INFORMATION TECHNOLOGY ACT, 2000

(Amended by IT Amendment Act, 2008)

COMPLIANCE DOCUMENT
Digital Signing
Document Type IT Act Compliance Statement
Scope Aadhaar OTP e-Sign, DSC Digital Sign, Draw Electronic Sign
Applicable Law IT Act 2000, IT Amendment Act 2008, IT Rules 2011
Document Date 20 May 2026
Classification Confidential — Internal & Legal Use

1. Executive Summary

This document sets out the compliance posture of the Digital Signing with respect to the Information Technology Act, 2000, as amended by the Information Technology (Amendment) Act, 2008, and the applicable rules.

The Platform provides Aadhaar OTP e-Sign, DSC-based Digital Signatures, and Draw-based Electronic Signatures.

2. Platform Services Overview

Service Description & Legal Classification
Aadhaar OTP e-Sign Electronic signature service using Aadhaar-based OTP authentication. User is redirected to a licensed ESP for Aadhaar verification.
DSC-Based Digital Sign Digital signature service using a Digital Signature Certificate issued by a licensed Certifying Authority.
Draw Electronic Sign Electronic signature created through a drawing/handwriting interface.

3. Applicable Legal Framework

3.1 Primary Legislation

3.2 Key Sections of the IT Act

Section / Rule Relevance
Section 3 Authentication of Electronic Records
Section 3A Electronic Signature Recognition
Section 5 Legal Recognition of Electronic Signatures
Section 43A Protection of Sensitive Personal Data
Section 79 Intermediary Safe Harbour

4. Service-Wise Compliance Analysis

4.1 Aadhaar OTP e-Sign Service

Legal Basis
Section 3A of the IT Act read with the Second Schedule and Electronic Signature Rules, 2015.

Compliance Status

COMPLIANT Aadhaar data is not stored by the Platform.
COMPLIANT Authentication is delegated to a UIDAI-licensed ESP.

4.2 DSC-Based Digital Signing Service

Legal Basis
Sections 2(1)(p), 3 and 5 of the IT Act.

Critical Obligations

PARTIAL In-memory PFX handling policy should be formally documented.

5. Data Protection & Privacy Compliance

Data Category Details
Username Stored for account identification and access control.
PFX File Processed in-memory only and never persisted.
Draw Signature Embedded into the final document.

6. Technical & Security Requirements

Control Area Requirement
Encryption in Transit TLS 1.2 or higher must be enforced.
Encryption at Rest User data must be encrypted using AES-256.
Access Control RBAC must be implemented.

7. Compliance Checklist

Compliance Item Status
Privacy Policy Published Required
Terms of Service Published Required
Annual VAPT Recommended

8. Recommendations

Immediate Actions

  1. Publish Privacy Policy and Terms of Service.
  2. Appoint a Grievance Officer.
  3. Execute DPA with Aadhaar e-Sign ESP.
  4. Document PFX in-memory handling policy.

Short-Term Actions

  1. Implement OTP verification for draw signatures.
  2. Establish CERT-In reporting workflow.
  3. Create data retention and deletion policy.

Long-Term Actions

  1. Pursue ISO/IEC 27001 certification.
  2. Conduct annual VAPT exercises.
  3. Prepare for DPDPA compliance.