Advanced Search Options : ❯
Section 43 of the Information Technology Act, 2000
Section 43 imposes compensatory liability for unauthorised access to computer resources, extraction of data, introduction of contaminants or viruses, and damage to computer systems, networks, data or programmes. It also covers disruption, denial of access to authorised users, assistance in unlawful access, and fraudulent charging of services to another person's account through manipulation of computer resources. Damages by way of compensation are payable to the affected person, subject to the prescribed maximum.
Section 42 of the Information Technology Act, 2000
Subscribers must exercise reasonable care to retain control of the private key corresponding to the public key in their Digital Signature Certificate and prevent unauthorised disclosure. A compromised private key must be promptly reported to the Certifying Authority in the prescribed manner. Liability continues until the Certifying Authority is informed of the compromise.
Section 41 of the Information Technology Act, 2000
Acceptance of a Digital Signature Certificate is deemed where a subscriber publishes or authorises its publication, places it in a repository, or otherwise demonstrates approval. The subscriber thereby certifies to reasonable relying parties that the corresponding private key is held lawfully, representations and material information given to the Certifying Authority are true, and information in the certificate within the subscriber's knowledge is true.
Section 40 of the Information Technology Act, 2000
A subscriber accepting a Digital Signature Certificate that lists a public key corresponding to the subscriber's private key must generate the associated key pair by applying the security procedure. This duty links certificate acceptance to secure generation of the public and private keys underlying the certificate.
Section 39 of the Information Technology Act, 2000
Suspension or revocation of a Digital Signature Certificate requires the Certifying Authority to publish notice in the repository identified in the certificate. If more than one repository is specified, publication is mandatory in every designated repository, ensuring notification of the certificate's status through each specified repository.
Section 38 of the Information Technology Act, 2000
A Certifying Authority may revoke a Digital Signature Certificate upon request, death of the subscriber, or dissolution or winding up of a subscriber firm or company. Revocation may also occur for false or concealed material facts, unmet issuance requirements, or a security compromise materially affecting reliability. Before revocation, the subscriber must receive an opportunity of being heard, and the revocation must be communicated to the subscriber.
Section 37 of the Information Technology Act, 2000
An issuing Certifying Authority may suspend a Digital Signature Certificate on the request of the subscriber or a duly authorised representative, or where suspension is considered necessary in the public interest. Suspension beyond fifteen days requires that the subscriber be given an opportunity of being heard. Following suspension, the Certifying Authority must communicate the suspension to the subscriber.
Section 36 of the Information Technology Act, 2000
Digital Signature Certificate issuance requires certification of statutory compliance, publication or availability to a relying person, and subscriber acceptance. The subscriber must hold a private key corresponding to the listed public key, capable of creating a digital signature, with the public key capable of verifying it. The key pair must function, certificate information must be accurate, and no known material fact may undermine the reliability of these representations.
Section 35 of the Information Technology Act, 2000
Any person may apply for an electronic signature certificate in the prescribed form, with the prescribed fee and a certification practice statement or other required statement of particulars. The Certifying Authority may conduct appropriate enquiries and grant or reject the application after considering the submitted material. A rejection must be supported by recorded reasons, and the applicant must receive a reasonable opportunity to show cause before the proposed refusal.
Section 34 of the Information Technology Act, 2000
Certifying Authorities must disclose electronic signature certificates, relevant certification practice statements, certificate revocation or suspension, and facts materially affecting certificate reliability or their ability to provide certification services. Where an event may materially affect computer-system integrity or conditions governing grant of an electronic signature certificate, they must notify persons likely to be affected through reasonable efforts or follow the procedure in their certification practice statements.
Section 33 of the Information Technology Act, 2000
Every Certifying Authority whose licence is suspended or revoked must immediately surrender the licence to the Controller. Failure to surrender the licence makes the person in whose favour it was issued liable to a penalty, which may extend to five lakh rupees.
Section 32 of the Information Technology Act, 2000
Every Certifying Authority must display its licence conspicuously at the premises where it carries on business. The requirement ensures that the licence is readily visible at the operational site.
Section 31 of the Information Technology Act, 2000
Certifying Authorities must ensure that every employee and other person engaged by them complies, while acting in the course of employment or engagement, with the Information Technology Act, 2000, and all rules, regulations, and orders made under it. The provision imposes an institutional compliance responsibility extending beyond the certifying entity itself to persons performing work under its direction or on its behalf.
Section 30 of the Information Technology Act, 2000
Certifying Authorities must deploy systems and procedures secure from intrusion and misuse, provide reliable services suited to intended functions, and protect the secrecy and privacy of electronic signatures. They must maintain a repository of issued electronic signature Certificates, publish information on their practices and certificate status, and comply with further regulatory standards.
Section 29 of the Information Technology Act, 2000
Section 29 empowers the Controller and authorised persons, on reasonable suspicion of a Chapter contravention, to access computer systems, apparatus, data, and connected material for searches to obtain available information or data. It also permits an order requiring persons responsible for or connected with operating the relevant system, data, apparatus, or material to provide necessary reasonable technical and other assistance.
Section 28 of the Information Technology Act, 2000
Investigation of contraventions is entrusted to the Controller or an officer authorised for that purpose. They must investigate breaches of applicable statutory provisions, rules, or regulations, and may exercise powers corresponding to those available to income-tax authorities, subject to the limitations governing those powers.
Section 27 of the Information Technology Act, 2000
Written authorisation enables the Controller to delegate any power exercisable under the Chapter regulating Certifying Authorities to a Deputy Controller, Assistant Controller, or any other officer. Delegation must be made in writing and permits the authorised officer to exercise those delegated Controller powers within the Chapter pursuant to that authorisation.
Section 26 of the Information Technology Act, 2000
Suspension or revocation of a Certifying Authority's licence requires publication of notice in the Controller's database and, where specified, in every designated repository. The database must be available through a website accessible round the clock. Where necessary, the Controller may further publicise its contents through electronic or other appropriate media.
Section 25 of the Information Technology Act, 2000
Section 25 permits revocation of a Certifying Authority's licence for materially false application statements, breach of licence terms, failure to maintain prescribed procedures and standards, or contravention of applicable legal requirements. Revocation requires a reasonable opportunity to show cause. Pending inquiry, suspension may be ordered where reasonable cause exists to believe a revocation ground is present; suspension exceeding ten days also requires a reasonable opportunity to show cause. A suspended Certifying Authority cannot issue electronic signature Certificates.
Section 24 of the Information Technology Act, 2000
Licensing of certifying authorities permits the Controller, on receiving an application under section 21, to grant a licence or reject it after considering the application, accompanying documents and other appropriate factors. Rejection is conditional on giving the applicant a reasonable opportunity to present its case before an adverse decision is made.