Sections 14 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Chapter V of the Information Technology Act, 2000 deals with "secure" electronic records and signatures. Section 14 says when a record is treated as a secure electronic record, section 15 says when an electronic signature is treated as a secure electronic signature, and section 16 lets the Central Government prescribe the security procedures and practices that sections 14 and 15 rely on.
A record to which a security procedure has been applied at a specific point of time is deemed a secure electronic record from that point until the time of verification (s.14). An electronic signature is deemed secure if the signature creation data was under the exclusive control of the signatory at the time of affixing and was stored and affixed in the exclusive manner prescribed (s.15). The Central Government may prescribe security procedures and practices, having regard to commercial circumstances and the nature of the transactions (s.16).
Source and scope
This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of these sections should be checked. Sections 15 and 16 are printed inside square brackets in the copy. If your business needs to decide how its electronic records and signatures should be protected, a legal consultation can help you tie the practice to what the text requires.
Section 14: secure electronic record
"Where any security procedure has been applied to an electronic record at a specific point of time, then such record shall be deemed to be a secure electronic record from such point of time to the time of verification."
Three elements:
- A security procedure. Section 2(1)(zf) defines it as "the security procedure prescribed under section 16 by the Central Government".
- Applied at a specific point of time. The protection runs from that point.
- To the time of verification. "Verify" is defined in section 2(1)(zh) as determining whether the initial electronic record was affixed with the digital signature by the use of the private key corresponding to the subscriber's public key, and whether the record is retained intact or has been altered since. See our article on section 2: digital signature, certifying authority and key pair.
The section says the record is "deemed" secure. It does not say what legal consequence follows from being a secure electronic record; the sources used here do not state one in this Chapter.
Section 15: secure electronic signature
An electronic signature "shall be deemed to be a secure electronic signature if":
| Clause | Condition as printed |
|---|---|
| (i) | the signature creation data, at the time of affixing signature, was under the exclusive control of signatory and no other person |
| (ii) | the signature creation data was stored and affixed in such exclusive manner as may be prescribed |
Both conditions are joined by "and", so both must be met.
The Explanation
"In case of digital signature, the 'signature creation data' means the private key of the subscriber." So for a digital signature, exclusive control means exclusive control of the private key; the related definition of "private key" is in section 2(1)(zc). A subscriber's duty to keep the private key secure appears later in the Act; see our article on duties of subscribers and control of the private key.
A note on the printing
In the copy, the Explanation runs on from clause (ii) in the same paragraph, and a square bracket that opens before the number "15." closes only after the proviso to section 16. This is a printing feature of the copy; the text between is read as printed.
"Exclusive manner as may be prescribed" means the detail is left to rules. The rules are not in the sources used here, so this article gives no form, step or standard.
Section 16: security procedures and practices
"The Central Government may, for the purposes of sections 14 and 15, prescribe the security procedures and practices."
The proviso: "in prescribing such security procedures and practices, the Central Government shall have regard to the commercial circumstances, nature of transactions and such other related factors as it may consider appropriate."
So the procedure is not fixed by the Act. It is set by the Central Government and the Government must consider commercial circumstances and the nature of transactions. The same section 2(1)(zf) definition then gives the procedure its legal name.
How the three sections fit
| Section | Subject | Trigger | Result |
|---|---|---|---|
| 14 | Secure electronic record | Security procedure applied at a specific point of time | Deemed secure from that time to verification |
| 15 | Secure electronic signature | Exclusive control and exclusive storage and affixing | Deemed secure electronic signature |
| 16 | Procedures and practices | Central Government prescribes them | Gives content to sections 14 and 15 |
How these sections differ from sections 3 to 5
Sections 3 and 3A tell you how a record can be authenticated; sections 4 and 5 treat electronic records and signatures as meeting requirements of writing and signature. Chapter V adds a layer: records and signatures that are protected in the way described are called secure. The wording "deemed to be" in each of sections 14 and 15 is the whole of what the text says about the effect. See our articles on authentication of electronic records by digital signature and electronic signature and the Second Schedule.
A worked example
Brightwell Estates Private Limited stores its board minutes as electronic records. Its IT head applies a security procedure to the minutes on 4 April, when the final version is saved. Under section 14, if that security procedure is the one prescribed under section 16, the minutes are deemed a secure electronic record from that point until the time they are verified. Separately, the company secretary signs the minutes with a digital signature. The private key is kept only by her, on a token not shared with anyone, and it is stored and used in the exclusive manner prescribed. On those facts, section 15 deems her electronic signature a secure electronic signature. If she had shared the token with an assistant, the first condition (exclusive control "and no other person") would fail.
Need help with securing electronic records and signatures?
If your organisation signs and stores important records electronically, we can review who holds the keys, where signing data is stored and how your policy reads against sections 14 to 16. Start with a legal consultation and bring your signing and storage policy.
Key takeaways
- A record is deemed secure from the point a prescribed security procedure is applied to the time of verification.
- A signature is deemed secure only if signature creation data was under exclusive control and was stored and affixed in the exclusive manner prescribed.
- For a digital signature, the signature creation data is the subscriber's private key.
- The Central Government prescribes security procedures and practices, having regard to commercial circumstances and the nature of transactions.
- The Act itself prints no fee, period or penalty in these sections.
Read next
- Sections 17 to 19: Controller of Certifying Authorities, appointment and functions
- Sections 40 to 42: duties of subscribers and control of the private key
- Section 3: authentication of electronic records by digital signature
- Digital Signature Certificate (DSC): how to get, renew and use
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
