Trads Legal Panama Osvaldo Quintero Digital law attorney · Panama
Law 51 of 2008 · Law 82 of 2012

Electronic signatures in the Republic of Panama

Electronic signatures in Panama are legally recognized by Law 51 of 2008 as amended by Law 82 of 2012. A simple electronic signature is valid where it allows the signatory to be identified and their acceptance of the document to be shown, while the qualified electronic signature enjoys an automatic legal presumption of validity.

The National Directorate of Electronic Signature is the directorate of the Public Registry of Panama in charge of this field. It is the Public Registry, through that directorate, that authorizes and registers certification service providers, and that also acts as the national government’s own provider.

Definition of electronic signature and its legal value

Law 51 of 2008, as amended by Law 82 of 2012, defines the electronic signature and the qualified electronic signature as follows:

Electronic signature. A technical method to identify a person and to indicate that this person approves the information contained in a data message or electronic document.

Qualified electronic signature. An electronic signature whose validity is backed by a qualified electronic certificate that:

  • Allows the signatory to be identified and any subsequent change to the signed data to be detected.
  • Is linked to the signatory uniquely and to the data it refers to.
  • Has been created using secure signature creation devices, which the signatory keeps under their exclusive control.
  • Has been created through the infrastructure of a certification service provider registered with the National Directorate of Electronic Signature.

The same law defines the legal value of the electronic signature: where the law requires a person’s signature, or attaches consequences to its absence, that requirement is satisfied by a data message if a method has been used to identify the originator and to indicate that the content has their approval, and if that method is reliable and appropriate for the purpose for which the message was generated or communicated.

Both requirements are presumed as a matter of law where there is a qualified electronic signature and, therefore, where a certification service provider authorized by the National Directorate of Electronic Signature took part in issuing it.

Simple and qualified electronic signatures

There is a doctrinal distinction between what is called the simple electronic signature and the qualified electronic signature. Both have legal value, the fundamental distinction being that the qualified one carries a presumption of validity as a matter of law.

The qualified electronic signature is the one issued by a certification service provider registered with the National Directorate of Electronic Signature, and also the one issued by the Public Registry of Panama itself as the national government’s provider under Law 82 of 2012.

In short: for a simple electronic signature to have legal value in litigation, it has to be proven. The qualified electronic signature enters the proceedings, in principle, in a far stronger position, with a presumption of validity conferred by the law itself that requires no proof. In theory, the qualified electronic signature has automatic legal validity.

Electronic signatures at the technical level

The SHA-256 hash algorithm is, alongside the elliptic curve algorithm ECDSA and RSA, among the most widely used for the digital signature, the advanced electronic signature, or the qualified or certified electronic signature depending on the country. It is a cryptographic hash function from the SHA-2 family, designed by the National Security Agency and standardized by the National Institute of Standards and Technology (NIST).

What does SHA-256 do?

It takes any amount of data —text, a file, a password, a document— and transforms it into a fixed mathematical fingerprint of 256 bits. That unintelligible numeric result is called the hash or digest.

Main characteristics

  • It always produces the same result. If the content is identical, the hash will be identical.
  • A small change alters the hash completely. “Hello world” and “hello world” generate entirely different hashes.
  • It is one-way. The hash cannot be decrypted to recover the original content.
  • It has a fixed length. It always generates 256 bits, that is, 64 hexadecimal characters.

What is it used for?

In digital certificates, advanced and qualified electronic signatures, time stamping and document integrity. In PKI systems the whole document is normally not signed: what gets signed is the document’s SHA-256 hash.

The typical signing process is: the SHA-256 of the document is computed; that hash is signed with the signatory’s private key using, for example, 2048-bit RSA with SHA-256; the recipient recomputes the hash; and if both hashes match, the document was not altered and the signature is valid.

It is also used for integrity verification —software downloads, digital evidence, legal documents— and in blockchain: Bitcoin uses SHA-256 in its mining and block-chaining mechanism.

Official sources

The full text of both laws is published in the Official Gazette of the Republic of Panama, in Spanish:

  • Law 51 of 2008 — Official Gazette 26090, of 24 July 2008.
  • Law 82 of 2012 — Official Gazette 27160, of November 2012. (A law of my own authorship)

Further reading on electronic signatures

For more detail you can read my essay Quick guide to electronic signatures in Panama, freely available, and the comparative table of electronic signatures and e-invoicing in Central America and part of the Caribbean. Both are in Spanish.

Essay · PDF · 17 pages · in Spanish

Quick guide to electronic signatures in Panama

My essay on the legal framework for electronic signatures in the Republic of Panama. Free access, no sign-up.

Download the essay →
Comparative analysis

Electronic signatures and e-invoicing in the SICA region

Rules, regulations and governing bodies across eight jurisdictions of Central America and part of the Caribbean, in a single table.

View the comparison →

Frequently asked questions about electronic signatures

What is the difference between a simple and a qualified electronic signature in Panama?

Both have legal value. The fundamental distinction is that the qualified electronic signature carries a presumption of validity as a matter of law. A simple signature has to be proven in litigation; a qualified one enters the proceedings with a presumption of validity conferred by the law itself, which requires no proof.

Which law governs electronic signatures in the Republic of Panama?

Law 51 of 2008, as amended by Law 82 of 2012. A qualified electronic signature requires a qualified electronic certificate issued by a certification service provider registered with the National Directorate of Electronic Signature of the Public Registry of Panama.

Who may issue qualified electronic certificates in Panama?

All certification service providers (PSC) duly authorized and registered by the Public Registry of Panama, and that institution itself acting as the national government’s PSC through the National Directorate of Electronic Signature, under Law 82 of 2012.

Is a foreign electronic signature valid in Panama?

A signature made abroad can have legal value in Panama, but the automatic presumption of validity attaches to the qualified electronic signature as defined by Panamanian law — that is, one issued through a certification service provider registered with the National Directorate of Electronic Signature. For a cross-border transaction, that is the point to review before signing, not after.

Keep reading

Personal data protection in Panama → Certified translation English–Spanish → SICA comparison →

Get in touch

Write to me with the details of your matter and I will reply with scope, timeline and cost.

Send an email WhatsApp
Email
tradslegal@outlook.com
Telephone
Follow me
WhatsApp Instagram LinkedIn
Working languages
Spanish · English (authorized public translation)
Where
Panama City, Republic of Panama