The bank statement landed in the inbox at 11:32 AM. Two transactions the reader had not made — a transfer to an unknown account and a UPI debit she did not recognise. She thought back to where she had last logged in. The morning before, at a cyber cafe near the railway station, in a hurry, to download an admit card. She had logged in to her email to retrieve a forwarded copy of the form. She was sure she had logged out. She was sure. But the cafe terminal had a Chrome with a hundred saved sessions, the operator had been distracted, and the boy at the next computer had been watching the screen.
The other version of this story plays out in offices. An employee resigns on Friday, hands in his laptop, gets a polite send-off — and on Monday morning the IT team notices that someone has logged into the company drive from the same IP address he was using last week, and downloaded the master client list. Or the version that plays out in homes. A cousin who used the family computer to "check his email" came back twice when nobody was home, and now the household's saved logins are turning up in places they should not.
What This Article Will Answer
If you are reading this because somebody used a shared computer to get to your data, here are the questions that need clear answers:
- Is unauthorised access to a computer even an offence in India?
- Can I claim compensation for the loss caused?
- What if the offender used my login — does that change anything?
- What duties does a cyber cafe operator owe?
- What if it was an ex-employee or a current colleague?
- Where do I file — civil track, criminal track, or both?
- How do I prove that a particular person used a particular machine?
We will work through these in order, ground every answer in a section of the IT Act or a rule, and end with a clean ten-step checklist.
Two Typical Scenarios
Indian law treats unauthorised computer access along the same legal spine, regardless of the device — cyber cafe terminal, office workstation, school computer, or home laptop. What changes is the surrounding factual matrix. We focus on two scenarios because they cover the bulk of the cases lawyers see.
Scenario A — the cyber cafe. A cyber cafe is a physical space where access to the internet is offered to members of the public for a fee. Section 2(1)(na) of the amended IT Act, 2000 defines it as "any facility from where access to the internet is offered by any person in the ordinary course of business to the members of the public". Cyber cafes are intermediaries under Section 2(1)(w) of the IT Act, with specific compliance obligations under the Cyber Cafe Rules 2011, discussed below.
Scenario B — the office or workplace. Office workstations are owned by the employer. Employees access them under a contract that defines the scope of permitted use. Once that contract ends, or where the employee uses the access for a purpose outside the contract, the access becomes "without permission" within the meaning of Section 43 of the IT Act. Ex-employees who continue to use credentials are particularly common offenders — and they are particularly easy to prosecute because the trail is concentrated.
Section 43 — The Civil Compensation Route
Section 43 of the IT Act is the workhorse civil provision. The section, in substance, says that if any person without the permission of the owner of a computer, computer system or computer network does any of ten specified activities, he is liable to pay damages by way of compensation to the person so affected. The ten activities are exhaustive — every plausible misuse of a computer is listed.
The two most relevant clauses for our scenarios are:
Section 43(a) — accessing or securing access to a computer, computer system, computer network or computer resource without permission. This is the bare unauthorised-access ground. The moment the cafe operator allowed someone else into your active session, or the ex-employee logged in after his employment ended, Section 43(a) is attracted.
Section 43(b) — downloading, copying or extracting any data, computer database or information from such computer, computer system or computer network. The section explicitly covers downloading or copying from removable storage media too — pen drives, CDs, Zip drives. So if the offender pulled an Excel sheet, a PDF, a database extract, or a contact list onto his pen drive, Section 43(b) is attracted on top of 43(a).
Other Section 43 limbs catch related misuse: 43(c) for introducing a virus or computer contaminant; 43(d) for damaging data or programs; 43(g) for abetment by facilitating unauthorised access. The Section was deliberately drafted in broad terms to cover all possible scenarios of computer misuse.
Section 43 covers everybody — individual owner or large network company, small establishment or sole proprietor. There is no statutory cap on damages. As Section 46(1A) provides, the Adjudicating Officer's jurisdiction extends to claims up to Rs 5 crore; claims beyond that go to the competent civil court. Section 47 sets out the factors for quantification — the gain to the offender, the loss to the complainant, and the repetitive nature of the default.
Section 66 — When Access Becomes Criminal
Section 66 of the IT Act runs in parallel with Section 43. The amended Section 66 reads, in substance, that if any person, dishonestly or fraudulently, does any act referred to in Section 43, he commits an offence punishable with imprisonment up to three years or fine up to five lakh rupees, or both.
The transition from civil to criminal turns on two words — dishonestly or fraudulently. Both have established legal meanings. "Dishonestly" — defined in Section 24 of the IPC — means with the intention of causing wrongful gain to oneself or wrongful loss to another. "Fraudulently" — defined in Section 25 of the IPC — means with intent to defraud. So a casual snoop who looked at your email out of curiosity may attract civil compensation under Section 43 but not criminal liability under Section 66; the moment the snoop pulled the data with intent to misuse it, Section 66 is attracted on top.
The Supreme Court in Shreya Singhal v Union of India, AIR 2015 SC 1523 contrasted Section 66A — which it struck down — with Section 66, which it specifically endorsed as a narrowly drawn and constitutionally valid provision. So if the police officer suggests Section 66A, politely insist on Section 66 instead.
Sections 66C, 66D and 72A
Section 66C — identity theft. The section punishes any person who fraudulently or dishonestly makes use of the electronic signature, password, or any other unique identification feature of any other person. Punishment is up to three years and a fine up to one lakh. As the source commentary records, "in case a person comes to know about a password of another and then misuses it on the computers and communication devices of other person, such an act would also come within the ambit of section 66C". So when the boy at the next cyber cafe terminal used your saved Gmail to log in, Section 66C is squarely attracted.
Section 66D — cheating by personation using a computer resource. The section punishes any person who, by means of any communication device or computer resource, cheats by personation. Punishment is up to three years and a fine up to one lakh. The classic fact pattern — sending fraudulent emails from your account, using your bank login to transfer money, pretending to be you on social media to extract money from your contacts — is squarely covered. Section 66D is currently a bailable offence; the source commentary notes this as a deterrence gap.
Section 72A — disclosure in breach of contract. The section punishes any person — including an intermediary — who, while providing services under the terms of a lawful contract, secured access to material containing personal information about another person, and discloses that material without consent or in breach of the contract, with intent to cause or knowing that he is likely to cause wrongful loss or wrongful gain. Punishment is up to three years and a fine up to five lakh. Section 72A is the standard hammer for the ex-employee scenario, where the access was secured under the employment contract.
Cyber Cafe Rules 2011 Obligations
Cyber cafes are a regulated category. The Information Technology (Guidelines for Cyber Cafe) Rules, 2011 — issued under the IT Act — impose specific compliance duties on every cafe operator. The duties typically include:
- Identification of users. The operator must identify every user before granting access, by checking a government-issued photo identification — passport, voter ID, driving licence, Aadhaar, PAN — and recording the type and number.
- Maintenance of register. The operator must maintain a register, in physical or electronic form, recording the user's name, address, identification details, the time of arrival, time of departure, and the terminal used.
- Storage of logs. The operator must maintain log records of websites visited, online activity and IP addresses, typically for at least one year, and provide access to law-enforcement on a written request.
- Layout and CCTV. The cafe layout must allow for reasonable visibility of the screens; CCTV coverage of common areas is typically required.
- Disabling autosave. Most state-level cafe regulations also require the operator to disable browser-level password saving and to clear sessions after each user.
Where the cafe operator failed to comply with these rules, the cafe itself can be liable. Cyber cafes are intermediaries under Section 2(1)(w) of the IT Act, and Section 79 gives intermediaries a safe harbour from liability only as long as they observe due diligence. A non-compliant cafe has not exercised due diligence, and its safe harbour falls away. Section 43 of the IT Act would also lie against the cafe operator if the negligence facilitated the unauthorised access.
The Workplace Scenario
The workplace version of this matter is, in volume, far more common than the cyber cafe version. Three sub-scenarios recur:
One — the ex-employee who keeps logging in. The most common sub-scenario. The exit checklist was sloppy. The credentials were not revoked. The ex-employee uses VPN credentials, SSO tokens, or saved Office365 logins to come back. Here Section 43(a) is squarely attracted — the moment employment ended, his right to access ended. Section 43(b) for downloading and Section 43(d) for damaging follow. If he was dishonest, Section 66 makes it criminal. If he used a colleague's password, Section 66C applies. If he disclosed customer or employee data, Section 72A applies.
Two — the IT administrator who exceeded his role. An admin had legitimate access for system maintenance but used it to read personal emails or download confidential files. Here too, Section 43 is attracted — "without the permission of the owner" includes use beyond the consented scope. Section 72 of the IT Act, which punishes officials who disclose information secured under statutory powers, can also apply if the admin was a regulated person.
Three — the employer accessing personal data of an employee. The mirror image. An employer monitored an employee's personal Gmail or WhatsApp on the office machine, beyond the scope of the employment contract or the IT-use policy. Where the conduct exceeds the contract, Section 43 lies against the employer too — combined with the privacy reasoning of Justice K S Puttaswamy v Union of India. Section 43A and Section 72A also apply if the employer is a body corporate processing the employee's personal data. For a deeper look at privacy in personal data handling, the same provisions are the workhorse.
What Should I Actually Do Now?
If a cyber cafe terminal, office workstation or shared computer was used to misuse your data, here is the action sequence — in order:
- Map the terminal and the time. Identify the cafe or office machine, the date and the time slot. Take a photo of the terminal if it is a cafe.
- Reset every credential. Email, banking, social media, work systems. Enable two-factor authentication. Revoke saved sessions on all devices.
- Inform your bank if any financial data may have been compromised. Ask for a hold on suspect transactions and a credit-pull alert.
- Send a written notice to the cafe operator or the employer — under Section 43 of the IT Act and the Cyber Cafe Rules 2011 — demanding logs, identification of the offender, and confirmation of corrective steps.
- Save the logs. Cafe register entry, CCTV footage, system access logs, IP records, email "new sign-in" notifications, OTP records. Section 65B-compliant.
- File a cyber complaint at cybercrime.gov.in. Save the acknowledgment number.
- File an FIR at the cyber cell or the local police station under Sections 43 read with 66 of the IT Act, plus 66C and 66D for identity theft and personation, and 72A where the offender accessed under a contract.
- If the loss is significant, file a parallel claim before the Adjudicating Officer under Section 46 of the IT Act for compensation under Section 43.
- Tell HR or IT security if the misuse was workplace-related — they have parallel internal channels and may already have recorded the access.
- Talk to a lawyer. Identification of the offender is the make-or-break step in this category — strong investigation in week one decides everything that follows.
Talking to a Lawyer
This category of matter rewards quick action. Cafe registers get re-written, CCTV footage rolls over, and ex-employee credentials get auto-deactivated by IT — all of which can erase the evidence trail if not preserved in the first week. The civil compensation track and the criminal track each have their own paperwork. The Section 65B certificate has to be drafted carefully or the entire evidence basket can be ruled inadmissible at trial.
If you would prefer to have someone walk you through it, the team at Pinaka Legal handles cyber cafe and workplace data-misuse matters out of Delhi. The first conversation is confidential and free of cost; most of it is about preserving the evidence in the first forty-eight hours and choosing the right combination of forums to file.
Frequently Asked Questions
Someone used my login on a cyber cafe terminal — is that an offence?
Yes, on two fronts. Section 43 of the Information Technology Act, 2000 makes unauthorised access to a computer, computer system or computer network a civil wrong attracting compensation. Section 43(b) covers downloading or copying data without permission. Where the unauthorised access was dishonest or fraudulent, Section 66 makes it a criminal offence punishable with imprisonment up to three years and a fine up to five lakh rupees. The IT Act covers everybody — individual owner or large network — making the cyber cafe operator and the actual misuser both potentially liable.
What is the difference between cyber cafe or office computer misused my data legal options and a regular hacking case?
There is no real difference in the underlying sections. Indian law uses the same provisions — Section 43 for civil compensation and Section 66 for criminal liability — for unauthorised access whether the device is a cyber cafe terminal, an office workstation, or a private home computer. What changes is the procedural route. Cyber cafes are intermediaries under Section 2(1)(w) of the IT Act, so the cafe operator has additional record-keeping duties. Offices have employer-employee duties. Home break-ins are between individuals only.
What is identity theft under Section 66C?
Section 66C of the IT Act punishes any person who fraudulently or dishonestly makes use of the electronic signature, password, or any other unique identification feature of any other person. Punishment is imprisonment up to three years and a fine up to one lakh rupees. The section is drafted in broad terms — passwords used on computers and on communication devices are equally covered, as the source commentary records. So if a cyber cafe operator or an ex-colleague used your saved Gmail password to log in, Section 66C is squarely attracted.
What is Section 66D — cheating by personation?
Section 66D punishes any person who, by means of any communication device or computer resource, cheats by personation. The classic fact pattern is one person posing as another online — sending fraudulent emails from your account, using your bank login to transfer money, or pretending to be you on social media to extract money from your contacts. Punishment is imprisonment up to three years and a fine up to one lakh rupees. The offence is, however, currently bailable. Section 66D often runs together with Section 66C in identity-misuse cases.
What about Section 72 of the IT Act?
Section 72 punishes any person who, having secured access to electronic records or information in pursuance of any of the powers conferred by the IT Act, discloses that information without consent. Section 72 mainly catches officials, certifying authorities, regulators and government-appointed officers — and on facts, an IT-administrator at an office who accessed records under his statutory or contractual authority and then disclosed them. For most ex-employee misuse cases, Section 72A — discussed below — fits better, since it applies to anyone providing services under a contract.
My ex-employee is still accessing our office data — what can I do?
This is one of the most common workplace cyber matters in India. Section 43(a) of the IT Act covers unauthorised access — the moment the employment ended, his right to access ended. Section 43(b) covers downloading or copying data, and Section 43(d) covers damaging or causing damage to the data. Where the conduct was dishonest, Section 66 makes it a criminal offence. Section 66C for identity theft applies if he used a colleague's password. Section 72A covers disclosure of personal information secured under the contract of employment. File the FIR at the cyber cell and the Section 43 compensation claim before the Adjudicating Officer in parallel.
Are cyber cafe operators required to maintain records of users?
Yes. The Information Technology (Guidelines for Cyber Cafe) Rules, 2011 — issued under the IT Act — require every cyber cafe operator to identify each user before allowing access, by checking a government-issued photo ID, and to maintain a register with the user's name, photo, address, ID type and the time of use. The cyber cafe is also required to maintain log records of websites visited and online activity, typically for at least one year, and to keep the IDs for inspection. So the cafe operator should be able to identify the person who used the terminal at a particular time.
Cyber complaint or FIR — which one should I file first?
File both. The cyber complaint at cybercrime.gov.in is the fastest channel — it accepts file uploads and routes the matter to the relevant cyber cell. The FIR at the police station under BNSS Section 173 (which has replaced CrPC Section 154) is the formal step that triggers a criminal investigation. Where the unauthorised access has caused immediate financial loss, walk into the police station first. The compensation claim under Section 43 of the IT Act is filed separately before the Adjudicating Officer under Section 46 — that is the civil track, distinct from the criminal track.
How much compensation can I get under Section 43?
There is no statutory cap. The Adjudicating Officer's jurisdiction is limited to claims up to Rs 5 crore under Section 46(1A) of the IT Act. Where the claim exceeds Rs 5 crore, jurisdiction vests in the competent civil court. Section 47 of the IT Act sets out the factors the officer must consider — the amount of gain or unfair advantage made by the offender, the amount of loss caused, and the repetitive nature of the default. Civil courts in India have historically been hesitant to grant large damages, but adjudication under the IT Act is more focused and quantification-driven.
What evidence do I need to prove unauthorised access?
Documents that show three things — that the person had no permission, that the access actually happened, and that you suffered loss. Save the office login policy, the employment contract, the cyber cafe register entry, the log file showing the access, the email from the bank or the OTP received during the unauthorised transaction, and any subsequent fraudulent transactions. Section 65B of the Indian Evidence Act, as confirmed by the Supreme Court in Anvar P V v P K Basheer (2015), requires a certificate alongside the electronic record. The cafe operator and the IT administrator can be summoned as witnesses.
Can my company sue a cyber cafe operator for negligence?
Yes, on two grounds. The cyber cafe is an intermediary under Section 2(1)(w) of the IT Act, and Section 79 gives intermediaries a safe harbour only if they observe due diligence. A cafe that fails to verify ID, maintain logs, or comply with the Cyber Cafe Rules 2011 has not exercised due diligence. Section 43 of the IT Act would also lie against the cafe if its negligence facilitated the unauthorised access. The complainant has to prove the failure of the cafe operator to comply with mandatory rules — not merely allege harm.
How long does a cyber cafe data-misuse case usually take?
It depends on identification of the user. Where the cyber cafe register has the offender's photo and ID, investigation often closes within sixty to ninety days. Where the cafe failed to maintain the register, the matter takes longer because the police have to trace the user through CCTV, payment records and witness identification. Adjudication under Section 46 of the IT Act is summary in nature, with several states deciding cases within twelve to eighteen months of filing. Office-employee cases move faster because the offender is usually known.
Written by the Pinaka Legal Editorial Team. For queries, call +91 8595704798 or email info@pinakalegal.com. For more articles on Indian law, visit the Pinaka Legal Blog.