person other than the subscriber, the certification service provider or the
Controller if the certification service provider is not available, shall, after
verifying the identity of the person requesting for the suspension and satisfying
itself that the certificate is unreliable, suspend the certificate and investigate.
(3) The certification service provider shall complete the investigation into the
reliability of the certificate and decide within forty-eight hours whether to
reinstate the certificate or to revoke the certificate.
(4) A certification service provider shall give notice to the subscriber immediately
upon the revocation of a certificate.
(5) A certification service provider shall maintain facilities to receive and act
upon requests for suspension and revocation at all times of the day and on all
days of every year.
21. Order by Controller to suspend or revoke certificate
(1) Where the Controller believes that there are reasonable grounds to suspend
or revoke a certificate, the Controller shall immediately notify the certification
service provider and the subscriber, inviting them to show cause within twenty
four hours why the certificate should not be suspended or revoked.
(2) If the certification service provider and the subscriber fail to show cause why
the certificate should not be suspended or revoked within the time specified in
sub regulation (1), the Controller shall order the provider to revoke the
certificate.
22. Privacy and protection of subscriber’s information
(1) Every certification service provider or agent shall keep all subscriber-specific
information confidential.
(2) Sub-regulation (1) does not apply to —
(a)
any disclosure of subscriber-specific information made —
(i)
with the permission of the subscriber; or
(iv) in compliance with an order of court or the requirement of any