
United States
Fully legal
Overview
Intro & Key Facts
Quick Summary
Practical Usage
Permitted Document Types
Commercial contracts
NDAs
SaaS terms and MSAs
Purchase orders
Employment agreements (in most states)
Real estate contracts and leases
Insurance applications
Financial agreements
Healthcare consent forms (with HIPAA safeguards)
Restricted Document Types
Wills, codicils, and testamentary trusts
Court orders and filings
Documents requiring notarization
Powers of attorney (rules vary by state)
Adoption and certain divorce filings
Foreclosure notices on primary residences
Utility and insurance cancellation notices
Product recall notices
Hazardous materials shipping documents
Common Exclusions
Authentication Required
B2B transactions: No statutory authentication requirement. ESIGN and UETA require only that the signature be reliably attributable to the signer and that the signer intended to sign.
Consumer transactions: Additional requirement to demonstrate the signer can access electronic records.
HIPAA-covered documents: Sector-specific authentication requirements apply on top of the ESIGN/UETA baseline.
FDA 21 CFR Part 11 documents: Sector-specific authentication requirements apply on top of the ESIGN/UETA baseline.
Restrictions
Signing Workflow Controls
Generally Permitted
Time-limited signature windows.
Sequential signing order.
Mandatory field completion.
Document expiration dates.
IP-based access restrictions.
Password-protected envelope access.
SMS or email verification codes.
Attachment requirements.
May Require Special Handling or Exclusions
Restrictions that prevent signers from reviewing the complete document before signing.
Restrictions that obscure material terms.
Blanket prohibitions on retaining personal copies.
Requirements for specific hardware or paid software to complete signing.
For consumer transactions, skipping the affirmative opt-in to electronic delivery that ESIGN requires, or blocking a consumer's right to withdraw that consent.
Legal Requirements
United States E-Signature Law Explained
Legal Frameworks
Regulatory Bodies
Minimum Retention
General commercial contracts: 4-6 years (statute of limitations)
Tax records: 7 years
HIPAA-covered records: 6 years
FDA 21 CFR Part 11 records: Per the applicable predicate rule
SEC-regulated records: 3-6 years, depending on record type
Retention Notes
Data, Privacy & Cross-Border
Data Privacy and Compliance United States
Privacy Frameworks
No federal comprehensive privacy law. California's CCPA/CPRA is the most established, and more than 20 other states now have their own comprehensive privacy statutes (Virginia, Colorado, Connecticut, Utah, and others), each with its own scope and thresholds.
Privacy Compliance Status
Firma.dev processes signer data consistent with the obligations that apply to a processor under US state privacy law. No special certification is required for standard commercial e-signature workflows. Healthcare customers who need a Business Associate Agreement for HIPAA-covered documents should confirm current availability directly with the Firma.dev team.
Privacy Notes
Requirements vary by state, but most give consumers rights to access, correct, delete, and opt out of the sale of their data. CCPA/CPRA is the most comprehensive and unusually extends some rights to employees and B2B contacts, not just consumers. None of these laws impose a data localization requirement.
Data Residency
Adequacy Decision
The US isn't an EU member state and has no domestic adequacy-decision system for judging other countries' data protection, so this doesn't apply symmetrically the way it does on EU-country pages. What does apply: the US holds adequacy status under the EU-US Data Privacy Framework (July 2023, replacing the invalidated Privacy Shield), permitting lawful transfers of EU personal data into the US for Framework participants. This doesn't affect Firma.dev's ability to serve US customers from EU-hosted infrastructure.
Cross-Border Transfers
Yes, unrestricted for e-signature purposes. The US doesn't operate its own adequacy-decision regime; the relevant mechanism runs the other direction, EU-to-US, under the EU-US Data Privacy Framework.
Residency Notes
The US has no data residency requirement for e-signature data. Foreign hosting is fully permitted, so Firma.dev's EU-hosted infrastructure (AWS Paris) serves US customers without restriction.
Maximum Retention
No statutory maximum tied to e-signature data specifically. CCPA/CPRA requires retention be limited to what's reasonably necessary for the disclosed purpose, and businesses must disclose retention periods or criteria at the point of collection. Consumer request records must be kept at least 24 months.
Industry Compatibility
E-Signatures by Industry in United States
Fully Supported Industries
General Commercial
SaaS Software
Insurance
Financial Services/Fintech
HR Tech Employment
Legal Tech
Real Estate Tech
Education/Edtech
Construction
Supported with Agreement
Healthcare
Life Sciences/Pharma
Should Consult Counsel
Government
Industry Matrix Notes
Most B2B commercial use cases work with standard e-signatures under ESIGN/UETA. Healthcare and life sciences need HIPAA and FDA 21 CFR Part 11 controls layered on top. Government contracting varies by agency and should be confirmed case by case. A short, named list of document types (wills, court orders, notarized instruments) sits outside ESIGN/UETA entirely regardless of industry.
General Commercial
Standard B2B contracts, vendor agreements, NDAs, purchase orders, and service agreements are all valid with e-signatures under ESIGN and UETA. There's no requirement to use a specific signature technology or a domestically certified provider; any method that shows intent to sign and can be tied to the signer works.
SaaS Software
SaaS companies can use standard e-signatures for the full range of B2B agreements: software licenses, subscription terms, MSAs, DPAs, and API terms of service. ESIGN and UETA's technology-neutral standard means there's no signature tier to worry about, just the four baseline requirements: intent, consent, association with the record, and retention capability.
Healthcare
Documents containing protected health information need extra care beyond standard ESIGN/UETA validity. HIPAA requires audit trails, signer authentication, and encryption in transit and at rest, and typically a signed Business Associate Agreement with the platform before it can handle PHI. Firma.dev's audit trail, authentication options, and encryption are designed to support HIPAA-aligned workflows; confirm BAA availability with the Firma.dev team before handling PHI-bearing documents.
Life Sciences/Pharma
FDA-regulated electronic records and signatures fall under 21 CFR Part 11, which calls for unique signer identification, a complete audit trail, and tamper-evident records, with the retention period set by the applicable predicate rule. Firma.dev's audit trails, authentication, and document integrity features are designed to support Part 11 workflows; system validation and predicate-rule compliance remain the customer's responsibility.
Insurance
Insurance applications and policy documents are generally valid with standard e-signatures. Some states apply their own disclosure rules to insurance transactions specifically, so confirm state-level requirements for consumer-facing policies.
Financial Services/Fintech
Loan documents, account agreements, and other financial services paperwork are valid under ESIGN/UETA with no additional signature tier required. The SEC and state regulators impose their own recordkeeping rules for regulated entities, so retention periods should follow the applicable rule rather than the general statute-of-limitations default.
HR Tech Employment
Offer letters, onboarding paperwork, and most employment agreements are valid with standard e-signatures in the large majority of states. Section 1 of Form I-9 can be completed electronically under DHS rules; Section 2 carries its own in-person or authorized-representative verification requirement that e-signature alone doesn't satisfy.
Legal Tech
Engagement letters, NDAs, and most legal services documents are valid with standard e-signatures. Court filings and certain notarized instruments fall outside ESIGN/UETA and need to go through the court's own e-filing system or a notarial process instead.
Real Estate Tech
Most real estate paperwork, including leases, disclosures, and purchase agreements, is valid with standard e-signatures under ESIGN/UETA. The exclusion is narrow: instruments that legally require notarization or recording, most deeds and mortgages, still need a notarial process, increasingly available as remote online notarization in most states.
Education/Edtech
Enrollment agreements, consent forms, and administrative paperwork are valid with standard e-signatures. FERPA governs the privacy of the underlying student records rather than the signature method itself.
Construction
Contracts, subcontractor agreements, change orders, and project documentation are all valid with standard e-signatures under ESIGN/UETA. No federal or state requirement calls for anything beyond standard signer identification and an audit trail.
Government
Government contracting requirements vary by agency and can include their own procurement-specific rules. Confirm the specific agency's requirements before relying on standard e-signatures for a government contract.
How we works
How Firma.dev Works in United States
Firma.dev Supports
Firma.dev's signature capabilities meet US requirements without any additional certification. ESIGN and UETA don't tier signatures the way eIDAS does, so the SES/AES distinction that matters in the EU has no direct legal equivalent here: any technology-neutral method that shows intent to sign is fully valid, including what Firma.dev provides.
Firma.dev meets US e-signature requirements without any additional certification. The platform provides:
Signer identification: Email-link or SMS one-time-code authentication
Tamper-evident documents: Cryptographic sealing ensures any modification after signing is detectable
Complete audit trails: Every action is timestamped and logged
EU data residency: All data hosted in AWS Paris, which the US imposes no residency requirement against
For B2B software agreements, SaaS subscriptions, employment contracts, NDAs, and vendor agreements, Firma.dev's signature process satisfies the ESIGN Act and UETA's four validity requirements.
Firma.dev's API-first design means you can embed signing directly into your application. US companies using Customer Workspaces get isolated environments for each customer, with templates and envelope usage tracked separately.
Legal Details
The United States built its e-signature framework around two pillars: the federal ESIGN Act and the state-level UETA.
The Electronic Signatures in Global and National Commerce Act (ESIGN, 2000) is the federal law that established e-signature validity nationwide. It's deliberately technology-neutral and provider-neutral: there's no requirement to use a specific signature technology or a domestically certified provider, which is unusual compared to jurisdictions built around a tiered system like the EU's eIDAS.
The Uniform Electronic Transactions Act (UETA, 1999) is a model state law that fills in the state-level detail underneath ESIGN. It's now been adopted, by name, in 49 states, including Illinois and Washington, which each ran their own separate electronic-transactions statutes for years before formally enacting UETA in 2021 and 2020. New York is the only holdout: it still relies on its own Electronic Signatures and Records Act (ESRA, 2000) rather than adopting UETA. In practice ESRA reaches a similar result to UETA, though its excluded-document list runs a little broader, barring e-signatures on all individually executed trusts and powers of attorney rather than just wills.
Signature Types Recognized
Unlike eIDAS, US law doesn't define separate signature tiers. Both ESIGN and UETA test validity against the same four requirements regardless of the technology used: intent to sign, consent to conduct the transaction electronically, association of the signature with the record being signed, and the ability to retain and reproduce that record. There's no second tier of "advanced" or "qualified" signatures required for higher-stakes documents.
Firma.dev's signing flow meets the same security bar that eIDAS calls SES and AES, though US law has no equivalent classification for it: any valid electronic signature works the same way here.
US law handles exclusions differently: a short, named list of document types sits outside ESIGN/UETA's scope entirely, regardless of signature method. Wills, codicils, and testamentary trusts, court orders, documents requiring notarization, and a handful of consumer-protection notices (utility and insurance cancellation, foreclosure on a primary residence, product recalls) fall into this category. Everything else, including commercial contracts, NDAs, employment agreements, and real estate leases, is fair game for standard e-signatures.
Industry-specific rules layer on top of this baseline rather than replacing it. HIPAA adds authentication, audit trail, and encryption requirements for documents containing protected health information, typically alongside a Business Associate Agreement with the platform. FDA 21 CFR Part 11 adds unique signer identification, audit trails, and system validation requirements for FDA-regulated electronic records. Neither changes what counts as a valid signature under ESIGN/UETA; both add controls on top of it.
For SaaS companies, agencies, and internal teams building or using signing workflows in the US, the practical result is straightforward: standard e-signatures cover commercial contracts, NDAs, employment paperwork, and vendor agreements without any special signature tier, and the main things to track are the narrow document exclusions and the sector-specific overlays for healthcare and life sciences.
Recent developments
E-Signature Landscape in United States: 2026
CCPA enforcement acceleration: major 2025 settlements include Tractor Supply ($1.35M), Sling TV ($1.4M for missing mobile app opt-outs), and Honda for dark-patterns violations. CalPrivacy launched a Data Broker Enforcement Strike Force in November 2025.
New CCPA regulations (effective January 1, 2026): cybersecurity audit and risk assessment requirements, new automated decision-making technology (ADMT) rules, mobile apps now required to link their privacy policy, annual risk assessment reports required (first due April 2028).
Delete Act (SB 362), effective January 1, 2026: requires data broker registration and compliance with deletion requests via California's DROP system.
State Privacy Consortium: a nine-state bipartisan Consortium of Privacy Regulators (including California, Connecticut, New York, Colorado, and Minnesota) is now active, reaching a joint $5.1M settlement with Illuminate Education in November 2025 and launching a joint GPC enforcement sweep in September 2025.
Remote Online Notarization: 47 states plus DC now have RON laws as of February 2025. The SECURE Notarization Act of 2025 has been reintroduced in Congress to establish federal RON standards but remains in committee.
ESIGN/UETA stability: the core e-signature framework hasn't changed. Illinois and Washington completed their shift from older, separate state statutes to UETA proper in 2021 and 2020, leaving New York as the only remaining non-UETA state. Courts continue to uphold e-signature validity, including Maddox v. Indochino (Ohio, 2025) and JPMorgan v. Desert Palace (S.D. Cal., 2023).
Sources
ESIGN Act, 15 U.S.C. § 7001 et seq.: https://www.govinfo.gov/content/pkg/USCODE-2021-title15/pdf/USCODE-2021-title15-chap96.pdf
Uniform Electronic Transactions Act (Uniform Law Commission): https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034
DLA Piper, "With Illinois's adoption of UETA, United States near full adoption" (2021): https://www.dlapiper.com/en-us/insights/publications/2021/07/with-illinoiss-adoption-of-ueta-united-states-near-full-adoption
Miller Nash, "Electronic Signatures in Washington: New State Law": https://www.millernash.com/asset/60a0b4eca5f9f
New York City Bar Association, "Why New York Must Modernize Its Electronic Transactions Law: UETA & ESRA": https://www.nycbar.org/issues-policy/advocacy-campaigns/ueta-esra-new-york-electronic-transactions-law/
New York Electronic Signatures and Records Act, NY State Technology Law Art. III: https://www.nysenate.gov/legislation/laws/STT/A3
California Consumer Privacy Act / CPRA: https://oag.ca.gov/privacy/ccpa
HHS, HIPAA Business Associate Agreements: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
OneSpan, US e-signature legality guide: https://www.onespan.com/resources/esignature-legality/united-states
DocuSign, US e-signature legality guide: https://www.docusign.com/products/electronic-signature/legality/united-states


