Offences and Penalties Under Information Technology Act, 2000

The rapid growth of computers, the internet, digital communication, online banking, e-commerce, and social media has transformed the way individuals, businesses, and governments function. Along with these advancements, various forms of cyber misconduct have also emerged, ranging from identity theft and online fraud to cyber terrorism and violations of privacy.
To address such challenges, India enacted the Information Technology Act, 2000, which provides a legal framework for electronic transactions and prescribes punishments for cyber offences. The Act, particularly after its amendment in 2008, contains detailed provisions dealing with various offences committed through computer systems and digital networks.

Meaning of Cyber Offences Under the Information Technology Act, 2000
The Information Technology Act, 2000 does not specifically define the term “cyber offence” or “cyber crime.” However, the Act identifies numerous unlawful activities involving computers, computer systems, computer networks, communication devices, electronic records, and digital information.
A cyber offence may be understood as any illegal act committed through the use of a computer, digital device, or network, where the computer may act as a tool, a target, or both. Such offences can affect individuals, organisations, critical infrastructure, and even national security.
Cyber offences are generally classified into three broad categories:
- Offences against individuals, such as identity theft, cheating by personation, and privacy violations.
- Offences against property, including hacking, data theft, and tampering with computer systems.
- Offences against the State, such as cyber terrorism and attacks on critical information infrastructure.
Chapter XI of the Information Technology Act, 2000 contains most of the provisions relating to cyber offences and penalties.
Importance of Penal Provisions Under the IT Act
The penal provisions of the Information Technology Act serve several important purposes:
- They deter individuals from engaging in cyber misconduct.
- They protect sensitive personal and commercial information.
- They promote trust in electronic transactions and digital governance.
- They strengthen cybersecurity and national security.
- They provide legal remedies against misuse of technology.
As digital dependence continues to increase, these provisions play a significant role in maintaining order and security in cyberspace.
Offences and Penalties Under the Information Technology Act, 2000
Section 65: Tampering With Computer Source Documents
Section 65 deals with the intentional concealment, destruction, or alteration of computer source code that is required to be maintained by law.
Computer source code includes programs, commands, design documents, and other instructions necessary for the functioning of a computer system. Tampering with such source code can affect the reliability and integrity of digital systems.
A person who knowingly alters, destroys, conceals, or causes another person to alter or destroy such source code commits an offence under this section.
Punishment: Imprisonment up to three years, or fine up to ₹2 lakh, or both.
Section 66: Computer-Related Offences
Section 66 covers computer-related offences arising from acts mentioned under Section 43 of the Act when such acts are committed dishonestly or fraudulently.
These acts include:
- Unauthorised access to computer systems.
- Downloading data without permission.
- Introducing viruses or malware.
- Causing disruption to computer networks.
- Damaging or destroying digital information.
The provision addresses various forms of hacking and unauthorised interference with computer resources.
Punishment: Imprisonment up to three years, or fine up to ₹5 lakh, or both.
Section 66B: Dishonestly Receiving Stolen Computer Resources
This provision applies to individuals who knowingly receive or retain stolen computer resources or communication devices.
The offence is similar to receiving stolen property under traditional criminal law. The essential requirement is knowledge or reasonable belief that the computer resource or device has been stolen.
Punishment: Imprisonment up to three years, or fine up to ₹1 lakh, or both.
Section 66C: Identity Theft
Identity theft has become one of the most common cyber crimes in the digital era.
Section 66C punishes any person who fraudulently or dishonestly uses another person’s:
- Electronic signature,
- Password,
- Unique identification feature, or
- Digital credentials.
Examples include misuse of login credentials, unauthorised use of digital signatures, and impersonation through stolen online identities.
Punishment: Imprisonment up to three years and fine up to ₹1 lakh.
Section 66D: Cheating by Personation Using Computer Resources
Section 66D addresses online fraud committed through impersonation.
The offence occurs when a person pretends to be someone else through a computer resource or communication device with the intention of cheating another person.
Common examples include:
- Fake online profiles.
- Fraudulent emails.
- Online investment scams.
- Banking and payment frauds.
- Impersonation of government officials.
This provision is frequently invoked in cases involving phishing and online financial fraud.
Punishment: Imprisonment up to three years and fine up to ₹1 lakh.
Section 66E: Violation of Privacy
Privacy is an essential aspect of individual dignity and personal liberty.
Section 66E criminalises the intentional capture, publication, or transmission of images of a person’s private area without consent under circumstances violating privacy.
The provision seeks to protect individuals from unauthorised recording and sharing of intimate images through electronic means.
The term “publication” includes both printed and electronic forms of dissemination.
Punishment: Imprisonment up to three years, or fine up to ₹2 lakh, or both.
Section 66F: Cyber Terrorism
Section 66F is among the most serious provisions under the Information Technology Act.
A person commits cyber terrorism when computer resources are used to threaten:
- The unity of India,
- The integrity of India,
- The security of India,
- The sovereignty of India, or
- Public safety.
Cyber terrorism may involve:
- Denial of access to authorised users.
- Unauthorised access to protected systems.
- Introduction of computer contaminants.
- Attacks on critical information infrastructure.
- Accessing sensitive information affecting national security.
The provision also covers unauthorised access to restricted information that may be used against India’s security interests or foreign relations.
Punishment: Imprisonment for life.
Offences Relating to Obscene and Sexually Explicit Content
Section 67: Publishing or Transmitting Obscene Material
Section 67 penalises publication or transmission of obscene material in electronic form.
The provision applies to material that is:
- Lascivious,
- Appeals to prurient interests, or
- Tends to deprave and corrupt persons exposed to it.
The objective is to regulate harmful and obscene content circulated through digital platforms.
Punishment:
- First conviction: Imprisonment up to three years and fine up to ₹5 lakh.
- Subsequent conviction: Imprisonment up to five years and fine up to ₹10 lakh.
Section 67A: Publishing Sexually Explicit Material
Section 67A specifically deals with sexually explicit content.
It covers publication, transmission, or causing the publication or transmission of material containing sexually explicit acts or conduct through electronic means.
Since sexually explicit material is considered more serious than ordinary obscenity, the punishment prescribed is higher.
Punishment:
- First conviction: Imprisonment up to five years and fine up to ₹10 lakh.
- Subsequent conviction: Imprisonment up to seven years and fine up to ₹10 lakh.
Section 67B: Child Sexual Abuse Material
Section 67B provides special protection to children against online exploitation.
The section covers:
- Publishing material depicting children in sexually explicit acts.
- Creating or distributing such material.
- Downloading or browsing child sexual abuse material.
- Inducing children into online sexual relationships.
- Facilitating online abuse of children.
- Recording sexual abuse involving children.
The provision reflects the legislature’s commitment to protecting children in digital spaces.
Punishment:
- First conviction: Imprisonment up to five years and fine up to ₹10 lakh.
- Subsequent conviction: Imprisonment up to seven years and fine up to ₹10 lakh.
Section 67C: Failure to Preserve Information
Intermediaries such as internet service providers, social media platforms, and online service providers are required to preserve and retain information as prescribed by law.
Failure to comply with these obligations attracts liability under Section 67C.
Punishment: Imprisonment up to three years and fine.
Offences Relating to Government Directions and Protected Systems
Sections 68, 69 and 69A
These provisions deal with compliance with lawful directions issued by competent authorities.
Section 68 empowers the Controller to issue directions.
Section 69 relates to interception, monitoring, and decryption of information for specified purposes such as national security and public order.
Section 69A authorises the Government to block public access to certain information under prescribed circumstances.
Failure to comply with these lawful directions constitutes an offence.
Punishment:
- Section 68: Imprisonment up to two years, or fine up to ₹1 lakh, or both.
- Section 69: Imprisonment up to seven years and fine.
- Section 69A: Imprisonment up to seven years and fine.
Section 69B
Section 69B authorises monitoring and collection of traffic data for cybersecurity purposes.
Failure to assist authorities in carrying out such monitoring activities attracts punishment under this provision.
Punishment: Imprisonment up to three years and fine.
Sections 70, 70A and 70B
These sections protect critical information infrastructure and cybersecurity systems.
Section 70 deals with unauthorised access to protected systems.
Section 70A concerns the protection of critical information infrastructure.
Section 70B establishes the Indian Computer Emergency Response Team (CERT-In), which serves as the national agency for responding to cybersecurity incidents.
Violation of directions relating to these provisions may result in criminal liability.
Punishment:
- Section 70: Imprisonment up to ten years and fine.
- Section 70B: Imprisonment up to one year, or fine up to ₹1 lakh, or both.
Offences Relating to Misrepresentation and Privacy
Section 71: Misrepresentation
Section 71 penalises false statements and suppression of material facts before the Controller or Certifying Authority.
The provision seeks to maintain the integrity of the electronic certification system.
Punishment: Imprisonment up to two years, or fine up to ₹1 lakh, or both.
Section 72: Breach of Confidentiality and Privacy
Section 72 protects information obtained through powers conferred under the Act.
A person who gains access to electronic records, documents, or information and discloses them without authority commits an offence.
The provision is intended to safeguard confidential information and privacy.
Punishment: Imprisonment up to two years, or fine up to ₹1 lakh, or both.
Section 72A: Disclosure of Information in Breach of Lawful Contract
This section applies when a person obtains access to personal information while providing services under a lawful contract and subsequently discloses that information without consent.
The offence requires an intention to cause wrongful gain or wrongful loss.
The provision is particularly relevant in the context of service providers, intermediaries, and commercial organisations handling personal data.
Punishment: Imprisonment up to three years, or fine up to ₹5 lakh, or both.
Offences Relating to Electronic Signature Certificates
Section 73: False Publication of Electronic Signature Certificates
Section 73 prohibits publication of an Electronic Signature Certificate when the publisher knows that:
- The certificate was not issued by the Certifying Authority.
- The subscriber has not accepted it.
- The certificate has been revoked or suspended.
The provision protects the reliability of electronic authentication systems.
Punishment: Imprisonment up to two years, or fine up to ₹1 lakh, or both.
Section 74: Publication for Fraudulent Purposes
Section 74 applies when an Electronic Signature Certificate is created, published, or made available for fraudulent or unlawful purposes.
The provision addresses misuse of digital authentication mechanisms.
Punishment: Imprisonment up to two years, or fine up to ₹1 lakh, or both.
Section 66A and the Shreya Singhal Judgment
Section 66A originally criminalised sending offensive, annoying, or inconvenient messages through communication services.
The provision faced significant criticism because of its broad and vague language, which created concerns regarding freedom of speech and expression.
In the landmark case of Shreya Singhal v. Union of India (2015), the Supreme Court declared Section 66A unconstitutional. The Court held that the provision violated Article 19(1)(a) of the Constitution and imposed unreasonable restrictions on free speech.
As a result, Section 66A no longer forms part of the enforceable provisions of the Information Technology Act.
Extraterritorial Application of the IT Act
Section 75 gives the Information Technology Act extraterritorial operation.
The Act applies not only to offences committed within India but also to offences committed outside India, provided that the act involves a computer, computer system, computer network, or computer resource located in India.
This provision is particularly important because cyber crimes frequently transcend national boundaries and involve international actors.
Conclusion
The Information Technology Act, 2000 serves as the primary legislation governing cyber offences in India. Through its detailed provisions, the Act addresses a wide range of cyber crimes, including hacking, identity theft, online fraud, privacy violations, cyber terrorism, publication of obscene content, and misuse of electronic signatures.
The 2008 amendments significantly strengthened the legal framework by introducing specialised provisions for emerging cyber threats. As digital technologies continue to evolve, these penal provisions remain essential for ensuring cybersecurity, protecting individual rights, preserving public order, and promoting confidence in electronic transactions and digital governance.
Attention all law students and lawyers!
Are you tired of missing out on internship, job opportunities and law notes?
Well, fear no more! With 2+ lakhs students already on board, you don't want to be left behind. Be a part of the biggest legal community around!
Join our WhatsApp Groups (Click Here) and Telegram Channel (Click Here) and get instant notifications.








