Section 3 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 3 of the Information Technology Act, 2000 says how a subscriber may authenticate an electronic record with a digital signature. It requires an asymmetric crypto system and a hash function, lets anyone verify the record with the subscriber's public key, and declares that the private key and public key are unique to the subscriber and form a functioning key pair.
Under section 3, any subscriber may authenticate an electronic record by affixing his digital signature, subject to the section. The authentication is effected by an asymmetric crypto system and hash function, which envelop and transform the initial electronic record into another electronic record. Any person can verify the record by the subscriber's public key. The two keys are unique to the subscriber.
Source and scope
This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008). Later amendments and the current position of the section should be checked. The defined terms used below (subscriber, digital signature, key pair, verify) are explained in our article on section 2: digital signature, electronic signature, certifying authority and key pair. Chapter II is headed "Digital signature and electronic signature" in the copy, and section 3A (the wider electronic signature route) follows this section. If you need advice on how your own documents should be signed, ask for a legal consultation.
Sub-section (1): who may authenticate
Sub-section (1) reads: "Subject to the provisions of this section, any subscriber may authenticate an electronic record by affixing his digital signature." Three points:
- The person who authenticates is a subscriber, that is, a person in whose name the Electronic Signature Certificate is issued (section 2(1)(zg)).
- The act is affixing a digital signature. Section 2(1)(d) defines affixing an electronic signature as adopting any methodology or procedure for the purpose of authenticating an electronic record.
- The permission is subject to the rest of the section, which sets out the method.
If you want the certificate side, see our practical guide on how to get, renew and use a Digital Signature Certificate. The Act leaves several matters to rules and the sources used here do not contain those rules.
Sub-section (2): asymmetric crypto system and hash function
Sub-section (2) says the authentication "shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record".
Section 2(1)(f) defines an asymmetric crypto system as a system of a secure key pair consisting of a private key for creating a digital signature and a public key to verify the digital signature. The sub-section adds the hash function and defines it in an Explanation.
The Explanation on "hash function"
For the purposes of sub-section (2), "hash function" means an algorithm mapping or translation of one sequence of bits into another, generally smaller, set known as "hash result", such that an electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input. The algorithm must make it computationally infeasible:
- (a) to derive or reconstruct the original electronic record from the hash result produced by the algorithm; and
- (b) that two electronic records can produce the same hash result using the algorithm.
In plain words, the hash function turns a record into a short result. The same record always gives the same result, the original cannot be rebuilt from the result, and two different records cannot be made to give the same result. If someone alters the record after signing, the hash result no longer matches, and that is what lets a verifier detect the alteration.
Sub-section (3): anyone can verify
Sub-section (3) says "Any person by the use of a public key of the subscriber can verify the electronic record." Section 2(1)(zh) defines "verify" as determining whether (a) the initial electronic record was affixed with the digital signature by the use of the private key corresponding to the public key of the subscriber, and (b) the initial electronic record is retained intact or has been altered since it was so affixed. The public key is the key "used to verify a digital signature and listed in the Digital Signature Certificate" (section 2(1)(zd)). So the person receiving the record does not need the subscriber's secret; the public key is enough.
Sub-section (4): the key pair
Sub-section (4) provides that "The private key and the public key are unique to the subscriber and constitute a functioning key pair." Two consequences follow from the words. The private key is the means by which the digital signature is created (section 2(1)(zc)), so who holds it matters. And a subscriber's duties on holding and controlling the private key are set out later in the Act; see our article on duties of subscribers and control of the private key.
How the steps fit together
| Step | What happens | Source |
|---|---|---|
| 1 | A subscriber decides to authenticate an electronic record | s.3(1) |
| 2 | The record is passed through a hash function and an asymmetric crypto system | s.3(2) and Explanation |
| 3 | The private key creates the digital signature | s.2(1)(zc), (p) |
| 4 | Any person uses the subscriber's public key to verify | s.3(3) |
| 5 | Verification tests the key link and whether the record was altered | s.2(1)(zh) |
A worked example
Tanvi Exports Private Limited sends a revised price schedule to Delta Packaging by e-mail, signed by Tanvi's authorised director with her digital signature. The schedule is the electronic record, the director is the subscriber, and the signature is created with her private key. Delta uses the public key listed in the certificate to verify. If the verification shows the schedule is intact, Delta has the means to rely on it as authenticated under section 3. If someone changed one figure after signing, the verification would show that the record has been altered. What the signature proves, and what a court makes of it in a dispute, depends on other provisions and on the evidence; section 3 itself only supplies the method.
Our post on digital signatures and electronic records and their impact on drafting looks at how this affects the clauses of an agreement.
What section 3 does not say
Section 3 prints no penalty, no fee and no period. It does not say which documents must be digitally signed; it only says how a subscriber may authenticate. The legal effect of an electronic signature in place of a handwritten one is the subject of section 5, explained in our article on legal recognition of electronic signatures. The First Schedule (see our article on section 1 and the First Schedule) lists documents to which the Act does not apply.
Need help with signing electronic records?
If your business signs agreements, filings or board papers electronically and wants the arrangement checked against the Act, we can review the process with you. Begin with a legal consultation on how your records are authenticated.
Key takeaways
- Only a subscriber may authenticate under section 3.
- The method is an asymmetric crypto system plus a hash function.
- The hash result must be one from which the record cannot be rebuilt, and two records cannot give the same hash result.
- Any person can verify using the subscriber's public key.
- The private and public key are unique to the subscriber.
Read next
- Section 3A: electronic signature and the Second Schedule
- Section 5: legal recognition of electronic signatures
- Section 2: digital signature, electronic signature, certifying authority and key pair defined
- E-contracts and digital signatures: validity in India
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
