The Information Technology Act, 2000. When was it last amended? This question, whether I ask the enlightened or the novice, I get the same answer, i.e., in 2008. This unawareness exists, because today’s world remains updated from the search engines or ChatGPT, which in turn rely on websites and blogs, which are often authored by IT professionals or the Cyber Law Diploma holders. The takeaway is that India needs specialist lawyers, or at least individuals should rely on articles written by specialist lawyers. Now to answer the question, when the IT Act was majorly amended, it was amended twice, on 11th August 2023 by The Jan Vishwas (Amendment of Provisions) Act, 2023 and by The Digital Personal Data Protection Act, 2023 (DPDPA). While the Jan Vishwas Act amended 11 sections, the DPDPA 2023 amended 3 sections of the IT Act. Recently, Ministry of Electronics and Information Technology (MeitY) has notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025 on 22nd October 2025, thereby amending Rule 3(1)(d) of IT Rules 2021. The amended Rule comes into effect from 15th November 2025 marking October 22, 2025 as the last amendment to The IT Act, 2000.
It has been 25 years since the IT Act came into force on 17th October 2000 by notification from MeitY. This makes it a silver jubilee for one of the foundational laws in the cyber legal framework in India. It has been a quarter-century of evolution, struggle, tweaks, court battles, reform attempts, and we are yet to complete the adoption of the Model UNCITRAL Model Law. It gave legal recognition to electronic records and digital signatures, enabled e-governance, created basic cyber offences and paved a way towards the admissibility of electronic evidence. While the framework is provided by the legislation; over 25 years, much has been shaped in practice by courts, subordinate legislation (IT Rules), and the demands of society & technology. It was our first legislative handshake with cyberspace, it was ambitious, necessary, and some say ahead of its time.
When the Parliament passed the IT Act, India stood at the threshold of the digital century, a nation cautiously stepping from paper to pixels. It was a law born in the flicker of cathode-ray screens and dial-up modems, meant to legitimise e-commerce and e-mail, and not to govern deepfakes, AI-driven fraud, or algorithmic manipulation. Yet, this slender statute became the nervous system of India’s digital governance. For twenty-five years, it has silently authenticated our signatures, secured our Aadhaar databases, and guided courts through the labyrinth of cybercrime. However, as we celebrate this silver jubilee, a truth stares at us in the face: the law that once led the future is now struggling to catch up with it. The IT Act has survived hacking sprees, ransomware epidemics, and the social media explosion, but it now faces its most formidable challenge: the age of Autonomous Intelligence (AI) where machines no longer just obey, they decide.
Let me share a little memoir; the President gave assent to the IT Act on June 9, 2000, and it officially came into force only on October 17, 2000 but in that four-month gap, the police had already registered cyber offences under this Act, across the country, only to later discover that the law was not yet operational, rendering those FIRs legally void! Why did this happen? Because, as every law student, police and the IPS officers, were taught, “Once the President gives assent, a Bill becomes a Law.” That is a half-truth in the age of delegated legislation. Modern laws, especially in the tech domain, do not spring to life upon assent; they need to be notified by the respective ministry to become operational. The IT Act’s early enforcement fiasco was a masterclass in the difference between assent and notification, and a reminder that in cyber law, even time matters in binary.
Major amendment after multiple demands and requests came into force on October 27, 2009 by the IT (Amendment) Act, 2008. This Amendment expanded the domain of offences (identity theft, cyber-terrorism, privacy invasion via images), created new investigative powers (interception/decryption), strengthened intermediaries’ treatment, and formalised some institutional pieces (CERT-In role under the Act). Some provisions later proved controversial (e.g., Section 66A was added in this amendment). The Amendment responded to phishing, spam, malware, cyber-terrorism risks, and the rise of social media/online messaging, but it was drafted before smartphones/AI became a commonhold.
Inclusion of Section 66A brought in the hurricane, which stopped with Shreya Singhal v. Union of India. On March 24, 2015 the Hon’ble Supreme Court struck down Section 66A as unconstitutional, marking a defining moment for digital free speech in India. Here again, my memory plays in, where I must have advised police, public prosecutors and judges, not to consider Section 66A in filing of FIR, framing of charges and even when pronouncing a judgement. I found myself in many places, either arguing against the court orders or critiquing the application of Section 66A in the media till 2022. The Hon’ble Supreme Court on August 02, 2021 had issued notices to all states, Union Territories and Registrars General of High Courts; the Government yet had to actually bring in a Section in the Jan Vishwas Act, 2023 which formally repealed this section. This entails that Hon’ble Supreme Court already declaring the section unconstitutional in 2015 did not legally suffice and hence, section 66A resulted in having its own journey of fourteen years.
Intermediary rules under the IT Act have their own journey, from 2011 to 2023, evolving into stringent Intermediary Guidelines & Digital Media Ethics Code, 2021. Intermediary Guidelines in 2011 started to set due diligence expectations for platforms; these evolved substantially into the 2021 Intermediary Guidelines & Digital Media Ethics Code, which imposed stronger obligations (traceability, grievance officers, takedowns, compliance timelines). These guidelines as amended on April 06, 2023 have added a provision of a ‘Fact-Check Units’ (FCUs) to identify fake or false or misleading online content related to the government. On September 20, 2024 the Bombay High Court struck down the Rule 3 of Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2023, which empowered the Central government to form FCUs for identifying false or fake news against the government on social media and online platforms [Kunal Kamra v. Union of India & Ors and connected petitions].
“PROTECTED SYSTEMS” UNDER SECTION 70 (AND RELATED SECTION 70A) OF THE IT ACT
As of now, India has formally declared at least ten systems as “Protected Systems” under Section 70 of the IT Act, marking them as part of the nation’s Critical Information Infrastructure (CII). The first such notification came for the Terrestrial Trunked Radio (TETRA) secured communication network of the Government of NCT of Delhi, followed by major entities such as the UIDAI’s Central Identities Data Repository (Aadhaar CIDR); core banking and payment resources of ICICI Bank, HDFC Bank, Bank of Baroda, Union Bank of India, Punjab National Bank, and Kotak Mahindra Bank; the National Payments Corporation of India (NPCI) including UPI infrastructure; and the Census and National Population Register (NPR) systems operated by the Office of the Registrar General & Census Commissioner. These notifications, published through various Gazette orders between 2010 and 2023, reflect the government’s expanding recognition. Section 70A established NCIIPC as the nodal agency for CII protection.
Section 70B of the Information Technology Act, 2000 expressly designates the Indian Computer Emergency Response Team (CERT-In) as the national nodal agency for cyber-incident response, empowering it to collect, analyse and disseminate information on cyber incidents, issue forecasts and alerts, take emergency measures, and prescribe the manner in which these functions are to be performed. Pursuant to the enabling provisions, the Central Government notified the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013 (G.S.R. 20(E), dated 16 Jan 2014), which set out CERT-In’s operational mandate and procedures.
More recently, exercising powers under sub-section (6) of Section 70B, CERT-In has issued a series of directions and operational notifications to the constituency (notably the April 28, 2022 “Cyber Security Directions” and accompanying FAQs) that impose reporting obligations, log-keeping and certain security practices on service providers, intermediaries, data centres and other entities to improve incident response and forensics; those directions have been the subject of subsequent clarifications and industry FAQs. It mandated reporting of defined cyber incidents within six hours of detection among the fastest response windows in the world.
In short, CERT-In’s statutory authority rests on Section 70B, is operationalised by the 2013 Rules, and has been substantially augmented in practice through targeted directions and notifications (particularly since 2022) aimed at tightening incident reporting, evidence preservation and national cyber resilience.
Since the enactment of the IT Act, 2000, India has witnessed a significant surge in cybercrime incidents, reflecting both the proliferation of digital platforms and the challenges in enforcement. According to the National Crime Records Bureau (NCRB), the number of cybercrime cases escalated from 52,974 in 2021 to 86,420 in 2023, marking a 63% increase over two years. Notably, fraud accounted for approximately 69% of these cases, followed by sexual exploitation (4.9%) and extortion (3.8%). However, the conviction rate remains alarmingly low. In 2021, only 490 convictions were recorded out of 52,430 cybercrime cases, resulting in a mere 0.93% conviction rate. This figure slightly improved to 1.7% in 2022, with 1,107 convictions out of 64,907 cases. The NCRB’s 2023 report indicates that the national rate of cybercrime rose to 6.2 cases per lakh population, up from 4.8 the previous year, underscoring the urgent need for enhanced cyber law enforcement and judicial reforms.
What failed in the IT Act, 2000 experiment? Yes – failed! The supposed star of the Act, the Adjudicating Officer (AO) appointed under Section 46, turned out to be a non-starter. After twenty-five years, nearly half the states in India still do not have an AO, and in many others, the AO exists only on paper. I have personally handled and secured landmark decisions from these experimental cyber courts cases, like Sanjay Dhande v. ICICI Bank & Vodafone, Rohit Maheshwari v. Vodafone, and the recent Dhule Janata Sahakari Bank v. Axis Bank. Ironically, their appellate body, the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), functions far more efficiently than most AOs ever did. The grim reality is that some AO offices have not even taken up cases filed four years ago!
I recall, during my one-on-one consultation with the then IT Minister on the DPDPA, 2023, I was adamant that the provision for AOs should be removed altogether. The system has failed, and there is no sense in repeating a broken model. My recommendation was clear: take adjudication online, much like the Grievance Appellate Committee (GAC) mechanism under the IT Rules, 2021, which was conceptualised on my advice. In hindsight, I consider this one of my most impactful contributions: advocating for Online Dispute Resolution (ODR) mechanisms under the IT legal framework. Because, let us face it, the AO experiment was a noble idea, but a failed one.
In the twenty-five years since the Information Technology Act, 2000 came into force, India has built an expansive cyber legal and enforcement framework, yet cybercrime awareness among citizens has not reached its full potential. One of the core reasons lies in the country’s linguistic diversity and the historic lack of vernacular outreach. For most of these years, cyber safety campaigns, CERT-In advisories, and police awareness drives have been disseminated primarily in English or Hindi, leaving vast segments of rural and semi-urban India, where internet adoption exploded through cheap smartphones and regional-language apps, largely uninformed about basic digital hygiene. While institutions like the Indian Cyber Crime Coordination Centre (I4C) and NCRB’s CyTrain platform have made strides in capacity building for police and educators, mass citizen awareness has lagged behind, particularly in non-metro areas where digital literacy is functional but cyber risk comprehension is minimal. Bridging this gap requires localised cyber education in every Indian language, school curricula integration, and state-level community campaigns. Until cybersecurity awareness speaks the language of the people, cybercrime will continue to outpace consciousness.
WHAT REMAINS TO BE ACHIEVED?
When the IT Act, 2000, was enacted, technologies like Artificial Intelligence, the Internet of Things, blockchain, algorithmic decision-making, social media manipulation, and deepfakes were merely science fiction. Two and a half decades later, they are shaping economies, influencing elections, and even determining justice, yet our legal frameworks still chase their shadows. Many of these emerging technologies continue to operate in regulatory grey zones, where ethical dilemmas outpace statutory clarity.
India’s cyber law still grapples with cross-border data transfers, jurisdiction over cloud storage, foreign intermediaries, and the prosecution of extra-territorial cybercrime. The IT Act provides a legal skeleton, but the muscle of implementation and the lifeblood of international cooperation remain underdeveloped. Cybercrime today is borderless; the law, however, remains territorially bound. Equally concerning is the imbalance between state power and citizen rights. When the State exercises powers of blocking, content takedown, interception, or surveillance, there must be procedural transparency, judicial remedy, and independent oversight. Unfortunately, these safeguards are still inconsistently applied, eroding both trust and accountability.
After 25 years, the IT Act stands as a remarkable foundation, but it was designed for the dial-up era, not the AI-first century. India now needs an “IT Act 2.0”, the Digital India Act in the waiting, one that integrates privacy, AI governance, and digital sovereignty into its DNA. The next chapter of our cyber jurisprudence must not just regulate technology; it must anticipate it.
This blog is written by Advocate (Dr.) Prashant Mali, Cyber Law Expert, Legal Counsel, Bombay High Court