What is qualified timestamping — and why it matters for copyright proof

Article 41(2) of Regulation (EU) No 910/2014 (eIDAS) states that a qualified electronic time stamp „shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound“. That is the entire legal presumption: when the data existed, and that it has not changed since. It carries no presumption about who created the work, who owns the rights in it, or whether it is original.

A blockchain timestamp is not automatically the same legal category. Article 42(1) requires a qualified time stamp to be issued by a qualified trust service provider and signed with that provider’s advanced electronic signature or seal, on a time source linked to Coordinated Universal Time. A public-ledger entry generally satisfies none of those conditions, so it does not attract the Article 41(2) presumption — although under Article 41(1) it still cannot be denied legal effect and admissibility as evidence in legal proceedings solely because it is electronic or not qualified.

Qualified electronic timestamping (Qualified Electronic Time Stamp, QeTS) is a cryptographic operation that binds an exact date and time to a digital document, in a way certified by an accredited third party. The result is a Time-Stamp Token (TST): a signed package per RFC 3161 containing the file's SHA-256 hash, Coordinated Universal Time (UTC) and the certificate of the Trust Service Provider (TSA).

How it works technically

By default the SHA-256 hash is calculated locally in your browser, and only the hash and the certification data are sent to the server — the file itself is not uploaded. The original is uploaded only if you explicitly select the optional „Save the uploaded file“ setting. The hash goes to BORICA – B-Trust (a qualified trust service provider listed on the EU Trust List), which returns a TST signed with its qualified certificate. StampR binds the TST to your authorship declaration and issues a PDF certificate with a QR code for public verification.

Technical flow from local SHA-256 hashing through qualified timestamping to a certificate, with optional original-file storage shown separately
StampR technical flow: the default route sends only the SHA-256 hash and declaration metadata. Original-file storage is a separate, explicit opt-in path.

Legal standing under eIDAS

Regulation (EU) No 910/2014 (eIDAS), Article 41(2), states that a qualified electronic time stamp „shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound“. Article 41(1) adds that an electronic time stamp shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form.

The practical consequence is about the burden of proof: the presumption holds until the other side rebuts it, and it covers two things — the date and time, and the integrity of the data. How much that evidence weighs, and whether it is sufficient in a particular case, is for the court to assess under national procedural law.

Are blockchain timestamps equivalent to qualified electronic timestamps under eIDAS?

No — not automatically. eIDAS does not recognise a technology; it recognises a service that meets Article 42(1) and is supplied by a provider that has been granted qualified status and appears on a Member State trusted list. Article 42(1) sets three requirements, and a public blockchain entry typically meets only the first:

  • (a) binding that makes undetectable change unreasonable — a ledger entry generally does satisfy this.
  • (b) an accurate time source linked to UTC — block time is consensus time, not a traceable UTC reference, so this is usually not satisfied.
  • (c) signed with the advanced electronic signature or seal of the qualified trust service provider — a public ledger has no such provider, so this is not satisfied.

The practical difference is the burden of proof, not admissibility. Both can be put in evidence. Only the qualified time stamp arrives with the Article 41(2) presumption already attached, which the opposing party must rebut; with a blockchain record, the party relying on it is the one who has to establish the date and the integrity. Whether either is sufficient in a given case remains for the court to assess under national procedural law.

What it establishes and what it does not

Article 3(33) of eIDAS defines an electronic time stamp as data that binds other data to a particular time „establishing evidence that the latter data existed at that time“. That is the precise description of its scope:

  • It establishes: that a specific hash value existed at a specific moment, and that the associated data has not been altered since.
  • It does not establish: who created the work, who owns the rights in it, whether it is original, or whether any infringement has occurred.

Copyright arises automatically when a work is created and is not registered. A StampR certificate documents when and by whom an authorship declaration was made — it does not create or register rights, and it does not guarantee the outcome of a dispute. More in proof of authorship in Bulgaria.

RFC 3161 and ETSI EN 319 422

RFC 3161 is the internet standard defining the request/response protocol between a client and a TSA. ETSI EN 319 421 and EN 319 422 are the European profiles built on RFC 3161, adding requirements for auditing, key security and long-term validity. The B-Trust TST complies with both, which allows independent verification with any standard tool.

Qualified versus ordinary timestamps

An ordinary timestamp (server metadata, a blockchain entry) is not issued by a qualified provider and carries no automatic presumption under Article 41(2). The qualified eIDAS timestamp is the only one to which the Regulation attaches that presumption, and under Article 41(3) it is recognised as qualified in every Member State.

Issue a qualified timestamp at StampR – €6.80, under 2 minutes.

Frequently asked questions

What is a qualified electronic timestamp?
A timestamp issued by a qualified trust service provider under Regulation (EU) No 910/2014 (eIDAS). It cryptographically binds a file's SHA-256 hash to a precise UTC date and time per RFC 3161. Under Article 41(2) it enjoys a presumption of the accuracy of the date and time and of the integrity of the associated data.
What is the difference between a qualified and an ordinary timestamp?
An ordinary timestamp is not issued by a qualified provider and carries no automatic legal presumption. The qualified eIDAS timestamp does, and it is recognised in every EU Member State.
What is RFC 3161?
The internet standard defining the Time-Stamp Protocol — the request and response protocol between a client and a Time Stamping Authority. It also specifies the format of the Time-Stamp Token (TST) containing the hash, the time and the TSA signature.
Does a timestamp prove the work is mine?
No. It establishes that a particular hash value existed at a particular moment and that the data has not changed since. Who created the work and who owns the rights are separate questions, evidenced by other means — working files, correspondence, version history.
Are blockchain timestamps equivalent to qualified electronic timestamps under eIDAS?
Not automatically. eIDAS attaches its legal effect to a service that meets Article 42(1) and is supplied by a qualified trust service provider on a Member State trusted list, not to a technology. A public blockchain entry typically satisfies neither the accurate-UTC-time-source requirement nor the qualified-provider signature requirement, so it does not carry the Article 41(2) presumption. Both can be put in evidence; the difference is who bears the burden of proof.
Is my original file uploaded?
By default no — the hash is computed locally in your browser and only the hash is sent. The file is uploaded and stored only if you explicitly select the „Save the uploaded file“ option.

← Back to all news