Every time you file your GST returns, upload a tender document, or e-sign a company filing with the Ministry of Corporate Affairs, a Digital Signature Certificate (DSC) is doing the quiet work of proving it’s really you. But that convenience comes with a catch: the law puts real legal weight on the person holding the certificate, called the “subscriber”. The Information Technology Act, 2000 doesn’t just protect subscribers, it also holds them accountable. Understanding these duties is essential for anyone studying e-commerce law, and even more useful if you’ll ever apply for a DSC yourself.

Table of Contents

Who exactly is a “subscriber”?

A subscriber is the person in whose name a Digital Signature Certificate is issued by a Certifying Authority (CA). Certifying Authorities are private and government entities licensed and supervised by the Controller of Certifying Authorities (CCA), a body functioning under the Ministry of Electronics and Information Technology. Once a CA verifies your identity and issues a DSC, you become the subscriber, and the certificate links your identity to a unique cryptographic key pair: a public key that others can see, and a private key that only you should ever hold.

This private key is what actually creates the digital signature on a document. The public key, listed in the certificate, is used by others to verify that the signature genuinely came from you. The entire system of trust in electronic transactions collapses if that private key falls into the wrong hands, which is exactly why Chapter VIII of the Act (Sections 40 to 42) spells out what subscribers must do to keep it safe.

The core duties spelled out in Sections 40 to 42

The Act frames a subscriber’s responsibilities around three connected ideas: generate your keys securely, protect your private key at all times, and report immediately if anything goes wrong. Each has a distinct legal basis.

Generating the key pair securely (Section 40)

Where a subscriber has accepted a Digital Signature Certificate whose listed public key was generated by the subscriber, Section 40 requires that the corresponding key pair be generated by applying the prescribed security procedure. In simple terms, you can’t cut corners on how the cryptographic keys are created. Section 40A extends similar obligations to Electronic Signature Certificates, since the Act was amended in 2008 to recognise signature technologies beyond the original digital signature scheme.

Exercising reasonable care over the private key (Section 42)

This is the heart of the subscriber’s duty. Section 42(1) of the Act requires every subscriber to exercise reasonable care to retain control of the private key corresponding to the public key listed in the certificate, and to take all steps necessary to prevent its disclosure. Think of it the way banks describe your UPI PIN or net-banking password: you’re not expected to be a cybersecurity expert, but you are expected to behave like a reasonably careful person would with something this sensitive. That could mean using encrypted USB tokens, never sharing your DSC token or its password, and keeping the physical hardware token secure the way you’d protect a chequebook.

Reporting compromise without delay

If the private key is ever compromised, whether it’s lost, stolen, or you suspect someone else has accessed it, Section 42(2) requires the subscriber to communicate this to the Certifying Authority immediately, in the manner specified by the applicable regulations. Delay isn’t a minor procedural lapse here; it has direct legal consequences, covered in the next section. In practice, the CCA’s own guidance confirms that once a certificate is compromised or no longer needed, it should be formally revoked and the keys destroyed by the subscriber, not left dormant and vulnerable.

Why the “till informed” clause matters so much

Here’s the part students often underestimate. The Explanation to Section 42(2) makes it explicit: the subscriber remains liable for any misuse of the digital signature until the Certifying Authority has been informed that the private key has been compromised. This isn’t a small technicality. It means that even if someone else misused your signature without your knowledge, you could still bear legal responsibility for transactions signed in that window, right up until you formally notify the CA.

This is why prompt reporting isn’t just good practice, it’s a legal firewall. A digital signature carries the same evidentiary weight as a handwritten signature under Indian law, and courts have consistently upheld electronic authentication as legally valid in commercial disputes, as reflected in the broader body of case law recognising digital signatures under the IT Act framework. If your signature is used to sign a contract, place an order, or authorise a payment while your key is compromised and unreported, that transaction can potentially be enforced against you.

Acceptance obligations under Section 41

Duties don’t start only after something goes wrong, they begin the moment you accept the certificate. Under Section 41, a subscriber is deemed to have accepted a Digital Signature Certificate if they publish it, authorise its publication in a repository, or otherwise demonstrate approval of it. By accepting the certificate, the subscriber is effectively certifying three things to anyone who relies on it: that they genuinely hold the private key matching the public key in the certificate, that all representations made to the Certifying Authority during the application were true, and that all information in the certificate within their knowledge is accurate.

This matters because Certifying Authorities such as those licensed by the CCA, and recognised for corporate filings by the Ministry of Corporate Affairs, issue certificates based largely on the information and documents a subscriber provides. If that information turns out to be false, the subscriber, not just the CA, bears responsibility for the misrepresentation.

A quick summary

Provision Core duty
Section 40 / 40A Secure key generation – follow the prescribed security procedure when generating key pairs
Section 41 Truthful acceptance – certify that all information given to the CA is accurate
Section 42(1) Reasonable care – protect the private key and prevent unauthorised disclosure
Section 42(2) Immediate reporting – inform the CA without delay if the key is compromised, and remain liable until you do

Why this matters for e-commerce specifically

E-commerce runs on trust between parties who often never meet. Digital signatures allow platforms, vendors, tax authorities, and banks to authenticate a person’s identity electronically, without paperwork or physical presence. That system only works if the humans behind those signatures are held to a real standard of care. Subscriber duties under the IT Act are what make it legally safe for a marketplace to accept an e-signed vendor agreement, or for a government portal to accept a digitally signed tender bid, because the law assigns clear responsibility for the security of that signature to the person who holds it.

For students of e-commerce law, this topic is a good reminder that legal frameworks don’t just regulate large platforms and corporations. They also place direct, personal obligations on individuals participating in the digital economy, whether that’s a company director e-filing MCA documents or a freelancer signing contracts online. Negligence with a private key isn’t treated as a technical mishap; it’s treated as a failure of legal duty.

What do you think? If someone’s DSC token is stolen and misused before they even realise it’s missing, should the law still hold them liable for transactions signed in that gap? And as India moves toward Aadhaar-based eSign and cloud-based signing, do you think the “reasonable care” standard needs to evolve to match these newer technologies?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.digitalindia.gov.in/di_ecosystem/controller-of-certifying-authorities-cca/
  2. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
  3. https://cca.gov.in/faq.html
  4. https://www.mondaq.com/india/contracts-and-commercial-law/1441750/law-of-digital-signatures-in-india
  5. https://www.mca.gov.in/MinistryV2/certifyingauthorities.html

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

E-Commerce

1 Introduction to E-commerce

  1. Introduction
  2. Meaning of E-Commerce
  3. E-Commerce Web Portal
  4. E-Commerce Software
  5. E-Commerce APIs
  6. M-Commerce and Multi-channel Commerce
  7. Use of Emerging Technologies in E-Commerce
  8. Why E-Commerce
  9. Evolution of E-Commerce
  10. Types of E-Commerce
  11. Advantages and Disadvantages of E-Commerce

2 E-Commerce Business Models

  1. Introduction
  2. What is a Business Model?
  3. Key Elements of a Business Model
  4. E-Commerce Business Models to Understand Target Customer
  5. E-Commerce Design Models
  6. Implementing E-Commerce Models
  7. E-Commerce Revenue Models
  8. Impact of COVID on E-Commerce

3 Technology used in E-Commerce

  1. Introduction
  2. Design Considerations of E-Commerce
  3. Essential Technology Features Required
  4. Difference between App Based and Web-Based Business
  5. Building, Designing and Launching E-Commerce Website
  6. SDLC Cycle for Designing E-Commerce Solutions
  7. Architectural Framework and Network Infrastructure
  8. Impact of Emerging Technologies on E-Commerce
  9. Digital Platforms and E-Commerce
  10. Digitalisation and Digital Transformation in Businesses

4 Electronic Governance

  1. Introduction
  2. Meaning of E-Governance
  3. Differences between E-Government and E-Governance
  4. Differences between E-Governance and E-Commerce
  5. Advantages of Employing Digital Technologies in Governance
  6. Gartnerโ€™s Evolution Model of E-Governance
  7. E-Governance in India
  8. Digital India
  9. E-Governance initiatives in India

5 E-Payment

  1. Introduction
  2. Overview of Payment System
  3. Meaning of E-Payment
  4. Difference between E-Payment & Conventional Payment
  5. Payment Gateways
  6. Steps about Functioning of a Payment Gateway
  7. Types of Payment Gateways
  8. Types of Payment Methods
  9. Requirements Metrics of a Payment System
  10. Merits of E-Payment System
  11. Risks Involved in E-Payment

6 E-Banking

  1. Introduction
  2. Concept of E-Banking
  3. Importance of E-Banking
  4. Technology used in Banking
  5. EFT (Electronic Fund Transfer)
  6. NEFT (National Electronic Fund Transfer)
  7. RTGS (Real Time Gross Settlement)
  8. IMPS (Immediate Payment Service)
  9. UPI (Unified Payments Interface)
  10. Difference between NEFT, RTGS & IMPS
  11. Virtual Currency
  12. Automated Clearing House
  13. Automated Ledger Posting
  14. Distributed Ledger Technology

7 Website Development

  1. Introduction
  2. Meaning of Website
  3. Evolution of Website
  4. Website Usage
  5. HTTP & HTTPS Protocols
  6. Types of Website
  7. Development of Website
  8. Ingredients Required for Website Development
  9. Website Hosting

8 Electronic Commerce Software

  1. Introduction
  2. E-commerce Software Platform
  3. Types of Software Platforms
  4. Shopify – An Online Store Builder
  5. E-Auction Processes the Real-Time Visibility
  6. PayPal Holdings Online Payments
  7. SAP Commerce Cloud
  8. Functions of E-Commerce Software Platforms
  9. Advanced Functions of E-Commerce Software
  10. E-Commerce Software for Small & Midsize Companies
  11. E-Commerce Software for Midsize to Large Business
  12. E-Commerce Software for Large Business
  13. Planning Electronic Commerce Initiatives
  14. Strategies for Developing E-Commerce Websites
  15. Managing E-Commerce Implementations

9 Web Server Hardware and Software

  1. Meaning of Server
  2. Web Server Essentials
  3. Different Types of Web Server
  4. Characteristics of a Web Server
  5. Functioning of a Web Server
  6. Mail Server
  7. Process of Sending E-mails
  8. Operating System
  9. Windows
  10. Linux
  11. Linux vs. Windows
  12. Web Server Hardware
  13. Hardware used in Web Servers
  14. Web Server Software
  15. Application Server Software
  16. Web Server & Application Server
  17. Web Site and Internet Utility Programs

10 Cyber Security

  1. Meaning of Cyber Security
  2. Cyber Security Impact on E-Commerce
  3. Cyber Security Relevance
  4. Information Security V/s Cyber Security
  5. Basics of Cyber World
  6. Need & Concepts behind Security
  7. IoT and Cyber World
  8. Cyber Crime and Law
  9. Security Barriers

11 Cyber Security Measures

  1. Role of Cyber Security Analysts
  2. Essential Cyber Security Measures
  3. Precautionary Cyber-Security Measures Enterprise Takes
  4. IoT and its Impact
  5. Vulnerable Information on Internet
  6. Vulnerabilities of Systems
  7. Internet Vulnerabilities
  8. Wireless Security Challenges
  9. Malicious Software
  10. Hackers and Computer Crime
  11. Cyber Crime
  12. Global Threats: Cyber terrorism and Cyber Warfare
  13. Cyber Forensic
  14. Securing the Business on Internet
  15. Securing Network Transactions
  16. Security Measures and Enforcement

12 IT Act 2000

  1. Definition
  2. Formulation of IT Act 2000
  3. Amendments in IT Act 2000
  4. Digital Signature & Encryption
  5. Attribution
  6. Acknowledgement and Dispatch of Electronic Records
  7. Regulation of Certifying Authorities
  8. Digital Signatures Certificates
  9. Duties of Subscribers
  10. Penalties and Adjudication
  11. Procedure, Working & Legal Position in Digital Signature
  12. Appellate Tribunal
  13. Offences and Cyber-Crimes
  14. E-Signature and Digital Signature
  15. Encryption

13 E-Tailing

  1. E-tailing
  2. E-tailing Models
  3. E-retail Mix-Sale the 7Cs
  4. E-tailing in India

14 E-Services

  1. Meaning of E-Services
  2. Benefits of E-Services
  3. FinTech
  4. eFinancial Services
  5. eTravel Services
  6. eAuction Services
  7. eLearning
  8. Virtual Communities and Web Portals
  9. Online Learning
  10. ePublishing Services
  11. Online Entertainment

15 App Based Commerce

  1. What is an App?
  2. Classification of Apps
  3. Types of Apps
  4. Steps for App Development
  5. Mobile Development Frameworks
  6. App Store
  7. Apps for Various Domains & Segments