The new regulations on the formation and management of computerized documents

Summary

Foreword

Adopted with Determination No. 407/2020 by the Agency for Digital Italy (AGID) and then amended with Determination No. 371/2021, last Sept. 28 the "Guidelines for the formation, management and preservation of electronic documents" became fully operational and binding erga omnes, following a transitional period granted for adaptation, which began as early as Jan. 1, 2022, the date on which they came into force.

This legislation has had (and will have) a considerable impact, not only for P.A., but also for private entities (e.g., professional firms and companies), which, if they intend to use IT tools for the creation of digital documents having legal effect, will have to scrupulously comply with the discipline dictated on the subject by the CAD and its Guidelines, not only for the creation of the IT document, but also for its management and preservation.

The purpose of the reform, in fact, is to dictate certain rules on the creation and management of computerized documents, such as to guarantee their total reliability, on a par with any other document drawn up in paper format (e.g., a contract with a holographic signature of the parties), by means of systems suitable for ensuring the security, integrity and unmodifiability of the document, as well as its manifest and unequivocal traceability back to the author.

From a substantive point of view, the main novelties pertain to the evidentiary value of the computer document created and managed in accordance with these regulations, which is expressly given the effectiveness of full evidence under Article 2702 of the Civil Code, as well as the suitability of the same to integrate the requirements of the written form, as per Article 1350 of the Civil Code.

More specifically, Art. 20 of the CAD stipulates that "The computer document satisfies the requirement of written form and has the effectiveness provided for in Article 2702 of the Civil Code when a digital signature, other type of qualified electronic signature or an advanced electronic signature is affixed to it or, in any case, it is formed, after computer identification of its author, (...) in such a way as to guarantee the security, integrity and unchangeability of the document and, in a manifest and unequivocal manner, its traceability back to its author."

By reason of the aforementioned rule, therefore, the computer document, created and managed in accordance with the regulations under consideration, will "make full proof, up to suit of forgery of the provenance of the statements from the person who signed it, if the person against whom the writing is produced recognizes its signature, or if it is legally considered as recognized" (Art. 2702 Civil Code); in all other cases, however, the probative value of the computer document that may be produced in court, again by express normative provision, will be freely assessable by the individual Magistrate.

The other important innovation introduced by the CAD, in Article 21 below, concerns the suitability of a computer document prepared and maintained in accordance with the provisions of the Code to supplement the requirement of written form, even when provided ad substantiam, pursuant to Article 1350 of the Civil Code.

And in fact, this provision stipulates that "except in the case of a notarized signature, private deeds referred to in Article 1350, first paragraph, numbers 1 to 12, of the Civil Code, if made on a computer document, shall be signed, under penalty of nullity, with a qualified electronic signature or digital signature. The acts referred to in Article 1350, number 13) of the Civil Code drawn up on a computer document or formed through computer processes shall be signed, under penalty of nullity, with an advanced, qualified or digital electronic signature."

Even in such cases, benvero, the computer document will have the aforementioned effectiveness and validity, provided that it is created and managed in accordance with the provisions of the CAD, i.e., in ways that guarantee "the security, integrity and unmodifiability of the document and, in a manifest and unequivocal manner, its traceability back to the author."

On the other hand, a private contract drafted and signed in a manner that does not comply with the regulations under consideration will be ineligible to integrate the requirement of written form, pursuant to Article 1350 of the Civil Code, resulting in the nullity of the relevant agreements.

Already from the brief remarks above, therefore, it becomes evident how important it is for companies, professional firms and, more generally, for any private entity exercising a business and/or professional activity, to adapt to the regulations provided for by the CAD, for the purposes of the creation and management of computerized documents, all the more so, in the hypotheses in which (e.g., due to the distance of the subjects involved) the use of computerized tools and documents is, if not indispensable, at least of obvious support for a more streamlined and effective management of the relative activity.

The formation of the electronic document

Going into the more technical and practical aspects of the regulations under consideration, enshrined in particular in the "Guidelines for the Formation, Management and Preservation of Computer Documents," to which the CAD regulations themselves expressly refer, it is first necessary to examine the criteria and methods for the formation of the computer document.

More specifically, these provisions prescribe four different ways of creating the so-called electronic document, and in particular:

(a) creation through the use of qualified software tools or cloud services;

(b) acquisition of a computer document electronically or in a computer medium, acquisition of the computer image copy of an analog document, acquisition of the computer copy of an analog document;

(c) computer storage in digital format of information resulting from computer transactions or processes or from the telematic submission of data through forms or forms made available to the user;

(d) generation or grouping even automatically of a set of data or records, from one or more databases, including those belonging to several inter-operating parties, according to a predetermined logical structure and stored in static form.

The document created according to one of the aforementioned methods must then be uniquely and persistently identified by stakeholders and must be unchangeable.

This immodifiability must be ensured differently, depending on the above-mentioned ways in which the computer document was created, viz:

  1. (1) in the case of a computer document formed in the manner referred to in (a) above, immodifiability and integrity shall be ensured by one or more of the following operations:

    • affixing a qualified electronic signature, digital signature or qualified electronic seal or advanced electronic signature;

    • storage on document management systems that adopt appropriate security measures;

    • transfer to third parties through a certified electronic mail service or a qualified certified electronic delivery service valid for the purpose of electronic communications having legal value;

    • deposit to a preservation system.

  2. (2) in the case of a computer document formed in the manner set forth in (b) above

    immodifiability and integrity are guaranteed by one or more of the following operations by:

    • affixing a qualified electronic signature, digital signature or qualified electronic seal or advanced electronic signature;

    • storage on document management systems that adopt appropriate security measures;

    • deposit to a preservation system.

  3. (3) in the case of a computer document formed in the manner referred to in (c) and (d) above, the characteristics of immodifiability and integrity are guaranteed by one or more of the following operations:

    • affixing a qualified electronic signature, digital signature or qualified electronic seal or advanced electronic signature;

    • recording in system logs of the outcome of the computer document formation operation, including the application of measures to protect the integrity of databases and the production and preservation of system logs;

    • production of a static data extraction and transferring it to the preservation system.

      At the time of formation of the unalterable computer document, in addition, relevant metadata must be generated and permanently associated with it.

The reproduction of the computer document

Computer-based image copies of analog documents.

With reference to the methods of digital copying and reproduction, the regulations under consideration provide for different regulations, depending on the nature, digital or analog, of the original document.

More specifically, the computer image copy of an analog document must be produced by means of processes and tools that ensure that the computer document has the same content and form as the analog document from which it is taken, after carrying out the so-called "document comparison" procedure.

The use of this procedure ensures that the content of the digital copy conforms to the information in the source analog document.

Such compliance must subsequently be attested to, by the affixing of the digital signature or qualified electronic signature or advanced electronic signature, as well as the qualified and advanced electronic seal by the person making the comparison, except in cases where said attestation has already been affixed by a public official.

Where required by the nature of the activity, the attestation of conformity of copies of computerized documents may be included in the computerized document containing the copy; or, it may be produced as a separate computerized document containing a time reference and the imprint of each computerized copy or extract.

In the latter case, the computer document containing the attestation must be signed with a digital signature or with a qualified or advanced electronic signature of the notary or public official authorized to do so.

Computer duplicates, copies and extracts of computer documents.

In the case where the original document is already in digital format, on the other hand, different hypotheses must be distinguished, depending on the type of operation to be carried out, that is, whether it is the creation of a duplicate, a copy or an extract, and in particular:

  1. (a) the computer duplicate has the same legal value as the computer document from which it is taken, if it is obtained by storing the same computer evidence, either on the same device or on different devices (e.g., by making a copy from a PC to a pen-drive of a document in the same format);

  2. (b) a copy of a computer document is a document whose content is the same as the original but with a different computer evidence from the document from which it is taken, such as when transforming a document with a ".doc" extension into a ".pdf" document.

  3. (c) the extract of a computer document is a part of the document with a different computer evidence than the document from which it is taken.

From an evidentiary point of view, such documents have the same value as the original from which they originated, if the same conformity is not expressly disavowed.

However, for copies and/or extracts of computerized documents to be valid, they must be formed by one of the following two methods:

  • Comparison of documents;

  • process certification.

    In fact, the use of either of the above methods ensures that the content of the computer copy or extract conforms to the information in the source computer document.

    Such compliance must subsequently be attested to, by the affixing of the digital signature or qualified electronic signature or advanced electronic signature, as well as the qualified and advanced electronic seal by the person making the comparison, except in cases where said attestation has already been affixed by a public official.

    Where required by the nature of the activity, in addition, the attestation of conformity of computer copies or extracts of computer documents may be included in the computer document containing the copy or extract; or, it may be produced as a separate computer document containing a time reference and the imprint of each computer copy or extract.

    In the latter case, the computer document containing the attestation must be signed with a digital signature or with a qualified or advanced electronic signature of the notary or public official authorized to do so.

The management of computerized documents

The system of standards introduced by the CAD does not merely regulate the stage of formation of the computer document, but provides a set of rules and prescriptions, aimed at ensuring the reliability of the document at all stages of its existence until its (eventual) deletion.

And indeed, Article 44 of the CAD provides that, in all cases in which the law prescribes preservation obligations, including those of private parties, the system of preservation of computerized documents must be such as to ensure, for what is preserved in it, characteristics of authenticity, integrity, reliability, legibility, and retrievability, according to the methods indicated in the Guidelines.

Among the main obligations related to IT document management, aimed at ensuring compliance with the principles last mentioned, are undoubtedly that of the appointment of a Document Management Officer and the preparation by the latter of a document management manual.

Duties of the document management officer.

One of the main responsibilities of the document management manager is to prepare, in consultation with the preservation manager:

- The document management manual on the formation, management, transmission, interchange, and access to computerized documents in compliance with the regulations on the processing of personal data and consistent with the provisions of the preservation manual.

In addition, this manual must contain, as an integral part of it, the information security plan, for its share, in accordance with the:

  • ✓ security measures prepared by AgID and other relevant bodies;

  • ✓ of data protection provisions in line with the risk analysis done;

  • ✓ guidance on business continuity of information systems prepared by AGID.

Document management manual

The document management manual is the document designed to regulate the computerized document management system and provide instructions for the proper operation of the service for the maintenance of computer protocol, document flow management and archives.

Mainly, the document management manual should include:

1. regarding organizational aspects:

(a) how to use computer tools for the formation of computer documents;

2. regarding document formats:

  1. (a) the identification of the formats used for the formation of the electronic document, from among those listed in Annex 2 "File Formats and Reversal."

  2. (b) a description of any additional formats used for document formation in relation to specific operational contexts that are not identified in Annex 2, "File Formats and Reversion."

  3. (c) the procedures for the periodic evaluation of interoperability of formats and for the planned spillover procedures as outlined in Annex 2 "File Formats and Spillover."

3. with respect to computer protocol:

  1. (a) how to record information cancelled or changed in registration activities;

  2. (b) the complete and timely description of how to use the "computer protocol system" component of the computer document management system;

4. regarding classification and selection actions:

(a) the classification plan adopted, with an indication of how it will be updated, supplemented with information on the timing, criteria and rules for selection and preservation, with reference to discard procedures;

5. regarding the formation of document aggregations:

(a) the methods of formation, management and storage of computer files and computer document aggregations with the minimum set of metadata associated with them;

6. regarding the document processing flows in use:

(a) the description of internal processing flows, including the formal representation of processes through the use of languages specified by AgID, applied to the management of documents received, sent or for internal use;

7. regarding the organization of computer documents, computer files and computer series:

(a) the definition of the structure of the archive within the computerized document management system;

8. regarding the personal data security and protection measures taken:

(a) the appropriate technical and organizational measures to ensure a level of security appropriate to the risk including personal data protection;

9. regarding conservation:

(a) for entities other than public administrations that do not have a preservation plan, if a Management Manual needs to be prepared due to the complexity of the organizational structure and the documentation produced, the criteria for organizing the archive, periodic selection and preservation of documents should be defined, including the timeframe within which the different types of digital objects must be transferred to preservation and, if necessary, discarded.

The computer document retention system.

The preservation system

The last phase regulated by the CAD, regarding the management of the computer document, concerns the process of its preservation

Such a preservation system must ensure, from taking charge to eventual discard, the preservation of the following digital objects stored in it, through the adoption of rules, procedures and technologies, guaranteeing their characteristics of authenticity, integrity, reliability, readability, retrievability:

  1. computerized documents and computerized administrative records with their associated metadata;

  2. computerized document aggregations (files and series) with associated metadata containing references that uniquely identify the individual document objects that constitute those aggregations.

In addition, the preservation system must guarantee access to the preserved object for the period stipulated in the preservation plan of the owner of the object of preservation and in the applicable regulations, or for a longer time that may be agreed upon between the parties, regardless of the evolution of the technological environment.

The preservation system is at least logically distinct from the computerized document management system.

Organizational models of conservation

The preservation process can be carried out inside or outside the organizational structure of the institution.

The requirements of the preservation process, the responsibilities and duties of the preservation manager and the preservation service manager, and how they interact are formalized in the preservation manual of the Preservation Object Holder.

In order to ensure the authenticity, integrity, reliability, readability and retrievability of documents, preservation service providers must possess high-level quality and security requirements in adherence to ISO/IEC 27001 (Information security management systems - Requirements) standard of the information security management system in the logical, physical and organizational domain in which the preservation process is implemented and ISO 14721 OAIS (Open Archival Information System), and ETSI recommendations TS 101 533-1 v. 1.2.1 (Requirements for implementing and operating secure and reliable systems for the electronic preservation of information)

Roles and responsibilities

The roles identified in the preservation process are:

  1. Holder of the object of preservation;

  2. PdV producer;

  3. enabled user;

  4. responsible for preservation;

  5. conservative.

The authorized user may request access to documents from the preservation system to acquire information of interest within the limits provided by law and in the manner prescribed by the preservation manual.

In the case of entrusting to a third party, the PdV producer generates and transmits to the preservation system the pouring packages in the manner and with the formats agreed with the conservator and described in the preservation manual of the preservation system. It also provides for verifying the successful completion of the transfer operation to the preservation system by means of viewing the deposit report produced by the preservation system itself.

The Conservation Officer

The preservation officer operates in accordance with the provisions of Article 44, paragraph 1-quater, of the CAD.

The role of the preservation manager may be carried out by an individual inside or outside the organization, possessing appropriate legal, information technology and archival skills, as long as he or she is third party to the Preservation Officer in order to ensure the function of the Preservation Object Holder with respect to the preservation system.

The preservation manager defines and implements the overall policies of the preservation system and governs its management with full responsibility and autonomy.

The preservation manager, under his or her own responsibility, may delegate the performance of his or her activities or part of them to one or more individuals within the organizational structure who have specific skills and experience. Such a delegation, reported in the preservation manual, must identify the specific functions and skills delegated.

In particular, the conservation officer:

  1. defines the preservation policies and functional requirements of the preservation system, in accordance with current legislation and taking into account international standards, due to the specificities of the digital objects to be preserved (computer documents, computer aggregations, computer archives), the nature of the activities that the Preservation Object Holder performs, and the characteristics of the adopted computer document management system;

  2. manages the preservation process and ensures its compliance with current regulations over time;

  3. Generates and signs the deposit report in the manner prescribed in the preservation manual;

  4. generates and signs the distribution package with digital signature or qualified electronic signature, in the cases provided by the preservation manual;

  5. Performs monitoring of the proper functionality of the preservation system;

  6. performs periodic verification, not more frequently than every five years, of the integrity and readability of computer records and documentary aggregations of archives;

  7. in order to ensure the preservation of and access to computerized documents, takes measures to promptly detect any degradation of storage systems and records and, where necessary, to restore proper functionality; takes similar measures with regard to obsolescence of formats;

  8. Provides for duplication or copying of computerized documents as the technological environment evolves, in accordance with the preservation manual;

  9. Prepares the necessary measures for the physical and logical security of the preservation system;

  10. Prepares the preservation manual and ensures that it is updated periodically when there are relevant regulatory, organizational, procedural, or technological changes.

In the event that the preservation service is entrusted to a conservator, the aforementioned activities or some of them may be entrusted to the person in charge of the preservation service, it being understood in any case that the general legal responsibility over the preservation processes, not being delegable, remains with the person in charge of preservation, who is also called upon to carry out the necessary verification and control activities.

The conservation manual

The preservation manual is the information technology document that must detail the organization, the people involved and the roles played by them, the operating model, a description of the process, a description of the architectures and infrastructure used, the security measures adopted, and any other information useful for managing and verifying the operation, over time, of the preservation system.

In addition, the preservation manual should state, mainly:

a. the details of the individuals who have assumed responsibility for the preservation system over time, describing in detail, in case of delegation, the individuals, functions and areas covered by the delegation;

b. the organizational structure including the functions, responsibilities and obligations of the various parties involved in the preservation process;

c. a description of the types of digital objects subject to preservation, including an indication of the formats managed, the metadata to be associated with the different types of objects, and any exceptions;

d. a description of how to take charge of one or more deposit packages, including the preparation of the deposit report;

e. A description of the storage process and processing of storage packages;

f. how the process of performing and exporting from the preservation system with the production of the distribution package is carried out;

g. a description of the preservation system, including all technological, physical and logical components, appropriately documented, and the procedures for their management and evolution;

h. a description of the procedures for monitoring the functionality of the preservation system and the integrity checks of the archives with evidence of the solutions adopted in case of anomalies;

i. A description of the procedures for producing duplicates or copies;

j. the time frames within which the different types of digital objects must be transferred to preservation and, if necessary, discarded;

k. the regulations in force in the places where digital objects are stored.

The preservation process

The transfer of the storage object into the preservation system is done by generating a PdV in the manner and format prescribed by the preservation manual.

More specifically, the preservation process involves:

  1. The acquisition by the preservation system of the PdV for taking it over;

  2. Verification that the PdV and the digital objects contained therein are consistent with the methods set forth in the preservation manual and with what is indicated in Annex 2 "File Formats and Reversal" regarding formats;

  3. The rejection of the PdV, in case the checks referred to in (b) have revealed anomalies. The maximum number of rejections shall be established within a contract or agreement;

  4. The generation, also in an automatic manner, of the spill report relating to one or more spill packages, uniquely identified by the preservation system and containing a time reference, specified with reference to Coordinated Universal Time (UTC), and one or more imprints, calculated on the entire contents of the spill package, in the manner described in the preservation manual;

  5. the signing of the deposit report with a digital signature or qualified or advanced electronic signature affixed by the preservation manager or the person in charge of the preservation service, where provided for in the preservation manual;

  6. the preparation, signing with digital signature or electronic signature - qualified or advanced - of the person in charge of preservation or the person in charge of the preservation service or with the electronic seal - qualified or advanced - affixed by the external preserver, as well as the management of the storage package on the basis of the data structure specifications indicated by the UNI 11386 standard and according to the methods given in the preservation manual;

  7. for the purpose of user-requested performance, the preparation and signing with a digital signature or qualified or advanced electronic signature of the preservation officer or the preservation service manager, or the affixing of the qualified or advanced electronic seal, in the manner specified in the preservation manual, of distribution packages that may contain part, one, or more storage packages;

  8. for the sole purpose of interoperability between preservation systems, the production of distribution packets coincident with archiving packets or otherwise containing archiving packets generated on the basis of the data structure specifications indicated by the UNI 11386 standard and in accordance with the procedures set out in the preservation manual;

  9. The production of computer duplicates or computer copies made at the request of users in accordance with the provisions of these guidelines;

  1. The production of computer copies by means of reversion activities in order to adapt the format to the preservation needs of readability over time according to the guidance provided in Annex 2 "File Formats and Reversion."

  2. the eventual discarding of the storage package from the preservation system upon expiration of the preservation terms prescribed by the standard or as indicated by the preservation plan of the Preservation Object Holder and the procedures described in Section 4.12 below.

In the case of outsourcing the preservation service to a third party, the relevant modalities may be specified in the manuals of the Owner of the object of preservation and the preserver and agreed upon between the parties.

You might be interested in
New Rules Effective 1 May 2022 on Covid Restrictions
23 May 2022
The "Aid bis" decree and the new extensions on smart working
October 5, 2022
Civil cassation, sec. labor, Sept. 6, 2022 No. 26246
September 16, 2022
Legislative Decree June 27, 2022 No. 104 and the new transparency obligations on working conditions
September 2, 2022