The Certificate Behind the Signature
Every electronic signature that carries real legal weight in India rests on a document most people never actually read: the Electronic Signature Certificate issued by a licensed Certifying Authority, vouching for who controls a given signing key and what that key is meant to be used for. Section 86 of this Act — covered in the next article in this backward-moving series — presumes things about the signature itself. Section 87 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA) goes one layer deeper — it presumes things about the certificate the signature depends on in the first place.
Get this section wrong and the mistake is easy to make in both directions: assuming the certificate proves everything about the signer, or assuming it proves nothing at all. Neither is accurate.
87. Presumption as to Electronic Signature Certificates.
The Court shall presume, unless contrary is proved, that the information listed in an Electronic Signature Certificate is correct, except for information specified as subscriber information which has not been verified, if the certificate was accepted by the subscriber.
Section 87 corresponds to Section 85C of the Indian Evidence Act, 1872 — itself not part of the original 1872 Act but inserted by the Information Technology Act, 2000, and later updated by the Information Technology (Amendment) Act, 2008 to replace "Digital Signature Certificate" with the broader "Electronic Signature Certificate" throughout. The BSA carries the wording forward unchanged, confirmed by comparing the text above against two independent sources, latestlaws.com and indianevidenceact1872.com, cross-checked against the BSA-to-IEA correspondence table.
A Rebuttable Presumption, Sharply Carved Out at One Point
Unlike Section 89's discretionary "may presume," Section 87 uses the stronger "shall presume, unless contrary is proved" — the same mandatory-but-rebuttable formula this Act reserves for information the drafters consider inherently reliable. But the section builds its own exception directly into the same sentence: information in the certificate that is expressly marked as "subscriber information which has not been verified" is carved out of the presumption entirely. A Certifying Authority sometimes includes details supplied by the applicant that it has not independently checked, and flags them as such in the certificate itself — Section 87 refuses to extend any presumption of correctness to exactly that flagged information.
| Information Type | Presumption Under Section 87 |
|---|---|
| Information verified by the Certifying Authority as part of issuance | Presumed correct, unless the contrary is proved |
| Subscriber information expressly marked as unverified | No presumption at all — must be independently proved by whoever relies on it |
Why Acceptance by the Subscriber Is the Trigger, Not Issuance
The presumption does not switch on the moment a Certifying Authority issues a certificate — it switches on only once the subscriber has "accepted" it. This tracks the structure of the Information Technology Act, 2000 itself: under Section 35, a Certifying Authority issues the certificate on application, but under the IT Act's acceptance framework, a subscriber's acceptance of a certificate is what represents to everyone relying on it that the subscriber holds the corresponding signature creation data and that all material representations in the certificate are true. Section 87 borrows that same acceptance point as its own trigger, because it is only from acceptance onward that the subscriber has taken on responsibility for the certificate's contents being accurate.
How This Connects to the Signature Itself
Read alongside Section 86 (secure electronic records and signatures, the next section in this backward-moving series), the relationship becomes clear: Section 86 presumes that a secure electronic signature was affixed by the subscriber with the intention of signing or approving the record. Section 87 presumes that the certificate identifying who that subscriber is, and what key belongs to them, contains correct information. Together, the two sections let a party relying on a digitally signed document skip separate proof of both "this signature was validly and intentionally made" and "this certificate correctly identifies who made it" — provided the record is secure and the certificate has been accepted.
A Practical Illustration
A vendor disputes a digitally signed purchase order, claiming the signature is not genuinely theirs. The buyer produces the vendor's Electronic Signature Certificate, accepted by the vendor at the time it was issued, showing the vendor's verified organisational details and public key. Section 87 lets the court presume that verified information — the vendor's identity as recorded by the Certifying Authority — is correct without further proof. But if the certificate separately lists a business address flagged by the Certifying Authority as unverified subscriber-supplied information, and that address becomes relevant to the dispute, the buyer cannot rely on Section 87 for that specific detail; it must be proved independently, exactly as the section's own carve-out requires.
Key Takeaways
- Section 87 BSA carries forward Section 85C IEA (itself an Information Technology Act, 2000 insertion, later updated in 2008) unchanged, confirmed against two independent sources.
- It creates a mandatory but rebuttable presumption ("shall presume, unless contrary is proved") that a certificate's information is correct — except information the certificate itself flags as unverified subscriber information, which is expressly carved out.
- The presumption activates only once the certificate has been accepted by the subscriber, mirroring the acceptance framework under the Information Technology Act, 2000.
- Sections 73 and 74 of the IT Act separately criminalise publishing or creating false Electronic Signature Certificates, reinforcing this evidentiary presumption with penal consequences.
- Section 87 works together with Section 86 BSA: one presumes the signature was validly made by the subscriber, the other presumes the certificate correctly identifies who that subscriber is.
Conclusion
Section 87 is a narrow but load-bearing provision — it lets courts trust the identity information behind a digital signature without demanding fresh proof every time, while still refusing to extend that trust to anything the certificate itself admits was never checked. That calibrated caution, carried over intact from the Information Technology Act-era amendments to the old Evidence Act, remains exactly as relevant under the BSA. The presumption chain continues one section further back with Section 86, covered next.