How to use electronic signatures while complying with the EU General Data Protection Regulation.
Sarah Chen
CEO & Co-founder
The General Data Protection Regulation (GDPR) affects how organizations collect, process, and store personal data - including data collected during the e-signature process.
The following data may be collected:
You need a lawful basis to process signer data:
Only collect data necessary for the signing process.
Use collected data only for the stated purpose.
Don't keep data longer than necessary.
Implement appropriate security measures.
Under GDPR, signers have the right to:
SignFlow is fully GDPR compliant:
A comprehensive guide to the US Electronic Signatures in Global and National Commerce Act.
Understanding the EU regulatory framework for electronic signatures and trust services.
How healthcare organizations can use electronic signatures while maintaining HIPAA compliance.