Electronic signature framework

Size: px
Start display at page:

Download "Electronic signature framework"

Transcription

1 R E P U B L I C O F S E R B I A Negotation Team for the Accession of Republic of Serbia to the European Union Working Group for Chapter 10 Information society and media Electronic signature framework

2 Contents Legal framework Harmonization with the EU Directive Supervision Certification bodies Projects Challenges and future activities

3 Relevant Acquis Directive 1999/93/EC of the European Parliament and of the Council of 13 December 1999 on a community Framework for Electronic Signature 31999L0093 Commission Decision 2000/709/EC of 6 November 2000 on the minimum criteria to be taken into account by Member States when designating bodies in accordance with Article 3(4) of Directive 1999/93/EC of the European Parliament and of the Council on a Community framework for electronic signatures 32000D0709 Commission Decision 2003/511/EC of 14 July 2003 on the publication of reference numbers of generally recognised standards for electronic signature products in accordance with Directive 1999/93/EC of the European Parliament and of the Council D0511 Proposal for a Regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market COM(2012) 238 final of /0146 (COD) 52012PC0238

4 National Legislation Law on Electronic Signature (Official Gazette of RS No. 135/04) Regulation on specific terms and conditions for issuing qualified electronic certificates (Official Gazette of RS No. 26/08) Regulation on technical and technological procedures for creating a qualified electronic signature and criteria to be met by devices for creating a qualified electronic signature (Official Gazette of RS No. 26/08, 13/10) Rulebook on register of certification bodies for qualified electronic certificates issuing in the Republic of Serbia (Official Gazette of of RS No. 26/08) Rulebook on the records of certification authorities (Official Gazette of of RS No. 48/05, 82/05, 116/05) Law on Electronic Document (Official Gazette of RS No. 51/09) Regulation on Time Stamp Issuing (Official Gazette of RS No. 112/2009)

5 esignature framework Law on Electronic Signature (2004) - Regulation on specific terms and conditions for issuing qualified electronic certificates (2008); - Regulation on technical and technological procedures for creating a qualified electronic signature and criteria to be met by devices for creating a qualified electronic signature (2008, 2010); - Rulebook on register of certification bodies for qualified electronic certificates issuing in the Republic of Serbia (2008); - Rulebook on the records of certification authorities (2005) Law is harmonized with EU regulations Two main roles of Law: - To define conditions under which electronic signatures are legally equal to handwritten signatures; - To define which requirements must be met by Certification bodies for the issuance of qualified electronic certificates

6 Technological framework for esignatures Standards ETSI (European Telecommunications Standards Institute) ESI (Electronic Signatures and Infrastructures); Standards CEN/ISSS and documents CWA (CEN Workshop Agreement); Documents IETF RFC (Request for Comments); Documents and recommendations of the company RSA Data Security PKCS (Public Key Cryptographic Standards); Common Criteria (for Information Technology Security Evaluation) in section EAL (Evaluation Assurance Level); American standards FIPS (determined by the standardization body: National Institute of Standards and Technology - Federal Information Processing Standards).

7 Scope Directive 1999/93/EC - Article 1 Law on Electronic Signature: Scope of the Law: The present Law shall govern the use of the electronic signature in legal transactions and other legal deeds and in the conduct of business, as well as the rights, duties and liabilities associated with the electronic certificates, unless otherwise provided by other laws. The provisions of the present Law shall also apply to the communications between authorities, communications between authorities and parties and presentation and drawing up of decisions of the authorities in electronic form in the administrative, court and other proceedings before a government agency, if the law governing such proceedings provides for the use of electronic signature. Article 1

8 Law on Electronic Signature: Definitions - Article 2 Electronic signature Advanced electronic signature Certification service provider Etc. Definitions Directive 1999/93/EC - Article 2 A qualified electronic signature shall meet the following requirements : 1) That it is associated with the signatory exclusively; 2) That it identifies the signatory unambiguously; 3) That it comes into being using the means which the signatory can control independently and which are kept under the signatory s exclusive supervision; 4) That it is directly associated with the data it relates to in a way which unambiguously allows any change made in the original data to be inspected; 5) That it has been formed on the basis of the signatory s qualified electronic signature; 6) That it can be verified on the basis of the signatory s qualified electronic certificate. Article 7

9 Law on Electronic Signature: Market access Directive 1999/93/EC - Article 3 Certification bodies do not have to possess special electronic certificateissuing licences - Article 13 The ministry responsible for the information society (hereinafter: the competent authority) shall set the technical and technological procedures for the formation of qualified electronic signatures and the criteria to be satisfied by the qualified electronic signature forming means - Article 11 The competent authority shall keep the Register of Certification Bodies for the Issuance of Qualified Electronic Certificates in the Republic of Serbia Article 19

10 Market access Directive 1999/93/EC - Article 3 Law on Electronic Signature: If a certification body meets the requirements referred to in Article 18 of the present Law, the competent authority shall render a decision allowing it be entered in the Register - Article 20 The competent authority shall exercise inspective supervision over the enforcement of the present Law and operation of the certification bodies - Article 36 There is no provision in the Law on Electronic Signatures, which prevents the use of electronic signatures in the public sector.

11 Legal effects of electronic signatures Directive 1999/93/EC - Article 5 Law on Electronic Signature: In relation to the data in the electronic form, a qualified electronic signature shall produce the same legal effect and probative force as a manually affixed signature and as a manually affixed signature and stamp, in relation to the data in paper form - Article 10 An electronic signature may produce legal effect and may be used as evidence in legal proceedings, except when under a special law, only a manually affixed signature can produce legal effect and probative force - Article 6

12 Law on Electronic Signature: Liability Directive 1999/93/EC - Article 6 Any certification body which is issuing qualified electronic certificates or guarantees the qualified electronic certificates of some other certification body shall be liable for any damage done to a person who has relied on such certificate in the following cases: 1) If the information included in a qualified electronic certificate was not correct at the time of its issuance; 2) If the certificate does not include all of the elements prescribed for a qualified electronic certificate; 3) If it has not checked at the moment of issuance of the certificate whether the signatory is in possession of the electronic signature forming data which correspond to the electronic signature verification data;

13 Law on Electronic Signature: Liability Directive 1999/93/EC - Article 6 4) If it fails to make sure that the electronic signature forming and verification data can be used complementarily, in the cases in which such data are generated by the certification body; 5) If it fails to revoke a certificate in compliance with the provisions of Article 30 of the present Law; No certification body shall be liable for the damage referred to in paragraph 1 of this Article, if it proves that it has acted in accordance with law and its general and internal rules of operation - Article 34

14 Liability Directive 1999/93/EC - Article 6 Law on Electronic Signature: For the purposes of the present Law, a qualified electronic certificate shall mean an electronic certificate issued by a certification body engaged in the issuance of qualified electronic certificates, which shall contain the following: 8) Limitations on the use of certificate, if any Article 17 No certification body shall be liable for any damage resulting from the use of a certificate beyond the scope of limitations, if such limitations are clearly stated in the certificate Article 34

15 International aspects Directive 1999/93/EC - Article 7 Law on Electronic Signature: The electronic certificates issued by any foreign certification body shall enjoy the same treatment as domestic electronic certificates. The qualified electronic certificates issued by foreign certification bodies shall enjoy the same treatment as the domestic ones in the following cases: 1) If the foreign verification body concerned has obtained the competent authority s permit pursuant to Articles 18 and 20 of the present Law, or 2) If they originate from a country with which a bilateral agreement has been concluded on the mutual recognition of qualified electronic certificates Article 35

16 Law on Electronic Signature: Data protection Directive 1999/93/EC - Article 8 The duties of any certification body engaged in the issuing of qualified electronic certificates shall be as follows: 9) Acting in compliance with the provisions of laws and regulations governing the safeguarding of personal data. Article 28 A qualified electronic certificate may be issued to any person on its own request, on the basis of its identity which has been established beyond any doubt and other data relating to the applicant. Article 24 The use of pseudonyms is not regulated by the Law on Electronic Signature.

17 Directive 1999/93/EC ANNEX I Requirements for qualified certificates ANNEX II Requirements for certificationservice-providers issuing qualified certificates ANNEX III Requirements for secure signature-creation device ANNEX IV Recommendations for secure signature verification Law on electronic signature Article 17 and (A Article and Article of Regulation on specific terms and conditions for issuing qualified electronic certificates) Article 18 Article 8 Article 9

18 Commission Decision 2003/511/EC Decision 2003/511/EC Law on electronic signature 1. Regulation on specific terms and conditions for issuing qualified electronic certificates; Decision 2003/511/EC 2. Regulation on technical and technological procedures for creating a qualified electronic signature and criteria to be met by devices for creating a qualified electronic signature A.1.1 (1) Article 58 A.1.2 (2) Article A.2 (1) Article (1) Article (2) Article (2) Article (2) Article

19 Supervision Law on Electronic Signature: Article The competent authority shall exercise inspective supervision over the enforcement of the present Law and operation of the certification bodies. The authorities duly designated by the laws and regulations governing the safeguarding of personal data shall supervise the operation of certification bodies in the collection, use and safeguarding of the personal data of users. Supervision-Ministry of Trade, Tourism and Telecommunications. FESA Membership

20 Proposal for a Regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market Electronic time stamp Section 5 Law on Electronic Document: - Time Stamp Generation System - Article 14 and Article 15 - Request for Time Stamp Generation - Article 16 - Time Stamp Data Structure Content - Article 17 - Time Contained in the Time Stamp - Article 18 - Time Stamp Safekeeping - Article 19 Regulation on Time Stamp Issuing

21 Proposal for a Regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market Electronic documents Section 6 Law on Electronic Document: - Electronic Document Legal Effect Article 4 - Electronic Document Creation - Article 5 - Electronic Document Presentation Forms - Article 6 - Electronic Document Copy - Article 7

22 Proposal for a Regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market Qualified electronic delivery service Section 7 Law on Electronic Document: Electronic documents' delivery Section 3: - Certificate on Electronic Document Receipt Article 8 - Electronic Document Duplication Article 9 - Electronic Documents' Delivery among Government Bodies and Users Article 10 - Electronic Documents' Delivery among Government Bodies Article 11

23 Certification Bodies in Republic of Serbia 1. Republic of Serbia Post CePP Setifikaciono telo pošte 2. Chamber of Commerce and Industry of Serbia PKS CA 3. Halcom BG CA 4. E Smart Systems ESS QCA 5. Ministry of Interior MUP CA

24 Certification Bodies in Republic of Serbia Time Stamp Service Providers 1. Republic of Serbia Post CePP Setifikaciono telo pošte 2. Directorate for egovernment

25 Ministry of Interior Certification Body An identification card issued by the certification body MUP after personalization have added on the chip a certificate for authentication. Certificate for the digital signature will be generated and entered into the chip of ID cards only on the request of citizens. The total number of issued certificates for authentication on the identity cards from the beginning of publication

26 Ministry of Interior Certification Body The total number of issued QES on the ID card on the request of the citizens

27 Number of issued QES per year CA 1 CA 2 CA 3 CA 4 CA 5 QES/year up to Total number of issued QES

28 QES in electronic services E-Portal services E-Submission of payroll tax applications

29 Challenges and Future Activities Establishing of a national trusted list Adoption of a new national law in accordance with the Proposal for a Regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market

30 Thank you for your attention QUESTIONS Brussels, 11 July 2014

Digital Signatures Act 1

Digital Signatures Act 1 Issuer: Riigikogu Type: act In force from: 01.07.2014 In force until: 25.10.2016 Translation published: 08.07.2014 Digital Signatures Act 1 Amended by the following acts Passed 08.03.2000 RT I 2000, 26,

More information

Cosmos POFESSIONALS OF SAFETY ENGINEERING

Cosmos POFESSIONALS OF SAFETY ENGINEERING Japan-Europe Comparison of Legal Frameworks for Electronic Signatures July 4 th, 2017@Japan-Europe Internet Trust Symposium Soshi Hamaguchi, Corporation eidas Regulation and e-signature Act Definition

More information

European Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the EU internal market

European Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the EU internal market European Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the EU internal market Gérard GALLER Policy Officer European Commission -

More information

DIGITAL AGENDA FOR EUROPE

DIGITAL AGENDA FOR EUROPE DIGITAL AGENDA FOR EUROPE Talk overview Background Institutional framework Administrative capacities Electronic Communications Strategy, Information Society Strategy Current and future activities. Background

More information

Comparison of Electronic Signature between Europe and Japan: Possibiltiy of Mutual Recognition

Comparison of Electronic Signature between Europe and Japan: Possibiltiy of Mutual Recognition Comparison of Electronic Signature between Europe and Japan: Possibiltiy of Mutual Recognition 1 Soshi Hamaguchi, 1 Toshiyuki Kinoshita, 2 Satoru Tezuka 1 Tokyo University of Technology, Tokyo, Japan,

More information

DECISION OF THE EUROPEAN CENTRAL BANK

DECISION OF THE EUROPEAN CENTRAL BANK L 74/30 Official Journal of the European Union 16.3.2013 DECISIONS DECISION OF THE EUROPEAN CENTRAL BANK of 11 January 2013 laying down the framework for a public key infrastructure for the European System

More information

Trust Services for Electronic Transactions

Trust Services for Electronic Transactions Trust Services for Electronic Transactions ROUMEN TRIFONOV Faculty of Computer Systems and Control Technical University of Sofia 8 st. Kliment Ohridski bul., 1000 Sofia BULGARIA r_trifonov@tu-sofia.bg

More information

Section I. GENERAL PROVISIONS

Section I. GENERAL PROVISIONS LAW OF THE RUSSIAN FEDERATION NO. 5151-1 OF JUNE 10, 1993 ON CERTIFICATION OF PRODUCTS AND SERVICES (with the Additions and Amendments of December 27, 1995, March 2, July 31, 1998) Federal Law No. 154-FZ

More information

eidas Regulation in the context of Cybersecurity: Electronic seals and website certificates: Two sides of a (gold) medal?

eidas Regulation in the context of Cybersecurity: Electronic seals and website certificates: Two sides of a (gold) medal? eidas Regulation in the context of Cybersecurity: Electronic seals and website certificates: Two sides of a (gold) medal? public 1 AGENDA 1. eidas Strategic View 2. Website Certificates 3. Electronic Seals

More information

ILNAS/PSCQ/Pr004 Qualification of technical assessors

ILNAS/PSCQ/Pr004 Qualification of technical assessors Version 1.1 21.6.2016 Page 1 of 6 ILNAS/PSCQ/Pr004 Qualification of technical assessors Modifications: review of the document 1, avenue du Swing L-4367 Belvaux Tél.: (+352) 247 743-53 Fax: (+352) 247 943-50

More information

Unofficial translation

Unofficial translation Unofficial translation LAW OF THE REPUBLIC OF ARMENIA Approved by National Assembly on 9 November 1999 ON THE CONFORMITY ASSESSMENT OF PRODUCTS AND SERVICES TO NORMATIVE REQUIREMENTS Article 1. Scope of

More information

EXBO e-signing Automated for scanned invoices

EXBO e-signing Automated for scanned invoices EXBO e-signing Automated for scanned invoices Signature Policy Document OID: 0.3.2062.7.2.1.12.1.0 Approval Status: Approved Version: 1.0 Page #: 1 of 13 1. Introduction 1.1. Scope This document covers

More information

eidas Regulation eid and assurance levels Outcome of eias study

eidas Regulation eid and assurance levels Outcome of eias study eidas Regulation eid and assurance levels Outcome of eias study Dr. Marijke De Soete Security4Biz (Belgium) ETSI eidas Workshop 24 June 2015 Sophia Antipolis eidas Regulation Regulation on electronic identification

More information

DIGITALSIGN - CERTIFICADORA DIGITAL, SA.

DIGITALSIGN - CERTIFICADORA DIGITAL, SA. DIGITALSIGN - CERTIFICADORA DIGITAL, SA. TIMESTAMP POLICY VERSION 1.1 21/12/2017 Page 1 / 18 VERSION HISTORY Date Edition n.º Content 10/04/2013 1.0 Initial drafting 21/12/2017 1.1 Revision AUTHORIZATIONS

More information

FOR QTSPs BASED ON STANDARDS

FOR QTSPs BASED ON STANDARDS THE EU CYBER SECURITY AGENCY FOR QTSPs BASED ON STANDARDS Technical guidelines on trust services DECEMBER 2017 About ENISA The European Union Agency for Network and Information Security (ENISA) is a centre

More information

Data Processing Clauses

Data Processing Clauses Data Processing Clauses The examples of processing clauses below are proposed pending the adoption of standard contractual clauses within the meaning of Article 28.8 of general data protection regulation.

More information

ETSI TR V1.1.1 ( )

ETSI TR V1.1.1 ( ) TR 119 400 V1.1.1 (2016-03) TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Guidance on the use of standards for trust service providers supporting digital signatures and related services

More information

BOARD OF THE BANK OF LITHUANIA. RESOLUTION No 46 ON THE REGULATIONS ON KEEPING THE PUBLIC REGISTER OF PAYMENT INSTITUTIONS. of 24 December 2009

BOARD OF THE BANK OF LITHUANIA. RESOLUTION No 46 ON THE REGULATIONS ON KEEPING THE PUBLIC REGISTER OF PAYMENT INSTITUTIONS. of 24 December 2009 BOARD OF THE BANK OF LITHUANIA Unofficial translation RESOLUTION No 46 ON THE REGULATIONS ON KEEPING THE PUBLIC REGISTER OF PAYMENT INSTITUTIONS of 24 December 2009 Vilnius Acting pursuant to Article 9

More information

EUROPEAN COMMISSION DIRECTORATE-GENERAL INFORMATION SOCIETY AND MEDIA

EUROPEAN COMMISSION DIRECTORATE-GENERAL INFORMATION SOCIETY AND MEDIA Ref. Ares(2011)514527-12/05/2011 EUROPEAN COMMISSION DIRECTORATE-GENERAL INFORMATION SOCIETY AND MEDIA Electronic Communications Policy Implementation of Regulatory Framework (I) Brussels, 6th May 2011

More information

Disclosure text - PDS (PKI Disclosure Statement) for electronic signature and authentication certificates

Disclosure text - PDS (PKI Disclosure Statement) for electronic signature and authentication certificates Disclosure text - PDS (PKI Disclosure Statement) for electronic signature and authentication certificates Index INDEX... 2 1. DISCLOSURE TEXT APPLICABLE TO NATURAL PERSON CERTIFICATES ISSUED ON QSCD...

More information

IFY e-signing Automated for scanned invoices

IFY e-signing Automated for scanned invoices IFY e-signing Automated for scanned invoices Signature Policy Document OID: 0.3.2062.7.2.1.13.1.0 Approval Status: Approved Version: 1.0 Page #: 1 of 13 1. Introduction 1.1. Scope This document covers

More information

The Basic Terms and Legal Aspects of The ESA from The Practical and Security Points of View

The Basic Terms and Legal Aspects of The ESA from The Practical and Security Points of View The Basic Terms and Legal Aspects of The ESA from The Practical and Security Points of View Abstract Ján Matejka matejka@ilaw.cas.cz The Institute of State and Law of the Czech Academy of Sciences Pavel

More information

Guidance for Requirements for qualified trust service providers: trustworthy systems and products

Guidance for Requirements for qualified trust service providers: trustworthy systems and products Guidance for Requirements for qualified trust service providers: trustworthy systems and products Note on using the guidance: examples are used throughout they are not normative or exclusive, but there

More information

NATIONAL PROGRAMME Chapter 15 Telecommunication and Post. Telecommunication and Post

NATIONAL PROGRAMME Chapter 15 Telecommunication and Post. Telecommunication and Post Introduction Telecommunication and Post The n legislation in the field of telecommunication and post is almost in full incompliance with that of the EU, except for certain legal rules on general legal

More information

SPECIFIC CERTIFICATION PRACTICES AND POLICY OF

SPECIFIC CERTIFICATION PRACTICES AND POLICY OF SPECIFIC CERTIFICATION PRACTICES AND POLICY OF CERTIFICATES OF REPRESENTATIVES OF LEGAL ENTITIES AND OF INSTITUTIONS WITH NO LEGAL ENTITY FROM THE AC REPRESENTACIÓN NAME DATE Prepared by: FNMT-RCM / v1.5

More information

eidas Regulation (EU) 910/2014 eidas implementation State of Play

eidas Regulation (EU) 910/2014 eidas implementation State of Play eidas Regulation (EU) 910/2014 eidas implementation State of Play CA-Day 19 September 2016 Elena Alampi DG CONNECT, European Commission elena.alampi@ec.europa.eu eidas The Regulation in a nutshell 2 MAIN

More information

Regulations for Compulsory Product Certification

Regulations for Compulsory Product Certification Regulations for Compulsory Product Certification Chapter I General Provisions Article 1 Based on relevant laws and regulations covering product safety licensing and product quality certification so as

More information

DATA PROCESSING TERMS

DATA PROCESSING TERMS DATA PROCESSING TERMS Safetica Technologies s.r.o. These Data Processing Terms (hereinafter the Terms ) govern the rights and obligations between the Software User (hereinafter the User ) and Safetica

More information

PostSignum CA Certification Policy applicable to qualified certificates for electronic signature

PostSignum CA Certification Policy applicable to qualified certificates for electronic signature PostSignum CA Certification Policy applicable to qualified certificates for electronic signature Version 1.1 7565 Page 1/61 TABLE OF CONTENTS 1 Introduction... 5 1.1 Overview... 5 1.2 Document Name and

More information

Protection Profiles for Signing Devices

Protection Profiles for Signing Devices www.thales-esecurity.com Protection Profiles for Signing Devices Report on CEN Standardisation Activities on Security of Electronic Signatures 2 / Topics EU Legislation driving standardisation for Electronic

More information

EVROTRUST TECHNOLOGIES JSC

EVROTRUST TECHNOLOGIES JSC CERTIFICATE OF CONFORMITY The certification body LSTI declares EVROTRUST TECHNOLOGIES JSC HEADQUARTER: #101 TSARIGRADSKO SHAUSSE BLVD., BUSINESS CENTER ACTIVE, FLOOR 6, SOFIA 1113, REPUBLIC OF BULGARIA

More information

Certification Practice Statement

Certification Practice Statement Contents 1. Outline 1 Certification Practice Statement Ver. 1.6 Dec 2013 1.1 Background & Purpose 1 1.1.1 Electronic Signature Certification System 1 1.1.2 Certification Practice Statement 1 1.1.3 Introduction

More information

Digital Signatures: How Close Is Europe to Truly Interoperable Solutions?

Digital Signatures: How Close Is Europe to Truly Interoperable Solutions? Digital Signatures: How Close Is Europe to Truly Interoperable Solutions? Konstantinos Rantos Kavala Institute of Technology, Kavala GR-65404, Greece krantos@teikav.edu.gr Abstract. Digital signatures

More information

CORPME TRUST SERVICE PROVIDER

CORPME TRUST SERVICE PROVIDER CORPME TRUST SERVICE PROVIDER QUALIFIED CERTIFICATE OF ADMINISTRATIVE POSITION USE LICENSE In..,.. 20... Mr/Mrs/Ms/Miss.........., with DNI/NIF/National Passport nº., e-mail........., phone number....,

More information

WORLD TRADE ORGANIZATION

WORLD TRADE ORGANIZATION WORLD TRADE ORGANIZATION Committee on Trade-Related Investment Measures G/TRIMS/W/61 8 May 2009 (09-2263) Original: English COMMUNICATION FROM THE EUROPEAN COMMUNITIES AND THE UNITED STATES Certain New

More information

Gateway Certification Authority pilot project

Gateway Certification Authority pilot project Results of the IDABC Bridge / Gateway Certification Authority pilot project Gzim Ocakoglu Commission Enterprise and Industry Directorate General ITAPA Congress Bratislava, 22 November 2005 1 Outline Introduction

More information

Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)

Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) Adopted on 4 December 2018 Adopted 1 Contents 1 Introduction... 3 2

More information

GDPR AMC SAAS AND HOSTED MODULES. UK version. AMC Consult A/S June 26, 2018 Version 1.10

GDPR AMC SAAS AND HOSTED MODULES. UK version. AMC Consult A/S June 26, 2018 Version 1.10 GDPR AMC SAAS AND HOSTED MODULES UK version AMC Consult A/S June 26, 2018 Version 1.10 INDEX 1 Signatures...3 2 General...4 3 Definitions...5 4 Scoping...6 4.1 In scope...6 5 Responsibilities of the data

More information

IAS2. Electronic signatures & electronic seals Up-dates - feedbacks from :

IAS2. Electronic signatures & electronic seals Up-dates - feedbacks from : IAS2 Study to support the implementation of a pan-european framework on electronic identification and trust services for electronic transactions in the internal market Electronic signatures & electronic

More information

Utimaco eidas Update. June Thorsten Groetker CTO. Utimaco HSM Business Unit Aachen, Germany 2017 Utimaco eidas Update, June 2017 Page 1

Utimaco eidas Update. June Thorsten Groetker CTO. Utimaco HSM Business Unit Aachen, Germany 2017 Utimaco eidas Update, June 2017 Page 1 Utimaco eidas Update June 2017 Thorsten Groetker CTO Utimaco HSM Business Unit Aachen, Germany 2017 Utimaco eidas Update, June 2017 Page 1 eidas Agenda Recap eidas, Trust Services, Standardization Signature

More information

EVROTRUST TECHNOLOGIES AD

EVROTRUST TECHNOLOGIES AD CERTIFICATE OF CONFORMITY The certification body LSTI declares EVROTRUST TECHNOLOGIES AD SIEGE : 2 NIKOLAI HAITOV STR., ENTR.D, FL.2 1113 SOFIA - BULGARIA Provides trust electronic services 1 that comply

More information

ACCREDITATION: A BRIEFING FOR GOVERNMENTS AND REGULATORS

ACCREDITATION: A BRIEFING FOR GOVERNMENTS AND REGULATORS ACCREDITATION: A BRIEFING FOR GOVERNMENTS AND REGULATORS Accreditation is continuously gaining recognition as an important technical tool in the delivery of objectives across an increasing range of policy

More information

SAT for eid [EIRA extension]

SAT for eid [EIRA extension] SAT for eid [EIRA extension] eid Solution Architecture Template (SAT) v1.0.0 ISA² Action 2.1 - European Interoperability Architecture Page 1 of 1 Change control Modification Details Version 1.0.0 Migration

More information

CERTIFICATE OF CONFORMITY. The certification body LSTI. declares ALEAT HEADQUARTER : SH.P.K RRUGA: XHANFIZE KEKO - TIRANA-ALBANIA

CERTIFICATE OF CONFORMITY. The certification body LSTI. declares ALEAT HEADQUARTER : SH.P.K RRUGA: XHANFIZE KEKO - TIRANA-ALBANIA CERTIFICATE OF CONFORMITY The certification body LSTI declares ALEAT HEADQUARTER : SH.P.K RRUGA: XHANFIZE KEKO - TIRANA-ALBANIA Provides trust electronic services 1 that comply with Regulation (EU) No.

More information

ENISA s Position on the NIS Directive

ENISA s Position on the NIS Directive ENISA s Position on the NIS Directive 1 Introduction This note briefly summarises ENISA s position on the NIS Directive. It provides the background to the Directive, explains its significance, provides

More information

VeriSign Trust Network European Directive Supplemental Policies

VeriSign Trust Network European Directive Supplemental Policies VeriSign Trust Network European Directive Supplemental Policies Version 1.0 Effective Date: September 19, 2001 VeriSign, Inc. 487 East Middlefield Road Mountain View, CA 94043 USA +1 650.961.7500 http//:www.verisign.com

More information

Identity Documents Personalisation Centre. Conformity Assessment Report: Conformity Certificate and Summary. T-Systems

Identity Documents Personalisation Centre. Conformity Assessment Report: Conformity Certificate and Summary. T-Systems Conformity Assessment Report: Conformity Certificate and Summary T-Systems.031.0258.05.2017 Trust Service Provider: Identity Documents Personalisation Centre Conformity Certificate T-Systems.031.0258.05.2017

More information

Conformity assessment

Conformity assessment Training Course on Conformity and Interoperability, Tunis-Tunisia, from 22 to 26 May 2017 Conformity assessment Presented by: Karim Loukil & Kaïs Siala Page 1 Today s Objectives Present basic information

More information

Federal Electronic Signature Law. (Signature Law - SigG)

Federal Electronic Signature Law. (Signature Law - SigG) Federal Electronic Signature Law (Signature Law - SigG) (Click here for checking the up-to-date list of amendments in the Austrian Legal Information System) Section l Purpose and definitions Purpose and

More information

The current status of Esi TC and the future of electronic signatures

The current status of Esi TC and the future of electronic signatures SG&A ETSI FUTURE WORKSHOP Sophia Antipolis, 16th January 2006 The current status of Esi TC and the future of electronic signatures Riccardo Genghini, Chairman of Etsi Esi TC riccardo.genghini@sng.it The

More information

Mutual Recognition Agreement/Arrangement: General Introduction, Framework and Benefits

Mutual Recognition Agreement/Arrangement: General Introduction, Framework and Benefits Workshop for Caribbean countries to promote the development and implementation of Conformity Assessment programmes St. Augustine (Trinidad and Tobago) 2-4 December 2014 Mutual Recognition Agreement/Arrangement:

More information

Information memorandum. SUNČANI HVAR d.d.

Information memorandum. SUNČANI HVAR d.d. Information memorandum Version 1.1. May, 2018 01 Information on the processing of personal data of accommodated persons by the Company Introduction Below you will find information on the processing of

More information

[CZ01] CZ_Data Boxes. CZ_Data Boxes

[CZ01] CZ_Data Boxes. CZ_Data Boxes [CZ01] CZ_Data Boxes ID Initiative Short description Owner Contact Type Sub-Type Context Base Registry type Operating model CZ_Data Boxes Summary CZ01 Not Ava The Datove Schranky / Data boxes are an electronic

More information

Validation Policy r tra is g e R ANF AC MALTA, LTD

Validation Policy r tra is g e R ANF AC MALTA, LTD Maltese Registrar of Companies Number C75870 and VAT number MT ANF AC MALTA, LTD B2 Industry Street, Qormi, QRM 3000 Malta Telephone: (+356) 2299 3100 Fax:(+356) 2299 3101 Web: www.anfacmalta.com Security

More information

eias Study on an electronic identification, authentication and signature policy SUPERVISION Presentation on status

eias Study on an electronic identification, authentication and signature policy SUPERVISION Presentation on status eias Study on an electronic identification, authentication and signature policy SUPERVISION Presentation on status in the context of COM(2012) 238 Proposal for a Regulation on electronic identification

More information

Privacy Statement for Use of the Certification Service of Swisscom (sales name: "All-in Signing Service")

Privacy Statement for Use of the Certification Service of Swisscom (sales name: All-in Signing Service) Swisscom (sales name: "All-in Signing Service") General Privacy is a matter of trust, and your trust is important to us. Handling personal data in a responsible and legally compliant manner is a top priority

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 18/EN WP261 Article 29 Working Party Draft Guidelines on the accreditation of certification bodies under Regulation (EU) 2016/679 Adopted on 6 february 2018 1 THE

More information

Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation 2016/679

Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation 2016/679 Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation 2016/679 Adopted on 25 May 2018 Contents 1. Introduction... 2 1.1. Scope

More information

Lao PDR Practice for Information Security

Lao PDR Practice for Information Security Lao PDR Practice for Information Security Ministry of Science and Technology (MOST) Department of Information and Technology (DIT) Daovalath Phommalath PhD EU-SEA Workshop International Cooperation on

More information

CERTIFICATE OF CONFORMITY. The certification body LSTI. declares BALTSTAMP HEADQUARTER : DARIAUS IR GIRENO STR. 40, LT VILNIUS - LITHUANIA

CERTIFICATE OF CONFORMITY. The certification body LSTI. declares BALTSTAMP HEADQUARTER : DARIAUS IR GIRENO STR. 40, LT VILNIUS - LITHUANIA CERTIFICATE OF CONFORMITY The certification body LSTI declares BALTSTAMP HEADQUARTER : DARIAUS IR GIRENO STR. 40, LT-02189 VILNIUS - LITHUANIA Provides trust electronic services 1 that comply with Regulation

More information

Certification Practice Statement of the Federal Reserve Banks Services Public Key Infrastructure

Certification Practice Statement of the Federal Reserve Banks Services Public Key Infrastructure Certification Practice Statement of the Federal Reserve Banks Services Public Key Infrastructure 1.0 INTRODUCTION 1.1 Overview The Federal Reserve Banks operate a public key infrastructure (PKI) that manages

More information

Electronic Commerce Working Group report

Electronic Commerce Working Group report RESTRICTED CEFACT/ECAWG/97N012 4 December 1997 Electronic Commerce Ad hoc Working Group (ECAWG) Electronic Commerce Working Group report SOURCE: 10 th ICT Standards Board, Sophia Antipolis, 4 th November

More information

Data subject ( Customer or Data subject ): individual to whom personal data relates.

Data subject ( Customer or Data subject ): individual to whom personal data relates. Privacy Policy 1. Information on the processing of personal data We hereby inform you in this document about the principles and procedures for processing your personal data and your rights, in accordance

More information

ICT Legal Consulting on GDPR: the possible value of certification in data protection compliance and accountability

ICT Legal Consulting on GDPR: the possible value of certification in data protection compliance and accountability ICT Legal Consulting on GDPR: the possible value of certification in data protection compliance and accountability Prof. Dr. Paolo Balboni Founding Partner Professor of Privacy, Cybersecurity, and IT Contract

More information

Spanish Information Technology Security Evaluation and Certification Scheme

Spanish Information Technology Security Evaluation and Certification Scheme Spanish Information Technology Security Evaluation and Certification Scheme IT-009 Remote Qualified Electronic Signature Creation Device Evaluation Methodology Version 1.0 January 2017 Documento del Esquema

More information

eidas Workshop Return on Experience from Conformity Assessment Bodies - EY June 13, 2016 Contacts: Arvid Vermote

eidas Workshop Return on Experience from Conformity Assessment Bodies - EY June 13, 2016 Contacts: Arvid Vermote eidas Workshop Return on Experience from Conformity Assessment Bodies - EY June 13, 2016 Contacts: Arvid Vermote arvid.vermote@be.ey.com EY eidas Certification scheme Scheme EY CertifyPoint B.V. is currently

More information

EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Time-stamping protocol and time-stamp token profiles

EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Time-stamping protocol and time-stamp token profiles Final draft EN 319 422 V1.1.0 (2015-12) EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Time-stamping protocol and time-stamp token profiles 2 Final draft EN 319 422 V1.1.0 (2015-12)

More information

eidas compliant Trust Services with Utimaco HSMs

eidas compliant Trust Services with Utimaco HSMs eidas compliant Trust Services with Utimaco HSMs March 15, 2018 Dieter Bong Product Manager Utimaco HSM Business Unit Aachen, Germany 2018 eidas-compliant Trust Services with Utimaco HSMs Page 1 eidas

More information

BSI-PP for. Protection Profile Secure Signature-Creation Device Type 3, Version developed by

BSI-PP for. Protection Profile Secure Signature-Creation Device Type 3, Version developed by BSI-PP-0006-2002 for Protection Profile Secure Signature-Creation Device Type 3, Version 1.05 developed by CEN/ISSS Information Society Standardization System, Workshop on Electronic Signatures - Bundesamt

More information

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act'' CEN Identification number in the EC register: 63623305522-13 CENELEC Identification number in the EC register: 58258552517-56 CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

More information

SWAMID Person-Proofed Multi-Factor Profile

SWAMID Person-Proofed Multi-Factor Profile Document SWAMID Person-Proofed Multi-Factor Profile Identifier http://www.swamid.se/policy/assurance/al2mfa Version V1.0 Last modified 2018-09-12 Pages 10 Status FINAL License Creative Commons BY-SA 3.0

More information

IT Security Evaluation and Certification Scheme Document

IT Security Evaluation and Certification Scheme Document IT Security Evaluation and Certification Scheme Document June 2015 CCS-01 Information-technology Promotion Agency, Japan (IPA) IT Security Evaluation and Certification Scheme (CCS-01) i / ii Table of Contents

More information

ETSI ESI and Signature Validation Services

ETSI ESI and Signature Validation Services ETSI ESI and Signature Validation Services Presented by: Andrea Röck For: Universign and ETSI STF 524 expert 24.10.2018 CA day ETSI 2018 Agenda Update on standardisation under eidas Signature validation

More information

TITLE 595. DEPARTMENT OF PUBLIC SAFETY CHAPTER 10. CLASS D DRIVER LICENSES AND IDENTIFICATION CARDS AND MOTOR LICENSE AGENT PROCEDURES

TITLE 595. DEPARTMENT OF PUBLIC SAFETY CHAPTER 10. CLASS D DRIVER LICENSES AND IDENTIFICATION CARDS AND MOTOR LICENSE AGENT PROCEDURES TITLE 595. DEPARTMENT OF PUBLIC SAFETY CHAPTER 10. CLASS D DRIVER LICENSES AND IDENTIFICATION CARDS AND MOTOR LICENSE AGENT PROCEDURES RULEMAKING ACTION: EMERGENCY adoption PROPOSED RULES: Subchapter 11.

More information

COMPUTERIZATION. Bilateral Screening Chapter 29 Customs Union Presentation by the Republic of Serbia Brussels, 3-4 June 2014

COMPUTERIZATION. Bilateral Screening Chapter 29 Customs Union Presentation by the Republic of Serbia Brussels, 3-4 June 2014 COMPUTERIZATION Bilateral Screening Chapter 29 Customs Union Presentation by the Republic of Serbia Brussels, 3-4 June 2014 CONTENT 1) Legal Framework 2) Strategic documents 3) Short historical overview

More information

CHAPTER 13 ELECTRONIC COMMERCE

CHAPTER 13 ELECTRONIC COMMERCE CHAPTER 13 ELECTRONIC COMMERCE Article 13.1: Definitions For the purposes of this Chapter: computing facilities means computer servers and storage devices for processing or storing information for commercial

More information

Mohammed Ahmed Al Amer Chairman of the Board of Directors. Issued on: 16 Rabi' al-awwal 1437 (Arabic calendar) Corresponding to: 27 December 2015

Mohammed Ahmed Al Amer Chairman of the Board of Directors. Issued on: 16 Rabi' al-awwal 1437 (Arabic calendar) Corresponding to: 27 December 2015 The Telecommunications Regulatory Authority s Board of Directors Resolution No. (13) of 2015 Promulgating the SIM-Card Enabled Telecommunications Services Registration Regulation Chairman of the Telecommunications

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement Merchant (the "Data Controller") and Nets (the "Data Processor") (separately referred to as a Party and collectively the Parties ) have concluded this DATA PROCESSING AGREEMENT

More information

DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure

DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure Change Control Date Version Description of changes 15-December- 2016 1-December- 2016 17-March- 2016 4-February- 2016 3-February-

More information

ACCV Certification Practice Statement (CPS)

ACCV Certification Practice Statement (CPS) (CPS) Date: 20/05/2017 Version: 4.0.1 Estado: APPROVED No. of pages: 56 OID: 1.3.6.1.4.1.8149.2.4.0 Classification: PUBLIC File: ACCV-CPS-V4.0-EN-2017.doc Prepared by: Agencia de Tecnología y Certificación

More information

CEN & ETSI standards & eidas Compliance

CEN & ETSI standards & eidas Compliance CEN & ETSI standards & eidas Compliance Nick Pope - Thales Vice Chair, ETSI TC Electronic Signature & Infrastructures Jan Ulrik Kjærsgaard Cryptomathic Editor CEN EN 419 241-2 (Remote Signing) eidas and

More information

10007/16 MP/mj 1 DG D 2B

10007/16 MP/mj 1 DG D 2B Council of the European Union Brussels, 9 June 2016 (OR. en) 10007/16 OUTCOME OF PROCEEDINGS From: On: 9 June 2016 To: General Secretariat of the Council Delegations No. prev. doc.: 9579/16 + COR 1 Subject:

More information

QUICKSIGN Registration Policy

QUICKSIGN Registration Policy QUICKSIGN Registration Policy Amendment to DOCUSIGN FRANCE s Certificate Policy for using the QUICKSIGN platform as a registration service to identify Subscribers September 27, 2016 QUICKSIGN_Registration_Policy_V1.0

More information

UDRP Pilot Project. 1. Simplified way of sending signed hardcopies of Complaints and/or Responses to the Provider (Par. 3(b), Par. 5(b) of the Rules)

UDRP Pilot Project. 1. Simplified way of sending signed hardcopies of Complaints and/or Responses to the Provider (Par. 3(b), Par. 5(b) of the Rules) UDRP Pilot Project The Czech Arbitration Court (CAC) proposes that it runs two pilot projects (Pilot) related to its implementation of UDRP. During the Pilot, the following proposed new UDRP-related services

More information

Media-break resistant esignatures in egovernment an Austrian experience

Media-break resistant esignatures in egovernment an Austrian experience Media-break resistant esignatures in egovernment an Austrian experience Herbert Leitold Secure Information Technology Center Austria (A-SIT), Herbert.Leitold@a-sit.at Reinhard Posch Federal Chief Information

More information

A comprehensive approach on personal data protection in the European Union

A comprehensive approach on personal data protection in the European Union A comprehensive approach on personal data protection in the Justice Date 1 Main legal instruments on EU level Data Protection Directive 95/46/EC Directive 2002/58/EC on privacy and electronic communications

More information

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov Contributed by Djingov, Gouginski, Kyutchukov & Velichkov General I Data Protection Laws National Legislation General data protection laws The Personal Data Protection Act implemented the Data Protection

More information

The Institute of Certified Accountants of Montenegro. RADUNOVIC VESNA, Certified auditor Member of the Board of Directors

The Institute of Certified Accountants of Montenegro. RADUNOVIC VESNA, Certified auditor Member of the Board of Directors The Institute of Certified Accountants of Montenegro RADUNOVIC VESNA, Certified auditor Member of the Board of Directors The establishment of the Institute Accounting reform Disagreements within the then

More information

ING Public Key Infrastructure Technical Certificate Policy

ING Public Key Infrastructure Technical Certificate Policy ING Public Key Infrastructure Technical Certificate Policy Version 5.4 - November 2015 Commissioned by ING PKI Policy Approval Authority (PAA) Additional copies Document version General Of this document

More information

Trust Services Practice Statement

Trust Services Practice Statement Trust Services Practice Statement TrustWeaver AB V. 1.2 PUBLIC Page 1 IMPORTANT LEGAL NOTICE Copyright 2016, TrustWeaver AB. All rights reserved. This document contains TrustWeaver AB proprietary information,

More information

EU TRADE RELATED ASSISTANCE PHASE II Consulta)ve Workshop on Dra3 Electronic Transac)ons Act

EU TRADE RELATED ASSISTANCE PHASE II Consulta)ve Workshop on Dra3 Electronic Transac)ons Act EU TRADE RELATED ASSISTANCE PHASE II Consulta)ve Workshop on Dra3 Electronic Transac)ons Act 10 May 2018 Lamana Hotel hhp://www.pngeutra2.org.pg Implemented by the Department of Trade, Commerce and Industry

More information

EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 5: QCStatements

EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 5: QCStatements EN 319 412-5 V2.1.1 (2016-02) EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Certificate Profiles; Part 5: QCStatements 2 EN 319 412-5 V2.1.1 (2016-02) Reference REN/ESI-0019412-5v211

More information

BE INVEST INTERNATIONAL SA

BE INVEST INTERNATIONAL SA CERTIFICATE OF CONFORMITY The certification body LSTI declares BE INVEST INTERNATIONAL SA HEADQUARTER: 117, ROUTE D'ARLON - 8009 STRASSEN - LUXEMBOURG Provides trust electronic services 1 that comply with

More information

Market Surveillance Action Plan

Market Surveillance Action Plan Ref. Ares(2015)402331-02/02/2015 MEMORANDUM Date 12 November 2014 1(8) Spectrum Department Market Surveillance Action Plan 2013-2015 1 Legal basis According to Section 1 of the Ordinance (2007:951) with

More information

Electronic registered delivery services (ERDS) in light of the eidas regulation. Warsaw Common Sign Conference 2015

Electronic registered delivery services (ERDS) in light of the eidas regulation. Warsaw Common Sign Conference 2015 Electronic registered delivery services (ERDS) in light of the eidas regulation Warsaw Common Sign Conference 2015 ! 1. e-delivery and the eidas regulation - EU legislative framework - French legislative

More information

LL-C (Certification) Services Overview

LL-C (Certification) Services Overview LL-C (Certification) Services Overview Who is LL-C (Certification)? LL-C (Certification) is an international certification body operating in more than 40 countries with experience in the field. Provides

More information

TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Guidance on the use of standards for cryptographic suites

TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Guidance on the use of standards for cryptographic suites TR 119 300 V1.2.1 (2016-03) TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Guidance on the use of standards for cryptographic suites 2 TR 119 300 V1.2.1 (2016-03) Reference RTR/ESI-0019300v121

More information

NIS Standardisation ENISA view

NIS Standardisation ENISA view NIS Standardisation ENISA view Dr. Steve Purser Brussels, 19 th September 2017 European Union Agency for Network and Information Security Instruments For Improving Cybersecurity Policy makers have a number

More information

E-Signature Law of Iraq no. ( 78) of 2012

E-Signature Law of Iraq no. ( 78) of 2012 INTER-REGIONAL STANDARDIZATION FORUM FOR BRIDGING THE STANDARDIZATION GAP (BSG) Muscat, Oman, 11-12 December 2017 E-Signature Law of Iraq no. ( 78) of 2012 Halah Alrubaye Projects follow-up manager, Ministry

More information

ETSI Electronic Signatures and Infrastructures (ESI) TC

ETSI Electronic Signatures and Infrastructures (ESI) TC ETSI Electronic Signatures and Infrastructures (ESI) TC Presented by Andrea Caccia, ETSI/ESI liaison to ISO SC27 ( a.caccia @ kworks.it ) ETSI 2011. All rights reserved ETSI TC ESI - Electronic Signatures

More information