INFORMATION TECHNOLOGY ACT, 2000
(Amended by IT Amendment Act, 2008)
COMPLIANCE DOCUMENT
Digital Signing
1. Executive Summary
This document sets out the compliance posture of the Digital Signing with respect to the Information Technology Act, 2000, as amended by the
Information Technology (Amendment) Act, 2008, and the applicable rules.
The Platform provides Aadhaar OTP e-Sign, DSC-based Digital Signatures,
and Draw-based Electronic Signatures.
2. Platform Services Overview
| Service |
Description & Legal Classification |
| Aadhaar OTP e-Sign |
Electronic signature service using Aadhaar-based OTP authentication.
User is redirected to a licensed ESP for Aadhaar verification.
|
| DSC-Based Digital Sign |
Digital signature service using a Digital Signature Certificate
issued by a licensed Certifying Authority.
|
| Draw Electronic Sign |
Electronic signature created through a drawing/handwriting interface.
|
3. Applicable Legal Framework
3.1 Primary Legislation
- Information Technology Act, 2000
- Information Technology (Amendment) Act, 2008
- IT (Certifying Authorities) Rules, 2000
- Electronic Signature Rules, 2015
- IT Rules 2021
3.2 Key Sections of the IT Act
| Section / Rule |
Relevance |
| Section 3 |
Authentication of Electronic Records |
| Section 3A |
Electronic Signature Recognition |
| Section 5 |
Legal Recognition of Electronic Signatures |
| Section 43A |
Protection of Sensitive Personal Data |
| Section 79 |
Intermediary Safe Harbour |
4. Service-Wise Compliance Analysis
4.1 Aadhaar OTP e-Sign Service
Section 3A of the IT Act read with the Second Schedule and
Electronic Signature Rules, 2015.
Compliance Status
COMPLIANT
Aadhaar data is not stored by the Platform.
COMPLIANT
Authentication is delegated to a UIDAI-licensed ESP.
4.2 DSC-Based Digital Signing Service
Sections 2(1)(p), 3 and 5 of the IT Act.
Critical Obligations
- PFX files must never be permanently stored.
- PFX passwords must be handled in memory only.
- Encryption must be enforced during transmission.
PARTIAL
In-memory PFX handling policy should be formally documented.
5. Data Protection & Privacy Compliance
| Data Category |
Details |
| Username |
Stored for account identification and access control. |
| PFX File |
Processed in-memory only and never persisted. |
| Draw Signature |
Embedded into the final document. |
6. Technical & Security Requirements
| Control Area |
Requirement |
| Encryption in Transit |
TLS 1.2 or higher must be enforced. |
| Encryption at Rest |
User data must be encrypted using AES-256. |
| Access Control |
RBAC must be implemented. |
7. Compliance Checklist
| Compliance Item |
Status |
| Privacy Policy Published |
Required |
| Terms of Service Published |
Required |
| Annual VAPT |
Recommended |
8. Recommendations
Immediate Actions
- Publish Privacy Policy and Terms of Service.
- Appoint a Grievance Officer.
- Execute DPA with Aadhaar e-Sign ESP.
- Document PFX in-memory handling policy.
Short-Term Actions
- Implement OTP verification for draw signatures.
- Establish CERT-In reporting workflow.
- Create data retention and deletion policy.
Long-Term Actions
- Pursue ISO/IEC 27001 certification.
- Conduct annual VAPT exercises.
- Prepare for DPDPA compliance.