← Back to blog
Business & Legal

eIDAS Qualified Timestamps vs Free Timestamps: What the Difference Means for Evidence

By Provlyn·29 July 2026

A free timestamp proves a file existed at a point in time. An eIDAS qualified timestamp carries a legal presumption of accuracy across 27 EU member states. Neither, on its own, produces an immutable evidential record.

How Timestamping Works — the Process Most People Never See

When a file is timestamped, the process is sequential and automatic. The file is first reduced to a unique cryptographic fingerprint using SHA-256 — a one-way function that produces a fixed-length string from any input. Change a single byte of the file and the fingerprint changes entirely. The original file never leaves the user's control. Only the fingerprint is transmitted.

The fingerprint is submitted to a Time Stamping Authority (TSA), which operates under RFC 3161 — an internationally recognised standard published by the Internet Engineering Task Force. The TSA binds the fingerprint to a precise moment in time and returns a cryptographically signed token. That token is the timestamp. It proves that the fingerprint — and therefore the file it represents — existed at that specific moment.

The timestamp token is then anchored to the Bitcoin blockchain via OpenTimestamps. The fingerprint is written to a permanent, public, decentralised ledger that does not depend on any single provider's continued operation. The blockchain record is independently verifiable by anyone, indefinitely.

This entire chain — hash, timestamp, blockchain anchor — is a single automated process. Each step depends on the output of the preceding one. There is no manual intervention, no separate action the user must take. A file goes in and a timestamped, blockchain-anchored record comes out.

The standard matters because the alternative is substantially weaker. File system timestamps reflect activity on a specific device and can be altered. Email headers record when a message was processed by a mail server, not when the attached file was created. Platform metadata depends on the vendor’s own attestation. In the United States, 1,203 federal trade secret cases were filed in 2023, according to the Lex Machina 2024 Trade Secret Litigation Report. Across that body of litigation, the question of when a file existed in a specific form was consistently among the first factual disputes to be resolved.

None of this is proprietary. SHA-256 is a public standard maintained by the National Institute of Standards and Technology. RFC 3161 timestamps are available from dozens of TSAs, including free services. OpenTimestamps is open-source software.

The question is not whether the process works. It does. The question is what the timestamp means in a legal context, and whether a timestamp alone — however well-produced — constitutes the evidential record a dispute requires.

What an eIDAS Qualified Timestamp Adds — and What Changes Legally

An eIDAS qualified timestamp differs from a free timestamp in one critical respect: it carries a legal presumption of accuracy under EU law, shifting the burden of proof from the holder to the party challenging the record. The EU eIDAS Regulation (910/2014) draws the specific line between electronic timestamps generally and qualified electronic timestamps issued by Qualified Trust Service Providers (QTSPs).

Article 41(1) establishes that any electronic timestamp — qualified or not — cannot be denied legal effect solely because it is in electronic form. A free RFC 3161 timestamp is admissible as evidence in EU courts. It is technically sound. It is not, however, presumed accurate. The holder must establish the TSA's reliability, the time source's accuracy, and the soundness of the process. In a contested dispute, that means expert testimony, technical argument, and cost.

Article 41(2) changes the position. A qualified electronic timestamp carries a legal presumption of accuracy as to the date and time it records, and of the integrity of the data to which that date and time are bound. The court assumes accuracy. The party challenging the timestamp bears the burden of rebuttal. That reversal of the burden is the practical difference between a free timestamp and a qualified one — not the technology, which is substantially the same, but the legal standing the qualification confers.

To qualify under eIDAS Article 42, the timestamp must bind date and time to data in a manner that reasonably precludes undetectable alteration, be based on an accurate time source linked to Coordinated Universal Time, and be signed with an advanced electronic signature or seal of the QTSP. The QTSP itself must be listed on its member state's national Trusted List, audited by a Conformity Assessment Body, and supervised by the national supervisory authority. The EU maintains a consolidated Trusted List identifying more than 200 active QTSPs across member states.

Under UK law, eIDAS-qualified certificates are treated as strong electronic evidence. In the United States, Federal Rule of Evidence 901 provides for the admissibility of electronic records where integrity is established through a documented, reproducible process — a standard a qualified certificate meets more readily than a free timestamp, though the US has no direct statutory equivalent to the eIDAS presumption.

The eIDAS qualification is materially valuable. It is also, on its own, a timestamp — a record that a specific fingerprint existed at a specific moment. The question a dispute asks is broader than timing alone.

Where a Timestamp Stops — Even an eIDAS Qualified Timestamp

Even an eIDAS qualified timestamp has specific limitations that most users do not consider. A timestamp — free or qualified — answers one question: when did this fingerprint exist? In a real dispute, the questions multiply.

The first is versioning. A single timestamp proves a single file existed at a single moment. A business that creates, revises, and circulates documents over weeks or months needs a record of every version — not just the final one. A timestamp of the executed version does not prove what earlier versions contained, who reviewed them, or when each revision was made.

The second is controlled sharing. A timestamp proves when a file existed. It does not prove who received the file, under what conditions, or what version each recipient saw. When the dispute turns on what was disclosed to a specific party — an investor, a client, a counterparty — the timestamp answers the wrong question.

The third is access and attribution. A timestamp does not record who accessed the file after it was shared, whether it was downloaded or forwarded beyond its intended distribution. In disputes involving leaked confidential information or unauthorised distribution, the question is not when the file existed but who saw it and when.

The fourth is watermarking and leak attribution. If a confidential document appears outside its intended distribution, the question is which recipient's copy was the source. A timestamp of the original file does not answer that question. A per-recipient watermark — itself separately hashed and timestamped — creates a distinct, traceable record for each copy.

Consider what this means in practice. A consultancy sends a proprietary strategy document to three prospective clients. Six months later, the methodology appears in a competitor’s public materials. The consultancy can prove the document existed before the competitor’s publication — a timestamp establishes the date. What the consultancy cannot prove from a timestamp alone is which of the three recipients’ copies was the source, and when each recipient accessed the document. Those are the questions that determine the outcome. Those are the questions the infrastructure around the timestamp is designed to answer.

The EUIPO's 2023 Trade Secrets Litigation Trends report analysed 695 judicial proceedings across EU member states between 2017 and 2022. Across that body of litigation, the challenges claimants faced extended well beyond proving when something existed. They included proving what was disclosed, to whom, in what version, and whether the record had persisted in verifiable form. A timestamp — even a qualified one — addresses the first of those challenges. The infrastructure around the timestamp is what addresses the rest.

What a Complete Evidential Infrastructure Looks Like

The timestamp is the foundation. What determines whether a business has a defensible evidential record is what is built on top of that foundation.

A deposit process that automatically hashes, timestamps, and blockchain-anchors every file on creation is the starting point. That process produces a single portable certificate — a downloadable PDF recording the file name, the SHA-256 fingerprint, the RFC 3161 timestamp, and the blockchain anchor — which can be produced in court without reference to the platform that generated the record.

Versioning means every revision of every document is independently deposited. Each version carries its own certificate, its own timestamp, its own blockchain anchor. The full version history of a document is not reconstructed from email threads or platform logs — it is assembled from a sequence of independently anchored records, each made at the moment that version existed.

Controlled sharing means every recipient interaction is recorded. When a document is shared, the access event — who received access, to what file, at what time — is logged and anchored through a daily timestamping process. The access log is not held on a single platform's infrastructure as an unverified assertion. Each day's access record is anchored using the same eIDAS-qualified timestamping chain as the deposits — meaning the record of who accessed what, and when, carries the same legal presumption of accuracy as the deposit certificate itself.

Watermarking means every shared copy is individually traceable. Each recipient receives a copy with an invisible per-recipient watermark, and each watermarked copy is separately hashed and timestamped. If the document appears outside its intended distribution, the watermark identifies which copy was the source — and the timestamp on that specific copy establishes when it was created and shared.

The eIDAS Article 41 qualification applies to the timestamps within this infrastructure — adding legal presumption to the timing record for users who need it in EU jurisdictions. It is an optional layer that elevates the legal standing of the underlying process. It does not change what the process does. It changes how a court treats the output.

The result is an infrastructure where every document event — creation, revision, sharing, access, watermarked distribution — produces its own independently anchored record. The evidential picture is not a single timestamp proving a single file existed at a single moment. It is a complete, interconnected history of what was created, how it changed, who received each version, and what happened after sharing. That history is assembled from records made at the time of each event, not reconstructed after a dispute arises.

The 1,203 federal trade secret cases filed in the US in 2023 illustrate the point. The questions those cases turned on — what existed, who received what, in what version, and when — are not answered by a timestamp alone. They are answered by an infrastructure that applies the timestamping process systematically to every interaction a document has.

Why This Matters in Practice

The question a business should ask when evaluating timestamping services is not whether the timestamp is qualified — it is whether the entire document lifecycle is anchored. The timestamp is one record. What a dispute requires is a system of records — covering creation, versioning, sharing, access, and attribution — each independently anchored, each portable, each verifiable without reference to the platform that produced the record.

A free timestamp from an unaccredited TSA is technically sound but carries no legal presumption. A qualified timestamp from an accredited QTSP carries legal presumption but is still a single record of a single file at a single moment. A complete evidential infrastructure applies the timestamping chain — hash, timestamp, blockchain anchor — to every document event, assembles each record into a portable certificate, and optionally elevates the legal standing through eIDAS qualification.

The 27 per cent success rate for EU trade secret claims identified by the EUIPO reflects not a failure of timestamping technology but the broader evidential burden on claimants who must prove what existed, who received what, in what version, and when — questions that a timestamp alone, however well-qualified, does not answer.

The timestamp is the foundation. The infrastructure built on top of the timestamp — versioning, controlled sharing, access anchoring, watermarked distribution, portable certificates, and optional eIDAS qualification — determines whether the record holds up in a dispute.

This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.

Related Reading

eIDAS Regulation — EUR-Lex Official Text

Enforcement Insurance for Intellectual Property Assets — IRMI Expert Commentary

The Evidence Your IP Insurance Policy Assumes You Already Have

James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com