The IT Act 2000 for Chartered Accountants
Where a control failure becomes legal exposure, and what changed since the DISA material was written.
The Information Technology Act, 2000 is where weak IT controls turn into legal exposure. Unauthorised access, data theft and negligent handling of sensitive personal data carry compensation, penalties or prosecution, and the officers in charge of a company can be proceeded against along with it. An IS auditor gives no legal opinion here, but needs to know which sections a control failure touches and what has changed since the DISA 3.0 material was written.
Three changes matter most. Amendments made by Act 18 of 2023, in force from 30 November 2023, turned some offences into penalties. The Bharatiya Sakshya Adhiniyam replaced the Evidence Act from 1 July 2024, so section 65B is now section 63. And the DPDP Act will omit section 43A, though not yet.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Sections That Matter to an Auditor
43
What it covers
Access, downloading or copying data, introducing viruses, damage, disruption or denial of access without the owner's permission
Consequence (current text)
Compensation to the person affected
43A
What it covers
A body corporate handling sensitive personal data or information that is negligent in maintaining reasonable security practices, causing wrongful loss or gain
Consequence (current text)
Compensation to the person affected; omitted by DPDP Act s.44(2) once that commences
66
What it covers
Any section 43 act done dishonestly or fraudulently
Consequence (current text)
Imprisonment up to three years, fine up to ₹5 lakh, or both
66C
What it covers
Fraudulent use of another person's password, electronic signature or other unique identification feature (identity theft)
Consequence (current text)
Imprisonment up to three years and fine up to ₹1 lakh
66D
What it covers
Cheating by personation using a computer resource or communication device
Consequence (current text)
Imprisonment up to three years and fine up to ₹1 lakh
72
What it covers
A person who obtained records under powers given by the Act discloses them without consent
Consequence (current text)
Penalty up to ₹5 lakh
72A
What it covers
A service provider, under a lawful contract, discloses personal information without consent or in breach of contract, intending or knowing it is likely to cause wrongful loss or gain
Consequence (current text)
Penalty up to ₹25 lakh (was a punishable offence before 30 November 2023)
85
What it covers
Contraventions by companies
Consequence (current text)
Every person in charge of and responsible for the business is liable, unless they prove lack of knowledge or due diligence; directors and officers whose consent, connivance or neglect is proved are also liable
| Section | What it covers | Consequence (current text) |
|---|---|---|
| 43 | Access, downloading or copying data, introducing viruses, damage, disruption or denial of access without the owner's permission | Compensation to the person affected |
| 43A | A body corporate handling sensitive personal data or information that is negligent in maintaining reasonable security practices, causing wrongful loss or gain | Compensation to the person affected; omitted by DPDP Act s.44(2) once that commences |
| 66 | Any section 43 act done dishonestly or fraudulently | Imprisonment up to three years, fine up to ₹5 lakh, or both |
| 66C | Fraudulent use of another person's password, electronic signature or other unique identification feature (identity theft) | Imprisonment up to three years and fine up to ₹1 lakh |
| 66D | Cheating by personation using a computer resource or communication device | Imprisonment up to three years and fine up to ₹1 lakh |
| 72 | A person who obtained records under powers given by the Act discloses them without consent | Penalty up to ₹5 lakh |
| 72A | A service provider, under a lawful contract, discloses personal information without consent or in breach of contract, intending or knowing it is likely to cause wrongful loss or gain | Penalty up to ₹25 lakh (was a punishable offence before 30 November 2023) |
| 85 | Contraventions by companies | Every person in charge of and responsible for the business is liable, unless they prove lack of knowledge or due diligence; directors and officers whose consent, connivance or neglect is proved are also liable |
Section 43A Is Still Live
Section 44(2) of the DPDP Act omits section 43A, but under G.S.R. 843(E) that provision commences eighteen months after 13 November 2025, which falls in May 2027. Until then, section 43A and the reasonable security practices it relies on still apply. Pages saying 43A is already repealed are ahead of the law.
CERT-In and Section 70B
- What CERT-In is
- The Indian Computer Emergency Response Team, the national agency for cyber incident response under section 70B. Section 70B(6) lets it call for information and give directions to service providers, intermediaries, data centres, body corporates and others.
- Non-compliance
- Failing to provide information or comply with a direction is punishable under section 70B(7) with imprisonment up to one year, fine up to ₹1 crore, or both.
- The 28 April 2022 Directions
- Listed cyber incidents must be reported to CERT-In within 6 hours of noticing them. Logs of all ICT systems must be kept securely for a rolling 180 days within Indian jurisdiction. System clocks must sync with NIC or NPL time servers or servers traceable to them.
Quick practice on audit concepts. No signup.
Electronic Evidence: Section 65B Is Now BSA Section 63
From 1 July 2024 the Bharatiya Sakshya Adhiniyam, 2023 replaced the Indian Evidence Act. Section 63 carries forward the old section 65B scheme with changes an auditor producing system reports should know.
- 1
Computer output is a document
A printout or copy of an electronic record is admissible without producing the original, if the section's conditions are met.
- 2
The conditions
Produced during regular use of the computer or device for the activity; information regularly fed in; the device operating properly (or any fault not affecting the record); and the output reproducing information fed in the ordinary course.
- 3
The certificate
Submitted with the electronic record each time it is submitted for admission, in the form in the Schedule to the Adhiniyam, signed by the person in charge of the device or activity and by an expert.
- 4
What this means in practice
When a bank's core banking statements or ERP ledgers may end up in court, logs, clock synchronisation and change control over the system support the certifier's statements. Weak ITGCs make the certificate harder to give honestly.
How the DISA Assessment Test Tests This
The DISA 3.0 material predates the 2023 amendments and the BSA, and ICAI publishes no question bank. Expect section-to-offence matching, where the traps are:
- check_circleSection 43 vs 66: the same acts; 66 applies when done dishonestly or fraudulently.
- check_circleSection 72 vs 72A: 72 covers people acting under powers given by the Act; 72A covers service providers under contract. Both are now penalties, not imprisonment.
- check_circleSection 65B: older material and options may still cite it. The current provision is BSA section 63.
- check_circleCERT-In timings: 6 hours to report, 180 days of logs. Not 72 hours, which is the DPDP Rules' window for the detailed breach report to the Data Protection Board.
FAQs
What is section 43A of the IT Act?expand_more
It makes a body corporate that handles sensitive personal data or information, and is negligent in maintaining reasonable security practices, liable to compensate anyone who suffers wrongful loss as a result. The DPDP Act will omit it, from eighteen months after 13 November 2025.
What replaced section 65B of the Evidence Act?expand_more
Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, in force from 1 July 2024. It requires a certificate, in the form in the Schedule, signed by the person in charge and an expert.
What is the CERT-In 6-hour rule?expand_more
CERT-In's Directions of 28 April 2022 under section 70B(6) require listed cyber incidents to be reported within 6 hours of noticing them, and logs to be kept for a rolling 180 days in India.
Is section 72A of the IT Act still a criminal offence?expand_more
No. Since 30 November 2023, an amendment by Act 18 of 2023 makes it a penalty of up to ₹25 lakh for disclosing personal information in breach of a lawful contract.
Next steps
- DPDP Actarrow_forward
- Audit Trail & Logsarrow_forward
- Incident Responsearrow_forward
- Syllabusarrow_forward
Assessment Test format, timed and scored.
