PandaDoc eSignatures are compliant with the major electronic signature frameworks used across the United States, European Union, and other key jurisdictions worldwide — including ESIGN, UETA, eIDAS (SES, AES, and QES), HIPAA, FERPA, and FDA 21 CFR Part 11.
PandaDoc's compliance posture goes beyond basic eSignature laws. It is backed by SOC 2 Type II certification, FIPS 186-5 cryptographic standards, and certified participation in the EU-U.S. Data Privacy Framework — making it suitable for regulated industries including healthcare, life sciences, financial services, and education.
PandaDoc eSignature Compliance Standards Summary
Compliance Standard | Abbreviation | Country / Region | Supported |
Electronic Signatures in Global and National Commerce Act | United States | ✅ Yes | |
Uniform Electronic Transactions Act | United States | ✅ Yes | |
Electronic Signatures and Records Act | ESRA | United States (NY State) | ✅ Yes |
eIDAS Simple Electronic Signature | SES | EU / UK | ✅ Yes |
eIDAS Advanced Electronic Signature | EU / UK | ✅ Yes | |
eIDAS Qualified Electronic Signature | EU / UK | ✅ Yes | |
Health Insurance Portability and Accountability Act | United States | ✅ Yes | |
Family Educational Rights and Privacy Act | United States | ✅ Yes | |
FDA Electronic Records and Signatures | United States | ✅ Yes (dedicated workspace required) | |
FIPS 186-5 Digital Signature Standard | FIPS 186-5 DSS | United States | ✅ Yes |
General Data Protection Regulation | EU | ✅ Yes | |
California Consumer Privacy Act | United States (CA) | ✅ Yes | |
EU-U.S. Data Privacy Framework | DPF | US / EU / UK / Switzerland | ✅ Yes |
Payment Card Industry Data Security Standard | PCI-DSS | Global | ✅ Yes (via compliant processors) |
PandaDoc Signature US Compliance: ESIGN, UETA, and ESRA
ESIGN, UETA, and ESRA share four core requirements for a valid electronic signature, all of which PandaDoc is designed to satisfy:
Intent to sign — PandaDoc displays explicit language at the point of signature, indicating the signer intends to sign the document. Signers must actively click to complete the signing action.
Consent to do business electronically — Consent is captured during the signing flow. PandaDoc's signing screen includes disclosure language confirming that the signer agrees to transact electronically.
Association of the signature with the record — Each completed PandaDoc document includes a Certificate of Completion that identifies the signers, the document signed, and a timestamp for each signing event. This record is embedded in the completed PDF.
Record retention — Signed documents are retained within PandaDoc for the duration of the customer relationship. Documents can be downloaded and exported at any time, including upon account termination.
PandaDoc Signature EU Compliance: eIDAS (SES, AES, and QES)
The eIDAS Regulation 2014/910 defines three tiers of electronic signatures for use across the EU and UK. PandaDoc supports all three.
Simple Electronic Signature (SES)
PandaDoc's standard eSignature flow meets the SES definition — a data item attached to or logically associated with a document and used by the signatory to sign. SES is suitable for most everyday business documents.
Advanced Electronic Signature (AES)
An AES must meet four additional criteria:
Uniquely linked to the signer
Capable of identifying the signer
Created using data under the signer's sole control
Linked to the signed data so that any subsequent change is detectable
PandaDoc supports AES-compliant signatures when recipient identity verification is enabled on a document, combined with digital signature certificates backed by FIPS-validated AWS CloudHSM cryptographic services.
Qualified Electronic Signature (QES)
PandaDoc supports QES by integrating with trusted identity providers (IdPs), which handle the strict identity verification required by law.
QES is the highest standard under eIDAS and carries the same legal weight as a handwritten signature across all EU member states. PandaDoc provides QES-level signatures through integration with qualified Trust Service Providers (TSPs). QES requires a Qualified Signature Creation Device (QSCD) and identity proofing of the signer.
Digital Signature Certificates
Every completed PandaDoc document includes a Certificate of Completion that provides a verifiable audit trail of the signing process. This certificate captures:
Document reference number
Signers' names and verified email addresses
IP addresses and locations
Timestamps for when the document was sent, viewed, and completed
PandaDoc uses FIPS-validated AWS CloudHSM cryptographic services for document signing, operating in FIPS 140-3 certified mode and complying with the FIPS 186-5 Digital Signature Standard (DSS). These certificates are embedded in the signed PDF's metadata and confirm that the document has not been altered since signing.
Identity Verification
Configure these methods per document or enforce them at the workspace level for regulated workflows:
Passcode verification — Recipient must enter a passcode defined by the sender
SMS verification — A one-time code is sent to the recipient's mobile number
Knowledge-Based Authentication (KBA) — Recipients answer questions drawn from identity data sources
ID Check — Recipients upload and verify a government-issued photo ID
Healthcare: HIPAA Compliance
PandaDoc is fully HIPAA-compliant and supports the secure transmission and storage of electronic Protected Health Information (ePHI). PandaDoc's HIPAA compliance covers:
The HIPAA Privacy Rule
Administrative, Physical, and Technical Safeguards under the Security Rule
Execute a Business Associate Agreement (BAA) with PandaDoc before using the platform for any ePHI workflows. Contact your account team to request a BAA.
Life Sciences: FDA 21 CFR Part 11
PandaDoc offers dedicated 21 CFR Part 11–compliant workspaces for life sciences and other FDA-regulated organizations. This workspace configuration includes:
Enhanced signer verification methods
Secure, tamper-evident audit trails
Strict access controls and user authentication
Enable 21 CFR Part 11 compliance at the workspace level. Contact your account team to configure a compliant workspace.
Data Privacy and Security Certifications
PandaDoc's eSignature product is in scope for the following security certifications and audits:
Certification / Standard | Details |
SOC 2 Type II | Annual SSAE 18 audit; report available upon request |
GDPR | Lawful processing, data minimization, rights management; certified DPA available |
CCPA | Compliant as of January 1, 2020; updated for CPRA as of March 29, 2023 |
EU-U.S. Data Privacy Framework | Certified participant; covers UK and Swiss extensions |
PCI-DSS | Payments processed via PCI-DSS compliant third-party processors |
Data Residency | Customer data stored in US or EU; customer's choice |
PandaDoc also publishes a list of approved third-party subprocessors, all of which are contractually required to meet PandaDoc's security and data processing standards.
API and Embedded Signing Compliance
The legal enforceability of PandaDoc's API-based and embedded signing implementations depends on your configuration. PandaDoc's best practices and guidance are primarily based on US law, but the platform can be configured to comply in other international jurisdictions.
Work with your legal team to ensure an enforceable implementation when using:
PandaDoc Embedded Signing
PandaDoc eSignature API
Note: PandaDoc is not a law firm, and this article does not constitute or contain legal advice. To evaluate the accuracy, sufficiency, or reliability of the ideas and guidance reflected here, or their applicability to your business, consult a licensed attorney.
