Start free

Blog

The ESIGN Act and UETA: what they actually require

Two laws decide whether an electronic signature counts in the United States, and between them they ask for four things. Here they are.

A heavy bound volume lying open on a wide oak table beside a closed laptop, reading glasses folded on the page, an unlit brass desk lamp, tall windows behind.

Most of what is written about electronic signatures skips the part where somebody says what the law asks for. It is worth reading, because it is shorter and less mysterious than the marketing around it, and because knowing the four things it asks for tells you what to look for in any product, including this one.

Two laws are doing the work in the United States. ESIGN is federal — the Electronic Signatures in Global and National Commerce Act, 2000. UETA is the Uniform Electronic Transactions Act, a model law that almost every state has adopted in some form. They overlap heavily and say much the same thing.

The rule both of them start with

A record or a signature is not denied legal effect solely because it is electronic.

That sentence is the whole foundation, and note its shape. It does not say electronic signatures are good. It says that being electronic is not, by itself, a reason to throw one out. Everything else that would make a paper agreement fall over — nobody agreed, the wrong person signed, the terms were never shown — still applies exactly as it did before.

This is why "is an e-signature legal?" is not quite the right question. The law already answered it in 2000. The question that is still live is whether this particular signing shows what it needs to show.

The four things

Intent to sign. The person meant to sign. Not clicked something, not arrived on a page — meant to sign. A typed name in a box with nothing around it is a weak version of this. A distinct act, labelled as signing, with the document in front of them, is a strong one.

Consent to do business electronically. Both laws want the person to have agreed to transact this way. For consumer transactions ESIGN adds specific disclosure requirements before that consent counts. The practical version: the person is told that signing electronically is what is happening, and they agree to it, and that agreement is recorded separately from the signature itself.

Association of the signature with the record. The signature has to be attached to, or logically associated with, the thing signed. This is the one people skip. A signature image in one system and a PDF in another are two files that a person is asserting go together. A signature bound to a specific document, with that document's fingerprint recorded at the moment of signing, is a different kind of claim.

Retention. The record has to be capable of being retained and accurately reproduced by everyone entitled to it. That means the signer gets a copy they can keep, and what you hold later is the same thing they saw — not a regenerated approximation of it.

What the laws deliberately leave out

They do not require a certificate authority. They do not require a particular technology. They do not grade signatures into tiers. ESIGN is explicitly technology-neutral, which was the point: Congress declined to pick a vendor or a cryptographic scheme in 2000, and that decision has aged well.

It also means no product can hand you compliance. A product can make the four things above easy to do and easy to evidence. Whether they happened in a given case is a question about that case.

And what they exclude

Both carve out categories. Wills, codicils and testamentary trusts. Adoption and divorce papers and other family-law matters. Court orders and notices. Certain notices about utilities, insurance cancellation, eviction and foreclosure. Under the Uniform Commercial Code, most of Article 2 and 2A sit outside UETA's reach.

The list varies by state, which is the recurring theme with UETA: it is a model law, and states amended it as they adopted it. New York in particular went its own way with a separate statute. If a document type sits near one of these lines, that is a question for a lawyer about your state, not a question about software.

Reading a product against this

Once the four things are in view, the questions to ask get concrete:

  • What exact words did the signer agree to, and where are they stored?
  • Is the consent to sign electronically recorded separately from the signature?
  • What fingerprint of the document was taken, and when?
  • What does the signer receive, and can they still open it in three years?
  • Can somebody outside your account check a copy against the original?

Those are answerable. "Is it legally binding?" is not, by anybody selling you something.

Outside the United States

Different framework, same shape. The EU's eIDAS regulation recognises electronic signatures generally and then defines advanced and qualified tiers with additional requirements, and a qualified signature carries a specific legal status that the American laws have no equivalent of. The UK has its own post-Brexit version. Canada has PIPEDA and provincial acts.

If you operate across a border, that is the point at which the question stops being "is this a real signature" and starts being "which regime is this transaction under" — again a question for a lawyer, and one worth asking before rather than after.

SignSealer is not a law firm and this is not legal advice. What is written here describes what the statutes say; it does not tell you how they apply to anything you are doing.


More writing · Who SignSealer is for

A hand holding a phone showing a document and a signature, outside a timber lakeside cabin, with two guests walking to the door with luggage.

Ready when the next guest is.

Free for the first 25 agreements a month. No card to start.