From 82ac60342ca2f2b1f80a1b97b6674373b4d4cb7d Mon Sep 17 00:00:00 2001 From: JPedro Date: Wed, 14 Aug 2024 15:42:22 +0100 Subject: [PATCH] ToCs#2 --- .../check_a_difital_cerificate.markdown | 9 --------- .../legal_considerations.markdown | 17 ++--------------- 2 files changed, 2 insertions(+), 24 deletions(-) diff --git a/Legal and Security/check_a_difital_cerificate.markdown b/Legal and Security/check_a_difital_cerificate.markdown index 6d91e09..0c09a59 100644 --- a/Legal and Security/check_a_difital_cerificate.markdown +++ b/Legal and Security/check_a_difital_cerificate.markdown @@ -9,20 +9,12 @@ Now that we are eSigning documents and receiving eSigned documents, it is import **Please note that the steps below to verify a digital certificate are the same for a document signed using iSign or any other valid platform to electronically sign (DocuSign for instance). You might be interested to check a certificate that has been signed by a partner using another solution.** -**Table of contents:** -- [Responsability](#item-one) -- [Key Points](#item-two) -- [Advanced eSignature - How to verify a Digital signature?](#item-three) - - - # Key points - Digital signing is a cryptographic process. A timestamp and a unique number are assigned to a document, once signed. @@ -34,7 +26,6 @@ When ICRC Staff signs a contract with an electronic signature software different - The process to verify the Digital signature is the same when the document is signed using our internal platform (iSign/OneSpan Sign) or if the document is issued from another platform proposed by an external partner (DocuSign, Swiss Sign, Adobe...). - Duration of the validity of the Digital certificate is not a point/ a signature has to be valid at the moment of the signing process (a person's role in a company might change/what matters are the responsibilities of the person at the time of the signature). - - # GDPR The EU’s General Data Protection Regulation (GDPR) aims to harmonize data privacy laws across Europe. @@ -43,14 +34,12 @@ While the regulation doesn’t take aim at electronic signatures specifically, i Organizations seeking to utilize an electronic signature solution should understand the EU’s stance on these topics since they will be responsible for capturing and maintaining private information over an extended period in the form of contracts and digital agreements. - # Criteria for legally binding signatures As a general rule, legally binding e-signatures must: @@ -60,12 +49,10 @@ As a general rule, legally binding e-signatures must: - The signer’s willingness to sign is demonstrated (e.g. an option to not agree is also present, such as a “cancel” button). - The signer’s authenticity can be verified independently. This often means the presence of an email trail, timestamp, mobile phone number, and IP address. Two-step identification may also be helpful here for the purpose of attribution. - # Data Protection considerations **Strictly confidential documents cannot be uploaded nor signed on iSign (Cloud platform).**