IT (Amendment) Act, 2008: What It Changed
A 2008 name, a 2009 start date, and most of the cyber law banks rely on today.
The Information Technology (Amendment) Act, 2008 is the largest change ever made to India's IT Act. It carries a 2008 name but was numbered Act 10 of 2009, and almost all of it came into force on 27 October 2009. That gap between the name and the date is a favourite exam trap.
The 2000 Act was written mainly to make e-commerce legally possible. By 2008 the problem had shifted to phishing, identity theft, data leaks and attacks on critical systems. The amendment answered that: it made the law technology neutral, added a set of named cyber offences, created the data protection duty for companies, and gave CERT-In and a critical infrastructure agency a statutory footing.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
What the 2008 Amendment Added or Changed
Signatures
Change
'Digital signature' replaced by the wider, technology-neutral 'electronic signature'
Sections
3A, 2, throughout
E-governance and contracts
Change
Delivery of services by service providers; audit of electronic records; validity of contracts formed electronically
Sections
6A, 7A, 10A
Civil liability
Change
Section 43 extended (computer resource, deleting or altering information, source code theft); compensation for negligent handling of sensitive personal data
Sections
43, 43A
Adjudication
Change
Adjudicating officer's jurisdiction set at claims up to ₹5 crore, above which the competent court decides
Sections
46(1A)
Offences
Change
Section 66 rewritten around section 43 acts done dishonestly or fraudulently; new offences 66A to 66F
Sections
66 to 66F
Obscenity and child abuse material
Change
New offences for sexually explicit material and child sexual abuse material; duty on intermediaries to preserve information
Sections
67A, 67B, 67C
Government powers
Change
Interception and decryption rewritten; new powers to block public access and to monitor traffic data
Sections
69, 69A, 69B
Critical infrastructure
Change
Critical Information Infrastructure defined; national nodal agency for its protection; CERT-In made the national incident response agency
Sections
70, 70A, 70B
Data disclosure
Change
New offence of disclosing personal information in breach of a lawful contract (a monetary penalty since 30 November 2023)
Sections
72A
Procedure
Change
Compounding of offences; three-year offences made bailable and three-year-plus offences cognizable; investigation by an Inspector instead of a Deputy Superintendent of Police
Sections
77A, 77B, 78
Intermediaries and evidence
Change
Safe harbour for intermediaries that observe due diligence; Examiner of Electronic Evidence
Sections
79, 79A
Encryption, abetment, attempt
Change
Power to prescribe encryption methods; punishment for abetment and attempt
Sections
84A, 84B, 84C
| Area | Change | Sections |
|---|---|---|
| Signatures | 'Digital signature' replaced by the wider, technology-neutral 'electronic signature' | 3A, 2, throughout |
| E-governance and contracts | Delivery of services by service providers; audit of electronic records; validity of contracts formed electronically | 6A, 7A, 10A |
| Civil liability | Section 43 extended (computer resource, deleting or altering information, source code theft); compensation for negligent handling of sensitive personal data | 43, 43A |
| Adjudication | Adjudicating officer's jurisdiction set at claims up to ₹5 crore, above which the competent court decides | 46(1A) |
| Offences | Section 66 rewritten around section 43 acts done dishonestly or fraudulently; new offences 66A to 66F | 66 to 66F |
| Obscenity and child abuse material | New offences for sexually explicit material and child sexual abuse material; duty on intermediaries to preserve information | 67A, 67B, 67C |
| Government powers | Interception and decryption rewritten; new powers to block public access and to monitor traffic data | 69, 69A, 69B |
| Critical infrastructure | Critical Information Infrastructure defined; national nodal agency for its protection; CERT-In made the national incident response agency | 70, 70A, 70B |
| Data disclosure | New offence of disclosing personal information in breach of a lawful contract (a monetary penalty since 30 November 2023) | 72A |
| Procedure | Compounding of offences; three-year offences made bailable and three-year-plus offences cognizable; investigation by an Inspector instead of a Deputy Superintendent of Police | 77A, 77B, 78 |
| Intermediaries and evidence | Safe harbour for intermediaries that observe due diligence; Examiner of Electronic Evidence | 79, 79A |
| Encryption, abetment, attempt | Power to prescribe encryption methods; punishment for abetment and attempt | 84A, 84B, 84C |
One 2008 Addition Is No Longer Law
Section 66A, which punished offensive messages sent by computer or phone, came in with the 2008 amendment. The Supreme Court struck it down on 24 March 2015 in Shreya Singhal v. Union of India. Count it as a 2008 addition if a question asks what the amendment inserted, but never as a live offence.
Amendments After 2008
Unit 11 says 'the amendments', plural. These are the ones that change exam answers.
- check_circleFinance Act, 2017 (from 26 May 2017): the Cyber Appellate Tribunal was merged into the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which now hears IT Act appeals.
- check_circleJan Vishwas (Amendment of Provisions) Act, 2023 (from 30 November 2023): sections 72 and 72A became monetary penalties (up to ₹5 lakh and ₹25 lakh) instead of imprisonment; the section 44 and 45 penalties were raised; the CERT-In non-compliance fine under section 70B(7) went up from ₹1 lakh to ₹1 crore.
- check_circleDigital Personal Data Protection Act, 2023: omits section 43A. That part takes effect 18 months after the 13 November 2025 notification, in May 2027.
Quick practice on banking operations. No signup.
Why the 2008 Amendment Matters to Banks
Almost every provision a bank's fraud or IT security team relies on dates from 2008: identity theft (66C) and personation (66D) for customer frauds, 43A for the bank's own duty to protect data, 70B for CERT-In's power to demand incident reports, and the protected-system regime under section 70 that now covers several banks' core systems.
How the IIBF Exam Tests This
- check_circle'Which section was inserted by the 2008 amendment?' Options will mix 2000 originals (43, 65, 67) with 2008 insertions (43A, 66C, 70B).
- check_circle'From which date?' The answer is 27 October 2009, not any date in 2008.
- check_circle'What did the amendment replace?' Digital signature with electronic signature, and the Deputy Superintendent of Police with an Inspector as investigating officer.
FAQs
When did the IT Amendment Act 2008 come into force?expand_more
On 27 October 2009. The amending law is named the Information Technology (Amendment) Act, 2008 but is numbered Act 10 of 2009.
Which sections were added by the IT Amendment Act 2008?expand_more
Among others: 3A, 6A, 7A, 10A, 43A, 66A to 66F, 67A to 67C, 69A, 69B, 70A, 70B, 72A, 77A, 77B, 79A and 84A to 84C. Sections 66, 69 and 79 were rewritten.
What is the difference between digital signature and electronic signature?expand_more
A digital signature is one specific technique (asymmetric cryptography with a hash function). The 2008 amendment introduced 'electronic signature' as the wider term, covering any reliable technique listed in the Second Schedule, and digital signature is one of them.
Has the IT Act been amended after 2008?expand_more
Yes. The Finance Act, 2017 moved appeals to the TDSAT, the Jan Vishwas Act, 2023 converted some offences into penalties and raised several amounts, and the DPDP Act, 2023 will omit section 43A from May 2027.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
