Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

Section 3 of the Information Technology Act, 2000: authentication of electronic records by digital signature

Under section 3, any subscriber may authenticate an electronic record by affixing his digital signature, subject to the section. The authentication is effected by an asymmetric...

Published
Updated
Reading time
8 min
Views
13
Questions
6 answered
  • Expert Reviewed
  • High Complexity
  • In-Depth Guide
Topic
Cyber & Data Protection
Published
October 2, 2026
Last updated
Oct 8, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Section 3 of the Information Technology Act, 2000 says how a subscriber may authenticate an electronic record with a digital signature. It requires an asymmetric crypto system and a hash function, lets anyone verify the record with the subscriber's public key, and declares that the private key and public key are unique to the subscriber and form a functioning key pair.

Source and scope

This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of the section should be checked. The defined terms used below (subscriber, digital signature, key pair, verify) are explained in our article on section 2: digital signature, electronic signature, certifying authority and key pair. Chapter II is headed "Digital signature and electronic signature" in the copy, and section 3A (the wider electronic signature route) follows this section. If you need advice on how your own documents should be signed, ask for a legal consultation.

Sub-section (1): who may authenticate

Sub-section (1) reads: "Subject to the provisions of this section, any subscriber may authenticate an electronic record by affixing his digital signature." Three points:

  1. The person who authenticates is a subscriber, that is, a person in whose name the Electronic Signature Certificate is issued (section 2(1)(zg)).
  2. The act is affixing a digital signature. Section 2(1)(d) defines affixing an electronic signature as adopting any methodology or procedure for the purpose of authenticating an electronic record.
  3. The permission is subject to the rest of the section, which sets out the method.

If you want the certificate side, see our practical guide on how to get, renew and use a Digital Signature Certificate. The Act leaves several matters to rules and the sources used here do not contain those rules.

Sub-section (2): asymmetric crypto system and hash function

Sub-section (2) says the authentication "shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record".

Section 2(1)(f) defines an asymmetric crypto system as a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature. The sub-section adds the hash function and defines it in an Explanation.

The Explanation on "hash function"

For the purposes of sub-section (2), "hash function" means an algorithm mapping or translation of one sequence of bits into another, generally smaller, set known as "hash result", such that an electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input. The algorithm must make it computationally infeasible:

  • (a) to derive or reconstruct the original electronic record from the hash result produced by the algorithm; and
  • (b) that two electronic records can produce the same hash result using the algorithm.

In plain words, the hash function turns a record into a short result. The same record always gives the same result, the original cannot be rebuilt from the result, and two different records cannot be made to give the same result. If someone alters the record after signing, the hash result no longer matches, and that is what lets a verifier detect the alteration.

Sub-section (3): anyone can verify

Sub-section (3) says "Any person by the use of a public key of the subscriber can verify the electronic record." Section 2(1)(zh) defines "verify" as determining whether (a) the initial electronic record was affixed with the digital signature by the use of the private key corresponding to the public key of the subscriber, and (b) the initial electronic record is retained intact or has been altered since it was so affixed. The public key is the key "used to verify a digital signature and listed in the Digital Signature Certificate" (section 2(1)(zd)). So the person receiving the record does not need the subscriber's secret; the public key is enough.

Sub-section (4): the key pair

Sub-section (4) provides that "The private key and the public key are unique to the subscriber and constitute a functioning key pair." Two consequences follow from the words. The private key is the means by which the digital signature is created (section 2(1)(zc)), so who holds it matters. And a subscriber's duties on holding and controlling the private key are set out later in the Act; see our article on duties of subscribers and control of the private key.

How the steps fit together

StepWhat happensSource
1A subscriber decides to authenticate an electronic records.3(1)
2The record is passed through a hash function and an asymmetric crypto systems.3(2) and Explanation
3The private key creates the digital signatures.2(1)(zc), (p)
4Any person uses the subscriber's public key to verifys.3(3)
5Verification tests the key link and whether the record was altereds.2(1)(zh)

A worked example

Tanvi Exports Private Limited sends a revised price schedule to Delta Packaging by e-mail, signed by Tanvi's authorised director with her digital signature. The schedule is the electronic record, the director is the subscriber, and the signature is created with her private key. Delta uses the public key listed in the certificate to verify. If the verification shows the schedule is intact, Delta has the means to rely on it as authenticated under section 3. If someone changed one figure after signing, the verification would show that the record has been altered. What the signature proves, and what a court makes of it in a dispute, depends on other provisions and on the evidence; section 3 itself only supplies the method.

Our post on digital signatures and electronic records and their impact on drafting looks at how this affects the clauses of an agreement.

What section 3 does not say

Section 3 prints no penalty, no fee and no period. It does not say which documents must be digitally signed; it only says how a subscriber may authenticate. The legal effect of an electronic signature in place of a handwritten one is the subject of section 5, explained in our article on legal recognition of electronic signatures. The First Schedule (see our article on section 1 and the First Schedule) lists documents to which the Act does not apply.

Need help with signing electronic records?

If your business signs agreements, filings or board papers electronically and wants the arrangement checked against the Act, we can review the process with you. Begin with a legal consultation on how your records are authenticated.

Key takeaways

  • Only a subscriber may authenticate under section 3.
  • The method is an asymmetric crypto system plus a hash function.
  • The hash result must be one from which the record cannot be rebuilt, and two records cannot give the same hash result.
  • Any person can verify using the subscriber's public key.
  • The private and public key are unique to the subscriber.

Read next

Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Section 3

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who can use a digital signature under section 3?

Any subscriber, that is, a person in whose name the Electronic Signature Certificate is issued.

What is a hash function in the IT Act?

The Explanation to section 3(2) defines it as an algorithm mapping one sequence of bits into another, generally smaller, set known as the hash result, with the two safeguards in clauses (a) and (b).

Keep your documents in an order a stranger could follow — one day an officer or auditor will have to.

— TaxClue Compliance Desk

Section 3: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Any subscriber, that is, a person in whose name the Electronic Signature Certificate is issued.

The Explanation to section 3(2) defines it as an algorithm mapping one sequence of bits into another, generally smaller, set known as the hash result, with the two safeguards in clauses (a) and (b).

Sub-section (3) says any person, by using the subscriber's public key.

No. The section prints no penalty. Offences linked with signatures appear elsewhere in the Act.

No. Sub-section (4) says the private key and the public key are unique to the subscriber and constitute a functioning key pair.

Section 3 deals with the digital signature. Section 3A, explained in a separate article, deals with electronic signature or electronic authentication techniques.