In order for electronic documents to comply with the principles of digital security, they must meet a number of requirements that can be divided into several key categories:
Integrity
- Authenticity: The document must come from a reliable sender and must not be forged. Qualified electronic signatures or qualified seals, among others, are used to ensure authenticity.
- Non-repudiation: The sender cannot deny having sent the document, and the recipient cannot deny having received it. Electronic receipts and qualified time stamps help ensure non-repudiation.
- Data integrity: The content of a document cannot be altered without the knowledge and consent of the parties. Among other things, hash functions and electronic signatures are used to ensure data integrity.
Confidentiality
- Access control: Only authorized recipients should have access to the document. This uses, among other things, encryption, passwords and access permissions.
- Personal data protection: If a document contains personal data, it must be processed in accordance with data protection regulations (RODO).
Availability
- Long-term archiving: Documents should be stored securely and accessible for the required period of time.
- Verifiability: It should be possible to verify the authenticity and integrity of the document in the future, even if technologies change.
Additional requirements
- Regulatory compliance: Electronic documents must comply with applicable laws, e.g. eIDAS, RODO.
- Technical standards: Use appropriate technical standards, e.g., file formats (PDF/A), electronic signature standards (XAdES, PAdES).
- Secure infrastructure: Documents should be stored and processed on a secure infrastructure, protected from cyber attacks.
Digital trust services that help meet these requirements
- Qualified electronic signatures: Ensure the authenticity, integrity and non-repudiation of documents.
- Qualified seals: Certify the authenticity and integrity of documents issued by organizations.
- e-Delivery Boxes: Provide secure and confidential electronic communications.
- Identity confirmations: Enable reliable confirmation of the identity of the parties.
Meeting the above requirements is key to ensuring the digital security of electronic documents and trust in electronic transactions.
Do you want to learn more about a specific digital trust requirement or service? We would be happy to help!