The Information Technology Act, 2000
CHAPTER V: SECURE ELECTRONIC RECORDS AND SECURE ELECTRONIC SIGNATURE
Section 15: Secure Electronic Signature
Bare Act
15 Secure electronic signature - An electronic signature shall be deemed to be a secure electronic signature if:
- The signature creation data, at the time of affixing signature, was under the exclusive control of signatory and no other person; and
- The signature creation data was stored and affixed in such exclusive manner as may be prescribed.
Explanation - In case of digital signature, the "signature creation data" means the private key of the subscriber.
Simplified Act
What is a secure electronic signature?
A secure electronic signature is one that meets the following two conditions:
- Only the person signing had control over the data used to create the signature at the time it was used; no one else could access it.
- The data used to create the signature was stored and used in a specific way that is officially required.
Just so you know: When we talk about a digital signature, the "data used to create the signature" refers to what's called a private key, which is a secret code known only to the person signing.
Explanation using examples
Let's consider a hypothetical scenario to understand the application of Section 15 of The Information Technology Act, 2000.
Imagine Mr. John, a bank manager, is preparing a loan agreement for a client, Mr. Smith. To finalize the agreement, Mr. John needs to put his electronic signature on the document. According to Section 15:
- Mr. John, while affixing his signature, must ensure that the signature creation data (his private key in case of a digital signature) is under his exclusive control. This implies that no other person, including his colleagues or Mr. Smith, should have access to his private key at the time of signing.
- Moreover, the way Mr. John stores and affixes his signature should be in an exclusive manner as prescribed by the relevant authority. This means he should follow the standard procedures and guidelines set by his bank or regulatory body when creating and applying his electronic signature.
If these conditions are met, Mr. John's electronic signature will be deemed as a secure electronic signature as per Section 15 of The Information Technology Act, 2000.

