keyboard_tab EIDAS 2014/0910 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- 1 Article 3 Definitions
- 3 Article 8 Assurance levels of electronic identification schemes
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
ELECTRONIC IDENTIFICATION
CHAPTER III
TRUST SERVICES
SECTION 1
General provisions
SECTION 2
Supervision
SECTION 3
Qualified trust services
SECTION 4
Electronic signatures
SECTION 5
Electronic seals
SECTION 6
Electronic time stamps
SECTION 7
Electronic registered delivery services
SECTION 8
Website authentication
CHAPTER IV
ELECTRONIC DOCUMENTS
CHAPTER V
DELEGATIONS OF POWER AND IMPLEMENTING PROVISIONS
CHAPTER VI
FINAL PROVISIONS
- electronic identification
- electronic identification means
- person identification data
- electronic identification scheme
- authentication
- relying party
- public sector body
- body governed by public law
- signatory
- electronic signature
- advanced electronic signature
- qualified electronic signature
- electronic signature creation data
- certificate for electronic signature
- qualified certificate for electronic signature
- trust service
- qualified trust service
- conformity assessment body
- trust service provider
- qualified trust service provider
- product
- electronic signature creation device
- qualified electronic signature creation device
- creator of a seal
- electronic seal
- advanced electronic seal
- qualified electronic seal
- electronic seal creation data
- certificate for electronic seal
- qualified certificate for electronic seal
- electronic seal creation device
- qualified electronic seal creation device
- electronic time stamp
- qualified electronic time stamp
- electronic document
- electronic registered delivery service
- qualified electronic registered delivery service
- certificate for website authentication
- qualified certificate for website authentication
- validation data
- validation
- means 56
- which 27
- electronic_identification 23
- person 20
- data 16
- electronic_seal 15
- electronic 14
- legal 14
- natural 14
- electronic_signature 13
- creation 12
- qualified 12
- ‘qualified 11
- trust_service 10
- article 10
- meets 10
- requirements 10
- form 9
- certificate 9
- technical 9
- identity 9
- used 8
- laid 8
- down 8
- assurance 8
- shall 8
- issued 7
- provides 7
- specifications 6
- website 6
- standards 6
- provider 6
- substantial 6
- related 5
- electronic_signature’ 5
- reference 5
- procedures 5
- electronic_seal’ 5
- scheme 5
- annex 5
- body 4
- hardware 4
- software 4
- trust_services 4
- device’ 4
- including 4
- device 4
- electronic_signatures 4
- levels 4
- high 4
Article 3
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) | ‘ electronic_identification’ means the process of using person_identification_data in electronic form uniquely representing either a natural or legal person, or a natural person representing a legal person; |
(2) | ‘ electronic_identification means’ means a material and/or immaterial unit containing person_identification_data and which is used for authentication for an online service; |
(3) | ‘ person_identification_data’ means a set of data enabling the identity of a natural or legal person, or a natural person representing a legal person to be established; |
(4) | ‘ electronic_identification scheme’ means a system for electronic_identification under which electronic_identification means are issued to natural or legal persons, or natural persons representing legal persons; |
(5) | ‘ authentication’ means an electronic process that enables the electronic_identification of a natural or legal person, or the origin and integrity of data in electronic form to be confirmed; |
(6) | ‘ relying_party’ means a natural or legal person that relies upon an electronic_identification or a trust_service; |
(7) | ‘ public_sector_body’ means a state, regional or local authority, a body_governed_by_public_law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate; |
(8) | ‘ body_governed_by_public_law’ means a body defined in point (4) of Article 2(1) of Directive 2014/24/EU of the European Parliament and of the Council (15); |
(9) | ‘ signatory’ means a natural person who creates an electronic_signature; |
(10) | ‘ electronic_signature’ means data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign; |
(11) | ‘advanced electronic_signature’ means an electronic_signature which meets the requirements set out in Article 26; |
(12) | ‘qualified electronic_signature’ means an advanced electronic_signature that is created by a qualified electronic_signature creation device, and which is based on a qualified certificate for electronic_signatures; |
(13) | ‘ electronic_signature creation data’ means unique data which is used by the signatory to create an electronic_signature; |
(14) | ‘certificate for electronic_signature’ means an electronic attestation which links electronic_signature validation_data to a natural person and confirms at least the name or the pseudonym of that person; |
(15) | ‘qualified certificate for electronic_signature’ means a certificate for electronic_signatures, that is issued by a qualified trust_service provider and meets the requirements laid down in Annex I; |
(16) | ‘ trust_service’ means an electronic service normally provided for remuneration which consists of:
|
(17) | ‘qualified trust_service’ means a trust_service that meets the applicable requirements laid down in this Regulation; |
(18) | ‘ conformity_assessment_body’ means a body defined in point 13 of Article 2 of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust_service provider and the qualified trust_services it provides; |
(19) | ‘ trust_service provider’ means a natural or a legal person who provides one or more trust_services either as a qualified or as a non-qualified trust_service provider; |
(20) | ‘qualified trust_service provider’ means a trust_service provider who provides one or more qualified trust_services and is granted the qualified status by the supervisory body; |
(21) | ‘ product’ means hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of trust_services; |
(22) | ‘ electronic_signature creation device’ means configured software or hardware used to create an electronic_signature; |
(23) | ‘qualified electronic_signature creation device’ means an electronic_signature creation device that meets the requirements laid down in Annex II; |
(24) | ‘ creator_of_a_seal’ means a legal person who creates an electronic_seal; |
(25) | ‘ electronic_seal’ means data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the latter’s origin and integrity; |
(26) | ‘advanced electronic_seal’ means an electronic_seal, which meets the requirements set out in Article 36; |
(27) | ‘qualified electronic_seal’ means an advanced electronic_seal, which is created by a qualified electronic_seal creation device, and that is based on a qualified certificate for electronic_seal; |
(28) | ‘ electronic_seal creation data’ means unique data, which is used by the creator of the electronic_seal to create an electronic_seal; |
(29) | ‘certificate for electronic_seal’ means an electronic attestation that links electronic_seal validation_data to a legal person and confirms the name of that person; |
(30) | ‘qualified certificate for electronic_seal’ means a certificate for an electronic_seal, that is issued by a qualified trust_service provider and meets the requirements laid down in Annex III; |
(31) | ‘ electronic_seal creation device’ means configured software or hardware used to create an electronic_seal; |
(32) | ‘qualified electronic_seal creation device’ means an electronic_seal creation device that meets mutatis mutandis the requirements laid down in Annex II; |
(33) | ‘ electronic_time_stamp’ means data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time; |
(34) | ‘qualified electronic_time_stamp’ means an electronic_time_stamp which meets the requirements laid down in Article 42; |
(35) | ‘ electronic_document’ means any content stored in electronic form, in particular text or sound, visual or audiovisual recording; |
(36) | ‘ electronic_registered_delivery_service’ means a service that makes it possible to transmit data between third parties by electronic means and provides evidence relating to the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations; |
(37) | ‘qualified electronic_registered_delivery_service’ means an electronic_registered_delivery_service which meets the requirements laid down in Article 44; |
(38) | ‘certificate for website authentication’ means an attestation that makes it possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued; |
(39) | ‘qualified certificate for website authentication’ means a certificate for website authentication, which is issued by a qualified trust_service provider and meets the requirements laid down in Annex IV; |
(40) | ‘ validation_data’ means data that is used to validate an electronic_signature or an electronic_seal; |
(41) | ‘ validation’ means the process of verifying and confirming that an electronic_signature or a seal is valid. |
Article 8
Assurance levels of electronic_identification schemes
1. An electronic_identification scheme notified pursuant to Article 9(1) shall specify assurance levels low, substantial and/or high for electronic_identification means issued under that scheme.
2. The assurance levels low, substantial and high shall meet respectively the following criteria:
(a) | assurance level low shall refer to an electronic_identification means in the context of an electronic_identification scheme, which provides a limited degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of misuse or alteration of the identity; |
(b) | assurance level substantial shall refer to an electronic_identification means in the context of an electronic_identification scheme, which provides a substantial degree of confidence in the claimed or asserted identity of a person, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of misuse or alteration of the identity; |
(c) | assurance level high shall refer to an electronic_identification means in the context of an electronic_identification scheme, which provides a higher degree of confidence in the claimed or asserted identity of a person than electronic_identification means with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent misuse or alteration of the identity. |
3. By 18 September 2015, taking into account relevant international standards and subject to paragraph 2, the Commission shall, by means of implementing acts, set out minimum technical specifications, standards and procedures with reference to which assurance levels low, substantial and high are specified for electronic_identification means for the purposes of paragraph 1.
Those minimum technical specifications, standards and procedures shall be set out by reference to the reliability and quality of the following elements:
(a) | the procedure to prove and verify the identity of natural or legal persons applying for the issuance of electronic_identification means; |
(b) | the procedure for the issuance of the requested electronic_identification means; |
(c) | the authentication mechanism, through which the natural or legal person uses the electronic_identification means to confirm its identity to a relying_party; |
(d) | the entity issuing the electronic_identification means; |
(e) | any other body involved in the application for the issuance of the electronic_identification means; and |
(f) | the technical and security specifications of the issued electronic_identification means. |
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
whereas