If you are a notarius publicus, you should stop being your own identity verification system. A glance at a passport across the desk is risky, dated and impossible to prove after the fact, and you personally carry the risk when the identity turns out to be wrong. Instead, have every new client, including those who visit in person, verified remotely by a qualified trust service provider before the first meeting, so that the identity risk sits with the party the law makes liable for it.
A document that is shown, not an identity that is verified. The Swedish Ordinance (1982:327) on Notarius Publicus gives the mandate to certify signatures, copies and other information about the content of documents, but says nothing about how identity should be established. In practice, it is enough for a valid identity document to be presented.
That worked when most clients held Swedish passports and driving licences that were easy to recognise. It works less well when the client holds a Romanian ID card, an Indian passport or a residence permit from another country. With the naked eye, a notarius cannot read the document's chip, compare the face against the chip's biometrics or see whether the document has been revoked. Once the act is done, there is usually no trace of how identity was checked, only a certificate stating that it was.
The matters where a notarius publicus is needed most are also the ones where a manual check is weakest: documents for use abroad, powers of attorney and corporate documents with foreign representatives. For the wider European picture, see why notarial digitalisation has stopped at the video call.
Today, you do. The appointment from the County Administrative Board is personal. If a certification rests on a forged document, there is no standard to point to, no log showing what you checked and no other party sharing the responsibility.
A qualified trust service provider operates under an entirely different regime. Under Article 13 of the eIDAS Regulation, a qualified provider's intent or negligence is presumed when damage occurs, unless the provider proves otherwise. The burden of proof is reversed. Article 24(2)(c) also requires the provider to hold sufficient financial resources or liability insurance for exactly that risk, and its operations are audited regularly by an accredited conformity assessment body.
As a Qualified Trust Service Provider listed on the EU Trusted List, supervised by the Swedish Post and Telecom Authority and certified by TÜViT, ZealiD operates under that regime. The identity proofing behind every qualified certificate therefore has legal liability and insurance behind it, not a judgement made across a desk.
One boundary needs to be clear. Responsibility for the certification itself is and remains yours, because it is a public mandate. What moves is the identity risk: the question of whether the person really is who the document says. That risk belongs with the party the law makes liable for it.
The principle is simple. Every new client is routed into remote verification before they are given an appointment, including those who will come to your office in person. The flow has four steps:
When the client then sits in front of you, the meeting is no longer an identity check but a match. The only question is whether the person matches an identity that is already verified, logged and backed by liability insurance.
The client's qualified signature on the ID copy is not a formality. It is the proof. A qualified electronic signature can only be created with a qualified certificate, and such a certificate is only issued after identity proofing that meets Article 24(1) of the eIDAS Regulation. When the signature is applied in PAdES format, the European standard for signed PDF documents (ETSI EN 319 142), the document carries the signer's name, a unique identifier and a timestamp.
That gives you two things. First, the client binds themselves to the document: it is the client, not you, who attests that the copy is their own. Second, anyone can validate the signature free of charge against the EU Trusted List, without being a customer of any provider. A photocopy of a passport in a folder cannot be validated at all. For more on the difference, see what a qualified electronic signature actually is and what happens when you cannot prove who signed a document.
| Today | Pre-qualified client | |
|---|---|---|
| When identity is checked | At the meeting, visually | Before the first meeting, remotely |
| Who verifies | The notarius personally | A qualified trust service provider, to ETSI TS 119 461 |
| What is kept | Nothing, or a photocopy | ID copy with the client's qualified signature (PAdES) |
| Where it is stored | Folder, inbox or local drive | Environment audited to ETSI EN 319 401, in Sweden |
| Who carries the identity risk | The notarius, unsupported | The provider, with reversed burden of proof and insurance |
| At the meeting | Examine a document you cannot validate | Confirm the person matches a verified identity |
| If challenged later | Your recollection | A timestamped, signed and verifiable document |
AMLR affects most notaries public indirectly, but clearly. The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies from 10 July 2027 and covers notaries as obliged entities when they take part in financial or real estate transactions on a client's behalf. A straightforward certification of a signature generally falls outside that.
The indirect effect weighs more. Banks and firms have long relied on certificates from a notarius publicus to establish the identity of foreign customers who lack Swedish identity documents. AMLR Article 22(6)(b) now gives them an electronic route for exactly those customers: electronic identification at eIDAS assurance level substantial or high, or qualified trust services. A paper certificate based on a visual check will be compared with that standard. A certificate where identity has already been proofed by a qualified service passes the comparison. For more on the requirements, see what AMLR actually requires from small firms before July 2027.
The real risk is not that a forgery gets through once. It is that it gets through without a trace. A certification used abroad, in a corporate transaction or in a dispute can be challenged long after the act, and then the question becomes how you checked the identity. "I saw the passport" is an answer that cannot be tested.
There is also a data protection side. Copies of ID documents in folders, email or on local drives are personal data. Article 32 of the GDPR requires security appropriate to the risk, and Article 5(1)(f) requires protection against unauthorised access. A signed copy in an audited environment in Sweden meets that. A scanned copy in an inbox rarely does. See also why where your client data sits is now a client question.
Four questions show where you stand:
If the answers are "no", "no", "me" and "not sure", pre-qualification is the first step. ZealiD's identity verification performs remote verification to ETSI TS 119 461 free of charge for the client and lets the client sign their ID copy with a qualified signature before the first meeting.
Ordinance (1982:327) on Notarius Publicus (Förordning om notarius publicus). Swedish Parliament. https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/forordning-1982327-om-notarius-publicus_sfs-1982-327/
Regulation (EU) No 910/2014 (eIDAS), Articles 13 and 24, as amended by Regulation (EU) 2024/1183. European Union, 2014 and 2024. https://eur-lex.europa.eu/eli/reg/2014/910/oj/eng
Regulation (EU) 2024/1624 (AMLR), Articles 3 and 22. European Union, 2024. https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng
Regulation (EU) 2016/679 (GDPR), Articles 5 and 32. European Union, 2016. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
ETSI TS 119 461; ETSI EN 319 401; ETSI EN 319 142 (PAdES). ETSI.