NevTan Sign is a secure eSignature and document-approval platform that helps HR, legal, finance, and sales teams send, sign, and archive agreements with legally binding signatures and an audit-ready evidence trail.
If you operate in the European Union or handle data belonging to EU residents, GDPR compliance for eSignature processes is not optional — it is a legal obligation carrying fines up to €20 million or 4% of global annual turnover. This guide walks you through what GDPR requires from your eSignature tool, how to assess your current workflows, and the specific features to verify before you send another document. You will learn the difference between data controller and processor roles, what a Data Processing Addendum must contain, and how audit trails support your compliance evidence.
TL;DR — Key Takeaways
GDPR applies to any eSignature process handling EU personal data, regardless of where your company is based.
You need a Data Processing Addendum with your eSignature provider covering Article 28 requirements — NevTan Sign's DPA applies by reference as part of the Terms.
Audit trails, encryption in transit and at rest, and defined retention policies are mandatory technical controls.
Where personal data leaves the EEA, your provider must rely on a valid transfer mechanism such as Standard Contractual Clauses.
NevTan Sign provides the security controls and evidence trail needed to support your compliance program, with a published subprocessor list and trust center.
What You Need Before Starting
Before you evaluate any eSignature platform for GDPR compliance, map your current document workflows. Identify every type of agreement that contains personal data — employment contracts, customer agreements, NDAs, vendor forms, and onboarding packets. For each workflow, document what personal data is collected, why, and how long you retain it. This mapping forms the foundation of your Records of Processing Activities under Article 30.
Next, determine your role. If you decide the purpose and means of processing, you are the controller. Your eSignature provider acts as a processor on your behalf. This distinction matters because Article 28 requires controllers to use only processors that provide sufficient guarantees to meet GDPR requirements. Before you commit to any tool, request the provider's DPA, review their subprocessor list, and ask what security documentation they can share. NevTan Sign publishes all three: the Data Processing Addendum, the subprocessor list, and a security overview.
Apply the data minimisation principle (Article 5(1)(c)) to your document design. You do not need a signer's date of birth or national ID number to execute a standard commercial agreement. Review each template and remove unnecessary personal data fields. Then establish a retention schedule aligned to your legal obligations — employment contracts might be retained for the duration of employment plus a statutory period, while NDAs may have a shorter window. Document these periods in your Records of Processing Activities.
Step-by-Step Guide
Step 1: Conduct a Data Flow Audit for Every Signing Workflow
Create a complete inventory of every document type flowing through your eSignature process. For each one, list the personal data fields involved — names, email addresses, national ID numbers, financial details. Map where data originates, where it sits during signing, and where it goes after completion. Include documents sent to employees, customers, vendors, and partners.
Use a spreadsheet to track each workflow, the data categories involved, and the legal basis for processing under Article 6. Your basis might be contract performance, legal obligation, or legitimate interest — document it clearly for each workflow.
Pay particular attention to special category data under Article 9: health information, religious beliefs, trade union membership. An employment contract might reference sick leave records; a benefits enrolment form might reveal health conditions. Processing special category data requires an additional legal basis under Article 9(2), such as explicit consent or employment law obligations.
Note that NevTan Sign's DPA states special category data is not anticipated by default, and that the customer is responsible for ensuring such data is not processed through the Services without appropriate safeguards and legal basis. If your workflows genuinely involve Article 9 data, treat that as a design decision requiring its own assessment — not something to assume the platform handles for you.
💡 Pro Tip: Create a data flow diagram for your three highest-volume signing workflows first. Visualising the path from sender to signer to archive makes compliance gaps far easier to spot.
Step 2: Verify Your Provider's Processor Status and DPA
Under Article 28, your eSignature provider is a processor and you are the controller, meaning the provider can only process personal data on your documented instructions. Verify that the provider has a published DPA covering the subject matter and duration of processing, the nature and purpose, the types of personal data, and the categories of data subjects. It must also confirm that the processor acts only on your documented instructions and that authorised personnel are bound by confidentiality.
NevTan Sign's DPA forms part of the Terms and applies by reference — it does not require separate signature to take effect. Enterprise customers who need a countersigned copy for procurement or internal compliance can request one from the privacy team. Annex A of that DPA sets out the description of processing activities, including categories of data subjects and personal data, which maps directly onto what your Article 30 records need to contain.
The DPA must also address subprocessors. Under Article 28(2), a processor cannot engage another processor without prior specific or general written authorisation. NevTan Sign operates on general authorisation with a published subprocessor list, advance notice of material changes, and a 14-day window for customers to object on data protection grounds. Review that list for entities outside the EEA and confirm what transfer safeguards apply to each.
On security posture, ask what documentation the provider can share. NevTan Sign's DPA commits to providing security summaries, third-party audit reports where available, compliance attestations, and policy documentation on reasonable written request. Customer-initiated audits are limited to once per calendar year unless required by law or following a confirmed incident. If any provider refuses to discuss security documentation at all, treat that as a signal.
Step 3: Assess International Transfers
Chapter V restricts transfers of personal data outside the EEA unless specific conditions are met. You need to know where your data resides and which mechanism covers any transfer.
Where personal data moves from the EEA or UK to a country without an adequacy decision, your provider must implement appropriate safeguards. NevTan Sign's DPA identifies the mechanisms it may rely on: Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, binding corporate rules, or other approved mechanisms — incorporated by reference with the relevant module applying based on the nature of the transfer.
The EU maintains adequacy decisions for a number of jurisdictions, and the EU–US Data Privacy Framework provides a route for certified US recipients. Because adequacy decisions and transfer frameworks have been challenged and revised before — the Schrems II ruling invalidated Privacy Shield in 2020 — treat transfer mechanisms as something to re-verify periodically rather than settle once.
Remember that metadata is personal data too. Timestamps, IP addresses, and device information recorded in an audit trail all fall within scope and must be protected accordingly.
Step 4: Implement Technical and Organisational Measures
Article 32 requires controllers and processors to implement measures appropriate to the risk. For eSignature processes, that means several specific controls.
Encryption. Data should be encrypted in transit using modern transport protocols and encrypted at rest. NevTan Sign's security page confirms encryption at rest covers documents, audit records, user information, system logs, and backups — worth verifying with any provider, since some encrypt documents but not logs or backups.
Access controls. Only authorised personnel should reach signing workflows and completed documents. Look for role-based access control, least-privilege enforcement, and multi-factor authentication on administrative access. All three appear in NevTan Sign's published security controls.
Audit trails. Every action — upload, view, sign, download — should be logged with a timestamp and user identification, and the record should be resistant to alteration. This audit trail is your primary evidence under Article 5(2) if a supervisory authority investigates.
Breach response. Article 33 requires you to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. Your provider needs to alert you fast enough for that clock to be workable. NevTan Sign's DPA commits to notifying customers without undue delay and, where practicable, within 72 hours of becoming aware of a confirmed security incident, including the nature of the incident, categories and approximate volume of data affected, likely consequences, and remediation steps.
Training. Run regular security training for employees who handle signing workflows, covering phishing risk and secure document handling, and document those sessions as compliance evidence.
Step 5: Establish Retention and Deletion Policies
Article 5(1)(e) requires that personal data be kept no longer than necessary — the storage limitation principle. Define retention periods by document type and legal requirement. Employment contracts may need retention for the employment duration plus a statutory limitation period. Tax-related documents typically require longer. Commercial contracts often run several years past termination.
Under NevTan Sign's DPA, the customer controls retention periods through account settings and configuration; the platform retains data beyond those periods only where required by law, necessary for security, audit, or backup purposes, or needed to enforce contractual rights. That places the configuration responsibility firmly with you — an unconfigured retention policy is a compliance gap of your making, not the platform's.
On termination or on request, the DPA provides for export in a commercially reasonable format and/or deletion or anonymisation within a commercially reasonable timeframe, with certification of deletion available on request. Note the realistic caveat on backups: residual copies in backup systems are deleted in line with standard backup rotation rather than instantly. This is normal across the industry, but you should understand and document it rather than assume an erasure request purges every copy the moment it is made.
For Article 17 erasure requests, remember the right is not absolute — where you have a legal obligation to retain a document, you may refuse. Document that reasoning when you do.
Step 6: Document Your Compliance Evidence
GDPR compliance is ongoing, not a one-time exercise. Maintain and update your Records of Processing Activities under Article 30, covering purposes of processing, categories of data subjects and personal data, recipients, and third-country transfers. For each signing workflow, record the legal basis, retention period, and the technical and organisational measures in place. NevTan Sign's DPA Annex A gives you much of the processor-side detail in a form you can lift directly into your own records.
Maintain a breach register even if no breach has occurred. Conduct Data Protection Impact Assessments for high-risk processing under Article 35 — standard signing workflows often will not require one, but processing special category data or deploying new technology may.
Finally, review your provider periodically. Request current security documentation, watch for subprocessor changes, and re-check transfer mechanisms. Keep the whole set in a compliance file you could present to a supervisory authority.
How GDPR Applies to eSignature Technology
An eSignature platform processes personal data at multiple stages. When you upload a document, the platform records metadata — sender identity, timestamp, file details. When you add recipients, it stores names and email addresses. When a recipient signs, it records the timestamp, IP address, and device information. All of this is personal data under Article 4(1) because it relates to identifiable individuals.
NevTan Sign's DPA sets out the categories explicitly: identity data, contact data, authentication data, signature data and associated metadata, document contents as determined by the customer, audit trail data including timestamps and IP addresses, and technical data such as device identifiers and session tokens. That list is a useful starting point for your own data mapping, because it tells you what actually gets processed rather than what you assume does.
The signing process itself involves cryptographic operations. When a signer applies their signature, the platform creates a digital fingerprint of the document, which is stored alongside the audit trail and certificate of completion. If the document is altered afterwards, the fingerprint no longer matches and the tampering is detectable — the mechanism that makes an electronic signature evidentially useful, and the reason your audit trail is worth as much as the signature itself.
Across these layers — application database, document storage, log files — each must be encrypted, access-controlled, and covered by the DPA. The relevant point for compliance is that no single control satisfies Article 32 on its own. Encryption without access control, or access control without an audit trail, leaves a gap you would struggle to defend.
GDPR does not affect whether an electronic signature is valid. That question is governed by eIDAS Regulation (EU) No 910/2014, which confirms the legal effect of electronic signatures across the EU. GDPR governs how you process personal data during signing, not the enforceability of the signature.
Common Mistakes
Mistake 1: Assuming GDPR does not apply because your company is outside the EU. Article 3(2) extends the regulation to any organisation processing personal data of EU data subjects, regardless of where it is based. If you sign contracts with EU customers or employ EU residents, GDPR applies. Assess your data subjects properly rather than your headquarters.
Mistake 2: Treating the DPA as a formality. Not all DPAs are equivalent. Yours must include the Article 28 elements — subject matter, duration, nature and purpose, data types, data subject categories — plus subprocessor authorisation and the measures the processor will implement. Have legal counsel read it before you rely on it.
Mistake 3: Ignoring subprocessor arrangements. Your provider almost certainly uses subprocessors for hosting, email delivery, or identity verification. Review the published list, check each location, and confirm what safeguards cover transfers. Know your objection window and use it if a new subprocessor creates a genuine problem.
Mistake 4: Never configuring retention and deletion. Many organisations retain signed documents indefinitely simply because nobody set a policy. Indefinite retention is difficult to justify under storage limitation. Define periods by document category, configure them in the platform, and review annually.
Mistake 5: Overlooking the audit trail as evidence. The audit trail is not just a technical feature; it is your primary evidence under Article 5(2). Verify what your provider logs, whether entries can be altered, and whether logs can be exported for regulatory review. Request a sample audit trail during evaluation.
How to Choose
Apply these five criteria to every provider you evaluate.
DPA and contractual protections. Confirm the DPA meets Article 28 requirements, covering processing instructions, confidentiality, security measures, subprocessor authorisation, and data subject rights assistance. Read it before you sign up, not after.
Security controls and documentation. Confirm encryption in transit and at rest, role-based access control, MFA on admin access, and vulnerability management. Ask what audit reports or attestations the provider can supply and under what conditions.
Transfer mechanisms. Establish where data is processed and which safeguards apply — SCCs, the UK Addendum, or another approved route — including for every subprocessor.
Audit trail capabilities. Verify that logs capture timestamps, user identification, and IP addresses, that they resist modification, and that you can export them for regulatory review.
Retention and deletion features. Confirm you can configure retention by document category, delete on request, and export everything if you switch providers. Ask specifically how backups are handled.
Document your findings and compare providers side by side. Our general guide on how to choose an eSignature tool covers the commercial criteria that sit alongside these compliance ones.
Frequently Asked Questions
Is an eSignature legally binding under GDPR?
Yes. GDPR does not affect the legal validity of electronic signatures. The eIDAS Regulation (EU) No 910/2014 governs electronic signatures in the EU and confirms their legal effect; GDPR applies to the processing of personal data during signing, not to the signature's validity. Our breakdown of simple, advanced, and qualified signature types explains which level suits which document.
What is a Data Processing Addendum and why do I need one?
A DPA is the contract between you (controller) and your provider (processor) governing how personal data is processed. Article 28 requires one with any processor handling personal data on your behalf. It must specify processing instructions, confidentiality obligations, security measures, subprocessor arrangements, and data subject rights assistance.
Does NevTan Sign provide a DPA?
Yes. The NevTan Sign DPA forms part of the Terms of Service and applies by reference — no separate signature is needed for it to take effect. It is designed to support compliance with GDPR, UK GDPR, and equivalent global privacy legislation, and includes annexes describing processing activities and the security controls summary. Enterprise customers who need a countersigned copy for procurement can request one from the privacy team named on that page.
Where can I see NevTan Sign's subprocessors?
The current list is published at /subprocessors. Customers receive reasonable advance notice of material changes and may object in writing within 14 days on data protection grounds, after which both parties work in good faith to resolve the concern.
How does NevTan Sign handle security incidents?
The DPA commits to notifying customers without undue delay and, where practicable, within 72 hours of becoming aware of a confirmed security incident affecting customer personal data. Notification covers the nature of the incident, categories of data affected, approximate numbers of data subjects and records, likely consequences, and measures taken. That supports — but does not replace — your own Article 33 obligation to notify your supervisory authority.
How long should I retain signed documents under GDPR?
There is no single retention period. You determine it by document type and legal requirement: employment contracts for the employment duration plus statutory periods, tax documents for longer, commercial contracts typically for several years after termination. Under the NevTan Sign DPA, you control retention through your account settings, so configuring it is your responsibility as controller.
What should I do if a data subject requests deletion of a signed document?
Article 17 gives data subjects a right to erasure, but it is not absolute — where a legal obligation requires you to retain the document, you may refuse and should record why. Where no such obligation applies, delete the document and associated personal data. Note that residual copies in backups are removed in line with standard backup rotation rather than instantly, which is standard practice and should be documented in your own procedures.
What are the penalties for GDPR non-compliance?
Penalties reach up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier violations can result in fines up to €10 million or 2% of turnover. Beyond fines, non-compliance damages reputation and erodes customer trust.
Where can I review NevTan Sign's wider compliance posture?
Start with the Trust Center, then the security overview, privacy policy, cookie policy, AI and data usage policy, acceptable use policy, and terms and conditions.
Conclusion and Next Steps
GDPR compliance for eSignature requires a systematic approach: map your data flows, verify your provider's processor status and DPA, assess transfer mechanisms, implement technical controls, configure retention, and document your evidence. This is an ongoing commitment rather than a one-time task.
Start by auditing your current signing workflows. Then evaluate your provider against the criteria above. If your current tool cannot produce a DPA, a subprocessor list, or security documentation on request, that is a gap worth closing before a supervisory authority finds it for you.
NevTan Sign publishes its DPA, subprocessor list, and security controls, and provides the audit-ready evidence trail your accountability obligations depend on — alongside multi-party routing, reusable templates, and unlimited envelopes with no per-signature fees.
Start free and evaluate the platform against your own compliance checklist, review pricing, log in if you already have an account, or contact us to discuss your requirements with the team. For account or configuration questions, support can help.
Note: This guide is general information about GDPR requirements, not legal advice. Consult qualified counsel about your specific processing activities and obligations.
Related Reading & Resources
Further reading: How secure are electronic signatures? · Automate the contract lifecycle with CLM templates and approval flows · Remote online notarization explained · What's new in eSignature · Why every growing business needs a digital agreement strategy · eSignatures in HR onboarding · Best eSignature software for law firms · All articles · About NevTan · Integrations
Templates containing personal data — review these first:
HR & contractors: Employment Offer Letter · Independent Contractor · Consulting Agreement · Internship Agreement
Legal & corporate: Mutual NDA · One-Way NDA · Board Resolution · Shareholder Agreement · Partnership Agreement
Sales & vendors: Sales Contract · Service Agreement · MSA · SOW · Vendor Agreement · Franchise Agreement
Finance & property: Purchase Order · Invoice Acknowledgement · Loan Agreement · Residential Lease · Commercial Lease

