Nyaykosh
Home / Laws / The Information Technology Act
GovernanceIn force

The Information Technology Act, 2000

The Information Technology Act, 2000 is India's primary cyber law. It gives legal recognition to electronic records, e-signatures, and e-governance, regulates Certifying Authorities and intermediaries, and defines cyber offences and their penalties.

Compliance Rules

42 rules

Certifying Authority - A person granted a licence to issue D…

1 trigger · 9 rules

Controller of Certifying Authorities - The regulator that li…

1 trigger · 6 rules

Intermediary - Any person who receives

1 trigger · 3 rules

Cyber Cafe - A cyber cafe treated as an intermediary (Sectio…

1 trigger · 2 rules

Service Provider (CERT-In reporting) - A service provider

1 trigger · 2 rules

Digital Locker Service Provider - A Digital Locker intermedi…

1 trigger · 1 rules

Protected System Organisation - An organisation whose comput…

1 trigger · 2 rules

Subscriber / End Entity - A holder of an electronic-signatur…

1 trigger · 9 rules

Government Department / Agency - A Government department usi…

1 trigger · 8 rules

Rules & Subordinate Legislation

157 rules

Made under this Act

Statutory instruments & rules issued under its authority
  • 1. Short title, extent, commencement and application

    Short title, extent, commencement and application of the IT Act, 2000.

    Section 1
  • 2. Definitions

    ITA-06 (Intermediary): Observe the due diligence required of an intermediary. Breach: Failure to observe the prescribed due diligence. Penalty: Loss of the safe-harbour exemption u/s 79(1), so the intermediary becomes liable for the third-party information; failure to preserve required information -> s.67C (up to 3 years and fine).

    Rule under Section 2
  • 2. Definitions

    ITA-07 (CyberCafe): Register, identify users and maintain logs as an intermediary (cyber cafe). Breach: Failure to observe cyber-cafe due diligence (registration, user identification, logs). Penalty: Loss of the safe-harbour exemption u/s 79(1); residual contravention -> s.45.

    Rule under Section 2
  • 2. Definitions

    ITA-08 (ServiceProvider): Report cyber incidents and comply with CERT-In directions. Breach: Failure to report a cyber incident or to comply with a CERT-In direction. Penalty: Failure to provide information to, or comply with a direction of, CERT-In -> s.70B(7) (up to 1 year or fine up to Rs.1 lakh, or both).

    Rule under Section 2
  • 3. Authentication of electronic records

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 3
  • 3. Authentication of electronic records

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 3
  • 3A. Electronic signature

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 3A
  • 3A. Electronic signature

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 3A
  • 4. Legal recognition of electronic records

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 4
  • 5. Legal recognition of electronic signatures

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 5
  • 6. Use of electronic records and electronic signatures in Government and its agencies

    ITA-09 (EServiceProvider): Deliver public services electronically per the authorised framework. Breach: Non-compliance with the electronic service-delivery framework. Penalty: Misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 6
  • 6. Use of electronic records and electronic signatures in Government and its agencies

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 6
  • 6A. Delivery of services by service provider

    ITA-09 (EServiceProvider): Deliver public services electronically per the authorised framework. Breach: Non-compliance with the electronic service-delivery framework. Penalty: Misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 6A
  • 6A. Delivery of services by service provider

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 6A
  • 7. Retention of electronic records

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 7
  • 7A. Audit of documents, etc., maintained in electronic form

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 7A
  • 8. Publication of rule, regulation, etc., in Electronic Gazette

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 8
  • 9. Sections 6, 7 and 8 not to confer right to insist document should be accepted in electronic form

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 9
  • 10. Power to make rules by Central Government in respect of electronic signature

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 10
  • 10A. Validity of contracts formed through electronic means

    Validity of contracts formed through electronic means.

    Section 10A
  • 11. Attribution of electronic records

    Provides for attribution of electronic records.

    Section 11
  • 12. Acknowledgment of receipt

    Provides for acknowledgment of receipt.

    Section 12
  • 13. Time and place of despatch and receipt of electronic record

    Provides for time and place of despatch and receipt of electronic record.

    Section 13
  • 14. Secure electronic record

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 14
  • 14. Secure electronic record

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 14
  • 15. Secure electronic signature

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 15
  • 15. Secure electronic signature

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 15
  • 16. Security procedures and practices

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 16
  • 16. Security procedures and practices

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 16
  • 17. Appointment of Controller and other officers

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 17
  • 17. Appointment of Controller and other officers

    ITA-05 (ControllerStaff): Recruitment and conditions of service of officers/employees of the Office of the Controller.

    Rule under Section 17
  • 18. Functions of Controller

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 18
  • 19. Recognition of foreign Certifying Authorities

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 19
  • 20. [Omitted.]

    [Omitted by the IT (Amendment) Act, 2008.] The legal team notes that reliance on Section 20 is incorrect as it has been omitted.

    Section 20
  • 21. Licence to issue electronic signature Certificates

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 21
  • 21. Licence to issue electronic signature Certificates

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 21
  • 22. Application for licence

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 22
  • 22. Application for licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 22
  • 23. Renewal of licence

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 23
  • 23. Renewal of licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 23
  • 24. Procedure for grant or rejection of licence

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 24
  • 24. Procedure for grant or rejection of licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 24
  • 25. Suspension of licence

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 25
  • 25. Suspension of licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 25
  • 26. Notice of suspension or revocation of licence

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 26
  • 26. Notice of suspension or revocation of licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 26
  • 27. Power to delegate

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 27
  • 27. Power to delegate

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 27
  • 27. Power to delegate

    ITA-05 (ControllerStaff): Recruitment and conditions of service of officers/employees of the Office of the Controller.

    Rule under Section 27
  • 28. Power to investigate contraventions

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 28
  • 28. Power to investigate contraventions

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 28
  • 28. Power to investigate contraventions

    ITA-05 (ControllerStaff): Recruitment and conditions of service of officers/employees of the Office of the Controller.

    Rule under Section 28
  • 29. Access to computers and data

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 29
  • 29. Access to computers and data

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 29
  • 29. Access to computers and data

    ITA-05 (ControllerStaff): Recruitment and conditions of service of officers/employees of the Office of the Controller.

    Rule under Section 29
  • 30. Certifying Authority to follow certain procedures

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 30
  • 30. Certifying Authority to follow certain procedures

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 30
  • 31. Certifying Authority to ensure compliance of the Act, etc.

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 31
  • 32. Display of licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 32
  • 33. Surrender of licence

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 33
  • 34. Disclosure

    ITA-01 (CertifyingAuthority): Comply with Certifying Authority licensing, security and Digital Signature Certificate obligations. Breach: Failure to comply with CA licensing, security or DSC duties. Penalty: Failure to comply with the Controller's directions -> s.68 (up to 2 years / Rs.1 lakh); publishing a false DSC -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 34
  • 34. Disclosure

    ITA-02 (Controller): Exercise the Controller's licensing and supervisory functions (regulator).

    Rule under Section 34
  • 35. Certifying authority to issue electronic signature Certificate

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 35
  • 36. Representations upon issuance of Digital signature Certificate

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 36
  • 37. Suspension of Digital Signature Certificate

    Suspension of a Digital Signature Certificate.

    Section 37
  • 38. Revocation of Digital Signature Certificate

    Revocation of a Digital Signature Certificate.

    Section 38
  • 39. Notice of suspension or revocation

    Notice of suspension or revocation.

    Section 39
  • 40. Generating key pair

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 40
  • 40. Generating key pair

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 40
  • 40A. Duties of subscriber of Electronic Signature Certificate

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 40A
  • 40A. Duties of subscriber of Electronic Signature Certificate

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 40A
  • 41. Acceptance of Digital Signature Certificate

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 41
  • 41. Acceptance of Digital Signature Certificate

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 41
  • 42. Control of private key

    ITA-10 (Subscriber): Comply with secure electronic-record and electronic-signature / subscriber duties. Breach: Failure to comply with secure electronic-record / subscriber duties. Penalty: Publishing a false electronic-signature certificate -> s.73/s.74; misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 42
  • 42. Control of private key

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 42
  • 43. Penalty and compensation for damage to computer, computer system, etc.

    Penalty and compensation for damage to a computer, computer system, etc. (civil liability).

    Section 43
  • 43A. Compensation for failure to protect data

    [Omitted by the DPDP Act, 2023 (s.44).] Formerly: compensation for a body corporate's failure to protect sensitive personal data. Data-protection compensation is now governed by the DPDP Act, 2023.

    Section 43A
  • 44. Penalty for failure to furnish information, return, etc.

    Penalty for failure to furnish information, return, etc.

    Section 44
  • 45. Residuary penalty

    Residuary penalty.

    Section 45
  • 46. Power to adjudicate

    ITA-04 (AdjudicatingOfficer): Adjudicate contraventions under Chapter IX per the prescribed procedure.

    Rule under Section 46
  • 47. Factors to be taken into account by the adjudicating officer

    Factors to be taken into account by the Adjudicating Officer.

    Section 47
  • 48. Appellate Tribunal

    Appellate Tribunal (the Cyber Appellate Tribunal was merged into the TDSAT by the Finance Act, 2017).

    Section 48
  • 49. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 49
  • 50. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 50
  • 51. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 51
  • 52. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 52
  • 52A. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 52A
  • 52B. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 52B
  • 52C. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 52C
  • 52D. Decision by majority

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 52D
  • 53. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 53
  • 54. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 54
  • 55. Orders constituting Appellate Tribunal to be final and not to invalidate its proceedings

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 55
  • 56. [Omitted.]

    ITA-03 (PresidingOfficer): Service and conduct of the Presiding Officer / Chairperson / Members of the Cyber Appellate Tribunal.

    Rule under Section 56
  • 57. Appeal to Appellate Tribunal

    Appeal to the Appellate Tribunal.

    Section 57
  • 58. Procedure and powers of the Appellate Tribunal

    Procedure and powers of the Appellate Tribunal.

    Section 58
  • 59. Right to legal representation

    Provides for right to legal representation.

    Section 59
  • 60. Limitation

    Provides for limitation.

    Section 60
  • 61. Civil court not to have jurisdiction

    Provides for civil court not to have jurisdiction.

    Section 61
  • 62. Appeal to High Court

    Provides for appeal to high court.

    Section 62
  • 63. Compounding of contraventions

    Provides for compounding of contraventions.

    Section 63
  • 64. Recovery of penalty or compensation

    Provides for recovery of penalty or compensation.

    Section 64
  • 65. Tampering with computer source documents

    Tampering with computer source documents (up to 3 years or fine up to Rs.2 lakh).

    Section 65
  • 66. Computer related offences

    Computer related offences (up to 3 years or fine up to Rs.5 lakh).

    Section 66
  • 66A. Punishment for sending offensive messages through communication service, etc.

    [Struck down.] Sending offensive messages - declared unconstitutional in Shreya Singhal v. Union of India (2015) and unenforceable.

    Section 66A
  • 66B. Punishment for dishonestly receiving stolen computer resource or communication device

    Dishonestly receiving a stolen computer resource or communication device.

    Section 66B
  • 66C. Punishment for identity theft

    Identity theft.

    Section 66C
  • 66D. Punishment for cheating by personation by using computer resource

    Cheating by personation by using a computer resource.

    Section 66D
  • 66E. Punishment for violation of privacy

    Violation of privacy.

    Section 66E
  • 66F. Punishment for cyber terrorism

    Cyber terrorism (may extend to imprisonment for life).

    Section 66F
  • 67. Punishment for publishing or transmitting obscene material in electronic form

    Publishing/transmitting obscene material in electronic form.

    Section 67
  • 67A. Punishment for publishing or transmitting of material containing sexually explicit act, etc., in electronic form

    Sexually explicit material.

    Section 67A
  • 67B. Punishment for publishing or transmitting of material depicting children in sexually explicit act, etc., in electronic form

    Child sexually abusive material.

    Section 67B
  • 67C. Preservation and retention of information by intermediaries

    ITA-12 (DigitalLockerProvider): Preserve and retain information as a Digital Locker intermediary. Breach: Failure to preserve and retain information as required. Penalty: Failure to preserve/retain information -> s.67C (up to 3 years and fine); loss of the safe-harbour exemption u/s 79(1).

    Rule under Section 67C
  • 68. Power of Controller to give directions

    Power of the Controller to give directions (non-compliance up to 2 years or Rs.1 lakh).

    Section 68
  • 69. Power to issue directions for interception or monitoring or decryption of any information through any computer resource

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 69
  • 69A. Power to issue directions for blocking for public access of any information through any computer resource

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 69A
  • 69B. Power to authorise to monitor and collect traffic data or information through any computer resource for cyber security

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 69B
  • 70. Protected system

    ITA-13 (ProtectedSystemOrg): Implement information-security practices for the Protected System. Breach: Securing unauthorised access to, or failure to secure, a Protected System. Penalty: Securing unauthorised access to a Protected System -> s.70(3) (up to 10 years and fine).

    Rule under Section 70
  • 70. Protected system

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 70
  • 70A. National nodal agency

    ITA-13 (ProtectedSystemOrg): Implement information-security practices for the Protected System. Breach: Securing unauthorised access to, or failure to secure, a Protected System. Penalty: Securing unauthorised access to a Protected System -> s.70(3) (up to 10 years and fine).

    Rule under Section 70A
  • 70B. Indian Computer Emergency Response Team to serve as national agency for incident response

    ITA-08 (ServiceProvider): Report cyber incidents and comply with CERT-In directions. Breach: Failure to report a cyber incident or to comply with a CERT-In direction. Penalty: Failure to provide information to, or comply with a direction of, CERT-In -> s.70B(7) (up to 1 year or fine up to Rs.1 lakh, or both).

    Rule under Section 70B
  • 70B. Indian Computer Emergency Response Team to serve as national agency for incident response

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 70B
  • 71. Penalty for misrepresentation

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 71
  • 72. Penalty for Breach of confidentiality and privacy

    ITA-15 (GNCTD): Protect identity information and sensitive personal data held by the department. Breach: Failure to protect identity information / breach of confidentiality of personal data. Penalty: Breach of confidentiality/privacy -> s.72 (up to 2 years / Rs.1 lakh); disclosure in breach of a lawful contract -> s.72A (up to 3 years / Rs.5 lakh). Note: s.43A has been omitted; data-protection compensation is now under the DPDP Act, 2023.

    Rule under Section 72
  • 72A. Punishment for disclosure of information in breach of lawful contract

    ITA-15 (GNCTD): Protect identity information and sensitive personal data held by the department. Breach: Failure to protect identity information / breach of confidentiality of personal data. Penalty: Breach of confidentiality/privacy -> s.72 (up to 2 years / Rs.1 lakh); disclosure in breach of a lawful contract -> s.72A (up to 3 years / Rs.5 lakh). Note: s.43A has been omitted; data-protection compensation is now under the DPDP Act, 2023.

    Rule under Section 72A
  • 73. Penalty for publishing electronic signature Certificate false in certain particulars

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 73
  • 74. Publication for fraudulent purpose

    ITA-11 (EndEntity): Comply with electronic-signature / Digital Signature Certificate end-entity duties. Breach: Failure to comply with DSC / electronic-signature end-entity duties. Penalty: Publishing a false / fraudulent electronic-signature certificate -> s.73/s.74 (up to 2 years / Rs.1 lakh); misrepresentation -> s.71; residual contravention -> s.45.

    Rule under Section 74
  • 75. Act to apply for offence or contravention committed outside India

    Provides for act to apply for offence or contravention committed outside india.

    Section 75
  • 76. Confiscation

    Provides for confiscation.

    Section 76
  • 77. Compensation, penalties or confiscation not to interfere with other punishment

    Provides for compensation, penalties or confiscation not to interfere with other punishment.

    Section 77
  • 77A. Compounding of offences

    Provides for compounding of offences.

    Section 77A
  • 77B. Offences with three years imprisonment to be bailable

    Provides for offences with three years imprisonment to be bailable.

    Section 77B
  • 78. Power to investigate offences

    Provides for power to investigate offences.

    Section 78
  • 79. Exemption from liability of intermediary in certain cases

    ITA-06 (Intermediary): Observe the due diligence required of an intermediary. Breach: Failure to observe the prescribed due diligence. Penalty: Loss of the safe-harbour exemption u/s 79(1), so the intermediary becomes liable for the third-party information; failure to preserve required information -> s.67C (up to 3 years and fine).

    Rule under Section 79
  • 79. Exemption from liability of intermediary in certain cases

    ITA-07 (CyberCafe): Register, identify users and maintain logs as an intermediary (cyber cafe). Breach: Failure to observe cyber-cafe due diligence (registration, user identification, logs). Penalty: Loss of the safe-harbour exemption u/s 79(1); residual contravention -> s.45.

    Rule under Section 79
  • 79. Exemption from liability of intermediary in certain cases

    ITA-08 (ServiceProvider): Report cyber incidents and comply with CERT-In directions. Breach: Failure to report a cyber incident or to comply with a CERT-In direction. Penalty: Failure to provide information to, or comply with a direction of, CERT-In -> s.70B(7) (up to 1 year or fine up to Rs.1 lakh, or both).

    Rule under Section 79
  • 79A. Central Government to notify Examiner of Electronic Evidence

    Central Government to notify the Examiner of Electronic Evidence.

    Section 79A
  • 80. Power of police officer and other officers to enter, search, etc.

    Provides for power of police officer and other officers to enter, search, etc..

    Section 80
  • 81. Act to have overriding effect

    Provides for act to have overriding effect.

    Section 81
  • 81A. Application of the Act to electronic cheque and truncated cheque

    Provides for application of the act to electronic cheque and truncated cheque.

    Section 81A
  • 82. Controller, Deputy Controller and Assistant Controller to be public servants

    Provides for controller, deputy controller and assistant controller to be public servants.

    Section 82
  • 83. Power to give directions

    Provides for power to give directions.

    Section 83
  • 84. Protection of action taken in good faith

    Provides for protection of action taken in good faith.

    Section 84
  • 84A. Modes or methods for encryption

    Modes or methods for encryption.

    Section 84A
  • 84B. Punishment for abetment of offences

    Provides for punishment for abetment of offences.

    Section 84B
  • 84C. Punishment for attempt to commit offences

    Provides for punishment for attempt to commit offences.

    Section 84C
  • 85. Offences by companies

    Offences by companies.

    Section 85
  • 86. Removal of difficulties

    Provides for removal of difficulties.

    Section 86
  • 87. Power of Central Government to make rules

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 87
  • 88. Constitution of Advisory Committee

    Constitution of the Cyber Regulations Advisory Committee.

    Section 88
  • 89. Power of Controller to make regulations

    Power of the Controller to make regulations.

    Section 89
  • 90. Power of State Government to make rules

    ITA-14 (GovernmentDepartment): Comply with e-governance, interception/blocking/monitoring and protected-system provisions. Breach: Non-compliance with the applicable e-governance / interception / monitoring provisions. Penalty: Largely administrative; breach of confidentiality by an official -> s.72 (up to 2 years / Rs.1 lakh); residual contravention -> s.45.

    Rule under Section 90
  • 91. [Omitted.]

    [Omitted.]

    Section 91
  • 92. [Omitted.]

    [Omitted.]

    Section 92
  • 93. [Omitted.]

    [Omitted.]

    Section 93
  • 94. [Omitted.]

    [Omitted.]

    Section 94

Consumable API

Versioned JSON endpoints. Read access is open; write/usage needs a key.

cURL
JavaScript
Python
# Fetch the full law as JSON
curl https://lawascode.negd.in/laac-api/v1/laws/the-information-technology-act-2000

# Just the penalty schedule
curl https://lawascode.negd.in/laac-api/v1/laws/the-information-technology-act-2000/penalties

# A specific provision
curl https://lawascode.negd.in/laac-api/v1/laws/the-information-technology-act-2000/provisions/1