Flag of US

United States

Fully legal

E-Signature Legality in United States

E-Signature Legality in United States

The ESIGN Act and UETA make electronic signatures fully valid across nearly all US commercial contracts, with no signature tiers and no domestic certification required.

The ESIGN Act and UETA make electronic signatures fully valid across nearly all US commercial contracts, with no signature tiers and no domestic certification required.

Overview

Intro & Key Facts

Quick Summary

The United States is the most permissive major e-signature market Firma.dev operates in. The federal ESIGN Act and UETA, adopted by 49 states, give electronic signatures the same legal weight as wet-ink signatures for virtually all commercial transactions, with no SES/AES/QES-style tiering: any technology-neutral method that shows intent to sign is valid. New York is the only state running its own statute (ESRA) instead of UETA, and the differences rarely matter in practice. Firma.dev operates in the US without restriction, there's no data residency requirement, and the EU-US Data Privacy Framework covers the relevant cross-border transfer question from the EU side.

The United States is the most permissive major e-signature market Firma.dev operates in. The federal ESIGN Act and UETA, adopted by 49 states, give electronic signatures the same legal weight as wet-ink signatures for virtually all commercial transactions, with no SES/AES/QES-style tiering: any technology-neutral method that shows intent to sign is valid. New York is the only state running its own statute (ESRA) instead of UETA, and the differences rarely matter in practice. Firma.dev operates in the US without restriction, there's no data residency requirement, and the EU-US Data Privacy Framework covers the relevant cross-border transfer question from the EU side.

Practical Usage

Document Types in United States

Document Types in United States

Permitted Document Types

  • Commercial contracts

  • NDAs

  • SaaS terms and MSAs

  • Purchase orders

  • Employment agreements (in most states)

  • Real estate contracts and leases

  • Insurance applications

  • Financial agreements

  • Healthcare consent forms (with HIPAA safeguards)

Restricted Document Types

  • Wills, codicils, and testamentary trusts

  • Court orders and filings

  • Documents requiring notarization

  • Powers of attorney (rules vary by state)

  • Adoption and certain divorce filings

  • Foreclosure notices on primary residences

  • Utility and insurance cancellation notices

  • Product recall notices

  • Hazardous materials shipping documents

Common Exclusions

Unlike eIDAS jurisdictions, the US doesn't carve out signature tiers by document type. Instead a short, named list of document types is excluded from ESIGN/UETA entirely regardless of signature method: wills, court orders, notarized documents, and a handful of consumer-protection notices. Outside that list, standard e-signatures work for essentially all commercial use cases.

Unlike eIDAS jurisdictions, the US doesn't carve out signature tiers by document type. Instead a short, named list of document types is excluded from ESIGN/UETA entirely regardless of signature method: wills, court orders, notarized documents, and a handful of consumer-protection notices. Outside that list, standard e-signatures work for essentially all commercial use cases.

Authentication Required

  • B2B transactions: No statutory authentication requirement. ESIGN and UETA require only that the signature be reliably attributable to the signer and that the signer intended to sign.

  • Consumer transactions: Additional requirement to demonstrate the signer can access electronic records.

  • HIPAA-covered documents: Sector-specific authentication requirements apply on top of the ESIGN/UETA baseline.

  • FDA 21 CFR Part 11 documents: Sector-specific authentication requirements apply on top of the ESIGN/UETA baseline.

Restrictions

Signing Workflow Controls

Generally Permitted

  • Time-limited signature windows.

  • Sequential signing order.

  • Mandatory field completion.

  • Document expiration dates.

  • IP-based access restrictions.

  • Password-protected envelope access.

  • SMS or email verification codes.

  • Attachment requirements.

May Require Special Handling or Exclusions

  • Restrictions that prevent signers from reviewing the complete document before signing.

  • Restrictions that obscure material terms.

  • Blanket prohibitions on retaining personal copies.

  • Requirements for specific hardware or paid software to complete signing.

  • For consumer transactions, skipping the affirmative opt-in to electronic delivery that ESIGN requires, or blocking a consumer's right to withdraw that consent.

Legal Requirements

United States E-Signature Law Explained

Legal Frameworks

ESIGN Act (2000, federal) + UETA (1999, model state law adopted by 49 states). New York is the only state that hasn't adopted UETA; it runs its own Electronic Signatures and Records Act (ESRA, 2000) instead.

ESIGN Act (2000, federal) + UETA (1999, model state law adopted by 49 states). New York is the only state that hasn't adopted UETA; it runs its own Electronic Signatures and Records Act (ESRA, 2000) instead.

Regulatory Bodies

FTC (consumer protection and privacy enforcement), State Attorneys General (state privacy law enforcement), FDA (21 CFR Part 11 for pharma and medical devices), HHS/OCR (HIPAA enforcement), SEC (financial services recordkeeping)

FTC (consumer protection and privacy enforcement), State Attorneys General (state privacy law enforcement), FDA (21 CFR Part 11 for pharma and medical devices), HHS/OCR (HIPAA enforcement), SEC (financial services recordkeeping)

Minimum Retention

  • General commercial contracts: 4-6 years (statute of limitations)

  • Tax records: 7 years

  • HIPAA-covered records: 6 years

  • FDA 21 CFR Part 11 records: Per the applicable predicate rule

  • SEC-regulated records: 3-6 years, depending on record type

Retention Notes

ESIGN requires signed records be accurately reproducible and accessible; no specific format is mandated. Firma.dev stores signed documents and a complete audit trail, both retrievable via the API at any time.

ESIGN requires signed records be accurately reproducible and accessible; no specific format is mandated. Firma.dev stores signed documents and a complete audit trail, both retrievable via the API at any time.

Data, Privacy & Cross-Border

Data Privacy and Compliance United States

Privacy Frameworks

No federal comprehensive privacy law. California's CCPA/CPRA is the most established, and more than 20 other states now have their own comprehensive privacy statutes (Virginia, Colorado, Connecticut, Utah, and others), each with its own scope and thresholds.

Privacy Compliance Status

Firma.dev processes signer data consistent with the obligations that apply to a processor under US state privacy law. No special certification is required for standard commercial e-signature workflows. Healthcare customers who need a Business Associate Agreement for HIPAA-covered documents should confirm current availability directly with the Firma.dev team.

Privacy Notes

Requirements vary by state, but most give consumers rights to access, correct, delete, and opt out of the sale of their data. CCPA/CPRA is the most comprehensive and unusually extends some rights to employees and B2B contacts, not just consumers. None of these laws impose a data localization requirement.

Data Residency

No

No

Adequacy Decision

The US isn't an EU member state and has no domestic adequacy-decision system for judging other countries' data protection, so this doesn't apply symmetrically the way it does on EU-country pages. What does apply: the US holds adequacy status under the EU-US Data Privacy Framework (July 2023, replacing the invalidated Privacy Shield), permitting lawful transfers of EU personal data into the US for Framework participants. This doesn't affect Firma.dev's ability to serve US customers from EU-hosted infrastructure.

Cross-Border Transfers

Yes, unrestricted for e-signature purposes. The US doesn't operate its own adequacy-decision regime; the relevant mechanism runs the other direction, EU-to-US, under the EU-US Data Privacy Framework.

Residency Notes

The US has no data residency requirement for e-signature data. Foreign hosting is fully permitted, so Firma.dev's EU-hosted infrastructure (AWS Paris) serves US customers without restriction.

Maximum Retention

No statutory maximum tied to e-signature data specifically. CCPA/CPRA requires retention be limited to what's reasonably necessary for the disclosed purpose, and businesses must disclose retention periods or criteria at the point of collection. Consumer request records must be kept at least 24 months.

Industry Compatibility

E-Signatures by Industry in United States

Fully Supported Industries

General Commercial

SaaS Software

Insurance

Financial Services/Fintech

HR Tech Employment

Legal Tech

Real Estate Tech

Education/Edtech

Construction

Supported with Agreement

Healthcare

Life Sciences/Pharma

Should Consult Counsel

Government

Industry Matrix Notes

Most B2B commercial use cases work with standard e-signatures under ESIGN/UETA. Healthcare and life sciences need HIPAA and FDA 21 CFR Part 11 controls layered on top. Government contracting varies by agency and should be confirmed case by case. A short, named list of document types (wills, court orders, notarized instruments) sits outside ESIGN/UETA entirely regardless of industry.

General Commercial

Standard B2B contracts, vendor agreements, NDAs, purchase orders, and service agreements are all valid with e-signatures under ESIGN and UETA. There's no requirement to use a specific signature technology or a domestically certified provider; any method that shows intent to sign and can be tied to the signer works.

SaaS Software

SaaS companies can use standard e-signatures for the full range of B2B agreements: software licenses, subscription terms, MSAs, DPAs, and API terms of service. ESIGN and UETA's technology-neutral standard means there's no signature tier to worry about, just the four baseline requirements: intent, consent, association with the record, and retention capability.

Healthcare

Documents containing protected health information need extra care beyond standard ESIGN/UETA validity. HIPAA requires audit trails, signer authentication, and encryption in transit and at rest, and typically a signed Business Associate Agreement with the platform before it can handle PHI. Firma.dev's audit trail, authentication options, and encryption are designed to support HIPAA-aligned workflows; confirm BAA availability with the Firma.dev team before handling PHI-bearing documents.

Life Sciences/Pharma

FDA-regulated electronic records and signatures fall under 21 CFR Part 11, which calls for unique signer identification, a complete audit trail, and tamper-evident records, with the retention period set by the applicable predicate rule. Firma.dev's audit trails, authentication, and document integrity features are designed to support Part 11 workflows; system validation and predicate-rule compliance remain the customer's responsibility.

Insurance

Insurance applications and policy documents are generally valid with standard e-signatures. Some states apply their own disclosure rules to insurance transactions specifically, so confirm state-level requirements for consumer-facing policies.

Financial Services/Fintech

Loan documents, account agreements, and other financial services paperwork are valid under ESIGN/UETA with no additional signature tier required. The SEC and state regulators impose their own recordkeeping rules for regulated entities, so retention periods should follow the applicable rule rather than the general statute-of-limitations default.

HR Tech Employment

Offer letters, onboarding paperwork, and most employment agreements are valid with standard e-signatures in the large majority of states. Section 1 of Form I-9 can be completed electronically under DHS rules; Section 2 carries its own in-person or authorized-representative verification requirement that e-signature alone doesn't satisfy.

Legal Tech

Engagement letters, NDAs, and most legal services documents are valid with standard e-signatures. Court filings and certain notarized instruments fall outside ESIGN/UETA and need to go through the court's own e-filing system or a notarial process instead.

Real Estate Tech

Most real estate paperwork, including leases, disclosures, and purchase agreements, is valid with standard e-signatures under ESIGN/UETA. The exclusion is narrow: instruments that legally require notarization or recording, most deeds and mortgages, still need a notarial process, increasingly available as remote online notarization in most states.

Education/Edtech

Enrollment agreements, consent forms, and administrative paperwork are valid with standard e-signatures. FERPA governs the privacy of the underlying student records rather than the signature method itself.

Construction

Contracts, subcontractor agreements, change orders, and project documentation are all valid with standard e-signatures under ESIGN/UETA. No federal or state requirement calls for anything beyond standard signer identification and an audit trail.

Government

Government contracting requirements vary by agency and can include their own procurement-specific rules. Confirm the specific agency's requirements before relying on standard e-signatures for a government contract.

How we works

How Firma.dev Works in United States

Firma.dev Supports

Firma.dev's signature capabilities meet US requirements without any additional certification. ESIGN and UETA don't tier signatures the way eIDAS does, so the SES/AES distinction that matters in the EU has no direct legal equivalent here: any technology-neutral method that shows intent to sign is fully valid, including what Firma.dev provides.

Firma.dev meets US e-signature requirements without any additional certification. The platform provides:

  • Signer identification: Email-link or SMS one-time-code authentication

  • Tamper-evident documents: Cryptographic sealing ensures any modification after signing is detectable

  • Complete audit trails: Every action is timestamped and logged

  • EU data residency: All data hosted in AWS Paris, which the US imposes no residency requirement against

For B2B software agreements, SaaS subscriptions, employment contracts, NDAs, and vendor agreements, Firma.dev's signature process satisfies the ESIGN Act and UETA's four validity requirements.

// Create an envelope for a US commercial contract
const envelope = await firma.envelopes.create({
  title: 'Service Agreement',
  documents: [{ file: contractPdf }],
  signers: [{
    email: 'client@example.com',
    name: 'Jordan Smith',
    locale: 'en'
  }],
  metadata: {
    contract_type: 'service_agreement',
    jurisdiction: 'US'
  }
});
// Create an envelope for a US commercial contract
const envelope = await firma.envelopes.create({
  title: 'Service Agreement',
  documents: [{ file: contractPdf }],
  signers: [{
    email: 'client@example.com',
    name: 'Jordan Smith',
    locale: 'en'
  }],
  metadata: {
    contract_type: 'service_agreement',
    jurisdiction: 'US'
  }
});
// Create an envelope for a US commercial contract
const envelope = await firma.envelopes.create({
  title: 'Service Agreement',
  documents: [{ file: contractPdf }],
  signers: [{
    email: 'client@example.com',
    name: 'Jordan Smith',
    locale: 'en'
  }],
  metadata: {
    contract_type: 'service_agreement',
    jurisdiction: 'US'
  }
});

Firma.dev's API-first design means you can embed signing directly into your application. US companies using Customer Workspaces get isolated environments for each customer, with templates and envelope usage tracked separately.

Legal Details

Implementing E-Signatures in United States

Implementing E-Signatures in United States

The United States built its e-signature framework around two pillars: the federal ESIGN Act and the state-level UETA.

The Electronic Signatures in Global and National Commerce Act (ESIGN, 2000) is the federal law that established e-signature validity nationwide. It's deliberately technology-neutral and provider-neutral: there's no requirement to use a specific signature technology or a domestically certified provider, which is unusual compared to jurisdictions built around a tiered system like the EU's eIDAS.

The Uniform Electronic Transactions Act (UETA, 1999) is a model state law that fills in the state-level detail underneath ESIGN. It's now been adopted, by name, in 49 states, including Illinois and Washington, which each ran their own separate electronic-transactions statutes for years before formally enacting UETA in 2021 and 2020. New York is the only holdout: it still relies on its own Electronic Signatures and Records Act (ESRA, 2000) rather than adopting UETA. In practice ESRA reaches a similar result to UETA, though its excluded-document list runs a little broader, barring e-signatures on all individually executed trusts and powers of attorney rather than just wills.

Signature Types Recognized

Unlike eIDAS, US law doesn't define separate signature tiers. Both ESIGN and UETA test validity against the same four requirements regardless of the technology used: intent to sign, consent to conduct the transaction electronically, association of the signature with the record being signed, and the ability to retain and reproduce that record. There's no second tier of "advanced" or "qualified" signatures required for higher-stakes documents.

Firma.dev's signing flow meets the same security bar that eIDAS calls SES and AES, though US law has no equivalent classification for it: any valid electronic signature works the same way here.

US law handles exclusions differently: a short, named list of document types sits outside ESIGN/UETA's scope entirely, regardless of signature method. Wills, codicils, and testamentary trusts, court orders, documents requiring notarization, and a handful of consumer-protection notices (utility and insurance cancellation, foreclosure on a primary residence, product recalls) fall into this category. Everything else, including commercial contracts, NDAs, employment agreements, and real estate leases, is fair game for standard e-signatures.

Industry-specific rules layer on top of this baseline rather than replacing it. HIPAA adds authentication, audit trail, and encryption requirements for documents containing protected health information, typically alongside a Business Associate Agreement with the platform. FDA 21 CFR Part 11 adds unique signer identification, audit trails, and system validation requirements for FDA-regulated electronic records. Neither changes what counts as a valid signature under ESIGN/UETA; both add controls on top of it.

For SaaS companies, agencies, and internal teams building or using signing workflows in the US, the practical result is straightforward: standard e-signatures cover commercial contracts, NDAs, employment paperwork, and vendor agreements without any special signature tier, and the main things to track are the narrow document exclusions and the sector-specific overlays for healthcare and life sciences.

Recent developments

E-Signature Landscape in United States: 2026

CCPA enforcement acceleration: major 2025 settlements include Tractor Supply ($1.35M), Sling TV ($1.4M for missing mobile app opt-outs), and Honda for dark-patterns violations. CalPrivacy launched a Data Broker Enforcement Strike Force in November 2025.

New CCPA regulations (effective January 1, 2026): cybersecurity audit and risk assessment requirements, new automated decision-making technology (ADMT) rules, mobile apps now required to link their privacy policy, annual risk assessment reports required (first due April 2028).

Delete Act (SB 362), effective January 1, 2026: requires data broker registration and compliance with deletion requests via California's DROP system.

State Privacy Consortium: a nine-state bipartisan Consortium of Privacy Regulators (including California, Connecticut, New York, Colorado, and Minnesota) is now active, reaching a joint $5.1M settlement with Illuminate Education in November 2025 and launching a joint GPC enforcement sweep in September 2025.

Remote Online Notarization: 47 states plus DC now have RON laws as of February 2025. The SECURE Notarization Act of 2025 has been reintroduced in Congress to establish federal RON standards but remains in committee.

ESIGN/UETA stability: the core e-signature framework hasn't changed. Illinois and Washington completed their shift from older, separate state statutes to UETA proper in 2021 and 2020, leaving New York as the only remaining non-UETA state. Courts continue to uphold e-signature validity, including Maddox v. Indochino (Ohio, 2025) and JPMorgan v. Desert Palace (S.D. Cal., 2023).

FAQ

Frequently asked questions

For any unanswered questions, reach out to our support team via email. We'll respond as soon as possible to assist you.

Are electronic signatures legally binding in the United States?

Yes. Under the federal ESIGN Act and UETA, adopted by 49 states, electronic signatures carry the same legal weight as handwritten signatures for virtually all commercial transactions. Courts have consistently upheld e-signed agreements, including recent rulings like Maddox v. Indochino (Ohio, 2025).

Does the US tier electronic signatures like the EU's eIDAS (SES/AES/QES)?

No. The US has no signature-level system. Any technology-neutral method is equally valid as long as it meets four requirements: intent to sign, consent to do business electronically, association of the signature with the record, and the ability to retain and reproduce the record.

What documents can't be signed electronically in the US?

A short, named list is excluded regardless of signature method: wills, codicils, and testamentary trusts; court orders and filings; documents requiring notarization; and a handful of consumer-protection notices such as utility or insurance cancellation, foreclosure on a primary residence, and product recalls. Powers of attorney rules vary by state.

Does New York have different e-signature rules?

Yes. New York is the only state that hasn't adopted UETA; it uses its own Electronic Signatures and Records Act (ESRA, 2000) instead. In practice the two frameworks work similarly, though ESRA's excluded-document list runs slightly broader, barring e-signatures on all individually executed trusts and powers of attorney, not just wills.

Can foreign e-signature providers like Firma.dev operate in the US?

Yes, without restriction. ESIGN and UETA are provider-neutral: there's no domestic certification requirement and no data residency rule that would block a foreign-hosted platform. Firma.dev's EU-hosted infrastructure serves US customers the same way it serves EU customers.

What privacy law applies to e-signature data in the US?

There's no single federal privacy law. California's CCPA/CPRA is the most comprehensive framework, and more than 20 other states now have their own comprehensive privacy statutes. Each carries its own scope, thresholds, and consumer rights, so multi-state businesses need to check applicability state by state.

What extra requirements apply to healthcare and life sciences documents?

PHI-containing documents need HIPAA-aligned handling: audit trails, signer authentication, encryption, and typically a Business Associate Agreement with the platform. FDA-regulated records fall under 21 CFR Part 11, which calls for unique signer IDs, a complete audit trail, and system validation. Firma.dev supports both through its audit trail and authentication features; confirm validation and BAA scope directly for your specific use case.

How long do signed records need to be retained?

It depends on the document and industry: general commercial contracts typically follow the 4-6 year statute of limitations, tax records need 7 years, HIPAA-covered records need 6 years, and FDA 21 CFR Part 11 records follow the applicable predicate rule. ESIGN requires records be accurately reproducible and accessible, but doesn't mandate a specific storage format.

FAQ

Frequently asked questions

For any unanswered questions, reach out to our support team via email. We'll respond as soon as possible to assist you.

Are electronic signatures legally binding in the United States?

Yes. Under the federal ESIGN Act and UETA, adopted by 49 states, electronic signatures carry the same legal weight as handwritten signatures for virtually all commercial transactions. Courts have consistently upheld e-signed agreements, including recent rulings like Maddox v. Indochino (Ohio, 2025).

Does the US tier electronic signatures like the EU's eIDAS (SES/AES/QES)?

No. The US has no signature-level system. Any technology-neutral method is equally valid as long as it meets four requirements: intent to sign, consent to do business electronically, association of the signature with the record, and the ability to retain and reproduce the record.

What documents can't be signed electronically in the US?

A short, named list is excluded regardless of signature method: wills, codicils, and testamentary trusts; court orders and filings; documents requiring notarization; and a handful of consumer-protection notices such as utility or insurance cancellation, foreclosure on a primary residence, and product recalls. Powers of attorney rules vary by state.

Does New York have different e-signature rules?

Yes. New York is the only state that hasn't adopted UETA; it uses its own Electronic Signatures and Records Act (ESRA, 2000) instead. In practice the two frameworks work similarly, though ESRA's excluded-document list runs slightly broader, barring e-signatures on all individually executed trusts and powers of attorney, not just wills.

Can foreign e-signature providers like Firma.dev operate in the US?

Yes, without restriction. ESIGN and UETA are provider-neutral: there's no domestic certification requirement and no data residency rule that would block a foreign-hosted platform. Firma.dev's EU-hosted infrastructure serves US customers the same way it serves EU customers.

What privacy law applies to e-signature data in the US?

There's no single federal privacy law. California's CCPA/CPRA is the most comprehensive framework, and more than 20 other states now have their own comprehensive privacy statutes. Each carries its own scope, thresholds, and consumer rights, so multi-state businesses need to check applicability state by state.

What extra requirements apply to healthcare and life sciences documents?

PHI-containing documents need HIPAA-aligned handling: audit trails, signer authentication, encryption, and typically a Business Associate Agreement with the platform. FDA-regulated records fall under 21 CFR Part 11, which calls for unique signer IDs, a complete audit trail, and system validation. Firma.dev supports both through its audit trail and authentication features; confirm validation and BAA scope directly for your specific use case.

How long do signed records need to be retained?

It depends on the document and industry: general commercial contracts typically follow the 4-6 year statute of limitations, tax records need 7 years, HIPAA-covered records need 6 years, and FDA 21 CFR Part 11 records follow the applicable predicate rule. ESIGN requires records be accurately reproducible and accessible, but doesn't mandate a specific storage format.

FAQ

Frequently asked questions

For any unanswered questions, reach out to our support team via email. We'll respond as soon as possible to assist you.

Are electronic signatures legally binding in the United States?

Yes. Under the federal ESIGN Act and UETA, adopted by 49 states, electronic signatures carry the same legal weight as handwritten signatures for virtually all commercial transactions. Courts have consistently upheld e-signed agreements, including recent rulings like Maddox v. Indochino (Ohio, 2025).

Does the US tier electronic signatures like the EU's eIDAS (SES/AES/QES)?

No. The US has no signature-level system. Any technology-neutral method is equally valid as long as it meets four requirements: intent to sign, consent to do business electronically, association of the signature with the record, and the ability to retain and reproduce the record.

What documents can't be signed electronically in the US?

A short, named list is excluded regardless of signature method: wills, codicils, and testamentary trusts; court orders and filings; documents requiring notarization; and a handful of consumer-protection notices such as utility or insurance cancellation, foreclosure on a primary residence, and product recalls. Powers of attorney rules vary by state.

Does New York have different e-signature rules?

Yes. New York is the only state that hasn't adopted UETA; it uses its own Electronic Signatures and Records Act (ESRA, 2000) instead. In practice the two frameworks work similarly, though ESRA's excluded-document list runs slightly broader, barring e-signatures on all individually executed trusts and powers of attorney, not just wills.

Can foreign e-signature providers like Firma.dev operate in the US?

Yes, without restriction. ESIGN and UETA are provider-neutral: there's no domestic certification requirement and no data residency rule that would block a foreign-hosted platform. Firma.dev's EU-hosted infrastructure serves US customers the same way it serves EU customers.

What privacy law applies to e-signature data in the US?

There's no single federal privacy law. California's CCPA/CPRA is the most comprehensive framework, and more than 20 other states now have their own comprehensive privacy statutes. Each carries its own scope, thresholds, and consumer rights, so multi-state businesses need to check applicability state by state.

What extra requirements apply to healthcare and life sciences documents?

PHI-containing documents need HIPAA-aligned handling: audit trails, signer authentication, encryption, and typically a Business Associate Agreement with the platform. FDA-regulated records fall under 21 CFR Part 11, which calls for unique signer IDs, a complete audit trail, and system validation. Firma.dev supports both through its audit trail and authentication features; confirm validation and BAA scope directly for your specific use case.

How long do signed records need to be retained?

It depends on the document and industry: general commercial contracts typically follow the 4-6 year statute of limitations, tax records need 7 years, HIPAA-covered records need 6 years, and FDA 21 CFR Part 11 records follow the applicable predicate rule. ESIGN requires records be accurately reproducible and accessible, but doesn't mandate a specific storage format.

Sources

  1. ESIGN Act, 15 U.S.C. § 7001 et seq.: https://www.govinfo.gov/content/pkg/USCODE-2021-title15/pdf/USCODE-2021-title15-chap96.pdf

  2. Uniform Electronic Transactions Act (Uniform Law Commission): https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034

  3. DLA Piper, "With Illinois's adoption of UETA, United States near full adoption" (2021): https://www.dlapiper.com/en-us/insights/publications/2021/07/with-illinoiss-adoption-of-ueta-united-states-near-full-adoption

  4. Miller Nash, "Electronic Signatures in Washington: New State Law": https://www.millernash.com/asset/60a0b4eca5f9f

  5. New York City Bar Association, "Why New York Must Modernize Its Electronic Transactions Law: UETA & ESRA": https://www.nycbar.org/issues-policy/advocacy-campaigns/ueta-esra-new-york-electronic-transactions-law/

  6. New York Electronic Signatures and Records Act, NY State Technology Law Art. III: https://www.nysenate.gov/legislation/laws/STT/A3

  7. California Consumer Privacy Act / CPRA: https://oag.ca.gov/privacy/ccpa

  8. HHS, HIPAA Business Associate Agreements: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html

  9. OneSpan, US e-signature legality guide: https://www.onespan.com/resources/esignature-legality/united-states

  10. DocuSign, US e-signature legality guide: https://www.docusign.com/products/electronic-signature/legality/united-states

Background Image

Start Building with Firma.dev

Firma.dev handles e-signatures for SaaS, agencies, and internal teams operating in the US. At €0.049 per envelope (~5¢) with no monthly minimums, you can ship legally binding signing flows without enterprise contracts or procurement delays.

Background Image

Start Building with Firma.dev

Firma.dev handles e-signatures for SaaS, agencies, and internal teams operating in the US. At €0.049 per envelope (~5¢) with no monthly minimums, you can ship legally binding signing flows without enterprise contracts or procurement delays.

Background Image

Start Building with Firma.dev

Firma.dev handles e-signatures for SaaS, agencies, and internal teams operating in the US. At €0.049 per envelope (~5¢) with no monthly minimums, you can ship legally binding signing flows without enterprise contracts or procurement delays.