The Information Technology Act, 2000: An Overview for Bankers
India's core cyber law, chapter by chapter, with the sections a bank actually uses.
The Information Technology Act, 2000 (Act 21 of 2000) is India's core cyber law. It came into force on 17 October 2000 and does two jobs: it gives electronic records and electronic signatures legal standing, and it defines the cyber contraventions and offences that banks deal with every week, from unauthorised access to identity theft.
For a banker, the Act matters at both ends of a fraud. It is the law under which a customer whose account was emptied through a fake KYC call files a complaint, and it is also the law that can hold a bank liable if its own systems or staff were careless with customer data.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
How the Act Is Organised
The chapters most likely to appear in the exam, with the sections that matter in a bank.
Electronic signatures and records
Key sections
3, 3A, 4, 5, 10A
What it does
Authenticates electronic records, recognises electronic signatures, and makes contracts formed electronically valid
Certifying Authorities
Key sections
17 to 42
What it does
Sets up the Controller of Certifying Authorities, who licenses the bodies that issue signature certificates
Penalties, compensation, adjudication
Key sections
43, 43A, 44 to 47
What it does
Civil liability: compensation for unauthorised access and data failures, decided by an adjudicating officer
Appeals
Key sections
48, 57, 62
What it does
Appeal to the Appellate Tribunal (the TDSAT since 2017), then to the High Court
Offences
Key sections
65 to 78
What it does
Criminal offences, including sections 66 to 66F, plus the powers to intercept, block and protect critical systems
Intermediaries and evidence
Key sections
79, 79A
What it does
Safe harbour for intermediaries that follow due diligence; Examiners of Electronic Evidence
Miscellaneous
Key sections
80, 81, 85
What it does
Police powers, the Act's overriding effect, and liability of companies and their officers
| Part of the Act | Key sections | What it does |
|---|---|---|
| Electronic signatures and records | 3, 3A, 4, 5, 10A | Authenticates electronic records, recognises electronic signatures, and makes contracts formed electronically valid |
| Certifying Authorities | 17 to 42 | Sets up the Controller of Certifying Authorities, who licenses the bodies that issue signature certificates |
| Penalties, compensation, adjudication | 43, 43A, 44 to 47 | Civil liability: compensation for unauthorised access and data failures, decided by an adjudicating officer |
| Appeals | 48, 57, 62 | Appeal to the Appellate Tribunal (the TDSAT since 2017), then to the High Court |
| Offences | 65 to 78 | Criminal offences, including sections 66 to 66F, plus the powers to intercept, block and protect critical systems |
| Intermediaries and evidence | 79, 79A | Safe harbour for intermediaries that follow due diligence; Examiners of Electronic Evidence |
| Miscellaneous | 80, 81, 85 | Police powers, the Act's overriding effect, and liability of companies and their officers |
Terms the Act Defines
- Electronic signature
- Authentication of an electronic record by a technique listed in the Second Schedule. It includes a digital signature, which is one specific technique.
- Intermediary
- Anyone who receives, stores or transmits a record for someone else. The Act names telecom and internet service providers, search engines, online payment sites, online marketplaces and cyber cafes.
- Cyber security
- Protecting information, devices and computer resources from unauthorised access, use, disclosure, disruption, modification or destruction.
- Critical Information Infrastructure
- A computer resource whose incapacitation would have a debilitating impact on national security, the economy, public health or safety (section 70).
Provisions Every Banker Should Know
- check_circleSection 1(2) and section 75: the Act reaches offences committed outside India, by anyone, if the act involves a computer or network located in India. A fraudster abroad who attacks an Indian bank's server is covered.
- check_circleSection 43: civil compensation for unauthorised access, data theft, viruses and denial of service. Section 66 makes the same acts a crime when done dishonestly or fraudulently.
- check_circleSection 43A: a body corporate that is negligent with sensitive personal data must compensate the person affected. It stays in force until the Digital Personal Data Protection Act, 2023 removes it 18 months after 13 November 2025, which falls in May 2027.
- check_circleSection 70B: CERT-In is the national agency for cyber incident response and can direct body corporates, banks included, to report incidents and share information.
- check_circleSection 78: offences under the Act are investigated by a police officer not below the rank of Inspector.
- check_circleSection 85: when a company contravenes the Act, every person in charge of its business is also liable, unless they prove they did not know or exercised due diligence.
Quick practice on banking operations. No signup.
Two Changes the Courseware May Not Show
First, the Jan Vishwas (Amendment of Provisions) Act, 2023 changed several IT Act penalties from 30 November 2023. Sections 72 and 72A are now monetary penalties (up to ₹5 lakh and ₹25 lakh) instead of imprisonment, and the section 44 and 45 amounts went up. Second, a September 2022 notification narrowed the First Schedule, the list of documents the Act does not cover. Demand promissory notes and bills of exchange in favour of entities regulated by RBI, NHB, SEBI, IRDAI or PFRDA, and powers of attorney given to such entities, can now be executed electronically, and contracts for the sale of immovable property were dropped from the list. Wills and trusts remain outside the Act.
How the IIBF Exam Tests This
Questions on the Act are usually short and factual. The traps are predictable.
- check_circleYear confusion: the Act is of 2000, the big amendment is of 2008, and the amending law came into force in October 2009. Options will mix these up.
- check_circleCivil versus criminal: section 43 gives compensation; section 66 gives imprisonment. A question about 'liability to pay damages' points to 43.
- check_circleStruck-down law: section 66A was struck down by the Supreme Court in March 2015 (Shreya Singhal). Any option that treats it as a live offence is wrong.
- check_circleWho appeals where: adjudicating officer, then the Appellate Tribunal, then the High Court. The Cyber Appellate Tribunal no longer exists as a separate body.
FAQs
When did the IT Act 2000 come into force?expand_more
On 17 October 2000. It is Act 21 of 2000. The major amendments made in 2008 came into force on 27 October 2009.
Does the IT Act apply to cyber crimes committed from outside India?expand_more
Yes. Under section 75 it applies to an offence or contravention committed outside India by any person, of any nationality, if it involves a computer, computer system or network located in India.
Which documents are not covered by the IT Act?expand_more
Those in the First Schedule. After the 2022 amendment it still excludes wills, trusts, most negotiable instruments other than cheques, and most powers of attorney, but carves out demand promissory notes, bills of exchange and powers of attorney in favour of entities regulated by RBI, NHB, SEBI, IRDAI or PFRDA. Contracts for the sale of immovable property are no longer on the list.
Who hears appeals under the IT Act now?expand_more
Since 26 May 2017 the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) acts as the Appellate Tribunal under the IT Act. An appeal from its order goes to the High Court within 60 days.
Next steps
- Section 66 Offencesarrow_forward
- Section 43 & 43Aarrow_forward
- IT Amendment 2008arrow_forward
- Syllabusarrow_forward
120 questions, 2 hours, scored instantly.
