Article · Practice

E-signatures for lawyers in Spain: what actually holds

A practical matrix by destination: court, notary, registry and foreign clients. What needs a qualified signature — and who pays to prove it if challenged.

8 min read
A person signing a paper document on a dark desk.

The question that reaches the firm is usually the wrong one: “is a DocuSign signature valid?” It is, almost always, for almost everything. Article 25.1 of the eIDAS Regulation says an electronic signature cannot be denied legal effect or admissibility as evidence solely because it is electronic — and that covers a squiggle drawn with a finger on a tablet.

The useful question is different: when the other side challenges that signature three years from now, who has to prove what, and who pays for the proof?

There the differences are large, and since Ley 6/2020 they are procedural rather than theoretical.

What changed in 2020 and almost nobody applies

Ley 6/2020 amended article 326 of the Spanish Civil Procedure Act and added a fourth paragraph that allocates the burden of proof very precisely.

If the document was signed using a qualified trust service — a provider listed on the European trusted list — the document is presumed to have the contested characteristic, and the service is presumed to have been correctly provided. If it is challenged anyway, the challenger pays for the verification. If the verification comes back negative, costs and expenses fall on them, and the court may impose a fine of €300 to €1,200 where it finds the challenge reckless.

If the service was not qualified, paragraph 3 applies: general rules, and the weight of establishing authenticity falls in practice on whoever produced the document. Expert examination, provider reports, timestamps, access logs. All of that exists and works; it simply costs you money, takes months, and opens a front that never needed to exist.

That is the whole difference, and it is enough to reorder how a firm decides. The mistake is not signing electronically too often — it is signing everything the same way. The same platform, the same level and the same flow for the engagement letter, for an NDA and for a €124,000 deposit contract. Those three documents carry radically different challenge risk and deserve different decisions.

The three levels, in two sentences each

Simple (SES). Any electronic data used to sign: a click on “I accept”, an image of a signature, an email confirming agreement. Valid, admissible, and with the entire evidentiary burden on your side.

Advanced (AES). Uniquely linked to the signatory, capable of identifying them, created using means under their sole control, and detecting any later alteration. This is what most commercial platforms produce when used with identity verification. Good traceability, without the 326.4 presumption.

Qualified (QES). An advanced signature with a qualified certificate and a qualified signature creation device. Article 25.2 of eIDAS gives it the same legal effect as a handwritten signature, and it is what triggers 326.4. It requires the provider to be on the trusted list — worth checking, because “eIDAS compliant” on a marketing page does not mean “qualified”.

One distinction that gets confused daily: the digital certificate (FNMT, the DNIe, the Spanish bar’s ACA certificate) is not a signature — it is the identity you sign with. Cl@ve is not strictly an electronic signature either: it is an identification system for dealing with public administration that, in its cloud-signature mode, allows signing. Three different things, all living in the same firm.

And it is worth knowing that electronic signatures turn up where you would not expect them: under the RD 1007/2023 invoicing regime, the “non-verifiable system” option requires every billing record to be electronically signed, while the VeriFactu option does not. That is worked through in the VeriFactu article.

The matrix that matters: by destination, not by type

The operational criterion is not “what signature level do I want” but “who is receiving this”. The recipient decides, not the firm.

To the court. No decision to make. Filings go through LexNET signed with the certificate issued by the Spanish bar’s certification authority or an equivalent. No commercial platform substitutes for that.

Litigation powers of attorney. The electronic apud acta appointment on the Sede Judicial Electrónica is free, takes minutes with a certificate or Cl@ve, and a general power lasts five years across any proceedings. Firms are still sending clients to a notary for this. That is the client’s money wasted and a week lost.

To the notary. Ley 11/2023 opened up execution by videoconference, but only for the closed list in article 17 ter of the Notarial Act: powers of representation in court and before public administration, powers for specific acts, revocations, corporate acts, receipts and cancellations of security. A property sale is not on that list, nor is a mortgage, a gift, or an estate distribution deed. If your German client wants to sign the deed from Munich, the answer is not “by videoconference” — it is a notarial power of attorney with an Apostille, executed before a German notary or at the consulate. There is more on this in the article on conveyancing for lawyers.

To the land registry and the tax office. A representative’s or the party’s own digital certificate, with electronic authorisation where the firm is acting. Not signature-platform territory.

Between the firm and its client. Engagement letters, sign-off on a draft filing, approval of a fee quote, authorisation to order a nota simple. An advanced signature with decent traceability is more than enough here, and insisting on qualified only adds friction for a client who is already hesitating.

Private contracts with a counterparty. The one band that requires real thought. An NDA can be signed like everything else. A deposit contract, an acknowledgement of debt, a shareholders’ agreement or a settlement cannot: these are precisely the documents the other side will challenge if it suits them, and they are what justifies paying for a qualified signature. The rule we apply: if the document could end up produced as evidence in litigation between the parties who signed it, use qualified.

The foreign client, which is where it hurts

In a coastal firm this is not an edge case. It is half the work.

Inside the EU and the EEA, eIDAS mandates mutual recognition. A qualified provider on the French or Estonian trusted list is qualified in Spain too, and no additional restriction can be imposed on it. A Swedish client with a national eID, or a Norwegian with bank-issued identification, can reach a qualified signature without setting foot in Spain.

Outside the EEA the symmetry disappears. A British, Swiss or US client has, by default, no European qualified signature at all. Their real options are two: obtain a qualified certificate from a European provider through video identification — workable, and usually resolved within a day — or sign on paper with notarial certification and an Apostille. The third route, simply accepting their platform signature, is perfectly legitimate and perfectly risky depending on what is being signed.

One practical detail that saves weeks: video identification for a qualified certificate requires a valid identity document and, with some providers, that the applicant already holds a NIE. Asking for it at the start of the matter, rather than the afternoon before signing, is the difference between completing on time and not completing.

What arrives before the end of 2026

Regulation (EU) 2024/1183 — eIDAS 2 — has been in force since 20 May 2024 and requires every Member State to make at least one European Digital Identity Wallet available to its citizens before the end of 2026. It is free, voluntary for the citizen, and supports qualified signatures from a phone.

For a law firm, the predictable effect is that the cost and friction of obtaining a qualified signature drop sharply, and with them the “but the client can’t” objection. Worth not rewriting your signing workflows this year on the basis of the current picture alone.

What to demand from your tools

Three questions for the vendor, all three with a documentary answer:

  1. What level does it actually produce — simple, advanced or qualified — and through which provider? If the answer is qualified, ask for the entity’s name and check it against the EU trusted list.
  2. What survives as the evidence file, and for how long? Timestamp, identification evidence, access log, document hash. If it disappears after twelve months, it is no use to you in litigation.
  3. Where are the documents hosted, and is there an article 28 processing agreement? That is the same question as in the GDPR article, and it fails just as often.

On our own tool, precision is warranted: the electronic signature built into Mandato is not an eIDAS qualified signature. It exists to speed up client approvals and internal sign-off, with traceability and filing into the matter. For anything requiring qualification, the firm needs a qualified provider. Saying otherwise would sell better and would be false.

Where to start

Take the last twenty documents your firm had signed and sort them by destination rather than by type: court, notary, registry, administration, client, counterparty. Two things will be obvious within ten minutes. First, that a handful of documents in the “counterparty” column were signed at the same level as an engagement letter. Second, that something in the “notary” column could have been handled with a free electronic apud acta.

Fix those two, and you have solved 90% of the problem without changing vendor.

Less admin. More law.

Mandato brings matters, communications, billing and compliance into one platform built for firms in Spain.

Start free 14-day trial14 days. No card.
Start free 14-day trial