DigitalSign is first and foremost a Certification Authority (CA) accredited by the GNS, acting as a provider of qualified trust services under the eIDAS regulation, with operations in Portugal, Europe and Brazil. It therefore issues digital certificates and also provides electronic signature solutions for both companies and individuals.
DigitalSign is based in Largo Fr. Bernardino Ribeiro Fernandes, 26, 4835-489 Nespereira - Guimarães, Portugal.
Telephone (351) 253 560 650/651 or e-mails geral@digitalsign.pt and comercial@digitalsign.pt.
Legally, an electronic signature is "data in electronic format that connects or is logically linked to other data in electronic format and is used by the signatory to sign" (Article 3(10) of the EIDAS Regulation).
This definition is deliberately broad: it covers from a simple name written at the end of an email to a cryptographic signature based on a qualified digital certificate. What distinguishes the various types of signature is not the format, but the level of guarantee they offer regarding the identity of the signatory and the integrity of the document and, consequently, its evidentiary value.
It is the base category, corresponding to the general definition above. Includes any mechanism that expresses the will to sign: a digitally written name, a handwritten signature image scanned in a PDF, a confirmation click. It does not require identity verification or guarantees the integrity of the document.
Adds safety requirements as defined in Article 26 of the EIDAS. It shall fulfil four cumulative conditions: be uniquely associated with the signatory; enable the signatory to be identified; be created with creation data which the signatory can use, with a high level of confidence, under his sole control; and be linked to the data signed in such a way that any subsequent change is detectable.
It's the highest level. This is an advanced electronic signature that meets two additional requirements: it is created by a qualified electronic signature creation device and is based on a qualified certificate issued by a qualified trust service provider (Article 3(12)). It is the only type of signature that the law equates to handwritten signature and enjoys the same probative force.
The decisive difference lies in two elements: the qualified certificate and the qualified creation device.
An advanced signature may be technically robust, but the identity of the signatory may not have been verified by a Certified Trust Service Provider, such as DigitalSign, and the signature creation data may not be protected on a certified device.
In a qualified signature, a Qualified Trust Service Provider (QTSP) has previously verified the identity of the holder, and the private key is protected on a qualified device (a smartcard, USB token or a hardware security module – HSM – for cloud solutions).
The Portuguese regime results from the articulation between eIDAS and Decree-Law No 12/2021. The legal value of
document is essentially modulated according to the type of subscription bet:
In turn, it is the strongest regime. In accordance with Article 25(2) of the EIDAS, the qualified electronic signature has a legal effect equivalent to that of a handwritten signature. Decree-Law No 12/2021 implements this principle: the affixing of a qualified electronic signature to an electronic document is equivalent to the autograph signature and creates the presumption that (i) the person who signed the signature is its holder or has the power to represent the legal person; (ii) the signature was affixed with the intention of signing the document; and (iii) the document has not been changed since the affixment. Where the content is susceptible to representation as a written declaration, the document shall have the probatory force of a particular document signed in accordance with Article 376 of the Civil Code.
In this case, the law does not attribute an enhanced and specific probationary regime to these types. The rule of Article 3(10) of Decree-Law No 12/2021 applies: unless special provision is made, the probative value of electronic documents not associated with qualified trust services shall be assessed in general terms of law. In practice, this means that its probationary force is subject to free trial by the court. The electronic document is not devalued because it is electronic but does not benefit from automatic assumptions reserved for qualified electronic signature.
Nope. The EIDAS Regulation establishes the principle of non-discrimination: no legal effect or admissibility as evidence in legal proceedings may be denied to an electronic signature simply because it is presented in electronic format or does not comply with the requirements of the qualified signature (Article 25(1)).
The same principle applies to electronic seals, time stamps, registered shipping services and electronic documents in general.
In other words: a simple or advanced signature is admissible as evidence. The question is not admissibility, but the evidentiary weight, and that is where the qualified signature is distinguished, because it benefits from equivalence to the handwritten signature and associated legal assumptions.
The electronic seal is a figure introduced by the EIDAS Regulation, technically similar to a signature certificate, but with an essential difference: it is intended exclusively for legal persons, while the signature is for natural persons.
The purpose is also distinct, and the signature expresses the will of a natural person (the signatory). In turn, the seal guarantees the origin and integrity of a document emanating from a legal person. It works, in the logic of the Regulation, in a manner similar to an organisation's white stamp or stamp.
Therefore, the stamp is not, in itself, the appropriate figure to contractually bind the legal person, in the same way that, in the physical world, the stamp of a company does not suffice to bind it.
The choice depends on the legal risk and legal requirements applicable to the act. As general guidance:
It is recommended where equivalence to written form and handwritten signature is required, in acts of high value, in a regulated context, or where legal certainty and non-repudiation are critical. A recurring example is public procurement, where documents submitted on electronic platforms must be signed with a qualified signature.
It may be suitable for internal flows or relationships between parties that have previously agreed on its value, where changes are intended to be identified and detected without the maximum level of guarantee.
Serves for low-risk and high-volume acts (acceptance of terms, confirmations), where friction should be minimal.
A Digital Certificate Qualified is an electronic certificate issued by a Qualified Trust Services Provider that safely associates the identity of a person (pre-verified by the provider) to a pair of cryptographic keys. It is this certificate, combined with a qualified signature creation device, which allows the production of qualified electronic signatures with equivalence to the handwritten signature.
The CDQ may be housed in a physical cryptographic device owned by the holder (smartcard or USB token) or in a cloud solution where the key is protected in a hardware security module (HSM) managed by the qualified provider.
Because the private key is what makes your signature. Annex II to the EIDAS Regulation requires qualified devices to ensure that signature creation data are protected against use by third parties and that their confidentiality is reasonably guaranteed. The holder shall have the duty to keep the private key under his sole control and to take the necessary measures to prevent unauthorized use throughout the period of validity of the certificate.
If a third party obtains access to the key and activation codes, it may produce qualified signatures on its behalf, with all the associated legal consequences, including the presumption that it was the holder who signed it.
On the basis of safety recommendations for holders of qualified certificates:
When issuing the certificate, choose an email and/or mobile phone number for personal and exclusive use, to which only the holder has access. It is through these channels that communications and codes relating to the use of the certificate circulate and should therefore be protected from third-party access.
As for the physical device (smartcard or token), never provide it to third parties, nor share the access passwords (PIN and PUK). These codes are exclusive and are intended only for the legitimate use of the certificate by the holder. As regards the private key, ensure that it is kept under its control and that it takes the necessary steps to prevent unauthorized use throughout the period of validity. Do not disclose or provide third parties with identification parameters and procedures.
As for authentication, value dual-factor mechanisms. In cloud solutions, each signature typically requires two factors: a password defined by the owner and a random code sent by SMS to the previously confirmed mobile phone number.
Strong user authentication is defined by eIDAS (Article 3, paragraph 51, in the wording of eIDAS 2.0) as an authentication based on at least two factors belonging to different categories, knowledge (something only the user knows, as a password), possession (something only the user has, as a mobile phone) and inertia (a characteristic of the user, such as biometrics).
These factors should be independent, so that the breach of one does not compromise the reliability of the others, and the mechanism should protect the confidentiality of authentication data. It is this principle that is the basis of the double factor (password + SMS code) used in signatures in cloud solutions.
Yeah. As a provider of qualified trust services and IDAS, certificates are recognised throughout the European Union. In addition, DigitalSign also certifies in Brazil.
It shall immediately request the withdrawal of the certificate from the qualified provider. The revocation shall definitively withdraw the validity of the certificate: in accordance with the EIDAS Regulation, a qualified certificate revoked after initial activation shall lose its validity from the moment of revocation, and no one may reverse its status under any circumstances (Articles 28(4) and 38(4)).
The qualified provider shall record the revocation in his database and publish it in good time, always within 24 hours of receiving the request, and the revocation shall take effect immediately after publication (Article 24(3)).
Note that, for security reasons, cloud solutions usually do not have password recovery mechanisms: if the password is lost, the certificate may become unusable and have to be reissued. Therefore, safe guarding of activation codes is an essential part of good practice.
Typically not. In cloud solutions, you can change the password as long as you know the current password, but there are no recovery mechanisms if the password is forgotten, a deliberate security measure that prevents third parties (including the provider itself) from accessing the key.
Losing the password actually means losing access to the certificate.
Validating a signature is the electronic process by which the signature is verified and confirmed (Article 3(41) of the EIDAS Regulation). It is not enough that a document appears to be signed: validation technically confirms that the signature is qualified, that the certificate on which it is based was valid at the time of signature, that the identity of the signatory is correctly represented, and that the document has not been changed since it was signed.
Thus, it is an essential step before accepting any signed document, from a contract to an electronic invoice
Because validation only has full confidence value if whoever carries it out is able to do so. In accordance with Article 33 of the EIDAS, only qualified providers of trusted services can provide qualified services to validate qualified signatures. DigitalSign is accredited in Portugal to provide this qualified service.
Using a qualified service gives you the certainty that the verification is carried out in accordance with a strict validation policy and in accordance with the technical standards that implement Article 32, and allows you to obtain official reports with evidence value.
DigitalSign provides an affordable electronic signature validator (DS Verify) Here..
The typical flow consists of loading the signed electronic document (e.g. a PDF or an XML file); the tool returns, in real time, the result of validation of the signature(s) or stamp(s) present, accompanied by a report that can be kept as documentary evidence.
The tool complies with eIDAS, in particular Article 32, and is a qualified service, which you can check on the EU Trusted List.
A validation report is a document demonstrating the results of the validation carried out. It can be used as evidence that the signatures and stamps present in a document were valid at the time of its creation and until the time when the validation was carried out, something particularly useful in audits, legal proceedings or formal acceptance of documents. DS Verify provides two types of report:
In turn, the Summary report, which gives access to essential information on the validation process in a simplified way
In this case, the Detailed Report, which presents the complete result of the technical checks carried out.
In this way, maintaining these reports allows you to implement, in your organization, a vector flow that proves that validation was effectively carried out
It's a good recommended practice. Before accounting for an electronic invoice, it is appropriate to always verify the legal validity of the signature or stamp attached to it, which helps prevent fraud. The authenticity of the origin and the integrity of the content of the electronic invoices shall be deemed to be guaranteed, in particular by affixing a qualified electronic signature or a qualified electronic seal.
Because the technical trust of a signature is not eternal. Cryptographic algorithms age, certificates expire, and technology evolves. A signature that is unquestionably valid today can, in several years' time, become difficult to verify if nothing is done, not because someone tampered with the document, but because the technical means that supported its validity have become obsolete.
The preservation solves this problem: it prolongs the reliability of the signature beyond the technological validity period, ensuring that it is still valid in the long term.
In accordance with Article 34(1), only qualified trusted service providers using procedures and technologies capable of prolonging the reliability of qualified signatures beyond the technological validity period may provide qualified electronic signature preservation services.
Where the service complies with the standards, specifications and reference procedures established by the Commission, the law assumes that it complies with this requirement (Article 34(1a).
These are complementary but distinct operations:
According to (Article 32/33) it is a verification at a time: it confirms whether the signature is valid now, or whether it was valid at a given date.
In turn, preservation (Article 34) is a protection over time. In other words, it ensures that the signature will remain verifiable and reliable in the future, even with the evolution of cryptographic algorithms. This happens, in particular, through the application of mechanisms such as the renewal of temporal seals and the maintenance of validation evidence.
In a simple image: on the one hand, validating is taking a photograph that proves the status of the signature; on the other, preserving is ensuring that this proof remains legible and reliable for years.
DigitalSign provides an electronic signature preservation service (DS Verify), accessible Here..
This is therefore a qualified service. In addition, it ensures the validity of signatures over time as well as their suitability for new cryptographic algorithms. It can also be combined with secure custody (file) of the documents.
DigitalSign has thus obtained the certification for the qualified electronic signature preservation service. In this way, this service joins the validation services that it had previously provided.
The European Digital Identity Wallet, or EUDI Wallet) is one of the main innovations introduced by Regulation (EU) 2024/1183 (eIDAS 2.0). Thus, it is defined as an electronic means of identification.
This enables the user to safely store, manage and validate personal identification data and electronic attribution certificates. On the other hand, it also allows you to provide them to third parties who need them.
In addition, it makes it possible to sign with a qualified electronic signature and also to affix stamps with qualified electronic seals (Article 3, paragraph 42).
In practice, it will be a mobile application that will function as a digital "container" of identity and documents, usable both online and in face-to-face (out-of-line) throughout the European Union.
Yeah. In accordance with Article 5a(1), each Member State shall provide at least one European Digital Identity Card. This, however, within 24 months of the entry into force of the relevant implementing acts.
Moreover, the widely disseminated timetable points to the availability of portfolios by Member States by the end of 2026.
The portfolio may be provided in one of three ways (Article 5a(2)): directly by a Member State; by mandate of a Member State; or independently of a Member State, but recognised by it
It does not replace and is not mandatory. Moreover, the use of the European Digital Identity Card is voluntary (Article 5a, paragraph 15).
The law is expressed: no one can restrict access to public and private services, to the labour market and to freedom of enterprise, nor to disfavor anyone who does not use the portfolio. It is therefore still possible to access these services through existing means of identification and authentication.
Poranto, in Portugal, the Citizen Card will continue to exist as a physical document; the digital wallet is an additional option, not mandatory.
Total control, by design. EIDAS 2.0 is based on principles of data protection and user sovereignty. The user shall fully monitor the use of the portfolio and the data contained therein (Article 5a(14)), and the supplier shall not collect information on the use that is not necessary for the provision of the service, nor shall the data be combined with those of other services without express request from the user.
The portfolio also allows selective disclosure of data. That is, it allows you to share only the strictly necessary attribute. For example, you can prove that you are of age without revealing the date of birth.
In addition, the technical framework shall prevent suppliers of attribute certificates or third parties from following, connecting or correlating the user’s behaviour. It should also allow techniques to preserve privacy. Therefore, these techniques guarantee the absence of association where identification is not required (Article 5a(16)).
The user also has a control panel recording all transactions. This panel allows you, on the one hand, to see with which entities you have connected and what data you have exchanged. On the other hand, it allows you to request the deletion of personal data and to report requests for illegal or suspicious data (Article 5a(4)(d).
An attribute is a characteristic, quality, right or authorisation of a person or object (Article 3, point 43). An electronic certificate of attributes is an electronic certificate that allows authenticating those attributes (paragraph 44), e.g. an academic qualification, a professional qualification, age, address or representation mandate.
The portfolio is designed to request, obtain, store and manage these attribute certificates by combining them with personal identification data. The EIDAS 2.0 Regulation establishes in Annex VI a minimum list of attributes (such as address, age, gender, marital status, nationality, qualifications, professional qualifications, or powers of representation) which Member States shall allow to verify electronically, by comparison with authentic sources of the public sector (Article 45e).
The highest. The portfolio shall be provided under an electronic identification system with high collateral level (Article 5a(11)) and shall ensure security from design (paragraph 12). Its compliance, including cybersecurity aspects, shall be certified by conformity assessment bodies designated by Member States (Article 5c).
In the event of a security breach which compromises the reliability of the portfolio, the Member State shall suspend its supply and use without delay and, if the gravity justifies it or if the failure is not corrected in three months, withdraw it and revoke its validity (Article 5e).
Yeah. Cross-border interoperability is one of the pillars of the regime.
Therefore, where a Member State requires electronic identification and authentication to access an online service of a public body, it shall also accept the European Digital Identity Cards provided under Regulation (Article 5f(1)).
In addition, the obligation extends to certain private individuals. In other words, service providers in sectors such as banking, energy, transport, health, telecommunications or education, when required to use strong authentication of the user, should also accept the portfolio. This, however, only within 36 months of the entry into force of the relevant implementing acts (Article 5f(2)).
The portfolio tends to become the uniform European basis for identification and onboarding processes of customers and employees, including KYC (Know Your Customer) and prevention of money laundering, with cross-border legal validity. To this end, it integrates the possibility of qualified electronic signature directly into the application.
For Qualified Trust Service Providers as DigitalSign, makes room for value added services around the portfolio, remote qualified signatures integrated into EUDI Wallet, timing, electronic stamps, e-delivery, validation and preservation, which complement digital identity and make it possible, with simple usability, to maintain security and legal validity.