Guide · Compliance

E-signature compliance

What PIPEDA, the ESIGN Act, and UETA require for a legally valid e-signature — and exactly what GetSigned captures to meet those requirements.

The three e-signature frameworks

PIPEDA — Canada

Since 2000

Personal Information Protection and Electronic Documents Act

  • Federal legislation that defines "electronic signature" as information in electronic form that a person has created or adopted in order to sign a document and that is in, attached to, or associated with the document.
  • Schedule 2 of PIPEDA provides that an electronic signature satisfies a legal requirement for a signature when the signature can be reliably created and verified in the circumstances.
  • Provincial e-commerce acts (Ontario ECA, BC ECTA, Alberta ETA, etc.) provide supplementary recognition at the provincial level.
  • Quebec's Act to establish a legal framework for information technology (LCCJTI) sets equivalent standards independently of PIPEDA.

ESIGN Act — United States Federal

Since 2000

Electronic Signatures in Global and National Commerce Act

  • Federal law that gives electronic signatures the same legal weight as handwritten signatures and eliminates paper-only requirements for contracts in interstate and foreign commerce.
  • Requires that the signer have consented to use an electronic signature — consent must be voluntary and documented.
  • Electronic records are the legal equivalent of paper records when all parties have agreed to conduct the transaction electronically.
  • Preempts state laws that restrict electronic signatures, except those consistent with UETA.

UETA — United States (49 States)

Since 1999 (adopted state-by-state)

Uniform Electronic Transactions Act

  • Model law adopted by 49 states and the District of Columbia. New York has its own equivalent (Electronic Signatures and Records Act — ESRA).
  • Establishes that a record or signature may not be denied legal effect solely because it is in electronic form.
  • Requires that the parties agree to conduct the transaction electronically (expressly or by context and conduct).
  • Governs electronic signatures for intrastate commercial transactions, complementing the federal ESIGN Act.

What GetSigned captures for compliance

Every envelope generates a complete evidentiary record — automatically, on every signing.

🔏
Explicit e-sign consent

A mandatory consent click before any signing begins. Logged with timestamp, IP, user agent, and geolocation. Consent is a legal requirement under ESIGN and UETA.

📱
OTP identity verification

Signers verify their identity via a time-limited code sent to their registered email or SMS number before access to the document is granted.

👁
Document view event

The moment a signer opens the document is logged — proving they had the opportunity to read what they were signing.

✍️
Signature event

Each signature application is recorded with full event metadata: which field was signed, by whom, at what time, from which IP.

#️⃣
SHA-256 document hashes

The original document's SHA-256 hash is recorded at creation. The final sealed document's hash is recorded on completion. Any pre- or post-signing modification is detectable.

🔒
PKCS#7 digital seal

A CA-issued digital signature is applied to the entire sealed PDF. Any byte-level modification after sealing invalidates the signature — verifiable in Adobe Reader or any PDF validator.

📋
Hash-chained audit log

All events are appended to an append-only, hash-chained log. Each row hashes the previous row, so tampering with any event is mathematically detectable even with direct database access.

📄
Audit certificate page

A machine-generated certificate page listing all events is embedded in the final PDF before sealing — so the evidentiary record travels with the document.

Exclusions — document types e-signatures cannot cover

ESIGN and UETA explicitly exclude certain document categories. These are not edge cases — check before assuming.

Wills and codicils
Most jurisdictions exclude wills from e-signature legislation — check your jurisdiction.
Adoption and family law orders
Court orders for adoption and custody typically require wet ink signatures.
Certain real estate deeds
Some states and provinces require notarized wet-ink deeds for property title transfer.
Negotiable instruments (some)
Promissory notes and certain negotiable instruments may require paper originals depending on jurisdiction.
Court filings and process
Documents filed with courts generally require jurisdiction-specific e-filing systems, not generic e-signatures.
Notarized documents
Documents requiring notarization need a notary's seal — remote online notarization (RON) is a separate category.

This list is illustrative, not exhaustive. Requirements vary by state and province. Consult qualified legal counsel for your specific documents and jurisdictions.

Frequently asked questions

What is e-signature compliance?

E-signature compliance means that an electronic signature was collected in a way that satisfies the legal requirements of the applicable jurisdiction — most commonly PIPEDA (Canada), the ESIGN Act (US federal), or UETA (US state). The key requirements across all three are: (1) the signer voluntarily consented to sign electronically; (2) the signature is attributable to the signer (via identity verification); (3) the signed document and signing record are retained and accessible. GetSigned is designed to satisfy all three requirements.

What evidence does GetSigned capture to prove an e-signature is valid?

GetSigned captures: explicit e-sign consent with timestamp and IP; OTP identity verification event; document view event; each signature event with metadata; SHA-256 hashes of the original and final document; a PKCS#7 digital seal applied to the entire PDF; and a hash-chained, append-only audit log. All of this is summarized in an audit certificate page embedded in the sealed document. This evidence record is sufficient for defensibility under PIPEDA, ESIGN, and UETA.

Is GetSigned compliant with PIPEDA?

GetSigned is designed to produce e-signatures that satisfy PIPEDA's requirements: the signature is in electronic form, it is created by the signer (via OTP-verified identity), it is attached to the document (via field flattening and PKCS#7 seal), and the record is retained. For PIPEDA Schedule 2 "secure electronic signature" requirements (applicable to specific government documents), a qualified certificate-based signature is required — GetSigned uses a service-level seal rather than a per-signer qualified certificate, which is the correct approach for commercial e-signatures under ESIGN/UETA and most PIPEDA use cases.

What is the difference between an e-signature and a digital signature for compliance purposes?

An e-signature is a legally defined concept: any electronic process that indicates a person's intent to sign. A digital signature is a technical implementation: a cryptographic operation using a public/private key pair that proves document integrity. For ESIGN/UETA/PIPEDA compliance, a legally valid e-signature is what matters — the law does not require a PKI-based digital signature. GetSigned collects a legally valid e-signature (with consent, identity verification, and audit trail) and additionally applies a service-level digital seal (PKCS#7) to the document for tamper-evidence. This gives you both the legal standard and the technical proof.

Are there document types that e-signatures cannot be used for?

Yes. ESIGN and UETA both exclude certain categories: wills and codicils, adoption papers, certain family law documents, and specific notices (utility disconnection, eviction). Negotiable instruments and certain real property conveyances may have additional requirements depending on state law. PIPEDA similarly excludes specific document types from electronic signature recognition. The list above covers the most common exclusions — consult qualified legal counsel for your specific document types and jurisdictions.

Does using GetSigned make my documents automatically compliant?

GetSigned provides the technical infrastructure for legally defensible e-signatures: consent capture, identity verification, document integrity sealing, and audit trail. Compliance also depends on: (1) the document type — see exclusions above; (2) your specific use case and jurisdiction; (3) any sector-specific regulations that may apply (financial services, healthcare, government). "The tool was compliant" is necessary but not sufficient — the overall process must also be compliant. Consult qualified legal counsel for your specific use case.

This page is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for your specific jurisdiction, document types, and compliance requirements.

Related: E-signature legality guide · Audit trail guide · E-sig vs digital signature · E-signatures for legal

Built for compliance from the start

Every envelope captures the full evidence record automatically. No configuration required.

Get free API keys →