Skip to content

CMA Final · Corporate and Economic Laws

Laws and Regulations related to Cyber Security and Data Privacy

This chapter covers the Information Technology Act, 2000 and the data privacy framework around it. You study definitions, digital signatures, cyber offences, cyber terrorism (Section 66F), traffic data monitoring (Section 69B), intermediaries and adjudication. To solve questions, identify the actor, the act, the intent and the section, then state the consequence.

What this chapter covers

This chapter is about how Indian law treats computers, electronic records and data. The core is the Information Technology Act, 2000. It defines terms such as computer, computer resource, data, electronic record, intermediary and cyber security. It recognises digital and electronic signatures. It creates offences and penalties, and it gives the Central Government powers for cyber security. Around this sits the data protection and privacy framework.

Most exam questions test two things. The first is whether you know the exact definition or ingredient of an offence. The second is whether you can apply it to a short fact situation. For example, Section 66F (cyber terrorism) needs a specific intent plus a specific result or access. Section 69B lets the Central Government authorise a government agency to monitor and collect traffic data, and it puts a duty on intermediaries to help.

In Paper 13, this chapter sits with the other law chapters. It shares the same skill: read the facts, find the legal condition, and apply it. Some questions overlap with company and business law, such as electronic records, electronic signatures and the duties of a company's IT function. Treat it as a definitions-plus-ingredients chapter, not a story chapter.

Paper 13 has a compulsory Section A of MCQs, and a short case study there can be built on a technology or data situation. This chapter suits that format because its rules are precise: an offence either has its ingredients or it does not. Definitions in Section 2(1) and the exact wording of Sections 66F and 69B are easy to test and easy to lose marks on if you only remember the gist. It is also a compact chapter, so careful study here pays back quickly compared with its length, and it gives you a clear application answer in the written section.

Laws and Regulations related to Cyber Security and Data Privacy: topics in the order to study them

  1. 1Overview of the Information Technology Act, 2000Start here because every later topic uses the Section 2(1) definitions, such as computer resource, data, electronic record and intermediary.
  2. 2Digital Signature and Electronic GovernanceNext, learn how electronic records and signatures get legal recognition, since the later offences and duties refer to the same electronic world.
  3. 3Cyber Crimes and Penalties under the IT ActThen study the general offences and penalties, so you can tell ordinary cyber offences apart from the serious ones that follow.
  4. 4Cyber Terrorism under Section 66FThis is the most serious offence in the chapter and has a long wording, so study it once you know the basic offences.
  5. 5Monitoring of Traffic Data and Cyber Security (Section 69B)This section moves from offences to government powers, and it introduces the intermediary's duty to assist.
  6. 6Intermediary Liability and Adjudication MechanismNow that you have seen intermediary duties in Section 69B, study who an intermediary is, how liability works and who decides disputes.
  7. 7Data Protection and Privacy FrameworkFinish with the wider privacy framework, which builds on the IT Act ideas of data, consent and responsibility.

How to prepare Laws and Regulations related to Cyber Security and Data Privacy

Treat this as a precision chapter. You need exact wording for a few sections and clear plain-language understanding for the rest.

  1. Read the Section 2(1) definitions first and write one line for each of: access, computer, computer resource, computer network, data, electronic record, intermediary, cyber security and originator.
  2. For each offence, break it into three parts: who acts, what the act and intent are, and what the result or punishment is. Keep these in a small table in your own notes.
  3. Learn Section 66F in two limbs. Limb (A) needs intent to threaten the unity, integrity, security or sovereignty of India or to strike terror, plus one of three means and a harmful result. Limb (B) is about unauthorised access to restricted information, with reason to believe it may be misused.
  4. Learn Section 69B as a chain: Central Government notification, authorised agency, monitoring of traffic data, intermediary duty to give technical assistance, and penalty for knowing or intentional default.
  5. Write short answers to two or three fact-based questions on each topic. Name the section, apply the ingredients to the facts, and end with a clear conclusion.
  6. Practise MCQs, especially case-based ones, where two options differ by only one condition such as intent, authorisation or who must assist.
  7. Revise the data protection and privacy framework from the latest ICMAI study material and current law, and note which statements are dated.

Common mistakes in Laws and Regulations related to Cyber Security and Data Privacy

  • Applying Section 66F without checking intent

    Fix: First look for the intent to threaten India's unity, integrity, security or sovereignty, or to strike terror. Without it, limb (A) does not apply. For limb (B), check for restricted information and reason to believe it may be misused.

  • Mixing up traffic data with the content of a message

    Fix: Use the definition. Traffic data identifies a person, system, network or location and covers origin, destination, route, time, date, size, duration and type of service. Link it to cyber security monitoring.

  • Stating the old Section 69B penalty

    Fix: The current text says imprisonment up to one year, or a fine up to one crore rupees, or both, as substituted with effect from 30 November 2023.

  • Treating every service provider as an intermediary or originator

    Fix: Use the definitions. An originator sends or generates the message and excludes an intermediary. An intermediary handles the record on behalf of another person or provides a service for it.

  • Writing chapter answers as general essays on cyber crime

    Fix: Open every answer with the section and its conditions, apply them to the facts in a sentence or two, and close with the result or penalty.

  • Giving section numbers or penalties from memory for sections you have not checked

    Fix: Use only the numbers you have verified in the Act or ICMAI study material. If unsure, describe the offence and its ingredients in plain words.

Last-day revision: Laws and Regulations related to Cyber Security and Data Privacy

  • Section 2(1) defines computer resource as computer, computer system, computer network, data, computer data base or software.
  • An intermediary receives, stores or transmits an electronic record on behalf of another person, or provides a service for that record. It includes telecom, network, internet and web-hosting providers, search engines, online payment sites, online-auction sites, online marketplaces and cyber cafes.
  • An originator sends, generates, stores or transmits an electronic message, and does not include an intermediary.
  • Cyber security means protecting information, equipment, devices, computer, computer resource and communication device from unauthorised access, use, disclosure, disruption, modification or destruction.
  • Section 66F limb (A) needs intent to threaten India's unity, integrity, security or sovereignty, or to strike terror, plus a listed means and a harmful result.
  • The three means in Section 66F(1)(A) are denial of access, unauthorised access or exceeding authorised access, and introducing a computer contaminant.
  • Section 66F limb (B) covers knowing or intentional unauthorised access to information restricted for State security or foreign relations reasons, or other restricted information, with reason to believe it may cause injury.
  • Punishment for committing or conspiring to commit cyber terrorism may extend to imprisonment for life.
  • Under Section 69B, the Central Government authorises a Government agency by notification to monitor and collect traffic data for cyber security.
  • Traffic data identifies or purports to identify a person, system, network or location, and includes origin, destination, route, time, date, size, duration and type of service.
  • An intermediary who intentionally or knowingly fails to give technical assistance under Section 69B(2) faces imprisonment up to one year, or a fine up to one crore rupees, or both.
  • Adjudicating officers are appointed under Section 46(1), and the Indian Computer Emergency Response Team is established under Section 70B(1).

Laws and Regulations related to Cyber Security and Data Privacy practice questions

Laws and Regulations related to Cyber Security and Data Privacy in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Laws and Regulations related to Cyber Security and Data Privacy: frequently asked questions

Which sections of the IT Act matter most for CMA Final?

Learn the Section 2(1) definitions, the provisions on digital and electronic signatures, the main cyber offences, Section 66F and Section 69B. Also cover intermediaries and adjudication. Check the latest ICMAI study material for the exact list.

What is cyber terrorism under Section 66F?

It is an offence committed with intent to threaten India's unity, integrity, security or sovereignty, or to strike terror, using means such as denial of access, unauthorised access or a computer contaminant, with a harmful result. It also covers unauthorised access to restricted information with reason to believe it may be misused. Punishment may extend to imprisonment for life.

What does Section 69B allow the government to do?

The Central Government can authorise a Government agency, by notification in the Official Gazette, to monitor and collect traffic data or information in any computer resource. The purpose is to enhance cyber security and to identify, analyse and prevent intrusion or the spread of computer contaminants. Intermediaries must give technical assistance when the agency asks.

Is there a penalty if an intermediary refuses to help under Section 69B?

Yes, if the intermediary intentionally or knowingly contravenes the duty to assist. The punishment is imprisonment up to one year, or a fine up to one crore rupees, or both.

How should I answer a case-based MCQ from this chapter?

Read the facts for the actor, the act, the intent and any authorisation. Match them to the section's conditions and eliminate options that miss one condition. Do not pick an option only because it sounds serious.