Civil Law And Virtual Legal Identity Authentication Disputes In Europe .

Civil Law and Virtual Legal Identity Authentication Disputes in Europe

1. Introduction

Virtual legal identity authentication concerns the processes by which a person's identity, legal capacity, authority, or signature is established in a digital environment.

Examples include:

electronic identification systems;

digital identity wallets;

electronic signatures;

remote customer identification;

online notarisation;

digital banking authentication;

government e-ID systems;

biometric authentication;

authentication through digital certificates;

identity verification for online contracts;

corporate digital-authority verification;

authentication of lawyers, directors, shareholders and representatives;

remote execution of commercial agreements.

A civil dispute can arise when an online system incorrectly identifies a person, accepts a fraudulent identity, rejects a genuine identity, or processes excessive identity information.

The legal issues can involve:

contract law + electronic-signature law + identity fraud + data protection + tort/delict + consumer law + company law + evidence law + private international law.

A particularly important European distinction is between:

identification — determining who a person is;

and

authentication — determining whether the person attempting to act is genuinely the person identified.

A third concept is:

legal attribution — determining whether an electronically performed act, such as signing a contract, can legally be attributed to that person.

2. What Is a Virtual Legal Identity?

A virtual legal identity is the digital representation through which an individual or organization can be recognized for legal or commercial purposes.

It can contain or be associated with:

name;

date of birth;

nationality;

address;

identification number;

digital certificate;

public/private cryptographic keys;

biometric information;

electronic signature;

authentication credentials;

corporate authority;

professional status.

For example, a company director may use a qualified electronic signature to execute a €10 million financing agreement.

The legal question is not simply:

"Was the signature technically valid?"

It may also be:

"Was the person actually the director?"

"Did the director have authority?"

"Was the authentication credential compromised?"

"Did the counterparty reasonably rely upon the authentication?"

"Who bears the loss if the identity system failed?"

3. Why Identity Authentication Creates Civil Disputes

Digital identity systems create a chain of legal relationships.

For example:

Person → identity provider → platform → bank → counterparty

A failure at any point can generate litigation.

Example

A fraudster obtains another person's digital credentials and signs a loan agreement.

The bank argues:

"The electronic authentication proves that the customer signed."

The customer argues:

"My credentials were stolen. I never authorized the transaction."

The resulting litigation may involve:

authenticity;

electronic-signature rules;

contractual formation;

negligence;

identity theft;

security obligations;

data protection;

unjust enrichment;

allocation of technological risk.

4. European Legal Framework

A. eIDAS Regulation

The central EU instrument is Regulation (EU) No 910/2014, commonly known as the eIDAS Regulation.

It regulates:

electronic identification;

trust services;

electronic signatures;

electronic seals;

electronic timestamps;

electronic documents;

website authentication.

The Regulation distinguishes between:

Electronic signature

Data attached to or logically associated with other electronic data and used by a person to sign.

Advanced electronic signature

Provides stronger identity and integrity guarantees.

Qualified electronic signature

An advanced electronic signature satisfying specified regulatory requirements and created using a qualified signature-creation device/certificate.

A qualified electronic signature receives particularly strong legal recognition.

5. Civil-Law Importance of Electronic Signatures

A major principle is:

An electronic signature cannot simply be denied legal effect merely because it is electronic.

But this does not mean that every electronic action proves the identity of the person who performed it.

This distinction is critical.

Example

Someone types:

"John Smith"

at the bottom of an email.

That is evidence of an electronic act, but it does not necessarily establish:

John Smith's identity;

his intention;

his authority;

the integrity of the document.

A qualified electronic signature provides much stronger evidence.

6. Identification, Authentication and Authorization

These should be treated separately.

Identification

"Who are you?"

Authentication

"Can you demonstrate that you are that person?"

Authorization

"Are you legally entitled to perform this particular act?"

Example

A person successfully logs into a company's digital banking system.

Authentication establishes that the person possesses the relevant credentials.

But it does not necessarily establish that the person was authorized to:

transfer €20 million to another company.

Thus:

authentication ≠ authorization.

7. GDPR and Digital Identity

Virtual identity systems process substantial personal data.

Relevant information may include:

identity documents;

facial images;

fingerprints;

voice recordings;

addresses;

identification numbers;

authentication logs;

IP addresses;

device identifiers;

transaction histories.

The GDPR imposes requirements concerning:

lawfulness;

fairness;

transparency;

purpose limitation;

data minimization;

accuracy;

storage limitation;

security;

accountability.

Biometric authentication can be particularly sensitive because biometric data used for uniquely identifying a person can fall within Article 9 GDPR.

8. Biometric Authentication

Biometric authentication includes:

facial recognition;

fingerprint recognition;

iris recognition;

voice recognition.

It can improve security but creates serious civil-law risks.

False rejection

A genuine person is incorrectly denied access.

False acceptance

A fraudster is incorrectly recognized as the genuine person.

Excessive collection

A service collects biometric data when less intrusive authentication would suffice.

Security breach

Biometric templates are stolen.

The final problem is particularly serious because:

A password can be changed; a person's face or fingerprint cannot simply be replaced.

9. Electronic Identification Under eIDAS

The eIDAS framework also concerns electronic identification schemes used for access to public services.

Cross-border recognition can therefore become relevant.

For example:

A person using an electronic identification mechanism issued in one EU Member State seeks to access a public service in another Member State.

Disputes may arise concerning:

recognition;

authentication;

identity attributes;

interoperability;

liability;

security;

refusal of access.

10. Civil-Law Categories of Virtual Identity Disputes

10.1 Identity Theft

A fraudster impersonates another person.

Potential claims include:

declaration of non-liability;

cancellation/rescission;

restitution;

damages;

injunction;

correction of records.

10.2 Unauthorized Electronic Contract

A person denies having electronically concluded a contract.

The court may examine:

authentication method;

electronic signature;

device logs;

IP information;

timestamps;

two-factor authentication;

certificate records;

correspondence;

surrounding circumstances.

10.3 Fraudulent Digital Signature

A fraudster obtains or misuses another person's signing credentials.

The dispute may concern whether:

the signature belongs to the alleged signatory;

the certificate was valid;

the signing device was controlled by the signatory;

the certificate was revoked;

the counterparty reasonably relied upon it.

10.4 Corporate Identity Fraud

A person falsely represents themselves as:

company director;

shareholder;

attorney;

beneficial owner;

corporate secretary.

This can result in disputes concerning:

share transfers;

financing agreements;

corporate resolutions;

bank transactions;

property sales;

mergers and acquisitions.

11. Important European Case Law

There is an important qualification:

European reported case law specifically labelled "virtual legal identity authentication" remains relatively limited.

Consequently, the most useful authorities come from closely connected areas: electronic identity, biometric identification, data protection, digital authentication, electronic communications and privacy.

The following cases provide a strong European legal foundation.

12. Case 1 — Schwarz v Stadt Bochum

CJEU, Case C-291/12, 2013

Facts

The case concerned the inclusion of fingerprints in biometric passports.

The applicant challenged the requirement involving fingerprints.

Issue

Whether collecting fingerprints for passports was compatible with EU fundamental rights.

Decision

The CJEU upheld the measure, finding that fingerprint collection could be justified by the objective of preventing fraudulent use of passports and combating identity fraud, subject to appropriate safeguards.

Importance for virtual identity

This is a foundational authority for the principle that:

Biometric authentication can constitute a legitimate means of preventing identity fraud, but it must operate within legal safeguards.

The case is directly relevant to digital identity systems using biometric verification.

It also demonstrates the balancing exercise between:

identity security ↔ privacy and personal-data protection.

13. Case 2 — Willems and Others

CJEU, Joined Cases C-446/12 to C-449/12, 2014

Facts

The proceedings concerned the use of fingerprints in passports and related questions concerning the processing of biometric information.

Importance

The Court addressed issues surrounding the use and storage of biometric information in identity documents.

Relevance

The case is significant because digital identity authentication often involves the same technological architecture:

identity document → biometric information → authentication → access to legal service.

The case supports the proposition that biometric identity verification must have a sufficiently defined legal basis and appropriate safeguards.

14. Case 3 — Breyer v Germany

CJEU, Case C-582/14, 2016

Facts

Mr Breyer's dynamic IP address was recorded when he accessed German websites.

The dispute concerned whether such information could constitute personal data and the circumstances in which it could be processed.

Decision

The CJEU interpreted the concept of personal data broadly.

Importance for virtual identity

Digital authentication frequently produces:

IP addresses;

device identifiers;

login records;

timestamps.

These data can contribute to identifying or distinguishing a user.

Breyer therefore demonstrates that:

Digital identifiers cannot automatically be treated as anonymous merely because they do not directly display a person's name.

This is highly relevant in authentication disputes.

15. Case 4 — Nowak v Data Protection Commissioner

CJEU, Case C-434/16, 2017

Facts

Mr Nowak sought access to information connected with an examination.

The dispute concerned the meaning of "personal data."

Decision

The CJEU adopted a broad interpretation of personal data.

Information can constitute personal data where it is related to an identifiable person.

Importance for digital identity

Authentication systems generate extensive information about an individual.

For example:

authentication attempts;

verification results;

security assessments;

identity attributes;

transaction records.

Nowak supports the principle that such information can fall within data-protection rights when sufficiently connected to an identifiable individual.

16. Case 5 — Wirtschaftsakademie Schleswig-Holstein

CJEU, Case C-210/16, 2018

Facts

The dispute involved a Facebook fan page administrator and the processing of visitors' personal data.

Decision

The CJEU held that the administrator could have responsibility concerning processing carried out through the page, despite Facebook operating the underlying platform.

Importance for virtual identity

This is important because identity authentication frequently involves multiple actors.

For example:

identity provider → platform → merchant → analytics provider

A company cannot necessarily argue:

"The technology was operated by somebody else, therefore I have no responsibility."

Responsibility may be distributed according to the actual processing activities.

17. Case 6 — Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW

CJEU, Case C-40/17, 2019

Facts

Fashion ID embedded a Facebook "Like" button on its website.

The integration could result in personal data being transmitted to Facebook.

Decision

The CJEU examined joint responsibility for certain stages of processing.

Importance for authentication

The case is important for understanding multi-party digital identity ecosystems.

An authentication system may involve:

the website;

identity provider;

social-login provider;

analytics provider;

cloud infrastructure.

The legal responsibility of each participant must be examined rather than assuming that only the final service provider is responsible.

18. Case 7 — Orange România SA v Autoritatea Națională de Supraveghere

CJEU, Case C-61/19, 2020

Facts

The case concerned consent for processing personal data in connection with telecommunications contracts.

The CJEU examined whether consent could genuinely be considered freely given and informed.

Importance for digital identity

Identity systems often ask users to consent to extensive processing.

For example:

"To verify your identity, we will collect your face, ID document, location, device information and transaction history."

A company cannot necessarily assume that clicking "I agree" makes all subsequent processing lawful.

The legal validity of consent depends upon the requirements of EU data-protection law.

19. Case 8 — Österreichische Post AG

CJEU, Case C-300/21, 2023

Subject

The case concerned compensation under Article 82 GDPR.

Importance

The Court addressed the relationship between:

unlawful data processing;

damage;

causation;

compensation.

This matters in identity-authentication disputes because an unlawful identity-verification process does not automatically answer the separate question of what compensation is recoverable.

A claimant must establish the legally relevant elements of the compensation claim.

20. Case 9 — S. and Marper v United Kingdom

ECtHR, 2008

Facts

The United Kingdom retained fingerprints, cellular samples and DNA profiles of individuals whose criminal proceedings had ended without conviction.

Decision

The ECtHR found a violation of Article 8.

Importance

The case is extremely important for biometric identity systems.

It establishes that:

The collection and retention of biometric information can seriously interfere with private life.

In virtual authentication, this principle applies to questions such as:

how long biometric information is retained;

whether it is reused;

who can access it;

whether it can be shared with third parties.

21. Case 10 — Gaughran v United Kingdom

ECtHR, 2020

Facts

The applicant challenged indefinite retention of personal and biometric information following a criminal conviction.

Decision

The Court found an Article 8 violation.

Importance for virtual identity

The case reinforces the principle that even information initially collected for a legitimate identity or security purpose cannot necessarily be retained indefinitely.

This is particularly relevant to digital identity databases.

22. Case 11 — Glukhin v Russia

ECtHR, 2023

Facts

The applicant participated in a peaceful protest.

Authorities used facial-recognition technology to identify him.

Decision

The ECtHR found violations involving privacy and freedom of expression.

Importance

Glukhin is particularly significant for the modern digital-authentication environment.

It demonstrates the legal sensitivity of linking:

biometric identification → individual identity → political activity.

The case therefore provides an important warning against unrestricted technological identification.

23. Case 12 — Ryneš v Úřad pro ochranu osobních údajů

CJEU, Case C-212/13, 2014

Facts

A private individual operated a camera that recorded areas beyond his property.

Decision

The CJEU interpreted the household exemption narrowly.

Importance

Although not an electronic-signature case, Ryneš is important to identity verification because it demonstrates that supposedly "private" technological monitoring can become subject to data-protection law when it extends into public or third-party spheres.

24. Case-Law Comparison

CaseCourtPrincipal issueRelevance to virtual identity
SchwarzCJEUBiometric passportsBiometric authentication
WillemsCJEUFingerprints/identity documentsBiometric data safeguards
BreyerCJEUIP addressesDigital identification
NowakCJEUPersonal dataAuthentication records
WirtschaftsakademieCJEUSocial-media dataMulti-party responsibility
Fashion IDCJEUData transmissionIdentity ecosystem responsibility
Orange RomâniaCJEUConsentConsent to identity processing
Österreichische PostCJEUGDPR compensationCivil damages
S. and MarperECtHRDNA/fingerprint retentionBiometric privacy
GaughranECtHRRetention of biometric dataIdentity databases
GlukhinECtHRFacial recognitionDigital identification and rights
RynešCJEUVideo surveillanceTechnological monitoring

25. When Does Authentication Create a Valid Contract?

One of the most difficult civil-law questions is:

Does successful digital authentication prove contractual consent?

Not necessarily.

Courts may distinguish:

Identity

Was the account registered to the person?

Authentication

Did the authentication system recognize the user?

Intention

Did the person intend to conclude the contract?

Authority

Was the person authorized to act?

Integrity

Was the electronic document altered?

Attribution

Can the transaction legally be attributed to the alleged signatory?

All five may become disputed.

26. Example: Fraudulent Digital Loan

Suppose Alice has a digital banking account.

A criminal obtains:

her username;

password;

authentication token.

The criminal obtains a €100,000 loan electronically.

The bank argues:

"The authentication system confirmed Alice's identity."

Alice argues:

"I never applied for the loan."

The court might investigate:

how Alice was authenticated;

whether two-factor authentication was used;

whether the device was familiar;

whether the transaction was unusual;

whether the bank detected suspicious behavior;

whether credentials were compromised;

whether the electronic signature was qualified;

whether the bank complied with security obligations;

whether Alice was negligent;

whether the bank reasonably relied on the authentication.

This is a classic allocation-of-risk problem.

27. Liability of Identity Providers

An identity provider could potentially face civil liability where applicable law establishes:

contractual breach;

negligence;

inadequate security;

failure to follow regulatory requirements;

inaccurate identity verification;

unauthorized disclosure.

However, liability is not automatic merely because fraud occurred.

The claimant generally needs to establish the legal elements required by the relevant national law.

28. Liability of the User

The user may also bear responsibility.

For example, a person may:

deliberately share authentication credentials;

knowingly permit another person to use their identity;

ignore security warnings;

lose a signing device through serious negligence;

authorize a transaction and later deny it.

The precise effect depends upon the applicable legislation and contract.

29. Liability of the Platform

A platform may be liable where:

it failed to implement legally required security measures;

it misrepresented the reliability of authentication;

it processed identity information unlawfully;

it failed to protect personal data;

it breached contractual obligations.

Again, liability depends on the applicable legal regime.

30. Electronic Signatures and Evidentiary Value

In civil litigation, electronic authentication can become evidence.

Potential evidence includes:

certificate information;

audit trails;

timestamp;

IP address;

device information;

authentication logs;

SMS authentication records;

biometric verification records;

cryptographic signatures.

The court must determine what evidentiary weight should be assigned to each.

A qualified electronic signature generally provides a much stronger evidentiary position than a simple typed name.

31. Identity Errors

There are two fundamental categories.

False acceptance

The system authenticates the wrong person.

Example:

Fraudster passes facial recognition as the genuine account holder.

Potential consequences:

unauthorized contract;

financial loss;

identity theft;

damages.

False rejection

The system rejects the genuine person.

Example:

A facial-recognition system cannot recognize a genuine user and denies access to their bank account.

Potential consequences:

inability to transact;

breach of service contract;

economic loss;

discrimination concerns;

reputational harm.

32. Algorithmic Bias

Authentication systems can produce different error rates among populations.

Potential problems include:

facial-recognition accuracy;

language recognition;

accent recognition;

document verification;

automated fraud scoring.

Civil litigation may ask:

Was the system designed or operated with reasonable safeguards?

and:

Was the resulting treatment discriminatory?

33. Data Minimization

A particularly important GDPR principle is data minimization.

Suppose an online service merely needs to establish:

"The user is over 18."

It may not necessarily need to retain:

complete passport information;

exact date of birth;

home address;

passport number;

facial image.

A privacy-preserving system could provide only:

"Age requirement satisfied."

This concept is increasingly important in European digital identity architecture.

34. Digital Identity Wallets

The development of European digital identity wallets makes these issues even more important.

A digital wallet may allow users to present verified attributes such as:

identity;

age;

professional qualifications;

driving entitlement;

educational qualifications;

corporate authority.

The civil-law challenge becomes:

Who bears responsibility when an attribute is incorrect?

Potentially relevant actors include:

issuing authority;

wallet provider;

relying party;

identity provider;

certification authority.

35. Corporate Digital Identity

Virtual identity disputes are especially significant in corporate law.

Imagine a person digitally represents themselves as:

"Managing Director of XYZ GmbH."

They then electronically sign:

a loan;

share-transfer agreement;

guarantee;

property purchase;

merger agreement.

The authentication system may prove the person's identity but not necessarily their corporate authority.

Therefore:

authentication ≠ corporate authority.

A counterparty may need to verify:

company register;

board resolution;

power of attorney;

signing authority;

constitutional documents.

36. Virtual Notarisation

Some European legal transactions require special formalities.

A digital authentication system cannot automatically replace every statutory requirement.

For example, national law may require:

notarisation;

qualified signature;

official registration;

witnessed execution.

Consequently, a digitally authenticated agreement may still be legally defective if mandatory formalities were not satisfied.

37. Cross-Border Authentication

European identity systems create another problem:

A digital identity issued in Country A may be used to conclude a legal transaction in Country B.

Questions include:

Is the identity scheme recognized?

Which law governs the contract?

Which court has jurisdiction?

Is the electronic signature recognized?

What happens if the identity provider is located elsewhere?

Who bears liability for authentication failure?

EU rules on electronic identification and trust services seek to facilitate cross-border recognition, but civil disputes can still require application of national contract and liability law.

38. Private International Law

Cross-border disputes can involve:

Rome I

Potentially determines the law applicable to contractual obligations.

Rome II

May apply to certain non-contractual obligations.

Brussels I Recast

May determine jurisdiction and recognition/enforcement in relevant civil and commercial disputes.

GDPR

Provides its own framework concerning personal-data processing and certain jurisdictional/remedial questions.

39. Remedies in Civil Litigation

Possible remedies include:

Declaration

A court may declare that:

the claimant did not enter the contract;

the electronic signature was not attributable;

the identity verification was defective.

Rescission or avoidance

A contract obtained through fraud or identity theft may potentially be challenged under applicable national law.

Damages

Possible losses include:

financial loss;

transaction losses;

business interruption;

reputational damage;

qualifying non-material damage.

Injunction

A court may order:

cessation of processing;

correction of identity records;

deletion;

restoration of access;

prevention of disclosure.

40. Defences

A defendant may argue:

the authentication was valid;

the claimant controlled the authentication device;

the transaction was properly authorized;

security procedures were followed;

the claimant was negligent;

no legally compensable damage occurred;

causation has not been established;

the claimant consented to processing;

the disputed transaction was independently confirmed.

41. Burden of Proof

The burden of proof is particularly important.

A claimant saying:

"I did not sign this electronically"

may force the defendant to produce technical evidence concerning:

signature certificate;

authentication;

audit logs;

device records;

timestamps;

identity verification.

The exact allocation of evidentiary burdens differs among European jurisdictions.

Courts should also be cautious about treating technological records as infallible.

42. Hypothetical Civil Case

Facts

A German company, EuroTech GmbH, uses a qualified electronic signature system.

Its finance director's credentials are compromised.

A fraudster signs a €5 million financing agreement with a French bank.

The bank relies on the digital certificate.

EuroTech discovers the fraud and refuses to perform.

Issues

The court may have to determine:

Was the electronic signature technically valid?

Was the certificate still valid?

Who controlled the signature-creation device?

Was the director actually involved?

Was the credential compromised?

Did EuroTech adequately protect its credentials?

Did the bank conduct reasonable verification?

Was the bank entitled to rely upon the signature?

Which law governs the agreement?

Which court has jurisdiction?

This demonstrates why virtual identity authentication is both a technological and civil-law issue.

43. Key Difference Between Identity Fraud and Authentication Failure

These concepts should not be confused.

Identity fraud

Someone deliberately pretends to be another person.

Authentication failure

The technological system incorrectly confirms or rejects identity.

Credential compromise

The genuine person's authentication credentials are stolen.

Authorization failure

A genuine person is authenticated but lacks authority to perform the transaction.

Each can generate different causes of action.

44. Six Core Legal Principles

Principle 1 — Electronic acts can have full legal significance

An electronic transaction is not legally meaningless merely because it occurs online.

Principle 2 — Stronger authentication creates stronger evidence

Qualified electronic signatures generally provide stronger legal assurance than basic authentication.

Principle 3 — Authentication does not automatically prove authority

A person's identity and their legal power to act are separate questions.

Principle 4 — Biometric identity systems implicate privacy

Schwarz, Willems, S. and Marper, Gaughran and Glukhin demonstrate the importance of safeguards.

Principle 5 — Digital identifiers can be personal data

Breyer and Nowak demonstrate the broad approach to personal data.

Principle 6 — Liability may be distributed

Identity providers, platforms, relying parties and users may each have different responsibilities.

45. Consolidated Case-Law Table

No.CaseCourt/YearCentral contribution
1Schwarz v Stadt Bochum, C-291/12CJEU, 2013Biometric identity and fraud prevention
2Willems and Others, C-446/12 to C-449/12CJEU, 2014Fingerprints and identity documents
3Ryneš, C-212/13CJEU, 2014Technological surveillance and data protection
4Breyer, C-582/14CJEU, 2016IP addresses as personal data
5Nowak, C-434/16CJEU, 2017Broad concept of personal data
6Wirtschaftsakademie, C-210/16CJEU, 2018Responsibility in digital platforms
7Fashion ID, C-40/17CJEU, 2019Multi-party data-processing responsibility
8Orange România, C-61/19CJEU, 2020Consent for personal-data processing
9S. and Marper v UKECtHR, 2008Biometric data retention
10Gaughran v UKECtHR, 2020Long-term identity-data retention
11Glukhin v RussiaECtHR, 2023Facial recognition and fundamental rights
12Österreichische Post, C-300/21CJEU, 2023GDPR compensation

46. Conclusion

Virtual legal identity authentication disputes in Europe represent a rapidly developing area at the intersection of civil law, electronic commerce, data protection, technology regulation and fundamental rights.

The principal legal problem is not simply whether a person was "recognized" by a computer system. Courts must determine a much broader chain:

Identity → Authentication → Intention → Authorization → Attribution → Contract → Liability → Damage.

The eIDAS framework provides the principal European framework for electronic identification and trust services, while the GDPR regulates the extensive personal data generated by authentication systems.

The case law of Schwarz, Willems, Breyer, Nowak, Wirtschaftsakademie, Fashion ID, Orange România, S. and Marper, Gaughran and Glukhin demonstrates three central propositions.

First, European law recognizes the importance of reliable digital identity and authentication for combating fraud. Second, biometric and digital identification systems can seriously interfere with privacy and therefore require appropriate safeguards. Third, when authentication fails, civil liability depends upon the precise allocation of responsibility among the user, identity provider, platform, certification provider and relying party.

Accordingly, the most significant future civil disputes are likely to concern fraudulent electronic signatures, stolen digital identities, compromised authentication credentials, biometric misidentification, unauthorized contracts, corporate identity fraud, defective digital identity wallets, cross-border authentication, and compensation for unlawful processing of identity information.

LEAVE A COMMENT