
India
Fully legal
Overview
Intro & Key Facts
Quick Summary
Practical Usage
Permitted Document Types
Commercial contracts and vendor agreements
NDAs
Purchase orders and invoices
Software licenses and SaaS subscription agreements
MSAs
Employment contracts and offer letters
Insurance e-proposals
General B2B correspondence and terms of service
Restricted Document Types
Negotiable instruments other than cheques
Powers of attorney
Trust deeds
Wills and other testamentary dispositions
A 2022 amendment exempted instruments involving RBI, SEBI, IRDAI, NHB, or PFRDA-regulated entities from the first two exclusions above
Common Exclusions
Authentication Required
Signer identification: Firma.dev uses email-link authentication with optional SMS verification.
Document integrity: tamper-evident documents with cryptographic sealing and a complete timestamped audit trail.
Section 3A(2) reliability test: the signature must be uniquely linked to the signatory, created under their sole control, with any later change to the signature or record detectable. No Indian-issued certificate is required to meet this standard for commercial contracts.
Restrictions
Signing Workflow Controls
Generally Permitted
Time-limited signature windows.
Sequential signing order.
Mandatory field completion.
Document expiration dates.
IP-based access restrictions.
Password-protected envelope access.
SMS verification codes.
Attachment requirements.
May Require Special Handling or Exclusions
Restrictions that prevent signers from reviewing the complete document before signing.
Restrictions that obscure material terms.
Blanket prohibitions on retaining personal copies.
Requirements for specific hardware or paid software to complete signing.
Legal Requirements
India E-Signature Law Explained
Legal Frameworks
Regulatory Bodies
Minimum Retention
No single general statute sets a retention minimum for e-signed commercial contracts. The Limitation Act 1963 gives most contract claims a 3-year limitation period, a reasonable floor for retention planning; regulated sectors carry their own separate requirements.
Retention Notes
Data, Privacy & Cross-Border
Data Privacy and Compliance India
Privacy Frameworks
Digital Personal Data Protection Act 2023 (DPDP Act), notified in phases from November 2025, not yet fully in force
Privacy Compliance Status
Firma.dev processes data as a processor. EU-only hosting in AWS Paris means no data is stored in India. India's DPDP Act 2023 has no general data-localization mandate for contract or e-signature data, so EU hosting satisfies current requirements.
Privacy Notes
The DPDP Act 2023 is notified but not fully in force. Only institutional provisions (the Data Protection Board of India) are active as of September 2026. The Consent Manager registration framework activates 13 November 2026, and substantive data-fiduciary obligations commence 13 May 2027. Until then, the older IT Rules 2011 (SPDI Rules) remain the operative data-protection baseline.
Data Residency
Adequacy Decision
India has no GDPR adequacy decision from the European Commission. This does not directly affect Firma.dev's India operations, since Firma hosts and processes data in the EU rather than transferring EU data to India.
Cross-Border Transfers
Unrestricted by default. The DPDP Act's Section 16 uses a negative-list model: transfers are allowed to any country except ones the government specifically notifies as restricted, and none are notified as of this writing. This provision is not yet in force (commences 13 May 2027), so no DPDP-specific transfer restriction currently applies.
Residency Notes
No general data-localization law applies to e-signature or contract data in India. The DPDP Act gives the Central Government discretion to notify specific data categories for mandatory localization, not yet exercised. A separate 2018 RBI circular requiring in-country storage applies only to licensed payment-system operators, not to a document-signing platform like Firma.dev.
Maximum Retention
Not established by a general statute; DPDP's storage-limitation principle is not yet in force (commences May 2027). Sector-specific rules (company law, tax, AML/KYC) apply independently in the meantime.
Industry Compatibility
E-Signatures by Industry in India
Fully Supported Industries
General Commercial
SaaS Software
HR Tech Employment
Education/Edtech
Construction
Supported with Agreement
Healthcare
Life Sciences/Pharma
Insurance
Financial Services/Fintech
Legal Tech
Real Estate Tech
Should Consult Counsel
Government
Industry Matrix Notes
Most B2B commercial use cases work with a general reliable electronic signature under Section 3A(2), no certificate required. Insurance has an explicit regulatory green light for OTP-validated e-proposals. Financial services and healthcare carry KYC and consent-management overlays worth planning around, not blockers. Real estate is a two-law nuance: the IT Act's own bar was lifted in 2022, but property registration still needs in-person verification in most states. Government interactions typically expect a Digital Signature Certificate or Aadhaar eSign, both outside Firma.dev's current scope.
General Commercial
Standard B2B contracts, vendor agreements, NDAs, purchase orders, and service agreements are valid under the Indian Contract Act 1872 and enforceable when executed electronically under IT Act Sections 5 and 10A. No special signature tier is required beyond reliable signer identification and a tamper-evident record.
SaaS Software
SaaS companies can rely on a general reliable electronic signature for software licenses, subscription agreements, API terms of service, and MSAs. Section 10A recognizes contract formation by electronic means, and courts have upheld electronically formed commercial agreements between sophisticated parties. Firma.dev's API-first signing fits self-serve onboarding and negotiated enterprise agreements alike.
Healthcare
No dedicated statute governs e-signatures on healthcare documents specifically. The Ayushman Bharat Digital Mission runs a separate consent-management architecture for sharing health records between providers, distinct from contract e-signing. Administrative agreements, vendor contracts, and consent forms for non-clinical purposes work with Firma.dev's standard signing flow; clinical-record-specific workflows should be evaluated against ABDM's consent layer separately.
Life Sciences/Pharma
Clinical trials fall under CDSCO's New Drugs and Clinical Trials Rules. This research did not find a CDSCO-specific electronic-signature regulation comparable to FDA 21 CFR Part 11, so treat GxP-adjacent signature requirements as a gap to confirm with counsel rather than an established rule. General commercial agreements between life-sciences companies, such as CRO contracts and research collaborations, work with Firma.dev's standard signing flow.
Insurance
The IRDAI (Issuance of e-Insurance Policies) Regulations 2016 require insurers to offer policies electronically and explicitly permit OTP-based validation as an alternative to a formal electronic signature for e-proposals and e-insurance-account setup. This is a favorable, OTP-friendly regime for a platform like Firma.dev.
Financial Services/Fintech
General commercial agreements between financial-services companies work with a standard reliable electronic signature. RBI and SEBI's KYC frameworks layer Aadhaar-based eKYC onto customer onboarding for regulated entities, but that access is restricted to licensed intermediaries and does not affect ordinary B2B contract signing. OTP-based non-face-to-face authentication triggers enhanced due diligence classification under RBI norms for KYC purposes specifically, not for general contract execution.
HR Tech Employment
Employment contracts, offer letters, NDAs, and HR policy acknowledgments are recognized as valid electronic records under the IT Act. One caveat: labor tribunals sometimes weigh state-specific labor protections alongside central IT Act validity in disputes, so enforceability can vary slightly by state even though the central framework is settled.
Legal Tech
General commercial and engagement-letter documents work with a standard reliable electronic signature. Certain court filings and regulated procedures may require a Digital Signature Certificate, so law firms should confirm the requirement per matter rather than assuming one signature tier covers every filing.
Real Estate Tech
A September 2022 amendment removed the IT Act's own bar on e-signing property sale and conveyance contracts. In practice, the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable instruments in most states, so e-signing alone does not complete a registered property transaction. Property management agreements, brokerage contracts, and other non-registrable real-estate-adjacent documents work with Firma.dev's standard flow.
Education/Edtech
Enrollment agreements, administrative contracts, and institutional vendor agreements work with a standard reliable electronic signature. No dedicated statute governs e-signatures in education specifically.
Construction
Construction contracts, subcontractor agreements, and change orders work with a standard reliable electronic signature under general contract law. No construction-specific e-signature rule was found; state-level RERA regulations govern real-estate project registration and sale-agreement terms but don't set a distinct signature requirement.
Government
Government interactions typically expect a Digital Signature Certificate or Aadhaar eSign, both of which require Indian licensing or a regulated intermediary relationship that Firma.dev does not currently hold. DigiLocker, India's government document wallet, treats its stored documents as legally valid under the IT Act, illustrating how seriously Indian government systems already treat digital documents. Contractors working with government bodies should plan for a DSC rather than Firma.dev's standard signing flow.
How we works
How Firma.dev Works in India
Firma.dev Supports
Firma.dev supports the general reliable electronic signature standard that covers the large majority of B2B commercial use cases in India.
Firma.dev provides signer identification via email-based authentication with optional SMS verification, tamper-evident documents with cryptographic sealing, complete audit trails with timestamped logging, and EU data residency with all data hosted in AWS Paris. This maps directly onto India's Section 3A(2) reliability test: a signature uniquely linked to the signatory, created under their sole control, with any later change detectable. Customer Workspaces give each of your customers a private, partitioned space with isolated templates and per-customer envelope usage, suited to multi-tenant SaaS building signing into their own product for the Indian market.
Legal Details
India's e-signature framework rests on the Information Technology Act 2000, substantially amended in 2008, alongside the general contract-law backbone of the Indian Contract Act 1872. Electronic evidence admissibility now runs through the Bharatiya Sakshya Adhiniyam 2023, which replaced the old Evidence Act's Section 65B with a stricter certification requirement from 1 July 2024.
The IT Act recognizes signatures on two tracks. Section 3 covers 'digital signatures': asymmetric cryptography tied to a Digital Signature Certificate issued by a Certifying Authority licensed by the Controller of Certifying Authorities. Section 3A, inserted by the 2008 amendment, covers 'electronic signatures' more broadly: any technique the Second Schedule recognizes as reliable, including Aadhaar-based eSign, plus a general reliability test for techniques not specifically listed. That test asks whether the signature is uniquely linked to the signatory, created under their sole control, and whether any later change to the signature or the signed record would be detectable, criteria that read almost identically to the EU's advanced-electronic-signature standard, despite India never adopting eIDAS vocabulary.
Neither a Digital Signature Certificate nor Aadhaar eSign is available to an unlicensed foreign platform. DSC issuance requires CCA licensing as a Certifying Authority. Aadhaar's authentication API is restricted to entities simultaneously recognized under the anti-money-laundering law and registered with UIDAI as a KUA or Sub-KUA, a closed list of mostly regulated financial and government entities. None of that matters for ordinary commercial signing, though. Section 3A's general reliability test, combined with Section 5's signature recognition and Section 10A's validation of electronic contract formation, is the same legal path DocuSign, Adobe Sign, and Zoho Sign already operate under in India, and it's the path a tamper-evident, audit-trailed platform like Firma.dev satisfies without any domestic license.
Exclusions are narrow and named rather than broad. The First Schedule bars electronic execution of negotiable instruments other than cheques, powers of attorney, trust deeds, and wills, though a 2022 amendment narrowed the first two exclusions to exempt instruments involving RBI, SEBI, IRDAI, or PFRDA-regulated entities. Property sale and conveyance contracts lost their IT Act exclusion the same year, though the separate Registration Act 1908 still requires in-person registration for compulsorily registrable instruments in most states, so the practical barrier for real estate outlives the legal one that used to justify it.
For most SaaS companies and B2B platforms operating in India, the general reliable-signature standard covers commercial contracts, employment agreements, NDAs, software licenses, and insurance e-proposals with confidence. A Digital Signature Certificate or Aadhaar eSign matters for government filings, specific regulated financial-sector KYC flows, and the small list of First Schedule exclusions, not for standard business documents.
Recent developments
E-Signature Landscape in India: 2026
Bharatiya Sakshya Adhiniyam 2023 (effective 1 July 2024): Replaced the Indian Evidence Act's Section 65B with Section 63, tightening the certification requirement for electronic evidence to two signatories plus a disclosed hash value. This is the current citation for how e-signed documents hold up as evidence in Indian courts.
DPDP Act 2023, phased commencement (from 13 November 2025): India's Digital Personal Data Protection Act is notified but not fully in force. Institutional provisions, including the Data Protection Board of India, are active now. The Consent Manager framework activates 13 November 2026. Substantive data-fiduciary obligations and the Section 16 cross-border transfer rules commence 13 May 2027.
Draft Digital India Act (in consultation, not enacted): A future law intended to eventually replace the IT Act 2000 entirely, including its electronic-signature provisions. Nothing to act on yet, but worth watching since it could restructure the signature-tier system described above.
Sources
IT Act 2000, Section 3A (Indian Kanoon): https://indiankanoon.org/doc/166473284/
IT Act 2000, Section 1 (Indian Kanoon): https://indiankanoon.org/doc/473983/
Controller of Certifying Authorities: https://cca.gov.in/about.html
CCA eSign brochure: https://cca.gov.in/sites/files/pdf/esign/esignbrochure1.5.pdf
PIB, DPDP Rules 2025 Notified: https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
IRDAI (Issuance of e-Insurance Policies) Regulations 2016: https://irdai.gov.in/documents/37343/602265/Insurance+Regulatory+And+Development+Authority+Of+India+(Issuance+Of+E-Insurance+Policies)+Regulations+2016.pdf
SEBI circular, Aadhaar e-KYC authorized entities: https://www.sebi.gov.in/legal/circulars/may-2020/entities-permitted-to-undertake-e-kyc-aadhaar-authentication-service-of-uidai-in-securities-market_46665.html
DigiLocker: https://www.digilocker.gov.in/
Leegality, Section 3A explainer: https://www.leegality.com/blog/section3a
Leegality, First Schedule amendment: https://www.leegality.com/blog/first-schedule
Leegality, Aadhaar eSign legality: https://www.leegality.com/blog/law-around-aadhaar-esign
Vinod Kothari Consultants, Aadhaar KUA/Sub-KUA restriction: https://vinodkothari.com/2025/05/online-authentication-of-aadhaar-exclusive-club-members-only/
ksandk, BSA Section 63 explainer: https://ksandk.com/litigation/section-63-bharatiya-sakshya-adhiniyam-2023/
ksandk, DPDP transfer model explainer: https://ksandk.com/data-protection-and-data-privacy/dpdp-act-2023-whitelist-blacklist-rules-for-data/
Mondaq, SaaS contract enforceability in India: https://www.mondaq.com/india/contracts-and-commercial-law/1670160/clickwrap-browsewrap-and-negotiated-saas-contracts-enforceability-in-india
DoveRunner, RBI data localization guidelines: https://doverunner.com/blogs/everything-to-know-about-rbi-data-localization-guidelines/


