Identity Checks by a Notarius Publicus: Why a Qualified Trust Service Provider Should Do Them

Share

If you are a notarius publicus, you should stop being your own identity verification system. A glance at a passport across the desk is risky, dated and impossible to prove after the fact, and you personally carry the risk when the identity turns out to be wrong. Instead, have every new client, including those who visit in person, verified remotely by a qualified trust service provider before the first meeting, so that the identity risk sits with the party the law makes liable for it.

What Does a Notarius Publicus Actually Check Today?

A document that is shown, not an identity that is verified. The Swedish Ordinance (1982:327) on Notarius Publicus gives the mandate to certify signatures, copies and other information about the content of documents, but says nothing about how identity should be established. In practice, it is enough for a valid identity document to be presented.

That worked when most clients held Swedish passports and driving licences that were easy to recognise. It works less well when the client holds a Romanian ID card, an Indian passport or a residence permit from another country. With the naked eye, a notarius cannot read the document's chip, compare the face against the chip's biometrics or see whether the document has been revoked. Once the act is done, there is usually no trace of how identity was checked, only a certificate stating that it was.

The matters where a notarius publicus is needed most are also the ones where a manual check is weakest: documents for use abroad, powers of attorney and corporate documents with foreign representatives. For the wider European picture, see why notarial digitalisation has stopped at the video call.

Who Carries the Risk When the Identity Is Wrong?

Today, you do. The appointment from the County Administrative Board is personal. If a certification rests on a forged document, there is no standard to point to, no log showing what you checked and no other party sharing the responsibility.

A qualified trust service provider operates under an entirely different regime. Under Article 13 of the eIDAS Regulation, a qualified provider's intent or negligence is presumed when damage occurs, unless the provider proves otherwise. The burden of proof is reversed. Article 24(2)(c) also requires the provider to hold sufficient financial resources or liability insurance for exactly that risk, and its operations are audited regularly by an accredited conformity assessment body.

As a Qualified Trust Service Provider listed on the EU Trusted List, supervised by the Swedish Post and Telecom Authority and certified by TÜViT, ZealiD operates under that regime. The identity proofing behind every qualified certificate therefore has legal liability and insurance behind it, not a judgement made across a desk.

One boundary needs to be clear. Responsibility for the certification itself is and remains yours, because it is a public mandate. What moves is the identity risk: the question of whether the person really is who the document says. That risk belongs with the party the law makes liable for it.

Pre-Qualification: Verify Identity Before the First Meeting

The principle is simple. Every new client is routed into remote verification before they are given an appointment, including those who will come to your office in person. The flow has four steps:

  1. The client receives a link when booking and verifies in a regulated identity app. The ID document's chip is read, the face is matched against the chip photo and the app checks that the person is live and present.
  2. Verification follows ETSI TS 119 461, the European standard for identity proofing behind qualified certificates.
  3. The client signs a copy of their ID document with a qualified electronic signature.
  4. The signed copy is stored in an environment audited against ETSI EN 319 401, in data centres in Sweden.

When the client then sits in front of you, the meeting is no longer an identity check but a match. The only question is whether the person matches an identity that is already verified, logged and backed by liability insurance.

Why the Client's Signature on the ID Copy Is the Validation

The client's qualified signature on the ID copy is not a formality. It is the proof. A qualified electronic signature can only be created with a qualified certificate, and such a certificate is only issued after identity proofing that meets Article 24(1) of the eIDAS Regulation. When the signature is applied in PAdES format, the European standard for signed PDF documents (ETSI EN 319 142), the document carries the signer's name, a unique identifier and a timestamp.

That gives you two things. First, the client binds themselves to the document: it is the client, not you, who attests that the copy is their own. Second, anyone can validate the signature free of charge against the EU Trusted List, without being a customer of any provider. A photocopy of a passport in a folder cannot be validated at all. For more on the difference, see what a qualified electronic signature actually is and what happens when you cannot prove who signed a document.

Today Pre-qualified client
When identity is checked At the meeting, visually Before the first meeting, remotely
Who verifies The notarius personally A qualified trust service provider, to ETSI TS 119 461
What is kept Nothing, or a photocopy ID copy with the client's qualified signature (PAdES)
Where it is stored Folder, inbox or local drive Environment audited to ETSI EN 319 401, in Sweden
Who carries the identity risk The notarius, unsupported The provider, with reversed burden of proof and insurance
At the meeting Examine a document you cannot validate Confirm the person matches a verified identity
If challenged later Your recollection A timestamped, signed and verifiable document

What AMLR Changes for a Notarius Publicus

AMLR affects most notaries public indirectly, but clearly. The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies from 10 July 2027 and covers notaries as obliged entities when they take part in financial or real estate transactions on a client's behalf. A straightforward certification of a signature generally falls outside that.

The indirect effect weighs more. Banks and firms have long relied on certificates from a notarius publicus to establish the identity of foreign customers who lack Swedish identity documents. AMLR Article 22(6)(b) now gives them an electronic route for exactly those customers: electronic identification at eIDAS assurance level substantial or high, or qualified trust services. A paper certificate based on a visual check will be compared with that standard. A certificate where identity has already been proofed by a qualified service passes the comparison. For more on the requirements, see what AMLR actually requires from small firms before July 2027.

What Happens If You Carry On as Today

The real risk is not that a forgery gets through once. It is that it gets through without a trace. A certification used abroad, in a corporate transaction or in a dispute can be challenged long after the act, and then the question becomes how you checked the identity. "I saw the passport" is an answer that cannot be tested.

There is also a data protection side. Copies of ID documents in folders, email or on local drives are personal data. Article 32 of the GDPR requires security appropriate to the risk, and Article 5(1)(f) requires protection against unauthorised access. A signed copy in an audited environment in Sweden meets that. A scanned copy in an inbox rarely does. See also why where your client data sits is now a client question.

How to Get Started

Four questions show where you stand:

  1. Can you show today how you checked identity at an act you performed a year ago?
  2. Can you validate a foreign ID document you have never seen before?
  3. Who carries the responsibility if a document you accepted turns out to be forged?
  4. Where and how are the ID copies you keep stored?

If the answers are "no", "no", "me" and "not sure", pre-qualification is the first step. ZealiD's identity verification performs remote verification to ETSI TS 119 461 free of charge for the client and lets the client sign their ID copy with a qualified signature before the first meeting.

References

Ordinance (1982:327) on Notarius Publicus (Förordning om notarius publicus). Swedish Parliament. https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/forordning-1982327-om-notarius-publicus_sfs-1982-327/

Regulation (EU) No 910/2014 (eIDAS), Articles 13 and 24, as amended by Regulation (EU) 2024/1183. European Union, 2014 and 2024. https://eur-lex.europa.eu/eli/reg/2014/910/oj/eng

Regulation (EU) 2024/1624 (AMLR), Articles 3 and 22. European Union, 2024. https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng

Regulation (EU) 2016/679 (GDPR), Articles 5 and 32. European Union, 2016. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng

ETSI TS 119 461; ETSI EN 319 401; ETSI EN 319 142 (PAdES). ETSI.