Skip to content

Legal Compliance

WPsigner provides the tools and features necessary to create legally compliant electronic signatures. This page covers the major regulations and how WPsigner helps you meet compliance requirements.

The Electronic Signatures in Global and National Commerce Act establishes that:

RequirementMeaning
Legal equivalenceE-signatures have same legal weight as handwritten
IntentSigner must intend to sign
ConsentParties must agree to use electronic format
Record retentionE-records must be accurately retained

WPsigner compliance:

  • ✅ Captures clear intent through signing action
  • ✅ Records consent in audit trail
  • ✅ Stores documents with full audit history

The Uniform Electronic Transactions Act is adopted by 49 states (all except New York, which has similar laws):

PrincipleWPsigner Support
E-signature validity✅ Fully supported
E-record validity✅ PDF storage with audit trail
Attribution✅ Links signature to signer identity
Effect of change✅ Digital signature detects tampering

The EU’s electronic IDentification, Authentication and trust Services regulation defines three signature levels:

LevelDescriptionLegal EffectWPsigner
SES (Simple)Any electronic signatureValid, may need additional evidence✅ Default
AdES (Advanced)Uniquely linked to signer, under signer’s controlStronger presumption of validity✅ With OTP
QES (Qualified)AdES + qualified certificate + QTSPEquivalent to handwritten⚠️ Requires QTSP certificate

WPsigner signature levels:

┌─────────────────────────────────────────────────────────┐
│ QES (Qualified) │
│ • Commercial AATL certificate from QTSP │
│ • Highest legal standing in EU │
├─────────────────────────────────────────────────────────┤
│ AdES (Advanced) ✅ │
│ • OTP verification enabled │
│ • Digital ID configured │
│ • Timestamping enabled │
├─────────────────────────────────────────────────────────┤
│ SES (Simple) ✅ │
│ • Basic WPsigner signatures │
│ • Audit trail with IP and device info │
└─────────────────────────────────────────────────────────┘
Country/RegionLawStatus
United KingdomUK eIDAS / ECA 2000✅ Recognized
CanadaPIPEDA + Provincial✅ Recognized
AustraliaElectronic Transactions Act 1999✅ Recognized
IndiaIT Act 2000✅ Recognized
BrazilMP 2.200-2/2001✅ Recognized

The Health Insurance Portability and Accountability Act applies to Protected Health Information (PHI):

HIPAA RequirementWPsigner Solution
Access controlsRole-based WordPress permissions
Audit controlsComplete audit trail logging
Integrity controlsDigital signatures detect tampering
Transmission securityHTTPS encryption (your server)
Business Associate AgreementRequired with hosting provider

HIPAA Compliance Checklist:

  • Host on HIPAA-compliant infrastructure
  • Configure OTP verification
  • Enable Digital ID signing
  • Enable audit trail with geolocation
  • Sign BAA with hosting provider
  • Implement access controls
  • Train staff on procedures

[!IMPORTANT] WPsigner provides the technical controls. You are responsible for administrative and physical safeguards, plus BAA with your hosting provider.

RequirementWPsigner Feature
SOX 802 - Record retentionPermanent document storage
SOX 802 - IntegrityDigital signatures, tampering detection
FINRA 4511 - Books and recordsTimestamped audit trails
FINRA 3110 - SupervisionAudit logs show who signed what

The American Bar Association recognizes e-signatures for:

  • Client engagement letters
  • Contracts and agreements
  • Settlement agreements
  • Non-disclosure agreements

Best practices for legal documents:

  1. Enable Digital ID (PKI certificate)
  2. Enable timestamping (TSA)
  3. Use sequential signing for approval chains
  4. Keep complete audit trails

Many real estate documents can be signed electronically:

✅ Allowed⚠️ May Require Wet Signature
Purchase agreementsDeeds (varies by state)
Listing agreementsNotarized documents
Lease agreementsSome title documents
Addendums

Cryptographic signatures that prove:

  • Authenticity - Who signed
  • Integrity - Document not altered
  • Non-repudiation - Signer cannot deny signing

Configure at: WPsigner → More → Digital ID

RFC 3161 timestamps prove:

  • Exact signing time - From trusted third party
  • Long-term validity - Valid after certificate expires

Configure at: WPsigner → Settings → Legal & Privacy

Every document includes:

  • All signer actions with timestamps
  • IP addresses and device information
  • Consent records
  • Viewing history

See: Audit Trails Documentation

Multiple verification methods:

  • Email verification - Link only works for recipient
  • OTP verification - Code sent to signer’s email
  • PIN protection - Additional access code

Every completed document includes:

  • Summary of all signatures
  • Complete audit trail
  • Compliance attestation

Document TypeNotes
ContractsAll jurisdictions
NDAsAll jurisdictions
Employment agreementsAll jurisdictions
Service agreementsAll jurisdictions
Purchase ordersAll jurisdictions
Terms and conditionsAll jurisdictions
Client proposalsAll jurisdictions
HR documentsMost jurisdictions
Document TypeConsideration
Real estate deedsCheck state requirements
Wills and testamentsOften require witnesses/notarization
Court documentsCheck local rules
Powers of attorneyVaries by jurisdiction
Healthcare directivesMay require witnesses
Document TypeReason
Notarized documentsPhysical notary required
Some government formsSpecific requirements
Certain immigration formsFederal requirements

  • WPsigner installed and configured
  • HTTPS enabled on your site
  • Audit trail enabled (default)
  • Documents stored securely
  • Access controls in place
  • Digital ID configured
  • OTP verification enabled
  • Timestamping enabled
  • Advanced audit trail (geolocation, device)
  • Document retention policy defined
  • All AdES requirements
  • Commercial AATL certificate from QTSP
  • Identity verification procedures
  • Staff training documented
  • Compliance policies written

WPsigner displays a Compliance Score in More → Security & Compliance:

ScoreLevelFeatures Enabled
Basic (SES)Simple Electronic SignatureDefault configuration
Enhanced (SES+)Enhanced Simple+ Identity verification
Advanced (AdES)Advanced Electronic Signature+ Digital ID + TSA + OTP

[!CAUTION] This documentation provides general information about electronic signature laws and is not legal advice. Laws vary by jurisdiction and change over time. Consult with a qualified attorney for specific legal requirements applicable to your situation.

WPsigner provides technical tools for compliance. You are responsible for:

  • Understanding applicable regulations
  • Configuring appropriate security settings
  • Implementing proper procedures
  • Training your staff
  • Maintaining documentation