electronic record shall be determined as follows, namely:–
(a) if the addressee has designated a computer resource for the purpose of receiving electronic
records,–
(i) receipt occurs at the time when the electronic record enters the designated computer
resource; or
(ii) if the electronic record is sent to a computer resource of the addressee that is not the
designated computer resource, receipt occurs at the time when the electronic record is retrieved
by the addressee;
(b) if the addressee has not designated a computer resource along with specified timings, if any,
receipt occurs when the electronic record enters the computer resource of the addressee.
(3) Save as otherwise agreed to between the originator and the addressee, an electronic record is
deemed to be despatched at the place where the originator has his place of business, and is deemed to be
received at the place where the addressee has his place of business.
(4) The provisions of sub-section (2) shall apply notwithstanding that the place where the computer
resource is located may be different from the place where the electronic record is deemed to have been
received under sub-section (3).
(5) For the purposes of this section,–
(a) if the originator or the addressee has more than one place of business, the principal place of
business, shall be the place of business;
(b) if the originator or the addressee does not have a place of business, his usual place of
residence shall be deemed to be the place of business;
(c) “usual place of residence”, in relation to a body corporate, means the place where it is
registered.
CHAPTER V
SECURE ELECTRONIC RECORDS ANS SECURE 1[ELECTRONIC SIGNATURE]
14. Secure electronic record.–Where any security procedure has been applied to an electronic record
at a specific point of time, then such record shall he deemed to be a secure electronic record from such
point of time to the time of verification.
2
[15. Secure electronic signature.– An electronic signature shall be deemed to be a secure electronic
signature if–
(i) the signature creation data, at the time of affixing signature, was under the exclusive control of
signatory and no other person; and
(ii) the signature creation data was stored and affixed in such exclusive manner as may be
prescribed.
Explanation.–In case of digital signature, the “signature creation data” means the private key of the
subscriber.
16. Security procedures and practices.–The Central Government may, for the purposes of sections
14 and 15, prescribe the security procedures and practices:
Provided that in prescribing such security procedures and practices, the Central Government shall
have regard to the commercial circumstances, nature of transactions and such other related factors as it
may consider appropriate.]
CHAPTER VI
REGULATION OF CERTIFYING AUTHORITIES
17. Appointment of Controller and other officers.–(1) The Central Government may, by
notification in the Official Gazette, appoint a Controller of Certifying Authorities for the purposes of this
Act and may also by the same or subsequent notification appoint such number of Deputy Controllers
3
[, Assistant Controllers, other officers and employees] as it deems fit.
1. Subs. by Act 10 of 2009, s. 2, for “digital signatures” (w.e.f. 27-10-2009).
2. Subs. by s 11, ibid., for sections 15 and 16 (w.e.f. 27-10-2009).
3. Subs. by s.12, ibid., for “and Assistant Controllers” (w.e.f. 27-10-2009).
12