Law of the Peoples Republic of China on Electronic Signature

文章摘要 《中华人民共和国电子签名法》确立电子签名的法律效力,规范电子签名行为,保护各方合法权益。电子签名指数据电文中以电子形式所含、所附用于识别签名人身份并表明其认可内容的数据。当事人可约定使用或不使用电子签名,不得仅以电子形式否定文书效力,但婚姻、收养、继承等人身关系文书,不动产权益转让文书及公用事业服务文书除外。数据电文符合条件可视为书面形式、原件并满足保存要求,可作为证据使用。可靠电子签名与手写签名或盖章具有同等法律效力。

Contents


Chapter I General Provisions
 Chapter II Data Message
 Chapter III Electronic Signature and Certification
 Chapter IV Legal Liabilities
 Chapter V Supplementary Provisions
 
Chapter I General Provisions


 Article 1 The present Law is enacted in order to regulate the act of electronic signature, establish the legal effect of electronic signature, and maintain the lawful rights and interests of the relevant parties concerned.


 Article 2 For the purpose of this Law, the term of "Electronic Signature" refers to the data included and attached in data message in electronic form used to identify the identity of the signatory and show that the signatory has recognized the contents therein.


 For purpose of this Law, the term of "Data Message" refers to the information created, sent, received or stored by means such as electron, optics, magnetism or similar means.


 Article 3 The interested parties may stipulate to use or not to use electronic signature or data message in the contract or other documents and documentations in civil activities.


 The force adeffect of any document using electronic signature and data message as stipulated by the interested parties shall not be denied only because the document takes the form of electronic signature and data message.


 The aforesaid provisions shall not be applied to the following documents:
 1. Documents concerning personal relations such as marriage, adoption, inheritance and etc.;
 2. Documents concerning the transfer of such real estate rights and interests as land, house and etc.;
 3. Documents concerning stopping the service of public utility such as water supply, heat supply, gas supply, power supply and etc.;
 4. Other circumstances under which the electronic documents are inapplicable as prescribed by laws and administrative regulations.
 
Chapter II Data Message


 Article 4 Any data message, which can represent the contents it specifies in material form and may be picked up for reference and use at any time, shall be regarded as congruous written forms prescribed by laws and regulations.


 Article 5 Any data message meeting the following requirements shall be regarded as satisfying the requirements for the form of the original as prescribed by laws and regulations:
 1. Data message that is capable of effectively representing the contents it specifies and may be picked up for reference and use at any time; and
 2. Data message that can reliably ensure that the contents are complete and unaltered from the time when it finally comes into being. But the integrality of the data message will not be influenced by adding endorsement in the data message and the transformation of forms occurred during the course of data interchange, storage and display.


 Article 6 Any data message meeting the following requirements shall be regarded as satisfying the requirements for document preservation as prescribed by laws and regulations:
 1. Being capable of effectively representing the contents it specifies and may be picked up for reference and use at any time;
 2. The format of the data message is the same as that when it is created, sent or received, or the format is different but is able to accurately represent the contents of original creation, sending, or receiving;
 3. Being capable of identifying the addresser and addressee of the data message and the time for sending and receiving it.


 Article 7 Any data message may not be refused for being used as evidence only because it is created, sent, received or stored by ways of electron, optics, magnetism, or the similar means.


 Article 8 When making examination on the authenticity of any data message as evidence, the following factors shall be taken into consideration:
 1. The reliability of the methods for creation, storage or transmission of data message;
 2. The reliability of the methods for keeping the integrality of the contents;
 3. The reliability of the methods for identifying the addresser; and
 4. Other relevant factors.


 Article 9 Under any of the following circumstances, the data message shall be regarded as being sent by the addresser:
 1. Being sent with the authorization of the addresser;
 2. Being sent automatically by the information system of the addresser; or
 3. The consequence is proved congruous after the validation on the data message by the addressee according to the method approved by the addresser.


 Unless there are different stipulations by the interested parties on the matters prescribed in the preceding paragraph, the stipulations shall be followed.


 Article 10 In case that the receiving of any data message needs to be confirmed as prescribed by laws and administrative regulations or the stipulations of the interested parties, the receiving shall be confirmed. If an addresser has received any confirmation on the receiving from the addressee, the data message shall be regarded as having been received.


 Article 11 The time when any data message enters into a certain information system beyond the control of the addresser shall be regarded as the time for sending the data message.


 Where an addressee has appointed a given system to receive any data message, the time when the data message enters into the given system shall be regarded as the time for receiving the data message. Where no given system is appointed, the time when the data message enters into any system of the addressee for the first time shall be regarded as the time for receiving the data message.


 In case the interested parties have different stipulations on the time for sending and receiving data message, the stipulations shall be followed.


 Article 12 The main business place of the addresser shall be regarded as the place for sending data message, and the main business place of the addressee shall be regarded as the place for receiving data message. If there is no main business place, the habitual residence shall be regarded as the sending or receiving place.


 In case the interested parties have different stipulations on the place for sending or receiving data message, the stipulations shall be followed.
 
Chapter III Electronic Signature and Certification


 Article 13 Any electronic signature, simultaneously according with the following circumstances, shall be regarded as a reliable electronic signature:
 1. Where any data made by electronic signature is used for electronic signature, and it is owned exclusively by the electronic signatory;
 2. The data made by electronic signature is controlled only by the electronic signatory when signing;
 3. Any alteration on electronic signature after signing can be found out; and
 4. Any alteration on the content and the form of any data message after signing can be found out.


 The parties may also choose to use the electronic signature stipulated by themselves of reliable conditions.


 Article 14 Reliable electronic signatures shall have the same force adeffect as the hand signatures or seals.


 Article 15 The electronic signatory shall well keep the data made by electronic signature. In case that an electronic signatory realizes that the data made by electronic signature has given away official secrets or may give away official secrets, he shall notify relevant parties in time and terminate the use of the data made by electronic signature.


 Article 16 Where it is necessary for an electronic signature to be certified by a third party, the certification service shall be provided by a legally established electronic certification service provider.


 Article 17 The following conditions shall be met when providing electronic certification service:
 1. Having professional technicians and managers suited for providing electronic certification service;
 2. Having capital and business places meeting the requirements for providing electronic certification service;
 3. Having techniques and equipments up to the standard of the national safety;
 4. Having certification documents on using codes approved by the state code administration organs;
 5. Other conditions prescribed by laws and administrative regulations.


 Article 18 The applicant, who is to provide electronic certification service, shall bring forward an application to the competent department of information industry of the State Council, and submit relevant materials prescribed in Article 17 of the present Law. The competent department of information industry of the State Council shall make examination according to law after receiving the application, and make a decision on whether to give permission or not within 45 days from the date when the application is accepted after soliciting the opinions of the competent commerce department of the State Council and other relevant departments. If the permission is granted, an electronic certification exequatur shall be issued. Or else the applicant shall be notified in writing form and the reasons shall be explained.


 The applicant shall, with the electronic certification licensing certificate, go to the administrative department for industry and commerce to go through formalities for enterprise registration according to law.


 Any electronic certification service providers who have obtained the qualification of certification shall publicize their names and numbers of licenses and other information in the internet in accordance with the provisions of the competent department of information industry of the State Council.


 Article 19 The electronic certification service provider shall formulate and promulgate the electronic certification business rules according with the relevant provisions of the state, and put them on records at the competent department of information industry of the State Council.


 The electronic certification business rules shall include the scope of liabilities, the criterions of work operation, the information safeguard measures, and other matters concerned.


 Article 20 When any electronic signatory applies for electronic signature certification certificate to any electronic certification service provider, he shall provide true, complete and accurate information.


 After receiving any application for electronic signature certification certificates, the electronic certification service provider shall check the identity of the applicant and make examination on the relevant materials.


 Article 21 Any electronic signature certification certificate signed by electronic certification service providers shall be accurate and inerrant, and shall specify the following contents:
 1. Name of the electronic certification service provider;
 2. Name of the certificate holder;
 3. Serial number of the certificate;
 4. Period of validity of the certificate;
 5. Electronic signature validation data of the certificate holder;
 6. Electronic signature of the electronic certification service provider; and
 7. Other contents prescribed by the competent department of information industry of the State Council.


 Article 22 The electronic certification service provider shall ensure that the contents of the electronic signature certification certificates are complete and accurate within the period of validity, and ensure that the parties depending on the electronic signature are able to prove or know the contents specified in the electronic certification certificate and other relevant matters concerned.


 Article 23 Where any electronic certification service provider intends to suspend or terminate the electronic certification service, it shall notify relevant parties concerned of the carrying-on of the operation and other relevant matters 90 days before the suspension or termination of the service.


 Where any electronic certification service provider intends to suspend or terminate the electronic certification service, it shall report to the competent department of information industry of the State Council 60 days before the suspension or termination of the service, and negotiates with other electronic certification service providers about the carrying-on of the operation, so as to make proper arrangements.


 Where any electronic certification service provider fails to reach an agreement on the carrying-on of the operation with other electronic certification service providers, it shall apply to the competent department of information industry of the State Council for arranging other electronic certification service providers to carry on its operation.


 Where any electronic certification service provider is revoked of the electronic certification licensing certificate, the matters of carrying on its operation shall be handled according to the provisions of the competent department of information industry of the State Council.


 Article 24 The electronic certification service providers shall well keep the information related to certification. The time limit for keeping the information shall be at least 5 years after the invalidation of the electronic signature certification certificates.


 Article 25 The competent department of information industry of the State Council shall formulate concrete measures for the administration of electronic certification service industry in accordance with the present Law and conduct supervision over electronic certification service providers according to law.


 Article 26 Upon the approval of the competent department of information industry of the State Council, and in light of the relevant agreement or the principle of reciprocity, any electronic signature certification certificate issued overseas by any electronic certification service provider outside the territory of the People's Republic of China shall have the same force adeffect as the electronic certification certificates issued by the electronic certification service providers established according to the present Law.
 
Chapter IV Legal Liabilities


 Article 27 The electronic certification service provides shall undertake compensation liabilities, in case that he knows that data made by electronic signature has given away official secrets or may have given away official secrets but fails to notify the relevant interested parties concerned and terminate the use of the data made by electronic signature, or fails to provide truthful, complete and accurate information to the electronic service providers, or has any other faults resulting in the damage to the party depending on electronic signature .


 Article 28 The electronic certification service provider shall undertake compensation liabilities, if any electronic signatory or any party depending on electronic signature suffers losses due to engaging in civil activities based on the electronic signature certification service provided by the electronic certification service provider and he cannot prove that he has no faults.


 Article 29 Where anyone provides electronic certification service without approval, the competent department of information industry of the State Council shall order it to stop the illegal act; where there are illegal gains, they shall be confiscated; and if the illegal gains are more than RMB 300 thousand Yuan, it shall be given a fine of one time to three times of the illegal gains; if there are no illegal gains or the illegal gains are less than RMB 300 thousand Yuan, it shall be given a fine of RMB 100 thousand Yuan to RMB 300 thousand Yuan.


 Article 30 Where any electronic certification service provider suspends or terminates the electronic certification service, but fails to report to the competent department of information industry of the State Council within 60 days before the suspension or termination of the service, the competent department of information industry of the State Council shall penalize the person directly in charge with a fine of RMB 10 thousand Yuan up to RMB 50 thousand.


 Article 31 Where any electronic certification service provider does not comply with the certification operation rules, fails to well keep the information related to the certification, or has any other illegal acts, the competent department of information industry of the State Council may charge it to correct within a prescribed time limit; if the electronic certification service provider fails to correct within the time limit, its electronic certification licensing certificate shall be revoked and the person directly in charge and other persons directly liable shall be banned from undertaking electronic certification service within 10 years; and if the electronic certification licensing certificate is revoked, a public notice on this shall be made, and the administrative administrations for industry and commerce shall be notified.


 Article 32 Where anyone forges, falsely uses or embezzles electronic signature of others and commits a crime, he shall be subject to criminal liability according to law. Where that causes damage to others, he shall undertake civil liabilities.


 Article 33 Where any staff member of the department in charge of the work for the supervision over electronic certification service, according to the present Law, fails to perform duties of administration approval and supervision, he shall be given an administrative punishment according to law. Where a crime is constituted, he shall be subject to criminal liabilities.
 
Chapter V Supplementary Provisions


 Article 34 The words used in the present Law shall have meanings as follows:
 1. The "Electronic Signatory" shall refer to the person who holds data made by electronic signature and implements electronic signature in his own identity or on behalf of the person he represents;
 2. The "Party Depending on Electronic Signature" shall refer to the person who engages in relevant activities based on his trust in any electronic signature certification certificate or electronic signature;
 3. The "Electronic Signature Certification Certificate" shall refer to the data message or other electronic records that can prove that any electronic signatory has some relations with the data made by electronic signature;
 4. The "Data Made by Electronic Signature" shall refer to such data as characters, coding and etc., which are used in the course of electronic signature and can reliably connect electronic signature with electronic signatory; and
 5. The "Electronic Signature Validation Data" shall refer to the data used to validate electronic signature, including codes, passwords, arithmetic or public keys and etc..


 Article 35 The State Council or the departments prescribed by the State Council may, in accordance with the present Law, formulate concrete measures for the use of electronic signature and data message in government affairs and other social activities.


 Article 36 The present Law shall go into effect as of April 1, 2005.

最后编辑于:2018-09-01 11:02

杨春宝一级律师简介

杨春宝一级律师,大成上海高级合伙人、资本市场部主任、国资基金研究中心主任,大成中国区私募基金专业带头人、科技与文化法律研究中心联合牵头人。执业30余年,长期从事私募基金、投融资、并购重组法律服务,尤其对对赌研究颇深且具有非常丰富的实战经验,并专注于金融机构股权投资业务。2004年起多次入选The Legal 500"私募基金"和"公司与商业"等境内外各类律师榜单,代理的中国法院首例适用外国法律审理外国公司的董事损害小股东权益纠纷案入选上海高院发布的《上海法院域外法查明典型案例》和威科先行"要案头条"。入选上海涉外法律人才库、上海市司法局鼎新法治人才库、上海国有企业改制法律顾问团,具有上市公司独立董事任职资格,系多家知名高校的兼职教授或兼职研究生导师及上海市商务委跨国经营人才培训班讲师。出版《私募股权投资基金风险防控操作实务》等16本投融资法律专著。了解更多

常见法律问题

什么是可靠电子签名?其法律效力如何?

可靠电子签名须同时满足四项条件:一是电子签名制作数据专属于签名人所有;二是签署时电子签名制作数据仅由签名人控制;三是签署后对电子签名的任何改动能被发现;四是签署后对数据电文内容和形式的任何改动能被发现。当事人也可以选择使用符合其约定的可靠条件的电子签名。满足上述条件的可靠电子签名与手写签名或者盖章具有同等法律效力,这意味着经可靠电子签名签署的电子合同、电子单证等文书,在诉讼中可直接作为认定事实的依据。实务中,企业应选择具备资质的电子认证服务机构提供的服务,采用可信时间戳、哈希值校验等技术手段固定签署过程,确保签名数据由签名人专有并控制。风险提示:若签名制作数据发生泄露或被他人冒用,签名人应及时通知有关各方并终止使用该数据,否则可能因未妥善保管而承担不利后果;发生争议时,主张签名有效的一方需就签名的可靠性承担举证责任,故完整的签署流程存证至关重要。

哪些文书不适用电子签名和数据电文?

依据电子签名法的规定,当事人可以约定在民事活动中使用或不使用电子签名、数据电文,且不得仅以采用电子签名、数据电文的形式为由否定文书的法律效力,但下列文书不适用该规则:一是涉及婚姻、收养、继承等人身关系的文书;二是涉及土地、房屋等不动产权益转让的文书;三是涉及停止供水、供热、供气、供电等公用事业服务的文书;四是法律、行政法规规定的不适用电子文书的其他情形。上述排除情形的核心考量在于人身关系变更具有强烈的人身属性,不动产转让价值重大且涉及登记公示,公用事业服务关系基本民生保障,故立法要求采用传统书面形式以审慎保护当事人权益。实务操作中,企业签署上述类型文件时仍应采用纸质书面形式并配合手写签名或盖章,否则可能面临文书形式瑕疵甚至效力争议的法律风险。需要注意的是,排除范围应从严把握,一般商业合同、电子订单、电子保单等均可依法采用电子签名,但涉及不动产网签备案等另有特殊规定的,还应遵循相关主管部门的具体要求。

数据电文作为证据使用时如何审查其真实性?

数据电文不得仅因为以电子、光学、磁或者类似手段生成、发送、接收或者储存而被拒绝作为证据使用,这确立了电子证据的合法地位。审查数据电文真实性时,应综合考虑四方面因素:一是生成、储存或者传递数据电文方法的可靠性;二是保持内容完整性方法的可靠性,即数据电文自最终形成时起内容是否保持完整、未被更改,但添加背书以及数据电文在传递、储存和显示中发生的形式变化不影响其完整性;三是用以鉴别发件人方法的可靠性;四是其他相关因素。此外,数据电文在经发件人授权发送、由发件人信息系统自动发送、或收件人按照发件人认可的方法验证结果相符等情形下,视为发件人发送。实务建议:企业应通过可信第三方存证平台、区块链存证、公证等方式固定电子证据,完整保留系统日志、时间戳等原始记录;发送重要数据电文时可要求对方确认收讫,以确认收讫作为收到数据电文的证明。风险提示:仅有截图而无原始载体核对的电子数据易被质疑真实性,举证时应提供原始存储介质或经权威机构固定的证据形式。

以上内容仅供参考,不构成法律意见。如需专业法律服务,请联系杨春宝一级律师:chambers.yang@dentons.cn

  • 本站声明:本站所载之法律论文、法律评论、案例、法律咨询等,除非另有注明,著作权人均为站长杨春宝高级律师本人。欢迎其他网站链接,但是,未经书面许可,不得擅自摘编、转载。引用及经许可转载时均应注明作者和出处"法律桥",并链接本站。本站网址:https://lawbridge.org/。
  •  
  •         本站所有内容(包括法律咨询、法律法规)仅供参考,不构成法律意见,本站不对资料的完整性和时效性负责。您在处理具体法律事务时,请洽询有资质的律师。本站将努力为广大网友提供更好的服务,但不对本站提供的任何免费服务作出正式的承诺。本站所载投稿文章,其言论不代表本站观点,如需使用,请与原作者联系,版权归原作者所有。

发表回复