Compliance
Last updated: 11 July 2026
Here is where Squigggle stands on the legal and security frameworks that matter for an electronic-signature service. We believe in being transparent — including about what we are still working towards.
Frameworks
Electronic signatures (UK Electronic Communications Act 2000; UK & EU eIDAS)
Compliant — our signatures are designed to be legally effective under these frameworks. See our Signature Levels page.
UK GDPR & Data Protection Act 2018
Compliant.
EU GDPR
Compliant to the extent it applies to our processing.
PECR & the Data (Use and Access) Act 2025
Compliant.
International data transfers
Safeguarded using the UK IDTA/Addendum and the EU Standard Contractual Clauses.
Cyber Essentials (UK Government scheme)
Certified — we hold a current Cyber Essentials certificate (number 5dbdde12-a374-41ab-9347-99a5b3c70dbd).
ISO 27001 (information security)
Aligned — our security programme follows the ISO 27001 framework. Not yet certified; certification planned as we grow.
SOC 2
Aligned — our controls are designed around the SOC 2 Trust Services Criteria. We do not currently hold a SOC 2 report; we intend to obtain one as we grow.
Accessibility (WCAG 2.2 AA)
Aligned — we design Squigggle to conform to WCAG 2.2 Level AA. See our Accessibility Statement.
Building our programme
As a growing company, we are building our formal compliance and certification programme. We will update this page as we reach new milestones. For any compliance or due-diligence questions, contact privacy@squigggle.io.
Document control
- Version 2.0 — 11 July 2026 (current version)