Digital Signature vs E-Signature: What's Legally Binding in India?

A digital signature uses cryptography to prove a document wasn't altered. Here's how it differs from a simple e-signature in Indian law.

Oct 7, 2026 - 12:05
5 min read
 0
Digital Signature vs E-Signature: What's Legally Binding in India?

You've just finished filing your income tax return online, and instead of printing a form and signing it with a pen, you click a button that says "Sign and Submit." Somewhere in that click, math happens that a courtroom will treat as more reliable evidence than your actual handwriting. Most people never ask what that math is, or why a scanned signature pasted onto a PDF isn't the same thing at all.

What a digital signature actually does

A digital signature isn't a picture of your signature — it's a cryptographic proof built from two things: a hash function and a key pair. A hash function takes a document, however long, and crunches it into a short, unique string of characters called a hash. Change even one comma in that document and the hash comes out completely different. When you "digitally sign" a file, software encrypts that hash using your private key — a secret piece of data only you hold, paired with a public key anyone can use to check your work.

Anyone with your public key can then verify two things at once: that the signature really came from your private key, and that the document hasn't been altered since you signed it, because the hash still matches. This is the same public-key cryptography that underpins how encryption protects your data more broadly, and the same trust model your browser uses when it checks a website's certificate.

A digital signature doesn't prove who you are. It proves the document hasn't changed since whoever held that key signed it.

Digital signature vs e-signature: not the same thing

This is where most people get tripped up, including plenty of businesses that should know better. An "e-signature" is a broad legal term for any electronic indication of consent — typing your name into a web form, drawing your signature with a mouse, or clicking "I agree" on a terms page. It's convenient and legally valid for plenty of everyday purposes, but it carries no built-in proof that the document wasn't edited afterward, and relatively weak proof of who actually clicked.

A digital signature is a specific, cryptographically verifiable kind of e-signature. Every digital signature is an e-signature, but very few e-signatures are digital signatures in this strict sense. The difference matters most when something is disputed later and someone has to prove, technically, that a document is exactly what was originally signed.

  • E-signature: typed name, scanned signature image, or a click-to-accept checkbox — fast, but weak as standalone proof of integrity.
  • Digital signature: backed by a cryptographic key pair and usually a certificate — tamper-evident and designed to hold up as legal evidence.

How this works under Indian law

India dealt with this distinction unusually early. The Information Technology Act, 2000 gives digital signatures legal recognition, and documents signed this way are treated as equivalent to a handwritten signature in court, provided the signature was created using a valid Digital Signature Certificate (DSC) issued by a licensed Certifying Authority. A DSC is essentially an ID card for your public key — it ties that key to your verified identity, the way a passport ties a photo to a name.

In practice, Indian professionals run into DSCs constantly without necessarily knowing the theory behind them. A Class 3 DSC, usually stored on a small USB token, is mandatory for company incorporation and annual filings with the Ministry of Corporate Affairs (MCA), for GST registration and certain returns, for filing an income tax audit report, and for bidding on most government e-tender portals. Separately, India also recognises Aadhaar-based eSign — where UIDAI verifies your identity through an OTP or biometric check and a licensed provider generates a digital signature on your behalf in that moment — which is why services like DigiLocker can produce instantly, legally signed documents without anyone owning a USB token at all.

Where people actually get this wrong

Most of the real-world risk isn't cryptographic, it's procedural. A handful of mistakes keep showing up:

  1. Treating a scanned signature as a digital signature. A JPEG of your signature pasted into a Word file proves almost nothing if challenged — it has none of the tamper-evidence a real digital signature provides.
  2. Sharing a DSC USB token. Company staff sometimes hand a director's token to an accountant "just for convenience." Legally, anything signed with it is treated as if that director signed it personally.
  3. Letting a DSC expire mid-filing season. Certificates are typically valid for one to three years; renewing late can cause missed MCA or GST deadlines that carry their own penalties.
  4. Falling for eSign OTP phishing. Because Aadhaar eSign relies on an OTP, fraudsters impersonating banks or government portals try to trick people into approving a signature request they never actually initiated — treat an unexpected eSign OTP exactly as warily as a banking OTP.

None of this requires becoming a cryptography expert. If you're a founder, freelancer, or small business owner in India, the practical rule is simple: use a proper DSC or Aadhaar eSign for anything that's legally or financially consequential — tax filings, contracts, company paperwork — and save plain e-signatures for low-stakes internal approvals where a dispute would never really arise. The technology behind that little "verified signature" badge is quietly doing more legal heavy lifting than most of the documents it's attached to.

Short URL: https://code24.in/7b19efa2

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Ashif Sadique As an full-stack developer, I'm passionate about sharing tutorials and tips that aid other programmers. With expertise in PHP, Python, Laravel, Angular, Vue, Node, Javascript, JQuery, MySql, Codeigniter, and Bootstrap. To me, consistency and hard work are the keys to success.