Articles

What is an electronic signature, and when does it hold up

What is an electronic signature, what makes one legally binding under the ESIGN Act and eIDAS, where the law excludes it, and what to do if one is rejected.

What is an electronic signature, and when does it hold up

What is an electronic signature?

An electronic signature is any data in electronic form that a signer attaches to a record to show they agree to it. Typed name, clicked checkbox, drawn squiggle, cryptographic certificate. All of them count.

That breadth surprises people. The law was written to be technology-neutral on purpose.

In the United States the rule sits in the ESIGN Act, at 15 U.S.C. §7001(a). It says a signature, contract or other record relating to a transaction "may not be denied legal effect, validity, or enforceability solely because it is in electronic form", and that a contract may not be denied legal effect "solely because an electronic signature or electronic record was used in its formation".

Read it twice. It does not say electronic signatures are always valid. It says being electronic is not, by itself, a reason to throw one out.

That is a narrower promise than most vendor pages imply, and the distinction matters the moment somebody disputes a document.

Alongside ESIGN sits the Uniform Electronic Transactions Act, adopted by almost every state. ESIGN gives federal validity in interstate and foreign commerce; UETA governs transactions inside a state. Between them they cover essentially all US commercial activity.

In the European Union the equivalent is Regulation 910/2014, better known as eIDAS. Its Article 3(10) defines an electronic signature as data in electronic form which is attached to or logically associated with other electronic data and which the signatory uses to sign.

What that means in practice

Everything else follows from those two sentences. The question is never really "is my electronic signature legal". It is "can I prove what happened, to the standard this particular document needs".

Those are different questions. Most disputes turn on the second one.

It also helps to be clear about what an electronic signature is not. It is not a scanned picture of your handwriting, although pasting one into a PDF may technically qualify as a simple signature. It is not a password. It is not the same thing as an electronic record, which is the document rather than the act of agreeing to it.

And it is not automatically a digital signature, which is a specific cryptographic technique covered further down.

Checked against primary sources on 1 August 2026: 15 U.S.C. §7001 on govinfo.gov, Regulation (EU) 910/2014 on EUR-Lex, and §126a and §623 of the German Civil Code on gesetze-im-internet.de. Statutes change. Confirm the current text before relying on any of it for a specific document.

Simple, advanced, qualified: the three levels

eIDAS sorts electronic signatures into three tiers, and the tiers carry different legal weight. US law has no formal tiering, but the same technical distinctions show up in evidence anyway.

Simple electronic signature. A name typed into a box. A checkbox. A signature drawn with a mouse. Perfectly valid for the vast majority of commercial agreements.

Advanced electronic signature. Article 26 of eIDAS sets four conditions. It must be uniquely linked to the signatory. It must be capable of identifying them. It must be created using means the signatory can keep under their sole control. And it must be linked to the signed data in a way that makes any later change detectable.

Qualified electronic signature. An advanced signature made with a qualified signature creation device and based on a qualified certificate, per Article 3(12). Article 25(2) gives it the payoff: the legal effect of a qualified electronic signature is equivalent to that of a handwritten signature.

That is the only tier the regulation puts on a par with ink. Everything below it is valid but has to be proven. The qualified electronic signature guide goes through how to get one and when it is worth the cost.

How to pick a tier without overthinking it

Start from the document, not from the technology. Three questions settle it almost every time.

Does a statute prescribe a form for this document? If yes, the statute decides and you have no discretion. Does the counterparty impose a requirement of its own? Banks, insurers and public bodies routinely do, and they are entitled to. Is the amount at stake large enough that somebody might genuinely litigate it?

If all three answers are no, a simple signature with a solid audit trail is the proportionate choice. Reaching for a qualified signature on a routine NDA costs money and friction and buys nothing.

One cross-border caveat. A tier is meaningful inside the legal system that defines it. A qualified signature carries its Article 25(2) effect across all EU member states, but outside the EU it is treated as evidence like anything else, weighed on its merits. Plan for the law that will actually govern the contract.

Person signing a document electronically on a tablet

Three legal tiers, one interface. The tier decides how much you have to prove.

What makes an electronic signature hold up

Legislation sets the rule. Your evidence decides the case. Four things have to be provable when someone disputes a signed document.

What you must showWhat proves it
Intent to signAn affirmative act: a consent checkbox, a click on "I agree"
AttributionWho signed, via verified email, IP record, unique signer link
IntegrityA cryptographic hash that changes if the file changes
RetentionThe signed file and its audit trail, kept and retrievable

Integrity is where most tools quietly fail. A scanned image of a handwriting pasted into a PDF proves nothing about whether page four was swapped afterwards.

A cryptographic hash does. Change one byte and the hash no longer matches. That is not a policy promise from a vendor. It is arithmetic, and anyone can rerun it.

The audit trail is the actual product

An audit trail is a timestamped record of every action taken on the document: who opened it, who signed it, when, from which IP address, against which verified email identity.

Without one, a service cannot prove intent, attribution or integrity when it matters. With one, the argument is usually over before it starts. You can inspect what a signed file actually carries with the PDF signature checker.

Two details separate a useful trail from a decorative one. It has to be exportable, because a record you can only view inside somebody's web app is awkward to put in front of a court. And it has to be tamper-evident, meaning a change to the trail itself is detectable rather than merely discouraged by access controls.

Retention is the part everyone forgets

A signature that verified perfectly in year one is worthless in year six if nobody kept the file. Retention periods vary by document type and jurisdiction, and they routinely outrun the life of the software that produced the record.

Store the original signed file rather than a re-exported copy. Store the audit trail with it. And check that you can still open both without a live subscription to the service that made them.

Electronic signature vs digital signature

These two phrases get swapped constantly and they are not synonyms.

An electronic signature is a legal concept. It represents a person's intention to be bound.

A digital signature is a specific cryptographic technique. It uses public key infrastructure and a certificate authority to bind a key pair to an identity, then produces a hash of the document at the moment of signing.

So a digital signature is one way to implement an electronic signature. It is not the only way, and the law does not require it for most agreements.

What the cryptographic route buys you is non-repudiation: the signer cannot credibly claim afterwards that it was not them, because the proof travels inside the file rather than inside a vendor's database.

Diagram of the four elements that make an electronic signature defensible

Intent, attribution, integrity, retention. Miss one and the rest stops helping.

Where the law still says no

Electronic signatures cover almost everything. The exclusions are narrow, specific and jurisdictional, which is exactly why people get caught out.

Common exclusions include wills and testamentary instruments, certain real property conveyances, some family law documents, particular court filings and a handful of official government records. The exact list depends on where you are.

Germany is a useful example of how sharp these edges can be. Section 126a of the German Civil Code allows the statutory written form to be replaced electronically, but only if the issuer adds their name and signs the electronic document with a qualified electronic signature. Nothing less will do.

And Section 623 of the same code, on the termination of employment relationships, states flatly that the electronic form is excluded. No signature tier saves you there. Paper or nothing.

Check the document type against the local rule before you send it. This takes five minutes and saves entire deals.

When a signature gets rejected

A rejected signature is rarely a broken signature. Usually it is a mismatch, and the fix depends on which kind.

Wrong tier. The recipient needs a qualified signature and you sent a simple one. No amount of resending helps. You need a certificate from a qualified trust service provider.

No agreement on method. Between private parties nobody is obliged to accept your signing system unless it was agreed. A bank can insist on a specific certificate and is within its rights.

Broken integrity. The file changed after signing. Even flattening a PDF or re-saving it in the wrong tool can do this. The fix is to reissue and re-sign, not to argue.

Expired certificate. Certificates carry an end date. Once past it, the signature may still be historically valid but new signings will fail.

A worked example

A supplier sends a signed framework agreement. Legal opens it, adds a comment, saves, and forwards it to finance. Finance runs a validation check and gets a failure.

Nobody acted in bad faith. The comment rewrote the file, the hash no longer matched the one captured at signing, and the validator did exactly what it should. The document was fine; the copy was not.

The fix is procedural rather than technical. Keep the signed original untouched in one place, and circulate copies for reading. If you genuinely need to annotate, annotate a duplicate and say so.

The practical defence against the rest is equally boring and equally effective. Write into the contract which signature method the parties accept, before anyone signs. Our contract templates already include that clause.

A signature that verified last year can fail today. Re-saving a signed PDF in the wrong tool rewrites the file and breaks the hash, even though nothing visible changed. Archive the original signed file, not a re-exported copy of it.

Team reviewing signed agreements and audit trail records

The audit trail is what you actually buy. The signature is the visible part.

What to check before you choose a service

Once compliance is settled, the platform choice comes down to what happens around the signature.

Look for end-to-end encryption in transit and at rest. Look for a tamper-evident audit trail you can export. Look for non-repudiation backed by an actual certificate rather than a picture. Look for SOC 2, ISO 27001 and GDPR handling if you operate in regulated markets.

Then look at the workflow, because that is where the time goes: signing order for multi-party agreements, bulk send, a template library, and an API that talks to whatever system already holds your customer records.

Three questions vendors dislike

Ask what happens to your evidence if you stop paying. If the audit trail lives only inside the vendor's database, cancelling the subscription can quietly cost you the proof.

Ask whether a third party can verify a signed document without an account. Independent verification is the difference between evidence and a claim.

Ask what the pricing does at volume. Per-envelope pricing looks cheap on a pilot and gets expensive precisely when adoption succeeds.

If all you need is a clean signature graphic to drop into a document, the signature generator does that in a minute. If you want to compare tiers and costs, the pricing page lists them. And if you need the full agreement lifecycle with an evidence trail behind it, see how signing works with Chaindoc.

Signatures are easy. Proving them later is the hard part

Chaindoc anchors each signed document to a cryptographic hash anyone can verify independently, so the evidence does not depend on us still being here in ten years.

Tags

#electronic-signatures#esign-act#eidas#legal-validity
FAQ

Frequently Asked Questions

Answers to popular questions about Chaindoc and secure document workflows.

An electronic signature is data in electronic form attached to or logically associated with a record, which the signer uses to indicate agreement. Under eIDAS Article 3(10) that includes a typed name, a checkbox, a drawn mark or a cryptographic certificate. Under the ESIGN Act at 15 U.S.C. §7001(a), such a record may not be denied legal effect, validity or enforceability solely because it is in electronic form.

In most jurisdictions, yes, provided you can prove what happened. The ESIGN Act and UETA cover the United States, and eIDAS covers the European Union. None of them make every electronic signature automatically enforceable. They remove being electronic as a reason to reject one. Enforceability still depends on provable intent, attribution, integrity of the record and proper retention.

An electronic signature is the legal concept: a person's intention to be bound by a record. A digital signature is a cryptographic technique that uses public key infrastructure and a certificate authority to bind a key pair to an identity and generate a document hash at signing time. A digital signature is one way to implement an electronic signature, and it is what makes non-repudiation possible.

eIDAS defines simple, advanced and qualified. A simple signature identifies the signer. An advanced signature must meet the four conditions in Article 26: unique linkage to the signatory, capability of identifying them, sole control of the creation means, and detectability of any later change. A qualified signature adds a qualified creation device and a qualified certificate, and under Article 25(2) it is equivalent to a handwritten signature.

The exclusions are narrow but real and they vary by country. They typically cover wills and testamentary instruments, some real property conveyances, certain family law documents and specific court or government filings. German law is a clear example: Section 623 of the Civil Code excludes the electronic form for terminating an employment relationship outright, regardless of the signature tier used.

An audit trail is a timestamped, tamper-evident record of every action taken on a document during signing: who created it, who opened it, who signed, when each action happened, from which IP address and against which verified email identity. It is the evidentiary basis for a defensible electronic signature. Without one, a service cannot demonstrate intent, attribution or integrity in a dispute.

Non-repudiation is the cryptographic assurance that a signer cannot later credibly deny having signed. It comes from a digital signature built on public key infrastructure, a certificate authority binding identity to a key, and a document hash generated at signing. If the document changes by even one character afterwards, the hash no longer matches and the tampering is immediately visible.

Usually for one of four reasons. The recipient required a higher signature tier than you used. No method was agreed in advance, and private parties are not obliged to accept a system they did not agree to. The file changed after signing, so the integrity check fails. Or the signing certificate had expired. Agreeing the accepted signature method in writing before signing prevents most of these.

Related Content

More e-signature and blockchain guides

Practical guides on electronic signatures, blockchain audit trails, and secure document management — handpicked to build on what you just read.

View All Articles