Are electronic signatures legally binding? What the law actually requires
Yes, in the United States, the European Union, the United Kingdom and most other developed jurisdictions, an electronic signature is legally enforceable and has been for over twenty years. The interesting question is not whether it counts. It is what has to be true for it to hold up when someone disputes it, and which documents are carved out.
This is a plain-language summary, not legal advice. For a specific transaction in a specific jurisdiction, ask a lawyer.
The laws that make it work
United States. The federal ESIGN Act, passed in 2000, provides that a signature, contract or record may not be denied legal effect solely because it is in electronic form. At state level the Uniform Electronic Transactions Act, published in 1999, does the same thing and has been adopted by the large majority of states. New York operates under its own Electronic Signatures and Records Act rather than UETA, and reaches a similar result.
European Union. Regulation 910/2014, known as eIDAS, has applied since 2016. It recognises three tiers:
- Simple electronic signature (SES). Data in electronic form used to sign. A typed name or a drawn signature qualifies. Admissible, and not deniable in evidence solely for being electronic.
- Advanced electronic signature (AdES). Uniquely linked to the signatory, capable of identifying them, created using means under their sole control, and linked to the data so that later changes are detectable.
- Qualified electronic signature (QES). An AdES created by a qualified signature creation device with a qualified certificate. A QES has the equivalent legal effect of a handwritten signature across the EU.
Most commercial contracts are signed with a simple or advanced signature. QES is normally reserved for specific regulated cases where national law requires it.
United Kingdom. The Electronic Communications Act 2000 and the retained UK version of eIDAS produce the same practical outcome, and the Law Commission confirmed in 2019 that electronic signatures can be used to execute documents including deeds, subject to the usual witnessing requirements.
The four things that have to be true
Across all of these regimes the requirements converge on the same short list. Almost every dispute is about one of these four.
1. Intent to sign
The signer has to have intended to sign. A name typed in an email footer is not a signature; a name typed into a field labelled "sign here" after being shown the document is. This is why the interface matters legally and not only cosmetically.
2. Consent to do business electronically
Both parties have to agree to transact electronically. In consumer transactions in the US, ESIGN adds specific disclosure requirements, including telling the consumer they may request a paper copy and what hardware or software they need. In business-to-business transactions this is usually satisfied by a short consent statement shown before signing.
3. Association with the record
The signature has to be attached to, or logically associated with, the specific document signed. This is the requirement that trips up informal methods. A scanned image of a signature pasted into a document proves nothing about which version it was applied to.
4. Retention and reproduction
The record has to be capable of being retained and accurately reproduced by everyone entitled to it. A signing system that cannot produce the exact signed version later does not satisfy this.
What "electronic signature" and "digital signature" mean
They are not synonyms, and the distinction is worth knowing.
An electronic signature is a legal concept: any electronic mark made with intent to sign. A digital signature is a cryptographic technique, using a key pair to produce a value that can be verified and that detects any later modification of the data.
A digital signature is one way to implement an electronic signature, and it is the way that produces the strongest evidence, because it makes tampering detectable rather than merely unlikely. Cryptographic hashing of the signed version does similar evidentiary work: if the document changes by one character, the hash changes, so the parties can prove which exact version was agreed.
What is excluded
ESIGN carves out categories where electronic signatures do not apply. The main ones:
- Wills, codicils and testamentary trusts
- Adoption, divorce and other family law matters
- Most of the Uniform Commercial Code, other than the sales provisions in Articles 2 and 2A
- Court orders, notices and official court documents
- Notices of cancellation of utility services
- Notices of default, foreclosure, repossession or eviction relating to a primary residence
- Cancellation of health or life insurance benefits
- Product recalls and notices of material failure affecting health or safety
- Documents required to accompany transport of hazardous materials
Other jurisdictions have their own lists, and several countries require a notary or a qualified signature for property transfers, powers of attorney and some corporate filings. If your document is on one of these lists, the answer is not "sign it electronically anyway".
What a defensible signed record contains
When a signature is challenged, the argument is almost never about the law. It is about evidence. The party relying on the signature has to show who signed, what they signed, and that it has not changed since.
A record that can do that usually contains:
- Identity evidence. Email address verified by delivering a unique link to it, and increasingly a code sent to a separate channel for higher-value documents.
- A timestamp for each signature, and for the key events before it.
- The IP address and device the signature was made from.
- A content fingerprint, meaning a cryptographic hash of the exact document version that was signed, recorded at signing time.
- An audit trail: when it was sent, when it was opened, by whom, what was viewed, when each party signed.
- The consent record, showing the signer agreed to transact electronically.
- The signed document itself, reproducible in its final form by every party.
That bundle is usually issued as a certificate of completion attached to the final PDF. If your current signing method cannot produce that bundle, you do not have a weak signature, you have a weak evidence position, and the two are easy to confuse until the day it matters.
The practical failure modes
In roughly the order they cause problems:
Signing a version that was later edited. Without a hash recorded at signing, "that is not the version I agreed to" is hard to rebut.
No verified identity. Anyone with access to an inbox can click a link. Email verification is the floor, and for high-value agreements a second factor is worth the friction.
Missing consumer disclosures. In US consumer transactions, skipping the ESIGN disclosures can undermine enforceability even when everything else is right.
Signing authority. The signer has to have authority to bind their organisation. This is a governance question, not a technical one, and no signing product solves it. For material contracts, confirm the signer's role.
No retained copy for the other side. Both parties must be able to keep and reproduce it.
What this means for how you send documents
If you are sending proposals, quotes or statements of work for signature, the bar is not high, but it is specific: show the document, capture intent clearly, verify the signer's email at minimum, record the version signed with a hash, and give everyone a copy with an audit trail attached. Once you are doing that, an electronically signed contract is ordinarily as enforceable as a paper one, and considerably easier to prove.
This is the basis DocuDeal signs on. Each signer agrees to use electronic records before signing, signs a specific version identified by its content hash, and the certificate of completion records who signed what, when, and from where, attached to the final PDF. Sequential or parallel signing, typed or drawn, with email verification, on every plan including the free one. For notarised or in-person signing you still need a notary, and no software changes that.
The signature is the last step, and every product in this space gets it right. What changes your week is the drafting. You describe the agreement in a sentence and the AI writes it, so it goes out the same afternoon rather than two days later, and you can see when each party opened it and how long they spent before signing. Sending sooner and knowing where a document is stuck is most of what closing more deals looks like in practice. Users are unlimited from Pro, so everyone who needs to send something has an account from day one.
Short answer
Legally binding in most of the world since around 2000, provided there is intent, consent, association with the specific record, and a retained reproducible copy. The law is the easy part. The evidence is the part worth paying attention to.