An electronic signature is not a picture of your signature. It is a legal act with defined tiers, and which tier you used decides whether it holds up when someone disputes it. That distinction is the whole subject, and it is where most explanations go wrong — including the earlier version of this article, which credited the GDPR with legitimising e-signatures. The GDPR governs personal data. Electronic signatures in Europe are governed by a different regulation entirely: eIDAS.
The three tiers, and why they are not interchangeable
European law recognises three levels. Almost every argument about whether an e-signature “counts” is really an argument about which of these was used.
| Tier | What it requires | Typical use |
|---|---|---|
| Simple (SES) | Any electronic mark indicating intent — a typed name, a tick box, a drawn squiggle | Low-value agreements, internal approvals |
| Advanced (AES) | Uniquely linked to the signer, capable of identifying them, under their sole control, and detecting later changes to the document | Commercial contracts, HR paperwork |
| Qualified (QES) | An advanced signature created with a certified device and a qualified certificate from a trust service provider on the official list | Anything requiring the legal weight of a handwritten signature |
The practical difference is who carries the burden of proof. A qualified signature is granted legal effect equivalent to a handwritten one, and the person disputing it has to unpick that. With a simple signature, the party relying on it has to demonstrate the signer really was who they claim — which is a much harder afternoon in front of a judge.
Why this matters for payments
Payments and signatures converged because both came to depend on the same question: can you prove, later, who authorised this? A payment mandate, a credit agreement, a change of bank details — each is a signed instruction, and each is a target for fraud.
The audit trail is what does the work. A serious e-signature platform records who opened the document, from which address, when, what they saw and what they agreed to, and seals the document so any later edit is detectable. When a transaction is challenged, that trail is the evidence. A scanned image pasted into a PDF has none of it, which is why it is worth almost nothing in a dispute even though it looks the most like a signature.
Elsewhere in the world
The tiering idea is not unique to Europe. The United States works from the ESIGN Act and state-level UETA, which take a broader approach: an electronic signature is generally valid provided intent and consent can be shown, without a formal ladder of tiers. India’s Information Technology Act recognises digital signatures issued by licensed certifying authorities, alongside Aadhaar-based eSign for individuals. The United Kingdom retained its own version of eIDAS after leaving the EU.
The common thread is that all of these care about the same three things — identifying the signer, showing intent, and proving the document has not changed since. A tool that cannot demonstrate all three is not really offering a signature, whatever it is called.
Where the GDPR does come in
Not as the source of validity, but as a constraint on how the process is run. Signing generates personal data: names, addresses, identity documents, device and location information in the audit trail. That data needs a lawful basis, a retention period, and appropriate security. Verifying identity by collecting a passport scan is a data protection decision as much as a fraud one, and holding those scans indefinitely afterwards is the mistake organisations most often make.
So both regulations apply to the same transaction, doing different jobs: eIDAS decides whether the signature is valid, the GDPR decides whether you were allowed to collect what you collected in order to produce it.
Choosing an approach
Match the tier to the consequence of being wrong. Most day-to-day business does not need qualified signatures, and insisting on them adds friction that costs more than the risk it removes. Ask what happens if this specific document is disputed — if the answer is a serious loss, move up a tier. Then check three things about any platform: that it produces a tamper-evident sealed document, that the audit trail is exportable rather than locked inside the vendor, and that the retention settings are yours to configure. A signature you cannot produce evidence for after you stop paying the vendor is not a durable record.
Frequently asked questions
Is a typed name a legally valid signature?
It can be, as a simple electronic signature, where intent and consent can be shown. It carries the least evidential weight of the three tiers, so it suits low-risk documents rather than important ones.
What is the difference between an electronic and a digital signature?
Electronic signature is the legal concept — any electronic indication of intent. Digital signature is the cryptographic technique used to implement the stronger tiers. Every digital signature is an electronic signature; the reverse is not true.
Does the GDPR make electronic signatures legal?
No. That is a common confusion. Validity comes from eIDAS in Europe; the GDPR governs the personal data generated when you sign.
Is a scanned image of my signature good enough?
Rarely. It can be copied from any previous document, and it carries no audit trail, so it is among the weakest options despite looking the most familiar.
Which tier do I actually need?
Match it to the cost of a dispute. Routine paperwork is fine at the simple or advanced level; anything where a challenge would be expensive justifies a qualified signature.
What should I keep after signing?
The sealed document and its audit trail, exported and stored somewhere you control, for as long as the agreement could be disputed — and no longer, since the trail contains personal data.
Related reading
See also how to protect yourself from cybersecurity threats.


