Sections 86 and 87 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 86 of the Information Technology Act, 2000 let the Central Government remove difficulties by order within two years from the commencement of the Act. Section 87 gives the Central Government power to make rules by notification in the Official Gazette and in the Electronic Gazette, lists the matters in sub-section (2), and requires laying before Parliament in sub-section (3). Section 44(2)(c) of the Digital Personal Data Protection Act, 2023 omits clause (ob) of section 87(2). This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008); later amendments and the current position should be checked.
Section 87(1) lets the Central Government make rules to carry out the provisions of the Act. Section 87(2) lists the matters on which rules may be made, clause by clause, each tied to a section. The text of the rules is not in the Act; of all rules under the Act, the sources used for this article contain only the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 as originally notified. As amended by section 44(2)(c) of the Digital Personal Data Protection Act, 2023, clause (ob) of section 87(2) is omitted; check whether it has been brought into force.
Section 86: removal of difficulties
Section 86(1) reads: "If any difficulty arises in giving effect to the provisions of this Act, the Central Government may, by order published in the Official Gazette, make such provisions not inconsistent with the provisions of this Act as appear to it to be necessary or expedient for removing the difficulty: Provided that no order shall be made under this section after the expiry of a period of two years from the commencement of this Act."
Sub-section (2) reads: "Every order made under this section shall be laid, as soon as may be after it is made, before each House of Parliament."
| Element | What the words say |
|---|---|
| Trigger | A difficulty arises in giving effect to the provisions of the Act |
| Power | The Central Government may, by order published in the Official Gazette, make provisions not inconsistent with the Act as appear necessary or expedient for removing the difficulty |
| Time limit | No order after the expiry of two years from the commencement of the Act |
| Laying | Every order laid, as soon as may be, before each House of Parliament |
The header of the consolidated copy prints that the Act was "Brought into force on 17.10.2000 vide G.S.R. 788(E)". The two-year limit runs from the commencement of the Act, and this article does not compute a date.
Section 87(1): the power to make rules
Section 87(1) reads: "The Central Government may, by notification in the Official Gazette and in the Electronic Gazette, make rules to carry out the provisions of this Act."
Section 87(2): the matters, clause by clause
Sub-section (2) reads: "In particular, and without prejudice to the generality of the foregoing power, such rules may provide for all or any of the following matters, namely:-". The clauses, in the order of the copy, are:
| Clause | Subject of the rules | Section it serves |
|---|---|---|
| (a) | conditions for considering reliability of electronic signature or electronic authentication technique | 3A(2) |
| (aa) | procedure for ascertaining electronic signature or authentication | 3A(3) |
| (ab) | manner in which any information or matter may be authenticated by means of electronic signature | 5 |
| (b) | electronic form in which filing, issue, grant or payment shall be effected | 6(1) |
| (c) | manner and format in which electronic records shall be filed or issued, and the method of payment | 6(2) |
| (ca) | manner in which the authorised service provider may collect, retain and appropriate service charges | 6A(2) |
| (d) | matters relating to the type of electronic signature, manner and format in which it may be affixed | 10 |
| (e) | manner of storing and affixing electronic signature creation data | 15 |
| (ea) | security procedures and practices | 16 |
| (f) | qualifications, experience and terms and conditions of service of the Controller, Deputy Controllers, Assistant Controllers, other officers and employees | 17 |
| (g) | omitted ("[ *]" in the copy) | not applicable |
| (h) | requirements which an applicant must fulfil | 21(2) |
| (i) | period of validity of licence | 21(3)(a) |
| (j) | form in which an application for license may be made | 22(1) |
| (k) | amount of fees payable | 22(2)(c) |
| (l) | other documents which shall accompany an application for license | 22(2)(d) |
| (m) | form and fee for renewal of a license | 23 |
| (ma) | form of application and fee for issue of Electronic Signature Certificate | 35 |
| (n) | form in which an application for issue of a Certificate may be made | 35(1) |
| (o) | fee to be paid to the Certifying Authority for issue of a Certificate | 35(2) |
| (oa) | duties of subscribers | 40A |
| (ob) | reasonable security practices and procedures and sensitive personal data or information | 43A |
| (p) | manner in which the adjudicating officer shall hold inquiry | 46(1) |
| (q) | qualification and experience of the adjudicating officer | 46(3) |
| (r) | salary, allowances and other terms and conditions of service of the Chairperson and Members | 52 |
| (s) | procedure for investigation of misbehavior or incapacity of the Chairperson and Members | 54(3) |
| (t) | salary and allowances and other conditions of service of other officers and employees | 56(3) |
| (u) | form in which appeal may be filed and the fee | 57(3) |
| (v) | any other power of a civil Court required to be prescribed | 58(2)(g) |
| (w) | powers and functions of the Chairperson of the Cyber Appellate Tribunal | 52A |
| (wa) | information, duration, manner and form of information to be retained and preserved | 67C |
| (x) | procedures and safeguards for interception, monitoring or decryption | 69(2) |
| (xa) | procedure and safeguards for blocking for access by the public | 69A(2) |
| (xb) | procedure and safeguards for monitoring and collecting traffic data or information | 69B(3) |
| (y) | information security practices and procedures for protected system | 70 |
| (ya) | manner of performing functions and duties of the agency | 70A(3) |
| (yb) | officers and employees | 70B(2) |
| (yc) | salaries and allowances and terms and conditions of service of the Director-General and other officers and employees | 70B(3) |
| (yd) | manner in which the functions and duties of agency shall be performed | 70B(5) |
| (z) | guidelines to be observed by the intermediaries | "sub-section (4) of section 79", as printed |
| (za) | modes or methods for encryption | 84A |
If you are drafting a policy that depends on a rule, a legal consultation on which clause the rule is made under, and what the Act itself says on the matter, helps avoid reading a rule into the Act.
Printing slips to know
Two slips affect how the clauses are read. First, clause (z) refers to "sub-section (4) of section 79", but section 79 as printed has no sub-section (4); the guidelines are in section 79(2)(c). Our article on section 79 discusses the section. Second, the copy prints clause (z) followed by clause (za), and no clause (zf) or (zg). The Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 as originally notified cite "clauses (z) and (zg) of sub-section (2) of section 87", and the CERT-In Directions of 28 April 2022 cite "clause (zf)" in a recital about another set of rules. We flag the mismatch and do not correct any text. Clause (g) is printed as "[ *]", that is, omitted.
Section 87(3): laying before Parliament
Section 87(3) provides, in the copy, that every notification made by the Central Government under sub-section (1) of section 70A and every rule made by it shall be laid, as soon as may be after it is made, before each House of Parliament while it is in session, for a total period of thirty days which may be comprised in one session or in two or more successive sessions. If, before the expiry of the session immediately following, both Houses agree in making any modification in the rule or agree that the rule should not be made, the rule thereafter has effect only in such modified form or is of no effect, as the case may be, without prejudice to the validity of anything previously done under it. The printed text is broken up by brackets and "[ *]" marks; we quote the sense and do not correct it.
As amended by the Digital Personal Data Protection Act, 2023
Section 44(2) of the Digital Personal Data Protection Act, 2023 reads in part: "(c) in section 87, in sub-section (2), clause (ob) shall be omitted." Clause (a) of the same sub-section says "section 43A shall be omitted".
| Provision | As printed in the consolidated copy | Under section 44(2) of the Digital Personal Data Protection Act, 2023 |
|---|---|---|
| Section 87(2)(ob) | "the reasonable security practices and procedures and sensitive personal data or information under section 43-A" | Omitted |
| Section 43A | Printed as a compensation provision | Omitted by clause (a) |
Section 1(2) of the Digital Personal Data Protection Act, 2023 brings it into force on notified dates, with different dates for different provisions, and no date for section 44 is in the sources used for this article. Check whether section 44(2) has been brought into force. Our articles on section 43A of the IT Act and on section 44 of the Digital Personal Data Protection Act, 2023 cover the connected provisions.
Which rules are in the sources
Rules under the Act are not in the sources used for this article, with one exception: the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021. Later amendments to those Rules are not covered here; check the current text of the Rules before acting. Our articles on rule 3 and on the definitions and non-observance rules explain them. Where this series says a matter is "as may be prescribed", it means the detail is left to rules and the Act itself prints none.
A worked example
A company that issues logins to staff reads section 70(4): "The Central Government shall prescribe the information security practices and procedures for such protected system." The company then looks at clause (y) of section 87(2), which names this matter. The Act sets the power and the subject; the actual practices are in the rules. Without the rules in hand, the company cannot say what they require, and a summary of section 70(4) is therefore not a summary of those rules.
Need help with rules made under the Act?
If you need to know which rule applies to your business and how the Act's rule-making clauses fit, our team can help you read them together. Start with a legal consultation.
Key takeaways
- Section 86 allowed removal of difficulties by order, not after two years from the commencement of the Act.
- Section 87(1) lets the Central Government make rules by notification in the Official Gazette and in the Electronic Gazette.
- Section 87(2) lists the matters clause by clause; each clause is tied to a section of the Act.
- Section 44(2)(c) of the Digital Personal Data Protection Act, 2023 omits clause (ob); check whether it has been brought into force.
- Of all rules under the Act, only the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 as originally notified are in the sources used here.
Read next
- Section 43A of the Information Technology Act, 2000: compensation for failure to protect data
- Section 44 of the Digital Personal Data Protection Act, 2023: amendments to the IT Act, RTI Act and TRAI Act
- Sections 88 to 90 of the Information Technology Act, 2000: Advisory Committee, regulations and State rules
- Rule 3 of the Intermediary Guidelines Rules, 2021: due diligence and grievance redressal
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
