All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Legal Recognition of Electronic Records, Signatures and Transactions under the IT Act

The first purpose of the Information Technology Act, 2000 is to make electronic activity legally effective. It does so through five linked sets of provisions: recognition of electronic records, recognition of electronic signatures, validity of electronic transactions and contracts, facilitation of electronic governance, and a regulated system of Certifying Authorities that makes electronic signatures trustworthy. This note takes each in turn, with the statutory text of Sections 4, 5 and 10A.

1. Paper Law, Electronic Keys

Imagine a building whose every door has a paper lock: it opens only for someone holding a signed paper pass. The IT Act does not tear down the doors. It fits each lock with a second keyhole that accepts an electronic key. Section 4 is the keyhole for 'writing', Section 5 for 'signature', Section 10A for 'contract', and Sections 6 to 8 for the government's own doors. The Certifying Authorities are the locksmiths licensed to cut the keys, and the Controller licenses the locksmiths.

The five pillars of legal recognition

Figure 1: The five pillars of legal recognition

2. Legal Recognition of Electronic Records (Section 4)

Section 4, Information Technology Act, 2000

Legal recognition of electronic records. Where any law provides that information or any other matter shall be in writing or in the typewritten or printed form, then, notwithstanding anything contained in such law, such requirement shall be deemed to have been satisfied if such information or matter is (a) rendered or made available in an electronic form; and (b) accessible so as to be usable for a subsequent reference.

  • Two conditions. The information must be in electronic form, and it must be accessible so as to be usable for later reference. A message that disappears after reading does not satisfy the second condition.
  • Non obstante. Section 4 operates notwithstanding anything in the law that imposes the writing requirement, so that law need not be separately amended.
  • Electronic record. Defined in Section 2(1)(t) as data, record or data generated, image or sound stored, received or sent in an electronic form, or micro film or computer generated micro fiche.
  • Limits. Section 4 does not apply to documents in the First Schedule (negotiable instruments other than cheques, powers of attorney, trusts and wills, subject to the 2022 exceptions; immovable property contracts were removed from the list in 2022). Admissibility in court is a separate question, governed by Sections 61 to 63 of the BSA.
  • Source. Section 4 follows Articles 5 and 6 of the UNCITRAL Model Law (see Topic 3)

3. Legal Recognition of Electronic Signatures (Sections 3, 3A and 5)

Section 5, Information Technology Act, 2000

Legal recognition of electronic signatures. Where any law provides that information or any other matter shall be authenticated by affixing the signature or any document shall be signed or bear the signature of any person, then, notwithstanding anything contained in such law, such requirement shall be deemed to have been satisfied, if such information or matter is authenticated by means of electronic signature affixed in such manner as may be prescribed by the Central Government.

Explanation. For the purposes of this section, 'signed', with its grammatical variations and cognate expressions, shall, with reference to a person, mean affixing of his hand written signature or any mark on any document and the expression 'signature' shall be construed accordingly.

Digital signature and electronic signature

Figure 2: Digital signature and electronic signature

Digital signature (Section 3)

How a digital signature is created and verified

Figure 3: How a digital signature is created and verified

  • Authentication. A subscriber may authenticate an electronic record by affixing his digital signature (s.3(1)), using an asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record (s.3(2))
  • Hash function. An algorithm that maps the record into a smaller 'hash result', so that the same record always yields the same result and it is computationally infeasible to derive the record from the hash or to find two records with the same hash.
  • Key pair. The private key and the public key are unique to the subscriber and constitute a functioning key pair (s.3(4)). The private key signs; any person can use the public key to verify the record (s.3(3))

Electronic signature (Section 3A)

  • Technology neutral. Inserted in 2008. A subscriber may authenticate an electronic record by an electronic signature or authentication technique that is considered reliable and is specified in the Second Schedule.
  • Reliability conditions (s.3A(2)). (a) the signature creation data are linked to the signatory and to no other person; (b) the data were under the control of the signatory at the time of signing; (c) any alteration to the signature after affixing is detectable; (d) any alteration to the information after authentication is detectable; and (e) it fulfils any other prescribed conditions.
  • Second Schedule. Includes e-authentication using Aadhaar or other e-KYC services, the basis of the e-Sign service introduced in 2015.
  • Relationship. Every digital signature is an electronic signature (s.2(1)(ta)), but not every electronic signature is a digital signature.
  • Secure signature. Chapter V adds the concept of a secure electronic record and a secure electronic signature (ss.14 to 16), which carry presumptions under the law of evidence.

4. Legal Recognition of Electronic Transactions (Sections 10A and 11 to 13)

Section 10A, Information Technology Act, 2000

Validity of contracts formed through electronic means. Where in a contract formation, the communication of proposals, the acceptance of proposals, the revocation of proposals and acceptances, as the case may be, are expressed in electronic form or by means of an electronic record, such contract shall not be deemed to be unenforceable solely on the ground that such electronic form or means was used for that purpose.

  • What s.10A does. It removes one objection only: the electronic form. The contract must still satisfy the Indian Contract Act, 1872 as to consent, consideration, capacity and lawful object.
  • Before 2008. Electronic contracts were upheld through Section 4 and the Contract Act, but Section 10A, following Article 11 of the Model Law, put the matter beyond doubt.
  • Attribution (s.11). An electronic record is attributed to the originator if it was sent by the originator himself, by a person authorised to act for him, or by an information system programmed by or on behalf of the originator to operate automatically.
  • Acknowledgment (s.12). Where the originator has not stipulated a form, any communication or conduct of the addressee sufficient to indicate receipt is enough. Where the originator has stipulated that the record binds only on acknowledgment, it is deemed never sent until acknowledgment is received.
  • Despatch and receipt (s.13). Despatch occurs when the record enters a computer resource outside the originator's control. Receipt occurs when it enters the addressee's designated computer resource or, if sent elsewhere, when retrieved. The record is deemed despatched at the originator's place of business and received at the addressee's place of business, even if the computer resource is located elsewhere.
  • Case law. Trimex International FZE Ltd. v. Vedanta Aluminium Ltd., (2010) 3 SCC 1 upheld a contract concluded by email (see Topic 4)

5. Facilitation of Electronic Governance (Sections 6 to 10)

The e-governance provisions of Chapter III

Figure 4: The e-governance provisions of Chapter III

  • Section 6. Where a law requires the filing of forms or applications with government, the issue of licences, permits, sanctions or approvals, or the receipt or payment of money, the requirement is satisfied if done electronically in the prescribed manner.
  • Section 6A. Inserted in 2008. The government may authorise service providers to deliver electronic services to the public and permit them to collect service charges.
  • Section 7. A requirement to retain documents or records is satisfied by electronic retention if the information remains accessible for later reference, is kept in its original format or one that accurately represents it, and details of its origin, destination and time of despatch or receipt are retained.
  • Section 7A. Inserted in 2008. Any law providing for audit of documents applies equally to documents kept in electronic form.
  • Section 8. A requirement to publish a rule, regulation, order, bye-law or notification in the Official Gazette is satisfied by publication in the Electronic Gazette, and the date of first publication in either form is the date of publication.
  • Section 9. Sections 6, 7 and 8 do not confer a right on any person to insist that a Ministry, Department, authority or body accept, issue, create, retain or preserve any document, or make any payment, in electronic form.
  • Section 10. Empowers the Central Government to make rules on the type of electronic signature, the manner and format in which it is affixed, and related procedures and controls.

⚠ Section 9: the government may, not must

Sections 6 to 8 are enabling, not mandatory. A citizen cannot compel a department to accept an electronic filing merely by relying on the IT Act; the department must have adopted the electronic mode. The same logic appears where a statute prescribes a mode of service: in Satender Kumar Antil v. CBI, the Supreme Court in January 2025 directed that notices to accused persons under Section 41A CrPC and Section 35 BNSS be served in the manner prescribed, and not through WhatsApp or other electronic modes, and in July 2025 (2025 INSC 909) it rejected a plea to permit electronic service of such notices.

  • Courts embracing e-records. By contrast, where the court itself adopts electronic means, electronic service is valid. In In Re: Cognizance for Extension of Limitation (2020), the Supreme Court permitted service of notices and summons by email, fax and instant messaging services such as WhatsApp during the pandemic.

6. Regulation of Certifying Authorities (Sections 17 to 34)

An electronic signature is useful only if a relying party can trust that the public key really belongs to the signer. The Act creates a chain of trust: the Central Government appoints a Controller, the Controller licenses Certifying Authorities, and Certifying Authorities issue electronic signature certificates to subscribers.

The chain of trust under Chapters VI to VIII

Figure 5: The chain of trust under Chapters VI to VIII

  • Controller (s.17). The Central Government appoints a Controller of Certifying Authorities by notification, and may appoint Deputy and Assistant Controllers, who work under the Controller's general superintendence.
  • Functions (s.18). Supervising Certifying Authorities; certifying their public keys; laying down standards; specifying qualifications of their employees and the conditions on which they conduct business; specifying the contents of certificates and the form of accounts; resolving conflicts of interest between Certifying Authorities and subscribers; and maintaining a database of their disclosure records. In practice the Controller operates the Root Certifying Authority of India.
  • Foreign Certifying Authorities (s.19). With the previous approval of the Central Government, the Controller may by notification recognise a foreign Certifying Authority, and may revoke the recognition for contravention of the conditions.
  • Licensing (ss.21 to 26). No one may issue electronic signature certificates without a licence (s.21); the Act provides for application (s.22), renewal (s.23), grant or rejection after a reasonable opportunity of being heard (s.24), suspension or revocation for false statements or non-compliance (s.25), and publication of any suspension or revocation (s.26)
  • Investigation and access (ss.28 and 29). The Controller may investigate contraventions and, where there is reasonable cause to suspect a contravention of the Chapter, have access to any computer system and data.
  • Duties of Certifying Authorities (ss.30 to 34). Use secure hardware, software and procedures and ensure the secrecy and privacy of signatures (s.30); ensure compliance by employees (s.31); display the licence (s.32); surrender a suspended or revoked licence (s.33); and disclose their certificate, practice statement and any adverse events (s.34)
  • Certificates and subscribers. Certifying Authorities issue, suspend and revoke electronic signature certificates (ss.35 to 39); subscribers must generate the key pair, accept the certificate and exercise reasonable care to retain control of the private key (ss.40 to 42)
  • Sanctions. Misrepresentation to the Controller (s.71), publishing a false certificate (s.73) and publication for a fraudulent purpose (s.74) are offences.

⚠ Exam trap

Do not confuse the Controller with the Certifying Authority. The Controller regulates and does not issue certificates to the public; licensed Certifying Authorities do. Also note that Section 20, which made the Controller the repository of signatures, was omitted in 2008.

7. Quick Revision and Memory Aids

  • 'Keyhole in every paper lock'. The Act adds an electronic route without repealing the paper route.
  • '4 writes, 5 signs, 10A binds'. The three recognition sections.
  • 'Accessible and usable later'. The test in Section 4.
  • 'Hash, private key, public key'. How a digital signature works under Section 3.
  • 'Linked, controlled, alteration detected twice, prescribed'. The five reliability conditions in Section 3A(2)
  • 'Sent, authorised, programmed'. Attribution under Section 11.
  • 'Government may, not must'. Section 9.
  • 'Government, Controller, CA, subscriber'. The chain of trust.

8. Frequently Asked Questions

How does the IT Act give legal recognition to electronic records?

Section 4 provides that a legal requirement of writing is satisfied if the information is in electronic form and accessible so as to be usable for subsequent reference, notwithstanding anything in the law imposing the requirement.

What is the difference between a digital signature and an electronic signature?

A digital signature under Section 3 uses an asymmetric crypto system and hash function. An electronic signature under Section 3A is any reliable technique specified in the Second Schedule, including a digital signature and Aadhaar-based e-Sign.

Can a citizen insist that a government department accept an electronic filing?

No. Section 9 provides that Sections 6 to 8 do not confer any right to insist on electronic filing, issue or retention.

9. Related Topics

  • Topic 3: UNCITRAL Model Law. The source of Sections 4 to 13.
  • Topic 4: Electronic Commerce. E-contracts and the leading cases.