{"id":332,"date":"2011-04-15T12:04:00","date_gmt":"2026-02-23T06:00:58","guid":{"rendered":"https:\/\/legal.indiafin.com\/?p=332"},"modified":"2026-02-23T06:03:53","modified_gmt":"2026-02-23T06:03:53","slug":"electronic-signatures-act","status":"publish","type":"post","link":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/","title":{"rendered":"ELECTRONIC SIGNATURES ACT."},"content":{"rendered":"<p class=\"title\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\">\n<p>ELECTRONIC SIGNATURES ACT.<\/p>\n<p class=\"ListingCentered\"><b>ARRANGEMENT OF SECTIONS<\/b><\/p>\n<p>\u00a0\u00a0\u00a0Section<\/p>\n<p class=\"ListingCentered\">PART I<br \/>PRELIMINARY.<\/p>\n<p>\u00a0<\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s1\">1.\u00a0\u00a0\u00a0Commencement. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s2\">2.\u00a0\u00a0\u00a0Interpretation. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s3\">3.\u00a0\u00a0\u00a0Equal treatment of signature technologies. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0<\/p>\n<p class=\"ListingCentered\">PART II<br \/>ELECTRONIC SIGNATURES.<\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s4\">4.\u00a0\u00a0\u00a0Compliance with a requirement for a signature. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s5\">5.\u00a0\u00a0\u00a0Conduct of the signatory. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s6\">6.\u00a0\u00a0\u00a0Variation by agreement. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s7\">7.\u00a0\u00a0\u00a0Conduct of the relying party. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s8\">8.\u00a0\u00a0\u00a0Trustworthiness. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s9\">9.\u00a0\u00a0\u00a0Conduct of the certification service provider. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s10\">10.\u00a0\u00a0\u00a0Advanced signatures. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s11\">11.\u00a0\u00a0\u00a0Secure electronic signature. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s12\">12.\u00a0\u00a0\u00a0Presumptions relating to secure and advanced electronic signatures. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0<\/p>\n<p class=\"ListingCentered\">PART III<br \/>SECURE DIGITAL SIGNATURES.<\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s13\">13.\u00a0\u00a0\u00a0Secure digital signatures. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s14\">14.\u00a0\u00a0\u00a0Satisfaction of signature requirements. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s15\">15.\u00a0\u00a0\u00a0Unreliable digital signatures. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s16\">16.\u00a0\u00a0\u00a0Digitally signed document taken to be written document. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s17\">17.\u00a0\u00a0\u00a0Digitally signed document deemed to be original document. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s18\">18.\u00a0\u00a0\u00a0Authentication of digital signatures. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s19\">19.\u00a0\u00a0\u00a0Presumptions in adjudicating disputes. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0<\/p>\n<p class=\"ListingCentered\">PART IV<br \/>PUBLIC KEY INFRASTRUCTURE.<\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s20\">20.\u00a0\u00a0\u00a0Sphere of application. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s21\">21.\u00a0\u00a0\u00a0Controller. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s22\">22.\u00a0\u00a0\u00a0Certification service providers to be licensed. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s23\">23.\u00a0\u00a0\u00a0Qualifications of certification service providers. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s24\">24.\u00a0\u00a0\u00a0Functions of licensed certification service providers. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s25\">25.\u00a0\u00a0\u00a0Application for licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s26\">26.\u00a0\u00a0\u00a0Grant or refusal of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s27\">27.\u00a0\u00a0\u00a0Revocation of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s28\">28.\u00a0\u00a0\u00a0Appeal. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s29\">29.\u00a0\u00a0\u00a0Surrender of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s30\">30.\u00a0\u00a0\u00a0Effect of revocation, surrender or expiry of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s31\">31.\u00a0\u00a0\u00a0Effect of lack of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s32\">32.\u00a0\u00a0\u00a0Return of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s33\">33.\u00a0\u00a0\u00a0Restricted licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s34\">34.\u00a0\u00a0\u00a0Restriction on use of expression &#8220;certification service provider&#8221;. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s35\">35.\u00a0\u00a0\u00a0Renewal of licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s36\">36.\u00a0\u00a0\u00a0Lost licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s37\">37.\u00a0\u00a0\u00a0Recognition of other licenses. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s38\">38.\u00a0\u00a0\u00a0Performance audit. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s39\">39.\u00a0\u00a0\u00a0Activities of certification service providers. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s40\">40.\u00a0\u00a0\u00a0Requirement to display licence. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s41\">41.\u00a0\u00a0\u00a0Requirement to submit information on business operations. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s42\">42.\u00a0\u00a0\u00a0Notification of change of information. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s43\">43.\u00a0\u00a0\u00a0Use of trustworthy systems. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s44\">44.\u00a0\u00a0\u00a0Disclosures on inquiry. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s45\">45.\u00a0\u00a0\u00a0Prerequisites to issue of certificate to subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s46\">46.\u00a0\u00a0\u00a0Publication of issued and accepted certificate. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s47\">47.\u00a0\u00a0\u00a0Adoption of more rigorous requirements permitted. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s48\">48.\u00a0\u00a0\u00a0Suspension or revocation of certificate for faculty issuance. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s49\">49.\u00a0\u00a0\u00a0Suspension or revocation of certificate by order. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s50\">50.\u00a0\u00a0\u00a0Warranties to subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s51\">51.\u00a0\u00a0\u00a0Continuing obligations to subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s52\">52.\u00a0\u00a0\u00a0Representations upon issuance. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s53\">53.\u00a0\u00a0\u00a0Representations upon publications. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s54\">54.\u00a0\u00a0\u00a0Implied representations by subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s55\">55.\u00a0\u00a0\u00a0Representations by agent of subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s56\">56.\u00a0\u00a0\u00a0Disclaimer or indemnity limited. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s57\">57.\u00a0\u00a0\u00a0Indemnification of certification service provider by subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s58\">58.\u00a0\u00a0\u00a0Certification of accuracy of information given. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s59\">59.\u00a0\u00a0\u00a0Duty of subscriber to keep private key secure. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s60\">60.\u00a0\u00a0\u00a0Property in private key. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s61\">61.\u00a0\u00a0\u00a0Fiduciary duty of a certification service provider. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s62\">62.\u00a0\u00a0\u00a0Suspension of certificate by certification service provider. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s63\">63.\u00a0\u00a0\u00a0Suspension of certificate by Controller. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s64\">64.\u00a0\u00a0\u00a0Notice of suspension. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s65\">65.\u00a0\u00a0\u00a0Termination of suspension initiated by request. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s66\">66.\u00a0\u00a0\u00a0Alternate contractual procedures. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s67\">67.\u00a0\u00a0\u00a0Effect of suspension of certificate. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s68\">68.\u00a0\u00a0\u00a0Revocation of request. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s69\">69.\u00a0\u00a0\u00a0Revocation on subscriber&#8217;s demise. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s70\">70.\u00a0\u00a0\u00a0Revocation of unreliable certificates. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s71\">71.\u00a0\u00a0\u00a0Notice of revocation. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s72\">72.\u00a0\u00a0\u00a0Effect of revocation request on subscriber. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s73\">73.\u00a0\u00a0\u00a0Effect of notification on certification service provider. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s74\">74.\u00a0\u00a0\u00a0Expiration of certificate. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s75\">75.\u00a0\u00a0\u00a0Reliance limit. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s76\">76.\u00a0\u00a0\u00a0Liability limits for certification service providers. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s77\">77.\u00a0\u00a0\u00a0Recognition of repositories. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s78\">78.\u00a0\u00a0\u00a0Liability of repositories. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s79\">79.\u00a0\u00a0\u00a0Recognition of date or time stamp services. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0<\/p>\n<p class=\"ListingCentered\">PART V<br \/>MISCELLANEOUS.<\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s80\">80.\u00a0\u00a0\u00a0Prohibition against dangerous activities. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s81\">81.\u00a0\u00a0\u00a0Obligation of confidentiality. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s82\">82.\u00a0\u00a0\u00a0False information. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s83\">83.\u00a0\u00a0\u00a0Offences by body corporate. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s84\">84.\u00a0\u00a0\u00a0Authorised officer. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s85\">85.\u00a0\u00a0\u00a0Power to investigate. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s86\">86.\u00a0\u00a0\u00a0Search by warrant. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s87\">87.\u00a0\u00a0\u00a0Search and seizure without warrant. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s88\">88.\u00a0\u00a0\u00a0Access to computerised data. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s89\">89.\u00a0\u00a0\u00a0List of things seized. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s90\">90.\u00a0\u00a0\u00a0Obstruction of authorised officer. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s91\">91.\u00a0\u00a0\u00a0Additional powers. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s92\">92.\u00a0\u00a0\u00a0General penalty. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s93\">93.\u00a0\u00a0\u00a0Institution and conduct of prosecution. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s94\">94.\u00a0\u00a0\u00a0Jurisdiction to try offences. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s95\">95.\u00a0\u00a0\u00a0Prosecution of officers. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s96\">96.\u00a0\u00a0\u00a0Limitation on disclaiming or limiting application of the Act. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s97\">97.\u00a0\u00a0\u00a0Regulations. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s98\">98.\u00a0\u00a0\u00a0Compensation. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s99\">99.\u00a0\u00a0\u00a0Power of Minister to amend schedule. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0<a href=\"#Act7of2011s100\">100.\u00a0\u00a0\u00a0Savings and transitional provisions. <\/a><\/p>\n<p class=\"ListingRI\">\u00a0<\/p>\n<p class=\"ListingRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<i><a href=\"#Act7of2011-Sch\">Schedule\u00a0\u00a0\u00a0<\/a><\/i>Currency point.<\/p>\n<p class=\"ListingRI\">\u00a0<\/p>\n<p class=\"CenteredBold\">ELECTRONIC SIGNATURES ACT.<\/p>\n<p align=\"right\"><i>Commencement:<\/i> 15 April 2011.<\/p>\n<p>\u00a0\u00a0\u00a0<b>An Act to make provision for and to regulate the use of electronic signatures and to provide for other related matters.<\/b><\/p>\n<p class=\"L5\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\">PART I<br \/>PRELIMINARY.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s1\"><\/a>1.\u00a0\u00a0\u00a0Commencement.<\/p>\n<p>\u00a0\u00a0\u00a0This Act shall come into force on a date appointed by the Minister by statutory instrument<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s2\"><\/a>2.\u00a0\u00a0\u00a0Interpretation.<\/p>\n<p>\u00a0\u00a0\u00a0In this Act, unless the context otherwise requires\u2014<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;accept a certificate&#8221;<\/b> means\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0to manifest approval of a certificate, while knowing or having notice of its contents; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0to apply to a certification service provider for a certificate, without revoking the application by delivering notice of the revocation to the licensed certification service provider and obtaining a signed, written receipt from the certification service provider, if the certification service provider subsequently issues a certificate based on the application;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;advanced electronic signature&#8221;<\/b> means an electronic signature, which is\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0uniquely linked to the signatory;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0reliably capable of identifying the signatory;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0created using secure signature creation device that the signatory can maintain; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0linked to the data to which it relates in such a manner that any subsequent change of the data or the connections between the data and the signature are detectable;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;asymmetric cryptosystem&#8221;<\/b> means an algorithm or series of algorithms, which provide a secure key pair;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;authorised officer&#8221;<\/b> means the Controller or a police officer or a public officer performing any functions under this Act; and includes any public officer authorised by the Minister or by the controller to perform any functions under this Act;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;certificate&#8221;<\/b> means a data message or other records confirming the link between a signatory and a signature creation data;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;certification service provider disclosure record&#8221;<\/b> means an online and publicly accessible record that concerns a licensed certification service provider, which is kept by the Controller under subsection 21(5);<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;certification practice statement&#8221;<\/b> means a declaration of the practices, which a certification service provider employs in issuing certificates generally or employs in issuing a particular certificate;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;certification service provider&#8221;<\/b> means a person that issues certificates and may provide other services related to electronic signatures;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;certify&#8221;<\/b> means to declare with reference to a certificate, with ample opportunity to reflect and with a duty to apprise oneself of all material facts;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;confirm&#8221;<\/b> means to ascertain through diligent inquiry and investigation;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;Controller&#8221;<\/b> means National Information Technology Authority-Uganda;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;correspond&#8221;<\/b>, with reference to keys, means to belong to the same key pair;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;currency point&#8221;<\/b> has the meaning assigned to it in the Schedule in this Act;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;digital signature&#8221;<\/b> means a transformation of a message using an asymmetric cryptosystem such that a person having the initial message and the signer&#8217;s public key can accurately determine\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0whether the transformation was created using the private key that corresponds to the signer&#8217;s public key; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0whether the message has been altered since the transformation was made;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;electronic signature&#8221;<\/b> means data in electronic form affixed to or logically associated with a data message, which may be used to identify the signatory in relation to the data message and indicate the signatory&#8217;s approval of the information contained in the data message; and includes an advance electronic signature and the secure signature;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;electronic signature product&#8221;<\/b> means configured hardware or software or relevant components of it, which are intended to be used by a certification service provider for the provision of electronic signature services or are intended to be used for the creation or verification of electronic signatures;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;forge a digital signature&#8221;<\/b> means\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0to create a digital signature without the authorisation of the rightful holder of the private key; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0to create a digital signature verifiable by a certificate listing as subscriber a person who either does not exist or does not hold the private key corresponding to the public key listed in the certificate;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;hold a private key&#8221;<\/b> means to be able to utilise a private key;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;incorporate by reference&#8221;<\/b> means to make one message a part of another message by identifying the message to be incorporated and expressing the intention that it be incorporated;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;issue a certificate&#8221;<\/b> means the act of a certification service provider in creating a certificate and notifying the subscriber listed in the certificate of the contents of the certificate;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;key pair&#8221;<\/b> means a private key and its corresponding public key in an asymmetric cryptosystem, where the public key can verify a digital signature that the private key creates;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;licensed certification service provider&#8221;<\/b> means a certification service provider to whom a licence has been issued by the Controller and whose licence is in effect;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;message&#8221;<\/b> means a digital representation of information;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;Minister&#8221;<\/b> means the Minister responsible for information and communication technology;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;notify&#8221;<\/b> means to communicate a fact to another person in a manner reasonably likely under the circumstances to impart knowledge of the information to the other person;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;person&#8221;<\/b> includes any company or association or body of persons corporate or unincorporate;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;prescribed&#8221;<\/b> means prescribed by or under this Act or any regulations made under this Act;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;private key&#8221;<\/b> means the key of a key pair used to create a digital signature;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;public key&#8221;<\/b> means the key of a key pair used to verify a digital signature and listed in the digital signature certificate;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;public key infrastructure&#8221;<\/b> means a framework for creating a secure method for exchanging information based on public key cryptography;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;publish&#8221;<\/b> means to record or file in a repository;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;qualified certification service provider&#8221;<\/b> means a certification service provider that satisfies the requirements under section 23;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;recipient&#8221;<\/b> means a person who receives or has a digital signature and is in a position to rely on it;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;recognised date or time stamp service&#8221;<\/b> means a date\/time stamp service recognised by the Controller under section 79;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;recognised repository&#8221;<\/b> means a repository recognised by the Controller under section 77;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;recommended reliance limit&#8221;<\/b> means the monetary amount recommended for reliance on a certificate under section 76;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;relying party&#8221;<\/b> means a person that may act on the basis of a certificate or an electronic signature;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;repository&#8221;<\/b> means a system for storing and retrieving certificates and other information relevant to digital signatures;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;revoke a certificate&#8221;<\/b> means to make a certificate ineffective permanently from a specified time forward;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;rightfully hold a private key&#8221;<\/b> means to be able to utilise a private key\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0which the holder or the holder&#8217;s agents have not disclosed to any person in contravention of this act; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0which the holder has not obtained through theft, deceit, eavesdropping or other unlawful means;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;security procedure&#8221;<\/b> means a procedure for the purpose of\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0verifying that an electronic record is that of a specific person; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0detecting error or alteration in the communication, content or storage of an electronic record since a specific point in time, which may require the use of algorithms or codes, identifying words or numbers, encryption, answer back or acknowledgement procedures or similar security devices;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;secure signature creation device&#8221;<\/b> means a signature creation device which meets the requirements laid down in section 4;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;signatory&#8221;<\/b> means a person that holds signature creation data and acts either on its own behalf or on behalf of the person it represents<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;signature creation device&#8221;<\/b> means configured software or hardware, used by the signatory to create an electronic signature;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;signature verification data&#8221;<\/b> means unique data such as codes or public cryptographic keys, used for the purpose of verifying an electronic signature;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;signature verification device&#8221;<\/b> means configured software or hardware, used for the purpose of verifying an electronic signature;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;signed&#8221;<\/b> or <b>&#8220;signature&#8221;<\/b> and its grammatical variations includes any symbol executed or adapted or any methodology or procedure employed or adapted, by a person with the intention of authenticating a record, including an electronic or digital method;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;subscriber&#8221;<\/b> means a person who\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0is the subject listed in a certificate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0accepts the certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0holds a private key which corresponds to a public key listed in that certificate;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;suspend a certificate&#8221;<\/b> means to make a certificate ineffective temporarily for a specified time forward;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;this Act&#8221;<\/b> includes any regulations made under this Act;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;time-stamp&#8221;<\/b> means\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0to append or attach to a message, digital signature or certificate a digitally signed notation indicating at least the date, time and identity of the person appending or attaching the notation; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the notation appended or attached;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;transactional certificate&#8221;<\/b> means a certificate, incorporating by reference one or more digital signatures, issued and valid for a specific transaction;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;trustworthy system&#8221;<\/b> means computer hardware and software which\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0are reasonably secure from intrusion and misuse;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0provide a reasonable level of availability, reliability and correct operation; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0are reasonably suited to performing their intended functions;<\/p>\n<p>\u00a0\u00a0\u00a0&#8220;valid certificate&#8221; means a certificate which\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0a licensed certification service provider has issued;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0has been accepted by the subscriber listed in it;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0has not been revoked or suspended; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0has not expired,<\/p>\n<p>but a transactional certificate is a valid certificate only in relation to the digital signature incorporated in it by reference;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;verify a digital signature&#8221;<\/b> means, in relation to a given digital signature, message and public key, to determine accurately that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the digital signature was created by the private key corresponding to the public key; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the message has not been altered since its digital signature was created;<\/p>\n<p>\u00a0\u00a0\u00a0<b>&#8220;writing&#8221;<\/b> or <b>&#8220;written&#8221;<\/b> includes any handwriting, typewriting, printing, electronic storage or transmission or any other method of recording information or fixing information in a form capable of being preserved.<\/p>\n<p>\u00a0\u00a0\u00a0(2) For the purposes of this Act, a certificate shall be revoked by making a notation to that effect on the certificate or by including the certificate in a set of revoked certificates.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The revocation of a certificate does not mean that it is destroyed or made illegible.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s3\"><\/a>3.\u00a0\u00a0\u00a0Equal treatment of signature technologies.<\/p>\n<p>Nothing in this Act shall be applied so as to exclude, restrict or deprive of legal effect any method of creating an electronic signature that satisfies the requirements for a signature in this Act or otherwise meets with the requirements of any other applicable law.<\/p>\n<p class=\"L5\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\">PART II<br \/>ELECTRONIC SIGNATURES.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s4\"><\/a>4.\u00a0\u00a0\u00a0Compliance with a requirement for a signature.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where the law requires a signature of a person, that requirement is met in relation to a data message if an electronic signature is used which is as reliable as was appropriate for the purpose for which the data message was generated or communicated, in light of all the circumstances, including any relevant agreement.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Subsection (1) applies whether the requirement referred to in that subsection in the form of an obligation or whether the law simply provides consequences for the absence of a signature.<\/p>\n<p>\u00a0\u00a0\u00a0(3) An electronic signature is considered to be reliable for the purpose of satisfying the requirement referred to in subsection (1) if\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the signature creation data are, within the context in which they are used, linked to the signatory and to no other person;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the signature creation data were, at the time of signing, under the control of the signatory and of no other person;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0any alteration to the electronic signature, made after the time of signing, is detectable; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0where a purpose of legal requirement for a signature is to provide assurance as to the integrity of the information to which it relates, any alteration made to that information after the time of signing is detectable.<\/p>\n<p>\u00a0\u00a0\u00a0(4) Subsection (3) does not limit the liability of any person\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0to establish in any other way, for the purpose of satisfying the requirement referred to in subsection (1), the reliability of an electronic signature; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0to adduce evidence of the non-reliability of an electronic signature.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s5\"><\/a>5.\u00a0\u00a0\u00a0Conduct of the signatory.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where signature creation data can be used to create a signature that has legal effect, each signatory shall\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0exercise reasonable care to avoid unauthorised use of its signature creation data;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0without undue delay, notify any person that may reasonably be expected by the signatory to rely on or to provide services in support of the electronic signature if\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0the signatory knows that the signature creation data have been compromised; or<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0the circumstances known to the signatory give rise to a substantial risk that the signature creation data may have been compromised;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0where a certificate is used to support the electronic signature, exercise reasonable care to ensure the accuracy and completeness of all material representations made by the signatory which are relevant to the certificate throughout its life-cycle or which are to be included in the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s6\"><\/a>6.\u00a0\u00a0\u00a0Variation by agreement.<\/p>\n<p>\u00a0\u00a0\u00a0The provisions of this Act may be derogated from or their effect may be varied by agreement unless that agreement would not be valid or effective under any law.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s7\"><\/a>7.\u00a0\u00a0\u00a0Conduct of the relying party.<\/p>\n<p>\u00a0\u00a0\u00a0A relying party shall bear the legal consequences of his or her failure to\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0take reasonable steps to verify the reliability of an electronic signature; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0where an electronic signature is supported by a certificate, take reasonable steps\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0to verify the validity, suspension or revocation of the certificate; and<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0to observe any limitation with respect to the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s8\"><\/a>8.\u00a0\u00a0\u00a0Trustworthiness.<\/p>\n<p>\u00a0\u00a0\u00a0When determining whether or to what extent any systems procedures and human resources utilised by a certification service provider are trustwo<\/p>\n<p>{mprestriction ids=&#8221;1,2,3&#8243;}<\/p>\n<p>rthy, regard may be had to the following factors\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0financial and human resources, including existence of assets;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0quality of hardware and software systems;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0procedure for processing of certificates and applications for certificates and retention of records;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0availability of information to signatories identified in certificates and to potential relying parties;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0regularity and extent of audit by an independent body;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>f<\/i>)\u00a0\u00a0\u00a0the existence of a declaration by the state, an accreditation body or the certification service provider regarding compliance with or existence of the foregoing; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>g<\/i>)\u00a0\u00a0\u00a0any other relevant factor.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s9\"><\/a>9.\u00a0\u00a0\u00a0Conduct of the certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where a certification service provider provides services to support an electronic signature that may be used for legal effect as a signature, that certification service provider shall\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0act in accordance with representations made by it with respect to its policies and practices;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0exercise reasonable care to ensure the accuracy and completeness of all material representations made by it that are relevant to the certificate throughout its life-cycle or which are included in the certificate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0provide reasonably accessible means which enable a relying party to ascertain from the certificate\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0the identity of the certification service provider;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0that the signatory that is identified in the certificate had control of the signature creation data at the time when the certificate was issued;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iii)\u00a0\u00a0\u00a0that signature creation data were valid at or before the time when the certificate was issued;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0provide reasonably accessible means which enable a relying party to ascertain, where relevant, from the certificate or otherwise\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0the method used to identify the signatory;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0any limitation on the purpose or value for which the signature creation data or the certificate may be used;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iii)\u00a0\u00a0\u00a0that the signature creation data are valid and have not been compromised;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iv)\u00a0\u00a0\u00a0any limitation on the scope or extent of liability stipulated by the certification service provider;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(v)\u00a0\u00a0\u00a0whether means exist for the signatory to give notice under section 4(1);<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(vi)\u00a0\u00a0\u00a0whether a timely revocation service is offered;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0where services under paragraph (<i>d<\/i>)(v) are offered, provide a means for a signatory to give notice under section 4(1)(<i>b<\/i>) and, where services under paragraph (<i>d)<\/i>(vi) are offered, ensure the availability of a timely revocation service;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>f<\/i>)\u00a0\u00a0\u00a0utilise trustworthy systems, procedures and human resources in performing its services.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certification service provider shall be liable for its failure to satisfy the requirements of subsection (1).<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s10\"><\/a>10.\u00a0\u00a0\u00a0Advanced signatures.<\/p>\n<p>\u00a0\u00a0\u00a0(1) An advanced electronic signature, verified with a qualified certificate, is equal to an autographic signature in relation to data in electronic form and has therefore equal legal effectiveness and admissibility as evidence.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The advanced signature verification process shall ensure that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the data used for verifying the electronic signature correspond to the data displayed to the verifier;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the signature is reliably verified and the result of the verification and identity of the certificate holder is correctly displayed to the verifier;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0the verifier can reliably establish the contents of the signed data;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0the authenticity and validity of the certificate required at the time of signature verification are verified;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0the use of a pseudonym is clearly indicated;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>f<\/i>)\u00a0\u00a0\u00a0any security-relevant changes can be detected.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s11\"><\/a>11.\u00a0\u00a0\u00a0Secure electronic signature.<\/p>\n<p>\u00a0\u00a0\u00a0Where, through the application of a prescribed security procedure or a commercially reasonable security procedure agreed to by the parties involved, an electronic signature is executed in a trustworthy manner, reasonably and in good faith relied upon by the relying party, that signature shall be treated as a secure electronic signature at the time of verification to the extent that it can be verified that the electronic signature satisfied, at the time it was made, the following criteria\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the signature creation data used for signature creation is unique and its secrecy is reasonably assured;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0it was capable of being used to objectively identify that person;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0it was created in a manner or using a means under the sole control of the person using it, that cannot be readily duplicated or compromised;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0it is linked to the electronic record to which it relates in such a manner that if the record was changed to electronic signature would be invalidated;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0the signatory can reliably protect his or her signature creation data from unauthorised access.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s12\"><\/a>12.\u00a0\u00a0\u00a0Presumptions relating to secure and advanced electronic signatures.<\/p>\n<p>\u00a0\u00a0\u00a0(1) In any civil proceedings involving a secure electronic record, it shall be presumed, unless the contrary is proved, that the secure or advanced electronic record has not been altered since the specific point in time to which the secure status relates.<\/p>\n<p>\u00a0\u00a0\u00a0(2) In any civil proceedings involving a secure or advanced electronic signature, the following shall be presumed unless the contrary is proved\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the secure or advanced electronic signature is the signature of the person to whom it correlates; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the secure or advanced electronic signature was affixed by that person with the intention of signing or approving the electronic record.<\/p>\n<p>\u00a0\u00a0\u00a0(3) In the absence of a secure or advanced electronic signature, nothing in this Part shall create any presumption relating to the authenticity and integrity of the electronic record or an electronic signature.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The effect of presumptions provided in this section is to place on the party challenging the genuineness of a secure or advanced electronic signature both the burden of going forward with evidence to rebut the presumption and the burden of persuading the court of the fact that the non-existence of the presumed fact is more.<\/p>\n<p class=\"L5\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\">PART III<br \/>SECURE DIGITAL SIGNATURES.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s13\"><\/a>13.\u00a0\u00a0\u00a0Secure digital signatures.<\/p>\n<p>\u00a0\u00a0\u00a0When a portion of an electronic record is signed with a digital signature the digital signature shall be treated as a secure electronic signature in respect of that portion of the record, if\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the digital signature was created during the operational period of a valid certificate and is verified by reference to a public key listed in the certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the certificate is considered trustworthy, in that it is an accurate binding of a public key to a person&#8217;s identity because\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0the certificate was issued by a certification service provider operating in compliance with regulations made under this Act;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0the certificate was issued by a certification service provider outside Uganda recognised for the purpose by the Controller pursuant to regulations made under this Act;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iii)\u00a0\u00a0\u00a0the certificate was issued by a department or ministry of the Government, an organ of state of statutory corporation approved by the minister to act as a certification service provider on such conditions as the regulations may specify; or<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iv)\u00a0\u00a0\u00a0the parties have expressly agreed between themselves to use digital signatures as a security procedure and the digital signature was properly verified by reference to the sender&#8217;s public key.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s14\"><\/a>14.\u00a0\u00a0\u00a0Satisfaction of signature requirements.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where a rule of law requires a signature or provides for certain consequences in the absence of a signature, that rule shall be satisfied by a digital signature where\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0that digital signature is verified by reference to the public key listed in a valid certificate issued by a licensed certification service provider;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0that digital signature was affixed by the signer with the intention of signing the message; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0the recipient has no knowledge or notice that the signer\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0has breached a duty as a subscriber; or<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0does not rightfully hold the private key used to affix the digital signature.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Notwithstanding any written law to the contrary\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0a document signed with a digital signature in accordance with this Act shall be as legally binding as a document signed with a handwritten signature, an affixed thumbprint or any other mark; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0a digital signature created in accordance with this Act shall be taken to be a legally binding signature.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Nothing in this Act shall preclude a symbol from being valid as a signature under any other applicable law.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s15\"><\/a>15.\u00a0\u00a0\u00a0Unreliable digital signatures.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Unless otherwise provided by law or contract, the recipient of a digital signature assumes the risk that a digital signature is forged, if reliance on the digital signature is not reasonable under the circumstances.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where the recipient decides not to rely on a digital signature under this section, the recipient shall promptly notify the signer of its determination not to rely on a digital signature and the grounds for that determination.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s16\"><\/a>16.\u00a0\u00a0\u00a0Digitally signed document taken to be written document.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A message shall be as valid, enforceable and effective as if it had been written on paper if\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0it bears in its entirety a digital signature; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0that digital signature is verified by the public key listed in a certificate which\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0was issued by a licensed certification service provider; and<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0was valid at the time the digital signature was created.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Nothing in this Act shall preclude any message, document or record from being considered written or in writing under any other applicable law.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s17\"><\/a>17.\u00a0\u00a0\u00a0Digitally signed document deemed to be original document.<\/p>\n<p>\u00a0\u00a0\u00a0A copy of a digitally signed message shall be as valid, enforceable and effective as the original of the message unless it is evident that the signer designated an instance of the digitally signed message to be a unique original, in which case only that instance constitutes the valid, enforceable and effective message.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s18\"><\/a>18.\u00a0\u00a0\u00a0Authentication of digital signatures.<\/p>\n<p>\u00a0\u00a0\u00a0A certificate issued by a licensed certification service provider shall be an acknowledgement of a digital signature verified by reference to the public key listed in the certificate, regardless of whether words of an express acknowledgement appear with the digital signature and regardless of whether the signer physically appeared before the licensed certification service provider when the digital signature was created, if that digital signature is\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0verifiable by that certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0was affixed when that certificate was valid.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s19\"><\/a>19.\u00a0\u00a0\u00a0Presumptions in adjudicating disputes.<\/p>\n<p>\u00a0\u00a0\u00a0In adjudicating a dispute involving a digital signature, a court shall presume\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0that a certificate digitally signed by a licensed certification service provider and\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0published in a recognised repository; or<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0made available by the issuing licensed certification service provider or by the subscriber listed in the certificate, is issued by the licensed certification service provider which digitally signed it and is accepted by the subscriber listed in it;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0that the information listed in a valid certificate and confirmed by a licensed certification service provider issuing the certificate is accurate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0that where the public key verifies a digital signature listed in a valid certificate issued by a licensed certification service provider\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0that digital signature is the digital signature of the subscriber listed in that certificate;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0that digital signature was affixed by that subscriber with the intention of signing the message; and<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iii)\u00a0\u00a0\u00a0the recipient of that digital signature has no knowledge or notice that the signer\u2014<\/p>\n<p class=\"TTI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(<i>aa<\/i>)\u00a0\u00a0\u00a0has breached a duty as a subscriber; or<\/p>\n<p class=\"TTI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(<i>ab<\/i>)\u00a0\u00a0\u00a0does not rightfully hold the private key used to affix the digital signature; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0that a digital signature was created before it was time-stamped by a recognised date or time stamp service utilising a trustworthy system.<\/p>\n<p class=\"L5\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\">PART IV<br \/>PUBLIC KEY INFRASTRUCTURE.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s20\"><\/a>20.\u00a0\u00a0\u00a0Sphere of application.<\/p>\n<p>\u00a0\u00a0\u00a0This part applies to digital signatures or signatures that are able to use the public key infrastructure (PKI).<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s21\"><\/a>21.\u00a0\u00a0\u00a0Controller.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller shall, in particular be responsible for monitoring and overseeing the activities of certification service providers and shall perform the functions conferred on the Controller under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The Controller shall exercise its functions under this Act subject to such directions as to the general policy guidelines as may be given by the Minister.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The Controller shall maintain a publicly accessible database containing a certification service provider disclosure record for each certification service provider, which shall contain all the particulars required under regulations made under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The Controller shall publish the contents of the database in at least one recognised repository.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s22\"><\/a>22.\u00a0\u00a0\u00a0Certification service providers to be licensed.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A person shall not carry on or operate or hold himself out as carrying on or operating, as a certification service provider unless that person has a valid licence issued under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding 240 currency points or imprisonment not exceeding 10 years or both; and in the case of a continuing offence is in addition liable to a daily fine not exceeding 10 currency points for each day the offence continues.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The Minister may, on an application in writing being made in accordance with this Act, exempt a person operating as a certification service provider within an organisation from the requirement of a licence under this section where certificates and key pairs are issued to members of the organisation for internal use only; but the Minister shall not delegate that power to the Controller.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The liability limits specified in Part IV shall not apply to an exempted certification service provider and Part V shall not apply in relation to a digital signature verified by a certificate issued by an exempted certification service provider.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s23\"><\/a>23.\u00a0\u00a0\u00a0Qualifications of certification service providers.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Minister in consultation with National Information Technology Authority-Uganda shall, by regulations made under this Act, prescribe the qualifications required for certification service providers.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The Minister in consultation with National Information Technology Authority-Uganda may vary or amend the qualifications prescribed under subsection (1) but any such variation or amendment shall not be applied to a certification service provider holding a valid licence under this Act until the expiry of that licence.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s24\"><\/a>24.\u00a0\u00a0\u00a0Functions of licensed certification service providers.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The function of a certification service provider shall be to issue a certificate to a subscriber upon application and upon satisfaction of the certification service providers requirements as to the identity of the subscriber to be listed in the certificate and upon payment of the prescribed fees and charges.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The certification service provider shall, before issuing a certificate under this Act, take all reasonable measures to check for proper identification of the subscriber to be listed in the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s25\"><\/a>25.\u00a0\u00a0\u00a0Application for licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) An application for a licence under this Act shall be made in writing to the Controller in such form as may be prescribed.<\/p>\n<p>\u00a0\u00a0\u00a0(2) An application under subsection (1) shall be accompanied by such documents or information as may be prescribed and the Controller may, at any time after receiving the application and before it is determined, require the applicant to provide such additional documents or information as may be considered necessary by the Controller for the purposes of determining the suitability of the applicant for the licence.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Where any additional document or information required under subsection (2) is not provided by the applicant within the time specified in the requirement or any extension granted by the Controller, the application shall be taken to be withdrawn and shall not be further proceeded with, without prejudice to a fresh application being made by the applicant.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s26\"><\/a>26.\u00a0\u00a0\u00a0Grant or refusal of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller shall, on an application having been duly made in accordance with section 25 and after being provided with all the documents and information as he may require, consider the application and when he or she is satisfied that the applicant is a qualified certification service provider and a suitable licensee and upon payment of the prescribed fee, grant the licence with or without conditions or refuse to grant a licence.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A licence granted under subsection (1) shall set out the duration of the licence and the licence number.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The terms and conditions imposed under the licence may at any time be varied for just cause or amended by the Controller but the licensee shall be given a reasonable opportunity of being heard.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The Controller shall notify the applicant in writing of his or her decision to grant or refuse to grant a licence within 30 days of receiving the application.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s27\"><\/a>27.\u00a0\u00a0\u00a0Revocation of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may revoke a licence granted under section 26 if satisfied that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the certification service provider has failed to comply with an obligation imposed upon it by or under this Act;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the certification service provider has contravened any condition imposed under the licence, any provision of this Act or any other written law;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0the certification service provider has, either in connection with the application for the licence or at any time after the grant of the licence, provided the Controller with false, misleading or inaccurate information or a document or declaration made by or on behalf of the certification service provider or by or on behalf of a person who is or is to be a director, Controller or manager of the licensed certification service provider which is false, misleading or inaccurate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0the certification service provider is carrying on its business in a manner which is prejudicial to the interest of the public or to the national economy;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0the certification service provider has insufficient assets to meet its liabilities;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>f<\/i>)\u00a0\u00a0\u00a0a winding up order has been made against the licensed certification service provider or a resolution for its voluntary winding-up has been passed;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>g<\/i>)\u00a0\u00a0\u00a0the certification service provider or its director, Controller or manager has been convicted of an offence under this Act in his or her capacity as; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>h<\/i>)\u00a0\u00a0\u00a0the certification service provider has ceased to be a qualified certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Before revoking a licence, the Controller shall give the licensed certification service provider a notice in writing of his or her intention to revoke the licence and require the licensed certification service provider to show cause within 30 days as to why the licence should not be revoked.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Where the Controller decides to revoke the licence, he or she shall notify the certification service provider of his or her decision by a notice in writing within 48 hours of making the decision.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The revocation of a licence shall take effect where there is no appeal against the revocation, on the expiration of 30 days from the date on which the notice of revocation is served on the licensed certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(5) Where an appeal has been made against the revocation of a licence, the certification service provider whose licence has been revoked shall not issue any certificates until the appeal has been disposed of and the revocation has been set aside by the Minister but nothing in this subsection shall prevent the certification service provider from fulfilling its other obligations to its subscribers during that period.<\/p>\n<p>\u00a0\u00a0\u00a0(6) A person who contravenes subsection (5) commits an offence and is liable, on conviction, to a fine not exceeding 240 currency points or to imprisonment not exceeding 10 years or both.<\/p>\n<p>\u00a0\u00a0\u00a0(7) Where the revocation of a licence has taken effect, the Controller shall, as soon as practicable, cause the revocation to be published in the certification service provider disclosure record he or she maintains for the certification service provider concerned and advertised in at least two English language national daily newspapers for at least three consecutive days.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s28\"><\/a>28.\u00a0\u00a0\u00a0Appeal.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A person who is aggrieved by\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the refusal of the Controller to license a certification service provider under section 26 or to renew a licence under section 35; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the revocation of a licence under section 27, may appeal in writing to the Minister within 30 days from the date on which the notice of refusal or revocation is served on that person.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The Minister shall, upon receipt of the appeal respond within 30 days.<\/p>\n<p>\u00a0\u00a0\u00a0(3) A person not satisfied with the Minister&#8217;s decision may appeal to the High Court.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s29\"><\/a>29.\u00a0\u00a0\u00a0Surrender of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider may surrender its licence by forwarding it to the Controller with a written notice of its surrender.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The surrender shall take effect on the date the Controller receives the licence and the notice under subsection (1) or where a later date is specified in the notice, on that date.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The licensed certification service provider shall, not later than 14 days after the date referred to in subsection (2), cause the surrender to be published in the certification service provider disclosure record of the certification service provider concerned and advertised in at least two English language national daily newspapers for at least three days consecutive.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s30\"><\/a>30.\u00a0\u00a0\u00a0Effect of revocation, surrender or expiry of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where the revocation of a licence under section 27 or its surrender under section 29 has taken effect or where the licence has expired, the licensed certification service provider shall immediately cease to carry on or operate any business in respect of which the licence was granted.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Notwithstanding subsection (1), the Minister may, on the recommendation of the Controller, authorise the licensed certification service provider in writing to carry on its business for such duration as the Minister may specify in the authorisation for the purpose of winding up its affairs.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Notwithstanding subsection (1), a licensed certification service provider whose licence has expired shall be entitled to carry on its business as if its licence had not expired upon proof being submitted to the Controller that the licensed certification service provider has applied for a renewal of the licence and that such application is pending determination.<\/p>\n<p>\u00a0\u00a0\u00a0(4) A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding 72 currency points or to imprisonment not exceeding 10 years or both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding five currency points for each day the offence continues.<\/p>\n<p>\u00a0\u00a0\u00a0(5) Without prejudice to the Controller&#8217;s powers under section 26, the revocation of a licence under section 27 or its surrender under section 29 or its expiry shall not affect the validity or effect of any certificate issued by the certification service provider concerned before such revocation, surrender or expiry.<\/p>\n<p>\u00a0\u00a0\u00a0(6) For the purposes of subsection (5), the Controller shall appoint another licensed certification service provider to take over the certificates issued by the certification service provider whose licence has been revoked or surrendered or has expired and the certificate shall, to the extent that they comply with the requirements of the appointed licensed certification service provider, be deemed to have been issued by that licensed certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(7) Subsection (6) shall not preclude the appointed licensed certification service provider from requiring the subscriber to comply with its requirements in relation to the issue of certificates or from issuing a new certificate to the subscriber for the unexpired period of the original certificate except that any additional fees or charges to be imposed shall only be imposed with the prior written approval of the Controller.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s31\"><\/a>31.\u00a0\u00a0\u00a0Effect of lack of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The liability limits specified in Part IV shall not apply to unlicensed certification service providers.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Part V shall not apply in relation to an electronic signature, which cannot be verified by a certificate issued by a licensed certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(3) In any other case, unless the parties expressly provide otherwise by contract between themselves, the licensing requirements under this Act shall not affect the effectiveness, enforceability or validity of any digital signature.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s32\"><\/a>32.\u00a0\u00a0\u00a0Return of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where the revocation of a licence under section 27 has taken effect or where the licence has expired and no application for its renewal has been submitted within the period specified or where an application for renewal has been refused under section 35, the licensed certification service provider shall within 14 days return the licence to the Controller.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding seventy two eight currency points or to imprisonment not exceeding three years or to both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding five currency points for each day the offence continues and the court shall retain the licence and forward it to the Controller.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s33\"><\/a>33.\u00a0\u00a0\u00a0Restricted licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may classify licences according to specified limitations including\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0maximum number of outstanding certificates;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0cumulative maximum of recommended reliance limits in certificates issued by the licensed certification service provider; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0issuance only within a single firm or organisation.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The Controller may issue licences restricted according to the limits of each classification.<\/p>\n<p>\u00a0\u00a0\u00a0(3) A licensed certification service provider that issues a certificate exceeding the restrictions of its licence commits an offence.<\/p>\n<p>\u00a0\u00a0\u00a0(4) Where a licensed certification service provider issues a certificate exceeding the restrictions of its licence, the liability limits specified in Part IV shall not apply to the licensed certification service provider in relation to that certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(5) Nothing in subsection (3) or (4) shall affect the validity or effect of the issued certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s34\"><\/a>34.\u00a0\u00a0\u00a0Restriction on use of expression <b>&#8220;certification service provider&#8221;<\/b>.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Except with the written consent of the Controller, a person shall not being a licensed certification service provider, assume or use the expressions &#8220;certification service provider&#8221; or &#8220;licensed certification service provider&#8221;, as the case may be or any derivative of those expressions in any language or any other words in any language capable of being construed as indicating the carrying on or operation of such business, in relation to the business or any part of the business carried on by that person or make any representation to that effect in any bill head, letter, paper, notice, advertisement or in any other manner.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding 168 currency points or to imprisonment not exceeding seven years or to both.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s35\"><\/a>35.\u00a0\u00a0\u00a0Renewal of licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A licensed certification service provider shall submit an application to the Controller in such form as may be prescribed for the renewal of its licence at least 30 days before the date of expiry of the licence and the application shall be accompanied by such documents and information as may be required by the Controller.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The prescribed fee shall be payable upon approval of the application.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Where a licensed certification service provider has no intention of renewing its licence, the licensed certification service provider shall, at least 30 days before the expiry of the licence, publish the intention in the certification service provider disclosure record of the certification service provider concerned and advertise such intention in at least two English language national daily newspapers for at least five consecutive days.<\/p>\n<p>\u00a0\u00a0\u00a0(4) Without prejudice to any other grounds, the Controller may refuse to renew a licence where the requirements of subsection (1) have not been complied with.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s36\"><\/a>36.\u00a0\u00a0\u00a0Lost licence.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where a certification service provider has lost its licence, it shall immediately notify the Controller in writing of the loss.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The certification service provider shall, as soon as practicable, submit an application for a replacement licence accompanied by all such information and documents as may be required by the Controller together with the prescribed fee.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s37\"><\/a>37.\u00a0\u00a0\u00a0Recognition of other licenses.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may recognise, by order published in the <i>Gazette<\/i>, certification service providers licensed or otherwise authorised by entities outside Uganda that satisfy the prescribed requirements.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where a licence or other authorisation of an entity is recognised under subsection (1)\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the recommended reliance limit, if any, specified in a certificate issued by the certification service provider licensed or otherwise authorised by such an entity shall have effect in the same manner as a recommended reliance limit specified in a certificate issued by a certification service provider of Uganda; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0Part IV shall apply to the certificates issued by the certification service provider licensed or otherwise authorised by such entity in the same manner as it applies to a certificate issued by a certification service provider of Uganda.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s38\"><\/a>38.\u00a0\u00a0\u00a0Performance audit.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The operations of a certification service provider shall be audited a least once a year to evaluate its compliance with this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The audit shall be carried out by an internationally recognised computer security professional or a certified public accountant having expertise in the relevant field.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The qualifications of the auditors and the procedure for an audit shall be as may be prescribed by regulations made under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The Controller shall maintain and publish, the date and result of the audit in the certification service provider disclosure record he or she maintains for the certification service provider concerned.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s39\"><\/a>39.\u00a0\u00a0\u00a0Activities of certification service providers.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider shall only carry on such activities as may be specified in its licence.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certification service provider shall carry on its activities in accordance with this Act and any regulations made under this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s40\"><\/a>40.\u00a0\u00a0\u00a0Requirement to display licence.<\/p>\n<p>\u00a0\u00a0\u00a0A certification service provider shall at all times display its licence in a conspicuous place at its place of business and on its website.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s41\"><\/a>41.\u00a0\u00a0\u00a0Requirement to submit information on business operations.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A licensed certification service provider shall submit to the Controller such information and particulars including financial statements, audited balance sheets and profit and loss accounts relating to its entire business operations as may be required by the Controller within the time he or she may determine.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding 24 currency points or imprisonment not exceeding one year or both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding two currency points for each day the offence continues.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s42\"><\/a>42.\u00a0\u00a0\u00a0Notification of change of information.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider shall, before making an amendment or alteration to any of its constituent documents or before any change in its director or chief executive officer, furnish the Controller particulars in writing of any proposed amendment, alteration or change.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A licensed certification service provider shall immediately notify the Controller of any amendment or alteration to any information or document which has been furnished to the Controller in connection with the licence.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s43\"><\/a>43.\u00a0\u00a0\u00a0Use of trustworthy systems.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider shall only use a trustworthy system\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0to issue, suspend or revoke a certificate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0to publish or give notice of the issuance, suspension or revocation of a certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0to create a private key, whether for itself or for a subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A subscriber shall only use a trustworthy system to create a private key.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s44\"><\/a>44.\u00a0\u00a0\u00a0Disclosures on inquiry.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider shall, on an inquiry being made to it under this Act, disclose any material certification practice statement and any fact material to either the reliability of a certificate, which it has issued or its ability to perform its services.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certification service provider may require a signed, written and reasonably specific inquiry from an identified person and payment of the prescribed fee, as conditions precedent to effecting a disclosure required under subsection (1).<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s45\"><\/a>45.\u00a0\u00a0\u00a0Prerequisites to issue of certificate to subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider may issue a certificate to a subscriber where the following conditions are satisfied\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the certification service provider has received a request for issuance signed by the prospective subscriber; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the certification service provider has confirmed that\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0the prospective subscriber is the person to be listed in the certificate to be issued;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0if the prospective subscriber is acting through one or more agents, the subscriber has duly authorised the agent or agents to have custody of the subscriber&#8217;s private key and to request issuance of a certificate listing the corresponding public key;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iii)\u00a0\u00a0\u00a0the information in the certificate to be issued is accurate;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(iv)\u00a0\u00a0\u00a0the prospective subscriber rightfully holds the private key corresponding to the public key to be listed in the certificate;<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(v)\u00a0\u00a0\u00a0the prospective subscriber holds a private key capable of creating a digital signature; and<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(vi)\u00a0\u00a0\u00a0the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the prospective subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The requirements of subsection (1) shall not be waived or disclaimed by the certification service provider, the subscriber or both.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s46\"><\/a>46.\u00a0\u00a0\u00a0Publication of issued and accepted certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where the subscriber accepts the issued certificate, the certification service provider shall publish a signed copy of the certificate in a recognised repository, as the certification service provider and the subscriber named in the certificate may agree, unless a contract between the certification service provider and the subscriber provides otherwise.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where the subscriber does not accept the certificate, a certification service provider shall not publish it or shall cancel its publication if the certificate has already been published.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s47\"><\/a>47.\u00a0\u00a0\u00a0Adoption of more rigorous requirements permitted.<\/p>\n<p>\u00a0\u00a0\u00a0Nothing in sections 31 and 32 shall preclude a certification service provider from conforming to standards, certification practice statements, security plans or contractual requirements more rigorous than, but nevertheless consistent with, this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s48\"><\/a>48.\u00a0\u00a0\u00a0Suspension or revocation of certificate for faulty issuance.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where after issuing a certificate a certification service provider confirms that it was not issued in accordance with sections 31 and 32, the certification service provider shall immediately revoke it.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certification service provider may suspend a certificate which it has issued for a reasonable period not exceeding 48 hours as may be necessary for an investigation to be carried out to confirm the grounds for a revocation under subsection (1).<\/p>\n<p>\u00a0\u00a0\u00a0(3) The certification service provider shall immediately notify the subscriber of a revocation or suspension under this section.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s49\"><\/a>49.\u00a0\u00a0\u00a0Suspension or revocation of certificate by order.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may order the certification service provider to suspend or revoke a certificate where the Controller determines that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the certificate was issued without compliance with sections 31 and 32; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the noncompliance poses a significant risk to persons reasonably relying on the certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Before making a determination under subsection (1), the Controller shall give the licensed certification service provider and the subscriber a reasonable opportunity of being heard.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Notwithstanding subsections (1) and (2), where in the opinion of the Controller there exists an emergency that requires an immediate remedy, the Controller may, after consultation with the Minister, suspend a certificate for a period not exceeding 48 hours.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s50\"><\/a>50.\u00a0\u00a0\u00a0Warranties to subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0(1) By issuing a certificate, a certification service provider warrants to the subscriber named in the certificate that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the certificate contains no information known to the certification service provider to be false;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the certificate satisfies all the requirements of this Act; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0the certification service provider has not exceeded any limits of its licence in issuing the certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certification service provider shall not disclaim or limit the warranties under subsection (1).<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s51\"><\/a>51.\u00a0\u00a0\u00a0Continuing obligations to subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0Unless the subscriber and certification service provider otherwise agree, a certification service provider, by issuing a certificate, promises to the subscriber\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0to act promptly to suspend or revoke a certificate in accordance with Part IV; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0to notify the subscriber within a reasonable time of any facts known to the licensed certification service provider, which significantly affect the validity or reliability of the certificate once it is issued.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s52\"><\/a>52.\u00a0\u00a0\u00a0Representations upon issuance.<\/p>\n<p>\u00a0\u00a0\u00a0By issuing a certificate, a certification service provider certifies to all who reasonably rely on the information contained in the certificate that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the information in the certificate and listed as confirmed by the licensed certification service provider is accurate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0all information foreseeable and material to the reliability of the certificate is stated or incorporated by reference within the certificate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0the subscriber has accepted the certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0the certification service provider has complied with all applicable laws governing the issue of the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s52\"><\/a>52.\u00a0\u00a0\u00a0Representations upon publication.<\/p>\n<p>\u00a0\u00a0\u00a0By publishing a certificate, a certification service provider certifies to the repository in which the certificate is published and to all who reasonably rely on the information contained in the certificate that the licensed certification service provider has issued the certificate to the subscriber.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s54\"><\/a>54.\u00a0\u00a0\u00a0Implied representations by subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0By accepting a certificate issued by a certification service provider, the subscriber listed in the certificate certifies to all who reasonably rely on the information contained in the certificate that\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0the subscriber rightfully holds the private key corresponding to the public key listed in the certificate;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0all representations made by the subscriber to the certification service provider and material to information listed in the certificate are true; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0all material representations made by the subscriber to a certification service provider or made in the certificate and not confirmed by the certification service provider in issuing the certificate are true.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s55\"><\/a>55.\u00a0\u00a0\u00a0Representations by agent of subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0By requesting on behalf of a principal the issue of a certificate naming the principal as subscriber, the requesting person certifies in that person&#8217;s own right to all who reasonably rely on the information contained in the certificate that the requesting person\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0holds all authority legally required to apply for issuance of a certificate naming the principal as subscriber; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0has authority to sign digitally on behalf of the principal, and, if that authority is limited in any way, adequate safeguards exist to prevent a digital signature exceeding the bounds of the person&#8217;s authority.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s56\"><\/a>56.\u00a0\u00a0\u00a0Disclaimer or indemnity limited.<\/p>\n<p>\u00a0\u00a0\u00a0A person shall not disclaim or contractually limit the application of this part, nor obtain indemnity for its effects, if the disclaimer, limitation or indemnity restricts liability for misrepresentation as against persons reasonably relying on the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s57\"><\/a>57.\u00a0\u00a0\u00a0Indemnification of certification service provider by subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0(1) By accepting a certificate, a subscriber undertakes to indemnify the issuing licensed certification service provider for any loss or damage caused by issue or publication of the certificate in reliance on\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0a false and material representation of fact by the subscriber; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the failure by the subscriber to disclose a material fact, if the representation or failure to disclose was made either with intent to deceive the certification service provider or a person relying on the certificate or with negligence.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where the certification service provider issued the certificate at the request of one or more agents of the subscriber, the agent or agents personally undertake to indemnify the certification service provider under this section, as if they were accepting subscribers in their own right.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The indemnity provided in this section shall not be disclaimed or contractually limited in scope.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s58\"><\/a>58.\u00a0\u00a0\u00a0Certification of accuracy of information given.<\/p>\n<p>\u00a0\u00a0\u00a0When obtaining information from a subscriber which is material to the issue of a certificate, the certification service provider may require the subscriber to certify the accuracy of the relevant information under oath or affirmation.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s59\"><\/a>59.\u00a0\u00a0\u00a0Duty of subscriber to keep private key secure.<\/p>\n<p>\u00a0\u00a0\u00a0By accepting a certificate issued by a certification service provider, the subscriber named in the certificate assumes a duty to exercise reasonable care to retain control of the private key and prevent its disclosure to any person not authorised to create the subscriber&#8217;s digital signature.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s60\"><\/a>60.\u00a0\u00a0\u00a0Property in private key.<\/p>\n<p>\u00a0\u00a0\u00a0A private key is the personal property of the subscriber who rightfully holds it.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s61\"><\/a>61.\u00a0\u00a0\u00a0Fiduciary duty of a certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0Where a certification service provider holds the private key corresponding to a public key listed in a certificate which it has issued, the certification service provider shall hold the private key as a fiduciary of the subscriber named in the certificate and may use that private key only with the subscriber&#8217;s prior written approval, unless the subscriber expressly and in writing grants the private key to the licensed certification service provider and expressly and in writing permits the licensed certification service provider to hold the private key according to other terms.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s62\"><\/a>62.\u00a0\u00a0\u00a0Suspension of certificate by certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Unless the certification service provider and the subscriber agree otherwise, the licensed certification service provider, which issued a certificate, which is not a transactional certificate, shall suspend the certificate for a period not exceeding 48 hours\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0upon request by a person identifying himself as the subscriber named in the certificate or as a person in a position likely to know of a compromise of the security of a subscriber&#8217;s private key, such as an agent, business associate, employee or member of the immediate family of the subscriber; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0by order of the Controller under section 35.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The certification service provider shall take reasonable measures to check the identity or agency of the person requesting suspension.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s63\"><\/a>63.\u00a0\u00a0\u00a0Suspension of certificate by Controller.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Unless the certificate provides otherwise or the certificate is a transactional certificate, the Controller may suspend a certificate issued by a certification service provider for a period of 48 hours, if\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0a person identifying himself or herself as the subscriber named in the certificate or as an agent, business associate, employee or member of the immediate family of the subscriber requests suspension; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0the requester represents that the certification service provider, which issued the certificate, is unavailable.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The Controller may require the person requesting suspension to provide evidence, including a statement under oath or affirmation regarding his or her identity and authorisation and the unavailability of the issuing licensed certification service provider and may decline to suspend the certificate in his or her discretion.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The Controller or other law enforcement agency may investigate suspensions by the Controller for possible wrongdoing by persons requesting suspension.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s64\"><\/a>64.\u00a0\u00a0\u00a0Notice of suspension.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Upon suspension of a certificate by a certification service provider, the certification service provider shall publish a signed notice of the suspension in the repository specified in the certificate for publication of notice of suspension.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where one or more repositories are specified, the certification service provider shall publish signed notices of the suspension in all those repositories.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Where any repository specified no longer exists or refuses to accept publication or if no such repository is recognised under section 69 the certification service provider shall also publish the notice in a recognised repository.<\/p>\n<p>\u00a0\u00a0\u00a0(4) Where a certificate is suspended by the Controller, the Controller shall give notice as required in this section for a certification service provider if the person requesting suspension pays in advance any prescribed fee required by a repository for publication of the notice of suspension.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s65\"><\/a>65.\u00a0\u00a0\u00a0Termination of suspension initiated by request.<\/p>\n<p>\u00a0\u00a0\u00a0A certification service provider shall terminate a suspension initiated by request\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0where the subscriber named in the suspended certificate requests termination of the suspension, only if the certification service provider has confirmed that the person requesting suspension is the subscriber or an agent of the subscriber authorised to terminate the suspension; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0where the licensed certification service provider discovers and confirms that the request for the suspension was made without authorisation by the subscriber.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s66\"><\/a>66.\u00a0\u00a0\u00a0Alternate contractual procedures.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The contract between a subscriber and a licensed certification service provider may limit or preclude requested suspension by the certification service provider or may provide otherwise for termination of a requested suspension.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where the contract limits or precludes suspension by the Controller when the issuing licensed certification service provider is unavailable, the limitation or preclusion shall be effective only if notice of it is published in the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s67\"><\/a>67.\u00a0\u00a0\u00a0Effect of suspension of certificate.<\/p>\n<p>\u00a0\u00a0\u00a0Nothing in this Part shall release the subscriber from the duty under section 47 to keep the private key secure while a certificate is suspended.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s68\"><\/a>68.\u00a0\u00a0\u00a0Revocation on request.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A licensed certification service provider shall revoke a certificate, which it issued but which is not a transactional certificate\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0upon receiving a request for revocation by the subscriber named in the certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0upon confirming that the person requesting revocation is that subscriber or is an agent of that subscriber with authority to request the revocation.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certification service provider shall confirm a request for revocation and revoke a certificate within one business day after receiving both a subscriber&#8217;s written request and evidence reasonably sufficient to confirm the identity of the person requesting the revocation or of the agent.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s69\"><\/a>69.\u00a0\u00a0\u00a0Revocation on subscriber&#8217;s demise.<\/p>\n<p>\u00a0\u00a0\u00a0A licensed certification service provider shall revoke a certificate which it issued\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0upon receiving a certified copy of the subscriber&#8217;s death certificate or upon confirming by other evidence that the subscriber is dead; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0upon presentation of documents effecting a dissolution of the subscriber or upon confirming by other evidence that the subscriber has been dissolved or has ceased to exist.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s70\"><\/a>70.\u00a0\u00a0\u00a0Revocation of unreliable certificates.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A licensed certification service provider may revoke one or more certificates, which it issued if the certificates are or become unreliable regardless of whether the subscriber consents to the revocation and notwithstanding any provision to the contrary in a contract between the subscriber and the licensed certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Nothing in subsection (1) shall prevent the subscriber from seeking damages or other relief against the licensed certification service provider in the event of wrongful revocation.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s71\"><\/a>71.\u00a0\u00a0\u00a0Notice of revocation.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Upon revocation of a certificate by a licensed certification service provider, the licensed certification service provider shall publish a signed notice of the revocation in the repository specified in the certificate for publication of notice of revocation.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where one or more repositories are specified, the licensed certification service provider shall publish signed notices of the revocation in all such repositories.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Where any repository specified no longer exists or refuses to accept publication or if no such repository is recognised under section 69, the licensed certification service provider shall also publish the notice in a recognised repository.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s72\"><\/a>72.\u00a0\u00a0\u00a0Effect of revocation request on subscriber.<\/p>\n<p>\u00a0\u00a0\u00a0Where a subscriber has requested for the revocation of a certificate, the subscriber ceases to certify as provided in Part IV and has no further duty to keep the private key secure as required under section 59\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0when notice of the revocation is published as required under section 71; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0where 48 hours have lapsed after the subscriber requests for the revocation in writing, supplies to the issuing licensed certification service provider information reasonably sufficient to confirm the request and pays any prescribed fee, whichever occurs first.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s73\"><\/a>73.\u00a0\u00a0\u00a0Effect of notification on certification service provider.<\/p>\n<p>\u00a0\u00a0\u00a0Upon notification as required under section 71, a certification service provider shall be discharged of its warranties based on issue of the revoked certificate and ceases to certify as provided in sections 22 and 24 in relation to the revoked certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s74\"><\/a>74.\u00a0\u00a0\u00a0Expiration of certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The date of expiry of a certificate shall be specified in the certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A certificate may be issued for a period not exceeding three years from the date of issue.<\/p>\n<p>\u00a0\u00a0\u00a0(3) When a certificate expires, the subscriber and licensed certification service provider shall cease to certify as provided under this Act and the licensed certification service provider shall be discharged of its duties based on issue in relation to the expired certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(4) The expiry of a certificate shall not affect the duties and obligations of the subscriber and licensed certification service provider incurred under and in relation to the expired certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s75\"><\/a>75.\u00a0\u00a0\u00a0Reliance limit.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A licensed certification service provider shall, when issuing a certificate to a subscriber, specify a recommended reliance limit in the certificate.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The licensed certification service provider may specify different limits in different certificates as it considers fit.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s76\"><\/a>76.\u00a0\u00a0\u00a0Liability limits for certification service providers.<\/p>\n<p>\u00a0\u00a0\u00a0Unless a licensed certification service provider waives the application of this section, a licensed certification service provider\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0shall not be liable for any loss caused by reliance on a false or forged digital signature of a subscriber, if, with respect to the false or forged digital signature, the licensed certification service provider complied with the requirements of this Act;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0shall not be liable in excess of the amount specified in the certificate as its recommended reliance limit for either\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0a loss caused by reliance on a misrepresentation in the certificate of any fact that the licensed certification service provider is required to confirm; or<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0failure to comply with sections 31 and 32 when issuing the certificate.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s77\"><\/a>77.\u00a0\u00a0\u00a0Recognition of repositories.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may recognise one or more repositories, after determining that a repository to be recognised satisfies the requirements prescribed in the regulations made under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The procedure for recognition of repositories shall be as prescribed by regulations made under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The Controller shall publish a list of recognised repositories in such form and manner as he or she may determine.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s78\"><\/a>78.\u00a0\u00a0\u00a0Liability of repositories.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Notwithstanding any disclaimer by the repository or a contract to the contrary between the repository and a licensed certification service provider or a subscriber, a repository shall be liable for a loss incurred by a person reasonably relying on an electronic signature verified by the public key listed in a suspended or revoked certificate, if loss was incurred more than one business day after receipt by the repository of a request to publish notice of the suspension or revocation and the repository had failed to publish the notice when the person relied on the digital signature.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Unless waived, a recognised repository or the owner or operator of a recognised repository\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0shall not be liable for failure to record publication of a suspension or revocation, unless the repository has received notice of publication and one business day has elapsed since the notice was received;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0shall not be liable under subsection (1) in excess of the amount specified in the certificate as the recommended reliance limit;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0shall not be liable for misrepresentation in a certificate published by a certification service provider;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0shall not be liable for accurately recording or reporting information which a licensed certification service provider, a court or the Controller has published as required or permitted under this Act, including information about the suspension or revocation of a certificate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0shall not be liable for reporting information about a certification service provider, a certificate or a subscriber, if the information is published as required or permitted under this Act or is published by order of the Controller in the performance of his or her licensing and regulatory duties under this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s79\"><\/a>79.\u00a0\u00a0\u00a0Recognition of date or time stamp services.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may recognise one or more date or time stamp services, after determining that a service to be recognised satisfies the requirements prescribed in the regulations made under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The procedure for recognising of date or time stamp services shall be as may be prescribed by regulations made under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(3) The Controller shall publish a list of recognised date or time stamp services in a form and manner as he may determine.<\/p>\n<p class=\"L5\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\">PART V<br \/>MISCELLANEOUS.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s80\"><\/a>80.\u00a0\u00a0\u00a0Prohibition against dangerous activities.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider, whether licensed or not, shall not conduct its business in a manner that creates an unreasonable risk of loss to the subscribers of the certification service provider, to persons relying on certificates issued by the certification service provider or to a repository.<\/p>\n<p>\u00a0\u00a0\u00a0(2) The Controller may publish in one or more recognised repositories brief statements advising subscribers, persons relying on digital signatures and repositories about any activities of a certification service provider, whether licensed or not, which create a risk prohibited under subsection (1).<\/p>\n<p>\u00a0\u00a0\u00a0(3) The certification service provider named in a statement as creating or causing a risk may protest the publication of the statement by filing a brief written defence.<\/p>\n<p>\u00a0\u00a0\u00a0(4) On receipt of a protest made under subsection (3), the Controller shall publish a written defence together with the Controller&#8217;s statement and shall immediately give the protesting certification service provider notice and a reasonable opportunity of being heard.<\/p>\n<p>\u00a0\u00a0\u00a0(5) Where, after a hearing, the Controller determines that the publication of the advisory statement was unwarranted, the Controller shall revoke the advisory statement.<\/p>\n<p>\u00a0\u00a0\u00a0(6) Where, after a hearing, the Controller determines that the advisory statement is no longer warranted, the Controller shall revoke the advisory statement.<\/p>\n<p>\u00a0\u00a0\u00a0(7) Where, after a hearing, the Controller determines that the advisory statement remains warranted, the Controller may continue or amend the advisory statement and may take further legal action to eliminate or reduce the risk prohibited under subsection (1).<\/p>\n<p>\u00a0\u00a0\u00a0(8) The Controller shall publish his decision under subsection (5), (6) or (7), as the case may be, in one or more recognised repositories.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s81\"><\/a>81.\u00a0\u00a0\u00a0Obligation of confidentiality.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Except for the purpose of this Act or for any prosecution for an offence under any written law or under an order of court, a person under any powers conferred under this Act, shall not obtain access to any electronic record, book, register, correspondence, information, document, other material or grant access to any other person.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding 120 currency points or imprisonment for a term not exceeding five years or both.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s82\"><\/a>82.\u00a0\u00a0\u00a0False information.<\/p>\n<p>\u00a0\u00a0\u00a0A person who knowingly makes, orally or in writing, signs or furnishes any declaration, return, certificate or other document or information required under this Act which is false or misleading in any particular way commits an offence and is liable, on conviction, to a fine not exceeding 120 currency points or imprisonment for a term not exceeding five years or both.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s83\"><\/a>83.\u00a0\u00a0\u00a0Offences by body corporate.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Where a body corporate commits an offence under this Act, a person who at the time of the commission of the offence is a director, manager, secretary or other similar officer of the body corporate or was purporting to act in that capacity or was in any manner or to any extent responsible for the management of any of the affairs of the body corporate or was assisting in such management\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0may be charged severally or jointly in the same proceedings with the body corporate; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0where the body corporate is convicted of the offence, such a person shall be deemed to have committed an offence unless, having regard to the nature of his functions in that capacity and to all circumstances, he proves\u2014<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(i)\u00a0\u00a0\u00a0that the offence was committed without his knowledge, consent or connivance; and<\/p>\n<p class=\"TRI\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(ii)\u00a0\u00a0\u00a0that he took all reasonable precautions and had exercised due diligence to prevent the commission of the offence.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where a person is liable under this Act to a punishment or penalty for any act, omission, neglect or default, he or she is liable to the same punishment or penalty for every such act, omission, neglect or default of any employee or agent of his or of the employee of such agent, if the act, omission, neglect or default was committed\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0by his employee in the course of his employment;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0by the agent when acting on his behalf; or<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0by the employee of such agent in the course of his employment by such agent or otherwise on behalf of the agent.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s84\"><\/a>84.\u00a0\u00a0\u00a0Authorised officer.<\/p>\n<p>\u00a0\u00a0\u00a0An authorised officer may exercise the powers of enforcement under this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s85\"><\/a>85.\u00a0\u00a0\u00a0Power to investigate.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Controller may investigate the activities of a certification service provider material to its compliance with this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) For the purposes of subsection (1), the Controller may issue orders to a certification service provider to further its investigation and secure compliance with this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Further, in any case relating to the commission of an offence under this Act, any authorised officer carrying on an investigation may exercise all or any of the special powers in relation to police investigation in all cases given by the Criminal Procedure Code.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s86\"><\/a>86.\u00a0\u00a0\u00a0Search by warrant.<\/p>\n<p>\u00a0\u00a0\u00a0(1) If it appears to a Magistrate, upon written information on oath and after such inquiry as he or she considers necessary, that there is reasonable cause to believe that an offence under this Act is being or has been committed on any premises, the Magistrate may issue a warrant authorising any police officer not below the rank of Inspector or any authorised officer named in the warrant, to enter the premises at any reasonable time by day or by night, with or without assistance and if need be by force, to search for and seize\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0copies of any books, accounts or other documents, including computerised data, which contain or are reasonably suspected to contain information as to any offence so suspected to have been committed;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0any signboard, card, letter, pamphlet, leaflet, notice or other device representing or implying that the person is a licensed certification service provider; and<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0any other document, article or item that is reasonably believed to furnish evidence of the commission of that offence.<\/p>\n<p>\u00a0\u00a0\u00a0(2) A police officer or an authorised officer conducting a search under subsection (1) may, if in his or her opinion it is reasonably necessary to do so for the purpose of investigating into the offence, search any person who is in or on those premises.<\/p>\n<p>\u00a0\u00a0\u00a0(3) A police officer or an authorised officer making a search of a person under subsection (2) may seize, detain or take possession of any book, accounts, document, computerised data, card, letter, pamphlet, leaflet, notice, device, article or item found on that person for the purpose of the investigation being carried out by that officer.<\/p>\n<p>\u00a0\u00a0\u00a0(4) A female person shall not be searched under this section except by another female person.<\/p>\n<p>\u00a0\u00a0\u00a0(5) Where, by reason of its nature, size or amount, it is not practicable to remove any book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item seized under this section, the seizing officer shall, by any means, seal that book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item in the premises or container in which it is found.<\/p>\n<p>\u00a0\u00a0\u00a0(6) A person who, without lawful authority, breaks, tampers with or damages the seal referred to in subsection (5) or removes any book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item under seal or attempts to do so commits an offence.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s87\"><\/a>87.\u00a0\u00a0\u00a0Search and seizure without warrant.<\/p>\n<p>\u00a0\u00a0\u00a0If a police officer not below the rank of Inspector in any of the circumstances referred to in section 86 has reasonable cause to believe that by reason of delay in obtaining a search warrant under that section the investigation would be adversely affected or evidence of the commission of an offence is likely to be tampered with, removed, damaged or destroyed, that officer may enter the premises and exercise in, upon and in respect of the premises all the powers referred to in section 86 in as full and ample a manner as if he or she were authorised to do so by a warrant issued under that section.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s88\"><\/a>88.\u00a0\u00a0\u00a0Access to computerised data.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A police officer conducting a search under section 86 or 87 shall be given unlimited access to computerised data whether stored in a computer or otherwise.<\/p>\n<p>\u00a0\u00a0\u00a0(2) For the purposes of this section, <b>&#8220;access&#8221;<\/b> includes being provided with the necessary password, encryption code, decryption code, software or hardware and any other means required to enable comprehension of computerised data.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s89\"><\/a>89.\u00a0\u00a0\u00a0List of things seized.<\/p>\n<p>\u00a0\u00a0\u00a0(1) Except as provided in subsection (2), where any book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item is seized under section 86 or 87, the seizing officer shall prepare a list of the things seized and immediately deliver a copy of the list signed by him or her to the occupier of the premises which have been searched or to his or her agent or servant, at those premises.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where the premises are unoccupied, the seizing officer shall post a list of things seized conspicuously on the premises and leave a copy with the local authorities.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s90\"><\/a>90.\u00a0\u00a0\u00a0Obstruction of authorised officer.<\/p>\n<p>\u00a0\u00a0\u00a0A person who obstructs, impedes, assaults or interferes in any way with any authorised officer in the performance of his functions under this Act commits an offence.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s91\"><\/a>91.\u00a0\u00a0\u00a0Additional powers.<\/p>\n<p>\u00a0\u00a0\u00a0An authorised officer may, for the purposes of the execution of this Act, to do all or any of the following\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0require the production of records, accounts, computerised data and documents kept by a licensed certification service provider and to inspect, examine and copy any of them;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0require the production of any identification document from a person in relation to any case or offence under this Act;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0make such inquiry as may be necessary to ascertain whether the provisions of this Act have been complied with.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s92\"><\/a>92.\u00a0\u00a0\u00a0General penalty.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A person who commits an offence under this Act for which no penalty is expressly provided is liable, on conviction, to a fine not exceeding 72 currency points or to imprisonment for a term not exceeding three years or both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding two currency points for each day the offence continues.<\/p>\n<p>\u00a0\u00a0\u00a0(2) For the purposes of this section, &#8220;this Act&#8221; does not include the regulations made under this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s93\"><\/a>93.\u00a0\u00a0\u00a0Institution and conduct of prosecution.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A prosecution under this Act shall not be instituted except by or with the consent of the Director of Public Prosecution, but a person charged with such an offence may be arrested or a warrant for his or her arrest issued and executed and the person may be detained or released on police bond, notwithstanding that the consent of the Director of Public Prosecution to the institution of a prosecution for the offence has not yet been obtained, but no further or other proceedings shall be taken until that consent has been obtained.<\/p>\n<p>\u00a0\u00a0\u00a0(2) An officer of the Controller duly authorised in writing by the Director of Public Prosecutions may conduct the prosecution for any offence under this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s94\"><\/a>94.\u00a0\u00a0\u00a0Jurisdiction to try offences.<\/p>\n<p>\u00a0\u00a0\u00a0Notwithstanding any written law to the contrary, a Magistrate Grade I shall have jurisdiction to try an offence under this Act and to impose the full punishment for the offence.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s95\"><\/a>95.\u00a0\u00a0\u00a0Prosecution of officers.<\/p>\n<p>\u00a0\u00a0\u00a0An action or prosecution shall not be brought, instituted or maintained in a court against the Controller or any officer duly authorised under this Act for or on account of or in respect of any act ordered or done for the purpose of carrying into effect this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s96\"><\/a>96.\u00a0\u00a0\u00a0Limitation on disclaiming or limiting application of the Act.<\/p>\n<p>\u00a0\u00a0\u00a0Unless it is expressly provided for under this Act, a person shall not disclaim or contractually limit the application of this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s97\"><\/a>97.\u00a0\u00a0\u00a0Regulations.<\/p>\n<p>\u00a0\u00a0\u00a0(1) The Minister may on the recommendation of the Controller make regulations for all or any of the following purposes\u2014<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>a<\/i>)\u00a0\u00a0\u00a0prescribing the qualification requirements for certification service providers;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>b<\/i>)\u00a0\u00a0\u00a0prescribing the manner of applying for licences and certificates under this Act, the particulars to be supplied by an applicant, the manner of licensing and certification, the fees payable there for, the conditions or restrictions to be imposed and the form of licences and certificates;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>c<\/i>)\u00a0\u00a0\u00a0regulating the operations of licensed certification service provider;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>d<\/i>)\u00a0\u00a0\u00a0prescribing the requirements for the content, form and sources of information in certification service provider disclosure records, the updating and timeliness of such information and other practices and policies relating to certification service provider disclosure records;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>e<\/i>)\u00a0\u00a0\u00a0prescribing the form of certification practice statements;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>f<\/i>)\u00a0\u00a0\u00a0prescribing the qualification requirements for auditors and the procedure for audits;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>g<\/i>)\u00a0\u00a0\u00a0prescribing the requirements for repositories and the procedure for recognition of repositories;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>h<\/i>)\u00a0\u00a0\u00a0prescribing the requirements for date and time stamp services and the procedure for recognition of date and time stamp services;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>i<\/i>)\u00a0\u00a0\u00a0prescribing the procedure for the review of software for use in creating digital signatures and of the applicable standards in relation to digital signatures and certification practice and for the publication of reports on such software and standards;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>j<\/i>) prescribing the forms for the purposes of this Act;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>k<\/i>)\u00a0\u00a0\u00a0prescribing the fees and charges payable under this Act and the manner for collecting and disbursing the fees and charges;<\/p>\n<p class=\"TI\">\u00a0\u00a0\u00a0(<i>l<\/i>)\u00a0\u00a0\u00a0providing for such other matters as are contemplated by or necessary for giving full effect to, the provisions of this Act and for their due administration.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Regulations made under subsection (1) may prescribe any act in contravention of the regulations to be an offence and may prescribe in relation to the offence, penalties not exceeding a fine of 72 currency points or imprisonment for three years or both.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s98\"><\/a>98.\u00a0\u00a0\u00a0Compensation.<\/p>\n<p>\u00a0\u00a0\u00a0Where a person is convicted under this Act, the court shall in addition to the punishment provided therein, order such person to pay by way of compensation to the aggrieved party, such sum as is in the opinion of the court just, having regard to the loss suffered by the aggrieved party; and such order shall be a decree under the provisions of the Civil Procedure Act, and shall be executed in the manner provided under that Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s99\"><\/a>99.\u00a0\u00a0\u00a0Power of Minister to amend the Schedule.<\/p>\n<p>\u00a0\u00a0\u00a0The Minister may, with the approval of Cabinet, by statutory instrument, amend the Schedule to this Act.<\/p>\n<p class=\"L8\">\u00a0<\/p>\n<p class=\"Level-Iblue\"><a name=\"Act7of2011s100\"><\/a>100.\u00a0\u00a0\u00a0Savings and transitional provisions.<\/p>\n<p>\u00a0\u00a0\u00a0(1) A certification service provider that has been carrying on or operating as a certification service provider before the commencement of this Act shall, not later than three months from the commencement, obtain a licence under this Act.<\/p>\n<p>\u00a0\u00a0\u00a0(2) Where a certification service provider referred to in subsection (1) fails to obtain a licence after the period prescribed in subsection (1), it shall be taken to be an unlicensed certification service provider and the provisions of this Act shall apply to it and a certificate issued by it accordingly.<\/p>\n<p>\u00a0\u00a0\u00a0(3) Where a certification service provider referred to in subsection (1) has obtained a licence in accordance with this Act within the period prescribed in subsection (1), all certificates issued by that certification service provider before the commencement of this Act, to the extent that they are not inconsistent with this Act, shall be taken to have been issued under this Act and shall have effect accordingly.<\/p>\n<p class=\"L5\">\u00a0<\/p>\n<p class=\"Level-Centeredblue\"><a name=\"Act7of2011-Sch\"><\/a>SCHEDULE<\/p>\n<p align=\"right\">s<i>. 2.<\/i><\/p>\n<p class=\"CenteredBold\">CURRENCY POINT<\/p>\n<p>\u00a0\u00a0\u00a0One currency point is equivalent to twenty thousand shillings.<\/p>\n<table class=\"tableborder\" width=\"100%\" cellspacing=\"3\" cellpadding=\"3\">\n<tbody>\n<tr style=\"font-size: 12px\">\n<td class=\"tableborder\" colspan=\"2\">\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"Centered\"><b><i>History<\/i><\/b><i>Legislation<\/i><i>Number<\/i>Act7\/2011S.I.37\/2011{\/mprestriction}<\/p>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 ELECTRONIC SIGNATURES ACT. ARRANGEMENT OF SECTIONS \u00a0\u00a0\u00a0Section PART IPRELIMINARY. \u00a0 \u00a0\u00a0\u00a01.\u00a0\u00a0\u00a0Commencement. \u00a0\u00a0\u00a02.\u00a0\u00a0\u00a0Interpretation. \u00a0\u00a0\u00a03.\u00a0\u00a0\u00a0Equal treatment of signature technologies. \u00a0 PART [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[2655],"tags":[],"class_list":["post-332","post","type-post","status-publish","format-standard","hentry","category-principal-legislation"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ELECTRONIC SIGNATURES ACT. -<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ELECTRONIC SIGNATURES ACT. -\" \/>\n<meta property=\"og:description\" content=\"\u00a0 ELECTRONIC SIGNATURES ACT. ARRANGEMENT OF SECTIONS \u00a0\u00a0\u00a0Section PART IPRELIMINARY. \u00a0 \u00a0\u00a0\u00a01.\u00a0\u00a0\u00a0Commencement. \u00a0\u00a0\u00a02.\u00a0\u00a0\u00a0Interpretation. \u00a0\u00a0\u00a03.\u00a0\u00a0\u00a0Equal treatment of signature technologies. \u00a0 PART [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-23T06:00:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-23T06:03:53+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"67 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/#\\\/schema\\\/person\\\/76b818fec3bfb6b825690d6d057d9356\"},\"headline\":\"ELECTRONIC SIGNATURES ACT.\",\"datePublished\":\"2026-02-23T06:00:58+00:00\",\"dateModified\":\"2026-02-23T06:03:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/\"},\"wordCount\":13330,\"commentCount\":0,\"articleSection\":[\"Principal Legislation\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/\",\"url\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/\",\"name\":\"ELECTRONIC SIGNATURES ACT. -\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/#website\"},\"datePublished\":\"2026-02-23T06:00:58+00:00\",\"dateModified\":\"2026-02-23T06:03:53+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/#\\\/schema\\\/person\\\/76b818fec3bfb6b825690d6d057d9356\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/2011\\\/04\\\/15\\\/electronic-signatures-act\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/legal.indiafin.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ELECTRONIC SIGNATURES ACT.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/#website\",\"url\":\"https:\\\/\\\/legal.indiafin.com\\\/\",\"name\":\"\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/legal.indiafin.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/legal.indiafin.com\\\/#\\\/schema\\\/person\\\/76b818fec3bfb6b825690d6d057d9356\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bba4a925801808704e2ddc69a2625edeac83d56aa4ccbd7182d90992ad47bd1f?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bba4a925801808704e2ddc69a2625edeac83d56aa4ccbd7182d90992ad47bd1f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bba4a925801808704e2ddc69a2625edeac83d56aa4ccbd7182d90992ad47bd1f?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\\\/\\\/legal.indiafin.com\"],\"url\":\"https:\\\/\\\/legal.indiafin.com\\\/index.php\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ELECTRONIC SIGNATURES ACT. -","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/","og_locale":"en_US","og_type":"article","og_title":"ELECTRONIC SIGNATURES ACT. -","og_description":"\u00a0 ELECTRONIC SIGNATURES ACT. ARRANGEMENT OF SECTIONS \u00a0\u00a0\u00a0Section PART IPRELIMINARY. \u00a0 \u00a0\u00a0\u00a01.\u00a0\u00a0\u00a0Commencement. \u00a0\u00a0\u00a02.\u00a0\u00a0\u00a0Interpretation. \u00a0\u00a0\u00a03.\u00a0\u00a0\u00a0Equal treatment of signature technologies. \u00a0 PART [&hellip;]","og_url":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/","article_published_time":"2026-02-23T06:00:58+00:00","article_modified_time":"2026-02-23T06:03:53+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"67 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/#article","isPartOf":{"@id":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/"},"author":{"name":"admin","@id":"https:\/\/legal.indiafin.com\/#\/schema\/person\/76b818fec3bfb6b825690d6d057d9356"},"headline":"ELECTRONIC SIGNATURES ACT.","datePublished":"2026-02-23T06:00:58+00:00","dateModified":"2026-02-23T06:03:53+00:00","mainEntityOfPage":{"@id":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/"},"wordCount":13330,"commentCount":0,"articleSection":["Principal Legislation"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/","url":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/","name":"ELECTRONIC SIGNATURES ACT. -","isPartOf":{"@id":"https:\/\/legal.indiafin.com\/#website"},"datePublished":"2026-02-23T06:00:58+00:00","dateModified":"2026-02-23T06:03:53+00:00","author":{"@id":"https:\/\/legal.indiafin.com\/#\/schema\/person\/76b818fec3bfb6b825690d6d057d9356"},"breadcrumb":{"@id":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/legal.indiafin.com\/index.php\/2011\/04\/15\/electronic-signatures-act\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legal.indiafin.com\/"},{"@type":"ListItem","position":2,"name":"ELECTRONIC SIGNATURES ACT."}]},{"@type":"WebSite","@id":"https:\/\/legal.indiafin.com\/#website","url":"https:\/\/legal.indiafin.com\/","name":"","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legal.indiafin.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/legal.indiafin.com\/#\/schema\/person\/76b818fec3bfb6b825690d6d057d9356","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/bba4a925801808704e2ddc69a2625edeac83d56aa4ccbd7182d90992ad47bd1f?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/bba4a925801808704e2ddc69a2625edeac83d56aa4ccbd7182d90992ad47bd1f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bba4a925801808704e2ddc69a2625edeac83d56aa4ccbd7182d90992ad47bd1f?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/legal.indiafin.com"],"url":"https:\/\/legal.indiafin.com\/index.php\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/posts\/332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/comments?post=332"}],"version-history":[{"count":1,"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/posts\/332\/revisions"}],"predecessor-version":[{"id":934,"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/posts\/332\/revisions\/934"}],"wp:attachment":[{"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/media?parent=332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/categories?post=332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legal.indiafin.com\/index.php\/wp-json\/wp\/v2\/tags?post=332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}