E-commerce generates specific legal issues in taxation of digital transactions, regulation of electronic banking, liability in online publishing, and security of credit card payments.
Legal Framework
| Area | Governing Law |
|---|---|
| E-taxation | Income Tax Act (Equalization Levy), CGST Act (TCS S.52), Finance Act |
| E-banking | RBI Act 1934, Payment and Settlement Systems Act 2007, RBI Guidelines on Internet Banking |
| Online publishing | IT Act (S.79 intermediary), Copyright Act 1957, Press Council Act |
| Credit card payments | RBI Circular on Card Security, Payment Card Industry Data Security Standard (PCI-DSS), IT Act S.43A |
E-Taxation
| Mechanism | Provision | Application |
|---|---|---|
| Equalization Levy (6%) | Finance Act 2016, Ch.VIII | Non-resident providing digital advertising services to Indian business |
| Equalization Levy (2%) | Finance Act 2020, S.165A | Non-resident e-commerce operators (repealed from 1 Aug 2024) |
| TCS (1%) | S.52 CGST Act | E-commerce operators collecting tax on net taxable supplies made through them |
| Significant Economic Presence | S.9(1)(i) Explanation 2A, Income Tax Act | Non-resident with digital transactions above threshold deemed to have business connection in India |
| Permanent Establishment (digital) | OECD BEPS Action 1 recommendations | Evolving international consensus on taxing digital economy |
Why: Digital businesses can derive substantial revenue from a country without physical presence. Traditional tax rules (based on physical PE) fail to capture this value. Equalization Levy and SEP ensure source-country taxation of digital profits.
E-Banking
RBI Framework for Internet Banking
| Requirement | Guideline |
|---|---|
| Two-factor authentication | Mandatory for all internet banking transactions |
| Customer liability limitation | Zero liability if reported within 3 days; limited liability if reported in 4-7 days |
| SMS/email alerts | Real-time notification for all transactions |
| Encryption | Minimum 128-bit SSL encryption |
| Phishing protection | Banks must maintain secure domain, educate customers |
| Grievance redressal | Internal ombudsman + Banking Ombudsman |
| Time limit for reversal | 10 working days for unauthorized transaction credit |
Types of E-Banking Services
| Service | Description |
|---|---|
| Internet banking (NEFT/RTGS/IMPS) | Fund transfer through bank's website |
| Mobile banking | Banking through smartphone applications |
| UPI (Unified Payments Interface) | Real-time inter-bank payment via mobile |
| Digital wallets | Pre-paid instruments (Paytm, PhonePe wallet) |
| AEPS (Aadhaar Enabled Payment) | Banking through Aadhaar biometric authentication |
| Debit/Credit card payment | POS and online transactions |
Online Credit Card Payment
Legal Issues
| Issue | Legal Position |
|---|---|
| Unauthorized transaction | Bank liable if customer reports within 3 days (RBI circular); customer gets zero liability |
| Card cloning/skimming | Offence under S.66C IT Act (identity theft) and BNS S.318 (cheating) |
| Phishing for card details | S.66D IT Act (cheating by personation using computer resource) |
| Data breach | Card issuer liable under S.43A IT Act if security practices inadequate |
| Chargeback | Consumer's right to dispute; merchant bears burden of proving legitimate transaction |
| PCI-DSS compliance | Industry standard; non-compliance shifts liability to non-compliant party |
Customer Liability Framework (RBI 2017 Circular)
| Timeframe of Reporting | Customer Liability |
|---|---|
| Within 3 working days | Zero liability |
| Within 4-7 working days | Limited to transaction value or Rs.10,000 (whichever is lower) for savings; Rs.25,000 for current account |
| Beyond 7 working days | As per bank's internal policy |
| Bank's delay in notification | Zero liability regardless of reporting delay |
Online Publishing
| Issue | Applicable Law |
|---|---|
| Copyright in online content | Copyright Act 1957, S.14 (reproduction right includes digital) |
| Intermediary liability for published content | IT Act S.79 (safe harbour for platforms) |
| Defamation in online publication | BNS S.356 (defamation) + IT Act provisions |
| Regulation of digital news | IT Rules 2021 Part III (Digital Media Ethics Code) |
| Right to be forgotten | DPDP Act 2023, S.14(8) (right to erasure) |
Recall Check
- What is the Equalization Levy and why was it introduced?
- What is the customer's liability for unauthorized electronic banking transactions reported within 3 days?
- Name three legal issues specific to online credit card payments.
Key Cases
NASSCOM v. Ajay Sood (2005) NASSCOM-v-Ajay-Sood-2005 Issue: Whether sending fraudulent emails impersonating a company to extract personal/financial information (phishing) is actionable. Rule: Phishing constitutes passing off and is an actionable civil wrong in India; courts can grant injunction against phishing operations. Held: Delhi HC held that phishing is a form of internet fraud amounting to passing off. Coined phishing as an offence even before specific statutory provision (later S.66D IT Act codified it).
State Bank of India v. Dr. VPS Rathore (2006) SBI-v-VPS-Rathore-2006 Issue: Whether a bank is liable for unauthorized ATM/online transactions caused by system vulnerabilities. Rule: Banks offering electronic banking services owe a duty of care to customers; failure in security systems makes the bank liable for customer losses. Held: Consumer forum held SBI liable for unauthorized withdrawal through ATM card cloning. Bank must ensure adequate security and cannot shift liability to customer for system-level failures.
Distinctions
| Aspect | E-Banking | Traditional Banking |
|---|---|---|
| Channel | Internet/mobile/UPI | Physical branch |
| Authentication | Digital (OTP, biometric, PIN) | Physical (signature, presence) |
| Speed | Real-time (IMPS/UPI: instant) | Working hours; clearing cycle |
| Geographic reach | Anywhere with internet | Limited to branch locations |
| Risk profile | Phishing, hacking, card cloning | Robbery, forgery, impersonation |
| Governing framework | IT Act + RBI circulars + PSS Act | NI Act + RBI regulations |
| Dispute resolution | Banking Ombudsman + Consumer Forum | Same + civil court |
Flashcards
Q: What is the Equalization Levy (6%)? A: Tax on non-resident entities providing digital advertising services to Indian businesses, ensuring India can tax digital revenue derived from Indian users.
Q: What is TCS under S.52 CGST Act in e-commerce context? A: E-commerce operators must collect 1% of net taxable supplies made through their platform and deposit with government.
Q: What is a customer's zero-liability protection in e-banking? A: If customer reports unauthorized transaction within 3 working days of receiving communication, customer bears zero liability (RBI Circular, July 2017).
Q: What did NASSCOM v. Ajay Sood (2005) establish? A: Phishing constitutes passing off and is an actionable civil wrong; Delhi HC recognized it before specific statutory provision existed.
Q: What is PCI-DSS? A: Payment Card Industry Data Security Standard: global security standard for entities handling credit card information; non-compliance shifts liability to the non-compliant party in disputes.
Q: What is "Significant Economic Presence" under Income Tax Act? A: A non-resident with digital transactions above threshold (Rs.2 crores revenue or 3 lakh users) is deemed to have business connection in India, enabling India to tax such income.
Q: What is UPI? A: Unified Payments Interface: NPCI-developed real-time inter-bank payment system allowing instant fund transfer via mobile using virtual payment address.
Q: How does the RBI framework limit bank liability in unauthorized transactions? A: If the bank fails to send timely alerts to the customer, the customer has zero liability regardless of reporting delay; the bank bears the loss.
Exam Scenario
A customer receives an email appearing to be from her bank, asking her to update KYC details. She clicks the link and enters her debit card details. Subsequently, Rs.2 lakhs is debited from her account. She reports to the bank after 5 days. Advise on the legal position regarding liability.
This is a phishing attack (S.66D IT Act: cheating by personation through computer resource). Customer liability: Under RBI 2017 Circular, reporting between 4-7 working days means limited liability (Rs.10,000 for savings account). The bank must credit the remaining amount within 10 working days and investigate. If investigation shows the bank's system was compromised (no adequate phishing warnings, weak authentication), bank bears full liability. If the customer was negligent (sharing OTP despite warnings), limited liability applies. Criminal action: FIR under S.66C (identity theft), S.66D (cheating by personation) IT Act, and S.318 BNS (cheating). The phisher, if identified, faces imprisonment up to 3 years and fine up to Rs.1 lakh under each section.