GlobalSign Blog

The Burden of Proof – Why Partnering with a QTSP Lets You Off the Hook for eIDAS Compliance

The Burden of Proof – Why Partnering with a QTSP Lets You Off the Hook for eIDAS Compliance

There are three types of people in the world:

  • Those who don’t know what eIDAS is
  • Those who have heard the term but don’t have time to investigate further
  • DPOs

We joke, of course. The truth is, people in a wide range of job titles and functional groups are finding themselves furiously Googling questions like “What is eIDAS?”  With many new data privacy and digital trust regulations popping up across Europe – and around the world – this issue certainly isn’t going away any time soon.

But one of the most reassuring things to know is that you can relieve much of this burden simply by partnering with an official Qualified Trust Service Provider like GlobalSign. Instead of having to prove that your systems and business transactions are fully secure and sound, you can rest assured that your QTSP has the necessary tools to help you get and stay compliant.  In today’s world where the pace of business is moving faster than ever, that kind of peace of mind is invaluable.

So, what is a Qualified Trust Service Provider (QTSP)?

A Qualified Trust Service Provider is accredited to issue trust services that fulfil the requirements of the eIDAS regulation. All QTSPs are listed on the European Commission’s Trusted List Browser and on the UK Trust List (this is an important distinction since, due to Brexit, an EU QTSP isn't automatically UK QTSP and vice versa).  GlobalSign is the first CA to be awarded the UK QTSP accreditation.

In comparison to a generic Trust Service Provider, the biggest difference is that QTSPs are allowed to issue eIDAS qualified certificates, signatures, and seals. By choosing to buy their certificates, a business can be sure that they will comply with EU data security standards and regulations.

But the strict auditing process for QTSPs has further advantages. It’s an easy indicator that your company is dealing with an established and reliable partner that has gone through a vigorous security audit – offering a level of trust, assurance, and quality that not every service provider can promise.

Why do I need qualified services?

In many cases it’s because of compliance: the need to comply with eIDAS, PSD2, or similar regulations. If you’re doing business within the EU, no matter where your company is based, you’re legally required to adhere to the European regulations.

However, there are many other reasons why companies may decide to work with a QTSP in adopting qualified certificates.

  1. Reduced liability and burden of proof
    Qualified Trust Services can act as evidence in legal proceedings. Qualified Trust Services are assumed to be fully reliable evidence, unless proven otherwise. This stands in contrast to the usual handling of electronic evidence where more often than not, the reliability of electronic records or processes first needs to be proven
  2. Highest level of assurance and trust
    Qualified services are the highest-available level of assurance and trust on the market. Especially in industries where trust is of utmost importance – like the financial sector, education or utilities – this added level of security is critical for the day-to-day operations.
  3. Visual EU trust symbols
    Companies that use QTSPs are allowed to add an EU trust symbol to their website and resources, helping them to gain a competitive advantage and increase customer trust.

 

See how eIDAS and Qualified Trust Services can help in these common scenarios

For public cross-country tenders...streamline and speed up long, paper-heavy processes

Public tenders allow suppliers to bid on projects in a fair and equal way. In the past this was often a very manual paper-heavy process, but with eIDAS this process is shifting to digital. With eIDAS-compliant IDs and websites the players of a tender process are identified, and with a digital signature a document is considered legally signed and tamper proof.
See how eIDAS and Qualified Trust Services can help in these common scenarios:

For taxpayers...avoid last minute penalties with digital tax returns

Submission time at the end of a tax year often ends with a crazy rush to get documents completed in time for the governmental deadlines. Luckily eIDAS allows you to submit your tax return digitally, whether you’re an individual or a company. With the right tools you can prove your identity and digitally sign your tax return.

For invoicing...eIDAS invoicing ensures secure and tamper proof invoice management

Digital invoices have several advantages over paper:

  • Being able to get the invoice to the customer quicker (thus being paid earlier!)
  • Being able to show proof of delivery and acceptance
  • Maintaining invoice integrity by preventing retrospective changes
  • And saving time and costs by simplifying the process.

For signing contracts...enable speedy and convenient document signing world-wide with added assurances

Multi-signature contracts can be a burden to manage, especially with an increase in remote working. Digital signatures are the legal equivalent of handwritten signatures, but also guarantee that a document hasn’t been changed retrospectively. They speed up the process and allow signees in different locations to add their signature simultaneously.

What do I need to get started?

First of all, you need to establish which trust services will help your business thrive. If you’re unsure, you can either check out some of the available services below, or reach out to members of our team, who would be happy to discuss your specific requirements.

Advanced or qualified digital signatures express agreement to content or a set of data in a digital format. They are legally on par with handwritten signatures. They are a convenient way for businesses and customers to legally sign documents, reducing costs and time.

Qualified timestamping adds a trusted, undisputable time and date to electronic signatures. They enhance document tracking and add accountability.

Qualified digital seals provide guarantee of origin and data integrity. This creates trust and helps reduce costs and time. They can be used for authentication purposes and ensuring secure end-to-end communication.

Qualified Website Authentication Certificates prove ownership of a website and ensure secure transmittance of data. This leads to increased consumer trust and protects the reputation of your business.

Benefits of GlobalSign as your QTSP

GlobalSign has been accredited as QTSP as one of the first global certificate authorities back in 2018. As an established QTSP GlobalSign can help you comply with regulations like eIDAS or PSD2.

Here are the top three reasons why you should make GlobalSign your eIDAS certificate authority:

  1. 25 years industry experience
    GlobalSign has been in the industry for a quarter of a century. We’ve grown and shaped the security landscape over the years and have experts on hand to guide you to the right solutions. GlobalSign is already an approved Qualified Trust Service Provider in the EU, and is now the first QTSP on the UK trust list.
  2. Broad range of qualified solutions
    You can buy a wide range of qualified solutions from one trust provider. GlobalSign has one of the broadest ranges of available solutions, so you can be sure that we’ve got what you need.
  3. Multi-lingual 5-star support team
    We’re a global company with support staff across the globe – you can rely on us to help you when you need it, wherever you need it.

eIDAS has helped organizations to innovate and to add security to their business processes. With qualified trust services businesses can ensure authenticity, data origin and data integrity, provide cross-border trust within the EU and EEA countries and most importantly give you compliance with regulations like eIDAS and PSD2.

If you want to benefit from the high assurance, please get in touch with us for more information.

Share this Post