GDPR-Compliant eSignatures: What EU Data Protection Actually Requires
Discover what GDPR actually requires for electronic signatures. This guide covers lawful basis, data processing agreements, security controls, audit trails, data residency, and practical steps for choosing a GDPR-supportive eSignature solution.

Businesses often assume that a “GDPR-compliant eSignature” is a checkbox: either an electronic signature vendor has GDPR compliance or it doesn't. The reality is more nuanced. GDPR compliance depends on how personal data is collected, processed, stored, and protected throughout the signing process, not simply on the signature mechanism itself.
Every time someone signs a document electronically, the workflow may involve personal information such as their name, email address, IP address, and signing timestamp. To use eSignatures responsibly, businesses need to understand their legal obligations, choose appropriate security measures, and know how their signing software handles that data. This guide explains what makes an eSignature GDPR compliant, what to check with your vendor, and how to build a signing process that supports EU data protection requirements.
What Is a GDPR-Compliant eSignature?
A GDPR-compliant eSignature is a signing process in which the personal data it handles, such as signer identity, audit trail, IP address, and timestamp, is handled in accordance with GDPR's rules for lawful processing, security, transparency, and data subject rights. It typically involves appropriate safeguards, including a Data Processing Agreement (DPA) with the software vendor, when the vendor processes personal data on the business's behalf.
The GDPR is technology-neutral. It applies to personal data regardless of whether it is processed on paper, in an app, or through electronic signature software. That means a signing workflow can be GDPR compliant when its data handling meets the regulation's requirements.
Are eSignatures Allowed Under GDPR?
Yes. GDPR does not ban electronic signatures. It regulates how personal data is collected, used, stored, and protected during the signing process.
The important distinction is between GDPR and eIDAS. They address different legal questions:
See the European Commission's eSignature portal for more information.
For example, GDPR may govern how a company stores a signer's email address and IP address, while eIDAS may be relevant to the legal effect or type of electronic signature used.
A signing process can therefore satisfy eIDAS requirements without automatically satisfying every GDPR obligation. Both frameworks may matter, depending on the document, the parties, and the signing workflow.
Learn more about the legal validity of electronic signatures in our guide to Are Electronic Signatures Legal?.
What Actually Makes an eSignature GDPR Compliant?
A GDPR-compliant eSignature process needs more than a secure-looking signing screen. Businesses should consider the legal basis for processing personal data, their relationship with the signing vendor, technical safeguards, and the retention period for signing records. The European Commission's GDPR guidance explains how data protection rules apply to organizations processing personal data.
Here are the core requirements teams should evaluate.
1. A Lawful Basis for Processing the Signer's Data
Under GDPR Article 6, businesses need a lawful basis for processing personal data. The appropriate basis depends on why the data is being processed.
For many signing workflows, processing may be necessary to execute a contract or to take steps at a person's request before entering into a contract. Other situations may involve a legal obligation or legitimate interests.
Consent is not automatically required for every eSignature. If processing is necessary to execute a contract, contractual necessity may be the appropriate legal basis. Consent may be relevant in other circumstances, but it should not be used as a default substitute for assessing the actual purpose of processing.
For example, a business processing a customer's name and email address to prepare and execute a service agreement may rely on contractual necessity where the applicable requirements are met.
Teams should document:
- What personal data is collected during signing.
- Why the data is needed.
- Which lawful basis applies.
- How the signer is informed about the processing.
The European Data Protection Board identifies six lawful bases under GDPR, including consent, contractual necessity, legal obligation, and legitimate interests. The right basis depends on the specific processing activity.
2. A Data Processing Agreement (DPA) With the Vendor
If an eSignature provider processes personal data on behalf of your business, the relationship may fall under GDPR's controller-processor rules.
A Data Processing Agreement, or DPA, sets out the parties' responsibilities for that processing. GDPR Article 28 establishes requirements for contracts between controllers and processors.
A DPA should address relevant matters such as:
- The subject matter and duration of processing.
- The types of personal data involved.
- The categories of data subjects.
- The processor's obligations and responsibilities.
- Confidentiality and security measures.
- Assistance with applicable GDPR obligations.
- Subprocessors and relevant processing arrangements.
- Deletion or return of personal data upon service termination, subject to applicable legal requirements.
Why this matters: Signing software may handle personal information on your behalf, but that does not transfer your entire GDPR responsibility to the vendor. Your business still needs to understand its own role and obligations.
Before adopting an eSignature tool, ask whether a DPA is available, what it covers, and whether the vendor's processing practices match your requirements.
3. Encryption of Personal Data in Transit and at Rest
Electronic signing workflows may contain sensitive business and personal information. Encryption helps protect that information from unauthorized access.
A GDPR-compliant signing process should consider encryption:
- In transit: Protects information as it moves between the signer, browser, and service.
- At rest: Protects stored documents and related personal data.
Encryption is an important technical safeguard, but it is not a complete GDPR compliance program by itself. Businesses should also consider access controls, authentication, internal procedures, and other appropriate security measures.
When evaluating eSignature software, look for clear documentation about encryption and how the provider protects documents and signing records.
4. Audit Trails and Tamper-Evidence
A signing workflow should preserve useful records of what happened during the signing process.
An audit trail may include information such as:
- Who signed the document.
- When the document was signed.
- The signing events and their sequence.
- Relevant IP address or device information, where collected.
- Document and signature status.
Tamper-evident records can help show whether a signed document has been altered after signing. This supports document integrity and can also help businesses investigate disputes or demonstrate how a document was executed.
However, an audit trail does not guarantee that a signature is legally valid or that a process meets all GDPR requirements. The records themselves contain personal data and must also be handled appropriately.
5. EU Data Residency and International Transfers
Where personal data is stored and processed matters for businesses subject to GDPR.
A vendor may process signing data in the EU, outside the EU, or across multiple locations. If personal data is transferred outside the European Economic Area, GDPR Chapter V requires an applicable transfer mechanism and safeguards.
Depending on the circumstances, these may include:
- An applicable European Commission adequacy decision.
- Standard Contractual Clauses (SCCs).
- Other valid transfer mechanisms under GDPR.
EU data residency and GDPR compliance are not the same thing. Storing data in the EU does not automatically make a process compliant, and processing data outside the EU does not automatically make it noncompliant.
Ask your vendor where personal data is processed, which subprocessors are involved, and what safeguards apply to international transfers.
6. Data Subject Rights: Access, Erasure, and Portability
GDPR gives individuals rights concerning their personal data. Depending on the circumstances, these include rights to access, rectification, erasure, restriction of processing, and data portability.
An eSignature workflow should account for these rights.
For example, a business may need to locate a signer's personal data, explain how it is used, or respond to a valid request for access or deletion. The right to erasure is not absolute: legal obligations, contractual needs, and other exceptions may affect whether data can be deleted.
Signed documents may need to be retained for legal, regulatory, or business reasons. A request to erase personal data, therefore, requires an assessment of the applicable obligations rather than automatic deletion of every document.
The GDPR-Compliant Signing Checklist (What Teams Actually Need)
Use this checklist when evaluating an eSignature process or vendor.
Use this checklist as a starting point, not as a substitute for a legal or security review.
If you're comparing eSignature tools, use Fill's eSignature software comparison guide to evaluate the features and workflows that matter to your team.
GDPR eSignature Use Cases: Contracts, HR, and Cross-Border Agreements
The GDPR considerations for eSignatures depend on the type of document, the people involved, and the data being processed.
Customer Contracts and Consent Forms
Businesses should identify the personal data collected, provide appropriate privacy information, and select a lawful basis that matches the purpose of processing.
HR and Employee Onboarding
HR documents may contain sensitive personal information. Limit access to authorized personnel and establish appropriate retention and security practices.
Cross-Border B2B Agreements
Cross-border signing may involve GDPR, local privacy laws, international data transfers, and rules governing electronic signatures. Review the vendor’s processing locations and contractual safeguards.
GDPR, HIPAA, SOC 2, and UETA/ESIGN: Do You Need All of Them?
GDPR, HIPAA, SOC 2, and UETA/ESIGN address different questions. They are not interchangeable certifications or legal requirements.
A single signing workflow may involve more than one framework. The right combination depends on the parties, data, jurisdictions, and purpose of the signing process.
How Fill Supports GDPR-Compliant eSignatures
Fill provides electronic signature and document management features that support several safeguards businesses may evaluate in a GDPR-sensitive signing workflow.
Audit Trails
Fill includes audit trails on every plan to help businesses track relevant signing activity and document the signing process.
256-bit AES Encryption
Fill includes 256-bit AES encryption across all plans to help protect stored document data.
Pro Plan for Additional Healthcare Requirements
Fill's Pro plan includes HIPAA-related support, including a signed Business Associate Agreement (BAA), where applicable. See Fill's pricing page for current plan details.
These features support a broader compliance program. They do not automatically establish that every workflow or organization is GDPR compliant. Businesses remain responsible for evaluating their own legal and operational requirements.
What to Ask an eSignature Vendor Before Signing Up
Before choosing an eSignature vendor, ask how it handles personal data, protects signed documents, and supports your organization’s compliance requirements.
1. Do you have a Data Processing Agreement (DPA)?
Ask whether the vendor provides a DPA, what processing activities it covers, whether subprocessors are involved, and what responsibilities remain with your organization.
2. How do you protect signed documents and personal data?
Ask about encryption, access controls, authentication, security procedures, and available security documentation. Look for specific, verifiable information rather than general claims that the platform is secure.
3. Do you maintain audit trails for signed documents?
Confirm which signing events are recorded, how audit records are protected against unauthorized changes, and how long they are retained.
4. Where is my data stored and processed?
Ask where documents and related personal data are stored and processed, which subprocessors may access them, and what safeguards apply to transfers outside the EEA.
5. What security certifications and compliance support do you have?
Ask which certifications or independent audit reports the vendor has, what they cover, and whether relevant documentation is available.
For example, Fill has undergone a SOC 2 Type II assessment covering controls relevant to Security, Availability, and Confidentiality. A SOC 2 report can support vendor due diligence, but it does not replace your own GDPR obligations.
Remember: A long list of certifications does not replace a review of the vendor’s actual data handling, contractual terms, and security practices.
Common GDPR Signing Mistakes to Avoid
Treating eIDAS Validity and GDPR Compliance as the Same Thing
eIDAS addresses electronic identification and trust services, while GDPR governs personal data processing. A legally valid signature may still involve additional GDPR obligations.
Defaulting to Consent for Every Signing Workflow
Consent is only one possible lawful basis. Assess the actual purpose of processing before selecting a legal basis.
Using a Vendor Without Appropriate Contractual Terms
If a provider processes personal data on your behalf, review whether a DPA and other contractual safeguards are required.
Keeping Signed Documents Indefinitely
Define a retention period based on legal obligations, business needs, and the purpose for which the data was collected.
Frequently Asked Questions
Are electronic signatures GDPR compliant?
Yes, electronic signatures can be used under GDPR. GDPR does not prohibit eSignatures; it regulates how personal data is processed during the signing workflow. Businesses should assess the lawful basis, security safeguards, vendor agreements, retention practices, and applicable data subject rights.
Do I need a Data Processing Agreement (DPA) for eSignatures?
You may need a DPA if your eSignature vendor processes personal data on your behalf as a processor under GDPR. The DPA should address relevant processing responsibilities, security obligations, subprocessors, and other applicable requirements.
What are the GDPR requirements for electronic signatures?
GDPR eSignature requirements may include identifying a lawful basis, protecting personal data, reviewing vendor agreements, managing retention, addressing data subject rights, and assessing international transfers. GDPR does not prescribe one specific electronic signature technology.
What's the difference between GDPR and eIDAS?
GDPR governs the processing and protection of personal data, while eIDAS establishes the EU legal framework for electronic identification and trust services, including electronic signatures. Both may apply to the same signing workflow.
Is EU data residency required for GDPR compliance?
No. GDPR does not universally require personal data to be stored in the EU. However, transfers outside the EEA may require an appropriate legal mechanism and safeguards, such as an adequacy decision or Standard Contractual Clauses.
Conclusion
A GDPR-compliant eSignature is not defined by a single certification or signature type. It depends on how your business processes signer data, protects documents, manages vendors, and respects data protection obligations.
Before choosing an eSignature tool, check the lawful basis, DPA, encryption, audit trail, international transfers, and retention practices. These safeguards help build a signing workflow that supports GDPR compliance while keeping document execution simple.
Evaluating eSignature software for GDPR-sensitive workflows? Explore how Fill supports electronic signing, document management, audit trails, and encryption.


