Practical guides for e-signatures & contracts
Honest writing on e-signature law, contract lifecycle management, compliance, signing workflows, and the realities of running a paperless, defensible signing process.
QES vs AES vs SES: The Three Levels of Electronic Signature Under eIDAS
European e-signature law does something US law does not: it defines three distinct legal tiers of electronic signature — simple (SES), advanced (AES), and qualified (QES) — each with its own requirements and legal weight. Only one, the QES, is granted the same legal effect as a handwritten signature across the entire EU. Here is what separates the three levels, when each is appropriate, and why most cross-border business never needs the top tier.
SOC 2 and Your E-Signature Vendor: What the Report Actually Proves
Procurement asks "are they SOC 2?" as if it were a yes/no fact about trustworthiness. It is neither. A plain explanation of what a SOC 2 report is, what the two types and five Trust Services Criteria actually cover, why a signing tool needs Security and Confidentiality most, and the concrete controls you can verify yourself — with or without a report on the table.
Legal Hold: Preserving Signed Documents When Litigation Is Coming
The moment you reasonably anticipate a dispute, your ordinary deletion schedule becomes a liability. A practical guide to the duty to preserve, why the "reasonably anticipated" trigger is earlier than most people think, how a legal hold interacts with a retention schedule, and why a tamper-evident audit trail turns preservation from a scramble into a checkbox.
eIDAS 2.0 and the EU Digital Identity Wallet: What Changes for Signing
The 2024 reform of eIDAS did not tear up the three signature tiers — it added a new way to prove who you are. A clear look at what eIDAS 2.0 actually changed, what the EU Digital Identity Wallet is, how it could make a qualified signature far easier to obtain, and what a business signing with European counterparties should do now versus later.
E-Signatures and GDPR: Lawful Basis, the DPA, and the Right to Erasure
Whether an electronic signature is legally valid and whether the personal data behind it is handled lawfully are two different questions — the first is eIDAS, the second is GDPR. A practical map of the lawful basis you actually rely on, why signing consent is not GDPR consent, the controller/processor split, and how the right to erasure collides with a signed record you are obliged to keep.
E-Signatures for Government Contractors: FAR, ESIGN, and What Actually Applies
Government contracting sounds like it should have its own special signing rules — and in a few places it does. But most federal contract documents e-sign under the same law as everything else. A clear map of where FAR touches signatures, where ESIGN carries the day, and what to keep in your file.