Skip to content
Batch 13

Information Technology Act, 2000 and Electronic Transactions - Complete Professional Corpus

Complete mapped publication architecture, operational masters, delegated-instrument register, searchable PDFs, cheat sheets, decision flows and deployment controls.

See also the Data Privacy, DPDP and Cyber Law Hub for practical guides and checklists.

119 statutory records40 publication unitsReview cut-off 2026-07-18
Mapped and interpreted - multi-instrument cyber framework

Source, commencement and implementation control

Primary authority
MeitY / CERT-In / Controller of Certifying Authorities
Commencement
The Act commenced on 17 October 2000, subject to later inserted provisions and separately effective subordinate instruments.
Currentness gate
IT Act, Intermediary Rules, CERT-In directions and current amendments/corrigenda must be read separately. Draft amendments are not operative law.
Text status
Provision architecture and professional interpretation are local. Exact statutory wording and event-date instruments remain controlled by the official source.

Official source: Open the current India Code record.

Provision-specific operating checklist

  1. Classify electronic record, computer resource, intermediary and regulated service.
  2. Preserve logs, hashes, chain of custody and access records.
  3. Separate civil compensation, criminal offence and regulatory direction.
  4. Test safe-harbour conditions and actual-knowledge workflow.
  5. Apply cert-in incident reporting and retention controls.
  6. Exclude section 66a as invalidated and historical only.

Topic under review: Information Technology Act, 2000 and Electronic Transactions - Complete Professional Corpus. Before advice, filing, enforcement or publication, preserve the operative Act, commencement notification, applicable Rules/regulations, amendments, portal instructions and current judicial treatment in the matter file.

Finin2min implementation record for this unit

Decision question. Identify the exact statutory or regulatory trigger covered by Information Technology Act, 2000 and Electronic Transactions - Complete Professional Corpus, the person on whom the duty falls, the event date and the evidence that proves compliance or breach.

Applicability test. Record the entity, transaction, product, data set, project, market or proceeding in scope; test statutory exclusions and exemptions; then freeze the version of the law applying on the event date.

Execution workflow. Allocate the matter to responsible legal, compliance, finance, operations and evidence owners; prepare a dated issue note; obtain approvals; complete filing, disclosure, notice, payment or remediation; and retain acknowledgement plus supporting evidence.

Consequence and remedy. Distinguish administrative correction, civil relief, compensation, monetary penalty, prosecution, appeal, settlement, mediation, arbitration and constitutional or judicial review. Limitation and pre-deposit requirements must be computed independently.

Cross-law review. Test the Contract Act, Companies Act, GST, income tax, accounting, evidence, limitation, arbitration, consumer, competition, insolvency, data-protection and sector-regulatory overlays only where factually relevant.

Official source: https://www.indiacode.nic.in/handle/123456789/13683?view_type=browse
The IT Act corpus is read with the IT Rules 2021 updated on 10 February 2026 and corrigenda dated 26 February 2026, CERT-In directions and the DPDP transition. Section 66A is retained only as an invalidated/historical provision.
chapters
Chapter I - Preliminary

Map computer resource, data, electronic record, intermediary, communication device, cyber security and territorial reach.

chapters
Chapters II-III - Electronic Signatures and E-governance

Control authentication, legal recognition, retention, electronic filing and e-contract validity.

chapters
Chapters IV-V - Attribution and Secure Records

Prove originator, acknowledgement, time/place and security procedure.

chapters
Chapters VI-VIII - Certifying Authorities, Certificates and Subscribers

Map Controller, licensing, certificates, repositories, subscriber duties, suspension and revocation.

chapters
Chapter IX - Compensation and Adjudication

Control unauthorised acts, data-security compensation, adjudicating officer and quantum evidence.

chapters
Chapter X - Appellate Framework

Track successor appellate forum, appeal, procedure, civil-court bar and limitation.

chapters
Chapter XI-A - Cyber Offences

Separate civil contraventions and criminal offences; preserve forensic and authorisation evidence.

chapters
Chapter XII - Intermediary Safe Harbour and Evidence Examiner

Safe harbour depends on actual intermediary role, due diligence, knowledge, takedown and non-participation.

chapters
Chapters XII-XIII - Search, Extraterritoriality and Miscellaneous

Map search, confiscation, company liability, encryption, abetment, attempt, rule-making and excluded documents.

chapters
IT Act Schedules and Excluded Documents

Track excluded documents and consequential legislative amendments, including current status of omitted schedules.

instruments
IT Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 - Updated 2026

Apply current due diligence, grievance, SSMI, publisher, GAC and synthetically generated information requirements.

instruments
IT Rules Synthetically Generated Information Amendment, 2026 and Corrigenda

Map labels, provenance, intermediary duties, timing and corrected text for SGI.

instruments
Grievance Appellate Committee Notification, 2026

Track committee constitution, appeal process and digital filing.

instruments
CERT-In Directions, 2022 and FAQs

Control incident reporting, log retention, time synchronisation, subscriber/KYC records and point of contact.

instruments
Sensitive Personal Data or Information Rules, 2011

Apply transitional/overlapping data-security and privacy obligations only after reconciling DPDP commencement and savings.

instruments
Reasonable Security Practices and ISO 27001 Interface

Build documented security programme and audit evidence for section 43A and sector law.

instruments
Blocking for Access of Information Rules, 2009

Map authorised requests, committee procedure, emergency blocking, confidentiality and review.

instruments
Interception, Monitoring and Decryption Rules, 2009

Control lawful authorisation, service-provider assistance, safeguards and records.

instruments
Traffic Data Monitoring Rules, 2009

Map cyber-security traffic monitoring directions and safeguards.

instruments
Certifying Authorities Rules and Regulations

Control licensing, repositories, audit, certificate practice statements and subscriber lifecycle.

instruments
IT Adjudicating Officer Rules, 2003 as amended

Map complaint, inquiry, service, evidence, order and appeal.

instruments
Cyber Cafe Rules, 2011

Map identity, logs, layout, inspection and retention for covered establishments.

masters
Electronic Contract Formation and Clickwrap

Professional technology-law control master for electronic contract formation and clickwrap

masters
Electronic Signature and Document Integrity

Professional technology-law control master for electronic signature and document integrity

masters
Electronic Evidence and Forensic Collection

Professional technology-law control master for electronic evidence and forensic collection

masters
Access Control Logging and Attribution

Professional technology-law control master for access control logging and attribution

masters
Cyber Incident and CERT-In Reporting

Professional technology-law control master for cyber incident and cert-in reporting

masters
Intermediary Classification and Safe Harbour

Professional technology-law control master for intermediary classification and safe harbour

masters
Grievance Takedown and GAC Appeals

Professional technology-law control master for grievance takedown and gac appeals

masters
Social Media Intermediary Compliance

Professional technology-law control master for social media intermediary compliance

masters
Synthetic Media and Deepfake Governance

Professional technology-law control master for synthetic media and deepfake governance

masters
Website App Terms Privacy and Cookies

Professional technology-law control master for website app terms privacy and cookies

masters
Vendor Cloud and Data Processing Contracts

Professional technology-law control master for vendor cloud and data processing contracts

masters
Cyber Crime Complaint and Investigation Response

Professional technology-law control master for cyber crime complaint and investigation response

masters
Search Seizure and Device Preservation

Professional technology-law control master for search seizure and device preservation

masters
Critical Information Infrastructure Readiness

Professional technology-law control master for critical information infrastructure readiness

masters
Employee Monitoring and Acceptable Use

Professional technology-law control master for employee monitoring and acceptable use

masters
E-commerce Fintech and Payment Interface

Professional technology-law control master for e-commerce fintech and payment interface

masters
DPDP Transition and Data Security

Professional technology-law control master for dpdp transition and data security

masters
Case-law Citator and MeitY Advisory Tracker

Professional technology-law control master for case-law citator and meity advisory tracker