What eIDAS Actually Says About Electronic Signatures (And What It Does Not Guarantee)
What eIDAS means for electronic signatures, the difference between SES, AES, and QES, and what everyday click-to-accept flows actually prove under EU law.
[!CAUTION] DISCLAIMER: This article provides general information about eIDAS and electronic signatures. It is not legal advice and cannot determine whether a particular agreement will be enforceable in your specific situation. For advice on your circumstances, consult a qualified lawyer.
In short
eIDAS is the EU regulation that provides a common legal framework for electronic signatures and trust services.
It says that an electronic signature cannot be denied legal effect or rejected as evidence solely because it is electronic or does not meet the requirements for a Qualified Electronic Signature.
That does not mean every agreement accepted electronically is automatically valid or enforceable.
Electronic signatures are generally divided into three levels: Simple, Advanced and Qualified, with each level having stricter requirements than the previous one. Only a Qualified Electronic Signature has the same legal effect as a handwritten signature throughout the EU. The other two levels still have legal effect under eIDAS, but how much weight they carry as evidence in a dispute is assessed case by case, under national law.
This short article explains how that framework works. Please note that it is not legal advice and cannot tell you whether a particular agreement will be enforceable in your situation. For that, speak to a qualified lawyer.
Why this matters when sending work to clients
If you are a freelancer sending a Figma file, pitch deck, proposal or strategy document, you may have wondered whether the recipient should accept something before receiving access.
For some people, that leads to another question:
“Could a checkbox on a website actually count as a signature?”
The honest answer is that it can, but it depends on how the acceptance process works. The existence of a checkbox alone is not enough.
The three levels of electronic signature
Simple Electronic Signature
A Simple Electronic Signature, usually shortened to SES, is the broadest level.
A typed name, an email reply stating “I agree,” or a click to accept action may count as an electronic signature when someone uses it with the intention of accepting the specific terms connected to it.
An SES cannot be denied legal effect simply because it is electronic. However, it does not automatically establish who performed the action or make the underlying agreement enforceable.
Verifying an email address is also not the same as accepting an agreement. Email verification may show that someone had access to a particular inbox. The separate acceptance action is what records their apparent intention to accept the terms.
Advanced Electronic Signature
An Advanced Electronic Signature, or AES, has to meet a stricter standard.
It must be uniquely linked to the signer and capable of identifying them. It must be created using signature data that the signer can use under their sole control with a high level of confidence. It must also be connected to the signed information in a way that makes later changes detectable.
Qualified Electronic Signature
A Qualified Electronic Signature, or QES, is an Advanced Electronic Signature created using a qualified signature creation device and based on a qualified certificate issued by a qualified trust service provider.
It is the only type of electronic signature that eIDAS gives the same legal effect as a handwritten signature throughout the EU.
This does not mean a QES can never be questioned. Like a handwritten signature, it may still be challenged under national procedural rules. The Court of Justice of the European Union has confirmed that national courts may assess the evidentiary value of a QES under the same rules that apply to handwritten signatures.
Where everyday acceptance flows fit
Many everyday business agreements are accepted by clicking a button. This includes processes where someone must accept terms before viewing a file.
That acceptance may be defined as a SES if the recipient’s action clearly shows an intention to accept the specific terms presented.
This is the type of process SignToSee is designed to support. Whether a particular acceptance legally qualifies as an electronic signature still depends on what the recipient saw, what action they took, how that action was connected to the terms and what evidence was retained.
A QES is intended for situations where the law or one of the parties requires a higher level of assurance. It involves a qualified trust service provider, a qualified signature creation device and a prescribed identity verification process.
For access to a file for evaluation purposes, that level of formality may be disproportionate. The right approach depends on the value involved, the risks and any relevant legal requirements.
With an SES, the label alone does not make the evidence strong. What matters is the information surrounding the acceptance.
Legally admissible does not mean automatically successful
People sometimes treat electronic acceptance as a simple switch. Either it is legally binding or it is not.
In practice, it is more complicated.
eIDAS says that an electronic signature cannot be denied legal effect or rejected as evidence solely because it is electronic or does not meet the requirements for a QES.
If a dispute reaches court, the available evidence may still need to be assessed. A court might consider questions such as:
- Was the signer’s identity established or merely entered into a form?
- Is there a reliable record of when the acceptance happened?
- Can later changes to the accepted terms be detected?
- How clearly is that person connected to the acceptance?
- Which version of the terms did they see?
An SES with little supporting information may be harder to authenticate if it is disputed.
Its strength depends on all the available evidence. For example, the other party might admit that they performed the acceptance action. That could largely resolve that particular question, although there could still be disagreements about their intention, authority or the terms they saw.
If the acceptance is disputed, national procedural law determines who has to prove what. In practice, a party relying on an SES should be prepared to show how the acceptance was connected to the person who allegedly accepted it.
Evidence of access to the stated email account, a reliable timestamp, the precise terms presented and a properly protected record may make the acceptance easier to substantiate. It nevertheless remains an SES.
What eIDAS does not promise
eIDAS does not give an SES a fixed evidential weight. It does not guarantee that an SES will be treated as strong evidence in every dispute, make every click legally binding or repair unclear and unenforceable terms.
It also does not guarantee that the person using an email account is the person named in the agreement.
National contract law and court procedure still matter.
Applicable law and court jurisdiction are also separate questions. In many EU disputes involving parties in different countries, the law applicable to an agreement is determined under the Rome I Regulation. Jurisdiction is addressed separately by the Brussels I bis Regulation.
Choosing the law of one country does not automatically mean that only the courts of that country can hear a dispute. Special rules can also apply, particularly in consumer and employment contracts.
Where the acceptance record comes in
The strength of an SES depends partly on the information surrounding it. That information should be captured when the recipient accepts the terms, rather than reconstructed later from memory or an email conversation.
A well designed acceptance process may record:
- The email address used during acceptance
- Evidence that someone had access to that email account at the time
- The date and time of acceptance
- The exact version of the agreement presented
- The protected content connected to the agreement
- A method for detecting later changes to the agreement or acceptance record
Recipients should also be able to save or reproduce the terms made available to them.
There are two important limitations.
First, email verification shows access to an inbox. It does not necessarily establish the legal identity of the person using it.
Second, a cryptographic hash can help detect changes to the terms, but it does not prove identity, intention or the time of acceptance. Its usefulness also depends on how securely the hash and associated records are stored and protected.
Ordinary and qualified electronic time stamps
An ordinary timestamp generated by a platform may be useful evidence. It is not the same as a qualified electronic time stamp under eIDAS.
A qualified electronic time stamp benefits from a legal presumption concerning the accuracy of its date and time and the integrity of the information connected to it.
An ordinary timestamp does not receive that same presumption. It may still support an acceptance record, but its reliability can be assessed together with the other evidence.
When to involve a lawyer
Having a lawyer review important terms is always sensible. This article explains the general legal framework, but it cannot determine whether particular terms will be valid or enforceable in a specific country or dispute.
Legal review becomes especially important when:
- The work contains valuable or sensitive intellectual property
- You are entering an ongoing commercial relationship
- A substantial amount of money is involved
- You are dealing with consumers rather than other businesses
- You want to choose a particular governing law or court
- You are unsure whether the agreement meets the requirements of a specific country
Simply said
eIDAS provides a common legal framework for electronic signatures across the EU.
An electronic signature cannot be denied legal effect or rejected as evidence solely because it is electronic or does not meet the requirements for a QES.
That does not make every click automatically valid, binding or equally persuasive as evidence. The applicable law, the terms presented, the recipient’s intention and the information surrounding the acceptance still matter.
Try SignToSee free and create up to 3 protected links for your next client document.
Official sources
Continue reading
Watermark, NDA, or Gated Access: Which One Should Freelancers Use?
A practical guide to what each method actually does, where it falls short, and when a combined workflow makes more sense.
How to send design concepts to clients before approval without losing control
Freelance designers often have to share previews, concepts, and client-facing files before trust is fully in place. Here’s an easy, more structured way to do that.
Ready to stop sending bare links?
A link with your name on it, and a record of who opened it and when. It's free to start.
Start on the Free plan. No credit card required.