Under Indian cyber jurisprudence, Section 85 Information Technology Act offences by companies establishes the primary statutory mechanism for attributing criminal and civil liability to corporate entities and their management. The provision governs corporate cyber liability and director responsibility by creating a legal presumption that individuals who were in charge of and responsible for the conduct of the business at the time of a contravention are jointly liable alongside the corporate body. However, the statute incorporates a vital statutory due diligence defense Section 85 proviso, which protects executives who establish that the violation occurred without their knowledge or despite exercising reasonable organizational care, while separately penalizing the proven consent connivance or neglect of company officers.
Statutory Architecture of Section 85 of the Information Technology Act
The Information Technology Act, 2000 was enacted to create a predictable legal environment for electronic commerce, digital transactions, and cybersecurity enforcement. Because corporations act exclusively through human agents, Parliament enacted Section 85 to ensure that corporate personality cannot be used as a shield to evade responsibility for electronic fraud, unauthorized data access, network tampering, or non-compliance with statutory cybersecurity directions.
Section 85 is divided into two operational sub-sections and an explanatory clause that defines the scope of corporate structures and managerial roles subject to prosecution:
- Sub-section (1) - Primary Managerial Liability: Establishes that where a company commits a contravention of the Act, rules, directions, or orders, every person who was in charge of, and responsible to, the company for the conduct of its business, as well as the company itself, shall be deemed guilty.
- Proviso to Sub-section (1) - The Exculpatory Exception: Protects a managerial officer from penal sanctions if they prove that the contravention occurred without their knowledge or that they exercised all due diligence to prevent the breach.
- Sub-section (2) - Specific Officer Fault: Extends liability to any director, manager, secretary, or other officer where it is demonstrated that the contravention occurred with their consent, connivance, or attributable neglect.
- Explanation: Clarifies that "Company" includes any body corporate, partnership firm, or association of individuals, and "Director" in relation to a firm means a partner.
The Mechanics of Vicarious Liability in Corporate Cyber Offences
In criminal jurisprudence, vicarious liability is an exception to the fundamental rule of personal fault. For vicarious liability of directors IT Act provisions to apply, there must be specific, substantive allegations demonstrating that the named officer exercised operational control over the specific business division or digital infrastructure where the infraction occurred.
The Supreme Court of India has consistently held in landmark corporate liability rulings that simply holding a directorial designation is insufficient to sustain a criminal prosecution. The complaint must contain clear averments explaining how the director was in charge of and responsible for the day-to-day conduct of the company's electronic systems or regulatory compliances at the material time.
Establishing the Statutory Due Diligence Defense
The proviso to Section 85(1) provides an essential safeguard for non-executive directors, independent board members, and compliance officers who maintain proper oversight frameworks. To successfully invoke this defense, the accused person must establish one of two statutory conditions:
- Absence of Knowledge: Demonstrating that the unauthorized act or technical breach was concealed or carried out without the officer's awareness or authorization.
- Exercise of All Due Diligence: Providing documentary proof that the organization had implemented recognized cybersecurity standards, periodic technical audits, access control policies, and prompt incident response protocols.
In practice, Indian courts evaluate due diligence through contemporary information security standards, such as adherence to ISO/IEC 27001 guidelines, implementation of reasonable security practices under Section 43A of the IT Act, and routine reporting of cybersecurity incidents to the Indian Computer Emergency Response Team (CERT-In).
Proof of Consent, Connivance, or Attributable Neglect Under Section 85(2)
While sub-section (1) focuses on general operational management, sub-section (2) targets direct individual culpability. Under this provision, any officer of the company, regardless of whether they were formally in charge of daily business, can be prosecuted if the investigating agency proves:
- Consent: Explicit approval or instruction given by the officer to bypass security controls or execute an unlawful digital operation.
- Connivance: Tacit knowledge and deliberate acquiescence in ongoing non-compliance or data compromise without taking corrective measures.
- Attributable Neglect: Gross failure to enforce mandatory data protection measures, ignoring critical vulnerability alerts, or failing to maintain statutory digital logs.
Judicial Interpretation and Precedential Benchmarks
The principles governing Section 85 closely mirror the vicarious liability provisions found under Section 141 of the Negotiable Instruments Act and Section 149 of the Companies Act. The Supreme Court in decisions such as Aneeta Hada v. Godfather Travels and Tours Private Limited and SMS Pharmaceuticals Ltd. v. Neeta Bhalla established that a company must be arrayed as a principal accused before vicarious liability can be fastened upon its directors or officers.
Consequently, an information technology prosecution that attempts to charge directors without joining the corporate body itself is legally unsustainable and vulnerable to quashing under Section 482 of the Code of Criminal Procedure.
Essential Cybersecurity Compliance Checklist for Corporate Boards
To mitigate exposure under Section 85, enterprises operating digital platforms in India should maintain disciplined governance protocols:
- Formulate Written Information Security Policies: Document clear roles and technical responsibilities across IT administrators, chief information security officers, and executive directors.
- Maintain Audited Log Systems: Implement immutable access logs, data protection safeguards, and encryption controls to demonstrate active regulatory compliance.
- Establish Prompt Incident Response Mechanisms: Comply strictly with mandatory CERT-In reporting timelines to prevent allegations of neglect or concealment.
- Board-Level Security Reviews: Schedule regular cybersecurity oversight briefings to ensure executive awareness and demonstrate organizational due diligence.
