CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice
Regulatory Framework on AI, Cyber Security and Cyberspace: formula sheet
Key formulas
- Territorial reach of the IT Act
- Applies to whole of India + offences or contraventions committed outside India by any person (save as otherwise provided)
- Section 1(2). Exceptions: documents or transactions in the First Schedule (section 1(4)).
- CERT-In functions
- Collect, analyse and disseminate cyber incident information; forecast and alerts; emergency measures; coordinate response; issue guidelines, advisories, vulnerability notes and white papers; other prescribed functions
- Section 70B(4)(a) to (f).
- CERT-In powers and penalty
- May call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. Default: imprisonment up to 1 year or fine up to ₹1 crore or both
- Section 70B(6) and (7). Court takes cognizance only on a complaint by an officer authorised by CERT-In (70B(8)).
- Section 69B traffic data monitoring
- Central Government notifies an agency to monitor and collect traffic data; intermediary or person in charge must give technical assistance; intermediary's intentional or knowing default: up to 1 year imprisonment or fine up to ₹1 crore or both
- Section 69B(1), (2), (4). Procedure and safeguards are as prescribed.
- Cyber terrorism
- Section 66F: intent to threaten unity, integrity, security or sovereignty of India or strike terror + prohibited act + specified consequence; punishment up to imprisonment for life
- Also covers unauthorised access to information restricted for State security or foreign relations (66F(1)(B)). Conspiracy is punished equally.
- Section 43A status
- Section 43A (compensation for failure to protect data) omitted by section 44(2)(a) of the DPDP Act, 2023
- Contrast old and new regimes when asked.
- Computer resource
- Computer resource = computer + computer system + computer network + data + computer data base + software
- Section 2(1)(k). Any one of these items is enough.
- Cyber security
- Protection of information, equipment, devices, computer, computer resource, communication device and stored information from unauthorised access, use, disclosure, disruption, modification or destruction
- Section 2(1)(nb). Inserted in 2017. Quote the six threats.
- Intermediary
- Person who, on behalf of another, receives, stores or transmits a particular electronic record or provides a service for it
- Section 2(1)(w). Includes ISPs, search engines, online marketplaces, payment sites and cyber cafes.
- Electronic record
- Data, record, generated data, image or sound stored, received or sent in electronic form or micro film or computer generated micro fiche
- Section 2(1)(t).
- Originator and addressee
- Originator sends, generates, stores or transmits a message; addressee is the intended recipient. Neither includes an intermediary
- Section 2(1)(za) and (b).
- Electronic signature
- Electronic signature = authentication by the technique in the Second Schedule, and includes digital signature
- Section 2(1)(ta). A digital signature uses an asymmetric crypto system with a key pair.
- Traffic data (section 69B Explanation)
- Data identifying or purporting to identify any person, computer system, network or location to or from which a communication is or may be transmitted, including origin, destination, route, time, data, size, duration or type of service
- Defined for section 69B only, not in section 2.
- Power under s. 69B(1)
- Central Government + Gazette notification → authorised Government agency → monitor and collect traffic data or information
- Purpose: enhance cyber security; identify, analyse and prevent intrusion or spread of computer contaminant.
- Duty under s. 69B(2)
- Intermediary or person in charge of computer resource, when called upon → technical assistance + all facilities → online access
- Applies to the resource generating, transmitting, receiving or storing the traffic data or information.
- Procedure under s. 69B(3)
- Procedure and safeguards = as prescribed
- Rule-making power is in section 87(2)(za).
- Penalty under s. 69B(4)
- Intermediary intentionally or knowingly contravenes (2) → imprisonment up to one year, or fine up to ₹1 crore, or both
- Substituted by Act 18 of 2023 w.e.f. 30-11-2023. Earlier text: imprisonment up to three years and also fine. Applies to intermediary only.
- Traffic data (Explanation)
- Data identifying or purporting to identify any person, computer system, network or location to or from which communication is or may be transmitted, incl. origin, destination, route, time, data, size, duration, type of service and other information
- Computer contaminant takes its meaning from section 43.
- Section 69 vs 69B
- s. 69: interception, monitoring, decryption of information, by order with reasons in writing | s. 69B: monitoring and collecting traffic data, by notification of agency, for cyber security
- Section 69 non-assistance: up to seven years and fine. Section 69B: up to one year or fine up to ₹1 crore or both.
- Limb (A) structure
- Intent + one of three acts + (actual or likely) harm = cyber terrorism
- Intent: threaten unity, integrity, security or sovereignty of India, or strike terror. Acts: denial of access, unauthorised access (or exceeding authorised access), introducing a computer contaminant.
- Limb (B) structure
- Knowing or intentional unauthorised access + obtaining restricted information = cyber terrorism
- Restricted for security of the State or foreign relations, or other restricted data with reason to believe it may be used to cause injury to listed interests.
- Punishment
- Section 66F(2): imprisonment which may extend to imprisonment for life
- Applies to whoever commits or conspires to commit. Maximum only; the section states no fine.
- Harm results under limb (A)
- Causes or is likely to cause death or injuries to persons or damage to or destruction of property | disrupts, or knowing that it is likely to cause damage or disruption of, supplies or services essential to the life of the community | adversely affect the critical information infrastructure specified under section 70
- Any one result is enough. Use the exact wording of each: 'causes or is likely to cause' for death, injuries or damage to property; 'disrupts or knowing that it is likely to cause damage or disruption' for essential supplies or services; 'adversely affect' for critical information infrastructure, where the section states no likelihood qualifier.
- Adjudicating officer: who and what rank
- Officer not below Director to Government of India (or equivalent State officer), appointed by Central Government – section 46(1)
- Must have the prescribed IT and legal or judicial experience (section 46(3)).
- Monetary jurisdiction
- Claim for damage ≤ ₹5 crore → adjudicating officer; claim > ₹5 crore → competent court
- From section 46(1A). Say 'does not exceed ₹5 crore' for the officer.
- Appeal under IT Act
- Appeal to Appellate Tribunal within 45 days of receiving the order (section 57(3))
- Tribunal may condone delay for sufficient cause. No appeal lies against an order made by an adjudicating officer with the consent of the parties (section 57(2)).
- Disposal target
- Tribunal to endeavour to dispose of the appeal within 6 months of receipt (section 57(6))
- It is an endeavour, not a hard bar.
- Appeal under DPDP Act
- Appeal against Board order or direction within 60 days (DPDP section 29(2))
- Orders of the Tribunal are executable as a civil court decree (DPDP section 30).
- Bar on civil courts
- No civil court jurisdiction over matters the adjudicating officer or Appellate Tribunal can decide – section 61
- No injunction by any court or authority against action under the Act.
- Penalty vs offence
- Contravention → penalty or compensation (adjudicating officer); Offence → imprisonment or fine (criminal court)
- Always classify first.
- Key offence punishments
- s.66: up to 3 years or fine up to ₹5 lakh, or both; s.66C and s.66D: up to 3 years and fine up to ₹1 lakh; s.66E: up to 3 years or fine up to ₹2 lakh, or both; s.66F: imprisonment for life; s.67 first conviction: up to 3 years and fine up to ₹5 lakh
- Check the bare Act for exact wording before the exam, as the elective is open book.
- Protected system (s 70)
- Gazette notification by appropriate Government + computer resource that directly or indirectly affects CII = protected system
- Access only by persons authorised by written order. Unauthorised access or attempt: imprisonment up to 10 years and fine.
- CII definition (s 70 Explanation)
- CII = computer resource whose incapacitation or destruction has a debilitating impact on national security, economy, public health or safety
- Quote the four heads: national security, economy, public health, safety.
- National nodal agency (s 70A)
- Central Government notification designates a Government organisation for CII protection, including R&D
- Section is silent on the name. NCIIPC is the practice name.
- CERT-In functions (s 70B(4))
- Collect/analyse/disseminate incident information; forecast and alerts; emergency measures; coordinate response; issue guidelines and advisories; other prescribed functions
- Six functions: (a) to (f).
- CERT-In directions and penalty (s 70B(6), (7))
- Failure to provide information or comply with direction: imprisonment up to 1 year, or fine up to ₹1 crore, or both
- Fine limit raised from one lakh to one crore from 30-11-2023.
- Cognizance (s 70B(8))
- Court takes cognizance only on complaint by an officer authorised by CERT-In
- Frequently missed in case answers.
Quick revision
- The IT Act, 2000 extends to the whole of India and applies to offences or contraventions committed outside India by any person, unless the Act provides otherwise.
- The Act does not apply to documents or transactions in the First Schedule; the Central Government can amend that Schedule by notification.
- Section 69B: the Central Government may, by notification, authorise any Government agency to monitor and collect traffic data for cyber security.
- Section 69B purpose: to enhance cyber security and to identify, analyse and prevent intrusion or spread of computer contaminant.
- Section 69B(2): the intermediary or person in charge must give technical assistance and facilities to the authorised agency.
- Section 69B(4): an intermediary who intentionally or knowingly contravenes sub-section (2) may face imprisonment up to one year, or a fine up to one crore rupees, or both.
- Traffic data includes origin, destination, route, time, date, size, duration or type of underlying service of a communication.
- Section 69 allows directions to intercept, monitor or decrypt information; failure to assist can mean imprisonment up to seven years and a fine.
- Section 66F covers cyber terrorism: intent to threaten India's unity, integrity, security or sovereignty, or to strike terror, plus the prescribed conduct and effect.
- Section 66F punishment: imprisonment which may extend to life, for committing or conspiring to commit cyber terrorism.
- Section 77: compensation, penalty or confiscation under the IT Act does not prevent punishment under any other law.
- The DPDP Act, 2023 omitted section 43A of the IT Act.
Common mistakes
- Saying India has a comprehensive AI Act. Fix: State that AI is governed through existing laws such as the IT Act and DPDP Act plus policy guidance.
- Treating section 43A as still the main data protection remedy. Fix: Mention that DPDP Act section 44(2)(a) omits it, and explain the shift to the DPDP framework.
- Treating computer resource as only a physical computer. Fix: Remember that data, computer data base and software are also computer resources.
- Calling every website owner an intermediary. Fix: Check whether the person receives, stores, transmits or serves a record for someone else.
- Saying section 69B allows interception and decryption of message content. Fix: Link 69 to interception, monitoring and decryption of information, and 69B to traffic data for cyber security.
- Stating the old penalty of three years' imprisonment and fine. Fix: Write: imprisonment up to one year, or fine up to ₹1 crore, or both, as substituted w.e.f. 30-11-2023.
- Treating every serious hacking incident as cyber terrorism. Fix: Always prove the intent to threaten India's unity, integrity, security or sovereignty, or to strike terror. A hack for money fits other sections, not 66F.
- Stating that section 66F prescribes a fine or a minimum jail term. Fix: Write only what sub-section (2) says: imprisonment which may extend to imprisonment for life.
- Saying the adjudicating officer can send a hacker to jail. Fix: The officer imposes only penalty or compensation. Imprisonment is for criminal courts.
- Saying the adjudicating officer handles every claim. Fix: Write that claims for damage above ₹5 crore vest in the competent court.
Exam tips
- Open every answer by stating that India regulates AI through existing laws, then name them.
- Learn the section 69B and 70B penalty (up to one year, fine up to ₹1 crore) and the 2023 amendment date.
- Keep a one-line contrast ready: section 43A omitted by DPDP Act section 44(2)(a).
- Use the format provision, application to facts, conclusion, and add one practical compliance step.
- For policy-based questions, say whether the instrument is binding or advisory.
- Learn the definitions almost word for word. Examiners reward the statutory test, not paraphrases.
- In a case on intermediaries, always add the link to section 69B duty of technical assistance and the penalty if the facts show non-cooperation.
- Mention that traffic data is defined in the Explanation to section 69B, not in section 2.