eSign.AIeSign.AI

Glossary

eIDAS Trust Services and Encryption: The Missing Confidentiality Layer

EUTL, qualified signatures, and seals establish trust and integrity — but none of them encrypt your document. Where encryption fits in the eIDAS trust ecosystem.

eSign.AI Digital Trust Research Team8 min read

The layer most compliance guides skip

The EU eIDAS Regulation built a world-class system for trust: the EU Trusted List (EUTL), qualified trust service providers (QTSPs), qualified signatures, and qualified seals. Together they answer two questions: "is this signature valid and who is behind it?" What they do not answer is "can anyone else read this document?" Confidentiality is the missing layer — and it is provided not by trust services but by encryption, typically envelope encryption. This guide maps where encryption fits in the eIDAS trust ecosystem, and why compliant workflows need both.

Trust in providers

EUTL provides

Identity + integrity

QES provides

Origin + integrity

Seal provides

Confidentiality

Encryption provides

Envelope encryption

Missing piece

Four layers of a compliant eIDAS workflow

A document that must be both legally valid and protected against prying eyes stacks four distinct mechanisms — and only one of them encrypts.

01

The EUTL is Europe's machine-readable register of supervised trust service providers. Validating a signature means checking its certificate chain against a listed QTSP — it tells you the signer's identity can be trusted, not that the content is hidden.

02

A qualified electronic signature (QES) — the highest eIDAS level — binds the signer's identity to the document and detects tampering. It proves who signed and that nothing changed after signing.

03

A qualified seal (QESeal) does for organizations what QES does for individuals: it proves the document came from a specific legal entity and is unaltered. Neither signatures nor seals encrypt anything.

04

Envelope encryption (or TLS in transit, field-level controls in databases) is what actually keeps content confidential. It is orthogonal to eIDAS trust — a document can carry a perfect QES and still be readable by anyone who gets a copy.

The trust stack, mapped

Where each mechanism sits in the stack — and what question it answers.

Why confidentiality keeps getting forgotten

Three habits push encryption out of eIDAS conversations — each is understandable, and each leaves a gap.

The regulation never mentions it

eIDAS is a regulation about signatures and trust services, so compliance checklists center on QES, seals, and the EUTL. Encryption never appears in the regulation's signature provisions — so it never makes the checklist.

"Sealed" feels like encrypted

In e-signature products, signing locks the document against further edits, which feels like protection. But edit-locking is workflow state — anyone who receives a copy can still read the content.

Confidentiality lives in GDPR

GDPR is where confidentiality actually lives in EU law. Teams that treat eIDAS and GDPR as separate projects often miss that a signed contract full of personal data needs both regimes at once — one for validity, one for secrecy.

Common questions

No. A QES proves the signer's identity and the document's integrity. It does not encrypt — a document with a perfect qualified signature is still readable by anyone with a copy. Confidentiality requires encryption (envelope encryption at rest, TLS in transit).

How eSign.AI covers all four layers

eSign.AI supports eIDAS-aligned qualified signatures and seals with certificate-chain evidence, and pairs them with TLS 1.2+, envelope encryption at rest, and managed key options — so a document is not only valid under eIDAS but actually confidential in practice.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.