Information Technology Law
Subjects / Information Technology Law / E Commerce Trends and Digital Payments
Unit 3 · Unit 3

E Commerce Trends and Digital Payments

E-commerce generates specific legal issues in taxation of digital transactions, regulation of electronic banking, liability in online publishing, and security of credit card payments.

E-commerce generates specific legal issues in taxation of digital transactions, regulation of electronic banking, liability in online publishing, and security of credit card payments.

Legal Framework

Area Governing Law
E-taxation Income Tax Act (Equalization Levy), CGST Act (TCS S.52), Finance Act
E-banking RBI Act 1934, Payment and Settlement Systems Act 2007, RBI Guidelines on Internet Banking
Online publishing IT Act (S.79 intermediary), Copyright Act 1957, Press Council Act
Credit card payments RBI Circular on Card Security, Payment Card Industry Data Security Standard (PCI-DSS), IT Act S.43A

E-Taxation

Mechanism Provision Application
Equalization Levy (6%) Finance Act 2016, Ch.VIII Non-resident providing digital advertising services to Indian business
Equalization Levy (2%) Finance Act 2020, S.165A Non-resident e-commerce operators (repealed from 1 Aug 2024)
TCS (1%) S.52 CGST Act E-commerce operators collecting tax on net taxable supplies made through them
Significant Economic Presence S.9(1)(i) Explanation 2A, Income Tax Act Non-resident with digital transactions above threshold deemed to have business connection in India
Permanent Establishment (digital) OECD BEPS Action 1 recommendations Evolving international consensus on taxing digital economy

Why: Digital businesses can derive substantial revenue from a country without physical presence. Traditional tax rules (based on physical PE) fail to capture this value. Equalization Levy and SEP ensure source-country taxation of digital profits.

E-Banking

RBI Framework for Internet Banking

Requirement Guideline
Two-factor authentication Mandatory for all internet banking transactions
Customer liability limitation Zero liability if reported within 3 days; limited liability if reported in 4-7 days
SMS/email alerts Real-time notification for all transactions
Encryption Minimum 128-bit SSL encryption
Phishing protection Banks must maintain secure domain, educate customers
Grievance redressal Internal ombudsman + Banking Ombudsman
Time limit for reversal 10 working days for unauthorized transaction credit

Types of E-Banking Services

Service Description
Internet banking (NEFT/RTGS/IMPS) Fund transfer through bank's website
Mobile banking Banking through smartphone applications
UPI (Unified Payments Interface) Real-time inter-bank payment via mobile
Digital wallets Pre-paid instruments (Paytm, PhonePe wallet)
AEPS (Aadhaar Enabled Payment) Banking through Aadhaar biometric authentication
Debit/Credit card payment POS and online transactions

Online Credit Card Payment

Legal Issues

Issue Legal Position
Unauthorized transaction Bank liable if customer reports within 3 days (RBI circular); customer gets zero liability
Card cloning/skimming Offence under S.66C IT Act (identity theft) and BNS S.318 (cheating)
Phishing for card details S.66D IT Act (cheating by personation using computer resource)
Data breach Card issuer liable under S.43A IT Act if security practices inadequate
Chargeback Consumer's right to dispute; merchant bears burden of proving legitimate transaction
PCI-DSS compliance Industry standard; non-compliance shifts liability to non-compliant party

Customer Liability Framework (RBI 2017 Circular)

Timeframe of Reporting Customer Liability
Within 3 working days Zero liability
Within 4-7 working days Limited to transaction value or Rs.10,000 (whichever is lower) for savings; Rs.25,000 for current account
Beyond 7 working days As per bank's internal policy
Bank's delay in notification Zero liability regardless of reporting delay

Online Publishing

Issue Applicable Law
Copyright in online content Copyright Act 1957, S.14 (reproduction right includes digital)
Intermediary liability for published content IT Act S.79 (safe harbour for platforms)
Defamation in online publication BNS S.356 (defamation) + IT Act provisions
Regulation of digital news IT Rules 2021 Part III (Digital Media Ethics Code)
Right to be forgotten DPDP Act 2023, S.14(8) (right to erasure)

Recall Check

  1. What is the Equalization Levy and why was it introduced?
  2. What is the customer's liability for unauthorized electronic banking transactions reported within 3 days?
  3. Name three legal issues specific to online credit card payments.

Key Cases

NASSCOM v. Ajay Sood (2005) NASSCOM-v-Ajay-Sood-2005 Issue: Whether sending fraudulent emails impersonating a company to extract personal/financial information (phishing) is actionable. Rule: Phishing constitutes passing off and is an actionable civil wrong in India; courts can grant injunction against phishing operations. Held: Delhi HC held that phishing is a form of internet fraud amounting to passing off. Coined phishing as an offence even before specific statutory provision (later S.66D IT Act codified it).

State Bank of India v. Dr. VPS Rathore (2006) SBI-v-VPS-Rathore-2006 Issue: Whether a bank is liable for unauthorized ATM/online transactions caused by system vulnerabilities. Rule: Banks offering electronic banking services owe a duty of care to customers; failure in security systems makes the bank liable for customer losses. Held: Consumer forum held SBI liable for unauthorized withdrawal through ATM card cloning. Bank must ensure adequate security and cannot shift liability to customer for system-level failures.

Distinctions

Aspect E-Banking Traditional Banking
Channel Internet/mobile/UPI Physical branch
Authentication Digital (OTP, biometric, PIN) Physical (signature, presence)
Speed Real-time (IMPS/UPI: instant) Working hours; clearing cycle
Geographic reach Anywhere with internet Limited to branch locations
Risk profile Phishing, hacking, card cloning Robbery, forgery, impersonation
Governing framework IT Act + RBI circulars + PSS Act NI Act + RBI regulations
Dispute resolution Banking Ombudsman + Consumer Forum Same + civil court

Flashcards

Q: What is the Equalization Levy (6%)? A: Tax on non-resident entities providing digital advertising services to Indian businesses, ensuring India can tax digital revenue derived from Indian users.

Q: What is TCS under S.52 CGST Act in e-commerce context? A: E-commerce operators must collect 1% of net taxable supplies made through their platform and deposit with government.

Q: What is a customer's zero-liability protection in e-banking? A: If customer reports unauthorized transaction within 3 working days of receiving communication, customer bears zero liability (RBI Circular, July 2017).

Q: What did NASSCOM v. Ajay Sood (2005) establish? A: Phishing constitutes passing off and is an actionable civil wrong; Delhi HC recognized it before specific statutory provision existed.

Q: What is PCI-DSS? A: Payment Card Industry Data Security Standard: global security standard for entities handling credit card information; non-compliance shifts liability to the non-compliant party in disputes.

Q: What is "Significant Economic Presence" under Income Tax Act? A: A non-resident with digital transactions above threshold (Rs.2 crores revenue or 3 lakh users) is deemed to have business connection in India, enabling India to tax such income.

Q: What is UPI? A: Unified Payments Interface: NPCI-developed real-time inter-bank payment system allowing instant fund transfer via mobile using virtual payment address.

Q: How does the RBI framework limit bank liability in unauthorized transactions? A: If the bank fails to send timely alerts to the customer, the customer has zero liability regardless of reporting delay; the bank bears the loss.

Exam Scenario

A customer receives an email appearing to be from her bank, asking her to update KYC details. She clicks the link and enters her debit card details. Subsequently, Rs.2 lakhs is debited from her account. She reports to the bank after 5 days. Advise on the legal position regarding liability.

This is a phishing attack (S.66D IT Act: cheating by personation through computer resource). Customer liability: Under RBI 2017 Circular, reporting between 4-7 working days means limited liability (Rs.10,000 for savings account). The bank must credit the remaining amount within 10 working days and investigate. If investigation shows the bank's system was compromised (no adequate phishing warnings, weak authentication), bank bears full liability. If the customer was negligent (sharing OTP despite warnings), limited liability applies. Criminal action: FIR under S.66C (identity theft), S.66D (cheating by personation) IT Act, and S.318 BNS (cheating). The phisher, if identified, faces imprisonment up to 3 years and fine up to Rs.1 lakh under each section.