The Scheme of the Information Technology Act
Chapter Twelve
Syllabus topic 1.3, "An Overview of the Information Technology Act"
Pages 66 to 71 of 948
In one line
The Act has thirteen chapters, and they fall into four blocks: making electronic records work, regulating the people who certify signatures, punishing misuse, and giving the State powers over the network.
In the wording a student can write in an exam: the Information Technology Act, 2000 is arranged in thirteen chapters running from section 1 to section 90, comprising a preliminary chapter, three chapters giving legal effect to electronic records and signatures, a chapter on secure records, two chapters regulating Certifying Authorities and Electronic Signature Certificates, a chapter of subscriber duties, chapters on penalties and adjudication and on appeals, a chapter of offences, a chapter conferring immunity on intermediaries, and a miscellaneous chapter.
Why a student needs the map before the detail
A statute read section by section teaches nothing about why the sections are where they are. The reason section 43 sits next to section 44 is that both are civil penalties. The reason section 66 borrows its conduct from section 43 is that Chapter XI was written later, on top of Chapter IX. The reason section 79 has a chapter to itself is that it was rewritten in 2008 to do a job the original Act had not thought about.
And an examination answer that locates a provision earns marks that one which merely recites it does not. Being able to say that section 69A sits in the offences chapter although it creates no offence, or that section 43A sits in the penalties chapter although it is a compensation provision, shows a reader who has understood the architecture.
The thirteen chapters
| Chapter | Heading | Sections | What it does |
|---|---|---|---|
| I | Preliminary | 1 to 2 | Extent, application, the First Schedule exclusions, and every definition |
| II | Digital Signature and Electronic Signature | 3 to 10A | Authentication, electronic signature, legal recognition of records and signatures |
| III | Electronic Governance | 6 to 9 | Use in Government, service delivery, retention, audit, Electronic Gazette |
| IV | Attribution, Acknowledgment and Despatch of Electronic Records | 11 to 13 | Whose record it is, acknowledgment, time and place |
| V | Secure Electronic Records and Secure Electronic Signatures | 14 to 16 | What makes a record or signature secure, and the security procedure |
| VI | Regulation of Certifying Authorities | 17 to 34 | The Controller, licensing, and the duties of a Certifying Authority |
| VII | Electronic Signature Certificates | 35 to 39 | Issue, representations, suspension and revocation |
| VIII | Duties of Subscribers | 40 to 42 | The key pair, acceptance, control of the private key |
| IX | Penalties, Compensation and Adjudication | 43 to 47 | Civil liability for damage and for failing to protect data, and the adjudicating officer |
| X | The Appellate Tribunal | 48 to 64 | The Tribunal, appeals, compounding and recovery |
| XI | Offences | 65 to 78 | The criminal provisions, and the State powers in sections 69 to 70B |
| XII | Intermediaries Not To Be Liable In Certain Cases | 79 to 79A | The safe harbour, and the Examiner of Electronic Evidence |
| XIII | Miscellaneous | 80 to 90 | Search, overriding effect, encryption, companies, rule-making |
The Scheme of the Information Technology Act
Two notes on that table, and both are traps.
Chapter II and Chapter III overlap in numbering because section 6A was inserted into Chapter III and sections 10 and 10A into Chapter II, so the section runs are not neatly separated. Read the chapter headings, not the numbers.
The chapter headings themselves have been amended. Chapter II was headed "Digital Signature" until 2008 and is now "Digital Signature and Electronic Signature"; Chapter X was headed "The Cyber Appellate Tribunal" until the Finance Act 2017 and is now "The Appellate Tribunal"; Chapter XII was substituted whole in 2008. A textbook printed before 2009 gives the old headings.
The four blocks
Block one, Chapters I to V, sections 1 to 16: making electronic records work. This is the Model Law. Everything here is about giving an electronic record the legal effect a paper one would have had, and about the mechanical rules that follow once people communicate by machine. If the Act had stopped at section 16 it would have been a faithful enactment of the 1996 Model Law and nothing else.
Block two, Chapters VI to VIII, sections 17 to 42: the trust infrastructure. Because section 5 accepts only a prescribed method, somebody must supply and vouch for that method, and somebody must supervise the suppliers. Chapter VI creates the Controller and the licence; Chapter VII governs the certificate; Chapter VIII binds the subscriber. Chapter 110 explains why India needed this block and the Model Law did not.
Block three, Chapters IX to XI, sections 43 to 78: consequences. Chapter IX is civil: damage, compensation, adjudication by an officer rather than a court. Chapter X is the appeal. Chapter XI is criminal. The sequence is deliberate and useful: the Act tries a civil answer first and reaches for the criminal law afterwards.
Block four, sections 69 to 70B and Chapter XII, and much of Chapter XIII: the State and the network. These sit inside Chapters XI and XIII rather than in a chapter of their own, which is the Act's least tidy feature. Interception, blocking, traffic-data monitoring, protected systems, critical information infrastructure and CERT-In are all in the offences chapter. The intermediary safe harbour has a chapter to itself. Module III is largely block four.
Where to find things: a lookup for the whole subject
Definitions: section 2. Every term. Chapters 150 and 160.
Does the Act apply to this document at all? Section 1(4) and the First Schedule. Chapter 140.
The Scheme of the Information Technology Act
Is this electronic record as good as writing? Section 4. As good as a signature? Section 5 with sections 3 and 3A.
How long must this be kept, and in what form? Section 7.
Whose message is it? Section 11. When and where was it sent and received? Section 13.
Who licenses the people who issue certificates? Section 17, and the licence is under section 24.
My certificate has been misused. What now? Sections 37 to 39 on suspension and revocation, section 42 on the duty to keep the private key secret, and section 43 or 66 against whoever misused it.
Somebody damaged my data. Section 43 for compensation, section 66 for the offence, section 46 for who adjudicates a claim up to five crore rupees.
Somebody published my private photograph. Section 66E, and section 67 or 67A if it is obscene or sexually explicit, and rule 3(2)(b) of the 2021 Rules for a takedown in twenty-four hours.
The Government wants to read my messages. Section 69 and the Interception Rules 2009.
The Government wants a website blocked. Section 69A and the Blocking Rules 2009.
A platform is refusing to take down defamatory material. Section 79 with the 2021 Rules, and chapter 1360.
A company's server was breached and my data leaked. Section 43A with the SPDI Rules 2011 for compensation, section 72A if there was a service-provider disclosure in breach of contract, and the CERT-In directions for the reporting obligation.
Where does the Act say it prevails over other law? Section 81, with its proviso preserving the Copyright Act and the Patents Act. Chapter 1280.
The rules, and why the Act is unreadable without them
Section 87 empowers the Central Government to make rules, and it is a very long section. Almost every important question in this subject is answered in a rule and not in the Act.
| Section | Rules made under it | Chapter |
|---|---|---|
| 6A | Electronic Service Delivery Rules 2011 | 370 |
| 10 and 3A | Certifying Authorities Rules 2000; the 2016 electronic signature notifications | 460, 290 |
| 43A | Reasonable Security Practices Rules 2011, the SPDI Rules | 230 |
| 46 | Adjudicating Officers Rules 2003 | 1120 |
| 69 | Interception, Monitoring and Decryption Rules 2009 | 800 |
| 69A | Blocking for Access of Information by Public Rules 2009 | 810 |
| 69B | Monitoring and Collecting Traffic Data Rules 2009 | 820 |
| 70 | Information Security Practices for Protected System Rules 2018 | 780 |
| 70A | NCIIPC Rules 2013 | 780 |
| 70B | CERT-In Rules 2013, and the Directions of 28 April 2022 | 760, 770 |
| 79 | Intermediary Guidelines and Digital Media Ethics Code Rules 2021, as amended 10 February 2026 | 1350, 1360, 1370, 990, 1000 |
| 79, cyber cafes | Guidelines for Cyber Cafe Rules 2011 | 1430 |
A student who reads the Act and not the rules will know that section 79 confers an immunity and will not know a single thing an intermediary actually has to do.
The Scheme of the Information Technology Act
The four Schedules
The First Schedule, under section 1(4), lists the documents and transactions the Act does not apply to. Chapter 140 owns it.
The Second Schedule, under section 3A, specifies the electronic signature or electronic authentication techniques. Chapter 290 owns it.
The Third and Fourth Schedules were the amending Schedules, carried by sections 91 to 94, which amended the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934. Sections 91 to 94 were omitted in 2008 as spent, having done their work. What section 92 did to the Evidence Act, inserting the old section 65B, is taught in chapter 1270 as history.
A worked example: finding your way
A client says: "Our accounts clerk received an email that looked like it came from our supplier, changed the bank details, and we paid eighteen lakh rupees to a fraudster. What can we do?"
Start with Chapter I. Is this within the Act at all? Yes: an electronic record, a computer resource, and nothing in the First Schedule excludes it.
Chapter IV. Was the email attributed to the supplier under section 11? No, unless it was sent by the supplier, by somebody authorised, or by the supplier's automated system. So the supplier is not bound by it, and chapter 940 explains what the Act does not say about reliance.
Chapter IX. Section 43 gives a claim for compensation against whoever accessed a computer resource without authorisation or introduced a deceptive record; if the supplier's mail account was compromised and the supplier was negligent in protecting sensitive personal data, section 43A may reach the supplier too, and chapter 230 works the SPDI Rules.
Chapter XI. Section 66 makes the fraudster's conduct an offence; section 66C reaches the use of another's identifying feature; section 66D reaches cheating by personation using a computer resource.
Chapter IX again. Section 46: the claim for eighteen lakh rupees goes to the adjudicating officer, not to a civil court, because it is under five crore rupees.
Chapter XII. Is the email provider liable? Section 79, and almost certainly not.
Outside the Act. Section 318 of the Bharatiya Nyaya Sanhita for cheating, the bank's obligations under the Reserve Bank's directions on unauthorised electronic transactions, and section 63 of the Bharatiya Sakshya Adhiniyam to prove the emails.
Every one of those steps is a chapter of this book, and the map is what let us find them in order.
What this does NOT mean
It does not mean the chapters are watertight. Sections 69 to 70B create no offence in the ordinary sense and sit in the offences chapter; section 43A creates no penalty and sits in the penalties chapter. The headings are a guide, not a classification.
The Scheme of the Information Technology Act
It does not mean the Act is self-contained. Section 81 gives it overriding effect, but the general criminal law, the law of contract, the law of evidence and the law of copyright all continue to apply, and much of Module IV is about how they fit together.
It does not mean sections 91 to 94 never mattered. They are the reason electronic records are admissible in Indian courts at all, and their omission in 2008 is a tidying up of provisions that had already done their work.
Quick revision
- Thirteen chapters, sections 1 to 90. Five omitted sections: 20, 91, 92, 93, 94.
- Four blocks: recognition (I to V, ss.1 to 16); trust infrastructure (VI to VIII, ss.17 to 42); consequences (IX to XI, ss.43 to 78); the State and the network (ss.69 to 70B, XII and parts of XIII).
- Chapter headings have been amended: Chapter II gained "and Electronic Signature" in 2008; Chapter X lost "Cyber" in 2017; Chapter XII was substituted in 2008.
- Section 87 is the rule-making power, and almost every operative detail is in a rule, not in the Act.
- Four Schedules: the First under s.1(4), exclusions; the Second under s.3A, signature techniques; the Third and Fourth, the amending Schedules carried by ss.91 to 94, now omitted as spent.
- The untidiness worth naming: sections 69 to 70B are State powers sitting in the offences chapter, and section 43A is a compensation provision sitting in the penalties chapter.
Test yourself
1. Name the four blocks of the Act and the sections in each. Recognition, Chapters I to V, sections 1 to 16. The trust infrastructure, Chapters VI to VIII, sections 17 to 42. Consequences, Chapters IX to XI, sections 43 to 78. The State and the network, sections 69 to 70B inside Chapter XI, Chapter XII on intermediaries, and parts of Chapter XIII.
2. Which chapter would you look in for each of: whether an email satisfies a requirement of writing; who licenses a Certifying Authority; whether a marketplace is liable for a seller's listing; and where a claim for four crore rupees is decided? Chapter II, section 4. Chapter VI, sections 17 and 24. Chapter XII, section 79. Chapter IX, section 46, because the claim is under five crore rupees and goes to the adjudicating officer.
3. Why is it a mistake to read the Act without the rules? Because section 87 leaves the operative detail to rules, and the provisions that decide practical questions are in them: what reasonable security practices are, how a blocking direction is made and reviewed, what an intermediary must do to keep its immunity, and how an adjudication proceeds. Section 79 confers an immunity and says nothing about what an intermediary must actually do; the 2021 Rules do.
The Scheme of the Information Technology Act
4. What did sections 91 to 94 do, and why are they no longer in the Act? They carried the Third and Fourth Schedules, which amended the Indian Penal Code, the Indian Evidence Act 1872, the Bankers' Books Evidence Act 1891 and the Reserve Bank of India Act 1934, and it was section 92 with the Second Schedule that inserted the old section 65B into the Evidence Act. They were omitted by the 2008 amendment as spent, the amendments having already taken effect in the amended statutes.
5. Give two places where the Act's chapter headings mislead. Sections 69, 69A, 69B, 70, 70A and 70B confer State powers and sit in Chapter XI, headed "Offences", although the sections themselves create powers rather than offences, with the offences attached as consequences of non-compliance. And section 43A, which creates a right to compensation with no penalty at all, sits in Chapter IX headed "Penalties, Compensation and Adjudication".
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.