Advanced Search Options : ❯
Section 31 of the Information Technology Act, 2000
Certifying Authorities must ensure that every employee and other person engaged by them complies, while acting in the course of employment or engagement, with the Information Technology Act, 2000, and all rules, regulations, and orders made under it. The provision imposes an institutional compliance responsibility extending beyond the certifying entity itself to persons performing work under its direction or on its behalf.
Section 30 of the Information Technology Act, 2000
Certifying Authorities must deploy systems and procedures secure from intrusion and misuse, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of issued electronic signature Certificates, publish information on their practices and certificate status, and comply with further regulatory standards.
Section 29 of the Information Technology Act, 2000
Section 29 empowers the Controller and authorised persons, on reasonable suspicion of a Chapter contravention, to access computer systems, apparatus, data, and connected material for searches to obtain available information or data. It also permits an order requiring persons responsible for or connected with operating the relevant system, data, apparatus, or material to provide necessary reasonable technical and other assistance.
Section 28 of the Information Technology Act, 2000
Contraventions of the Information Technology Act, 2000, and subordinate rules and regulations must be investigated by the Controller or an authorised officer. Investigative powers correspond to those available to Income-tax authorities under Chapter XIII of the Income-tax Act, 1961, and must be exercised subject to the limitations applicable under that framework.
Section 27 of the Information Technology Act, 2000
Written authorisation enables the Controller to delegate any power exercisable under the Chapter regulating Certifying Authorities to a Deputy Controller, Assistant Controller, or any other officer. Delegation must be made in writing and permits the authorised officer to exercise those delegated Controller powers within the Chapter pursuant to that authorisation.
Section 26 of the Information Technology Act, 2000
The Controller must publish notice in the maintained database when a Certifying Authority's licence is suspended or revoked. Where specified repositories exist, notice must be published in all of them. The database containing the notice must be accessible round the clock through a website, and its contents may additionally be publicised through appropriate electronic or other media.
Section 25 of the Information Technology Act, 2000
Section 25 permits revocation of a Certifying Authority's licence for materially false application statements, breach of licence terms, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements. Revocation requires a reasonable opportunity to show cause. Pending inquiry, suspension may be ordered where reasonable cause exists to believe a revocation ground is present; suspension exceeding ten days also requires a reasonable opportunity to show cause. A suspended Certifying Authority cannot issue electronic signature Certificates.
Section 24 of the Information Technology Act, 2000
The Controller may grant or reject a licence application after considering the accompanying documents and other relevant factors. An application cannot be rejected unless the applicant has been given a reasonable opportunity to present its case.
Section 23 of the Information Technology Act, 2000
Renewal of a certifying authority licence requires an application in the prescribed form, accompanied by a prescribed fee not exceeding five thousand rupees. The application must be filed at least forty-five days before expiry of the licence's validity period. These requirements combine mandatory form, fee-limit, and advance-filing conditions for licence renewal.
Section 22 of the Information Technology Act, 2000
Applications for a licence must be made in the form prescribed by the Central Government and accompanied by a certification practice statement, applicant-identification procedures, the prescribed fee subject to the statutory ceiling, and other prescribed documents.
Section 21 of the Information Technology Act, 2000
Electronic signature certificate licensing is available upon application to the Controller, subject to prescribed requirements relating to qualifications, expertise, manpower, financial resources and infrastructure. Licences are valid for the prescribed period, are non-transferable and non-heritable, and remain subject to regulatory terms and conditions.
Section 20 of the Information Technology Act, 2000
Section 20 concerning the Controller's role as repository has been omitted. Before omission, the Controller was required to retain all Digital Signature Certificates issued under the Act, use hardware, software and procedures secure against intrusion and misuse, observe prescribed standards protecting digital-signature secrecy and security, and maintain a computerised database of public keys accessible to every member of the public.
Section 19 of the Information Technology Act, 2000
Recognition of foreign Certifying Authorities is subject to regulatory conditions and restrictions, prior governmental approval, and notification in the Official Gazette. A recognised foreign Certifying Authority may function for statutory purposes, and its electronic signature Certificates are valid for those purposes. Recognition may be revoked upon contravention of attached conditions or restrictions, provided written reasons are recorded and revocation is notified in the Official Gazette.
Section 18 of the Information Technology Act, 2000
Section 18 empowers the Controller to supervise Certifying Authorities, certify public keys, prescribe operational standards, and regulate their business conditions, employee qualifications, electronic signature Certificates, advertising materials, accounts, and auditors. The Controller may regulate electronic systems and subscriber dealings, resolve conflicts of interest, lay down duties, and maintain a publicly accessible database of prescribed disclosure records for every Certifying Authority.
Section 17 of the Information Technology Act, 2000
Section 17 empowers the Central Government to appoint a Controller of Certifying Authorities, along with Deputy Controllers, Assistant Controllers, officers and employees, through notification in the Official Gazette. The Controller functions under governmental control and direction, while Deputy and Assistant Controllers perform assigned functions under the Controller's superintendence. Service qualifications and conditions are prescribed by the Central Government, which also determines the locations of head and branch offices. The Office of the Controller is required to have a seal.
Section 16 of the Information Technology Act, 2000
Section 16 empowers the Central Government to prescribe security procedures and practices for secure electronic records and secure electronic signatures. The prescription must take account of commercial circumstances, the nature of transactions, and other related factors considered appropriate when determining applicable procedures and practices.
Section 15 of the Information Technology Act, 2000
Secure electronic signature status arises where signature-creation data is under the exclusive control of the signatory when the signature is affixed, and is stored and affixed in the prescribed exclusively controlled manner. For a digital signature, signature-creation data means the subscriber's private key.
Section 14 of the Information Technology Act, 2000
Secure electronic record status attaches where a security procedure is applied to an electronic record at a specific point in time. The record is deemed secure from that point until verification, defining the temporal period during which the secure-record classification operates. The classification is linked to application of the security procedure and its continuation until verification.
Section 13 of the Information Technology Act, 2000
Despatch occurs when an electronic record enters a computer resource outside the originator's control. Where the addressee has designated a computer resource, receipt occurs on entry into that resource; where the record is sent to another computer resource of the addressee, receipt occurs upon retrieval. Electronic records are deemed dispatched at the originator's place of business and received at the addressee's place of business, irrespective of the physical location of the computer resource.
Section 12 of the Information Technology Act, 2000
Where the originator makes receipt of acknowledgment a condition for the electronic record to be binding, failure to receive acknowledgment results in the record being deemed never sent. Where no such condition is stipulated, the originator may, after non-receipt within the applicable period, notify the addressee and prescribe a reasonable further period. If acknowledgment remains outstanding, the originator may treat the electronic record as never sent.