Flag of India

India

Fully legal

E-Signature Legality in India

E-Signature Legality in India

India recognizes electronic signatures under the IT Act 2000. A general reliable e-signature covers nearly all commercial contracts, with Digital Signature Certificates and Aadhaar eSign reserved for government filings and specific regulated use cases.

India recognizes electronic signatures under the IT Act 2000. A general reliable e-signature covers nearly all commercial contracts, with Digital Signature Certificates and Aadhaar eSign reserved for government filings and specific regulated use cases.

Overview

Intro & Key Facts

Quick Summary

India is a workable market for B2B e-signatures. The Information Technology Act 2000 recognizes electronic signatures for contract formation, and Section 3A's technology-neutral reliability test, not a government-issued certificate, is what makes a signature enforceable for ordinary commercial use. Digital Signature Certificates and Aadhaar eSign matter for government filings and specific regulated sectors, not standard B2B agreements. Foreign providers operate on the same legal footing as domestic ones for this general path, and EU hosting meets India's data handling requirements since no general localization law applies to contract data.

India is a workable market for B2B e-signatures. The Information Technology Act 2000 recognizes electronic signatures for contract formation, and Section 3A's technology-neutral reliability test, not a government-issued certificate, is what makes a signature enforceable for ordinary commercial use. Digital Signature Certificates and Aadhaar eSign matter for government filings and specific regulated sectors, not standard B2B agreements. Foreign providers operate on the same legal footing as domestic ones for this general path, and EU hosting meets India's data handling requirements since no general localization law applies to contract data.

Practical Usage

Document Types in India

Document Types in India

Permitted Document Types

  • Commercial contracts and vendor agreements

  • NDAs

  • Purchase orders and invoices

  • Software licenses and SaaS subscription agreements

  • MSAs

  • Employment contracts and offer letters

  • Insurance e-proposals

  • General B2B correspondence and terms of service

Restricted Document Types

  • Negotiable instruments other than cheques

  • Powers of attorney

  • Trust deeds

  • Wills and other testamentary dispositions

  • A 2022 amendment exempted instruments involving RBI, SEBI, IRDAI, NHB, or PFRDA-regulated entities from the first two exclusions above

Common Exclusions

Real estate sale and conveyance contracts are no longer barred from electronic signing under the IT Act itself as of a September 2022 amendment, but the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable property instruments in most states. So e-signing alone does not complete a registered property transaction today.

Real estate sale and conveyance contracts are no longer barred from electronic signing under the IT Act itself as of a September 2022 amendment, but the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable property instruments in most states. So e-signing alone does not complete a registered property transaction today.

Authentication Required

  • Signer identification: Firma.dev uses email-link authentication with optional SMS verification.

  • Document integrity: tamper-evident documents with cryptographic sealing and a complete timestamped audit trail.

  • Section 3A(2) reliability test: the signature must be uniquely linked to the signatory, created under their sole control, with any later change to the signature or record detectable. No Indian-issued certificate is required to meet this standard for commercial contracts.

Restrictions

Signing Workflow Controls

Generally Permitted

  • Time-limited signature windows.

  • Sequential signing order.

  • Mandatory field completion.

  • Document expiration dates.

  • IP-based access restrictions.

  • Password-protected envelope access.

  • SMS verification codes.

  • Attachment requirements.

May Require Special Handling or Exclusions

  • Restrictions that prevent signers from reviewing the complete document before signing.

  • Restrictions that obscure material terms.

  • Blanket prohibitions on retaining personal copies.

  • Requirements for specific hardware or paid software to complete signing.

Legal Requirements

India E-Signature Law Explained

Legal Frameworks

Information Technology Act 2000, as amended by the IT (Amendment) Act 2008 (Sections 3, 3A, 5, and 10A) + Indian Contract Act 1872 + Bharatiya Sakshya Adhiniyam 2023, Section 63 (electronic evidence, in force since 1 July 2024, replacing the Indian Evidence Act's Section 65B)

Information Technology Act 2000, as amended by the IT (Amendment) Act 2008 (Sections 3, 3A, 5, and 10A) + Indian Contract Act 1872 + Bharatiya Sakshya Adhiniyam 2023, Section 63 (electronic evidence, in force since 1 July 2024, replacing the Indian Evidence Act's Section 65B)

Regulatory Bodies

Controller of Certifying Authorities (CCA), under the Ministry of Electronics and Information Technology (MeitY), licenses Certifying Authorities and oversees Digital Signature Certificates. The Data Protection Board of India (DPBI), established under the DPDP Act 2023, handles data-protection enforcement once its substantive provisions commence.

Controller of Certifying Authorities (CCA), under the Ministry of Electronics and Information Technology (MeitY), licenses Certifying Authorities and oversees Digital Signature Certificates. The Data Protection Board of India (DPBI), established under the DPDP Act 2023, handles data-protection enforcement once its substantive provisions commence.

Minimum Retention

No single general statute sets a retention minimum for e-signed commercial contracts. The Limitation Act 1963 gives most contract claims a 3-year limitation period, a reasonable floor for retention planning; regulated sectors carry their own separate requirements.

Retention Notes

Company law, tax, and AML/KYC records carry their own sector-specific retention rules independent of e-signature law. Retaining signed documents and their full audit trail for at least the applicable limitation period is the safer default.

Company law, tax, and AML/KYC records carry their own sector-specific retention rules independent of e-signature law. Retaining signed documents and their full audit trail for at least the applicable limitation period is the safer default.

Data, Privacy & Cross-Border

Data Privacy and Compliance India

Privacy Frameworks

Digital Personal Data Protection Act 2023 (DPDP Act), notified in phases from November 2025, not yet fully in force

Privacy Compliance Status

Firma.dev processes data as a processor. EU-only hosting in AWS Paris means no data is stored in India. India's DPDP Act 2023 has no general data-localization mandate for contract or e-signature data, so EU hosting satisfies current requirements.

Privacy Notes

The DPDP Act 2023 is notified but not fully in force. Only institutional provisions (the Data Protection Board of India) are active as of September 2026. The Consent Manager registration framework activates 13 November 2026, and substantive data-fiduciary obligations commence 13 May 2027. Until then, the older IT Rules 2011 (SPDI Rules) remain the operative data-protection baseline.

Data Residency

No

No

Adequacy Decision

India has no GDPR adequacy decision from the European Commission. This does not directly affect Firma.dev's India operations, since Firma hosts and processes data in the EU rather than transferring EU data to India.

Cross-Border Transfers

Unrestricted by default. The DPDP Act's Section 16 uses a negative-list model: transfers are allowed to any country except ones the government specifically notifies as restricted, and none are notified as of this writing. This provision is not yet in force (commences 13 May 2027), so no DPDP-specific transfer restriction currently applies.

Residency Notes

No general data-localization law applies to e-signature or contract data in India. The DPDP Act gives the Central Government discretion to notify specific data categories for mandatory localization, not yet exercised. A separate 2018 RBI circular requiring in-country storage applies only to licensed payment-system operators, not to a document-signing platform like Firma.dev.

Maximum Retention

Not established by a general statute; DPDP's storage-limitation principle is not yet in force (commences May 2027). Sector-specific rules (company law, tax, AML/KYC) apply independently in the meantime.

Industry Compatibility

E-Signatures by Industry in India

Fully Supported Industries

General Commercial

SaaS Software

HR Tech Employment

Education/Edtech

Construction

Supported with Agreement

Healthcare

Life Sciences/Pharma

Insurance

Financial Services/Fintech

Legal Tech

Real Estate Tech

Should Consult Counsel

Government

Industry Matrix Notes

Most B2B commercial use cases work with a general reliable electronic signature under Section 3A(2), no certificate required. Insurance has an explicit regulatory green light for OTP-validated e-proposals. Financial services and healthcare carry KYC and consent-management overlays worth planning around, not blockers. Real estate is a two-law nuance: the IT Act's own bar was lifted in 2022, but property registration still needs in-person verification in most states. Government interactions typically expect a Digital Signature Certificate or Aadhaar eSign, both outside Firma.dev's current scope.

General Commercial

Standard B2B contracts, vendor agreements, NDAs, purchase orders, and service agreements are valid under the Indian Contract Act 1872 and enforceable when executed electronically under IT Act Sections 5 and 10A. No special signature tier is required beyond reliable signer identification and a tamper-evident record.

SaaS Software

SaaS companies can rely on a general reliable electronic signature for software licenses, subscription agreements, API terms of service, and MSAs. Section 10A recognizes contract formation by electronic means, and courts have upheld electronically formed commercial agreements between sophisticated parties. Firma.dev's API-first signing fits self-serve onboarding and negotiated enterprise agreements alike.

Healthcare

No dedicated statute governs e-signatures on healthcare documents specifically. The Ayushman Bharat Digital Mission runs a separate consent-management architecture for sharing health records between providers, distinct from contract e-signing. Administrative agreements, vendor contracts, and consent forms for non-clinical purposes work with Firma.dev's standard signing flow; clinical-record-specific workflows should be evaluated against ABDM's consent layer separately.

Life Sciences/Pharma

Clinical trials fall under CDSCO's New Drugs and Clinical Trials Rules. This research did not find a CDSCO-specific electronic-signature regulation comparable to FDA 21 CFR Part 11, so treat GxP-adjacent signature requirements as a gap to confirm with counsel rather than an established rule. General commercial agreements between life-sciences companies, such as CRO contracts and research collaborations, work with Firma.dev's standard signing flow.

Insurance

The IRDAI (Issuance of e-Insurance Policies) Regulations 2016 require insurers to offer policies electronically and explicitly permit OTP-based validation as an alternative to a formal electronic signature for e-proposals and e-insurance-account setup. This is a favorable, OTP-friendly regime for a platform like Firma.dev.

Financial Services/Fintech

General commercial agreements between financial-services companies work with a standard reliable electronic signature. RBI and SEBI's KYC frameworks layer Aadhaar-based eKYC onto customer onboarding for regulated entities, but that access is restricted to licensed intermediaries and does not affect ordinary B2B contract signing. OTP-based non-face-to-face authentication triggers enhanced due diligence classification under RBI norms for KYC purposes specifically, not for general contract execution.

HR Tech Employment

Employment contracts, offer letters, NDAs, and HR policy acknowledgments are recognized as valid electronic records under the IT Act. One caveat: labor tribunals sometimes weigh state-specific labor protections alongside central IT Act validity in disputes, so enforceability can vary slightly by state even though the central framework is settled.

Legal Tech

General commercial and engagement-letter documents work with a standard reliable electronic signature. Certain court filings and regulated procedures may require a Digital Signature Certificate, so law firms should confirm the requirement per matter rather than assuming one signature tier covers every filing.

Real Estate Tech

A September 2022 amendment removed the IT Act's own bar on e-signing property sale and conveyance contracts. In practice, the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable instruments in most states, so e-signing alone does not complete a registered property transaction. Property management agreements, brokerage contracts, and other non-registrable real-estate-adjacent documents work with Firma.dev's standard flow.

Education/Edtech

Enrollment agreements, administrative contracts, and institutional vendor agreements work with a standard reliable electronic signature. No dedicated statute governs e-signatures in education specifically.

Construction

Construction contracts, subcontractor agreements, and change orders work with a standard reliable electronic signature under general contract law. No construction-specific e-signature rule was found; state-level RERA regulations govern real-estate project registration and sale-agreement terms but don't set a distinct signature requirement.

Government

Government interactions typically expect a Digital Signature Certificate or Aadhaar eSign, both of which require Indian licensing or a regulated intermediary relationship that Firma.dev does not currently hold. DigiLocker, India's government document wallet, treats its stored documents as legally valid under the IT Act, illustrating how seriously Indian government systems already treat digital documents. Contractors working with government bodies should plan for a DSC rather than Firma.dev's standard signing flow.

How we works

How Firma.dev Works in India

Firma.dev Supports

Firma.dev supports the general reliable electronic signature standard that covers the large majority of B2B commercial use cases in India.

Firma.dev provides signer identification via email-based authentication with optional SMS verification, tamper-evident documents with cryptographic sealing, complete audit trails with timestamped logging, and EU data residency with all data hosted in AWS Paris. This maps directly onto India's Section 3A(2) reliability test: a signature uniquely linked to the signatory, created under their sole control, with any later change detectable. Customer Workspaces give each of your customers a private, partitioned space with isolated templates and per-customer envelope usage, suited to multi-tenant SaaS building signing into their own product for the Indian market.

Legal Details

Implementing E-Signatures in India

Implementing E-Signatures in India

India's e-signature framework rests on the Information Technology Act 2000, substantially amended in 2008, alongside the general contract-law backbone of the Indian Contract Act 1872. Electronic evidence admissibility now runs through the Bharatiya Sakshya Adhiniyam 2023, which replaced the old Evidence Act's Section 65B with a stricter certification requirement from 1 July 2024.

The IT Act recognizes signatures on two tracks. Section 3 covers 'digital signatures': asymmetric cryptography tied to a Digital Signature Certificate issued by a Certifying Authority licensed by the Controller of Certifying Authorities. Section 3A, inserted by the 2008 amendment, covers 'electronic signatures' more broadly: any technique the Second Schedule recognizes as reliable, including Aadhaar-based eSign, plus a general reliability test for techniques not specifically listed. That test asks whether the signature is uniquely linked to the signatory, created under their sole control, and whether any later change to the signature or the signed record would be detectable, criteria that read almost identically to the EU's advanced-electronic-signature standard, despite India never adopting eIDAS vocabulary.

Neither a Digital Signature Certificate nor Aadhaar eSign is available to an unlicensed foreign platform. DSC issuance requires CCA licensing as a Certifying Authority. Aadhaar's authentication API is restricted to entities simultaneously recognized under the anti-money-laundering law and registered with UIDAI as a KUA or Sub-KUA, a closed list of mostly regulated financial and government entities. None of that matters for ordinary commercial signing, though. Section 3A's general reliability test, combined with Section 5's signature recognition and Section 10A's validation of electronic contract formation, is the same legal path DocuSign, Adobe Sign, and Zoho Sign already operate under in India, and it's the path a tamper-evident, audit-trailed platform like Firma.dev satisfies without any domestic license.

Exclusions are narrow and named rather than broad. The First Schedule bars electronic execution of negotiable instruments other than cheques, powers of attorney, trust deeds, and wills, though a 2022 amendment narrowed the first two exclusions to exempt instruments involving RBI, SEBI, IRDAI, or PFRDA-regulated entities. Property sale and conveyance contracts lost their IT Act exclusion the same year, though the separate Registration Act 1908 still requires in-person registration for compulsorily registrable instruments in most states, so the practical barrier for real estate outlives the legal one that used to justify it.

For most SaaS companies and B2B platforms operating in India, the general reliable-signature standard covers commercial contracts, employment agreements, NDAs, software licenses, and insurance e-proposals with confidence. A Digital Signature Certificate or Aadhaar eSign matters for government filings, specific regulated financial-sector KYC flows, and the small list of First Schedule exclusions, not for standard business documents.

Recent developments

E-Signature Landscape in India: 2026

Bharatiya Sakshya Adhiniyam 2023 (effective 1 July 2024): Replaced the Indian Evidence Act's Section 65B with Section 63, tightening the certification requirement for electronic evidence to two signatories plus a disclosed hash value. This is the current citation for how e-signed documents hold up as evidence in Indian courts.

DPDP Act 2023, phased commencement (from 13 November 2025): India's Digital Personal Data Protection Act is notified but not fully in force. Institutional provisions, including the Data Protection Board of India, are active now. The Consent Manager framework activates 13 November 2026. Substantive data-fiduciary obligations and the Section 16 cross-border transfer rules commence 13 May 2027.

Draft Digital India Act (in consultation, not enacted): A future law intended to eventually replace the IT Act 2000 entirely, including its electronic-signature provisions. Nothing to act on yet, but worth watching since it could restructure the signature-tier system described above.

FAQ

Frequently asked questions

For any unanswered questions, reach out to our support team via email. We'll respond as soon as possible to assist you.

Are e-signatures legal in India?

Yes. The Information Technology Act 2000 recognizes electronic signatures for contract formation and gives them the same legal standing as handwritten signatures under Sections 3A, 5, and 10A. A general reliable electronic signature, no government certificate required, covers the large majority of commercial contracts.

What types of electronic signatures does India recognize?

Three practical tiers. A general reliable electronic signature under Section 3A(2), technology-neutral and requiring no certificate. Aadhaar eSign, an OTP or biometric-authenticated signature tied to India's national ID system. And Digital Signature Certificates, PKI-based certificates issued by Certifying Authorities licensed by the government. Most B2B commercial contracts only need the first tier.

What documents can't be e-signed in India?

The First Schedule of the IT Act excludes negotiable instruments other than cheques, powers of attorney, trust deeds, and wills. A 2022 amendment narrowed the first two exclusions for instruments involving RBI, SEBI, IRDAI, or PFRDA-regulated entities. None of these are typical SaaS or commercial-contract categories.

Does India require a Digital Signature Certificate for business contracts?

No. A Digital Signature Certificate matters for specific government filings and some regulated-sector transactions, not for ordinary commercial agreements. Standard B2B contracts, NDAs, and employment documents work with a general reliable electronic signature that requires no certificate.

What is Aadhaar eSign, and can Firma.dev use it?

Aadhaar eSign lets an Aadhaar holder authenticate via OTP or biometrics to sign a document, with a licensed intermediary generating a backing digital signature. Access to Aadhaar's authentication API is restricted to entities registered with UIDAI as a KUA or Sub-KUA and separately recognized under India's anti-money-laundering law, a closed list of mostly regulated financial and government entities. Firma.dev doesn't hold that license, and doesn't need to for standard commercial signing.

How does India's evidence law treat e-signed documents in court?

The Bharatiya Sakshya Adhiniyam 2023, in force since 1 July 2024, governs admissibility of electronic records as evidence. Its Section 63 requires a certificate from the person in charge of the relevant device plus an independent expert, disclosing the record's hash value. A platform with a complete, tamper-evident audit trail is built for exactly this bar.

Is India's DPDP Act 2023 already in force?

Partly. The Act was notified in phases starting 13 November 2025, but only institutional provisions are active so far. The Consent Manager framework activates 13 November 2026, and substantive obligations, including cross-border transfer rules, commence 13 May 2027. Until then, the older IT Rules 2011 remain the operative data-protection baseline.

Can foreign e-signature providers operate in India?

Yes, for the signature tier that covers standard commercial use. The general reliable-signature path under Section 3A(2) requires no Indian license, and it's the same path DocuSign, Adobe Sign, and Zoho Sign already use there. What foreign providers can't get without a licensed Indian intermediary is a Certifying Authority license or Aadhaar eSign API access, neither of which ordinary B2B contracts need.

Does Firma.dev need to store data in India?

No. India's DPDP Act doesn't set a general data-localization requirement for contract or e-signature data. A 2018 RBI rule requiring in-country storage applies only to licensed payment-system operators. Firma.dev's EU hosting in AWS Paris satisfies current requirements for Indian customers.

How does India handle cross-border data transfers?

The DPDP Act's Section 16 uses a negative-list model: transfers are allowed to any country by default except ones the government specifically notifies as restricted, and none are notified yet. This is the reverse of the EU's adequacy-decision approach. Section 16 itself isn't in force until 13 May 2027, so no DPDP-specific transfer restriction currently applies.

Can real estate or property contracts be e-signed in India?

Partly. A 2022 amendment removed the IT Act's own bar on e-signing property sale and conveyance contracts. But the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable instruments in most states, so e-signing alone doesn't complete a registered property transaction today.

Are e-signatures valid for SaaS and software agreements in India?

Yes. Software licenses, subscription agreements, and API terms of service are ordinary commercial contracts under Indian law, valid when formed electronically under Section 10A. Courts generally defer to negotiated terms between business parties, and a signing flow with clear assent and a complete audit trail is exactly what strengthens enforceability.

FAQ

Frequently asked questions

For any unanswered questions, reach out to our support team via email. We'll respond as soon as possible to assist you.

Are e-signatures legal in India?

Yes. The Information Technology Act 2000 recognizes electronic signatures for contract formation and gives them the same legal standing as handwritten signatures under Sections 3A, 5, and 10A. A general reliable electronic signature, no government certificate required, covers the large majority of commercial contracts.

What types of electronic signatures does India recognize?

Three practical tiers. A general reliable electronic signature under Section 3A(2), technology-neutral and requiring no certificate. Aadhaar eSign, an OTP or biometric-authenticated signature tied to India's national ID system. And Digital Signature Certificates, PKI-based certificates issued by Certifying Authorities licensed by the government. Most B2B commercial contracts only need the first tier.

What documents can't be e-signed in India?

The First Schedule of the IT Act excludes negotiable instruments other than cheques, powers of attorney, trust deeds, and wills. A 2022 amendment narrowed the first two exclusions for instruments involving RBI, SEBI, IRDAI, or PFRDA-regulated entities. None of these are typical SaaS or commercial-contract categories.

Does India require a Digital Signature Certificate for business contracts?

No. A Digital Signature Certificate matters for specific government filings and some regulated-sector transactions, not for ordinary commercial agreements. Standard B2B contracts, NDAs, and employment documents work with a general reliable electronic signature that requires no certificate.

What is Aadhaar eSign, and can Firma.dev use it?

Aadhaar eSign lets an Aadhaar holder authenticate via OTP or biometrics to sign a document, with a licensed intermediary generating a backing digital signature. Access to Aadhaar's authentication API is restricted to entities registered with UIDAI as a KUA or Sub-KUA and separately recognized under India's anti-money-laundering law, a closed list of mostly regulated financial and government entities. Firma.dev doesn't hold that license, and doesn't need to for standard commercial signing.

How does India's evidence law treat e-signed documents in court?

The Bharatiya Sakshya Adhiniyam 2023, in force since 1 July 2024, governs admissibility of electronic records as evidence. Its Section 63 requires a certificate from the person in charge of the relevant device plus an independent expert, disclosing the record's hash value. A platform with a complete, tamper-evident audit trail is built for exactly this bar.

Is India's DPDP Act 2023 already in force?

Partly. The Act was notified in phases starting 13 November 2025, but only institutional provisions are active so far. The Consent Manager framework activates 13 November 2026, and substantive obligations, including cross-border transfer rules, commence 13 May 2027. Until then, the older IT Rules 2011 remain the operative data-protection baseline.

Can foreign e-signature providers operate in India?

Yes, for the signature tier that covers standard commercial use. The general reliable-signature path under Section 3A(2) requires no Indian license, and it's the same path DocuSign, Adobe Sign, and Zoho Sign already use there. What foreign providers can't get without a licensed Indian intermediary is a Certifying Authority license or Aadhaar eSign API access, neither of which ordinary B2B contracts need.

Does Firma.dev need to store data in India?

No. India's DPDP Act doesn't set a general data-localization requirement for contract or e-signature data. A 2018 RBI rule requiring in-country storage applies only to licensed payment-system operators. Firma.dev's EU hosting in AWS Paris satisfies current requirements for Indian customers.

How does India handle cross-border data transfers?

The DPDP Act's Section 16 uses a negative-list model: transfers are allowed to any country by default except ones the government specifically notifies as restricted, and none are notified yet. This is the reverse of the EU's adequacy-decision approach. Section 16 itself isn't in force until 13 May 2027, so no DPDP-specific transfer restriction currently applies.

Can real estate or property contracts be e-signed in India?

Partly. A 2022 amendment removed the IT Act's own bar on e-signing property sale and conveyance contracts. But the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable instruments in most states, so e-signing alone doesn't complete a registered property transaction today.

Are e-signatures valid for SaaS and software agreements in India?

Yes. Software licenses, subscription agreements, and API terms of service are ordinary commercial contracts under Indian law, valid when formed electronically under Section 10A. Courts generally defer to negotiated terms between business parties, and a signing flow with clear assent and a complete audit trail is exactly what strengthens enforceability.

FAQ

Frequently asked questions

For any unanswered questions, reach out to our support team via email. We'll respond as soon as possible to assist you.

Are e-signatures legal in India?

Yes. The Information Technology Act 2000 recognizes electronic signatures for contract formation and gives them the same legal standing as handwritten signatures under Sections 3A, 5, and 10A. A general reliable electronic signature, no government certificate required, covers the large majority of commercial contracts.

What types of electronic signatures does India recognize?

Three practical tiers. A general reliable electronic signature under Section 3A(2), technology-neutral and requiring no certificate. Aadhaar eSign, an OTP or biometric-authenticated signature tied to India's national ID system. And Digital Signature Certificates, PKI-based certificates issued by Certifying Authorities licensed by the government. Most B2B commercial contracts only need the first tier.

What documents can't be e-signed in India?

The First Schedule of the IT Act excludes negotiable instruments other than cheques, powers of attorney, trust deeds, and wills. A 2022 amendment narrowed the first two exclusions for instruments involving RBI, SEBI, IRDAI, or PFRDA-regulated entities. None of these are typical SaaS or commercial-contract categories.

Does India require a Digital Signature Certificate for business contracts?

No. A Digital Signature Certificate matters for specific government filings and some regulated-sector transactions, not for ordinary commercial agreements. Standard B2B contracts, NDAs, and employment documents work with a general reliable electronic signature that requires no certificate.

What is Aadhaar eSign, and can Firma.dev use it?

Aadhaar eSign lets an Aadhaar holder authenticate via OTP or biometrics to sign a document, with a licensed intermediary generating a backing digital signature. Access to Aadhaar's authentication API is restricted to entities registered with UIDAI as a KUA or Sub-KUA and separately recognized under India's anti-money-laundering law, a closed list of mostly regulated financial and government entities. Firma.dev doesn't hold that license, and doesn't need to for standard commercial signing.

How does India's evidence law treat e-signed documents in court?

The Bharatiya Sakshya Adhiniyam 2023, in force since 1 July 2024, governs admissibility of electronic records as evidence. Its Section 63 requires a certificate from the person in charge of the relevant device plus an independent expert, disclosing the record's hash value. A platform with a complete, tamper-evident audit trail is built for exactly this bar.

Is India's DPDP Act 2023 already in force?

Partly. The Act was notified in phases starting 13 November 2025, but only institutional provisions are active so far. The Consent Manager framework activates 13 November 2026, and substantive obligations, including cross-border transfer rules, commence 13 May 2027. Until then, the older IT Rules 2011 remain the operative data-protection baseline.

Can foreign e-signature providers operate in India?

Yes, for the signature tier that covers standard commercial use. The general reliable-signature path under Section 3A(2) requires no Indian license, and it's the same path DocuSign, Adobe Sign, and Zoho Sign already use there. What foreign providers can't get without a licensed Indian intermediary is a Certifying Authority license or Aadhaar eSign API access, neither of which ordinary B2B contracts need.

Does Firma.dev need to store data in India?

No. India's DPDP Act doesn't set a general data-localization requirement for contract or e-signature data. A 2018 RBI rule requiring in-country storage applies only to licensed payment-system operators. Firma.dev's EU hosting in AWS Paris satisfies current requirements for Indian customers.

How does India handle cross-border data transfers?

The DPDP Act's Section 16 uses a negative-list model: transfers are allowed to any country by default except ones the government specifically notifies as restricted, and none are notified yet. This is the reverse of the EU's adequacy-decision approach. Section 16 itself isn't in force until 13 May 2027, so no DPDP-specific transfer restriction currently applies.

Can real estate or property contracts be e-signed in India?

Partly. A 2022 amendment removed the IT Act's own bar on e-signing property sale and conveyance contracts. But the separate Registration Act 1908 still requires in-person, biometrically verified registration for compulsorily registrable instruments in most states, so e-signing alone doesn't complete a registered property transaction today.

Are e-signatures valid for SaaS and software agreements in India?

Yes. Software licenses, subscription agreements, and API terms of service are ordinary commercial contracts under Indian law, valid when formed electronically under Section 10A. Courts generally defer to negotiated terms between business parties, and a signing flow with clear assent and a complete audit trail is exactly what strengthens enforceability.

Sources

  1. IT Act 2000, Section 3A (Indian Kanoon): https://indiankanoon.org/doc/166473284/

  2. IT Act 2000, Section 1 (Indian Kanoon): https://indiankanoon.org/doc/473983/

  3. Controller of Certifying Authorities: https://cca.gov.in/about.html

  4. CCA eSign brochure: https://cca.gov.in/sites/files/pdf/esign/esignbrochure1.5.pdf

  5. PIB, DPDP Rules 2025 Notified: https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf

  6. IRDAI (Issuance of e-Insurance Policies) Regulations 2016: https://irdai.gov.in/documents/37343/602265/Insurance+Regulatory+And+Development+Authority+Of+India+(Issuance+Of+E-Insurance+Policies)+Regulations+2016.pdf

  7. SEBI circular, Aadhaar e-KYC authorized entities: https://www.sebi.gov.in/legal/circulars/may-2020/entities-permitted-to-undertake-e-kyc-aadhaar-authentication-service-of-uidai-in-securities-market_46665.html

  8. DigiLocker: https://www.digilocker.gov.in/

  9. Leegality, Section 3A explainer: https://www.leegality.com/blog/section3a

  10. Leegality, First Schedule amendment: https://www.leegality.com/blog/first-schedule

  11. Leegality, Aadhaar eSign legality: https://www.leegality.com/blog/law-around-aadhaar-esign

  12. Vinod Kothari Consultants, Aadhaar KUA/Sub-KUA restriction: https://vinodkothari.com/2025/05/online-authentication-of-aadhaar-exclusive-club-members-only/

  13. ksandk, BSA Section 63 explainer: https://ksandk.com/litigation/section-63-bharatiya-sakshya-adhiniyam-2023/

  14. ksandk, DPDP transfer model explainer: https://ksandk.com/data-protection-and-data-privacy/dpdp-act-2023-whitelist-blacklist-rules-for-data/

  15. Mondaq, SaaS contract enforceability in India: https://www.mondaq.com/india/contracts-and-commercial-law/1670160/clickwrap-browsewrap-and-negotiated-saas-contracts-enforceability-in-india

  16. DoveRunner, RBI data localization guidelines: https://doverunner.com/blogs/everything-to-know-about-rbi-data-localization-guidelines/

Background Image

Start Building with Firma.dev in India

Firma.dev handles e-signatures for B2B SaaS operating in India and worldwide. At €0.049 per envelope (~5¢ USD) with no monthly minimums, you can ship signing flows designed to support India's e-signature requirements without enterprise contracts or procurement delays.

Background Image

Start Building with Firma.dev in India

Firma.dev handles e-signatures for B2B SaaS operating in India and worldwide. At €0.049 per envelope (~5¢ USD) with no monthly minimums, you can ship signing flows designed to support India's e-signature requirements without enterprise contracts or procurement delays.

Background Image

Start Building with Firma.dev in India

Firma.dev handles e-signatures for B2B SaaS operating in India and worldwide. At €0.049 per envelope (~5¢ USD) with no monthly minimums, you can ship signing flows designed to support India's e-signature requirements without enterprise contracts or procurement delays.