Advanced Search Options : ❯
Section 45 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 45 establishes a residuary penalty for contravention of rules, regulations, directions or orders where no separate penalty is prescribed. A penalty not exceeding one lakh rupees may be imposed in addition to compensation for the affected person. Compensation is capped at ten lakh rupees for an intermediary, company or body corporate, and at one lakh rupees for any other person.
Section 44 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 44 of the Information Technology Act, 2000 imposes penalties for failures to furnish required documents, returns or reports, file returns or provide information within prescribed time limits, and maintain books of account or records. Non-furnishing may attract a penalty up to fifteen lakh rupees for each failure, while delayed filings and record-keeping failures may attract daily penalties up to fifty thousand rupees and one lakh rupees respectively during the continuing default.
Section 43 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 43 imposes compensatory liability on a person who, without permission of the owner or person in charge, interferes with a computer, computer system, computer network or computer resource. Covered conduct includes unauthorised access, data extraction, introduction of contaminants or viruses, damage or disruption, denial of authorised access, facilitating prohibited access, manipulation of service charges, harmful alteration of information, and intentional theft, concealment, destruction or alteration of source code to cause damage.
Section 42 of the Information Technology Act, 2000 - Indian Laws - Acts
Subscribers must exercise reasonable care to retain control of the private key corresponding to the public key recorded in their Digital Signature Certificate and prevent its disclosure. If the private key is compromised, they must notify the Certifying Authority without delay in the prescribed manner. Liability continues until the Certifying Authority receives notice of the compromise.
Section 41 of the Information Technology Act, 2000 - Indian Laws - Acts
Acceptance of a Digital Signature Certificate is deemed where a subscriber publishes or authorises publication to persons, places it in a repository, or otherwise manifests approval. By accepting it, the subscriber certifies to reasonable relying persons that they hold and are entitled to hold the corresponding private key, and that representations, relevant material information, and certificate information within their knowledge are true.
Section 40 of the Information Technology Act, 2000 - Indian Laws - Acts
Where a subscriber accepts a Digital Signature Certificate whose public key corresponds to the subscriber's private key intended for inclusion in that certificate, the subscriber must generate the corresponding key pair by applying the security procedure. This creates a subscriber obligation concerning cryptographic key generation for an accepted Digital Signature Certificate.
Section 39 of the Information Technology Act, 2000 - Indian Laws - Acts
Notice of suspension or revocation of a Digital Signature Certificate must be published by the Certifying Authority in the repository identified in the certificate for that purpose. Where more than one repository is identified, notice must be published in each specified repository.
Section 38 of the Information Technology Act, 2000 - Indian Laws - Acts
Digital Signature Certificates may be revoked on request, death, insolvency, dissolution or winding up of a subscriber, false or concealed material information, failure to meet issuance requirements, or compromise of the issuing authority's private key or security system affecting certificate reliability. The subscriber must receive an opportunity of being heard before revocation, and the revocation must then be communicated to the subscriber.
Section 37 of the Information Technology Act, 2000 - Indian Laws - Acts
A Digital Signature Certificate may be suspended on the request of the named subscriber or a duly authorised person, or where suspension is considered necessary in the public interest. Suspension beyond fifteen days requires that the subscriber be given an opportunity of being heard. Following suspension, the Certifying Authority must communicate the suspension to the subscriber.
Section 36 of the Information Technology Act, 2000 - Indian Laws - Acts
Issuance of a Digital Signature Certificate requires certification of statutory compliance, publication or availability of the certificate to a relying person, and subscriber acceptance. The subscriber must hold a private key corresponding to the listed public key; the private key must create a digital signature and the public key must verify it. The key pair must function properly, certificate information must be accurate, and no known material fact may adversely affect the reliability of these representations.
Section 35 of the Information Technology Act, 2000 - Indian Laws - Acts
Applications for electronic signature Certificates must be made in the prescribed form, with the prescribed fee and a certification practice statement or regulatory-compliant statement of particulars. The Certifying Authority may consider the accompanying statement and conduct enquiries before granting or rejecting a certificate. Any rejection must record written reasons and follow a reasonable opportunity for the applicant to show cause against the proposed refusal.
Section 34 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 34 requires every Certifying Authority to disclose its electronic signature certificate, relevant certification practice statement, certificate revocation or suspension, and material adverse facts affecting certificate reliability or service capacity. Where events or situations may adversely affect computer-system integrity or certificate conditions, the Authority must reasonably notify likely affected persons or follow its certification practice statement procedure.
Section 33 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence surrender is immediately required when a Certifying Authority's licence is suspended or revoked. Failure to surrender the licence to the Controller is an offence by the person in whose favour the licence was issued and attracts a penalty that may extend to five lakh rupees. The monetary penalty framework replaced the earlier sanction of imprisonment, fine, or both from 30 November 2023.
Section 32 of the Information Technology Act, 2000 - Indian Laws - Acts
Every Certifying Authority must conspicuously display its licence at the premises where it carries on business. This requirement ensures that the authority's authorisation is visibly available at its operational location.
Section 31 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities bear responsibility for ensuring that every person employed or otherwise engaged by them complies, during employment or engagement, with the Information Technology Act, 2000 and all rules, regulations, and orders made under it. The obligation extends beyond direct employees to all engaged persons and requires internal compliance oversight in relation to their work.
Section 30 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities must use secure hardware, software and procedures, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of Electronic Signature Certificates, publish information on their practices, certificates and current certificate status, and comply with additional standards prescribed by regulations.
Section 29 of the Information Technology Act, 2000 - Indian Laws - Acts
The Controller or an authorised person may access computer systems, connected apparatus, data, and related material when there is reasonable cause to suspect a Chapter contravention. Access may be used to search for information or data and operates without prejudice to powers under section 69(1). By order, persons responsible for or involved in operating the relevant system, data, apparatus, or material may be required to provide reasonable technical and other assistance necessary for access and search.
Section 28 of the Information Technology Act, 2000 - Indian Laws - Acts
Investigation of contraventions under the Information Technology Act, 2000, its rules and regulations is undertaken by the Controller or an authorised officer. The investigating authority exercises powers corresponding to those available to Income-tax authorities, subject to the limitations applicable to those powers.
Section 27 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 27 of the Information Technology Act establishes a delegation mechanism for the regulation of Certifying Authorities. The Controller may, by written authorisation, empower a Deputy Controller, Assistant Controller, or other officer to exercise any of the Controller's powers under that Chapter. Written authorisation enables designated officers to exercise the Controller's Chapter-specific powers.
Section 26 of the Information Technology Act, 2000 - Indian Laws - Acts
Suspension or revocation of a Certifying Authority's licence requires the Controller to publish notice in the Controller's database and, where specified, in all relevant repositories. The database must be available through a website accessible round the clock. The Controller may also publicise its contents through appropriate electronic or other media.