eSignature Legality Guide

eSignature Legality in Malaysia

Electronic signatures are recognized in Malaysia under Electronic Commerce Act 2006 and Digital Signature Act 1997, as amended. Their legal effect, evidentiary weight and equivalence to handwritten signatures are determined by the signature method, the transaction and the applicable statutory formalities or exclusions.

E-Signature Legality Summary

This guide explains the electronic-signature framework in Malaysia, including the governing laws, legal effect, accepted signature methods, validity requirements, exclusions and practical business uses.

Applicable Laws

Electronic Commerce Act 2006 and Digital Signature Act 1997, as amended

Legal Status

Electronic records and signatures receive legal recognition in Malaysia under Electronic Commerce Act 2006 and Digital Signature Act 1997, as amended. The signing process must also satisfy every document-specific rule on identity, evidence, delivery, retention, witnessing, notarization, registration or filing.

Regulatory Authority

Malaysian Communications and Multimedia Commission (MCMC)

Legal Recognition (Effect)

The legal effect of an electronic signature is assessed under Electronic Commerce Act 2006 and Digital Signature Act 1997, as amended. The assessment covers signer intent, reliable attribution, integrity of the signed record and compliance with every prescribed form for the document or transaction.

Accepted Types of Electronic Signatures

Electronic signature types recognized in Malaysia: Digital Signature, Electronic Signature (ES).

Reliance on an unreliable Digital Signature is at the relying party’s risk of forgery. A recipient that elects not to rely on such a signature must promptly notify the signatory of that decision and the reasons for it, pursuant to Article 63 of the Digital Signature Act (DSA). A Digital Signature is valid if it is verified by reference to the public key contained in a valid digital certificate issued by a licensed certification authority, was intentionally affixed by the signatory, and the recipient has no reason to know that the signatory breached the obligations of a subscriber or unlawfully possessed the private key used to affix the signature, pursuant to Article 62 of the Digital Signature Act (DSA). For commercial transactions and government-to-public transactions, an Electronic Signature must be associated with electronic information, identify the person sufficiently, indicate the person’s approval of that information, and be appropriately reliable in the circumstances, including by being unique, under the person’s control, and resistant to tampering. These requirements are set out in Article 9 of the Electronic Commerce Act (ECA) and Article 13 of the Electronic Government Activities Act (EGAA).

Electronic signature (ES): Electronic Signature (Section 9 of the ECA) (Section 13 of the EGAA) refers to any letter, character, number, or other symbol in electronic form attached to or logically associated with a data message, used to identify the signer and indicate their approval of the content of the data message.

  • Digital Signature (DS):

Digital Signature (Section 62 of the DSA) is a specific technical implementation of an electronic signature based on Public Key Infrastructure (PKI) technology. It uses asymmetric cryptography and hash functions to uniquely associate with the signer and detect data tampering.

Legal Requirements for Electronic Signatures

Unreliable Digital Signature (Section 63 of the DSA) a) If relying on such signature, the risk of the signature being forged is borne; b) If not relying on such signature, the recipient shall immediately notify the signer of the decision not to rely and the reasons for such decision.

Digital Signature (Section 62 of the DSA) a) Requirements: i. Verified by reference to the public key listed in a valid digital certificate issued by a licensed certification authority; ii. The digital signature was affixed by the signer with the intention of signing; iii. The recipient has no reason to believe that the signer has breached the duty as a subscriber or does not rightfully hold the private key used to affix the digital signature.

In laws related to commercial transactions and transactions between the government and the public: ES: Electronic Signature (Section 9 of the ECA) (Section 13 of the EGAA) a) Requirements: Associated with electronic information and sufficiently identifies the individual, sufficiently indicating the individual's approval of the relevant information; b) Possesses appropriate reliability (uniqueness, control, tamper-evidence) based on the circumstances in which the electronic signature is used.

Limitations and Exceptions

Section 2 and Schedule of the ECA:

  • Power of Attorney
  • The creation of Wills and Codicils
  • The creation of Trusts
  • Negotiable Instruments
  • Statutory Declarations (Case: SS Precast Sdn Bhd v. Serba Dinamik Group Bhd & Ors [2020] MLJU 400)

Industry Applications and Typical Use Cases

Section 2 and Schedule of the ECA:

Transactions between the government and the public (EGAA) E.g., Taxation: Electronic tax filing for companies and individuals. Corporate Matters: Submission of statutory documents to the Companies Commission (annual returns, financial reports). Customs: Electronic customs declarations for import and export.

DISCLAIMER: The information on this page is provided for general informational purposes only and does not constitute legal advice. Laws, regulations and regulatory guidance are updated over time, and their application is determined by the facts and circumstances of each transaction. Consult qualified legal counsel in the relevant jurisdiction before relying on this information.

Last updated: January 16, 2026

Sign with confidence, anywhere

Build secure, compliant eSignature workflows with Nota Sign.

Nota Sign electronic signature workflow