In short: Both terms are correct but describe different layers. An electronic signature is the legal act of signing electronically; a digital signature is the cryptographic technology that can secure it. Under eIDAS, advanced and qualified signatures are electronic signatures that rely on digital signature technology, which is why the labels are so often mixed up.
Ask ten people to define these terms and you will get ten answers. The confusion is understandable, because vendors and articles often swap the words freely. Getting the distinction right matters, though, because it changes how you talk about security, compliance and legal validity — and which questions you should ask before trusting a signed file. Here is the clearest way to separate the two.
An electronic signature is a broad legal concept. eIDAS defines it as data in electronic form attached to or logically associated with other data and used by the signatory to sign. That definition is deliberately technology-neutral: a typed name, a checkbox, a drawn squiggle or a cryptographically protected signature can all qualify as an electronic signature.
Because the term is so wide, the law layers assurance levels on top of it. The value of any given signature depends on how well it identifies the signer and protects the document, not on the label itself. That is why 'electronic signature' answers the question 'is this legally a signature?' rather than 'how secure is it?'
A digital signature is a specific technical mechanism, not a legal category. It uses public-key cryptography: the signer holds a private key, and a matching public key lets anyone verify the result. The software calculates a hash of the document, encrypts that hash with the private key, and binds it to the file.
If a single character in the document changes afterwards, the hash no longer matches and verification fails, which is how tampering is detected. A trusted certificate ties the key pair to a verified identity, so a verifier can see who signed. This is the engine behind stronger e-signatures — but a digital signature on its own is a tool, not a statement of legal effect.
The e-signature difference becomes obvious when you place the two side by side:
In short, the two words answer different questions: one asks whether a valid signature exists, and the other asks how that signature is technically secured. Knowing which is which stops you from over-trusting a plain typed name, or under-valuing a properly protected file.
A simple electronic signature may not use any digital signature technology at all. An advanced electronic signature (AES) almost always does, because it must be uniquely linked to the signatory and detect any later change — requirements that public-key cryptography is designed to meet.
A qualified electronic signature (QES) is an advanced signature built on a qualified certificate and a qualified device, giving it legal effect equivalent to a handwritten signature. So the strongest electronic signature is powered by a digital signature, which is exactly why the two ideas are so easy to confuse in everyday conversation.
primesign turns the digital signature vs electronic signature theory into practice: its platform issues advanced and qualified electronic signatures that use standards-based cryptographic signing, so you get both legal recognition and technical integrity in a single step - no need to choose between the two.
Want the legal weight of an electronic signature and the security of a digital one together?