Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

How is my data protected when signing remotely?

Remote signing processes two categories of data: identity data for certificate issuance, and the documents to be signed or their hash values. Both fall under the General Data Protection Regulation (GDPR).

Qualified trust service providers are additionally subject to the security and supervisory obligations in Chapter III of the eIDAS Regulation and are audited regularly by a conformity assessment body. For a data protection assessment, however, what matters most is which data reaches the provider at all.

Here's how data protection is implemented in remote signing:

  • Data minimisation through hash signing: With hash signing your application computes the hash locally and transmits only that value. The document content never leaves your system boundary.
  • Processing location: For a GDPR assessment what counts is where processing happens and which law the provider is subject to — not only where the servers stand.
  • Group structure: Providers with a parent company outside the EU may be exposed to third-country access even with European hosting.
  • Data processing agreement: An agreement under Article 28 GDPR governs purpose limitation, instruction rights and sub-processor relationships.
  • Retention periods: Signing logs and identity evidence carry their own retention obligations, which must be documented.
  • Encryption: Transmission and storage are encrypted; signing keys reside exclusively in the certified HSM.

What to check during evaluation:

  • Provider jurisdiction: Ask about the registered office and group structure, not only the data centre location.
  • Verifiable certifications: Conformity reports and certificates should be publicly retrievable and current.
  • Hash signing as an option: Check whether the provider supports hash signing — often the single most effective data protection measure.

primesign is operated by CRYPTAS International GmbH, headquartered in Austria, with EU hosting and locations in Vienna, Graz, Düsseldorf, Hengelo and Stockholm. Through the HASH SIGNING API, documents can be signed without their content ever reaching primesign; the related data protection and conformity documents are published in the primesign Trust Center.

Benefits

  • Processing and hosting entirely within the EU
  • No third-country access via a foreign parent company
  • Data minimisation possible through hash signing
  • Publicly available evidence for audit and privacy reviews
  • Clear responsibilities set out in the data processing agreement

Still have questions?

Clarify data protection and hosting questions directly with our team.

Talk to an expert