Information Technology Act Section 3A — Electronic signature
CHAPTER II 2[DIGITAL SIGNATURE AND ELECTRONIC SIGNATURE]
Cyber Law
Summary
Sub-section (1) allows a subscriber to authenticate an electronic record using an electronic signature or electronic authentication technique, instead of the method mentioned in section 3, as long as that signature or technique is considered reliable and is specified in the Second Schedule.
Sub-section (2) lists the conditions under which an electronic signature or authentication technique is considered reliable. Under clause (a), the signature creation data or authentication data must be linked, in the context of their use, to the signatory or authenticator and to no other person. Under clause (b), at the time of signing, the signature creation data or authentication data must be under the control of the signatory or authenticator and no one else. Under clause (c), any change to the electronic signature after it is affixed must be detectable. Under clause (d), any change to the information after it is authenticated by the electronic signature must be detectable. Under clause (e), the signature or technique must also fulfil any other conditions that may be prescribed.
Sub-section (3) states that the Central Government may prescribe the procedure for determining whether an electronic signature is that of the person who is claimed to have affixed or authenticated it.
Sub-section (4) allows the Central Government to add or remove any electronic signature or authentication technique, along with the procedure for affixing such signature, from the Second Schedule through a notification in the Official Gazette. However, no electronic signature or authentication technique may be specified in the Second Schedule unless it is reliable.
Sub-section (5) requires that every notification issued under sub-section (4) must be laid before each House of Parliament.
Official Text
(1) Notwithstanding anything contained in section 3, but subject to the provisions of sub-section (2), a subscriber may authenticate any electronic record by such electronic signature or electronic authentication technique which—
(a) is considered reliable; and
(b) may be specified in the Second Schedule.
(2) For the purposes of this section any electronic signature or electronic authentication technique shall be considered reliable if—
(a) the signature creation data or the authentication data are, within the context in which they are used, linked to the signatory or, as the case may be, the authenticator and to no other person;
(b) the signature creation data or the authentication data were, at the time of signing, under the control of the signatory or, as the case may be, the authenticator and of no other person;
(c) any alteration to the electronic signature made after affixing such signature is detectable;
(d) any alteration to the information made after its authentication by electronic signature is detectable; and
(e) it fulfils such other conditions which may be prescribed.
(3) The Central Government may prescribe the procedure for the purpose of ascertaining whether electronic signature is that of the person by whom it is purported to have been affixed or authenticated.
(4) The Central Government may, by notification in the Official Gazette, add to or omit any electronic signature or electronic authentication technique and the procedure for affixing such signature from the Second Schedule:
Provided that no electronic signature or authentication technique shall be specified in the Second Schedule unless such signature or technique is reliable.
(5) Every notification issued under sub-section (4) shall be laid before each House of Parliament.]