Is a digital signature on a proposal legally valid? What is the difference between a simple, advanced and qualified signature, what does article 25 say and what belongs in an audit trail? The eIDAS rules explained for the Netherlands and the EU.
Yes, in nearly all cases. The basis is the European eIDAS Regulation (EU 910/2014), which has applied directly in every member state since 2016 and is implemented in the Netherlands through article 3:15a of the Dutch Civil Code. The core rule is that an electronic signature has the same legal effect as a handwritten one, as long as the method used is sufficiently reliable for the purpose it serves. For a commercial proposal between two businesses that purpose is straightforward: recording that the client agrees to the described scope and price. There is no reason to expect a signed PDF in the post. What does matter is the evidence you hold if a dispute arises later about who agreed to which version and when. This article explains the three eIDAS levels, what an audit trail should contain and when you need a heavier level. It is general information, not legal advice, so consult a lawyer if you are in doubt.
eIDAS distinguishes three levels, each with its own requirements. A simple electronic signature (SES) is any electronic data attached to other data and used by the signatory to sign. A typed name under an email, a tick next to "I agree" or a signature drawn with the mouse are all a SES. An advanced electronic signature (AES) adds four requirements: it is uniquely linked to the signatory, it is capable of identifying the signatory, it is created using means the signatory alone controls, and it is linked to the document so that any later change can be detected. A qualified electronic signature (QES) is an AES created with a qualified signature creation device and based on a qualified certificate issued by a supervised trust service provider, in the Netherlands overseen by the Dutch Authority for Digital Infrastructure. Only the QES is automatically equivalent to a handwritten signature by law. For SES and AES a court assesses case by case whether the method was reliable enough.
Article 25 of eIDAS is the one to know. Paragraph 1 states that an electronic signature shall not be denied legal effect or admissibility as evidence solely on the grounds that it is in electronic form or that it does not meet the requirements for a qualified signature. That means a court cannot dismiss a SES with the argument that it is "only" an electronic signature. Paragraph 2 gives a QES the legal effect of a handwritten signature. Paragraph 3 states that a QES based on a certificate from one member state is recognised in all others. In practice this means a SES gives you a valid signature, but in a dispute you have to demonstrate yourself that the signature came from the client and that the document has not changed since. That is where the audit trail comes in.
An audit trail is the logbook around the signature and it determines how strong your evidence is. A usable audit trail contains at least the following. 1. The identity of the signatory: name and email address, and the way that person gained access to the document, for example a unique link sent only to that address. 2. The time of every event: sending, opening, viewing sections and signing, with time zone. 3. The IP address and the device used to sign. 4. A cryptographic hash of the document at the moment of signing, so you can show the text has not changed. 5. The version of the proposal that was signed, because proposals are often revised after sending. 6. A seal on the signed document and a place where the client or a third party can verify the signature. Proposal Expert delivers a SES within eIDAS with exactly that kind of audit trail: timestamp, IP logging, a sealed document and a unique verification URL per signature. The electronic signatures page lists the fields the evidence report contains.
A QES is required in a limited set of situations. When a law explicitly prescribes a qualified signature, as with certain deeds and some court filings and government procedures. When a contract with a counterparty or an industry rule demands that level, which you mainly see with financial institutions and in public tenders. When the stakes are high enough that you want to rule out any argument about the identity of the signatory, for example an acquisition or a long-term contract with a large value. And when you work across borders and want to be certain the signature is recognised in every member state without discussion. For a proposal for a website, a consulting engagement or a renovation none of that applies. A SES with a solid audit trail is sufficient there, and that is what Proposal Expert deliberately provides.
An example. A marketing agency sends a proposal for 14,500 euros to a client on Monday via a unique link. On Tuesday the client opens the proposal, reads the approach and the pricing, and forwards the link to the finance director. On Wednesday the director signs via the same link with a typed name and a tick next to the terms. The evidence report then shows: two different IP addresses and devices, the time of each step, the hash of version 2 of the proposal that was open at that moment, and the seal applied after signing. If three months later the client claims a different amount was agreed, you can show which text was on screen at the moment of signing and that it has not been altered since. That is precisely the evidence article 25 asks of you with a SES.
It is a SES and therefore valid in principle, but the evidence is weak. Anyone can copy that image and the document can be edited after signing without it showing. You have no timestamp, no log and no seal. In a dispute the question of who signed what and when becomes hard to answer.
Within the EU, yes, eIDAS applies in every member state. The United Kingdom kept its own version of eIDAS after Brexit that works the same way in outline. For clients outside Europe, for example in the United States, other laws such as the ESIGN Act apply and they also recognise electronic signatures. For large amounts outside the EU, check what applies locally.
Then it comes down to your audit trail. You show that the link was sent only to the client's email address, from which IP address and device the signature was placed and at what time, and that the document has been sealed since. Keep the evidence report together with the signed proposal for as long as the agreement and the limitation period run.