Advanced Search Options : ❯
Section 31 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities must ensure that every employee and other person engaged by them complies, while acting in the course of employment or engagement, with the Information Technology Act, 2000, and all rules, regulations, and orders made under it. The provision imposes an institutional compliance responsibility extending beyond the certifying entity itself to persons performing work under its direction or on its behalf.
Section 30 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities must deploy systems and procedures secure from intrusion and misuse, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of issued electronic signature Certificates, publish information on their practices and certificate status, and comply with further regulatory standards.
Section 29 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 29 permits the Controller or an authorised person, on reasonable cause to suspect a contravention of the relevant Chapter, to access computer systems, connected apparatus, data and other material for obtaining available information or data. A person responsible for or involved in operating the relevant system, data, apparatus or material may be ordered to provide reasonable technical and other necessary assistance.
Section 28 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 28 establishes an investigation mechanism for contraventions of the Information Technology Act, 2000, and of rules and regulations made under it. The Controller or an authorised officer must investigate such contraventions and exercise powers corresponding to those conferred on Income-tax authorities, subject to applicable statutory limitations.
Section 27 of the Information Technology Act, 2000 - Indian Laws - Acts
Written authorisation enables the Controller to delegate any power exercisable under the Chapter regulating Certifying Authorities to a Deputy Controller, Assistant Controller, or any other officer. Delegation must be made in writing and permits the authorised officer to exercise those delegated Controller powers within the Chapter pursuant to that authorisation.
Section 26 of the Information Technology Act, 2000 - Indian Laws - Acts
Suspension or revocation of a Certifying Authority's licence requires the Controller to publish notice in the maintained database and, where repositories are specified, in each repository. The database carrying the notice must remain accessible through a website on a round-the-clock basis. Further publicity may be given through appropriate electronic or other media where considered necessary.
Section 25 of the Information Technology Act, 2000 - Indian Laws - Acts
The Controller may revoke a Certifying Authority's licence for materially false licensing statements, breach of licence conditions, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements, subject to a reasonable opportunity to show cause. Where reasonable cause exists to believe that revocation grounds are present, the licence may be suspended pending inquiry. Suspension beyond ten days requires an opportunity to show cause, and no electronic signature certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence applications made under section 21 may be granted or rejected after the Controller considers accompanying documents and other factors considered appropriate. The assessment is not confined to application materials. Rejection requires a reasonable opportunity to present the case; no application may be rejected before the applicant is afforded that procedural safeguard.
Section 23 of the Information Technology Act, 2000 - Indian Laws - Acts
Renewal of a Certifying Authority licence requires an application in the prescribed form, accompanied by the prescribed fee subject to a maximum of five thousand rupees, and filed at least forty-five days before expiry of the licence validity period. The Central Government prescribes the applicable form and fee within that limit.
Section 22 of the Information Technology Act, 2000 - Indian Laws - Acts
Applications for a licence must be made in the form prescribed by the Central Government and accompanied by a certification practice statement, applicant-identification procedures, the prescribed fee subject to the statutory ceiling, and other prescribed documents.
Section 21 of the Information Technology Act, 2000 - Indian Laws - Acts
Licensing for the issuance of electronic signature Certificates is available upon application to the Controller, subject to prescribed eligibility requirements. Applicants must meet standards relating to qualifications, expertise, manpower, financial resources and infrastructure. Licences are valid for the prescribed period, are not transferable or heritable, and remain subject to regulatory conditions.
Section 20 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 20 was omitted, removing the statutory framework under which the Controller served as repository for all Digital Signature Certificates. Before omission, the Controller was required to use secure hardware, software and procedures, observe prescribed standards protecting digital-signature secrecy and security, maintain a computerised database of public keys, and make that database and the public keys available to the public.
Section 19 of the Information Technology Act, 2000 - Indian Laws - Acts
Recognition of foreign Certifying Authorities may be granted by the Controller, subject to regulatory conditions and restrictions, prior Central Government approval, and publication in the Official Gazette. Electronic signature certificates issued by a recognised foreign Certifying Authority are valid for statutory purposes. Recognition may be revoked where the Certifying Authority contravenes applicable conditions or restrictions, provided reasons are recorded in writing and the revocation is published in the Official Gazette.
Section 18 of the Information Technology Act, 2000 - Indian Laws - Acts
Controller oversight of Certifying Authorities includes supervision, public-key certification, operational standards, employee qualifications, business conditions, electronic signature certificate requirements, account maintenance, and auditor conditions. The Controller may regulate electronic systems, prescribe dealings with subscribers, resolve conflicts of interest, define duties, and maintain a publicly accessible database of disclosure records. References to digital signatures have been replaced with electronic signatures.
Section 17 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 17 provides for appointment of a Controller of Certifying Authorities, Deputy Controllers, Assistant Controllers, other officers and employees through Official Gazette notification. The Controller acts under the general control and directions of the Central Government, and subordinate Controllers perform assigned functions under the Controller's superintendence and control. The Central Government prescribes service conditions, specifies and establishes Head and Branch Offices, and the Office of the Controller must have an official seal.
Section 16 of the Information Technology Act, 2000 - Indian Laws - Acts
Security procedures and practices for secure electronic records and secure electronic signatures may be prescribed by the Central Government for the purposes of sections 14 and 15. Prescribing such measures requires regard to commercial circumstances, the nature of transactions, and other related factors considered appropriate.
Section 15 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 15 deems an electronic signature secure where signature creation data is exclusively controlled by the signatory at the time of signing and is stored and affixed in the prescribed exclusively controlled manner. In relation to a digital signature, the signature creation data is the subscriber's private key. The earlier framework for secure digital signatures also required uniqueness, subscriber identification, exclusive control, and linkage to the electronic record ensuring invalidation upon alteration.
Section 14 of the Information Technology Act, 2000 - Indian Laws - Acts
An electronic record is deemed a secure electronic record when a security procedure is applied at a specific point in time. Its secure status continues from the time of application until verification. Chapter V addresses secure electronic records and secure electronic signatures, replacing the earlier reference to digital signatures.
Section 13 of the Information Technology Act, 2000 - Indian Laws - Acts
Despatch occurs when an electronic record enters a computer resource outside the originator's control. Receipt depends on whether the addressee has designated a computer resource: entry into the designated resource constitutes receipt, while a record sent to an undesignated resource is received upon retrieval. Electronic records are deemed despatched and received at the respective parties' places of business, irrespective of the computer resource's physical location.
Section 12 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 12 permits acknowledgment of electronic records through any communication or conduct indicating receipt where no particular form or method is stipulated. If binding effect is expressly conditional on acknowledgment, non-receipt means the record is treated as never sent. Otherwise, after the specified, agreed, or reasonable time, the originator may issue notice, allow a reasonable further period, and treat the unacknowledged record as never sent if acknowledgment is still not received.