25. Contents of a certification practice statement
(1) Every certification practice statement shall include –
(a)
a statement of the purpose and effect of the certification practice statement;
(b)
a statement advising the potential subscribers of the rights, duties and
liabilities of the certification service provider, the subscriber and a person relying
on a certificate;
(c)
a statement of the conditions or restrictions on the certification service
provider's licence or recognition;
(d)
a list and description of the services provided and the fees and charges
relating to those services;
(e)
complete, accurate and clear operating procedures, including procedures
for applying, issuing, suspension and revocation of certificates;
(f)
a statement with regard to the different classes of certificates available and
advising potential subscribers that the subscriber shall decide which class of
certificate is right for the subscriber's needs;
(g)
a statement regarding the determination of the recommended reliance
limits for certificates, advising potential subscribers that the subscriber shall
decide the amount of the recommended reliance limit that is right for the
subscriber's needs;
(h)
procedures for complaints and claims against the certification service
provider;
(i)
a statement regarding the protection and use of data obtained from the
subscribers;
(j)
a statement advising the potential subscribers in respect of the generation
of key pairs, the need to keep the private key secure from compromise and in a
trustworthy manner;
(k)
a statement advising potential subscribers that before communicating any
certificate to another person, or otherwise inducing their use or reliance on it, the