September 16, 2026

Electronic Signature: Types and Legal Validity Guide

Summary · 9 min read

What an electronic signature is under eIDAS, the simple/advanced/qualified levels, legal validity in Spain, and how to roll it out across your company.

An electronic signature is, under the EU's eIDAS Regulation, any data in electronic form that a person uses to sign — from a typed name to certificate-based cryptography. In Spain and across the EU it is fully legally valid, and the qualified level equals a handwritten signature. This guide explains the three levels, the evidence behind them, and how to adopt them in your company.

What an electronic signature is under the eIDAS Regulation

Regulation (EU) 910/2014, known as eIDAS, defines the electronic signature deliberately broadly: data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign. The key is not the technology but the intent — any electronic act by which a person expresses acceptance of a document can be an electronic signature.

That definition covers very different realities: a name typed at the end of an email, a signature drawn with a finger on a courier's screen, a click on an "I accept" button with the process logged, and, at the most sophisticated end, a signature backed by a qualified certificate issued by a trust service provider. All of them are electronic signatures; what changes between them is the strength of the evidence they generate.

This breadth has one important practical consequence: eIDAS forbids any court or public authority from rejecting a signature merely because it is electronic. The right question is therefore not "is it valid?" but "if the other party denies signing, can I prove who signed and what they signed?" The entire architecture of levels we cover next grows out of that question.

Electronic signature vs. digital signature: which term to use

This is the most widespread terminological confusion in the Spanish market. "Electronic signature" is the legal category: the eIDAS umbrella under which any signature made by electronic means fits. "Digital signature," by contrast, is a technical term for the specific cryptographic mechanism — private key, public key and certificate — used to build the higher security levels.

The relationship is set and subset: every digital signature is an electronic signature, but not every electronic signature is digital. An image of a handwritten signature pasted into a PDF is a simple electronic signature, not a digital one, because no cryptography protects it. If you want the technical inner workings — hashing, keys and certificates — our guide to digital signatures and how they differ from electronic signatures covers them in depth.

In business language the recommendation is simple: use "electronic signature" when you talk about contracts, validity and processes, and reserve "digital signature" for technical conversations about certificates. Confusing the terms invalidates nothing — but it can lead you to buy less evidence than your contracts actually need.

The three eIDAS levels: simple, advanced and qualified

eIDAS organizes the subject into three levels of increasing stringency. Knowing the ladder is the first step toward assigning each document the right level.

Simple electronic signature (SES). Any electronic data used with the intent to sign: a typed name, an image of a signature, an acceptance click. It is valid, but its evidential weight depends entirely on the context and on the evidence the platform captured around the act.

Advanced electronic signature (AES). It must be uniquely linked to the signatory, capable of identifying them, created using means under their sole control, and able to detect any subsequent change to the document. In practice this is achieved through signer authentication plus cryptography, and it is the reasonable standard for most business contracts. Our article on the advanced electronic signature as the business standard explains why.

Qualified electronic signature (QES). An advanced signature created with a qualified signature creation device (QSCD) and based on a qualified certificate issued by a supervised trust service provider. It is the only level with a legal presumption: it is equivalent to a handwritten signature throughout the European Union. For the wider regulatory picture, see our guide to the eIDAS-compliant electronic signature.

The Spanish framework is twofold. The eIDAS Regulation applies directly across the country, and Law 6/2020 regulates electronic trust services: who may issue qualified certificates, how providers are supervised, and which technical requirements they must meet.

Three rules follow from that framework, and every company should be clear on them. First: no document may be rejected as evidence solely because it was signed electronically, whatever the level. Second: the qualified signature enjoys a presumption of validity and equals the handwritten one. Third: with simple and advanced signatures, if the other party challenges the signature, the burden of proof falls on you — you must demonstrate who signed and that the document was not altered.

That third rule is the most underestimated one. In litigation, the difference between winning and losing rarely lies in the act of signing but in the quality of the evidence file: signer authentication, timestamps, IP addresses, a log of every event in the process. The certificate of completion and audit trail model shows exactly what data a signing operation should preserve so it stands up in court.

Which signature level each document needs

The practical decision fits in one table: cross the document's risk with the evidential strength you would need if the agreement were ever questioned.

DocumentLevelWhy
Internal approvalSimpleLow risk
Client quoteSimpleSpeed matters
Sales contractAdvancedDispute evidence
Employment contractAdvancedVerified identity
Official filingQualifiedLegal requirement
Credit or guaranteeQualifiedLegal presumption

Two nuances the table cannot hold. First: a simple signature is only advisable inside a platform that records the process, because a loose signature image in a PDF generates no evidence at all. Second: "qualified" does not mean "always better" — it means "necessary when the law or the risk justifies it." Demanding a qualified certificate for a vacation request adds friction without adding legal certainty.

How to adopt electronic signatures: from pilot to company-wide rollout

Successful adoption rarely starts by buying licenses for the entire workforce. It follows a four-stage path, and each stage has its own success criterion.

1. Choose the pilot scenario. Look for a process with high volume, moderate risk and visible pain: standard sales contracts or HR documents are the usual candidates. Avoid starting with the company's most complex case.

2. Assign the signature level. Using the table above, decide which level fits the pilot and document the reasoning. That reasoning will later become the internal policy governing every other document type.

3. Design the workflow and the evidence. Define who initiates, who signs, in what order, with which authentication and which reminders. Verify that the platform produces a complete evidence file for every transaction. Our guide to setting up an electronic signature workflow details this phase.

4. Measure and scale. Cycle time, completion rate and pilot errors will tell you what to adjust before extending the system to more departments and document types.

Scaling from pilot to company-wide rollout with Nota Sign

Many electronic signature projects stall at the same point: the pilot works, but as it expands the level policy drifts, the evidence stops being homogeneous, or the invoice grows with every new user. Nota Sign, FaDaDa's global e-signature platform, is built for that full journey. The policy you define in the pilot — which documents go with simple, which with advanced and which require qualified signatures — holds as you grow, because the platform covers all three levels of the eIDAS framework and the legal requirements of more than 100 countries and regions: what you decide in Madrid today remains valid when the company signs in other markets.

The due diligence your IT team will run is answered too: Nota Sign has completed a SOC 2 Type II audit, with security, availability and confidentiality controls reviewed independently on an ongoing basis, and operates regional data centers so data residency can be aligned with each jurisdiction. And the last reason pilots fail to scale — cost — disappears under a model with no per-seat fees: going from ten signers to ten thousand does not multiply the bill, while mid-sized and large organizations can structure tailored plans. If you want to design your route from pilot to full deployment, talk to our team.

FAQ

Find the right eSignature solution for your team

Nota Sign helps businesses build compliant agreement workflows, and our content follows strict editorial guidelines.

Discover a better way to e-sign your documents

Start for Free
Contact Sales