Überspringen und weiter zum Hauptinhalt
Blog
Startseite/

EU-Verordnung zur elektronischen Signatur kurz erklärt

Zusammenfassung4 Min. Lesezeit

Wir haben für Sie die häufig gestellten Fragen zum Thema eIDAS und Rechtsgültigkeit von elektronischen Signaturen zusammengefasst und beantwortet. 

Inhaltsverzeichnis

Elektronische Signaturen sind in Deutschland und der EU 100% rechtsgültig, wenn diese von einem vertrauenswürdigen Anbieter erstellt wurden. Doch wer setzt hier die Richtlinien und was hat es mit eIDAS auf sich? Wir haben für Sie die häufig gestellten Fragen zum Thema eIDAS und Rechtsgültigkeit von elektronischen Signaturen zusammengefasst und beantwortet.

Was ist eIDAS?

Die Abkürzung eIDAS steht für electronic IDentification, Authentication and trust Services. Diese EU-Verordnung regelt den Umgang mit elektronischen Signaturen. Für die allermeisten Unternehmens- und Verbrauchertransaktionen in der EU ist keine besondere Art der elektronischen Signatur vorgeschrieben. Allerdings setzen einige Transaktionen—je nach dem geltenden nationalen Recht—eine fortgeschrittene oder qualifizierte Signatur voraus. In manchen Fällen ist es auch sinnvoll, sich freiwillig für eine dieser Signaturarten zu entscheiden, da sie mehr Sicherheit und eine zuverlässigere Authentifizierung bieten.

In Deutschland zum Beispiel sieht das Gesetz vor, dass die qualifizierte Signatur für folgende Zwecke zwingend erforderlich ist:

  • Vertrieb von Verbraucherkrediten

  • Arbeitsverträge für Zeitarbeitskräfte

Außerdem ziehen einige Branchen, insbesondere Banken und Gesundheitsdienstleister, aus „kulturellen" Gründen digitale Signaturen vor. Die Berücksichtigung dieser Technologie in den nach eIDAS empfohlenen Standards für fortgeschrittene und qualifizierte elektronische Signaturen könnte diesen Trend verstärken.

Was haben Unternehmen von der eIDAS-Verordnung?

Die eIDAS-Verordnung schafft eine klarere Rechtsgrundlage für elektronische Transaktionen. Zumindest theoretisch dürfte dies den grenzüberschreitenden E-Commerce und die Digitalwirtschaft fördern.

Voraussichtlich wird die Nachfrage von Unternehmen nach Vertrauensdiensten und sicheren Plattformen für elektronische Signaturen wie Docusign steigen. Da eIDAS den Vertrauensdiensteanbietern die Nutzung von Cloud-Technologien ermöglicht, können Kunden elektronische Signaturen unterwegs per Smartphone oder Tablet erstellen und überprüfen. Das beschleunigt Prozesse und erhöht die Produktivität. Diese Entwicklung könnte die digitale Transformation der Unternehmenswelt in Deutschland und in der EU vorantreiben.

Besonders seit der COVID-19 Pandemie sind Remote-Transaktionen wichtiger den je. Unternehmen die es Kunden ermöglichen Verträge ohne manuelle Prozesse zu unterschreiben sind daher klar im Vorteil.

Wie hat sich Docusign auf eIDAS vorbereitet?

Im November 2015 übernahm Docusign das elektronische Signaturgeschäft von OpenTrust (jetzt IDnomic). Dadurch können wir Kunden, die Transaktionen innerhalb der EU durchführen, nun sämtliche Arten elektronischer Signaturen anbieten, die in der eIDAS-Verordnung definiert sind—auch fortgeschrittene und qualifizierte Signaturen.

Die Standards-Based Signatures-Technologie von Docusign basiert zudem auf den in eIDAS empfohlenen technischen Standards für elektronische Signaturen, darunter digitale Technologiestandards (X.509 PKI, PAdES, XAdES und CAdES sowie andere Standards nach ETSI, CEN und ANSI). Docusign eSignature ermöglicht es Unternehmen, Verträge und Dokumente schnell und sicher elektronisch zu signieren.

Wie erstellt man eine elektronische Signatur?Blog lesen

Einheitliche Standards in Europa dank eIDAS

Elektronische Signatur

  • Erfüllt Textformerfordernis ( § 126b BGB)

  • Zulässig als Beweismittel im Rechtsstreit (vgl. Art. 25 Abs. 1 und ErwGr 49 eIDAS-VO)

Fortgeschrittene Signatur

  • Erfüllt Textformerfordernis (§ 126b BGB)

  • Möglichkeit der Identifizierung des Unterzeichners

  • Leichtere Prüfung der Gültigkeit im Falle eines Rechtsstreits

  • Verbesserter Schutz gegen nachträgliche Veränderung

Qualifizierte Signatur

  • Erfüllt gesetzl. Schriftformerfordernis (§ 126 BGB)

  • Gleiche Rechtswirkung wie eine handschriftliche Unterschrift

  • Gesteigerte Beweiskraft, wie Privatkunde (§ 371a Abs. 1 ZPO)

Erfahren Sie mehr über Docusign, insbesondere über eIDAS und die Rechtsgültigkeit der elektronischen Signatur in unserem kürzlich stattgefunden Online Event Discovering Docusign. Hier geht es zur praktischen On Demand Version

Vereinbaren Sie jetzt einen Termin mit einem/einer Experten/ExpertinVertrieb kontaktieren

Ähnliche Beiträge

  • Einblicke für Führungskräfte

    Was macht ein Contract Manager

    Author Tobias S.
    Tobias S.
    You may notice when on Docusign’s website that a green padlock sits in front of the URL at the top of your browser. This is a visual cue that our website is secure thanks to SSL certificates, and it’s one that savvy consumers look for when doing business online. SSL certificates play an important role at Docusign, and they should be a part of your data privacy efforts too. Find out more about what they are, what they do, and how you can obtain them, with our SSL FAQs, below. What is an SSL Certificate? SSL stands for Secure Sockets Layer, and SSL certificates are also known as digital certificates. An SSL certificate creates a secure link between a website and a visitor's browser. It ensures that all data passed between the two remains private and secure. There are three types of SSL certificate: Extended Validation (EV SSL), Organisation Validated (OV SSL) and Domain Validated (DV SSL). There are also what is known as wildcard certificates, used to extend SSL encryption to subdomains. Why do companies need an SSL Certificate? SSL certificates establish trust between you and your customer. To obtain an SSL Certificate, the purchasing company's identity must be authenticated. With this safeguard in place, customers know that your business is not only legitimate but that it's safe to do business with you online. If you want to accept credit card information on your website, for example, then you will need to comply with Payment Card Industry (PCI) standards. One of the PCI requirements is using an SSL certificate. SSL certificates also help to prevent you and your customers from suffering a phishing attack. Phishing emails aim to impersonate your website for criminal gain. As the sender cannot receive their own SSL certificate, it makes it far more difficult for them to impersonate your website and easier for them to be caught out. As a result of SSL encryption, hackers and identity thieves are prevented from stealing private and sensitive information such as addresses, social media logins and credit card numbers. Only the intended recipient will be able to understand the information being sent. What should I look for in an SSL certificate provider? The cost of a solution can often be a deciding factor when choosing any tech solution, but when the security of your data it at risk, you shouldn’t necessarily go with the cheapest option. With that in mind, these are the top factors to consider over price alone: Compatibility: The provider should have a high trust pedigree in as many commonly used operating systems, web browsers, apps and devices as possible. Scalability: The provider should also be able to handle volumes that grow with your company, as you may end up needing thousands of certificates per second to be issued. Flexibility: The leading providers offer flexible purchasing terms. Pay-as-you-go, for example, allows you to order certificates when you see fit, regardless of amount. Bulk balance models also allow you to load money into your account. Platform: Your solution needs to be easy to use, support a variety of workflows and has a dynamic portal. Support: It's important to evaluate the services and support offerings available to help you succeed. Is an account manager on-hand, online support offered, communities to ask questions, and educational resources enabling you to self-serve? Where can I find Docusign's certificates? Docusign's digital certificates provide higher levels of identity authentication and document transaction security. Digital certificates cryptography uses Public Key Infrastructure (PKI) technology to issue certificates based on X.509 standards to represent the digital identity of a signer. The latest SSL certificate is always available for download from the Docusign Trust Site. Do I need to update my Docusign SSL certificate? If you do not have a custom SSL integration then no action is needed. Docusign’s SSL (secure sockets layer) certificate used for our DEMO, NA1, NA2, NA3 and EU environments occasionally expires (every 2 years). When the SSL certificate is set to expire a new SSL certificate will be used. That means If you have custom API, Connect, or any other system integration that depends on Docusign’s SSL certificate then contact your IT department's network administrator to update the certificate to ensure seamless functionality.

Was macht ein Contract Manager

Author Tobias S.
Tobias S.
You may notice when on Docusign’s website that a green padlock sits in front of the URL at the top of your browser. This is a visual cue that our website is secure thanks to SSL certificates, and it’s one that savvy consumers look for when doing business online. SSL certificates play an important role at Docusign, and they should be a part of your data privacy efforts too. Find out more about what they are, what they do, and how you can obtain them, with our SSL FAQs, below. What is an SSL Certificate? SSL stands for Secure Sockets Layer, and SSL certificates are also known as digital certificates. An SSL certificate creates a secure link between a website and a visitor's browser. It ensures that all data passed between the two remains private and secure. There are three types of SSL certificate: Extended Validation (EV SSL), Organisation Validated (OV SSL) and Domain Validated (DV SSL). There are also what is known as wildcard certificates, used to extend SSL encryption to subdomains. Why do companies need an SSL Certificate? SSL certificates establish trust between you and your customer. To obtain an SSL Certificate, the purchasing company's identity must be authenticated. With this safeguard in place, customers know that your business is not only legitimate but that it's safe to do business with you online. If you want to accept credit card information on your website, for example, then you will need to comply with Payment Card Industry (PCI) standards. One of the PCI requirements is using an SSL certificate. SSL certificates also help to prevent you and your customers from suffering a phishing attack. Phishing emails aim to impersonate your website for criminal gain. As the sender cannot receive their own SSL certificate, it makes it far more difficult for them to impersonate your website and easier for them to be caught out. As a result of SSL encryption, hackers and identity thieves are prevented from stealing private and sensitive information such as addresses, social media logins and credit card numbers. Only the intended recipient will be able to understand the information being sent. What should I look for in an SSL certificate provider? The cost of a solution can often be a deciding factor when choosing any tech solution, but when the security of your data it at risk, you shouldn’t necessarily go with the cheapest option. With that in mind, these are the top factors to consider over price alone: Compatibility: The provider should have a high trust pedigree in as many commonly used operating systems, web browsers, apps and devices as possible. Scalability: The provider should also be able to handle volumes that grow with your company, as you may end up needing thousands of certificates per second to be issued. Flexibility: The leading providers offer flexible purchasing terms. Pay-as-you-go, for example, allows you to order certificates when you see fit, regardless of amount. Bulk balance models also allow you to load money into your account. Platform: Your solution needs to be easy to use, support a variety of workflows and has a dynamic portal. Support: It's important to evaluate the services and support offerings available to help you succeed. Is an account manager on-hand, online support offered, communities to ask questions, and educational resources enabling you to self-serve? Where can I find Docusign's certificates? Docusign's digital certificates provide higher levels of identity authentication and document transaction security. Digital certificates cryptography uses Public Key Infrastructure (PKI) technology to issue certificates based on X.509 standards to represent the digital identity of a signer. The latest SSL certificate is always available for download from the Docusign Trust Site. Do I need to update my Docusign SSL certificate? If you do not have a custom SSL integration then no action is needed. Docusign’s SSL (secure sockets layer) certificate used for our DEMO, NA1, NA2, NA3 and EU environments occasionally expires (every 2 years). When the SSL certificate is set to expire a new SSL certificate will be used. That means If you have custom API, Connect, or any other system integration that depends on Docusign’s SSL certificate then contact your IT department's network administrator to update the certificate to ensure seamless functionality.

Entdecken Sie die Neuheiten von Docusign IAM oder starten Sie kostenlos mit eSignature

Entdecken Sie Docusign IAMTesten Sie eSignature kostenlos
Person smiling while presenting