The Electronic Transactions (Certification Services) Regulations, 2025
This section is titled as an interpretation provision within a part on certification services licensing.
- Jurisdiction
- Tanzania
- Instrument
- Regulation
- Citation
- The Electronic Transactions (Certification Services) Regulations, 2025
- Version
- Undated source snapshot
- Language
- en
- Official source
- View official record ↗
Statute overview
About this statute
This section is titled as an interpretation provision within a part on certification services licensing. Section 13 is titled “Display of license.” This section is titled “Registration authority.” Section title only: Functions of registration authority. This section is titled “Functions of certification authority.”
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of The Electronic Transactions (Certification Services) Regulations, 2025
Showing 48 of 48
- 3 Verify source ↗
Section 3
This section is titled as an interpretation provision within a part on certification services licensing.
3. Interpretation. PART II CERTIFICATION SERVICES LICENSE Prohibition to provide certification services. Issuance of license and validity. Criteria for grant of license.
Part
PART II
- 13 Verify source ↗
Display of license
Section 13 is titled “Display of license.”
13. Display of license. PART III CERTIFICATION SERVICES - 4 Verify source ↗
(1) A person shall not provide certification
A person must not provide certification services unless licensed.
4.-(1) A person shall not provide certification services without a licence. (2) A person who contravenes the provision of subregulation (1) commits an offence and shall, on conviction be liable to fine not less than ten million shillings or to imprisonment for a term of not less than five years or both. Application for licence - 5 Verify source ↗
(1) A person who
A person offering certification services as a certification authority or registration authority must apply for a licence to the regulator and include specified application details and proof of fee payment.
5.-(1) A person who intends to offer certification services as- 5 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (a) a certification authority appointed by the Minister; or (b) registration authority, shall apply for a licence to the regulator in the form as prescribed in the First Schedule to these Regulations. (2) The Application in subregulation (1) shall consist of the following information: (a) the name and contact, including the physical address, telephone and e-mail of the applicant; (b) a description of the- (i) type of service to be provided; (ii) purpose for which the service will be applied; and (iii) technology to be applied in the provision of services; and (c) any other relevant particulars as may be prescribed by the regulator. (3) The application made under subsection (1) shall be accompanied by proof of payment of a nonrefundable fee prescribed in the Second Schedule to these Regulations. - 6 Verify source ↗
(1) An applicant for a licence shall
An applicant for a licence must meet company, insurance, capital, guarantee, trusted-person, and audit requirements.
6.-(1) An applicant for a licence shall- (a) be a company registered or incorporated under the laws of the United Republic; (b) be insured against liability for loss of the amount to be determined by the regulator for each claim arising out of any act or omission on the part of an applicant, its officers, employees or agent; (c) have a paid-up capital and proof of available financing as determined by the regulator; (d) furnish a banker's guarantee to the regulator in the prescribed approved form together with a fee to be determined by the regulator; 6 Criteria for grant of licence Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (e) have a trusted person who: (i) have a good knowledge of the Act and these Regulations; (ii) be trained in the certification services; (iii) possesses the relevant technical qualifications, and experience to effectively carry out the assigned duties; expertise (iv) is not declared bankrupt in Tanzania or elsewhere or has made a composition or an arrangement with his creditors; and (v) has not been convicted of any or involving offence dishonesty or in elsewhere, or any offence under these Regulations. fraud Tanzania (f) undergo and pass- (i) an initial audit on facilities, equipment and technology to be used; (ii) other audits as the regulator may require by notice in writing. (3) The performance banker's guarantee in sub regulation (1) may be invoked for payment of- (a) an offer of composition made by the regulator; for (b) costs rectification liabilities and attributed due to the negligence of the certification authority, its officer, employee or agent; or (c) costs incurred in the discontinuation or transfer of operations of the certification service provider, where the certification in authority's discontinued. licence or operations 7 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) Determination of application Validity of licence - 7 Verify source ↗
(1) The regulator shall, upon receipt of an
The regulator must issue a licence if the application is received and meets the licensing requirements. If it does not meet those requirements, the regulator must reject the application and tell the applicant in writing within 60 days, giving the reasons.
7.-(1) The regulator shall, upon receipt of an application and being satisfied that the application meets the licensing requirements shall issue a licence. (2) Where the application fails to meet the licensing requirements, the regulator shall reject the application and inform the applicant in writing, within sixty days explaining the grounds for rejection. - 8 Verify source ↗
(1) A licence issued to a
Some licences last 15 years or 5 years, may be renewed, are not transferable, and must start within one year unless the regulator extends the commencement period for sufficient reasons.
8.-(1) A licence issued to a- (a) certification authority shall be valid for a period of fifteen years and may be renewed; and (b) a registration authority shall be valid for a period of five years and may be renewed. (2) The licenses in sub regulation (1) shall- (a) contain terms and conditions as the regulator my determine; (b) not be transferable; and (c) expire where is not commenced within one year from the date the licence was issued. the business Annual licence fee Renewal of licence (3) Notwithstanding subregulation (3)(c), the regulator may extend the commencement period (3) where the licensee adduces sufficient reasons for the extension. - 9 Verify source ↗
The licensee shall pay an annual licence fee
The licensee must pay an annual licence fee to the regulator.
9. The licensee shall pay an annual licence fee to the regulator as prescribed in the Second Schedule to these Regulations. - 10 Verify source ↗
(1) A licensee may apply for renewal of a
A licensee may apply to renew a licence, but if it does not want renewal it must notify the regulator, subscribers, and the public within six months before expiry.
10.- (1) A licensee may apply for renewal of a licence not later than six months prior to the expiry of the licence. (2) The conditions for application for a licence shall apply mutatis mutandis to the application for the renewal of a licence. 8 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (3) A licensee who has no intention to renew a license shall, not later than six months prior to expiry of the licence - (a) inform the regulator in writing; (b) inform its subscribers in writing; and (c) send notification through a widely Suspension of licence circulated newspaper. (4) The regulator shall, upon receipt of notification from the licensee pursuant to sub regulation (3), issue a general notice to the public that the service provider has no intention to renew licence. - 11 Verify source ↗
(1) The regulator shall, where a licensee
If a licensee fails to meet its certification-service obligations, the regulator must notify it in writing and require correction, and the licensee must respond in writing and fix the default within the regulator’s set period.
11.-(1) The regulator shall, where a licensee fails to fulfil his obligations as certification service provider, notify the licensee in writing, specifying the nature of the default and require the licensee to rectify the default within the time specified in the notice. (2) The licensee shall, upon receipt of the notice under subregulation (1), make representation in writing to the regulator and rectify the default within the period prescribed by the regulator. (3) The regulator may, suspend or revoke the licence where a licensee fails to rectify the default within the prescribed period. Revocation of licence - 12 Verify source ↗
(1) The regulator may revoke a licence
The regulator may revoke a licence for listed compliance and insolvency reasons, and the licensee must surrender a revoked licence immediately.
12.-(1) The regulator may revoke a licence where- (a) the licensee: (i) has contravened any condition imposed under the licence; (ii) has provided the regulator with false, misleading or inaccurate information either in connection with the application for the licence or at any time after the grant of the licence; 9 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (iii) is carrying on its business in a manner which is prejudicial to the interest of the public or to the national economy; (iv) has insufficient assets to meet its liabilities; or (v) fails to rectify a default in terms of regulation 11 within the specified period; and (b) a winding up order is made against the licensee or a resolution for its voluntary winding-up is passed; and (2) The regulator shall, before revoking a licence give the licensee a notice in writing of the intention to revoke the licence and require the licensee to show sufficient reasons within thirty days as to why the licence should not be revoked. (3) Subject to sub regulation (2), the regulator shall revoke the licence where the licensee fails to show sufficient reasons; Provided that the regulator shall notify the licensee in writing of its decision within 48 hours of making the decision. (4) A licensee whose licence is revoked shall immediately surrender the licence to the regulator upon receipt of the decision of the revocation in subregulation (3). (5) A licensee who fails to surrender a licence under sub regulation (4) commits an offence and shall, upon conviction, be liable to a fine of not less than five million shillings but not exceeding ten million shillings or to imprisonment for a period not less than six months but not exceeding one year or to both. Display of Licence - 13 Verify source ↗
A Licensee shall display a copy of a valid
A licensee must display a copy of a valid licence in a conspicuous place where business is carried out.
13. A Licensee shall display a copy of a valid licence at a conspicuous place where business is carried out. 10 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) PART III CERTIFICATION SERVICES (a) The Registration Authority Registration authority
Part
PART III
- 14 Verify source ↗
Registration authority
This section is titled “Registration authority.”
14. Registration authority. 1 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) - 15 Verify source ↗
Functions of registration authority
Section title only: Functions of registration authority.
15. Functions of registration authority. - 16 Verify source ↗
Functions of certification authority
This section is titled “Functions of certification authority.”
16. Functions of certification authority. - 31 Verify source ↗
Complaint handling
This section is titled “Complaint handling.”
31. Complaint handling. PART IV GENERAL PROVISIONS - 14 Verify source ↗
(1) A certification authority shall, when
A certification authority must work with a licensed registration authority when providing certification services, and it may also be licensed as a registration authority.
14.-(1) A certification authority shall, when providing certification services work with a licensed registration authority for the proper carrying out of its functions under the Act. (2) Without prejudice to the provisions of subregulation (1), a certification authority may be licensed as a registration authority. Functions of registration authority - 15 Verify source ↗
The registration authority shall perform
The registration authority must carry out listed registration and certification-related functions.
15. The registration authority shall perform the following functions: (a) validate the identity of the subscriber who requested a certificate; (b) register subscribers for certification services; (c) issue notification of changes the information supporting the certification process of subscribers; in (d) initiate the process of revocation of a the certification issued by certificate authority; (e) archive registration files; and (f) perform other functions as may be directed by the regulator. (b) The Certification Authority - 16 Verify source ↗
(1) A certification authority shall
A certification authority must issue, verify, secure, maintain, and manage certificate services and comply with regulator-issued standards.
16.-(1) A certification authority shall- (a) issue a certificate to a subscriber upon the the authority validating registration information of the subscriber; (b) manage the lifecycle of certificates; 11 Functions of certification authority Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (c) validate the identity of a subscriber who requests for a certificate, before its issuance; (d) ensure integrity, confidentiality, availability, authentication and non- repudiation of certificate services; (e) keep and maintain accurate and complete information of the certification service status; (f) operate and manage the certification system, facilities and equipment in a safe manner as to assure validity and stability of issued certificate; and (g) control risks associated with certification services. (2) The certification authority shall, in the performance of its functions- (a) make use of hardware, software and procedures that are secure from intrusion and misuse; (b) ensure reliability of its services; (c) adhere to security procedures to ensure that the secrecy and privacy of the electronic signatures are assured; and (d) comply with standards issued by the regulator. - 17 Verify source ↗
(1) A person who intends to obtain
A person seeking a certificate must apply to the registration authority and include the listed supporting documents and details.
17.-(1) A person who intends to obtain certificate from Certification Authority shall apply to the registration authority in the manner specified by the regulator in the certificate policy and certification practice statement. (2) The application under sub regulation (1) shall be accompanied by- (a) a copy of the National Identification Card or passport; 12 Application for certificate Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (b) a registered power of attorney for legal persons, in case of an entity; (c) certificate of incorporation or business registration certificate in case of an entity; including phone number, physical address and e -mail address; and (d) personal particulars (e) declaration verifying submitted information. (3) The registration authority shall, upon receipt of an application under sub regulation (1), validate the information and forward the application to the certification authority. Issuance of certificate - 18 Verify source ↗
(1) The certification authority shall issue a
The certification authority must issue a certificate only after receiving an application from the registration authority and being satisfied the application meets the policy requirements.
18.-(1) The certification authority shall issue a certificate after receipt of an application from registration authority and being satisfied that the application meets the requirements of the certificate policy and certification practice statement. (2) A certificate - (a) shall state the expiration date; (b) shall not be transferable; (c) shall contain information sufficient to locate or identify one or more repositories in which notification of the revocation or suspension of the certificate is listed; and (d) may be renewed. (3) The certification authority shall- (a) provide a reasonable opportunity for the subscriber to verify the contents of the certificate before it is issued; and (b) keep record of the date and time of the process in relation to the issuance of a certificate in the prescribed manner. Renewal of certificate - 19 Verify source ↗
(1) A subscriber may apply for renewal of
A subscriber may apply to renew a certificate, but the application must be made at least three months before the certificate expires.
19.-(1) A subscriber may apply for renewal of a certificate at least three months before expiration period of the certificate. 13 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (2) The provisions for an application for a certificate shall apply mutatis mutandis to application for renewal of a certificate. Suspension of certificate - 20 Verify source ↗
(1) The certification Authority may
The certification authority may suspend a certificate in specified cases, and must notify, publish, and record the suspension details.
20.-(1) The certification Authority may suspend the certificate- (a) upon the request of the subscriber; (b) for public interest; and (c) where there are reasonable grounds to believe that the certificate is not fictitious. (2) The certification authority upon suspension of a certificate shall- (a) issue a notice of the suspension subscriber specifying grounds for suspension; to the (b) publish the notice in the repository; and (c) keep record the date and time of the process in relation to the suspension of a certificate in the prescribed manner. (3) A certification authority shall terminate a request for suspension of a certificate where the certification authority discovers and confirms that the request was made without authorisation of the subscriber. (4) A person relying on a certificate shall be responsible to ensure that certificate has not been suspended. (5) The certification authority shall maintain facilities to receive and act upon requests for suspension of a certificate. Revocation of certificate - 21 Verify source ↗
(1) The certification authority shall revoke
The certification authority must revoke a certificate when specified events happen, and it must notify the subscriber, publish the notice, and keep revocation records.
21.-(1) The certification authority shall revoke a certificate where: (a) a request for revocation from registration authority or subscriber is received; (b) the subscriber dies; 14 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (c) the firm is dissolved or company wound up; (d) the certificate was obtained due to false representation, fraud or the information has been concealed; (e) the private key of a subscriber or security system of the certification authority was compromised in a manner materially affecting the reliability of a certificate; and (f) a request for suspension is received and there is sufficient evidence to substantiate the request. (2) A certification authority shall, upon revocation of a certificate- (a) issue a notice of to subscriber specifying grounds for the revocation; the revocation (b) publish the notice in the repository; and (c) keep record of the date and time of the process in relation to the revocation of a certificate. (3) The certification authority shall use the subscriber identity verification method specified in the certificate policy and certification practice statement for the purpose of confirming the identity of the subscriber submitting a request for revocation. - 22 Verify source ↗
A certification authority shall
A certification authority must maintain and upgrade computerized facilities and may only determine, collect, retain, and charge service charges subject to the regulator’s approval.
22. A certification authority shall- (a) maintain and upgrade computerized facilities for efficient delivery of services to the public through electronic means; and (b) determine, collect, retain and charge appropriate service charges from the person receiving service subject to the approval of the regulator. Delivery of services Key operations - 23 Verify source ↗
(1) A certification authority shall
A certification authority must handle keys and private keys securely, and may use tamper-proof storage options.
23.-(1) A certification authority shall- 15 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (a) transfer the keys from the key generation system to the storage device by using a secure mechanism that ensures end-to-end confidentiality and integrity; (b) use standard equipment and programs to securely store the subscriber's private key in an encrypted form; (c) store private key backups in a separate secure storage facility at a different location where the original key is stored; and (d) securely archive and store in a secure location component of the private key and its backup copies upon termination of the use of a private key. (2) A certification authority may (a) store keys in a tamper-proof cryptographic module; or (b) split keys into sub keys and store them in tamper-proof devices. Change of Keys Handling of Incidents - 24 Verify source ↗
(1) A
A certification authority must give notice when its key pair changes, and the notice goes to certificate users or the subscriber depending on whether the change is manual or automatic.
24.-(1) A certification and subscriber keys shall be changed or regenerated according to the certification practice statement of the respective certification authority. authority (2) The certification authority shall issue a notice of change of its key pair- (a) to certificates users before using the keys where the changes are done manually; and (b) to the subscriber for changes that are the through performed automatically system. - 25 Verify source ↗
A certification authority shall
A certification authority must maintain an incident management plan, have a regulator-approved procedure for key compromise, and notify the regulator and revoke affected subscriber certificates if its private key is compromised.
25. A certification authority shall- (a) implement an incident management plan security certification which covers handling of incidents within authority’s systems and networks; the 16 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) (b) establish a procedure that is approved by the regulator to handle cases where a compromise of the certification authority's key has occurred; and (c) notify the regulator and revoke the affected subscriber's certificates in case of a certification authority's private key compromise. Certification Practice Statement - 26 Verify source ↗
A certification authority shall
A certification authority must prepare a certification practice statement, get regulator approval before changes, and include required liability and identity-verification details.
26. A certification authority shall- (a) prepare a certification practice statement in manner as may be prescribed by the regulator; (b) obtain approval of the regulator before the certification to making changes practice statement; (c) highlight statement liabilities; and in the certificate practice limitations of subscriber’s (d) specify in the certification practice statement methods for verification of subscriber issuance, suspension, revocation and renewal of a certificate. identity for Digital Signature (c) The Subscriber - 27 Verify source ↗
(1) Subscriber shall authenticate an
A subscriber must authenticate an electronic transaction by affixing a digital signature, and a person may verify authenticity using the subscriber’s public key.
27.-(1) Subscriber shall authenticate an electronic transaction by affixing a digital signature. (2) The authentication of the electronic transaction shall be effective by the use of public key infrastructure the purposes of enclosing and transforming the initial electronic transaction into a secure electronic transaction. technologies for (3) A person may verify authenticity of an electronic transaction by use of the public key of a subscriber. 17 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) Generating key pair - 28 Verify source ↗
(1) Generation of key pair shall be done, in
Key pairs must be generated under specified conditions for subscribers and certification authorities, and a certification authority may generate a subscriber’s key pair on the subscriber’s behalf.
28.-(1) Generation of key pair shall be done, in the case of- (a) a subscriber within hardware or software, as prescribed in the certification practice statement of the certification authority; (b) a certification authority as part of a key ceremony trusted environment by trusted personnel within a secure device as may be prescribed by the regulator. a physically in (2) The private key and the public key for a subscriber, authorized by certification authority, shall constitute a unique functioning key pair. (3) A certification authority may generate subscriber a key pair on behalf of a subscriber. Acceptance of certificate - 29 Verify source ↗
(1) A subscriber shall be deemed to have
A subscriber is treated as having accepted a certificate if the certificate is used, published, or authorised by the subscriber to be published.
29.-(1) A subscriber shall be deemed to have accepted a certificate when the certificate is- Control of private key (a) used; (b) published; or (c) authorised subscriber. to be published, by the - 30 Verify source ↗
(1) A subscriber shall maintain control of
A subscriber must keep control of the private key and not disclose it to unauthorised persons, and must notify the certification authority in writing within three days after a key compromise is noticed.
30.-(1) A subscriber shall maintain control of the private key corresponding to the public key listed in the certificate and prevent disclosure of the private key to a person not authorised to affix the digital signature of the subscriber. (2) The subscriber shall communicate in writing to the certification authority within three days from the date the compromise was noticed, where the private key corresponding to the public key listed in the certificate has been compromised. (3) A subscriber who contravenes sub regulation (2) commits an offense. 18 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) Complaint handling - 31 Verify source ↗
(1) A subscriber who is aggrieved by the
A subscriber aggrieved by a certification authority decision may complain to the regulator within 21 days. The regulator must serve the complaint on the certification authority, ask for a reply within 7 days, then summon the parties, hold a hearing, and decide within 14 days after the service period lapses.
31.-(1) A subscriber who is aggrieved by the decision of the certification authority may file a complaint to the regulator within twenty-one days. (2) The regulator shall, upon receipt of a complaint, serve a copy of the complaint to the certification authority and request a reply within seven days. (3) The regulator shall, upon lapse of seven days from the date of service of the complaint to the certification authority summon the parties, conduct hearing and give its decision within fourteen days. PART IV GENERAL PROVISIONS Submission of progressive and financial report
Part
PART IV
- 32 Verify source ↗
Submission of progressive and financial report
This section is titled “Submission of progressive and financial report.”
32. Submission of progressive and financial report. - 36 Verify source ↗
Revocation
This section is titled “Revocation,” and the regulations may be cited as the “(Certification Services) Electronic Transactions Regulations, 2025.”
36. Revocation. __________ SCHEDULES __________ 2 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) THE ELECTRONIC TRANSACTIONS ACT, (CAP. 442) __________ REGULATIONS __________ THE ELECTRONIC TRANSACTIONS (CERTIFICATION SERVICES) REGULATIONS, 2025 PART I PRELIMINARY PROVISIONS Citation l. These Regulations may be cited as the (Certification Services) Electronic Transactions Regulations, 2025. Application - 32 Verify source ↗
(1) A licensee shall submit to the regulator
A licensee must send quarterly progress reports and annual audited financial reports to the regulator.
32.-(1) A licensee shall submit to the regulator quarterly progress reports and annual audited financial reports. (2) The progress reports shall include- (a) the number of subscribers; (b) the number of issued, suspended, revoked, expired or renewed; (c) a system performance report including, system up and down time and other extraordinary incidents; certificates (d) changes in the organizational structure of the certification authority; (e) changes of particulars of trusted persons; and (f) any other information as may be required by the regulator. (3) The annual audited financial report shall be prepared by a person registered as an auditor under the Accountants and Auditors (Registration) Act. (4) A copy of annual audited financial report shall be submitted to the regulator within thirty days of the completion of an audit. 19 Cap. 286 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) Appeals - 33 Verify source ↗
A person who is aggrieved by the decision
An aggrieved person may appeal a decision to the regulator, or from the regulator to the Fair Competition Tribunal, within 21 days of receiving the decision.
33. A person who is aggrieved by the decision of- (a) the certification authority or registration authority may appeal to the regulator; within twenty-one days from the date of receipt of the decision and (b) the regulator may appeal to the Fair Competition Tribunal within twenty-one days from the date of receipt of the decision. - 34 Verify source ↗
A licensee shall not disclose confidential
A licensee must not disclose a subscriber’s confidential information unless the subscriber has given prior approval.
34. A licensee shall not disclose confidential information in relation to a subscriber without prior approval of the subscriber. - 35 Verify source ↗
A person who contravenes any provision
A person who breaks a regulation with no specific penalty provided may be convicted and fined, imprisoned, or both.
35. A person who contravenes any provision of these Regulations for which a specific penalty is not provided, shall on conviction, be liable to a fine of not less than five million shillings but not exceeding ten million shillings or to imprisonment for a term of not less than twelve months but not exceeding twenty- four months or to both. - 36 Verify source ↗
Section 36
This section revokes the Transactions (Cryptographic and Certification Services Provider) Regulations.
36. The Transactions (Cryptographic and Certification Services Provider) Regulations are hereby revoked. Electronic Confidentiality Offences and penalties Revocation GN. No. 228 of 2016 20 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) ________ FIRST SCHEDULE ________ (Made under regulation 5(1)(a) and (b)) APPLICATION FORM APPLICATION FOR ELECTRONIC TRANSACTIONS CERTIFICATION SERVICES LICENCE - 2 Verify source ↗
Section 2
This section is a form-style entry for recording application fee receipt and applicant contact details.
2. Application Fee Receipt No: ………… dated ……../……...…/……..… Name of Applicant: ……………………………………………….… Physical Address:.…………………………………………..…………… Postal Address: ……………………….………………………………… Telephone No: …………………………………………………….…… E-mail: ………….………………………………………….…………. Website: ……….………………………………………………….…. - 3 Verify source ↗
Section 3
Tick the applicable certification services licence applied.
3. Tick (√) applicable certification services licence applied: - 3
This provision lists Certification Authority (CA) and Registration Authority (RA) with blank placeholders.
3.2 Certification Authority (CA)…………………………( ) Registration Authority (RA)…………………………( ) - 4 Verify source ↗
Section 4
The applicant/declarant must state that the application information is true and correct to the best of their knowledge.
4. DECLARATION I hereby declare that the information provided in this application is true and correct to the best of my/ our knowledge. Name…………………………………………………..…… Designation………………………………………………… Signature…………………………………………………… Date…………………………………………………….….. Official stamp/seal - 5 Verify source ↗
Section 5
Section 5 lists the documents that must accompany an application and sets the fee amounts in the Second Schedule.
5. Attachments The dully filled application form must be submitted with the following documents. A. Certification Authority 21 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) I. For Government Institutions (a) (b) (c) Receipt of the application fee Transmittal letter from the Government institutions Business Plan containing the following: - Location of hosting of certification systems both primary and backup (i) (ii) System security features to be deployed (iii) Services to be offered (iv) Services pricing/costing (v) Complaint handling procedure (vi) Financing plan, (vii) List of qualified staff and with their profile (viii) Personnel and human resource development plan (d) Certified TIN certificate II. For Private Institutions (a) (b) (c) (d) (e) (f) (g) Receipt of the application fee Company Profile Certified Copy of Certificate of Incorporation Certified Copy of Tax Identification Number (TIN) Certified Copy of Tax Clearance Certified Copy of Memorandum and Articles of Association Business Plan containing the following: - (i) (ii) (iii) (iv) (v) (vi) (vii) List of qualified staff and with their profile (viii) Personnel and human resource development plan (ix) (x) Location of hosting of certification systems both primary and backup System security features to be deployed Services to be offered Services pricing/costing Complaint handling procedure Financing plan Five years Projected financial statement, cash flow and balance sheet Capital Investment Ratio (Equity: Debt) B. Registration Authority I. For Government Institutions (a) (b) (c) (d) Receipt of the application fee Transmittal letter from the Government institutions Business Plan containing the following: - (i) (ii) (iii) (iv) (v) (vi) (vii) List of qualified staff and with their profile (viii) Personnel and human resource development plan Certified TIN certificate Location of hosting of certification systems both primary and backup System security features to be deployed Services to be offered Services pricing/costing Complaint handling procedure Financing plan, 22 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) II. For Private Institutions (a) (b) (c) (d) (e) (f) (g) S/N o 1 2 Receipt of the application fee Company Profile Certified Copy of Certificate of Incorporation Certified Copy of Tax Identification Number (TIN) Certified Copy of Tax Clearance Certified Copy of Memorandum of Articles of Association Business Plan containing the following: - (i) (ii) (iii) (iv) (v) (vi) (vii) List of qualified staff and with their profile (viii) Personnel and human resource development plan (ix) (x) Location of hosting of certification systems both primary and backup System security features to be deployed Services to be offered Services pricing/costing Complaint handling procedure Financing plan Five years Projected financial statement, cash flow and balance sheet Capital Investment Ratio (Equity: Debt) __________ SECOND SCHEDULE ________ (Made under regulations 5(3) and 9) Type of Licence Application Fee (TZS) Initial Fee (TZS) Renewal Fee (TZS) Annual Fee (TZS) Certification Authority Registration Authority 400,000 4,000,000 4,000,000 1% of GAT 100,000 1,000,000 1,000,000 1% of GAT 5 Duration of Licence (Years) 15 Dodoma, 27th September, 2024. JERRY WILLIAM SILAA Minister for Information, Communication and Information Technology 23
Part
PART I
- 2 Verify source ↗
These Regulations shall apply to Mainland
These Regulations apply in Mainland Tanzania and Tanzania Zanzibar.
2. These Regulations shall apply to Mainland Tanzania as well as Tanzania Zanzibar. Interpretation - 3 Verify source ↗
In these Regulations, unless the context
This section defines terms used in the Regulations.
3. In these Regulations, unless the context Cap. 442 requires otherwise- "Act" means the Electronic Transactions Act; "bridge certification authority" means a bridge certification allows interoperability of public key infrastructure certification from authorities, directorate, certificate policies and certificate practice statements to peer and establish trust relationship; authority which domains, different "certificate" has the meaning as ascribed to it under the Act.; "certificate policy" means a document which states the sets of rules indicating the applicability of certificate and class of application with common security requirements; "certification practice statement" means a document from a certification authority which describes their practice for issuance and management of a certificate; 3 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) "certification authority means an entity licensed to issue an electronic certificate; "certification path" means the chain of trust built by the certification authority or service provider responsible for certification; "cross certificate" means a certificate that is used to establish a trust relationship between two Certification Authorities; "certification services" means a range of services provided by a certification authorityor other trusted entity within a public key infrastructure to support the issuance, management and validation of digital certificates; "digital signature" means a mathematical scheme for verifying the authenticity of digital messages or documents; "digital certificate" has the meaning as ascribed to it under the Act; "electronic signature" shall has the meaning ascribed to it under the Act; "key compromise" means the compromise of private key where it’s content is disclosed to an unauthorised person or that person had access to it; "key pair" means a private key and its associated public key; "licence" means a licence granted under these Regulations for the provision of certification services; "Minister" means the Minister responsible for Information and Communication Technology; "public key" means a key known to the public and used for encryption of data and validation of digital signature; "public key infrastructure" means a set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, 4 Electronic Transactions (Certification Services) Regulations, GN. No. 133 (Contd) store, revoke digital certificate and manage public-key encryption; "private key" means a secret key that is used by an individual to decrypt information and to create a digital signature; "regulator" means a Government institution designated to be a regulator of certification services under the Act; “repository” means a system that contains issued certificates and list of certificates that have been revoked or suspended; "root certification authority" has the meaning as ascribed to it under the Act; "subscriber" has the meaning as ascribed to it under the Act; "trusted person" means a person who has direct responsibilities for the day-to-day operations, security and performance of the business activities that are regulated under the Act. "generating key pairs" means creating a private key and its corresponding public key which is to be listed in the digital certificate. PART II CERTIFICATION SERVICES LICENCE Prohibition to provide certification service
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
The Electronic Transactions (Certification Services) Regulations, 2025
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.