No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
    • Upcoming
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

How the GDPR Will Impact E-Signatures

by Rahim Kaba
July 9, 2018
in Data Privacy, Featured
blue "sign" button on keyboard

4 Key Criteria to Consider When Evaluating Solutions

The EU General Data Protection Regulation is now officially in effect. If your organization transacts with individuals and businesses on a global scale and is looking to implement e-signatures, ensure the solutions on your shortlist are able to demonstrate full compliance with the GDPR requirements. Here are four key criteria to consider.

The European Union’s (EU) new landmark privacy law called the General Data Protection Regulation (GDPR) [Regulation (EU) 2016/679] is now officially in effect. The GDPR expands the privacy rights of EU individuals and places new obligations on organizations that market, track or handle EU personal data. The rise of technologies such as the cloud and social media has changed the privacy landscape for good, and the EU’s updated data privacy standard takes into account the implications of these new technologies on personal data. The good news is that unlike its predecessor, the Data Protection Directive 95/46/EC that introduced administrative burdens and a fragmented legal framework, the GDPR is a single law and applies unilaterally across the EU as of May 25, 2018.

All companies that process and hold the personal data of individuals residing in the EU must comply with the GDPR, regardless of company location. This includes e-signature providers that help organizations around the world automate and digitize their manual, paper-based processes. E-signature solutions manage and process documents that may include personal data, therefore it is important that they ensure adequate privacy protection and empower citizens the right to access their personal data. If your organization transacts with individuals and businesses on a global scale and is looking to implement e-signatures, ensure the solutions on your shortlist are able to demonstrate full compliance with the GDPR requirements.

Here are four key criteria to consider when evaluating e-signature solutions to ensure they meet the security and data privacy needs of businesses in the EU:

1. Does it prohibit the export of personal data from the EU?

The solution should be able to meet data localization requirements by using a deployment model where the system used to process personal data is self-contained within the target region (i.e., the EU). This is important because data should be captured, processed and stored within in the target region and there should be no interconnection between the environments that would result in data and documents being transferred over to a different geographic area. If personal data leaves the EU and the e-signature system has a dependency on servers in other parts of the world (e.g., the U.S.), the solution is not meeting requirements outlined in the GDPR.

2. Does it ensure the “right of access?”

Part of the expanded rights of data subjects (i.e., your consumers) outlined by the GDPR is their right to obtain from the data controller (i.e., your business) confirmation as to whether or not personal data concerning them is being processed, where and for what purpose. Make sure the vendor you select ensures the right of access, a critical GDPR requirement.

3. Does it offer a flexible deployment architecture?

If your organization isn’t ready for the cloud, look for a provider that also offers both on-premises and private cloud deployment options with data centers around the world to meet regional data residency requirements. And because your IT and security needs will change over time, ensure that you have the flexibility to migrate from one deployment to the other.

4. Is it built on market-leading cloud infrastructure services (e.g., Amazon Web Services, Microsoft Azure, IBM Cloud, etc.)?

Proven and enterprise-ready e-signature solutions are built on compliant and highly secure global data centers with real-time replication of data, optimal performance and military-grade security of facilities. E-signature vendors with an “owned” data center strategy should be considered a risky bet.

Consult your legal counsel to determine the impact of the GDPR on your business and what you can do to ensure the GDPR-compliant processing of your data and documents. GDPR readiness is a shared responsibility. The GDPR is a shared journey, as it sets out obligations for the various parties involved in controlling and processing personal data. It is a set of regulations that go beyond a simple checklist of requirements that can be fulfilled by a service provider alone. GDPR compliance requires a partnership between the provider that processes personal data and the business or organization that controls it.


Tags: GDPR
Previous Post

5 Essential Strategies to Improve Workplace Culture

Next Post

Moving From Reports to Analytics, Part 2

Rahim Kaba

Rahim Kaba

Rahim Kaba is Director of Product Marketing at OneSpan, where he is responsible for planning and growth strategies for the OneSign Sign and Vault product portfolio. He leads the global product marketing team and is responsible for the company's go-to-market, gathering customer & market insights and driving innovation in the core markets that OneSpan serves. An expert in the field of electronic signatures and e-vaulting solutions, Rahim has been a driving force in advancing the digital transactions marketplace.

Related Posts

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

gdpr website screenshot

In the World of JavaScript, GDPR Consent Forms Merely Scratching the Surface

by Rui Ribeiro
December 16, 2024

Consent forms alone don’t mean much when consumers are so tired of checking boxes they don’t even read the policies

us map black and white

Minnesota Latest State to OK Consumer Data Privacy Law

by Amanda Novak
August 26, 2024

Measure set to go into effect for most covered entities next summer

Next Post
businessman on virtual screen reading HR

Moving From Reports to Analytics, Part 2

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
    • Upcoming
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights