An electronic signature is legally valid in the UAE. Article 10(2) of Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services states that a contract does not lose its validity, evidential weight or enforceability merely because it is made in the form of one or more electronic documents. The law has been in force since 2 January 2022.
What most guidance gets wrong is the tiering. The decree-law recognizes three different grades of electronic signature, and only the top grade, the qualified electronic signature, is expressly equal in authenticity to a handwritten signature under Article 18(3). Everything below that is valid but proves less. This guide sets out the three tiers, what makes each one work, the widely repeated list of documents you supposedly cannot sign electronically and why that list comes from a repealed law, who bears the risk when a signature turns out to be bad, and the penalties for forging one.
The Starting Point: Electronic Form Changes Nothing
Article 5(1) provides that an electronic document does not lose its legal force or enforceability for being in electronic form. Article 10(1) allows offer and acceptance to be expressed electronically. Article 18(1) prevents a court from refusing an electronic document, signature, seal or transaction as evidence merely because it is in electronic form.
Three further articles convert traditional formalities into their digital equivalents, and they are the ones to cite when someone insists on paper:
- Writing (Article 7). Where any UAE legislation requires information, a statement, a document, a record, a transaction or evidence to be in writing, that requirement is met by an electronic document if the information is stored in a way that allows it to be used and referenced.
- Signature or seal (Article 8). Where legislation requires a signature or seal, the requirement is met by using a means of identifying a person and indicating that person’s intention regarding the information in the document, provided the means is either qualified for the purpose the document was created for, or meets that identification-and-intention test alone or with other evidence.
- Original document (Article 9). Where legislation requires an original, an electronic document satisfies it if there is technical evidence confirming the integrity of the information since it was first created in final form, and the document can present the information whenever requested.
Article 8(2) then states the general permission in one line: any person may use any form of electronic authentication unless the law provides otherwise.
Nobody can be forced to go electronic
Article 5(3) provides that nothing in the decree-law requires a person to use an electronic document without their consent, and Article 28(1) repeats it for electronic dealing generally. Both add the practical qualifier that consent may be inferred from any conduct indicating it. Signing back through the platform, or performing the contract, is conduct indicating consent. Nobody has to accept an electronic process, but nobody who has visibly used one can later claim they never agreed to it.
The Three Tiers of Electronic Signature
The decree-law creates an ordinary electronic signature, a reliable electronic signature and a qualified electronic signature. They are not interchangeable. The higher the tier, the less you have to prove if the signature is ever challenged.
| Tier | What it requires | Evidential effect |
|---|---|---|
| Electronic signature | A means of identifying the person and indicating their intention regarding the information in the document (Article 8) | Admissible; cannot be rejected for being electronic. Its weight depends on the surrounding evidence. |
| Reliable electronic signature or seal | Article 19: linked to and under the full and exclusive control of the signatory; capable of identifying them; linked to the signed data so that any alteration can be detected; created using technical and security techniques meeting the Executive Regulations | Valid and legally effective where the conditions are met (Article 18(7)) |
| Qualified electronic signature or seal | Article 20: created on a valid qualified authentication certificate, using a qualified signature device, with validation data identical to what the relying party is given, from a licensed qualified trust service provider | Article 18(3): equal in authenticity to a manual signature, with the same legal effect |
The practical translation is straightforward. A typed name at the bottom of an email is an electronic signature and is admissible, but if the other side denies signing, you are back to proving it with everything else you have. A qualified electronic signature carries the statutory equivalence, so the argument starts from a much stronger position.
Article 18 adds three more evidential rules worth knowing. A hard copy of an official electronic document is conclusive evidence to the extent that it is identical to the original (Article 18(2)). A qualified electronic seal of a legal person is evidence of the validity and integrity of the original information it is linked to (Article 18(4)). And a qualified electronic time stamp verifies the date and time whenever it is linked to correct data (Article 18(5)), which is what makes an electronically signed document defensible on the question of when as well as whether.
Who is allowed to issue these signatures
Article 15 makes trust services a licensed activity: no person may provide trust services without a licence from the Telecommunications and Digital Government Regulatory Authority, and no person may provide qualified trust services without both a licence and qualified status. Article 27 requires the TDRA to prepare, publish and update a UAE Trust List of licensees, trust services and qualified trust services, and Article 26 provides for a qualified trust mark.
That list is the check to run before relying on a provider’s claim to deliver a qualified signature. Article 16 adds that where the service is directed at the government sector, or depends on the data or services of the Federal Authority for Identity and Citizenship, that authority sets the controls, standards and requirements, and the TDRA verifies compliance and can suspend or cancel the licence for breach.
UAE PASS and Digital Identity
Article 28(4) is the provision that makes the national digital identity so useful: using a digital identity issued through the approved electronic identification system to access government electronic services is considered to meet the requirements for identification and personal presence, where it provides the required level of trust and security.
“Personal presence” is the significant phrase. A requirement that someone attend in person can be satisfied digitally where the identity system carries the right assurance level. Article 28(3) makes the digital identity the adopted means of accessing government electronic services, and Article 28(5) requires government authorities to accept electronic signatures, seals, digital identities and electronic documents used in services provided by other government authorities, in the form and at the trust levels the TDRA determines. That is the legal basis for the interoperability behind the UAE PASS digital identity across government apps.
Article 28(6) then lets government authorities accept electronic filing and storage, issue documents, permits, licences, decisions and approvals as electronic records, collect fees electronically, and run government procurement tendering and awards electronically, all with the same legal effect. Article 28(8) requires them to archive documents bearing a reliable or qualified signature or seal in line with the Executive Regulations.
The Exclusion List Everyone Repeats Is From a Repealed Law
Almost every guide to UAE e-signatures states that wills, marriage and divorce contracts, negotiable instruments, court documents and property title deeds cannot be signed electronically. That list came from Federal Law No. 1 of 2006 on Electronic Commerce and Transactions, and Article 53(1) of the 2021 decree-law repealed that law outright.
Federal Decree-Law No. 46 of 2021 contains no equivalent list. What it does instead is Article 2(2): the Cabinet may add, delete or exclude any transaction, document, service or procedure from the law’s scope, and may exclude any entity from all or some of its provisions. Exclusions are therefore a matter for Cabinet decision rather than a fixed statutory list, and the Executive Regulations issued under Article 52 govern much of the detail.
Be careful what you take from that, in both directions. It does not mean you can now e-sign a will or a property transfer. Those transactions are governed by their own legislation, which sets its own formalities: registration in the Property Register, notarization, attestation, or personal attendance before a registrar. Article 8 converts a general “must be signed” requirement into its electronic equivalent; it does not override a specific statute that demands a particular procedure before a particular official. The honest position is that the blanket exclusion list is out of date as a citation, and the correct question for any given document is what its own governing law requires. For anything touching property, wills or personal status, check the specific requirement, and for anything requiring notarization the route runs through the notary public and its own e-notary channel.
We flag this as a limitation rather than an answer: the Executive Regulations of the decree-law were not retrievable from any official source at the time of writing, and they are where any current list of excluded transactions would sit.
Contracts Made by Machines
Article 11 handles automated contracting, and it is unusually clear for a provision of this age. A contract may be made between automated electronic mediums comprising one or more electronic information systems prepared and programmed in advance, and such a contract is valid, enforceable and legally effective even in the absence of personal or direct interference by any natural person in the making of it.
Article 11(2) extends this to a contract made between one party’s automated system and another person, provided that person knows, or is supposed to know, that the system will make or execute the contract automatically. For anyone running an online business in the UAE, that is the provision that makes automated checkout, dynamic pricing and API-driven ordering enforceable without a human in the loop.
Attribution: When a Document Counts as Yours
Article 12 decides when an electronic document is treated as having come from you. It is issued by you if you sent it yourself, if it was sent by someone with authority to act on your behalf, or if it was sent by an automated medium programmed to operate by or for you.
Article 12(3) then lets the recipient treat a document as yours in two further situations: where the recipient correctly applies a procedure you previously approved for verifying that documents come from you, or where the document resulted from the actions of a person who, through their relationship with you or your agent, could access a method you use to prove documents are yours. That second limb is what catches employers whose staff share credentials.
Three defences sit in Article 12(4). The attribution rule does not apply where the recipient has received notice from you that the document was not yours and has had reasonable time to act on it; where the recipient knew or should have known it was not yours; or where it is unreasonable for the recipient to have treated it as yours. Article 12(7) further disapplies the rule where the recipient knew or should have known that an error occurred through a technical failure during transmission. The practical lesson is that notice matters and speed matters: the moment credentials are compromised, notifying counterparties in writing is what starts the protection.
Who Carries the Risk When a Signature Is Bad
The decree-law allocates responsibility across three parties, and it is not the neutral split most people assume.
The relying party. Article 29 is demanding. A relying party is responsible for the consequences of failing to take necessary measures to confirm the validity and enforceability of an authentication certificate or a digital identity and to observe any restrictions on it. Article 29(3) requires it to determine the security level appropriate to the nature, value or importance of the transaction, verify the signatory’s identity and the certificate’s validity, check the signature meets the requirements, consider whether it knew or should have known of a breach or cancellation, and weigh any prior dealings. Article 29(4) is the sting: if reliance was not acceptable under those tests, the relying party bears the risk of invalidity and is responsible for damage caused to the signature’s owner or to third parties. Accepting a low-assurance signature on a high-value contract is a risk you have taken, not one you can pass back.
The signatory. Article 30 makes the signatory responsible for failing to exercise due diligence against unauthorized use of signature creation data, to notify the licensee when there is doubt about the security or validity of that data, to keep material certificate data accurate throughout its validity, to report changes or a loss of confidentiality, and to use valid certificates. Article 31 imposes a parallel set of duties on the owner of a digital identity.
The provider. Article 38 makes trust service providers civilly liable for damages incurred by any person as a result of breaching the decree-law, the Executive Regulations or TDRA decisions.
Penalties for Forging an Electronic Signature
Article 39 punishes forgery, or participation in the forgery, of an electronic document, signature, seal, authentication certificate or trust service with imprisonment and/or a fine of AED 100,000 to AED 300,000. Where the forged item belongs to federal or local government or a public authority or institution, the penalty rises to temporary imprisonment and a fine of AED 150,000 to AED 750,000. Knowingly using a forged electronic document attracts the same penalty as the forgery itself.
Article 40 separately punishes unlawfully exploiting any trust service or qualified trust service, and using fraudulent methods or a false name or capacity to obtain a qualified trust service, with imprisonment up to one year and/or a fine of AED 100,000 to AED 1,000,000. Where those acts are carried out with the intention of committing a crime, that is an aggravating circumstance.
Administrative penalties sit outside the decree-law. Article 48 leaves the acts that constitute violations, and the administrative penalties for them, to a Cabinet decision, so no administrative fine figure appears in the statute itself. Article 49 gives designated TDRA employees law enforcement capacity to detect violations.
Practical Rules for UAE Businesses
- Match the tier to the transaction. Article 29(3) effectively requires it. Low-value, high-volume paperwork can run on ordinary electronic signatures. A shareholder agreement, a guarantee or a settlement deserves a qualified electronic signature from a provider on the UAE Trust List.
- Check the counterparty’s authority separately. The decree-law authenticates the signature, not the signatory’s power to bind their company. That is a companies law and power of attorney question, and it is where electronically executed contracts most often fail.
- Keep the audit trail, not just the signed PDF. Article 6 sets storage requirements: keep the document in the form created, sent or received or in a form that accurately represents it; keep it usable and referenceable; and keep the information identifying the originator, the destination, and the date and time of sending and receiving. A signed file with no accompanying certificate and timestamp evidence is a weaker document than it looks.
- Do not assume a foreign e-signature is automatically recognized. Article 37 addresses international trust services, and cross-border recognition depends on the conditions set under the decree-law and its Executive Regulations rather than being automatic.
- Watch the sector rules. Article 4(6) requires the TDRA to coordinate with the Central Bank on inspecting financial institutions it licenses, and Article 28(7) lets government authorities specify their own required signature form and security level. A regulator can demand more than the general law does.
Contracts executed this way still sit inside the ordinary rules on formation and dispute resolution. If the agreement contains an arbitration clause, note that the UAE arbitration law expressly accepts an agreement concluded by email as satisfying its writing requirement, which pairs neatly with Article 7 here.
Frequently Asked Questions
Are electronic signatures legally binding in the UAE?
Yes. Article 10(2) of Federal Decree-Law No. 46 of 2021 states that a contract does not lose its validity, evidential weight or enforceability merely because it is made in the form of electronic documents, and Article 18(1) prevents a court from rejecting an electronic document, signature or seal as evidence merely because it is electronic. Article 8 converts a statutory requirement for a signature into its electronic equivalent where the means identifies the person and indicates their intention.
Is a DocuSign-style signature the same as a qualified electronic signature in the UAE?
Not necessarily. The decree-law recognizes three tiers. An ordinary electronic signature is valid and admissible. A reliable electronic signature must meet Article 19’s conditions, including exclusive control by the signatory and detectability of any alteration. Only a qualified electronic signature under Article 20, created on a qualified certificate with a qualified device from a licensed qualified trust service provider, is treated by Article 18(3) as equal in authenticity to a manual signature. Check the provider against the UAE Trust List the TDRA maintains under Article 27.
Can I sign a will or a property transfer electronically in the UAE?
Treat that as governed by the specific law for the document, not by the e-transactions law. The widely repeated list of excluded documents comes from Federal Law No. 1 of 2006, which Article 53(1) of the 2021 decree-law repealed. The new decree-law contains no equivalent list and instead lets the Cabinet exclude transactions under Article 2(2). But wills, property transfers and personal status matters have their own formalities, including registration and notarization, and Article 8 does not override a statute that requires a particular procedure before a particular official.
Does a typed name at the bottom of an email count as a signature in the UAE?
It can qualify as an electronic signature under Article 8 if it functions as a means of identifying the person and indicating their intention regarding the information in the document. It is admissible and cannot be rejected for being electronic. What it does not carry is the statutory equivalence to a handwritten signature that Article 18(3) gives a qualified electronic signature, so if the other side denies signing, the weight of that evidence depends on everything else surrounding it.
Can someone refuse to accept an electronic document in the UAE?
Yes. Article 5(3) provides that nothing in the decree-law requires a person to use an electronic document without their consent, and Article 28(1) says the same for electronic dealing generally. Both add that consent may be inferred from any conduct indicating it, so a party who has been using the electronic process cannot credibly claim afterwards that it never agreed to it.
Does UAE PASS count as a legal signature?
For government services it goes further than that. Article 28(4) provides that using a digital identity issued through the approved electronic identification system to access government electronic services is considered to meet the requirements for identification and personal presence, where the identity provides the required level of trust and security. Article 28(5) requires government authorities to accept electronic signatures, seals, digital identities and documents used in other government authorities’ services at the form and trust levels the TDRA determines.
Who is liable if an electronic signature turns out to be forged or invalid?
It depends on who failed. Article 29 makes the relying party responsible for the consequences of not verifying the certificate or digital identity and not matching the security level to the nature, value or importance of the transaction, and Article 29(4) makes it bear the risk of invalidity and any damage caused where reliance was not acceptable. Article 30 makes the signatory responsible for failing to guard the signature creation data, notify doubts, keep certificate data accurate and use valid certificates. Article 38 makes trust service providers civilly liable for breaches of the law.
What is the penalty for forging an electronic signature in the UAE?
Article 39 sets imprisonment and/or a fine of AED 100,000 to AED 300,000 for forging or participating in the forgery of an electronic document, signature, seal, authentication certificate or trust service. Where the item belongs to federal or local government or a public authority or institution, it is temporary imprisonment and a fine of AED 150,000 to AED 750,000. Knowingly using a forged electronic document carries the same penalty as the forgery.
Are contracts made automatically by software valid in the UAE?
Yes. Article 11(1) provides that a contract may be made between automated electronic mediums comprising pre-programmed electronic information systems, and is valid, enforceable and legally effective even without personal or direct interference by any natural person. Article 11(2) extends this to contracts between one party’s automated system and another person who knows, or is supposed to know, that the system will make or execute the contract automatically.
How long do I have to keep electronically signed documents?
The decree-law sets the manner rather than a universal period: Article 6 requires the document to be stored in the form created, sent or received or in a form accurately representing it, kept usable and referenceable, and kept together with the information identifying the originator, the destination and the date and time of sending and receiving. Retention periods themselves come from whichever law requires the record, such as tax, corporate or anti-money-laundering rules, and Article 6(4) lets government authorities add their own requirements.
Official Sources
- The Official Platform of the UAE Government – Electronic Transactions and Trust Services Law
- UAE Legislation – Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services, full text
- UAE Legislation – Cabinet Resolution on the Executive Regulations of the Electronic Transactions and Trust Services Decree-Law
- Telecommunications and Digital Government Regulatory Authority – Trust services laws and regulations
Information is current as of August 2026. Every article number, tier, responsibility rule and penalty above was read from the official English text of Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services, which entered into force on 2 January 2022 and repealed Federal Law No. 1 of 2006. Four limitations are stated rather than smoothed over. The Executive Regulations issued under Article 52 govern a great deal of the operative detail, including the technical requirements for reliable and qualified signatures, licensing conditions and any current list of excluded transactions, and their text was not retrievable from any official source at the time of writing, so this guide reports what the decree-law itself says and marks the gaps. Because of that, no list of documents that cannot be signed electronically is asserted here; the commonly circulated list derives from the repealed 2006 law, and the correct question for any specific document is what its own governing legislation requires. Article 48 leaves administrative violations and penalties to a Cabinet decision, so no administrative fine figure is quoted. And Article 51 leaves fees to a Cabinet decision, so no trust service or licensing fee is quoted. The Arabic text of UAE legislation prevails in case of any conflict with an English translation. This is general information, not legal advice.