India processes billions of digital transactions every day – from online banking and e-commerce to government services and healthcare records. That scale of digital activity also opens the door to serious misuse: unauthorized data access, identity theft, system sabotage, and corporate negligence. The Information Technology Act, 2000 (IT Act) is India’s primary legislation for addressing these threats. It doesn’t just define what counts as a cyber wrong – it prescribes specific consequences, ranging from financial compensation to criminal imprisonment. Understanding how these penalties work is essential for anyone operating in India’s digital landscape, whether as an individual, a professional, or a business.

Table of Contents

The difference between civil penalties and criminal offences

Before diving into specific sections, it’s worth understanding a fundamental distinction the IT Act makes. Civil penalties are about compensation – the wronged party files a claim, and the offender pays damages. These cases are handled by an Adjudicating Officer, making the process faster than a full criminal trial. Criminal offences, on the other hand, are treated as crimes against society. The police investigate, the case goes to a criminal court, and punishments can include imprisonment. Crucially, the same act – say, accessing a database without permission – can be either a civil wrong or a crime, depending on the person’s intent. This intent-based distinction is central to how the IT Act is structured.

Section 43: Civil penalties for unauthorized access

Section 43 of the IT Act is the cornerstone of civil liability in Indian cyber law. It covers a wide range of unauthorized digital activities and holds the offender liable to pay compensation to the affected party – even if the act was accidental or unintentional. This is an important point: you don’t need criminal intent for Section 43 to apply.

What activities does Section 43 cover?

The section lists several specific prohibited acts, all carried out without the permission of the owner or the person in charge of a computer system or network. These include:

  • Unauthorized access: Simply accessing or securing access to a computer, system, or network without permission triggers liability.
  • Data extraction: Downloading, copying, or extracting data – including data stored on removable storage media – without authorization is prohibited.
  • Introducing contaminants: Introducing a computer virus or any other harmful software (a “computer contaminant”) into a system falls under this section.
  • Causing disruption: Deliberately disrupting the functioning of a computer system or network, including denial-of-service attacks, is covered.
  • Denial of access: Preventing authorized users from accessing a system they have a right to use.
  • Tampering with source code: Destroying, altering, or otherwise tampering with computer source code.

What is the compensation amount?

Originally, compensation under Section 43 was capped at โ‚น1 crore. The Information Technology (Amendment) Act, 2008 removed this ceiling. Today, victims can claim higher amounts through adjudicating officers, and if the compensation exceeds โ‚น5 crores, the matter is transferred to a civil court. There is no imprisonment under Section 43 alone – the punishment is purely financial, focused on redress and deterrence.

A landmark illustration of Section 43 in practice is the Mphasis BPO fraud (2005), widely considered India’s first major call centre scam. In that case, employees accessed Citibank customers’ PIN codes without authorization and transferred approximately $426,000 from US accounts into fraudulent Indian accounts. The accused were charged under Section 43(a) as well as Section 66 of the IT Act, alongside provisions of the Indian Penal Code for cheating and forgery – a multi-statute approach that has since become standard practice in complex cybercrime cases.

Section 43 versus Section 66: the intent question

Section 43 creates civil liability regardless of intent. However, when the same acts are committed dishonestly or fraudulently, Section 66 comes into play as the criminal counterpart. Under Section 66, the punishment includes imprisonment for up to three years, a fine of up to โ‚น5 lakh, or both. Together, Sections 43 and 66 form a layered framework – civil compensation for harm caused, criminal prosecution when fraudulent intent is proven.

Section 44: Penalties for failure to furnish information

While Section 43 deals with active wrongdoing, Section 44 addresses passive non-compliance – specifically, the failure to fulfill disclosure and record-keeping obligations that the IT Act or its regulations require. These obligations typically apply to entities regulated under the Act, such as those involved with digital certificates or Certifying Authorities.

Three-tier penalty structure under Section 44

Section 44 sets out a clear, graduated penalty structure based on the nature of the failure:

  • Failure to furnish documents or reports: If a person required to submit any document, return, or report to the Controller or Certifying Authority fails to do so, they are liable to a penalty of up to โ‚น1,50,000 for each such failure.
  • Failure to file returns or information on time: If a person fails to file returns or furnish information, books, or other documents within the time specified by regulations, they face a penalty of up to โ‚น5,000 for every day the failure continues.
  • Failure to maintain books of account or records: If a person fails to maintain the required books of account or other records, the penalty can be up to โ‚น10,000 for every day the failure continues.

The daily accrual model for the second and third categories is deliberate – it creates a continuous financial incentive to remedy the non-compliance as quickly as possible. The longer a company delays, the heavier the financial burden grows.

Criminal offences under Chapter XI

Chapter XI of the IT Act (Sections 65 to 74) moves beyond civil liability into the territory of outright criminal offences. These are acts that the law treats as serious enough to warrant prosecution, imprisonment, and fines – not just financial compensation paid to a victim. The chapter covers a broad spectrum of cybercrimes, reflecting the many ways in which digital technology can be misused to harm individuals, institutions, and the state.

Key offences and their punishments

Section 65 – Tampering with computer source documents: Intentionally concealing, destroying, or altering computer source code when legally required to maintain it carries a penalty of up to โ‚น2,00,000, or imprisonment of up to three years, or both.

Section 66 – Computer-related offences: As discussed above, this is the criminal counterpart to Section 43. Committing any of the acts in Section 43 with dishonest or fraudulent intent attracts imprisonment of up to three years, a fine of up to โ‚น5 lakh, or both.

Section 66C – Identity theft: Fraudulently using another person’s electronic signature, password, or any unique identification feature is punishable with imprisonment of up to three years and a fine of up to โ‚น1 lakh.

Section 66D – Cheating by personation: Using a computer resource or communication device to cheat by impersonating someone else also carries imprisonment of up to three years and a fine of up to โ‚น1 lakh.

Section 66E – Violation of privacy: Intentionally capturing, publishing, or transmitting images of a person’s private areas without their consent is punishable with imprisonment of up to three years or a fine of up to โ‚น2 lakh.

Section 67 series – Obscene and sexually explicit content: Publishing or transmitting obscene material electronically (Section 67) carries imprisonment of up to three years and a fine of โ‚น5 lakh on first conviction, increasing on subsequent offences. Section 67A covers sexually explicit content (up to five years imprisonment), while Section 67B specifically addresses material depicting children in sexually explicit acts, attracting the same penalties.

Section 66F – Cyber terrorism: This is the most severe provision in the IT Act. It covers acts carried out with the intent to threaten the unity, integrity, security, or sovereignty of India through digital means – such as unauthorized access to protected systems like power grids or military networks, or introducing contaminants that could cause widespread disruption or death. The punishment for cyber terrorism can extend to life imprisonment. The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency responsible for tracking and responding to such high-level threats.

Section 85: Liability of companies and their officers

A critical question arises when the offender is not an individual but a corporation. You cannot imprison a company. The IT Act addresses this directly through Section 85, “Offences by Companies.”

Who is held liable when a company commits an offence?

Section 85(1) establishes that when a company commits a contravention of any provision of the IT Act, every person who was in charge of and responsible to the company for the conduct of its business at the time of the offence shall be deemed guilty and liable to be prosecuted. This means senior management – directors, managers, and officers – can face personal criminal liability for their company’s digital wrongdoing.

Section 85(2) extends this further. Even if an officer was not directly in charge of the business, if it is proven that the contravention took place with their consent or connivance, or is attributable to any neglect on their part, they too can be held guilty. This covers directors, managers, secretaries, and other officers of the company.

The Act also clarifies the scope of the term “company” in an explanation: it means any body corporate and includes firms and other associations of individuals. A “director” in the context of a firm refers to a partner in that firm.

The due diligence defence

Section 85 does provide an escape route, but the burden of proof rests squarely on the accused officer. A director or manager can avoid liability by proving one of two things: first, that the offence was committed without their knowledge; or second, that they had exercised all due diligence to prevent the commission of the offence.

That second condition – “due diligence” – has significant practical implications. Under India’s cybersecurity law framework, directors are expected to ensure that companies have implemented adequate security measures, cybersecurity policies, staff training programs, and regular audits. A passive claim of ignorance is not enough. If a data breach occurs because the company had no security policy and never trained its employees, the directors are likely to be held personally responsible. This provision effectively makes cybersecurity a boardroom-level obligation – not just an IT department concern.

Section 85 of the IT Act specifically states that any person in charge of supervising a company’s affairs will be liable unless they can prove the contravention occurred without their knowledge or that they exercised all due diligence to prevent it. This is why large organizations today invest heavily in cybersecurity frameworks, compliance audits, and incident response protocols – not merely as good practice, but as legal protection for the people at the top.

The Avnish Bajaj case: a landmark judicial interpretation

The Bazee.com case involving Avnish Bajaj (then CEO of Baazee.com, an eBay subsidiary) tested the limits of Section 85 in Indian courts. A prima facie case was initially made against Bajaj for an offence under Section 67 of the IT Act after obscene content was listed on the platform by a third-party user. However, the Supreme Court later overturned the finding, holding that vicarious liability under Section 85 cannot be fastened to a director if the company itself has not been made an accused in the case. This ruling had a direct influence on subsequent amendments to the IT Act, particularly the strengthening of Section 79, which provides safe harbour protection to intermediaries for third-party content under defined conditions.

The broader enforcement architecture

The penalties and offences under the IT Act don’t operate in isolation. Chapter IX (Sections 43-47) handles civil liabilities through Adjudicating Officers, while Chapter XI (Sections 65-74) handles criminal offences through the regular criminal courts. Victims can also approach the National Cyber Crime Reporting Portal to file complaints, and CERT-In coordinates responses to significant cybersecurity incidents at the national level. This dual-track system – civil remedies for compensation, criminal prosecution for punishment – gives the law flexibility to respond proportionately to a wide range of cyber misconduct, from minor negligence to acts of terror.

What do you think? Given that Section 85 places personal criminal liability on company directors for cybersecurity failures, do you think this is sufficient to drive genuine boardroom-level investment in data protection – or does the law need stronger, more specific mandates? And with the scale of modern data breaches involving millions of records, is a compensation-focused civil remedy under Section 43 still a realistic deterrent for large corporations?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.indiacode.nic.in/handle/123456789/1999
  2. https://cis-india.org/internet-governance/resources/section-43-it-act.txt
  3. https://disaster.shiksha/industrial-safety-rules-acts/understanding-section-43-it-act-penalty/
  4. https://thelaw.institute/regulation-of-cyberspace/penalties-offences-information-technology-act/
  5. https://indiankanoon.org/doc/1258940/
  6. https://en.wikipedia.org/wiki/Information_Technology_Act,_2000
  7. https://www.cert-in.org.in/
  8. https://indiankanoon.org/doc/1708482/
  9. https://www.nishithdesai.com/SectionCategory/33/Technology-Law-Analysis/12/60/TechnologyLawAnalysis/5026/3.html
  10. https://naavi.org/geeta_narula/corporate_criminal_liability_nov12.html
  11. https://iclg.com/practice-areas/cybersecurity-laws-and-regulations/india
  12. https://www.lexology.com/library/detail.aspx?g=4cd0bdb1-da7d-4a04-bd9c-30881dd3eadf
  13. https://www.cybercrime.gov.in

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Contemporary Scenario of Digital Media

1 Emergence of Digital Media

  1. Defining Digital Media
  2. Characteristics of Digital Media
  3. Digital Media in India
  4. Digital Media and Journalism: Emerging Trends
  5. Challenges

2 Information Society

  1. Technological Transformation and Human Progress
  2. The Emergence of Information Society
  3. What is a Knowledge/Information Society?
  4. Knowledge Economy and Knowledge Workers in an Information Society
  5. Skill Acquisition and Training for Work in Knowledge Society
  6. ICT Infrastructure and Knowledge Dissemination

3 Emerging Trendsโ€“Media, Internet, Globalisation

  1. Media
  2. Internet
  3. Globalisation and Human Rights

4 ICTs and Women (Issues of Access and Equity)

  1. Gender Issues in ICT
  2. Womenโ€™s Access to ICTs
  3. Strategies for Gender Equity
  4. Benefits of ICTs for Women

5 India Diaspora in Cyberspace

  1. Defining Cyberspace
  2. Understanding Virtual Community
  3. Indian Digital Diasporas
  4. A critical Overview of Literature on Indian Digital Diasporas
  5. ICTs, Nationalism, Religious Diasporas
  6. South Asian Digital Diasporas-Mobile (gadget) Generations

6 ICT and Disability

  1. ICT for Persons with Disabilities
  2. Present and Future of ICT
  3. ICT for various types of Disabilities

7 Convergent Technologies

  1. Electronic Information
  2. Networked Society
  3. Genesis of Convergence
  4. Driving Factors
  5. Technology Convergence
  6. Network Convergence
  7. Switching Convergence
  8. Access Convergence
  9. Service Convergence

8 Open Source Movement

  1. History of Open Source
  2. Open Source Movement
  3. Open Source Software: Philosophy, Principles and Licensing
  4. Types of Software
  5. Desirable Software Attributes
  6. Advantages of Open Source Software
  7. Legal Issues
  8. Other Successful Open Source Software
  9. Applications of Open Source in Other Fields

9 The Regulability of Cyberspace

  1. Desirability of Regulation of Cyberspace
  2. How Cyberspace can be Regulated
  3. Legal and Self Regulatory Framework
  4. Government Policies and Laws Regarding Regulation of Internet Content
  5. Regulation of Cyberspace Content in the United States
  6. Regulation of Cyberspace Content in Australia
  7. Regulation of Cyberspace Content in European Union
  8. Regulation of Cyberspace Content in the United Kingdom
  9. Regulation of Cyberspace Content in India
  10. International Initiatives for Regulation of Cyberspace

10 New Media and Ethical Issues

  1. Definition of New Media Ethics
  2. Rights and Ethical responsibilities of Content Creators
  3. Content Curation and Limits to Sharing
  4. Rights and Ethics of Online Readers
  5. Dealing with Ethical Violations

11 The Concept of Security in Cyberspace

  1. Cyberspace โ€“ Why is it not Secure?
  2. Why Should We Secure Cyberspace?
  3. Security Challenges in Cyberspace
  4. The Concept of Cyber Security
  5. Computer Related or Computer Facilitated Crime
  6. Application of Basic Criminal law Concepts

12 Cyberspace and Cyber Crime

  1. Real Space Vs Cyberspace
  2. Digital Identity: An Overview
  3. Verifying Vs. Revealing an Identity
  4. Cyber and Computer Crimes
  5. Architecture of Cyberspace
  6. Preventing Crimes
  7. Implications of Choosing the Link System
  8. Road to Implementation

13 Cyber Law

  1. Concept of Cyberspace
  2. Issues emerging from cyberspace and the need for regulation
  3. International and National Cyber Laws
  4. Information Technology Act, 2000 as amended
  5. Cyber Crimes

14 Information Technology (IT) Act

  1. Statement of Objects and Reasons
  2. Application of the Act โ€“ The Extra-Territorial Effect
  3. Electronic Signatures
  4. E-governance
  5. Adjudication
  6. Penalties and Offences
  7. Network Service Provider Liability
  8. Amendments to the Information Technology Act, 14000
  9. Amendments to Certain Statutes