Is E-Signature Legally Valid in India? What the IT Act Requires (2026)
india-esignature electronic-signature information-technology-act aadhaar-esign india-law

Is E-Signature Legally Valid in India? What the IT Act Requires (2026)

A 2026 guide to Indian e-signature law — what the IT Act and Evidence Act s.65B require, how Aadhaar eSign works, and where a wet signature is still needed.

Sophie Sophie · Legal Content Specialist September 13, 2026 9 min read

A Bengaluru startup is closing a services agreement with an enterprise client in Mumbai. The client's procurement team is ready to sign, but one lawyer asks whether an electronic signature is actually valid under Indian law — and whether it matters which kind is used. The draft is final; what counts as a defensible signature is what's holding it up.

The short answer in 2026 is that electronic signatures are legally recognized in India for the overwhelming majority of commercial contracts. The useful question is not "is it legal" but "does this specific signing method give me enough evidence if the signature is ever challenged." This is general information, not legal advice — for anything unusually high-value or government-facing, consult a qualified Indian lawyer.

What the IT Act covers

India's foundation is the Information Technology Act, 2000 (IT Act). Section 3 gives legal recognition to electronic signatures, and Section 3A sets the framework for how they may be effected: through an electronic process designated by the Central Government, or through a digital signature certificate. The designated method is the Aadhaar-based eSign service.

As with the regimes in Thailand and the UAE, the core test is whether the signing method reliably does three things:

  1. Identifies the signer — the method reasonably ties the signature to a specific person
  2. Shows intent — the signer took a deliberate action indicating agreement, not an accidental click
  3. Preserves integrity — the signed document can be shown not to have been altered afterward

In practice, India has two widely used routes. Aadhaar eSign verifies the signer through their Aadhaar identity: the signer authenticates with an OTP sent to the Aadhaar-linked mobile number, or with biometric data, and the service affixes a legally recognized electronic signature. Digital Signature Certificates (DSCs) — typically Class 3 certificates issued by licensed Certifying Authorities — bind a cryptographic key pair to the signer and are common in filings and higher-assurance transactions. Both routes satisfy the IT Act; neither is required for a routine commercial contract, provided the evidence around the signing is properly captured.

Ordinary signature versus a "reliable" one

The IT Act distinguishes between an electronic signature in the general sense and one that meets a higher bar of reliability — broadly, a method under the signer's sole control, capable of identifying them, where any later alteration to the document can be detected. Aadhaar eSign and Class 3 DSCs sit at the stronger end of this spectrum.

For the documents that make up most business volume — NDAs, service agreements, supplier contracts, employment offers, MOUs — a standard workflow is normally sufficient. What makes it defensible later is largely the record around it:

  • A clear invitation sent to a verified email address or mobile number
  • The complete, final document presented before signing, not a summary
  • An unambiguous signing action, not a passive read receipt
  • Timestamped records of when the document was viewed and signed
  • A hash or similar integrity check showing the file didn't change after signing

Where a counterparty's policy, a lender, or a regulator demands certificate-based signing, use the process they require rather than assuming a standard e-signature will be accepted.

When you should expect something stronger

Before sending a document for e-signature in India, ask:

  • Is this a filing with a government body — the Ministry of Corporate Affairs for company filings, the GST portal, SEBI-regulated entities — that specifies its own authentication method? These portals generally require a DSC or their own credential system, which sits outside a private commercial signing tool.
  • Does the counterparty's bank, auditor, or compliance policy specify a certificate-based signature?
  • Is the transaction value or dispute risk high enough that Aadhaar eSign or a DSC is worth the extra verification step, even if not strictly required?

If any answer is yes, follow the recipient's stated requirement rather than assuming a general e-signature tool will be accepted.

What still needs a wet signature or in-person process

The IT Act's schedules exclude certain instruments from its electronic signature regime. In practice, the following generally cannot be completed with an e-signature alone:

  • Immovable property transfers. A sale deed must be executed on stamp paper and registered physically at the sub-registrar's office under the Registration Act, 1908. A preliminary agreement may be drafted electronically, but the registration itself is in-person.
  • Wills. A will is excluded from the electronic signature framework.
  • Trust deeds. These are similarly excluded.
  • Powers of Attorney. These generally require attestation and, in many cases, physical execution.
  • Negotiable instruments other than cheques. Promissory notes and bills of exchange fall outside the regime.

For everything else — the routine commercial contracts that drive most business activity — electronic signing is fully usable.

Evidence and data protection: the part businesses forget

Two separate questions matter here. The first is evidentiary. Section 65B of the Indian Evidence Act, 1872 governs the admissibility of electronic records in Indian courts: to admit a computer output as evidence, you generally need a certificate identifying the record, describing how it was produced, and confirming it came from a system operating normally. This is far easier to secure at signing than to reconstruct after a dispute — ask whether your signing process produces a record you could actually certify in court.

The second is data protection. The Digital Personal Data Protection Act, 2023 (DPDP Act) governs how personal data — names, email addresses, phone numbers, IP addresses — may be collected and processed. A signing platform stores exactly this kind of data in its audit trail, so it should be clear about:

  • What personal data it collects during signing, and on what legal basis
  • How long that data is retained
  • Where the data is stored and under what safeguards
  • Who can access the signed document and its audit trail afterward

A platform that cannot answer these questions clearly is a compliance gap, independent of whether the signature itself is legally valid.

Building a signing record that holds up

Build the record you'd want to show a judge or an auditor a year from now, not just the one you need to close the deal today. Keep together: the final signed document, the audit trail (who was invited, when they viewed it, when they signed), the signer's verified contact details, and any integrity check the platform provides. If the final version lives in one email thread and the audit trail in another system, you've weakened your Section 65B position without realizing it.

AiDocX keeps the document, the signing workflow, and the audit trail in one place, so an Indian business doesn't have to reconstruct what happened from scattered emails if a signature is ever questioned. For teams embedding signing into their own systems, an e-signature API produces the same structured record programmatically.

Common mistakes

Assuming every contract needs Aadhaar eSign or a DSC. Most commercial agreements don't; requiring a certificate for a routine NDA just adds friction.

Treating government filings like private contracts. An MCA or GST portal submission has its own authentication — don't assume a general e-signature tool covers it.

Ignoring the evidence certificate question. A valid signature with no retrievable record is a weak position — Section 65B is about the record, not just the signature.

Overlooking excluded instruments. Sending a will, trust deed, power of attorney, or sale deed through an e-signature platform wastes time and creates false confidence.

A simple decision checklist

Use a standard e-signature workflow when: the contract is a routine commercial agreement, both parties accept electronic contracting, and the platform produces a clear audit trail of identity, intent, and document integrity — see how to send a contract for e-signature for a step-by-step walkthrough.

Use Aadhaar eSign or a Class 3 DSC when: a government agency, regulator, or counterparty's compliance policy specifically requires it, or the transaction's value justifies the extra assurance.

Always use the traditional, in-person process for: sale deeds of immovable property, wills, trust deeds, powers of attorney, and negotiable instruments other than cheques.

This is general information, not legal advice — for anything unusual or government-facing, confirm the requirement with qualified Indian counsel before you sign. For most business document volume, the IT Act gives electronic signing a solid legal foundation, and AiDocX gives you the evidence trail to back it up.

Ready to automate your documents with AI?

Start free with AiDocX — AI contract drafting, meeting minutes, consultation notes, e-signatures, and more in one platform.

Get Started Free