The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق
Read the stored legal text, review its version and status evidence, or ask LexChat a question grounded in exact provisions.
- Jurisdiction
- Qatar
- Instrument
- Regulation
- Version
- Undated source snapshot
- Language
- ar
- Official source
- View official record ↗
Citation provenance: source:global:stored-legal-sources · schema StatuteEnrichmentPublicV1.
Statute overview
About this statute
This page preserves the statute’s identified version, provision structure, official source link, and stored legal text for reading and research.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق
Showing 2 of 2
Part document.segment-1
The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق — segment 1
- document.segment-1 Verify source ↗
The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق — segment 1
The provisions of the attached bylaw on the Accreditation of Foreign Certification Certificates and the Regulation of the Work of Certification Service Providers shall come into force. All competent authorities, each within its jurisdiction, shall implement this resolution which shall be published in the Official Gazette . In the application of the provisions of this bylaw the following words and expressions shall have the meanings assigned to each, unless the context requires otherwise: “State” means the State of Qatar. “The Supreme Council” means the Supreme Council of Information and Communication Technology. “The Board” means the Board of Directors of the Supreme Council. “General Secretariat” means the General Secretariat of the Supreme Council. “Competent Department” means the concerned administrative unit in the General Secretariat. “Committee” means the Grievance and Disputes Settlement Committee referred to in Article 64 of the Law. “The Law” means the Electronic Transactions and Commerce Law promulgated by Decree Law No. 16 of 2010. “Person” means a natural or juristic person. “Electronic signature” means the inscription affixed to a data message in the form of letters, numbers, symbols or tokens with a unique feature used to identify the signatory and distinguish him from others for the purpose of indicating the signatory's approval of the data message. “Signature-creation data” means information or symbols or special encryption keys used by the signatory in the creation of the electronic signature. “Signatory” means the person legally entitled to access signature creation data and to act personally or on behalf of a person in using such information for the creation of the electronic signature; “Certification service provider” means a person licensed to maintain an infrastructure of public keys, to issue certification certificates and to provide services related to electronic signatures; “Certification certificate” means a document issued by a certification service provider that affirms the validity of the link between a signatory and the signature creation data. “Encryption” means the use of uncommon symbols or signs that make the information intended to be forwarded or sent incomprehensible to third parties, or the use of symbols or signs without which the information will not be accessible. “Certified person” means the person who acts upon a certification certificate or electronic signature. “Business location” means a non-transitory establishment or facility used for the provision of certification services. “Entrusted employee” means any employee working for the certification service provider who is assigned to undertake or assist in undertaking any of the functions, competencies or responsibilities of the certification service provider in accordance with the provisions of the Law and this bylaw. “Reliable” means that the systems, procedures, operations, human resources, products and services shall perform properly and in a consistent and reliable manner. “Consumer” means a person acting for purposes other than those related to his trade, profession or business. Unless licensed by the General Secretariat, the performance of any of the certification service providers' work is prohibited, including: Maintaining an infrastructure for public keys. Providing services related to electronic signatures. Issuing electronic certification certificates. Any person interested in the work of providing certification services shall apply to the Competent Department by submitting an application on the prescribed form and shall attach the following documents therewith, as the case may be: Memorandum and articles of association pursuant to the State's applicable legislation. The Commercial Register or the commercial license. The organizational structure of the company. Title deed or lease contract. Accredited auditors' report on the company's financial status for the last two years, or for the duration as from its establishment until the date of submitting the application, whichever is more recent. Proof of payment of due fees. A written acknowledgement that the business location satisfies the technical standards required by the Law and this bylaw. A written acknowledgement that all entrusted employees fulfil the requirements for the provision of certification services pursuant to the Law and this bylaw, as well as a detailed statement and supporting documents regarding their qualifications and experience in the field of certification services. Technical specifications of equipment and the adopted certification systems accredited for the provision of certification services; accompanied with an approved graphic illustration thereof. A plan for the service provider's business location and a precise description of the adopted safety measures for its security. A comprehensive economic feasibility study for the project to be established. The concerned department may, within thirty (30) days from the date of submitting the application, request the license applicant to provide any information, data or documents it deems necessary, as the case may be, in the form and the manner and at the time as may be specified by the concerned department. The license shall be valid for five (5) years effective from the date of its issuance, and may be renewed for similar period(s) pursuant to the terms, conditions and controls set forth in the Law and this bylaw. Subject to the provisions stipulated in Article 3 of this bylaw, the certification service provider shall apply for a license renewal at least three (3) months prior to the expiration of the valid license. The applicant for a license or license renewal shall pay the prescribed fees pursuant to the annex attached to this bylaw. Where the application is rejected or withdrawn by the applicant before a decision is taken thereon, or upon the cancellation or suspension of the license after being issued, such fees shall not be refunded unless the General Secretariat otherwise decides. The concerned department shall examine the application for license issuance or renewal and supporting documents in order to ensure the fulfillment of all necessary terms, conditions, specifications and standards as set out in the Law and this bylaw. The General Secretariat shall, within thirty (30) days from the date of receiving the application, or from the date of fulfillment of all necessary terms, conditions, specifications and standards, issue a decision to grant or renew the license, or to reject the application. The General Secretariat shall notify the applicant of its decision in writing at the address affixed to the application. The General Secretariat shall provide reasons for its decision to reject the application. The lapse of the aforesaid 30-day period without a decision shall be considered an implied rejection of the application. The concerned persons may appeal against such decision to the Committee within thirty (30) days from the date of their being notified thereof. Where the grant of a license is approved, the concerned department shall record and maintain the licensee's data in a special register called “The Accredited Certification Service Providers Register”. The license shall include the following data: Name of the provider of the certification service. Address of the certification service provider's place of business. License number, issue date, validity and expiry date. Any conditions, controls, provisions or restrictions imposed by the General Secretariat pursuant to the provisions of the Law and this bylaw. The following requirements shall be met for a license or license renewal: The applicant shall have a commercial register or commercial license. The applicant shall be resident in the State. If a juristic person, the applicant may be a branch of a certification service provider established outside the State. The applicant shall prove his solvency by producing evidence of financial resources of at least five million Qatari Riyal (QAR 5,000,000) The applicant shall carry insurance against any potential financial loss pursuant to the laws, systems and legislation applicable in the State. Neither the applicant nor any of his employees shall be an owner or shareholder in any company considered by the General Secretariat as having the potential to reduce or limit fair competition. The applicant shall be of good reputation and conduct and shall not have been convicted of a crime involving a breach of honour or trust; unless he has been rehabilitated. The abovementioned requirements shall be maintained by the certification service provider during the validity of the license. In all cases, the applicant shall comply with all rules, conditions, controls, standards, decisions, procedures, instructions and specifications issued by the Supreme Council from time to time pursuant to the provisions of the Law, this bylaw and other legislation related to the work of certification service providers. 1. The certification service provider shall be subject to all inspection and audit processes as required pursuant to the provisions of the Law and this bylaw, according to the method, manner and time to be determined by the General Secretariat. The certification service provider shall submit any documents, data, papers or information required for the inspection and audit processes, and shall respond to any questions or inquiries raised by inspectors or auditors to enable them to accomplish their assigned duties. Inspection and audit processes shall be carried out in the following cases: Upon submitting the application for a license for the first time. Every two years from the license issue date. Upon submitting a license renewal application. At any other time as may be determined by the General Secretariat at its sole discretion. Inspectors or auditors shall verify the following issues: Protection and planning policy. Physical security (access perimeters, controls, data centre). Information Communication Technology infrastructure (network and systems). Electronic storage capacity/Information/Data Repositories. Certification services quality management system (certificates lifecycle management, delivery, issuance, etc). Availability of electronic certification practice statement and compliance with policies and regulations. Compliance with the guidelines and technical requirements issued by the General Secretariat. Agreements concluded with authorized signatories and other certification service providers. Compliance with the license terms. Compliance with the provisions of the Law and this bylaw. The certification service provider acts in accordance with the data it submits in relation to practicing its business. Any other activities undertaken by the certification service provider. The auditor or inspector shall prepare a report including the results/findings of his work and shall submit it to the concerned department within fifteen (15) days from the date of completing the inspection or audit process. Where it is proved in the inspection or audit report that a certification service provider has not met the terms and conditions related to its business pursuant to the provisions of the Law and this bylaw, the General Secretariat may reject the application for license issue or renewal, or suspend such license, as the case may be The technical audit entity must be registered in the State and must have no financial, legal or other relationship with the certification service provider. The General Secretariat shall ensure that the technical auditor meets the following requirements: Sufficient familiarity with the provisions of the Law and this bylaw as well as all guidelines, controls, standards and instructions issued by the Supreme Council in relation to certification services. Accredited by an entity specialized in technical inspection. Holds a Certified Information Systems Auditor (CISA) certificate, Certified Information Technology Professional (CPA.CITP) certificate, Certified Internal Auditor (CIA) certificate or an accredited Information Security Auditor certificate. Able to conduct technical audits in compliance with ISO 27000 standards, particularly ISO (27001:2005) regarding information systems, security technologies and information systems management, as well as ISO (272002) regarding codes of practicing information security management. Sufficient experience in the fields of electronic signatures, electronic certification certificates, electronic programs, information security tools and technology, security and financial reviews rules and specialized audit technologies. In performing its work, the certification service provider shall abide by all terms, controls and conditions pertinent to such work as set out in the Law and this bylaw; particularly the following: Adhering to technical standards approved by the General Secretariat and enclosed with this decision, including procedures, systems and processes of encryption, and issuing electronic signatures and electronic certification certificates. These standards may be amended by the General Secretariat from time to time, provided that the certification service provider is advised of such amendments. Taking any action necessary to ensure that all systems, processes, procedures, employees, apparatus, equipment, products and services meet the approved controls, standards and requirements based on the ISO standards (27000) and the decisions, instructions and guidelines issued by the General Secretariat. In this respect, the certification service provider shall submit a report to the General Secretariat on such compliance upon submitting an application for the issue or renewal of a license. Using approved and reliable systems and measures in all its activities and processes, and adopting the utmost degree of care and diligence in performing all activities efficiently, honestly and reliably. Taking any action necessary to ensure compliance with all terms, requirements and standards required by any government or semi-governmental body to which the certification service provider provides services within the framework of its business. Keeping reliable, complete and accurate registers for all processes of issuing, renewing, suspending or cancelling certification certificates. Allowing registers to be continuously accessible for electronic review by the concerned parties by using regular precautionary backup, and taking all necessary actions and employing all sufficient and appropriate means to protect data from any unauthorized alteration. Meeting all safety and security standards, requirements and terms at the certification service provider's place of business and in the certification system by using server and storage unit technology in such a manner that guarantees continuity of business upon the occurrence of a failure or malfunction of any apparatus. Using reliable means for issuing, delivering and storing certificates, and taking sufficient and appropriate measures to protect certificates against fraud, forgery, tampering, distortion, confidentiality violation or illegal or unauthorized access. Providing physical protection for the place of business and the certification system against tampering or illegal or unauthorized access. Ensuring that the compensation received by the certification service provider against the services and works it provides to clients is reasonable and appropriate to the nature and type of such services, and consistent with the best international and regional practices. The Supreme Council shall have the right to review such compensation from time to time. The certification service provider shall, in providing electronic signature support services, act according to the data it provides to the concerned department in respect of practicing its business, and shall particularly comply with the following: Preparing, reviewing, auditing and updating the data on a regular basis and maintaining a copy thereof in its database and on its website in accordance with the related controls and standards set out in the Law and this bylaw. Presenting an updated copy of such data upon submitting an application for issuing or renewing the license. Registering all changes which may occur to such data promptly upon their occurrence, and retaining a copy thereof in its database and on its website, in addition to advising the concerned department in writing of any changes which occur to such data within fifteen (15) days of such occurrence. 1. The certification service provider shall use encryption or any other technology as a means for protecting electronic transactions for the purpose of maintaining confidentiality of information and data, identifying the creator's personality and preventing third parties from accessing information or messages, intercepting them or preventing the respective addressees from receiving, distorting or modifying them by deletion or addition. The certification service provider shall have a well-defined key management process which shall include a dedicated key ceremony. The certification service provider shall use one or more of the following methods, as the case may be, for protecting the certification system or the information systems: 1. Public key encryption. 2. Access control mechanisms. 3. Firewalls and network security filtering devices. 4. Information filters. 5. Blocking denial set. 6. Data encryption technologies. 7. Backup/recovery (procedures) protection measures. 8. Malware protection mechanisms (software, hardware) 9. Any reliable and trustworthy method or means of technology related to preventing security penetration attempts as required or allowed by the concerned department. The certification service provider shall keep all registers related to performance of its work in accordance with the standards and controls set out in the Law and this bylaw, and shall particularly adhere to the following: Keeping registers in hardcopy and electronic copy or in any other appropriate form required by the concerned department, provided that the registers are accurate, complete, legible, accessible and usable by concerned parties. Providing means that enable concerned parties to use the registers in a timely and appropriate manner. Preparing an archive for the purpose of classifying, storing, keeping, copying and archiving all registers and files related to the certification service provider's work, as well as the data, information or certificates associated therewith. The certification service provider shall have mechanisms available for accessing such archives for a period not less than seven (7) years and shall ensure compliance with all related requirements, controls and technical standards. The archive shall particularly contain the data related to certification certificates, including the identification process used in the event that a person requests a certification certificate from the certification service provider, the double symbols issuance process, the alternative technical processes used for the purpose of providing electronic certification, electronic information management, information systems, and place of business and network facilities of the certification service provider. The certification service provider shall have an electronic storage space on the internet to enable it to perform its work, and such storage space shall have the following features: Continuously accessible to the public, with disconnection of any service related to the storage space, whether scheduled or non-scheduled, not exceeding one hour at any time; and provided that the service availability percentage does not drop below 99.95 percent per annum. Sufficient, complete and accurate information about the following: Certification certificates and all data, information, documents or papers related thereto. Lists pertaining to suspending or cancelling certification certificates. A complete archive of the certification certificates that have been stopped, cancelled, suspended, or which have expired, for a period not less than seven (7) years. Any information, data, documents, clarifications, prerequisites, instructions, standards or requirements which the Supreme Council may require. The certification service provider shall, in the event of any violation of its place of business or certification system, advise the concerned department, as well as the clients affected by such violation, in writing within twenty-four (24) hours from the date of its certain or presumed knowledge of such violation; whether such violation is physical or electronic. 1. The certification service provider may not merge or have joint liability with any third party except after notifying the concerned department of the consequences thereof on the services and clients. The General Secretariat shall have the right to take the action it deems appropriate in light of the content of such notice and the potential impact of such merger or joint liability on the terms of granting the license or on the interests of related parties. The certification service provider shall: 1. Suspend the certificate validity immediately upon a request by its holder, or in case it discovers or has grounds to believe that: A. The certificate has been issued on the basis of erroneous or untrue information. B. The signature tool has been violated. C. The certificate has been used for fraudulent purposes. D. The information contained in the certificate has changed. 2. Notify the certificate holder immediately upon suspending the certificate validity and provide the reasons for such action. 3. Remove the certificate suspension immediately if the certificate holder withdraws the suspension request, or when the correctness of the information included in the certificate and the legality of using it are proven. 4. The certificate holder or any interested third party may object to the suspension decision issued by the certification service provider before the concerned department. The certification service provider shall cancel the certificate immediately upon the occurrence of any of the following cases: Where the certificate holder requests cancellation. Where the certification service provider knows of the demise of the natural person or the dissolution or liquidation of the juristic person holding the certificate. Where the certification service provider, after conducting detailed verification, is confident of the correctness of the reasons on which it has relied for suspending the certificate validity. The certification service provider shall be liable for the damages resulting from its negligence in taking the necessary action to suspend or cancel certificates, pursuant to the provisions set out in Articles 27 and 28 above. The certification service provider shall ensure the following: Fulfillment on the part of its entrusted employees of all requirements of qualification, experience and all other standards and prerequisites stipulated in the Law and this bylaw. No entrusted employee shall have any interests or relations that conflict with his work. The certification service provider shall maintain a register showing complete data of all employees. The certification service provider shall take all necessary action to ensure fulfillment of all terms, controls and standards related to protecting privacy, personal information and data security in accordance with the provisions of the Law and this bylaw. The certification service provider shall provide adequate information to consumers regarding the reporting of any grievance in respect of any of the activities and services it renders in terms of the form of grievance, the data it should contain, as well as the method, time and place for lodging it, through a clear and transparent mechanism and according to predefined procedures. 1. A certification service provider wishing to obtain the express consent from a consumer to send commercial electronic messages shall specify the following issues when requesting such consent: A. The purpose of requesting the consumer's consent. B. Sufficient information about the service provider's identity. The consumer who receives commercial electronic communications from a certification service provider may withdraw such consent by sending a notice to the service provider mentioning his wish not to receive further electronic communications; and the service provider shall immediately stop sending any electronic messages to such consumer. The electronic communication should include precise information about the manner in which the consumer can contact the service provider. The certification service provider shall keep a special register to record consumers' grievances in the order in which such grievances were received, and shall deal with such grievances in an effective and transparent manner. The certification service provider shall decide on grievances within thirty (30) days from the date of receiving them, and shall advise the concerned department and the consumer of the result of examining the grievance and the action taken in respect thereof. 1. Where the thirty (30)-day period mentioned in the above article elapses without action being taken by the certification service provider, the consumer may submit a written request in this regard to the concerned department. The concerned department may take any action or issue any instructions to the certification service provider regarding the grievance in accordance with the authorities and competences assigned thereto in this respect by the provisions of the Law and this bylaw. The General Secretariat may suspend the certification service provider's license if the certification service provider breaches any of the provisions stipulated in the Law or this bylaw. The certification service provider shall, in compliance with a decision to cease its business, carry out the following: 1. Retain all registers and electronic data related to its business as a certification service provider, and those related to certification certificates in particular, but without modifying their content until they are disposed of in accordance with the decisions, instructions, guidelines or circulars issued by the General Secretariat. 2. Provide the General Secretariat with all technical details related to the data and its specifications. 3. Transfer the data, either wholly or partially, according to the technical controls to be set by the General Secretariat in such a manner that preserves consumers' rights. The General Secretariat may revoke the certification service provider's license in any of the following cases: 1. Where the certification service provider becomes non-compliant with the terms, controls and standards set out in the Law and this bylaw. 2. Where six (6) months have elapsed from the date on which the General Secretariat issues a decision to suspend the license and the certification service provider does not remedy the reasons of suspension. 3. Upon a written request from the certification service provider to cease its business as a certification service provider. 4. Where the certification service provider ceases its business without notifying the Secretariat General. 1. The General Secretariat shall notify the certification service provider in writing, or by any other legal means, of its decision to suspend or cancel the license. The decision to suspend or cancel the license of a certification service provider shall be published on the Supreme Council's website. A certification service provider whose license has been cancelled shall not be permitted to obtain a new license before a period of five (5) years has elapsed after the date of cancellation of its license, unless the General Secretariat otherwise decides. A certification service provider whose license has been suspended or cancelled shall coordinate with the General Secretariat and implement any decisions, instructions or guidelines issued thereby until the certification service provider completes the liquidation of its business. The certification service provider shall follow the following procedures if it intends to terminate its business as a certification service provider: 1. Notify the General Secretariat at least three (3) months prior to terminating its business. 2. Notify concerned parties in writing of its intention to terminate its business at least two (2) months in advance. 3. After giving such notice, the certification service provider shall allow subscribers an appropriate opportunity to switch to other certification service providers. After terminating its business, the certification service provider shall take all necessary measures to maintain its registers and certified certificates for at least seven (7) years from the date of closing down its business, in accordance with the controls and terms to be determined by the General Secretariat. In all cases, the certification service provider may not keep any copies of its business registers and electronic data for any reason in relation to its terminated business after the said seven-year period. 1- The licensee may only assign the license to other party after obtaining the prior written consent of the Secretariat. 2- Should the certification service provider wishes to assign the license to a third-party, he shall notify the Secretariat at least (3) months from the date specified for the assignment. 3. The notification referred to in paragraph (2) must include all data and documents which prove that the Assignee meets the terms of the license contained in Article 11 herein. 4. The Secretariat has the right to accept or reject the assignment request. Such decision shall be final. 5. The Secretariat shall notify the Assignee of its decision in writing or by any other legal means. Without prejudice to the provisions set out in Article 64 of the Law, the General Secretariat may, either independently or in cooperation with any competent authority, examine any grievance or claim that may be lodged against any of the certification service providers, their officers, representatives or entrusted employees, pursuant to the provisions of the Law and this bylaw. The General Secretariat shall have the right, if it is of the opinion that a grievance or a claim filed against any certification service provider is serious or valid, to take all necessary action, decisions and measures in accordance with the provisions of the Law and this bylaw. The General Secretariat shall create a general register for certification service providers in the State and shall maintain it in a hardcopy and an electronic copy, and such register shall include all data, papers and documents related to certification service providers. The certification service provider shall advise the General Secretariat in writing of any modification in the data pertinent to its work as a certification service provider within fifteen (15) days from the date on which such modification occurred. The General Secretariat may approve certification certificates issued by foreign entities that have competence to issue electronic certification certificates, provided that any of the following conditions is met: 1. The foreign entity issuing the certificate must comply with the rules and requirements set out in this bylaw for licensing the practice of certification service provider's activity. 2. The foreign entity issuing the certificate must have an agent in the State licensed by the General Secretariat to issue electronic certification certificates and must meet the necessary requirements and prerequisites to deal with electronic certification certificates. 3. The foreign entity must be among those entities which have been approved by the General Secretariat, pursuant to an effective agreement, as a competent foreign authority authorized to issue electronic certification certificates. 4. The foreign entity must be one of the approved or licensed entities authorized to issue electronic certification certificates by the certification authority in its native country; provided that there is an agreement to this effect between the foreign licensing authority and the General Secretariat. Approval of a foreign authority shall be granted upon a request submitted thereby, or by concerned parties, on the forms prepared by the General Secretariat. Moreover, the General Secretariat may approve a foreign authority, on its own initiative, in the cases mentioned in Article 47 (1), (2) and (3) above. 1. Where a foreign authority applies for accreditation, the General Secretariat shall, after receiving and verifying the correctness of the required documents and data, decide on the application within a period not exceeding ninety (90)days from the date on which the foreign authority fulfils all requirements of the General Secretariat. Where the aforementioned period elapses without the accreditation being issued, the request shall be deemed rejected unless the General Secretariat advises the requesting authority in writing of an extension of such period. A decision to accredit a foreign authority shall be issued by the General Secretariat and such decision shall determine the period of accreditation and the conditions for renewal thereof. The General Secretariat may, by a reasoned decision, revoke or suspend the accreditation. Accredited foreign authorities may request the General Secretariat to approve the types of electronic certification certificates issued by them in accordance with the rules and controls set by the General Secretariat in this respect. Whoever violates the provisions of Chapter Three of this Bylaw shall be obliged to pay an amount not less than five thousand (5,000) riyals and not more than fifty thousand (50,000) riyals. 2. Whoever violates the provisions of Chapter Four of this Bylaw shall be obliged to pay an amount not less than twenty thousand (20,000) riyals and not more than two hundred and fifty thousand (250,000) to riyals. 3. Whoever violates any other provision of this Bylaw, shall be obliged to pay an amount not less than five thousand (5,000) riyals and not more than one hundred thousand (100,000) riyals. 4. Financial sanctions provided for in this Article shall be applied by a decision of the General Secretariat. --- يُعمل بأحكام اللائحة المرفقة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق. على جميع الجهات المختصة، كل فيما يخصه، تنفيذ هذا القرار. ويُنشر في الجريدة الرسمية. في تطبيق أحكام هذه اللائحة، تكون للكلمات والعبارات التالية، المعاني الموضحة قرين كل منها، ما لم يقتض السياق معنى آخر: الدولة: دولة قطر. المجلس الأعلى: المجلس الأعلى للاتصالات وتكنولوجيا المعلومات. المجلس: مجلس إدارة المجلس الأعلى. الأمانة العامة: الأمانة العامة للمجلس الأعلى. الإدارة المختصة: الوحدة الإدارية المختصة بالأمانة العامة. اللجنة: لجنة التظلمات وتسوية المنازعات المنصوص عليها في المادة ( 64 ) من القانون. القانون: قانون المعاملات والتجارة الالكترونية الصادر بالمرسوم بقانون رقم (16) لسنة 2010. الشخص: الشخص الطبيعي أو المعنوي. التوقيع الالكتروني: ما يوضع على رسالة البيانات، ويتخذ شكل حروف، أو أرقام، أو رموز، أو إشارات، أو غيرها، ويكون له طابع متفرد، يُستخدم لتحديد هوية المُوَقّع، ويميزه عن غيره، وبغرض بيان موافقة المُوَقّع على رسالة البيانات. معلومات إنشاء التوقيع: المعلومات أو الرموز أو مفاتيح التشفير الخاصة المستخدمة من قبل المُوَقّع في إنشاء التوقيع الالكتروني. المُوَقّع: الشخص صاحب الحق القانوني في الوصول إلى معلومات إنشاء التوقيع، ويتصرف إما بالأصالة عن نفسه أو بالنيابة عن شخص يمثله، لاستخدام هذه المعلومات لإنشاء التوقيع الالكتروني. مقدم خدمة التصديق: شخص مرخص له بالاحتفاظ ببنية تحتية للمفاتيح العمومية، وبإصدار شهادات التصديق، وبتقديم خدمات ذات صلة بالتوقيعات الإلكترونية. شهادة التصديق: وثيقة تصدر عن مقدم خدمة التصديق، تؤكد صحة الارتباط بين المُوَقّع ومعلومات إنشاء التوقيع. التشفير: استعمال رموز أو إشارات غير متداولة تصبح بمقتضاها المعلومات المرغوب تمريرها أو إرسالها غير قابلة للفهم من قبل الغير أو استعمال رموز أو إشارات لا يمكن الوصول إلى المعلومات بدونها. طرف مُعتَمِد: الشخص الذي يتصرف على أساس شهادة تصديق أو توقيع الكتروني. مقر العمل: المنشآت أو المرافق غير العارضة، المستخدمة لمزاولة أعمال تقديم خدمات التصديق. الموظف المؤتمن: أي موظف يعمل لدى مقدم خدمة التصديق، ويُناط به القيام أو المساعدة في القيام بأي من مهام أو اختصاصات أو مسؤوليات مقدم خدمة التصديق، بموجب أحكام القانون وهذه اللائحة. جديرة بالثقة: أن تؤدي الأنظمة والإجراءات والعمليات والموارد البشرية والمنتجات والخدمات وظائفها بطريقة سليمة ومتناسقة ويمكن الاعتماد عليها. المستهلك: الشخص الذي يتصرف لأغراض غير تلك الخاصة بتجارته أو مهنته أو أعماله. يُحظر بغير ترخيص من الأمانة العامة، مزاولة أي عمل من أعمال مقدمي خدمة التصديق، بما في ذلك: 1. الاحتفاظ ببنية تحتية للمفاتيح العمومية. 2. تقديم خدمات ذات صلة بالتوقيعات الالكترونية. 3. إصدار شهادات التصديق الالكتروني. يجب على كل شخص يرغب في تقديم خدمة التصديق، أن يقدم طلباً بذلك للإدارة المختصة على النموذج المعد لهذا الغرض، على أن يرفق به المستندات التالية، بحسب الأحوال: 1. عقد التأسيس والنظام الأساسي، وفقاً للتشريعات المعمول بها في الدولة. 2. السجل التجاري أو الرخصة التجارية. 3. الهيكل التنظيمي للمنشأة. 4. سند الملكية أو عقد الإيجار. 5. تقرير مدقق حسابات معتمد عن المركز المالي للشركة عن السنتين الماليتين الأخيرتين، أو عن الفترة من تاريخ تأسيسها وحتى تاريخ تقديم الطلب، أيهما أقرب. 6. ما يفيد سداد الرسوم المقررة. 7. إقرار كتابي بمطابقة مقر العمل لكافة المعايير التقنية التي يتطلبها القانون وهذه اللائحة. 8. إقرار كتابي يفيد باستيفاء الموظفين المؤتمنين لكافة الاشتراطات المتعلقة بهم وفقاً للقانون وهذه اللائحة مع بيان تفصيلي بمؤهلاتهم وخبراتهم في مجال خدمات التصديق، ومدعماً بالمستندات المؤيدة. 9. الخصائص أو المواصفات التقنية للمعدات ومنظومات التصديق المعتمدة لتقديم خدمة التصديق، مصحوبة برسم بياني معتمد لها. 10. رسم بياني لمقر عمل مقدم الخدمة ووصف دقيق لإجراءات السلامة المعتمدة لتأمينه. 11. دراسة جدوى اقتصادية متكاملة للمشروع المزمع إنشاؤه. ويجوز للإدارة المختصة خلال (30) ثلاثين يوماً من تاريخ تقديم الطلب أن تطلب من مقدمه استيفاء أي معلومات أو بيانات أو مستندات تراها ضرورية بحسب الأحوال، وبالشكل والطريقة وفي الوقت الذي تحدده. تكون مدة الترخيص (5) خمس سنوات، تبدأ من تاريخ صدوره، ويجوز تجديده لمدة أو لمدد أخرى مماثلة، وذلك وفقاً للشروط والأحكام والضوابط الواردة بالقانون وهذه اللائحة. مع مراعاة الأحكام الواردة بالمادة ( 3 ) من هذه اللائحة، يجب على مقدم خدمة التصديق، تقديم طلب تجديد الترخيص قبل (3) ثلاثة أشهر على الأقل من تاريخ انتهاء الترخيص الساري. يجب على مقدم طلب الترخيص أو تجديده سداد الرسوم المقررة وفقاً للجدول المرفق بهذه اللائحة. وفي حال رفض الطلب أو سحبه من قبل مقدمه قبل البت فيه، أو إلغاء أو إيقاف الترخيص بعد إصداره، لا تسترد تلك الرسوم ما لم تقرر الأمانة العامة خلاف ذلك. تتولى الإدارة المختصة تلقي وفحص طلب الترخيص أو تجديده، وكذلك ما أرفق به من مستندات، والتأكد من استيفائه لكافة الشروط والضوابط والمواصفات والمعايير ذات الصلة الواردة بالقانون وهذه اللائحة. تصدر الأمانة العامة خلال (30) ثلاثين يوماً من تاريخ استلام الطلب، أو من تاريخ استيفاء ما طلبته من بيانات ومعلومات ومستندات، قراراً بمنح الترخيص أو تجديده أو رفض الطلب، ويخطر مقدم الطلب بذلك القرار كتابياً على عنوانه الثابت بالطلب. ويجب أن يكون القرار الصادر بالرفض مسبباً. ويعتبر مضى هذه المدة دون رد بمثابة رفض ضمني للطلب. ويجوز لذوي الشأن التظلم من هذا القرار إلى اللجنة خلال (30) ثلاثين يوماً من تاريخ إخطارهم به. في حال الموافقة على منح الترخيص، تقوم الإدارة المختصة بإدراج بيانات المرخص له في سجل خاص يسمى سجل "مقدمي خدمات التصديق المعتمدين". يجب أن يتضمن الترخيص البيانات التالية: 1. اسم مقدم خدمة التصديق. 2. عنوان مقر عمل مقدم خدمة التصديق. 3. رقم الترخيص وتاريخ صدوره، ومدة سريانه، وتاريخ انتهائه. 4. أي شروط أو ضوابط أو أحكام أو قيود تقررها الأمانة العامة وفقاً لأحكام القانون وهذه اللائحة. يشترط في طالب الترخيص أو تجديده، أن يستوفي الشروط التالية: 1. أن يكون حاصلاً على سجل تجاري أو رخصة تجارية. 2. أن يكون مقيماً بالدولة، ويجوز أن يكون فرعاً لمقدم خدمة تصديق جرى تأسيس مقره الرئيسي خارج الدولة. 3. الملاءة المالية، وذلك بتقديم ما يثبت امتلاكه مصادر مالية لا تقل عن (5,000,000) خمسة ملايين ريال. 4. أن يكون مؤمناً على عمله المتعلق بتقديم خدمة التصديق ضد أي خسارة مالية محتملة، وذلك وفقاً للقوانين والأنظمة والتشريعات ذات الصلة المعمول بها في الدولة. 5. ألا يكون طالب الترخيص أو أي من موظفيه المؤتمنين مالكاً أو مساهماً في أي شركة ترى الأمانة العامة أنها يمكن أن تقلل أو تحد من المنافسة العادلة. 6. أن يكون محمود السيرة حسن السلوك، ولم يسبق صدور أي حكم نهائي ضده في جريمة مُخلة بالشرف أو الأمانة، ما لم يكن قد رد إليه اعتباره. ويجب أن يستمر توفر الشروط المشار إليها في مقدم خدمة التصديق أثناء سريان الترخيص. وفي جميع الأحوال، يجب على مقدم خدمة التصديق الالتزام بكافة القواعد والشروط والضوابط والمعايير والقرارات والإجراءات والتعليمات والمواصفات التي يصدرها المجلس الأعلى من وقت لآخر، وفقاً لأحكام القانون وهذه اللائحة، وسائر التشريعات ذات الصلة بعمله كمقدم لخدمة التصديق. يخضع مُقدم خدمة التصديق لكافة عمليات التفتيش والتدقيق المطلوبة بمُقتضى أحكام القانون وهذه اللائحة، بالطريقة والكيفية وفي الوقت الذي تحدده الأمانة العامة. ويجب على مقدم خدمة التصديق أن يبادر إلى تقديم ما تتطلبه عمليات التدقيق أو التفتيش من مستندات أو بيانات أو أوراق أو معلومات، وأن يجيب على ما يطرحهُ المُدقق أو المُفتش من أسئلة أو إستفسارات تُمكنه من القيام بمهام وظيفته المُكلف بها. تجرى عمليات التفتيش والتدقيق في الحالات الآتية: 1. عند تقديم طلب استخراج الترخيص لأول مرة. 2. كل سنتين من تاريخ صدور الترخيص. 3. عند تقديم طلب تجديد الترخيص. 4. في أي وقت آخر تُحدده الأمانة العامة. يجب على المدقق أو المفتش التثبت من الأمور التالية: 1. سياسة الحماية والتخطيط. 2. الحماية المادية (حدود النفاذ والضوابط ومركز البيانات). 3. شبكة التقنية والبُنية التحتية. 4. مساحة التخزين الإلكتروني (سجلات تخزين المعلومات والبيانات). 5. نظام جودة إدارة خدمات التصديق (إدارة دورة سريان الشهادات والتسليم والإصدار). 6. وجود بيان مُمارسة التصديق الالكتروني والالتزام بتطبيقه وفقاً للسياسات واللوائح. 7. الالتزام بالإرشادات والمُتطلبات الفنية التي تُصدرها الأمانة العامة. 8. الاتفاقيات مع المفوضين بالتوقيع وغيرهم من مُقدمي خدمة التصديق. 9. الالتزام بشروط الترخيص. 10. الالتزام بأحكام القانون وهذه اللائحة. 11. التثبت من أن مقدم خدمة التصديق يتصرف وفقاً للبيانات التي يقدمها بشأن ممارسة نشاطه. 12. أي أعمال أخرى من أعمال مقدم خدمة التصديق. على المُدقق أو المُفتش إعداد تقرير بنتيجة أعماله ورفعه إلى الإدارة المختصة خلال (15) خمسة عشر يوماً من تاريخ انتهاء عملية التدقيق أو التفتيش. إذا ثبت من تقارير التدقيق أو التفتيش، أن مقدم خدمة التصديق لم يستوف الشروط والضوابط ذات الصلة بنشاطه، بمقتضى أحكام القانون وهذه اللائحة، يحق للأمانة العامة رفض طلب الترخيص، أو تجديده، أو تعليقه، بحسب الأحوال. يُشترط في جهة التدقيق الفني أن تكون مسجلة في الدولة، وألا تكون بينها وبين مقدم خدمة التصديق، أي علاقة مالية أو قانونية أو غيرها. يجب على الأمانة العامة التحقق من مدى استيفاء المدقق الفني للاشتراطات التالية: 1. الإلمام الكافي بأحكام القانون وهذه اللائحة وسائر الإرشادات والضوابط والمعايير والتعليمات ذات الصلة بخدمات التصديق، والتي يصدرها المجلس الأعلى. 2. أن يكون معتمداً من قبل جهة متخصصة في التدقيق الفني. 3. أن يكون حاصلاً على شهادة مدقق أنظمة معلومات (CISA)، أو شهادة محترف أنظمة معلومات (CPA.CITP)، أو شهادة مدقق داخلي (CIA) أو لديه شهادة مدقق أمن معلومات معترف بها. 4. أن تكون لديه القدرة على إجراء تدقيق فني متوافق مع معايير الأيزو (27000)، وبخاصة الأيزو (27001: 2005) بشأن نظم المعلومات- التقنيات الأمنية- إدارة نظم المعلومات، وكذلك الأيزو (27002) بشأن رموز ممارسة إدارة أمن المعلومات. 5. أن تكون لديه الخبرة الكافية في مجالات التوقيعات الإلكترونية وشهادات التصديق الإلكتروني والبرامج الإلكترونية وأدوات وتقنيات أمن المعلومات، وأسس وقواعد المراجعات الأمنية والمالية، وتقنيات التدقيق المتخصصة. يلتزم مقدم خدمة التصديق في أداء عمله بكافة الشروط والضوابط والأحكام المتعلقة به، والواردة بالقانون وهذه اللائحة، وبخاصة ما يلي: 1. الالتزام بالمعايير الفنية المعتمدة من قبل الأمانة العامة، وتشمل إجراءات وأنظمة وعمليات التشفير واصدار التوقيعات الالكترونية وشهادات التصديق الالكتروني. وللأمانة العامة تعديل هذه المعايير من وقت لآخر على أن يتم إخطار مقدم خدمة التصديق بهذه التعديلات. 2. اتخاذ كافة الإجراءات لضمان استيفاء كافة الأنظمة والعمليات والإجراءات والموظفين والأجهزة والمعدات والمنتجات والخدمات، للضوابط والمعايير والاشتراطات المعتمدة، وذلك استناداً إلى مجموعة معايير الأيزو (27000)، والقرارات والتعليمات والإرشادات التي تصدرها الأمانة العامة في هذا الشأن، وأن يقدم إقراراً بذلك إلى الأمانة العامة لدى تقديم طلب استخراج ترخيص جديد أو تجديد الترخيص الساري. 3. استخدام أنظمة وإجراءات معتمدة وجديرة بالثقة في جميع أنشطته وعملياته وبذل أقصى درجات الحيطة والحذر والعناية الكافية في ممارسته لجميع الأنشطة، وأدائها بكفاءة وأمانة ومصداقية. 4. اتخاذ كافة الإجراءات لضمان استيفاء كافة الاشتراطات والمُتطلبات والمعايير التي تتطلبها أي جهة حكومية أو شبه حكومية يقوم مقدم خدمة التصديق بأداء خدمات لها في إطار عمله. 5. إمساك سجلات جديرة بالثقة، وكاملة، ودقيقة، وذلك عن كافة عمليات إصدار، أو تجديد، أو تعليق أو إلغاء لشهادات التصديق. 6. إتاحة السجلات للاطلاع الكترونياً لذوي الشأن بصفة مستمرة، وذلك من خلال استخدام تقنيات النسخ الاحتياطي الدوري للبيانات، واتخاذ كافة الوسائل الكافية والملائمة لحمايتها من كل تغيير غير مرخص به. 7. استيفاء كافة معايير ومتطلبات واشتراطات الأمن والسلامة في مقر العمل، ومنظومة التصديق، وذلك بما يضمن استمرارية العمل عند حدوث أي عطل أو توقف بعض الأجهزة عن العمل، وذلك من خلال استخدام تقنيات تكرار الأجهزة والخدمات ووحدات التخزين. 8. استعمال وسائل موثوق بها لإصدار وتسليم وحفظ الشهادات واتخاذ الوسائل الكافية والملائمة لحمايتها من الغش أو التقليد أو التدليس أو العبث أو التحوير أو انتهاك السرية، أو الاطلاع غير المرخص به قانوناً. 9. توفير الحماية المادية لمقر العمل ومنظومة التصديق من العبث أو النفاذ غير المصرح به. 10. أن يكون المقابل الذي يحصله مقدم خدمة التصديق لقاء الخدمات والأعمال التي يقدمها للمتعاملين معه معقولا ومتناسبا مع طبيعة ونوعية تلك الخدمات ومتسقا مع أفضل الممارسات المطبقة دولياً وإقليمياً، ويحق للمجلس الأعلى من وقت لآخر مراجعة هذا المقابل. يجب على مقدم خدمة التصديق، لدى تقديمه خدمات تعزيز التوقيع الالكتروني أن يتصرف وفقاً للبيانات التي يقدمها للإدارة المختصة بشأن ممارسة نشاطه، وبوجه خاص الالتزام بما يلي: 1. إعداد ومراجعة وتدقيق وتحديث البيانات بصفة دورية، وإيداع نسخة منها بقاعدة البيانات لديه، وعلى موقعه الالكتروني، وذلك وفقاً للضوابط والمعايير ذات الصلة والمنصوص عليها بالقانون وهذه اللائحة. 2. تقديم نسخة محدثة من تلك البيانات لدى تقديم طلب منح أو تجديد الترخيص. 3. تسجيل كافة التغييرات التي قد ترد على تلك البيانات فور حدوثها والاحتفاظ بنسخة منها بقاعدة البيانات لديه، وعلى موقعه الالكتروني، وإبلاغ الإدارة المختصة كتابياً بأي تغييرات يمكن أن ترد على تلك البيانات خلال (15) خمسة عشر يوماً من تاريخ حدوثها. على مقدم خدمة التصديق استخدام التشفير، أو أي تقنيات أخرى، كوسيلة لحماية المعاملات الإلكترونية، بهدف المحافظة على سرية المعلومات أو البيانات، والتحقق من شخصية المنشئ، ومنع الغير من التقاط المعلومات أو الرسائل أو اعتراضها أو منع وصولها إلى المرسل إليه أو تشويهها أو تعديلها بالحذف أو الإضافة. ويكون لدى مقدم خدمة التصديق معرفة جيدة بإدارة المفاتيح تتضمن مراسم مخصصة لإدخال المفاتيح في النظام. على مقدم خدمة التصديق أن يستخدم في حماية منظومة التصديق أو نظم المعلومات، واحداً أو أكثر من الطرق التالية وبحسب الأحوال: 1. التشفير بالمفتاح العام. 2. ضبط النفاذ. 3. الجدران النارية. 4. مرشحات المعلومات. 5. مجموعة الوسائل المتعلقة بمنع الإنكار. 6. تقنيات تشفير المعطيات والملفات. 7. إجراءات حماية حفظ نسخ الحفظ الاحتياطية. 8. البرامج المضادة للديدان والفيروسات وسائر البرمجيات الخبيثة. 9. أية طريقة أو وسيلة ذات مصداقية أو اعتمادية من التقنيات ذات الصلة بالتصدي لمحاولات الاختراق الأمني تشترطها أو تجيزها الإدارة المختصة. يجب على مقدم خدمة التصديق إمساك كافة السجلات ذات الصلة بأداء عمله، وفقاً للمعايير والضوابط الواردة بالقانون وهذه اللائحة، وعلى الأخص الالتزام بما يلي: 1. إمساك السجلات في نسختين إحداهما ورقية والأخرى إلكترونية، أو في أي شكل آخر مناسب تتطلبه الإدارة المختصة، على أن تكون دقيقة وكاملة ومقروءة ومتاحة وقابلة للاستخدام من قبل ذوي الشأن. 2. توفير الوسائل التي تمكن ذوي الشأن من استخدامها، في الوقت وبالشكل الملائمين. 3. إعداد أرشيف لتبويب وتخزين وحفظ ونسخ وأرشفة كافة السجلات والملفات ذات الصلة بأداء عمله، وما يتعلق بها من بيانات أو معلومات أو شهادات، مع الاحتفاظ بآليات الوصول إليها لمدة لا تقل عن (7) سبع سنوات، ومراعاة استيفاء كافة المتطلبات والضوابط والمعايير الفنية ذات الصلة. 4.Referenced legislation
- ISO (272002) (unresolved)
- ISO (27001:2005) (unresolved)
- Electronic Transactions and Commerce Law promulgated by Decree Law No. 16 of 2010 (unresolved)
- ISO 27000 standards (unresolved)
- ISO standards (27000) (unresolved)
Part document.segment-2
The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق — segment 2
- document.segment-2 Verify source ↗
The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق — segment 2
تضمين الأرشيف بوجه خاص البيانات المتعلقة بشهادات التصديق، ومن ضمنها عملية تحري الهوية المستخدمة في حال طلب أي شخص لشهادة تصديق من مقدم خدمة التصديق وعملية إصدار الرموز المزدوجة، والعمليات التقنية البديلة المستخدمة بغرض توفير خدمات التصديق الالكتروني، وإدارة المعلومات الإلكترونية، ونظم المعلومات، ومقر العمل، ومرافق الشبكات الخاصة بمقدم خدمة التصديق. يجب على مقدم خدمة التصديق توفير مساحة تخزين الكترونية على شبكة الإنترنت، تمكنه من القيام بأداء عمله، على أن تتوفر بها الخصائص التالية: 1. أن تكون متاحة للجمهور بشكل مستمر، وألا تتجاوز أية خدمة منقطعة لمساحة التخزين سواء أكانت مجدولة أم غير مجدولة ساعة واحدة في أي وقت، وعلى أن لا تقل نسبة توفر الخدمة عن 99,95% في السنة. 2. أن تحتوي مساحة التخزين على معلومات كافية وكاملة ودقيقة بشأن ما يلي: أ- شهادات التصديق، وكافة ما يتعلق بها من بيانات أو معلومات أو مستندات أو أوراق. ب- القوائم المتعلقة بإيقاف أو إلغاء شهادات التصديق. ج- أرشيف كامل بشهادات التصديق التي تم إيقافها أو إلغاؤها أو تعليقها أو انتهاء صلاحيتها. ويتم الاحتفاظ بالأرشيف لمدة لا تقل عن (7) سبع سنوات. د- أي معلومات أو بيانات أو مستندات أو إيضاحات أو اشتراطات أو تعليمات أو معايير أو مُتطلبات يمكن أن يطلبها المجلس الأعلى. يجب على مقدم خدمة التصديق حال حدوث أي انتهاك لمقر عمله أو لمنظومة التصديق إخطار الإدارة المختصة والعملاء المتأثرين بهذا الانتهاك كتابياً خلال (24) أربع وعشرين ساعة من تاريخ علمه اليقيني أو المفترض بذلك، وذلك سواء أكان ذلك الانتهاك مادياً أم الكترونياً. لا يجوز لمقدم خدمة التصديق أن يندمج مع أي طرف آخر إلا بعد إخطار الإدارة المختصة بالآثار المترتبة على الخدمات والمستفيدين. ويجوز للأمانة العامة اتخاذ الإجراء المناسب في ضوء ما ورد بهذا الإخطار والتأثير المحتمل لهذا الاندماج على شروط منح الترخيص أو مصالح الأطراف ذات الصلة. يتعين على مقدم خدمات التصديق الالتزام بما يلى: 1. تعليق العمل بشهادة التصديق فوراً بناءً على طلب صاحبها أو إذا تبين له أو كان هناك ما يحمله على الاعتقاد بأن: أ- الشهادة قد سلمت على أساس معلومات خاطئة أو غير صحيحة. ب- أداة التوقيع كانت منتهكة. ج- الشهادة قد استخدمت لأغراض التدليس. د- المعلومات المتضمنة في الشهادة قد تغيرت. 2. إبلاغ صاحب شهادة التصديق على الفور عند تعليق العمل بالشهادة وأسباب ذلك الإجراء. 3. أن يرفع التعليق فوراً إذا رجع صاحب شهادة التصديق عن طلب التعليق أو عند ثبوت صحة المعلومات المتضمنة في الشهادة ومشروعية استعمالها. ولصاحب شهادة التصديق أو أي طرف ثالث صاحب مصلحة أن يعترض لدى الإدارة المختصة على قرار التعليق الصادر من مقدم خدمة التصديق. يجب على مقدم خدمات التصديق إلغاء شهادة التصديق فوراً في أي من الحالات الآتية: أ- إذا طلب صاحب الشهادة إلغاءها. ب- إذا علم بوفاة الشخص أو حل أو تصفية الشخص المعنوي صاحب الشهادة. ج- إذا تأكد بعد الفحص الدقيق من صحة الأسباب التي استند إليها في تعليق العمل بالشهادة. تحمل مقدم خدمات التصديق المسؤولية عن الضرر الناتج عن تقصيره في اتخاذ إجراءات تعليق أو إلغاء الشهادة وفقا لأحكام المادتين السابقتين. يجب على مقدم خدمة التصديق مراعاة ما يلى: 1. استيفاء موظفيه المؤتمنين لكافة اشتراطات التأهيل والخبرة، وسائر المعايير والمتطلبات الأخرى المنصوص عليها في القانون وهذه اللائحة. 2. ألا تكون لدى الموظف المؤتمن أي مصالح أو علاقات تتعارض مع عمله. ويجب أن يحتفظ مقدم خدمة التصديق بسجل يوضح البيانات الكاملة لكل الموظفين. يجب على مقدم خدمة التصديق اتخاذ كافة الإجراءات لضمان استيفاء الشروط والضوابط والمعايير ذات الصلة بحماية الخصوصية، والبيانات الشخصية، وسرية البيانات، وفقاً لأحكام القانون وهذه اللائحة. يجب على مقدم خدمة التصديق توفير المعلومات الكافية للمستهلك بشأن الإبلاغ عن أي شكوى ذات صلة بما يقدمه من أنشطة وخدمات، وذلك من حيث شكل الشكوى وبياناتها وكيفية ووقت ومكان تقديمها، وذلك من خلال آلية واضحة معلنة، ووفقاً لإجراءات محددة سلفاً. يتعين على مقدم الخدمة الراغب في الحصول على موافقة صريحة من أي مستهلك على إرسال اتصالات الكترونية ذات طبيعة تجارية أن يحدد الأمور التالية عند طلب الحصول على تلك الموافقة: أ- غرض طلب الحصول على الموافقة من المستهلك. ب- معلومات كافية عن هوية مقدم الخدمة. ويجوز للمستهلك الذي استلم اتصالات إلكترونية ذات طبيعة تجارية من مقدم خدمة أن يسحب تلك الموافقة عن طريق إرسال إخطار إلى مقدم الخدمة يذكر فيه عدم رغبته في استلام المزيد من الاتصالات الإلكترونية، وعلى مقدم الخدمة التوقف فوراً عن إرسال أي اتصالات إلكترونية لذلك المستهلك. ويجب أن يتضمن الاتصال الإلكتروني معلومات دقيقة عن كيفية اتصال المستهلك بمقدم الخدمة. على مقدم خدمة التصديق إمساك سجل خاص بقيد شكاوى المستهلكين، بشكل مسلسل، وبحسب أسبقية ورودها، وأن يتعامل مع هذه الشكاوى على نحو فعال ومعلن. يقوم مقدم خدمة التصديق بالبت في الشكاوى، خلال (30) ثلاثين يوماً من تاريخ استلامها، وإخطار الإدارة المختصة والمستهلك بنتيجة فحص الشكوى، وما اتُخذ بصددها من إجراءات. للمستهلك في حال انقضاء فترة (30) الثلاثين يوماً المشار إليها في المادة السابقة دون اتخاذ إجراء من قبل مقدم خدمة التصديق، أن يتقدم بطلب كتابي في هذا الشأن إلى الإدارة المختصة. وللإدارة المختصة اتخاذ أي إجراءات أو إصدار أي تعليمات إلى مقدم خدمة التصديق بشأن الشكوى، وذلك وفقاً للصلاحيات والاختصاصات المُخولة لها في هذا الشأن بموجب أحكام القانون وهذه اللائحة. يجوز للأمانة العامة وقف ترخيص مقدم خدمة التصديق، في حال مخالفته أي من أحكام القانون أو هذه اللائحة. ويلتزم مقدم خدمة التصديق في جميع حالات وقف نشاطه بالوفاء بالمتطلبات التالية: 1. الاحتفاظ بجميع السجلات والبيانات الالكترونية المتعلقة بنشاطه كمقدم لخدمات التصديق، وتلك المتعلقة بشهادات التصديق بوجه خاص، وعدم تعديل محتواها، وذلك إلى حين التصرف بها وفقاً للقرارات أو التعليمات أو الإرشادات أو التعميمات الصادرة من الأمانة العامة. 2. تزويد الأمانة العامة بجميع التفاصيل الفنية المتعلقة بالبيانات ومواصفاتها. 3. تحويل البيانات ونقلها سواءً بشكل كلي أم جزئي، وفقاً للضوابط الفنية التي تحددها الأمانة العامة، بما يحفظ حقوق المستهلكين. يجوز للأمانة العامة إلغاء ترخيص مقدم خدمات التصديق في أي من الحالات التالية: 1. إذا أصبح مقدم خدمة التصديق غير مستوف للشروط والضوابط والمعايير المنصوص عليها في القانون وهذه اللائحة. 2. مرور (6) ستة أشهر على صدور قرار الأمانة العامة بوقف الترخيص دون قيام مقدم خدمة التصديق بإزالة أسباب الوقف. 3. بناءً على طلب كتابي من مقدم خدمة التصديق بالتوقف عن نشاطه كمقدم لخدمة التصديق. 4. إذا توقف مقدم خدمة التصديق عن عمله دون إخطار الأمانة العامة بذلك. تخطر الأمانة العامة مقدم خدمة التصديق كتابياً، أو بأي وسيلة أخرى مقررة قانوناً، بقرار وقف أو إلغاء الترخيص. ويُنشر القرار الصادر بوقف أو إلغاء ترخيص مقدم خدمة التصديق على الموقع الإلكتروني للمجلس الأعلى. ولا يجوز بأي حال من الأحوال لمن ألغي ترخيصه الحصول على ترخيص مقدم خدمة تصديق لمدة (5) خمس سنوات لاحقة على تاريخ إلغاء ترخيصه ما لم تقرر الأمانة العامة خلاف ذلك. يجب على مقدم خدمة التصديق، الذي صدر بشأنه قرار بإيقاف أو إلغاء ترخيصه، العمل لحين انتهائه من تصفية أعماله، بالتنسيق مع الأمانة العامة، وتنفيذ أي قرارات أو تعليمات أو إرشادات صادرة عنها في هذا الشأن. يجب على مقدم خدمة التصديق إذا رغب في التوقف عن نشاطه القيام بما يلي: 1. إخطار الأمانة العامة قبل (3) ثلاثة أشهر على الأقل من التوقف. 2. إخطار ذوي الشأن كتابة بعزمه التوقف عن النشاط قبل شهرين على الأقل. 3. يجب على مقدم خدمة التصديق بعد توجيه الإخطار المشار إليه في البند (2) أن يتيح للمشتركين الفرصة المناسبة للاشتراك لدى غيره من مقدمي خدمات التصديق. يجب على مقدم خدمة التصديق بعد إنهاء نشاطه أن يقوم باتخاذ كافة التدابير اللازمة لحفظ سجلاته وما أصدره من شهادات معتمدة لمدة لا تقل عن (7) سبع سنوات من تاريخ إنهاء النشاط، وفقاً للضوابط والشروط التي تحددها الأمانة العامة. وفي جميع الأحوال، لا يجوز لمقدم خدمة التصديق، لأي سبب من الأسباب أن يحتفظ بأي نسخ من السجلات والبيانات الالكترونية الناتجة عن ممارسة نشاطه كمقدم لخدمة التصديق وذلك عن نشاطه الذي تم إيقافه، وذلك بعد انقضاء فترة السبع (7) سنوات المشار إليها. 1. لا يجوز للمرخص له التنازل عن الترخيص لأية جهة أخرى إلا بعد الحصول على موافقة كتابية مسبقة من الأمانة العامة. 2. يجب على مقدم خدمة التصديق إذا رغب في التنازل عن الترخيص لجهة أخرى إخطار الأمانة العامة قبل (3) أشهر على الأقل من التاريخ المحدد للتنازل. 3. يجب أن يتضمن الإخطار المشار إليه في الفقرة (2) كافة البيانات والمستندات التي تثبت استيفاء المتنازل له لشروط الترخيص الواردة في المادة ( 11 ) من هذه اللائحة. 4. يحق للأمانة العامة قبول أو رفض طلب التنازل ويكون القرار الصادر بذلك نهائياً. 5. تخطر الأمانة العامة طالب التنازل بقرارها كتابياً أو بأي وسيلة أخرى مقررة قانوناً. مع عدم الإخلال بأحكام المادة ( 64 ) من القانون، يجوز للأمانة العامة، مستقلةً أو بالتعاون مع أي جهة مختصة، البحث في أي شكوى أو مطالبة قد تقدم ضد أي من مقدمي خدمة التصديق، أو مسؤولية ممثليه أو الموظفين المؤتمنين لديه، وفقاً لأحكام القانون وهذه اللائحة. للأمانة العامة إذا ما ارتأت جدية أو ثبوت الشكوى أو المطالبة في حق مقدم خدمة التصديق، في ضوء أحكام القانون وهذه اللائحة، أن تتخذ كافة الإجراءات والقرارات والتدابير اللازمة وفقاً لأحكامهما. تنشئ الأمانة العامة سجلاً عاماً لمقدمي خدمة التصديق في الدولة، في نسختين إحداهما الكترونية والأخرى ورقية، على أن يتضمن ذلك السجل كافة البيانات والأوراق والوثائق المتعلقة بمقدمي خدمة التصديق. يجب على مقدم خدمة التصديق إخطار الأمانة العامة كتابيا بأية تعديلات في البيانات المتعلقة بعمله كمقدم خدمة التصديق خلال (15) خمسة عشر يوما من تاريخ حدوث تلك التعديلات. للأمانة العامة اعتماد شهادات التصديق الصادرة من الجهات الأجنبية المختصة بإصدار شهادات التصديق الإلكتروني، في أي من الحالات التالية: 1. أن يتوافر لدى الجهة الأجنبية مصدرة الشهادة بصفة أساسية القواعد والاشتراطات المبينة في القانون وهذه اللائحة. 2. أن يكون لدى الجهة الأجنبية مصدرة الشهادة وكيل في الدولة مرخص له من قبل الأمانة العامة بإصدار شهادات التصديق الإلكتروني، وتكون لديه المقومات والاشتراطات المطلوبة للتعامل بشهادات التصديق الإلكتروني. 3. أن تكون الجهة الأجنبية ضمن الجهات التي وافقت الأمانة العامة بموجب اتفاقية نافذة على اعتمادها باعتبارها جهة أجنبية مختصة بإصدار شهادات التصديق الإلكتروني. 4. أن تكون الجهة الأجنبية ضمن الجهات المعتمدة أو المرخص لها بإصدار شهادات تصديق إلكتروني من قبل جهة الترخيص في بلدها، وبشرط أن يكون هناك اتفاق بين جهة الترخيص الأجنبية وبين الأمانة العامة على ذلك. يكون اعتماد الجهات الأجنبية بناءً على طلب مقدم منها أو من ذوي الشأن على النماذج التي تعدها الأمانة العامة. كما يكون للأمانة العامة في الحالات المشار إليها في البنود (1 ،2، 3) من المادة السابقة اعتماد تلك الجهات من تلقاء نفسها. في حال تقدم جهة أجنبية بطلب للاعتماد، تقوم الأمانة العامة بعد تسلمها للمستندات والبيانات المطلوبة بفحصها والتأكد من سلامتها بالبت في طلب الاعتماد خلال مدة لا تجاوز (90) تسعين يوماُ من تاريخ استيفاء الجهة الأجنبية لكل ما تطلبه الأمانة العامة. وفي حالة انقضاء هذه المدة دون إصدار الاعتماد يعتبر الطلب مرفوضاً، وذلك ما لم تخطر الأمانة العامة كتابةً الجهة الطالبة بمد هذه المدة. ويصدر قرار اعتماد الجهة الأجنبية من الأمانة العامة، ويحدد في القرار الصادر بالاعتماد مدته وأحوال تجديده. وللأمانة العامة بقرار مسبب، الحق في إلغاء الاعتماد أو وقفه. للجهات الأجنبية المعتمدة أن تطلب من الأمانة العامة اعتماد أنواع شهادات التصديق الإلكتروني التي تصدرها وفقاً للقواعد والضوابط التي تضعها الأمانة العامة في هذا الشأن. 1. كل من خالف أحكام الفصل الثالث من هذه اللائحة، يلتزم بأداء مبلغ لا يقل عن (5,000) خمسة آلاف ريال ولا يزيد على (50,000) خمسين ألف ريال. 2. كل من خالف أحكام الفصل الرابع من هذه اللائحة، يلتزم بأداء مبلغ لا يقل عن (20,000) عشرين ألف ريال ولا يزيد على (250,000) مائتين وخمسين ألف ريال. 3. كل من خالف أي حكم أخر من أحكام هذه اللائحة، يلتزم بأداء مبلغ لا يقل عن (5,000) خمسة آلاف ريال ولا يزيد على (100,000) مائة ألف ريال. 4. تُطبق الجزاءات المالية المنصوص عليها في هذه المادة بقرار يصدر من الأمانة العامة.
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
The Supreme Council of Information and Communication Technology (ICT QATAR) Board of Directors' Resolution No. 1 of 2012 Issuing the Bylaw on the Accreditation of Foreign Certification Certificates Issued Abroad and the Regulation of the Work of Certifica التشريعات | قرار مجلس إدارة المجلس الأعلى للاتصالات وتكنولوجيا المعلومات رقم (1) لسنة 2012 بإصدار لائحة بشأن اعتماد شهادات التصديق الأجنبية الصادرة من خارج الدولة وتنظيم عمل مقدمي خدمة التصديق
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign in