Daan van Tongeren
PDFen Team
You prove it by binding the file to an independent record of time that a third party can check, and by doing that before anyone disputes anything. In European practice the routes come down to two families: a record made by a public official, or an electronic timestamp calculated over the hash of the file. The date printed on the document, the properties panel on your laptop and the email you sent yourself are claims about time, not proof of it.
Key Takeaways
Admissibility is not your problem. Article 152 Rv allows evidence by any means and leaves the weighing to the court, so the contest is about persuasive force.
eIDAS separates two things that sound alike. Article 41(1) keeps any electronic timestamp from being refused merely for being electronic; article 41(2) gives only the qualified one a presumption of accuracy.
Ask any supplier two questions. Can the other side recompute this without you, and what is left of my proof if I stop paying?
Services that keep the evidence inside their own archive answer both questions badly.
A timestamp shows that data existed no later than that moment. It says nothing about who produced it, or whether the content is true.
Paper archives answered the existence question through custody and cataloguing, which works only as long as the institution holding the shelves stays intact.
eIDAS defines an electronic time stamp as data that binds other data to a particular time, "establishing evidence that the latter data existed at that time" (Regulation (EU) 910/2014, article 3(33)). Read that literally: the wording sets a ceiling, not a floor. Your file existed no later than that moment. Whether it existed earlier is a separate question, and the token is silent about it.
It is equally silent about authorship. Nothing in the definition speaks to who produced the document, whether anyone agreed to its contents, or whether those contents are true. Suppliers rarely say so out loud, and clients tend to assume the opposite.
The mechanics matter for privileged material. Under RFC 3161 the client sends only a hash, called the message imprint, and the authority returns a signed token carrying that same imprint, a serial number and the recorded time. Your document never leaves your office. That also explains the fragility: change one byte, re-export the file, convert the format, and the imprint stops matching.
Because it is a field, not a fact. Dates inside a PDF are ordinary values written by whichever program produced the file, editable in seconds, and the clock on that machine can be set to anything beforehand. We took that apart separately in can a PDF's creation date prove anything.
The legal consequence arrives faster than most people expect. Under article 159(2) Rv, a private deed whose signature is firmly denied produces no evidence at all until it is proven whose signature it is, and the Supreme Court held in April 2019 that the denying party need not substantiate the denial (ECLI:NL:HR:2019:572). That rule is about signatures rather than dates. The mechanism is the one you meet anyway: a bare denial costs the other side nothing and moves all the work to you.
There are seven or eight realistic options, depending on how you count. Of the Dutch and English pages ranking for this question that we read while preparing this piece, every comparison had been published by a supplier of one of the rows, ours included. The two columns that decide cases are usually the two nobody fills in. Can the opposing party recompute the proof without your supplier, and does the proof survive that supplier's disappearance?
Route | Recomputable without the supplier? | Presumption under art. 41(2)? | If the supplier disappears |
|---|---|---|---|
Notarial deed or bailiff's report | Not cryptographically, but a third party can return to the office that made it | No, this runs on national evidence law | The record stays with the office, independent of software |
Emailing the document to yourself | No, mailbox and headers are under your own control | No | Whatever your mail provider still holds, in a form you cannot prove |
WIPO PROOF token | Yes, with open source tools plus the certificate chain | Not claimed | Issuance ended in January 2022; issued tokens still verify |
Blockchain anchoring (OpenTimestamps, OriginStamp) | Yes, against the public chain, if the verifier can read one | No | The anchor stays public; you keep the proof file and the bytes |
RFC 3161 timestamp from an ordinary TSA | Yes, offline, with the token and the certificate chain | No | The token, if you archived the responder certificate |
Qualified timestamp from a QTSP | Yes, it is the same kind of token | Yes | The token, plus the Trusted List entry you saved at the time |
Acrobat document timestamping | Depends entirely on the authority behind it | Only if that authority is a qualified service | The token sits in the PDF and keeps verifying |
Web capture or archiving service | No, the proof is their statement and their archive | No | Usually nothing, once portal access ends |
Two notes on that table. Acrobat applies a timestamp, it does not issue one, so whether the result carries the article 41(2) presumption follows from the outside authority behind it and that service's Trusted List entry, never from the software you bought. Current prices sit on Adobe's own page, and what a reader displays afterwards is a different question again, unpicked in what makes an electronic timestamp qualified. Second, free public authorities are real. FreeTSA publishes a full openssl workflow at no cost, while Sectigo's public endpoint was built for code signing, which is why its FAQ asks you to pause between calls.
This is the question that separates a token from a testimonial. An RFC 3161 token is a signed structure holding the imprint, the time and the issuing certificate. A forensic expert or a court-appointed examiner can check it offline with openssl and the certificate chain, without an account, a licence or your goodwill.
One detail took us a while to get right on our own side. Validating a token against a root certificate that travelled in the same envelope is an integrity check wearing the costume of a trust check: anyone able to forge the token could forge the root beside it. The verifier has to fetch that root independently, which is why we leave ours out of the package on purpose.
Now hold the alternatives against the same standard. OriginStamp makes the strongest independence claim of the services we compared, stating that anyone can confirm a timestamp against the public blockchain with no account and no special software. OpenTimestamps is free, needs no registration, and its own homepage makes no claim about legal effect at all. Both are genuinely recomputable. Neither carries the eIDAS presumption.
WIPO PROOF is the cleanest test case available, because it actually happened. The World Intellectual Property Organization ended token generation on 31 January 2022, and its own page states that issued tokens remain verifiable indefinitely, through equivalent timestamping platforms or readily available open source utilities. The service is gone. The evidence is not.
Compare a model where the proof lives in a portal. Page Vault's FAQ documents that you keep access to your captures for seven days after you stop renewing, unless you pay to keep the account hibernated. Nothing dishonest is happening there, and their affidavit model demonstrably works in the courts it was designed for. But a litigation file may need to hold up for a decade, and a proof you rent comes with a maintenance schedule.
The design choice underneath is how long the record outlives the file. We keep the two on separate clocks: a proof record is a few hundred bytes and is kept for twenty years by default, while the document follows the ordinary retention period. Ask any supplier which of the two their price protects.
These are two different rewards, and vendor pages routinely garble the difference. Article 41(1) says an electronic time stamp may not be denied legal effect and admissibility as evidence "solely on the grounds that it is in an electronic form" or that it falls short of the qualified requirements. That covers every electronic timestamp, free ones included. It is a rule against exclusion, and in the Netherlands it adds little, since article 152 Rv already allows evidence by any means.
Article 41(2) is the sentence worth paying for. A qualified electronic time stamp "shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound" (article 41). The burden inverts: the party attacking the timestamp has to show it is wrong. Several ranking suppliers attribute this to article 42. That is the wrong article to cite in a submission, because article 42 holds the technical requirements rather than the legal effect.
Qualified status is also something you can check yourself, which is unusual in this field. Open the European Commission's EU Trusted List Browser, pick the country, filter on the timestamp service type and read the status. The machine readable list underneath is public at ec.europa.eu/tools/lotl/eu-lotl.xml.
It looks like a stalemate that nobody wins. On 4 February 2026 the Court of Appeal in The Hague ruled in a matrimonial property dispute in which two emails, from 2008 and 2014, were said by one party to have been altered after the fact (ECLI:NL:GHDHA:2026:180). An investigation report found strong indications that the emails were not authentic, or had at least been manipulated. The court still could not establish who had falsified anything.
Forensic examination was commissioned, it produced a substantive finding, and the case ended without a determination on the point. The evidence was not rejected. It simply could not carry the weight asked of it, eighteen years after the earlier of the two emails was sent. That is the realistic downside, and it is far more common than the version where a forgery gets exposed.
Whichever route you pick, the first step is the same and most people skip it: preserve the exact bytes. Every method here is anchored to a hash, and that hash changes the moment the file is re-saved or rewritten for an archive.
The risk is not theoretical. In ECLI:NL:RVS:2024:4237 the Council of State could not validate the electronic signature on a detention order. After signing, the file had been sent to the judiciary and converted there to a format for digital archiving, and the expert report records that this conversion damaged information in the part of the file where the signature sits. The same expert validated the signature in the original file without difficulty. A routine filing step produced the broken copy that reached the case file.
After that it is proportionality. One decisive document may warrant a notarial or bailiff's record. A stream of routine files that could be questioned years from now argues for a timestamp you can hand over together with the file. Recording the hash of an incoming document costs nothing and settles later arguments about whether it changed in your hands, which is all our fingerprint tool does.
It is better than nothing and considerably weaker than most people assume. The message sits in a mailbox you control, headers can be altered, and the other side has no independent way to check the file. In the 2026 Hague appeal above, disputed emails ended in a stalemate even after a forensic report.
Yes, and that is the uncomfortable part. Dates inside a PDF are ordinary fields that can be rewritten in seconds, and the clock on the machine producing the file can be set to any value beforehand. A screenshot of the properties panel settles nothing. Our metadata viewer shows what a file says about itself, which is the point: that is a claim, not a record.
No. Under RFC 3161 the client sends only the hash, and the authority returns a signed token containing that same imprint, a serial number and the recorded time. The file itself never leaves your environment, which matters when the material is privileged or commercially sensitive.
You can, and it is usually worth doing, as long as you are honest about the result. The token shows that the file existed no later than today. It says nothing about last year. Earlier existence has to come from other evidence, such as correspondence or system records.
Look it up in the European Commission's Trusted List Browser rather than taking a sales page at face value: choose the country, filter on the timestamp service, and read the status and its date. The machine readable list behind that interface is published openly, so this is one claim you never have to accept on trust.

If it helps to have the underlying legal material in one place, the framework we work from sits on our legal pages. One disclosure belongs beside it: we sell one of the rows in that table ourselves, a qualified timestamp issued through Disig a.s. in Slovakia, whose service we checked on the Slovak Trusted List on 29 July 2026, status granted. That is exactly why the two columns above are the ones we would want a buyer to hold us to, ourselves included. Proving that a document existed on a date is cheap before the argument starts and expensive afterwards, so keep the bytes as they are today, then pick a route.
Daan van Tongeren is the founder of PDFen and works on document evidence, file integrity and what software can honestly claim about either. Questions about anything here are welcome through our contact page.
Bundling and saving your emails correctly is crucial; for legal compliance, organization continuity,...
PDFen, IlovePDF and Freeconvert.com all offer well-functioning and quick tools to convert documents...