Signatures and UK GDPR: handling signature data
In short A signature is personal data, and checking it with software can make it biometric data. Know your lawful basis, assess the risks before you start, keep it only as long as you need, and use a processor with a proper data processing agreement.
General information, not legal advice
This guide gives general information about UK GDPR as it applies to signatures. It is not legal advice. Take advice from a qualified lawyer or your data protection officer about your own case.
The Information Commissioner’s Office (ICO) is the UK regulator. Its guidance on biometric data and impact assessments is the place to check the detail.
Is a signature personal data?
Yes. A signature relates to an identifiable person, so it is personal data. The documents it sits on usually hold more personal data too: names, addresses and account numbers.
A signature can also be biometric data. That covers personal data from specific technical processing of a person’s physical or behavioural characteristics, which allows or confirms who they are. Comparing a signature by software to confirm the signer can fall within it.
Lawful basis, and special category data
Every use of personal data needs a lawful basis under Article 6, such as a contract, a legal obligation or legitimate interests.
Biometric data used to identify a person is special category data. If your processing counts as that, you also need a condition under Article 9, such as explicit consent or a substantial public interest condition. Take advice on which applies.
Write down your lawful basis, and your Article 9 condition if you need one, before you start. Under the accountability principle you must be able to show how you reached them.
Assess the risks first
A data protection impact assessment (DPIA) is required for processing likely to result in a high risk to people. Biometric processing, and processing at a large scale, often meet that test.
A DPIA sets out what you process, why, the risks to people and how you reduce them. Do it before you start, and keep it up to date.
Controllers and processors
When you send signatures to a verification service, you are usually the controller: you decide why and how the data is used. The service is your processor and acts on your instructions.
Article 28 requires a written contract between you, often called a data processing agreement. Unforged’s data processing addendum is part of its terms and lists its subprocessors.
Keep only what you need, for as long as you need it
- Send only the documents and references a check needs.
- Set a retention period that matches your purpose, such as your claims or audit window, and no longer.
- Delete references when a customer leaves.
- Record why you chose each period.
With Unforged Nib you choose the period. Uploads and results are kept for your history-retention period: 90 days by default, or anything from 30 minutes to 10 years, or indefinitely.
Tell people, and respect their rights
Your privacy notice should say that you check signatures, why, and who helps you do it. People can ask to see their data, correct it or have it erased in many cases. Your processor should help you answer.
Where a decision has legal or similarly significant effects, UK GDPR limits decisions made solely by automated means. Keeping a person in the loop for unclear and failed cases helps. With Unforged Nib, FAILED always goes to a person.
Where the data goes
Check where your processor stores data and who else handles it. Unforged stores customer data in London (AWS eu-west-2). Where a subprocessor handles it outside the UK or EU, safeguards apply. Customer data is never used to train anything.
For more, read the privacy policy and the security page.