Overview of the Information Technology Act 2000 for CS Executive
The Information Technology Act 2000 CS Executive curriculum serves as the primary statutory framework in India governing electronic commerce, cyber security, and commercial data management. Enacted to give legal recognition to electronic transactions and facilitate paperless communication, the statute establishes rules for the attribution, acknowledgment, and dispatch of electronic records, regulates certifying authorities, and penalizes unauthorized computer access. CS Executive students preparing for Paper 1 must understand how the Act balances digital contract validity under Section 10A with strict data protection liabilities under Section 43A and intermediary safe harbours under Section 79.
Legal Recognition of Electronic Records and Digital Signatures
The IT Act 2000 provides formal legal equivalence between physical paper documents and digital instruments, creating a formal digital signature electronic record IT Act legal structure. Under Section 4, where any law requires information to be in writing or typewritten form, such requirement is satisfied if the information is rendered in an electronic record accessible for subsequent reference. Similarly, Section 5 accords legal recognition to digital signatures, confirming that where any law requires a signature, that condition is satisfied if authenticated by an electronic signature affixed in the prescribed manner.
Section 10A validates contracts formed through electronic means. It provides that where in a contract formation, the communication of proposals, acceptance of proposals, or revocation of proposals are expressed in electronic form, such contract shall not be deemed unenforceable solely on the ground that electronic means were used. This statutory rule provides legal certainty to online agreements and commercial e-contracts across India.
Attribution, Dispatch, and Receipt of Electronic Records
Sections 11 to 13 of the IT Act establish clear statutory presumptions regarding the timing and origin of electronic communications:
- Attribution (Section 11): An electronic record is attributed to the originator if it was sent by the originator personally, by a person authorized to act on behalf of the originator, or by an information system programmed by or on behalf of the originator to operate automatically.
- Acknowledgment of Receipt (Section 12): Where the originator has not agreed on a particular method of acknowledgment, receipt may be established by any communication from the addressee or by conduct showing that the addressee received the record.
- Time and Place of Dispatch and Receipt (Section 13): Dispatch occurs when an electronic record enters a computer resource outside the control of the originator. Receipt occurs when the record enters the designated computer resource of the addressee, or when retrieved by the addressee from a non-designated resource.
Certifying Authorities and Digital Signature Certificates
The IT Act creates a hierarchical regulatory framework to guarantee authentication and public key infrastructure. The Central Government appoints the Controller of Certifying Authorities (CCA) under Section 17 to license, supervise, and regulate Certifying Authorities (CAs). Certifying Authorities issue Digital Signature Certificates (DSC) to subscribers under Section 35 after verifying identity and cryptographic key pairs.
A Digital Signature Certificate contains the subscriber's public key, name, validity period, and digital signature of the issuing authority. Under Section 38, a CA may revoke a certificate upon the subscriber's request, upon death or dissolution, or if the private key has been compromised. In-depth revision notes on related commercial legal subjects are available in our CS Executive Notes reference collection, alongside detailed modules such as SEM VI Intellectual Property Rights-II - Unit IV Class Notes covering digital copyright and intangible assets.
Section 43A: Sensitive Personal Data and Corporate Liability
The mandate under Section 43A sensitive personal data rules is a cornerstone provision for corporate compliance. It stipulates that where a body corporate possesses, deals with, or handles any sensitive personal data or information in a computer resource which it owns, controls, or operates, and is negligent in implementing and maintaining reasonable security practices and procedures, causing wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay compensation by way of damages to the affected party.
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 define sensitive personal data (passwords, financial information, biometric data, health conditions) and require corporate entities to publish a clear privacy policy, obtain consent before collection, and maintain audit standards.
Intermediary Liability and Safe Harbour under Section 79
The statutory defense for intermediary liability Section 79 IT Act provides a conditional safe harbour to network service providers and internet intermediaries (such as web hosts, telecom providers, and online platforms). An intermediary is not liable for third-party information, data, or communication link hosted or transmitted by it, provided that:
- The intermediary's function is limited to providing access to a communication system over which information is transmitted or temporarily stored.
- The intermediary does not initiate the transmission, select the receiver of the transmission, or modify the information contained in the transmission.
- The intermediary observes due diligence while discharging its duties and abides by guidelines prescribed by the Central Government.
Under the landmark Supreme Court ruling in Shreya Singhal vs Union of India, an intermediary loses safe harbour protection only if, upon receiving actual knowledge through a court order or authorized government notification, it fails to expeditiously remove or disable access to unlawful material.
Cyber Regulations Appellate Tribunal and Statutory Offences
The Act established the Cyber Regulations Appellate Tribunal (now merged with the Telecom Disputes Settlement and Appellate Tribunal, TDSAT) to hear appeals from orders passed by Adjudicating Officers appointed under Section 46. Chapter XI sets forth major cyber offences and penalties:
- Section 65: Tampering with computer source documents (imprisonment up to three years or fine up to two lakh rupees).
- Section 66: Computer-related offences and hacking committed dishonestly or fraudulently (imprisonment up to three years or fine up to five lakh rupees).
- Section 66B: Receiving stolen computer resource or communication device.
- Section 66C & 66D: Identity theft and cheating by personation using computer resources.
- Section 66E: Violation of privacy by capturing or transmitting images of private body parts without consent.
- Section 66F: Cyber terrorism punishable with imprisonment for life.
- Section 67: Publishing or transmitting obscene material in electronic form.
- Section 72: Breach of confidentiality and privacy by authorized personnel.
Key Practical Takeaways for CS Examination Preparation
For CS Executive Paper 1 examination questions, students should practice drafting answers that integrate statutory definitions with practical corporate compliance examples. Ensure clear distinctions between digital signatures and electronic signatures, understand the jurisdictional scope of Section 75 over offences committed outside India, and explain the step-by-step procedural chain from certifying authorities to Cyber Regulations Appellate Tribunal and TDSAT reviews.
