Overview
This Proclamation establishes a legal framework for electronic signatures and electronic messages in Ethiopia to promote e-commerce and digital government services. It provides legal recognition to electronic signatures and sets rules for their use.
Key words:
Electronic Signature, Digital Signature, Electronic Record, Electronic Message, Legal Recognition, Legal Presumption, Cryptography, Public Key Infrastructure (PKI), Secure System, Authentication, Data Integrity, Encryption, Root Certificate Authority (RCA) , Information Network Security Agency (INSA), Certificate Provider, license, Burden of Proof , Valid Certificate, Reliable Electronic Signature, Signatory Intent, E-commerce, E-government, Digital Transactions, Online Contracts, Digital Economy
Key Provisions
Legal Recognition
- Electronic messages and signatures cannot be denied legal effect solely because they are in electronic form
- Electronic signatures satisfy legal signature requirements if they are reliable
- A reliable electronic signature is presumed to:
- Belong to the signer
- Show the signer’s intent
- Ensure the document has not been altered
- Digital signatures supported by valid certificates are presumed reliable
Institutional Framework
- Root Certificate Authority: The Information Network Security Agency (INSA) serves as the root certificate authority, issuing licenses to certificate providers and monitoring their activities
Certificate Providers
- Must obtain a valid license from the Root Certificate Authority (valid for 5 years, renewable)
- Can Provide digital certificates, encryption services, and time stamp services
- Must use trustworthy systems, maintain financial capacity, and keep records for 2 years
- Provide warranties to subscribers and relying parties
- Can delegate certain functions to registration and authentication bodies
Conditions for License Denial
License is denied if the applicant:
- Is an individual (not an entity)
- Is not established in Ethiopia
- Has a criminal conviction (not reinstated)
Validity and Renewal of License
- License validity: 5 years
- Renewal must be requested 60 working days before expiry
- Providers cannot operate with an expired license
Supervision, Suspension & Revocation
- Regulatory body can:
- Suspend certificate services temporarily (e.g., for investigation or correction)
- Revoke licenses if:
- Laws are violated
Certificates
- Must contain: subscriber’s name/address, public key, provider’s digital signature, validity period, reliance limits, and other specified information
- Can be suspended (up to 6 months) or revoked for various reasons (false information, security breaches, subscriber death, etc.)
- Suspended/revoked certificates become invalid for use
Obligations and Liability
- Subscribers: Must provide accurate information, safeguard private keys, and request suspension/revocation if security is compromised
- Relying Parties: Must follow verification procedures, respect reliance limits, and use certificates only for permitted purposes
- Certificate Providers: Liable for damages from failure to meet obligations, except for losses beyond stated reliance limits
Offenses and Penalties
- Operating without license: 100,000-200,000 Birr fine
- Operating with revoked/expired license: 100,000-200,000 Birr fine
- Using suspended/revoked certificates: 20,000-50,000 Birr fine
- Misuse of key pairs: 40,000-100,000 Birr fine
- Various other fines for non-compliance
Dispute Resolution
- National Crypto Council handles complaints related to licensing, renewal, and related services
- Administrative appeals to Root Certificate Authority within 30 days
- Court appeals available to Federal High Court
Effective Date
February 16, 2018
Leave a Reply
You must be logged in to post a comment.