← All posts

Digital Notarization11 min read

Managing E-Journals and Tamper-Evident Records for Notaries

A practical guide to creating, securing, retaining, auditing, and recovering notary e-journal entries with tamper-evident technology, covering jurisdiction-specific requirements across the US, UK, and EU.

By Self Service Notary

A compliant notary e-journal captures every notarial act in real time, seals each entry with cryptographic tamper-evident technology, and retains records for the statutory period. The workflow involves five stages: creating entries during sessions, securing them against alteration, retaining them for mandated periods, auditing them regularly, and backing them up against loss. Jurisdictional rules vary, but the technical requirements for digital integrity remain consistent.

Jurisdiction dictates what is permissible. In the US, remote online notarization (RON) is only permitted where a specific state authorises it and where the notary has confirmed their own authorisation. In EU civil-law jurisdictions, the notarial act stays in the notary's office; digital tools handle intake, identity verification, and document transmission. The UK operates under faculty rules issued by the Faculty Office of the Archbishop of Canterbury. Hong Kong and the UAE permit front-office digital workflows only. Do not treat one jurisdiction's rule as universal.

Creating journal entries during notarizations

Every journal entry must be created at the moment the notarial act occurs. Contemporaneous recording is the baseline requirement across jurisdictions. Retroactive entry introduces discrepancies that surface during audits. The entry is sealed immediately after the act, and no field is edited afterward.

Manual re-keying of journal data after the session is a common source of errors. If signer details are transcribed from recordings or documents rather than captured live, typographical errors accumulate. The journal should pull data directly from the session workflow so the notary confirms each field as the act proceeds. For practices setting up intake workflows that feed journal data automatically, automating client intake reduces transcription risks.

The specific data fields required in an e-journal entry typically include:

  • Date and time of the notarial act
  • Full name and signature of the signer
  • Signer identity verification method, including ID type or credential analysis used
  • Description and title of the document notarised
  • Type of notarial act performed (acknowledgement, jurat, copy certification)
  • Fee charged for the act
  • For RON, the location of the signer and notary at the time of the act

California's statute illustrates the control requirement. The California State Legislature provides that "A notary public shall keep one active sequential journal at a time, of all official acts performed as a notary public. The journal shall be kept in a locked and secured area, under the direct and exclusive control of the notary."

For practices handling payments during the session, the fee field in the journal must match the transaction record exactly. Integrating secure payment collection prevents mismatches between the journal entry and the payment record.

Securing entries with tamper-evident technology

Tamper-evident means any alteration to a journal entry after sealing is immediately visible through cryptographic verification. It does not mean the system prevents attempts to change data. The distinction matters: tamper-evident technology creates a mathematical proof that the current state matches the state at sealing. Any modification, deletion, or insertion is independently verifiable as an alteration.

The mechanism works through cryptographic hashing. When a journal entry is sealed, the system computes a hash digest of the entry data. That digest is bound to the record using a digital certificate, typically aligned with ITU-T X.509 standards and NIST FIPS algorithms. Any subsequent change produces a different hash, which no longer matches the sealed digest. This mismatch is the evidence of tampering.

Tamper-evident versus tamper-proof

Tamper-evident records detect alteration after the fact. Tamper-proof records claim to prevent alteration entirely. Notarial regulations require the former: a mechanism that proves whether the record has been changed since sealing, not one that promises no one can ever change it.

State administrative codes define this requirement explicitly. Arizona Administrative Code R2-12-1204 defines tamper-evident technology as an electronic process logically bound to the record so that any modification after signature and seal affixation is independently verifiable. Illinois and Oregon have adopted parallel standards.

The digital seal applies to the journal entry itself, not just the document being notarised. When a notary completes an act, two things are sealed: the electronic document with the notary's signature, and the journal entry recording the act. The journal entry receives its own cryptographic seal. For details on how digital seals and cryptographic time-stamping work together, see the guide on cryptographic time-stamping for notary digital seals.

Penalties for failing to meet this standard are concrete. The Pennsylvania Department of State has imposed 24-month commission suspensions and civil penalties of $2,000 against notaries for maintaining electronic journals in non-tamper-evident formats.

$2,000Civil penalty for maintaining a non-tamper-evident electronic journalPennsylvania Department of State

Record retention policies by jurisdiction

Retention periods vary by jurisdiction and record type. Journal entries, audio-video recordings, and session data each carry statutory minimums. The table below summarises confirmed requirements across major jurisdictions as of 2024.

Notarial record retention requirements by jurisdiction
JurisdictionJournal retentionRON audio-video retentionSource
New York10 years minimum10 years minimum19 NYCRR 182.9
TexasUntil 10th anniversary of act5 years minimumTex. Govt. Code 406.014, 406.108
Florida10 years minimum10 years minimumFla. Stat. 117.245
CaliforniaSurrender to county clerk on commission endN/A (RON journal rules apply separately)Cal. Govt. Code 8206, 8209
UK (England and Wales)Permanent (public form); 12 years (private form)N/ANotaries Practice Rules 2019, Rule 24

New York's requirement, effective January 25, 2023, applies to all commissioned notaries performing traditional, electronic, or remote online notarizations. Under Title 19 NYCRR Part 182, records including audio-video recordings for remote notarizations must be retained for at least 10 years and produced upon demand.

Texas distinguishes between journal records and session recordings. Under the Texas Government Code Section 406.014, a notary must retain records of notarial acts until the 10th anniversary of the date of notarization. For RON, the audio-visual recording must be retained for at least five years.

Florida requires electronic journal entries and remote audio-visual session recordings to be retained for at least ten years under Florida Statutes Section 117.245, as confirmed by the Florida Department of State.

California takes a different approach. Rather than specifying a retention period, California requires notaries to surrender journals to the county clerk upon cessation of commission. Under California Government Code Section 8209, if a notary resigns, is disqualified, removed, or allows a commission to expire without reappointment within 30 days, they must deliver all journals and papers to the clerk within 30 days.

In England and Wales, the Faculty Office oversees digital record-keeping. Under the Notaries Practice Rules 2019, notarial acts in public form must be preserved permanently, while acts in private form must be kept for a minimum of 12 years. Any notary preserving records via a digital system must provide access credentials directly to the Registrar.

A notary who preserves records by means of a digital or other electronic system in accordance with rules 24.3 and 24.4 shall notify the Registrar of any username and password required for access to such digital or electronic system and the Registrar shall keep such information confidential.

Charles Richard George QC, Master of the Faculties of the Archbishop of Canterbury

For practices operating across multiple US states, the guide on notary compliance across jurisdictions covers tracking differing state requirements.

Auditing and reviewing e-journals

Periodic self-audits catch gaps before a regulatory inspection or client dispute surfaces them. A structured audit verifies three things: that every notarial act has a corresponding journal entry, that every entry contains all required data fields, and that the cryptographic seal on each entry verifies as intact.

Run the audit on a fixed schedule, monthly for active practices and quarterly at minimum. The process covers four checks:

  1. Completeness checkCompare your appointment or session log against your journal entries. Every completed notarial act should have a corresponding entry. Flag missing entries and investigate immediately.
  2. Field verificationConfirm each entry contains all required data fields for your jurisdiction. Check that signer identity verification method, document description, notarial act type, and fee charged are populated. Empty or placeholder fields are compliance gaps.
  3. Integrity verificationRun the tamper-evident verification function on each entry. The system should confirm that the sealed hash matches the current content hash. Any mismatch indicates the entry was altered after sealing.
  4. Retention schedule reviewConfirm that entries within their retention period are accessible and that entries past their retention period are disposed of according to your jurisdiction's rules. Document the disposal.

Document each audit. Keep a record of when the audit was performed, who performed it, what was checked, and what discrepancies were found and resolved. If a regulator requests proof of compliance, your audit log demonstrates ongoing diligence. Get started with a system that supports built-in audit reporting so these checks become routine rather than manual.

Recovering and backing up journal data

Notarial journals are legal records, and their loss creates liability exposure. Redundant storage and a tested recovery plan protect against hardware failure, accidental deletion, and facility loss. The strategy should separate personal device storage from encrypted cloud or portal storage so that a compromised or lost device does not mean lost records.

Effective backup strategies

  • Automated daily sync from the local device to an encrypted cloud repository
  • Geographically separated secondary backup so a single site loss does not destroy records
  • Periodic test restores to confirm backups are recoverable, not just written
  • Access logging on the backup repository to track who accessed or exported records

Practices to avoid

  • Storing journal entries solely on a personal laptop or phone with no cloud sync
  • Using consumer-grade cloud storage without encryption at rest
  • Never testing a restore, then discovering the backup is corrupt during a crisis
  • Allowing multiple staff to keep local copies on unmanaged devices

The separation between personal device and cloud storage matters for security and access continuity. If a notary's laptop is lost or stolen, the journal entries should be recoverable from the encrypted cloud copy. If the cloud service experiences an outage, the local copy on the device provides operational continuity. Neither copy alone is sufficient.

For RON sessions, the audio-video recording requires the same backup discipline as the journal entries. Florida and New York both require ten-year retention of these recordings. A practice that loses a session recording during that window cannot produce it on demand. The backup plan should cover journal entries, session recordings, and the signed documents themselves.

Access to backups should be logged and reviewed. Every retrieval, export, or viewing of a journal entry in the backup repository should generate an access record. This creates an audit trail for the audit trail, demonstrating that the records were preserved and protected from unauthorised access.

See pricing for systems that provide encrypted cloud storage with automated sync and access logging built in.

Separating storage and managing access

Best practice for separating personal device storage from encrypted cloud or portal storage means the notary's local device holds a working copy for the day's sessions, and the encrypted cloud or portal holds the authoritative record. The cloud copy is the one produced for regulators. The local copy exists for operational convenience during the session.

In a small practice with one to five notaries, each notary should have their own credentials for the journal system. Shared logins destroy individual accountability and make audit trails meaningless. When a discrepancy arises, you need to know which notary created which entry and when.

For practices building out their RON setup, the guide on what a US notary needs to set up before their first remote online notarization covers the full infrastructure checklist, including journal configuration.

Jurisdictional timeline for key regulatory changes

Several jurisdictions have updated their electronic notarization and journal requirements recently. The timeline below tracks the regulatory milestones that shape current practice.

  • November 2019UK Faculty Office brings Notaries Practice Rules 2019 into force, requiring digital credential submission to the Registrar
  • February 2021Oregon Secretary of State adopts Administrative Rule 160-100-0855 for tamper-evident rendering and 10-year retention
  • June 2021Pennsylvania Secretary of the Commonwealth issues disciplinary orders against non-tamper-evident journal use
  • January 2023New York Department of State Title 19 NYCRR Part 182 takes effect, mandating 10-year journal retention
  • June 2023Illinois Secretary of State implements administrative rules under 14 Ill. Admin. Code 176 for tamper-evident digital seals
  • September 2025Texas Senate Bill 693 extends record retention to the 10th anniversary of the notarial act

Key requirements to verify in your setup

  • Your journal entries are created during the session, not reconstructed afterward
  • Each entry is sealed with tamper-evident cryptographic technology immediately after the act
  • Your retention period matches the longest applicable requirement across the jurisdictions where you practise
  • Your backup strategy separates local working copies from encrypted cloud storage
  • Your audit process verifies completeness, field population, seal integrity, and retention schedule on a fixed cadence

Build your compliant e-journal workflow

A tamper-evident journal that meets these standards protects your commission and your practice. Start free with a system built for notary compliance, or compare plans to find the right fit for your practice size.

Create Your Account

ShareXLinkedIn