Skip to content

Banking and Insurance - Laws and Practice · Digital Banking

Cyber Offences, Penalties and Data Protection in Banking

Updated 11 October 2026 · Fact-checked

Cyber offences in banking are acts like hacking, data theft, identity theft and data breach. Under the IT Act, 2000, section 43 gives compensation for damage to computers, section 43A makes negligent bodies corporate pay for data failures, and sections 66C, 66F and 72A punish specific acts. Solve questions by matching facts to the section.

Understand Cyber Offences, Penalties and Data Protection in Banking

Banks run on computers and data. A customer's money is, in practice, a record in a computer. So most banking frauds today are cyber offences. The IT Act, 2000 is the main law that deals with them.

The Act works on two tracks. The first track is civil: a person who suffers loss gets compensation. Section 43 and section 43A sit here. The second track is criminal or penal: the wrongdoer is punished with imprisonment or fine. Section 66C (identity theft) and section 66F (cyber terrorism) sit here. Section 72A and section 69B carry their own penalty or punishment for specific breaches.

Section 43 covers a person who, without the permission of the owner or person in charge of a computer, computer system or computer network, does listed acts. These include accessing it, downloading or copying data, introducing a computer virus or contaminant, damaging it, disrupting it, denying access to an authorised person, helping another to gain access in contravention of the Act, charging services to another person's account by tampering, destroying or altering information, or stealing, concealing or altering source code with intent to cause damage. The result is liability to pay damages by way of compensation to the person affected.

Section 43A is aimed at banks and other bodies corporate. If a body corporate holds sensitive personal data or information in a computer resource it owns, controls or operates, and is negligent in keeping reasonable security practices and procedures, and this causes wrongful loss or wrongful gain to anyone, it must pay compensation. Here "body corporate" includes any company, firm, sole proprietorship or other association engaged in commercial or professional activities.

Section 77 says that compensation or penalty under the Act does not stop punishment under any other law. So a fraudster can pay compensation under section 43 and still be prosecuted under other laws. Your answers should always name the section, apply the facts, and then conclude.

Key rules to remember

Section 43 – compensation for damage
Act without permission of owner/person in charge + listed act (access, download, virus, damage, disruption, denial of access, etc.) ⇒ liable to pay damages by way of compensation
Civil liability. Permission is the key condition. The Act has no fixed ceiling in the text supplied.
Section 43A – failure to protect data
Body corporate + sensitive personal data in computer resource it owns/controls/operates + negligent in reasonable security practices + wrongful loss or gain ⇒ compensation
All four elements must be present. Negligence is the trigger, not intent.
Section 66C – identity theft
Fraudulent or dishonest use of another person's electronic signature, password or other unique identification feature ⇒ imprisonment up to 3 years and fine up to ₹1,00,000
Imprisonment of either description. The fine is 'may extend to', so it is a maximum.
Section 66F – cyber terrorism
Clause (A): intent to threaten the unity, integrity, security or sovereignty of India, or to strike terror + a listed act (denying access to an authorised person, unauthorised penetration or access, or introducing a computer contaminant) + the conduct causes or is likely to cause death or injury, damage to or destruction of property, disruption of supplies or services essential to the life of the community, or harm to critical information infrastructure. Clause (B): knowing or intentional unauthorised access that obtains restricted information (State security or foreign relations) with reason to believe it may be used to cause injury to the interests listed in the section. Either clause ⇒ imprisonment which may extend to life
Intent alone is not enough under clause (A). The harmful result, or the likelihood of it, must also be present. Conspiracy to commit cyber terrorism is also punishable.
Section 72A – disclosure in breach of lawful contract
Person (including intermediary) with access to personal information under a lawful contract + intent or knowledge of likely wrongful loss or gain + disclosure without consent or in breach of contract ⇒ penalty up to ₹25,00,000
The section as supplied provides a penalty up to twenty-five lakh rupees.
Section 69B – monitoring of traffic data
Central Government authorises an agency to monitor and collect traffic data for cyber security; the intermediary or person in charge of the computer resource must give technical assistance under s.69B(2); an intermediary who intentionally or knowingly contravenes s.69B(2) ⇒ imprisonment up to 1 year or fine up to ₹1 crore, or both (s.69B(4))
The duty to assist under sub-section (2) is on the intermediary or person in charge of the computer resource. The punishment in sub-section (4) is on the intermediary only. It does not apply to the ordinary customer.
Section 77 – other laws not barred
Compensation, penalty or confiscation under the IT Act ⇏ bar on other penalty or punishment under any other law
Use it to say that civil and criminal action can run together.

How to solve Cyber Offences, Penalties and Data Protection in Banking questions

Use the same route for every case-based question: provision, facts, conclusion.

  1. 1Read the facts and list what was done: who accessed or took what, with or without permission, and from which system.
  2. 2Decide the track: civil compensation (sections 43, 43A), or penal (66C, 66F, 72A, 69B).
  3. 3Pick the section whose elements match. For example, use of another's password points to 66C, and a bank's weak security leading to a leak points to 43A.
  4. 4State the section's conditions in plain words, then tick each one against the facts.
  5. 5Name the consequence: compensation, imprisonment, fine or penalty, with the limit given in the section.
  6. 6Add section 77 if the facts suggest both compensation and another prosecution.
  7. 7Give practical points for the bank: security practices, incident reporting, cooperation with authorised agencies, record keeping.
  8. 8Close with a one-line conclusion that answers the question asked.

Quickest way: Match the act to the section in 60 seconds

When to use it: Use it when time is short and the question asks which section applies or what the liability is.

  1. Ask first: was it the bank's negligence in protecting data? If yes, think 43A.
  2. Ask: did a person act without permission on a system or data? If yes, think 43.
  3. Ask: was someone's password or e-signature used dishonestly? If yes, 66C.
  4. Ask: was there intent to threaten national security or strike terror? If yes, 66F.
  5. Ask: did someone with contractual access disclose personal information without consent? If yes, 72A.
  6. Write the consequence and add section 77 in one line.

Common mistakes in Cyber Offences, Penalties and Data Protection in Banking

  • Applying section 43A to an individual hacker.

    Students link all data breach cases to 43A.

    Fix: 43A applies to a body corporate that was negligent in security. A hacker acting without permission is dealt with under section 43.

  • Saying section 43 gives imprisonment.

    The word 'offence' is used loosely for all cyber acts.

    Fix: Section 43 provides compensation only. Imprisonment comes from penal sections such as 66C.

  • Quoting the wrong punishment for 66C.

    Numbers are mixed up with other sections.

    Fix: Remember: up to 3 years imprisonment and fine up to ₹1,00,000.

  • Ignoring the word 'sensitive' in 43A.

    Students treat any data as covered.

    Fix: The section covers sensitive personal data or information, as prescribed by the Central Government. State this condition.

  • Forgetting section 77.

    Students stop once compensation is awarded.

    Fix: Add that compensation under the Act does not prevent punishment under any other law.

  • Treating 72A as imprisonment.

    Older notes describe it as a punishment section.

    Fix: As amended, it provides a penalty up to ₹25,00,000. Use the current wording.

Worked examples

Example 1

Suraksha Bank Ltd stores customer Aadhaar and account details on its own servers but does not maintain reasonable security practices. A leak results in money being drawn from Ramesh's account. What is the bank's liability under the IT Act, 2000?

Show the solution
  1. Provision: section 43A makes a body corporate liable to compensation where it handles sensitive personal data in a computer resource it owns, controls or operates.
  2. Condition 1: Suraksha Bank is a company, so it is a body corporate.
  3. Condition 2: the data is sensitive personal data held on its own servers.
  4. Condition 3: it was negligent in implementing and maintaining reasonable security practices.
  5. Condition 4: the leak caused wrongful loss to Ramesh, since money was drawn from his account.
  6. Section 77 adds that this compensation does not prevent other punishment under any other law.

Answer: Suraksha Bank Ltd is liable under section 43A to pay damages by way of compensation to Ramesh, because all the conditions are met. Other legal action under other laws is not barred by section 77.

Example 2

Meera, a bank employee, uses a colleague Anil's password without his knowledge to approve a transaction and shifts ₹5,00,000 to a friend's account. Which IT Act provisions apply and what is the maximum penal consequence?

Show the solution
  1. Her act is the dishonest use of another person's password, which fits section 66C.
  2. Section 66C punishes with imprisonment of either description up to three years and also a fine which may extend to ₹1,00,000.
  3. Section 43 may also apply, but only if her access to or use of the system was without the permission of the owner or person in charge. This must be checked against the facts. If it applies, the affected person can claim compensation.
  4. Section 77 allows compensation and punishment to run together, and other laws can also apply.
  5. Practical point: the bank should preserve logs and report the matter to the authorities.

Answer: Section 66C applies. The maximum penal consequence under the IT Act is imprisonment up to 3 years and fine up to ₹1,00,000. Section 43 may also apply if the access was unauthorised, and section 77 allows other punishment under other laws as well.

Exam tips

  • Write the section number, then its conditions, then tick them against the facts. Markers look for this order.
  • Learn the three numbers: 66C (3 years, ₹1,00,000), 69B(4) (intermediary: up to 1 year or fine up to ₹1 crore, or both), 72A (₹25,00,000 penalty).
  • Separate compensation (43, 43A) from punishment (66C, 66F). Say which track you use.
  • In case questions, add one or two practical compliance points for the bank, such as security practices and cooperation with authorised agencies.
  • Use the current amended wording for 69B and 72A.

Practice questions from Digital Banking

Cyber Offences, Penalties and Data Protection in Banking in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Offences, Penalties and Data Protection in Banking: frequently asked questions

What is the difference between section 43 and section 43A?

Section 43 covers any person who does listed acts such as unauthorised access or data copying without permission. Section 43A covers a body corporate that is negligent in protecting sensitive personal data. Both lead to compensation.

Does section 66C apply to online banking fraud?

Yes, where someone fraudulently or dishonestly uses another person's password, electronic signature or other unique identification feature. The punishment is imprisonment up to three years and fine up to ₹1,00,000.

Can a bank be punished for a data breach?

A bank that is a body corporate can be made to pay compensation under section 43A if it was negligent in security practices and caused wrongful loss or gain. Section 77 keeps other laws open.

What does section 72A deal with?

It deals with disclosure of personal information, without consent or in breach of a lawful contract, by a person who got access while providing services under that contract. The disclosure must be with intent or knowledge of likely wrongful loss or gain. The penalty may extend to ₹25,00,000.