IT Act Section 43 and 43A: Compensation for Cyber Contraventions
The civil side of cyber law: who pays, who decides, and why 43A ends in May 2027.
Section 43 of the Information Technology Act, 2000 is the civil side of cyber law. If anyone, without the permission of the owner or person in charge, does one of the acts it lists to a computer, system or network, they must pay damages by way of compensation to the person affected. No criminal intent is needed; the question is only whether the act happened without permission.
Section 43A extends compensation to data protection: a company that is negligent with sensitive personal data and causes wrongful loss or gain must compensate the person affected. For a bank, 43 is the section a customer uses against a fraudster, and 43A is the one a customer could use against the bank.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Ten Acts Listed in Section 43
Each is done without permission of the owner or person in charge.
- check_circle(a) Accessing or securing access to a computer, system, network or computer resource
- check_circle(b) Downloading, copying or extracting data, including from removable storage
- check_circle(c) Introducing a computer contaminant or virus
- check_circle(d) Damaging a computer, system, network, data or programme
- check_circle(e) Disrupting a computer, system or network
- check_circle(f) Denying access to an authorised person
- check_circle(g) Helping someone else gain access in breach of the Act
- check_circle(h) Charging services used by one person to another person's account by tampering with a system
- check_circle(i) Destroying, deleting or altering information, or reducing its value or utility
- check_circle(j) Stealing, concealing, destroying or altering source code with intent to cause damage
Section 43 Versus Section 66
Nature
Section 43
Civil contravention
Section 66
Criminal offence
Intent needed
Section 43
None beyond acting without permission
Section 66
Dishonestly or fraudulently
Outcome
Section 43
Damages by way of compensation, no fixed upper limit in the section
Section 66
Imprisonment up to 3 years, fine up to ₹5 lakh, or both
Decided by
Section 43
Adjudicating officer (claims up to ₹5 crore) or competent court
Section 66
Criminal court, after police investigation
| Point | Section 43 | Section 66 |
|---|---|---|
| Nature | Civil contravention | Criminal offence |
| Intent needed | None beyond acting without permission | Dishonestly or fraudulently |
| Outcome | Damages by way of compensation, no fixed upper limit in the section | Imprisonment up to 3 years, fine up to ₹5 lakh, or both |
| Decided by | Adjudicating officer (claims up to ₹5 crore) or competent court | Criminal court, after police investigation |
How a Compensation Claim Moves
- 1
Claim before the adjudicating officer
Under section 46, adjudicating officers decide claims where the damage claimed does not exceed ₹5 crore. The Secretary of the Information Technology Department of each State or Union Territory has been appointed to this role since 2003.
- 2
Larger claims go to court
If the claim exceeds ₹5 crore, jurisdiction lies with the competent court. Below that limit, section 61 bars civil courts from hearing matters the adjudicating officer is empowered to decide.
- 3
Quantum of compensation
Section 47 asks the officer to weigh the unfair gain made, the loss caused, and whether the default is repetitive.
- 4
Appeal
An appeal lies to the Appellate Tribunal (the TDSAT since 2017) within 45 days of receiving the order, and from there to the High Court within 60 days. No appeal lies from an order passed with the consent of the parties.
Quick practice on banking operations. No signup.
Section 43A Has an End Date
The Digital Personal Data Protection Act, 2023 omits section 43A. That omission is in section 44(2) of the DPDP Act, which comes into force 18 months after the 13 November 2025 notification, so in May 2027. Until then 43A and the 2011 rules on reasonable security practices still apply. After that, a bank's failure to protect personal data is dealt with by the Data Protection Board through monetary penalties, not by compensation under 43A.
How the IIBF Exam Tests This
- check_circleThe ₹5 crore figure: it is the adjudicating officer's jurisdiction limit, not a cap on compensation. Section 43 itself sets no ceiling.
- check_circle43 or 66: an option that mentions imprisonment belongs to 66. An option about damages belongs to 43.
- check_circle43A's subject: a body corporate, sensitive personal data, and negligence in reasonable security practices. Individuals are not liable under 43A.
FAQs
What is section 43 of the IT Act?expand_more
It makes anyone who accesses, copies, damages, disrupts or infects a computer, system or network without the owner's permission liable to pay compensation to the person affected. It lists ten such acts, from (a) to (j).
What is the maximum compensation under section 43?expand_more
Section 43 sets no maximum. The ₹5 crore figure in section 46 decides who hears the claim: an adjudicating officer up to ₹5 crore, a competent court above it.
Is section 43A of the IT Act still in force?expand_more
Yes, as of October 2026. The DPDP Act, 2023 omits it, but that provision takes effect 18 months after the 13 November 2025 notification, in May 2027.
Where do I file a claim under section 43?expand_more
With the adjudicating officer for your State, the Secretary of its Information Technology Department, if the claim is up to ₹5 crore. Larger claims go to the competent court.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
