keyboard_tab EIDAS 2014/0910 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- 1 Article 3 Definitions
- 3 Article 30 Certification of qualified electronic signature creation devices
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
ELECTRONIC IDENTIFICATION
CHAPTER III
TRUST SERVICES
SECTION 1
General provisions
SECTION 2
Supervision
SECTION 3
Qualified trust services
SECTION 4
Electronic signatures
SECTION 5
Electronic seals
SECTION 6
Electronic time stamps
SECTION 7
Electronic registered delivery services
SECTION 8
Website authentication
CHAPTER IV
ELECTRONIC DOCUMENTS
CHAPTER V
DELEGATIONS OF POWER AND IMPLEMENTING PROVISIONS
CHAPTER VI
FINAL PROVISIONS
- electronic identification
- electronic identification means
- person identification data
- electronic identification scheme
- authentication
- relying party
- public sector body
- body governed by public law
- signatory
- electronic signature
- advanced electronic signature
- qualified electronic signature
- electronic signature creation data
- certificate for electronic signature
- qualified certificate for electronic signature
- trust service
- qualified trust service
- conformity assessment body
- trust service provider
- qualified trust service provider
- product
- electronic signature creation device
- qualified electronic signature creation device
- creator of a seal
- electronic seal
- advanced electronic seal
- qualified electronic seal
- electronic seal creation data
- certificate for electronic seal
- qualified certificate for electronic seal
- electronic seal creation device
- qualified electronic seal creation device
- electronic time stamp
- qualified electronic time stamp
- electronic document
- electronic registered delivery service
- qualified electronic registered delivery service
- certificate for website authentication
- qualified certificate for website authentication
- validation data
- validation
- means 87
- which 38
- person 32
- data 32
- electronic_seal 30
- electronic_signature 28
- electronic 28
- qualified 26
- creation 26
- legal 24
- natural 24
- ‘qualified 22
- requirements 21
- trust_service 20
- meets 20
- article 18
- form 18
- certificate 18
- laid 17
- down 17
- used 17
- provider 12
- electronic_identification 12
- process 12
- website 12
- annex 11
- electronic_signature’ 10
- issued 10
- electronic_seal’ 10
- referred 9
- electronic_signatures 8
- point 8
- provides 8
- body 8
- device 8
- representing 8
- create 8
- trust_services 8
- hardware 8
- software 8
- device’ 8
- regulation 8
- shall 7
- public 7
- services 6
- such 6
- ‘certificate 6
- bodies 6
- attestation 6
- certificates 6
Article 3
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) | ‘ electronic_identification’ means the process of using person_identification_data in electronic form uniquely representing either a natural or legal person, or a natural person representing a legal person; |
(2) | ‘ electronic_identification means’ means a material and/or immaterial unit containing person_identification_data and which is used for authentication for an online service; |
(3) | ‘ person_identification_data’ means a set of data enabling the identity of a natural or legal person, or a natural person representing a legal person to be established; |
(4) | ‘ electronic_identification scheme’ means a system for electronic_identification under which electronic_identification means are issued to natural or legal persons, or natural persons representing legal persons; |
(5) | ‘ authentication’ means an electronic process that enables the electronic_identification of a natural or legal person, or the origin and integrity of data in electronic form to be confirmed; |
(6) | ‘ relying_party’ means a natural or legal person that relies upon an electronic_identification or a trust_service; |
(7) | ‘ public_sector_body’ means a state, regional or local authority, a body_governed_by_public_law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate; |
(8) | ‘ body_governed_by_public_law’ means a body defined in point (4) of Article 2(1) of Directive 2014/24/EU of the European Parliament and of the Council (15); |
(9) | ‘ signatory’ means a natural person who creates an electronic_signature; |
(10) | ‘ electronic_signature’ means data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign; |
(11) | ‘advanced electronic_signature’ means an electronic_signature which meets the requirements set out in Article 26; |
(12) | ‘qualified electronic_signature’ means an advanced electronic_signature that is created by a qualified electronic_signature creation device, and which is based on a qualified certificate for electronic_signatures; |
(13) | ‘ electronic_signature creation data’ means unique data which is used by the signatory to create an electronic_signature; |
(14) | ‘certificate for electronic_signature’ means an electronic attestation which links electronic_signature validation_data to a natural person and confirms at least the name or the pseudonym of that person; |
(15) | ‘qualified certificate for electronic_signature’ means a certificate for electronic_signatures, that is issued by a qualified trust_service provider and meets the requirements laid down in Annex I; |
(16) | ‘ trust_service’ means an electronic service normally provided for remuneration which consists of:
|
(17) | ‘qualified trust_service’ means a trust_service that meets the applicable requirements laid down in this Regulation; |
(18) | ‘ conformity_assessment_body’ means a body defined in point 13 of Article 2 of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust_service provider and the qualified trust_services it provides; |
(19) | ‘ trust_service provider’ means a natural or a legal person who provides one or more trust_services either as a qualified or as a non-qualified trust_service provider; |
(20) | ‘qualified trust_service provider’ means a trust_service provider who provides one or more qualified trust_services and is granted the qualified status by the supervisory body; |
(21) | ‘ product’ means hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of trust_services; |
(22) | ‘ electronic_signature creation device’ means configured software or hardware used to create an electronic_signature; |
(23) | ‘qualified electronic_signature creation device’ means an electronic_signature creation device that meets the requirements laid down in Annex II; |
(24) | ‘ creator_of_a_seal’ means a legal person who creates an electronic_seal; |
(25) | ‘ electronic_seal’ means data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the latter’s origin and integrity; |
(26) | ‘advanced electronic_seal’ means an electronic_seal, which meets the requirements set out in Article 36; |
(27) | ‘qualified electronic_seal’ means an advanced electronic_seal, which is created by a qualified electronic_seal creation device, and that is based on a qualified certificate for electronic_seal; |
(28) | ‘ electronic_seal creation data’ means unique data, which is used by the creator of the electronic_seal to create an electronic_seal; |
(29) | ‘certificate for electronic_seal’ means an electronic attestation that links electronic_seal validation_data to a legal person and confirms the name of that person; |
(30) | ‘qualified certificate for electronic_seal’ means a certificate for an electronic_seal, that is issued by a qualified trust_service provider and meets the requirements laid down in Annex III; |
(31) | ‘ electronic_seal creation device’ means configured software or hardware used to create an electronic_seal; |
(32) | ‘qualified electronic_seal creation device’ means an electronic_seal creation device that meets mutatis mutandis the requirements laid down in Annex II; |
(33) | ‘ electronic_time_stamp’ means data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time; |
(34) | ‘qualified electronic_time_stamp’ means an electronic_time_stamp which meets the requirements laid down in Article 42; |
(35) | ‘ electronic_document’ means any content stored in electronic form, in particular text or sound, visual or audiovisual recording; |
(36) | ‘ electronic_registered_delivery_service’ means a service that makes it possible to transmit data between third parties by electronic means and provides evidence relating to the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations; |
(37) | ‘qualified electronic_registered_delivery_service’ means an electronic_registered_delivery_service which meets the requirements laid down in Article 44; |
(38) | ‘certificate for website authentication’ means an attestation that makes it possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued; |
(39) | ‘qualified certificate for website authentication’ means a certificate for website authentication, which is issued by a qualified trust_service provider and meets the requirements laid down in Annex IV; |
(40) | ‘ validation_data’ means data that is used to validate an electronic_signature or an electronic_seal; |
(41) | ‘ validation’ means the process of verifying and confirming that an electronic_signature or a seal is valid. |
Article 3
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) | ‘ electronic_identification’ means the process of using person_identification_data in electronic form uniquely representing either a natural or legal person, or a natural person representing a legal person; |
(2) | ‘ electronic_identification means’ means a material and/or immaterial unit containing person_identification_data and which is used for authentication for an online service; |
(3) | ‘ person_identification_data’ means a set of data enabling the identity of a natural or legal person, or a natural person representing a legal person to be established; |
(4) | ‘ electronic_identification scheme’ means a system for electronic_identification under which electronic_identification means are issued to natural or legal persons, or natural persons representing legal persons; |
(5) | ‘ authentication’ means an electronic process that enables the electronic_identification of a natural or legal person, or the origin and integrity of data in electronic form to be confirmed; |
(6) | ‘ relying_party’ means a natural or legal person that relies upon an electronic_identification or a trust_service; |
(7) | ‘ public_sector_body’ means a state, regional or local authority, a body_governed_by_public_law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate; |
(8) | ‘ body_governed_by_public_law’ means a body defined in point (4) of Article 2(1) of Directive 2014/24/EU of the European Parliament and of the Council (15); |
(9) | ‘ signatory’ means a natural person who creates an electronic_signature; |
(10) | ‘ electronic_signature’ means data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign; |
(11) | ‘advanced electronic_signature’ means an electronic_signature which meets the requirements set out in Article 26; |
(12) | ‘qualified electronic_signature’ means an advanced electronic_signature that is created by a qualified electronic_signature creation device, and which is based on a qualified certificate for electronic_signatures; |
(13) | ‘ electronic_signature creation data’ means unique data which is used by the signatory to create an electronic_signature; |
(14) | ‘certificate for electronic_signature’ means an electronic attestation which links electronic_signature validation_data to a natural person and confirms at least the name or the pseudonym of that person; |
(15) | ‘qualified certificate for electronic_signature’ means a certificate for electronic_signatures, that is issued by a qualified trust_service provider and meets the requirements laid down in Annex I; |
(16) | ‘ trust_service’ means an electronic service normally provided for remuneration which consists of:
|
(17) | ‘qualified trust_service’ means a trust_service that meets the applicable requirements laid down in this Regulation; |
(18) | ‘ conformity_assessment_body’ means a body defined in point 13 of Article 2 of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust_service provider and the qualified trust_services it provides; |
(19) | ‘ trust_service provider’ means a natural or a legal person who provides one or more trust_services either as a qualified or as a non-qualified trust_service provider; |
(20) | ‘qualified trust_service provider’ means a trust_service provider who provides one or more qualified trust_services and is granted the qualified status by the supervisory body; |
(21) | ‘ product’ means hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of trust_services; |
(22) | ‘ electronic_signature creation device’ means configured software or hardware used to create an electronic_signature; |
(23) | ‘qualified electronic_signature creation device’ means an electronic_signature creation device that meets the requirements laid down in Annex II; |
(24) | ‘ creator_of_a_seal’ means a legal person who creates an electronic_seal; |
(25) | ‘ electronic_seal’ means data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the latter’s origin and integrity; |
(26) | ‘advanced electronic_seal’ means an electronic_seal, which meets the requirements set out in Article 36; |
(27) | ‘qualified electronic_seal’ means an advanced electronic_seal, which is created by a qualified electronic_seal creation device, and that is based on a qualified certificate for electronic_seal; |
(28) | ‘ electronic_seal creation data’ means unique data, which is used by the creator of the electronic_seal to create an electronic_seal; |
(29) | ‘certificate for electronic_seal’ means an electronic attestation that links electronic_seal validation_data to a legal person and confirms the name of that person; |
(30) | ‘qualified certificate for electronic_seal’ means a certificate for an electronic_seal, that is issued by a qualified trust_service provider and meets the requirements laid down in Annex III; |
(31) | ‘ electronic_seal creation device’ means configured software or hardware used to create an electronic_seal; |
(32) | ‘qualified electronic_seal creation device’ means an electronic_seal creation device that meets mutatis mutandis the requirements laid down in Annex II; |
(33) | ‘ electronic_time_stamp’ means data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time; |
(34) | ‘qualified electronic_time_stamp’ means an electronic_time_stamp which meets the requirements laid down in Article 42; |
(35) | ‘ electronic_document’ means any content stored in electronic form, in particular text or sound, visual or audiovisual recording; |
(36) | ‘ electronic_registered_delivery_service’ means a service that makes it possible to transmit data between third parties by electronic means and provides evidence relating to the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations; |
(37) | ‘qualified electronic_registered_delivery_service’ means an electronic_registered_delivery_service which meets the requirements laid down in Article 44; |
(38) | ‘certificate for website authentication’ means an attestation that makes it possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued; |
(39) | ‘qualified certificate for website authentication’ means a certificate for website authentication, which is issued by a qualified trust_service provider and meets the requirements laid down in Annex IV; |
(40) | ‘ validation_data’ means data that is used to validate an electronic_signature or an electronic_seal; |
(41) | ‘ validation’ means the process of verifying and confirming that an electronic_signature or a seal is valid. |
Article 30
Certification of qualified electronic_signature creation devices
1. Conformity of qualified electronic_signature creation devices with the requirements laid down in Annex II shall be certified by appropriate public or private bodies designated by Member States.
2. Member States shall notify to the Commission the names and addresses of the public or private body referred to in paragraph 1. The Commission shall make that information available to Member States.
3. The certification referred to in paragraph 1 shall be based on one of the following:
(a) | a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or |
(b) | a process other than the process referred to in point (a), provided that it uses comparable security levels and provided that the public or private body referred to in paragraph 1 notifies that process to the Commission. That process may be used only in the absence of standards referred to in point (a) or when a security evaluation process referred to in point (a) is ongoing. |
The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
4. The Commission shall be empowered to adopt delegated acts in accordance with Article 47 concerning the establishment of specific criteria to be met by the designated bodies referred to in paragraph 1 of this Article.
whereas