Why does your digital training signature need a timestamp?

Digital signatures are an essential tool for guaranteeing the authenticity and security of electronic documents, especially in the field of subsidised training. However, do you know what a timestamp is and why it's so important? We'll explain everything you need to know about timestamps, how they work, and what the law says about them.

Digital signatures are a secure and efficient method for authenticating documents such as contracts and agreements, among others. In fact, they are accepted by FUNDAE for monitoring attendance in its subsidised training courses.

However, the authenticity and security of digital signatures depend heavily on timestamps. So it's time to learn the essentials about them in the following lines.

What is a timestamp in a digital signature and what is it used for?

A timestamp is a record of information used to prove that a document or digital file existed at a specific time.

Timestamps are essential in digital signatures because they guarantee the authenticity and security of electronically signed documents.

In addition, timestamps are necessary to verify the integrity of the document, that is, that it has not been modified since the time it was digitally signed.

In addition, timestamps help prevent fraud and counterfeiting, as they provide proof that the document or digital file is authentic.

How does it work?

Timestamps in digital signatures work by using a timestamp authority (TSA). A TSA is a trusted entity that issues timestamps and guarantees that the document or digital file existed at a specific point in time.

There are different types of timestamp authorities, each with its own characteristics and levels of confidence:

  • Internal timestamp authorities: These are managed by the organisation or company that issues the digital signatures.
  • External time stamp authorities: These are managed by trusted third parties that provide time stamp services to other organisations or companies.
  • Government time stamp authorities: These are those that have a high level of trust because they are regulated by government laws and regulations.

When a document is digitally signed, the TSA issues a timestamp that is attached to the document.

The timestamp contains information about the date and time the document was signed, as well as a unique serial number that identifies the timestamp.

 

What does the law say about the value of timestamps in digital signatures?

Digital signatures with timestamps have important legal implications. In fact, in many countries, digital signatures with timestamps have the same legal validity as handwritten signatures.

Furthermore, digital signatures with timestamps can be used as evidence in a court of law.

In general, the legal and regulatory requirements for timestamps in digital signatures include the following:

  • Timestamps must be issued by a trusted authority.
  • Time stamps must comply with established technical and security standards.
  • Timestamps must be verifiable and accessible for a specific period of time.

Timestamps are subject to specific regulations and laws in different countries and regions. In the case of European Union member states, timestamps in digital signatures are regulated by the eIDAS Regulation (EU 910/2014). 

According to Article 41 of this:

"Legal effect and admissibility as evidence in judicial proceedings shall not be denied to an electronic timestamp merely because it is in electronic format or does not meet the requirements of a qualified electronic timestamp."

However, Article 42 states the following:

"A qualified electronic timestamp shall enjoy the highest level of legal presumption regarding the accuracy of the date and time it indicates and the integrity of the data to which the timestamp refers."

This means that a qualified digital signature timestamp provides greater legal and evidentiary security than an unqualified timestamp, as it is based on a secure time source and a qualified timestamp authority, which is a trusted service provider supervised by the competent authorities.

This does not mean that a timestamp on an unqualified digital signature is worthless. It all depends on the circumstances of its use and the level of legal certainty required.

Best practices to follow for the use of timestamps in digital signatures

Currently, many digital signature solutions already have integrations with external timestamping services.

This means that it is something within reach of all companies that have committed to digital transformation. 

Furthermore, they must take care to follow a series of guidelines that will guarantee the authenticity and security of their digital signatures, such as:

  • Use a trusted timestamp authority.
  • Verify the synchronisation of the computer's system time with the timestamp time.
  • Make sure the timestamp has not expired.
  • Maintain records of the timestamps used in digital signatures.

And all of this is easier to achieve by choosing solutions like the one SoWeSign offers to large companies. With SoWeSign Corporate, you can easily and quickly register the digital signatures of students and instructors with their corresponding timestamps.

This way, you will have clear and legally supported evidence to apply for the training subsidies offered by FUNDAE.

Without the signatures related to attendance control, receipt of materials, the quality questionnaire, and the delivery of diplomas and certificates of attendance, you will not be able to access these key resources to optimise business processes and results.

Finally, we encourage you to see for yourself everything we've told you by requesting a free consultation and a personalised demo of our software. Don't put it off any longer!