UK GDPR Compliance
UK GDPR and Electronic Signatures
Electronic signatures process personal data. Here's what UK businesses need to know about GDPR compliance when signing documents digitally.
Why Electronic Signatures Are a UK GDPR Matter
Every time a document is sent for electronic signature, personal data is processed. This includes the signer's name, email address, IP address, and timestamp — all of which constitute personal data under UK GDPR. As a data controller, the business sending the document must ensure this data is handled lawfully, transparently, and securely. The platform you use becomes a data processor acting on your behalf, and you must have a Data Processing Agreement (DPA) in place with them.
Legal Basis for Processing Signature Data
Under UK GDPR, you must have a valid legal basis for processing the personal data involved in e-signature workflows. The most applicable bases are:
- Contract performance (Article 6(1)(b)): Processing is necessary to enter into or perform a contract with the signer — the most common basis for employment contracts, service agreements, and client engagements.
- Legal obligation (Article 6(1)(c)): Where the signature is required to comply with a legal requirement, such as a workplace safety declaration or HMRC authorisation.
- Legitimate interests (Article 6(1)(f)): May apply in some commercial contexts, but requires a Legitimate Interests Assessment (LIA).
Data Processing Agreements with Your E-Signature Provider
Because your e-signature platform processes personal data on your behalf, UK GDPR Article 28 requires you to have a written Data Processing Agreement in place. This DPA must specify:
- The subject matter, duration, nature, and purpose of the processing
- The type of personal data and categories of data subjects
- The obligations and rights of the controller
- Sub-processor arrangements (e.g., the cloud infrastructure provider)
- Data deletion or return procedures after the contract ends
International Data Transfers and US-Based Providers
Many e-signature platforms — including DocuSign, Adobe Sign, SignNow, and Dropbox Sign — store data on US-based infrastructure. Under UK GDPR, transferring personal data to the US requires either an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Agreement). While these safeguards are available, they add compliance documentation and ongoing monitoring obligations. UK businesses choosing a UK-hosted e-signature platform like VedaSign avoid international transfer requirements entirely.
VedaSign and UK GDPR Compliance
VedaSign is incorporated in the UK (VedaSign Ltd, Company No. 17288206) and stores all data exclusively on UK servers. There is no international data transfer. VedaSign provides a Data Processing Agreement (DPA) as standard, available at vedasign.uk/dpa.
- UK-only data hosting — no international transfer documentation required
- Data Processing Agreement provided as standard
- Sub-processors documented and available on request
- Audit trails stored securely with access controls
- Data deletion on account cancellation in accordance with our DPA
£15/month
UK-hosted · GDPR compliant · Unlimited users
No per-user fees. No document caps. No hidden charges.
Start Your 14-Day Free TrialFrequently Asked Questions
Does using an e-signature platform require a Data Processing Agreement?
Yes. Under UK GDPR Article 28, you must have a written Data Processing Agreement with any service provider that processes personal data on your behalf, including e-signature platforms. VedaSign provides a DPA as standard.
Why does it matter whether my e-signature platform stores data in the UK?
Under UK GDPR, transferring personal data outside the UK requires either an adequacy decision or appropriate safeguards. Using a UK-hosted provider like VedaSign eliminates this requirement and simplifies your compliance documentation.
What personal data does an e-signature platform process?
Typically: signer names, email addresses, IP addresses, timestamps, and the content of any signed document. This all constitutes personal data under UK GDPR and must be processed lawfully.
How long should I keep signed documents under UK GDPR?
The Limitation Act 1980 generally means contracts should be retained for 6 years after they end. Employment contracts are typically kept for 6 years after the employment ends.
Is VedaSign UK GDPR compliant?
Yes. VedaSign is a UK company with UK-only data hosting, provides a standard Data Processing Agreement, documents sub-processors, and has designed its platform with UK GDPR requirements in mind.
