Ethiopia’s Electronic Signature Proclamation No. 1072/2018

Overview

This Proclamation establishes a legal framework for electronic signatures and electronic messages in Ethiopia to promote e-commerce and digital government services. It provides legal recognition to electronic signatures and sets rules for their use.

Key words:

Electronic Signature, Digital Signature, Electronic Record, Electronic Message, Legal Recognition, Legal Presumption, Cryptography, Public Key Infrastructure (PKI), Secure System, Authentication, Data Integrity, Encryption, Root Certificate Authority (RCA) , Information Network Security Agency (INSA), Certificate Provider, license, Burden of Proof , Valid Certificate, Reliable Electronic Signature, Signatory Intent, E-commerce, E-government, Digital Transactions, Online Contracts, Digital Economy

Key Provisions

Legal Recognition

  • Electronic messages and signatures cannot be denied legal effect solely because they are in electronic form
  • Electronic signatures satisfy legal signature requirements if they are reliable
  • A reliable electronic signature is presumed to:
    • Belong to the signer
    • Show the signer’s intent
    • Ensure the document has not been altered
  • Digital signatures supported by valid certificates are presumed reliable

Institutional Framework

  • Root Certificate Authority: The Information Network Security Agency (INSA) serves as the root certificate authority, issuing licenses to certificate providers and monitoring their activities

Certificate Providers

  • Must obtain a valid license from the Root Certificate Authority (valid for 5 years, renewable)
  • Can Provide digital certificates, encryption services, and time stamp services
  • Must use trustworthy systems, maintain financial capacity, and keep records for 2 years
  • Provide warranties to subscribers and relying parties
  • Can delegate certain functions to registration and authentication bodies

Conditions for License Denial

License is denied if the applicant:

  • Is an individual (not an entity)
  • Is not established in Ethiopia
  • Has a criminal conviction (not reinstated)

Validity and Renewal of License

  • License validity: 5 years
  • Renewal must be requested 60 working days before expiry
  • Providers cannot operate with an expired license

Supervision, Suspension & Revocation

  • Regulatory body can:
    • Suspend certificate services temporarily (e.g., for investigation or correction)
    • Revoke licenses if:
      • Laws are violated

Certificates

  • Must contain: subscriber’s name/address, public key, provider’s digital signature, validity period, reliance limits, and other specified information
  • Can be suspended (up to 6 months) or revoked for various reasons (false information, security breaches, subscriber death, etc.)
  • Suspended/revoked certificates become invalid for use

Obligations and Liability

  • Subscribers: Must provide accurate information, safeguard private keys, and request suspension/revocation if security is compromised
  • Relying Parties: Must follow verification procedures, respect reliance limits, and use certificates only for permitted purposes
  • Certificate Providers: Liable for damages from failure to meet obligations, except for losses beyond stated reliance limits

Offenses and Penalties

  • Operating without license: 100,000-200,000 Birr fine
  • Operating with revoked/expired license: 100,000-200,000 Birr fine
  • Using suspended/revoked certificates: 20,000-50,000 Birr fine
  • Misuse of key pairs: 40,000-100,000 Birr fine
  • Various other fines for non-compliance

Dispute Resolution

  • National Crypto Council handles complaints related to licensing, renewal, and related services
  • Administrative appeals to Root Certificate Authority within 30 days
  • Court appeals available to Federal High Court

Effective Date

February 16, 2018

Comments

Leave a Reply