Every time you file your income tax return online, sign a company incorporation form on the MCA portal, or approve a high-value bank transaction, there’s a good chance a digital signature is working quietly in the background. It’s the invisible seal that tells the receiving system: this record genuinely came from the person who claims to have sent it, and nobody tampered with it along the way. The Information Technology Act, 2000 (IT Act) is what gives this digital seal the same legal weight as your handwritten signature on paper.

For anyone studying e-commerce law, this topic often feels intimidating because it mixes legal language with cryptography. But once you break it down, the logic is fairly simple, and it explains why online contracts, e-filing, and digital payments in India actually hold up in court.

Table of Contents

What the IT Act 2000 says about digital signatures

Section 3 of the IT Act is the starting point. It states that any subscriber may authenticate an electronic record by affixing a digital signature, and that this authentication must be carried out using an asymmetric crypto system and a hash function. The official text of the Act defines a hash function as an algorithm that maps a piece of data into a smaller, fixed-size output, in such a way that it is computationally infeasible to reconstruct the original record from that output, or to find two different records that produce the same result.

In plain terms, the law doesn’t just say “you can sign things digitally.” It specifies the exact cryptographic method that qualifies as a legally valid digital signature. This is deliberate. By tying legal recognition to a specific, verifiable technology, the Act ensures that a digital signature can actually be tested and proven in a dispute, rather than relying on trust alone.

The technology behind the signature: asymmetric cryptography and hashing

To understand why the law insists on these two components, it helps to understand what each one does.

Asymmetric crypto system

Also called public-key cryptography, this system generates a mathematically linked pair of keys for every user: a private key, which only the owner knows and controls, and a public key, which can be shared freely with anyone. Whatever is encrypted with one key can only be decrypted with the other half of the pair. A signatory uses their private key to “lock” a document, and anyone with the corresponding public key can “unlock” it to confirm the signatory’s identity. Because the private key never has to be shared, its secrecy is what keeps the whole system trustworthy.

Hash function

A hash function takes an electronic record of any size and compresses it into a fixed-length string of characters, known as a hash or message digest. Two properties make this useful for signatures. First, the same input always produces the same hash, so the result is predictable and verifiable. Second, even a tiny change, such as altering one word in a contract, produces a completely different hash. This is often called the avalanche effect, and it’s what makes tampering instantly detectable.

How the digital signature process actually works

The process described in the IT Act’s outline combines both technologies into a clear sequence. Here’s how it plays out between a sender and a recipient.

Step What the sender does What the recipient does
1 Runs the original electronic record through a hash function to generate a unique hash value Receives the message along with the attached digital signature
2 Encrypts that hash value using their own private key, creating the digital signature Uses the sender’s public key to decrypt the signature and retrieve the original hash
3 Attaches the encrypted hash (the signature) to the original message and sends both together Independently hashes the received message and compares the two hash values
4   If the two hashes match, the message is authentic and unaltered; if they don’t, it has been tampered with or the signature is invalid

This two-step verification, confirming both identity (only the sender’s private key could have created a signature that opens with the sender’s public key) and integrity (only an unaltered document produces a matching hash), is what gives digital signatures their legal strength. A detailed reading of Section 3 shows the law is built entirely around this dual guarantee.

Digital signature vs electronic signature

Students often confuse these two terms, and the IT Act actually treats them differently. Section 3 deals specifically with digital signatures based on asymmetric cryptography and hashing. When the Act was amended in 2008, Section 3A was inserted to introduce a broader, technology-neutral category called the electronic signature, which recognises any authentication technique listed in the Second Schedule of the Act, including Aadhaar-based e-KYC signing. So every digital signature is a type of electronic signature, but not every electronic signature qualifies as a digital signature under the strict cryptographic definition in Section 3.

Certifying authorities and the trust chain

A key pair alone doesn’t prove who owns it. Someone independent has to vouch for the link between a public key and the real person or organisation behind it. This is where Certifying Authorities (CAs) come in. CAs issue Digital Signature Certificates (DSCs) that bind a subscriber’s identity to their public key.

Overseeing this entire ecosystem is the Controller of Certifying Authorities (CCA), appointed by the Central Government under Section 17 of the IT Act. According to the Digital India initiative, the CCA licenses and regulates CAs to make sure none of them violate the provisions of the Act, and it operates the Root Certifying Authority of India, which digitally signs the public keys of every licensed CA in the country. This creates a verifiable chain of trust: the government vouches for the CA, and the CA vouches for the individual subscriber. The CCA’s own framework page also notes that it maintains a public repository of all digital certificates issued in India, which anyone can use to verify a signer’s credentials.

Where encryption fits into the picture

Encryption and digital signatures often get bundled together, but they solve slightly different problems. A digital signature proves who sent a message and that it wasn’t altered. Encryption, on the other hand, is about confidentiality, making sure that only the intended recipient can read the content at all.

Interestingly, the IT Act does not lay down a detailed, standalone encryption law. Section 84A, added through a later amendment, simply empowers the Central Government to prescribe modes or methods of encryption for the secure use of electronic mediums and to promote e-governance and e-commerce. As of now, no comprehensive rules have been notified under this section. According to the Software Freedom Law Centre, India, a draft National Encryption Policy was published in September 2015 but was withdrawn within two days following public criticism, and India continues to rely instead on sector-specific encryption standards set by regulators such as the Reserve Bank of India for banking and SEBI for securities trading.

In practice, this means encryption strength in Indian e-commerce is largely governed by industry norms and contractual standards, such as SSL/TLS protocols for websites and payment gateways, rather than a single unified statute. Digital signatures, by contrast, remain far more tightly codified because they carry direct legal consequences for contract validity and evidentiary value in court.

Why this matters for e-commerce

Before this legal framework existed, a scanned signature or a typed name at the end of an email carried very little weight in a dispute. Section 3’s cryptographic approach changed that by giving electronic authentication a scientifically verifiable basis. This is what allows online tenders, e-contracts, GST filings, and company e-filings to be treated as legally binding, and it’s a major reason India’s digital economy has been able to scale the way it has. It also shifts responsibility onto users: since the security of the entire system hinges on keeping the private key confidential, courts generally presume that a document signed with a subscriber’s private key was indeed signed by them, unless proven otherwise.

What do you think? If the security of a digital signature depends entirely on the subscriber protecting their private key, how much of the legal certainty the IT Act promises actually rests on individual user behaviour rather than the technology itself? And as digital transactions grow more complex, should India move towards a more comprehensive encryption law instead of relying on sector-specific standards?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
  2. https://indiankanoon.org/doc/1869099/
  3. https://www.digitalindia.gov.in/di_ecosystem/controller-of-certifying-authorities-cca/
  4. https://cca.gov.in/pki_framework.html
  5. https://sflc.in/faq-legal-position-encryption-india/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

E-Commerce

1 Introduction to E-commerce

  1. Introduction
  2. Meaning of E-Commerce
  3. E-Commerce Web Portal
  4. E-Commerce Software
  5. E-Commerce APIs
  6. M-Commerce and Multi-channel Commerce
  7. Use of Emerging Technologies in E-Commerce
  8. Why E-Commerce
  9. Evolution of E-Commerce
  10. Types of E-Commerce
  11. Advantages and Disadvantages of E-Commerce

2 E-Commerce Business Models

  1. Introduction
  2. What is a Business Model?
  3. Key Elements of a Business Model
  4. E-Commerce Business Models to Understand Target Customer
  5. E-Commerce Design Models
  6. Implementing E-Commerce Models
  7. E-Commerce Revenue Models
  8. Impact of COVID on E-Commerce

3 Technology used in E-Commerce

  1. Introduction
  2. Design Considerations of E-Commerce
  3. Essential Technology Features Required
  4. Difference between App Based and Web-Based Business
  5. Building, Designing and Launching E-Commerce Website
  6. SDLC Cycle for Designing E-Commerce Solutions
  7. Architectural Framework and Network Infrastructure
  8. Impact of Emerging Technologies on E-Commerce
  9. Digital Platforms and E-Commerce
  10. Digitalisation and Digital Transformation in Businesses

4 Electronic Governance

  1. Introduction
  2. Meaning of E-Governance
  3. Differences between E-Government and E-Governance
  4. Differences between E-Governance and E-Commerce
  5. Advantages of Employing Digital Technologies in Governance
  6. Gartnerโ€™s Evolution Model of E-Governance
  7. E-Governance in India
  8. Digital India
  9. E-Governance initiatives in India

5 E-Payment

  1. Introduction
  2. Overview of Payment System
  3. Meaning of E-Payment
  4. Difference between E-Payment & Conventional Payment
  5. Payment Gateways
  6. Steps about Functioning of a Payment Gateway
  7. Types of Payment Gateways
  8. Types of Payment Methods
  9. Requirements Metrics of a Payment System
  10. Merits of E-Payment System
  11. Risks Involved in E-Payment

6 E-Banking

  1. Introduction
  2. Concept of E-Banking
  3. Importance of E-Banking
  4. Technology used in Banking
  5. EFT (Electronic Fund Transfer)
  6. NEFT (National Electronic Fund Transfer)
  7. RTGS (Real Time Gross Settlement)
  8. IMPS (Immediate Payment Service)
  9. UPI (Unified Payments Interface)
  10. Difference between NEFT, RTGS & IMPS
  11. Virtual Currency
  12. Automated Clearing House
  13. Automated Ledger Posting
  14. Distributed Ledger Technology

7 Website Development

  1. Introduction
  2. Meaning of Website
  3. Evolution of Website
  4. Website Usage
  5. HTTP & HTTPS Protocols
  6. Types of Website
  7. Development of Website
  8. Ingredients Required for Website Development
  9. Website Hosting

8 Electronic Commerce Software

  1. Introduction
  2. E-commerce Software Platform
  3. Types of Software Platforms
  4. Shopify – An Online Store Builder
  5. E-Auction Processes the Real-Time Visibility
  6. PayPal Holdings Online Payments
  7. SAP Commerce Cloud
  8. Functions of E-Commerce Software Platforms
  9. Advanced Functions of E-Commerce Software
  10. E-Commerce Software for Small & Midsize Companies
  11. E-Commerce Software for Midsize to Large Business
  12. E-Commerce Software for Large Business
  13. Planning Electronic Commerce Initiatives
  14. Strategies for Developing E-Commerce Websites
  15. Managing E-Commerce Implementations

9 Web Server Hardware and Software

  1. Meaning of Server
  2. Web Server Essentials
  3. Different Types of Web Server
  4. Characteristics of a Web Server
  5. Functioning of a Web Server
  6. Mail Server
  7. Process of Sending E-mails
  8. Operating System
  9. Windows
  10. Linux
  11. Linux vs. Windows
  12. Web Server Hardware
  13. Hardware used in Web Servers
  14. Web Server Software
  15. Application Server Software
  16. Web Server & Application Server
  17. Web Site and Internet Utility Programs

10 Cyber Security

  1. Meaning of Cyber Security
  2. Cyber Security Impact on E-Commerce
  3. Cyber Security Relevance
  4. Information Security V/s Cyber Security
  5. Basics of Cyber World
  6. Need & Concepts behind Security
  7. IoT and Cyber World
  8. Cyber Crime and Law
  9. Security Barriers

11 Cyber Security Measures

  1. Role of Cyber Security Analysts
  2. Essential Cyber Security Measures
  3. Precautionary Cyber-Security Measures Enterprise Takes
  4. IoT and its Impact
  5. Vulnerable Information on Internet
  6. Vulnerabilities of Systems
  7. Internet Vulnerabilities
  8. Wireless Security Challenges
  9. Malicious Software
  10. Hackers and Computer Crime
  11. Cyber Crime
  12. Global Threats: Cyber terrorism and Cyber Warfare
  13. Cyber Forensic
  14. Securing the Business on Internet
  15. Securing Network Transactions
  16. Security Measures and Enforcement

12 IT Act 2000

  1. Definition
  2. Formulation of IT Act 2000
  3. Amendments in IT Act 2000
  4. Digital Signature & Encryption
  5. Attribution
  6. Acknowledgement and Dispatch of Electronic Records
  7. Regulation of Certifying Authorities
  8. Digital Signatures Certificates
  9. Duties of Subscribers
  10. Penalties and Adjudication
  11. Procedure, Working & Legal Position in Digital Signature
  12. Appellate Tribunal
  13. Offences and Cyber-Crimes
  14. E-Signature and Digital Signature
  15. Encryption

13 E-Tailing

  1. E-tailing
  2. E-tailing Models
  3. E-retail Mix-Sale the 7Cs
  4. E-tailing in India

14 E-Services

  1. Meaning of E-Services
  2. Benefits of E-Services
  3. FinTech
  4. eFinancial Services
  5. eTravel Services
  6. eAuction Services
  7. eLearning
  8. Virtual Communities and Web Portals
  9. Online Learning
  10. ePublishing Services
  11. Online Entertainment

15 App Based Commerce

  1. What is an App?
  2. Classification of Apps
  3. Types of Apps
  4. Steps for App Development
  5. Mobile Development Frameworks
  6. App Store
  7. Apps for Various Domains & Segments