Every time you enter your card number on a shopping site or scan a QR code to pay, your data travels through networks that thousands of strangers could technically intercept. It reaches its destination safely because of one quiet mechanism working in the background: encryption. In e-commerce, where money, personal details, and business records move online every second, encryption is not a technical afterthought. It is the legal and practical foundation on which digital trust is built, and the IT Act 2000 was the first Indian law to give it formal recognition.

Table of Contents

What encryption actually does

Encryption is the process of converting readable information, called plain text, into a scrambled, unreadable format called cipher text. Decryption reverses this process, turning the cipher text back into its original form using a key. Without the correct key, the cipher text looks like meaningless noise to anyone who intercepts it.

The Information Technology Act, 2000 was India’s first attempt to give legal structure to this idea. It was drafted to support electronic commerce and electronic governance, and encryption sits at the centre of that goal because digital transactions cannot be trusted unless the data behind them is protected from tampering and unauthorised access.

How the IT Act 2000 addresses encryption

The Act does not prescribe a single fixed encryption standard. Instead, it builds a framework that allows encryption practices to evolve alongside technology, while keeping the government in a position to regulate and, when necessary, access encrypted data.

Section 84A: Power to prescribe modes of encryption

Inserted through the 2008 amendment, Section 84A empowers the central government to prescribe modes or methods of encryption for the secure use of electronic mediums and for promoting e-governance and e-commerce. This is a deliberately flexible provision. Rather than locking the law to one algorithm, it lets regulators update encryption standards as cryptography advances.

Section 69: Power to intercept and decrypt

Balancing this is the government’s power to direct any agency to intercept, monitor, or decrypt information stored in a computer resource, when it is necessary in the interest of national security, public order, or the investigation of an offence. This provision recognises that strong encryption, while essential for privacy and commerce, can also be misused, and it gives law enforcement a legal route to access data under defined circumstances.

Sections 3, 3A, and 5: Digital signatures built on encryption

The Act gives legal recognition to electronic records authenticated through digital signatures, and specifically ties this recognition to asymmetric cryptography. Under this system, a digital signature is created by encrypting a hash of the document using the signer’s private key, and any change to the document after signing produces a completely different hash value, which causes the signature verification to fail. This is what makes electronic contracts, e-invoices, and online agreements legally reliable. The 2008 amendment added Section 3A to recognise broader forms of electronic signatures as technology diversified beyond the original digital signature model.

The two types of encryption the law works with

Encryption used in Indian e-commerce and recognised in the broader legal and technical framework falls into two categories: symmetric and asymmetric. Each solves a different part of the security problem.

Symmetric encryption

Symmetric encryption uses a single secret key to both encrypt and decrypt data. The sender and receiver must both possess this same key beforehand. Its biggest advantage is speed. Because the underlying mathematics is simpler, symmetric encryption is generally faster and requires less processing power than asymmetric encryption, which makes it well suited to encrypting large volumes of data, such as database records or files.

The catch is key distribution. Both parties need a secure way to exchange the shared key before communication starts. If that key is intercepted during transfer, the entire system is compromised, since anyone holding it can decrypt every message protected by it.

Asymmetric encryption

Asymmetric encryption solves the key-sharing problem by using a mathematically linked pair of keys: a public key that can be shared openly, and a private key that is kept secret by its owner. Data encrypted with the public key can only be decrypted with the corresponding private key, and vice versa. This is the model the IT Act explicitly recognises for digital signatures, since a message encrypted using the sender’s private key can be decrypted by anyone holding the corresponding public key, which proves the message genuinely came from that sender.

Asymmetric encryption is slower than symmetric encryption because of its longer keys and heavier computation, but it removes the need to exchange a secret key over a potentially unsafe channel. This is why it is the preferred method for establishing trust between two parties who have never communicated before, such as your browser and an online store’s payment gateway.

Aspect Symmetric encryption Asymmetric encryption
Keys used One shared secret key A public key and a private key
Speed Faster, lower processing load Slower, higher processing load
Main challenge Securely sharing the key Managing key pairs and certificates
Typical use Encrypting bulk data, files, databases Digital signatures, key exchange, authentication

Why this matters for digital transactions

E-commerce depends on four things happening correctly every time you shop, pay a bill, or sign a contract online: confidentiality, so your card details cannot be read by outsiders; integrity, so the order amount or contract terms cannot be silently altered; authentication, so both parties know who they are really dealing with; and non-repudiation, so a signer cannot later deny having agreed to a transaction. Symmetric encryption works well for confidentiality of large data volumes, while asymmetric encryption is best suited for digital signatures, secure key exchange, and authentication, which is why most real systems use both together.

A typical secure website connection illustrates this combination well. During a website’s secure handshake, the browser uses the site’s public key to help set up a shared session key, after which the actual data exchange switches to faster symmetric encryption. Asymmetric cryptography establishes trust at the start of the connection; symmetric cryptography then does the heavy lifting of encrypting the ongoing traffic.

Where you meet this in Indian digital commerce

This dual-encryption model quietly runs underneath activities students interact with daily:

  • Secure browsing: Any website using HTTPS relies on this handshake to protect login details and payment data.
  • UPI and net banking: Payment apps encrypt transaction data end to end, and digital signatures authenticate the parties involved.
  • Government and MCA filings: Company incorporation documents, GST returns, and court filings increasingly require Digital Signature Certificates issued by licensed Certifying Authorities, which are built entirely on asymmetric cryptography.
  • E-contracts and e-invoices: Businesses rely on digital signatures to make electronic agreements legally binding without needing physical signing.

The other side: regulation and compliance

Because encryption can be misused to hide criminal activity, Indian regulators keep a close eye on how it is deployed. The Indian Computer Emergency Response Team (CERT-In), established under Section 70B of the IT Act, issues guidelines that push organisations toward stronger data protection practices, including encrypting sensitive information at rest and in transit. Businesses handling customer data for e-commerce, especially payment and personal information, are expected to align with these evolving standards, alongside sector-specific rules from bodies like the RBI for digital payments.

This creates a constant balancing act. Strong encryption protects consumers and businesses from fraud and data theft, but it can also make lawful investigation harder. Section 69’s decryption powers exist precisely to give the state a legal, narrowly defined route into encrypted data when public interest genuinely requires it, rather than weakening encryption standards for everyone.

What do you think?

What do you think? If every e-commerce platform you use already relies on both symmetric and asymmetric encryption without you noticing, does encryption law need to focus more on regulating businesses that handle your data, or on giving individuals more visibility into how their information is protected? And as quantum computing develops, should India’s encryption framework under the IT Act be revisited sooner rather than later?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
  2. https://bhattandjoshiassociates.com/digital-signature-laws-in-india/
  3. https://www.ibm.com/think/topics/symmetric-encryption
  4. https://blog.ipleaders.in/digital-electronic-signature/
  5. https://www.geeksforgeeks.org/computer-networks/difference-between-symmetric-and-asymmetric-key-encryption/
  6. https://www.esignglobal.com/blog/electronic-signature-valid-information-technology-act-2000-india
  7. https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=1936470&reg=48&lang=2

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

E-Commerce

1 Introduction to E-commerce

  1. Introduction
  2. Meaning of E-Commerce
  3. E-Commerce Web Portal
  4. E-Commerce Software
  5. E-Commerce APIs
  6. M-Commerce and Multi-channel Commerce
  7. Use of Emerging Technologies in E-Commerce
  8. Why E-Commerce
  9. Evolution of E-Commerce
  10. Types of E-Commerce
  11. Advantages and Disadvantages of E-Commerce

2 E-Commerce Business Models

  1. Introduction
  2. What is a Business Model?
  3. Key Elements of a Business Model
  4. E-Commerce Business Models to Understand Target Customer
  5. E-Commerce Design Models
  6. Implementing E-Commerce Models
  7. E-Commerce Revenue Models
  8. Impact of COVID on E-Commerce

3 Technology used in E-Commerce

  1. Introduction
  2. Design Considerations of E-Commerce
  3. Essential Technology Features Required
  4. Difference between App Based and Web-Based Business
  5. Building, Designing and Launching E-Commerce Website
  6. SDLC Cycle for Designing E-Commerce Solutions
  7. Architectural Framework and Network Infrastructure
  8. Impact of Emerging Technologies on E-Commerce
  9. Digital Platforms and E-Commerce
  10. Digitalisation and Digital Transformation in Businesses

4 Electronic Governance

  1. Introduction
  2. Meaning of E-Governance
  3. Differences between E-Government and E-Governance
  4. Differences between E-Governance and E-Commerce
  5. Advantages of Employing Digital Technologies in Governance
  6. Gartnerโ€™s Evolution Model of E-Governance
  7. E-Governance in India
  8. Digital India
  9. E-Governance initiatives in India

5 E-Payment

  1. Introduction
  2. Overview of Payment System
  3. Meaning of E-Payment
  4. Difference between E-Payment & Conventional Payment
  5. Payment Gateways
  6. Steps about Functioning of a Payment Gateway
  7. Types of Payment Gateways
  8. Types of Payment Methods
  9. Requirements Metrics of a Payment System
  10. Merits of E-Payment System
  11. Risks Involved in E-Payment

6 E-Banking

  1. Introduction
  2. Concept of E-Banking
  3. Importance of E-Banking
  4. Technology used in Banking
  5. EFT (Electronic Fund Transfer)
  6. NEFT (National Electronic Fund Transfer)
  7. RTGS (Real Time Gross Settlement)
  8. IMPS (Immediate Payment Service)
  9. UPI (Unified Payments Interface)
  10. Difference between NEFT, RTGS & IMPS
  11. Virtual Currency
  12. Automated Clearing House
  13. Automated Ledger Posting
  14. Distributed Ledger Technology

7 Website Development

  1. Introduction
  2. Meaning of Website
  3. Evolution of Website
  4. Website Usage
  5. HTTP & HTTPS Protocols
  6. Types of Website
  7. Development of Website
  8. Ingredients Required for Website Development
  9. Website Hosting

8 Electronic Commerce Software

  1. Introduction
  2. E-commerce Software Platform
  3. Types of Software Platforms
  4. Shopify – An Online Store Builder
  5. E-Auction Processes the Real-Time Visibility
  6. PayPal Holdings Online Payments
  7. SAP Commerce Cloud
  8. Functions of E-Commerce Software Platforms
  9. Advanced Functions of E-Commerce Software
  10. E-Commerce Software for Small & Midsize Companies
  11. E-Commerce Software for Midsize to Large Business
  12. E-Commerce Software for Large Business
  13. Planning Electronic Commerce Initiatives
  14. Strategies for Developing E-Commerce Websites
  15. Managing E-Commerce Implementations

9 Web Server Hardware and Software

  1. Meaning of Server
  2. Web Server Essentials
  3. Different Types of Web Server
  4. Characteristics of a Web Server
  5. Functioning of a Web Server
  6. Mail Server
  7. Process of Sending E-mails
  8. Operating System
  9. Windows
  10. Linux
  11. Linux vs. Windows
  12. Web Server Hardware
  13. Hardware used in Web Servers
  14. Web Server Software
  15. Application Server Software
  16. Web Server & Application Server
  17. Web Site and Internet Utility Programs

10 Cyber Security

  1. Meaning of Cyber Security
  2. Cyber Security Impact on E-Commerce
  3. Cyber Security Relevance
  4. Information Security V/s Cyber Security
  5. Basics of Cyber World
  6. Need & Concepts behind Security
  7. IoT and Cyber World
  8. Cyber Crime and Law
  9. Security Barriers

11 Cyber Security Measures

  1. Role of Cyber Security Analysts
  2. Essential Cyber Security Measures
  3. Precautionary Cyber-Security Measures Enterprise Takes
  4. IoT and its Impact
  5. Vulnerable Information on Internet
  6. Vulnerabilities of Systems
  7. Internet Vulnerabilities
  8. Wireless Security Challenges
  9. Malicious Software
  10. Hackers and Computer Crime
  11. Cyber Crime
  12. Global Threats: Cyber terrorism and Cyber Warfare
  13. Cyber Forensic
  14. Securing the Business on Internet
  15. Securing Network Transactions
  16. Security Measures and Enforcement

12 IT Act 2000

  1. Definition
  2. Formulation of IT Act 2000
  3. Amendments in IT Act 2000
  4. Digital Signature & Encryption
  5. Attribution
  6. Acknowledgement and Dispatch of Electronic Records
  7. Regulation of Certifying Authorities
  8. Digital Signatures Certificates
  9. Duties of Subscribers
  10. Penalties and Adjudication
  11. Procedure, Working & Legal Position in Digital Signature
  12. Appellate Tribunal
  13. Offences and Cyber-Crimes
  14. E-Signature and Digital Signature
  15. Encryption

13 E-Tailing

  1. E-tailing
  2. E-tailing Models
  3. E-retail Mix-Sale the 7Cs
  4. E-tailing in India

14 E-Services

  1. Meaning of E-Services
  2. Benefits of E-Services
  3. FinTech
  4. eFinancial Services
  5. eTravel Services
  6. eAuction Services
  7. eLearning
  8. Virtual Communities and Web Portals
  9. Online Learning
  10. ePublishing Services
  11. Online Entertainment

15 App Based Commerce

  1. What is an App?
  2. Classification of Apps
  3. Types of Apps
  4. Steps for App Development
  5. Mobile Development Frameworks
  6. App Store
  7. Apps for Various Domains & Segments