₹99 ₹499 · Full access — all mocks, practice sets & books · Unlock now
← Index: Indian Polity — Complete GuideChapter 70
Study Guide · Chapter 70

Information Technology Act and Cyber Law Framework

Free study material · concepts, shortcuts & solved questions

✍️ Select any text to highlight or save it

Regulating the Digital Domain — Constitutional Boundaries and Statutory Detail


The Information Technology Act, 2000

India's principal cyber law statute, providing legal recognition for electronic transactions/records/digital signatures, and criminalizing various cyber offences (hacking, identity theft, cyber terrorism, publishing obscene material electronically, among others).

Section 66A and Shreya Singhal v. Union of India (2015)

  • Section 66A (inserted by a 2008 amendment) criminalized sending "offensive" messages through communication services — extremely broadly worded, without clear definitional boundaries for what counted as "offensive," "grossly offensive," or causing "annoyance/inconvenience."
  • Shreya Singhal v. Union of India (2015): The Supreme Court struck down Section 66A in its entirety as unconstitutional, violating Article 19(1)(a) (freedom of speech and expression) — held the provision's vagueness and overbreadth created a "chilling effect" on legitimate speech, since its subjective, undefined terms could criminalize a vast range of ordinary online expression, with no clear boundary between protected speech and criminal offence.
  • Significance: A landmark digital-age free speech case, frequently cited alongside the sedition-law discussion (Chapter 37) as part of the broader constitutional conversation about vague, overbroad speech-restricting provisions.
  • Persistent enforcement issue: Despite being struck down in 2015, subsequent studies/reports have found Section 66A continued to be invoked by police in some cases for years afterward, due to lack of awareness/updated procedural guidance at the ground level — a notable real-world illustration of the gap between a Supreme Court ruling's formal legal effect and its actual on-the-ground implementation, which the Supreme Court itself later had to specifically re-address with directions to state governments/police to cease any continued use.

Intermediary Liability and IT Rules, 2021

  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 established due-diligence obligations for social media/digital platforms ("intermediaries"), content takedown procedures, and a three-tier grievance redressal mechanism for digital news/OTT content — a significant, relatively recent regulatory expansion into digital platform governance.
  • Distinguishes between ordinary intermediaries and "significant social media intermediaries" (those crossing specified user-count thresholds), imposing additional obligations on the latter (e.g., appointment of a Chief Compliance Officer, grievance officer, and — for significant platforms enabling messaging — traceability requirements for the "first originator" of specific flagged content, itself a subject of ongoing privacy-related legal debate).

Cyber Federalism

Since "cybercrime" spans both traditional criminal law (State List policing) and specialized central legislation (the IT Act, a Union-enacted statute), cybercrime investigation/enforcement exhibits similar Centre-state coordination dynamics to the terrorism/NIA framework discussed in Chapter 54 — most cybercrime is investigated by state police (through dedicated Cyber Crime cells), while certain categories (particularly those with a cross-border or national-security dimension) fall within the NIA's expanded 2019 scheduled-offences jurisdiction.


Common Traps

  • Section 66A was struck down in 2015 but continued to see some enforcement in practice for years afterward — a frequently tested "law struck down but still misapplied" nuance, illustrating implementation gaps even for clear Supreme Court rulings.
  • Shreya Singhal (2015) struck down Section 66A specifically for vagueness/overbreadth and its chilling effect on Article 19(1)(a) — not on privacy grounds (that came later, via Puttaswamy, 2017) — a frequently confused chronology/reasoning point.
  • The IT Rules, 2021, are delegated/subordinate legislation (Rules made under the IT Act's rule-making power), not a standalone Act of Parliament — a frequently tested "Rules vs Act" distinction relevant to understanding their comparatively easier amendability (executive rule-making) versus a full parliamentary statute.

Solved Example (UPSC Prelims-Format MCQ)

Q1. Which case struck down Section 66A of the IT Act as unconstitutional? (a) Justice K.S. Puttaswamy case (b) Shreya Singhal v. Union of India (c) Anuradha Bhasin case (d) Navtej Singh Johar case Answer: (b)


Practice Set (Exam-Format MCQs)

Q1. Section 66A of the IT Act was struck down primarily on grounds of: (a) Violating the right to privacy (b) Vagueness/overbreadth creating a chilling effect on Article 19(1)(a) (c) Violating federalism principles (d) Violating Article 21 exclusively Answer: (b)

Q2. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules were notified in: (a) 2000 (b) 2008 (c) 2015 (d) 2021 Answer: (d)

Q3. The IT Rules, 2021, are best classified as: (a) A standalone Act of Parliament (b) Delegated/subordinate legislation under the IT Act (c) A constitutional amendment (d) A Supreme Court judgment Answer: (b)

Q4. "Significant social media intermediaries" under the 2021 Rules face additional obligations including: (a) Complete exemption from all regulation (b) Appointment of Chief Compliance Officer and grievance officer, plus traceability requirements (c) Automatic government ownership (d) Mandatory relocation to India Answer: (b)


Chapter 69 Quick Revision Sheet

  • IT Act, 2000: Principal cyber law statute.
  • Section 66A: Struck down in Shreya Singhal (2015) for vagueness/Article 19(1)(a) chilling effect — but saw continued enforcement in practice for years afterward.
  • IT Rules, 2021: Delegated legislation; intermediary due-diligence, grievance redressal, "significant" intermediary additional obligations (traceability, compliance officers).
  • Cyber federalism: State police (Cyber Crime cells) generally investigate; NIA's 2019-expanded jurisdiction covers specific national-security-linked cybercrime categories.
← Chapter 69TOC IndexChapter 71