India processes billions of digital transactions every day – from online banking and e-commerce to government services and healthcare records. That scale of digital activity also opens the door to serious misuse: unauthorized data access, identity theft, system sabotage, and corporate negligence. The Information Technology Act, 2000 (IT Act) is India’s primary legislation for addressing these threats. It doesn’t just define what counts as a cyber wrong – it prescribes specific consequences, ranging from financial compensation to criminal imprisonment. Understanding how these penalties work is essential for anyone operating in India’s digital landscape, whether as an individual, a professional, or a business.
Table of Contents
- The difference between civil penalties and criminal offences
- Section 43: Civil penalties for unauthorized access
- What activities does Section 43 cover?
- What is the compensation amount?
- Section 43 versus Section 66: the intent question
- Section 44: Penalties for failure to furnish information
- Three-tier penalty structure under Section 44
- Criminal offences under Chapter XI
- Key offences and their punishments
- Section 85: Liability of companies and their officers
- Who is held liable when a company commits an offence?
- The due diligence defence
- The Avnish Bajaj case: a landmark judicial interpretation
- The broader enforcement architecture
The difference between civil penalties and criminal offences
Before diving into specific sections, it’s worth understanding a fundamental distinction the IT Act makes. Civil penalties are about compensation – the wronged party files a claim, and the offender pays damages. These cases are handled by an Adjudicating Officer, making the process faster than a full criminal trial. Criminal offences, on the other hand, are treated as crimes against society. The police investigate, the case goes to a criminal court, and punishments can include imprisonment. Crucially, the same act – say, accessing a database without permission – can be either a civil wrong or a crime, depending on the person’s intent. This intent-based distinction is central to how the IT Act is structured.
Section 43: Civil penalties for unauthorized access
Section 43 of the IT Act is the cornerstone of civil liability in Indian cyber law. It covers a wide range of unauthorized digital activities and holds the offender liable to pay compensation to the affected party – even if the act was accidental or unintentional. This is an important point: you don’t need criminal intent for Section 43 to apply.
What activities does Section 43 cover?
The section lists several specific prohibited acts, all carried out without the permission of the owner or the person in charge of a computer system or network. These include:
- Unauthorized access: Simply accessing or securing access to a computer, system, or network without permission triggers liability.
- Data extraction: Downloading, copying, or extracting data – including data stored on removable storage media – without authorization is prohibited.
- Introducing contaminants: Introducing a computer virus or any other harmful software (a “computer contaminant”) into a system falls under this section.
- Causing disruption: Deliberately disrupting the functioning of a computer system or network, including denial-of-service attacks, is covered.
- Denial of access: Preventing authorized users from accessing a system they have a right to use.
- Tampering with source code: Destroying, altering, or otherwise tampering with computer source code.
What is the compensation amount?
Originally, compensation under Section 43 was capped at โน1 crore. The Information Technology (Amendment) Act, 2008 removed this ceiling. Today, victims can claim higher amounts through adjudicating officers, and if the compensation exceeds โน5 crores, the matter is transferred to a civil court. There is no imprisonment under Section 43 alone – the punishment is purely financial, focused on redress and deterrence.
A landmark illustration of Section 43 in practice is the Mphasis BPO fraud (2005), widely considered India’s first major call centre scam. In that case, employees accessed Citibank customers’ PIN codes without authorization and transferred approximately $426,000 from US accounts into fraudulent Indian accounts. The accused were charged under Section 43(a) as well as Section 66 of the IT Act, alongside provisions of the Indian Penal Code for cheating and forgery – a multi-statute approach that has since become standard practice in complex cybercrime cases.
Section 43 versus Section 66: the intent question
Section 43 creates civil liability regardless of intent. However, when the same acts are committed dishonestly or fraudulently, Section 66 comes into play as the criminal counterpart. Under Section 66, the punishment includes imprisonment for up to three years, a fine of up to โน5 lakh, or both. Together, Sections 43 and 66 form a layered framework – civil compensation for harm caused, criminal prosecution when fraudulent intent is proven.
Section 44: Penalties for failure to furnish information
While Section 43 deals with active wrongdoing, Section 44 addresses passive non-compliance – specifically, the failure to fulfill disclosure and record-keeping obligations that the IT Act or its regulations require. These obligations typically apply to entities regulated under the Act, such as those involved with digital certificates or Certifying Authorities.
Three-tier penalty structure under Section 44
Section 44 sets out a clear, graduated penalty structure based on the nature of the failure:
- Failure to furnish documents or reports: If a person required to submit any document, return, or report to the Controller or Certifying Authority fails to do so, they are liable to a penalty of up to โน1,50,000 for each such failure.
- Failure to file returns or information on time: If a person fails to file returns or furnish information, books, or other documents within the time specified by regulations, they face a penalty of up to โน5,000 for every day the failure continues.
- Failure to maintain books of account or records: If a person fails to maintain the required books of account or other records, the penalty can be up to โน10,000 for every day the failure continues.
The daily accrual model for the second and third categories is deliberate – it creates a continuous financial incentive to remedy the non-compliance as quickly as possible. The longer a company delays, the heavier the financial burden grows.
Criminal offences under Chapter XI
Chapter XI of the IT Act (Sections 65 to 74) moves beyond civil liability into the territory of outright criminal offences. These are acts that the law treats as serious enough to warrant prosecution, imprisonment, and fines – not just financial compensation paid to a victim. The chapter covers a broad spectrum of cybercrimes, reflecting the many ways in which digital technology can be misused to harm individuals, institutions, and the state.
Key offences and their punishments
Section 65 – Tampering with computer source documents: Intentionally concealing, destroying, or altering computer source code when legally required to maintain it carries a penalty of up to โน2,00,000, or imprisonment of up to three years, or both.
Section 66 – Computer-related offences: As discussed above, this is the criminal counterpart to Section 43. Committing any of the acts in Section 43 with dishonest or fraudulent intent attracts imprisonment of up to three years, a fine of up to โน5 lakh, or both.
Section 66C – Identity theft: Fraudulently using another person’s electronic signature, password, or any unique identification feature is punishable with imprisonment of up to three years and a fine of up to โน1 lakh.
Section 66D – Cheating by personation: Using a computer resource or communication device to cheat by impersonating someone else also carries imprisonment of up to three years and a fine of up to โน1 lakh.
Section 66E – Violation of privacy: Intentionally capturing, publishing, or transmitting images of a person’s private areas without their consent is punishable with imprisonment of up to three years or a fine of up to โน2 lakh.
Section 67 series – Obscene and sexually explicit content: Publishing or transmitting obscene material electronically (Section 67) carries imprisonment of up to three years and a fine of โน5 lakh on first conviction, increasing on subsequent offences. Section 67A covers sexually explicit content (up to five years imprisonment), while Section 67B specifically addresses material depicting children in sexually explicit acts, attracting the same penalties.
Section 66F – Cyber terrorism: This is the most severe provision in the IT Act. It covers acts carried out with the intent to threaten the unity, integrity, security, or sovereignty of India through digital means – such as unauthorized access to protected systems like power grids or military networks, or introducing contaminants that could cause widespread disruption or death. The punishment for cyber terrorism can extend to life imprisonment. The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency responsible for tracking and responding to such high-level threats.
Section 85: Liability of companies and their officers
A critical question arises when the offender is not an individual but a corporation. You cannot imprison a company. The IT Act addresses this directly through Section 85, “Offences by Companies.”
Who is held liable when a company commits an offence?
Section 85(1) establishes that when a company commits a contravention of any provision of the IT Act, every person who was in charge of and responsible to the company for the conduct of its business at the time of the offence shall be deemed guilty and liable to be prosecuted. This means senior management – directors, managers, and officers – can face personal criminal liability for their company’s digital wrongdoing.
Section 85(2) extends this further. Even if an officer was not directly in charge of the business, if it is proven that the contravention took place with their consent or connivance, or is attributable to any neglect on their part, they too can be held guilty. This covers directors, managers, secretaries, and other officers of the company.
The Act also clarifies the scope of the term “company” in an explanation: it means any body corporate and includes firms and other associations of individuals. A “director” in the context of a firm refers to a partner in that firm.
The due diligence defence
Section 85 does provide an escape route, but the burden of proof rests squarely on the accused officer. A director or manager can avoid liability by proving one of two things: first, that the offence was committed without their knowledge; or second, that they had exercised all due diligence to prevent the commission of the offence.
That second condition – “due diligence” – has significant practical implications. Under India’s cybersecurity law framework, directors are expected to ensure that companies have implemented adequate security measures, cybersecurity policies, staff training programs, and regular audits. A passive claim of ignorance is not enough. If a data breach occurs because the company had no security policy and never trained its employees, the directors are likely to be held personally responsible. This provision effectively makes cybersecurity a boardroom-level obligation – not just an IT department concern.
Section 85 of the IT Act specifically states that any person in charge of supervising a company’s affairs will be liable unless they can prove the contravention occurred without their knowledge or that they exercised all due diligence to prevent it. This is why large organizations today invest heavily in cybersecurity frameworks, compliance audits, and incident response protocols – not merely as good practice, but as legal protection for the people at the top.
The Avnish Bajaj case: a landmark judicial interpretation
The Bazee.com case involving Avnish Bajaj (then CEO of Baazee.com, an eBay subsidiary) tested the limits of Section 85 in Indian courts. A prima facie case was initially made against Bajaj for an offence under Section 67 of the IT Act after obscene content was listed on the platform by a third-party user. However, the Supreme Court later overturned the finding, holding that vicarious liability under Section 85 cannot be fastened to a director if the company itself has not been made an accused in the case. This ruling had a direct influence on subsequent amendments to the IT Act, particularly the strengthening of Section 79, which provides safe harbour protection to intermediaries for third-party content under defined conditions.
The broader enforcement architecture
The penalties and offences under the IT Act don’t operate in isolation. Chapter IX (Sections 43-47) handles civil liabilities through Adjudicating Officers, while Chapter XI (Sections 65-74) handles criminal offences through the regular criminal courts. Victims can also approach the National Cyber Crime Reporting Portal to file complaints, and CERT-In coordinates responses to significant cybersecurity incidents at the national level. This dual-track system – civil remedies for compensation, criminal prosecution for punishment – gives the law flexibility to respond proportionately to a wide range of cyber misconduct, from minor negligence to acts of terror.
What do you think? Given that Section 85 places personal criminal liability on company directors for cybersecurity failures, do you think this is sufficient to drive genuine boardroom-level investment in data protection – or does the law need stronger, more specific mandates? And with the scale of modern data breaches involving millions of records, is a compensation-focused civil remedy under Section 43 still a realistic deterrent for large corporations?
References
- https://www.indiacode.nic.in/handle/123456789/1999
- https://cis-india.org/internet-governance/resources/section-43-it-act.txt
- https://disaster.shiksha/industrial-safety-rules-acts/understanding-section-43-it-act-penalty/
- https://thelaw.institute/regulation-of-cyberspace/penalties-offences-information-technology-act/
- https://indiankanoon.org/doc/1258940/
- https://en.wikipedia.org/wiki/Information_Technology_Act,_2000
- https://www.cert-in.org.in/
- https://indiankanoon.org/doc/1708482/
- https://www.nishithdesai.com/SectionCategory/33/Technology-Law-Analysis/12/60/TechnologyLawAnalysis/5026/3.html
- https://naavi.org/geeta_narula/corporate_criminal_liability_nov12.html
- https://iclg.com/practice-areas/cybersecurity-laws-and-regulations/india
- https://www.lexology.com/library/detail.aspx?g=4cd0bdb1-da7d-4a04-bd9c-30881dd3eadf
- https://www.cybercrime.gov.in
Leave a Reply