Electronic Signatures Act
The Minister appoints the date on which the Act comes into force by statutory instrument.
- Jurisdiction
- Uganda
- Instrument
- Act or statute
- Citation
- Chapter 98
- Version
- 18 Mar 2011
- Language
- en
- Official source
- View official record ↗
Source attribution: Source: Uganda Legal Information Institute
Statute overview
About this statute
The Minister appoints the date on which the Act comes into force by statutory instrument. This section provides definitions of terms used in the Act (interpretation section). Nothing in this Act shall be applied so as to exclude, restrict or deprive of legal effect any method of creating an electronic signature that satisfies the requirements for a signature in this Act or otherwise meets with the requirements of any other applicable law. The advanced signature verification process must ensure that advanced electronic signatures verified with a qualified certificate meet specified reliability, correspondence, display and authenticity criteria and are treated as equal to autographic signatures. An electronic signature that, when executed using a prescribed or commercially reasonable security procedure and relied upon in good faith by the relying party, meets specified criteria at the time it was made and at verification will be treated as a secure electronic signature.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of Electronic Signatures Act
Showing 100 of 100
Part 1
Preliminary
- 1 Verify source ↗
Preliminary - Commencement
The Minister appoints the date on which the Act comes into force by statutory instrument.
Section Commencement Section This Act shall come into force on a date appointed by the Minister by statutory instrument. - 2 Verify source ↗
Preliminary - Interpretation
This section provides definitions of terms used in the Act (interpretation section).
Section Interpretation Section In this Act , unless the context otherwise requires— " accept a certificate " means— (a) to manifest approval of a certificate , while knowing or having notice of its contents; or (b) to apply to a certification service provider for a certificate , without revoking the application by delivering notice of the revocation to the licensed certification service provider and obtaining a signed , written receipt from the certification service provider , if the certification service provider subsequently issues a certificate based on the application; " advanced electronic signature " means an electronic signature , which is— (a) uniquely linked to the signatory ; (b) reliably capable of identifying the signatory ; (c) created using secure signature creation device that the signatory can maintain; and (d) linked to the data to which it relates in such a manner that any subsequent change of the data or the connections between the data and the signature are detectable; " asymmetric cryptosystem " means an algorithm or series of algorithms, which provide a secure key pair ; " authorised officer " means the Controller or a police officer or a public officer performing any functions under this Act ; and includes any public officer authorised by the Minister or by the controller to perform any functions under this Act ; " certificate " means a data message or other records confirming the link between a signatory and a signature creation data; " certification service provider disclosure record " means an online and publicly accessible record that concerns a licensed certification service provider , which is kept by the Controller under subsection 21(5); " certification practice statement " means a declaration of the practices, which a certification service provider employs in issuing certificates generally or employs in issuing a particular certificate ; " certification service provider " means a person that issues certificates and may provide other services related to electronic signatures; " certify " means to declare with reference to a certificate , with ample opportunity to reflect and with a duty to apprise oneself of all material facts; " confirm " means to ascertain through diligent inquiry and investigation; " Controller " means National Information Technology Authority-Uganda; " correspond ", with reference to keys, means to belong to the same key pair ; " currency point " has the meaning assigned to it in the Schedule in this Act ; " digital signature " means a transformation of a message using an asymmetric cryptosystem such that a person having the initial message and the signer’s public key can accurately determine— (a) whether the transformation was created using the private key that corresponds to the signer’s public key ; and (b) whether the message has been altered since the transformation was made; " electronic signature " means data in electronic form affixed to or logically associated with a data message , which may be used to identify the signatory in relation to the data message and indicate the signatory 's approval of the information contained in the data message ; and includes an advance electronic signature and the secure signature; " electronic signature product " means configured hardware or software or relevant components of it, which are intended to be used by a certification service provider for the provision of electronic signature services or are intended to be used for the creation or verification of electronic signatures; " forge a digital signature " means— (a) to create a digital signature without the authorisation of the rightful holder of the private key ; or (b) to create a digital signature verifiable by a certificate listing as subscriber a person who either does not exist or does not hold the private key corresponding to the public key listed in the certificate ; " hold a private key " means to be able to utilise a private key ; " incorporate by reference " means to make one message a part of another message by identifying the message to be incorporated and expressing the intention that it be incorporated; " issue a certificate " means the act of a certification service provider in creating a certificate and notifying the subscriber listed in the certificate of the contents of the certificate ; " key pair " means a private key and its corresponding public key in an asymmetric cryptosystem , where the public key can verify a digital signature that the private key creates; " licensed certification service provider " means a certification service provider to whom a licence has been issued by the Controller and whose licence is in effect; " message " means a digital representation of information; " Minister " means the Minister responsible for information and communication technology; " notify " means to communicate a fact to another person in a manner reasonably likely under the circumstances to impart knowledge of the information to the other person ; " person " includes any company or association or body of persons corporate or unincorporate; " prescribed " means prescribed by or under this Act or any regulations made under this Act ; " private key " means the key of a key pair used to create a digital signature ; " public key " means the key of a key pair used to verify a digital signature and listed in the digital signature certificate ; " public key infrastructure " means a framework for creating a secure method for exchanging information based on public key cryptography; " publish " means to record or file in a repository ; " qualified certification service provider " means a certification service provider that satisfies the requirements under section 23 ; " recipient " means a person who receives or has a digital signature and is in a position to rely on it; " recognised date or time stamp service " means a date/time stamp service recognised by the Controller under section 79 ; " recognised repository " means a repository recognised by the Controller under section 77 ; " recommended reliance limit " means the monetary amount recommended for reliance on a certificate under section 76 ; " relying party " means a person that may act on the basis of a certificate or an electronic signature ; " repository " means a system for storing and retrieving certificates and other information relevant to digital signatures; " revoke a certificate " means to make a certificate ineffective permanently from a specified time forward; " rightfully hold a private key " means to be able to utilise a private key — (a) which the holder or the holder’s agents have not disclosed to any person in contravention of this act; and (b) which the holder has not obtained through theft, deceit, eavesdropping or other unlawful means; " security procedure " means a procedure for the purpose of— (a) verifying that an electronic record is that of a specific person ; or (b) detecting error or alteration in the communication, content or storage of an electronic record since a specific point in time, which may require the use of algorithms or codes, identifying words or numbers, encryption, answer back or acknowledgement procedures or similar security devices; " secure signature creation device " means a signature creation device which meets the requirements laid down in section 4 ; " signatory " means a person that holds signature creation data and acts either on its own behalf or on behalf of the person it represents " signature creation device " means configured software or hardware, used by the signatory to create an electronic signature ; " signature verification data " means unique data such as codes or public cryptographic keys, used for the purpose of verifying an electronic signature ; " signature verification device " means configured software or hardware, used for the purpose of verifying an electronic signature ; " signed " or "signature" and its grammatical variations includes any symbol executed or adapted or any methodology or procedure employed or adapted, by a person with the intention of authenticating a record, including an electronic or digital method; " subscriber " means a person who— (a) is the subject listed in a certificate ; (b) accepts the certificate ; and (c) holds a private key which corresponds to a public key listed in that certificate ; " suspend a certificate " means to make a certificate ineffective temporarily for a specified time forward; " this Act " includes any regulations made under this Act; " time-stamp " means— (a) to append or attach to a message , digital signature or certificate a digitally signed notation indicating at least the date, time and identity of the person appending or attaching the notation; or (b) the notation appended or attached; " transactional certificate " means a certificate , incorporating by reference one or more digital signatures, issued and valid for a specific transaction; " trustworthy system " means computer hardware and software which— (a) are reasonably secure from intrusion and misuse; (b) provide a reasonable level of availability, reliability and correct operation; and (c) are reasonably suited to performing their intended functions; " valid certificate " means a certificate which— (a) a licensed certification service provider has issued; (b) has been accepted by the subscriber listed in it; (c) has not been revoked or suspended; and (d) has not expired, but a transactional certificate is a valid certificate only in relation to the digital signature incorporated in it by reference; " verify a digital signature " means, in relation to a given digital signature , message and public key , to determine accurately that— (a) the digital signature was created by the private key corresponding to the public key ; and (b) the message has not been altered since its digital signature was created; " writing " or "written" includes any handwriting, typewriting, printing, electronic storage or transmission or any other method of recording information or fixing information in a form capable of being preserved. For the purposes of this Act , a certificate shall be revoked by making a notation to that effect on the certificate or by including the certificate in a set of revoked certificates. The revocation of a certificate does not mean that it is destroyed or made illegible. - 3 Verify source ↗
Preliminary - Equal treatment of signature technologies
Nothing in this Act shall be applied so as to exclude, restrict or deprive of legal effect any method of creating an electronic signature that satisfies the requirements for a signature in this Act or otherwise meets with the requirements of any other applicable law.
Section Equal treatment of signature technologies Section Nothing in this Act shall be applied so as to exclude, restrict or deprive of legal effect any method of creating an electronic signature that satisfies the requirements for a signature in this Act or otherwise meets with the requirements of any other applicable law.
Part II
Electronic signatures
- 10 Verify source ↗
Electronic signatures - Advanced signatures
The advanced signature verification process must ensure that advanced electronic signatures verified with a qualified certificate meet specified reliability, correspondence, display and authenticity criteria and are treated as equal to autographic signatures.
Section Advanced signatures Section The advanced signature verification process shall ensure that— An advanced electronic signature , verified with a qualified certificate , is equal to an autographic signature in relation to data in electronic form and has therefore equal legal effectiveness and admissibility as evidence. the data used for verifying the electronic signature correspond to the data displayed to the verifier; the signature is reliably verified and the result of the verification and identity of the certificate holder is correctly displayed to the verifier; the verifier can reliably establish the contents of the signed data; the authenticity and validity of the certificate required at the time of signature verification are verified; the use of a pseudonym is clearly indicated; any security-relevant changes can be detected. - 11 Verify source ↗
Electronic signatures - Secure electronic signature
An electronic signature that, when executed using a prescribed or commercially reasonable security procedure and relied upon in good faith by the relying party, meets specified criteria at the time it was made and at verification will be treated as a secure electronic signature.
Section Secure electronic signature Section Where, through the application of a prescribed security procedure or a commercially reasonable security procedure agreed to by the parties involved, an electronic signature is executed in a trustworthy manner, reasonably and in good faith relied upon by the relying party , that signature shall be treated as a secure electronic signature at the time of verification to the extent that it can be verified that the electronic signature satisfied, at the time it was made, the following criteria— the signature creation data used for signature creation is unique and its secrecy is reasonably assured; it was capable of being used to objectively identify that person ; it was created in a manner or using a means under the sole control of the person using it, that cannot be readily duplicated or compromised; it is linked to the electronic record to which it relates in such a manner that if the record was changed to electronic signature would be invalidated; the signatory can reliably protect his or her signature creation data from unauthorised access. - 12 Verify source ↗
Electronic signatures - Presumptions relating to secure and advanced electronic signatures
In civil cases involving a secure or advanced electronic signature or record, certain facts are presumed (including that the signature is that person’s and was affixed with intent, and that a secure/advanced record has not been altered), and the party who challenges the genuineness of such a signature must both produce evidence to rebut the presumption and persuade the court.
Section Presumptions relating to secure and advanced electronic signatures Section In any civil proceedings involving a secure or advanced electronic signature , the following shall be presumed unless the contrary is proved— In any civil proceedings involving a secure electronic record, it shall be presumed, unless the contrary is proved, that the secure or advanced electronic record has not been altered since the specific point in time to which the secure status relates. the secure or advanced electronic signature is the signature of the person to whom it correlates; and the secure or advanced electronic signature was affixed by that person with the intention of signing or approving the electronic record. In the absence of a secure or advanced electronic signature , nothing in this Part shall create any presumption relating to the authenticity and integrity of the electronic record or an electronic signature . The effect of presumptions provided in this section is to place on the party challenging the genuineness of a secure or advanced electronic signature both the burden of going forward with evidence to rebut the presumption and the burden of persuading the court of the fact that the non-existence of the presumed fact is more. - 4 Verify source ↗
Electronic signatures - Compliance with a requirement for a signature
An electronic signature satisfies a legal signature requirement if it is sufficiently reliable for the message's purpose; the signatory's signature creation data must be linked to and controlled by the signatory, alterations to the signature or signed information must be detectable.
Section Compliance with a requirement for a signature Section An electronic signature is considered to be reliable for the purpose of satisfying the requirement referred to in subsection (1) if— Subsection (3) does not limit the liability of any person — Where the law requires a signature of a person , that requirement is met in relation to a data message if an electronic signature is used which is as reliable as was appropriate for the purpose for which the data message was generated or communicated, in light of all the circumstances, including any relevant agreement. Subsection (1) applies whether the requirement referred to in that subsection in the form of an obligation or whether the law simply provides consequences for the absence of a signature. the signature creation data are, within the context in which they are used, linked to the signatory and to no other person ; the signature creation data were, at the time of signing, under the control of the signatory and of no other person ; any alteration to the electronic signature , made after the time of signing, is detectable; and where a purpose of legal requirement for a signature is to provide assurance as to the integrity of the information to which it relates, any alteration made to that information after the time of signing is detectable. to establish in any other way, for the purpose of satisfying the requirement referred to in subsection (l), the reliability of an electronic signature ; or to adduce evidence of the non-reliability of an electronic signature . - 5 Verify source ↗
Electronic signatures - Conduct of the signatory
Each signatory must promptly notify foreseeable relying parties if signature-creation data are (or may be) compromised, must exercise reasonable care to avoid unauthorised use of signature-creation data, and where a certificate supports the electronic signature must ensure material representations relevant to the certificate are accurate and complete.
Section Conduct of the signatory Section Where signature creation data can be used to create a signature that has legal effect, each signatory shall— without undue delay, notify any person that may reasonably be expected by the signatory to rely on or to provide services in support of the electronic signature if— exercise reasonable care to avoid unauthorised use of its signature creation data; the signatory knows that the signature creation data have been compromised; or the circumstances known to the signatory give rise to a substantial risk that the signature creation data may have been compromised; where a certificate is used to support the electronic signature , exercise reasonable care to ensure the accuracy and completeness of all material representations made by the signatory which are relevant to the certificate throughout its life-cycle or which are to be included in the certificate . - 6 Verify source ↗
Electronic signatures - Variation by agreement
The provisions of this Act can be derogated from or varied by agreement, unless that agreement would be invalid or ineffective under any law.
Section Variation by agreement Section The provisions of this Act may be derogated from or their effect may be varied by agreement unless that agreement would not be valid or effective under any law. - 7 Verify source ↗
Electronic signatures - Conduct of the relying party
When an electronic signature is supported by a certificate, a relying party must take reasonable steps to verify the signature's reliability, verify the certificate's validity/suspension/revocation, and observe any certificate limitations; the relying party shall bear the legal consequences of failing to do so.
Section Conduct of the relying party Section A relying party shall bear the legal consequences of his or her failure to— where an electronic signature is supported by a certificate , take reasonable steps— take reasonable steps to verify the reliability of an electronic signature ; or to verify the validity, suspension or revocation of the certificate ; and to observe any limitation with respect to the certificate . - 8 Verify source ↗
Electronic signatures - Trustworthiness
When assessing whether systems, procedures and human resources used by a certification service provider are trustworthy, regard may be had to specified factors such as financial and human resources (including assets), quality of hardware and software, certificate processing and record retention procedures, availability of information to signatories and relying parties, independent audits, declarations of compliance, or any other relevant factor.
Section Trustworthiness Section When determining whether or to what extent any systems procedures and human resources utilised by a certification service provider are trustworthy, regard may be had to the following factors— financial and human resources, including existence of assets; quality of hardware and software systems; procedure for processing of certificates and applications for certificates and retention of records; availability of information to signatories identified in certificates and to potential relying parties; regularity and extent of audit by an independent body; the existence of a declaration by the state, an accreditation body or the certification service provider regarding compliance with or existence of the foregoing; or any other relevant factor. - 9 Verify source ↗
Electronic signatures - Conduct of the certification service provider
A certification service provider that supports legally effective electronic signatures must provide accessible certificate information, act according to its representations, exercise reasonable care for accuracy, offer notice and revocation mechanisms where stated, use trustworthy systems, and is liable for failure to meet these requirements.
Section Conduct of the certification service provider Section Where a certification service provider provides services to support an electronic signature that may be used for legal effect as a signature, that certification service provider shall— provide reasonably accessible means which enable a relying party to ascertain from the certificate — provide reasonably accessible means which enable a relying party to ascertain, where relevant, from the certificate or otherwise— act in accordance with representations made by it with respect to its policies and practices; exercise reasonable care to ensure the accuracy and completeness of all material representations made by it that are relevant to the certificate throughout its life-cycle or which are included in the certificate ; the identity of the certification service provider ; that the signatory that is identified in the certificate had control of the signature creation data at the time when the certificate was issued; that signature creation data were valid at or before the time when the certificate was issued; the method used to identify the signatory ; any limitation on the purpose or value for which the signature creation data or the certificate may be used; that the signature creation data are valid and have not been compromised; any limitation on the scope or extent of liability stipulated by the certification service provider ; whether means exist for the signatory to give notice under section 4 (1); whether a timely revocation service is offered; where services under paragraph (d) (v) are offered, provide a means for a signatory to give notice under section 4 (1)(b) and, where services under paragraph d(vi) are offered, ensure the availability of a timely revocation service; utilize trustworthy systems, procedures and human resources in performing its services. A certification service provider shall be liable for its failure to satisfy the requirements of subsection (1).
Part III
Secure digital signatures
- 13 Verify source ↗
Secure digital signatures - Secure digital signatures
A digital signature on part of an electronic record is treated as a secure electronic signature for that part if specific certificate‑trustworthiness or party‑agreement conditions are met.
Section Secure digital signatures Section When a portion of an electronic record is signed with a digital signature the digital signature shall be treated as a secure electronic signature in respect of that portion of the record, if— the certificate is considered trustworthy, in that it is an accurate binding of a public key to a person ’s identity because— the digital signature was created during the operational period of a valid certificate and is verified by reference to a public key listed in the certificate ; and the certificate was issued by a certification service provider operating in compliance with regulations made under this Act ; the certificate was issued by a certification service provider outside Uganda recognised for the purpose by the Controller pursuant to regulations made under this Act ; the certificate was issued by a department or ministry of the Government, an organ of state of statutory corporation approved by the minister to act as a certification service provider on such conditions as the regulations may specify; or the parties have expressly agreed between themselves to use digital signatures as a security procedure and the digital signature was properly verified by reference to the sender’s public key . - 14 Verify source ↗
Secure digital signatures - Satisfaction of signature requirements
A digital signature satisfies a signature requirement when the digital signature was affixed by the signer with the intention of signing the message.
Section Satisfaction of signature requirements Section Where a rule of law requires a signature or provides for certain consequences in the absence of a signature, that rule shall be satisfied by a digital signature where— the recipient has no knowledge or notice that the signer— Notwithstanding any written law to the contrary— that digital signature is verified by reference to the public key listed in a valid certificate issued by a licensed certification service provider ; that digital signature was affixed by the signer with the intention of signing the message ; and has breached a duty as a subscriber ; or does not rightfully hold the private key used to affix the digital signature . a document signed with a digital signature in accordance with this Act shall be as legally binding as a document signed with a handwritten signature, an affixed thumbprint or any other mark; and a digital signature created in accordance with this Act shall be taken to be a legally binding signature. Nothing in this Act shall preclude a symbol from being valid as a signature under any other applicable law. - 15 Verify source ↗
Secure digital signatures - Unreliable digital signatures
Unless law or contract provides otherwise, a recipient who unreasonably relies on a digital signature assumes the risk it is forged; if the recipient decides not to rely, they must promptly notify the signer and state the grounds.
Section Unreliable digital signatures Section Unless otherwise provided by law or contract, the recipient of a digital signature assumes the risk that a digital signature is forged, if reliance on the digital signature is not reasonable under the circumstances. Where the recipient decides not to rely on a digital signature under this section, the recipient shall promptly notify the signer of its determination not to rely on a digital signature and the grounds for that determination. - 16 Verify source ↗
Secure digital signatures - Digitally signed document taken to be written document
A digitally signed message is treated as if it were written on paper when the digital signature is verified by the public key in a certificate that (a) bears an entire digital signature, (b) was issued by a licensed certification service provider, and (c) was valid when the digital signature was created.
Section Digitally signed document taken to be written document Section A message shall be as valid, enforceable and effective as if it had been written on paper if— that digital signature is verified by the public key listed in a certificate which— it bears in its entirety a digital signature ; and was issued by a licensed certification service provider ; and was valid at the time the digital signature was created. Nothing in this Act shall preclude any message , document or record from being considered written or in writing under any other applicable law. - 17 Verify source ↗
Secure digital signatures - Digitally signed document deemed to be original document
A copy of a digitally signed message is as valid, enforceable and effective as the original unless the signer designated an instance as a unique original, in which case only that instance is valid, enforceable and effective.
Section Digitally signed document deemed to be original document Section A copy of a digitally signed message shall be as valid, enforceable and effective as the original of the message unless it is evident that the signer designated an instance of the digitally signed message to be a unique original, in which case only that instance constitutes the valid, enforceable and effective message . - 18 Verify source ↗
Secure digital signatures - Authentication of digital signatures
A certificate issued by a licensed certification service provider must be an acknowledgement of a digital signature verified by the public key in the certificate, when the signature is verifiable by that certificate and was affixed while the certificate was valid.
Section Authentication of digital signatures Section A certificate issued by a licensed certification service provider shall be an acknowledgement of a digital signature verified by reference to the public key listed in the certificate , regardless of whether words of an express acknowledgement appear with the digital signature and regardless of whether the signer physically appeared before the licensed certification service provider when the digital signature was created, if that digital signature is— verifiable by that certificate ; and was affixed when that certificate was valid. - 19 Verify source ↗
Secure digital signatures - Presumptions in adjudicating disputes
When deciding disputes about digital signatures, a court must presume certain listed facts about certificates, signatures, timestamps, and the intentions and authority of subscribers and certification service providers.
Section Presumptions in adjudicating disputes Section In adjudicating a dispute involving a digital signature , a court shall presume— that a certificate digitally signed by a licensed certification service provider and— that where the public key verifies a digital signature listed in a valid certificate issued by a licensed certification service provider — the recipient of that digital signature has no knowledge or notice that the signer— published in a recognised repository ; or made available by the issuing licensed certification service provider or by the subscriber listed in the certificate , is issued by the licensed certification service provider which digitally signed it and is accepted by the subscriber listed in it; that the information listed in a valid certificate and confirmed by a licensed certification service provider issuing the certificate is accurate; that digital signature is the digital signature of the subscriber listed in that certificate ; that digital signature was affixed by that subscriber with the intention of signing the message ; and has breached a duty as a subscriber ; or does not rightfully hold the private key used to affix the digital signature ; and that a digital signature was created before it was time stamped by a recognised date or time stamp service utilising a trustworthy system .
Part IV
Public key infrastructure (PKI)
- 20 Verify source ↗
Public key infrastructure (PKI) - Sphere of application
This Part applies to digital signatures or signatures that are able to use the public key infrastructure (PKI).
Section Sphere of application Section This Part applies to digital signatures or signatures that are able to use the public key infrastructure (PKI). - 21 Verify source ↗
Public key infrastructure (PKI) - Controller
The Controller must monitor and oversee certification service providers, perform its Act functions, follow Ministerial policy directions, keep a public disclosure database for each provider, and publish that database in at least one recognised repository.
Section Controller Section The Controller shall, in particular be responsible for monitoring and overseeing the activities of certification service providers and shall perform the functions conferred on the Controller under this Act . The Controller shall exercise its functions under this Act subject to such directions as to the general policy guidelines as may be given by the Minister . The Controller shall maintain a publicly accessible database containing a certification service provider disclosure record for each certification service provider , which shall contain all the particulars required under regulations made under this Act . The Controller shall publish the contents of the database in at least one recognised repository . - 22 Verify source ↗
Public key infrastructure (PKI) - Certification service providers to be licensed
A person must not operate as a certification service provider unless they hold a valid licence issued under this Act.
Section Certification service providers to be licensed Section A person shall not carry on or operate or hold himself out as carrying on or operating, as a certification service provider unless that person has a valid licence issued under this Act . A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding two hundred and forty currency points or imprisonment not exceeding ten years or both; and in the case of a continuing offence is in addition liable to a daily fine not exceeding ten currency points for each day the offence continues. The Minister may, on an application in writing being made in accordance with this Act , exempt a person operating as a certification service provider within an organisation from the requirement of a licence under this section where certificates and key pairs are issued to members of the organisation for internal use only; but the Minister shall not delegate that power to the Controller . The liability limits specified in Part IV shall not apply to an exempted certification service provider and Part V shall not apply in relation to a digital signature verified by a certificate issued by an exempted certification service provider . - 23 Verify source ↗
Public key infrastructure (PKI) - Qualifications of certification service providers
The Minister, together with the National Information Technology Authority-Uganda, must set qualifications for certification service providers and may later vary or amend them, but changes cannot be applied to currently licensed providers until their licence expires.
Section Qualifications of certification service providers Section The Minister in consultation with National Information Technolology Authority-Uganda shall, by regulations made under this Act , prescribe the qualifications required for certification service providers. The Minister in consultation with National Information Technolology Authority-Uganda may vary or amend the qualifications prescribed under subsection (1) but any such variation or amendment shall not be applied to a certification service provider holding a valid licence under this Act until the expiry of that licence. - 24 Verify source ↗
Public key infrastructure (PKI) - Functions of licensed certification service providers
A certification service provider must issue a certificate to a subscriber when the subscriber applies and meets identity requirements and pays prescribed fees, and must take all reasonable measures to verify the subscriber's identification before issuing the certificate.
Section Functions of licensed certification service providers Section The function of a certification service provider shall be to issue a certificate to a subscriber upon application and upon satisfaction of the certification service providers requirements as to the identity of the subscriber to be listed in the certificate and upon payment of the prescribed fees and charges. The certification service provider shall, before issuing a certificate under this Act , take all reasonable measures to check for proper identification of the subscriber to be listed in the certificate . - 25 Verify source ↗
Public key infrastructure (PKI) - Application for licence
An applicant must apply in writing to the Controller for a licence, include prescribed documents, and provide additional information if the Controller requires it.
Section Application for licence Section An application for a licence under this Act shall be made in writing to the Controller in such form as may be prescribed . An application under subsection (1) shall be accompanied by such documents or information as may be prescribed and the Controller may, at any time after receiving the application and before it is determined, require the applicant to provide such additional documents or information as may be considered necessary by the Controller for the purposes of determining the suitability of the applicant for the licence. Where any additional document or information required under subsection (2) is not provided by the applicant within the time specified in the requirement or any extension granted by the Controller , the application shall be taken to be withdrawn and shall not be further proceeded with, without prejudice to a fresh application being made by the applicant. - 26 Verify source ↗
Public key infrastructure (PKI) - Grant or refusal of licence
The Controller must consider properly made applications, may grant or refuse a licence after satisfaction and payment of the prescribed fee, a licence must state duration and number, the Controller may vary or amend licence terms for just cause but must give the licensee a reasonable opportunity to be heard, and the Controller must notify the applicant in writing within thirty days.
Section Grant or refusal of licence Section The Controller shall, on an application having been duly made in accordance with section 25 and after being provided with all the documents and information as he may require, consider the application and when he or she is satisfied that the applicant is a qualified certification service provider and a suitable licensee and upon payment of the prescribed fee, grant the licence with or without conditions or refuse to grant a licence. A licence granted under subsection (1) shall set out the duration of the licence and the licence number. The terms and conditions imposed under the licence may at any time be varied for just cause or amended by the Controller but the licensee shall be given a reasonable opportunity of being heard. The Controller shall notify the applicant in writing of his or her decision to grant or refuse to grant a licence within thirty days of receiving the application. - 27 Verify source ↗
Public key infrastructure (PKI) - Revocation of licence
The Controller may revoke a licence for specified grounds; before revocation the Controller must give written notice and require the licensee to show cause within thirty days; if revoking the Controller must notify the licensee within 48 hours; revocation takes effect after 30 days if no appeal, and appeals suspend issuance of certificates until set aside by the Minister; contravention attracts fines up to 240 currency points or imprisonment up to ten years.
Section Revocation of licence Section The Controller may revoke a licence granted under section 26 if satisfied that— the certification service provider has failed to comply with an obligation imposed upon it by or under this Act ; the certification service provider has contravened any condition imposed under the licence, any provision of this Act or any other written law; the certification service provider has, either in connection with the application for the licence or at any time after the grant of the licence, provided the Controller with false, misleading or inaccurate information or a document or declaration made by or on behalf of the certification service provider or by or on behalf of a person who is or is to be a director, Controller or manager of the licensed certification service provider which is false, misleading or inaccurate; the certification service provider is carrying on its business in a manner which is prejudicial to the interest of the public or to the national economy; the certification service provider has insufficient assets to meet its liabilities; a winding up order has been made against the licensed certification service provider or a resolution for its voluntary winding-up has been passed; the certification service provider or its director, Controller or manager has been convicted of an offence under this Act in his or her capacity as; or the certification service provider has ceased to be a qualified certification service provider . Before revoking a licence, the Controller shall give the licensed certification service provider a notice in writing of his or her intention to revoke the licence and require the licensed certification service provider to show cause within thirty days as to why the licence should not be revoked. Where the Controller decides to revoke the licence, he or she shall notify the certification service provider of his or her decision by a notice in writing within 48 hours of making the decision. The revocation of a licence shall take effect where there is no appeal against the revocation, on the expiration of thirty days from the date on which the notice of revocation is served on the licensed certification service provider . Where an appeal has been made against the revocation of a licence, the certification service provider whose licence has been revoked shall not issue any certificates until the appeal has been disposed of and the revocation has been set aside by the Minister but nothing in this subsection shall prevent the certification service provider from fulfilling its other obligations to its subscribers during that period. A person who contravenes subsection (5) commits an offence and is liable, on conviction, to a fine not exceeding two hundred and forty currency points or to imprisonment not exceeding ten years or both. Where the revocation of a licence has taken effect, the Controller shall, as soon as practicable, cause the revocation to be published in the certification service provider disclosure record he or she maintains for the certification service provider concerned and advertised in at least two English language national daily newspapers for at least three consecutive days. - 28 Verify source ↗
Public key infrastructure (PKI) - Appeal
The Minister must respond to an appeal within thirty days; a person not satisfied with the Minister's decision may appeal to the High Court.
Section Appeal Section A person who is aggrieved by— the refusal of the Controller to license a certification service provider under section 26 or to renew a licence under section 35 ; or the revocation of a licence under section 27 , The Minister shall, upon receipt of the appeal respond within thirty days. A person not satisfied with the Minister 's decision may appeal to the High Court. - 29 Verify source ↗
Public key infrastructure (PKI) - Surrender of licence
A certification service provider may surrender its licence by sending the licence and a written notice to the Controller; the surrender takes effect when the Controller receives both the licence and notice (or on a later date specified), and the licensed provider must publish and advertise the surrender within fourteen days.
Section Surrender of licence Section A certification service provider may surrender its licence by forwarding it to the Controller with a written notice of its surrender. The surrender shall take effect on the date the Controller receives the licence and the notice under subsection (1) or where a later date is specified in the notice, on that date. The licensed certification service provider shall, not later than fourteen days after the date referred to in subsection (2), cause the surrender to be published in the certification service provider disclosure record of the certification service provider concerned and advertised in at least two English language national daily newspapers for at least three days consecutive. - 30 Verify source ↗
Public key infrastructure (PKI) - Effect of revocation, surrender or expiry of licence
When a certification service provider's licence is revoked, surrendered or expires they must stop operating; the Minister may authorise continued operation to wind up affairs; an expired licence-holder who has applied for renewal and is pending determination may continue to operate on proof; contravening the duty is an offence with fines and imprisonment; the Controller must appoint another provider to take over certificates and the appointed provider may require subscribers to comply or reissue certificates.
Section Effect of revocation, surrender or expiry of licence Section Where the revocation of a licence under section 27 or its surrender under section 29 has taken effect or where the licence has expired, the licensed certification service provider shall immediately cease to carry on or operate any business in respect of which the licence was granted. Notwithstanding subsection (1), the Minister may, on the recommendation of the Controller , authorise the licensed certification service provider in writing to carry on its business for such duration as the Minister may specify in the authorisation for the purpose of winding up its affairs. Notwithstanding subsection (1), a licensed certification service provider whose licence has expired shall be entitled to carry on its business as if its licence had not expired upon proof being submitted to the Controller that the licensed certification service provider has applied for a renewal of the licence and that such application is pending determination. A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding seventy two currency points or to imprisonment not exceeding ten years or both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding five currency points for each day the offence continues. Without prejudice to the Controller ’s powers under section 26 , the revocation of a licence under section 27 or its surrender under section 29 or its expiry shall not affect the validity or effect of any certificate issued by the certification service provider concerned before such revocation, surrender or expiry. For the purposes of subsection (5), the Controller shall appoint another licensed certification service provider to take over the certificates issued by the certification service provider whose licence has been revoked or surrendered or has expired and the certificate shall, to the extent that they comply with the requirements of the appointed licensed certification service provider , be deemed to have been issued by that licensed certification service provider . Subsection (6) shall not preclude the appointed licensed certification service provider from requiring the subscriber to comply with its requirements in relation to the issue of certificates or from issuing a new certificate to the subscriber for the unexpired period of the original certificate except that any additional fees or charges to be imposed shall only be imposed with the prior written approval of the Controller . - 31 Verify source ↗
Public key infrastructure (PKI) - Effect of lack of licence
Licensing requirements do not affect the validity of certain digital signatures; Parts IV and V do not apply in specified unlicensed or unverifiable cases.
Section Effect of lack of licence Section The liability limits specified in Part IV shall not apply to unlicensed certification service providers. Part V shall not apply in relation to an electronic signature , which cannot be verified by a certificate issued by a licensed certification service provider . In any other case, unless the parties expressly provide otherwise by contract between themselves, the licensing requirements under this Act shall not affect the effectiveness, enforceability or validity of any digital signature . - 32 Verify source ↗
Public key infrastructure (PKI) - Return of licence
Licensed certification service providers must return the licence to the Controller within fourteen days when the licence is revoked, has expired without timely renewal application, or renewal is refused.
Section Return of licence Section Where the revocation of a licence under section 27 has taken effect or where the licence has expired and no application for its renewal has been submitted within the period specified or where an application for renewal has been refused under section 35 , the licensed certification service provider shall within fourteen days return the licence to the Controller . A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding seventy two eight currency points or to imprisonment not exceeding three years or to both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding five currency points for each day the offence continues and the court shall retain the licence and forward it to the Controller . - 33 Verify source ↗
Public key infrastructure (PKI) - Restricted licence
The Controller may classify and issue licences with specified limitations; licensed certification service providers must not issue certificates that exceed their licence restrictions, and doing so is an offence with specified consequences that do not affect certificate validity.
Section Restricted licence Section The Controller may classify licences according to specified limitations including— maximum number of outstanding certificates; cumulative maximum of recommended reliance limits in certificates issued by the licensed certification service provider ; and issuance only within a single firm or organisation. The Controller may issue licences restricted according to the limits of each classification. A licensed certification service provider that issues a certificate exceeding the restrictions of its licence commits an offence. Where a licensed certification service provider issues a certificate exceeding the restrictions of its licence, the liability limits specified in Part IV shall not apply to the licensed certification service provider in relation to that certificate . Nothing in subsection (3) or (4) shall affect the validity or effect of the issued certificate . - 34 Verify source ↗
Public key infrastructure (PKI) - Restriction on use of expression "certification service provider"
Persons must not use or claim the expression "certification service provider" or derivatives in relation to their business without the Controller's written consent.
Section Restriction on use of expression "certification service provider" Section Except with the written consent of the Controller , a person shall not being a licensed certification service provider , assume or use the expressions " certification service provider " or " licensed certification service provider ", as the case may be or any derivative of those expressions in any language or any other words in any language capable of being construed as indicating the carrying on or operation of such business, in relation to the business or any part of the business carried on by that person or make any representation to that effect in any bill head, letter, paper, notice, advertisement or in any other manner. A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding one hundred sixty eight currency points or to imprisonment not exceeding seven years or to both. - 35 Verify source ↗
Public key infrastructure (PKI) - Renewal of licence
Licensed certification service providers must apply to the Controller and submit required documents at least thirty days before licence expiry to renew; if they do not intend to renew they must publish and advertise that intention at least thirty days before expiry for at least five consecutive days; the Controller may refuse renewal where subsection (1) requirements are not met.
Section Renewal of licence Section A licensed certification service provider shall submit an application to the Controller in such form as may be prescribed for the renewal of its licence at least thirty days before the date of expiry of the licence and the application shall be accompanied by such documents and information as may be required by the Controller . The prescribed fee shall be payable upon approval of the application. Where a licensed certification service provider has no intention of renewing its licence, the licensed certification service provider shall, at least thirty days before the expiry of the licence, publish the intention in the certification service provider disclosure record of the certification service provider concerned and advertise such intention in at least two English language national daily newspapers for at least five consecutive days. Without prejudice to any other grounds, the Controller may refuse to renew a licence where the requirements of subsection (1) have not been complied with. - 36 Verify source ↗
Public key infrastructure (PKI) - Lost license
If a certification service provider has lost its license, it must immediately notify the Controller in writing and, as soon as practicable, apply for a replacement license with required information, documents and the prescribed fee.
Section Lost license Section Where a certification service provider has lost its license, it shall immediately notify the Controller in writing of the loss. The certification service provider shall, as soon as practicable, submit an application for a replacement license accompanied by all such information and documents as may be required by the Controller together with the prescribed fee. - 37 Verify source ↗
Public key infrastructure (PKI) - Recognition of other licenses
The Controller may, by order published in the Gazette, recognise certification service providers authorised outside Uganda if they satisfy the prescribed requirements.
Section Recognition of other licenses Section Where a license or other authorisation of an entity is recognised under subsection (1)— The Controller may recognise, by order published in the Gazette , certification service providers licensed or otherwise authorised by entities outside Uganda that satisfy the prescribed requirements. the recommended reliance limit , if any, specified in a certificate issued by the certification service provider licensed or otherwise authorised by such an entity shall have effect in the same manner as a recommended reliance limit specified in a certificate issued by a certification service provider of Uganda; and Part IV shall apply to the certificates issued by the certification service provider licensed or otherwise authorised by such entity in the same manner as it applies to a certificate issued by a certification service provider of Uganda. - 38 Verify source ↗
Public key infrastructure (PKI) - Performance audit
Certification service providers must have their operations audited at least once a year; the Controller must maintain and publish the audit date and result.
Section Performance audit Section The operations of a certification service provider shall be audited a least once a year to evaluate its compliance with this Act . The audit shall be carried out by an internationally recognised computer security professional or a certified public accountant having expertise in the relevant field. The qualifications of the auditors and the procedure for an audit shall be as may be prescribed by regulations made under this Act . The Controller shall maintain and publish , the date and result of the audit in the certification service provider disclosure record he or she maintains for the certification service provider concerned. - 39 Verify source ↗
Public key infrastructure (PKI) - Activities of certification service providers
Certification service providers must only perform activities that are specified in their licence and must carry out activities in accordance with the Act and any regulations made under it.
Section Activities of certification service providers Section A certification service provider shall only carry on such activities as may be specified in its license. A certification service provider shall carry on its activities in accordance with this Act and any regulations made under this Act . - 40 Verify source ↗
Public key infrastructure (PKI) - Requirement to display license
A certification service provider must at all times display its license in a conspicuous place at its place of business and on its website.
Section Requirement to display license Section A certification service provider shall at all times display its license in a conspicuous place at its place of business and on its website. - 41 Verify source ↗
Public key infrastructure (PKI) - Requirement to submit information on business operations
Licensed certification service providers must submit to the Controller information and particulars about their entire business operations, including financial statements, audited balance sheets and profit and loss accounts, within a time the Controller may determine; contravention is an offence punishable by fines or imprisonment and a daily fine for continuing offences.
Section Requirement to submit information on business operations Section A licensed certification service provider shall submit to the Controller such information and particulars including financial statements, audited balance sheets and profit and loss accounts relating to its entire business operations as may be required by the Controller within the time he or she may determine. A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding twenty four currency points or imprisonment not exceeding one year or both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding two currency points for each day the offence continues. - 42 Verify source ↗
Public key infrastructure (PKI) - Notification of change of information
Certification service providers must inform the Controller in writing before certain amendments or director/CEO changes, and licensed providers must immediately notify the Controller of amendments or alterations to information or documents previously furnished with the licence.
Section Notification of change of information Section A certification service provider shall, before making an amendment or alteration to any of its constituent documents or before any change in its director or chief executive officer, furnish the Controller particulars in writing of any proposed amendment, alteration or change. A licensed certification service provider shall immediately notify the Controller of any amendment or alteration to any information or document which has been furnished to the Controller in connection with the licence. - 43 Verify source ↗
Public key infrastructure (PKI) - Use of trustworthy systems
Section Use of trustworthy systems Section A certification service provider shall only use a trustworthy system — to issue, suspend or revoke a certificate ; to publish or give notice of the issuance, suspension or revocation of a
Section Use of trustworthy systems Section A certification service provider shall only use a trustworthy system — to issue, suspend or revoke a certificate ; to publish or give notice of the issuance, suspension or revocation of a certificate ; and to create a private key , whether for itself or for a subscriber . A subscriber shall only use a trustworthy system to create a private key . - 44 Verify source ↗
Public key infrastructure (PKI) - Disclosures on inquiry
A certification service provider must disclose material certification practice statements and any facts affecting a certificate's reliability or the provider's ability to perform, when an inquiry is made under this Act.
Section Disclosures on inquiry Section A certification service provider shall, on an inquiry being made to it under this Act , disclose any material certification practice statement and any fact material to either the reliability of a certificate , which it has issued or its ability to perform its services. A certification service provider may require a signed , written and reasonably specific inquiry from an identified person and payment of the prescribed fee, as conditions precedent to effecting a disclosure required under subsection (1). - 45 Verify source ↗
Public key infrastructure (PKI) - Prerequisites to issue of certificate to subscriber
A certification service provider may issue a certificate to a subscriber if specified conditions are met; those requirements cannot be waived or disclaimed by the provider or the subscriber.
Section Prerequisites to issue of certificate to subscriber Section A certification service provider may issue a certificate to a subscriber where the following conditions are satisfied— the certification service provider has confirmed that— the certification service provider has received a request for issuance signed by the prospective subscriber ; and the prospective subscriber is the person to be listed in the certificate to be issued; if the prospective subscriber is acting through one or more agents, the subscriber has duly authorised the agent or agents to have custody of the subscriber ’s private key and to request issuance of a certificate listing the corresponding public key ; the information in the certificate to be issued is accurate; the prospective subscriber rightfully holds the private key corresponding to the public key to be listed in the certificate ; the prospective subscriber holds a private key capable of creating a digital signature ; and the public key to be listed in the certificate can be used to verify a digital signature affixed by the private key held by the prospective subscriber . The requirements of subsection (1) shall not be waived or disclaimed by the certification service provider , the subscriber or both. - 46 Verify source ↗
Public key infrastructure (PKI) - Publication of issued and accepted certificate
If a subscriber accepts an issued certificate, the certification service provider must publish a signed copy in a recognised repository unless a contract provides otherwise; if the subscriber does not accept it, the provider must not publish and must cancel publication if already published.
Section Publication of issued and accepted certificate Section Where the subscriber accepts the issued certificate , the certification service provider shall publish a signed copy of the certificate in a recognised repository , as the certification service provider and the subscriber named in the certificate may agree, unless a contract between the certification service provider and the subscriber provides otherwise. Where the subscriber does not accept the certificate , a certification service provider shall not publish it or shall cancel its publication if the certificate has already been published. - 47 Verify source ↗
Public key infrastructure (PKI) - Adoption of more rigorous requirements permitted
A certification service provider may conform to standards or contractual requirements that are more rigorous than this Act so long as they remain consistent with the Act.
Section Adoption of more rigorous requirements permitted Section Nothing in sections 31 and 32 shall preclude a certification service provider from conforming to standards, certification practice statements, security plans or contractual requirements more rigorous than, but nevertheless consistent with, this Act . - 48 Verify source ↗
Public key infrastructure (PKI) - Suspension or revocation of certificate for faulty issuance
If a certification service provider finds a certificate was issued not in accordance with sections 31 and 32 it must immediately revoke it; it may suspend a certificate for up to forty-eight hours for investigation; and it must immediately notify the subscriber of any revocation or suspension.
Section Suspension or revocation of certificate for faulty issuance Section Where after issuing a certificate a certification service provider confirms that it was not issued in accordance with sections 31 and 32 , the certification service provider shall immediately revoke it. A certification service provider may suspend a certificate which it has issued for a reasonable period not exceeding forty-eight hours as may be necessary for an investigation to be carried out to confirm the grounds for a revocation under subsection (1). The certification service provider shall immediately notify the subscriber of a revocation or suspension under this section. - 49 Verify source ↗
Public key infrastructure (PKI) - Suspension or revocation of certificate by order
The Controller may order suspension or revocation of a certificate if it was issued without complying with sections 31 and 32 and poses significant risk; before making that determination the Controller must give the certification service provider and the subscriber a reasonable opportunity to be heard; in an emergency, after consultation with the Minister, the Controller may suspend a certificate for up to forty-eight hours.
Section Suspension or revocation of certificate by order Section The Controller may order the certification service provider to suspend or revoke a certificate where the Controller determines that— the certificate was issued without compliance with sections 31 and 32 ; and the non-compliance poses a significant risk to persons reasonably relying on the certificate . Before making a determination under subsection (1), the Controller shall give the licensed certification service provider and the subscriber a reasonable opportunity of being heard. Notwithstanding subsections (1) and (2), where in the opinion of the Controller there exists an emergency that requires an immediate remedy, the Controller may, after consultation with the Minister , suspend a certificate for a period not exceeding forty-eight hours. - 50 Verify source ↗
Public key infrastructure (PKI) - Warranties to subscriber
When a certification service provider issues a certificate it must warrant to the named subscriber three things: no known false information in the certificate, the certificate meets the Act's requirements, and issuance did not exceed licence limits; the provider may not disclaim or limit those warranties.
Section Warranties to subscriber Section By issuing a certificate , a certification service provider warrants to the subscriber named in the certificate that— the certificate contains no information known to the certification service provider to be false; the certificate satisfies all the requirements of this Act ; and the certification service provider has not exceeded any limits of its licence in issuing the certificate . A certification service provider shall not disclaim or limit the warranties under subsection (1). - 51 Verify source ↗
Public key infrastructure (PKI) - Continuing obligations to subscriber
A certification service provider who issues a certificate must promptly suspend or revoke it in accordance with Part IV and must notify the subscriber within a reasonable time of any known facts that significantly affect the certificate's validity or reliability.
Section Continuing obligations to subscriber Section Unless the subscriber and certification service provider otherwise agree, a certification service provider , by issuing a certificate , promises to the subscriber — to act promptly to suspend or revoke a certificate in accordance with Part IV; and to notify the subscriber within a reasonable time of any facts known to the licensed certification service provider , which significantly affect the validity or reliability of the certificate once it is issued. - 52 Verify source ↗
Public key infrastructure (PKI) - Representations upon issuance
When issuing a certificate, a certification service provider certifies that the certificate information is accurate, material information affecting reliability is included or incorporated by reference, the subscriber has accepted the certificate, and the provider has complied with applicable laws governing issuance.
Section Representations upon issuance Section By issuing a certificate , a certification service provider certifies to all who reasonably rely on the information contained in the certificate that— the information in the certificate and listed as confirmed by the licensed certification service provider is accurate; all information foreseeable and material to the reliability of the certificate is stated or incorporated by reference within the certificate ; the subscriber has accepted the certificate ; and the certification service provider has complied with all applicable laws governing the issue of the certificate . - 53 Verify source ↗
Public key infrastructure (PKI) - Representations upon publication
When a certification service provider publishes a certificate, it certifies to the repository and to those who reasonably rely on the certificate that the licensed provider issued the certificate to the subscriber.
Section Representations upon publication Section By publishing a certificate , a certification service provider certifies to the repository in which the certificate is published and to all who reasonably rely on the information contained in the certificate that the licensed certification service provider has issued the certificate to the subscriber . - 54 Verify source ↗
Public key infrastructure (PKI) - Implied representations by subscriber
The subscriber named in a certificate must certify that they hold the corresponding private key and that specified material representations are true.
Section Implied representations by subscriber Section By accepting a certificate issued by a certification service provider , the subscriber listed in the certificate certifies to all who reasonably rely on the information contained in the certificate that— the subscriber rightfully holds the private key corresponding to the public key listed in the certificate ; all representations made by the subscriber to the certification service provider and material to information listed in the certificate are true; and all material representations made by the subscriber to a certification service provider or made in the certificate and not confirmed by the certification service provider in issuing the certificate are true. - 55 Verify source ↗
Public key infrastructure (PKI) - Representations by agent of subscriber
A person requesting a certificate on behalf of a principal must certify they have authority to apply for the certificate and to sign digitally for the principal; if their signing authority is limited they must ensure safeguards to prevent signatures beyond their authority.
Section Representations by agent of subscriber Section By requesting on behalf of a principal the issue of a certificate naming the principal as subscriber , the requesting person certifies in that person 's own right to all who reasonably rely on the information contained in the certificate that the requesting person — holds all authority legally required to apply for issuance of a certificate naming the principal as subscriber ; and has authority to sign digitally on behalf of the principal, and, if that authority is limited in any way, adequate safeguards exist to prevent a digital signature exceeding the bounds of the person ’s authority. - 56 Verify source ↗
Public key infrastructure (PKI) - Disclaimer or indemnity limited
A person must not disclaim or contractually limit this part or obtain indemnity for its effects when that disclaimer, limitation or indemnity would restrict liability for misrepresentation against persons reasonably relying on the certificate.
Section Disclaimer or indemnity limited Section A person shall not disclaim or contractually limit the application of this part, nor obtain indemnity for its effects, if the disclaimer, limitation or indemnity restricts liability for misrepresentation as against persons reasonably relying on the certificate . - 57 Verify source ↗
Public key infrastructure (PKI) - Indemnification of certification service provider by subscriber
By accepting a certificate, a subscriber must indemnify the issuing licensed certification service provider for loss or damage caused by issuance or publication of the certificate when the subscriber made a false material representation or failed to disclose a material fact with intent to deceive or through negligence; agents who requested the certificate undertake the same indemnity; the indemnity cannot be disclaimed or contractually limited.
Section Indemnification of certification service provider by subscriber Section By accepting a certificate , a subscriber undertakes to indemnify the issuing licensed certification service provider for any loss or damage caused by issue or publication of the certificate in reliance on— a false and material representation of fact by the subscriber ; or the failure by the subscriber to disclose a material fact, if the representation or failure to disclose was made either with intent to deceive the certification service provider or a person relying on the certificate or with negligence. Where the certification service provider issued the certificate at the request of one or more agents of the subscriber , the agent or agents personally undertake to indemnify the certification service provider under this section, as if they were accepting subscribers in their own right. The indemnity provided in this section shall not be disclaimed or contractually limited in scope. - 58 Verify source ↗
Public key infrastructure (PKI) - Certification of accuracy of information given
A certification service provider may require a subscriber to swear or affirm that material information given for issuing a certificate is accurate.
Section Certification of accuracy of information given Section When obtaining information from a subscriber which is material to the issue of a certificate , the certification service provider may require the subscriber to certify the accuracy of the relevant information under oath or affirmation. - 59 Verify source ↗
Public key infrastructure (PKI) - Duty of subscriber to keep private key secure
A subscriber named in a certificate must take reasonable care to keep their private key under their control and prevent its disclosure to anyone not authorised to create the subscriber’s digital signature.
Section Duty of subscriber to keep private key secure Section By accepting a certificate issued by a certification service provider , the subscriber named in the certificate assumes a duty to exercise reasonable care to retain control of the private key and prevent its disclosure to any person not authorised to create the subscriber ’s digital signature . - 60 Verify source ↗
Public key infrastructure (PKI) - Property in private key
A private key is the personal property of the subscriber who rightfully holds it.
Section Property in private key Section A private key is the personal property of the subscriber who rightfully holds it. - 61 Verify source ↗
Public key infrastructure (PKI) - Fiduciary duty of a certification service provider
A certification service provider that holds a subscriber's private key must hold it as a fiduciary of the named subscriber and may use it only with the subscriber's prior written approval, except where the subscriber expressly grants the private key and permits other terms in writing.
Section Fiduciary duty of a certification service provider Section Where a certification service provider holds the private key corresponding to a public key listed in a certificate which it has issued, the certification service provider shall hold the private key as a fiduciary of the subscriber named in the certificate and may use that private key only with the subscriber ’s prior written approval, unless the subscriber expressly and in writing grants the private key to the licensed certification service provider and expressly and in writing permits the licensed certification service provider to hold the private key according to other terms. - 62 Verify source ↗
Public key infrastructure (PKI) - Suspension of certificate by certification service provider
A licensed certification service provider must suspend a non-transactional certificate for up to forty-eight hours on request by the subscriber (or a person likely to know of key compromise) or by order of the Controller, unless the provider and subscriber agree otherwise; the provider must verify the requester’s identity or agency.
Section Suspension of certificate by certification service provider Section Unless the certification service provider and the subscriber agree otherwise, the licensed certification service provider , which issued a certificate , which is not a transactional certificate , shall suspend the certificate for a period not exceeding forty-eight hours— upon request by a person identifying himself as the subscriber named in the certificate or as a person in a position likely to know of a compromise of the security of a subscriber ’s private key , such as an agent, business associate, employee or member of the immediate family of the subscriber ; or by order of the Controller under section 35 . The certification service provider shall take reasonable measures to check the identity or agency of the person requesting suspension. - 63 Verify source ↗
Public key infrastructure (PKI) - Suspension of certificate by Controller
The Controller may suspend a non-transactional certificate for forty-eight hours when a person identifying the subscriber requests suspension and represents that the issuer is unavailable; the Controller may require evidence and may decline to suspend.
Section Suspension of certificate by Controller Section Unless the certificate provides otherwise or the certificate is a transactional certificate , the Controller may suspend a certificate issued by a certification service provider for a period of forty-eight hours, if— a person identifying himself or herself as the subscriber named in the certificate or as an agent, business associate, employee or member of the immediate family of the subscriber requests suspension; and the requester represents that the certification service provider , which issued the certificate , is unavailable. The Controller may require the person requesting suspension to provide evidence, including a statement under oath or affirmation regarding his or her identity and authorisation and the unavailability of the issuing licensed certification service provider and may decline to suspend the certificate in his or her discretion. The Controller or other law enforcement agency may investigate suspensions by the Controller for possible wrongdoing by persons requesting suspension. - 64 Verify source ↗
Public key infrastructure (PKI) - Notice of suspension
When a certificate is suspended the certification service provider must publish a signed notice of suspension in the repository specified in the certificate (in all specified repositories if more than one); if a specified repository no longer exists or refuses publication or none is recognised under section 69, the certification service provider must also publish in a recognised repository. If the Controller suspends a certificate, the Controller must give the same notice where the requester pays any prescribed repository fee in advance.
Section Notice of suspension Section Upon suspension of a certificate by a certification service provider , the certification service provider shall publish a signed notice of the suspension in the repository specified in the certificate for publication of notice of suspension. Where one or more repositories are specified, the certification service provider shall publish signed notices of the suspension in all those repositories. Where any repository specified no longer exists or refuses to accept publication or if no such repository is recognised under section 69 the certification service provider shall also publish the notice in a recognised repository . Where a certificate is suspended by the Controller , the Controller shall give notice as required in this section for a certification service provider if the person requesting suspension pays in advance any prescribed fee required by a repository for publication of the notice of suspension. - 65 Verify source ↗
Public key infrastructure (PKI) - Termination of suspension initiated by request
A certification service provider must terminate a suspension initiated by request when the subscriber requests termination and the provider has confirmed the requester is the subscriber or an authorised agent, or when the provider discovers the suspension request was unauthorised by the subscriber.
Section Termination of suspension initiated by request Section A certification service provider shall terminate a suspension initiated by request— where the subscriber named in the suspended certificate requests termination of the suspension, only if the certification service provider has confirmed that the person requesting suspension is the subscriber or an agent of the subscriber authorised to terminate the suspension; or where the licensed certification service provider discovers and confirms that the request for the suspension was made without authorisation by the subscriber . - 66 Verify source ↗
Public key infrastructure (PKI) - Alternate contractual procedures
A contract between a subscriber and a licensed certification service provider may limit or prevent requested suspension by the certification service provider or may provide for termination of such suspension; limits that preclude Controller suspension when the issuing provider is unavailable are effective only if notice is published in the certificate.
Section Alternate contractual procedures Section The contract between a subscriber and a licensed certification service provider may limit or preclude requested suspension by the certification service provider or may provide otherwise for termination of a requested suspension. Where the contract limits or precludes suspension by the Controller when the issuing licensed certification service provider is unavailable, the limitation or preclusion shall be effective only if notice of it is published in the certificate . - 67 Verify source ↗
Public key infrastructure (PKI) - Effect of suspension of certificate
A subscriber remains obligated to keep their private key secure while a certificate is suspended and is not released from the duty under section 47.
Section Effect of suspension of certificate Section Nothing in this Part shall release the subscriber from the duty under section 47 to keep the private key secure while a certificate is suspended. - 68 Verify source ↗
Public key infrastructure (PKI) - Revocation on request
A licensed certification service provider must revoke non-transactional certificates when the named subscriber requests revocation and the requester’s identity (or agent authority) is confirmed, and must confirm and revoke within one business day after receiving a written request plus identity-confirming evidence.
Section Revocation on request Section A licensed certification service provider shall revoke a certificate , which it issued but which is not a transactional certificate — upon receiving a request for revocation by the subscriber named in the certificate ; and upon confirming that the person requesting revocation is that subscriber or is an agent of that subscriber with authority to request the revocation. A certification service provider shall confirm a request for revocation and revoke a certificate within one business day after receiving both a subscriber ’s written request and evidence reasonably sufficient to confirm the identity of the person requesting the revocation or of the agent. - 69 Verify source ↗
Public key infrastructure (PKI) - Revocation on subscriber’s demise
A licensed certification service provider must revoke a certificate it issued when it receives a certified copy of the subscriber's death certificate, confirms the subscriber is dead by other evidence, receives documents effecting dissolution of the subscriber, or confirms the subscriber has been dissolved or ceased to exist.
Section Revocation on subscriber’s demise Section A licensed certification service provider shall revoke a certificate which it issued— upon receiving a certified copy of the subscriber ’s death certificate or upon confirming by other evidence that the subscriber is dead; or upon presentation of documents effecting a dissolution of the subscriber or upon confirming by other evidence that the subscriber has been dissolved or has ceased to exist. - 70 Verify source ↗
Public key infrastructure (PKI) - Revocation of unreliable certificates
A licensed certification service provider may revoke certificates it issued if those certificates are or become unreliable; the subscriber may still sue for damages if revocation is wrongful.
Section Revocation of unreliable certificates Section A licensed certification service provider may revoke one or more certificates, which it issued if the certificates are or become unreliable regardless of whether the subscriber consents to the revocation and notwithstanding any provision to the contrary in a contract between the subscriber and the licensed certification service provider . Nothing in subsection (1) shall prevent the subscriber from seeking damages or other relief against the licensed certification service provider in the event of wrongful revocation. - 71 Verify source ↗
Public key infrastructure (PKI) - Notice of revocation
When a licensed certification service provider revokes a certificate it must publish a signed notice of revocation in the repository(s) specified in the certificate; if those repositories do not exist or refuse publication (or none is recognised under section 69) it must publish in a recognised repository.
Section Notice of revocation Section Upon revocation of a certificate by a licensed certification service provider , the licensed certification service provider shall publish a signed notice of the revocation in the repository specified in the certificate for publication of notice of revocation. Where one or more repositories are specified, the licensed certification service provider shall publish signed notices of the revocation in all such repositories. Where any repository specified no longer exists or refuses to accept publication or if no such repository is recognised under section 69 , the licensed certification service provider shall also publish the notice in a recognised repository . - 72 Verify source ↗
Public key infrastructure (PKI) - Effect of revocation request on subscriber
A subscriber stops certifying and is no longer required to keep the private key secure once revocation is either (a) published as required under section 71, or (b) forty eight hours have lapsed after a written revocation request accompanied by information to confirm the request and payment of any prescribed fee, whichever occurs first.
Section Effect of revocation request on subscriber Section Where a subscriber has requested for the revocation of a certificate , the subscriber ceases to certify as provided in Part IV and has no further duty to keep the private key secure as required under section 59 — when notice of the revocation is published as required under section 71 ; or where forty eight hours have lapsed after the subscriber requests for the revocation in writing , supplies to the issuing licensed certification service provider information reasonably sufficient to confirm the request and pays any prescribed fee, whichever occurs first. - 73 Verify source ↗
Public key infrastructure (PKI) - Effect of notification on certification service provider
After notification under section 71, a certification service provider is discharged of warranties for the revoked certificate and must cease certifying that revoked certificate.
Section Effect of notification on certification service provider Section Upon notification as required under section 71 , a certification service provider shall be discharged of its warranties based on issue of the revoked certificate and ceases to certify as provided in sections 22 and 24 in relation to the revoked certificate . - 74 Verify source ↗
Public key infrastructure (PKI) - Expiration of certificate
When a certificate expires, the subscriber and the licensed certification service provider must stop certifying; the licensed certification service provider will be discharged of duties arising from that expired certificate.
Section Expiration of certificate Section The date of expiry of a certificate shall be specified in the certificate . A certificate may be issued for a period not exceeding three years from the date of issue. When a certificate expires, the subscriber and licensed certification service provider shall cease to certify as provided under this Act and the licensed certification service provider shall be discharged of its duties based on issue in relation to the expired certificate . The expiry of a certificate shall not affect the duties and obligations of the subscriber and licensed certification service provider incurred under and in relation to the expired certificate . - 75 Verify source ↗
Public key infrastructure (PKI) - Reliance limit
A licensed certification service provider must specify a recommended reliance limit in the certificate when issuing a certificate to a subscriber.
Section Reliance limit Section A licensed certification service provider shall, when issuing a certificate to a subscriber , specify a recommended reliance limit in the certificate . The licensed certification service provider may specify different limits in different certificates as it considers fit. - 76 Verify source ↗
Public key infrastructure (PKI) - Liability limits for certification service providers
A licensed certification service provider is not liable beyond the amount specified in the certificate as its recommended reliance limit, subject to the section and any waiver by the provider.
Section Liability limits for certification service providers Section Unless a licensed certification service provider waives the application of this section, a licensed certification service provider — shall not be liable in excess of the amount specified in the certificate as its recommended reliance limit for either— shall not be liable for any loss caused by reliance on a false or forged digital signature of a subscriber , if, with respect to the false or forged digital signature , the licensed certification service provider complied with the requirements of this Act ; a loss caused by reliance on a misrepresentation in the certificate of any fact that the licensed certification service provider is required to confirm ; or failure to comply with sections 31 and 32 when issuing the certificate . - 77 Verify source ↗
Public key infrastructure (PKI) - Recognition of repositories
The Controller may recognise repositories after confirming they meet regulatory requirements, and must publish a list of recognised repositories in a form and manner he or she determines.
Section Recognition of repositories Section The Controller may recognise one or more repositories, after determining that a repository to be recognised satisfies the requirements prescribed in the regulations made under this Act . The procedure for recognition of repositories shall be as prescribed by regulations made under this Act . The Controller shall publish a list of recognised repositories in such form and manner as he or she may determine. - 78 Verify source ↗
Public key infrastructure (PKI) - Liability of repositories
Recognised repositories (including owners or operators) are liable for loss when a person reasonably relies on an electronic signature verified by a public key listed in a suspended or revoked certificate if the loss occurred more than one business day after the repository received a request to publish notice of suspension/revocation and the repository failed to publish the notice; several specified limits and non-liabilities apply.
Section Liability of repositories Section Unless waived, a recognised repository or the owner or operator of a recognised repository — Notwithstanding any disclaimer by the repository or a contract to the contrary between the repository and a licensed certification service provider or a subscriber , a repository shall be liable for a loss incurred by a person reasonably relying on an electronic signature verified by the public key listed in a suspended or revoked certificate , if loss was incurred more than one business day after receipt by the repository of a request to publish notice of the suspension or revocation and the repository had failed to publish the notice when the person relied on the digital signature . shall not be liable for failure to record publication of a suspension or revocation, unless the repository has received notice of publication and one business day has elapsed since the notice was received; shall not be liable under subsection (1) in excess of the amount specified in the certificate as the recommended reliance limit ; shall not be liable for misrepresentation in a certificate published by a certification service provider ; shall not be liable for accurately recording or reporting information which a licensed certification service provider , a court or the Controller has published as required or permitted under this Act , including information about the suspension or revocation of a certificate ; and shall not be liable for reporting information about a certification service provider , a certificate or a subscriber , if the information is published as required or permitted under this Act or is published by order of the Controller in the performance of his or her licensing and regulatory duties under this Act . - 79 Verify source ↗
Public key infrastructure (PKI) - Recognition of date or time stamp services
The Controller may recognise date or time stamp services (subject to regulatory requirements) and shall publish a list of recognised services.
Section Recognition of date or time stamp services Section The Controller may recognise one or more date or time stamp services, after determining that a service to be recognised satisfies the requirements prescribed in the regulations made under this Act . The procedure for recognising of date or time stamp services shall be as may be prescribed by regulations made under this Act . The Controller shall publish a list of recognised date or time stamp services in a form and manner as he may determine.
Part V
Miscellaneous
- 100 Verify source ↗
Miscellaneous - Savings and transitional provisions
Certification service providers already operating before commencement must obtain a licence within three months from commencement; failure means they are treated as unlicensed and the Act's provisions apply to them.
Section Savings and transitional provisions Section A certification service provider that has been carrying on or operating as a certification service provider before the commencement of this Act shall, not later than three months from the commencement, obtain a licence under this Act . Where a certification service provider referred to in subsection (1) fails to obtain a licence after the period prescribed in subsection (1), it shall be taken to be an unlicensed certification service provider and the provisions of this Act shall apply to it and a certificate issued by it accordingly. Where a certification service provider referred to in subsection (1) has obtained a licence in accordance with this Act within the period prescribed in subsection (1), all certificates issued by that certification service provider before the commencement of this Act , to the extent that they are not inconsistent with this Act , shall be taken to have been issued under this Act and shall have effect accordingly. - 80 Verify source ↗
Miscellaneous - Prohibition against dangerous activities
Certification service providers must not run their business in a way that creates unreasonable risk of loss to subscribers, relying persons, or repositories; the Controller may publish advisories, the named provider may protest, and the Controller must publish decisions and may revoke, continue, amend or take further legal action after hearings.
Section Prohibition against dangerous activities Section A certification service provider , whether licensed or not, shall not conduct its business in a manner that creates an unreasonable risk of loss to the subscribers of the certification service provider , to persons relying on certificates issued by the certification service provider or to a repository . The Controller may publish in one or more recognised repositories brief statements advising subscribers, persons relying on digital signatures and repositories about any activities of a certification service provider , whether licensed or not, which create a risk prohibited under subsection (1). The certification service provider named in a statement as creating or causing a risk may protest the publication of the statement by filing a brief written defence. On receipt of a protest made under subsection (3), the Controller shall publish a written defence together with the Controller ’s statement and shall immediately give the protesting certification service provider notice and a reasonable opportunity of being heard. Where, after a hearing, the Controller determines that the publication of the advisory statement was unwarranted, the Controller shall revoke the advisory statement. Where, after a hearing, the Controller determines that the advisory statement is no longer warranted, the Controller shall revoke the advisory statement. Where, after a hearing, the Controller determines that the advisory statement remains warranted, the Controller may continue or amend the advisory statement and may take further legal action to eliminate or reduce the risk prohibited under subsection (1). The Controller shall publish his decision under subsection (5), (6) or (7), as the case may be, in one or more recognised repositories. - 81 Verify source ↗
Miscellaneous - Obligation of confidentiality
Persons with powers under this Act must not access or grant access to electronic records or other material except for the purposes of the Act or prosecutions; contravention is an offence with fines or imprisonment.
Section Obligation of confidentiality Section Except for the purpose of this Act or for any prosecution for an offence under any written law or under an order of court, a person under any powers conferred under this Act , shall not obtain access to any electronic record, book, register, correspondence, information, document, other material or grant access to any other person . A person who contravenes subsection (1) commits an offence and is liable, on conviction, to a fine not exceeding one hundred twenty currency points or imprisonment for a term not exceeding five years or both. - 82 Verify source ↗
Miscellaneous - False information
Making or supplying, knowingly, any declaration, return, certificate or other required document or information that is false or misleading is prohibited and is an offence punishable by a fine not exceeding one hundred and twenty currency points or imprisonment for a term not exceeding five years or both.
Section False information Section A person who knowingly makes, orally or in writing , signs or furnishes any declaration, return, certificate or other document or information required under this Act which is false or misleading in any particular way commits an offence and is liable, on conviction, to a fine not exceeding one hundred and twenty currency points or imprisonment for a term not exceeding five years or both. - 83 Verify source ↗
Miscellaneous - Offences by body corporate
Directors, managers and similar officers are deemed to have committed an offence if the body corporate is convicted unless they can prove lack of knowledge and due diligence; persons liable are also liable for acts of employees or agents, and such persons may be charged jointly or severally with the body corporate.
Section Offences by body corporate Section Where a body corporate commits an offence under this Act , a person who at the time of the commission of the offence is a director, manager, secretary or other similar officer of the body corporate or was purporting to act in that capacity or was in any manner or to any extent responsible for the management of any of the affairs of the body corporate or was assisting in such management— where the body corporate is convicted of the offence, such a person shall be deemed to have committed an offence unless, having regard to the nature of his functions in that capacity and to all circumstances, he proves— Where a person is liable under this Act to a punishment or penalty for any act, omission, neglect or default, he or she is liable to the same punishment or penalty for every such act, omission, neglect or default of any employee or agent of his or of the employee of such agent, if the act, omission, neglect or default was committed— may be charged severally or jointly in the same proceedings with the body corporate; and that the offence was committed without his knowledge, consent or connivance; and that he took all reasonable precautions and had exercised due diligence to prevent the commission of the offence. by his employee in the course of his employment; by the agent when acting on his behalf; or by the employee of such agent in the course of his employment by such agent or otherwise on behalf of the agent. - 84 Verify source ↗
Miscellaneous - Authorised officer
An authorised officer may exercise enforcement powers under this Act.
Section Authorised officer Section An authorised officer may exercise the powers of enforcement under this Act . - 85 Verify source ↗
Miscellaneous - Power to investigate
The Controller may investigate certification service providers and may issue orders to them; authorised officers investigating offences may exercise police investigation powers under the Criminal Procedure Code.
Section Power to investigate Section The Controller may investigate the activities of a certification service provider material to its compliance with this Act . For the purposes of subsection (1), the Controller may issue orders to a certification service provider to further its investigation and secure compliance with this Act . Further, in any case relating to the commission of an offence under this Act , any authorised officer carrying on an investigation may exercise all or any of the special powers in relation to police investigation in all cases given by the Criminal Procedure Code. - 86 Verify source ↗
Miscellaneous - Search by warrant
A Magistrate may issue a warrant on written information on oath and reasonable cause; that warrant authorises inspectors or named authorised officers to enter, search and seize relevant items; officers may search persons and seize items; seizing officers must seal items that cannot practicably be removed; breaking or removing seals without authority is an offence.
Section Search by warrant Section If it appears to a Magistrate, upon written information on oath and after such inquiry as he or she considers necessary, that there is reasonable cause to believe that an offence under this Act is being or has been committed on any premises, the Magistrate may issue a warrant authorising any police officer not below the rank of Inspector or any authorised officer named in the warrant, to enter the premises at any reasonable time by day or by night, with or without assistance and if need be by force, to search for and seize— copies of any books, accounts or other documents, including computerized data, which contain or are reasonably suspected to contain information as to any offence so suspected to have been committed; any signboard, card, letter, pamphlet, leaflet, notice or other device representing or implying that the person is a licensed certification service provider ; and any other document, article or item that is reasonably believed to furnish evidence of the commission of that offence. A police officer or an authorised officer conducting a search under subsection (1) may, if in his or her opinion it is reasonably necessary to do so for the purpose of investigating into the offence, search any person who is in or on those premises. A police officer or an authorised officer making a search of a person under subsection (2) may seize, detain or take possession of any book, accounts, document, computerised data, card, letter, pamphlet, leaflet, notice, device, article or item found on that person for the purpose of the investigation being carried out by that officer. A female person shall not be searched under this section except by another female person . Where, by reason of its nature, size or amount, it is not practicable to remove any book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item seized under this section, the seizing officer shall, by any means, seal that book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item in the premises or container in which it is found. A person who, without lawful authority, breaks, tampers with or damages the seal referred to in subsection (5) or removes any book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item under seal or attempts to do so commits an offence. - 87 Verify source ↗
Miscellaneous - Search and seizure without warrant
A police officer of at least Inspector rank may, without a warrant, enter premises and use the powers in section 86 if there is reasonable cause to believe delay would harm the investigation or that evidence might be tampered with, removed, damaged or destroyed.
Section Search and seizure without warrant Section If a police officer not below the rank of Inspector in any of the circumstances referred to in section 86 has reasonable cause to believe that by reason of delay in obtaining a search warrant under that section the investigation would be adversely affected or evidence of the commission of an offence is likely to be tampered with, removed, damaged or destroyed, that officer may enter the premises and exercise in, upon and in respect of the premises all the powers referred to in section 86 in as full and ample a manner as if he or she were authorised to do so by a warrant issued under that section. - 88 Verify source ↗
Miscellaneous - Access to computerised data
Police officers conducting searches under sections 86 or 87 are entitled to unlimited access to computerised data.
Section Access to computerised data Section A police officer conducting a search under section 86 or 87 shall be given unlimited access to computerised data whether stored in a computer or otherwise. For the purposes of this section, "access" includes being provided with the necessary password, encryption code, decryption code, software or hardware and any other means required to enable comprehension of computerised data. - 89 Verify source ↗
Miscellaneous - List of things seized
Seizing officers must prepare a list of seized items and immediately give a signed copy to the occupier (or their agent/servant) at the premises; if premises are unoccupied, the officer must post the list conspicuously and leave a copy with local authorities.
Section List of things seized Section Except as provided in subsection (2), where any book, accounts, document, computerised data, signboard, card, letter, pamphlet, leaflet, notice, device, article or item is seized under section 86 or 87 , the seizing officer shall prepare a list of the things seized and immediately deliver a copy of the list signed by him or her to the occupier of the premises which have been searched or to his or her agent or servant, at those premises. Where the premises are unoccupied, the seizing officer shall post a list of things seized conspicuously on the premises and leave a copy with the local authorities. - 90 Verify source ↗
Miscellaneous - Obstruction of authorised officer
It is an offence for a person to obstruct, impede, assault or interfere with an authorised officer performing his functions under this Act.
Section Obstruction of authorised officer Section A person who obstructs, impedes, assaults or interferes in any way with any authorised officer in the performance of his functions under this Act commits an offence. - 91 Verify source ↗
Miscellaneous - Additional powers
An authorised officer may require production and inspection of documents and identification and may make inquiries for executing the Act.
Section Additional powers Section An authorised officer may, for the purposes of the execution of this Act , to do all or any of the following— require the production of records, accounts, computerised data and documents kept by a licensed certification service provider and to inspect, examine and copy any of them; require the production of any identification document from a person in relation to any case or offence under this Act ; make such inquiry as may be necessary to ascertain whether the provisions of this Act have been complied with. - 92 Verify source ↗
Miscellaneous - General penalty
A person who commits an offence under this Act for which no penalty is provided is liable on conviction to a fine not exceeding seventy two currency points or to imprisonment for up to three years or both; for continuing offences an additional daily fine not exceeding two currency points applies.
Section General penalty Section A person who commits an offence under this Act for which no penalty is expressly provided is liable, on conviction, to a fine not exceeding seventy two currency points or to imprisonment for a term not exceeding three years or both and in the case of a continuing offence shall in addition be liable to a daily fine not exceeding two currency points for each day the offence continues. For the purposes of this section, " this Act " does not include the regulations made under this Act . - 93 Verify source ↗
Miscellaneous - Institution and conduct of prosecution
An officer of the Controller authorised in writing by the Director of Public Prosecutions may conduct prosecutions for offences under the Act.
Section Institution and conduct of prosecution Section A prosecution under this Act shall not be instituted except by or with the consent of the Director of Public Prosecution, but a person charged with such an offence may be arrested or a warrant for his or her arrest issued and executed and the person may be detained or released on police bond, not withstanding that the consent of the Director of Public Prosecution to the institution of a prosecution for the offence has not yet been obtained, but no further or other proceedings shall be taken until that consent has been obtained. An officer of the Controller duly authorised in writing by the Director of Public Prosecutions may conduct the prosecution for any offence under this Act . - 94 Verify source ↗
Miscellaneous - Jurisdiction to try offences
A Magistrate Grade I shall have jurisdiction to try offences under this Act and to impose the full punishment for those offences, notwithstanding any written law to the contrary.
Section Jurisdiction to try offences Section Notwithstanding any written law to the contrary, a Magistrate Grade I shall have jurisdiction to try an offence under this Act and to impose the full punishment for the offence. - 95 Verify source ↗
Miscellaneous - Protection of officers
The Controller and any officer duly authorised under this Act are protected from being the subject of actions or prosecutions in court for acts ordered or done to carry the Act into effect.
Section Protection of officers Section An action or prosecution shall not be brought, instituted or maintained in a court against the Controller or any officer duly authorised under this Act for or on account of or in respect of any act ordered or done for the purpose of carrying into effect this Act . - 96 Verify source ↗
Miscellaneous - Limitation on disclaiming or limiting application of Act
A person must not disclaim or contractually limit the application of the Act unless the Act expressly allows it.
Section Limitation on disclaiming or limiting application of Act Section Unless it is expressly provided for under this Act , a person shall not disclaim or contractually limit the application of this Act . - 97 Verify source ↗
Miscellaneous - Regulations
The Minister may make regulations for the purposes listed in the section, and regulations may create offences and prescribe penalties (up to a fine of seventy two currency points or three years' imprisonment or both).
Section Regulations Section The Minister may on the recommendation of the Controller make regulations for all or any of the following purposes— prescribing the qualification requirements for certification service providers; prescribing the manner of applying for licences and certificates under this Act , the particulars to be supplied by an applicant, the manner of licensing and certification, the fees payable there for, the conditions or restrictions to be imposed and the form of licences and certificates; regulating the operations of licensed certification service provider ; prescribing the requirements for the content, form and sources of information in certification service provider disclosure records, the updating and timeliness of such information and other practices and policies relating to certification service provider disclosure records; prescribing the form of certification practice statements; prescribing the qualification requirements for auditors and the procedure for audits; prescribing the requirements for repositories and the procedure for recognition of repositories; prescribing the requirements for date and time stamp services and the procedure for recognition of date and time stamp services; prescribing the procedure for the review of software for use in creating digital signatures and of the applicable standards in relation to digital signatures and certification practice and for the publication of reports on such software and standards; prescribing the forms for the purposes of this Act ; prescribing the fees and charges payable under this Act and the manner for collecting and disbursing the fees and charges; providing for such other matters as are contemplated by or necessary for giving full effect to, the provisions of this Act and for their due administration. Regulations made under subsection (1) may prescribe any act in contravention of the regulations to be an offence and may prescribe in relation to the offence, penalties not exceeding a fine of seventy two currency points or imprisonment for three years or both. - 98 Verify source ↗
Miscellaneous - Compensation
If a person is convicted under this Act, the court must order that person to pay compensation to the aggrieved party.
Section Compensation Section Where a person is convicted under this Act , the court shall in addition to the punishment provided therein, order such person to pay by way of compensation to the aggrieved party, such sum as is in the opinion of the court just, having regard to the loss suffered by the aggrieved party; and such order shall be a decree under the provisions of the Civil Procedure Act, and shall be executed in the manner provided under that Act. - 99 Verify source ↗
Miscellaneous - Power of Minister to amend the Schedule
The Minister may amend the Schedule to this Act, subject to Cabinet approval and by statutory instrument.
Section Power of Minister to amend the Schedule Section The Minister may, with the approval of Cabinet, by statutory instrument, amend the Schedule to this Act .
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
Electronic Signatures Act
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.