Source, commencement and implementation control
MeitY / CERT-In / Controller of Certifying Authorities
The Act commenced on 17 October 2000, subject to later inserted provisions and separately effective subordinate instruments.
IT Act, Intermediary Rules, CERT-In directions and current amendments/corrigenda must be read separately. Draft amendments are not operative law.
Provision architecture and professional interpretation are local. Exact statutory wording and event-date instruments remain controlled by the official source.
Official source: Open the current India Code record.
Provision-specific operating checklist
- Classify electronic record, computer resource, intermediary and regulated service.
- Preserve logs, hashes, chain of custody and access records.
- Separate civil compensation, criminal offence and regulatory direction.
- Test safe-harbour conditions and actual-knowledge workflow.
- Apply cert-in incident reporting and retention controls.
- Exclude section 66a as invalidated and historical only.
Topic under review: Information Technology Act, 2000 and Electronic Transactions - Complete Professional Corpus. Before advice, filing, enforcement or publication, preserve the operative Act, commencement notification, applicable Rules/regulations, amendments, portal instructions and current judicial treatment in the matter file.
Finin2min implementation record for this unit
Decision question. Identify the exact statutory or regulatory trigger covered by Information Technology Act, 2000 and Electronic Transactions - Complete Professional Corpus, the person on whom the duty falls, the event date and the evidence that proves compliance or breach.
Applicability test. Record the entity, transaction, product, data set, project, market or proceeding in scope; test statutory exclusions and exemptions; then freeze the version of the law applying on the event date.
Execution workflow. Allocate the matter to responsible legal, compliance, finance, operations and evidence owners; prepare a dated issue note; obtain approvals; complete filing, disclosure, notice, payment or remediation; and retain acknowledgement plus supporting evidence.
Consequence and remedy. Distinguish administrative correction, civil relief, compensation, monetary penalty, prosecution, appeal, settlement, mediation, arbitration and constitutional or judicial review. Limitation and pre-deposit requirements must be computed independently.
Cross-law review. Test the Contract Act, Companies Act, GST, income tax, accounting, evidence, limitation, arbitration, consumer, competition, insolvency, data-protection and sector-regulatory overlays only where factually relevant.
The IT Act corpus is read with the IT Rules 2021 updated on 10 February 2026 and corrigenda dated 26 February 2026, CERT-In directions and the DPDP transition. Section 66A is retained only as an invalidated/historical provision.
Map computer resource, data, electronic record, intermediary, communication device, cyber security and territorial reach.
Control authentication, legal recognition, retention, electronic filing and e-contract validity.
Prove originator, acknowledgement, time/place and security procedure.
Map Controller, licensing, certificates, repositories, subscriber duties, suspension and revocation.
Control unauthorised acts, data-security compensation, adjudicating officer and quantum evidence.
Track successor appellate forum, appeal, procedure, civil-court bar and limitation.
Separate civil contraventions and criminal offences; preserve forensic and authorisation evidence.
Safe harbour depends on actual intermediary role, due diligence, knowledge, takedown and non-participation.
Map search, confiscation, company liability, encryption, abetment, attempt, rule-making and excluded documents.
Track excluded documents and consequential legislative amendments, including current status of omitted schedules.
Apply current due diligence, grievance, SSMI, publisher, GAC and synthetically generated information requirements.
Map labels, provenance, intermediary duties, timing and corrected text for SGI.
Track committee constitution, appeal process and digital filing.
Control incident reporting, log retention, time synchronisation, subscriber/KYC records and point of contact.
Apply transitional/overlapping data-security and privacy obligations only after reconciling DPDP commencement and savings.
Build documented security programme and audit evidence for section 43A and sector law.
Map authorised requests, committee procedure, emergency blocking, confidentiality and review.
Control lawful authorisation, service-provider assistance, safeguards and records.
Map cyber-security traffic monitoring directions and safeguards.
Control licensing, repositories, audit, certificate practice statements and subscriber lifecycle.
Map complaint, inquiry, service, evidence, order and appeal.
Map identity, logs, layout, inspection and retention for covered establishments.
Professional technology-law control master for electronic contract formation and clickwrap
Professional technology-law control master for electronic signature and document integrity
Professional technology-law control master for electronic evidence and forensic collection
Professional technology-law control master for access control logging and attribution
Professional technology-law control master for cyber incident and cert-in reporting
Professional technology-law control master for intermediary classification and safe harbour
Professional technology-law control master for grievance takedown and gac appeals
Professional technology-law control master for social media intermediary compliance
Professional technology-law control master for synthetic media and deepfake governance
Professional technology-law control master for website app terms privacy and cookies
Professional technology-law control master for vendor cloud and data processing contracts
Professional technology-law control master for cyber crime complaint and investigation response
Professional technology-law control master for search seizure and device preservation
Professional technology-law control master for critical information infrastructure readiness
Professional technology-law control master for employee monitoring and acceptable use
Professional technology-law control master for e-commerce fintech and payment interface
Professional technology-law control master for dpdp transition and data security
Professional technology-law control master for case-law citator and meity advisory tracker