Question:medium

The Information Technology Act, 2000, distinguishes between civil liability and criminal liability in cases of misuse of computer resources. In which of the following situations would such conduct attract criminal punishment rather than mere compensation?

Show Hint

Civil = Compensation (Section 43). Criminal = Intent (Dishonesty/Fraud). If you see "Dishonestly or Fraudulently," it is almost certainly a criminal offence under the IT Act!
Updated On: Jul 13, 2026
  • When the damage to computer resources exceeds a prescribed monetary limit
  • When the act is done dishonestly or fraudulently in addition to unauthorised access
  • When the affected party chooses to initiate criminal proceedings
  • When access to a computer system is without permission, irrespective of intent
Show Solution

The Correct Option is B

Approach Solution - 1

This question can be tested in two parts: first fixing what counts as the civil baseline under the IT Act, then identifying what extra element pushes conduct into criminal territory.

Test 1, civil baseline:
Section 43 makes unauthorised access to or damage of a computer resource a civil wrong calling for compensation, without requiring any particular state of mind beyond the act itself, and without regard to monetary damage or who initiated proceedings.


Test 2, criminal add-on:
Chapter XI's offences, covering hacking, identity theft, and cheating by personation, all require the same underlying unauthorised conduct to be accompanied by dishonest or fraudulent intent.


Conclusion:
Only the presence of dishonest or fraudulent intent supplies the missing ingredient that Test 2 requires, while a monetary threshold, the victim's choice to sue criminally, or plain unauthorised access without intent all remain within the civil baseline of Test 1.

\[ \boxed{\text{When the act is done dishonestly or fraudulently in addition to unauthorised access}} \]
Was this answer helpful?
0
Show Solution

Approach Solution -2

Criminal law generally reserves punishment for conduct backed by a guilty state of mind, while civil remedies simply address harm regardless of intent. The IT Act's split between civil contraventions and criminal offences follows this same purpose, and testing each option against it shows which one actually fits.

  1. Monetary damage exceeding a limit: Punishing based purely on the size of the loss, without asking whether the wrongdoer had any guilty intent, would ignore the very reason criminal law exists.
  2. Dishonest or fraudulent intent added to unauthorised access: Building in a requirement of dishonesty or fraud captures exactly the guilty state of mind that justifies criminal punishment, distinguishing a wrongdoer who deliberately sets out to cheat or deceive from one who merely causes accidental harm.
  3. The victim's choice to initiate criminal proceedings: Letting the victim's preference decide whether conduct is criminal would delink criminal liability entirely from the wrongdoer's own state of mind.
  4. Unauthorised access irrespective of intent: Treating access without permission as criminal regardless of intent would criminalise conduct that may be entirely accidental or careless.

Only dishonest or fraudulent intent captures the guilty state of mind that criminal law exists to punish.

Therefore, the correct answer is When the act is done dishonestly or fraudulently in addition to unauthorised access.

Was this answer helpful?
0