Two questions people keep merging into one
There are two entirely separate questions hiding inside "is our e-signature GDPR-compliant?", and answering them together is how teams tie themselves in knots.
The first question is whether the signature is legally valid — whether a court will treat the electronic mark as equivalent to wet ink. In Europe that is answered by eIDAS, not by GDPR. The second question is whether the personal data generated when someone signs — their name, email, IP address, timestamps, and any identity-verification data — is collected and kept lawfully. That is GDPR, and it has nothing to do with whether the signature holds up.
You can have a perfectly valid signature built on unlawful data handling, and vice versa. This article is about the second question. It is general guidance, not legal advice — confirm your own position with a qualified data-protection adviser.
The personal data a signature actually creates
Before you can reason about lawful basis, you have to see the data. A single completed signature typically produces:
- Identity data — the signer's name and email address, and often their role or company.
- Attribution and evidence data — the IP address they signed from, device and browser details, and the sent/viewed/signed timestamps that make the audit trail hold up.
- Verification data — if you required identity verification, the fact and result of an access code, SMS code, or knowledge-based check.
- The document itself, which frequently contains far more personal data than the signature metadata — home addresses, salary, health details, financial terms.
Under GDPR all of this is personal data, and the metadata that proves who signed and when is not incidental — it is the evidence. That creates the central tension we come back to below: the very data that makes a signature defensible is data a signer might one day ask you to delete.
The lawful basis you actually rely on
GDPR requires a lawful basis under Article 6 for processing personal data. The instinct is to reach for consent — but consent is usually the wrong basis for a signing record, for two reasons.
First, "I consent to sign this document electronically" is not the same thing as GDPR consent. The consent and disclosure step in an e-signature flow is an ESIGN/UETA/eIDAS concept — the signer agreeing to transact electronically. It is about signature validity, not about a lawful basis to process their data. Merging the two produces a consent notice that satisfies neither regime cleanly.
Second, GDPR consent must be freely given and freely withdrawable. If a signer could withdraw consent and thereby force you to delete a signed contract, the signature would be worthless as evidence. That is not a stable foundation for a legal record.
In practice the defensible bases are:
- Performance of a contract (Art. 6(1)(b)) — for signing the agreement the signer is a party to. Processing their data to execute and evidence that contract is necessary for the contract itself.
- Compliance with a legal obligation (Art. 6(1)(c)) — where a law requires you to keep signed records for a retention period.
- Legitimate interests (Art. 6(1)(f)) — for the audit and fraud-prevention metadata that proves the signature, balanced against the signer's rights. Being able to prove a signature was genuine is a textbook legitimate interest.
The point: reach for contract, legal obligation, and legitimate interests — not consent — as the backbone of a signing record.
Controller and processor: who is responsible for what
GDPR splits responsibility between the controller, who decides why and how personal data is processed, and the processor, who processes it on the controller's instructions.
When your business sends a document for signature, you are the controller — you chose to collect the signer's data for your purpose. The signing platform is your processor. Article 28 requires a written data processing agreement (DPA) between you that binds the processor to act only on your instructions, to apply appropriate security, to help you answer data-subject requests, and to handle sub-processors and deletion properly.
This is not paperwork you skip. If you are a European business, or you process the data of people in the EU, a DPA with your e-signature provider is a hard requirement, not a nice-to-have. Before you commit to any platform, confirm a DPA is available and read what it says about sub-processors and where data is stored. If you need one for Hitt Hosting Sign, contact us.
Data minimization: collect only what proves the signature
GDPR's minimization principle says collect no more personal data than you need for the purpose. For signing, the purpose is attribution — proving this specific person signed this specific document. That justifies capturing identity, IP, and timestamps. It does not justify demanding a passport scan for a routine internal approval.
Match the verification method to the risk of the document. A low-stakes acknowledgement needs an email link; a high-value contract may justify SMS or knowledge-based verification. Escalating everyone to the strictest check "to be safe" is the opposite of safe under GDPR — it is over-collection you then have to secure, justify, and eventually delete.
The right to erasure meets the record you must keep
This is where e-signatures and GDPR genuinely collide, and where most confusion lives.
Article 17 gives individuals a right to erasure — the "right to be forgotten." A signer can ask you to delete their personal data. But that right is not absolute. It does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise, or defense of legal claims.
A signed contract is the archetypal case for both exceptions. You often have a statutory obligation to retain it, and you almost always need it available to defend or enforce the agreement. So when a signer asks you to erase a contract they signed, the lawful answer is frequently: the signed record and its audit trail are retained under a legal-obligation and legal-claims basis for the retention period, after which they are deleted. You can — and often must — decline erasure of the evidence itself, while still honoring erasure of data you no longer have a basis to keep, like a marketing profile built from the same email.
Two disciplines make this defensible rather than arbitrary:
- Have a real retention schedule. "We keep signed documents forever because deleting is scary" is not a lawful basis. Decide how long each document type must be kept and why, then actually delete on schedule — the mechanics of which are covered in data retention and deletion.
- Do not silently alter the record to satisfy a request. You cannot redact a name out of a signed PDF to "comply" — that breaks the very integrity the signature depends on. The tamper-evident chain exists precisely so no byte changes after signing. Erasure is handled by retention expiry and deletion of the whole record, not by editing a sealed one.
Cross-border transfers and where the data lives
If EU personal data leaves the European Economic Area, GDPR requires a transfer safeguard — an adequacy decision, standard contractual clauses, or another Chapter V mechanism. For an e-signature, that turns on where your provider stores the signed documents and audit trail, which is why data residency is a GDPR question and not just an operational one. Confirm the storage region and the transfer mechanism in your DPA before you send EU signers' documents anywhere.
Security is a GDPR obligation, not a bonus
Article 32 requires appropriate technical measures to protect personal data, including — where appropriate — encryption and the ability to ensure the integrity of processing. An e-signature platform is unusually well placed here. Every document sealed with a SHA-256 hash and an RFC 3161 trusted timestamp, with each step written to a tamper-evident audit trail, is directly evidencing the integrity that Article 32 asks for. Encryption in transit and at rest covers the confidentiality side. Being able to prove a record was not altered is not just good for a court case — it is a data-protection control.
A short checklist
- Separate the two questions: eIDAS for signature validity, GDPR for data handling.
- Rely on contract, legal obligation, and legitimate interests — not consent — as your lawful basis for a signing record.
- Sign a DPA with your provider before processing EU signers' data, and read the sub-processor and storage terms.
- Minimize: match the verification level to the document's risk.
- Set a real retention schedule and delete on it; decline erasure of records you are obliged to keep, and never mutate a sealed document to fake compliance.
- Confirm the storage region and any cross-border transfer safeguard.
Handled this way, GDPR and e-signatures are not in conflict. A properly run signing platform collects the minimum data needed to prove a signature, secures it, keeps it exactly as long as the law requires, and can demonstrate — with a sealed, verifiable record — that nothing changed in between. See the features or start free.
This article is general guidance on data protection and e-signatures, not legal advice. GDPR obligations are fact-specific and depend on your role, your data, and your jurisdiction; confirm your position with a qualified data-protection adviser.