Sections 67C and 69B explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 67C of the Information Technology Act, 2000 makes an intermediary preserve and retain specified information in the manner the Central Government prescribes. Section 69B lets the Central Government authorise an agency to monitor and collect traffic data, and requires the intermediary to provide technical assistance. Both sections print a consequence for the intermediary, and both are amended by an item of the Jan Vishwas (Amendment of Provisions) Act, 2023. This article explains the sections as per the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008), then as amended; later amendments and the current position should be checked.
Under section 67C(1) an intermediary shall preserve and retain such information as may be specified for such duration, manner and format as the Central Government may prescribe. Section 69B(2) requires an intermediary or person in charge to give technical assistance to an authorised agency. As printed, section 67C(2) prints imprisonment up to three years and liability to fine and section 69B(4) prints imprisonment up to three years and liability to fine. As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023: section 67C(2) becomes liable to penalty which may extend to twenty-five lakh rupees, and section 69B(4) becomes one year or fine up to one crore rupees, or both.
Section 67C: preservation and retention
Section 67C is headed "Preservation and retention of information by intermediaries". Sub-section (1) reads: "Intermediary shall preserve and retain such information as may be specified for such duration and in such manner and format as the Central Government may prescribe." The Act leaves the information, the duration, the manner and the format to rules. This article states no form, period or step, because the Act prints none.
"Intermediary" is defined in section 2(1)(w): "with respect to any particular electronic records, means any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record and includes telecoms service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes". Our article on section 2 of the IT Act explains the definition.
Sub-section (2), as printed in the consolidated copy: "Any intermediary who intentionally or knowingly contravences the provisions of sub-section (1) shall be punished with an imprisonment for a term which may extend to three years and also be liable to fine." The copy prints "contravences" for "contravenes"; we flag the slip and do not correct it.
Section 69B: traffic data and cyber security
Section 69B is headed "Power to authorize to monitor and collect traffic data or information through any computer resource for cyber security". As printed:
- (1) The Central Government may, "to enhance cyber security and for identification, analysis and prevention of intrusion or spread of computer contaminant in the country, by notification in the Official Gazette, authorize any agency of the Government to monitor and collect traffic data or information generated, transmitted, received or stored in any computer resource".
- (2) The intermediary or any person in charge of the computer resource shall, when called upon by the authorised agency, "provide technical assistance and extend all facilities to such agency to enable online access or to secure and provide online access to the computer resource generating, transmitting, receiving or storing such traffic data or information". The copy prints "any person in-charge or the computer resource", a slip we flag and do not correct.
- (3) The procedure and safeguards for monitoring and collecting traffic data or information "shall be such as may be prescribed". No rule on this is in the sources used for this article.
- (4) As printed: "Any intermediary who intentionally or knowingly contravenes the provisions of sub-section (2) shall be punished with an imprisonment for a term which any extend to three years and shall also be liable to fine." The copy prints "which any extend" for "which may extend"; we flag the slip.
The Explanation to section 69B says that "computer contaminant" has the meaning assigned in section 43, and that "traffic data" "means any data identifying or purporting to identify any person, computer system or computer network or location to or from which the communication is or may be transmitted and includes communications origin, destination, route, time, data, size, duration or type of underlying service and any other information".
If you operate a platform, a hosting service or an app, a legal due diligence review of what you log, who may ask for it and how you respond to an authorised agency is a sound control before a request is received.
Table: as printed and as amended
The Jan Vishwas (Amendment of Provisions) Act, 2023, in item 32 of its Schedule, amends this Act. Item (F) reads: in section 67C, in sub-section (2), for the words "punished with an imprisonment for a term which may extend to three years and also be liable to fine", the words "liable to penalty which may extend to twenty-five lakh rupees" shall be substituted. Item (H) reads: in section 69B, in sub-section (4), for the words "three years and shall also be liable to fine", the words "one year or shall be liable to fine which may extend to one crore rupees, or with both" shall be substituted.
| Provision | As printed in the consolidated copy | As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023 |
|---|---|---|
| Section 67C(2) | "shall be punished with an imprisonment for a term which may extend to three years and also be liable to fine" | "liable to penalty which may extend to twenty-five lakh rupees" |
| Section 69B(4) | "punished with an imprisonment for a term which any extend to three years and shall also be liable to fine" | "punished with an imprisonment for a term which any extend to one year or shall be liable to fine which may extend to one crore rupees, or with both" |
Two reading points follow from applying the words. In section 67C(2), imprisonment is replaced by a "penalty", and this article infers nothing more than that; who imposes the penalty is read from section 46 as amended by the same item, which speaks of contraventions "under this Act". In section 69B(4), the text that remains after the substitution is "punished with an imprisonment for a term which any extend to one year or shall be liable to fine which may extend to one crore rupees, or with both"; the slip "any extend" stays in the words that were not substituted.
Commencement of the Jan Vishwas (Amendment of Provisions) Act, 2023 is by notification of the Central Government, and different dates may be appointed for amendments relating to different enactments; no date is in the sources used for this article. Check whether the amendments to sections 67C and 69B have been brought into force.
Link with the 2021 Intermediary Rules
This article uses the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 only for a short cross-reference; later amendments to those Rules are not covered here, and the current text of the Rules should be checked before acting. Rule 3(1)(g) of the Rules as originally notified speaks of preserving removed information and associated records "for one hundred and eighty days", and rule 3(1)(h) speaks of retaining registration information "for a period of one hundred and eighty days after any cancellation or withdrawal" of registration. Our article on rule 3 of the Intermediary Guidelines Rules explains them, and these rule periods are not a reading of section 67C, which leaves the duration to rules the Central Government may prescribe.
The CERT-In Directions of 28 April 2022, issued under sub-section (6) of section 70B, separately speak of logs maintained "for a rolling period of 180 days"; see our article on cyber incident reporting and log retention under the CERT-In Directions.
A worked example
Sagar Cloud Services Private Limited, an invented web-hosting provider, receives a written request from an agency that has been authorised by notification under section 69B(1), calling for technical assistance to give online access to a computer resource that stores traffic data. Under section 69B(2) the provider, as an intermediary, is among those who "shall" give technical assistance and extend facilities. The provider's questions are whether the agency is the one authorised by notification, what exactly is called for, and how to keep a record of what it did. The Act leaves the procedure and safeguards to rules.
Need help with intermediary obligations?
If you run an intermediary service and want to understand what sections 67C and 69B mean for your records and your response to an authorised request, our team can review your position. See our legal due diligence service.
Key takeaways
- Section 67C(1) requires an intermediary to preserve and retain specified information as the Central Government may prescribe; the Act prints no duration, manner or format.
- Section 69B lets the Central Government authorise an agency to monitor and collect traffic data, and requires technical assistance from the intermediary or person in charge.
- As printed, both sub-sections 67C(2) and 69B(4) carry imprisonment up to three years and liability to fine.
- As amended by the Jan Vishwas (Amendment of Provisions) Act, 2023: section 67C(2) is a penalty up to twenty-five lakh rupees; section 69B(4) is one year or fine up to one crore rupees, or both. No commencement date is in the sources; check whether the amendment is in force.
Read next
- Section 69 of the Information Technology Act, 2000: interception, monitoring and decryption directions
- Rule 3 of the Intermediary Guidelines Rules, 2021: due diligence and grievance redressal
- CERT-In Directions of 28 April 2022: cyber incident reporting and log retention
- Cyber Law: Information Technology Act 2000, offences, penalties and adjudication
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
