Information Technology Act Section 19 — Recognition of foreign Certifying Authorities

CHAPTER VI REGULATION OF CERTIFYING AUTHORITIES

Cyber Law

Summary

Sub-section (1) allows the Controller to officially recognise a foreign Certifying Authority as a Certifying Authority under this Act. This can only be done with the prior approval of the Central Government, through a notification in the Official Gazette, and is subject to any conditions and restrictions that may be set out in regulations.

Sub-section (2) states that once a foreign Certifying Authority is recognised under sub-section (1), any electronic signature Certificate issued by that authority will be considered valid for the purposes of this Act.

Sub-section (3) gives the Controller the power to revoke the recognition of a foreign Certifying Authority. This can happen if the Controller is satisfied that the authority has violated any of the conditions or restrictions under which its recognition was granted. The revocation must be done by a notification in the Official Gazette, and the Controller must record the reasons for the revocation in writing.

Official Text

(1) Subject to such conditions and restrictions as may be specified by regulations, the Controller may with the previous approval of the Central Government, and by notification in the Official Gazette, recognise any foreign Certifying Authority as a Certifying Authority for the purposes of this Act.

(2) Where any Certifying Authority is recognised under sub-section (1), the 2[electronic signature] Certificate issued by such Certifying Authority shall be valid for the purposes of this Act.

(3) The Controller may, if he is satisfied that any Certifying Authority has contravened any of the conditions and restrictions subject to which it was granted recognition under sub-section (1) he may, for reasons to be recorded in writing, by notification in the Official Gazette, revoke such recognition.