Information Technology Act, 2000
The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a significant turning point for privacy regulation in India. For HR professionals, this legislation redefines how employee and candidate data must be handled, stored, and protected.
Whether you’re overseeing payroll, onboarding, background checks, or HRMS systems, the DPDP Act impacts your workflows. This guide walks you through everything HR needs to know to comply confidently and proactively.
Overview
The Information Technology Act, 2000 (often abbreviated as the IT Act) is India’s first digital-age law. It provides legal recognition for electronic transactions, establishes standards for cybersecurity, and sets up mechanisms to tackle cybercrime.
This Act ensures businesses and individuals can operate securely in India’s expanding digital economy. And yes—that includes everything from employee databases and payroll systems to WhatsApp policies and biometric attendance tools.
Enactment Year
- Introduced: May 9, 2000
- Came into effect: October 17, 2000
- Latest major update: Information Technology (Amendment) Act, 2008
Purpose
The core mission of the IT Act is to:
- Provide legal validity to electronic records and digital signatures
- Protect against data breaches, hacking, and cybercrimes
- Support e-governance and digital communication
- Set the tone for privacy, surveillance, and corporate liability
It aligns India’s digital laws with global standards, giving businesses a clear framework to follow—and penalties if they don’t.
Applicability
The IT Act has pan-India jurisdiction and applies to any person or organization that:
- Sends, receives, or stores digital data
- Operates websites, apps, or online platforms
- Handles sensitive personal data (e.g., employee health info)
- Uses electronic records or digital signatures
It also applies extraterritorially—if a foreign company commits a cybercrime affecting India, it can still be prosecuted under this law.
Key Provisions & Major Sections
Let’s break down the sections that actually matter for your day-to-day work.
Sections 4 & 5: Legal Recognition for Electronic Records and Signatures
This gives your PDFs, scanned documents, and e-contracts the same weight as paper documents, provided they’re authenticated using a recognized digital signature.
Section 43: Unauthorized Access and Data Theft
If someone hacks into a computer system, introduces malware, or damages data, they can be held civilly liable for the damages. HR teams using shared servers or cloud-based tools need strong access controls to stay compliant.
Section 43A: Data Security & Corporate Responsibility
This section is a must-know for HR and compliance folks. It holds body corporates liable for failing to implement “reasonable security practices” for sensitive personal data. The good news? If you follow standards like ISO 27001, you’re in the clear.
Section 66: Hacking with Criminal Intent
This is the criminal twin of Section 43. If someone causes damage with malicious intent, it’s not just a fine—it’s jail time (up to 3 years).
Section 69: Government Monitoring Powers
Allows government agencies to intercept or decrypt information for security reasons. It puts the onus on employers to maintain records and protocols in case of compliance checks.
Section 70: Protected Systems
Systems critical to national infrastructure (like banking, power, or telecom) can be declared “protected.” Unauthorized access? Up to 10 years in prison.
Section 72A: Disclosure Without Consent
Anyone disclosing personal data without consent—including HR vendors and staff—can face criminal penalties. Always get documented consent.
Section 79: Intermediary Liability (Safe Harbor)
If you’re a platform or SaaS provider, this section gives you legal protection against user-generated content—as long as you act on complaints promptly and follow due diligence.
HR Implications: Critical Compliance Checklist
- Employee Data Handling: Ensure all sensitive personal data (e.g., salary, PAN, health data) is stored securely
- Digital Signatures: Use approved digital signatures for offer letters, contracts, and compliance forms
- Consent Management: Collect written consent for data collection and explain usage clearly
- Third-Party Vendors: Include data protection clauses in HRMS, payroll, and background verification vendor contracts
- Security Breach Protocols: Establish breach response plans in coordination with IT
- Employee Training: Run regular sessions on phishing, password hygiene, and device security
Rules Under This Act
The IT Act is supported by several rules that put theory into practice.
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
These rules define:
- What counts as sensitive personal data (like biometric info or bank details)
- The need for privacy policies and user consent
- Mandatory appointment of a grievance officer
- Implementation of ISO 27001 or equivalent standards
Intermediary Guidelines and Digital Media Ethics Code, 2021
Applicable if you operate a digital platform, these rules lay down:
- Due diligence requirements for content
- User privacy safeguards
- Grievance redressal mechanisms
State-Specific Rules
Note: The IT Act, 2000 is a Central law. There are no state-specific versions or rules. Its provisions apply uniformly across all states and union territories, including Jammu & Kashmir.
Forms and Returns
Documentation Corner
| Form/Document | Purpose | Rule/Section |
| Privacy Policy Document | Disclose data collection and sharing practices | IT Rules, 2011 – Rule 4 |
| Consent Forms | Capture user/employee permission to process sensitive data | IT Rules, 2011 – Rule 5 |
| Digital Signature Certificate | Authenticate documents electronically | Section 5 |
| Data Breach Report Template | Incident report for data leaks | Section 43A |
| Vendor Agreement Checklist | Ensure third parties comply with data rules | Section 72A |
| Grievance Redressal Log | Document user complaints & resolutions | Rule 5(9) |
Penalties for Non-Compliance
The IT Act comes with real teeth. Violations can result in both financial and criminal penalties.
Financial Penalties
- Unauthorized Access (Section 43): No cap—courts decide based on damages
- Negligence in Data Security (Section 43A): Compensation to victims
- Other Contraventions (Section 45): Fines up to Rs. 25,000
Criminal Offenses
- Hacking (Section 66): Up to 3 years + Rs. 5 lakh fine
- Tampering with Source Code (Section 65): 3 years + Rs. 2 lakh
- Illegal Disclosure (Section 72A): 3 years + Rs. 5 lakh
- Accessing Protected Systems (Section 70): Up to 10 years
Corporate Accountability (Section 85)
If your company messes up, the directors and officers are personally liable—unless they can prove they exercised due diligence.
Quick Prevention Strategies
- Secure Employee Data
→ Encrypt personal/salary/health records. Limit access.
- Get Consent
→ Written permission before collecting sensitive data (Aadhaar, biometrics, etc.).
- Vendor Caution
→ Use contracts with clear data protection clauses. Audit them.
- Use Valid Digital Signatures
→ For contracts, offer letters—must be legally recognized.
- Train Employees
→ Regular sessions on phishing, password safety, device use.
- Have a Breach Plan
→ Assign a grievance officer. Be ready to report incidents.
- Review Annually
→ Audit HR+IT systems and update policies.
Recent Updates
Information Technology (Amendment) Act, 2008
- Introduced Section 43A and Section 72A
- Expanded definitions of cyber offenses
- Enabled electronic signatures beyond digital ones
IT Rules, 2011
- Defined sensitive personal data
- Set out privacy policy and security standards
Intermediary Guidelines, 2021
- New obligations for digital platforms
- Tighter data retention and content takedown requirements
Section 66A Scrapped (2023 via Jan Vishwas Act)
- Removed the controversial section after Shreya Singhal vs Union of India ruling
What’s Next?
Digital Personal Data Protection (DPDP) Act, 2023: Expected to supplement or replace key provisions of the IT Act. Stay tuned.
90-Day Compliance Implementation Plan
Phase 1: Foundation (Days 1-30)
Week 1-2: Assessment and Documentation
- Audit employee access to IT systems and HRIS
- Review existing data security and IT usage policies
- Identify sensitive employee data being processed/stored
- Check past incidents of data breaches or misuse
Week 3-4: Policy Development
- Draft HR IT usage and cybersecurity policy
- Create employee onboarding IT compliance checklist
- Develop incident reporting and escalation process
- Establish protocols for remote work data security
Phase 2: Implementation (Days 31-60)
Week 5-6: Team Training
- Train employees on safe IT practices (phishing, passwords, data handling)
- Educate HR staff on Section 43A and data protection obligations
- Prepare reference guides on handling digital evidence in disputes
- Define escalation procedures for cyber incidents
Week 7-8: System Setup
- Implement multi-factor authentication and access control for HR data
- Set up audit trails in HRIS and payroll software
- Establish encryption protocols for sensitive employee records
- Conduct vulnerability scans on HR-related systems
Phase 3: Optimization (Days 61-90)
Week 9-10: Relationship Building
- Conduct awareness sessions with employees on data security rights and duties
- Collaborate with IT/security teams for periodic checks
- Create employee feedback loop on IT security practices
- Build external consultant partnerships for cyber audits
Week 11-12: Continuous Improvement
- Review IT access logs and user activity reports
- Update HR and IT security policies quarterly
- Evaluate employee awareness training effectiveness
- Plan annual cybersecurity simulation drill
Monthly Ongoing Tasks
- Monitor HR system access logs and suspicious activities
- Track employee compliance with IT usage policies
- Conduct monthly IT security check-ins with IT team
- Review data breach preparedness status
Got questions?
Yes. You must ensure the vendor uses adequate data protection measures and signs a contract with data confidentiality clauses.
Includes passwords, financial info, health data, sexual orientation, biometrics, and any information given to provide a service.
Yes, unless it is mandated by law. Consent must be voluntary and informed.
Yes, if authenticated. Electronic evidence is admissible under the Indian Evidence Act (as amended).
At least once a year or whenever systems, vendors, or data handling practices change.