How Can Firms Certify Digital Signatures Abroad?

How Can Firms Certify Digital Signatures Abroad?

Introduction

Multinational corporations increasingly execute share purchase agreements, financing documents, board approvals, corporate filings, and other transaction papers electronically. In cross-border deals, however, accepting a digital signature is not enough. The parties must also establish who signed, whether the signature was applied with authority, whether the document was altered, and whether the receiving institution will recognize the certification.

Philippine law generally recognizes electronic documents and electronic signatures. The principal compliance issue is therefore not whether a digital signature can ever be valid, but whether the selected authentication method reliably proves identity, consent, document integrity, and the signatory’s authority.

Philippine Legal Basis for Electronic Signatures

Republic Act No. 8792, or the Electronic Commerce Act, gives electronic documents and electronic signatures legal recognition. Under Section 8, an electronic signature is equivalent to a handwritten signature when a prescribed and non-alterable procedure exists that identifies the person sought to be bound, indicates that person’s access to the electronic document for purposes of consent or approval, is reliable and appropriate in the circumstances, is necessary for the person to proceed with the transaction, and permits the other party to verify the signature and decide whether to proceed.

Accordingly, a signature image pasted into a document is not automatically equivalent to a secure digital signature. The evidentiary strength of the signature depends on the authentication process, the reliability of the technology, the surrounding agreement of the parties, and the ability to connect the signature to the identified signatory.

The Electronic Commerce Act also defines an electronic signature broadly. It may consist of a distinctive mark, characteristic, sound, methodology, or procedure in electronic form that is attached or logically associated with an electronic document and adopted with the intention of authenticating or approving it. The law is technology-neutral, but the method must still satisfy the statutory requirements for reliability and verification.

What Is a Certification Authority?

A certification authority, or CA, is an entity that issues or manages digital certificates used to associate a signatory’s identity with a public cryptographic key. The certificate enables a relying party to verify that a digital signature corresponds to the claimed signatory and that the signed document has not been altered after signing.

The Philippine National Public Key Infrastructure Certificate Policy recognizes the use of certification authorities and registration authorities within the national public-key infrastructure. The policy identifies the Department of Information and Communications Technology as the Philippine Root Certification Authority and provides that certificates issued under the policy are governed by Republic Act No. 8792, Republic Act No. 8484, Republic Act No. 7394, Republic Act No. 10173, and Executive Order No. 810, series of 2009.

A Philippine or foreign CA does not, by itself, guarantee that a signature will be accepted in every jurisdiction. The parties must still determine whether the receiving country, court, regulator, bank, stock exchange, notary, or corporate registry recognizes the CA and the type of certificate used.

Digital Signatures and Electronic Signatures

A digital signature is a particular type of electronic signature that uses an asymmetric or public-key cryptosystem. The signatory uses a private key to sign, while the relying party uses the corresponding public key to verify the signature and detect changes to the document.

The Supreme Court has explained that a digital signature allows a person possessing the original document and the signer’s public key to determine whether the signature was created using the corresponding private key and whether the original document was altered after signing. This distinction is important in cross-border transactions because a digital certificate and verification record can provide stronger evidence than a mere electronic image of a handwritten signature.

In AES Watch, et al. v. Commission on Elections, et al., G.R. No. 246332, 10 November 2020, the Court recognized that an electronic signature may consist of a distinctive mark, characteristic, sound, methodology, or procedure intended to authenticate, sign, or approve an electronic document. The decision also recognized the legal relevance of authentication procedures that allow the integrity and identity of the electronic transaction to be verified.

When Should a Certification Authority Be Used?

Use of a CA-issued digital certificate is particularly advisable when the transaction involves significant value, regulated entities, foreign signatories, documents intended for government or corporate filing, or a foreseeable dispute regarding execution or authority.

A CA-based process is especially appropriate when:

  • The signatory’s identity must be independently verified.
  • The parties require proof that the document was not altered after signing.
  • The agreement contains a non-repudiation or audit-trail requirement.
  • A regulator, bank, corporate registry, or court may later examine the signing process.
  • The contract involves several signatories located in different countries.

For low-risk commercial correspondence, a basic electronic-signature platform may be sufficient if the parties agree to its use and the platform produces adequate authentication and audit records. For major corporate deals, a qualified or otherwise strongly authenticated digital-signature process is generally safer.

Compliance Process for Cross-Border Corporate Deals

1. Identify the Governing Laws and Receiving Institutions

Before selecting a CA, determine the laws governing the transaction and the place where the document will be used. The analysis should include Philippine law, the law of the foreign signatory’s jurisdiction, the law governing the contract, and the rules of the institution that will receive or rely on the document.

A signature may be valid between the contracting parties but still fail to satisfy a filing office’s technical requirements. Corporate registries, financial institutions, tax authorities, and courts may impose separate rules on identity verification, certificate type, notarization, legalization, translation, or document retention.

2. Verify the Certification Authority

The parties should confirm that the CA is authorized or recognized in the relevant jurisdiction and that its certificate policy is publicly available. The certificate policy should identify the CA’s procedures for identity verification, certificate issuance, revocation, suspension, renewal, key protection, and audit logging.

For Philippine transactions, the parties may consider certificates issued within the Philippine National Public Key Infrastructure or certificates accepted under the applicable Philippine institutional rules. The PNPKI policy requires compliance with applicable Philippine laws and recognizes the importance of certification and registration authorities in securing electronic transactions.

3. Confirm the Signatory’s Identity

The CA or registration authority should conduct identity verification appropriate to the transaction. Depending on the certificate and the applicable rules, this may involve government-issued identification, corporate records, address verification, video identification, biometric checks, or confirmation by an authorized corporate representative.

Identity verification should distinguish between the individual signatory and the corporation. A certificate identifying an individual does not, by itself, prove that the individual is authorized to bind the company.

4. Verify Corporate Authority

Before signing, obtain evidence that the signatory has authority to execute the transaction. Relevant documents may include the articles and bylaws, secretary’s certificate, board resolution, incumbency certificate, delegation instrument, power of attorney, or equivalent foreign corporate authorization.

The signing package should state the signatory’s position and authority. Where the agreement is executed by an agent, the parties should preserve the authority document and confirm whether it must be notarized, apostilled, legalized, translated, or submitted to a government or financial institution.

5. Use a Certificate Appropriate to the Transaction

Not all digital certificates provide the same level of assurance. The parties should confirm whether the certificate is intended for individual signing, organizational signing, document encryption, website authentication, or another function.

A certificate used to authenticate a website should not automatically be treated as a certificate proving that a particular officer signed a contract. The certificate’s identity fields, permitted uses, validity period, issuing authority, and revocation status should match the transaction’s requirements.

6. Protect the Private Key

The signatory or authorized key custodian must maintain exclusive control over the private key and its authentication credentials. Sharing the private key, PIN, token, passphrase, or one-time authentication code can undermine the ability to prove that the named signatory personally approved the document.

The Supreme Court’s discussion of digital signatures in Capalla, et al. v. Commission on Elections, et al., G.R. No. 201112, 13 June 2012, emphasizes that a digital signature involves a private key and a corresponding public key. The reliability of the process depends on the relationship between the key, the signatory, and the verification mechanism.

7. Preserve the Validation Evidence

The transaction file should preserve the signed document and the records necessary to validate it later. These may include the digital certificate, certificate chain, signature-validation report, trusted timestamp, audit log, identity-verification record, certificate-revocation status, delivery record, and evidence of the signatory’s corporate authority.

Preservation is essential because a digital signature may be difficult to prove years later if the certificate has expired, the CA has ceased operations, the validation service is unavailable, or the signing platform no longer retains its audit records.

SEC Filings and Electronic Corporate Documents

For Philippine corporate transactions, Securities and Exchange Commission Memorandum Circular No. 10, series of 2024, permits users with credentialed eSECURE accounts to digitally authenticate electronic submissions through the Electronic Submission Authentication Portal.

The circular provides that electronic submissions digitally authenticated through the portal may be accepted as duly authenticated paper documents for SEC transactions. It also removes, for covered submissions, the need for wet signatures and notarization where the prescribed eSECURE and eSAP process is used.

The eSAP process uses the PNPKI Agency Certificate issued by DICT to the SEC together with the user’s credentialed eSECURE account. Its stated characteristics include authentication, integrity, and non-repudiation. These features are relevant when a multinational corporation files articles, bylaws, general information sheets, or other corporate documents with the SEC.

Foreign corporations and foreign signatories should not assume that any foreign electronic-signature platform will automatically satisfy SEC requirements. If the document is intended for SEC submission, the corporation should follow the SEC’s prescribed authentication process and separately preserve the foreign signatory’s corporate authority documents.

Notarization, Apostille, and Legalization

Electronic signing and notarization are different legal acts. A contract may be electronically signed without being notarized, but a law, regulation, corporate procedure, lender requirement, or receiving institution may still require notarization or another form of authentication.

Where a foreign public document must be used in the Philippines, the parties should determine whether the issuing country and the Philippines are parties to a treaty or convention that replaces traditional consular legalization with an apostille. The document may still require an apostille, certified translation, or other formalities depending on its nature and intended use.

The existence of an apostille generally authenticates the origin of a public document. It does not ordinarily establish the truth of every statement contained in that document, nor does it independently prove that a private contract was validly signed or that the signatory had corporate authority.

Philippine electronic notarization rules also distinguish among electronic signatures, digital signatures, and secure electronic signatures. Under the Rules on Electronic Notarization, A.M. No. 24-10-14-SC, an electronic notary public must use either a digital signature or a secure electronic signature as defined in the Rules. The parties must therefore determine whether electronic notarization is available and required for the particular document.

Common Risks in Cross-Border Digital Signing

RiskWhy It MattersRecommended Control
Unverified signing platformThe receiving party may be unable to establish identity or document integrity.Use a reputable CA or platform with a documented certificate policy and audit trail.
Shared credentialsAnother person may have applied the signature or accessed the private key.Require individual accounts, multi-factor authentication, and private-key control.
Unclear corporate authorityThe company may challenge the signatory’s power to bind it.Obtain board approvals, secretary’s certificates, or equivalent authority documents.
Expired or revoked certificateLater verification may fail or become legally disputed.Use trusted timestamps and preserve the certificate and validation report.
Incorrect filing methodA regulator or registry may reject the electronically signed document.Follow the receiving institution’s prescribed portal, account, and authentication process.

Contract Clauses for Electronic Signatures

A cross-border agreement should contain an electronic-signature clause addressing the parties’ consent to electronic execution, counterparts, electronic delivery, signature authentication, and evidentiary treatment.

The clause may also require each party to ensure that its signatories have authority, maintain control of their credentials, promptly report compromise, and retain the signed document and validation records. The parties may identify the approved signing platform or CA and specify whether a particular certificate level is required.

A well-drafted clause should not attempt to override mandatory requirements imposed by a court, regulator, corporate registry, lender, or applicable law. Instead, it should state that the parties will complete any additional notarization, apostille, legalization, translation, or filing requirements applicable to the document’s intended use.

Typical Transaction Example

A Philippine corporation acquires shares in a foreign company. The Philippine buyer’s director signs from Manila, while the foreign seller’s authorized officer signs from abroad. The parties use a CA-issued digital certificate for each signatory, verify the officers’ identities, exchange board resolutions and incumbency certificates, apply trusted timestamps, and retain the certificate chain and validation reports.

If the transaction documents must later be submitted to the Philippine SEC, the parties should separately comply with the SEC’s eSECURE and eSAP requirements where applicable. If a foreign board resolution or power of attorney will be used in the Philippines, the parties should also check whether an apostille, consular legalization, certified translation, or notarization is required.

In this example, the digital signature establishes a stronger evidentiary record, but it does not replace proof of corporate authority or compliance with filing and authentication rules.

Recommended Compliance Checklist

  • Identify every jurisdiction and institution that will rely on the document.
  • Confirm whether the transaction requires a CA-issued digital certificate, electronic notarization, apostille, legalization, or certified translation.
  • Use a CA whose identity-verification and certificate policies are appropriate to the transaction.
  • Verify the signatory’s corporate authority independently from the digital signature.
  • Require exclusive control of the private key and prohibit credential sharing.
  • Preserve the signed document, certificate chain, audit trail, timestamp, and validation report.
  • Check certificate validity and revocation status at the time of signing and, where possible, at the time of validation.
  • Follow the receiving regulator’s prescribed electronic-submission process.

Conclusion

Authorized certification authorities can substantially strengthen the enforceability and evidentiary value of digital signatures in international corporate transactions. Their use helps establish the signatory’s identity, document integrity, and signing event, but certification does not by itself prove corporate authority or guarantee acceptance in every jurisdiction.

Multinational firms should therefore treat digital-signature compliance as a coordinated process involving identity verification, CA selection, private-key security, corporate authorization, document preservation, and destination-country requirements. For Philippine filings, the parties should also comply with the applicable SEC, PNPKI, electronic-notarization, apostille, and institutional rules.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH