Information Technology Act, 2000
Secure Electronic Records and Signatures: Sections 14 to 16 IT Act
Chapter V of the IT Act is only three sections long, yet it carries the Act's main evidentiary reward. Sections 4 and 5 make electronic records and signatures valid, but validity says nothing about trust: a valid record can still be challenged as altered, and a valid signature as forged. Sections 14 to 16 create a higher grade, the secure electronic record and the secure electronic signature, earned by applying a security procedure. The prize is paid out in the law of evidence: the BSA presumes a secure record unaltered and a secure signature intentionally affixed, shifting the burden to whoever disputes them. This note covers each section, the meaning of security procedure, the comparisons examiners ask for, and the evidence law interface.
1. A Letter, and a Letter in a Sealed Envelope
Any letter can be produced in court, but the party relying on it must prove it was not tampered with. A letter in a tamper-evident sealed envelope is different: as long as the seal is intact, everyone starts from the assumption that the contents are as they were when sealed, and the challenger must show the seal was broken. Sections 14 and 15 define the sealed envelope of electronic commerce, Section 16 says who prescribes the seal, and the BSA supplies the assumption.
Figure 1: From ordinary to secure: how the grades build up
2. Section 14: Secure Electronic Record
Section 14, Information Technology Act, 2000 Where any security procedure has been applied to an electronic record at a specific point of time, then such record shall be deemed to be a secure electronic record from such point of time to the time of verification. |
Figure 2: The secure window under Section 14
- Security procedure applied. The trigger is the application of a security procedure, in practice a digital signature: hashing the record and encrypting the hash with a private key, so that any later change makes verification fail.
- A specific point of time. Secure status is anchored to the moment the procedure was applied. The record is not warranted against everything that ever happened to it, only against alteration after that point.
- To the time of verification. The deeming runs until verification, when the hash comparison either confirms integrity or exposes tampering.
- Illustration. A contract PDF digitally signed at 10:00 on 1 March is a secure electronic record for the period from that signing to its verification in court; a change of even one character in between makes the signature fail verification.
3. Section 15: Secure Electronic Signature
Section 15, Information Technology Act, 2000 (as substituted in 2008) An electronic signature shall be deemed to be a secure electronic signature if (i) the signature creation data, at the time of affixing signature, was under the exclusive control of signatory and no other person; and (ii) the signature creation data was stored and affixed in such exclusive manner as may be prescribed. |
Figure 3: Conditions of a secure electronic signature
- Signature creation data. The secret used to create the signature: the private key in a digital signature, held on a crypto token or, for eSign, generated for one use in the ESP's hardware security module.
- Exclusive control of the signatory. At the time of affixing, the creation data must be under the exclusive control of the signatory and no one else. A private key on a token protected by a PIN satisfies this; a key shared with the office clerk does not.
- Exclusive storage and affixation. The data must also be stored and affixed in the exclusive manner prescribed, tying secure status to the prescribed PKI discipline rather than to any home-made arrangement.
- Detectability of alterations. The practical consequence of the framework: because the signature is a function of the record's hash, any alteration to the signature or the signed record after affixing is detectable on verification. This is also what the reliability conditions in Section 3A(2)(c) and (d) demand.
- Old and new Section 15. As enacted in 2000, the section spoke of a 'secure digital signature' verified by an agreed security procedure; the 2008 substitution made it technology-neutral and tied it to exclusive control and prescribed manner.
4. Section 16: Security Procedures and Practices
Section 16, Information Technology Act, 2000 (as substituted in 2008) The Central Government may, for the purposes of sections 14 and 15, prescribe the security procedures and practices: Provided that in prescribing such security procedures and practices, the Central Government shall have regard to the commercial circumstances, nature of transactions and such other related factors as it may consider appropriate. |
- Security procedure: meaning. A method used to verify that an electronic record is that of a particular person and has not been altered, such as asymmetric cryptography with hash functions, applied through the PKI of Chapter VI.
- Commercially reasonable security procedure. The proviso captures the older idea that security must fit the transaction: what is reasonable for a ₹500 purchase differs from what a property document needs. The original Section 16 expressly listed the nature of the transaction, the parties' sophistication, alternatives and costs as factors.
- The prescribed procedure. The Information Technology (Security Procedure) Rules, 2004 prescribed the digital signature created and verified through asymmetric cryptography and hash functions as the security procedure, with smart cards or crypto tokens for key storage; the 2015 End Entity and eSign rules carry the discipline forward (see Topic 41)
- Effect. In practice, a record authenticated by a digital signature or eSign under the prescribed framework is a secure electronic record bearing a secure electronic signature; a scanned signature or plain email never is.
5. Secure vs Ordinary: The Comparisons
Figure 4: Ordinary and secure records and signatures compared
- Secure record vs ordinary record. Both are valid and admissible; the difference is the starting point in a dispute. The ordinary record's integrity must be proved by evidence; the secure record is presumed unaltered since the security procedure was applied.
- Secure signature vs ordinary signature. An ordinary electronic signature must be proved to be the subscriber's (s.66 BSA); a secure signature is presumed affixed by the subscriber with the intention of signing or approving the record.
- Why the grades exist. The Act follows a laddered trust model from the UNCITRAL framework: recognition for everything electronic, presumptions only for what passed through a verifiable security discipline.
6. The Evidence Law Interface
Figure 5: Presumptions under the BSA
- Secure record (s.86(1) BSA, formerly s.85B(1) IEA). In proceedings involving a secure electronic record, the court shall presume, unless the contrary is proved, that it has not been altered since the specific point of time to which the secure status relates.
- Secure signature (s.86(2) BSA, formerly s.85B(2) IEA). The court shall presume, unless the contrary is proved, that the secure electronic signature was affixed by the subscriber with the intention of signing or approving the record. The section adds that nothing is presumed about ordinary records and signatures.
- Supporting presumptions. An electronic agreement bearing the parties' electronic signatures is presumed concluded by affixing them (s.85 BSA), and the information in an Electronic Signature Certificate is presumed correct if the subscriber accepted it (s.87 BSA)
- Burden shifting. The presumptions are rebuttable. Their effect is to shift the burden: the challenger must prove alteration, compromise of the key, or absence of intent, for example through the Examiner of Electronic Evidence (s.79A)
- Still to be proved. The presumptions assume the record is properly before the court; a copy still needs the Section 63 BSA certificate, and the signature's link to the subscriber rests on the certificate chain (see Topics 9 and 42)
⚠ Exam trap Keep the pairs straight. Sections 4 and 5 give validity; Sections 14 and 15 give secure status; the BSA gives the presumptions. Writing that 'all electronic records are presumed genuine' is wrong twice over: ordinary records enjoy no presumption of integrity at all, and even secure records are presumed unaltered only from the time the security procedure was applied, not from their creation. |
7. Quick Revision and Memory Aids
- 'A letter in a sealed envelope'. The idea of secure status.
- '14 seals the record, 15 seals the signature, 16 prescribes the seal'. Chapter V in one line.
- 'From application to verification'. The secure window of s.14.
- 'Exclusive control, exclusive manner'. The two conditions of s.15.
- 'Valid is not secure; secure is presumed'. The ladder of trust.
- '86(1) record unaltered, 86(2) signed with intent'. The BSA presumptions.
8. Frequently Asked Questions
What is the difference between an electronic record and a secure electronic record?
An electronic record is any data stored or sent electronically, valid under Section 4 but with no presumption about its integrity. A secure electronic record is one to which a security procedure, in practice a digital signature, was applied at a specific time; under Section 86(1) BSA it is presumed unaltered from that time to verification.
What makes an electronic signature a secure electronic signature?
Under Section 15, the signature creation data must have been under the exclusive control of the signatory and no other person at the time of affixing, and must have been stored and affixed in the exclusive manner prescribed. Such a signature is presumed to have been affixed by the subscriber with intent to sign (Section 86(2) BSA).
9. Related Topics
- Topic 37: Digital and Electronic Signatures. The technology behind the security procedure.
- Topic 9: Electronic Evidence. Admissibility and the Section 63 BSA certificate.