Certified email (known as Posta elettronica certificata in Italy, or PEC in short) is a special type of email in use in Italy,[1] Switzerland,[2] Hong Kong[3] and Germany.[4] Certified email is meant to provide a legal equivalent of the traditional registered mail, where users are able to legally prove that a given email has been sent and received by paying a small fee.
Registered mail is mainly used in Italy,[5] but there are present efforts to extend its legal validity according to the framework of the European Union.[6]
A certified email can only be sent using a special Certified Email Account provided by a registered provider.When a certified email is sent, the sender's provider will release a receipt of the successful (or failed) transaction. This receipt has legal value and it includes precise information about the time the certified email was sent.Similarly, the receiver's provider will deliver the message in the appropriate certified email account and will then release to the sender a receipt of successful (or failed) delivery, indicating on this receipt the exact time of delivery.If either of these two receipts are lost by the sender, providers are required to issue a proof of transaction with equal legal validity, if this proof is requested within 30 months of delivery.
In terms of user experience, a certified email account is very similar to a normal email account.The only additional features are the receipts, received as attachments, providing details and timestamps for all transactions.A certified email account can only handle certified email and cannot be used to send regular email.
The development of this email service has conceptual variations that are dominated by two-party scenarios with only one sender and one receiver as well as a trusted third party (TTP) serving as a mediator. As in traditional registered mail, many certified email technologies call for the parties involved to trust the TTP, or the "postman", because it has the capacity to reveal the identity of the sender to the recipient once the protocol is initiated.[7] There are, however, some applications based on multi-party email protocols; these include the technology originally proposed by Markowitch and Kremer, that involves an online or offline TTP in addition to the sender and receiver.[8] There is also a multi-party version, wherein a user can send the same email to multiple recipients. In this system, those who acknowledge the receipt are able to view the data. Some applications also offer add-in features, such as the integration of the concept of timeliness, wherein a participant to the process can terminate a session in finite time in order to avoid waiting for a reply forever.[9]
The mediation of a trusted third party (TTP) requires both parties, the sender and the recipient, to come to terms in approving who will be the mediator. In compliance scenarios, where a regulation may simply require a party to deliver a notice to a given recipient and be able to prove having done so (i.e. GDPR), the role of a TTP can be trusted to an electronic registered delivery service capable to secure timestamped evidence of the contents and delivery of the electronic message, without the recipient's intervention.[10]
The Italian certified email (Posta elettronica certificata, PEC) was established in 2005[11] and it uses protocols described in the RFC 6109 (Request for Comments 6109), which was drafted in order to make the protocols public to the Internet community.
Since July 1 of 2013, all communications between enterprises and the Italian public administration are required to be sent through PEC and paper documents are no longer accepted.[12]
All matters concerning PEC in Italy are supervised and regulated by a special government agency called AgID ("Agenzia per l'Italia digitale") which determines the authorized certified email providers, the legal framework of PEC and the rules and terms of use.
Anyone may register a PEC address through a certified provider or reseller.
Starting from 2022, Italy is migrating from PEC to an EIDAS-compliant protocol, called Registered Electronic Mail. The switch over to the new protocol is being led by Roberto Reale[13] and Alessandra Antolini on behalf of AgID.
PEC provider | eidas compatible 2024? | DMA friendly (google\apple independent) | Limitation | address portability |
---|---|---|---|---|
Intesi Group | will be in 2024 | ? | unknown | no |
Aruba (Actalis) | partial | no | no | |
Infocert | yes | no | no | |
... | ? | Only for students and other business partners | no | |
TWT | no | ? | ... | no |
Sogei | n\a | ? | Only for business partners | no |
register.it | no | ? | ... | no |
Regione Marche - Posta Raffaello | n\a | ? | suppressed | no |
Poste Italiane | n\a | ? | ... | no |
Consiglio Nazionale del Notariato | no | ? | private | no |
Namirial S.p.A. | no | ? | n\a | no |
Cedacri Cert | ... | ? | ... | no |
IN.TE.SA. S.p.A | offline | ? | offline | no |
Irideos S.p.A. (kolst) | no | ? | no | |
Notartel S.p.A. | ? | no | ||
Sogei | no | ? | n\a | no |