munotes®

LLM Group 3 Law of Intellectual Property and Information Technology Information Technology Cyber Laws 2015 Question Paper with Solutions

Mumbai University Solved Question Papers

Information Technology Cyber Laws

Previous Year Question Paper with Solution

LLM · Group 3 Law of Intellectual Property and Information Technology

2015 Examination

munotes.in

Mumbai

munotes.in

First published on munotes.in on 14 September 2026.

Published by munotes.in, Mumbai.

Model answers written and edited by the munotes.in editorial desk.

Passages from this volume may be quoted, in print, online or by an AI system, with credit: name munotes.in and link to this volume's page. The volume may not be reproduced as a whole. Full terms at munotes.in/content-license.

munotes.in is an independent study resource for students of the University of Mumbai. It is not affiliated with the University of Mumbai, and is not endorsed by it.

The University does not publish an official answer key for this paper. The answers in this volume are model answers, written to show how a full-mark answer is built. They are a study aid, not an authority on what an examiner marked.

The question paper reproduced here is the paper as set by the University of Mumbai at the 2015 examination.

The law in these answers is stated as at September 2026, and five changes date every textbook on this subject. Criminal law is stated under the Bharatiya Nyaya Sanhita and electronic evidence under the Bharatiya Sakshya Adhiniyam, both in force since 1 July 2024, with the old Penal Code and Evidence Act sections given alongside wherever a question or a decided case uses them. Section 66A was omitted with effect from 30 November 2023, the day on which sections 72 and 72A became civil penalties. The Cyber Appellate Tribunal ceased to exist on 26 May 2017, and questions on it are answered on the Telecom Disputes Settlement and Appellate Tribunal. Intermediaries are answered on the 2021 Rules as amended to 20 February 2026. And section 43A is treated as live law until the Digital Personal Data Protection Act, 2023 omits it on 13 May 2027.

munotes.in ii
munotes.in iii
munotes.in iv

The Paper as Set

The questions in this volume are the questions asked at the 2015 examination, reproduced as the University of Mumbai set them, in the order it set them. Nothing has been reworded, added or left out. Only the answers are ours. See the original question paper.

Duration 3 hours  ·  Total marks 100  ·  14 questions answered

How to use this volume

Solve the paper first, under exam conditions and against the clock. Then read the answers here and mark your own. Reading a solution before attempting the question feels productive and teaches very little, because recognising an answer is not the same as being able to write one.

munotes.in v

SECTION I

QP Code 27232, printer's form BB-Con. 4117-15, the first paper on the scan, seven questions 100 Marks

munotes.in 1

1.What were the key amendements brought by Information Technology (Amendment) Act, 2008 in Indian information technology law? What was the purpose of these amendements?[25]

Answer

For full marks, cover: two questions. The KEY AMENDMENTS, which are too many to list one by one, so group them: technology-neutral electronic signatures; electronic commerce and governance (sections 6A, 7A, 10A, the First Schedule); data protection and privacy (sections 43A, 66E, 72A); a graded set of cyber offences (section 66 rewritten, sections 66A to 66F, 67A to 67C) with new procedure (sections 77A, 77B, 78, 84B, 84C); State powers and security institutions (sections 69, 69A, 69B, 70, 70A, 70B, 84A); intermediaries (sections 2(1)(w), 79); the Tribunal; and consequential amendments to the Penal Code and Evidence Act. Then the PURPOSE of each group, tied to its cause (technology change, the Bazee.com prosecution, data security concerns, the Mumbai attacks, the UNCITRAL Model Law on Electronic Signatures). Close with an assessment and later history: Shreya Singhal (2015), the Finance Act, 2017, the Jan Vishwas Act, 2023 and the Digital Personal Data Protection Act, 2023. Use Avnish Bajaj, Google India v. Visaka, Shreya Singhal and PUCL.

munotes.in 2

The amending Act and why it came

The Information Technology (Amendment) Act, 2008 (Act 10 of 2009) was passed by Parliament in December 2008, received assent in February 2009 and came into force on 27 October 2009. It is the largest change the principal Act has undergone: most of the provisions studied today in the chapters on offences, intermediaries and cyber security were put there by it.

The Act of 2000 had been an electronic commerce statute. It gave legal recognition to electronic records and digital signatures, set up the Controller and Certifying Authorities, and contained a handful of offences. By 2008 four developments pressed for change. The internet had become a mass medium of mobile phones, social networks, marketplaces and online banking. Decided cases had exposed gaps. Business, especially the outsourcing industry serving foreign clients, needed assurance that personal data would be protected. And an Expert Committee constituted by the Government had reported in 2005 recommending many of the changes. The attacks on Mumbai in November 2008 then added urgency, and the Bill was passed within weeks, with little debate, a criticism that has stayed with it.

munotes.in 3

The gap the courts had shown. In Avnish Bajaj v. State (NCT of Delhi), Delhi High Court, 29 May 2008, the managing director of the company running the Baazee.com auction site was prosecuted because a student had listed an obscene video clip for sale on the site. The Court found a prima facie case under section 67 read with section 85 against him while holding that the Penal Code imposed no vicarious liability on directors, and it observed that Indian law was not adequate to regulate pornography on the internet. The old section 79 gave a "network service provider" only a defence, which it had to prove, against liability under the IT Act alone.

The key amendments, grouped

1. From digital signature to electronic signature. The Act had recognised only the digital signature, made with an asymmetric crypto system and hash function (section 3). The amendment inserted section 2(1)(ta) (electronic signature) and section 2(1)(tb) (Electronic Signature Certificate), section 3A, which recognises any reliable electronic signature or authentication technique listed in the Second Schedule, substituted section 15 (secure electronic signature), added section 40A (duties of subscribers), and replaced "digital signature" with "electronic signature" through most of the Act.

2. Electronic commerce and electronic governance.

munotes.in 4
  • Section 10A: a contract is not unenforceable solely because proposals, acceptances or revocations were expressed electronically.
  • Section 6A: Government may authorise private service providers to deliver public services electronically and collect service charges.
  • Section 7A: where audit of documents is required by law, it applies equally to documents kept electronically.
  • Section 1(4) was substituted to exclude the documents listed in a new First Schedule, which the Central Government may amend by notification.

3. Data protection and privacy.

  • Section 43A: a body corporate that is negligent in implementing reasonable security practices for sensitive personal data and causes wrongful loss must pay compensation.
  • Section 72A: disclosing personal information obtained under a lawful contract, without consent and with intent to cause or knowledge of likely wrongful loss or gain, was made an offence.
  • Section 66E: capturing, publishing or transmitting images of a person's private area without consent.
munotes.in 5

4. A graded set of cyber offences.

  • Section 66 was rewritten: the offence headed "hacking with computer system" was replaced by "computer related offences", punishing any act in section 43 done dishonestly or fraudulently (up to three years or fine up to five lakh rupees).
  • Section 43 was widened with clauses (i) (destroying, deleting or altering information) and (j) (stealing or altering source code), and the one crore rupee cap on compensation was removed; section 46(1A) gave adjudicating officers jurisdiction up to five crore rupees.
munotes.in 6
  • New offences: 66A (offensive messages), 66B (receiving stolen computer resources), 66C (identity theft), 66D (cheating by personation using a computer resource), 66F (cyber terrorism, life imprisonment), 67A (sexually explicit material), 67B (child sexual abuse material, including browsing and downloading and enticing children online), and 67C (preservation of information by intermediaries); section 67 was recast with higher punishments.
  • Procedure: section 77A (compounding of offences up to three years, excluding those affecting the socio-economic conditions of the country or committed against a child or a woman), section 77B (offences of three years made bailable, three years and above cognizable), sections 78 and 80 (investigation and search by an Inspector instead of a Deputy Superintendent of Police), section 84B (abetment) and section 84C (attempt).

5. State powers and cyber security institutions.

  • Section 69 was substituted: the original section let the Controller direct interception; the new one lets the Central or State Government direct interception, monitoring or decryption on stated grounds, including investigation of any offence, with a duty on subscribers and intermediaries to assist.
munotes.in 7
  • Section 69A: power to block public access to information, with procedure in the 2009 Blocking Rules.
  • Section 69B: monitoring and collection of traffic data for cyber security.
  • Section 70 was amended to protect critical information infrastructure; section 70A created a national nodal agency (now the National Critical Information Infrastructure Protection Centre); section 70B made CERT-In the national incident response agency with power to issue directions; section 84A empowered the Government to prescribe modes of encryption.

6. Intermediaries. The definition of intermediary in section 2(1)(w) was substituted to name telecom, network and internet service providers, web hosts, search engines, payment sites, auction sites, marketplaces and cyber cafes; section 79 was substituted to give an intermediary a conditional exemption from liability under any law for third party information, if it does not initiate, select or modify transmissions, observes due diligence and removes unlawful material on actual knowledge.

munotes.in 8

7. The Tribunal and administration. The Cyber Regulations Appellate Tribunal became the Cyber Appellate Tribunal, with a Chairperson and Members and Benches (sections 48 to 52D); the Controller's office was enlarged; section 79A provided for notified Examiners of Electronic Evidence; and section 20 (the Controller as repository of all certificates) was omitted. A proviso to section 81 preserved rights under the Copyright Act and the Patents Act.

8. Consequential amendments. The Penal Code was amended, among other things, to add section 4(3), extending it to any person outside India committing an offence targeting a computer resource located in India (now section 1(5)(c) of the Bharatiya Nyaya Sanhita, 2023), and the Evidence Act gained section 45A, making the opinion of an Examiner of Electronic Evidence a relevant fact (now section 39(2) of the Bharatiya Sakshya Adhiniyam, 2023).

The purposes of the amendments

munotes.in 9
GroupPurpose
Electronic signaturesTechnology neutrality: to free the law from one technology, allow cheaper and newer methods such as Aadhaar-based eSign, and follow the approach of the UNCITRAL Model Law on Electronic Signatures, 2001
E-commerce and e-governanceLegal certainty for online contracts and wider e-governance through private service delivery and electronic audit
Data protectionTrust: to give data subjects a remedy and reassure foreign clients of Indian businesses, in the absence of a data protection statute
Graded offences and procedureTo reach new forms of cyber crime (identity theft, phishing, voyeurism, child sexual abuse material) with offences matched to harm, and to make enforcement practical (Inspector-level investigation, bail and compounding for lesser offences)
munotes.in 10
GroupPurpose
State powers and institutionsNational security after the Mumbai attacks: lawful interception, blocking, traffic monitoring, protection of critical infrastructure and coordinated incident response
IntermediariesBalance: to protect internet businesses from liability for users' content they do not control, while making them act against unlawful content, answering the problem exposed by the Bazee.com prosecution
Tribunal and evidenceSpecialised adjudication and expert evidence for technical disputes

The intermediary purpose was confirmed later. In Google India Private Ltd. v. Visaka Industries, (2020) 4 SCC 162, decided on 10 December 2019, a manufacturer prosecuted Google India for defamatory articles posted in 2008 on a group hosted on Google's platform; the Supreme Court held that the old section 79, which protected a network service provider only against liability under the IT Act, was no defence to criminal defamation under the Penal Code. The substituted section 79 was designed precisely to extend the shield to liability under any law.

munotes.in 11

The surveillance purpose raised its own concern. Interception of telephones had been controlled since People's Union for Civil Liberties v. Union of India, (1997) 1 SCC 301, where the Supreme Court held that tapping infringes the right to privacy under article 21 and required orders by the Home Secretary, recorded reasons, time limits and review by a committee. The 2009 Rules under sections 69 and 69A adopted that executive model, but without any judicial authorisation, which critics point to after the recognition of privacy as a fundamental right in 2017.

Assessment and later history

What the amendment achieved. It converted a narrow e-commerce statute into a general cyber law: technology-neutral signatures, a contract rule, a data protection remedy, a graded penal code for computer crime, an intermediary regime and cyber security institutions.

What went wrong.

munotes.in 12
  1. Section 66A was drafted too widely. In Shreya Singhal v. Union of India, (2015) 5 SCC 1, the Supreme Court struck down section 66A, which punished messages that were "grossly offensive", "menacing" or sent to cause "annoyance" or "inconvenience", because those terms were vague, had no proximate relation to the grounds in article 19(2) and chilled protected speech; it also read down section 79(3)(b) so that actual knowledge means a court order or government notification. Section 66A was finally omitted with effect from 30 November 2023 by the Jan Vishwas (Amendment of Provisions) Act, 2023.
  2. Punishments were light and most offences bailable, which critics argued weakened deterrence.
  3. The Cyber Appellate Tribunal failed in practice, lying non-functional from 2011, and the Finance Act, 2017 transferred its jurisdiction to the Telecom Disputes Settlement and Appellate Tribunal from 26 May 2017.
munotes.in 13
  1. Decriminalisation followed: from 30 November 2023 the Jan Vishwas Act converted sections 72 and 72A into penalties (up to five lakh and twenty-five lakh rupees), raised penalties under sections 44 and 45, and made section 67C a penalty.
  2. Data protection outgrew section 43A: the Digital Personal Data Protection Act, 2023 will omit section 43A on 13 May 2027, when its core provisions commence.
munotes.in 14

Conclusion. The Information Technology (Amendment) Act, 2008, in force from 27 October 2009, remade the 2000 Act: it introduced technology-neutral electronic signatures (sections 3A, 2(1)(ta), 15), secured electronic contracts and governance (sections 10A, 6A, 7A and the First Schedule), created data protection remedies (sections 43A, 72A, 66E), replaced the single hacking offence with a graded set of offences and practical procedure (sections 66, 66A to 66F, 67A to 67C, 77A, 77B, 78), armed the State with interception, blocking and monitoring powers and cyber security institutions (sections 69 to 70B), and gave intermediaries a conditional safe harbour (sections 2(1)(w), 79). Its purposes were to keep the law technology neutral, give certainty to electronic commerce, build trust in data handling, reach new cyber crimes, protect national security after the Mumbai attacks and balance the liability of intermediaries, answering gaps shown in Avnish Bajaj and later confirmed in Google India v. Visaka. Its excesses were corrected in Shreya Singhal, and its institutions and penalties have since been reshaped by the Finance Act, 2017, the Jan Vishwas Act, 2023 and the Digital Personal Data Protection Act, 2023.

munotes.in 15

The rest of the answers

The first answer is free. The rest are part of LL.M. Intellectual Property and Information Technology Semester 3.

You have read the paper as it was set and the first model answer in full. The remaining answers come with the bundle, along with every other solved paper for this semester.

See the semester for ₹798 Already bought it? Sign in

Or just the solved papers: ₹499

The question paper itself stays free, as does the syllabus and module one of every subject.

Report or request

Found an error in this volume? Report it and we will check it against the paper.

Done!