Advanced Search Options : ❯
Section 35 of the Information Technology Act, 2000 - Indian Laws - Acts
Applications for electronic signature Certificates must be made in the prescribed form, with the prescribed fee and a certification practice statement or regulatory-compliant statement of particulars. The Certifying Authority may consider the accompanying statement and conduct enquiries before granting or rejecting a certificate. Any rejection must record written reasons and follow a reasonable opportunity for the applicant to show cause against the proposed refusal.
Section 34 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 34 requires every Certifying Authority to disclose its electronic signature certificate, relevant certification practice statement, certificate revocation or suspension, and material adverse facts affecting certificate reliability or service capacity. Where events or situations may adversely affect computer-system integrity or certificate conditions, the Authority must reasonably notify likely affected persons or follow its certification practice statement procedure.
Section 33 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence surrender is immediately required when a Certifying Authority's licence is suspended or revoked. Failure to surrender the licence to the Controller is an offence by the person in whose favour the licence was issued and attracts a penalty that may extend to five lakh rupees. The monetary penalty framework replaced the earlier sanction of imprisonment, fine, or both from 30 November 2023.
Section 32 of the Information Technology Act, 2000 - Indian Laws - Acts
Every Certifying Authority must conspicuously display its licence at the premises where it carries on business. This requirement ensures that the authority's authorisation is visibly available at its operational location.
Section 31 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities bear responsibility for ensuring that every person employed or otherwise engaged by them complies, during employment or engagement, with the Information Technology Act, 2000 and all rules, regulations, and orders made under it. The obligation extends beyond direct employees to all engaged persons and requires internal compliance oversight in relation to their work.
Section 30 of the Information Technology Act, 2000 - Indian Laws - Acts
Certifying Authorities must use secure hardware, software and procedures, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of Electronic Signature Certificates, publish information on their practices, certificates and current certificate status, and comply with additional standards prescribed by regulations.
Section 29 of the Information Technology Act, 2000 - Indian Laws - Acts
The Controller or an authorised person may access computer systems, connected apparatus, data, and related material when there is reasonable cause to suspect a Chapter contravention. Access may be used to search for information or data and operates without prejudice to powers under section 69(1). By order, persons responsible for or involved in operating the relevant system, data, apparatus, or material may be required to provide reasonable technical and other assistance necessary for access and search.
Section 28 of the Information Technology Act, 2000 - Indian Laws - Acts
Investigation of contraventions under the Information Technology Act, 2000, its rules and regulations is undertaken by the Controller or an authorised officer. The investigating authority exercises powers corresponding to those available to Income-tax authorities, subject to the limitations applicable to those powers.
Section 27 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 27 of the Information Technology Act establishes a delegation mechanism for the regulation of Certifying Authorities. The Controller may, by written authorisation, empower a Deputy Controller, Assistant Controller, or other officer to exercise any of the Controller's powers under that Chapter. Written authorisation enables designated officers to exercise the Controller's Chapter-specific powers.
Section 26 of the Information Technology Act, 2000 - Indian Laws - Acts
Suspension or revocation of a Certifying Authority's licence requires the Controller to publish notice in the Controller's database and, where specified, in all relevant repositories. The database must be available through a website accessible round the clock. The Controller may also publicise its contents through appropriate electronic or other media.
Section 25 of the Information Technology Act, 2000 - Indian Laws - Acts
The Controller may revoke a Certifying Authority's licence for materially false licensing statements, breach of licence conditions, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements, subject to a reasonable opportunity to show cause. Where reasonable cause exists to believe that revocation grounds are present, the licence may be suspended pending inquiry. Suspension beyond ten days requires an opportunity to show cause, and no electronic signature certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence applications made under section 21 may be granted or rejected after the Controller considers accompanying documents and other factors considered appropriate. The assessment is not confined to application materials. Rejection requires a reasonable opportunity to present the case; no application may be rejected before the applicant is afforded that procedural safeguard.
Section 23 of the Information Technology Act, 2000 - Indian Laws - Acts
Licence renewal requires an application in the form prescribed by the Central Government, accompanied by the prescribed fee subject to a maximum of five thousand rupees. The application must be filed at least forty-five days before expiry of the licence. The Central Government determines the applicable form and fee within the statutory ceiling.
Section 22 of the Information Technology Act, 2000 - Indian Laws - Acts
Applications for issuance of a licence must be submitted in the form prescribed by the Central Government and must include a certification practice statement, a statement setting out applicant-identification procedures, the prescribed fee subject to a ceiling of twenty-five thousand rupees, and any additional prescribed documents. These requirements establish mandatory contents and accompanying materials for licence applications.
Section 21 of the Information Technology Act, 2000 - Indian Laws - Acts
Licensing for issuing electronic signature Certificates requires an application to the Controller and satisfaction of prescribed qualifications, expertise, manpower, financial resources and infrastructure requirements. A licence remains valid for the prescribed period, cannot be transferred or inherited, and operates subject to regulatory terms and conditions.
Section 20 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 20 was omitted, removing the statutory framework under which the Controller served as repository for all Digital Signature Certificates. Before omission, the Controller was required to use secure hardware, software and procedures, observe prescribed standards protecting digital-signature secrecy and security, maintain a computerised database of public keys, and make that database and the public keys available to the public.
Section 19 of the Information Technology Act, 2000 - Indian Laws - Acts
Recognition of foreign Certifying Authorities may be granted by the Controller, subject to regulatory conditions and restrictions, prior Central Government approval, and publication in the Official Gazette. Electronic signature certificates issued by a recognised foreign Certifying Authority are valid for statutory purposes. Recognition may be revoked where the Certifying Authority contravenes applicable conditions or restrictions, provided reasons are recorded in writing and the revocation is published in the Official Gazette.
Section 18 of the Information Technology Act, 2000 - Indian Laws - Acts
Controller oversight of Certifying Authorities includes supervision, public-key certification, operational standards, employee qualifications, business conditions, electronic signature certificate requirements, account maintenance, and auditor conditions. The Controller may regulate electronic systems, prescribe dealings with subscribers, resolve conflicts of interest, define duties, and maintain a publicly accessible database of disclosure records. References to digital signatures have been replaced with electronic signatures.
Section 17 of the Information Technology Act, 2000 - Indian Laws - Acts
Section 17 provides for appointment of a Controller of Certifying Authorities, Deputy Controllers, Assistant Controllers, other officers and employees through Official Gazette notification. The Controller acts under the general control and directions of the Central Government, and subordinate Controllers perform assigned functions under the Controller's superintendence and control. The Central Government prescribes service conditions, specifies and establishes Head and Branch Offices, and the Office of the Controller must have an official seal.
Section 16 of the Information Technology Act, 2000 - Indian Laws - Acts
Security procedures and practices for secure electronic records and secure electronic signatures may be prescribed by the Central Government for the purposes of sections 14 and 15. Prescribing such measures requires regard to commercial circumstances, the nature of transactions, and other related factors considered appropriate.