Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)
Magazine

When Is a Simple Electronic Signature Enough?

Product & Practice

When Is a Simple Electronic Signature Enough?

A simple electronic signature is suitable for many contracts that have no statutory form requirement. The key factors are legal formalities, the specific risk and the quality of the evidence.

August 10, 2026

An order accepted by clicking a button, a signed PDF returned by email or a signature completed through a link: many everyday contract processes use a simple electronic signature (SES). It is accessible and can eliminate breaks between digital and paper workflows. Legally, however, the decisive factor is not merely whether a document visibly appears to have been “signed”.

Whether an SES is sufficient mainly depends on three questions: Is there a statutory form requirement? Have the parties agreed on a particular form? And how significant is the risk that the conclusion, content or attribution of the contract will later be disputed?

What is a simple electronic signature?

The eIDAS Regulation defines an electronic signature as data in electronic form that is attached to or logically associated with other electronic data and used by the signatory to sign. An SES is the lowest of the three signature levels commonly distinguished under eIDAS:

  • simple electronic signature (SES),
  • advanced electronic signature (AES),
  • qualified electronic signature (QES).

An SES does not have to meet the specific technical and organisational requirements that apply to an AES or QES. Common examples include:

  • a typed name at the end of an email,
  • a scanned handwritten signature inserted into a PDF,
  • a signature drawn with a mouse or touchscreen,
  • confirmation using a button such as “Conclude contract”,
  • a signature completed through an individually issued link.

These methods do not all provide the same quality of evidence. An image pasted freely into a PDF is easier to copy than a signature connected to a documented authentication and approval process. Nevertheless, both may fall within the category of an SES.

General rule: many contracts have no formal requirement

Under German civil law, many contracts can generally be concluded without a particular form. An agreement may therefore be made orally, by email, through conduct or within a digital workflow. Where the law does not prescribe a specific form, an SES can generally be used to express and document contractual intent.

This often applies to documents such as:

  • quotations and order confirmations,
  • purchase and service agreements,
  • ordinary B2B framework agreements,
  • non-disclosure agreements,
  • approvals and internal authorisations,
  • handover or acceptance records,
  • consents, unless a more specific form is required.

The absence of a formal requirement does not mean the absence of legal requirements. A contract still requires corresponding declarations of intent and sufficiently clear terms. If a dispute arises, it should also be possible to establish who made which declaration in relation to which document.

When an SES will usually be sufficient in practice

An SES is a natural option where neither legislation nor the contract itself requires a particular form and the commercial and legal risks are manageable.

Consider a quotation issued by a trades business and accepted by a customer through a personal link. The process records the PDF presented to the customer, the declaration of acceptance, the date and time, and the email address used. If no special form applies, an SES can provide an appropriate way to conclude and document the agreement.

The same may apply to a non-disclosure agreement between two companies. If the individuals are already known through an established business relationship, corporate email accounts and existing contacts, an SES may be proportionate. An AES or QES may be more appropriate where highly sensitive information, substantial contractual penalties or an unknown counterparty are involved.

When selecting a signature level, organisations should consider in particular:

  • Does a statutory form requirement apply?
  • Does the contract itself require writing or a particular signature level?
  • How reliably has the signatory been identified?
  • Can the signed version of the document be determined unambiguously?
  • How likely is it that the transaction will later be disputed?
  • What would be the financial, regulatory or operational consequences of an invalid contract?

Where an SES is not sufficient

An SES does not automatically replace a statutory written-form requirement. Under German law, using electronic form as a substitute for written form generally requires a QES. This follows in particular from section 126a of the German Civil Code. A scanned signature or one drawn on a screen does not meet that requirement.

In some cases, legislation excludes electronic form entirely. Examples under German law include:

  • termination agreements and notices terminating employment under section 623 of the German Civil Code,
  • declarations of surety to the extent that section 766 excludes electronic form,
  • transactions requiring notarisation, such as a contract for the sale of real estate.

The statutory form applicable to fixed-term employment contracts must also be considered separately. Where written form is required and electronic form is not excluded, a QES can generally serve as the electronic substitute; an SES cannot.

The parties may also establish their own form requirements even where legislation does not. A clause stating that “amendments must be made in writing” has to be interpreted in the context of the contract as a whole. Organisations should not assume without review that every electronic confirmation satisfies the agreed requirement.

Under Article 25(1) eIDAS, an electronic signature may not be denied legal effect or admissibility as evidence solely because it is electronic or does not meet the requirements for a QES. This does not mean that every SES carries the same evidential weight.

Only a QES expressly has the equivalent legal effect of a handwritten signature under Article 25(2) eIDAS. For an SES, a court may assess the specific circumstances to determine whether the declaration can be attributed to a particular person and whether the document was subsequently changed.

A signature image on its own provides limited information. A connected body of evidence is more useful and may include:

  • the exact document version or its hash value,
  • the date and time of each process step,
  • sender and recipient addresses,
  • authentication steps such as one-time codes,
  • declarations and actively selected checkboxes,
  • the completion status and the copy supplied to the signatory,
  • a tamper-resistant audit trail.

An audit trail does not convert an SES into an AES or QES. It can, however, improve traceability and therefore its practical evidential value.

Choose the signature level based on risk

Organisations should not set one signature level for every document. A risk-based model can classify document types according to formal requirements, identity risk, risk of alteration and the potential consequences of invalidity.

An internal classification might look as follows:

  • SES: standard contracts without formal requirements, involving known business partners and limited risk,
  • AES: contracts without formal requirements but with an increased need to protect identity and document integrity,
  • QES: documents for which statutory written form is to be replaced electronically, or transactions with particularly high evidential requirements,
  • Paper or notarised form: cases in which electronic form is excluded or notarisation is required.

More stringent is not automatically better. Unnecessarily burdensome identification can create friction and lead to the collection of additional personal data. Conversely, a weak process for an important contract may create avoidable evidential problems.

Consider GDPR and retention requirements

Electronic signature processes regularly involve personal data, including names, email addresses, timestamps, IP addresses and authentication information. Controllers need an appropriate legal basis and must comply with the principles of the GDPR.

Relevant considerations include:

  • data minimisation: collect only the information needed to conclude and evidence the contract,
  • transparency: provide clear information about the processing,
  • processing on behalf of the controller: review agreements with signature providers,
  • access control: protect contracts and evidence using role-based permissions,
  • deletion and retention: account for statutory duties and limitation periods,
  • international transfers: review storage locations and subprocessors.

IP addresses and device information should not be retained indefinitely merely as a precaution. The evidence required and the appropriate retention period should be determined for each type of contract process.

Designing a reliable SES workflow

A reliable workflow begins before the visible signature step. The recipient should be shown the complete document and should understand which action creates a binding declaration. Preselected consent boxes or ambiguous buttons can make the process harder to interpret.

After completion, the parties should receive or be able to download the final document. The stored evidence should remain linked to that exact version. If a contract is changed later, the system should create a new version and, where necessary, initiate a new approval process rather than overwrite the original record.

Access security is equally important. A signature link that can be forwarded without restriction offers less assurance than a time-limited link combined with a second factor sent through a separate channel. The appropriate safeguard depends on the transaction rather than on the label “SES” alone.

Conclusion

A simple electronic signature is sufficient for many everyday contracts that are not subject to a statutory or effectively agreed special form. Its practical suitability depends heavily on how well the process records identity, contractual intent, the relevant document version and the time of completion.

Organisations should therefore assess the full signing workflow rather than the visible signature image alone. A well-documented SES can be appropriate for standard transactions without formal requirements. Where statutory written form, a high risk of dispute or significant consequences are involved, an AES, QES or non-electronic form should be considered. Classification of a specific transaction remains a legal assessment and should be reviewed by a qualified professional where uncertainty exists.