Qualified electronic signature – basic information

Electronic signatures are becoming increasingly popular due to their convenience and speed. They make it possible to sign documents remotely, which saves both time and money. More and more companies and government institutions accept qualified electronic signatures and treat them as equivalent to handwritten signatures. In this article, we will discuss the advantages of e-signatures and present various ways they can be used.

Electronic signature vs qualified electronic signature – comparison

An electronic signature and a qualified electronic signature are two different forms of electronic signatures that differ in several ways.

An electronic signature is a general term that refers to any form of electronic signature used to authorize a document. An electronic signature can be generated using various tools, such as a scanned handwritten signature, biometric data such as fingerprints, or dedicated software for creating electronic signatures.

A qualified electronic signature is one of the most advanced and secure forms of electronic signature. It is issued only after completing a detailed identity verification process, which ensures that the signer is truly the person they claim to be. A qualified e-signature also requires a special qualified certificate issued by authorized certification authorities.

Compared to a standard electronic signature, a qualified electronic signature has greater legal value because it meets specific requirements regarding the authenticity, integrity, and non-repudiation of the signed data. A qualified electronic signature is recognized in most countries and is widely used in areas such as commercial agreements, tax documents, insurance documents, and more.

Qualified electronic signature – how does it work?

An electronic signature is a modern version of a traditional handwritten signature, used to confirm the authenticity and integrity of an electronic document. An e-signature is based on cryptography, a technology that protects data against unauthorized access or modification. It consists of two parts: the electronic signature itself and an electronic certificate.

The signature is generated by the user who confirms the authenticity of the document, while the electronic certificate is issued by a trusted entity, such as a Trusted Third Party (TTP), which verifies the user’s identity. The main purpose of this solution is to confirm both the authenticity of the electronic document and the identity of the person who signed it.

A Certum electronic signature can be used, among other things, to sign:

  • financial statements,
  • PDF documents,
  • B2B and B2C agreements,
  • invoices

Where are digital signatures used?

A qualified signature certificate is being used increasingly often across various industries. Due to its convenience and efficiency, it is commonly applied in areas such as e-commerce, e-government services (for example, ZUS PUE), e-education, and e-healthcare.

However, to use it, you must have the appropriate tools and software, as well as an electronic certificate issued by a trusted provider such as Asseco Certum.

Types of e-signatures

There are different types of electronic signatures:

  • Qualified electronic signature – considered the highest level of security. It is used for important legal documents such as contracts and financial documents.
  • Advanced electronic signature – used for documents that require a medium level of security.
  • Simple electronic signature – used for documents that require a low level of security.

Advantages of an electronic signature

  1. Convenience – an electronic signature streamlines everyday work because you can sign documents electronically from anywhere and at any time. This is especially useful for people who need to sign documents quickly while being in different locations.
  2. Time and cost savings – a digital signature eliminates the need for physical travel and document delivery, resulting in significant savings in both time and costs.
  3. Security – electronic signatures are based on cryptography, which protects documents against unauthorized access or modification.
  4. Non-repudiation – an electronic signature is difficult to forge, which increases its credibility and makes it possible to prove that a document was signed by a specific person.
  5. Legality – in many countries, including Poland, there are legal regulations governing the use of qualified certificates for signing documents, giving them the same legal status as a traditional handwritten signature.

Electronic signature under Polish law

In Poland, digital signatures are regulated by the Electronic Signature Act, which came into force in 2002. The act states that a qualified electronic signature is equivalent to a traditional handwritten signature and has the same legal effect.

The act also defines the requirements for electronic certificates that must be met by entities issuing such certificates, namely qualified trust service providers.

Security of a qualified electronic signature

The security of a qualified electronic signature is crucial for its effective use in practice. To ensure an appropriate level of security, a number of protective measures are applied.

First, a qualified electronic signature must be based on a qualified certificate issued by certification authorities with the appropriate authorizations. The qualified certificate confirms that the signer is truly the person they claim to be and that the signature is valid.

Second, a qualified electronic signature must be based on a cryptographic key protected against unauthorized access by passwords or other authentication methods. The cryptographic key is used to sign documents and is uniquely linked to the qualified certificate.

Third, to ensure data integrity, a qualified electronic signature is usually based on cryptographic algorithms that prevent unauthorized modifications to the data after the document has been signed.

Ultimately, responsibility for unauthorized use of a qualified electronic signature lies with the signer, who should protect their passwords and cryptographic keys against unauthorized access and misuse.

All of these security measures help ensure that a qualified electronic signature is effective, secure, and trustworthy.

How long are qualified signature certificates valid?

The validity period of a certificate depends on individual needs and preferences. When purchasing a new electronic signature, you can choose a certificate valid for 1 year, 2 years, or 3 years (both for the mobile application version and the traditional card reader version).

If you need a qualified signature certificate or would like to extend the validity period of your certificate, please contact us.

Leave a comment