When India enacted the Information Technology Act, 2000, it did something far more significant than just acknowledge that computers exist – it built a legal vocabulary for the digital world. Section 2 of the Act lays down a set of definitions that serve as the bedrock for everything that follows: from validating an online contract to prosecuting a cybercrime. For law students and business professionals alike, getting these definitions right is not optional. They determine how courts interpret digital transactions, what counts as a valid signature on an email, and who has the legal authority to certify your identity online. This post breaks down the most critical definitions under the IT Act, 2000, and explains why each one matters in practice.

Table of Contents

Why definitions matter under the IT Act

In legislation, definitions do the heavy lifting. They fix the meaning of technical terms so that the same word carries the same legal weight in a courtroom in Chennai as it does in one in Delhi. The IT Act, 2000 is particularly definition-heavy because it deals with technology – a field where terms like “signature,” “record,” and “document” mean something quite different from their paper-based counterparts. Section 2(1) of the Act contains over 40 definitions, but a handful of them are foundational to understanding how digital transactions are authenticated, recorded, and legally enforced in India.

Asymmetric crypto system

Section 2(1)(f) defines “asymmetric crypto system” as a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature. This is the technical engine that powers digital signatures under the Act, and understanding it is essential before moving to any other definition.

The system works on a simple but powerful logic: two mathematically linked keys are generated together – one private, one public. The private key is kept secret by its owner and is used to sign (encrypt) an electronic record. The public key is shared openly and is used by anyone who wants to verify that the signature is genuine. Crucially, a signature created by the private key can only be verified by its corresponding public key, and vice versa. This means that if verification succeeds, you can be certain about who signed the document.

The Act further defines a “key pair” under Section 2(1)(x) as a private key and its mathematically related public key, which are so related that the public key can verify a digital signature created by the private key. The private and public keys are unique to each subscriber, making the system highly tamper-resistant. This is also why the asymmetric crypto system is called “asymmetric” – the key for signing is different from the key for verifying, unlike older symmetric systems where the same key does both jobs.

Section 3 of the Act goes a step further by mandating that authentication of an electronic record must be carried out using this asymmetric crypto system combined with a hash function. A hash function is an algorithm that maps a sequence of bits into a smaller set – called a hash result – such that any electronic record always yields the same hash result, making it computationally infeasible to reconstruct the original record from its hash or for two different records to produce the same hash. Together, the asymmetric crypto system and hash function ensure both the identity of the signer and the integrity of the document.

Digital signature

Section 2(1)(p) defines “digital signature” as the authentication of any electronic record by a subscriber by means of an electronic method or procedure in accordance with Section 3 of the Act. In plain terms, a digital signature is the legally recognised way to sign electronic documents in India – it is the digital equivalent of a handwritten signature on a paper contract.

What makes a digital signature legally valid? Under Section 5 of the IT Act, wherever any law requires that information be authenticated by affixing a signature, that requirement is deemed satisfied if it is authenticated by a digital signature affixed in the prescribed manner. This gives digital signatures the same legal standing as wet-ink signatures across most domains – from income tax filings to corporate resolutions.

The 2008 amendment to the IT Act introduced Section 3A and expanded the concept to “electronic signature”, defined under Section 2(1)(ta) as authentication of an electronic record by a subscriber by means of electronic technique specified in the Second Schedule. Digital signature is a subset of electronic signature – all digital signatures are electronic signatures, but not all electronic signatures qualify as digital signatures (which specifically require the asymmetric crypto system and a licensed Certifying Authority). For most high-stakes transactions – GST filings, MCA filings, government e-tendersdigital signatures are preferred and sometimes mandated.

Affixing a digital signature

The Act also defines “affixing digital signature” under Section 2(1)(d) as the adoption of any methodology or procedure by a person for the purpose of authenticating an electronic record by means of digital signature. This definition is important because it clarifies that the act of signing digitally is a deliberate, procedural step – not an accidental or passive event. Courts use this definition to determine whether a party genuinely intended to authenticate a document.

Certifying authority

Section 2(1)(g) defines “Certifying Authority” (CA) as a person who has been granted a licence to issue an electronic signature certificate under Section 24 of the Act. The Certifying Authority is essentially the trusted intermediary of the digital signature ecosystem – it vouches for the identity of the person whose public key is listed in the certificate.

Before a CA can operate, it must obtain a licence from the Controller of Certifying Authorities (CCA), which is the regulatory body appointed by the Central Government under Section 17 of the Act. Certifying Authorities are required to maintain strict security standards, submit Certification Practice Statements, and keep detailed records of all certificates issued. The CCA has authority to inspect, audit, and where necessary, suspend or revoke a CA’s licence.

A related definition is the “certification practice statement” under Section 2(1)(h) – a document issued by a Certifying Authority specifying the practices it employs in issuing digital signature certificates. Think of it as the CA’s operating manual made publicly available, so that subscribers and relying parties know exactly what standards have been followed.

In India, licensed CAs include entities like eMudhra, NIC (National Informatics Centre), CDAC, and (n)Code Solutions, all operating under the oversight of the CCA, which functions under the Ministry of Electronics and Information Technology (MeitY). When you apply for a Digital Signature Certificate (DSC) for filing your company’s annual return or participating in e-tendering, you are dealing directly with one of these licensed Certifying Authorities.

Digital Signature Certificate

Closely linked to the CA is the concept of a Digital Signature Certificate (DSC). Under Section 2(1)(tb), an “Electronic Signature Certificate” means a certificate issued under Section 35 and includes a Digital Signature Certificate. The DSC binds a subscriber’s identity to their public key – it essentially tells the world: “This public key belongs to this verified person.” An application for a DSC is filed with a Certifying Authority along with the prescribed fee, which cannot exceed Rs. 25,000, along with a certification practice statement or other prescribed particulars.

Electronic record

Section 2(1)(t) defines “electronic record” as data, record or data generated, image or sound stored, received or sent in an electronic form or micro film or computer generated micro fiche. This is one of the most expansive definitions in the Act, and deliberately so.

An electronic record is not limited to text files or PDFs. It covers emails, scanned images, audio files, video clips, database entries, and even data stored on microfilm. This breadth is intentional – the Act was designed to be technology-neutral so that it would not become obsolete as new formats emerged. Under Section 4 of the IT Act, wherever law requires that information be in writing or printed form, that requirement is satisfied if the information is made available in an electronic form that is accessible for future reference.

The definition of electronic record is foundational for understanding admissibility of evidence in digital disputes. Under Section 65B of the Indian Evidence Act, 1872 (now replaced by Section 63 of the Bharatiya Sakshya Adhiniyam, 2023), electronic records are admissible as evidence subject to a certificate of authenticity. Without a clear understanding of what qualifies as an “electronic record,” neither parties nor courts can correctly apply these evidentiary rules.

Information and data under the Act

The Act defines “information” under Section 2(1)(v) broadly to include data, message, text, images, sound, voice, codes, computer programmes, software, databases, or micro film. This feeds directly into the electronic record definition – any of these forms of information, when stored, sent, or received electronically, constitutes an electronic record. The wide scope ensures that SMS messages, WhatsApp chats, voice memos, and computer-generated reports all fall within the Act’s purview when relevant to a legal dispute or transaction.

Other important definitions at a glance

The Act contains several other definitions that regularly appear in practice and examinations. “Subscriber” under Section 2(1)(zg) means a person in whose name the electronic signature certificate is issued – the end-user of the digital signature system. “Intermediary” under Section 2(1)(w) means any person who on behalf of another receives, stores, or transmits an electronic record, and includes telecom service providers, internet service providers, web-hosting services, search engines, online payment sites, and online marketplaces. This definition has become particularly significant in the context of platform liability and the safe harbour provisions under Section 79 of the Act.

“Verify” under Section 2(1)(zh) means to determine, in relation to a digital signature or electronic record, whether the initial record was affixed with the digital signature using the private key corresponding to the subscriber’s public key, and whether the record remains intact or has been altered since being so affixed. This definition captures both authentication and integrity – two pillars of digital trust.

How these definitions connect in practice

These definitions do not operate in isolation – they form an interconnected legal framework. When a company director signs a board resolution electronically, the entire chain of definitions comes into play: the director (subscriber) uses an asymmetric crypto system to create a digital signature on an electronic record; the signature is verified using the public key listed in a Digital Signature Certificate issued by a licensed Certifying Authority; and the authenticated record is then legally recognised under Section 5 of the Act. Over 90% of government contracts are now processed electronically, with digital signature certificates mandatory for e-tendering on platforms like the Central Public Procurement Portal. The definitions in Section 2 are what make all of this legally coherent and enforceable.

For courts, these definitions resolve disputes about whether a particular electronic communication constitutes a valid contract, whether a signature on a PDF can be attributed to a specific person, and whether evidence stored on a server qualifies as an admissible electronic record. They are, in the truest sense, the vocabulary of digital law in India.

What do you think? Now that digital signatures carry the same legal weight as handwritten ones, should India consider making digital signature literacy a mandatory part of business and legal education – and how might clearer awareness of definitions like “certifying authority” and “asymmetric crypto system” change how professionals approach online contracts and cybersecurity compliance?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://indiankanoon.org/doc/629401/
  2. https://indiankanoon.org/doc/1869099/
  3. https://www.legalserviceindia.com/article/l212-Digital-Signatures.html
  4. https://helpx.adobe.com/legal/esignatures/regulations/india.html
  5. https://blog.ipleaders.in/digital-electronic-signature/
  6. https://www.meity.gov.in/static/uploads/2024/03/ITbill_2000.pdf
  7. https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
  8. https://www.esignglobal.com/blog/india-it-act-2000-digital-signature

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Business Law as Applicable to Co-operative-I

1 Indian Contract Act, 1872

  1. Lawful Proposal (Sec. 2(a))
  2. Lawful Acceptance (Sec.7)
  3. Capacity of Parties or Competency of Parties to make a Contract (Sec. 11)
  4. Minor’s Agreement (Compentency to Contract Sec.11)
  5. Lawful Consideration (Sec. 2(d))
  6. Free Consent (Sec. 13)
  7. Kinds of Contracts

2 The Transfer of Property Act, 1882

  1. Transfer of Property: Scope and Modes of Transfer
  2. Mortgages and Kinds of Mortgages (Sec. 58 to 99)
  3. Sale of Immovable Property (Sec. 54 to 56)
  4. Lease of Immovable Property (Sec. 105 to 117)
  5. Gift (Sec. 122 to 129)
  6. Other General Concepts/Terms Explained

3 The Sale of Goods Act, 1930

  1. The Term “Goods” Explained [Section 2(7)]
  2. Concept “Ownership in Goods” Explained [Section 2(4) and s(11)]
  3. Concepts: ‘Sale’ and ‘Agreement to Sell’ Explained (Section 4 and 26)
  4. Conditions and Warranties (Sec. 11-17)
  5. Quality of Goods (Doctrine of Caveat Emptor)
  6. Transfer of Title i.e. Property in Goods
  7. Unpaid Seller
  8. Rules Relating to the Auction-Sale

4 Civil Procedure Code, 1908

  1. Court
  2. Jurisdiction of Courts
  3. Suit
  4. Plaintiff and Defendant
  5. Decree
  6. Execution
  7. Res Judicata
  8. Execution against Property

5 Income Tax Law

  1. Important Concepts Definitions and Terms under the Income Tax Law
  2. Income from Salaries
  3. Income from House Property
  4. Profits and Gains from Business/Profession
  5. Income from other Sources
  6. Deductions Under Chapter VIA
  7. Taxation of Co-operative Societies
  8. Importance of Permanent Account Number (PAN)
  9. Litigations and Remedies

6 Other Tax-laws – VAT/GST, Service Tax, Stamp Act (Central And State)

  1. History
  2. Definitions
  3. Salient Features of VAT and GST
  4. Salient Features of Service Tax
  5. Salient Features of Stamp Act (Central and State)

7 Indian Penal Code, 1860

  1. History in Brief
  2. Important Definitions
  3. Scheme of the Penal Code
  4. Ingredients of Criminal Conspiracy
  5. Unlawful Assembly
  6. Public Servant Disobeying Law
  7. Giving False Evidence
  8. Dishonestly Making False Claim in Court
  9. Dishonest Misappropriation of Property
  10. Criminal Breach of Trust
  11. Cheating
  12. Mischief
  13. Forgery
  14. Defamation
  15. Falsification of Accounts
  16. Cognizance of Offence
  17. Provisions Related to Bail

8 The Prevention of Food Adulteration Act, 1954

  1. Historical Background and Need
  2. Important Definitions and Concepts
  3. Important Provisions
  4. Penalties

9 The Essential Commodities Act, 1955

  1. Historical Background and Need
  2. Important Concepts and Definitions
  3. Important Provisions
  4. Penalties
  5. Offences by Companies
  6. Procedure of Execution of Offences

10 The Consumer Protection Act, 1986 & Weights And Measurement Act, 1976

  1. Historical Background
  2. Important Concepts and Definitions
  3. Salient Features of the Consumer Protection Act 1986
  4. Salient Features of the Standards of Weights and Measures Act 1976

11 The Limitation Act, 1963

  1. Concept of Limitation and General Principles of Limitation
  2. Extension of Limitation for the Reason Sufficient Cause
  3. Legal Disability
  4. Exclusions for Computation of Period of Limitation
  5. Effects on Limitation
  6. Acquisition of Ownership by Possession
  7. General Information

12 The Indian Evidence Act, 1872

  1. Objects of the Indian Evidence Act
  2. Definitions
  3. Public Documents and Certified Copies
  4. Presumption as to Documents
  5. Principle of Estoppel
  6. Witnesses
  7. Important Amendments Subsequent the Introduction of the Information and Technology Act 2000

13 Information and Technology Act, 2002

  1. History in Brief
  2. Scheme of the Act
  3. Important Definitions
  4. Internet Culture and Advantages of the System
  5. Organizational Structure under the Act
  6. Emerging Crimes Offences
  7. Non-applicability of IT Act 2000 in Respect of Certain Acts

14 Right To Information Act, 2005

  1. History in Brief
  2. Important Definitions
  3. Scheme of the Act
  4. Important Topics for Study
  5. Public Authority to Fulfil Obligation by Proactive Disclosure
  6. The Central Information Commission
  7. Act to have Overriding Effect