Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Regulatory Framework on AI, Cyber Security and Cyberspace

Cyber Offences, Penalties and Adjudication under the IT Act

Updated 11 October 2026 · Fact-checked

The IT Act, 2000 splits wrongs into contraventions, which lead to penalty or compensation decided by an adjudicating officer, and criminal offences, which lead to imprisonment or fine decided by courts. Appeals from the adjudicating officer go to the Appellate Tribunal within 45 days. CERT-In handles incident response, not punishment.

Understand Cyber Offences, Penalties and Adjudication under the IT Act

Start with one split. The IT Act treats a wrong done through a computer in two ways. A contravention is a civil wrong. The person pays a penalty or compensation. An offence is a crime. The person can be punished with imprisonment, fine or both, after a criminal trial.

Contraventions such as unauthorised access, data theft, introducing a virus or denying access are decided by an adjudicating officer. Under section 46, the Central Government appoints an officer not below the rank of Director to the Government of India (or an equivalent State officer). The officer must hold the prescribed IT and legal or judicial experience. The officer holds an inquiry, gives the person a reasonable opportunity to be heard, and if satisfied imposes the penalty or awards compensation.

Money limit: the adjudicating officer decides claims for damage up to ₹5 crore. A claim above ₹5 crore goes to the competent court. Section 61 bars civil courts from entertaining any suit on a matter that the adjudicating officer or the Appellate Tribunal can decide, and bars injunctions on action taken under the Act.

Appeals go to the Appellate Tribunal. Under section 48, this is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). It follows natural justice, not the Code of Civil Procedure, but has civil court powers in matters such as summoning witnesses, requiring production of electronic records, taking evidence on affidavit and reviewing its decisions (section 58).

Offences are separate. Examples are computer-related offences (section 66), identity theft (66C), cheating by personation (66D), violation of privacy (66E), cyber terrorism (66F) and publishing obscene material (67). These are tried by courts. CERT-In (section 70B) is the national agency for incident response. It collects and analyses incident information, issues alerts and guidelines and coordinates response. It does not impose penalties.

Note the data-protection link. The Digital Personal Data Protection Act, 2023 omits section 43A of the IT Act. Appeals against orders of the Data Protection Board go to the same Appellate Tribunal, with a 60-day limit.

Key rules to remember

Adjudicating officer: who and what rank
Officer not below Director to Government of India (or equivalent State officer), appointed by Central Government – section 46(1)
Must have the prescribed IT and legal or judicial experience (section 46(3)).
Monetary jurisdiction
Claim for damage ≤ ₹5 crore → adjudicating officer; claim > ₹5 crore → competent court
From section 46(1A). Say 'does not exceed ₹5 crore' for the officer.
Appeal under IT Act
Appeal to Appellate Tribunal within 45 days of receiving the order (section 57(3))
Tribunal may condone delay for sufficient cause. No appeal lies against an order made by an adjudicating officer with the consent of the parties (section 57(2)).
Disposal target
Tribunal to endeavour to dispose of the appeal within 6 months of receipt (section 57(6))
It is an endeavour, not a hard bar.
Appeal under DPDP Act
Appeal against Board order or direction within 60 days (DPDP section 29(2))
Orders of the Tribunal are executable as a civil court decree (DPDP section 30).
Bar on civil courts
No civil court jurisdiction over matters the adjudicating officer or Appellate Tribunal can decide – section 61
No injunction by any court or authority against action under the Act.
Penalty vs offence
Contravention → penalty or compensation (adjudicating officer); Offence → imprisonment or fine (criminal court)
Always classify first.
Key offence punishments
s.66: up to 3 years or fine up to ₹5 lakh, or both; s.66C and s.66D: up to 3 years and fine up to ₹1 lakh; s.66E: up to 3 years or fine up to ₹2 lakh, or both; s.66F: imprisonment for life; s.67 first conviction: up to 3 years and fine up to ₹5 lakh
Check the bare Act for exact wording before the exam, as the elective is open book.

How to solve Cyber Offences, Penalties and Adjudication under the IT Act questions

Use this order for any case-based question on cyber wrongs and enforcement. It follows the provision, analysis, conclusion pattern.

  1. 1Read the facts and list each act done: access, copying, virus, impersonation, publication, interception, and so on.
  2. 2Classify each act as a contravention (civil, penalty or compensation) or an offence (criminal, imprisonment or fine). One act can be both.
  3. 3Name the provision. Quote the section only when you are sure, otherwise describe the rule in words.
  4. 4Identify the forum. Contravention: adjudicating officer if the claim does not exceed ₹5 crore, else the competent court. Offence: criminal court after investigation.
  5. 5Check the process points: reasonable opportunity of hearing, appeal to the Appellate Tribunal within 45 days, section 61 bar on civil courts.
  6. 6Add the role of CERT-In if there is an incident: reporting, alerts, coordination.
  7. 7Add practical compliance advice: preserve logs, report the incident, file the complaint or appeal in time.
  8. 8Write a one-line conclusion that answers the exact question asked.

Quickest way: Forum and time-limit check

When to use it: Use it when the question asks 'before whom' or 'within what time' and you have only a few minutes.

  1. Write 'civil or criminal?' in the margin and decide.
  2. If civil, compare the claim with ₹5 crore and name the forum.
  3. If an order exists, write the appeal route: Appellate Tribunal, 45 days under the IT Act (60 days for a Data Protection Board order).
  4. Add section 61 in one line to show civil courts are barred.
  5. Close with the CERT-In role if an incident or reporting is involved.

Common mistakes in Cyber Offences, Penalties and Adjudication under the IT Act

  • Saying the adjudicating officer can send a hacker to jail.

    Students blur penalty and punishment.

    Fix: The officer imposes only penalty or compensation. Imprisonment is for criminal courts.

  • Saying the adjudicating officer handles every claim.

    The ₹5 crore limit in section 46(1A) is forgotten.

    Fix: Write that claims for damage above ₹5 crore vest in the competent court.

  • Stating CERT-In can fine or prosecute.

    It is seen as the 'enforcer'.

    Fix: CERT-In is the national incident response agency. It collects, analyses, alerts and coordinates. Penalties come from adjudicating officers and courts.

  • Mixing the 45-day and 60-day appeal periods.

    Both Acts use the same Tribunal.

    Fix: IT Act appeal: 45 days. DPDP Act appeal against the Board: 60 days. Both allow delay for sufficient cause.

  • Still citing section 43A as a live provision.

    Old notes are used.

    Fix: The DPDP Act, 2023 omits section 43A of the IT Act. Cite it only as history.

  • Saying the Tribunal must follow the Code of Civil Procedure.

    It has civil court powers, so students assume full CPC procedure.

    Fix: Section 58 says it is not bound by the CPC but is guided by natural justice, and it regulates its own procedure.

Worked examples

Example 1

Nexora Tech Pvt. Ltd., Pune, finds that an ex-employee copied its customer database without permission and caused a loss of ₹3 crore. The company received the adjudicating officer's order on 10 March and wants to appeal. Advise on the forum, and the last date to appeal.

Show the solution
  1. Classification: unauthorised copying of data is a contravention giving rise to compensation, so it is a civil matter for the adjudicating officer.
  2. Forum: the claim for damage is ₹3 crore, which does not exceed ₹5 crore, so the adjudicating officer has jurisdiction under section 46(1A). Section 61 bars a civil suit on this matter.
  3. Process: the officer must give the ex-employee a reasonable opportunity to make representation before awarding compensation (section 46(2)).
  4. Appeal: an aggrieved person may appeal to the Appellate Tribunal within 45 days of receiving the order (section 57(3)).
  5. Computation: 10 March plus 45 days. 21 days remain in March (to 31 March), leaving 24 days, so the date is 24 April.
  6. Delay: if late, the Tribunal may entertain the appeal on showing sufficient cause.

Answer: The adjudicating officer has jurisdiction because ₹3 crore does not exceed ₹5 crore. The appeal lies to the Appellate Tribunal (TDSAT) by 24 April. The exact computation depends on the date of receipt of the order.

Example 2

A fraudster in Jaipur sends emails posing as a bank and cheats Ms. Meera Iyer of ₹4,00,000 by obtaining her net-banking password. Explain the legal position and the enforcement bodies involved.

Show the solution
  1. Classification: using another person's password to cheat is a criminal offence, not just a contravention.
  2. Provisions: identity theft (section 66C) and cheating by personation using a computer resource (section 66D) apply. Each carries imprisonment up to three years and a fine up to ₹1 lakh.
  3. Forum: the criminal courts try the offence after police investigation. The adjudicating officer cannot impose imprisonment.
  4. Civil side: if compensation for damage is claimed under the Act, it can be pursued before the adjudicating officer, since ₹4,00,000 is well below ₹5 crore.
  5. CERT-In: phishing incidents can be reported to CERT-In, which issues alerts and coordinates response. It does not punish the offender.
  6. Practical: Ms. Iyer should preserve the emails and bank messages and file a complaint promptly.

Answer: The fraudster commits offences under sections 66C and 66D, tried by a criminal court. Compensation can be sought from the adjudicating officer. CERT-In supports response and does not prosecute.

Exam tips

  • Always open with the civil or criminal split. It earns marks and prevents wrong forum answers.
  • Memorise the figures in the Act: ₹5 crore (adjudicating officer), 45 days (appeal), six months (target for disposal), rank of Director to Government of India.
  • In a case question, name the forum, the time limit and the CERT-In role even if the question does not list them.
  • Quote the punishment only for sections you are sure of, and since the elective is open book, verify it in the bare Act.
  • Use the DPDP Act link for a higher-scoring answer: section 43A omitted, 60-day appeal against the Board, same Tribunal.

Practice questions from Regulatory Framework on AI, Cyber Security and Cyberspace

Cyber Offences, Penalties and Adjudication under the IT Act in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Offences, Penalties and Adjudication under the IT Act: frequently asked questions

Who is an adjudicating officer under the IT Act, 2000?

The Central Government appoints an officer not below the rank of Director to the Government of India, or an equivalent State officer, under section 46. The officer must have the prescribed IT and legal or judicial experience. The officer decides whether a contravention occurred and imposes penalty or awards compensation.

What powers does the adjudicating officer have?

The officer holds an inquiry after giving a reasonable opportunity to be heard and can impose penalty or award compensation. The officer has the civil court powers given to the Appellate Tribunal under section 58(2), such as summoning witnesses and requiring production of documents. Proceedings are deemed judicial proceedings.

Where do you appeal against an adjudicating officer's order?

You appeal to the Appellate Tribunal, which is the Telecom Disputes Settlement and Appellate Tribunal, within 45 days of receiving the order. The Tribunal may allow a late appeal for sufficient cause. No appeal lies against an order made with the consent of the parties.

What is the role of CERT-In in enforcement?

CERT-In is the national agency for cyber incident response under section 70B. It collects and analyses incident information, issues alerts and guidelines, and coordinates response. It does not decide penalties or punish offenders.

Is section 43A of the IT Act still in force?

No. Section 44(2)(a) of the Digital Personal Data Protection Act, 2023 omits section 43A of the IT Act. Data protection duties now sit mainly under the DPDP Act.