Offences by Companies - Sec.85

Section 85 of the IT Act makes corporate officers liable for cyber offences committed by their companies. Learn about the 'due diligence' defense and the risks of executive neglect.

May 21, 2012

Section 85 of the Information Technology Act 2000 is a statutory framework that establishes vicarious legal liability for corporate entities and their key managerial personnel when a cyber offence is committed by a company. The provision stipulates that every person in charge of and responsible to the company for the conduct of its business at the time of the violation shall be deemed guilty alongside the corporate entity. This statutory mechanism ensures that corporate bodies maintain rigorous cybersecurity compliance and governance standards.

Legal Structure and Principles of Corporate Vicarious Liability

Corporate bodies operate through human agents, board members, and executive officers. Under general criminal law, attributing criminal intent to an artificial legal entity presents complex jurisprudential challenges. Section 85 resolves this by creating a statutory presumption of guilt against individuals who manage or control corporate operations when the company violates provisions of the Information Technology Act.

Section 85 of the Information Technology Act 2000 is an authoritative compliance mandate for commercial enterprises operating in India. The statutory mandate applies to incorporated companies, partnership firms, associations of individuals, and commercial trusts. When a cyber offence such as unauthorized data collection, privacy breach, or infrastructure misuse occurs within a company, statutory liability extends simultaneously to the legal entity itself and to responsible executive directors, managing partners, and designated security officers.

Designation of Responsible Officers and Board Accountability

To establish corporate vicarious liability, courts examine the operational hierarchy and decision-making authority within the organization. Corporate boards cannot insulate themselves from liability simply by delegating technical security duties to junior IT staff. Statutory accountability attaches to directors, company secretaries, chief technology officers, and managers who oversee operational policies and financial allocations for information security systems.

Proper corporate governance requires formal board-level designation of a Chief Information Security Officer (CISO) or compliance officer responsible for IT Act adherence. Documenting clear lines of administrative responsibility ensures that security policies are implemented enterprise-wide while establishing identifiable personnel accountable for regulatory compliance during legal reviews. Establishing formal incident reporting protocols within corporate bylaws ensures that key managerial personnel receive immediate notification of potential cyber security breaches. This proactive reporting structure facilitates timely regulatory disclosures and strengthens statutory defense arguments during judicial proceedings.

Statutory Defenses and Due Diligence Standards

Section 85 incorporates specific statutory exceptions that protect corporate officers who exercise proper oversight and due diligence:

  • Lack of Knowledge Defense: An officer is not liable if they prove that the cyber offence was committed without their knowledge or consent.
  • Due Diligence Compliance: Liability is negated if the officer demonstrates that they exercised all due diligence to prevent the commission of the offence.
  • Express Consent or Neglect: If an offence is proved to have occurred with the consent, connivance, or neglect of a director, manager, or secretary, that officer remains individually liable.
  • Technical Safeguard Verification: Maintaining documented ISO 27001 policies, regular security audits, and firewall logs serves as evidence of organizational due diligence.

Cross-References with Related IT Act Penalties

Corporate compliance evaluations under Section 85 frequently intersect with other penal sections of Indian cyber law. For instance, when investigating corporate liability during an uncompleted intrusion or system compromise, legal experts evaluate Section 85 alongside provisions governing attempted offences under Section 84C to determine organizational exposure.

Similarly, corporate liability inquiries examine whether company employees or third-party contractors aided or abetted cyber violations. Courts review corporate governance failures in conjunction with statutory penalties for abetment penalties under Section 84B to assign appropriate legal accountability across corporate management structures.

Information Security Management and Governance Systems

Demonstrating statutory due diligence under Section 85 requires commercial organizations to implement verifiable information security management systems. Enterprises must establish technical controls including data encryption at rest and in transit, multi-factor authentication, role-based access management, and continuous network vulnerability scanning. Adopting international standards such as ISO/IEC 27001 provides objective proof of organizational commitment to cyber security hygiene.

Furthermore, corporate bodies must conduct annual third-party cybersecurity audits and penetration testing to identify and remediate infrastructure vulnerabilities. Maintaining detailed audit trails, vulnerability remediation reports, and employee security awareness training logs provides essential documentary proof to establish the statutory due diligence defense if a cyber breach occurs. Documenting executive approval for security policies confirms administrative leadership involvement.

Statutory Text and Legally Verified Sources

Legal professionals, judicial officers, and corporate auditors examine statutory precedents directly from official legal records. Reviewing the legal text on the India Code IT Act Section 85 Record provides authoritative verification of corporate compliance obligations and judicial interpretation under Indian law.

Target PartyBasis of LiabilityStatutory Defense RequirementPenal Consequence
Corporate EntityDirect Corporate OffenceCompliance with Information Security StandardsMonetary Fine & License Cancellation
Managing Director / CEOOverall Business Conduct ResponsibilityProof of Lack of Knowledge or Due DiligenceStatutory Imprisonment & Fine
Designated Security OfficerOperational Oversight & CareMaintenance of Audit Logs & SafeguardsIndividual Legal Liability

Summary of Corporate Liability under Section 85

Section 85 enforces corporate accountability by attributing legal liability to companies and their managing personnel for cyber offences. By requiring active due diligence and information security management, Indian law ensures that commercial entities maintain active controls to safeguard digital operations.

Found this helpful?

Share this page with others