Data Authenticity Clauses: What B2B Contracts Now Require
For years, the authenticity of a piece of data was a problem that surfaced only in court, when someone questioned a photograph or a report and an expert had to reassemble the pieces. Data authenticity clauses are changing that pattern. Tender specifications, supply agreements and vendor qualification questionnaires increasingly ask that the evidence a supplier produces be independently verifiable, not simply asserted in good faith.
The shift is quiet but structural. The burden of proof moves from the moment of dispute to the moment of signature, and a supplier who cannot meet the requirement does not lose a case: they lose the contract, or the qualification. The difficulty is that almost no business process was designed to produce verifiable evidence. Service reports, progress photographs, training records and handover minutes are built for internal use, and they become debatable the instant someone decides to debate them.
The answer is not another document in the chain. It is certifying evidence at the moment it is created, so that its authenticity never has to be reconstructed afterwards. This article covers what these clauses actually require, where the pressure comes from, why ordinary processes fail the test, and how to respond without rebuilding the organisation.
What a data authenticity clause actually requires
A data authenticity clause requires that information produced by one party can be checked by a third party without having to trust the party that produced it. It is not about quality of work or good faith. It is about the ability to establish, years later, that a given piece of content existed in that form, at that time, in that place.
Evidence is verifiable when its origin, its date and its integrity can be checked by an independent party through technical elements, without relying on a statement from whoever produced it. The European eIDAS Regulation (Regulation EU 910/2014) defines two instruments designed for exactly this purpose: the qualified electronic time stamp, which carries a presumption of accuracy of the date and time it indicates, and the qualified electronic seal, which carries a presumption of integrity of the data and of correctness of its origin. In both cases the presumption operates in favour of the party producing the evidence: the counterparty has to prove otherwise, not the reverse. That is the difference between data you have to defend and data that defends itself.
Asserted data and verifiable data
Asserted data is a statement: the supplier says the photograph was taken on 12 March at that site. Verifiable data is a statement accompanied by elements anyone else can check independently. In the first case, a challenge opens a technical assessment. In the second, the challenge closes in minutes.
The distinction has immediate commercial consequences. In most European legal systems, digital reproductions carry full evidentiary weight only until the party they are used against denies them. Denial is cheap and easy. Overcoming denial without supporting technical elements is expensive and slow. That gap is precisely what a verifiability clause is written to close in advance.
Where these requirements are appearing
The wording varies but the core is constant. Tender specifications ask for photographic documentation with verifiable date and location. Supply agreements impose obligations to retain non alterable records of the work performed. Vendor qualification questionnaires ask about the non repudiability of training registers and periodic checks. None of these requests names a technology. They name an outcome.
Why the burden of proof moved from dispute to signature
The pressure did not start in legal departments. It started with European regulation, which over the past two years has stopped asking companies what they declare and started asking what they can demonstrate. When an obligation of that kind lands on a large company, it is passed down the supply chain in the simplest available form: a clause.
The digital product passport and certified measurements
The European ecodesign regulation (Regulation EU 2024/1781, known as ESPR) introduces the digital product passport: a structured set of information attached to each product and reachable through a unique data carrier, typically a QR code. Under the framework the regulation sets out, the scheme becomes operational from 19 July 2026. The passport collects measurements covering carbon footprint, repairability, the presence of substances on the REACH SVHC list, and the share of secondary raw materials.
The relevant point here is evidentiary rather than environmental. Those measurements are not generated by the final manufacturer. They arrive from the supply chain, usually as test reports and declarations of conformity, and whoever receives them has to stand behind them in front of a market surveillance authority. That is why the demand for checkable data travels down the chain long before any penalty does.
Regulated supply chains, where geolocation becomes a supply obligation
The clearest case is the European deforestation free products regulation (Regulation EU 2023/1115). Obligations became binding on 30 December 2025 for medium and large companies, and on 30 June 2026 for small and micro enterprises. Operators placing the covered commodities on the market must collect the geolocation coordinates of every plot of land where the raw material was produced or harvested, and file a due diligence statement through the dedicated European registry. The Commission opened a testing phase for GeoJSON files specifically to handle the volume of geographic data involved.
A coordinate typed into a spreadsheet and a coordinate captured and sealed at the moment of the survey are not the same thing, and the difference shows up at the first inspection. Buyers sourcing from outside the European Union know this, and they translate it into a contractual clause on the verifiability of origin data. The same mechanism already visible in food traceability and origin fraud is now reaching timber, cocoa, coffee, soy and rubber.
Public procurement, where traceability became a principle
Public buyers are moving in the same direction. Across the European Union, procurement procedures have been digitalised end to end, and traceability of the activities performed, accessibility of the data and knowability of automated decision processes are increasingly written as governing principles rather than optional features. Principles drafted in those terms do not stay in the statute. They become specification requirements for whoever performs the work, as already happens with certified evidence in digital public procurement.
There is also a counter movement worth reading carefully. The European simplification package known as Omnibus I, enacted as Directive (EU) 2026/470 and published in the Official Journal on 26 February 2026, in force since 18 March 2026, cut the scope of sustainability reporting obligations by more than 90 per cent, raising the threshold to companies above 1,000 employees and 450 million euro in net turnover. Fewer companies bound by law does not mean fewer requests. The large companies still inside the perimeter keep collecting data from suppliers, and they now do it by contract rather than by direct regulatory duty. For a mid sized supplier the practical effect is identical.
Why ordinary business processes fail the test
The reason is mundane, which is why it is rarely addressed: those documents were built for internal use. A service report exists to support an invoice, not to be defended three years later. A progress photograph exists for the site manager, not for a court appointed expert. Verifiability was never a design requirement, and it cannot be added retroactively.
The three points where evidence weakens
| Stage | What happens to the data | What the counterparty challenges |
|---|---|---|
| Capture | The shot is taken on a technician's phone, with no verifiable reference to date and location | That the photograph was taken at a different time or a different site |
| Transfer | The file travels through messaging apps, gets recompressed and loses its original metadata | That the delivered file matches what was actually captured on site |
| Storage | The image ends up in a shared folder that several users can edit | That nobody replaced or retouched it before delivery |
The first stage is decisive. Data that is born verifiable survives the other two without losing value, because every later copy can be compared against the original fingerprint. Data born ordinary never recovers: a chain of custody can be documented going forward, but it cannot be rebuilt backwards. This is the principle behind ISO/IEC 27037, which concentrates its strictest requirements on identification and acquisition rather than on later handling.
What certified at source evidence is
Certified at source evidence is digital content that receives, at the exact moment of capture, the technical elements that fix its date, its location and its integrity, before it can be copied, shared or filed. Certification is not applied to an existing file: it is created together with the file. TrueScreen is the platform that makes this possible, integrating through API the electronic seal and the time stamp issued by third party qualified trust service providers, and returning a technical report with the cryptographic fingerprint of the content for every capture. The result is that a supplier facing a verifiability clause does not have to prove they are trustworthy. They deliver evidence that verifies itself, using the same tools an independent expert would use.
Qualified time stamps and integrity seals
A qualified electronic time stamp fixes the exact moment the content was captured, with the presumption of accuracy eIDAS provides. The integrity seal binds that moment to the cryptographic fingerprint of the file: if a single bit changes, the fingerprint no longer matches and tampering becomes evident. These are two distinct functions, and contract language should keep them separate, because they answer different questions: when, and what.
One frequent drafting error is worth flagging. A digital signature is used to sign a document and to identify the person signing it. A digital seal certifies the integrity and origin of content such as a photograph, a video, a message or a web page. It identifies no person, but guarantees the content has not been altered since capture. A clause about photographic documentation needs the second, not the first, and a supplier asked for the wrong instrument ends up producing signed documents that say nothing about the authenticity of the evidence inside them.
A chain of custody that survives the years
Challenges do not arrive while memories are fresh. They arrive two or three years later, when the technician who performed the survey has moved on and nobody remembers which phone took the photograph. A certified digital chain of custody makes that memory irrelevant, because every step is documented technically rather than through testimony.
Two examples: the site specification and the qualification questionnaire
A specification requires photographic documentation of progress stages with verifiable date and location. The answer is not a signature on a monthly summary. It is certifying each capture as it happens, the way it works in construction draw inspections with legally valid photo reports. The monthly summary still exists, but it becomes a recap of already solid evidence rather than the only thing holding the file together.
A qualification questionnaire asks for non repudiable proof that staff training took place. The answer is not a register signed at the end of the course, which only proves somebody signed a sheet of paper. It is the certified capture of sessions, materials and assessments, following the same logic applied to test reports and measurement data provenance.
Reading your own clauses before clients impose them
For once the advantage sits with whoever moves first. A supplier arriving at a tender with a certification process already running satisfies the clause without renegotiating anything and without extraordinary cost. A supplier who discovers the requirement while preparing the bid ends up promising something they will have to build during performance, with the timing and risk that implies. It is the same reasoning that makes data authenticity a competitive advantage rather than a cost of conformity.
Four questions to ask before bidding
They are best answered by reading the specification through the eyes of whoever will have to defend the work three years from now. What evidence does this contract oblige me to produce? Who will challenge it, and with what interest? Does the current process produce that evidence in a form a third party can check, or only in a form I assert? And if the answer is the second, what does it cost to change it before signature compared with discovering it afterwards?
Whoever drafts contracts from the other side of the table has one question fewer and one responsibility more: making sure the clause asks for a verifiable outcome rather than a named technology. A clause that names a tool ages in two years. A clause that requires the evidence to be verifiable stays valid for as long as the contract does.

