From 1 January, the Communications Regulatory Authority (CRA) becomes the supervisory body for providers of qualified electronic identification (eID) services.
“Typically, an eSignature tool contains two certificates: an eID and an eSignature. eID is used to identify a person before electronic transactions are made, while an eSignature is a means of signing eDocuments. Technically, it is difficult for individuals to see and know which certificate is being used in which process, but an indicator could be which PIN is being requested: shorter or longer”, explains Irma Kazlienė, the Head of the Digital Services Regulatory Group at the CRA.
According to her, until now the CRA supervised only the qualified eSignature certificate, its creation, issuance and compliance with the requirements, but after the adoption of amendments to the Law of the Republic of Lithuania on Electronic Identification and Trust Services for Electronic Transactions in May 2023, the CRA has been obliged to supervise eID providers as well, the supervision model has been established and the CRA has been obliged to adopt the relevant legal acts.
“Depending on the procedures, technical and security aspects of the eID issuance, the eID may be assigned a certain level of security. There are three levels of security in the EU legal framework: low, sufficient and high. eIDs with a high level of security will have the highest level of trust and will enable individuals to access critical public and/or administrative services, for example, in the future, when voting online or using the eWallet application,” explains I. Kazlienė.
The legislation also provides for obligations and requirements for eID service providers to submit performance reports and decommissioning plans to the CRA as a supervisory body.
More information on the CRA legislation: https://www.e-tar.lt/portal/lt/legalAct/eabf89d0a0b511eea5a28c81c82193a8 https://www.e-tar.lt/portal/lt/legalAct/cb09dcd0a0b511eea5a28c81c82193a8
Updated on 2024-03-22