GDPR check

Is Scrive GDPR compliant? What universities should check

Scrive is a Stockholm-based e-signing and eID service used by Nordic organisations for contracts, HR documents and, increasingly, research consent forms. This page sets out what Scrive publicly documents about hosting, subprocessors, the personal data in a signature's evidence, retention and its trust service status, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Scrive AB is a Swedish company, with Scrive AS in Norway providing its certified trust services. It acts as processor for documents customers send for signing, states that all its data hosting is in the EU/EEA (on AWS infrastructure in the EU, or on Swedish provider Cleura for its Scrive EC platform), and says most of its subprocessors and processing locations are in the EU/EEA. It holds ISO 27001:2022 certification and Qualified Trust Service Provider status under eIDAS. A university's main questions are less about transfers than about content: what the signed documents reveal, whether eID signing should capture personal identity numbers, and how long signed documents and evidence stay in Scrive's archive.

What Scrive documents publicly

The table summarises Scrive's privacy notice, trust centre, terms of service and subprocessor list, read on 7 October 2026. It covers Scrive eSign and the eID Hub as used by an organisation.

TopicWhat the vendor statesSource
Company and roleDocumented Scrive AB (org. no. 556816-6804), Grev Turegatan 11A, Stockholm; Scrive AS in Oslo for certified trust services. The privacy notice (March 2026) says Scrive processes personal data for its own purposes and on behalf of its customers. Data protection officer: dpo@scrive.com.Privacy notice [1]
Where data is stored and processedDocumented All data hosting locations are in the EU/EEA. The standard platform runs on AWS infrastructure in the EU; Scrive EC runs on Cleura's infrastructure in the EU. Scrive says data may exceptionally be accessed from outside the EU/EEA when a global cloud provider is used, for example for support, and that some optional subprocessors may access data from outside the EU/EEA.[1], Trust centre: GDPR [2]
SubprocessorsPartly documented Scrive's privacy notice links a subprocessor list hosted by Openli and says most of its subprocessors and processing locations are in the EU/EEA, while some optional subprocessors may access personal data from outside the EU/EEA. The Openli list itself returned a bot check to our retrieval on 7 October 2026, so its contents are not summarised here.[1], Subprocessor list (Openli) [3]
Data processing agreementPartly documented Scrive refers to customer data processing agreements in its trust centre. A public DPA template: not found in public documentation (checked 7 October 2026). The published terms of service (March 2020) do not include one.[2], Terms of service [4]
Personal data in signingDocumented Signing parties may provide names, emails, phone numbers, title, company details and IP addresses, a drawn signature, and evidence of eID authentication including an ID number or similar. An evidence package with a transaction log is attached to each signed document.[1]
Retention and deletionCustomer-controlled Data is kept as long as the customer retains documents in the Scrive eSign archive. After a party deletes a document, Scrive may keep an encrypted backup for six months under its backup policy.[1], [4]
Trust servicesDocumented Scrive states it is a Qualified Trust Service Provider under eIDAS and, since February 2025, offers qualified electronic signatures with Swedish BankID.[1], QES announcement [5]
Security certificationsDocumented ISO 27001:2022 with yearly audits; data encrypted at rest and in transit; signed documents sealed against tampering.Trust centre [6]
AI featuresNot found AI processing of document content: not found in public documentation (checked 7 October 2026). Scrive's site promotes sending agreements for signing from an AI agent through an MCP server, which is an integration rather than analysis of documents.[6]

Scrive's strengths for a European university are clear from its documentation: EU/EEA hosting for all data locations, a Swedish hosting option through Scrive EC, a published subprocessor list, and qualified trust service status under eIDAS.

What this means for a university

Validemic's analysis

The content matters more than the platform. E-signing seems low-risk until you look at what is signed. Employment contracts, salary changes, disability adjustments, disciplinary agreements and research consent forms can all contain or imply sensitive information. A signed consent form for a study on, for example, mental health reveals that the signatory took part, which may be health-related data under Article 9 GDPR [7]. The same Scrive account can hold both a purchase order and such a form, so access rights inside the university's Scrive account deserve as much thought as the vendor.

Personal identity numbers. Signing with eID can record an ID number in the evidence [1]. Article 87 GDPR lets member states set conditions for processing national identification numbers [7], so check your national rules. For staff contracts this is usually justified; for research participants, ask whether an eID signature is necessary or whether a simpler signature level would do.

Retention in two places. Signed documents usually also go into the university's own records system. If they stay in Scrive's archive indefinitely as well, you hold two copies with different deletion rules. Decide which is the record and set a deletion routine for the other, bearing in mind Scrive's six-month backup period [4].

Transfers. With all hosting in the EU/EEA, transfer questions are narrower than for most SaaS. They do not disappear: Scrive notes possible exceptional access from outside the EU/EEA where a global cloud provider such as AWS is used, and says some optional subprocessors may access data from outside the EU/EEA [1]. If you use optional services, check which ones apply to your account and which transfer mechanism covers each.

Contract. Because no public DPA template was found, the university will negotiate or accept Scrive's DPA during procurement. Check it against Article 28 GDPR [7], in particular subprocessor notice and deletion at the end of the contract.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Scrive before approving it

  1. Can we see the DPA you would sign with us, including subprocessor notice periods and deletion at the end of the contract?
  2. Should we use the standard platform (AWS) or Scrive EC (Cleura), and what differs in practice?
  3. Which optional subprocessors would apply to our configuration, and where does each process data?
  4. Which data does the evidence package contain for each eID method we plan to use, and can we avoid storing personal identity numbers where not needed?
  5. Can we set automatic deletion from the archive per document type, for example after transfer to our records system?
  6. How are access rights managed between departments in one university account?
  7. In which exceptional cases could data be accessed from outside the EU/EEA, and how would we be informed?

The EU AI Act angle

E-signing and eID authentication are not among the education uses listed as high-risk in Annex III of the AI Act [8], and we found no AI analysis of document content in Scrive's public documentation. If a university connects Scrive to its own AI agent, the agent is the AI system to assess, and Article 4, as amended by Regulation (EU) 2026/1744, requires deployers to take measures to support the AI literacy of staff using it [9]. Under eIDAS, the European Commission states that qualified electronic signatures have the same legal effect as handwritten signatures [10].

Sources

  1. Scrive Privacy Notice (March 2026), retrieved 7 October 2026
  2. Scrive Trust Centre: GDPR compliance, retrieved 7 October 2026
  3. Scrive subprocessors, Scrive privacy page hosted by Openli; returned a bot check to automated retrieval on 7 October 2026 and could not be read
  4. Scrive Terms of Service (March 2020), retrieved 7 October 2026
  5. Following QTSP status, Scrive launches qualified electronic signatures with BankID, Scrive, 10 February 2025, retrieved 7 October 2026
  6. Scrive Trust Centre, retrieved 7 October 2026
  7. Regulation (EU) 2016/679 (GDPR), Articles 9, 28 and 87, text read from the Publications Office copy, retrieved 7 October 2026
  8. AI Act Annex III, AI Act Service Desk, retrieved 7 October 2026
  9. AI Act Article 4: AI literacy, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
  10. Discover eIDAS, European Commission, retrieved 7 October 2026

About this page

We read Scrive's privacy notice, trust centre pages, terms of service and its QES announcement, together with the relevant EU legal texts and the European Commission's eIDAS page, on 7 October 2026. Statements about Scrive come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Scrive complies with the GDPR. If you spot an error or Scrive has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Scrive GDPR compliant?

No tool is GDPR compliant on its own. Scrive is a Swedish company that acts as processor for customers' documents, hosts its service in the EU/EEA, publishes its subprocessor list and holds ISO 27001:2022 certification. Whether a university's use complies depends on its data processing agreement with Scrive, the eID methods chosen, retention settings and what the signed documents contain.

Where does Scrive store data?

Scrive says all its data hosting is in the EU/EEA. The standard platform runs on Amazon Web Services infrastructure in the EU, and Scrive EC runs on Swedish provider Cleura's infrastructure. Scrive notes that, where a global cloud provider is used, data may exceptionally be accessed from outside the EU/EEA, for example for support.

What personal data does a Scrive signature create?

According to Scrive's privacy notice, signing parties may share names, email addresses, phone numbers, company details and IP addresses, a drawn signature and evidence of eID authentication, which can include an ID number. Each signed document carries an evidence package with a transaction log.

Are Scrive signatures legally valid in the EU?

Scrive says it holds Qualified Trust Service Provider status under eIDAS and has offered qualified electronic signatures with Swedish BankID since February 2025. The European Commission states that qualified electronic signatures have the same legal effect as handwritten signatures. Which signature level a document needs is a legal question for the university.

Can researchers use Scrive for informed consent forms?

Technically yes, and it creates a strong audit trail. The data protection questions are what the consent form itself reveals (for example participation in a health study), whether collecting a personal identity number through eID is necessary, how long signed forms stay in Scrive's archive, and whether the participant information explains the e-signing step.