Advanced Search Options : ❯
Section 31 of the Information Technology Act, 2000
Certifying Authorities must ensure that every person employed or otherwise engaged by them complies, during such employment or engagement, with the Information Technology Act, its rules, regulations, and orders made under it. The obligation requires each Certifying Authority to secure personnel compliance with the applicable statutory and regulatory framework.
Section 30 of the Information Technology Act, 2000
Certifying Authorities must use hardware, software and procedures secure against intrusion and misuse, provide reasonably reliable services suited to intended functions, and maintain security procedures assuring the secrecy and privacy of digital signatures. They must also comply with further operational and security standards prescribed through regulations.
Section 29 of the Information Technology Act, 2000
Where reasonable cause exists to suspect a contravention of the Information Technology Act, its rules, or regulations, authorised access may be made to computer systems, connected apparatus, data, and other material to search for information or data. Persons operating or otherwise concerned with the relevant system or material may be ordered to provide reasonable technical and other assistance necessary for that access and search.
Section 28 of the Information Technology Act, 2000
Investigation of contraventions is entrusted to the Controller or an officer authorised for that purpose. They must investigate breaches of applicable statutory provisions, rules, or regulations, and may exercise powers corresponding to those available to income-tax authorities, subject to the limitations governing those powers.
Section 27 of the Information Technology Act, 2000
Written delegation of powers enables the Controller to authorise a Deputy Controller, Assistant Controller, or any officer to exercise powers vested in the Controller under the relevant chapter. Delegation depends on written authorisation and permits designated officers to exercise those chapter-specific functions to the extent authorised in writing. This mechanism allows administrative exercise of the Controller's powers by specifically authorised officials.
Section 26 of the Information Technology Act, 2000
Suspension or revocation of a Certifying Authority's licence requires publication of notice in the Controller's database and, where specified, in every designated repository. The database must be available through a website accessible round the clock. Where necessary, the Controller may further publicise its contents through electronic or other appropriate media.
Section 25 of the Information Technology Act, 2000
Licence revocation may be ordered after inquiry for materially false application statements, breach of licence conditions, failure to maintain prescribed standards, or contravention of applicable requirements, subject to a reasonable opportunity to show cause. Licence suspension may be imposed pending inquiry where grounds for revocation are reasonably believed to exist. Suspension beyond ten days requires an opportunity to show cause, and no Digital Signature Certificates may be issued during suspension.
Section 24 of the Information Technology Act, 2000
Licensing of certifying authorities permits the Controller, on receiving an application under section 21, to grant a licence or reject it after considering the application, accompanying documents and other appropriate factors. Rejection is conditional on giving the applicant a reasonable opportunity to present its case before an adverse decision is made.
Section 23 of the Information Technology Act, 2000
Licence renewal requires an application in the form prescribed by the Central Government, accompanied by the prescribed fee subject to a maximum of five thousand rupees. The application must be submitted at least forty-five days before expiry of the licence's validity period. These requirements establish the form, fee ceiling, and advance-filing condition governing renewal of licences under the regulatory framework for certifying authorities.
Section 22 of the Information Technology Act, 2000
Licence applications for Certifying Authorities must be made in the form prescribed by the Central Government. They must be accompanied by a certification practice statement, a statement on procedures for identifying the applicant, the prescribed fee subject to the statutory ceiling, and any other prescribed documents.
Section 21 of the Information Technology Act, 2000
Licensing to issue Digital Signature Certificates permits applications to the Controller, subject to prescribed requirements concerning qualifications, expertise, manpower, financial resources and infrastructure facilities. A granted licence is valid for the period prescribed by the Central Government, cannot be transferred or inherited, and remains subject to terms and conditions specified by regulations.
Section 20 of the Information Technology Act, 2000
The Controller functions as repository for Digital Signature Certificates and must use secure hardware, software and procedures against intrusion and misuse. It must comply with prescribed standards safeguarding digital-signature secrecy and security, and maintain a computerised database of public keys accessible to every member of the public.
Section 19 of the Information Technology Act, 2000
Recognition of a foreign Certifying Authority is subject to regulatory conditions and restrictions, previous Central Government approval, and Official Gazette publication. Certificates issued by a recognised foreign Certifying Authority are valid for relevant statutory purposes. Recognition may be revoked for contravention of attached conditions or restrictions, provided reasons are recorded in writing and the revocation is published in the Official Gazette.
Section 18 of the Information Technology Act, 2000
The Controller may supervise Certifying Authorities, certify their public keys, prescribe operational standards and employee qualifications, and regulate Digital Signature Certificate materials, formats, accounts, and auditors. The Controller may also regulate electronic systems and subscriber dealings, resolve conflicts of interest, lay down Certifying Authority duties, and maintain a publicly accessible database of disclosure records.
Section 17 of the Information Technology Act, 2000
The Central Government may appoint the Controller of Certifying Authorities, Deputy Controllers and Assistant Controllers by Official Gazette notification. The Controller functions under the Central Government's general control and directions, while Deputy Controllers and Assistant Controllers perform functions assigned by the Controller under the Controller's supervision. The Central Government prescribes service qualifications and conditions, specifies office locations, and may establish Head and Branch Offices. The Office of the Controller must have a seal.
Section 16 of the Information Technology Act, 2000
Security procedures for secure electronic records and secure electronic signatures are to be prescribed by the Central Government. The prescribed procedure must account for prevailing commercial circumstances, including the nature of the transaction, parties' technological sophistication, comparable transaction volume, rejected alternatives, costs of alternative procedures, and practices generally used for similar transactions or communications.
Section 15 of the Information Technology Act, 2000
Secure digital signature status depends on an agreed security procedure verifying, at the time of affixation, that the signature is unique to and identifies the subscriber, is created using means under the subscriber's exclusive control, and is linked to the electronic record so that alteration invalidates it. Where these cumulative conditions are satisfied, the signature is deemed a secure digital signature.
Section 14 of the Information Technology Act, 2000
Security procedures applied to an electronic record at a specific point in time give the record deemed status as a secure electronic record. This status operates from the moment the security procedure is applied and continues until verification. The deemed classification depends on application of the security procedure and covers the period between its application and verification, establishing the duration of secure electronic record status.
Section 13 of the Information Technology Act, 2000
Electronic-record despatch occurs when the record enters a computer resource outside the originator's control. Receipt occurs on entry into the addressee's designated computer resource, on retrieval where sent to a non-designated resource, or on entry into the addressee's computer resource if none is designated. Despatch and receipt are deemed to occur at the respective parties' places of business, regardless of computer-resource location, subject to contrary agreement.
Section 12 of the Information Technology Act, 2000
Electronic-record acknowledgment may be made by any communication or conduct indicating receipt where no agreed form or method exists. If the originator makes acknowledgment a condition of the record being binding, non-receipt causes the record to be deemed never sent. Otherwise, after non-receipt within the applicable period, the originator may give notice, fix a reasonable deadline, and treat the record as never sent if acknowledgment is still not received.