Mumbai University Solved Question Papers
Penal Laws
Previous Year Question Paper with Solution
LLM · Group 5 Criminal Law and Criminal Administration
2025-26 Examination
munotes.in
Mumbai
Mumbai University Solved Question Papers
Penal Laws
Previous Year Question Paper with Solution
LLM · Group 5 Criminal Law and Criminal Administration
2025-26 Examination
munotes.in
Mumbai
First published on munotes.in on 13 August 2026.
Published by munotes.in, Mumbai.
Model answers written and edited by the munotes.in editorial desk.
Passages from this volume may be quoted, in print, online or by an AI system, with credit: name munotes.in and link to this volume's page. The volume may not be reproduced as a whole. Full terms at munotes.in/content-license.
munotes.in is an independent study resource for students of the University of Mumbai. It is not affiliated with the University of Mumbai, and is not endorsed by it.
The University does not publish an official answer key for this paper. The answers in this volume are model answers, written to show how a full-mark answer is built. They are a study aid, not an authority on what an examiner marked.
The question paper reproduced here is the paper as set by the University of Mumbai at the 2025-26 examination.
The law in these answers is stated as at August 2026, and four changes date most textbooks on this subject. The Indian Penal Code was repealed on 1 July 2024 by the Bharatiya Nyaya Sanhita, 2023, which replaced sedition with section 152; section 124A has been in abeyance since 11 May 2022 and the Supreme Court agreed on 8 August 2025 to examine section 152 itself. Section 66A of the Information Technology Act was finally omitted from the statute book by the Jan Vishwas (Amendment of Provisions) Act, 2023 on 30 November 2023, eight years after Shreya Singhal struck it down, and sections 72 and 72A were decriminalised the same day. The Cyber Appellate Tribunal was abolished by the Finance Act, 2017 on 26 May 2017 and appeals now lie to the Telecom Disputes Settlement and Appellate Tribunal. And section 2(54) of the Juvenile Justice Act, 2015 was substituted on 1 September 2022 to enact Shilpa Mittal.
The questions below are the paper as the University of Mumbai set it at the 2025-26 examination, in the order it was set.
MarksPage
The questions in this volume are the questions asked at the 2025-26 examination, reproduced as the University of Mumbai set them, in the order it set them. Nothing has been reworded, added or left out. Only the answers are ours. See the original question paper.
Duration 3 hours · Total marks 100 · 7 questions answered
How to use this volume
Solve the paper first, under exam conditions and against the clock. Then read the answers here and mark your own. Reading a solution before attempting the question feels productive and teaches very little, because recognising an answer is not the same as being able to write one.
Form 05230, sat 2 March 2026
attempt any four of seven · 100 Marks
Answer
For full marks, cover: the question has three limbs and the examiner has weighted the second and third. A list of the Act's features will earn you a third of the marks. The marks are in showing what section 3 actually requires of a digital signature, how sections 4, 5 and 15 convert that into legal recognition, and which offences in Chapter XI protect the signature. Finish by separating a digital signature from an electronic signature, because section 3A made the Act technology neutral in 2009 and most answers still write as though it had not.
The Information Technology Act, 2000 received assent on 9 June 2000 and was brought into force on 17 October 2000. Its preamble traces it to the United Nations General Assembly resolution A/RES/51/162 of 30 January 1997, which commended the UNCITRAL Model Law on Electronic Commerce to member States. India was among the first countries to legislate on that model.
The problem the Act solves is narrow and practical. Indian law was written for paper. A contract had to be signed, a document had to be filed, a record had to be retained, and every one of those words assumed something you could hold. The Act does not rewrite the law of contract or evidence. It supplies a rule of equivalence: what the older law demands on paper is satisfied electronically if the Act's conditions are met.
Legal recognition of electronic records and signatures. Section 4 provides that where any law requires information to be in writing, that requirement is satisfied if the information is rendered in an electronic form and accessible for subsequent reference. Section 5 does the same for signatures. Section 7 covers retention of records and section 8 the publication of rules and notifications in an Electronic Gazette.
Electronic governance. Sections 6, 6A and 7A allow filing, issue and payment in electronic form and permit the Government to authorise service providers to deliver services. Section 9 is the safeguard: nothing in sections 6, 7 and 8 confers a right to insist that any Ministry or department accept a document in electronic form.
Attribution, acknowledgement and despatch. Sections 11 to 13 fix when an electronic record is attributed to the originator, when receipt is acknowledged, and the time and place of despatch and receipt. These are the rules that decide where an electronic contract is made, and they matter for jurisdiction.
Regulation of Certifying Authorities. Chapter VI, sections 17 to 34, creates the Controller of Certifying Authorities, licenses the authorities who issue certificates, and gives the Controller powers of investigation and of access to computers and data. Chapter VII governs the certificates themselves and Chapter VIII the duties of subscribers, including the duty in section 42 to keep the private key confidential.
Penalties, adjudication and appeal. Chapter IX creates civil liability. Section 43 makes a person who damages a computer or copies data without permission liable to pay compensation, and section 43A makes a body corporate that is negligent with sensitive personal data liable in damages. Section 46 gives an adjudicating officer jurisdiction where the claim does not exceed five crore rupees. Chapter X provides the appeal, and section 62 a further appeal to the High Court within sixty days.
Offences. Chapter XI, sections 65 to 78, creates the criminal offences. Chapter XII, section 79, gives an intermediary a conditional exemption from liability, and section 81 gives the Act overriding effect. Section 75 extends the Act to offences committed outside India where a computer or computer system located in India is involved.
What the Act does not touch. The First Schedule, read with section 1(4), excludes negotiable instruments other than a cheque, powers of attorney, trusts, wills and contracts for the sale or conveyance of immovable property. A will cannot be made electronically in India, and that exclusion has survived every amendment.
Section 2(1)(p) defines a digital signature as authentication of an electronic record by a subscriber by means of an electronic method or procedure in accordance with section 3. The definition is therefore empty until you read section 3, which is where the technical requirement sits.
Section 3(2) requires authentication to be effected by the use of an asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record. Two limbs follow. Section 3(3) says that any person can verify the record using the public key of the subscriber. Section 3(4) says that the private key and the public key are unique to the subscriber and constitute a functioning key pair.
The mechanism, put plainly, is this. The record is passed through a hash function to produce a short digest. The signer encrypts that digest with a private key which only the signer holds. Anyone who has the signer's public key, published in a certificate issued by a licensed Certifying Authority under section 35, can decrypt the digest and re-run the hash. If the two digests match, the record has not been altered and it was signed by the holder of the private key. Section 3 therefore delivers both authentication and integrity in one operation.
Section 15 adds a further tier. A secure electronic signature is one where the signature creation data was, at the time of affixing the signature, under the exclusive control of the signatory and no other person, and was stored and affixed in such exclusive manner as may be prescribed. The Explanation says that in the case of a digital signature the signature creation data means the private key of the subscriber. A secure signature is what the law of evidence attaches a presumption to: section 85B of the old Evidence Act, now section 86 of the Bharatiya Sakshya Adhiniyam, 2023.
The Act as passed in 2000 was tied to one technology. Only public key cryptography counted. The Information Technology (Amendment) Act, 2008, which came into force on 27 October 2009, inserted section 3A and recognised an electronic signature, defined in section 2(1)(ta), as authentication by any technique specified in the Second Schedule. The Central Government may add to that Schedule by notification under section 3A(2), and has done so: the Second Schedule now carries e-authentication using Aadhaar or other e-KYC services, which is how the great majority of Indian documents are signed today.
| Digital signature | Electronic signature | |
|---|---|---|
| Source | Section 3 | Section 3A, inserted in 2009 |
| Technique | Asymmetric crypto system and hash function only | Any technique in the Second Schedule |
| Governing definition | Section 2(1)(p) | Section 2(1)(ta) |
| Certificate | Issued by a licensed Certifying Authority under section 35 | Same, plus the reliability conditions in section 3A(1) |
| Amendment by notification | Not possible without amending section 3 | Second Schedule amendable under section 3A(2) |
| Typical Indian use | Company filings, income tax, tenders | Aadhaar e-sign for everyday documents |
The relationship is one of inclusion, not replacement. Section 2(1)(ta) makes a digital signature one species of electronic signature, so everything the Act says about an electronic signature applies to a digital signature as well.
Section 5 is the operative recognition. Where any law requires information to be authenticated by affixing a signature, that requirement is satisfied if the information is authenticated by an electronic signature affixed in the prescribed manner. Section 10 empowers the Central Government to prescribe the type of signature, the manner of affixing it and the procedure for identifying the signatory.
Recognition also reached older statutes. Section 93 of the IT Act, read with its Third Schedule, substituted section 2(8) of the Bankers' Books Evidence Act, 1891 and inserted section 2A into it with effect from 17 October 2000, so that a printout of a bank entry became a certified copy if accompanied by the two certificates section 2A prescribes. Sections 91 to 94 of the IT Act and its Third and Fourth Schedules were themselves omitted as spent by the 2008 amendment with effect from 27 October 2009, but the amendments they made stand in the amended Acts.
Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473, is the case to cite for how recognition is proved. The appellant sought to prove election propaganda recorded on CDs. The Supreme Court held that an electronic record produced as secondary evidence is inadmissible unless accompanied by the certificate under section 65B(4) of the Evidence Act, and that oral evidence cannot cure its absence. The Court expressly overruled the contrary view in State (NCT of Delhi) v. Navjot Sandhu, (2005) 11 SCC 600. The bearing on this question is that legal recognition under section 5 is not self-executing: the Act makes the signature valid, and the law of evidence still decides whether the record carrying it is admissible.
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, completed the picture. A three-judge Bench held that the section 65B(4) certificate is a mandatory condition precedent, resolved the conflict created by Shafhi Mohammad v. State of Himachal Pradesh, (2018) 2 SCC 801, and held that where a party cannot produce the certificate because the device is in another's control, the court may summon it. The requirement now sits in section 63 of the Bharatiya Sakshya Adhiniyam, 2023, which added a schedule for the certificate itself.
Trimex International FZE Ltd. v. Vedanta Aluminium Ltd., (2010) 3 SCC 1, shows the commercial consequence. The parties negotiated a supply of bauxite entirely by email and no formal contract was ever executed. The Supreme Court held that a concluded contract had come into existence, because unconditional acceptance had been communicated, and that the absence of a signed paper document did not affect it. Legal recognition of the electronic record is what allowed the Court to treat the exchange as the contract.
The signature scheme would be worthless if the key and the certificate were not protected, and Chapter XI supplies that protection.
Section 65 punishes knowing or intentional concealment, destruction or alteration of computer source code required to be kept by law, with imprisonment up to three years or fine up to two lakh rupees or both. Section 66 punishes any act referred to in section 43 done dishonestly or fraudulently, with imprisonment up to three years or fine up to five lakh rupees or both. Reading section 66 with section 43 is the standard route to prosecuting unauthorised access to a signing key.
Section 66C is the identity theft provision and is drafted directly at this scheme. It punishes fraudulent or dishonest use of the electronic signature, password or any other unique identification feature of another person, with imprisonment up to three years and fine up to one lakh rupees. Section 66D punishes cheating by personation using a computer resource on the same scale.
Section 71 punishes misrepresentation or suppression of a material fact made to the Controller or a Certifying Authority to obtain a licence or a certificate. Section 73 punishes publishing an electronic signature certificate false in material particulars, knowing that the Certifying Authority did not issue it, that the subscriber did not accept it, or that it has been revoked or suspended. Section 74 punishes creation, publication or making available of a certificate for any fraudulent or unlawful purpose. All three carry imprisonment up to two years or fine up to one lakh rupees or both.
One provision that every textbook still describes as an offence is no longer one. Section 72, breach of confidentiality and privacy by a person who secured access under a power conferred by the Act, and section 72A, disclosure in breach of a lawful contract, were both decriminalised by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023. Imprisonment was removed from each. Section 72 now attracts a penalty which may extend to five lakh rupees and section 72A a penalty which may extend to twenty five lakh rupees, and the marginal heading of section 72A was changed from Punishment to Penalty to make the shift explicit.
Two procedural sections complete the chapter. Section 77B makes every offence punishable with three years imprisonment bailable, and section 78 requires investigation by a police officer not below the rank of Inspector.
The criticism begins with enforcement architecture. The Cyber Appellate Tribunal, established under section 48, went without a Chairperson from 2011 and heard nothing. The Finance Act, 2017 omitted sections 49 to 56 with effect from 26 May 2017 and transferred the jurisdiction to the Telecom Disputes Settlement and Appellate Tribunal. A specialist tribunal for a specialist statute was allowed to die of a vacancy and was then folded into a telecom tribunal.
The second criticism is drafting by overreach. Section 66A punished the sending of offensive messages in language so vague that Shreya Singhal v. Union of India, (2015) 5 SCC 1, struck it down as violating Article 19(1)(a), holding that the terms used were open ended and undefined and that the section did not fall within any of the eight subjects in Article 19(2). The Court upheld section 69A, whose blocking power is hedged with reasons and safeguards, and read down section 79. Even after that judgment, prosecutions under section 66A continued for years because the text stayed printed in the Act; it was finally omitted only by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023.
The third criticism is that the civil remedy has not kept pace. Section 43A, the only compensation provision for a data breach, is due to be omitted when section 44(2) of the Digital Personal Data Protection Act, 2023 commences on 13 May 2027, and it will be replaced by a penalty regime that pays the State rather than the individual whose data was lost.
Conclusion. The Information Technology Act, 2000 is an enabling statute before it is a penal one. Its central achievement is the rule of equivalence in sections 4 and 5, and the digital signature under section 3 is the device that makes that equivalence safe, because an asymmetric key pair and a hash function deliver authentication and integrity together in a way a scanned image of a signature never can. Section 3A then freed the scheme from a single technology, which is why an Aadhaar based e-sign is as good in law today as a cryptographic one. The offences in sections 65, 66, 66C, 66D, 71, 73 and 74 exist to protect that chain of trust rather than to police content, and where the Act has failed it has failed on the enforcement side, in an appellate tribunal allowed to lapse and a struck down section left on the statute book for eight years.
The rest of the answers
You have read the question paper and its first answer in full. Buy the solved papers once and you can read every answer of every solved paper in this semester.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or solved papers only: ₹499
Or notes only: ₹499
The question paper itself stays free, as does the syllabus and module one of every subject.
Found an error in this volume? Report it and we will check it against the paper.