Legal background

Electronic signatures in AM CRM

This page explains what kind of signature this system creates, what evidence is produced along the way, and how electronic signatures are treated across different legal systems. It is written for everyone involved in a signing process — including people who have no account in this CRM.

Which level of signature is created?

AM CRM creates a simple electronic signature (SES). That means data in electronic form which is attached to a declaration and associated with the signing person — for example a drawn signature, a typed name or an uploaded signature image, together with the circumstances in which it was given.

What is expressly not created is an advanced (AES) or a qualified electronic signature (QES). Both require a personal signing certificate and — for the QES — a qualified trust service provider that has verified the signer’s identity beforehand. No such certificates are issued or integrated here. Wherever you have been promised a higher level, or the law requires one, this is not the right tool.

This classification also appears on every certificate produced, so that it does not get lost when the document is passed on.

What happens technically

The process is built so that every step can be evidenced on its own and later changes stand out — including changes made by the operator of the system.

  1. Fixing the document. When the document is sent out, a SHA-256 checksum is calculated over its original version. That checksum feeds into a short verification code which later appears on the certificate.
  2. Personal access. Every person involved receives their own link, valid only for them. There is no shared access through which several people could sign.
  3. Confirmation code. Before signing, a one-time code is sent to the email address on file and has to be entered. That evidences not only possession of the link but also access to the mailbox. The code is stored only as a hash; not even the operator can read it back.
  4. Express consent. Before signing, the signer separately confirms that they wish to sign electronically. The exact wording of that consent is recorded with its version, so it can later be established which text was actually shown.
  5. Signature. The signature is drawn, typed or uploaded as an image and placed into the document. A full first and last name is mandatory.
  6. Surrounding circumstances. For every step, the time, IP address, device class, browser identification and — as far as it can be derived from the network — the approximate region are recorded. No location is requested from the device and no external geolocation service is used.
  7. Sealing. Once everyone involved has signed, a final version with its own checksum is produced. From that point on, the process is locked against deletion.
  8. Chained history. Every step is stored with a checksum over its own content and the checksum of the preceding step. If an entry is subsequently altered, deleted or inserted, the chain no longer matches from that point onwards. This can be recalculated.
  9. Certificate. Everyone involved receives the sealed version together with the certificate: signature level, verification code, both checksums, the state of the chain and the full history with individual checksums.
  10. Independent verification. With the verification code, anyone can check the process at am-crm.com/pruefen — without signing in and without access to the CRM.

The verification page distinguishes honestly between “unchanged”, “changed” and “not verified”. A state that could not be recalculated at that moment is never reported as being in order.

Legal treatment by jurisdiction

As a general rule, the following applies in all of the jurisdictions listed below: most contracts are not subject to any particular form and can be concluded electronically; a declaration must not be treated as invalid merely because it was made electronically. Where the law does require a particular form, however, that requirement continues to apply — and a simple electronic signature is generally not sufficient there.

European Union

Legal basis

Regulation (EU) No 910/2014 (eIDAS); in Germany supplemented by §§ 126, 126a, 127 BGB (German Civil Code).

Treatment

eIDAS distinguishes between simple, advanced and qualified signatures. An electronic signature must not be denied legal effect merely because it is electronic; only the qualified signature is expressly placed on an equal footing with a handwritten one. Where a law requires written form, that can only be satisfied electronically by a qualified signature — so not by an SES.

Typically excluded (not exhaustive)

  • Termination of employment and termination agreements (§ 623 BGB — electronic form excluded, a handwritten signature is required)
  • Fixed-term clauses in employment contracts (§ 14 (4) TzBfG)
  • A guarantee given by a private individual (§ 766 BGB)
  • Consumer loan agreements (§ 492 BGB)
  • Leases with a term of more than one year (§ 550 BGB — otherwise the lease counts as open-ended)
  • Anything requiring notarisation, such as contracts for the sale of land (§ 311b BGB)
  • Wills and contracts of inheritance (§ 2247 BGB — handwritten or notarised)

United States

Legal basis

The ESIGN Act (15 U.S.C. §§ 7001 et seq.) at federal level, together with the Uniform Electronic Transactions Act (UETA), which has been adopted by almost every state; New York has its own, materially comparable statute.

Treatment

Electronic signatures and records are in principle placed on an equal footing with paper signatures, provided both sides agree to the electronic route, the signer intended to sign, and the record remains retrievable. No particular signature level is prescribed — what matters is that these points can be evidenced, which is precisely what the certificate documents.

Typically excluded (not exhaustive)

  • Wills, codicils and testamentary trusts
  • Family law matters such as divorce or adoption
  • Court filings, orders and official documents
  • Notices of cancellation for utility services such as electricity, water or heat
  • Eviction and foreclosure notices relating to a primary residence
  • Cancellation of health and life insurance policies
  • Product recalls and safety notices
  • Documents accompanying the transport of hazardous materials

United Kingdom

Legal basis

Electronic Communications Act 2000 (in particular s. 7); confirmed and set out by the Law Commission’s 2019 report on electronic execution of documents.

Treatment

Electronic signatures are effective for most contracts and admissible in court as evidence. For a deed, the additional requirements remain in place, in particular the presence and counter-signature of a witness.

Typically excluded (not exhaustive)

  • Wills
  • Lasting powers of attorney
  • Certain HM Land Registry applications and dispositions, depending on the type of transaction
  • Deeds without the additionally required witnessing

Switzerland

Legal basis

The Code of Obligations (Art. 11 et seq. OR, in particular Art. 14 (2bis) OR) and the Federal Act on Electronic Signatures (ZertES).

Treatment

Contracts are in principle not subject to any particular form and are therefore valid electronically as well. Only a qualified electronic signature combined with a qualified timestamp is placed on an equal footing with a handwritten signature. Where the law requires written form, a simple electronic signature is consequently not sufficient.

Typically excluded (not exhaustive)

  • Wills, marital property and inheritance contracts (public notarisation or handwritten execution)
  • Guarantees given by natural persons (Art. 493 OR)
  • Contracts for the sale of land (Art. 216 OR — public notarisation)
  • Consumer credit agreements under the Consumer Credit Act
  • Apprenticeship contracts and other contracts for which written form is prescribed by law

Canada

Legal basis

At federal level, Part 2 of the Personal Information Protection and Electronic Documents Act (PIPEDA); alongside it the provincial statutes, such as the Electronic Commerce Act 2000 in Ontario, the Electronic Transactions Acts in Alberta and British Columbia, and in Québec the Act to establish a legal framework for information technology.

Treatment

Electronic documents and signatures are in principle placed on an equal footing with paper, provided the parties consent to the electronic route. For certain dealings with federal authorities a “secure electronic signature” with a certificate is prescribed; AM CRM does not provide that level.

Typically excluded (not exhaustive)

  • Wills and codicils, as well as trusts created by a will
  • Powers of attorney over property and personal care
  • Bills of exchange, cheques and other negotiable instruments
  • Transfers of land, regulated differently from province to province
  • Any dealing for which a “secure electronic signature” is expressly required

What evidence is produced

In a dispute it is rarely the signature itself that matters, but who saw and confirmed what, and when. For every process, the following is therefore on record:

  • Checksum of the original version and of the sealed version (SHA-256)
  • Short verification code for independent checking
  • Time of every step: creation, sending, first opening, consent, code check, signature, completion
  • For each party: name, role, IP address, browser identification, device class, approximate region
  • The exact version of the consent to sign electronically
  • How the signature was created (drawn, typed, uploaded)
  • Checksum of every single history entry, chained to the preceding one
  • Evidence that the confirmation code was checked — without storing the code itself

Please note

This page gives a general overview and is not legal advice. The exceptions listed are examples and expressly not exhaustive; legislation and case law change, and depending on the state, province or type of contract, further formal requirements may apply. Whether a simple electronic signature is sufficient for your particular case should be checked legally before you rely on it — for employment matters, guarantees, land, powers of attorney and wills it regularly is not.

Verify a document · AM CRM