarchical system of data protection under article 21 with a stricter regime for core state data, provides for national security review of data handling activities under article 24 and export controls under article 25, and by article 36 forbids domestic organisations and individuals from providing data stored in China to foreign judicial or law enforcement bodies without the approval of the competent authorities; and the Personal Information Protection Law, in force from 1 November 2021, sets out lawful bases in article 13, individual rights in articles 44 to 50, cross-border transfer requirements in articles 38 to 40 and penalties of up to fifty million yuan or five per cent of the previous year's turnover in article 66.

Why there are three statutes and not one

Because they answer three different questions and China chose to keep them apart.

The Cybersecurity Law asks whether the network is secure. Its unit is the network operator and its concern is the integrity of infrastructure. Chapter 720.

The Data Security Law asks whether data is secure, whoever holds it and whether or not it is personal. Its unit is the data handler and its concern is national security and the public interest.

The Personal Information Protection Law asks whether the individual is protected. Its unit is the personal information handler and its concern is the rights of the person.

India has nothing corresponding to the middle one. There is no Indian statute about non-personal data, and the several committee reports proposing one have not produced legislation. That gap is worth naming in an answer.

The Data Security Law: the grading system

Articles 1 and 2 first, because they set the reach. Article 1 states the purposes: to regulate the handling of data, ensure data security, promote the development and exploitation of data, protect the lawful rights and interests of citizens and organisations, and preserve state sovereignty, security and development interests. Article 2 applies the Law to data handling and security regulation within the mainland territory, and then adds the second paragraph that matters: data handling carried out outside the territory that harms the national security of China, the public interest, or the lawful rights and interests of citizens and organisations is to be pursued for legal responsibility.

Read those two beside the Cybersecurity Law and the change is deliberate. Article 2 of the 2016 Law was purely territorial. Article 2 of this Law claims jurisdiction over conduct abroad by its effects, which is the same technique as section 75 of the Indian Act although the connecting factor differs: India's is a computer resource located in India, China's is harm to Chinese interests. Chapters 720 and 850.

Contents This chapter on its own page

munotes.in444

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Four

The Five Systems Side by Side

Syllabus topic 3.2, "United nations, India, U.S.A, Europe and China."

In one line

Four tables, five systems, and one axis at a time.

In the wording a student can write in an exam: the five systems named by the syllabus may usefully be compared on four axes, namely liability for content published by another, the protection of personal data, the powers of the State over the network, and jurisdictional reach; on each axis the United Nations supplies non-binding models and one convention not yet in force, the United States protects the platform and the speaker most and the data subject least, the European Union regulates by process and by right, China regulates by sovereignty and affirmative duty, and India occupies a middle position in which an immunity conditional on compliance with executive rules does most of the regulatory work.

How to use this chapter

Take one axis, give each system its provision, then say what the difference costs. Chapter 560 sets out the method and this chapter supplies the material.

And remember that the five are not comparable units. The United Nations is not a State and legislates for nobody. The European Union is not a State but has a legislator whose regulations apply directly. India, the United States and China are States, and the United States is a federation in which much of the relevant law is State law. Chapter 560 makes the point and an answer should make it once.

Axis one: liability for content published by another

ProvisionTrigger for removalConditional?Duty to monitor
United NationsModel Law art. 2(e) defines an intermediary and excludes it from being originator or addressee. No liability rule at all
Indias.79 with the IT Rules 2021Court order or government notification, after Shreya Singhal; shorter windows for specified categoriesYes, on function, on knowledge, and on compliance with the Rules, r.7Required for specified categories, r.4(4); and verification of synthetic content, r.3(3)
United Statess.230 CDA, and s.512 DMCA for copyrightNothing required for s.230; a private notice for copyrightNo for s.230; yes for s.512No, s.512(m)
European UnionArts. 4 to 6 DSA, with arts. 16, 17, 20 to 22 and 34 to 35A substantiated private notice gives actual knowledge, art. 16(3)Yes, on function and knowledge; the due diligence duties are separate obligationsNo general obligation, art. 8; own-initiative measures protected, art. 7
ChinaArt. 47 CSLThe operator's own discoveryNo immunity exists; the duty is affirmativeYes, by implication of art. 47

The axis that matters: who decides that content is unlawful?

Nobody need decide in the United States. The platform may act or not, and section 230(c)(2) protects the choice either way.

Contents This chapter on its own page

munotes.in455

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Five

What Cyber Security Means in Law

Syllabus topic 3.3, "Cyber Security"

In one line

Cyber security is a defined term in the Act, it means protecting things and the information in them from six named harms, and the law that delivers it is spread across one section of the Act, four sets of rules, one set of directions and at least five agencies, only two of which the Act creates.

The definition

Section 2(1)(nb) was inserted by the Amendment Act of 2008 and reads:

"cyber security" means protecting information, equipment, devices, computer, computer resource, communication device and information stored therein from unauthorised access, use, disclosure, disruption, modification or destruction

Take it in two halves.

What is protected, which is a list of seven items: information, equipment, devices, computer, computer resource, communication device, and information stored in any of them. The list is deliberately over-inclusive. Note that "information" appears twice, once standing alone and once as information stored in a device, so that data at rest and data in transit are both inside.

What it is protected from, which is a list of six harms: unauthorised access, use, disclosure, disruption, modification and destruction. This is the classical triad of confidentiality, integrity and availability, unpacked into verbs. Disclosure attacks confidentiality. Modification and destruction attack integrity. Disruption attacks availability. Access and use are the gateway to all three.

And the word doing the work in every limb is "unauthorised". Cyber security in Indian law is not about harm; it is about harm by someone who had no right to be there. That is the same idea section 43 uses, and chapter 1100 works it.

Where the definition is actually used

A definition matters only where the defined word appears. Section 2(1)(nb) is used in:

  • section 69B, monitoring and collecting traffic data "for cyber security", which chapter 820 works;
  • section 70B, the Indian Computer Emergency Response Team, whose functions in sub-section (4) are all "in the area of cyber security", chapter 760;
  • section 43A and the SPDI Rules, through the reasonable security practices obligation, chapter 1040;
  • rule 3(1)(f) and rule 3(1)(l) of the IT Rules 2021, the intermediary's cyber security obligations, chapter 1000.

And the definition is not used in section 70 at all. Section 70 protects a system by declaring it, and the standard is set by rules made under section 70(4), not by section 2(1)(nb). Chapter 780.

Cyber security, information security and cyber crime

Three phrases, and the exam rewards keeping them apart.

Information security is the wider idea. It protects information in any form, on paper as much as on a disk, and against any threat, fire and flood as much as intrusion. The classical standard is the ISO 27001 family, which the SPDI Rules name in rule 8.

Contents This chapter on its own page

munotes.in462

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Six

CERT-In and Incident Reporting

Syllabus topic 3.3, "Cyber Security"

In one line

Section 70B creates one agency, gives it six functions, and gives it one hard power, namely to call for information and give directions, backed by an offence carrying a year and a crore.

The section, sub-section by sub-section

Section 70B(1): the Central Government shall appoint an agency called the Indian Computer Emergency Response Team. Not "may". The notification was made on 27 October 2009, and CERT-In had existed as an executive body since 2004; the section put it on a statutory footing.

Sub-sections (2) and (3): a Director General, other officers and employees, and their terms, all as prescribed.

Sub-section (4), the functions, all "in the area of cyber security":

(a) collection, analysis and dissemination of information on cyber incidents;

(b) forecast and alerts of cyber security incidents;

(c) emergency measures for handling cyber security incidents;

(d) coordination of cyber incidents response activities;

(e) issue guidelines, advisories, vulnerability notes and white papers relating to information security practices, procedures, prevention, response and reporting of cyber incidents;

(f) such other functions relating to cyber security as may be prescribed.

Note what is absent from the list: no power to investigate, no power to enter or search, no power to prosecute, and no power to fine. CERT-In collects, forecasts, responds, coordinates and advises.

Sub-section (5): the manner of performing functions and duties shall be as prescribed. That is the rule-making hook for the 2013 Rules.

Sub-section (6), the power that matters:

For carrying out the provisions of sub-section (4), the agency referred to in sub-section (1) may call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person.

Five classes of addressee, and the fifth swallows the other four. "Any other person" means the power reaches anybody at all, and the enumeration exists to make the reach obvious rather than to limit it.

Sub-section (7), the offence: failure to provide the information called for, or to comply with a direction under sub-section (6), is punishable with imprisonment up to one year or a fine up to one crore rupees or both. The fine was raised from one lakh to one crore by the Finance Act, 2017.

Sub-section (8), the gate: no court shall take cognizance except on a complaint made by an officer authorised by CERT-In. Nobody else can set the offence in motion, and that is the practical control on the section.

The Rules of 2013

Made under section 87(2)(zf) read with section 70B(5), notified on 16 January 2014, and formally called the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013. Twenty rules.

Contents This chapter on its own page

munotes.in468

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Seven

The CERT-In Directions of 2022

Syllabus topic 3.3, "Cyber Security"

In one line

Six directions issued on 28 April 2022 under section 70B(6), effective 27 June 2022, which fixed a six-hour reporting window, required 180 days of logs to be kept inside India, and imposed five-year customer records on the providers whose business model is not keeping them.

The instrument

No. 20(3)/2022-CERT-In, dated 28 April 2022, headed "Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe and Trusted Internet".

Three things to notice about its form before its content.

It is a direction, not a rule. No draft was published, no consultation was held, and it was not laid before Parliament. Section 70B(6) requires none of that. Chapter 1420 makes the general point about delegated legislation and its controls; this instrument shows what the absence of controls looks like.

Its recitals borrow the language of section 69. The operative recital says it is expedient "in the interest of the sovereignty or integrity of India, defence of India, security of the state, friendly relations with foreign states or public order or for preventing incitement to the commission of any cognizable offence using computer resource or for handling of any cyber incident". The last limb is the one section 70B actually supports; the rest is borrowed from the interception power, and critics say it is there to make the direction look better grounded than it is.

And it took effect after sixty days, so from 27 June 2022.

Direction (i): synchronised clocks

Every service provider, intermediary, data centre, body corporate and Government organisation shall connect to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to servers traceable to them, for the synchronisation of all their systems clocks. An entity spanning multiple geographies may use another accurate standard source, provided it does not deviate from those two.

Why it is there. A log is evidence only if its timestamps can be correlated with another party's logs. Chapter 1270 on the certificate for electronic evidence makes the same point about admissibility. This is the least controversial of the six.

Direction (ii): the six-hour window

Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report the cyber incidents in Annexure I to CERT-In within 6 hours of noticing them or of being brought to notice of them, by email, telephone or fax.

Annexure I has twenty categories, the ten from the 2013 Annexure plus data breach; data leak; attacks on internet of things devices; attacks affecting digital payment systems; attacks through malicious mobile applications; fake mobile applications; unauthorised access to social media accounts; attacks affecting cloud systems; attacks affecting systems related to big data, blockchain, virtual assets, virtual asset exchanges, custodian wallets, robotics, 3D and 4D printing, additive manufacturing and drones; and attacks affecting systems related to artificial intelligence and machine learning.

Contents This chapter on its own page

munotes.in475

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Eight

Protected Systems and Critical Information Infrastructure

Syllabus topic 3.3, "Cyber Security"

In one line

The Government may declare any computer resource affecting critical information infrastructure to be a protected system, unauthorised access to which carries ten years; and a separate agency under an intelligence organisation exists to protect that infrastructure nationally.

Section 70 before and after 2008

As enacted in 2000, section 70(1) let the appropriate Government declare any computer, computer system or computer network a protected system, by notification. There was no criterion at all. A State could notify anything.

The Amendment Act of 2008 replaced sub-section (1) and added the definition. It now reads:

(1) The appropriate Government may, by notification in the Official Gazette, declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure, to be a protected system.

Explanation. For the purposes of this section, "Critical Information Infrastructure" means the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.

Three changes worth naming. The subject became a computer resource, a wider term than the original three. The power acquired a criterion: the resource must directly or indirectly affect the facility of critical information infrastructure. And critical information infrastructure got a statutory definition, in an Explanation rather than in section 2, which is why it is easy to miss.

Read the definition carefully. It has an effects test with a threshold: incapacitation or destruction must have a debilitating impact on one of four things, national security, economy, public health, or safety. Not any impact. Debilitating.

And note "directly or indirectly". A payroll server that would not itself debilitate anything, but whose compromise gives an attacker a route into a grid control system, is within the power.

The rest of section 70

Sub-section (2): the appropriate Government may by order in writing authorise the persons who may access a protected system. So a protected system has a closed list of authorised persons, and the list is an executive order.

Sub-section (3), the offence:

Any person who secures access or attempts to secure access to a protected system in contravention of the provisions of this section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.

Four points on the offence. It punishes securing access and attempting to secure access equally, so the inchoate form carries the full sentence and section 84C's halving does not apply. It requires no damage, no dishonesty and no intention beyond the access itself; the mental element is doing the act without authorisation. Ten years makes it the heaviest sentence in the Act other than cyber terrorism under section 66F, which carries life. And the fine is mandatory, "shall also be liable to fine", with no ceiling stated.

Contents This chapter on its own page

munotes.in482

The rest of this chapter comes with the notes. See the prices

Chapter Seventy-Nine

The National Cyber Security Policy, and After

Syllabus topic 3.3, "Cyber Security"

In one line

India has had a cyber security policy since 2013 and no cyber security law since ever, the promised strategy has not been published, and the gap has been filled by sectoral regulators issuing binding directions under their own statutes.

First, what a policy is

A policy is not law. The National Cyber Security Policy 2013 was released by the Department of Electronics and Information Technology on 2 July 2013. It was not made under any section of the Act, it creates no obligation, it confers no power, and nothing in it can be enforced by anybody against anybody.

Why it still matters in an examination. It is the only document in which the Government has stated what it is trying to achieve, and the distance between its targets and what exists is the substance of the answer. A question asking for a critical appraisal of India's cyber security framework is answered by setting the policy's promises against the record.

The 2013 Policy: vision and mission

Vision: to build a secure and resilient cyberspace for citizens, businesses and Government.

Mission: to protect information and information infrastructure in cyberspace, build capabilities to prevent and respond to cyber threats, reduce vulnerabilities and minimise damage from cyber incidents, through a combination of institutional structures, people, processes, technology and cooperation.

Its objectives, in the form worth reproducing

The Policy lists fourteen objectives. Grouped, they are:

Institutional. To create a secure cyber ecosystem and a assurance framework; to designate a national nodal agency to coordinate all matters of cyber security, with clearly defined roles and responsibilities; to operate a 24x7 National Critical Information Infrastructure Protection Centre; to create a national level computer emergency response mechanism and sectoral response teams.

Regulatory and assurance. To strengthen the regulatory framework; to encourage adoption of conformity assessment, that is certification against best practice standards, especially ISO 27001; to mandate periodic security audits by empanelled auditors; to enable fiscal benefits for adoption of security practices.

Capability. To create a workforce of five lakh cyber security professionals in five years; to promote research and development including indigenous security technologies; to promote testing and certification of information and communication technology products for trusted supply.

Operational. To enable protection of information in transit and at rest; to develop early warning, vulnerability management and response to threats; to encourage the use of open standards.

Cooperative. To create a culture of cyber security and privacy; to develop public and private partnership; and to enhance global cooperation.

What became of them

Delivered, or partly delivered.

The nodal agency and the protection centre exist. NCIIPC was designated by the Rules of 2013 and CERT-In was already statutory. Chapters 760 and 780.

Contents This chapter on its own page

munotes.in490

The rest of this chapter comes with the notes. See the prices

Chapter Eighty

Interception, Monitoring and Decryption

Syllabus topic 3.3, "Cyber Security"

In one line

Section 69 lets the Government order the interception, monitoring or decryption of any information in any computer resource on six grounds, and every safeguard on that power sits not in the section but in rules made under it, reviewed by a committee of officials rather than by a judge.

The section

Section 69(1), as substituted by the Amendment Act of 2008:

Where the Central Government or a State Government or any of its officers specially authorised by the Central Government or the State Government, as the case may be, in this behalf may, if satisfied that it is necessary or expedient so to do, in the interest of the sovereignty or integrity of India, defence of India, security of the State, friendly relations with foreign States or public order or for preventing incitement to the commission of any cognizable offence relating to above or for investigation of any offence, it may subject to the provisions of sub-section (2), for reasons to be recorded in writing, by order, direct any agency of the appropriate Government to intercept, monitor or decrypt or cause to be intercepted or monitored or decrypted any information generated, transmitted, received or stored in any computer resource.

Take it apart in five moves.

Who. The Central Government, a State Government, or an officer specially authorised. Both governments, unlike section 69A, which is Central only.

On what satisfaction. That it is necessary or expedient. Not necessary. "Or expedient" is the phrase the critics fasten on, because expedience is a lower standard than necessity and appears to sit uneasily with the necessity limb of the Puttaswamy proportionality test. Chapter 1040.

On what grounds, and there are six. Sovereignty or integrity of India; defence of India; security of the State; friendly relations with foreign States; public order; preventing incitement to the commission of any cognizable offence relating to the above. And then a seventh, which is the one that changes everything:

"or for investigation of any offence".

That limb has no parallel in section 69A, in section 69B, or in section 5(2) of the Indian Telegraph Act, 1885. The Telegraph Act permits interception only on a public emergency or in the interest of public safety, and then on the enumerated grounds. Section 69 adds ordinary criminal investigation, of any offence, however trivial. That is the single widest word in the section and the answer to a question asking how section 69 compares with the Telegraph Act.

What may be done. Intercept, monitor or decrypt. Interception is capture in transit. Monitoring is observation over time. Decryption is conversion into intelligible form, defined in rule 2(1)(f).

To what. Any information generated, transmitted, received or stored in any computer resource. So section 69 reaches data at rest, not merely in flight, which the Telegraph Act does not.

Contents This chapter on its own page

munotes.in496

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-One

Blocking Public Access to Information

Syllabus topic 3.3, "Cyber Security"

In one line

Section 69A lets the Central Government order information blocked from public access on the article 19(2) grounds alone, the 2009 Rules give the originator and the intermediary a hearing before a five-member committee, and Shreya Singhal upheld both because of exactly those two features.

The section

Section 69A(1), inserted by the Amendment Act of 2008:

Where the Central Government or any of its officers specially authorised by it in this behalf is satisfied that it is necessary or expedient so to do, in the interest of sovereignty and integrity of India, defence of India, security of the State, friendly relations with foreign States or public order or for preventing incitement to the commission of any cognizable offence relating to above, it may subject to the provisions of sub-section (2), for reasons to be recorded in writing, by order, direct any agency of the Government or intermediary to block for access by the public or cause to be blocked for access by the public any information generated, transmitted, received, stored or hosted in any computer resource.

Three differences from section 69, and each is examinable.

Central Government only. A State cannot block. Under section 69 a State Home Secretary can order interception within the State.

Six grounds, and no seventh. There is no "or for investigation of any offence". The six are the article 19(2) grounds, minus contempt of court, defamation and decency or morality. That omission is what makes the section narrow, and it is the first thing the Supreme Court noticed.

And the object is public access, not content. Blocking stops the public reading; it does not delete, and it does not touch the originator's own copy.

Sub-section (2): procedure and safeguards as prescribed. Sub-section (3): an intermediary that fails to comply is punishable with imprisonment up to seven years and also fine. Note that only the intermediary is punished, not the originator.

The Rules of 2009

Formally the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009, notified as G.S.R. 781(E) under section 87(2)(z) read with section 69A(2). Sixteen rules and a Form.

Rule 1, short title and commencement. The Rules came into force on the date of their publication in the Official Gazette, 27 October 2009, the same day as the interception Rules and the traffic data Rules.

Rule 2, the definitions, and three of them decide how the machinery runs. A Designated Officer is the officer designated under rule 3. A nodal officer is the officer designated under rule 4. An organisation is a Union Ministry or Department, a State Government or Union territory, or a Central agency notified in the Gazette, and a request means a request for blocking access by the public. The Review Committee is again the committee constituted under rule 419A of the Indian Telegraph Rules, 1951, borrowed here as it is in the interception Rules.

Contents This chapter on its own page

munotes.in505

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Two

Monitoring Traffic Data for Cyber Security

Syllabus topic 3.3, "Cyber Security"

In one line

Section 69B lets the Central Government authorise an agency to monitor and collect traffic data for cyber security, which is not content, not authorised by the Home Secretary, and not confined to a named person.

The section

Section 69B(1), inserted in 2008:

The Central Government may, to enhance cyber security and for identification, analysis and prevention of intrusion or spread of computer contaminant in the country, by notification in the Official Gazette, authorise any agency of the Government to monitor and collect traffic data or information generated, transmitted, received or stored in any computer resource.

Sub-section (2): the intermediary or person in charge shall, when called upon, provide technical assistance and extend all facilities to enable online access or to secure and provide online access to the resource.

Sub-section (3): procedure and safeguards as prescribed.

Sub-section (4): an intermediary that intentionally or knowingly contravenes sub-section (2) is punishable with imprisonment up to one year, or a fine up to one crore rupees, or both. The fine was raised from one lakh by the Finance Act, 2017.

And the Explanation defines traffic data:

"traffic data" means any data identifying or purporting to identify any person, computer system or computer network or location to or from which the communication is or may be transmitted and includes communications origin, destination, route, time, data, size, duration or type of underlying service and any other information.

Read the last five words. "And any other information" undoes the specificity of everything before it. On its face the definition is the classical envelope-not-letter distinction: who, to whom, when, how big, how long, by what service. The closing words leave it open.

Four differences from section 69

One: the object. Section 69 reaches information, meaning content. Section 69B reaches traffic data, meaning the metadata about a communication. Who spoke to whom, when and for how long, not what was said.

Two: the authority. Under section 69 the competent authority is the Home Secretary, Union or State. Under section 69B, by rule 2(1)(d) of the 2009 Rules, it is the Secretary to the Government of India in the Department of Information Technology. The power is with the technology ministry, not the home ministry, because the purpose is security of systems rather than law and order.

Three: the purpose. Section 69 has six grounds plus investigation of any offence. Section 69B has one purpose expressed two ways: to enhance cyber security, and for the identification, analysis and prevention of intrusion or the spread of a computer contaminant. Nothing about sovereignty, public order or crime.

Four: the penalty. Section 69(4) is seven years for failing to assist. Section 69B(4) is one year or one crore rupees, and requires the contravention to be intentional or knowing, a mental element section 69(4) does not have.

Contents This chapter on its own page

munotes.in513

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Three

Encryption and the Law

Syllabus topic 3.3, "Cyber Security"

In one line

India has a power to prescribe modes and methods of encryption which has never been exercised, a forty-bit licence condition that predates broadband, a draft policy withdrawn within days in 2015, and a traceability rule that puts the real pressure on encryption without ever using the word.

The section

Section 84A, inserted by the Amendment Act of 2008, in full:

The Central Government may, for secure use of the electronic medium and for promotion of e-governance and e-commerce, prescribe the modes or methods for encryption.

One sentence. Note four things.

"May." The power is discretionary and, seventeen years on, unexercised. No rules have been made under section 84A.

The purposes are enabling, not restrictive. Secure use of the electronic medium, promotion of e-governance and promotion of e-commerce. Nothing about law enforcement, national security or investigation. On its face section 84A is a power to make encryption work, not a power to weaken it.

"Modes or methods." Not standards, not key lengths, not escrow. What "modes or methods" covers is undefined.

And there is no offence. Nothing in the Act punishes using an encryption method other than a prescribed one, because nothing has been prescribed.

Where encryption law actually lives

Since the Act is silent, four other instruments do the work.

The Department of Telecommunications licence conditions. The Internet Service Provider licence has long limited individuals, groups and organisations to encryption of up to forty bits in symmetric key algorithms or their equivalent, with anything stronger requiring the permission of the licensor and the deposit of the decryption key. The licensee itself may not deploy bulk encryption on its network.

Why that number is absurd today. Forty-bit symmetric encryption was breakable by ordinary computers in the 1990s. Every banking session, every messaging application and every website served over the secure hypertext transfer protocol uses very much more. The condition is honoured by nobody and enforced against nobody, and it is the standing example of a rule that has been overtaken by the technology it regulates. It also sits inside a licence rather than in a statute, which is why it never had to survive a challenge.

Sectoral regulators requiring strong encryption. The Reserve Bank of India requires at least 128-bit encryption for internet banking, and the Securities and Exchange Board of India requires strong encryption for market systems. So one arm of the State caps encryption at forty bits by licence while another mandates 128 bits by direction, and both are binding on the same bank.

Rule 8 of the SPDI Rules 2011, which makes the ISO 27001 standard the benchmark for reasonable security practices, and that standard requires cryptographic controls. Chapter 230.

And rule 13(3) of the interception rules 2009, which is the only place in Indian law that squarely addresses what a service provider must do about a key it does not hold: a decryption direction to an intermediary is limited to the extent the information is encrypted by the intermediary or the intermediary has control over the decryption key. Chapter 800.

Contents This chapter on its own page

munotes.in521

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Four

Jurisdiction: the Five Bases

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

Five bases let a State claim criminal jurisdiction, they are territorial, nationality, passive personality, protective and universal, and the internet makes the first one, which is the strongest, do work it was never designed for.

Two questions the word hides

"Jurisdiction" answers two entirely different questions and an answer that runs them together loses marks.

Prescriptive jurisdiction: may this State's law govern this conduct at all? That is what the five bases are about, and what sections 1(2) and 75 answer for the Act.

Adjudicative and enforcement jurisdiction: may this State's courts try the case, and can the judgment be enforced? A State can prescribe for conduct in another country and still be unable to arrest the person or seize the server. Chapter 880 works the second question.

The cyber problem lives in the gap. India can validly make an offence out of what a person in another country did to a computer in Mumbai, and still have no way of reaching that person.

The five bases

One: territorial jurisdiction, which is the strongest and least controversial. A State has jurisdiction over conduct within its territory. It has two forms.

Subjective territoriality: the conduct began here. A person in India sends malware to a server abroad; India has jurisdiction because the act was done here.

Objective territoriality, also called the effects doctrine: the conduct was completed or had its effect here. A person abroad sends malware to a server in India; India has jurisdiction because the harm landed here. The classical authority is the Lotus case, decided by the Permanent Court of International Justice in 1927, where a collision on the high seas caused death aboard a Turkish vessel and Turkey was held entitled to prosecute the French officer of the other ship.

Two: nationality jurisdiction, also called active personality. A State has jurisdiction over its own nationals wherever they are. India uses it in section 4 of the Bharatiya Nyaya Sanhita, 2023, formerly section 4 of the Indian Penal Code, which reaches an offence committed by an Indian citizen anywhere.

Three: passive personality jurisdiction. A State claims jurisdiction because the victim is its national. Historically the most contested basis, and now accepted in limited fields, particularly terrorism and offences against internationally protected persons.

Four: protective jurisdiction. A State claims jurisdiction over conduct abroad by anybody that threatens its essential State interests: counterfeiting its currency, forging its passports, espionage. The connecting factor is the interest harmed, not the actor or the place.

Five: universal jurisdiction. Some offences are of such gravity that any State may try them regardless of where they occurred or whose nationals were involved. Piracy is the historical instance; genocide, war crimes, crimes against humanity and torture are the modern ones. No cyber offence is subject to universal jurisdiction, and an answer that suggests hacking is a universal crime is wrong. That is precisely the gap the Budapest Convention and the new United Nations Convention try to close by treaty rather than by custom. Chapters 600 and 610.

Contents This chapter on its own page

munotes.in527

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Five

The Act Reaching Outside India

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

The Act reaches an offence committed anywhere in the world by anybody of any nationality, on one condition, that a computer, computer system or computer network located in India is involved in the conduct.

The two sections

Section 1(2):

It shall extend to the whole of India and, save as otherwise provided in this Act, it applies also to any offence or contravention thereunder committed outside India by any person.

Section 75:

(1) Subject to the provisions of sub-section (2), the provisions of this Act shall apply also to any offence or contravention committed outside India by any person irrespective of his nationality.

(2) For the purposes of sub-section (1), this Act shall apply to an offence or contravention committed outside India by any person if the act or conduct constituting the offence or contravention involves a computer, computer system or computer network located in India.

Read them as one provision in two parts. Section 1(2) declares the extraterritorial reach; section 75(2) supplies the condition on which it operates. Section 1(2) alone would be an unlimited claim. Section 75(2) is the connecting factor that makes it a claim in objective territoriality rather than an assertion of universal jurisdiction.

The four elements

One: "any offence or contravention". Both words are used deliberately. Offence means the criminal provisions in Chapter XI, sections 65 to 74. Contravention means the civil provisions in Chapter IX, principally section 43 and section 43A, which are adjudicated by an adjudicating officer under section 46. So section 75 carries the compensation jurisdiction abroad as well as the criminal one, and an adjudicating officer may award compensation against a person who has never been in India.

Two: "committed outside India". The section is about conduct abroad. Conduct in India needs no special provision.

Three: "by any person irrespective of his nationality". Nationality is expressly excluded as a factor, which is unusual and deliberate. The Act does not care who the offender is.

Four: "involves a computer, computer system or computer network located in India". This is the condition, and every word of it repays attention.

"Involves" is wider than "targets" or "damages". A machine used as a route, a relay or a store is involved.

"Computer, computer system or computer network", the three defined in section 2(1)(i), (l) and (j). Note what is missing: "computer resource". That is the wider term, defined in section 2(1)(k) as a computer, computer system, computer network, data, computer database or software, and it is the term sections 43, 66, 69, 69A, 69B and 70 all use. Section 75(2) uses the narrower trio, so data located in India, standing alone, does not satisfy section 75(2). That is a drafting inconsistency and a point worth making.

Contents This chapter on its own page

munotes.in532

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Six

Civil Jurisdiction Over an Internet Dispute

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

An Indian civil court takes jurisdiction under section 20 of the Code of Civil Procedure, accessibility of a website in the forum is never enough, and the plaintiff must show that the defendant purposefully availed itself of the forum by a real commercial transaction that caused injury there.

Where an Indian suit begins

Section 20 of the Code of Civil Procedure, 1908. A suit is instituted in a court within whose local limits:

(a) the defendant actually and voluntarily resides, or carries on business, or personally works for gain; or

(b) any of several defendants so resides or carries on business, with the leave of the court or the acquiescence of the others; or

(c) the cause of action, wholly or in part, arises.

And two special statutes reverse the ordinary rule for intellectual property plaintiffs. Section 134(2) of the Trade Marks Act, 1999, and section 62(2) of the Copyright Act, 1957, allow the suit where the plaintiff resides or carries on business. That is why so much of the Indian internet jurisdiction case law is trade mark and copyright litigation: the plaintiff has a choice the ordinary civil plaintiff does not.

The internet question, then, is a question about two phrases: does hosting a website accessible in Delhi mean the defendant carries on business in Delhi under section 20(a), and does it mean part of the cause of action arose in Delhi under section 20(c)?

The American answer: Zippo

Zippo Manufacturing Co. v. Zippo Dot Com, Inc., 952 F. Supp. 1119 (W.D. Pa. 1997).

Facts. The plaintiff was a Pennsylvania company making cigarette lighters. The defendant was a Californian company with offices only in California, operating a website and an internet news service. About three thousand Pennsylvania residents had subscribed by filling in an online application and paying by card, and the defendant had agreements with seven Pennsylvania internet access providers. It was sued in Pennsylvania for trade mark dilution and infringement.

Held. Personal jurisdiction requires minimum contacts, a claim arising out of those contacts, and reasonableness. The court then articulated the sliding scale: "the likelihood that personal jurisdiction can be constitutionally exercised is directly proportionate to the nature and quality of commercial activity that an entity conducts over the internet". It classified websites in three bands.

Passive: the site merely posts information accessible to anybody. No jurisdiction.

Interactive: the user exchanges information with the host. Jurisdiction depends on the level of interactivity and the commercial nature of the exchange.

Integral to the defendant's business, sometimes called active: the defendant clearly does business over the internet with residents of the forum, by knowing and repeated transmission of files. Jurisdiction exists.

Contents This chapter on its own page

munotes.in538

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Seven

Where an Electronic Contract Is Made

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

Section 13 fixes when an electronic record is sent and received and where it is deemed to be sent and received, and the deeming of place is what decides which court can hear an internet contract dispute.

Why a special rule was needed

The general law of contract fixes the place of a contract at the place where acceptance is communicated, subject to the postal exception. Bhagwandas Kedia settled it for instantaneous communication: for a telephone conversation the contract is made where the acceptance is heard, that is at the offeror's end, and not where it is spoken.

An email is neither a letter nor a telephone call. It is not instantaneous, because it sits on servers between sending and reading. It is not a posting, because the sender knows within seconds whether it failed. And it may be read on a device in a fourth country by a person whose office is in a fifth. The common law rules do not decide the case cleanly, so the Model Law supplied a rule and section 13 enacted it.

Section 13 is section 15 of the UNCITRAL Model Law on Electronic Commerce, 1996, adopted almost word for word. Chapter 60.

The section, sub-section by sub-section

Section 13(1), despatch.

Save as otherwise agreed to between the originator and the addressee, the despatch of an electronic record occurs when it enters a computer resource outside the control of the originator.

The test is loss of control, not receipt. The moment the message passes to a resource the sender no longer controls, it is despatched. So a message sitting in a drafts folder or an outbox on the sender's own machine is not despatched; one that has reached the sender's outbound mail server, if that server is outside the sender's control, is.

Section 13(2), receipt. Two cases.

Where the addressee has designated a computer resource for receiving electronic records: receipt occurs when the record enters the designated resource. If the record is sent to a different resource of the addressee, receipt occurs when it is retrieved by the addressee.

Where the addressee has designated no computer resource: receipt occurs when the record enters any computer resource of the addressee.

Note the difference. Sending to the designated address means receipt on arrival, whether or not it is read. Sending to some other address of the addressee means receipt only on retrieval. So the party that designates an address gets certainty, and the party that ignores the designation carries the risk.

Section 13(3), the deeming of place, and the heart of the section.

Save as otherwise agreed to between the originator and the addressee, an electronic record is deemed to be despatched at the place where the originator has his place of business, and is deemed to be received at the place where the addressee has his place of business.

Contents This chapter on its own page

munotes.in544

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Eight

Getting Evidence from Abroad

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

Evidence held abroad is obtained by a treaty request or a letter of request routed through the Central Government, both of which take months, while the logs that answer them are kept for 180 days, and the difference between those two periods is the single most important fact in international cyber crime practice.

Two routes, and the difference between them

A mutual legal assistance treaty request is made under a bilateral treaty between India and another State. India has such treaties with about forty-five countries, and the Ministry of Home Affairs is the central authority that sends and receives them. It is a government-to-government instrument, and the requested State executes it under its own law.

A letter of request, or letter rogatory, is a court-to-court instrument used where there is no treaty or where the treaty does not cover the material. It rests on comity and is not enforceable.

In Indian law both run through Chapter VIII of the Bharatiya Nagarik Suraksha Sanhita, 2023, which replaced Chapter VII-A of the Code of Criminal Procedure, 1973, on 1 July 2024. The provisions were re-enacted with renumbering and are, for present purposes, the same.

The Sanhita provisions

Section 111 defines the terms. A "contracting State" is any country or place outside India with which the Central Government has made arrangements through a treaty or otherwise, so the chapter is not confined to treaty partners.

Section 112, evidence out of India. In the course of an investigation, on the application of the investigating officer or a superior, any Criminal Court may issue a letter of request to a court or competent authority abroad, to examine a person orally, record the statement, require the production of documents or things, and forward the evidence or authenticated copies to the issuing court. The letter is transmitted as the Central Government specifies, sub-section (2). And sub-section (3) is the provision that makes the exercise worthwhile: every statement recorded or thing received is deemed to be evidence collected during the investigation under the Sanhita, so it goes into the charge sheet without further proof of the manner of collection.

Section 113, evidence into India. On receipt of a letter of request from a competent foreign court or authority, the Central Government may, if it thinks fit, forward it to a Chief Judicial Magistrate or a Judicial Magistrate to summon the person and record a statement or cause a document or thing to be produced, or send it to a police officer to investigate as if the offence had been committed within India. The evidence goes back through the Central Government.

Section 114, transfer of persons, for warrants and summonses to and from a contracting State, including prisoners.

Contents This chapter on its own page

munotes.in550

The rest of this chapter comes with the notes. See the prices

Chapter Eighty-Nine

Conflicting Orders and the Global Takedown

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

Four courts have been asked whether an order about internet content can reach the whole world, and they gave four different answers, of which the Indian one is a compromise turned on where the content was uploaded from.

The question

A court in one country finds content unlawful. The platform is global. Two orders are possible.

Geo-blocking: make the content inaccessible from within this country, and leave it available everywhere else.

Global removal: take it down everywhere.

The case for global removal. An order that leaves the content on the platform is easily defeated, by a virtual private network, by visiting the platform's foreign domain, or by anyone abroad linking to it. A remedy that any competent user can circumvent is not a remedy. And when platforms remove content under their own policies they remove it globally, so there is no technical objection.

The case against. The content may be lawful in most of the world. A global order lets the most restrictive State set the rules for everyone, and there are eight thousand of these orders a year from every jurisdiction on earth. Comity requires a court to respect the interests of other States, and a global order respects none.

Yahoo! v. LICRA: the first collision

The French proceedings. In 2000 two French associations, the Ligue Contre le Racisme et l'Antisemitisme and the Union des Etudiants Juifs de France, sued Yahoo! in the Tribunal de Grande Instance de Paris because Nazi memorabilia was being auctioned on Yahoo!'s American site, accessible in France, where the display of such objects is a criminal offence. In November 2000 the Tribunal ordered Yahoo! to take all measures to make access to the auctions impossible from French territory, on a substantial daily penalty, having taken expert evidence that a high proportion of French users could be identified by their addresses.

The American proceedings. Yahoo! sued in the Northern District of California for a declaration that the French orders were unenforceable in the United States because they violated the First Amendment. The District Court granted it in 2001. The Ninth Circuit reversed on appeal, and in 2006, sitting en banc, dismissed the action, a majority holding that the case was not ripe or that personal jurisdiction over the French associations was lacking, without deciding the constitutional question.

Why it matters. It is the first and clearest statement of the problem. France could make the order and could not enforce it in America. America would not enforce it and could not stop it. Both were right under their own law, and there was no forum in which the conflict could be resolved. Yahoo! ultimately removed the material voluntarily.

Contents This chapter on its own page

munotes.in557

The rest of this chapter comes with the notes. See the prices

Chapter Ninety

Data Localisation and Cross-Border Data Flows

Syllabus topic 3.4, "Jurisdictional Issues in Transnational Crimes."

In one line

Data localisation means three quite different things, India has moved from proposing the strictest form to enacting the most permissive, and the hard requirements that survive are in a banking direction and a cyber security direction rather than in any statute.

The three degrees

Get these apart before anything else, because the word "localisation" is used for all three and they are not the same.

Mirroring, the weakest. A copy must be kept in India. The data may still be transferred and processed anywhere. The purpose is access: a regulator or investigator can obtain the copy without a treaty request.

Conditional or restricted transfer, the middle. Data may leave, but only on conditions: an adequacy finding, contractual safeguards, consent, or the approval of an authority. This is the European model under Chapter V of the GDPR, and chapter 700 works it.

Hard localisation, the strongest. The data must be stored and processed only in India and may not be transferred at all. This is the model China applies to the personal information and important data of critical information infrastructure operators under article 37 of the Cybersecurity Law. Chapter 720.

An answer that says "India requires data localisation" without saying which of the three is talking about nothing.

What actually binds in India today

One: the Reserve Bank of India's payment data direction.

The direction of 6 April 2018, on storage of payment system data, requires all payment system providers to ensure that the entire data relating to payment systems operated by them is stored in a system only in India. The data covered is comprehensive: end-to-end transaction details, and information collected, carried or processed as part of the message or payment instruction. Compliance was required within six months.

The clarification that followed permitted processing abroad where the transaction is foreign, provided the data is brought back to India within a short period and deleted from the foreign systems. So the operative model is hard localisation of storage with a narrow processing carve-out.

Why the Reserve Bank of India did it. Unfettered supervisory access. Its stated reason was the need for unrestricted access to payment data for supervisory purposes, given the growth of payment systems and the fact that much of the data was stored abroad.

Two: the CERT-In direction of 28 April 2022, direction (iv). Logs of all information and communication technology systems must be enabled and maintained for a rolling 180 days, and maintained within the Indian jurisdiction. Chapter 770. That is hard localisation of one narrow class of data, imposed by a direction issued under section 70B(6).

Three: sectoral rules. The insurance regulator requires policyholder records to be held in India; the Department of Telecommunications imposes conditions through licences; and the Ministry of Health's electronic health record standards contemplate storage in India.

Contents This chapter on its own page

munotes.in564

The rest of this chapter comes with the notes. See the prices

Module IV

munotes.in

Chapter Ninety-One

What an Electronic Contract Is

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

An electronic contract is an ordinary contract whose formation happens in electronic form, and there are six recognisable kinds, differing not in their law but in how much the customer can be said to have agreed to.

First, what the Act does and does not do

The Act does not create a new species of contract. It removes obstacles. Four provisions do the work.

Section 4 satisfies a requirement of writing. Section 5 satisfies a requirement of signature. Section 10A says a contract is not unenforceable merely because it was formed electronically. Section 13 says when and where despatch and receipt occur.

Everything else is the Indian Contract Act, 1872. Offer, acceptance, consideration, capacity, free consent, lawful object. There is no separate law of electronic contracts and an answer that suggests otherwise is wrong. Chapters 300, 930 and 870.

The six kinds

One: exchange of email. Two parties negotiate and conclude by messages. Legally the least difficult of all: it is offer and acceptance in writing, and the only novelty is fixing time and place, which section 13 does. Trimex International v. Vedanta Aluminium is the Indian authority that an email exchange makes a binding contract, and chapter 930 works it.

Two: electronic data interchange. Structured messages exchanged directly between the computer systems of two businesses in an agreed format, typically for purchase orders, invoices and shipping notices. It is machine to machine, but it operates under a framework agreement signed on paper by the two businesses beforehand, which is what makes it unproblematic. The Model Law was drafted with electronic data interchange principally in mind, and section 2(1)(t)'s definition of an electronic record still shows it. Chapter 60.

Three: the website contract. A customer selects goods, fills a form, pays, and receives a confirmation. The contract law question is whether the listing is an offer or an invitation to treat, which chapter 920 answers.

Four: shrink-wrap. The oldest of the forms, and it predates the internet. Software was sold in a box with the licence terms printed inside or visible through the wrapping, and the buyer was told that tearing the wrapping accepted them. The obvious objection is that the buyer paid before seeing the terms, so the terms came after the contract was complete. American courts split on it, and the case usually cited for enforceability is ProCD v. Zeidenberg, decided by the Seventh Circuit in 1996, which reasoned that the vendor may make the offer and specify acceptance by conduct after an opportunity to read and return.

Five: click-wrap. The terms are displayed, and the user must click an affirmative control, "I agree" or "I accept", before proceeding. This is the strongest form, because the user is shown the terms and does a positive act, and because the platform can prove both. It is what almost every online service now uses.

Contents This chapter on its own page

munotes.in571

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Two

Offer and Acceptance Online

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

A website listing is almost always an invitation to treat, the customer's order is the offer, the seller's confirmation is the acceptance, and section 13 of the Information Technology Act rather than the postal rule tells you when and where that acceptance takes effect.

The provisions in play

From the Indian Contract Act, 1872.

Section 2(a), a proposal: when one person signifies to another his willingness to do or abstain from doing anything, with a view to obtaining the assent of that other.

Section 2(b), a promise: when the person to whom the proposal is made signifies his assent, the proposal is said to be accepted.

Section 4, communication: the communication of a proposal is complete when it comes to the knowledge of the person to whom it is made. The communication of an acceptance is complete as against the proposer when it is put in a course of transmission to him so as to be out of the power of the acceptor, and as against the acceptor when it comes to the knowledge of the proposer.

Section 5, revocation: a proposal may be revoked at any time before the communication of its acceptance is complete as against the proposer, and not afterwards.

Section 7, acceptance must be absolute and unqualified.

Section 13, consent: two or more persons are said to consent when they agree upon the same thing in the same sense.

From the Information Technology Act: section 10A on validity, section 11 on attribution, section 12 on acknowledgment and section 13 on time and place.

Is a website listing an offer?

Almost always not. It is an invitation to treat, and there are three reasons.

Stock is finite. If a listing were an offer, every customer who clicked would form a contract, and a seller with ten units and a thousand orders would be in breach nine hundred and ninety times.

Pricing errors. A misprice of a rupee instead of a lakh would bind the seller to every order placed before it was noticed.

And the sellers say so. Every substantial platform's terms state that the display is an invitation to offer, that the customer's order is an offer, and that the contract is formed only when the seller despatches the goods or sends a specified confirmation. That is a term of the click-wrap the customer accepted, and it settles the question between those parties.

The common law analogy is the shop window and the self-service shelf, Pharmaceutical Society of Great Britain v. Boots Cash Chemists, where goods on a shelf were an invitation to treat and the offer was made at the till. A website is a self-service shelf.

Contents This chapter on its own page

munotes.in577

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Three

The Validity of an Electronic Contract: Section 10A

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

Section 10A says a contract is not unenforceable merely because it was made electronically, and it was inserted in 2008 to close an argument that the courts had already decided the same way without it.

The section

Section 10A, inserted by the Amendment Act of 2008 with effect from 27 October 2009:

Where in a contract formation, the communication of proposals, the acceptance of proposals, the revocation of proposals and acceptances, as the case may be, are expressed in electronic form or by means of an electronic records, such contract shall not be deemed to be unenforceable solely on the ground that such electronic form or means was used for that purpose.

Four things to notice.

It covers four communications, not two. Proposals, acceptances, revocation of proposals and revocation of acceptances. The last two are what sections 4 and 5 of the Indian Contract Act make so important, and section 10A puts them beyond argument.

It is negatively phrased. It does not say an electronic contract is valid. It says such a contract shall not be deemed unenforceable solely on the ground that electronic means were used. That is the functional equivalence technique of the Model Law, and chapter 70 works it.

"Solely" is the operative word. Every other ground of unenforceability survives untouched: want of capacity, absence of consideration, unlawful object, uncertainty, want of free consent, and the First Schedule exclusions.

And it is derived from article 11 of the Model Law, which provides that in the context of contract formation, unless otherwise agreed, an offer and its acceptance may be expressed by means of data messages, and a contract shall not be denied validity or enforceability on the sole ground that a data message was used. India's version drops "unless otherwise agreed" and adds revocation. Chapter 60.

Why it was needed

The position before 2009 was arguable but not settled.

The argument that an electronic contract was already good. Section 10 of the Contract Act requires free consent, competence, lawful consideration and object, and that the agreement not be expressly declared void; it says nothing about form. Section 9 recognises contracts made otherwise than in words. Sections 4 and 5 of the Information Technology Act already satisfied requirements of writing and signature. On that reasoning, nothing in Indian law ever made an electronic contract unenforceable.

The argument the other way was not that electronic contracts were void, but that a party might resist enforcement on the ground that the statute recognising electronic records did so only for the purposes it named, that section 1(4) excluded certain documents, and that the Act's silence on contract formation was deliberate. The point had never been decided, and uncertainty is itself a cost in commerce.

Contents This chapter on its own page

munotes.in584

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Four

Attribution of an Electronic Record

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

Section 11 attributes an electronic record to the originator in three cases, personally, by an authorised agent, or by a machine programmed on the originator's behalf, and it says nothing at all about the record sent by somebody who stole the password.

The section

11. Attribution of electronic records. An electronic record shall be attributed to the originator--

(a) if it was sent by the originator himself;

(b) by a person who had the authority to act on behalf of the originator in respect of that electronic record; or

(c) by an information system programmed by or on behalf of the originator to operate automatically.

"Originator" is defined in section 2(1)(za): a person who sends, generates, stores or transmits any electronic message, or causes any electronic message to be sent, generated, stored or transmitted to any other person, but does not include an intermediary.

Clause (a), the originator personally. The simple case, and it needs proof of who was at the keyboard.

Clause (b), an authorised agent. Ordinary agency, with the added requirement that the authority be "in respect of that electronic record". So general authority to correspond is not authority to send this particular record, and a company's employee with access to a mailbox is not for that reason authorised to bind it.

Clause (c), the machine. A record sent by an information system programmed by or on behalf of the originator to operate automatically. This is the provision that makes automated ordering, automated confirmations and algorithmic trading work. The person who set the machine going owns what it sends, and it does not matter that no human read the message before it left. Chapter 920.

Note what clause (c) does not say. It does not require the originator to have intended this particular message, or to have foreseen it. If the system was programmed by or on behalf of the originator, its output is the originator's. That is a strict rule, and it is deliberate: a party dealing with a machine must be able to rely on it.

Why the section is thinner than the Model Law

Article 13 of the UNCITRAL Model Law, from which section 11 is taken, has five paragraphs. India enacted the substance of two.

The Model Law adds two entitlements the Act omits. Article 13(3) allowed the addressee to regard a data message as the originator's and act on it where the addressee properly applied an agreed authentication procedure, or where the message resulted from the actions of a person whose relationship with the originator enabled that person to gain access to the originator's authentication method. And article 13(4) took that entitlement away where the addressee had received notice that the message was not the originator's, or knew or should have known, by exercising reasonable care or using an agreed procedure, that it was not.

Contents This chapter on its own page

munotes.in590

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Five

Acknowledgment of Receipt

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

Section 12 lets the originator ask for an acknowledgment, tells you what counts as one where no form was stipulated, and provides that where the originator made receipt of an acknowledgment a condition of being bound, a record never acknowledged is deemed never to have been sent.

The section

Sub-section (1), what counts as an acknowledgment. Where the originator has not stipulated that the acknowledgment be given in a particular form or by a particular method, an acknowledgment may be given by:

(a) any communication by the addressee, automated or otherwise; or

(b) any conduct of the addressee, sufficient to indicate to the originator that the electronic record has been received.

So the default is generous. An automated read receipt counts. A reply counts. And conduct counts: shipping the goods, paying the invoice, acting on the instruction. The addressee cannot avoid acknowledging by simply not replying if its conduct shows the record arrived.

Sub-section (2), the binding condition. Where the originator has stipulated that the electronic record shall be binding only on receipt of an acknowledgment, then unless the acknowledgment has been received, the electronic record shall be deemed to have been never sent by the originator.

Read that carefully, because it is counter-intuitive. The consequence is not that the record is ineffective, or unenforceable, or of no legal consequence. It is deemed never to have been sent. That is the strongest deeming in the whole Act, and its effect is to unwind the transaction to the point before despatch.

Sub-section (3), the no-stipulation case with a chase. Where the originator has not stipulated that the record shall be binding only on receipt of an acknowledgment, and no acknowledgment has been received within the time specified or agreed, or within a reasonable time if none was specified, the originator may give notice to the addressee stating that no acknowledgment has been received and specifying a reasonable time by which it must be received; and if none is received within that time, the originator may, after giving notice to the addressee, treat the electronic record as though it has never been sent.

The difference between (2) and (3), which is the whole chapter

Sub-section (2)Sub-section (3)
StipulationThe originator stipulated that the record binds only on acknowledgmentNo such stipulation
TriggerNon-receipt of the acknowledgmentNon-receipt within the specified or a reasonable time
Notice required?NoYes, and a second notice before treating it as unsent
EffectThe record is deemed never sent, automaticallyThe originator may treat it as never sent
Whose choice?Nobody's; it operates by itselfThe originator's

Three consequences of that difference.

Under (2) the effect is automatic and mandatory. "Shall be deemed". No election, no notice, and the originator cannot waive it by conduct without at least a variation of the stipulation.

Contents This chapter on its own page

munotes.in596

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Six

Enforcing an Electronic Contract

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

An electronic contract is enforced like any other, so the questions are capacity, free consent, unconscionability, the arbitration clause and proof, and each of them behaves slightly differently when the contract was made in four seconds by a person who did not read it.

Capacity

Section 11 of the Indian Contract Act, 1872: a person is competent to contract who is of the age of majority, of sound mind, and not disqualified.

The online problem is that age is asserted, not verified. A tick-box declaring that the user is eighteen proves nothing, and Mohori Bibee v. Dharmodas Ghose holds that an agreement by a minor is void ab initio, not merely voidable, so the platform gets nothing from the declaration.

Three consequences.

The contract is void, and the platform cannot enforce it against the minor.

Restitution is limited. Section 33 of the Specific Relief Act, 1963, allows a court to require a minor who seeks relief to restore benefits, and section 65 of the Contract Act has been held inapplicable to an agreement void because of minority. So a platform that supplied a service to a minor is in a poor position.

And the data protection statute now adds a duty. Section 9 of the Digital Personal Data Protection Act, 2023, requires verifiable consent of a parent or lawful guardian before processing the personal data of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. That is a separate obligation from contractual capacity, it commences on 13 May 2027, and it is what will actually force age assurance. Chapter 1050.

Free consent

Section 14 of the Contract Act: consent is free when not caused by coercion, undue influence, fraud, misrepresentation or mistake.

Undue influence, section 16, is the limb with real work to do. It applies where one party is in a position to dominate the will of the other and uses that position to obtain an unfair advantage, and sub-section (2)(b) includes a relationship where one party's position makes the other's ability to contract on equal terms illusory. A standard form contract with a dominant platform is not automatically within section 16, and no Indian decision has so held, but the argument is available where the terms are unfair and the user has no alternative.

And section 13, consent to the same thing in the same sense, is the provision that bears on browse-wrap: a user who never saw the terms did not consent to them. Chapter 910.

Unconscionable and unfair terms

This is where the marks are, and there are four routes.

The common law route. Central Inland Water Transport Corporation Ltd. v. Brojo Nath Ganguly, decided in 1986, in which the Supreme Court held that a term in a standard form contract between parties of unequal bargaining power, which is unconscionable, unfair and unreasonable, may be struck down under section 23 of the Contract Act as opposed to public policy. The Court expressly contemplated printed contracts of adhesion offered on a take-it-or-leave-it basis.

Contents This chapter on its own page

munotes.in601

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Seven

Consumer Protection in Electronic Commerce

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

The Consumer Protection Act, 2019, brought electronic commerce inside consumer law for the first time, the E-Commerce Rules 2020 impose duties on the marketplace and heavier ones on the inventory seller, and none of it is displaced by the section 79 exemption because the two statutes ask different questions.

What the 2019 Act changed

The Consumer Protection Act, 1986, said nothing about the internet. The 2019 Act, in force from 20 July 2020, changed four things that matter here.

The definition of consumer. Section 2(7) defines a consumer as one who buys goods or hires services for consideration, and the Explanation provides that the expressions "buys any goods" and "hires or avails any services" include offline or online transactions through electronic means, teleshopping, direct selling or multi-level marketing. That single Explanation is what brings electronic commerce inside the Act.

A definition of electronic commerce. Section 2(16): "e-commerce" means buying or selling of goods or services including digital products over digital or electronic network. And section 2(17) defines an "electronic service provider" as a person who provides technologies or processes to enable a product seller to engage in advertising or selling, including an online marketplace or online auction site.

Jurisdiction where the complainant is. Section 34(2)(d) allows a complaint to be filed in the District Commission within whose jurisdiction the complainant resides or personally works for gain. That reverses the ordinary rule of section 20 of the Code of Civil Procedure and is the provision that makes consumer litigation practical against a distant platform. Chapter 860.

And product liability. Chapter VI, sections 82 to 87, creates a statutory product liability action against a product manufacturer, product service provider and product seller, and section 2(37) defines a product seller in terms wide enough to include a person who, in the course of business, imports, sells, distributes or otherwise places a product in the stream of commerce.

The Central Consumer Protection Authority

Sections 10 to 27 create the Central Consumer Protection Authority, which is new in 2019 and has no predecessor.

Its powers: to inquire into violations of consumer rights, unfair trade practices and false or misleading advertisements, on its own motion or on a complaint; to order recall, refund and discontinuance; and under section 21 to issue directions on false or misleading advertisements, with penalties up to ten lakh rupees and up to fifty lakh rupees for a subsequent contravention, and to prohibit an endorser from endorsing for up to one year, and three years on a subsequent contravention.

Why it matters here. It is a regulator that can act without a complainant, which is what the 1986 Act lacked.

The E-Commerce Rules 2020

The Consumer Protection (E-Commerce) Rules, 2020, notified 23 July 2020 under section 101(1)(zg).

Contents This chapter on its own page

munotes.in608

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Eight

Electronic Payments and Their Law

Syllabus topic 4.1, "Formation of E – Contracts. Validity and Enforcement"

In one line

The Act itself contributes one section on cheques, the Payment and Settlement Systems Act, 2007, is the statute that authorises every payment system in India, and where an unauthorised transaction happens the loss is allocated by a Reserve Bank of India circular that turns on how fast the customer reported it.

Section 81A: the Act and the cheque

Section 81A was inserted by the Negotiable Instruments (Amendment and Miscellaneous Provisions) Act, 2002, and it is the only provision of the Information Technology Act about payments at all.

Sub-section (1): the provisions of this Act shall apply to, or in relation to, electronic cheques and truncated cheques, subject to such modifications and amendments as may be necessary for carrying out the purposes of the Negotiable Instruments Act, 1881, made by the Central Government in consultation with the Reserve Bank of India by notification.

Sub-section (2) requires every such notification to be laid before each House of Parliament for thirty days, with the usual power of modification or annulment.

And the Explanation adopts the meanings of "electronic cheque" and "truncated cheque" from section 6 of the Negotiable Instruments Act, 1881, where a cheque in electronic form is one drawn in electronic form using a secure system with a digital signature, and a truncated cheque is one truncated during a clearing cycle by the clearing house or the paying or receiving bank, the physical instrument being retained after generating an electronic image.

Two things follow.

The Act does not define an electronic cheque. It borrows the definition, which is the same technique it uses for the definitions in section 2 that point at other statutes.

And the First Schedule is consistent with it. Section 1(4) with the First Schedule excludes a negotiable instrument other than a cheque. Cheques are inside the Act, everything else negotiable is outside. Chapter 140.

What section 81A is worth in practice. Very little. Cheque truncation is now universal in India through the Cheque Truncation System, but it operates under the Negotiable Instruments Act and Reserve Bank of India directions rather than under this section. The section is examinable because it is in the Act; it is not the law of payments.

The Payment and Settlement Systems Act, 2007

This is the statute that matters. It was enacted because the Reserve Bank of India had been regulating payment systems without a clear statutory basis.

Section 4, the central prohibition: no person other than the Reserve Bank of India shall commence or operate a payment system except under and in accordance with an authorisation issued by the Reserve Bank under the Act. So every unified payments interface application, every card network, every prepaid instrument issuer and every clearing house operates on an authorisation, and operating without one is an offence under section 26(1) punishable with imprisonment up to ten years or a fine up to one crore rupees, or both.

Contents This chapter on its own page

munotes.in615

The rest of this chapter comes with the notes. See the prices

Chapter Ninety-Nine

Artificial Intelligence and the 2026 Amendment

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

On 10 February 2026 the Government inserted two definitions and two deeming provisions into the Intermediary Guidelines, and in doing so made synthetically generated information a category of the Rules rather than a topic of policy.

The instrument

G.S.R. 120(E), dated 10 February 2026, amending the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, in force from 20 February 2026.

It is the fifth instrument in the chain, and the chain should be learned:

NotificationDateWhat it did
G.S.R. 139(E)25 February 2021The principal Rules, superseding the Intermediaries Guidelines Rules, 2011
G.S.R. 794(E)28 October 2022Grievance Appellate Committees, rule 3A; rules 3(1)(m) and (n)
G.S.R. 275(E)6 April 2023Online gaming; the fact check unit in rule 3(1)(b)(v)
G.S.R. 775(E)22 October 2025, in force 15 November 2025Substituted the whole of rule 3(1)(d)
G.S.R. 120(E)10 February 2026, in force 20 February 2026Synthetically generated information

And there is a sixth that is not law. A draft second amendment of 2026 was published for consultation, the consultation closed on 7 May 2026, and the draft carries blanks for its date and notification number. It is a draft and must be described as one.

The first definition: synthetically generated information

Rule 2(1)(wa), inserted:

'synthetically generated information' means audio, visual or audio-visual information which is artificially or algorithmically created, generated, modified or altered using a computer resource, in a manner that such information appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as indistinguishable from a natural person or real-world event

Four elements, and each must be satisfied.

Audio, visual or audio-visual information. Not text. A wholly fabricated article of prose is outside the definition, which is a deliberate and much criticised limit.

Artificially or algorithmically created, generated, modified or altered using a computer resource. Four verbs, and "modified or altered" is important: an authentic photograph algorithmically altered is within the definition, not only a wholly fabricated one.

In a manner that it appears to be real, authentic or true. An obviously stylised or cartoon output is outside.

And depicting an individual or event in a manner that is, or is likely to be perceived as, indistinguishable from a natural person or real-world event. This is the realism threshold, and it is objective in form.

The proviso, which is three exclusions and which a good answer names. Information is not synthetically generated where it arises from:

(a) routine or good faith editing: formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription or compression, that does not materially alter, distort or misrepresent the substance, context or meaning of the underlying material;

Contents This chapter on its own page

munotes.in622

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred

Deepfakes, Labelling and Provenance

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

Every intermediary that offers a tool for making synthetic media must stop the unlawful kinds outright, label and permanently watermark the rest, and never let the label be removed; and a significant social media intermediary must in addition make its users declare and then check the declaration itself.

Rule 3(3): the core obligation

Inserted by G.S.R. 120(E) with effect from 20 February 2026. It applies to an intermediary that offers a computer resource which may enable, permit or facilitate the creation, generation, modification, alteration, publication, transmission, sharing or dissemination of information as synthetically generated information. So it binds the tool provider, not merely the platform where the output is posted.

Clause (a)(i), the prohibition. The intermediary must deploy reasonable and appropriate technical measures, including automated tools or other suitable mechanisms, to not allow any user to create, generate, modify, alter, publish, transmit, share or disseminate synthetic information that violates any law in force, including the Act, the Bharatiya Nyaya Sanhita, 2023, the Protection of Children from Sexual Offences Act, 2012, and the Explosive Substances Act, 1908, and includes synthetic information that:

(I) contains child sexual exploitative and abuse material, non-consensual intimate imagery, or is obscene, pornographic, paedophilic, invasive of another's privacy including bodily privacy, vulgar, indecent or sexually explicit;

(II) results in the creation, generation, modification or alteration of any false document or false electronic record;

(III) relates to the preparation, development or procurement of explosive material, arms or ammunition;

(IV) falsely depicts or portrays a natural person or real-world event by misrepresenting, in a manner likely to deceive, such person's identity, voice, conduct, action, statement, or such event as having occurred, with or without the involvement of a natural person.

Sub-clause (IV) is the deepfake provision, and it should be quoted. Note that it covers voice as well as image, and that it covers a fabricated event as well as a fabricated person.

Note also that the obligation is to prevent, not to remove. Rule 3(3)(a)(i) requires technical measures so as not to allow the user to make the thing in the first place. That is an obligation at the point of generation.

Clause (a)(ii), the labelling and provenance obligation. Every synthetic item not covered by (a)(i), that is every lawful piece of synthetic media, must be:

Prominently labelled in a manner ensuring prominent visibility in the visual display that is easily noticeable and adequately perceivable, or, for audio content, through a prominently prefixed audio disclosure, that can be used to immediately identify that the information is synthetically generated and was created, generated, modified or altered using a computer resource; and

Embedded with permanent metadata or other appropriate technical provenance mechanisms, to the extent technically feasible, including a unique identifier, to identify the computer resource of the intermediary used to create, generate, modify or alter it.

Contents This chapter on its own page

munotes.in629

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred One

Cryptocurrency and Virtual Digital Assets

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

India has no statute regulating cryptocurrency, the Reserve Bank of India's attempt to cut it off from the banking system was quashed as disproportionate in 2020, and what exists instead is a punitive tax, a reporting obligation under the anti-money-laundering law, and a five-year record-keeping direction from CERT-In.

What a cryptocurrency is, mechanically

Three ideas, and a lawyer needs all three to follow the argument.

A public ledger. Every transaction is recorded in a chain of blocks, each block carrying a hash of the previous one, so that altering an old block changes every hash after it. Chapter 270 explains hashing and chapter 1020 the ledger.

Key pairs instead of accounts. A holding is controlled by a private key. Whoever has the key can spend; there is no institution to appeal to, and a lost key is a lost holding. Chapter 260.

And a consensus mechanism by which participants agree which version of the ledger is correct, whether by proof of work, which is computationally expensive, or proof of stake.

Three consequences for law. There is no issuer to regulate, so there is nobody to license. There is no intermediary in the ordinary case, so the classic technique of regulating the bank does not reach it. And possession is the key, so theft is complete when the key is copied and is practically irreversible.

What Indian law calls it

Not a currency. Only the Reserve Bank of India may issue bank notes, under section 22 of the Reserve Bank of India Act, 1934, and nothing else is legal tender. A cryptocurrency is not money in Indian law, and no one is bound to accept it.

"Virtual digital asset" is the statutory term, and it comes from tax rather than from any regulatory statute. Section 2(47A) of the Income-tax Act, 1961, inserted by the Finance Act, 2022, defines it as any information, code, number or token, not being Indian or foreign currency, generated through cryptographic means or otherwise, by whatever name called, providing a digital representation of value exchanged with or without consideration, with the promise or representation of having inherent value, or functioning as a store of value or a unit of account; and includes a non-fungible token and any other token of a similar nature notified by the Central Government.

"Virtual asset service provider" is used by the CERT-In directions of 28 April 2022 and by the anti-money-laundering notification, following the Financial Action Task Force vocabulary.

And note what follows from the drafting. A thing may be a virtual digital asset for tax and be subject to record-keeping under two other instruments, without any statute saying whether it may be issued, traded, advertised or held.

Contents This chapter on its own page

munotes.in637

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Two

Blockchain and the Smart Contract

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

A blockchain is an append-only record kept by many parties at once, a smart contract is a program that runs on it, and a smart contract is usually neither smart nor a contract.

What a distributed ledger actually is

Four mechanisms, and no metaphors.

Records are grouped into blocks, and each block stores the hash of the block before it. A hash is a fixed-length output computed from an input, where any change to the input changes the output unrecognisably. Chapter 270. So altering a record in an old block changes that block's hash, which breaks the link recorded in the next block, and so on to the end. Tampering is therefore detectable, not impossible.

The ledger is held by many participants, each with a full copy. There is no single authoritative copy to attack or to subpoena.

A consensus mechanism decides which candidate block is added. Proof of work makes adding a block computationally expensive, so rewriting history costs more than it is worth. Proof of stake makes it economically expensive by putting the participant's own holding at risk.

And entries are authorised by digital signatures. A participant proves a right to move an entry by signing with a private key, which is the same public key cryptography the Act's own electronic signature scheme uses. Chapters 260 and 280.

Two distinctions that matter legally.

Permissionless against permissioned. A permissionless chain lets anyone join, and has no operator. A permissioned chain admits only approved participants and has one. Almost every enterprise and government use in India is permissioned, and a permissioned chain has an operator who can be regulated, sued and served.

And append-only is not immutable. Nothing prevents the participants from agreeing to rewrite the chain, and it has been done. What the design gives is that a change is visible and expensive, not that it is impossible.

Why the immutability claim is a legal problem

The right to erasure. Article 17 of the GDPR gives a right to erasure, and section 12(3) of the Digital Personal Data Protection Act, 2023, will give a right to erasure of personal data. Chapters 680 and 1050. A design whose selling point is that records cannot be deleted is in direct tension with both, and the answers offered, storing only a hash of the personal data on the chain and the data itself off it, or destroying the key so the data cannot be read, are engineering workarounds whose legal sufficiency has not been tested in India.

Correction. Section 12(2) of the DPDP Act will give a right to correction and completion. On an append-only ledger a correction is a new entry, and the wrong entry remains visible.

And who is the data fiduciary? On a permissionless chain every full node holds a copy of everything. Each is arguably a person determining the purpose and means of processing, and none of them can act alone. The DPDP Act has no provision for it.

Contents This chapter on its own page

munotes.in644

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Three

Cloud Computing and the Internet of Things

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

Cloud computing puts a person's data on somebody else's machine in an unknown country, the internet of things puts a computer in objects nobody thinks of as computers, and Indian law addresses the first through the service level agreement and the second hardly at all.

Cloud computing: the three models

By service.

Infrastructure as a service: the provider supplies raw compute, storage and networking, and the customer runs everything above it. The customer configures the security, and most breaches are the customer's fault.

Platform as a service: the provider supplies a runtime and the customer supplies the application.

Software as a service: the provider supplies the application and the customer supplies only its data. The customer controls nothing technical, and the contract is the only lever it has.

By deployment: public, private, community and hybrid. The legal difference is who else is on the same hardware and where it sits.

And the axis that matters legally is control, which runs opposite to convenience. The more the provider supplies, the less the customer can do about security, location, retention or exit, and the more the contract has to do.

Who is who under Indian law

Under the Information Technology Act.

The provider is an intermediary under section 2(1)(w), because it receives, stores or transmits electronic records on behalf of another. Chapter 1360. So it has the section 79 exemption and the due diligence obligations, and it is not the originator under section 2(1)(za). Chapter 940.

The customer is a body corporate for section 43A, if it possesses, deals with or handles sensitive personal data in a computer resource it owns, controls or operates. The SPDI Rules 2011 make the customer responsible for reasonable security practices, and outsourcing the machine does not outsource the duty. Chapter 230.

Under the DPDP Act, 2023, when it commences on 13 May 2027, the customer is the Data Fiduciary and the provider is a Data Processor, defined in section 2(k) as a person who processes personal data on behalf of a Data Fiduciary. Section 8(2) is the provision to remember: a Data Fiduciary may engage a Data Processor only under a valid contract, and under section 8(1) the Fiduciary is responsible for compliance whether or not the Data Principal has agreed and notwithstanding any agreement to the contrary. Chapter 1050.

Read section 8 twice. Liability cannot be contracted away to the provider. The customer answers to the individual and to the Board, and its recourse against the provider is a matter of contract alone.

Under the CERT-In directions of 28 April 2022. A cloud service provider is expressly named in direction (v), and must keep five years of validated subscriber records. Direction (iv) requires 180 days of logs within Indian jurisdiction, which for a cloud customer means insisting on Indian log retention in the contract. Chapter 770.

Contents This chapter on its own page

munotes.in651

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Four

Privacy After Puttaswamy

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

Nine judges held in 2017 that privacy is a fundamental right under article 21 and Part III, and laid down a three-fold requirement of legality, a legitimate State aim and proportionality against which every State power in this book must now be measured.

The case

Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, decided 24 August 2017 by a Bench of nine judges.

Facts. A challenge to the Aadhaar scheme raised the question whether there is a fundamental right to privacy. Two earlier decisions stood in the way: M.P. Sharma v. Satish Chandra, decided by eight judges in 1954, and Kharak Singh v. State of Uttar Pradesh, decided by six judges in 1962, both said to have held that the Constitution protects no such right. Because those Benches were larger than any that had since said otherwise, the question was referred to nine judges.

Held, and the order disposing of the reference has four clauses:

(i) the decision in M.P. Sharma, which holds that the right to privacy is not protected by the Constitution, stands overruled;

(ii) the decision in Kharak Singh, to the extent that it holds that the right to privacy is not protected by the Constitution, stands overruled;

(iii) the right to privacy is protected as an intrinsic part of the right to life and personal liberty under article 21 and as a part of the freedoms guaranteed by Part III of the Constitution;

(iv) decisions subsequent to Kharak Singh which enunciated that position lay down the correct law.

Six separate judgments were delivered, by Khehar C.J. with Agrawal and Nazeer JJ. through Chandrachud J., and separately by Chelameswar, Bobde, Nariman, Sapre and Kaul JJ. There is no single majority opinion, and the plurality judgment of Chandrachud J. is the one universally cited for the test.

Citation. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.

The three-fold requirement

In the plurality's own words, an invasion of life or personal liberty must meet a three-fold requirement of:

(i) legality, which postulates the existence of law; (ii) need, defined in terms of a legitimate state aim; and (iii) proportionality which ensures a rational nexus between the objects and the means adopted to achieve them

And the reasoning behind each limb, at paragraph 180.

Legality is an express requirement of article 21, because no person may be deprived of life or personal liberty except according to procedure established by law. A measure resting on executive instruction alone fails at the first step.

Need, in terms of a legitimate State aim, ensures that the content of the restricting law falls within the zone of reasonableness mandated by article 14, which is the guarantee against arbitrary State action. Judicial review does not second-guess the legislature's value judgment, but asks whether the aim suffers from palpable or manifest arbitrariness.

Contents This chapter on its own page

munotes.in657

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Five

The Digital Personal Data Protection Act, 2023

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

India's data protection statute was passed in August 2023 with forty-four sections and a Schedule, and its substantive obligations do not bind anybody until 13 May 2027.

The commencement fact, first

The Act received assent on 11 August 2023. Section 1(2) provides that it comes into force on such date as the Central Government may appoint, and different dates may be appointed for different provisions.

The notification is G.S.R. 843(E), dated 13 November 2025, and it stages the Act in three groups:

GroupProvisionsIn force
On publicationSections 1(2), 2, 18 to 26, 35, 38, 39, 40, 41, 42, 43, and 44(1) and 44(3)13 November 2025
One yearSection 6(9) and section 27(1)(d)13 November 2026
Eighteen monthsSections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 except (1)(d), sections 28 to 34, 36, 37, and section 44(2)13 May 2027

Read the middle row. Only two provisions commence at twelve months, and neither is obvious. Section 6(9) obliges a Consent Manager to be accountable to the Data Principal and to act on her behalf as prescribed, and section 27(1)(d) empowers the Board to inquire into a breach of a Consent Manager's conditions of registration. The staging exists so that the Consent Manager machinery, which rule 4 of the 2025 Rules builds, is running a year before the substantive obligations arrive.

Three consequences, and each is worth marks.

Chapters II and III do not bind anyone yet. No obligation of notice, consent, security, breach notification or children's data is in force. No right of access, correction, erasure, grievance or nomination is exercisable.

The Board exists but has nothing to enforce. Sections 18 to 26, establishing it and providing for its composition, are in force. Sections 27 to 34, its powers, procedure, appeal, alternate dispute resolution, voluntary undertakings and penalties, are not, save for the single clause 27(1)(d) at twelve months.

And section 43A of the Information Technology Act survives until 13 May 2027, because section 44(2), which omits it, is in the eighteen-month group. Chapter 1040.

Scope

Section 3(a): the Act applies to the processing of digital personal data within India where the personal data is collected in digital form, or in non-digital form and digitised subsequently.

Section 3(b): it applies also to processing outside India in connection with any activity related to the offering of goods or services to Data Principals within the territory of India. A person-based connecting factor, like article 3(2) of the GDPR, and unlike section 75 of the Information Technology Act, which follows the machine. Chapter 850.

Section 3(c), the exclusions: personal data processed by an individual for a personal or domestic purpose, and personal data made or caused to be made publicly available by the Data Principal herself or by a person under a legal obligation to make it public.

Contents This chapter on its own page

munotes.in664

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Six

The Data Protection Board and Enforcement

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

The Act creates a Board that is not a regulator, an appeal to a tribunal borrowed from telecommunications, penalties payable to the Government and not to the injured person, and a repeal that leaves the individual with no remedy at all.

The Data Protection Board of India

Established under section 18 by notification of the Central Government, and this is one of the few parts of the Act already in force.

Section 19, composition. A Chairperson and such number of Members as the Central Government may notify, all appointed by the Central Government in the prescribed manner. Each must be a person of ability, integrity and standing with special knowledge or practical experience in data governance, administration or implementation of laws relating to social or consumer protection, dispute resolution, information and communication technology, the digital economy, law, regulation or techno-regulation, or any other field the Central Government thinks useful, and at least one must be an expert in the field of law.

Section 20(2), the term: two years, and eligible for re-appointment.

That figure is the single most criticised provision in the Act. A two-year renewable term makes a member dependent on the executive for reappointment, and it is very short by comparison: a Chairperson of the Telecom Regulatory Authority of India serves three years or until sixty-five, and a member of the Central Information Commission serves three years. A body that adjudicates against the Government cannot easily be independent of it on a two-year renewable term.

Rule 17 of the 2025 Rules supplies the appointment machinery: a Search-cum-Selection Committee chaired by the Cabinet Secretary, with the Secretaries of Legal Affairs and of Electronics and Information Technology and two experts, to recommend the Chairperson; and a similar committee chaired by the Secretary of Electronics and Information Technology for other Members. Every member of both committees is appointed by, or is an officer of, the Central Government.

Section 28(1) and rule 20: the Board shall function as a digital office, with receipt of complaints and the allocation, hearing and pronouncement of decisions digital by design, and without requiring the physical presence of any person.

What the Board may do

Section 27(1), five functions, each of which is to inquire and impose a penalty:

on an intimation of a personal data breach under section 8(6), to direct urgent remedial or mitigation measures and to inquire and penalise; on a complaint by a Data Principal, or a reference by the Central or a State Government, or in compliance with a court's directions, to inquire and penalise; on a complaint against a Consent Manager; on an intimation of breach of a Consent Manager's conditions of registration; and on a reference by the Central Government about a breach of section 37(2).

Contents This chapter on its own page

munotes.in674

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Seven

Domain Names and Cybersquatting

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

A domain name is allotted first come first served, it behaves like a trade mark because commerce made it one, India has no statute about it, and the remedies are a passing off suit, an administrative complaint under the international policy, or a complaint under the Indian one.

How a domain name is allotted

The system has three layers.

The Internet Corporation for Assigned Names and Numbers coordinates the domain name system and accredits registrars.

Registries operate individual top level domains: the generic ones such as .com, .org and .net, the country code ones such as .in, and the newer ones. The .in registry is operated by the National Internet Exchange of India.

Registrars sell registrations to the public.

And the allocation rule is first come, first served. Nobody checks whether the applicant has any right to the name. Under rule 2 of the Uniform Domain Name Dispute Resolution Policy the applicant itself is required to determine whether the name "infringes or violates someone else's rights", which is a representation rather than a check.

Two consequences follow, and they are the whole of this chapter. A name can be registered by somebody with no connection to it. And a name is globally unique, so unlike trade marks, which can coexist across classes and countries, only one person in the world can have it.

Why a domain name behaves like a trade mark

Satyam Infoway Ltd. v. Siffynet Solutions Pvt. Ltd., (2004) 6 SCC 145, Supreme Court of India, 6 May 2004.

Facts. The appellant had used "Sify", coined from Satyam Infoway, since 1999, held www.sify.com, was listed on NASDAQ under that name, had applied to register more than forty marks with the prefix, and produced press coverage, advertising and awards showing public association. The respondent used "Siffynet" and "Siffy" for its own internet business from 2001. The trial court granted an injunction; the High Court set it aside, holding among other things that the appellant would suffer no prejudice because it had another domain name.

Held, allowing the appeal and restoring the injunction.

First, that a domain name may be a mark. The original role of a domain name was to provide an address for computers, but the internet has developed from a means of communication into a mode of carrying on commercial activity, and a domain name is now also used as a business identifier. It serves as an address, identifies the site, and distinguishes the business and its goods or services, so it may pertain to the provision of services within section 2(z) of the Trade Marks Act, 1999. A domain name must be peculiar and unique, and where it is used in connection with a business the value of maintaining an exclusive identity becomes critical.

Contents This chapter on its own page

munotes.in684

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Eight

Internet Shutdowns and Access to the Internet

Syllabus topic 4.2, "Emerging New Legal Issues."

In one line

An internet shutdown is ordered under rules made under the telecommunications law and not under the Information Technology Act at all, and the Supreme Court has held that it must be published, temporary, proportionate and reviewable.

Which power is being used

The commonest error in this topic is to say a shutdown is ordered under section 69A. It is not.

Section 69A blocks specified information from public access. It is targeted at content, it requires a Designated Officer and a committee, and it cannot switch off a network. Chapter 810.

A shutdown suspends the service itself. The power comes from section 5(2) of the Indian Telegraph Act, 1885, and the rules made under section 7, namely the Temporary Suspension of Telecom Services (Public Emergency or Public Safety) Rules, 2017. The Telegraph Act was replaced by the Telecommunications Act, 2023, whose sections 20 and 21 re-enact the interception and suspension powers, but the 2017 Rules and the case law about them are the material a student needs.

And before 2017 shutdowns were ordered under section 144 of the Code of Criminal Procedure, 1973, by district magistrates, which is why Anuradha Bhasin deals with both powers.

The Suspension Rules 2017

Rule 2(1): a direction to suspend telecom services may be issued only by an order of the Secretary to the Government of India in the Ministry of Home Affairs, or, in a State, the Secretary to the State Government in charge of the Home Department, and only in an unavoidable circumstance may it be issued by an officer not below Joint Secretary duly authorised by the Union Home Secretary, subject to confirmation by the competent authority within twenty-four hours, failing which it ceases.

Rule 2(2): the order must contain reasons, and a copy goes to a Review Committee.

Rule 2(5): the Review Committee. At the Union level, the Cabinet Secretary, the Secretary of Legal Affairs and the Secretary of the Department of Telecommunications. At the State level, the Chief Secretary, the Law Secretary and another Secretary other than the Home Secretary.

Rule 2(6): the Review Committee shall meet within five working days of the order and record its findings on whether the direction is in accordance with section 5(2).

Note the two gaps the Rules leave: no maximum duration, and no periodic review after the first. Both were filled by the Supreme Court.

Anuradha Bhasin

Anuradha Bhasin v. Union of India, (2020) 3 SCC 637, Supreme Court of India, 10 January 2020.

Facts. Following the constitutional changes in Jammu and Kashmir on 5 August 2019, telecommunications and internet services were suspended and movement restricted under section 144 of the Code. The Executive Editor of a newspaper petitioned, saying she had been unable to publish from 6 August to 11 October 2019, and journalists and others said their work had been prevented. The orders themselves had not been published.

Contents This chapter on its own page

munotes.in692

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Nine

What a Cyber Crime Is

Syllabus topic 4.3, "Cyber Crimes, Penalties and Adjudication"

In one line

"Cyber crime" is not defined in any Indian statute, does not appear as a heading in the Act, and is best understood by asking two questions of a fact pattern: what did the computer do, and who was harmed.

The definition problem

Search the Information Technology Act, 2000, for the words "cyber crime" and you will not find them. Chapter XI is headed "Offences". Section 2 defines "cyber security", "cyber cafe" and "cyber terrorism" through section 66F, but not cyber crime.

Nor is it in the Bharatiya Nyaya Sanhita, 2023, except in one place worth noting: section 111, organised crime, whose definition of a continuing unlawful activity includes "cyber-crimes" among the listed activities, without defining the term.

The Budapest Convention avoids the phrase too. It creates four groups of offences and never calls them cyber crime. Chapter 590.

Why the absence matters. A term with no legal definition cannot be an element of an offence, so nothing turns on whether a given act "is" a cyber crime. The classification is an aid to analysis and to answering examination questions, not a legal test. An answer should say so at the start, and then give the classification anyway, because that is what is being asked for.

The working definition usually given is a crime in which a computer, computer system, computer network or computer resource is the target, the instrument, or an incidental repository of evidence.

The first classification: what the computer did

This is the classification that actually decides which section applies. Every classification of cyber crime in the textbooks starts here, because the role the machine played is what sends a lawyer to one statute rather than another.

The computer as a target. The offence is against the machine or its contents. Nothing analogous existed before computers, so these needed new law. Unauthorised access, damage, contamination, denial of service, and tampering with source code.

The provisions: section 43 read with section 66, section 65 for source code, section 66F for cyber terrorism, section 70 for a protected system. Chapters 1100, 1170, 1180, 1320 and 780.

The computer as instrument. The offence is an old one committed by new means. Cheating, defamation, obscenity, extortion, forgery, theft of trade secrets, harassment. The conduct was criminal before computers; the computer changed only its speed, reach and anonymity.

The provisions: sections 66C, 66D, 66E, 67, 67A and 67B of the Act; and sections 318, 319, 351, 356 and the rest of the Bharatiya Nyaya Sanhita, 2023. Chapters 1200, 1210, 1220, 1230 and 1280.

The computer as evidence. The offence has nothing to do with computers at all, and a computer holds the proof: a murder planned by message, a bribe recorded in a spreadsheet. There is no cyber crime here and no provision of the Act applies, but the whole of the electronic evidence law does. Chapter 1270.

Contents This chapter on its own page

munotes.in699

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Ten

Penalty and Compensation: Section 43

Syllabus topic 4.3, "Cyber Crimes, Penalties and Adjudication"

In one line

Section 43 lists ten things a person may not do to a computer without permission, makes each of them give rise to unlimited compensation without any mental element, and by doing so defines the conduct that section 66 turns into an offence.

The opening words

If any person without permission of the owner or any other person who is in charge of a computer, computer system or computer network,--

Four points before the clauses.

"Without permission" is the whole mental element. There is no requirement of dishonesty, fraud, intention or knowledge. A person who exceeds an authorisation is within the section as much as one who had none.

Permission may come from the owner or from a person in charge, so a system administrator's permission suffices, and a person who has permission from neither is liable.

The section is civil. Its consequence is compensation, adjudicated by an adjudicating officer under section 46, and it is not an offence. Chapter 1120.

And it is the definition section for section 66, which reads "If any person, dishonestly or fraudulently, does any act referred to in section 43". Chapter 1180.

The ten clauses

(a) accesses or secures access to such computer, computer system or computer network or computer resource. The words "or computer resource" were added in 2008, which widened it to data, databases and software.

(b) downloads, copies or extracts any data, computer database or information, including information or data held or stored in any removable storage medium. So copying to a memory stick is within it, and this is the data theft clause.

(c) introduces or causes to be introduced any computer contaminant or computer virus. Both defined in the Explanation.

(d) damages or causes to be damaged the computer, system, network, data, database or any other programmes residing in it. "Damage" is defined as to destroy, alter, delete, add, modify or rearrange any computer resource by any means.

(e) disrupts or causes disruption. The denial of service clause.

(f) denies or causes the denial of access to any person authorised to access by any means. Ransomware fits (c), (d) and (f) at once.

(g) provides any assistance to any person to facilitate access in contravention of the Act, rules or regulations. The clause that reaches an insider who shares a password, and the only clause about helping rather than doing.

(h) charges the services availed of by a person to the account of another person by tampering with or manipulating a computer, system or network. Theft of service, which reaches the salami attack and unauthorised use of a paid account.

(i) destroys, deletes or alters any information residing in a computer resource, or diminishes its value or utility, or affects it injuriously by any means. Inserted in 2008 and the widest clause in the section. Note "diminishes its value or utility": economic harm without physical alteration is enough.

Contents This chapter on its own page

munotes.in705

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Eleven

The Residuary Penalties

Syllabus topic 4.3, "Cyber Crimes, Penalties and Adjudication"

In one line

Section 44 penalises three failures to file or keep records, section 45 penalises everything else the Act does not separately penalise, and both were rewritten by the Amendment Act of 2008 in ways that are usually misreported.

Section 44: failure to furnish

The section applies to a person "required under this Act or any rules or regulations made thereunder" to do one of three things.

(a) Furnish any document, return or report to the Controller or the Certifying Authority. Failure attracts a penalty not exceeding fifteen lakh rupees for each such failure.

(b) File any return or furnish any information, books or other documents within the time specified in the regulations. Failure attracts a penalty not exceeding fifty thousand rupees for every day during which the failure continues.

(c) Maintain books of account or records. Failure attracts a penalty not exceeding one lakh rupees for every day during which the failure continues.

Three things to notice.

The figures were raised in 2008. As enacted in 2000 they were one lakh and fifty thousand rupees for clause (a), five thousand rupees a day for clause (b), and ten thousand rupees a day for clause (c). The present figures of fifteen lakh, fifty thousand a day and one lakh a day are the amended ones, and older textbooks print the old figures.

Clause (a) is per failure; clauses (b) and (c) are per day. A continuing failure to maintain books at one lakh rupees a day is the heaviest civil exposure in the Act after section 43A, and there is no cap.

And the section is addressed to the licensing scheme. The Controller and the Certifying Authorities are the subject matter, so section 44 in practice binds a licensed Certifying Authority and not the public. Chapters 400, 450 and 460.

Section 45: the residuary penalty

As it now stands:

Whoever contravenes any rules, regulations, directions or orders made under this Act, for the contravention of which no penalty has been separately provided, shall be liable to pay a penalty not exceeding one lakh rupees, in addition to compensation to the person affected by such contravention not exceeding--

(a) ten lakh rupees, by an intermediary, company or body corporate; or

(b) one lakh rupees, by any other person.

What the 2008 amendment did, and this is the part usually missed.

As enacted in 2000 section 45 read: "Whoever contravenes any rules or regulations made under this Act, for the contravention of which no penalty has been separately provided, shall be liable to pay a compensation not exceeding twenty-five thousand rupees to the person affected by such contravention or a penalty not exceeding twenty-five thousand rupees."

Contents This chapter on its own page

munotes.in711

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twelve

Adjudication Under the Act

Syllabus topic 4.3, "Cyber Crimes, Penalties and Adjudication"

In one line

An adjudicating officer is a serving executive officer not below the rank of Director who decides claims for compensation under the Act up to five crore rupees, with the powers of a civil court, on a complaint filed in a proforma with a fee calculated on the sum claimed.

Section 46

Sub-section (1): for the purpose of adjudging whether any person has committed a contravention of the Act or of any rule, regulation, direction or order which renders him liable to pay penalty or compensation, the Central Government shall appoint any officer not below the rank of a Director to the Government of India or an equivalent officer of a State Government to be an adjudicating officer, to hold an inquiry in the manner prescribed.

Sub-section (1A), inserted in 2008: the adjudicating officer shall exercise jurisdiction where the claim for damage does not exceed five crore rupees; jurisdiction in respect of a claim exceeding five crore rupees vests with the competent court.

Sub-section (2): the officer must give a reasonable opportunity for making representation, and if satisfied on inquiry that the contravention was committed, may impose such penalty or award such compensation as he thinks fit.

Sub-section (3): no person shall be appointed unless he possesses such experience in the field of Information Technology and legal or judicial experience as may be prescribed.

Sub-section (4): where more than one officer is appointed, the Central Government specifies by order the matters and places for each.

Sub-section (5): every adjudicating officer has the powers of a civil court conferred on the Appellate Tribunal by section 58(2); all proceedings before it are judicial proceedings within sections 193 and 228 of the Penal Code, now sections 229 and 267 of the Bharatiya Nyaya Sanhita, 2023; and it is deemed a civil court for the purposes of sections 345 and 346 of the Code of Criminal Procedure, 1973, and for the execution of its orders.

Section 47: the three factors

While adjudging the quantum of compensation the officer shall have due regard to:

(a) the amount of gain of unfair advantage, wherever quantifiable, made as a result of the default;

(b) the amount of loss caused to any person as a result of the default; and

(c) the repetitive nature of the default.

Note that the three are not exhaustive of what may be considered, but they are the only factors the section names, and an order that does not address them is open to challenge on appeal. Note also that (a) looks at the defaulter's gain and (b) at the claimant's loss, so the two may differ, and (c) makes repetition an aggravating factor.

Contents This chapter on its own page

munotes.in717

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirteen

Compounding and Recovery

Syllabus topic 4.3, "Cyber Crimes, Penalties and Adjudication"

In one line

A contravention may be compounded by an official under section 63 and an offence only by a court under section 77A, and what is awarded and not paid is recovered as an arrear of land revenue with the offender's licence suspended.

Section 63: compounding a contravention

Sub-section (1): any contravention under this Act may, either before or after the institution of adjudication proceedings, be compounded by:

the Controller, or an officer specially authorised by him in this behalf, or the adjudicating officer, as the case may be,

subject to such conditions as that person may specify.

The proviso: the sum shall not in any case exceed the maximum amount of the penalty which may be imposed under the Act for the contravention compounded.

Sub-section (2), the three-year bar: sub-section (1) shall not apply to a person who commits the same or similar contravention within three years from the date on which the first contravention was compounded.

The Explanation makes the position workable: any second or subsequent contravention committed after the expiry of three years from the date of the previous compounding is deemed to be a first contravention. So the clock resets, and a person may compound again once three years have run.

Sub-section (3): where a contravention has been compounded, no proceeding or further proceeding shall be taken against that person in respect of the contravention so compounded.

Rule 11 of the 2003 Rules adds the machinery. An application may be made during the adjudication proceedings; and the proviso permits an application even before the contravention is reported, in which case the contravener must himself state the contravention committed, the likely loss to the various parties, and the amount of compensatory damages tendered. The sum determined is deposited in the office of the adjudicating officer, and may not exceed the maximum penalty. Chapter 1120.

Note what section 63 does not require: no consent of the person affected, and no hearing of that person. Compounding under this section is a transaction between the contravener and the official, and the compounding sum is a payment to the State, not compensation to the victim.

Section 63 against section 77A

This is the distinction, and it is worth a table.

Section 63Section 77A
What is compoundedA contravention, that is a civil default under Chapter IXAn offence under Chapter XI
Who compoundsThe Controller, an officer he authorises, or the adjudicating officerA court of competent jurisdiction
WhenBefore or after the institution of adjudication proceedingsOn an application in the court where the offence is pending trial
Limit on the sumNot exceeding the maximum penalty for the contraventionSet by the court
BarsThe same or similar contravention within three years of a previous compoundingOffences punishable with life or more than three years; where the accused is liable to enhanced or different punishment by reason of a previous conviction; and where the offence affects the socio-economic conditions of the country or is against a child below eighteen or a woman
ProcedureRule 11 of the 2003 RulesSections 265B and 265C of the Code of Criminal Procedure, 1973, now sections 291 and 292 of the Bharatiya Nagarik Suraksha Sanhita, 2023
EffectNo further proceeding on the compounded contraventionDischarge or acquittal in the ordinary way

Contents This chapter on its own page

munotes.in725

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Fourteen

The Appellate Tribunal Today

Syllabus topic 4.4, "Appellate Tribunal"

In one line

There is no Cyber Appellate Tribunal any more; the Appellate Tribunal under this Act is the Telecom Disputes Settlement and Appellate Tribunal, which is established by a different statute and headed by a judge of the Supreme Court or a Chief Justice of a High Court.

Section 48 as it now reads

Sub-section (1), as substituted by the Finance Act, 2017:

The Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997), shall, on and from the commencement of Part XIV of Chapter VI of the Finance Act, 2017 (7 of 2017), be the Appellate Tribunal for the purposes of this Act and the said Appellate Tribunal shall exercise the jurisdiction, powers and authority conferred on it by or under this Act.

Sub-section (2): the Central Government shall specify by notification the matters and places in relation to which the Appellate Tribunal may exercise jurisdiction.

The date is 26 May 2017, when Part XIV of Chapter VI of the Finance Act, 2017, came into force. Chapter 1150 works what that Part did.

And note the definition change too. Section 2(1)(da) now defines "Appellate Tribunal" as the Appellate Tribunal referred to in section 48(1), so every reference in the Act to the Tribunal is a reference to the telecommunications tribunal.

Where the Tribunal actually comes from

Section 14 of the Telecom Regulatory Authority of India Act, 1997, establishes it by notification of the Central Government to do three things:

(a) adjudicate any dispute between a licensor and a licensee, between two or more service providers, or between a service provider and a group of consumers, but not matters within the Competition Act successor to the Monopolies and Restrictive Trade Practices Act, not an individual consumer's complaint maintainable before a consumer forum, and not a dispute between the telegraph authority and any other person under section 7B of the Indian Telegraph Act, 1885;

(b) hear and dispose of an appeal against any direction, decision or order of the Telecom Regulatory Authority of India; and

(c) exercise the jurisdiction, powers and authority conferred on the Appellate Tribunal under the Information Technology Act, 2000, the Appellate Tribunal under the Airports Economic Regulatory Authority of India Act, 2008, and, since section 44(1) of the Digital Personal Data Protection Act, 2023, came into force on 13 November 2025, the Appellate Tribunal under that Act as well.

So one tribunal now hears telecommunications disputes, appeals from the telecommunications regulator, appeals under this Act, airport economic regulation appeals, and appeals from the Data Protection Board. Chapter 1060.

Composition and qualifications

Section 14B: a Chairperson and not more than two Members, appointed by notification by the Central Government, the selection being made in consultation with the Chief Justice of India. Jurisdiction may be exercised by Benches, constituted by the Chairperson with one or two Members; Benches ordinarily sit at New Delhi and at such other places as the Central Government may notify in consultation with the Chairperson; and where a matter ought to be heard by two Members the Chairperson may transfer it accordingly.

Contents This chapter on its own page

munotes.in731

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Fifteen

The Cyber Appellate Tribunal, and What Happened to It

Syllabus topic 4.4, "Appellate Tribunal"

In one line

The Act created a specialist appellate tribunal in 2000, renamed it in 2008, left it without a Presiding Officer from 2011, and abolished it by a Finance Act in 2017, and a student must be able to describe all four stages.

Why this chapter exists

The syllabus prints "Appellate Tribunal" as a topic, and past papers ask for the establishment, composition, jurisdiction and powers of the Cyber Appellate Tribunal. That Tribunal no longer exists. Nine sections of the Act about it were omitted on 26 May 2017.

So an answer must do two things. State what the Tribunal was, because that is what is asked. And state that it was abolished, when, by what, and what took its place, because an answer that describes a dead tribunal as current law is wrong. Chapter 1140.

Stage one: the Cyber Regulations Appellate Tribunal, 2000

As enacted, section 48(1) empowered the Central Government to establish, by notification, one or more appellate tribunals to be known as the Cyber Regulations Appellate Tribunal.

The name tells you the original conception. In 2000 the Act was about digital signatures and certifying authorities, and the Tribunal was designed to hear appeals from the Controller on licensing and from adjudicating officers on contraventions. "Cyber regulations" meant the regulation of certifying authorities, not cyber crime. Chapters 400 and 430.

Section 49 as enacted: the Tribunal shall consist of one person only, to be called the Presiding Officer, appointed by notification by the Central Government.

Section 50 as enacted, qualifications: a person shall not be qualified unless he is, or has been, or is qualified to be, a Judge of a High Court, or is or has been a member of the Indian Legal Service holding a post in Grade I of that Service for at least three years.

Section 51: a term of five years from the date of entering office, or until the age of sixty-five, whichever is earlier.

Stage two: the Cyber Appellate Tribunal, 2008

The Amendment Act of 2008 renamed it the Cyber Appellate Tribunal, and made it a multi-member body: a Chairperson and such number of other Members as the Central Government might notify, selected by the Central Government in consultation with the Chief Justice of India.

It also inserted sections 52A to 52D: powers of superintendence and direction over the Benches; distribution of business among Benches; the Chairperson's power to transfer cases; and section 52D, decision by majority, where two Members of a Bench differ, by reference to the Chairperson.

The renaming reflects what had happened to the Act. By 2008 the Act was about offences, data protection and intermediaries, and the Tribunal's jurisdiction had grown accordingly.

Contents This chapter on its own page

munotes.in739

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Sixteen

Appeals to the Tribunal, and Beyond

Syllabus topic 4.4, "Appellate Tribunal"

In one line

Any person aggrieved by an order of the Controller or an adjudicating officer may appeal to the Tribunal within forty-five days, unless the order was made by consent, and from the Tribunal to the High Court within sixty days on a question of fact or law.

Section 57: the appeal to the Tribunal

Sub-section (1): save as provided in sub-section (2), any person aggrieved by an order made by the Controller or an adjudicating officer under this Act may prefer an appeal to the Appellate Tribunal having jurisdiction in the matter.

Three things about who and what. The appellant is "any person aggrieved", which is wider than a party: a person affected by an order may appeal though not before the officer. The orders appealable are those of the Controller and of an adjudicating officer, and of nobody else, so an order of the Central Government under section 69A is not appealable here. And the Tribunal must be one "having jurisdiction in the matter", which section 48(2) leaves to notification.

Sub-section (2), the consent bar: no appeal shall lie from an order made by an adjudicating officer with the consent of the parties. A settled matter is closed, which is the same principle as section 96(3) of the Code of Civil Procedure. Note that the bar applies only to an adjudicating officer's consent order, not to the Controller's.

Sub-section (3), limitation: forty-five days from the date on which a copy of the order is received by the person aggrieved, in the prescribed form and with the prescribed fee. The proviso allows the Tribunal to entertain a late appeal if satisfied there was sufficient cause for not filing in time.

The clock runs from receipt, not from the date of the order, which matters where an order is served late.

Sub-section (4): on receipt, the Tribunal may, after giving the parties an opportunity of being heard, pass such orders as it thinks fit, confirming, modifying or setting aside the order appealed against.

Sub-section (5): a copy of every order goes to the parties and to the concerned Controller or adjudicating officer.

Sub-section (6): the appeal shall be dealt with as expeditiously as possible, and endeavour shall be made to dispose of it within six months.

Section 58: procedure and powers

Sub-section (1): the Tribunal shall not be bound by the Code of Civil Procedure, 1908, but shall be guided by the principles of natural justice, and, subject to the Act and the rules, shall have power to regulate its own procedure including the place at which it shall have its sittings.

Contents This chapter on its own page

munotes.in746

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Seventeen

Tampering with Computer Source Documents

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 65 punishes concealing, destroying or altering computer source code, but only where the code is required to be kept or is maintained by law, and that last condition is what the whole section turns on.

The section

65. Tampering with computer source documents. Whoever knowingly or intentionally conceals, destroys or alters or intentionally or knowingly causes another to conceal, destroy, or alter any computer source code used for a computer, computer programme, computer system or computer network, when the computer source code is required to be kept or maintained by law for the time being in force, shall be punishable with imprisonment up to three years, or with fine which may extend up to two lakh rupees, or with both.

Explanation. For the purposes of this section, "computer source code" means the listing of programmes, computer commands, design and layout and programme analysis of computer resource in any form.

The four requirements

One: the act. Conceal, destroy or alter. Not copy, and not merely access. A person who takes a copy of source code and leaves the original untouched is outside section 65 and is inside section 43(b) with section 66, and inside the Copyright Act.

Two: the mental element. Knowingly or intentionally for the doing, and intentionally or knowingly for causing another to do it. Both words appear, and either suffices.

Three: the subject matter. Computer source code, defined in the Explanation, used for a computer, computer programme, computer system or computer network.

Four, and this is the condition that decides every case: the code must be "required to be kept or maintained by law for the time being in force".

Read that phrase carefully. It is disjunctive. Either the law requires the code to be kept, or the code is in fact maintained by law. Syed Asifuddin turns on that reading.

Syed Asifuddin

Syed Asifuddin v. State of Andhra Pradesh, Andhra Pradesh High Court, 29 July 2005.

Facts. Reliance Infocomm sold subscribers a third generation handset worth about ten thousand five hundred rupees for an initial payment of about three thousand three hundred and fifty rupees, on terms locking the subscriber to its network for three years. Employees of Tata Teleservices, operating as Tata Indicom, were alleged to be taking those handsets from subscribers who wished to switch, and reprogramming the Electronic Serial Number so that the handset, which was exclusive to Reliance, would work on the Tata network. Sixty-three subscribers had been migrated. A first information report was registered under sections 409, 420 and 120B of the Penal Code, section 65 of this Act, and section 63 of the Copyright Act, 1957. The employees petitioned under section 482 of the Code of Criminal Procedure to quash it.

Contents This chapter on its own page

munotes.in753

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Nineteen

Section 66A, and Shreya Singhal

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 66A punished sending information that was grossly offensive, menacing, or sent to cause annoyance, and it was struck down in its entirety in 2015 because every word in it was undefined and it caught almost every opinion anybody could hold.

The section as it stood

66A. Punishment for sending offensive messages through communication service, etc. Any person who sends, by means of a computer resource or a communication device,

(a) any information that is grossly offensive or has menacing character; or

(b) any information which he knows to be false, but for the purpose of causing annoyance, inconvenience, danger, obstruction, insult, injury, criminal intimidation, enmity, hatred or ill will, persistently by making use of such computer resource or a communication device;

(c) any electronic mail or electronic mail message for the purpose of causing annoyance or inconvenience or to deceive or to mislead the addressee or recipient about the origin of such messages,

shall be punishable with imprisonment for a term which may extend to three years and with fine.

Inserted by the Amendment Act of 2008, in force from 27 October 2009. Note that the punishment is "three years and with fine", so the fine was mandatory, and that under section 77B a three-year offence is cognizable and bailable, so the police could arrest without a warrant.

What was done under it

The arrests are part of the answer, because they show what the words did in practice. A professor was arrested over a cartoon. Two young women were arrested, one for a post questioning a city shutdown and the other for liking it. A businessman was arrested over a post about a politician's son. A student was arrested over a post about a political leader. In each case the content was an opinion, and in each case the arrest was made under a cognizable provision carrying three years.

That pattern is what produced the petitions, and the Supreme Court described the reach of the section by reference to it.

Shreya Singhal v. Union of India

Shreya Singhal v. Union of India, (2015) 5 SCC 1, decided 24 March 2015.

The challenge was to section 66A, to section 69A with the Blocking Rules 2009, and to section 79 with the Intermediary Guidelines Rules 2011. Chapters 810 and 1360.

The framework the Court applied to section 66A. Article 19(1)(a) protects freedom of speech and expression; article 19(2) permits reasonable restrictions only on eight grounds, namely the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, public order, decency or morality, contempt of court, defamation, and incitement to an offence. A restriction outside those grounds cannot be saved.

Contents This chapter on its own page

munotes.in766

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty

Receiving a Stolen Computer Resource, and Identity Theft

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 66B punishes receiving a stolen device and section 66C punishes using another person's password or unique identification feature, and each has a counterpart in the general criminal law which a prosecutor may prefer.

Section 66B: receiving a stolen computer resource

66B. Whoever dishonestly receives or retains any stolen computer resource or communication device, knowing or having reason to believe the same to be a stolen computer resource or communication device, shall be punished with imprisonment of either description for a term which may extend to three years or with fine which may extend to one lakh rupees or with both.

Four elements.

Receives or retains. Retention is enough, so a person who lawfully came by a device and keeps it after learning it is stolen commits the offence.

A stolen computer resource or communication device. "Computer resource" is defined in section 2(1)(k) as a computer, computer system, computer network, data, computer database or software, and "communication device" in section 2(1)(ha) as a cell phone, personal digital assistance or any other device used to communicate, send or transmit text, video, audio or image. So the section reaches stolen data, not merely stolen hardware, which is its principal utility.

"Stolen" is not defined in this Act. The natural source is section 317(1) of the Bharatiya Nyaya Sanhita, 2023: property whose possession has been transferred by theft, extortion, robbery or cheating, or which has been criminally misappropriated or in respect of which criminal breach of trust has been committed, is stolen property, and it ceases to be stolen if it comes into the possession of a person legally entitled to it. Applied to data that definition is awkward, since data can be copied without any transfer of possession, and the point is undecided.

The mental element is double: dishonestly, which imports the intention of causing wrongful gain or loss, and knowing or having reason to believe the thing is stolen. "Reason to believe" is an objective standard and is lower than knowledge.

Section 66B against section 317 of the Sanhita

Section 66BSection 317(2) of the Sanhita
SubjectA stolen computer resource or communication device, so including data and softwareStolen property, defined in section 317(1)
ActDishonestly receives or retainsDishonestly receives or retains
KnowledgeKnowing or having reason to believeKnowing or having reason to believe
PunishmentThree years or one lakh rupees or bothThree years, or fine, or both, with no ceiling on the fine
Aggravated formsNoneSection 317(3), dacoity, and 317(4), habitual receiving, both up to life or ten years; 317(5), assisting in concealment, three years

So the special provision adds one thing, the express inclusion of data and software, and takes away the aggravated forms. A prosecutor dealing with a person who habitually deals in stolen phones would use section 317(4), which carries life, and not section 66B, which carries three years.

Contents This chapter on its own page

munotes.in773

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-One

Cheating by Personation, and Violation of Privacy

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 66D punishes cheating by personation using a computer, and section 66E punishes capturing, publishing or transmitting the image of a private area without consent, and the second is far more tightly drafted than the first.

Section 66D

66D. Whoever, by means of any communication device or computer resource, cheats by personation, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees.

The section borrows both its concepts.

"Cheats" is defined in section 318(1) of the Bharatiya Nyaya Sanhita, 2023, formerly section 415 of the Penal Code: whoever, by deceiving any person, fraudulently or dishonestly induces the person deceived to deliver any property or to consent that any person shall retain property, or intentionally induces the person deceived to do or omit to do anything which he would not do or omit if he were not so deceived, and which act or omission causes or is likely to cause damage or harm to that person in body, mind, reputation or property.

"By personation" is defined in section 319(1): a person cheats by personation if he cheats by pretending to be some other person, or by knowingly substituting one person for another, or representing that he or any other person is a person other than he really is. And the Explanation is the one to remember: the offence is committed whether the individual personated is a real or imaginary person.

So section 66D requires four things: deception; personation, real or imaginary; the inducement and damage or harm that section 318 requires; and that it be done by means of a communication device or computer resource.

And note the sentencing anomaly. Section 66D carries three years. Section 319(2) of the Sanhita, cheating by personation without any computer, carries five years. The special provision is lighter than the general one, which is the opposite of what students expect, and a prosecutor with a serious case will charge both.

What section 66D reaches

Phishing. An email or page pretending to be a bank, inducing the victim to part with credentials, and thereby with money. This is the paradigm case and section 66D is the provision the police charge.

Vishing and smishing, the same by telephone call or text message, since a cell phone is a communication device under section 2(1)(ha).

Fake profiles used to obtain money, including matrimonial and investment frauds, because the Explanation to section 319 covers an imaginary person.

Impersonating an official, a customer service representative or a courier company.

And what it does not reach. A fake profile used to harass but not to cheat, because there is no inducement causing damage or harm of the kind section 318 requires. That conduct is charged under section 79 of the Sanhita where it insults the modesty of a woman, under section 356 for defamation, or under section 78 for stalking. Chapter 1380.

Contents This chapter on its own page

munotes.in778

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Two

Obscenity in Electronic Form

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 67 punishes publishing or transmitting lascivious material in electronic form and section 67A punishes material containing a sexually explicit act, the second carrying nearly twice the sentence, and both are subject to the public good proviso in section 67B.

Section 67

67. Whoever publishes or transmits or causes to be published or transmitted in the electronic form, any material which is lascivious or appeals to the prurient interest or if its effect is such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it, shall be punished on first conviction with imprisonment of either description up to three years and with fine up to five lakh rupees, and on a second or subsequent conviction with imprisonment up to five years and fine up to ten lakh rupees.

The test is in three alternative limbs, and the material need satisfy only one: lascivious; appealing to the prurient interest; or having an effect tending to deprave and corrupt those likely to read, see or hear it.

Those words come from section 292 of the Indian Penal Code, 1860, now section 294 of the Bharatiya Nyaya Sanhita, 2023, and behind them lies the Hicklin test from R. v. Hicklin, decided in 1868, which asked whether the tendency of the matter is to deprave and corrupt those whose minds are open to such immoral influences.

The Indian courts have moved away from Hicklin. In Ranjit D. Udeshi v. State of Maharashtra, decided in 1965, the Supreme Court applied Hicklin while insisting that the work be judged as a whole and that the interests of art, literature and science be weighed. In Aveek Sarkar v. State of West Bengal, decided in 2014, the Court held that the Hicklin test should be discarded in favour of the community standards test: obscenity is to be judged from the point of view of an average person applying contemporary community standards, considering the material as a whole and in its context, and a picture is to be judged by whether it arouses sexual passion in the average viewer rather than by whether it might corrupt the most susceptible.

Note that section 67 was not amended to say so. The words of the section are still the Hicklin words; the change is in how courts read them, and an answer should state both.

What the 2008 amendment did to section 67

As enacted in 2000 section 67 carried, on a first conviction, imprisonment up to five years and a fine up to one lakh rupees, and on a subsequent conviction up to ten years and two lakh rupees.

Contents This chapter on its own page

munotes.in786

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Three

Material Depicting Children

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 67B creates five separate offences about material depicting children, only one of which is publishing, and the Protection of Children from Sexual Offences Act, 2012, sits beside it with heavier sentences and a mandatory reporting duty.

The five clauses

Section 67B punishes whoever:

(a) publishes or transmits or causes to be published or transmitted material in any electronic form which depicts children engaged in sexually explicit act or conduct;

(b) creates text or digital images, collects, seeks, browses, downloads, advertises, promotes, exchanges or distributes material in any electronic form depicting children in obscene or indecent or sexually explicit manner;

(c) cultivates, entices or induces children to online relationship with one or more children for and on a sexually explicit act, or in a manner that may offend a reasonable adult, on the computer resource;

(d) facilitates abusing children online; or

(e) records in any electronic form own abuse or that of others pertaining to a sexually explicit act with children,

with imprisonment up to five years and a fine up to ten lakh rupees on a first conviction, and up to seven years and ten lakh rupees on a second or subsequent conviction.

And the Explanation: "children" means a person who has not completed the age of eighteen years.

What each clause adds

Clause (a) is the publishing offence, the counterpart of sections 67 and 67A.

Clause (b) is the possession and consumption offence, and it is the widest in the Act. It reaches creating text, so written material is included, unlike sections 67E and 66E which are about images. It reaches collecting, seeking, browsing and downloading, so a person who merely looks is within it. And its test is obscene or indecent or sexually explicit, which is wider than clause (a)'s "sexually explicit act or conduct" because it adds obscene and indecent.

Note the consequence. Under sections 67 and 67A mere possession is no offence at all. Under section 67B(b) browsing is. That is the single most important structural difference in this part of the Act.

Clause (c) is the grooming offence. Cultivating, enticing or inducing children into an online relationship, either for a sexually explicit act or in a manner that may offend a reasonable adult. The second limb is very wide and imprecise, and the words "with one or more children" are awkwardly drafted, since the natural reading of the mischief is inducing a child into a relationship with the offender.

Clause (d), facilitating abuse online, is a residual clause with no further definition.

And clause (e) reaches the recording of abuse, including the offender's own, which matters because the recording may precede any publication.

Contents This chapter on its own page

munotes.in794

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Four

Preservation and Retention by Intermediaries

Syllabus topic 4.5, "Offences and Prosecution"

In one line

An intermediary must preserve removed content for a hundred and eighty days, keep a user's registration information for a hundred and eighty days after the registration ends, keep logs of all its systems for a hundred and eighty days inside India, and, from 2027, keep personal data and its logs for at least a year.

Section 67C

67C. Preservation and retention of information by intermediaries.

(1) Intermediary shall preserve and retain such information as may be specified for such duration and in such manner and format as the Central Government may prescribe.

(2) Any intermediary who intentionally or knowingly contravenes the provisions of sub-section (1) shall be liable to penalty which may extend to twenty-five lakh rupees.

Three things to notice.

The section prescribes nothing. It is an enabling provision: what is preserved, for how long, and in what manner and format are all left to rules. Section 67C on its own imposes no obligation at all.

The sanction changed. As inserted in 2008, sub-section (2) provided that the intermediary "shall be punished with an imprisonment for a term which may extend to three years and also be liable to fine". It is now a civil penalty of up to twenty-five lakh rupees, and the imprisonment has gone. So section 67C is no longer an offence, and it is adjudicated under section 46 like any other penalty. Chapter 1120.

And the mental element survives: the contravention must be intentional or knowing.

The three obligations that actually bind

One: rule 3(1)(g) of the IT Rules 2021, preserving removed content for 180 days.

Where, upon receiving actual knowledge under clause (d), on a voluntary basis on violation of clause (b), or on the basis of grievances received under sub-rule (2), any information has been removed or access to which has been disabled, the intermediary shall, without vitiating the evidence in any manner, preserve such information and associated records for one hundred and eighty days for investigation purposes, or for such longer period as may be required by the court or by Government agencies who are lawfully authorised.

Four features. It is triggered by removal, not by hosting, so it applies precisely to material that has gone. It covers the information and associated records, so the account details and the upload log go with it. The words "without vitiating the evidence in any manner" impose a chain of custody obligation on a private party. And the period may be extended by a court or an authorised Government agency, with no maximum.

Two: rule 3(1)(h), retaining registration information for 180 days after registration ends.

Where an intermediary collects information from a user for registration on the computer resource, it shall retain his information for a period of one hundred and eighty days after any cancellation or withdrawal of his registration.

Contents This chapter on its own page

munotes.in800

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Five

Breach of Confidentiality and Privacy

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 72 binds only a person who obtained access by exercising a power under the Act, section 72A binds anybody who obtained personal information while providing services under a contract, and the two are constantly confused.

Section 71: misrepresentation

71. Whoever makes any misrepresentation to, or suppresses any material fact from, the Controller or the Certifying Authority for obtaining any licence or electronic signature Certificate, shall be punished with imprisonment up to two years, or with fine up to one lakh rupees, or with both.

Two elements. A misrepresentation made to, or suppression of a material fact from, the Controller or a Certifying Authority. And the purpose: obtaining a licence or an electronic signature certificate.

So the section is confined to the certification scheme. It is the provision against lying to get a licence under section 21 or a certificate under section 35. Chapters 320 and 430.

Section 72: breach of confidentiality and privacy

72. Save as otherwise provided in this Act or any other law for the time being in force, if any person who, in pursuance of any of the powers conferred under this Act, rules or regulations made thereunder, has secured access to any electronic record, book, register, correspondence, information, document or other material without the consent of the person concerned discloses such material to any other person shall be liable to penalty which may extend to five lakh rupees.

The section has a very narrow gateway, and this is the point of the chapter.

"In pursuance of any of the powers conferred under this Act." The person must have secured access by exercising a power the Act confers. That means the Controller, a Deputy or Assistant Controller, an officer of a Certifying Authority acting under the Act, an adjudicating officer, an officer authorised under section 69, 69A, 69B or 70B, or a police officer acting under section 80.

It does not reach a private party. A bank employee, a hospital, a platform or an outsourcing company does not obtain access under a power conferred by the Act; it obtains access under a contract or in the course of business. Section 72 therefore does not apply to the ordinary data leak, and an answer that says it does is wrong.

The section is directed at the State's own officers, and it is the confidentiality obligation that balances the powers in sections 69 to 70B. Chapters 800 to 820.

Two further points. The act is disclosure without the consent of the person concerned, so consent is a complete answer, and the disclosure must be to any other person. And the opening words, "save as otherwise provided in this Act or any other law", preserve every lawful disclosure, including rule 13(4) of the CERT-In Rules and rule 25(2) of the interception rules. Chapters 760 and 800.

Contents This chapter on its own page

munotes.in806

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Six

Investigating a Cyber Offence

Syllabus topic 4.5, "Offences and Prosecution"

In one line

The Act says only two things about investigation, that an Inspector must do it and that a public place may be entered without a warrant, and every other step comes from the Bharatiya Nagarik Suraksha Sanhita, 2023.

Section 78: who may investigate

78. Notwithstanding anything contained in the Code of Criminal Procedure, 1973, a police officer not below the rank of Inspector shall investigate any offence under this Act.

Two points and a history.

The rank was raised. As enacted the section required an officer not below the rank of Deputy Superintendent of Police. The Amendment Act of 2008 substituted Inspector, which lowered the threshold considerably and was done because too few officers of the higher rank were available for a growing class of cases.

The section is mandatory. "Shall investigate" means an investigation by a Sub-Inspector is without jurisdiction, and the defence takes the point regularly. The consequence is not automatic acquittal, since a defect in investigation vitiates a trial only where prejudice is shown, but it is a real line of attack.

And it displaces the Sanhita only on rank. Everything else, the recording of the first information report, the powers of investigation, the arrest, the search, the charge sheet and the trial, is governed by the Sanhita.

Section 80: entry, search and arrest without a warrant

Sub-section (1): notwithstanding the Code, any police officer not below the rank of Inspector, or any other officer of the Central or a State Government authorised by the Central Government, may enter any public place and search and arrest without warrant any person found there who is reasonably suspected of having committed, or of committing, or of being about to commit any offence under this Act.

The Explanation defines "public place" to include any public conveyance, any hotel, any shop or any other place intended for use by, or accessible to, the public.

Sub-section (2): where the arrest is made by an officer other than a police officer, that officer shall without unnecessary delay take or send the person before a Magistrate having jurisdiction or before the officer in charge of a police station.

Sub-section (3): the Code applies, subject to this section, to any entry, search or arrest made under it.

Four things to notice.

It is confined to a public place, and a private residence or a private office is outside it. For those the ordinary search warrant provisions apply, sections 96 to 103 of the Sanhita.

It reaches a person "about to commit" an offence, which is a preventive power and unusual in a special statute.

It permits arrest without warrant even for an offence that is not cognizable, because the section opens with a non obstante clause.

Contents This chapter on its own page

munotes.in813

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Seven

Proving a Cyber Offence: Electronic Evidence

Syllabus topic 4.5, "Offences and Prosecution"

In one line

An electronic record is admissible, its contents are proved under one section, and the argument for twenty years has been about whether the certificate that section requires is mandatory, which the Supreme Court settled in 2020.

The concordance

The Indian Evidence Act, 1872, was repealed on 1 July 2024 by the Bharatiya Sakshya Adhiniyam, 2023. Every case in this field was decided under the old numbers, so a student must know both.

Evidence Act, 1872Bharatiya Sakshya Adhiniyam, 2023Subject
3, definition of "evidence"2(1)(e)Evidence includes any information given electronically
22A20, read with 2(1)(d)Oral admissions as to contents of a document, and a document now includes an electronic record
45A39(2)Opinion of the Examiner of Electronic Evidence
47A41(2)Opinion of the Certifying Authority as to an electronic signature
65A62Contents of electronic records proved under the following section
65B63Admissibility of electronic records and the certificate
67A66Proof as to the electronic signature of a subscriber
73A73Proof as to the verification of a digital signature
81A81Presumption as to Gazettes in electronic forms
85A, 85B, 85C85, 86, 87Presumptions as to electronic agreements, records and certificates
88A90Presumption as to electronic messages
90A93Presumption as to electronic records five years old

Two entries in that table deserve to be read out rather than looked up. Section 2(1)(d) defines a document as any matter expressed, described or recorded upon any substance by letters, figures, marks or any other means, intended to be used or usable for recording that matter, and it includes electronic and digital records. Its illustrations name emails, server logs, documents on a computer, laptop or smartphone, messages, websites, locational evidence and voice mail messages stored on digital devices. And section 2(1)(e) defines evidence to mean and include all statements including statements given electronically that the Court permits or requires a witness to make, and all documents including electronic or digital records produced for the Court's inspection.

Why that pair matters more than any other change. Under the Evidence Act an electronic record was let in by a special gateway. Under the Adhiniyam it is a document by definition, so every rule about documents reaches it without a bridging provision, and the illustrations put a server log and a website beyond argument. Chapter 940.

And there is a new provision with no predecessor. Section 57 of the Adhiniyam rewrites primary evidence, and Explanations 4 to 7 are new: where an electronic record is stored simultaneously or sequentially in multiple files, each file is primary evidence; where it is produced from proper custody it is primary evidence unless disputed; where a video recording is stored and simultaneously transmitted or broadcast, each stored recording is primary evidence; and where a record is stored in multiple storage spaces in a computer resource, each such automated storage, including temporary files, is primary evidence.

Contents This chapter on its own page

munotes.in820

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Eight

The IT Act and the General Penal Law

Syllabus topic 4.5, "Offences and Prosecution"

In one line

The Act overrides inconsistent law, so where it deals with a subject the general penal law gives way, but it saves copyright and patents expressly and it does not prevent a prosecution under a provision it does not cover.

Section 81

81. Act to have overriding effect. The provisions of this Act shall have effect notwithstanding anything inconsistent therewith contained in any other law for the time being in force.

Provided that nothing contained in this Act shall restrict any person from exercising any right conferred under the Copyright Act, 1957, or the Patents Act, 1970.

Three points.

The overriding effect operates only on inconsistency. Where there is no inconsistency, both statutes apply. So a charge under this Act and a charge under the Bharatiya Nyaya Sanhita, 2023, on the same facts is ordinarily competent.

The proviso was inserted in 2008 and is a saving, not an exception to the override. It ensures that nothing in this Act, in particular the section 79 intermediary exemption, cuts down a copyright owner's or a patentee's rights. It is why the MySpace line of cases proceeds under the Copyright Act with the section 79 exemption in issue rather than excluded. Chapters 500 and 1360.

And section 44(2)(b) of the Digital Personal Data Protection Act, 2023, will add the DPDP Act to the proviso on 13 May 2027, so that nothing in this Act will restrict a right conferred under that Act either. Chapter 1060.

Sharat Babu Digumarti

Sharat Babu Digumarti v. Government of NCT of Delhi, (2017) 2 SCC 18, is the leading case on section 81. Chapter 1220 works its facts.

The holding, in the Court's words. Section 67 read with sections 67A and 67B is a complete code relating to the offences that are covered under the Act. Section 79 is an exemption provision conferring protection, expanded by Shreya Singhal. Section 81 provides that the Act shall have effect notwithstanding anything inconsistent in any other law. All provisions have their play if the alleged offence pertains to an electronic record. Once the offence has a nexus or connection with an electronic record, the protection and effect of section 79 cannot be ignored and negated. A special law prevails over a general and prior law, and since the Act deals with obscenity in electronic form in its various provisions, it covers the offence under section 292 of the Penal Code.

The consequence. Where the Act deals with a subject and the material is in electronic form, the prosecution cannot avoid the Act's own conditions, including the intermediary exemption, by charging the general penal law.

The limits of Sharat Babu Digumarti

And this is what a good answer adds, because the case is regularly overstated.

Contents This chapter on its own page

munotes.in830

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Twenty-Nine

Confiscation, Abetment, Attempt and Companies

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Section 76 confiscates the equipment, section 84B punishes abetment with the full sentence, section 84C punishes attempt with half of it, and section 85 makes the officers of a company liable unless they prove due diligence.

Section 76: confiscation

76. Any computer, computer system, floppies, compact disks, tape drives or any other accessories related thereto, in respect of which any provision of this Act, rules, orders or regulations made thereunder has been or is being contravened, shall be liable to confiscation:

Provided that where it is established to the satisfaction of the court adjudicating the confiscation that the person in whose possession, power or control any such thing is found is not responsible for the contravention, the court may, instead of ordering confiscation, make such other order authorised by this Act against the person contravening as it may think fit.

Four points.

The list is dated. Floppies and tape drives were current in 2000; the words "any other accessories related thereto" carry the section forward, and "computer" and "computer system" are defined widely enough to cover anything modern. Chapter 150.

"Has been or is being contravened" covers a completed and a continuing contravention, and it reaches a contravention, not merely an offence, so equipment used in a section 43 contravention is confiscable.

Confiscation is discretionary in effect, because the thing is "liable to" confiscation, and the proviso gives the court an alternative.

And the proviso protects the innocent possessor. Where the person in whose possession, power or control the thing is found proves that he is not responsible for the contravention, the court may make another order against the person who is. So an employer's server used by an employee, or a device lent to a friend, is not automatically forfeited.

Note who decides. "The court adjudicating the confiscation", which is the criminal court trying the offence, or the adjudicating officer where the contravention is civil, since section 77 speaks of confiscation "made under this Act". Chapter 1120.

Section 84B: abetment

84B. Whoever abets any offence shall, if the act abetted is committed in consequence of the abetment, and no express provision is made by this Act for the punishment of such abetment, be punished with the punishment provided for the offence under this Act.

Explanation. An act or offence is said to be committed in consequence of abetment when it is committed in consequence of the instigation, or in pursuance of the conspiracy, or with the aid which constitutes the abetment.

Three conditions. There must be an abetment; the act abetted must have been committed in consequence of it; and the Act must make no express provision for punishing that abetment.

Contents This chapter on its own page

munotes.in839

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty

Compounding, Bail and the Shape of a Prosecution

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Most offences under the Act carry three years, which makes them cognizable and bailable and compoundable, and the three exceptions are the offences that carry more.

Section 77B: cognizable and bailable

77B. Notwithstanding anything contained in the Code of Criminal Procedure, 1973, the offence punishable with imprisonment of three years and above shall be cognizable and the offence punishable with imprisonment of three years shall be bailable.

Read the two limbs against each other and the result is counter-intuitive.

Three years and above is cognizable. So the police may register a first information report and investigate without a Magistrate's order, and may arrest without a warrant.

Exactly three years is bailable. So the accused is entitled to bail as of right.

Both together, for a three-year offence: the police may arrest without a warrant and must release on bail. Above three years: cognizable, and not bailable by force of this section, so the ordinary classification applies and bail is discretionary.

And below three years: the section says nothing, so the ordinary rule in the First Schedule to the Bharatiya Nagarik Suraksha Sanhita, 2023, applies, under which an offence under another law punishable with less than three years is non-cognizable and bailable.

Note that section 77B was inserted in 2008, at the same time as the sentences in sections 66 and 67 were reduced to three years. The two changes were designed together: the offences were made lighter and, by being made exactly three years, were made bailable.

The offence table

SectionOffenceMaximum imprisonmentCognizableBailableCompoundable under 77A
65Tampering with source code3 yearsYesYesYes
66Computer related offences3 yearsYesYesYes
66BReceiving a stolen resource3 yearsYesYesYes
66CIdentity theft3 yearsYesYesYes
66DCheating by personation3 yearsYesYesYes
66EViolation of privacy3 yearsYesYesNot if against a woman or a child
66FCyber terrorismLifeYesNoNo
67Obscene material3 years, 5 on a subsequent convictionYesYesNot if against a woman or a child
67ASexually explicit material5 years, 7 on a subsequent convictionYesNoNo
67BMaterial depicting children5 years, 7 on a subsequent convictionYesNoNo
68(2)Failure to comply with the Controller's direction2 yearsNoYesYes
69(4)Failure to assist interception7 yearsYesNoNo
69A(3)Intermediary failing to comply with a blocking direction7 yearsYesNoNo
69B(4)Intermediary contravening the traffic data duty1 year or one crore rupeesNoYesYes
70(3)Access to a protected system10 yearsYesNoNo
70B(7)Failure to comply with CERT-In1 year or one crore rupeesNoYesYes
71Misrepresentation2 yearsNoYesYes
73(2), 74Certificate offences2 yearsNoYesYes

Contents This chapter on its own page

munotes.in846

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-One

What Cyber Terrorism Is

Syllabus topic 4.6, "Cyber Terrorism."

In one line

Cyber terrorism has no agreed international definition, India has a statutory one in section 66F, and the whole subject turns on distinguishing it from three neighbours that look like it.

Why there is no agreed definition

Terrorism itself has no agreed definition in international law. The United Nations has twelve sectoral conventions on particular acts, hijacking, hostage-taking, bombing, financing, and no comprehensive convention, because States have never agreed on whether acts of national liberation movements or acts of State forces are within it. A comprehensive convention has been on the table since 1996 and has not been concluded, and India has been its principal sponsor.

So an offence defined by reference to terrorism inherits that problem. Add to it the difficulty that a computer intrusion looks the same whoever does it and for whatever motive, and the reason the offence is defined by intent rather than by conduct becomes obvious.

The Budapest Convention does not deal with it at all. Its four groups of offences are about confidentiality, integrity and availability, computer-related fraud and forgery, content, and copyright. Terrorism is absent. Chapter 590.

India defined it anyway, in section 66F, inserted by the Amendment Act of 2008 after the Mumbai attacks of that year, and the definition is by reference to intent and to consequence. Chapter 1320.

The four categories

One: cyber crime. A computer offence committed for gain, for revenge, for curiosity or for its own sake. The intent is private. Chapter 1090.

Two: hacktivism. A computer offence committed to make a political or social point: defacing a government website with a slogan, a denial of service attack against an organisation the actor disapproves of, leaking documents to embarrass. The intent is expressive and political.

Three: cyber terrorism. A computer offence committed with the intent to threaten the unity, integrity, security or sovereignty of the State, or to strike terror in the people, and causing or likely to cause death, injury, damage, or the disruption of essential supplies or services. The intent is coercive and the consequence is grave.

Four: cyber warfare. Operations by or on behalf of a State against another State, in or in preparation for armed conflict. The actor is a State.

And the tests that separate them.

ActorIntentConsequence requiredGoverning law
Cyber crimeAny personPrivate: gain, revenge, curiosityDamage or loss, or noneThis Act and the Sanhita
HacktivismAny person or groupPolitical expressionUsually disruption or embarrassmentThis Act, as ordinary cyber crime; there is no offence of hacktivism
Cyber terrorismAny personTo threaten the State or strike terrorDeath, injury, damage, disruption of essential supplies, or harm to critical infrastructureSection 66F, the Bharatiya Nyaya Sanhita section 113, and the Unlawful Activities (Prevention) Act, 1967
Cyber warfareA StateState policyVariableInternational humanitarian law and the law on the use of force, not domestic criminal law

Contents This chapter on its own page

munotes.in852

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Two

Section 66F Broken Down

Syllabus topic 4.6, "Cyber Terrorism."

In one line

Section 66F has two limbs, one about disrupting systems and one about obtaining restricted information, and each requires a specified intent or state of mind that the ordinary computer offences do not.

The section

Sub-section (1)(A), the disruption limb.

Whoever, with intent to threaten the unity, integrity, security or sovereignty of India or to strike terror in the people or any section of the people by:

(i) denying or causing the denial of access to any person authorised to access a computer resource; or

(ii) attempting to penetrate or access a computer resource without authorisation or exceeding authorised access; or

(iii) introducing or causing to introduce any computer contaminant,

and by means of such conduct causes or is likely to cause death or injuries to persons or damage to or destruction of property, or disrupts or knowing that it is likely to cause damage or disruption of supplies or services essential to the life of the community, or adversely affect the critical information infrastructure specified under section 70

Sub-section (1)(B), the espionage limb.

Whoever knowingly or intentionally penetrates or accesses a computer resource without authorisation or exceeding authorised access, and by means of such conduct obtains access to information, data or computer data base that is restricted for reasons of the security of the State or foreign relations; or any restricted information, data or computer data base, with reasons to believe that such information may be used to cause or is likely to cause injury to the interests of the sovereignty and integrity of India, the security of the State, friendly relations with foreign States, public order, decency or morality, or in relation to contempt of court, defamation or incitement to an offence, or to the advantage of any foreign nation, group of individuals or otherwise,

commits the offence of cyber terrorism.

Sub-section (2): whoever commits or conspires to commit cyber terrorism shall be punishable with imprisonment which may extend to imprisonment for life.

Limb (A) broken down

Three elements, all of which must be established.

The intent. Either to threaten the unity, integrity, security or sovereignty of India, or to strike terror in the people or any section of the people. Note that the second alternative does not require the terror to be directed at the State; a section of the people suffices.

The conduct, one of three. Denial of access to an authorised person, which is a denial of service attack. Attempting to penetrate or access without authorisation or exceeding authorised access, which is the second point to notice: the attempt is enough, and section 84C's halving does not apply because the section expressly covers the attempt. Chapter 1290. Or introducing a computer contaminant, which takes its meaning from the Explanation to section 43. Chapter 1100.

Contents This chapter on its own page

munotes.in858

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Three

Cyber Terrorism Beside the UAPA and the Sanhita

Syllabus topic 4.6, "Cyber Terrorism."

In one line

Three statutes now punish a terrorist act in India and one of them punishes organised crime by express reference to cyber-crimes, so a prosecutor choosing a charge is choosing a procedural regime as much as an offence.

Section 113 of the Bharatiya Nyaya Sanhita, 2023

This is new. The Indian Penal Code, 1860, contained no offence of terrorism; the Sanhita does.

Section 113(1): whoever does any act with the intent to threaten or likely to threaten the unity, integrity, sovereignty, security, or economic security of India, or with the intent to strike terror or likely to strike terror in the people or any section of the people in India or in any foreign country:

(a) by using bombs, dynamite or other explosive or inflammable substance, firearms or other lethal weapons, poisonous or noxious gases or other chemicals, or by any other substance whether biological, radioactive, nuclear or otherwise of a hazardous nature, or by any other means of whatever nature, to cause or likely to cause death or injury, loss, damage or destruction of property, disruption of any supplies or services essential to the life of the community in India or in any foreign country, damage to the monetary stability of India by counterfeit currency, or damage to property used for the defence of India; or

(b) overawes by criminal force or the show of criminal force, or attempts to do so, or causes or attempts to cause the death of a public functionary; or

(c) detains, kidnaps or abducts a person and threatens to kill or injure them, or does any other act, to compel the Government of India, a State Government, a foreign government, an international organisation or any other person to do or abstain from doing any act,

commits a terrorist act.

Sub-section (2): death or imprisonment for life where the act has resulted in the death of any person, and not less than five years, extending to life, in any other case, with fine.

Sub-section (3): conspiring, attempting, advocating, abetting, advising, inciting, or directly or knowingly facilitating a terrorist act or any act preparatory to one carries not less than five years, extending to life, and fine.

The words that make it a cyber provision. Clause (a) reaches an act done "by any other means of whatever nature", and the consequences include disruption of any supplies or services essential to the life of the community. A network attack on a power grid is a terrorist act under section 113(1)(a) as plainly as a bomb is, and the section requires no computer-specific drafting at all.

And the intent is wider than section 66F's in two ways: it includes economic security, which section 66F does not, and it extends to striking terror in any foreign country.

Contents This chapter on its own page

munotes.in865

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Four

Modes of Cyber Terrorism, and the Response

Syllabus topic 4.6, "Cyber Terrorism."

In one line

Terrorists use the network in four ways, to attack infrastructure, to propagandise and recruit, to raise and move money, and to communicate, and only the first is cyber terrorism as the Act defines it.

Mode one: attacks on critical infrastructure

What it means. Interfering with the systems that control power, water, transport, banking, telecommunications, health or defence, so as to cause physical harm or the disruption of services essential to life.

Why it is the only true cyber terrorism. It is the only mode that satisfies the consequence limb of section 66F(1)(A): death or injury, damage to or destruction of property, disruption of supplies or services essential to the life of the community, or an adverse effect on critical information infrastructure specified under section 70. Chapter 1320.

What makes it possible. Industrial control systems, known as supervisory control and data acquisition systems, were designed for isolated networks and for reliability rather than security. Many run software that is decades old and cannot be patched without stopping the plant. Connecting them to corporate networks, and thence to the internet, is what created the exposure.

The Indian response.

Section 70, notification as a protected system, with the ten year offence and the 2018 Rules requiring an Information Security Steering Committee, a Chief Information Security Officer, an information security management system, annual risk analysis, a Cyber Crisis Management Plan, audits and a Cyber Security Operation Centre. Chapter 780.

Section 70A and NCIIPC, the national nodal agency, which identifies critical elements for notification, issues guidelines and receives logs. Chapter 780.

Section 70B and CERT-In, incident response and the six-hour reporting obligation. Chapters 760 and 770.

And sectoral regulation: the Reserve Bank of India's Cyber Security Framework in Banks of 2016, the Central Electricity Authority's cyber security regulations for the power sector, and the equivalents in telecommunications and civil aviation. Chapter 790.

The international response. Article 16 of the Budapest Convention, expedited preservation; article 35, the 24/7 network; the norms of responsible State behaviour agreed in the Group of Governmental Experts process, including the norm that States should not knowingly allow their territory to be used for internationally wrongful acts and should not conduct or knowingly support activity that damages critical infrastructure; and the Tallinn Manual process, which is a scholarly restatement of how existing international law applies and is not itself law. Chapters 580 and 600.

Mode two: propaganda and recruitment

What it means. Publishing material to justify violence, to glorify it, to instruct in it, and to identify and cultivate recruits, using open platforms for reach and closed channels for the approach.

The legal response in India is not section 66F, because no consequence within the section follows. It is:

Contents This chapter on its own page

munotes.in872

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Five

Social Media in Law

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

The Rules create three categories of intermediary, the top one is defined by a user threshold and carries eleven additional duties, and the heaviest of those is the obligation to identify the first originator of a message.

Where the Rules come from

Rule 1 calls them the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and brings them into force on the date of their publication in the Official Gazette, which for G.S.R. 139(E) is 25 February 2021. They are made under section 87(1) and clauses (z) and (zg) of section 87(2), and they are made in supersession of the Information Technology (Intermediaries Guidelines) Rules, 2011, except as respects things done or omitted before the supersession.

That saving clause matters in an answer about an old takedown. Conduct in 2019 is judged by the 2011 Rules, which is why Shreya Singhal's reading of rule 3(4) of the 2011 Rules is still the law of that period. Chapter 1360.

The three categories

One: an intermediary. Section 2(1)(w) of the Act: any person who on behalf of another person receives, stores or transmits an electronic record or provides any service with respect to that record. The definition then gives examples: telecom service providers, network service providers, internet service providers, web hosting service providers, search engines, online payment sites, online auction sites, online market places and cyber cafes.

Two: a social media intermediary. Rule 2(1)(w) of the IT Rules 2021: an intermediary which primarily or solely enables online interaction between two or more users and allows them to create, upload, share, disseminate, modify or access information using its services.

Note the two limbs. The service must be primarily or solely for interaction, so a bank's website with a comment facility is not one; and it must allow users to do the listed things with information.

Three: a significant social media intermediary. Rule 2(1)(v): a social media intermediary having a number of registered users in India above such threshold as notified by the Central Government. The notified threshold is fifty lakh registered users in India.

And two more categories were added in 2023: an online gaming intermediary, which enables users to access one or more online games, and an online gaming self-regulatory body designated under rule 4A.

The consequence of the tiering. Rule 3 binds every intermediary. Rule 4 binds only a significant social media intermediary, with parts of it extended in 2023 to an online gaming intermediary enabling access to a permissible online real money game.

Rule 4(1): the three officers

A significant social media intermediary must, within three months of the notification of the threshold, appoint:

(a) a Chief Compliance Officer, responsible for ensuring compliance with the Act and the rules, who shall be liable in any proceedings relating to any relevant third party information, data or communication link made available or hosted by the intermediary where he fails to ensure that the intermediary observes due diligence, subject to a proviso that he shall not be liable without being given an opportunity of being heard. The Explanation requires him to be a key managerial personnel or other senior employee resident in India.

Contents This chapter on its own page

munotes.in879

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Six

Intermediary Liability and the Safe Harbour

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

An intermediary is not liable for third party content if it satisfies three conditions, and it loses that protection if it conspires in the unlawful act or fails to remove content on actual knowledge, which since 2015 means a court order or a government notification.

The section

Sub-section (1): notwithstanding anything contained in any law for the time being in force but subject to sub-sections (2) and (3), an intermediary shall not be liable for any third party information, data, or communication link made available or hosted by him.

Sub-section (2), the three conditions. Sub-section (1) applies if:

(a) the function of the intermediary is limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored or hosted; or

(b) the intermediary does not (i) initiate the transmission, (ii) select the receiver of the transmission, and (iii) select or modify the information contained in the transmission; and

(c) the intermediary observes due diligence while discharging his duties under this Act and also observes such other guidelines as the Central Government may prescribe.

Read the conjunctions carefully, because they decide cases. Clauses (a) and (b) are alternatives, joined by "or", and clause (c) is cumulative, joined by "and". So an intermediary must satisfy either (a) or (b), and must in every case satisfy (c).

Clause (a) describes a mere conduit; clause (b) describes a host that does not choose or alter. Together they exclude an intermediary that curates, and clause (c) makes compliance with the Rules a condition of the exemption. That last point is the whole of Indian intermediary law: the Government prescribes the guidelines and non-compliance costs the exemption. Chapter 1350.

Sub-section (3), the two disqualifications. Sub-section (1) shall not apply if:

(a) the intermediary has conspired or abetted or aided or induced, whether by threats or promise or otherwise, in the commission of the unlawful act; or

(b) upon receiving actual knowledge, or on being notified by the appropriate Government or its agency that any information, data or communication link residing in or connected to a computer resource controlled by the intermediary is being used to commit the unlawful act, the intermediary fails to expeditiously remove or disable access to that material without vitiating the evidence in any manner.

What Shreya Singhal did to sub-section (3)(b)

The problem. On its face, "actual knowledge" could be given by anybody. A platform receiving a private complaint would have to decide whether the content was unlawful, on pain of losing the exemption if it decided wrongly. The incentive is to remove everything complained of.

The Court's reasoning, at paragraph 116. Section 79 is an exemption provision and is closely related to provisions creating offences, including section 69A. Under section 69A blocking can take place only by a reasoned order after complying with several procedural safeguards including a hearing to the originator and the intermediary, and there are only two ways an order can be passed, by the Designated Officer under the 2009 Rules and by the Designated Officer following a court order. "The intermediary applying its own mind to whether information should or should not be blocked is noticeably absent in Section 69A read with 2009 Rules."

Contents This chapter on its own page

munotes.in889

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Seven

The Code of Ethics and the Three-Tier Mechanism

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

Part III applies a Code of Ethics to online news publishers and streaming services, administered by the Ministry of Information and Broadcasting, with a three-level grievance route ending in a committee of officials that can order content deleted, modified or blocked.

Who Part III applies to

Rule 8(1): the rules in this Part apply to publishers of news and current affairs content and publishers of online curated content, and shall be administered by the Ministry of Information and Broadcasting, referred to as "the Ministry". A proviso extends rules 15 and 16 to intermediaries.

Note the change of Ministry. Part II, on intermediaries, is administered by the Ministry of Electronics and Information Technology; Part III by the Ministry of Information and Broadcasting. Rule 2(1)(l) says so expressly.

Rule 8(2), the territorial reach. The Part applies to a publisher which operates in the territory of India, meaning it has a physical presence here, or which conducts systematic business activity of making its content available in India, "systematic activity" being defined as any structured or organised activity involving an element of planning, method, continuity or persistence.

So a foreign streaming service with no Indian office is within Part III if it makes content available here systematically.

Rule 8(3): the Part is in addition to and not in derogation of any other law and any remedies under it, including the Blocking Rules of 2009. Chapter 810.

The two definitions. A publisher of news and current affairs content, rule 2(1)(t), means an online paper, news portal, news aggregator, news agency or similar entity, but not a newspaper, a replica e-paper of a newspaper, or an individual or user not transmitting content in the course of a systematic business or professional activity. A publisher of online curated content, rule 2(1)(r) with rule 2(1)(q), means a publisher of a curated catalogue of audio-visual content other than news, owned by or licensed to it, made available on demand, including films, programmes, documentaries, serials and podcasts.

So a newspaper's print edition and its exact digital replica are outside; its news website is inside; and an individual blogger is outside unless blogging is a systematic business.

The Code of Ethics

In the Appendix, and it has two parts.

Part I, news and current affairs, incorporates three existing standards: the Norms of Journalistic Conduct of the Press Council of India under the Press Council Act, 1978; the Programme Code under section 5 of the Cable Television Networks (Regulation) Act, 1995; and a prohibition on publishing content prohibited by any law.

The technique is worth noticing. The Code creates no new standard for news. It applies to online publishers the standards that already bind newspapers and television, which is the answer to the objection that the Rules invent a new censorship: they extend an existing one.

Contents This chapter on its own page

munotes.in898

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Eight

Crimes Committed Through Social Media

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

Six named harms are committed through social media, none of them has a provision of its own in the Act, and each is charged under a general provision of the Bharatiya Nyaya Sanhita, 2023, or under one of the Act's specific offences.

The six harms

Cyberbullying. Repeated aggressive behaviour directed at a person through electronic means, intended to harm or humiliate. It has no statutory definition in India.

Trolling. Provocative or abusive posting, often coordinated, intended to distress or to drive a person off a platform.

Doxxing. Publishing a person's private identifying information, address, workplace, telephone number, family details, so that others may harass them. The word does not appear in any Indian statute.

Sextortion. Obtaining intimate images or acts, or a payment, by threatening to publish material the offender holds.

Catfishing. Creating a false persona to form a relationship, usually to obtain money, images or information.

Online stalking. Persistent unwanted contact and monitoring of a person's electronic communications.

What charges each

HarmPrincipal provisionsNotes
CyberbullyingSection 351 Sanhita, criminal intimidation; section 79 Sanhita, insulting the modesty of a woman; section 356, defamation; section 78, stalkingNo offence of bullying; the charge depends on what was said and to whom
TrollingSection 356 defamation; section 351 intimidation; section 196 promoting enmity; section 79 where a woman is targetedCoordinated trolling may be section 61 criminal conspiracy
DoxxingSection 66E if a private area is shown; section 72A if the information came from a service contract; section 351(2) intimidation; section 308 extortion where a demand followsNo offence of publishing an address, which is the gap
SextortionSection 308 Sanhita, extortion; section 67, 67A where material is published; section 66E; section 384 to 389 equivalent provisions; POCSO section 11 and 12 where the victim is a childExtortion is complete on the threat with intent to cause fear, so no image need be published
CatfishingSection 66D cheating by personation; section 319 Sanhita, cheating by personation, five years; section 318 cheating; section 336 forgery where documents are madeThe Explanation to section 319 covers a real or imaginary person
Online stalkingSection 78 Sanhita, stalking, which expressly includes monitoring the use by a woman of the internet, email or any other form of electronic communicationProtects a woman only; a man stalked online has no equivalent provision

The three provisions that do most of the work

Section 78 of the Bharatiya Nyaya Sanhita, 2023, stalking.

Any man who (i) follows a woman and contacts, or attempts to contact such woman to foster personal interaction repeatedly despite a clear indication of disinterest by such woman; or (ii) monitors the use by a woman of the internet, e-mail or any other form of electronic communication, commits the offence of stalking.

Contents This chapter on its own page

munotes.in907

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Thirty-Nine

Non-Consensual Images, Morphing and Revenge Pornography

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

Non-consensual intimate imagery is met by four criminal provisions, none of which was drafted for it, and by a removal rule that now gives two hours.

The harm

Three overlapping forms, and they are not the same.

Non-consensual sharing of images captured with consent. A person consented to the image being taken, in a relationship, and did not consent to its distribution. This is what is loosely called revenge pornography.

Non-consensual capture. The image was taken without knowledge or consent, by a hidden camera, a compromised device or an upskirt photograph.

And morphed or synthetic imagery. An innocent photograph of the victim is altered, or a wholly generated image is made, to place them in a sexual context.

Why the distinction matters legally. The provisions turn on capture or on publication, and the three forms engage them differently. And only the third is now addressed by a provision written for it, namely the 2026 amendment to the IT Rules. Chapter 1000.

The criminal provisions

Section 66E of this Act: intentionally or knowingly capturing, publishing or transmitting the image of a private area of any person without consent, under circumstances violating privacy. Three years or two lakh rupees or both. Chapter 1210.

Its strengths: it protects any person of any gender; the reasonable expectation is not tied to the place; and each of capture, publication and transmission is an independent offence, so a forwarder is liable.

Its limits: it reaches only an image of a private area as defined, namely the naked or undergarment clad genitals, pubic area, buttocks or female breast, so an intimate image showing none of those is outside it; and it speaks of capturing the image of a person, so a wholly generated image captures nothing.

Section 77 of the Bharatiya Nyaya Sanhita, 2023, voyeurism: watching, or capturing the image of, a woman engaging in a private act where she would usually expect not to be observed, or disseminating such image. One to three years on a first conviction and three to seven on a subsequent one, with a minimum in each case.

And Explanation 2 is the provision written for revenge pornography: where the victim consents to the capture of the images or any act but not to their dissemination to third persons, and the image or act is disseminated, such dissemination shall be considered an offence under this section.

So the exact case of an image shared by a former partner is squarely within section 77, provided the victim is a woman.

Sections 67 and 67A of this Act, where the material is lascivious or contains a sexually explicit act. Section 67A carries five years. Chapter 1220.

Contents This chapter on its own page

munotes.in913

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Forty

Fake News, Misinformation and the Fact Check Unit

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

The Rules require an intermediary to tell users not to share misinformation, an amendment of 2023 added a government fact check unit whose identification would settle the question, and a judge of the Bombay High Court would have struck that addition down.

Rule 3(1)(b)(v)

Rule 3(1)(b) requires an intermediary to inform its users, through its rules and regulations, privacy policy and user agreement, not to host, display, upload, modify, publish, transmit, store, update or share information falling within eleven sub-clauses. Sub-clause (v) is the one about misinformation:

(v) deceives or misleads the addressee about the origin of the message, or knowingly and intentionally communicates any misinformation or information which is patently false and untrue or misleading in nature [or, in respect of any business of the Central Government, is identified as fake or false or misleading by such fact check unit of the Central Government as the Ministry may, by notification published in the Official Gazette, specify]

The bracketed words were inserted by G.S.R. 275(E) of 6 April 2023. The rest is the original 2021 text.

Three parts, and they are different in kind.

Deception about the origin of the message, which is spoofing and is uncontroversial.

Knowingly and intentionally communicating misinformation or information which is patently false and untrue or misleading, which requires a mental element, "knowingly and intentionally", and an objective one, "patently false and untrue".

And the 2023 addition, which requires neither. Information relating to any business of the Central Government which the fact check unit identifies as fake, false or misleading falls within the sub-clause, whatever the user knew and whatever the truth may be.

What the amendment did in practice

Rule 3(1)(b) is a duty to inform users, not a duty to remove. But it is connected to two things that make it operative.

Rule 3(1)(d) requires removal on actual knowledge, and rule 2(1A) construes references to information used to commit an unlawful act to include synthetic information, but neither turns a fact check unit's identification into actual knowledge. Chapters 990 and 1360.

Rule 7 provides that failure to observe the Rules removes the section 79(1) exemption. So an intermediary that continues to host material the unit has identified risks the argument that it has not observed rule 3(1)(b), and therefore loses the safe harbour for all its content.

That is the mechanism, and it is why the amendment was described as compelling removal without any order requiring it.

Kunal Kamra v. Union of India

Kunal Kamra v. Union of India, Bombay High Court, 31 January 2024.

Facts. A comedian, a journalists' association, an editors' guild and others challenged the 2023 amendment inserting the fact check unit into rule 3(1)(b)(v).

Contents This chapter on its own page

munotes.in919

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Forty-One

Grievance Redress and Reporting a Cyber Crime

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

A victim has four routes, the platform's grievance officer, an appellate committee, the police through a national portal, and the financial helpline, and the clocks that govern the first two were all shortened in February 2026.

The Resident Grievance Officer and the clocks

Rule 3(2)(a) of the IT Rules 2021, as amended on 10 February 2026:

The intermediary must prominently publish on its website or application the name of the Grievance Officer and his contact details, and the mechanism by which a user or a victim may complain about a violation of the rule or about any other matter pertaining to the computer resources it makes available. "Prominently publish" is defined in the Explanation as publishing in a clearly visible manner on the home page of the website or the home screen of the application, or on a page directly accessible from it.

And the Grievance Officer shall:

(i) acknowledge the complaint within twenty-four hours and resolve it within seven days of receipt;

with a proviso that a complaint in the nature of a request for removal of information or a communication link relating to rule 3(1)(b), except sub-clauses (i), (iv) and (xi), shall be acted upon as expeditiously as possible and resolved within thirty-six hours;

and a further proviso that the intermediary may develop appropriate safeguards to avoid misuse by users;

(ii) receive and acknowledge any order, notice or direction issued by the appropriate Government, a competent authority or a court.

The figures changed on 10 February 2026, in force from 20 February. Resolution went from fifteen days to seven, and removal grievances from seventy-two hours to thirty-six. Chapter 990.

And rule 3(2)(b) gives two hours for content in the nature of nudity, a sexual act, or impersonation including artificially morphed images, reduced from twenty-four. Chapter 1390.

Rule 4(1)(c) requires a significant social media intermediary to appoint a Resident Grievance Officer, who must be an employee resident in India and who performs the rule 3(2) functions. Rule 4(6) requires a mechanism enabling the complainant to track the status of the complaint through a unique ticket number, and to be given reasons for action taken or not taken so far as reasonable. Chapter 1350.

The Grievance Appellate Committee

Rule 3A, inserted by G.S.R. 794(E) of 28 October 2022.

Constitution: the Central Government shall establish one or more Grievance Appellate Committees within three months of the commencement of the 2022 amendment. Each consists of a chairperson and two whole time members appointed by the Central Government, of whom one shall be a member ex officio and two shall be independent members.

Who may appeal: any person aggrieved by a decision of the Grievance Officer, or whose grievance is not resolved within the period specified, within thirty days of receipt of the communication from the Grievance Officer.

Contents This chapter on its own page

munotes.in926

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Forty-Two

The Closing Provisions of the Act

Syllabus topic 4.5, "Offences and Prosecution"

In one line

Nine sections close the Act, and one of them, the rule-making power in section 87, is the source of every set of rules worked in this book.

Sections 82 to 84: the officers

Section 82: the Controller, Deputy Controllers and Assistant Controllers shall be deemed to be public servants within the meaning of section 21 of the Indian Penal Code, 1860, now section 2(28) of the Bharatiya Nyaya Sanhita, 2023.

What that carries. The offences of a public servant taking gratification and of criminal misconduct apply to them, under the Prevention of Corruption Act, 1988; and the protection of sanction for prosecution applies. Chapter 400.

Section 83, directions to a State. The Central Government may give directions to any State Government as to the carrying into execution in the State of any provision of the Act or of any rule, regulation or order made under it.

Why this section exists. The Act is a Union law, but its execution depends on State police and State officers: adjudicating officers are State Secretaries, investigation is by State police under section 78, and the appropriate Government under section 2(1)(e) may be a State. Section 83 is the constitutional hook, corresponding to article 256 of the Constitution, which obliges a State to ensure compliance with laws made by Parliament and empowers the Union to give directions to that end.

Section 84, protection for good faith action. No suit, prosecution or other legal proceeding shall lie against the Central Government, a State Government, the Controller or any person acting on his behalf, or an adjudicating officer, for anything done or intended to be done in good faith in pursuance of the Act or any rule, regulation or order.

Two points. The protection is for good faith, which section 3(22) of the General Clauses Act, 1897, defines as done honestly, whether negligently or not. And an act done outside the Act, or in bad faith, is unprotected, so section 84 is no answer to a challenge to a direction made without jurisdiction.

And note who is not protected. An intermediary is not, which is why section 79 and rule 2(1B) exist separately. Chapters 1360 and 990.

Section 86: removal of difficulties

Sub-section (1): if any difficulty arises in giving effect to the Act, the Central Government may, by order published in the Official Gazette, make such provisions not inconsistent with the Act as appear necessary or expedient for removing the difficulty. The proviso: no order shall be made after the expiry of two years from the commencement of the Act.

Sub-section (2): every such order shall be laid before each House of Parliament.

So the power is spent. The Act commenced on 17 October 2000, and the power expired on 17 October 2002. It is worth knowing only because a student should be able to say that a removal of difficulties order cannot now be made, and because such clauses are a standing subject of criticism as permitting the executive to amend a statute.

Contents This chapter on its own page

munotes.in932

The rest of this chapter comes with the notes. See the prices

Chapter One Hundred Forty-Three

Cyber Cafes as a Worked Example of Due Diligence

Syllabus topic 4.7, "Social Media and Emerging Crimes."

In one line

The Cyber Cafe Rules are the only place in Indian law where the whole of an intermediary's due diligence is written out for one kind of business, and reading them shows exactly what section 79(2)(c) means.

Why this is the last chapter

Section 79(2)(c) makes the exemption conditional on the intermediary observing "such other guidelines as the Central Government may prescribe". Chapter 1360. For most intermediaries those guidelines are the IT Rules 2021, which are drafted in general terms because they apply to everything from a search engine to a payment gateway.

For one class of intermediary they are specific. A cyber cafe is an intermediary by name: section 2(1)(w) lists cyber cafes among the examples, and section 2(1)(na) defines a cyber cafe as any facility from where access to the internet is offered by any person in the ordinary course of business to the members of the public.

And the Cyber Cafe Rules tell that class exactly what to do, down to the height of a partition. So they are the answer to the question a student always asks about section 79(2)(c): what does observing guidelines actually require?

The instrument

The Information Technology (Guidelines for Cyber Cafe) Rules, 2011, notified as G.S.R. 315(E) on 11 April 2011, made under clause (zg) of section 87(2) read with section 79(2) of the Act. Seven rules.

Note the parent power. They are made under the same clause as the intermediary guidelines and expressly under section 79(2), so they are guidelines whose observance is a condition of the exemption. Chapter 1420.

Rule 1 commences them on publication, and rule 2 defines a cyber cafe by reference to the Act itself, clause (na) of section 2(1): any facility from where access to the internet is offered by any person in the ordinary course of business to the members of the public. So the definition turns on offering access as a business to the public, which is why a hotel's guest terminal and an office's visitor machine are outside the Rules while a paid terminal in a shop is inside them.

Rule 3: registration

All cyber cafes shall be registered with a unique registration number with a registration agency notified by the appropriate Government, which under rule 2(1)(b) means the Central Government, a State Government or a Union territory administration.

The registration records seven particulars: the name of the establishment; the address with contact details including an email address; whether it is an individual, partnership, sole proprietorship, society or company; the date of incorporation; the name of the owner, partner, proprietor or director; whether it is registered, with a copy of the registration with the Registrar of Firms, Companies or Societies; and the type of service to be provided.

Contents This chapter on its own page

munotes.in940

The rest of this chapter comes with the notes. See the prices

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!