Sign This, Dammit!

Live Free, Sign Hard

ad slot · header · set NEXT_PUBLIC_ADSENSE_CLIENT

2026-03-08

Are electronic signatures legal in Norway and the EU?

Yes: electronic signatures are legal in Norway and the EU. eIDAS applies through the EEA, and Norwegian contract law generally does not demand a special form. What people mix up is validity versus identity assurance — and the yellow triangle in Adobe, which is about trust lists, not the Contracts Act.

What does the law actually say — not the datasheet?

Norwegian contract law is old and mostly form-free. You can agree orally, by SMS, in a thread that started with 'ok, go'. Writing is useful because memory is bad. It is rarely a condition for the contract existing. Exceptions live in specific statutes, not in an American vendor's landing page.

eIDAS (Regulation 910/2014) applies in Norway via the EEA. It says three useful things for ordinary people: a signature cannot be dismissed merely because it is electronic; there are levels (SES, AES, QES); and QES must have the same legal effect as handwriting where that is required. It does not say you need QES to rent a flat in Grünerløkka.

When a salesperson says 'legally binding electronic signature', they often mean 'we keep a log'. That can be useful. It is not a court stamp. Binding happens if the usual conditions of agreement are met: offer, acceptance, parties who roughly knew what they were doing.

Why does everyone think BankID is the only thing that counts?

Because BankID is everywhere. Tax, banks, Altinn, health portals. The brain generalises: whatever opens the public sector must open everything. That is a reasonable mistake. Government picked high assurance because they must hit the right person in a register. A deal between two companies to deliver a report in May has a different threat model.

BankID used as a qualified signature (where a provider offers that) is QES territory: strong identity, regulated issuer. Ordinary 'I drew in the browser after an email link' is SES. Both can bind. They answer different questions. QES answers 'was it really you, with high confidence'. SES answers 'did someone say yes to this text, and can we show it'.

If you demand BankID from an international counterparty with no Norwegian eID, you just made the deal impossible. Cross-border validity is eIDAS and contract law, not a banking app.

What about the yellow triangle in Acrobat?

Adobe keeps a list of CAs it trusts. Public and commercial qualified issuers get on that list after a lot of paper and money. A small Oslo shop that signs PDFs with its own CA will not. Acrobat then says the signature is unknown, or that identity cannot be verified against their list.

That is an Adobe product choice, not a statute. You can still check that the bytes were not changed, against the issuer's certificate and a hash you stored. The PAdES standard is about how the signature sits in the PDF. Trust in who owns the key is a separate layer.

Tell the finance lead this before you send the file, not after they panic. 'Not QES, not on the Adobe Trust List, cryptographic mark against our CA' is an honest sentence. 'Green tick in Acrobat therefore valid in Norway' is a dishonest one.

When is SES enough, and when should you step up?

SES is enough when the parties know each other, the sum is survivable, and an email log would convince a grown-up that yes was said. Freelance, subcontracting, NDAs, board minutes in a small company, a deal with the agency down the street.

Step up when the other side is a stranger, the sum hurts, or a regulation points at qualified signature or special writing. Then BankID/QES or a regulated AES product is worth the money. You are buying identity assurance, not 'more contract'.

Cryptographic PAdES without QES sits in the middle for the file, not for the person: you get a tamper warning, you do not get the national registry. That is an honest place to stand if you say it out loud.

What should you keep if there is a fight?

The PDF itself, in the version that was signed. An evidence pack or certificate of completion with times, emails, IP if you have it, and the order of events. The email thread that points at the link. Not three scanned variants named final_v7.

If the PDF has PAdES, also keep the CA fingerprint and a hash. Then an expert can check integrity without trusting that you 'remember it was that file'. If it is only SES in a cloud, you depend on the vendor still existing and handing over the log.

None of that replaces a clear document. A fight about a mushy sentence in clause 12 is not solved by a certificate. The signature proves yes. It does not write the text for you.

Is Norway different from the EU here?

Not in the main rule. eIDAS is shared. Norway has BankID as the daily eID, so the culture is more BankID-heavy than countries where people sign with an SMS code and a shrug. Culture is not the law.

Some Norwegian statutes and regulations point at electronic ID at certain levels for public administration. That does not automatically spill into two private parties agreeing a delivery. Public procedure and private law are different tracks.

If you sell to a municipality, read the procurement and their portal. If you sell to a company in Tøyen, you are actually standing in the eIDAS default plus the Contracts Act — plus whatever you wrote in the contract about how signing should happen.

FAQ

Can I form a binding contract without BankID?

Yes. BankID is common and convenient, not a general condition of validity. An email where both sides say yes can bind. A signing tool gives you a better trail, not a new statute.

What is the difference between valid and 'approved by Adobe'?

Validity is law: was a contract formed. The Adobe panel is software policy: does Acrobat trust the certificate. A yellow triangle there is not a judgment from the district court.

Do I lose in court if it is 'only' SES?

You lose if you cannot show the other side actually accepted the text. QES will not save you either if clause 12 is mush. Evidence is logs, email, witnesses, course of dealing — and maybe crypto inside the PDF.

Valid and qualified are different sentences. If you need the first, with a trail in the file and without pretending to be BankID, that is an honest job — not a stamp from the Commission.

If you just need a PDF signed without a subscription, that’s what STD is built for.

Norsk