### 4.12.1 Key escrow and recovery policy and practices
The CA MAY escrow the Subscriber’s Private Key as specified in the CA's CP and/or CPS.
The CA SHALL notify Subscribers when their Private Keys are escrowed. Escrowed Private Keys SHALL be stored in encrypted form. The CA SHALL protect escrowed Private Keys from unauthorized disclosure.
The CA SHALL recover Subscriber Private Keys only under the circumstances permitted within the CA's CP and/or CPS.