Advanced Search Options : ❯
Section 26 of the Information Technology Act, 2000
Suspension or revocation of a Certifying Authority's licence requires the Controller to publish notice in the maintained database and, where repositories are specified, in each repository. The database carrying the notice must remain accessible through a website on a round-the-clock basis. Further publicity may be given through appropriate electronic or other media where considered necessary.
Section 25 of the Information Technology Act, 2000
Licensing control of Certifying Authorities permits the Controller to revoke a licence for materially false application particulars, breach of licence conditions, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements. Revocation requires a reasonable opportunity to show cause. Where reasonable cause exists for revocation, the licence may be suspended pending inquiry; suspension beyond ten days also requires such opportunity. No electronic signature certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000
Licensing of Certifying Authorities requires the Controller to consider the documents accompanying a licence application and other appropriate factors before granting or rejecting it. Rejection is subject to procedural fairness, and cannot occur unless the applicant has been given a reasonable opportunity to present its case.
Section 23 of the Information Technology Act, 2000
Renewal of a Certifying Authority licence requires an application in the prescribed form, accompanied by the prescribed fee subject to a maximum of five thousand rupees, and filed at least forty-five days before expiry of the licence validity period. The Central Government prescribes the applicable form and fee within that limit.
Section 22 of the Information Technology Act, 2000
Applications for a licence must be made in the form prescribed by the Central Government and accompanied by a certification practice statement, applicant-identification procedures, the prescribed fee subject to the statutory ceiling, and other prescribed documents.
Section 21 of the Information Technology Act, 2000
Licensing for the issuance of electronic signature Certificates is available upon application to the Controller, subject to prescribed eligibility requirements. Applicants must meet standards relating to qualifications, expertise, manpower, financial resources and infrastructure. Licences are valid for the prescribed period, are not transferable or heritable, and remain subject to regulatory conditions.
Section 20 of the Information Technology Act, 2000
Section 20 concerning the Controller's role as repository for Digital Signature Certificates was omitted with effect from 27 October 2009. Before omission, the Controller was required to retain issued Digital Signature Certificates, use secure systems and procedures against intrusion and misuse, comply with prescribed security standards, and maintain a computerised database of public keys accessible to the public.
Section 19 of the Information Technology Act, 2000
Recognition of foreign Certifying Authorities is subject to regulatory conditions and restrictions, prior governmental approval, and notification in the Official Gazette. A recognised foreign Certifying Authority may function for statutory purposes, and its electronic signature Certificates are valid for those purposes. Recognition may be revoked upon contravention of attached conditions or restrictions, provided written reasons are recorded and revocation is notified in the Official Gazette.
Section 18 of the Information Technology Act, 2000
Section 18 empowers the Controller to supervise Certifying Authorities, certify public keys, prescribe operational standards, and regulate their business conditions, employee qualifications, electronic signature Certificates, advertising materials, accounts, and auditors. The Controller may regulate electronic systems and subscriber dealings, resolve conflicts of interest, lay down duties, and maintain a publicly accessible database of prescribed disclosure records for every Certifying Authority.
Section 17 of the Information Technology Act, 2000
Section 17 empowers the Central Government to appoint a Controller of Certifying Authorities, along with Deputy Controllers, Assistant Controllers, officers and employees, through notification in the Official Gazette. The Controller functions under governmental control and direction, while Deputy and Assistant Controllers perform assigned functions under the Controller's superintendence. Service qualifications and conditions are prescribed by the Central Government, which also determines the locations of head and branch offices. The Office of the Controller is required to have a seal.
Section 16 of the Information Technology Act, 2000
Security procedures and practices for secure electronic records and secure electronic signatures may be prescribed for the purposes of sections 14 and 15. Their formulation must take account of commercial circumstances, the nature of relevant transactions, and other related factors considered appropriate, linking electronic security measures to transaction-specific operational conditions.
Section 15 of the Information Technology Act, 2000
An electronic signature is secure where its signature creation data is exclusively controlled by the signatory when affixed, and is stored and affixed in the prescribed exclusively controlled manner. In relation to a digital signature, signature creation data means the subscriber's private key.
Section 14 of the Information Technology Act, 2000
Secure electronic record status attaches where a security procedure is applied to an electronic record at a specific point in time. The record is deemed secure from that point until verification, defining the temporal period during which the secure-record classification operates. The classification is linked to application of the security procedure and its continuation until verification.
Section 13 of the Information Technology Act, 2000
Despatch occurs when an electronic record enters a computer resource outside the originator's control. Where the addressee has designated a computer resource, receipt occurs on entry into that resource; where the record is sent to another computer resource of the addressee, receipt occurs upon retrieval. Electronic records are deemed dispatched at the originator's place of business and received at the addressee's place of business, irrespective of the physical location of the computer resource.
Section 12 of the Information Technology Act, 2000
Where the originator makes receipt of acknowledgment a condition for the electronic record to be binding, failure to receive acknowledgment results in the record being deemed never sent. Where no such condition is stipulated, the originator may, after non-receipt within the applicable period, notify the addressee and prescribe a reasonable further period. If acknowledgment remains outstanding, the originator may treat the electronic record as never sent.
Section 11 of the Information Technology Act, 2000
Attribution of an electronic record to its originator arises where the originator personally sends it, where it is sent by a person authorised to act for the originator in relation to that record, or where an information system programmed by or for the originator automatically transmits it.
Section 10 of the Information Technology Act, 2000
Central Government rulemaking power for electronic signatures permits prescription of the types of electronic signature, the manner and format in which they are affixed, and procedures facilitating identification of the person affixing an electronic signature. Rulemaking may also establish processes ensuring the integrity, security and confidentiality of electronic records or payments, and address matters necessary to give legal effect to electronic signatures.
Section 9 of the Information Technology Act, 2000
Section 9 does not give any person a right to compel a Ministry, government department, statutory authority, or government-controlled or funded body to accept, issue, create, retain, or preserve documents as electronic records, or to conduct monetary transactions electronically. Electronic governance provisions operate without mandatory electronic acceptance or transaction obligations.
Section 8 of the Information Technology Act, 2000
Electronic Gazette publication satisfies a legal requirement for publication in the Official Gazette. Rules, regulations, orders, bye-laws, notifications and other matters may be published in either the Official Gazette or the Electronic Gazette. The deemed publication date is the date of the Gazette first published in any form.
Section 7 of the Information Technology Act, 2000
Electronic retention satisfies a statutory retention requirement where information remains accessible for subsequent reference, is preserved in its original or accurately reproducible format, and includes details identifying its origin, destination, and despatch or receipt timing. Automatically generated transmission information is excluded from the identification-details requirement. The framework does not apply where a law expressly provides for retention in electronic-record form.