India's Largest HR Virtual Summit
23rd July, 2026 Register for FREE
Acts /
Information Technology Act 2000

Information Technology Act, 2000

The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a significant turning point for privacy regulation in India. For HR professionals, this legislation redefines how employee and candidate data must be handled, stored, and protected.

Whether you’re overseeing payroll, onboarding, background checks, or HRMS systems, the DPDP Act impacts your workflows. This guide walks you through everything HR needs to know to comply confidently and proactively.

Overview 

The Information Technology Act, 2000 (often abbreviated as the IT Act) is India’s first digital-age law. It provides legal recognition for electronic transactions, establishes standards for cybersecurity, and sets up mechanisms to tackle cybercrime.

This Act ensures businesses and individuals can operate securely in India’s expanding digital economy. And yes—that includes everything from employee databases and payroll systems to WhatsApp policies and biometric attendance tools.

Enactment Year

  • Introduced: May 9, 2000
  • Came into effect: October 17, 2000
  • Latest major update: Information Technology (Amendment) Act, 2008

Purpose

The core mission of the IT Act is to:

  • Provide legal validity to electronic records and digital signatures
  • Protect against data breaches, hacking, and cybercrimes
  • Support e-governance and digital communication
  • Set the tone for privacy, surveillance, and corporate liability

It aligns India’s digital laws with global standards, giving businesses a clear framework to follow—and penalties if they don’t.

Applicability

The IT Act has pan-India jurisdiction and applies to any person or organization that:

  • Sends, receives, or stores digital data
  • Operates websites, apps, or online platforms
  • Handles sensitive personal data (e.g., employee health info)
  • Uses electronic records or digital signatures

It also applies extraterritorially—if a foreign company commits a cybercrime affecting India, it can still be prosecuted under this law.

Key Provisions & Major Sections

Let’s break down the sections that actually matter for your day-to-day work.

Sections 4 & 5: Legal Recognition for Electronic Records and Signatures

This gives your PDFs, scanned documents, and e-contracts the same weight as paper documents, provided they’re authenticated using a recognized digital signature.

Section 43: Unauthorized Access and Data Theft

If someone hacks into a computer system, introduces malware, or damages data, they can be held civilly liable for the damages. HR teams using shared servers or cloud-based tools need strong access controls to stay compliant.

Section 43A: Data Security & Corporate Responsibility

This section is a must-know for HR and compliance folks. It holds body corporates liable for failing to implement “reasonable security practices” for sensitive personal data. The good news? If you follow standards like ISO 27001, you’re in the clear.

Section 66: Hacking with Criminal Intent

This is the criminal twin of Section 43. If someone causes damage with malicious intent, it’s not just a fine—it’s jail time (up to 3 years).

Section 69: Government Monitoring Powers

Allows government agencies to intercept or decrypt information for security reasons. It puts the onus on employers to maintain records and protocols in case of compliance checks.

Section 70: Protected Systems

Systems critical to national infrastructure (like banking, power, or telecom) can be declared “protected.” Unauthorized access? Up to 10 years in prison.

Section 72A: Disclosure Without Consent

Anyone disclosing personal data without consent—including HR vendors and staff—can face criminal penalties. Always get documented consent.

Section 79: Intermediary Liability (Safe Harbor)

If you’re a platform or SaaS provider, this section gives you legal protection against user-generated content—as long as you act on complaints promptly and follow due diligence.

HR Implications: Critical Compliance Checklist

  • Employee Data Handling: Ensure all sensitive personal data (e.g., salary, PAN, health data) is stored securely
  • Digital Signatures: Use approved digital signatures for offer letters, contracts, and compliance forms
  • Consent Management: Collect written consent for data collection and explain usage clearly
  • Third-Party Vendors: Include data protection clauses in HRMS, payroll, and background verification vendor contracts
  • Security Breach Protocols: Establish breach response plans in coordination with IT
  • Employee Training: Run regular sessions on phishing, password hygiene, and device security

Rules Under This Act

The IT Act is supported by several rules that put theory into practice.

Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011

These rules define:

  • What counts as sensitive personal data (like biometric info or bank details)
  • The need for privacy policies and user consent
  • Mandatory appointment of a grievance officer
  • Implementation of ISO 27001 or equivalent standards

Intermediary Guidelines and Digital Media Ethics Code, 2021

Applicable if you operate a digital platform, these rules lay down:

  • Due diligence requirements for content
  • User privacy safeguards
  • Grievance redressal mechanisms

State-Specific Rules

Note: The IT Act, 2000 is a Central law. There are no state-specific versions or rules. Its provisions apply uniformly across all states and union territories, including Jammu & Kashmir.

Forms and Returns

Documentation Corner

Form/Document Purpose Rule/Section
Privacy Policy Document Disclose data collection and sharing practices IT Rules, 2011 – Rule 4
Consent Forms Capture user/employee permission to process sensitive data IT Rules, 2011 – Rule 5
Digital Signature Certificate Authenticate documents electronically Section 5
Data Breach Report Template Incident report for data leaks Section 43A
Vendor Agreement Checklist Ensure third parties comply with data rules Section 72A
Grievance Redressal Log Document user complaints & resolutions Rule 5(9)

Penalties for Non-Compliance

The IT Act comes with real teeth. Violations can result in both financial and criminal penalties.

Financial Penalties

  • Unauthorized Access (Section 43): No cap—courts decide based on damages
  • Negligence in Data Security (Section 43A): Compensation to victims
  • Other Contraventions (Section 45): Fines up to Rs. 25,000

Criminal Offenses

  • Hacking (Section 66): Up to 3 years + Rs. 5 lakh fine
  • Tampering with Source Code (Section 65): 3 years + Rs. 2 lakh
  • Illegal Disclosure (Section 72A): 3 years + Rs. 5 lakh
  • Accessing Protected Systems (Section 70): Up to 10 years

Corporate Accountability (Section 85)

If your company messes up, the directors and officers are personally liable—unless they can prove they exercised due diligence.

Quick Prevention Strategies

  • Secure Employee Data
    → Encrypt personal/salary/health records. Limit access.
  • Get Consent
    → Written permission before collecting sensitive data (Aadhaar, biometrics, etc.).
  • Vendor Caution
    → Use contracts with clear data protection clauses. Audit them.
  • Use Valid Digital Signatures
    → For contracts, offer letters—must be legally recognized.
  • Train Employees
    → Regular sessions on phishing, password safety, device use.
  • Have a Breach Plan
    → Assign a grievance officer. Be ready to report incidents.
  • Review Annually
    → Audit HR+IT systems and update policies.

Recent Updates

Information Technology (Amendment) Act, 2008

  • Introduced Section 43A and Section 72A
  • Expanded definitions of cyber offenses
  • Enabled electronic signatures beyond digital ones

IT Rules, 2011

  • Defined sensitive personal data
  • Set out privacy policy and security standards

Intermediary Guidelines, 2021

  • New obligations for digital platforms
  • Tighter data retention and content takedown requirements

Section 66A Scrapped (2023 via Jan Vishwas Act)

  • Removed the controversial section after Shreya Singhal vs Union of India ruling

What’s Next?

Digital Personal Data Protection (DPDP) Act, 2023: Expected to supplement or replace key provisions of the IT Act. Stay tuned.

90-Day Compliance Implementation Plan

Phase 1: Foundation (Days 1-30)

Week 1-2: Assessment and Documentation

  • Audit employee access to IT systems and HRIS
  • Review existing data security and IT usage policies
  • Identify sensitive employee data being processed/stored
  • Check past incidents of data breaches or misuse

Week 3-4: Policy Development

  • Draft HR IT usage and cybersecurity policy
  • Create employee onboarding IT compliance checklist
  • Develop incident reporting and escalation process
  • Establish protocols for remote work data security

Phase 2: Implementation (Days 31-60)

Week 5-6: Team Training

  • Train employees on safe IT practices (phishing, passwords, data handling)
  • Educate HR staff on Section 43A and data protection obligations
  • Prepare reference guides on handling digital evidence in disputes
  • Define escalation procedures for cyber incidents

Week 7-8: System Setup

  • Implement multi-factor authentication and access control for HR data
  • Set up audit trails in HRIS and payroll software
  • Establish encryption protocols for sensitive employee records
  • Conduct vulnerability scans on HR-related systems

Phase 3: Optimization (Days 61-90)

Week 9-10: Relationship Building

  • Conduct awareness sessions with employees on data security rights and duties
  • Collaborate with IT/security teams for periodic checks
  • Create employee feedback loop on IT security practices
  • Build external consultant partnerships for cyber audits

Week 11-12: Continuous Improvement

  • Review IT access logs and user activity reports
  • Update HR and IT security policies quarterly
  • Evaluate employee awareness training effectiveness
  • Plan annual cybersecurity simulation drill

Monthly Ongoing Tasks

  • Monitor HR system access logs and suspicious activities
  • Track employee compliance with IT usage policies
  • Conduct monthly IT security check-ins with IT team
  • Review data breach preparedness status

Got questions?

Does this Act apply to HR teams using third-party payroll systems?

Yes. You must ensure the vendor uses adequate data protection measures and signs a contract with data confidentiality clauses.

What is considered "sensitive personal data"?

Includes passwords, financial info, health data, sexual orientation, biometrics, and any information given to provide a service.

Can employees refuse to provide data like Aadhaar or biometrics?

Yes, unless it is mandated by law. Consent must be voluntary and informed.

Are WhatsApp screenshots or emails legally valid?

Yes, if authenticated. Electronic evidence is admissible under the Indian Evidence Act (as amended).

How often should IT security practices be reviewed?

At least once a year or whenever systems, vendors, or data handling practices change.

We use cookies to ensure you get the best experience. Check our "cookie policy