Many people use “e-signature” and “digital signature” interchangeably. In Malaysia, they’re not the same. Understanding the difference matters—from tenants signing a Tenancy Agreement (TA) to lawyers finalising a Sale & Purchase Agreement (SPA).
A) e-Signature (Electronic Signature) — ECA 2006
| Feature | Description |
|---|---|
| What it is | Any electronic method showing a person’s intent to sign. |
| Examples | Typing your name, ticking “I agree”, drawing a signature, inserting a signature image. |
| Legal status | Recognised for most commercial contracts if it can identify the signer, indicate approval, and is appropriate & reliable for the purpose. |
| Security level | Lower. Easier to challenge (identity/alteration disputes) unless there’s a strong audit trail. |
B) Digital Signature (PKI) — DSA 1997
| Feature | Description |
|---|---|
| What it is | A cryptographic (PKI) signature bound to a digital certificate issued by a licensed Certification Authority (CA) in Malaysia. |
| Examples | CA-backed signing platforms with KYC / identity verification and certificate issuance. |
| Legal status | Higher assurance of identity & document integrity; strong non-repudiation within a regulated trust framework. |
| Security level | Higher. Tamper-evident, identity-bound, and significantly harder to challenge. |
Simple e-sign: If someone later claims, “that wasn’t me” or “someone clicked for me,” proving identity and integrity can be harder—especially without robust logs.
Digital signature: The certificate is tied to a verified identity (often with OTP/PIN and KYC), and the platform preserves an audit trail—making repudiation far harder.
Use Case 1 — Low-stakes commercial docs
Use Case 2 — Tenancy Agreements (TA)
Use Case 3 — High-stakes property & land dealings
| Scenario | Recommended Method |
|---|---|
| Law/registry requires a prescribed form or witnessing (e.g., SPA, transfer/charge) | Wet-ink with witness (follow Bar guidance if remote witnessing is allowed) |
| High identity assurance & non-repudiation needed (money at stake, long term, financing) | Digital Signature (PKI, licensed CA) |
| Low-risk commercial doc where speed matters | e-Sign (ensure clear audit trail & reliability) |
A simple e-signature is typically not suitable (or expressly excluded) for documents that require special formality, including for example:
The Electronic Commerce Act prevents a document from being rejected just because it’s electronic. But disputes usually turn on identity, intent, reliability, and whether formalities were required.
For valuable or long-term agreements, a DSA-compliant digital signature (licensed CA, proper ID checks, strong audit trail) reduces the attack surface and makes “the e-sign isn’t valid” arguments far less persuasive. For SPA/land instruments, stick to wet-ink with witness unless the relevant authorities formally accept a compliant digital process.
Non-Legal Advice Disclaimer
This article provides general information based on Malaysian practice. Requirements vary by document type, counterparty (bank/developer), and registry. Always consult your solicitor before selecting a signing method for important transactions.