Non-repudiation

Non-repudiation means a signatory cannot credibly deny signing a document: the evidence from an electronic or digital signature binds the act to them.

Non-repudiation means a signatory cannot credibly deny having signed: the evidence binds the act to the person. It is the legal purpose behind the technical chain - identity verification proves who got the key, sole control proves only they could use it, the cryptographic binding proves what exactly was signed, and a timestamp proves when. The term is also used more broadly in information security (ISO/IEC 27000, X.800) to describe proof of origin, receipt or delivery of data - a purpose eIDAS also serves through electronic registered delivery services - and an X.509 certificate can carry a nonRepudiation (also called contentCommitment) keyUsage bit marking a key as intended for this purpose. eIDAS itself never uses the term non-repudiation, though; it is a security-standards term commonly applied to describe the effect the regulation's signature and seal provisions aim for.

A qualified electronic signature packages that chain with legal effect: eIDAS Article 25(2) gives it the same standing as a handwritten signature, and Dutch law builds on that foundation in article 3:15a of the Civil Code. Exactly how far this shifts the burden of proof is debated: article 159 of the Code of Civil Procedure states that once a private deed's signature is firmly denied, the deed carries no evidentiary weight until the party relying on it proves the signature's origin - so the formal burden in principle still rests with the relying party, not the denier. eIDAS gives a qualified signature no presumption of authenticity - Article 25(2) grants it the equivalent legal effect of a handwritten signature, and the express presumption of integrity and correctness of origin in Article 35(2) is written for qualified electronic seals. What makes the proof easier in practice is the evidentiary weight of that equivalence combined with the QTSP's audited process, which can push the practical burden back onto whoever denies signing; it is a strong, rebuttable evidentiary position rather than a statutory reversal of the burden of proof.

That evidentiary strength must also survive over time: certificates expire or can be revoked, so long-term validation or archiving is needed to keep proving the signature was valid at the moment of signing, beyond what the timestamp alone captures.

Frequently asked questions

Back to glossary