Skip to main content

PandaDoc eSignature Compliance

PandaDoc eSignatures are compliant with the major electronic signature frameworks used across the United States, European Union, and other key jurisdictions worldwide — including ESIGN, UETA, eIDAS (SES, AES, and QES), HIPAA, FERPA, and FDA 21 CFR Part 11.

PandaDoc's compliance posture goes beyond basic eSignature laws. It is backed by SOC 2 Type II certification, FIPS 186-5 cryptographic standards, and certified participation in the EU-U.S. Data Privacy Framework — making it suitable for regulated industries including healthcare, life sciences, financial services, and education.

PandaDoc eSignature Compliance Standards Summary

Compliance Standard

Abbreviation

Country / Region

Supported

Electronic Signatures in Global and National Commerce Act

United States

✅ Yes

Uniform Electronic Transactions Act

United States

✅ Yes

Electronic Signatures and Records Act

ESRA

United States (NY State)

✅ Yes

eIDAS Simple Electronic Signature

SES

EU / UK

✅ Yes

eIDAS Advanced Electronic Signature

EU / UK

✅ Yes

eIDAS Qualified Electronic Signature

EU / UK

✅ Yes

Health Insurance Portability and Accountability Act

United States

✅ Yes

Family Educational Rights and Privacy Act

United States

✅ Yes

FDA Electronic Records and Signatures

United States

✅ Yes (dedicated workspace required)

FIPS 186-5 Digital Signature Standard

FIPS 186-5 DSS

United States

✅ Yes

General Data Protection Regulation

EU

✅ Yes

California Consumer Privacy Act

United States (CA)

✅ Yes

EU-U.S. Data Privacy Framework

DPF

US / EU / UK / Switzerland

✅ Yes

Payment Card Industry Data Security Standard

PCI-DSS

Global

✅ Yes (via compliant processors)


PandaDoc Signature US Compliance: ESIGN, UETA, and ESRA

ESIGN, UETA, and ESRA share four core requirements for a valid electronic signature, all of which PandaDoc is designed to satisfy:

  • Intent to sign — PandaDoc displays explicit language at the point of signature, indicating the signer intends to sign the document. Signers must actively click to complete the signing action.

  • Consent to do business electronically — Consent is captured during the signing flow. PandaDoc's signing screen includes disclosure language confirming that the signer agrees to transact electronically.

  • Association of the signature with the record — Each completed PandaDoc document includes a Certificate of Completion that identifies the signers, the document signed, and a timestamp for each signing event. This record is embedded in the completed PDF.

  • Record retention — Signed documents are retained within PandaDoc for the duration of the customer relationship. Documents can be downloaded and exported at any time, including upon account termination.


PandaDoc Signature EU Compliance: eIDAS (SES, AES, and QES)

The eIDAS Regulation 2014/910 defines three tiers of electronic signatures for use across the EU and UK. PandaDoc supports all three.

Simple Electronic Signature (SES)

PandaDoc's standard eSignature flow meets the SES definition — a data item attached to or logically associated with a document and used by the signatory to sign. SES is suitable for most everyday business documents.

Advanced Electronic Signature (AES)

An AES must meet four additional criteria:

  1. Uniquely linked to the signer

  2. Capable of identifying the signer

  3. Created using data under the signer's sole control

  4. Linked to the signed data so that any subsequent change is detectable

PandaDoc supports AES-compliant signatures when recipient identity verification is enabled on a document, combined with digital signature certificates backed by FIPS-validated AWS CloudHSM cryptographic services.

Qualified Electronic Signature (QES)

PandaDoc supports QES by integrating with trusted identity providers (IdPs), which handle the strict identity verification required by law.

QES is the highest standard under eIDAS and carries the same legal weight as a handwritten signature across all EU member states. PandaDoc provides QES-level signatures through integration with qualified Trust Service Providers (TSPs). QES requires a Qualified Signature Creation Device (QSCD) and identity proofing of the signer.


Digital Signature Certificates

Every completed PandaDoc document includes a Certificate of Completion that provides a verifiable audit trail of the signing process. This certificate captures:

  • Document reference number

  • Signers' names and verified email addresses

  • IP addresses and locations

  • Timestamps for when the document was sent, viewed, and completed

PandaDoc uses FIPS-validated AWS CloudHSM cryptographic services for document signing, operating in FIPS 140-3 certified mode and complying with the FIPS 186-5 Digital Signature Standard (DSS). These certificates are embedded in the signed PDF's metadata and confirm that the document has not been altered since signing.


Identity Verification

Configure these methods per document or enforce them at the workspace level for regulated workflows:

  • Passcode verification — Recipient must enter a passcode defined by the sender

  • SMS verification — A one-time code is sent to the recipient's mobile number

  • Knowledge-Based Authentication (KBA) — Recipients answer questions drawn from identity data sources

  • ID Check — Recipients upload and verify a government-issued photo ID


Healthcare: HIPAA Compliance

PandaDoc is fully HIPAA-compliant and supports the secure transmission and storage of electronic Protected Health Information (ePHI). PandaDoc's HIPAA compliance covers:

  • The HIPAA Privacy Rule

  • Administrative, Physical, and Technical Safeguards under the Security Rule

Execute a Business Associate Agreement (BAA) with PandaDoc before using the platform for any ePHI workflows. Contact your account team to request a BAA.


Life Sciences: FDA 21 CFR Part 11

PandaDoc offers dedicated 21 CFR Part 11–compliant workspaces for life sciences and other FDA-regulated organizations. This workspace configuration includes:

  • Enhanced signer verification methods

  • Secure, tamper-evident audit trails

  • Strict access controls and user authentication

Enable 21 CFR Part 11 compliance at the workspace level. Contact your account team to configure a compliant workspace.


Data Privacy and Security Certifications

PandaDoc's eSignature product is in scope for the following security certifications and audits:

Certification / Standard

Details

SOC 2 Type II

Annual SSAE 18 audit; report available upon request

GDPR

Lawful processing, data minimization, rights management; certified DPA available

CCPA

Compliant as of January 1, 2020; updated for CPRA as of March 29, 2023

EU-U.S. Data Privacy Framework

Certified participant; covers UK and Swiss extensions

PCI-DSS

Payments processed via PCI-DSS compliant third-party processors

Data Residency

Customer data stored in US or EU; customer's choice

PandaDoc also publishes a list of approved third-party subprocessors, all of which are contractually required to meet PandaDoc's security and data processing standards.


API and Embedded Signing Compliance

The legal enforceability of PandaDoc's API-based and embedded signing implementations depends on your configuration. PandaDoc's best practices and guidance are primarily based on US law, but the platform can be configured to comply in other international jurisdictions.

Work with your legal team to ensure an enforceable implementation when using:

  • PandaDoc Embedded Signing

  • PandaDoc eSignature API


Note: PandaDoc is not a law firm, and this article does not constitute or contain legal advice. To evaluate the accuracy, sufficiency, or reliability of the ideas and guidance reflected here, or their applicability to your business, consult a licensed attorney.

Did this answer your question?