Glossary
eIDAS
Also called: eIDAS Regulation
eIDAS is the EU regulation establishing a framework for electronic identification and trust services. It defines three tiers of electronic signature — simple, advanced and qualified — of which only the qualified tier is given automatic legal equivalence to a handwritten signature across every member state.
eIDAS explained
The three tiers
Simple. Any data in electronic form attached to or logically associated with other data and used by the signatory to sign. A typed name or a click qualifies.
Advanced. Uniquely linked to the signatory, capable of identifying them, created using data under their sole control, and linked to the signed data such that any later change is detectable.
Qualified. An advanced signature created with a qualified signature creation device, based on a qualified certificate issued by a trust service provider on the EU trusted list.
What the tiers actually mean legally
Only the qualified tier has automatic equivalence to a handwritten signature across every member state. The other two are admissible and cannot be denied legal effect solely for being electronic — which for ordinary commercial contracts is generally sufficient.
Which tier a transaction needs
Almost always the simplest one that satisfies the applicable national law. Specific instruments — certain property transfers, succession documents, some employment and notarial acts — require qualified signatures in particular member states, and those requirements are national rather than harmonised.
The practical point
Disputes turn on evidence more often than on tier. A simple signature with a complete record of who signed, when, from where and against which version is frequently more defensible than an advanced signature with poor records.
FAQ
eIDAS: common questions
Do we need qualified signatures for commercial contracts?
Rarely. Simple or advanced is normally sufficient, and the qualified tier exists for instruments where national law specifically requires it. Take local advice for anything unusual.
Does the UK still follow eIDAS?
The UK retained a version of it after leaving the EU, with its own trusted list. The tier structure is the same; mutual recognition between the two regimes is the part that differs.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
- Golden threadThe golden thread is the requirement, introduced by the UK Building Safety Act 2022, to create and maintain accurate building safety information for higher-risk buildings throughout their life.
Última revisão: 28 de agosto de 2026. Browse the full glossary.