An electronic signature is any data in electronic form that a person uses to sign: a typed name, a click on "I agree", a signature drawn on a screen or a certificate-based signature in a PDF. What makes it reliable is not the image of a signature but the information that links a person, a document and a moment in time. This guide explains the definition, what happens when you sign online and how to check the result yourself.
The legal definition
In the EU, Article 3(10) of the eIDAS Regulation defines an electronic signature as "data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign". The European Commission puts it in plainer words: an electronic indication of a person's intent to agree to the content of a document, which, like its handwritten counterpart, captures the signatory's intent to be bound.
The UK, which left the EU, has a very similar definition in section 7(2) of the Electronic Communications Act 2000: anything in electronic form that is incorporated into or logically associated with electronic data and purports to be used by the individual creating it to sign. Both definitions turn on the same two ideas: a link to the document, and the intention to sign it.
Examples of electronic signatures
- A name typed under an email. The European Commission notes that this "might constitute an electronic signature".
- A ticked "I agree" box on a website or in an app.
- A signature drawn with a finger or stylus on a phone or tablet.
- A signature confirmed with a one-time code sent by email or SMS on a signing platform.
- A certificate-based signature embedded in a PDF, often called a digital signature.
All of these are electronic signatures. They are not equally strong as evidence: the difference lies in how well each one shows who signed, what they signed and when.
Electronic signature vs digital signature
The two terms are often used as synonyms, but they describe different things. "Electronic signature" is a legal concept: any of the examples above. "Digital signature" usually refers to a technology, public-key cryptography, in which a certificate and a private key seal the signed data so that any later change can be detected. The Commission notes that this is the most common way to build advanced signatures. "Digital signature" is not one of the three eIDAS levels, and in some countries it is also the name of a specific type of qualified signature (Italy's firma digitale, for instance), so check what a provider means by it.
How signing online works, step by step
On most signing platforms the process looks like this:
- The sender prepares the document. They upload a PDF, place the signature fields and enter each signer's email address or phone number.
- The signer receives a link. They open it in a browser, on a computer or a phone, with nothing to install.
- The signer confirms who they are. Typically with a one-time code sent by email or SMS; for higher-risk documents, with an identity document check.
- The signer signs. An explicit action, such as clicking or drawing, records their intent.
- The platform locks the result. It calculates a digital fingerprint of the final document (a hash, such as SHA-256), applies a certificate-based seal so that any later change becomes visible, adds a time stamp and saves an audit trail of every step.
The output is a signed PDF plus the evidence of how it was signed. Keep both: the PDF shows what was agreed, the evidence shows by whom and how.
What makes an electronic signature trustworthy
- Identity. A one-time code links the signature to a phone number or inbox; an identity document check links it to a person.
- Intent. The signer takes a deliberate action on a document they could read.
- Integrity. The fingerprint and the seal show whether a single character changed after signing. A qualified electronic seal enjoys a legal presumption of the integrity and origin of the data (Article 35(2) eIDAS).
- Time. A qualified time stamp enjoys a presumption of the accuracy of its date and time (Article 41(2)).
The three eIDAS levels in brief
- Simple electronic signature (SES): any electronic signature, from a typed name to a confirmed click.
- Advanced electronic signature (AES): uniquely linked to and capable of identifying the signer, under their sole control, and linked to the document so that changes are detectable (Article 26).
- Qualified electronic signature (QES): an advanced signature created with a qualified device and based on a qualified certificate; it has the equivalent legal effect of a handwritten signature (Article 25(2)).
Which one you need depends on the document and on national law. Our guide to eIDAS signature levels goes through them one by one.
Is an electronic signature legally valid?
Yes. Under Article 25(1) eIDAS, an electronic signature cannot be denied legal effect or admissibility as evidence solely because it is electronic or not qualified. National law still decides when a particular form is required and how much weight a signature carries in court: our guide to whether electronic signatures are legally binding goes through both questions with examples from four Member States.
What is an electronic signature certificate?
A certificate for electronic signatures is an electronic attestation that links signature validation data to a natural person and confirms at least their name or pseudonym (Article 3(14)). A qualified certificate is one issued by a qualified trust service provider that meets the requirements of Annex I of the regulation. Qualified signatures always rely on one; simple signatures often do not use a personal certificate at all, which is why the evidence around them matters so much.
How to check a signed PDF
- In your PDF reader. The signature panel shows who signed or sealed the file and whether it has been modified since.
- With the European Commission's validation tool. The Commission's DSS demonstration service validates signed PDFs online, without going back to the platform that produced them.
- For DOCUJET documents. The verification page compares the document's fingerprint with a public proof anchored on the Bitcoin blockchain: a complement to the legal evidence, not a substitute for it.
Signing with DOCUJET
With DOCUJET the signer needs no account and nothing to install. Every plan records who signed, when and from where. From the Starter plan upwards, the signed document also receives a qualified electronic seal and a qualified time stamp from Namirial, a qualified trust service provider, and signers can confirm with a one-time code by SMS; from the Business plan you can add the advanced electronic signature (AES) with identity verification. DOCUJET does not offer the qualified electronic signature. If you are weighing up costs, our guide to electronic signature pricing explains how providers charge.
Sources: Regulation (EU) No 910/2014 (eIDAS), Articles 3, 25, 26, 35, 41; European Commission, What is eSignature; Electronic Communications Act 2000, section 7; Italian Digital Administration Code, Article 1; European Commission, DSS validation demo.
Ready to try it?Open a free account: 3 documents a month, forever, with a complete audit trail.Start for free →
