Electronic signatures in the European Union, with GDPR-grade handling of biometrics.
Under eIDAS (Regulation 910/2014, amended by 2024/1183), a signature cannot be denied legal effect or admissibility in court just because it is electronic (art. 25.1). Its weight depends on the evidence behind it, and that is what we provide: verified identity, an immutable event chain, independent timestamps and a package any expert can check. Biometrics are a special category under the GDPR (art. 9), so liveness is optional, with explicit consent and a non-biometric alternative.
Legal review as of 2026-10-01. Legal information on this site is for guidance only and is not legal advice.
The legal framework, law by law.
eIDAS, Regulation (EU) 910/2014
Art. 25.1: electronic signatures cannot be denied legal effect or admissibility. Amended by Regulation 2024/1183 (eIDAS 2).
GDPR, Regulation (EU) 2016/679
Art. 9: biometrics for identification are special category data. Art. 7.4: consent may not be a condition when unnecessary. Art. 35: impact assessment.
AI Act, Regulation (EU) 2024/1689
Annex III 1(a) excludes biometric verification whose only purpose is to confirm a person is who they claim to be (1:1).
National civil and procedural law
Evidentiary weight of electronic signatures and retention periods are set by each member state (for example, 6 years for commercial records in Spain).
Electronic signatures with traceability, audit trail and immutable integrity.
Traceability
Every step is recorded: sending, opening, identity check, consent and signature, with date, time, IP and device.
Audit trail
A complete evidence package and a verifier any expert runs on their own machine, without relying on us.
Immutable integrity
PAdES signature, a SHA-256 event chain that rejects changes and deletions, timestamps, Bitcoin anchors and 10-year custody.
Requirement by requirement.
| Requirement | Law | How we meet it | Status |
|---|---|---|---|
| Non-discrimination of electronic signatures | eIDAS, art. 25.1 | Electronic signature with verified identity, explicit intent and a complete evidence package. | Meets |
| Verifiable date and integrity | eIDAS, art. 41.1 | Independent RFC 3161 timestamps, daily Bitcoin anchors and a SHA-256 event chain. | Meets |
| Biometrics: explicit consent | GDPR, art. 9.2(a) | Separate, optional biometric consent, recorded in the evidence log. | Meets |
| Consent not a condition of service | GDPR, art. 7.4 | Non-biometric alternative path always available. | Meets |
| Data protection impact assessment | GDPR, art. 35 | Likely required for biometric verification. Template provided; the controller completes it. | Partial |
| Representative in the Union | GDPR, art. 27 | Required while we have no EU establishment. Appointment pending. | Partial |
| International transfers | GDPR, arts. 44 to 49 | EU–US Data Privacy Framework or Standard Contractual Clauses (2021/914). | Partial |
| AI Act high-risk classification | AI Act, Annex III 1(a) | Our 1:1 liveness check is biometric verification, excluded from the high-risk list. | Meets |
Personal data and biometrics.
| Law | General Data Protection Regulation (EU) 2016/679, plus national implementing laws. |
|---|---|
| Authority | National data protection authorities, coordinated by the European Data Protection Board (EDPB) |
| Biometric data | Special category when processed to uniquely identify a person (art. 9). Explicit consent as legal basis; a DPIA is likely required. |
| Rights | One month, extendable by two more for complex requests (art. 12.3). |
| Security breaches | Notify the supervisory authority within 72 hours (art. 33) and data subjects without undue delay when the risk is high (art. 34). |
| International transfers | Adequacy decision (including the EU–US Data Privacy Framework for certified companies) or Standard Contractual Clauses with a transfer impact assessment. |
| Also | Controllers established outside the EU must appoint a representative in the Union (art. 27). |
- An EU representative (GDPR art. 27) and a DPIA template are pending before offering biometrics in the EU.
- Retention periods and the weight of electronic evidence in court vary by member state.
- B2B agreements, NDAs and service contracts.
- HR documents and employee acknowledgments.
- Consents, authorizations and terms acceptance.
- Purchase orders and internal approvals.
Is an electronic signature valid in the EU?
Yes. It cannot be denied legal effect or admissibility just because it is electronic (eIDAS art. 25.1). Its weight depends on the evidence, which is why we keep a full evidence package.
Is your liveness check high-risk AI under the AI Act?
No. It only confirms that the person is who they claim to be (1:1 verification), which Annex III 1(a) excludes. It still falls under GDPR art. 9.
What is the difference between an electronic signature and a digital signature?
| Electronic signature | Digital signature | |
|---|---|---|
| What it is | Any method that identifies the signer and shows they approve the document. | A type of electronic signature that uses a certificate issued in the signer’s name by a certification authority. |
| How the person is identified | At signing time: personal data, a one-time code and, if chosen, an ID document and a liveness check. | When the certificate is issued; afterwards the person signs with a key, token or app. |
| What the signer needs | A phone or computer. Nothing to install or buy. | A valid, paid, renewable certificate, often with a token or an app. |
| How it is proved in a dispute | With a full audit trail: who signed, when, from where and what, in an immutable record. | In many countries the certificate gives a legal presumption of authorship. |
| Integrity | PAdES signature, SHA-256 fingerprint and an immutable event chain: any change is detected. | Cryptographic signature with the certificate: any change is detected. |
| Typical uses | The vast majority of private contracts and documents. | Procedures and documents where a law or the other party requires it. |
Both are legally valid. For most private documents, an electronic signature is enough. In the EU, eIDAS calls certificate-based signatures “advanced” or “qualified”. A qualified signature has the effect of a handwritten one in every member state and is required for some national formalities.