Advanced Search Options : ❯
Section 22 of the Information Technology Act, 2000
Licence applications for Certifying Authorities must be made in the form prescribed by the Central Government. They must be accompanied by a certification practice statement, a statement on procedures for identifying the applicant, the prescribed fee subject to the statutory ceiling, and any other prescribed documents.
Section 21 of the Information Technology Act, 2000
Licensing to issue Digital Signature Certificates permits applications to the Controller, subject to prescribed requirements concerning qualifications, expertise, manpower, financial resources and infrastructure facilities. A granted licence is valid for the period prescribed by the Central Government, cannot be transferred or inherited, and remains subject to terms and conditions specified by regulations.
Section 20 of the Information Technology Act, 2000
The Controller functions as repository for Digital Signature Certificates and must use secure hardware, software and procedures against intrusion and misuse. It must comply with prescribed standards safeguarding digital-signature secrecy and security, and maintain a computerised database of public keys accessible to every member of the public.
Section 19 of the Information Technology Act, 2000
Recognition of a foreign Certifying Authority is subject to regulatory conditions and restrictions, previous Central Government approval, and Official Gazette publication. Certificates issued by a recognised foreign Certifying Authority are valid for relevant statutory purposes. Recognition may be revoked for contravention of attached conditions or restrictions, provided reasons are recorded in writing and the revocation is published in the Official Gazette.
Section 18 of the Information Technology Act, 2000
The Controller may supervise Certifying Authorities, certify their public keys, prescribe operational standards and employee qualifications, and regulate Digital Signature Certificate materials, formats, accounts, and auditors. The Controller may also regulate electronic systems and subscriber dealings, resolve conflicts of interest, lay down Certifying Authority duties, and maintain a publicly accessible database of disclosure records.
Section 17 of the Information Technology Act, 2000
The Central Government may appoint the Controller of Certifying Authorities, Deputy Controllers and Assistant Controllers by Official Gazette notification. The Controller functions under the Central Government's general control and directions, while Deputy Controllers and Assistant Controllers perform functions assigned by the Controller under the Controller's supervision. The Central Government prescribes service qualifications and conditions, specifies office locations, and may establish Head and Branch Offices. The Office of the Controller must have a seal.
Section 16 of the Information Technology Act, 2000
Security procedures for secure electronic records and secure electronic signatures are to be prescribed by the Central Government. The prescribed procedure must account for prevailing commercial circumstances, including the nature of the transaction, parties' technological sophistication, comparable transaction volume, rejected alternatives, costs of alternative procedures, and practices generally used for similar transactions or communications.
Section 15 of the Information Technology Act, 2000
Secure digital signature status depends on an agreed security procedure verifying, at the time of affixation, that the signature is unique to and identifies the subscriber, is created using means under the subscriber's exclusive control, and is linked to the electronic record so that alteration invalidates it. Where these cumulative conditions are satisfied, the signature is deemed a secure digital signature.
Section 14 of the Information Technology Act, 2000
Security procedures applied to an electronic record at a specific point in time give the record deemed status as a secure electronic record. This status operates from the moment the security procedure is applied and continues until verification. The deemed classification depends on application of the security procedure and covers the period between its application and verification, establishing the duration of secure electronic record status.
Section 13 of the Information Technology Act, 2000
Electronic-record despatch occurs when the record enters a computer resource outside the originator's control. Receipt occurs on entry into the addressee's designated computer resource, on retrieval where sent to a non-designated resource, or on entry into the addressee's computer resource if none is designated. Despatch and receipt are deemed to occur at the respective parties' places of business, regardless of computer-resource location, subject to contrary agreement.
Section 12 of the Information Technology Act, 2000
Electronic-record acknowledgment may be made by any communication or conduct indicating receipt where no agreed form or method exists. If the originator makes acknowledgment a condition of the record being binding, non-receipt causes the record to be deemed never sent. Otherwise, after non-receipt within the applicable period, the originator may give notice, fix a reasonable deadline, and treat the record as never sent if acknowledgment is still not received.
Section 11 of the Information Technology Act, 2000
Attribution of an electronic record to its originator arises where the originator personally sends it, where it is sent by a person authorised to act for the originator in relation to that record, or where an information system programmed by or for the originator automatically transmits it.
Section 10 of the Information Technology Act, 2000
Central Government rulemaking power for electronic signatures permits prescription of the types of electronic signature, the manner and format in which they are affixed, and procedures facilitating identification of the person affixing an electronic signature. Rulemaking may also establish processes ensuring the integrity, security and confidentiality of electronic records or payments, and address matters necessary to give legal effect to electronic signatures.
Section 9 of the Information Technology Act, 2000
Electronic governance provisions do not create an enforceable entitlement to require governmental ministries, departments, authorities, or publicly controlled or funded bodies to use electronic records. Such bodies cannot be compelled to accept, issue, create, retain, or preserve documents electronically, or to conduct monetary transactions in electronic form. Electronic governance is enabled without imposing mandatory electronic acceptance or transaction processing on public bodies.
Section 8 of the Information Technology Act, 2000
Publication in either the Official Gazette or Electronic Gazette fulfils a legal requirement that a rule, regulation, order, bye-law, notification or other matter be published in the Official Gazette. Where publication occurs in either form, the legally deemed publication date is the date of the Gazette first published in any form.
Section 7 of the Information Technology Act, 2000
Electronic retention satisfies a statutory retention requirement where information remains accessible for subsequent reference, is preserved in its original or accurately reproducible format, and includes details identifying its origin, destination, and despatch or receipt timing. Automatically generated transmission information is excluded from the identification-details requirement. The framework does not apply where a law expressly provides for retention in electronic-record form.
Section 6 of the Information Technology Act, 2000
Statutory requirements for filing documents with government offices or agencies, obtaining licences, permits, sanctions or approvals, and receiving or paying money may be satisfied through electronic forms prescribed by the appropriate Government. Rules may govern the manner and format for filing, creating or issuing electronic records, and the method for payment of related fees or charges.
Section 5 of the Information Technology Act, 2000
Legal recognition of electronic signatures applies where a law requires authentication by signature or requires a document to be signed or bear a person's signature. Such requirements are satisfied when authentication is effected through an electronic signature affixed in the manner prescribed by the Central Government.
Section 4 of the Information Technology Act, 2000
Legal recognition of electronic records under Section 4 applies where any law requires information or another matter in writing, typewritten or printed form. Such a requirement is deemed satisfied, notwithstanding anything inconsistent in that law, if the information or matter is rendered or made available in electronic form and is accessible so as to be usable for subsequent reference purposes.
Section 3 of the Information Technology Act, 2000
Authentication of electronic records may be undertaken by a subscriber by affixing a digital signature through an asymmetric cryptographic system and hash function. The hash function produces a consistent hash result for the same electronic record and must make reconstruction of the original record or generation of identical results for different records computationally infeasible. Verification may be performed using the subscriber's public key, which, together with the unique private key, forms a functioning key pair.