INTRODUCTION
Indian law no longer treats electronic authentication as a fringe issue. The Information Technology Act, 2000 gives legal recognition to electronic records and electronic signatures[1], while the Bharatiya Sakshya Adhiniyam, 2023 sets out how such records are proved in court[2]. The real question is not whether electronic execution is possible. It is whether the chosen method gives enough certainty about identity, integrity, and consent when a dispute reaches litigation. On that question, digital signatures are materially stronger than ordinary electronic signatures, though both can be legally valid if properly used and properly proved.
CONCEPTUAL AND TECHNICAL BACKGROUND
Under section 3 of the IT Act, a subscriber may authenticate an electronic record by affixing a digital signature[3]. The provision expressly ties authentication to asymmetric cryptography and hash functions. In other words, the document is mathematically bound to the signatory’s private key, and any later change in the record can be detected. Section 3A expands the law beyond pure digital signatures and recognizes a broader category of electronic signature or electronic authentication technique[4], provided it is reliable and fits the Second Schedule. The Act also contemplates electronic signature certificates and certifying authorities under section 35[5].
That distinction matters. A digital signature is a specific cryptographic technique. An electronic signature is a wider umbrella that can include OTP-based authentication, Aadhaar-based e-authentication workflows, scanned signatures, or click-based assent, so long as the method is legally recognized and reliable in context. The statutory design therefore separates form from strength. A method can be legally valid without being equally strong as evidence.
LEGAL FRAMEWORK UNDER INDIAN LAW
The IT Act gives legal recognition to electronic records and electronic signatures in sections 4 and 5, and section 10A[6] strengthens the position of contracts formed through electronic means. Digital signatures are regulated through Chapter II and Chapter VI, while certifying authorities issue electronic signature certificates and digital signature certificates under section 35[7] and related rules. The statutory scheme also recognizes secure electronic records and secure electronic signatures, and section 16 authorizes the Central Government to prescribe security procedures and practices[8].
The evidentiary regime is now in the Bharatiya Sakshya Adhiniyam, 2023. Sections 61 to 63 deal with electronic or digital records and their admissibility[9], section 66 requires proof of electronic signature except in the case of a secure electronic signature, and sections 85 to 87 create important presumptions[10] for electronic agreements, secure electronic records, and electronic signature certificates. The key point is simple: secure electronic signatures get a stronger statutory presumption than ordinary electronic signatures.
This is where statutory validity and practical enforceability diverge. A standard electronic signature may be valid in law, but if it is challenged, the party relying on it must usually prove who signed, how the sign was generated, and whether the record remained intact. By contrast, a secure electronic signature is backed by stronger presumptions about intent and integrity, and an electronic signature certificate also attracts a presumption of correctness unless rebutted.
EVIDENTIARY VALUE, AUTHENTICITY, AND SECURITY
Digital signatures have the strongest evidentiary profile because they are designed to connect the signer, the document, and the time of signing through cryptography and certificate infrastructure. The law further supports this structure by requiring certifying authorities, licenses, and revocation procedures for digital signature certificates[11]. That means the court is not just looking at a picture of a signature. It is looking at a traceable trust chain.
Standard electronic signatures are more flexible but less self-proving. OTP-based signatures, email acknowledgements, and click-based assent[12] can be useful, especially for high-volume commerce, but they are vulnerable to identity theft, SIM-swap attacks, mailbox compromise, device sharing, and disputes over who actually controlled the credential at the time of signing. Their evidence value often depends on surrounding material such as logs, device metadata, IP records, timestamps, and witness testimony. In practice, the signature itself may be less persuasive than the audit trail around it. That is not a bug in the statute. It is the trade-off of a broader, lower-friction model.
Digital signatures are stronger, but they are not magic. They can still fail if the private key is compromised, if the token is stolen, if malware acts before signing, or if the certificate is revoked or improperly managed. The IT Act itself anticipates these problems through rules on secure control, security procedures, suspension, and revocation of certificate[13]. So the practical question is not whether digital signatures are flawless. They are not. The question is whether they reduce the attack surface enough to justify their use where disputes are likely. They usually do.
JUDICIAL SCRUTINY AND BURDEN OF PROOF
The Supreme Court has repeatedly stressed that electronic evidence is admissible, but its proof is governed by statute. In Anvar P.V. v. P.K. Basheer[14], the Court held that secondary electronic evidence requires compliance with the certificate requirement then found in section 65B. In Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal[15], the Court reaffirmed that position and made clear that the certificate is a condition precedent for admissibility of electronic records by way of secondary evidence. Those holdings matter directly for electronic signatures because the signature is often proved through the electronic record and its surrounding metadata, not just by producing a paper printout.
The Court has also shown a practical willingness to accept technology-mediated transactions and evidence when reliability is established. In State of Maharashtra v. Dr. Praful B. Desai[16], the Court approved recording evidence through video conferencing. In Trimex International FZE Ltd. v. Vedanta Aluminium Ltd[17]., the Court treated email exchanges as sufficient to conclude a binding commercial arrangement. These cases support the broader proposition that Indian courts look to substance, not ceremony, but only where the record is reliable and the evidentiary foundation is sound.
COMPARATIVE JURISDICTIONAL NOTE
The European Union’s eIDAS Regulation is a useful comparator. Article 25 says that an electronic signature cannot be denied legal effect or admissibility[18] as evidence merely because it is electronic, and a qualified electronic signature has the equivalent legal effect of a handwritten signature. That model is tiered and explicit. India’s model is similar in structure but less rigidly segmented in everyday practice: it recognizes electronic signatures generally, yet gives the strongest legal comfort to secure signatures and certificate-based digital signatures. In short, EU law is more visibly graded; Indian law is more flexible but litigation-proofing depends more heavily on the quality of proof.
RECOMMENDATIONS
For high-value, regulated, or dispute-sensitive transactions, digital signatures should be the default. They offer better authenticity, stronger integrity protection, and cleaner proof in court. For routine workflows, standard electronic signatures can work, but only when backed by strong audit trails, user verification, timestamping, retention policies, and a clear record of consent. Businesses should also preserve the certificate chain, logs, and device metadata, because the signature alone is rarely the whole story in court.
For lawyers and organizations, the practical playbook is straightforward. Use digital signatures for contracts that may be litigated. Use OTP or click-based execution for low-risk matters only if the system captures identity, consent, and traceability. Check certificate validity and revocation status. Keep proof of the workflow. And never assume that a scanned signature is legally equivalent to a cryptographically verified signature. That assumption is how disputes become expensive.
CONCLUSION
Electronic signatures and digital signatures are both recognized under Indian law, but they are not equal in evidentiary strength. Electronic signatures offer flexibility and commercial convenience. Digital signatures offer stronger authenticity, security, and non-repudiation because they are built on asymmetric cryptography, hash functions, and certificate-based trust. Under current Indian law, the strongest legal position belongs to secure electronic signatures and certificate-backed digital signatures, especially when the document may face judicial scrutiny. So, signatures are legally useful and digital signatures are legally safer.
Author(s) Name: Yashasvi Nagar (College of Law, IPSA, Indore)
References
[1] Information Technology Act, 2000, Sec.4–5.
[2] Bharatiya Sakshya Adhiniyam, 2023, S. 61–63.
[3] Information Technology Act, 2000, S. 3.
[4] Information Technology Act, 2000, S. 3A.
[5] Information Technology Act, 2000, S.35.
[6] Information Technology Act, 2000, S 4, 5, 10A
[7] Information Technology Act, 2000, S 35.
[8] Information Technology Act, 2000, S 16.
[9] Bharatiya Sakshya Adhiniyam, 2023, S. 61–63.
[10] Bharatiya Sakshya Adhiniyam, 2023, S 85–87.
[11]Information Technology (Certifying Authorities) Rules, 2000.
[12] Pavan Duggal, Cyberlaw: The Indian Perspective 185–210 (2022).
[13] Information Technology Act, 2000, S. 37–39.
[14] Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473.
[15] Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.
[16] State of Maharashtra v. Dr. Praful B. Desai, (2003) 4 SCC 601.
[17] Trimex Int’l FZE Ltd. v. Vedanta Aluminium Ltd., (2010) 3 SCC 1.
[18] Id. art. 25.

