Question:medium

The Information Technology Act, 2000, distinguishes between civil liability and criminal liability in case of misuse of computer resources. In which of the following situations would such conduct attract criminal punishment rather than mere compensation?

Show Hint

For IT Act questions remember: \[ \text{Unauthorized Access} = \text{Civil Liability} \] but \[ \text{Unauthorized Access} + \text{Dishonest/Fraudulent Intent} = \text{Criminal Liability} \] Intent is the key examination keyword.
Updated On: Jul 13, 2026
  • When the affected party chooses to initiate criminal proceedings
  • When the act is done dishonestly or fraudulently in addition to unauthorised access
  • When the damage to computer resources exceeds a prescribed monetary limit
  • When access to a computer system is without permission, irrespective of intent
Show Solution

The Correct Option is B

Approach Solution - 1

This question can be answered by tracking how the Act itself is structured: one provision creates civil liability for a list of computer-related acts, and a separate provision escalates the same acts into a crime once a mental element is added.

  1. The civil-liability layer: The Act lists acts such as unauthorised access, downloading data without authority, or introducing a virus, and makes the person liable to pay compensation for these acts regardless of intent. Options describing "access without permission, irrespective of intent" or "damage exceeding a monetary limit" both stay within this civil layer, since neither adds any mental element.
  2. The criminal-liability layer: The Act separately provides that when the very same acts are committed dishonestly or fraudulently, the conduct becomes an offence punishable with imprisonment or fine, not just compensation. This is the layer that actually converts the civil wrong into a crime.
  3. Victim's choice is not a trigger: Nothing in this structure allows a victim's decision to pursue criminal proceedings to itself create criminal liability; the classification of the conduct as a crime depends on the offender's mental state, not on the victim's procedural choice.
  4. Matching the option to the structure: Since only dishonest or fraudulent intent, layered on top of the unauthorised conduct, moves the case from the compensation-only provision into the punishment provision, that is the option describing the true criminal threshold.

Because the Act's own two-layer structure specifically uses dishonest or fraudulent intent as the trigger for criminal liability, the correct answer is that the conduct becomes criminal when it is done dishonestly or fraudulently in addition to unauthorised access.

Was this answer helpful?
0
Show Solution

Approach Solution -2

This question can also be answered using a basic principle that runs through criminal law generally: a wrong becomes a crime, rather than remaining a purely compensable civil wrong, when it is accompanied by a blameworthy state of mind, and testing the four options against that general principle gives the same result.

  1. Access without permission, irrespective of intent: A rule that expressly disregards intent describes what is often called an intent-neutral civil wrong. Criminal liability, by contrast, is almost never intent-neutral for offences of this kind, so an option that removes intent from the equation cannot be describing the criminal threshold.
  2. Damage exceeding a monetary limit: Using a purely quantitative measure like a monetary threshold to distinguish crime from civil wrong would make criminality depend on the scale of harm rather than on the offender's blameworthiness, which is not how this Act, or criminal law generally, draws the civil-criminal line for computer misuse.
  3. Victim's choice to initiate criminal proceedings: Classification of conduct as criminal is a matter of substantive law fixed by the statute at the time of the act, not something that can be altered after the fact by the complainant's procedural preference.
  4. Act done dishonestly or fraudulently in addition to unauthorised access: This option supplies exactly the blameworthy state of mind, dishonest or fraudulent intention, that general criminal law principles require before an act that would otherwise just be a civil wrong is treated as an offence deserving punishment.

Applying the general principle that a guilty mind is what converts a wrong into a crime, the only option that actually supplies that guilty mind is the one requiring dishonest or fraudulent conduct alongside unauthorised access, which is therefore the correct answer.

Was this answer helpful?
0