These PG Diploma Cyber Law E Commerce class notes provide an in-depth academic and practical overview of the legal framework governing online commerce in India. The curriculum covers foundational concepts of digital transactions, technical protocols, statutory recognition under the Information Technology Act 2000, international harmonization, and electronic banking rules. Students preparing for semester examinations should review this guide alongside our specialized PGD Cyber Law Exam Guide.
Unit I: Fundamentals, Evolution, and Business Models of E-Commerce
Electronic commerce refers to the buying, selling, marketing, and servicing of goods and services over computer-mediated networks. E-commerce transformed traditional commercial practices by replacing paper-based documentation with electronic data interchange (EDI), automated supply chain tracking, and online payment settlements. The transition from early bulletin board systems to sophisticated multi-vendor digital platforms has eliminated geographical barriers and created dynamic global marketplaces.
The primary commercial classifications of e-commerce include:
- Business to Business (B2B): High-volume transactions between commercial enterprises, manufacturers, and wholesale distributors utilizing dedicated electronic procurement networks and automated enterprise resource planning systems.
- Business to Consumer (B2C): Retail transactions where commercial entities sell goods, software, and digital services directly to individual consumers via specialized digital storefronts and mobile applications.
- Consumer to Consumer (C2C): Direct exchanges between private individuals facilitated by online intermediaries, auction websites, and peer-to-peer marketplaces.
- Consumer to Business (C2B): Models where individual consumers offer freelance services, digital content, or custom pricing bids to commercial enterprises.
E-commerce offers major advantages, including 24/7 transaction availability, reduced operational overhead, global market reach, and customized consumer targeting. However, it also introduces significant legal disadvantages, such as jurisdictional ambiguity in cross-border disputes, consumer privacy vulnerabilities, data theft, and sophisticated electronic payment fraud.
Unit II: Technical Framework, Cryptography, and Transaction Security
Secure electronic commerce relies upon a resilient technical infrastructure designed to guarantee data confidentiality, message integrity, user authentication, and non-repudiation. Central to this architecture is the science of cryptography, which transforms readable plaintext into unreadable ciphertext through mathematical algorithms.
Key technical components examined in cyber law include:
- Symmetric Key Cryptography: Employs a single shared secret key for both encryption and decryption, requiring secure out-of-band key-exchange mechanisms between communicating parties.
- Asymmetric Key Cryptography: Utilizes mathematically linked key pairs comprising a private key (retained secretly by the owner) and a public key (distributed openly), creating the structural foundation for public key infrastructure (PKI).
- Cryptographic Hash Functions: One-way algorithms that generate fixed-length digital fingerprints of electronic documents, ensuring that any subsequent modification of data during transmission is instantly detected.
- Online Advertising and Trading Standards: Regulatory constraints governing digital behavioral advertising, disclosure of commercial terms, electronic consumer consent, and algorithmic pricing practices.
Unit III: Digital Signatures and Certifying Authorities Under the IT Act
Section 3 and Section 3A of the Information Technology Act 2000 establish the statutory mechanism for authenticating electronic records through digital signatures and electronic signatures. The regulatory structure governing digital signature and certifying authorities IT Act involves a hierarchical licensing system administered by the Controller of Certifying Authorities (CCA):
- Appointment and Functions of CCA: Appointed by the Central Government under Section 17, the CCA exercises supervisory jurisdiction over all licensed Certifying Authorities (CAs), lays down technical security standards, and maintains the National Repository of Digital Certificates.
- Licensing and Duties of Certifying Authorities: Licensed entities issue Digital Signature Certificates (DSC) to subscribers after verifying their identity and credentials. CAs must adhere to strict security guidelines, maintain reliable hardware and software systems, and prevent certificate compromise.
- Duties of Subscribers: Subscribers must generate their key pairs using secure mechanisms, exercise due diligence to maintain exclusive control over their private keys, and notify the CA immediately upon key compromise.
- Suspension and Revocation of Certificates: Sections 37 and 38 specify statutory grounds for suspending or revoking DSCs, including subscriber misrepresentation, death, insolvency, or dissolution of the subscriber entity.
Unit IV: Statutory Recognition, Evidence, and UNCITRAL Model Law
The IT Act 2000 legal framework for ecommerce was enacted to give effect to the United Nations Commission on International Trade Law (UNCITRAL) Model Law on Electronic Commerce adopted in 1996. Our UNCITRAL Model Law on Electronic Commerce notes emphasize two core principles: functional equivalence (treating electronic records on par with traditional paper documents) and non-discrimination against technology.
Statutory integration across Indian laws includes:
- Legal Recognition of Electronic Records: Sections 4, 5, and 10A of the IT Act validate electronic documents, digital signatures, and electronic contracts formed through automated data exchanges.
- Evidentiary Proof and Admissibility: The evidentiary value of electronic records under Indian law is governed by Section 65B of the Indian Evidence Act 1872, requiring a statutory certificate from a responsible manager to admit printouts, server logs, and digital correspondence in judicial trials.
- Negotiable Instruments Amendments: Amendments to the Negotiable Instruments Act 1881 formally recognized electronic cheques and truncated cheque images, accelerating banking clearance cycles.
Furthermore, digital transactions operate under broader statutory compliance frameworks, including statutory oversight mechanisms under Section 69B of the IT Act for cybersecurity monitoring.
Unit V: Electronic Banking, Plastic Money, and Payment Systems
Modern commercial law addresses diverse legal issues in electronic banking and plastic money, redefining the traditional banker-customer fiduciary relationship. The transition from physical branches to internet banking, automated teller machines (ATMs), point-of-sale (POS) terminals, and mobile payment interfaces has generated complex liability questions.
Key legal dimensions governing digital banking include:
- Plastic Money Regulation: Rights, duties, and chargeback liabilities arising from debit cards, credit cards, prepaid payment instruments (PPIs), and smart cards.
- Electronic Fund Transfer Frameworks: Operating rules established by the Reserve Bank of India (RBI) under the Payment and Settlement Systems Act 2007 for Real Time Gross Settlement (RTGS), National Electronic Funds Transfer (NEFT), Immediate Payment Service (IMPS), and Unified Payments Interface (UPI).
- Allocation of Fraud Liability: Under statutory RBI circulars, customer liability in unauthorized electronic transactions is strictly limited based on the promptness of reporting. Zero customer liability applies when the fraud results from contributory negligence by the bank or a third-party breach without customer fault. Limited customer liability applies when reports are submitted within specified daily windows.
