electronic record shall be determined as follows, namely:– (a) if the addressee has designated a computer resource for the purpose of receiving electronic records,– (i) receipt occurs at the time when the electronic record enters the designated computer resource; or (ii) if the electronic record is sent to a computer resource of the addressee that is not the designated computer resource, receipt occurs at the time when the electronic record is retrieved by the addressee; (b) if the addressee has not designated a computer resource along with specified timings, if any, receipt occurs when the electronic record enters the computer resource of the addressee. (3) Save as otherwise agreed to between the originator and the addressee, an electronic record is deemed to be despatched at the place where the originator has his place of business, and is deemed to be received at the place where the addressee has his place of business. (4) The provisions of sub-section (2) shall apply notwithstanding that the place where the computer resource is located may be different from the place where the electronic record is deemed to have been received under sub-section (3). (5) For the purposes of this section,– (a) if the originator or the addressee has more than one place of business, the principal place of business, shall be the place of business; (b) if the originator or the addressee does not have a place of business, his usual place of residence shall be deemed to be the place of business; (c) “usual place of residence”, in relation to a body corporate, means the place where it is registered. CHAPTER V SECURE ELECTRONIC RECORDS ANS SECURE 1[ELECTRONIC SIGNATURE] 14. Secure electronic record.–Where any security procedure has been applied to an electronic record at a specific point of time, then such record shall he deemed to be a secure electronic record from such point of time to the time of verification. 2 [15. Secure electronic signature.– An electronic signature shall be deemed to be a secure electronic signature if– (i) the signature creation data, at the time of affixing signature, was under the exclusive control of signatory and no other person; and (ii) the signature creation data was stored and affixed in such exclusive manner as may be prescribed. Explanation.–In case of digital signature, the “signature creation data” means the private key of the subscriber. 16. Security procedures and practices.–The Central Government may, for the purposes of sections 14 and 15, prescribe the security procedures and practices: Provided that in prescribing such security procedures and practices, the Central Government shall have regard to the commercial circumstances, nature of transactions and such other related factors as it may consider appropriate.] CHAPTER VI REGULATION OF CERTIFYING AUTHORITIES 17. Appointment of Controller and other officers.–(1) The Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities for the purposes of this Act and may also by the same or subsequent notification appoint such number of Deputy Controllers 3 [, Assistant Controllers, other officers and employees] as it deems fit. 1. Subs. by Act 10 of 2009, s. 2, for “digital signatures” (w.e.f. 27-10-2009). 2. Subs. by s 11, ibid., for sections 15 and 16 (w.e.f. 27-10-2009). 3. Subs. by s.12, ibid., for “and Assistant Controllers” (w.e.f. 27-10-2009). 12

Select target paragraph3