Skip to content

Information Technology · Ch 4 — Cyber Law

The Information Technology Act, 2000 — Objectives and Key Provisions

2

The Information Technology Act, 2000 — Objectives and Key Provisions

The central law of Indian cyberspace

The Information Technology Act, 2000 is India's primary law on cyber matters. It received the President's assent on 9 June 2000 and is modelled on the UNCITRAL Model Law on Electronic Commerce (1996) — a template recommended by the United Nations so that countries would frame broadly consistent e-commerce laws. It was substantially amended by the Information Technology (Amendment) Act, 2008, which widened the definition of offences and introduced the technology-neutral idea of an electronic signature.

Main objectives of the IT Act, 2000
  • To give legal recognition to electronic records, so that a transaction carried out by electronic means is not denied validity merely because it is not on paper.
  • To give legal recognition to digital (and, after 2008, electronic) signatures as a valid means of authenticating electronic records.
  • To facilitate electronic filing of documents with government departments and agencies (e-governance).
  • To promote e-commerce by providing a secure legal environment for online transactions.
  • To define cyber offences and prescribe penalties, and to provide for investigation and adjudication of such offences.
  • To amend related laws — the Indian Penal Code, the Indian Evidence Act, the Bankers' Books Evidence Act, and the Reserve Bank of India Act — so that they recognise electronic records and evidence.
Digital signatures and electronic signatures

Under Section 3 of the Act, an electronic record can be authenticated by affixing a digital signature. A digital signature is created using asymmetric cryptography (a pair of keys — a private key kept secret by the signer and a public key known to others) together with a hash function that produces a short 'fingerprint' of the record. This technique achieves two things at once:

  • Authentication — it proves who signed, because only the signer holds the private key.
  • Integrity — it proves the record was not altered after signing, because any change would produce a different hash.

A digital signature is therefore very different from a digitised signature (a scanned image of a handwritten signature), which offers none of these guarantees.

To make the system trustworthy, the Act creates an official structure:

RoleFunction
Controller of Certifying Authorities (CCA)A government authority that licenses and supervises Certifying Authorities.
Certifying Authority (CA)A licensed organisation that issues Digital Signature Certificates to users.
Definition 1Digital signature

An authentication of an electronic record using asymmetric cryptography and a hash function (Section 3, IT Act 2000). It confirms the identity of the signer and that th …

Definition 2Certifying Authority (CA)

A licensed body authorised to issue Digital Signature Certificates, supervised by the Controller of Certifyin …

Definition 3UNCITRAL Model Law

The United Nations Commission on International Trade Law's Model Law on Electronic Commerce (1996), on which the …