Information Technology Act, 2000
Electronic Signatures: Legal Validity, Forgery and Misuse
An electronic signature is only as useful as the law's willingness to treat it as a real signature, and the law's ability to punish those who fake or steal it. Topic 37 explained how digital signatures and eSign work, and Topic 41 the rules behind eSign. This note looks at the courtroom side: when an electronic signature is legally valid, how a party proves or challenges it, what counts as forgery of an electronic signature, which provisions punish its misuse, and how loss is allocated when a signing key falls into the wrong hands.
1. The Seal, the Forger and the Thief
A medieval merchant's seal raised three questions. Is a sealed letter as good as a signed one? (validity). Did this seal really come from his ring? (proof). And what happens to the forger who carves a copy, or the servant who steals the ring and seals letters in his name? (forgery and misuse). The IT Act, the BSA and the BNS answer the same three questions for the digital seal.
2. Legal Validity
Section 5, Information Technology Act, 2000 Where any law provides that information or any other matter shall be authenticated by affixing the signature or any document shall be signed or bear the signature of any person, then, notwithstanding anything contained in such law, such requirement shall be deemed to have been satisfied, if such information or matter is authenticated by means of electronic signature affixed in such manner as may be prescribed by the Central Government. Explanation: 'signed', with its grammatical variations and cognate expressions, shall, with reference to a person, mean affixing of his hand written signature or any mark on any document and the expression 'signature' shall be construed accordingly. |
- Functional equivalence. Section 5 does not say an electronic signature is a handwritten one; it says a legal requirement of signature is satisfied by it. The electronic signature performs the same functions: identifying the signer and showing intent to be bound.
- Which signatures qualify. Only a digital signature under Section 3 or a technique in the Second Schedule under Section 3A, affixed as prescribed with a valid certificate issued by a licensed CA (s.35)
- Secure electronic signature (s.15). A signature is secure if the signature creation data was under the exclusive control of the signatory at the time of affixing, and was stored and affixed in the exclusive manner prescribed. Secure signatures attract stronger presumptions.
- Contracts. Section 10A prevents an e-contract being unenforceable merely because it was formed electronically; the ordinary requirements of the Contract Act still apply.
Figure 1: Is this electronic signature legally effective?
- Limits: First Schedule. Wills, trusts, ordinary powers of attorney and negotiable instruments other than cheques (subject to the 2022 exceptions for regulated entities) cannot be signed electronically under the Act.
- Limits: Section 9. No one can force a government department to accept an electronically signed document unless it has chosen to.
- Limits: other formalities. Stamping, attestation and registration are governed by their own laws; an e-signature does not dispense with them (see Topic 35)
- Scanned images, typed names, OTP clicks. Not electronic signatures under the Act, though they may still prove assent to a contract that the law does not require to be signed.
3. Proving and Disputing an Electronic Signature
Figure 2: Provisions of the BSA on electronic signatures
- Burden. If a party alleges that an electronic signature is that of a particular subscriber, it must prove it (s.66 BSA, formerly s.67A IEA), unless the signature is a secure electronic signature.
- Method. The court may direct the subscriber, the Controller or the CA to produce the certificate, or direct any person to apply the public key and verify the signature (s.73 BSA, formerly s.73A IEA)
- Expert evidence. The opinion of the CA that issued the certificate is relevant (s.41(2) BSA), as is the opinion of a notified Examiner of Electronic Evidence (s.39(2) BSA)
- The electronic record. The signed document, if produced as a copy, needs the certificate under Section 63 BSA with hash values (see Topic 9)
- Practical proof for eSign. The CA's Form C archive, the e-KYC response code embedded in the certificate, the ASP's audit trail and the OTP delivery logs.
📖 Illustration: a disputed loan agreement Facts: A borrower denies signing an eSigned loan agreement; he says a recovery agent took his phone and read out the OTP. Proof: The lender produces the certificate, the CA's verification report and the audit trail showing the OTP to the borrower's registered mobile. The signature verifies cryptographically (s.73 BSA). But: Verification proves that the key was used, not that the borrower consented freely. If fraud or coercion is shown, the contract is voidable under Sections 17, 15 and 19 of the Contract Act, and the agent may be liable under Section 66C or 66D of the IT Act. Lesson: Separate the validity of the signature from the validity of consent. |
4. Forgery of Electronic Signatures
- Making a false document (s.335 BNS). A person makes a false document or false electronic record if he dishonestly or fraudulently makes or transmits an electronic record or part of it, or affixes any electronic signature on it, with the intention of causing it to be believed that it was made or signed by, or by the authority of, a person who did not do so. The same applies to altering a record after it was signed.
- Forgery (s.336 BNS). Making a false document or electronic record with intent to cause damage or injury, support a claim or title, cause a person to part with property, enter a contract, or commit fraud. Punishable with up to two years or fine or both; forgery for cheating, up to seven years and fine; forgery to harm reputation, up to three years and fine.
- Using as genuine (s.340 BNS). Fraudulently or dishonestly using as genuine a document or electronic record known to be forged is punished as if the user had forged it.
- Old numbering. Sections 463 to 471 IPC; the words 'electronic record' and 'electronic signature' were inserted into these provisions by the IT Act itself.
Figure 3: Forgery and misuse: provisions and punishments
5. Misuse of Electronic Signatures under the IT Act
- Identity theft (s.66C). Fraudulently or dishonestly making use of another person's electronic signature, password or other unique identification feature: up to three years and fine up to ₹1 lakh. This is the provision for a stolen token or a misused OTP.
- Personation (s.66D). Cheating by personation by means of a communication device or computer resource, for instance posing as the signer to a counterparty.
- Misrepresentation (s.71). Misrepresenting or suppressing a material fact to the Controller or a CA to obtain a licence or a certificate.
- False certificates (ss.73, 74). Publishing a certificate knowing the CA did not issue it, the subscriber did not accept it, or it has been revoked or suspended; or creating or publishing one for a fraudulent purpose.
- Civil remedy (s.43). Compensation for unauthorised access to the device or account holding the signing credentials; Section 66 if done dishonestly or fraudulently.
- Overlap with the BNS. In Sharat Babu Digumarti v. Government of NCT of Delhi, (2017) 2 SCC 18, the Supreme Court held that where the IT Act specifically covers the conduct (there, electronic obscenity), the general penal provision cannot be separately invoked. Whether forgery under the BNS can be charged alongside Section 66C depends on whether the ingredients differ: making a false record (forgery) is distinct from using another's genuine credential (identity theft)
6. Duties and Liability: Who Bears the Loss?
Figure 4: Duties of subscribers and Certifying Authorities
Figure 5: When a signing key is compromised
- Subscriber's risk. Under the Explanation to Section 42, the subscriber remains liable until he informs the CA that the private key has been compromised. A careless token holder bears the risk of misuse before reporting.
- CA's risk. A CA that issues a certificate without proper verification breaches Sections 30 and 36 and its licence conditions; the Controller may suspend or revoke its licence (s.25) and the CA may face compensation claims under the Act.
- eSign changes the picture. Because the key is one-time and held in the ESP's HSM, the risk shifts from losing a token to deceit at the moment of signing, such as a fraudster obtaining the OTP.
⚠ Exam trap Do not equate a verified signature with a valid transaction. Cryptographic verification proves the private key was used on that document; it does not prove the person consented, or that the document is outside the First Schedule, or that stamp and registration law were satisfied. In a problem question, deal with each layer separately. |
7. Quick Revision and Memory Aids
- 'Seal, forger, thief'. Validity, forgery, misuse.
- '5 equates, 15 secures'. Validity and secure signatures.
- '66 proves, 73 verifies'. BSA provisions on e-signatures.
- '335 makes, 336 forges, 340 uses'. BNS forgery chain.
- '66C steals the key, 66D wears the mask'. Identity theft and personation.
- '42: liable till you tell'. Compromise of a private key.
8. Frequently Asked Questions
Is an electronic signature as valid as a handwritten one?
Yes, where it is a digital signature under Section 3 or a Second Schedule technique under Section 3A affixed as prescribed: Section 5 deems the legal requirement of a signature satisfied. The First Schedule documents are the exception.
Which law punishes forging an electronic signature?
Sections 335, 336 and 340 of the BNS (formerly Sections 463 to 471 IPC) punish making and using a false electronic record, including affixing an electronic signature without authority. Using another person's genuine signature credentials is identity theft under Section 66C of the IT Act.
9. Related Topics
- Topic 37: Digital and Electronic Signatures. The technology and the statutory definitions.
- Topic 41: The 2015 Rules Framework. How eSign is regulated.