When you click “I agree” on a bank’s loan form online, or authenticate a government document using your fingerprint on a mobile app, you are using an electronic signature. But until 2008, Indian law did not formally recognize most of these methods. The original Information Technology Act, 2000 only acknowledged one narrow form of authentication: the cryptography-based digital signature. The IT (Amendment) Act, 2008 changed that fundamentally by introducing Section 3A, which expanded the legal framework to cover a much wider range of signing technologies – without being tied to any single one. This shift, from technology-specific to technologically neutral, is what makes electronic signatures relevant for India’s digital economy today.

Table of Contents

What Section 3A of the IT Act actually says

Before 2008, Section 3 of the IT Act governed digital signatures exclusively through an asymmetric cryptosystem – a method that uses a pair of mathematically linked keys (one private, one public) to sign and verify documents. While secure, this approach required hardware USB tokens issued by licensed Certifying Authorities, which made it impractical for mass adoption.

Section 3A introduced a broader, technology-neutral threshold: a subscriber may now authenticate any electronic record using an electronic signature or electronic authentication technique that is considered reliable and specified in the Second Schedule of the IT Act. Crucially, new additions to the Second Schedule do not need to originate from an Act of Parliament – the Central Government can notify them directly, allowing the law to keep pace with technological change.

For an electronic signature to qualify as reliable under Section 3A, it must meet five conditions:

  • The signature creation data must be linked to the signatory and no one else.
  • At the time of signing, the signature data must have been under the exclusive control of the signatory.
  • Any alteration to the electronic signature after it is affixed must be detectable.
  • Any alteration to the signed information must also be detectable.
  • It must fulfil any additional conditions prescribed by the Central Government.

These clauses ensure that electronic signatures are secure, verifiable, and legally enforceable – regardless of the specific technology used to create them.

Digital signature vs. electronic signature: an important distinction

The two terms are often used interchangeably, but they are not the same under Indian law. A digital signature, defined under Section 3, is cryptography-based and uses public key infrastructure (PKI), while an electronic signature, introduced through Section 3A in 2008, is a broader category that includes any approved authentication method – from Aadhaar-based OTP verification to biometrics.

Think of it this way: all digital signatures are electronic signatures, but not all electronic signatures are digital signatures. Section 3A expanded the definition of electronic signatures to include Aadhaar-based KYC authentication and biometric verification, making the law far more inclusive and accessible.

The legal standing of both is confirmed under Section 5 of the IT Act, which states that wherever any law requires a signature, an electronic signature – if it meets the prescribed standards – fulfills that requirement. Electronic signatures are treated as equivalent to traditional wet signatures and are legally recognised under Section 5 of the IT Act.

Categories of electronic authentication: the UNCITRAL framework

To understand how Indian law classifies electronic authentication, it helps to look at the international model it draws from. The UNCITRAL Model Law on Electronic Signatures (MLES), adopted in 2001, follows a technology-neutral approach that avoids favouring any specific technology or process – recognizing both PKI-based digital signatures and electronic signatures using other technologies. India’s 2008 amendment directly reflects this philosophy.

Based on the UNCITRAL framework, electronic authentication methods fall into three broad categories – and one residual group:

Knowledge-based authentication

These are methods that rely on something the user knows. Knowledge-based methods include passwords and Personal Identification Numbers (PINs). They are the most widely used form of digital authentication worldwide – from email logins to ATM transactions – though they carry higher risks if the user’s credentials are compromised.

Biometric-based authentication

These rely on something the user is – unique physical characteristics that cannot be transferred or duplicated. Biometric methods include fingerprints, iris scans, and voice recognition. In India, Aadhaar-based eSign makes biometric authentication legally viable at scale. Upon successful biometric or OTP authentication, Aadhaar eSign is affixed to the document, completing the process in under a minute.

Possession-based authentication

These depend on something the user has – a physical object that carries authentication data. This category includes codes or other information stored on magnetic cards, chip-based cards, and smart cards. The USB hardware tokens used for traditional Digital Signature Certificates (DSCs) also fall under this category.

Other authentication methods

UNCITRAL also recognizes methods that do not fit neatly into the above three. These include facsimiles of handwritten signatures, names typed at the bottom of electronic messages, scanned signatures, and verification of email addresses or IP addresses. While these carry lower security assurance, they may still carry legal weight in certain low-risk contexts.

Aadhaar eSign: India’s practical application of Section 3A

The most significant real-world application of Section 3A in India is the Aadhaar eSign framework. Introduced in 2015 by the Ministry of Electronics and Information Technology (MeitY), the eSign framework builds on Aadhaar-based authentication for e-signing, and was formally incorporated into the Second Schedule of the IT Act.

The process combines two categories of authentication: possession (Aadhaar number) and knowledge or biometrics (OTP or fingerprint). When a user opts to eSign, the document hash is securely transmitted to a Certifying Authority via the Aadhaar eSign API; upon OTP verification linked to the Aadhaar-registered mobile number, the digital signature is generated and embedded in the document – making it tamper-evident and legally valid.

The practical reach of this is significant. The GST platform now supports Aadhaar eSign for business registration, return filing, and compliance documentation, having minimised paperwork for over 1.3 crore registered businesses in India. Beyond tax, it is used for loan agreements, KYC documentation, insurance policies, hospital consent forms, and court-accepted digital affidavits.

MeitY has played a pivotal role by standardising eSign APIs and onboarding both government and private organisations, and has certified multiple eSign service providers under the Controller of Certifying Authorities (CCA) framework.

The technologically neutral approach of Section 3A does more than expand the range of signing methods – it builds trust in digital transactions by ensuring that legal recognition is not contingent on using one specific tool. The UNCITRAL Model Law on which Section 3A is based aims to enable States to establish a modern, harmonized, and fair legislative framework that gives certainty to the status of electronic signatures.

In India, this legal certainty extends to evidentiary value. Section 65A of the Indian Evidence Act, 1872 recognises the admissibility of electronic records as evidence, while Section 85C provides that if a digital signature is affixed to a document, the court shall presume that document to be true and correct. This means that a contract signed via Aadhaar biometrics carries the same evidential weight in court as one signed with ink on paper.

However, the law does draw clear boundaries. Under Section 1(4) of the IT Act, documents such as negotiable instruments, powers of attorney, trust deeds, wills and testaments, and contracts for the sale of immovable property are excluded from electronic execution. These exceptions exist because the formal and high-scrutiny nature of such documents demands physical presence and notarization.

For everything within the legal scope of the Act, the diverse recognition of electronic signature methods removes barriers to entry. Citizens who cannot afford hardware tokens or lack technical literacy can still participate in digital commerce using their Aadhaar OTP or fingerprint. The two-factor authentication process – which includes both Aadhaar identification and OTP verification – ensures a high level of security, making Aadhaar-based eSign a trusted solution for individuals and businesses handling critical documents.

Why this matters for the digital economy

Before Section 3A, digital authentication in India was effectively locked behind a technological wall that only large enterprises and tech-savvy users could navigate. The 2008 amendment – by anchoring the law in reliability rather than a specific technology – democratized legal authentication. It meant that a farmer in rural Maharashtra could sign a government form using their fingerprint with the same legal validity as a corporate executive using a PKI-based USB token in a city office.

A 2023 PwC report highlighted that 70% of Indian enterprises now use e-signatures, up from 45% in 2020, driven by cost savings – including up to 80% reduction in document processing time – and remote work trends post-COVID. This adoption trajectory is directly linked to the flexible legal architecture that Section 3A created.

Internationally, India’s approach aligns with global norms. The UNCITRAL Model Law has been enacted in over 30 countries, including India and China, ensuring that electronically signed Indian documents are increasingly recognized across jurisdictions. A Delhi High Court ruling in 2022 further affirmed e-signatures in arbitration agreements, solidifying their reliability in legal proceedings.

For a country of India’s scale and diversity, the shift from a single cryptographic standard to a spectrum of legally recognized authentication methods was not just a technical update – it was a policy decision to make trust in the digital economy inclusive, scalable, and future-ready.

What do you think? As electronic signatures continue to replace physical ones across banking, healthcare, and governance – should India consider extending their legal scope to documents currently excluded, like wills or powers of attorney? And does relying on a single national identity infrastructure like Aadhaar for authentication create a concentration of risk in India’s digital trust ecosystem?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.leegality.com/blog/section3a
  2. https://www.esignglobal.com/blog/are-electronic-signatures-legal-in-india
  3. https://www.certificate.digital/articles/25112016/digital-signature-electronic-signature-under-it-act-2000/
  4. https://corridalegal.com/e-signatures-india-legal-validity-compliance-use-cases/
  5. https://www.lexology.com/library/detail.aspx?g=c49488a8-7417-4920-a056-b7d1e4cd363b
  6. https://uncitral.un.org/en/texts/ecommerce/modellaw/electronic_signatures
  7. https://thelegalquotient.com/criminal-laws/information-technology-act/uncitral-model-law-on-electronic-signatures-mles/4439/
  8. https://www.bajajfinserv.in/aadhaar-esign
  9. https://www.tutorialspoint.com/information_security_cyber_law/digital_and_electronic_signatures.htm
  10. https://www.esignglobal.com/blog/india-aadhaar-based-esign-service-provider-online
  11. https://truecopy.in/blog/aadhaar-based-esign-to-sign-a-document-online/
  12. https://proteantech.in/articles/evolution-esignature-08-05-2025/
  13. https://truecopy.in/blog/electronic-signatures-legality-in-india/
  14. https://www.adobe.com/in/acrobat/roc/blog/aadhaar-linked-digital-signatures.html
  15. https://www.esignglobal.com/blog/india-it-act-2000-digital-signature-legal-status
  16. https://www.esignglobal.com/blog/electronic-signature-valid-information-technology-act-2000-india

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Contemporary Scenario of Digital Media

1 Emergence of Digital Media

  1. Defining Digital Media
  2. Characteristics of Digital Media
  3. Digital Media in India
  4. Digital Media and Journalism: Emerging Trends
  5. Challenges

2 Information Society

  1. Technological Transformation and Human Progress
  2. The Emergence of Information Society
  3. What is a Knowledge/Information Society?
  4. Knowledge Economy and Knowledge Workers in an Information Society
  5. Skill Acquisition and Training for Work in Knowledge Society
  6. ICT Infrastructure and Knowledge Dissemination

3 Emerging Trends–Media, Internet, Globalisation

  1. Media
  2. Internet
  3. Globalisation and Human Rights

4 ICTs and Women (Issues of Access and Equity)

  1. Gender Issues in ICT
  2. Women’s Access to ICTs
  3. Strategies for Gender Equity
  4. Benefits of ICTs for Women

5 India Diaspora in Cyberspace

  1. Defining Cyberspace
  2. Understanding Virtual Community
  3. Indian Digital Diasporas
  4. A critical Overview of Literature on Indian Digital Diasporas
  5. ICTs, Nationalism, Religious Diasporas
  6. South Asian Digital Diasporas-Mobile (gadget) Generations

6 ICT and Disability

  1. ICT for Persons with Disabilities
  2. Present and Future of ICT
  3. ICT for various types of Disabilities

7 Convergent Technologies

  1. Electronic Information
  2. Networked Society
  3. Genesis of Convergence
  4. Driving Factors
  5. Technology Convergence
  6. Network Convergence
  7. Switching Convergence
  8. Access Convergence
  9. Service Convergence

8 Open Source Movement

  1. History of Open Source
  2. Open Source Movement
  3. Open Source Software: Philosophy, Principles and Licensing
  4. Types of Software
  5. Desirable Software Attributes
  6. Advantages of Open Source Software
  7. Legal Issues
  8. Other Successful Open Source Software
  9. Applications of Open Source in Other Fields

9 The Regulability of Cyberspace

  1. Desirability of Regulation of Cyberspace
  2. How Cyberspace can be Regulated
  3. Legal and Self Regulatory Framework
  4. Government Policies and Laws Regarding Regulation of Internet Content
  5. Regulation of Cyberspace Content in the United States
  6. Regulation of Cyberspace Content in Australia
  7. Regulation of Cyberspace Content in European Union
  8. Regulation of Cyberspace Content in the United Kingdom
  9. Regulation of Cyberspace Content in India
  10. International Initiatives for Regulation of Cyberspace

10 New Media and Ethical Issues

  1. Definition of New Media Ethics
  2. Rights and Ethical responsibilities of Content Creators
  3. Content Curation and Limits to Sharing
  4. Rights and Ethics of Online Readers
  5. Dealing with Ethical Violations

11 The Concept of Security in Cyberspace

  1. Cyberspace – Why is it not Secure?
  2. Why Should We Secure Cyberspace?
  3. Security Challenges in Cyberspace
  4. The Concept of Cyber Security
  5. Computer Related or Computer Facilitated Crime
  6. Application of Basic Criminal law Concepts

12 Cyberspace and Cyber Crime

  1. Real Space Vs Cyberspace
  2. Digital Identity: An Overview
  3. Verifying Vs. Revealing an Identity
  4. Cyber and Computer Crimes
  5. Architecture of Cyberspace
  6. Preventing Crimes
  7. Implications of Choosing the Link System
  8. Road to Implementation

13 Cyber Law

  1. Concept of Cyberspace
  2. Issues emerging from cyberspace and the need for regulation
  3. International and National Cyber Laws
  4. Information Technology Act, 2000 as amended
  5. Cyber Crimes

14 Information Technology (IT) Act

  1. Statement of Objects and Reasons
  2. Application of the Act – The Extra-Territorial Effect
  3. Electronic Signatures
  4. E-governance
  5. Adjudication
  6. Penalties and Offences
  7. Network Service Provider Liability
  8. Amendments to the Information Technology Act, 14000
  9. Amendments to Certain Statutes