Advanced Search Options : ❯
Section 31 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities must ensure that every employee and other person engaged by them complies, while acting in the course of employment or engagement, with the Information Technology Act, 2000, and all rules, regulations, and orders made under it. The provision imposes an institutional compliance responsibility extending beyond the certifying entity itself to persons performing work under its direction or on its behalf.
Section 30 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities must deploy systems and procedures secure from intrusion and misuse, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of issued electronic signature Certificates, publish information on their practices and certificate status, and comply with further regulatory standards.
Section 29 of the Information Technology Act, 2000 - Indian Laws - Acts
The Controller or an authorised person may access computer systems, connected apparatus, data, and related material when there is reasonable cause to suspect a Chapter contravention. Access may be used to search for information or data and operates without prejudice to powers under section 69(1). By order, persons responsible for or involved in operating the relevant system, data, apparatus, or material may be required to provide reasonable technical and other assistance necessary for access and search.
Section 28 of the Information Technology Act, 2000 - Indian Laws - Acts
Investigation of contraventions under the Information Technology Act, 2000, its rules and regulations is undertaken by the Controller or an authorised officer. The investigating authority exercises powers corresponding to those available to Income-tax authorities, subject to the limitations applicable to those powers.
Section 27 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 27 of the Information Technology Act establishes a delegation mechanism for the regulation of Certifying Authorities. The Controller may, by written authorisation, empower a Deputy Controller, Assistant Controller, or other officer to exercise any of the Controller's powers under that Chapter. Written authorisation enables designated officers to exercise the Controller's Chapter-specific powers.
Section 26 of the Information Technology Act, 2000 - Indian Laws - Acts
Suspension or revocation of a Certifying Authority's licence requires the Controller to publish notice in the Controller's database and, where specified, in all relevant repositories. The database must be available through a website accessible round the clock. The Controller may also publicise its contents through appropriate electronic or other media.
Section 25 of the Information Technology Act, 2000 - Indian Laws - Acts
The Controller may revoke a Certifying Authority's licence for materially false licensing statements, breach of licence conditions, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements, subject to a reasonable opportunity to show cause. Where reasonable cause exists to believe that revocation grounds are present, the licence may be suspended pending inquiry. Suspension beyond ten days requires an opportunity to show cause, and no electronic signature certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence applications made under section 21 may be granted or rejected after the Controller considers accompanying documents and other factors considered appropriate. The assessment is not confined to application materials. Rejection requires a reasonable opportunity to present the case; no application may be rejected before the applicant is afforded that procedural safeguard.
Section 23 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence renewal requires an application in the form prescribed by the Central Government, accompanied by the prescribed fee subject to a maximum of five thousand rupees. The application must be filed at least forty-five days before expiry of the licence. The Central Government determines the applicable form and fee within the statutory ceiling.
Section 22 of the Information Technology Act, 2000 - Indian Laws - Acts
Applications for issuance of a licence must be submitted in the form prescribed by the Central Government and must include a certification practice statement, a statement setting out applicant-identification procedures, the prescribed fee subject to a ceiling of twenty-five thousand rupees, and any additional prescribed documents. These requirements establish mandatory contents and accompanying materials for licence applications.
Section 21 of the Information Technology Act, 2000 - Indian Laws - Acts
Licensing for issuing electronic signature Certificates requires an application to the Controller and satisfaction of prescribed qualifications, expertise, manpower, financial resources and infrastructure requirements. A licence remains valid for the prescribed period, cannot be transferred or inherited, and operates subject to regulatory terms and conditions.
Section 20 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 20 was omitted, removing the statutory framework under which the Controller served as repository for all Digital Signature Certificates. Before omission, the Controller was required to use secure hardware, software and procedures, observe prescribed standards protecting digital-signature secrecy and security, maintain a computerised database of public keys, and make that database and the public keys available to the public.
Section 19 of the Information Technology Act, 2000 - Indian Laws - Acts
Recognition of foreign Certifying Authorities may be granted by the Controller, subject to regulatory conditions and restrictions, prior Central Government approval, and publication in the Official Gazette. Electronic signature certificates issued by a recognised foreign Certifying Authority are valid for statutory purposes. Recognition may be revoked where the Certifying Authority contravenes applicable conditions or restrictions, provided reasons are recorded in writing and the revocation is published in the Official Gazette.
Section 18 of the Information Technology Act, 2000 - Indian Laws - Acts
Controller oversight of Certifying Authorities includes supervision, public-key certification, operational standards, employee qualifications, business conditions, electronic signature certificate requirements, account maintenance, and auditor conditions. The Controller may regulate electronic systems, prescribe dealings with subscribers, resolve conflicts of interest, define duties, and maintain a publicly accessible database of disclosure records. References to digital signatures have been replaced with electronic signatures.
Section 17 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 17 provides for appointment of a Controller of Certifying Authorities, Deputy Controllers, Assistant Controllers, other officers and employees through Official Gazette notification. The Controller acts under the general control and directions of the Central Government, and subordinate Controllers perform assigned functions under the Controller's superintendence and control. The Central Government prescribes service conditions, specifies and establishes Head and Branch Offices, and the Office of the Controller must have an official seal.
Section 16 of the Information Technology Act, 2000 - Indian Laws - Acts
Security procedures and practices for secure electronic records and secure electronic signatures may be prescribed by the Central Government for the purposes of sections 14 and 15. Prescribing such measures requires regard to commercial circumstances, the nature of transactions, and other related factors considered appropriate.
Section 15 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 15 deems an electronic signature secure where signature creation data is exclusively controlled by the signatory at the time of signing and is stored and affixed in the prescribed exclusively controlled manner. In relation to a digital signature, the signature creation data is the subscriber's private key. The earlier framework for secure digital signatures also required uniqueness, subscriber identification, exclusive control, and linkage to the electronic record ensuring invalidation upon alteration.
Section 14 of the Information Technology Act, 2000 - Indian Laws - Acts
An electronic record is deemed a secure electronic record when a security procedure is applied at a specific point in time. Its secure status continues from the time of application until verification. Chapter V addresses secure electronic records and secure electronic signatures, replacing the earlier reference to digital signatures.
Section 13 of the Information Technology Act, 2000 - Indian Laws - Acts
Despatch occurs when an electronic record enters a computer resource outside the originator's control. Receipt depends on whether the addressee has designated a computer resource: entry into the designated resource constitutes receipt, while a record sent to an undesignated resource is received upon retrieval. Electronic records are deemed despatched and received at the respective parties' places of business, irrespective of the computer resource's physical location.
Section 12 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 12 permits acknowledgment of electronic records through any communication or conduct indicating receipt where no particular form or method is stipulated. If binding effect is expressly conditional on acknowledgment, non-receipt means the record is treated as never sent. Otherwise, after the specified, agreed, or reasonable time, the originator may issue notice, allow a reasonable further period, and treat the unacknowledged record as never sent if acknowledgment is still not received.