Class Notes on PG. Diploma Cyber Law - Law and The Internet (SEM I)

December 2, 2012

These PG diploma cyber law study notes provide an in-depth academic analysis of the law and the internet semester 1 syllabus, covering digital governance, legal recognition of electronic records, cyber crimes, and network intermediary liability. The rapid expansion of digital networks has transformed commercial transactions and communications while introducing complex legal issues that challenge conventional territorial jurisprudence.

Foundations of Cyberspace and Internet Governance

Cyberspace represents an intangible, decentralized digital ecosystem created by interconnected computer networks, routers, servers, and communication protocols. Unlike physical territories governed by defined geographic borders, cyberspace operates without traditional physical boundaries, creating unique regulatory complexities.

Theories of Digital Regulation

Legal scholar Lawrence Lessig famously identified four primary modalities of cyberspace regulation: Law (statutory mandates and judicial sanctions), Architecture or Code (technical protocols, cryptography, and network design), Social Norms (community conventions and netiquette), and the Market (economic pricing mechanisms and commercial incentives). Understanding how code interacts with statutory law forms a primary pillar of modern cyber jurisprudence.

Students exploring foundational digital jurisprudence through the Cyber and IP Law curriculum must examine how statutory enactments reconcile traditional common law principles with electronic systems.

Statutory Framework: Information Technology Act, 2000

In India, the Information Technology Act, 2000 (IT Act) serves as the primary legislation governing electronic commerce, digital records, computer security, and cyber offences. Modeled after the UNCITRAL Model Law on Electronic Commerce (1996), the IT Act 2000 key provisions and cyberspace rules provide legal parity between physical documents and electronic records.

Key Statutory Enactments and Electronic Authentication

  • Legal Recognition of Electronic Records (Section 4): Stipulates that where any law requires information to be in writing or printed form, electronic records satisfy that requirement if accessible for subsequent reference.
  • Digital Signatures and Electronic Signatures (Sections 3 and 3A): Establishes asymmetric cryptosystem standards, hash functions, and authentication procedures for electronic documents.
  • Certifying Authorities (Sections 17 to 34): Regulates the appointment, licensing, and supervision of Certifying Authorities responsible for issuing Digital Signature Certificates.
  • Retention of Electronic Records (Section 7): Permits statutory retention of documents in electronic form under prescribed data integrity conditions.
  • Attribution and Dispatch of Electronic Records (Sections 11 to 13): Formulates clear rules on time and place of dispatch and receipt of electronic messages.

Jurisdictional Challenges in Cyberspace

One of the most complex dimensions of cyber law involves jurisdiction in cyberspace under cyber law. Traditional legal jurisdiction relies on territorial presence, nationality, or the physical location where the cause of action arose. In digital networks, an offender in one country can launch attacks against servers in a second country, harming victims in a third country.

Extraterritorial Jurisdiction Under Section 75

Section 75 of the IT Act explicitly grants extraterritorial applicability, providing that the Act applies to any offence or contravention committed outside India by any person, irrespective of nationality, if the act involves a computer, computer system, or computer network located in India. Courts apply principles such as the 'effects doctrine' and the 'minimum contacts test' to determine adjudicatory jurisdiction in cross-border internet disputes.

A structured breakdown of these jurisdictional tests is detailed in the PGD Cyber Law Exam Guide, providing exam preparation strategies for legal scholars.

Cyber Crime Classification and Digital Evidence

The IT Act, read with the Indian Penal Code and the Bharatiya Nyaya Sanhita, provides a systematic framework for cyber crime classification and digital evidence handling. Cyber offences broadly divide into computer-related crimes and content-related offences:

  • Unauthorized Access and Data Theft (Sections 43 and 66): Penalizes hacking, malware introduction, database destruction, unauthorized copying, and denial-of-service attacks with imprisonment and compensation.
  • Identity Theft and Impersonation (Sections 66C and 66D): Imposes criminal penalties for fraudulent use of digital signatures, passwords, or unique identification features.
  • Violation of Privacy (Section 66E): Criminalizes the intentional capture, publication, or transmission of images of private areas of individuals without consent.
  • Cyber Terrorism (Section 66F): Prescribes life imprisonment for acts threatening the unity, integrity, security, or sovereignty of the nation through unauthorized computer access.
  • Transmission of Obscene or Sexually Explicit Material (Sections 67, 67A, and 67B): Criminalizes publishing or transmitting illicit digital material.
  • Admissibility of Electronic Evidence: Electronic records are admissible under Section 65B of the Indian Evidence Act (and Section 63 of the Bharatiya Sakshya Adhiniyam) upon satisfying mandatory certification requirements regarding device integrity and unbroken chain of custody, as clarified by the Supreme Court in Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal.

Digital Forensics and Evidentiary Chain of Custody

Proving cyber crime allegations requires strict forensic protocols during evidence acquisition, analysis, and court presentation:

  • Bit-Stream Imaging and Write-Blocking: Creating forensically clean raw images of storage media using hardware write-blockers to prevent data contamination.
  • Cryptographic Hash Verification: Calculating SHA-256 and MD5 cryptographic hashes before and after analysis to prove that the forensic copy is identical to the seized original.
  • Volatile Memory Extraction: Capturing live RAM data to preserve transient network connections, encryption keys, and active process tables before computer shutdown.
  • Chain of Custody Documentation: Maintaining unbroken physical and digital custody ledgers detailing every investigator who accessed the electronic evidence.

Intermediary Liability and Safe Harbor Framework

Internet intermediaries, including social media networks, search engines, web hosts, and telecom service providers, process vast volumes of user-generated data. Under intermediary liability Section 79 IT Act, intermediaries receive statutory immunity (safe harbor protection) from third-party unlawful content, provided they act as passive conduits and observe mandatory due diligence guidelines. Following the landmark ruling in Shreya Singhal v Union of India, an intermediary is only required to take down content upon receiving actual knowledge through a court order or an authorized government directive.

Privacy and Data Protection in Cyberspace

The right to privacy in the digital age was firmly established by the nine-judge constitutional bench in Justice K.S. Puttaswamy v Union of India. Digital data governance requires strict adherence to data minimization, purpose limitation, storage limitation, and individual consent principles, establishing the foundation for contemporary data privacy jurisprudence.

Found this helpful?

Share this page with others