GDPR
Definition
Frequently asked questions
What personal data does an electronic signature process?
At minimum the signer''s identity and email address, often their telephone number for sending a code. This is supplemented by technical data collected as evidence, such as IP address and timestamp of actions. For high levels, a copy of an identity document may be processed. All fall under the GDPR.
On what legal basis does this processing rest?
Most often on the performance of a contract or pre-contractual measures, since the signature serves to conclude the agreement. The retention of evidence rests on the legitimate interest in being able to demonstrate the commitment, or on a legal obligation to retain. Consent is rarely the appropriate basis, as the signer cannot truly refuse the processing.
Does the right to erasure apply to signed documents?
With limitations. The GDPR excludes the right to erasure when retention is necessary to comply with a legal obligation or to establish, exercise or defend legal rights. A signed contract and its evidence may therefore be retained for as long as they remain useful, and must then be deleted.
What is the role of the signature service provider under the GDPR?
It generally acts as a processor: it processes the data of signatories on behalf of the client company, which remains responsible for the processing. The GDPR then requires a written contract specifying the purpose of the processing, security measures, recourse to other processors and the fate of data at the end of the service.
Related guides
Related terms
Ready to put these concepts into practice?
Certyneo allows you to create signature envelopes compliant with eIDAS in just a few clicks, without installation.