Skip to main content

Compliance

Last updated: 11 July 2026

Here is where Squigggle stands on the legal and security frameworks that matter for an electronic-signature service. We believe in being transparent — including about what we are still working towards.

Frameworks

Electronic signatures (UK Electronic Communications Act 2000; UK & EU eIDAS)

Compliant — our signatures are designed to be legally effective under these frameworks. See our Signature Levels page.

UK GDPR & Data Protection Act 2018

Compliant.

EU GDPR

Compliant to the extent it applies to our processing.

PECR & the Data (Use and Access) Act 2025

Compliant.

International data transfers

Safeguarded using the UK IDTA/Addendum and the EU Standard Contractual Clauses.

Cyber Essentials (UK Government scheme)

Certified — we hold a current Cyber Essentials certificate (number 5dbdde12-a374-41ab-9347-99a5b3c70dbd).

ISO 27001 (information security)

Aligned — our security programme follows the ISO 27001 framework. Not yet certified; certification planned as we grow.

SOC 2

Aligned — our controls are designed around the SOC 2 Trust Services Criteria. We do not currently hold a SOC 2 report; we intend to obtain one as we grow.

Accessibility (WCAG 2.2 AA)

Aligned — we design Squigggle to conform to WCAG 2.2 Level AA. See our Accessibility Statement.

Building our programme

As a growing company, we are building our formal compliance and certification programme. We will update this page as we reach new milestones. For any compliance or due-diligence questions, contact privacy@squigggle.io.

Document control

  • Version 2.0 — 11 July 2026 (current version)