IT Act, 2000 Explained: Key Sections, Digital Signatures and Worked Exam Examples

Build an exam-ready map of the IT Act, then apply it to an exact digital-signature walkthrough and a section 43, 66, 66C and 66D caselet.

KnowledgeGate Team

Exam prep & CS education

Updated 2 Oct 20266 min read

“IT Act, 2000” sounds like one date followed by a list of sections. Objective questions under exam pressure are harder: they test recognition of electronic records and signatures, classification of computer-related acts, and whether a provision is still current after amendments or court action. ICT for Teaching Exams: Fundamentals Explained provides the foundation for the record-integrity and incident-classification examples. These distinctions support exam preparation; they are not personal legal advice. All section references follow India Code's consolidated Information Technology Act, 2000.

1. What the IT Act, 2000 covers: a three-part map before section numbers

The current consolidated Information Technology Act, 2000 states a wider purpose than punishing cyber offences. The Act gives legal recognition to transactions carried out through electronic communication and facilitates electronic filing with government agencies.

Use this three-part memory map from its present arrangement:

  • Sections 3 to 16 cover electronic records, signatures and electronic governance.

  • Sections 17 to 42 cover Certifying Authorities, certificates and subscriber duties.

  • Section 43 onwards covers contraventions, offences, government powers and intermediary liability.

These ranges are a navigation aid, not a substitute for reading each provision. Teaching-recruitment papers may include ICT law, although individual exams need not share a syllabus or weightage. The Govt Teaching Job Exam Preparation category maps the wider exam family.

2. Six terms that stop most IT Act mix-ups

In the current statutory text, an electronic record includes data, a record, an image or sound stored, received or sent electronically. An originator generates, sends, stores or transmits an electronic message, but the definition excludes an intermediary. An intermediary receives, stores or transmits an electronic record for another person, or provides a related service.

A digital signature authenticates an electronic record through the section 3 method. An electronic signature is the broader defined category and includes a digital signature, so the terms are not automatic synonyms.

The subscriber is the person in whose name an electronic-signature certificate is issued. The subscriber's private key creates a digital signature, while the related public key verifies it. A licensed Certifying Authority issues the relevant certificate. Group the six terms by job: record, sender, relay, signature method, signature category and signer; place the Certifying Authority beside the signer as the certificate issuer.

3. Worked example: hash, private key and verification on one exact record

Take the exact UTF-8 record Application=TR-2048|Candidate=Asha|Score=72, with no spaces or trailing newline. Its SHA-256 digest is 3a83a6c43d2945d8f597f62bc49ee4a5e409d9734ca98f6ddc06e8980c7c199d. SHA-256 makes this integrity example reproducible; this does not mean the Act mandates that particular hash.

  1. Compute the record's hash.

  2. Use Asha's private key to create the digital signature over the record or its hash, following the section 3 concept.

  3. Send the record with the signature.

  4. Use the related public key to verify the signer linkage and that the record is unchanged.

Verification therefore tests two linked questions: was the matching private key used, and has the signed record changed?

A hash alone is not a digital signature. It can expose a changed record, but it does not authenticate the subscriber through the key pair.

Now change only Score=72 to Score=79. The digest becomes 232b9e2c3fc31dbb012a386626dace157e805ed0e38f24b8c168f9123f5f8891. It differs from the signed original, so verification of the altered record fails. Separately, current sections 4 and 5 address legal recognition of electronic records and electronic signatures. They do not make every electronic record secure, or every typed name a statutory digital signature.

Flow diagram of the SHA-256 digest, private-key signing and public-key verification, which fails once Score 72 becomes 79.

4. Electronic records in action: contract, attribution, acknowledgement and timing

An authorised recruitment portal sends candidate Asha an electronic training agreement at 10:05 IST; Asha accepts from her registered account at 10:12 IST; the portal issues an automated acknowledgement at 10:13 IST.

Section 10A means the contract is not unenforceable solely because proposal and acceptance used electronic form. Sections 11 to 13 cover attribution, acknowledgement, and the time and place of despatch and receipt. The facts do not prove validity; the reply does not establish every contractual requirement.

Fact

Concept to inspect

Why

10:05 send

Attribution and despatch

Identify sender and when the record left originator's control

10:12 registered-account acceptance

Attribution plus electronic contract

Link the response to Asha; inspect section 10A

10:13 automated reply

Acknowledgement

Apply the acknowledgement rule without treating it as proof

For “solely because it was electronic”, inspect section 10A before a cyber-offence section.

5. Worked incident classification: section 43, section 66, 66C and 66D

Ravi has no permission to enter a recruitment portal's administrator panel. At 14:20, he uses Asha's password, opens 200 candidate records and changes Asha's stored score from 72 to 79. At 14:28, he sends a message from a lookalike helpdesk account, pretends to be the portal administrator and asks Asha for a one-time code.

Classify the facts, not the person:

  • Unauthorised access and data alteration point first to acts listed in section 43.

  • Section 66 applies when an act referred to in section 43 is done dishonestly or fraudulently.

  • Fraudulent or dishonest use of another person's password points to section 66C.

  • Cheating by personation through a communication device or computer resource points to section 66D.

More than one provision can be relevant to one pattern. Section 43 and section 66 are not interchangeable, and classification is not a finding of guilt. Password use is one cue; the later impersonating message is another. The 200 records, 72 -> 79 change and timestamps trace the sequence, but do not create a section by themselves. Use the Teaching Recruitment (Computer Science) topic map to place this law-and-ICT case beside the broader subject areas.

Decision tree classifying Ravi's 14:20 unauthorised access and 14:28 impersonation against sections 43, 66, 66C and 66D.

6. High-risk traps: old notes, section 66A and safe-harbour shortcuts

Tempting statement

Why it fails

Exam-safe correction

“The 2000 bare text never changes.”

It ignores amendments and court action.

Use the current consolidated text; separate enactment from later changes.

“Section 66A is a current offence to quote from old notes.”

The present arrangement marks it omitted, and its note records the Supreme Court's 24 March 2015 striking-down order.

Do not treat section 66A as a live offence in a current-law question.

“Section 43 equals section 66.”

It erases a fact-sensitive statutory bridge.

Section 66 refers to acts in section 43 when done dishonestly or fraudulently.

“Section 79 gives every platform automatic immunity.”

The exemption is subject to conditions and exclusions in the current text.

Test the statutory conditions; do not assume automatic safe harbour.

Two further term traps matter. Electronic signature is broader than digital signature. Section 10A removes electronic form as the sole ground of unenforceability, but proves no other contract requirement.

7. How objective exams turn the Act into questions

Stable formats include matching a section to its subject, selecting definitions, evaluating statement pairs, classifying an incident, ordering an electronic-record sequence, and detecting an obsolete provision. Practice questions on the IT Act, 2000 apply these distinctions.

Test yourself before the key:

  1. Changing Score=72 to 79 changes the digest. Which property has been exposed?

  2. Ravi uses Asha's password. Which section cue is most direct?

  3. Ravi pretends through a computer resource to be an administrator in order to cheat. Which cue is most direct?

  4. An agreement uses electronic proposal and acceptance. Can electronic form alone make it unenforceable?

  5. Should section 66A be treated as a live offence in a current-law question?

Answer key: (1) Integrity; signer authentication additionally needs the key-pair and signature step. (2) Section 66C. (3) Section 66D. (4) No. Section 10A settles that narrow electronic-form point, not every validity question. (5) No. Current India Code marks it omitted and records the 2015 striking-down order.

8. IT Act, 2000: the short version and the next study step

  • Purpose: electronic transactions and e-governance beyond cyber offences.

  • Electronic record: data, record, image or sound handled electronically.

  • Electronic signature is broader than digital signature.

  • Section 43: specified computer-resource acts without permission.

  • Section 66: section 43 acts plus the dishonest or fraudulent element.

  • Section 66C cues password or identifier misuse; section 66D cues cheating by personation. Check India Code before trusting old notes.

DSSSB learners can use the DSSSB TGT CS 2026 Section B Course. Computer-instructor candidates can use the RSSB Basic Computer Instructor Course. Recreate the 72 -> 79 tree, then verify each section against India Code.