E-signatures · Glossary
What is a simple electronic signature (SES)?
A simple electronic signature is the base level under the eIDAS Regulation: data in electronic form attached to or logically associated with other data and used by the signatory to sign. There is no requirement for a certificate, a device or a verified identity, which is why the category is so broad.
Almost every signature collected by an ordinary business sits at this level. It is also the level that benefits most from the records kept around it, because the mark itself carries so little.
Nuwan Madhusanka · Co-founder
5 min read · Published
| Record kept | What it answers | What it still leaves open |
|---|---|---|
| Emailed link to one address | The invitation reached that mailbox | Who was reading the mailbox |
| Access code shared by phone | The signer knew something out of band | Whether the code was passed on |
| Emailed one time code | The signer held that mailbox at signing time | A shared or delegated inbox |
| Address and timestamp per event | Where and when each step happened | The person behind the connection |
| Hash of the document at signing | Exactly which file was signed | Nothing about identity |
The definition is a floor, not a description
Article 3 of the regulation defines an electronic signature without adjectives, and everything that fails the advanced tests lands here. A name typed into a field qualifies. So does a drawn mark, a click on a button, and a scanned image dropped into a PDF. Because the category is defined by what it does not require, two signatures at the same level can be worlds apart in practice: one collected through a checked link with a full event log, another pasted into a document by anybody who had the file. The level tells you what was not required, not what was done.
Why courts still take it seriously
The regulation says a signature cannot be denied legal effect or admissibility merely because it is electronic or because it fails to meet the higher levels. That non discrimination rule is the working protection for ordinary business. The rest is evidence. If the other side denies signing, the question becomes what the record shows, and a simple signature with a solid trail routinely beats an advanced one with a thin one. Judges are assessing whether this person agreed to this document, which is a factual question rather than a classification exercise.
Where the risk actually concentrates
Three places. Shared inboxes, where nobody can say which employee clicked. High value or high dispute documents, where the counterparty has an incentive to test the record. And documents whose form is prescribed by law, where the level may not be the issue at all because the act itself has to be executed a particular way. For everything else, the cost of upgrading the process usually outruns the risk, and the sensible move is to spend on identity checks for the small number of documents that warrant them.
Making a simple signature harder to deny
Send to a named individual rather than a role address. Add a second factor when the value justifies it. Record consent with its wording and version, so the signer's agreement to sign electronically is provable. Keep an event log that cannot be quietly rewritten. Hash the document at the moment of signing so the version is fixed. None of that changes the eIDAS level, and all of it changes the outcome of an argument, which is the only measure that matters once a dispute starts.
What a signing service records at this level
Choosing the email link only method leaves the level simple and the record dependent on the mailbox. Adding an access code of at least four characters, or an emailed six digit code that expires in ten minutes, adds a factor without changing the classification. Every step lands in an audit trail of eighteen event types chained with sha256, and the certificate of completion prints the verification method used, the signing time, the address, and the consent version accepted for each signer.
Writing a policy instead of deciding each time
Teams that sign regularly do better with a short written rule than with case by case judgement, because the judgement always happens under time pressure at the end of a negotiation. A workable policy fits on half a page. List the document types the business actually sends. Against each, name the verification method required, whether a second person must be in the signing order, and who may approve an exception. Set the trigger for stepping up: a value threshold, an indemnity or restraint clause, a counterparty nobody has dealt with before, or anything a regulator might read. Say what happens with shared mailboxes, since that single habit undoes more evidence than any technical choice. Review it once a year rather than after an incident. The point is not the level, which stays simple in almost every case, but consistency: a process applied the same way every time is far easier to defend than one that was tightened only for the document somebody happened to worry about on the day.
Questions people ask
Is a simple electronic signature legally valid?
Yes for most agreements. European law forbids denying it effect purely for being electronic or for not meeting a higher level, and single tier regimes such as Australia and the United States take the same practical position. Validity fails on document type or lack of intent, not on the tier of the signature.
Is SES the same as a click to accept?
A click can be a simple electronic signature if the person intended it as their signature and the interface made that clear. Labelling matters: a button that says continue is weaker evidence of intent than one that says I agree and sign, shown next to the terms being agreed.
Do I need to upgrade for contracts over a certain value?
No threshold appears in the statutes. Value is a proxy for how hard somebody will fight, so it is a reasonable trigger for your own policy. A common approach is a second factor above a set amount and for anything with a termination or indemnity clause worth arguing over.
Can a simple signature be used for employment contracts?
In most jurisdictions yes, and it is very common. The cautions are elsewhere: some countries require specific clauses or language for particular terms, and a few require paper for restraint or apprenticeship documents. Check the local employment rules rather than the signature rules.
What if the signer says somebody else used their email?
That is the classic attack on this level, and the answer comes from the record. A one time code sent at signing time, an address that matches their usual pattern, a consent acceptance and a document hash all narrow the claim. If none of that exists, the dispute is genuinely open.
Does the term appear in Australian or US law?
No. The three level split is a European construction. Australian and United States statutes define one category of electronic signature and let the surrounding evidence do the work, so an Australian lawyer will ask what your process recorded rather than which tier you used.
Make one with e-signatures
The button opens the generator with this use case already described. Change the wording to match your own.
Send a document for signingRelated questions
- What is eIDAS?eIDAS is the EU regulation covering electronic signatures, seals, timestamps and identity. What it sets out, what the 2024 amendment added, and who it binds.
- What is the ESIGN Act?The ESIGN Act is the US federal law giving electronic signatures legal effect. Its four conditions, the consumer consent rules, and the documents it excludes.
- Is an electronic signature legally binding?In most countries yes: a signature cannot be denied effect merely because it is electronic. What the statutes require, and the documents still excluded.
- What is an electronic signature?An electronic signature is any electronic mark made to show intent to sign. The four common forms, what each one proves, and how signing software records them.
Written and checked by the OneCraft team. Last checked .