Go to main content
Certyneo
Security

Identity of the signatory and digital proof

How to prove who signed an electronic document? Identification techniques, assurance levels and KYC issues explained.

Certyneo Editorial Team3 min read

Updated on

Digitalisation des processus administratifs — équipe en réunion de travail

The heart of the problem

A electronic signature only has value if you can prove who affixed it. A simple click on "I accept" says nothing reliable about identity.

Identification techniques

Trusted email

Unique link sent. Only the mailbox holder can click it. Basis of the simple electronic signature (SES).

SMS OTP

One-time code sent to the number. Combined with email, this is the standard for the advanced electronic signature (AES).

Video KYC

Verification by video call: identity document, liveness test, OCR. Used for QES and regulated sectors.

Qualified certificate

Personal cryptographic certificate issued by a QTSP. The highest level, required for QES.

National digital identity

FranceConnect+, itsme (Belgium), SPID (Italy). EUDIW wallets will extend this option.

Levels of assurance (LoA)

eIDAS defines three levels:

  • Low: simple email → SES
  • Substantial: two-factor → AES
  • High: strict verification → QES

GDPR considerations

Identification collects personal data. The GDPR requires:

  • Minimization (only collect what is necessary)
  • Documented retention period
  • Right of access and erasure
  • Legal basis (performance of the contract, article 6.1.b)

Biometric data (video KYC) is sensitive — explicit consent required.

KYC and regulated sectors

Banks, insurers, crypto firms, and real estate brokers are subject to anti-money laundering and counter-terrorism financing rules. KYC requires:

  • Identity document verification with OCR
  • Liveness test (dynamic selfie)
  • Cross-checking against sanctions lists (PEP, OFAC)
  • Sometimes a human operator via video

Mistakes to avoid

  • Relying on email alone for sensitive contracts
  • Storing identity documents indefinitely
  • Failing to document the legal basis
  • Collecting more than necessary

Use case: opening a neobank account

  1. Entering information (name, address, occupation)
  2. Uploading an identity document + proof of address
  3. Liveness test: dynamic selfie
  4. Signing the contract with AES using SMS OTP

In 10 minutes, the account is opened with "substantial" identification accepted by the ACPR.

How Certyneo helps you

Certyneo natively offers email + SMS OTP identification (AES). For cases requiring enhanced KYC, a video KYC integration is available: document verification, liveness test, sanctions cross-checking.

KYC data is hosted in the EU, encrypted, with documented retention periods in compliance with the GDPR.

Discover Certyneo's electronic signature solution

FAQ

Is email alone enough for a valid signature?

Technically yes for SES. For a high-stakes document, prefer AES with SMS OTP.

Does the GDPR prohibit storing identity documents?

No, it regulates it. Legal basis, limited retention period, enhanced security for sensitive data.

Can FranceConnect+ be used?

Yes, recognized at the "substantial" level for AES or even QES.

Is video KYC mandatory for insurance?

Not as such, but the ACPR expects enhanced identification.

Can you sign with an identity from another EU country?

Yes, thanks to eIDAS mutual recognition (itsme, SPID, nPA).

Conclusion

Identification is the weakest link in the chain of proof. Handle it carefully according to the stakes, and your signature will be solid.

Try Certyneo to send, sign, and track your documents online simply, quickly, and securely.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.