Information Technology · Ch 4 — Cyber Law
The Information Technology Act, 2000 — Objectives and Key Provisions
The Information Technology Act, 2000 — Objectives and Key Provisions
The central law of Indian cyberspace
The Information Technology Act, 2000 is India's primary law on cyber matters. It received the President's assent on 9 June 2000 and is modelled on the UNCITRAL Model Law on Electronic Commerce (1996) — a template recommended by the United Nations so that countries would frame broadly consistent e-commerce laws. It was substantially amended by the Information Technology (Amendment) Act, 2008, which widened the definition of offences and introduced the technology-neutral idea of an electronic signature.
Main objectives of the IT Act, 2000
- To give legal recognition to electronic records, so that a transaction carried out by electronic means is not denied validity merely because it is not on paper.
- To give legal recognition to digital (and, after 2008, electronic) signatures as a valid means of authenticating electronic records.
- To facilitate electronic filing of documents with government departments and agencies (e-governance).
- To promote e-commerce by providing a secure legal environment for online transactions.
- To define cyber offences and prescribe penalties, and to provide for investigation and adjudication of such offences.
- To amend related laws — the Indian Penal Code, the Indian Evidence Act, the Bankers' Books Evidence Act, and the Reserve Bank of India Act — so that they recognise electronic records and evidence.
Digital signatures and electronic signatures
Under Section 3 of the Act, an electronic record can be authenticated by affixing a digital signature. A digital signature is created using asymmetric cryptography (a pair of keys — a private key kept secret by the signer and a public key known to others) together with a hash function that produces a short 'fingerprint' of the record. This technique achieves two things at once:
- Authentication — it proves who signed, because only the signer holds the private key.
- Integrity — it proves the record was not altered after signing, because any change would produce a different hash.
A digital signature is therefore very different from a digitised signature (a scanned image of a handwritten signature), which offers none of these guarantees.
To make the system trustworthy, the Act creates an official structure:
| Role | Function |
|---|---|
| Controller of Certifying Authorities (CCA) | A government authority that licenses and supervises Certifying Authorities. |
| Certifying Authority (CA) | A licensed organisation that issues Digital Signature Certificates to users. |
An authentication of an electronic record using asymmetric cryptography and a hash function (Section 3, IT Act 2000). It confirms the identity of the signer and that th …
A licensed body authorised to issue Digital Signature Certificates, supervised by the Controller of Certifyin …
The United Nations Commission on International Trade Law's Model Law on Electronic Commerce (1996), on which the …