Breach of confidentiality and privacy – Sec.72

July 20, 2017

Section 72 of the Information Technology Act, 2000 penalizes the unauthorized disclosure of electronic records, books, registers, correspondence, or digital documents by persons who have secured access pursuant to statutory powers. Any individual who accesses electronic information under powers conferred by the Act or its regulations and discloses it without the consent of the concerned person faces imprisonment of up to two years, a fine of up to one lakh rupees, or both.

Statutory Framework of Section 72 of the Information Technology Act 2000

The Information Technology Act, 2000 serves as the primary legislative enactment in India governing electronic commerce, cyber offenses, data protection, and digital records administration. To maintain public confidence in electronic filings, digital signatures, subscriber identity management, and automated record-keeping systems, the legislature enacted Section 72 to establish strict confidentiality obligations for individuals exercising statutory oversight.

The statutory text of Section 72 provides:

Save as otherwise provided in this Act or any other law for the time being in force, any person who, in pursuant of any of the powers conferred under this Act, rules or regulations made there under, has secured access to any electronic record, book, register, correspondence, information, document or other material without the consent of the person concerned discloses such electronic record, book, register, correspondence, information, document or other material to any other person shall be punished with imprisonment for a term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.

Organizations handling sensitive communications, electronic registers, and digital identities frequently engage cyber security and data privacy legal consulting to align their information governance frameworks with statutory confidentiality mandates.

Essential Ingredients Constituting Breach of Confidentiality and Privacy

To establish a criminal offense under Section 72 of the Information Technology Act, the prosecution must substantiate several cumulative legal elements beyond reasonable doubt:

  • Statutory Power Origin: The accused must have secured access to the electronic material pursuant to specific powers conferred under the Information Technology Act, 2000 or the rules and regulations framed thereunder. This encompasses certifying authorities, network administrators, investigating officers, adjudicating officers, and statutory auditors exercising regulatory functions.
  • Nature of Electronic Material: The accessed data must constitute an electronic record, book, register, correspondence, confidential information, or official document as recognized under Section 2(1)(t) of the Act.
  • Lack of Consent: The access or subsequent dissemination must occur without the explicit or implied consent of the person to whom the record or personal information belongs.
  • Unauthorized Disclosure: The accused must actively disclose, publish, or transmit such electronic record to an unauthorized third person without legal sanction.

Statutory Penalties and Punishment Under Section 72

The offense under Section 72 carries a compound statutory punishment designed to deter regulatory functionaries and technical custodians from abusing official access. The court may impose:

  1. Imprisonment for a term that may extend up to two years.
  2. A monetary fine extending up to one lakh rupees (INR 1,00,000).
  3. Both imprisonment and monetary penalty simultaneously, depending upon the gravity of the data exposure and resulting commercial harm.

Under the First Schedule of the Code of Criminal Procedure, offenses under Section 72 are classified as bailable and non-cognizable, requiring an aggrieved person or authorized officer to lodge a formal complaint or petition before the competent judicial magistrate.

Distinction Between Section 72 and Section 72A of the IT Act

The Information Technology (Amendment) Act, 2008 introduced Section 72A to broaden the scope of liability beyond statutory functionaries to private service providers and commercial entities. Understanding the distinction between these two provisions is essential across diverse technology law and digital compliance practice areas:

  • Target Audience: Section 72 applies specifically to persons who access records while exercising powers under the IT Act. Section 72A applies to any person who discloses personal information acquired under a lawful contract or business relationship.
  • Mens Rea Standard: Section 72 focuses on unauthorized disclosure without consent. Section 72A requires proof of intention to cause wrongful loss or wrongful gain.
  • Penalty Threshold: Section 72 provides for imprisonment up to two years and fine up to one lakh rupees. Section 72A provides for enhanced imprisonment up to three years, a fine up to five lakh rupees, or both.

Lawful Disclosures, Statutory Exceptions, and Regulatory Duties

Section 72 begins with the non-obstante opening clause: "Save as otherwise provided in this Act or any other law for the time being in force". Consequently, disclosures made in compliance with mandatory statutory directives do not attract criminal culpability. Legitimate exceptions include:

  • Disclosures made pursuant to formal court orders, subpoenas, or judicial summons under Section 91 of the Code of Criminal Procedure.
  • Lawful interception and decryption requisitions issued by authorized government agencies under Section 69 of the Information Technology Act.
  • Mandatory incident reporting to the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Act.
  • Regulatory disclosures mandated by financial, corporate, or tax authorities under existing federal legislation.

Judicial Interpretations and Corporate Compliance Protocols

Indian courts have repeatedly held that the confidentiality protections under Section 72 must be interpreted strictly to preserve the constitutional right to privacy established in Justice K.S. Puttaswamy (Retd.) v. Union of India. When an officer or authorized custodian handles electronic databases containing sensitive communications, trade secrets, or personal data, the duty of secrecy is absolute unless overridden by explicit statutory provisions.

Commercial organizations and regulatory intermediaries must implement internal compliance systems to avoid accidental statutory violations. These safeguards include establishing non-disclosure agreements for system administrators, implementing strict segregation of duties, restricting privileged access rights, and conducting periodic forensic compliance audits across electronic repositories.

Digital Forensics, Electronic Evidence Preservation, and Privacy Compliance

In litigation involving unauthorized digital disclosures, technical evidence plays a decisive role in proving access logs, administrative credentials, and exfiltration paths. Investigating agencies and defense counsel must preserve electronic records in strict conformity with Section 65B of the Indian Evidence Act, 1872 (and Section 63 of the Bharatiya Sakshya Adhiniyam, 2023).

Organizations must maintain immutable audit trails, role-based access controls, and encrypted data storage to prevent insider leaks. Where unauthorized disclosure is alleged, forensic analysis of server metadata, timestamp integrity, and user session tokens provides the evidentiary foundation for establishing or rebutting culpability under Section 72 of the IT Act.

Found this helpful?

Share this page with others