Penalty for misrepresentation - Sec.71 - Information Technology Act

July 19, 2017

Section 71 of the Information Technology Act, 2000 establishes criminal liability for making misrepresentations or suppressing material facts before regulatory authorities to obtain licenses or digital signature certificates in India. The statutory provision specifically targets fraudulent submissions made to the Controller of Certifying Authorities or accredited Certifying Authorities during application processes. Individuals convicted of this offence face imprisonment for a term extending up to two years, a fine of up to one lakh rupees, or both.

Statutory Definition under Section 71 Information Technology Act

The legal foundation of electronic commerce and e-governance in India depends heavily on the integrity of Public Key Infrastructure (PKI). The Section 71 Information Technology Act provision protects this ecosystem by penalizing dishonest practices during certificate issuance. Electronic signatures and digital signature certificates (DSC) carry legal recognition equivalent to handwritten signatures under Section 5 of the Act; consequently, obtaining a certificate under false pretenses creates severe financial and legal vulnerabilities.

Section 71 states that whoever makes any misrepresentation to, or suppresses any material fact from, the Controller or the Certifying Authority for obtaining any license or Electronic Signature Certificate commits a criminal offence. The statute enforces truthfulness across all stages of identity verification and licensing applications.

Essential Ingredients of Penalty for Misrepresentation under IT Act

To secure a conviction and enforce the penalty for misrepresentation under IT Act, the prosecution must establish specific statutory ingredients before a competent magistrate:

  • Making a Misrepresentation: Submitting false identity details, forged organizational credentials, fabricated authorizations, or incorrect business declarations.
  • Suppressing Material Facts: Intentionally concealing disqualifications, previous certificate revocations, expired authorizations, or identity discrepancies.
  • Targeted Authorities: The misrepresentation or concealment must be directed at the Controller of Certifying Authorities (CCA) or an accredited Certifying Authority (such as eMudhra, Capricorn, or NSDL).
  • Specific Purpose: The dishonest act must be performed with the objective of obtaining an operational license or an Electronic Signature Certificate.

The Role of Controller of Certifying Authorities Offences

The regulatory structure governing Controller of Certifying Authorities offences ensures that only verified entities issue cryptographic credentials. The CCA acts as the root certifying authority in India, licensing and regulating private and public Certifying Authorities. When an applicant submits deceptive documentation to obtain an agency license, the entire public trust in digital transactions is jeopardized, justifying strict regulatory and criminal intervention under Section 71.

The CCA possesses broad investigatory powers under Chapter VIII of the Act to inspect Certifying Authority premises, audit cryptographic key generation systems, and revoke licenses if fraudulent procedures are detected. Section 71 operates as the direct criminal enforcement mechanism backing this regulatory oversight.

Fraudulent Applications and Digital Signature Certificate Misrepresentation

In commercial transactions, digital signature certificate misrepresentation typically arises when individuals attempt to secure Class 3 or organizational DSCs using stolen Know Your Customer (KYC) documents. Common fraudulent practices include:

  • Impersonating corporate directors to obtain signing certificates for unauthorized corporate filings with the Ministry of Corporate Affairs (MCA).
  • Submitting forged board resolutions, altered power of attorney documents, or invalid utility bills as address proof.
  • Using deactivated permanent account numbers (PAN) or fabricated Aadhaar credentials during automated video verification workflows.
  • Concealing the death or resignation of a designated signatory while continuing to renew organizational signing credentials.
  • Submitting altered corporate seal impressions or false company registration certificates to impersonate business entities.

Statutory Risks of Obtaining Electronic Signature Certificate by Fraud

The consequences of obtaining electronic signature certificate by fraud extend beyond Section 71. When an individual uses a fraudulently obtained DSC to sign contracts, transfer funds, or file tax returns, multiple additional charges under the Indian Penal Code (such as forgery, cheating by personation, and using forged documents under Sections 419, 465, and 471) apply simultaneously.

Certifying Authorities maintain automated revocation mechanisms. Upon discovering false representations, the authority immediately revokes the certificate, publishes the serial number to the Certificate Revocation List (CRL), and notifies law enforcement authorities.

Investigation Standards and Evidentiary Proof

Prosecuting Section 71 violations requires thorough digital and documentary forensic verification. Investigating officers collect electronic application forms, IP connection logs, video verification recordings, and original physical KYC records. Judicial standards in cases such as Aircel Cellular Vs. Union of India and Venjaramoodu M. Ziyad Vs. Union of India emphasize that administrative compliance and statutory integrity require strict adherence to verified records.

The regulatory authority, operating under the Controller of Certifying Authorities, issues strict identity verification guidelines that Certifying Authorities must enforce before generating key pairs and issuing certificates. Investigating agencies must establish the unbroken digital chain of custody under Section 65B of the Indian Evidence Act to prove that the submitted electronic records originated from the accused party.

Legal Defenses and Evidentiary Challenges

Defendants facing charges under Section 71 may present legitimate legal defenses based on absence of fraudulent intent or bona fide administrative error. Key defense considerations include:

  • Demonstrating that the alleged misstatement was an unintentional clerical error rather than a deliberate suppression of material facts.
  • Proving that third-party registration agents or intermediaries altered application forms without the applicant knowledge or authorization.
  • Establishing that the applicant reasonably relied on official documents issued by government departments that were later found to be defective.
  • Challenging digital forensics if the prosecution fails to connect the IP address or device used during application submission to the accused.

Compliance Guidelines for Applicants and Corporate Subscribers

To avoid inadvertent legal exposure and ensure smooth digital verification, corporate subscribers and individual applicants should adhere to structured compliance procedures:

  • Ensure all corporate authorization letters and board resolutions are authentic, current, and signed by active authorized signatories.
  • Perform physical or cryptographic verification of all submitted identity credentials prior to uploading them to Certifying Authority portals.
  • Promptly notify the issuing Certifying Authority if an authorized signatory leaves the organization or changes executive duties, requesting immediate certificate revocation.
  • Maintain internal audit logs detailing who initiated, approved, and managed digital certificate issuance within the corporate entity.

Section 71 guarantees that the trust anchored in digital signatures remains uncompromised. By penalizing misrepresentation and material suppression with imprisonment and fines, the Information Technology Act maintains confidence in India expanding digital legal and financial framework.

Found this helpful?

Share this page with others