Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Threats and Cyber Laws

Interception, Blocking and Protected Systems under the IT Act

Updated 11 October 2026 · Fact-checked

Sections 69, 69A and 70 of the IT Act, 2000 let the Government intercept or decrypt information, block public access to it, and declare critical computer resources as protected systems. Each power needs stated grounds and written reasons. Sections 70A and 70B set up the national nodal agency and CERT-In. Answer by listing power, authority, grounds, duty and penalty.

Understand Interception, Blocking and Protected Systems

The IT Act gives the State strong powers over information in computer resources. These powers sit in sections 69 to 70B. Each one is limited by grounds, reasons recorded in writing, and prescribed procedure and safeguards.

Interception (section 69) lets the Central Government, a State Government, or an officer specially authorised by them, direct any agency of the appropriate Government to intercept, monitor or decrypt information generated, transmitted, received or stored in any computer resource. The satisfaction must be that it is necessary or expedient in the interest of the sovereignty or integrity of India, defence of India, security of the State, friendly relations with foreign States or public order, or to prevent incitement to a cognizable offence relating to these, or for investigation of any offence. The order must record reasons in writing.

Blocking (section 69A) lets the Central Government, or an officer it specially authorises, direct a Government agency or an intermediary to block public access to information. The grounds are the same as in section 69, except that investigation of any offence is not a ground. Note that only the Central Government acts here, not a State Government.

Protected systems (section 70) work differently. The appropriate Government may notify, in the Official Gazette, a computer resource that directly or indirectly affects the facility of Critical Information Infrastructure (CII) as a protected system. CII means a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. Only persons authorised by written order may access it. Section 70A allows the Central Government to designate a Government organisation as the national nodal agency for CII protection, responsible for all measures including research and development. Section 70B creates the Indian Computer Emergency Response Team (CERT-In) as the national agency for incident response.

Key rules to remember

Section 69 – interception, monitoring, decryption
Central/State Government or specially authorised officer → written reasons → order to agency of the appropriate Government
Grounds include investigation of any offence. Procedure and safeguards are as prescribed. Failure to assist: up to 7 years' imprisonment and fine.
Section 69(3) – duty to assist
Subscriber / intermediary / person in charge must give all facilities and technical assistance
Assistance means access to the computer resource, interception, monitoring or decryption, or providing stored information.
Section 69A – blocking
Central Government or specially authorised officer → written reasons → direct Government agency or intermediary to block public access
Intermediary failing to comply: up to 7 years' imprisonment and fine. Investigation of any offence is not a ground.
Section 70 – protected system
Appropriate Government notifies in Official Gazette a resource affecting CII; access only by authorised persons
Unauthorised access or attempt: imprisonment of either description up to 10 years and fine. Central Government prescribes security practices.
Section 70A – national nodal agency
Central Government designates a Government organisation by notification for CII protection
Responsible for all measures including research and development.
Section 70B – CERT-In
Non-compliance with its call for information or directions: up to 1 year, or fine up to ₹1 crore, or both
No court takes cognizance except on a complaint by an officer authorised by CERT-In.

How to solve Interception, Blocking and Protected Systems questions

Use the same frame for any problem question on these sections: provision, facts, conclusion.

  1. 1Identify the power in the facts: reading content, stopping public access, protecting a critical system or incident reporting.
  2. 2Name the section: 69 for interception, 69A for blocking, 70 for protected systems, 70A for the nodal agency, 70B for CERT-In.
  3. 3Check who is acting. Section 69 covers Central or State Government. Section 69A covers only the Central Government or its specially authorised officer.
  4. 4Check the ground. Match the stated purpose to the listed grounds, and remember investigation of an offence applies to section 69 only.
  5. 5Check procedure: reasons recorded in writing, an order, and the prescribed safeguards.
  6. 6Identify the duty of the private party (assist, block, comply, not access) and the penalty for default.
  7. 7Write a clear conclusion: lawful or not, and the consequence for the person involved.

Quickest way: Power, who, ground, duty, penalty

When to use it: When time is short and the question asks for a short note or a quick fact pattern.

  1. Write the section number and one line on what it does.
  2. State who can act and the grounds.
  3. State that reasons must be recorded in writing and procedure is prescribed.
  4. State the duty on the intermediary or person and the penalty.
  5. Add one line applying the rule to the facts given.

Common mistakes in Interception, Blocking and Protected Systems

  • Saying a State Government can order blocking under section 69A.

    Section 69 mentions State Governments, so students assume 69A does too.

    Fix: Remember 69A names only the Central Government or its specially authorised officer.

  • Listing investigation of any offence as a ground for blocking.

    Students copy the section 69 grounds into 69A.

    Fix: Blocking grounds end with preventing incitement to a cognizable offence relating to the listed interests. Investigation is only in section 69.

  • Mixing up penalties: giving 7 years for CERT-In non-compliance or 1 year for failing to assist interception.

    The sections look alike and have many numbers.

    Fix: Learn: 69(4) and 69A(3) up to 7 years and fine; 70 up to 10 years and fine; 70B(7) up to 1 year or fine up to ₹1 crore or both.

  • Treating any computer as a protected system.

    Students overlook the notification requirement.

    Fix: A resource is protected only if notified in the Official Gazette and linked to Critical Information Infrastructure.

  • Confusing the national nodal agency (70A) with CERT-In (70B).

    Both deal with cyber security and are national agencies.

    Fix: 70A is for protection of CII, including research and development. 70B is for incident response: collecting information, alerts, emergency measures, coordination and advisories.

  • Omitting 'reasons to be recorded in writing'.

    Students focus on powers and forget the safeguard.

    Fix: State it in every answer on sections 69 and 69A, along with the prescribed procedure.

Worked examples

Example 1

A State Government officer, specially authorised by the State Government, orders an agency to monitor information stored on a server of an intermediary to investigate a cognizable offence. The intermediary refuses to extend technical assistance. Advise on the legal position.

Show the solution
  1. Provision: section 69(1) allows a State Government or its specially authorised officer to direct an agency to intercept, monitor or decrypt information, if satisfied it is necessary or expedient, for reasons recorded in writing.
  2. Ground: investigation of any offence is a listed ground, so the purpose is valid.
  3. Procedure: the order must be in writing with reasons, and follow the prescribed procedure and safeguards under section 69(2).
  4. Duty: under section 69(3) the intermediary must extend all facilities and technical assistance, including access to the resource and providing stored information.
  5. Consequence: under section 69(4) refusal is punishable with imprisonment up to seven years and fine.

Answer: If the written order with recorded reasons and prescribed safeguards exists, the monitoring is lawful and the intermediary must assist. Its refusal is an offence punishable with imprisonment up to seven years and fine.

Example 2

An officer of the Central Government, specially authorised, orders a social media intermediary to block a post that threatens public order. The intermediary does not comply. Another firm's server, notified as a protected system, is accessed by an unauthorised employee. State the consequences.

Show the solution
  1. Blocking: section 69A(1) allows the Central Government or its specially authorised officer to direct an intermediary to block public access, for reasons recorded in writing, on grounds including public order.
  2. The procedure and safeguards are as prescribed under section 69A(2).
  3. Intermediary default: under section 69A(3) non-compliance is punishable with imprisonment up to seven years and fine.
  4. Protected system: section 70 applies because the server is notified and access is limited to authorised persons.
  5. Employee: securing or attempting to secure access without authorisation is punishable under section 70(3) with imprisonment of either description up to ten years and fine.

Answer: The intermediary faces imprisonment up to seven years and fine under section 69A(3). The employee faces imprisonment of either description up to ten years and fine under section 70(3).

Exam tips

  • Write section numbers beside every power and penalty. Examiners reward precision.
  • Tabulate in your head: who acts, grounds, duty, penalty. Use it as the skeleton of every answer.
  • In problem questions, always check whether the notification or written reasons exist before concluding the action is lawful.
  • Know the CERT-In functions in section 70B(4) as a list: collection and analysis of incident information, forecasts and alerts, emergency measures, coordination, guidelines and advisories.
  • Always contrast 69 (interception), 69A (blocking) and 69B (traffic data) in one line each.

Practice questions from Cyber Threats and Cyber Laws

Interception, Blocking and Protected Systems: frequently asked questions

What is the difference between section 69 and section 69A?

Section 69 deals with interception, monitoring and decryption of information. Section 69A deals with blocking public access to information. Section 69 can be used by State Governments too and includes investigation of any offence as a ground; 69A is Central Government only.

How does the government block a website under the IT Act?

The Central Government or a specially authorised officer records reasons in writing and issues an order under section 69A to a Government agency or intermediary. The procedure and safeguards are those prescribed. An intermediary that fails to comply faces imprisonment up to seven years and fine.

What is a protected system under section 70?

It is a computer resource that directly or indirectly affects the facility of Critical Information Infrastructure and is declared so by notification in the Official Gazette. Only authorised persons may access it. Unauthorised access can bring imprisonment up to ten years and fine.

What does CERT-In do under the IT Act?

Under section 70B it is the national agency for cyber incident response. It collects and analyses incident information, issues forecasts and alerts, handles emergency measures, coordinates response and issues guidelines and advisories. It can call for information and give directions to service providers, intermediaries, data centres and body corporates.