AMENAZAS ESTRATEGIAS (DA) ESTRATEGIAS (FA) 1 Adulteración de licores
7.3 ANALISIS DEL IMPACTO DE LOS LICORES FORANEOS SOBRE EL MERCADO DE LOS PRODUCTOS DE LA ILB EN EL DEPARTAMENTO
The Digital Agenda has unambiguously announced a revision of the eSignature Directive, which will probably strive to fix at a minimum the shortcomings summarized elsewhere in this report, together with a possible Decision to ensure mutual recognition of certain eIDs between Member States. This would undoubtedly be a good step forward for the EU. None the less, a broader approach seems equally viable, building on the observation that e- authentication systems (to use the terminology of the Digital Agenda) are similar in most respects, but differ in small important details.
This can already be witnessed in the terminology as discussed above: the definition of an electronic signature as presented by the Directive (“data in electronic form which are attached to or logically associated with other electronic data and which serve as a method of authentication”) is broad enough to potentially cover eSignatures (in the equivalent-to-hand- written sense), eID and time stamping, among many others. It is worth considering whether a similar policy framework is also possible, and even desirable, for these related services. As a starting point, it is possible to consider prior experiences across the Member States. The need for a legal framework for ancillary services (time stamping, company seals, electronic registered e-mail, long term archiving) has been known for some time, and some Member States have been active in this field. To name but a few examples:
• Austria, as one of the leading EU Member States in this area, has implemented legislation regulating not only eSignatures, but also electronic identification, through the 2004 eGovernment Act.48
• Belgium adopted a generic legal framework for certain trusted services in 2007,49
including electronic registered mail, time stamping and electronic archiving. Despite a recent update for the rules on electronic registered mail in 2010 (integrated into the general eSignatures Act), executive rules were never fixed, and the law remains largely inoperative at present. However, new legislation in this area is planned for the near future.
48 E-Government-Gesetz.
49 Wet van 15 mei 2007 tot vaststelling van een juridisch kader voor sommige verleners van
vertrouwensdiensten/ Loi du 15 mai 2007 fixant un cadre juridique pour certains prestataires de services de confiance.
• The Czech Republic has implemented rules for time stamping in its eSignatures Act of 2000.50 Interestingly, the law uses the same logic and terminology (‘qualified time
stamp’) that is also in vogue for eSignatures.
• Estonia, as another technology leader in the EU, has a legal framework51 that
supports (and indeed requires) time stamping, digital stamps (advanced eSignatures created by legal entities), and official e-mails.
• Similarly, Finland has adopted an Act on strong electronic identification and electronic signatures.52
• Germany likewise introduced the notion of qualified time stamping in its eSignatures Act.53
• Italian law contains rules on electronic registered mail.54
• The Slovakian eSignatures Act contains specific rules for time stamping.55
• The Slovenian eSignatures Act recognizes the concept of a time stamp as being comparable to advanced eSignatures, with the same rules applying
by changing
those things which need to be changed
;56• Finally, the Spanish Act on Electronic Citizen Access to Public Services57 recognizes
eSignatures, e-seals (company signatures), and time stamping.
This listing is neither fully up to date nor exhaustive. Its purpose is merely to illustrate that a significant and increasing number of Member States have recognized the important role of e-authentication systems other than mere eSignatures, and that they have provided a legal
50 Zákon č. 227/2000 Sb., o elektronickém podpisu a o změně některých dalších zákonů (zákon o
elektronickém podpisu).
51
Digitaalallkirja seadus, RT I 2000, 26, 150.
52 Laki vahvasta sähköisestä tunnistamisesta ja sähköisistä allekirjoituksista, 7.8.2009/617.
53 Gesetz über Rahmenbedingungen für elektronische Signaturen (Signaturgesetz - SigG) vom 16.5.2001
(BGBl. I S. 876).
54 Through the Codice dell’Amministrazione Digitale (the current version is Decreto Legislativo 30
dicembre 2010, n. 235); Roberta Falciai and Laura Liberati, ‘The Italian certified e-mail system’,
Digital
Evidence and Electronic Signature Law Review, 3 (2006) 50 – 54.
55 Zákon č.215/2002 Z.z. o elektronickom podpise a o zmene a doplnení niektorých zákonov –The
Slovakian Act (‘as amended’ or ‘v znení neskorších predpisov’) was consolidated in 2009 (§9 of this Act
still explicitly refers to time stamping (Časová pečiatka – time stamping)), see
http://www.zbierka.sk/zz/predpisy/default.aspx?PredpisID=208862&FileName=zz2009-00076- 0208862&Rocnik=2009.
56
Zakon o elektronskem poslovanju in elektronskem podpisu.
57
framework for such services. When doing so, these laws are often integrated or at least closely aligned with general eSignature rules.
This is important for two reasons. First, it suggests that the principles and challenges for various e-authentication systems are similar, and that it might be possible to address them in unison. Second, it also shows a potential internal market barrier. If time stamping service provider A can guarantee the legal value of its services in one country (for instance, because it is considered a qualified time stamping service in that country) but not in another country (for instance, because that country has no rules, or worse yet, different ones), then that creates a market barrier. This is a challenge for the EU to address, as it was an almost identical observation that lead to the adoption of the eSignatures Directive.58
Indeed, if we look at the conceptual needs behind a comprehensive IAS policy as listed above, we already commented that all of these were already addressed (even if imperfectly) by the eSignatures Directive:
• An unambiguous understanding of IAS services and ancillary services
• The policy goals that an IAS approach should cover, including such aspects as the enabling of the internal market, technological neutrality and legal reliability.
• The legal translation of these policy goals and requirements, stipulating the goal of the regulatory text, definitions of basic concepts, provisions on general obligations for trust service providers, data protection, liability, internal market rules, legal effect of services, any supervision/accreditation mechanisms, etc.
• The trust framework needed to support a comprehensive IAS approach.
• The technical framework required to enable the comprehensive IAS approach, including standardisation needs.
At least theoretically, this suggests that it would be possible to apply the same approach to a comprehensive IAS framework.
58 For example, see the table of diverging national legislations on p. 4-5 of the 1998 Proposal for a
European Parliament and Council Directive on a common framework for electronic signatures, at http://ec.europa.eu/information_society/policy/esignature/docs/com1998_0297en.pdf. The table is strikingly similar to the list above.