Latest Updates

JC Master Information | People’s Justice: Determining the Legal Effectiveness of Digital Signatures in Electronic Contracts


Summary of the Judgment

The legal validity of an electronic signature should be assessed comprehensively, taking into account the technology employed, the evidentiary weight of third-party certification reports, and the procedures governing the electronic signing process. Depending on whether digital signature technology is used, electronic signatures may be classified as either ordinary electronic signatures or reliable electronic signatures. With respect to digital signatures that meet the technical requirements for reliable electronic signatures, their reliability may not be determined solely through handwriting analysis based on comparisons with sample writings; rather, it must be evaluated in conjunction with an examination of third-party certification reports and the electronic signing workflow, to ascertain whether they satisfy the characteristics of exclusivity, control, and tamper‑proofness prescribed by the Electronic Signature Law for reliable electronic signatures.  Image  Image  

 

Facts of the Case

 

Plaintiff: A certain financial leasing company.

Defendants: a certain trading company, Li, and Gao.


 

On October 15, 2021, a certain financial leasing company (the lessor), a certain trading company (the lessee), Li Mou (the guarantor), and Gao Mou (the guarantor) jointly executed a financial leasing contract through a designated electronic signing platform. Under the agreement, the financial leasing company purchased a batch of equipment from an equipment supplier and then leased it to the trading company for use; concurrently, Li Mou and Gao Mou assumed joint and several guarantee liabilities. The contract stipulated that the total purchase price of the leased equipment was RMB 2,363,300, with an initial down payment of RMB 472,660; the lease term was 36 months, with monthly rental payments of RMB 61,656, totaling RMB 2,219,616, and also set forth provisions regarding liability for breach of contract.


 

A forensic appraisal report issued by a certain appraisal institution indicates that the signature of “Gao Mou” on the aforementioned finance lease contract does not match Gao Mou’s actual handwriting. Evidence, including an evidence‑preservation report provided by a certain electronic signing platform, demonstrates that the specific steps of the electronic signing process on that platform are as follows: 1. The parties register an account on the electronic signing platform; 2. The parties undergo real‑name authentication; 3. A licensed electronic certification service provider issues a digital certificate to those who have passed real‑name authentication; 4. The parties send and receive the electronic contract and review its contents; 5. The parties acknowledge the content of the electronic contract and authorize the use of their own digital certificates to sign it. Upon completion of the electronic signature, the contract is deemed concluded and takes effect. The signed contract is then transmitted via internationally recognized… Hashing Technology Ensure that the electronic contract cannot be tampered with, or that any tampering with the electronic contract can be detected.


 

A certain financial leasing company alleges that it, together with a certain trading company, Li, and Gao, all executed electronic contracts through a specific electronic signing platform, and that the financial leasing contract at issue reflects the genuine intentions of all parties. Accordingly, the company seeks an order requiring the trading company to pay outstanding lease payments totaling RMB 924,840, together with liquidated damages, and holding Li and Gao jointly and severally liable for such obligations.


 

Gao argued that the finance lease contract at issue was not signed by him personally, and that the handwriting examination concluded that the electronic signature did not correspond to his own handwriting; accordingly, he refused to assume joint and several guarantee liability.

 

Trial

  

After trial, the People’s Court of Changning District, Shanghai, held that the finance lease contract at issue is genuine and valid, and that a certain trading company is liable for repayment and breach of contract. Li signed as a guarantor under the contract and thus bears joint and several guarantee liability. However, according to the forensic appraisal report, the signature “Gao” in the guarantor section does not correspond to Gao’s handwriting, and the existing evidence fails to establish that Gao expressed an intention to provide a guarantee for the finance lease contract in question. Accordingly, the Changning District Court rendered the following first-instance judgment: First, the trading company shall pay the finance leasing company RMB 924,840 in unpaid rent, together with default interest and other related sums; second, Li shall bear joint and several liability for the trading company’s obligation under the first item above; third, the finance leasing company’s remaining claims in the first instance are dismissed.


 

A certain financial leasing company, dissatisfied with the first-instance judgment, contended that Mr. Gao signed the contract through a specific electronic signing platform, as evidenced by an official evidence‑preservation report; accordingly, it argued that the contract in question should be deemed to have been executed by him personally and thus filed an appeal.


 

The Shanghai Financial Court, after trial, rendered its second-instance judgment as follows: First, the third item of the first-instance judgment is hereby revoked; second, Mr. Gao shall bear joint and several liability for the payment obligation set forth in the first item of the first-instance judgment; third, the remaining claims brought by a certain financial leasing company in the first instance are dismissed.


 

Analysis

 

As digital technologies become increasingly integrated with financial services, electronic data is increasingly emerging as the central type of evidence in internet‑finance disputes. Among these, the criteria for recognizing electronic signatures are particularly critical in determining the formation and legal validity of various financial contracts. Article 13 of the Electronic Signature Law explicitly sets forth the requirements for a reliable electronic signature; the establishment of this legal standard helps to accurately assess the often‑contentious issue of the validity of electronic signatures in contemporary contract disputes. Nevertheless, in judicial practice, significant controversies persist regarding the classification of electronic signatures, the methods of their certification, and the specific criteria for evaluating their reliability. This case, accordingly, seeks to explore and clarify the principles governing the adjudication of such matters.

 

One

Definition and Types of Electronic Signatures

(1) Definition of an Electronic Signature


 

Article 2 of the Electronic Signature Law provides: “For the purposes of this Law, an ‘electronic signature’ refers to data in electronic form contained in or attached to a data message, used to identify the signer’s identity and indicate the signer’s approval of the content therein. A ‘data message’ means information generated, sent, received, or stored by electronic, optical, magnetic, or similar means.” According to these provisions, an electronic signature must exist in the form of electronic data and be capable of identifying the signer’s identity. In practice, the scope of electronic signatures is quite broad; it may encompass any signature applied electronically, and various forms of electronic signatures are increasingly employed in modern commercial activities, particularly in diverse types of electronic contracts.


 

(II) Types of Electronic Signatures


 

Depending on whether digital signature technology is employed, electronic signatures are classified as either ordinary electronic signatures or qualified electronic signatures. In judicial proceedings, distinguishing between these types of electronic signatures directly affects the application of the criteria for determining their legal validity.


 

With regard to ordinary electronic signatures, in practice some electronic contracts employ electronic signatures that do not utilize digital signature technology. Such signatures encompass a broad spectrum and may be implemented through various technical means. A common approach involves the signer physically writing their signature on an electronic device’s screen and inserting the captured signature image into the designated signature field of the electronic contract. Compared with traditional paper‑based signatures, this type of electronic signature differs only in the medium used for recording the signature; it thus falls under the category of ordinary electronic signatures. For such ordinary electronic signatures that do not rely on digital signature technology, their fundamental nature is akin to that of conventional handwritten signatures. Consequently, standard handwriting analysis—by comparing the signature against reference samples—can be employed to determine whether the handwriting in question was produced by a specific individual, which is technically feasible. In addition, ordinary electronic signatures also include methods such as signing with software account credentials, transmitting computational tokens that verify the sender’s identity, or utilizing specific biometric identification techniques—none of which possess the formal characteristics of a written signature. However, regardless of the particular technical implementation, none of these approaches employs digital signature technology.


 

With regard to reliable electronic signatures, electronic signatures that employ digital signature technology differ from traditional paper-based signatures. They are not merely an electronic representation of a handwritten signature; rather, they are fundamentally grounded in digital signature technology. Digital signatures themselves constitute a type of electronic signature, involving the encryption of electronic records through an asymmetric cryptographic system, thereby offering enhanced security. Whether an electronic signature meets the criteria for reliability should be determined in accordance with the Electronic Signature Law. From a technical standpoint, digital signature technology is among the most compliant with the requirements for reliable electronic signatures; accordingly, its reliability cannot be assessed through handwriting analysis based on the comparison of ink‑sample traces.


 

In this case, the electronic signature technology employed by Mr. Gao during the execution of the contract at issue on a certain electronic signing platform was based on ADOBE PDF documents and complied with industry‑standard practices. X.509 Standard CA digital certificates and the RFC 3161 digital timestamp protocol, which employ asymmetric cryptographic algorithms and standard hash functions to generate electronic signatures on documents, have been recognized by the appellate court as constituting digital signatures. By contrast, the trial court relied on conventional handwriting analysis to assess the authenticity of such a digital signature, a approach that clearly conflicts with the technical characteristics inherent in digital signatures themselves. Accordingly, distinguishing among the types of electronic signatures is an essential factual prerequisite for the accurate application of the criteria governing their legal validity.


 

Two

Principles for Determining the Legal Effect and Reliability Requirements of Electronic Signatures

The Electronic Signature Law sets out general principles regarding the reliability requirements for electronic signatures. In judicial practice, whether an electronic signature is valid must be assessed comprehensively, taking into account the type of electronic signature, the evidentiary value of certification reports issued by third-party institutions, and the procedures followed in the electronic contracting process.


 

(1) Requirements for a Reliable Electronic Signature under the Electronic Signature Law


 

Article 13, Paragraph 1 of the Electronic Signature Law stipulates: “An electronic signature shall be deemed a reliable electronic signature if it simultaneously meets the following conditions: (1) the data used to create the electronic signature is exclusively under the control of the electronic signatory; (2) at the time of signing, such creation data is controlled solely by the electronic signatory; (3) any alteration to the electronic signature after signing can be detected; and (4) any modification to the content or form of the data message after signing can be detected.” Accordingly, a reliable electronic signature must satisfy three essential requirements: exclusivity, control, and tamper‑proofness. The “Interpretation of the People’s Republic of China Electronic Signature Law,” compiled by the Legislative Affairs Commission of the Standing Committee of the National People’s Congress, provides a detailed explanation of these three criteria for assessing reliability. First, the exclusivity of an electronic signature focuses on determining its attribution—ensuring the identity and accuracy of the link between the electronic signature and the electronic signatory. If the data used to create the electronic signature is in the possession of another party, the fundamental requirement of exclusivity is not met. Thus, this criterion primarily examines the authenticity of the signatory’s identity. Second, the control over the electronic signature emphasizes substantive control—that is, the ability to exercise control over the creation data based on the electronic signatory’s free will. During the process of executing an electronic signature, whether the signatory personally performs the act or delegates it to another, as long as the signatory retains substantive control, the act may be attributed to that individual. Consequently, this criterion places particular emphasis on the genuineness of the expression of intent. Third, the tamper‑proof nature of the electronic signature centers on using technical means to verify whether the digital signature has been altered after signing and whether the data message itself has been tampered with by others. Therefore, this criterion primarily assesses the consistency between the signature and the signed content and the original text signed by the party concerned.


 

(II) Principles of Judicial Recognition of Third-Party Certification Reports


 

Article 16 of the Electronic Signature Law stipulates: “Where an electronic signature requires third-party certification, such certification shall be provided by a legally established electronic certification service provider.” Administrative Measures for Electronic Certification Services Article 2 stipulates: “For the purposes of these Measures, ‘electronic certification services’ refer to activities that provide verification of the authenticity and reliability of parties involved in electronic signatures.” Accordingly, the service function of third-party certification is precisely to ensure the authenticity and reliability of electronic signatures. In judicial proceedings, courts often rely on certification reports issued by third-party institutions to assess the reliability of electronic signatures; such reports are typically prepared by third parties. CA authority , issued by an electronic signing platform or a notarization platform. As in this case, the digital certificate applied for by Mr. Gao was issued by a third-party CA, while the evidence‑preservation report for the signing process was generated by a certain electronic signing platform.


 

It should be noted that, in practice, reports issued by third-party institutions typically include identity verification reports and digital certification reports. Most certification reports merely state the name of the electronic contract file; therefore, during review, it remains essential to verify the correspondence between the certification report and the electronically signed contract. Such verification may involve a comprehensive assessment based on multiple factors, including hash‑value comparison, screen recordings of the certification process, signature timestamps, and the number of electronic contracts executed between the parties. In this case, for instance, Mr. Gao challenged the timestamp contained in the evidence‑preservation report, questioning why there was only a one‑second interval between facial recognition and the click to conoffice agreement at the time of signing and the actual completion of the contract. The court, through inquiries with the evidence‑preservation platform regarding the facial‑recognition procedure at the time of signing, determined that Mr. Gao had already undergone voluntary identity verification via facial recognition when registering his account on the electronic signing platform. Consequently, upon conofficeing the contract, he directly utilized the facial‑recognition data he had provided during registration, which explains the short time gap between his consent and the contract’s execution.


 

As for reports issued by third-party contract‑signing platforms and evidence‑preservation platforms, given that there are currently no regulatory requirements governing market access or qualification standards for such platforms, their validity may be assessed in light of factors such as whether the platform holds an electronic certification service license and its cooperation agreements with licensed institutions.


 

(3) The reliability of an electronic signature may also be assessed through a comprehensive review that takes into account the type of electronic signature, the electronic contracting process, and other relevant factors.


 

The Electronic Signature Law’s provisions on the three requirements for a reliable electronic signature are rather abstract, leading to inconsistencies in judicial practice regarding the criteria for determination. The primary reason is the diversity of electronic signature formats and the variations in the contracting procedures of different electronic agreements, which necessitate that the reliability of an electronic signature be assessed on a case-by-case basis, taking into account the specific circumstances involved. Overall, such assessments may be conducted from the following perspectives:


 

First, with respect to identity verification for electronic signatures, a distinction should be drawn between natural persons and legal entities. For natural persons, identification typically encompasses, but is not limited to, biometric methods such as dynamic facial recognition, authentication tied closely to personal information—such as national ID cards or bank cards—and various online verification techniques like mobile‑based one‑time SMS codes. In this process, if the party can provide an authentication report issued by an independent third‑party institution (e.g., a Certificate Authority), such evidence is generally admissible. As in the present case, after logging into a particular electronic contracting platform, Mr. Gao initiated the application for a digital certificate, undergoing both “name–ID card” consistency verification and facial‑recognition‑based intent conofficeation to complete real‑name authentication. The resulting digital certificate was ultimately certified and issued by a third‑party entity; accordingly, the court conofficeed that the electronic signature at issue was uniquely attributable to Mr. Gao. By contrast, for legal entities, two distinct forms of signing must be distinguished. First, where a legal entity authorizes a natural person to execute an electronic contract, the identity‑verification procedures for the legal entity’s electronic signature are essentially the same as those applied to the natural person’s electronic signature and may be treated analogously. Second, where a legal entity directly employs its own electronic seal to execute a contract, if the electronic signature consists of a combination of the legal entity’s electronic seal image and a digital certificate issued by a third‑party authority, such a signature is generally recognized, given that the legal entity has already undergone identity verification and validation when obtaining the digital certificate. In practice, some legal entities’ electronic seals have been filed with local public security organs; these may be verified in accordance with the relevant local regulations governing electronic seal management. However, at present, no uniform national standards for managing electronic seals exist, necessitating further research and exploration in practical application.


 

Secondly, with regard to the authenticity of the electronic signatory’s expression of intent, the electronic signing process helps determine whether such expression is genuine. Although electronic signatures may take various forms, the typical electronic signing procedure comprises three stages: real-name authentication, online signing, and document storage. In general, if a party fails to provide complete certification reports from third-party institutions—such as identity verification reports or digital signature certification reports—or if other evidence indicates inconsistency with the reported content, that party must submit documentation of the signing process to substantiate the relevant facts. Currently, commonly used methods for documenting the electronic signing process include videos tracing the signing sequence, notarized records of the signing process, and… Blockchain-based evidence preservation As in this case, Gao argued, on the basis of the handwriting‑expertise findings, that the electronic signature was not affixed by him. The second‑instance court further examined the signing procedure for the finance‑lease contract at issue; a certain electronic‑signing platform issued an evidence‑preservation report, which constituted blockchain‑based evidence preservation. Absent contrary evidence sufficient to rebut it, such evidence‑preservation reports should be deemed admissible.


 

Finally, with regard to the consistency of the content of electronic contracts: In practice, the most common types of electronic data evidence submitted by the parties include electronically signed contracts, audio‑video recordings, and system operation logs. Article 5 of the Electronic Signature Law sets forth the formal requirements for an original data message; Article 8 establishes the standards for verifying the authenticity of data messages as evidence; and Article 13 stipulates the tamper‑proofing requirements for electronic signatures—all aimed at ensuring that the disputed electronic contract is consistent with the party’s original signed version. Generally, electronic data preserved through third‑party notarization or blockchain-based preservation must be accompanied by a certification report issued by the preserving institution to conoffice its authenticity. As in this case, the notarization report issued by a third‑party certifying body explicitly states that the contract at issue has not been altered since its execution and includes the hash values of the relevant electronic contract PDF files. The second‑instance court accordingly conofficeed that the finance lease contract submitted by a certain financial leasing company was consistent with the contract terms—including the electronic signature and contractual provisions—at the time it was signed by Mr. Gao. By contrast, for electronic contracts that cannot provide such a certification report, the party bearing the burden of proof must submit the original storage medium or other readily viewable and identifiable output formats—such as dual‑recording videos, signing‑trail records, or data stored in internal databases—to further substantiate their authenticity.


 

Three

Determination of Legal Effect in Cases of Reuse of Electronic Signatures

In electronic contracts, determining the validity of an electronic signature in cases of “one signature for multiple uses” is a common source of dispute in practice. However, it is important to distinguish between two scenarios: “a single signature reused across multiple contracts in the same transaction,” and “a single signature reused within the same contract at different locations.” In the former, a party’s signature is applied to several contracts arising from the same transaction; in the latter, the same signature is used at different points within a single contract. Under these two distinct circumstances, the focus of reviewing the provider of standardized contract terms’ duty to provide adequate notice and explanation differs. In the former scenario, to facilitate transactions, the party offering standard-form contracts often adopts a practice of having multiple documents signed at once—through methods such as check-boxes or list‑based selections—so the burden of proof lies in demonstrating whether the signatory was aware that they were signing multiple documents. By contrast, in the latter scenario, if the provider of standardized terms submits an evidentiary report documenting the electronic signer’s identity verification, receipt of the electronic contract text, and the data associated with the act of signing, then, so long as it can be shown that the contract’s content has not been tampered with, the reuse of the same signature at multiple points within the same contract—resulting in different signature values at different locations—generally does not affect the determination of the contract’s validity. As in this case, Gao’s repeated signatures on various parts of the finance lease contract were, upon review, found to be page‑by‑page endorsements on the contract itself, and thus were deemed to constitute conofficeation of the same contract. Nevertheless, judicial practice continues to require that, with respect to unusual clauses that significantly affect the parties’ substantial interests, the provider of standardized terms must demonstrate that the other party, by accepting those terms, was both informed and consented, and that the provider fulfilled its obligation to provide appropriate notice and explanation.


 

( Reposted from: Shanghai Financial Court)

Related News