﻿<?xml version="1.0" encoding="utf-8"?><Regulation lims:pit-date="2011-03-10" hasPreviousVersion="true" lims:lastAmendedDate="2011-03-10" lims:current-date="2019-06-21" lims:inforce-start-date="2006-03-22" lims:fid="719293" lims:id="719293" regulation-type="SOR" xml:lang="en" xmlns:lims="http://justice.gc.ca/lims"><Identification lims:inforce-start-date="2006-03-22" lims:fid="719294" lims:id="719294"><InstrumentNumber>SOR/2005-30</InstrumentNumber><RegistrationDate><Date><YYYY>2005</YYYY><MM>2</MM><DD>1</DD></Date></RegistrationDate><ConsolidationDate lims:inforce-start-date="2006-03-22"><Date><YYYY>2019</YYYY><MM>6</MM><DD>22</DD></Date></ConsolidationDate><EnablingAuthority lims:inforce-start-date="2006-03-22" lims:fid="719296" lims:id="719296"><XRefExternal reference-type="act" link="P-8.6">PERSONAL INFORMATION PROTECTION AND ELECTRONIC DOCUMENTS ACT</XRefExternal><XRefExternal reference-type="act" link="C-5">CANADA EVIDENCE ACT</XRefExternal></EnablingAuthority><LongTitle lims:inforce-start-date="2006-03-22" lims:fid="719297" lims:id="719297">Secure Electronic Signature Regulations</LongTitle><RegulationMakerOrder><RegulationMaker>P.C.</RegulationMaker><OrderNumber>2005-57</OrderNumber><Date><YYYY>2005</YYYY><MM>2</MM><DD>1</DD></Date></RegulationMakerOrder></Identification><Order lims:inforce-start-date="2006-03-22" lims:fid="719298" lims:id="719298"><Provision lims:inforce-start-date="2006-03-22" lims:fid="719299" lims:id="719299" language-align="yes" bottommarginspacing="" format-ref="indent-0-0" list-item="no"><Text>Whereas the Governor in Council is satisfied that the technology or process prescribed in the annexed <XRefExternal reference-type="regulation" link="SOR-2005-30">Secure Electronic Signature Regulations</XRefExternal> can be proved to meet the requirements set out in paragraphs 48(2)(a) to (d) of the <XRefExternal reference-type="act" link="P-8.6">Personal Information Protection and Electronic Documents Act</XRefExternal><FootnoteRef idref="footnotea_e">a</FootnoteRef>;</Text></Provision><Provision lims:inforce-start-date="2006-03-22" lims:fid="719300" lims:id="719300" bottommarginspacing="" format-ref="indent-0-0" language-align="yes" list-item="no"><Text>Therefore, Her Excellency the Governor General in Council, on the recommendation of the Treasury Board, pursuant to subsection 48(1) of the <XRefExternal reference-type="act" link="P-8.6">Personal Information Protection and Electronic Documents Act</XRefExternal><FootnoteRef>a</FootnoteRef> and paragraph 31.4(a)<FootnoteRef idref="footnoteb_e">b</FootnoteRef> of the <XRefExternal reference-type="act" link="C-5">Canada Evidence Act</XRefExternal>, hereby makes the annexed <XRefExternal reference-type="regulation" link="SOR-2005-30">Secure Electronic Signature Regulations</XRefExternal>.</Text></Provision><Footnote id="footnotea_e" placement="page" status="official"><Label>a</Label><Text>S.C.  2000, c. 5</Text></Footnote><Footnote id="footnoteb_e" placement="page" status="official"><Label>b</Label><Text>S.C.  2000, c. 5, s. 56</Text></Footnote></Order><Body lims:inforce-start-date="2006-03-22" lims:fid="719301" lims:id="719301"><Heading lims:inforce-start-date="2006-03-22" lims:fid="719302" lims:id="719302" level="1"><TitleText>Interpretation</TitleText></Heading><Section lims:inforce-start-date="2011-03-10" lims:lastAmendedDate="2011-03-10" lims:fid="719303" lims:id="719303"><Label>1</Label><Text>The following definitions apply in these Regulations.</Text><Definition lims:inforce-start-date="2011-03-10" lims:fid="719304" lims:id="719304" generate-in-text="no"><Text><DefinedTermEn>Act</DefinedTermEn> means the <XRefExternal reference-type="act" link="P-8.6">Personal Information Protection and Electronic Documents Act</XRefExternal>. (<DefinedTermFr>Loi</DefinedTermFr>)</Text></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719305" lims:id="719305" generate-in-text="no"><Text><DefinedTermEn>asymmetric cryptography</DefinedTermEn> means a cryptographic system that relies on key pairs. (<DefinedTermFr>système de chiffrement à clé publique</DefinedTermFr>)</Text></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719306" lims:id="719306" generate-in-text="no"><Text><DefinedTermEn>certification authority</DefinedTermEn> means a person or entity that issues digital signature certificates and that is listed as such on the website of the Treasury Board Secretariat. (<DefinedTermFr>autorité de certification</DefinedTermFr>)</Text></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719307" lims:id="719307" generate-in-text="no"><Text><DefinedTermEn>digital signature certificate</DefinedTermEn>, in respect of a person, means an electronic document that</Text><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719308" lims:id="719308"><Label>(a)</Label><Text>identifies the certification authority that issued it and is digitally signed by that certification authority;</Text></Paragraph><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719309" lims:id="719309"><Label>(b)</Label><Text>identifies, or can be used to identify, the person; and</Text></Paragraph><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719310" lims:id="719310"><Label>(c)</Label><Text>contains the person's public key. (<DefinedTermFr>certificat de signature numérique</DefinedTermFr>)</Text></Paragraph></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719311" lims:id="719311" generate-in-text="no"><Text><DefinedTermEn>entity</DefinedTermEn> includes any federal department, branch, office, board, agency, commission, corporation or body for the administration of the affairs of which a minister of the Crown is accountable to Parliament. (<DefinedTermFr>entité</DefinedTermFr>)</Text></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719312" lims:id="719312" generate-in-text="no"><Text><DefinedTermEn>hash function</DefinedTermEn> means an electronic one-way mathematical process that converts data contained in an electronic document into a message digest that is unique to that data in a way that, were that data changed, it would, on conversion, result in a changed message digest. (<DefinedTermFr>fonction de hachage</DefinedTermFr>)</Text></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719313" lims:id="719313" generate-in-text="no"><Text><DefinedTermEn>key pair</DefinedTermEn> means a pair of keys held by or for a person that includes a private key and a public key that are mathematically related to, but different from, each other. (<DefinedTermFr>biclé</DefinedTermFr>)</Text></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719314" lims:id="719314" generate-in-text="no"><Text><DefinedTermEn>private key</DefinedTermEn> means a string of data that</Text><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719315" lims:id="719315"><Label>(a)</Label><Text>is used in asymmetric cryptography to encrypt data contained in an electronic document; and</Text></Paragraph><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719316" lims:id="719316"><Label>(b)</Label><Text>is unique to the person who is identified in, or can be identified through, a digital signature certificate and corresponds only to the public key in that certificate. (<DefinedTermFr>clé privée</DefinedTermFr>)</Text></Paragraph></Definition><Definition lims:inforce-start-date="2011-03-10" lims:fid="719317" lims:id="719317" generate-in-text="no"><Text><DefinedTermEn>public key</DefinedTermEn> means a string of data contained in a digital signature certificate that</Text><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719318" lims:id="719318"><Label>(a)</Label><Text>is used in asymmetric cryptography to decrypt data contained in an electronic document that was encrypted through the application of the private key in the key pair; and</Text></Paragraph><Paragraph lims:inforce-start-date="2011-03-10" lims:fid="719319" lims:id="719319"><Label>(b)</Label><Text>corresponds only to the private key in the key pair. (<DefinedTermFr>clé publique</DefinedTermFr>)</Text></Paragraph></Definition><HistoricalNote><HistoricalNoteSubItem lims:inforce-start-date="2011-03-10" lims:fid="719321" lims:id="719321">SOR/2011-71, s. 1(E)</HistoricalNoteSubItem></HistoricalNote></Section><Heading lims:inforce-start-date="2006-03-22" lims:fid="719322" lims:id="719322" level="1"><TitleText>Technology or Process</TitleText></Heading><Section lims:inforce-start-date="2006-03-22" lims:lastAmendedDate="2006-03-22" lims:fid="719323" lims:id="719323"><Label>2</Label><Text>For the purposes of the definition <DefinedTermEn>secure electronic signature</DefinedTermEn> in subsection 31(1) of the Act, a secure electronic signature in respect of data contained in an electronic document is a digital signature that results from completion of the following consecutive operations:</Text><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719324" lims:id="719324"><Label>(a)</Label><Text>application of the hash function to the data to generate a message digest;</Text></Paragraph><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719325" lims:id="719325"><Label>(b)</Label><Text>application of a private key to encrypt the message digest;</Text></Paragraph><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719326" lims:id="719326"><Label>(c)</Label><Text>incorporation in, attachment to, or association with the electronic document of the encrypted message digest;</Text></Paragraph><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719327" lims:id="719327"><Label>(d)</Label><Text>transmission of the electronic document and encrypted message digest together with either</Text><Subparagraph lims:inforce-start-date="2006-03-22" lims:fid="719328" lims:id="719328"><Label>(i)</Label><Text>a digital signature certificate, or</Text></Subparagraph><Subparagraph lims:inforce-start-date="2006-03-22" lims:fid="719329" lims:id="719329"><Label>(ii)</Label><Text>a means of access to a digital signature certificate; and</Text></Subparagraph></Paragraph><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719330" lims:id="719330"><Label>(e)</Label><Text>after receipt of the electronic document, the encrypted message digest and the digital signature certificate or the means of access to the digital signature certificate,</Text><Subparagraph lims:inforce-start-date="2006-03-22" lims:fid="719331" lims:id="719331"><Label>(i)</Label><Text>application of the public key contained in the digital signature certificate to decrypt the encrypted message digest and produce the message digest referred to in paragraph (a),</Text></Subparagraph><Subparagraph lims:inforce-start-date="2006-03-22" lims:fid="719332" lims:id="719332"><Label>(ii)</Label><Text>application of the hash function to the data contained in the electronic document to generate a new message digest,</Text></Subparagraph><Subparagraph lims:inforce-start-date="2006-03-22" lims:fid="719333" lims:id="719333"><Label>(iii)</Label><Text>verification that, on comparison, the message digests referred to in paragraph (a) and subparagraph (ii) are identical, and</Text></Subparagraph><Subparagraph lims:inforce-start-date="2006-03-22" lims:fid="719334" lims:id="719334"><Label>(iv)</Label><Text>verification that the digital signature certificate is valid in accordance with section 3.</Text></Subparagraph></Paragraph></Section><Section lims:inforce-start-date="2006-03-22" lims:lastAmendedDate="2006-03-22" lims:fid="719335" lims:id="719335"><Label>3</Label><Subsection lims:inforce-start-date="2006-03-22" lims:fid="719336" lims:id="719336"><Label>(1)</Label><Text>A digital signature certificate is valid if, at the time when the data contained in an electronic document is digitally signed in accordance with section 2, the certificate</Text><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719337" lims:id="719337"><Label>(a)</Label><Text>is readable or perceivable by any person or entity who is entitled to have access to the digital signature certificate; and</Text></Paragraph><Paragraph lims:inforce-start-date="2006-03-22" lims:fid="719338" lims:id="719338"><Label>(b)</Label><Text>has not expired or been revoked.</Text></Paragraph></Subsection><Subsection lims:inforce-start-date="2006-03-22" lims:fid="719339" lims:id="719339"><Label>(2)</Label><Text>In addition to the requirements for validity set out in subsection (1), when the digital signature certificate is supported by other digital signature certificates, in order for the digital signature certificate to be valid, the supporting certificates must also be valid in accordance with that subsection.</Text></Subsection></Section><Section lims:inforce-start-date="2006-03-22" lims:lastAmendedDate="2006-03-22" lims:fid="719340" lims:id="719340"><Label>4</Label><Subsection lims:inforce-start-date="2006-03-22" lims:fid="719341" lims:id="719341"><Label>(1)</Label><Text>Before recognizing a person or entity as a certification authority, the President of the Treasury Board must verify that the person or entity has the capacity to issue digital signature certificates in a secure and reliable manner within the context of these Regulations and paragraphs 48(2)(a) to (d) of the Act.</Text></Subsection><Subsection lims:inforce-start-date="2006-03-22" lims:fid="719342" lims:id="719342"><Label>(2)</Label><Text>Every person or entity that is recognized as a certification authority by the President of the Treasury Board shall be listed on the website of the Treasury Board Secretariat.</Text></Subsection></Section><Heading lims:inforce-start-date="2006-03-22" lims:fid="719343" lims:id="719343" level="1"><TitleText>Presumption</TitleText></Heading><Section lims:inforce-start-date="2006-03-22" lims:lastAmendedDate="2006-03-22" lims:fid="719344" lims:id="719344"><Label>5</Label><Text>When the technology or process set out in section 2 is used in respect of data contained in an electronic document, that data is presumed, in the absence of evidence to the contrary, to have been signed by the person who is identified in, or can be identified through, the digital signature certificate.</Text></Section><Heading lims:inforce-start-date="2006-03-22" lims:fid="719345" lims:id="719345" level="1"><TitleText>Coming into Force</TitleText></Heading><Section lims:inforce-start-date="2006-03-22" lims:lastAmendedDate="2006-03-22" lims:fid="719346" lims:id="719346" type="transitional"><Label>6</Label><Text>These Regulations come into force on the day on which they are registered.</Text></Section></Body></Regulation>