Electronic Evidence in India: A Cyber Lawyer's Perspective on Case Laws under IEA and BSA in 2026
Updated July 2026 - incorporating the Supreme Court's landmark ruling in Pune Bar Association v. Union of India (2026).
The digital realm has permeated every facet of modern life, leaving an indelible mark on the legal landscape. Electronic evidence - emails, messages, social media posts, CCTV footage and digital documents - has become a cornerstone of legal proceedings. India's legal system, recognising this paradigm shift, has evolved from the Indian Evidence Act, 1872 (IEA) to the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which came into force on 1 July 2024.
This post traces the evolution of electronic-evidence jurisprudence in India through its landmark case law, and then brings the story fully up to date - through the BSA's Section 63 certificate regime, the Supreme Court's 2026 constitutional verdict on the hash value, the deepfake frontier, chain-of-custody discipline, and the new data-protection overlay.
The Genesis: Electronic Evidence under the IEA
The IEA, designed for a pre-digital era, received its first major digital amendment in 2000 with the introduction of Section 65B. That provision addressed the admissibility of electronic records, acknowledging their growing significance. But the absence of a prescribed format for the Section 65B certificate bred inconsistency and years of judicial back-and-forth.
Landmark case law under the IEA:
State (NCT of Delhi) v. Navjot Sandhu @ Afsan Guru, (2005) 11 SCC 600 (Parliament Attack Case): Arising from the 2001 attack on Parliament, the Supreme Court admitted call detail records (CDRs) without strict adherence to Sections 65A and 65B. This liberal approach was later overruled in Anvar, which reasserted the mandatory nature of the certificate.
Manu Sharma v. State (NCT of Delhi), (2010) 6 SCC 1 (Jessica Lal Murder Case): The Court recognised the evidentiary value of electronic records, including phone records, and showed how digital evidence can both corroborate and contradict traditional testimony.
Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473: The watershed. A three-Judge Bench held the certificate under Section 65B(4) to be a mandatory pre-condition for the admissibility of electronic records as secondary evidence, stressing the need to establish authenticity and integrity given how easily digital data is manipulated.
Tomaso Bruno v. State of U.P., (2015) 7 SCC 178: Briefly muddied the waters by suggesting a more relaxed approach - later held to be per incuriam and overruled.
Shafhi Mohammad v. State of H.P., (2018) 2 SCC 801: A two-Judge Bench suggested the certificate requirement could be relaxed where the party tendering the evidence did not possess the device. Well-intentioned, but doctrinally unsound - and duly overruled.
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1: Overruling Tomaso Bruno and Shafhi Mohammad, the Supreme Court reaffirmed that the Section 65B(4) certificate is mandatory, and that difficulty in obtaining it is no excuse for dispensing with it - the remedy being to compel its production, not to bypass it. The Court also clarified that no certificate is needed where the original device is itself produced and its owner testifies to ownership.
Embracing the Digital Age: The Bharatiya Sakshya Adhiniyam, 2023
The BSA repealed the IEA and re-engineered the law of electronic evidence for the digital age. The key advances:
Electronic records placed on par with documents (Section 61): The BSA makes clear that a record cannot be denied admissibility merely because it is electronic; digital records are to be treated on the same footing as paper.
Special provisions and expanded secondary evidence (Sections 57–58, 62): The scope of secondary evidence is widened to include copies produced by mechanical processes, counterparts, and oral accounts of contents - with matching hash values recognised as proof of a secondary electronic record.
A standardised certificate (Section 63, with the Schedule): Section 63 is the operative admissibility provision - the lineal successor of the old Section 65B. Its genuine reform lies in the Schedule, which prescribes a standard-form certificate in two parts: Part A completed by the party/custodian, and Part B completed by an expert. Where Anvar and Arjun Panditrao left the contents of the certificate to improvisation, the BSA ends the guesswork.
Hash value as a statutory requirement: Part A now requires disclosure of the hash value of the record together with the algorithm used - the feature that most sharply distinguishes the BSA regime from its predecessor.
The 2026 Watershed: Pune Bar Association v. Union of India and the Constitutional Blessing of the Hash Value
For a while, the profession quietly hoped that Section 63 would go the way of a New Year's resolution - solemnly enacted, cheerfully ignored. That hope died on 22 May 2026.
In Pune Bar Association v. Union of India & Ors., Writ Petition (Civil) No. 599 of 2026 (decided 22-05-2026), a three-Judge Bench - Surya Kant, CJI, Joymalya Bagchi and Vipul M. Pancholi, JJ. - rejected a frontal constitutional challenge to Section 63(4) BSA read with the Schedule. The petitioner argued that requiring an ordinary litigant to (a) disclose the hash value in Part A, and (b) obtain an expert's signature in Part B, was so onerous as to be manifestly arbitrary under Article 14. The Court was unmoved:
"Hash value of an electronic data is synonymous with an electronic fingerprint and provides a sure way of identifying and verifying digital data. The necessity of incorporating the hash value of the electronic record in the certificate is thus to ensure its authenticity and integrity, and cannot be said to lack a rational nexus with the object of the Act. Similarly, certification by an expert in Part B provides an additional layer of authenticity to the secondary electronic evidence." - Pune Bar Association, para 4
Three practitioner takeaways flow from this:
The hash value is now constitutionally entrenched, not a technicality. The "electronic fingerprint" metaphor dictates strategy. A single altered byte flips the SHA-256 digest entirely (the avalanche effect) - which is precisely why the Court treats it as a guarantor of integrity. Offer the record, offer the hash, and the tribunal can verify tamper-status in seconds.
"Hardship" will not defeat admissibility. This is Arjun Panditrao logic carried into the BSA era: procedural difficulty is no passport around procedure. If the door is locked, find the key; do not climb through the window.
The Court expressly linked the certificate to the deepfake threat. Para 3 records that "challenges to admissibility and probative value of electronic records are further accentuated with the advent of artificial intelligence and deepfake technology." The certificate, in other words, is the statute's antibody against synthetic evidence.
Deconstructing the Section 63 Certificate: Part A, Part B, and the Hash Value
Part A - the party/custodian's declaration. Completed by the person lawfully in charge of the device or computer resource. It captures the identification of the record, how it was produced, the details and operating condition of the device, and — the headline addition — the hash value with the algorithm used (SHA-1, SHA-256 or SHA-512). Practitioners should default to SHA-256, now the courtroom lingua franca.
Part B - the expert's declaration. An independent, second authentication by a person with technical expertise.
A worked example. Your client, a small exporter, receives a forged payment-diversion email — a classic Business Email Compromise. To prove it:
Export the email in its native .eml/.msg form (never a screenshot), preserving headers.
Compute SHA-256 over that file and record it in Part A, with the mail client, device and export method.
A cyber-forensics expert independently re-computes the hash, confirms the match, examines the header chain and originating IP, and signs Part B.
The certificate travels with the record. If the defence later produces a "cleaned-up" version, the mismatched hash exposes the tampering instantly.
Contrast the failure mode: a WhatsApp screenshot pasted into a Word file - no export, no hash, no metadata. In 2026 that is not weak evidence; it is, increasingly, no evidence.
Who Is the "Expert"? The BSA's Biggest Gap - Now Answered
The BSA's silence on the meaning of "expert" in Part B was, for two years, its most litigable weakness. Two developments filled it - in opposite directions - before the Supreme Court settled the matter.
The Madras High Court's restrictive view. In R. v. B & Anr, 2024 SCC OnLine Mad 6084, the High Court read Part B narrowly: the expert must be an Examiner of Electronic Evidence notified under Section 79A of the Information Technology Act, 2000. The difficulty is arithmetic — barely a handful of laboratories are so notified. If every WhatsApp chat in every cheque-bounce and matrimonial matter had to queue behind that bottleneck, the right to lead electronic evidence would become, in the petitioner's word, illusory.
The Supreme Court's harmonious correction. In Pune Bar Association (paras 6–7), the Court read Section 39 BSA as a whole. Sub-section (2) deems the opinion of a Section 79A Examiner to be expert opinion - but, crucially, it is not prefaced by a non-obstante clause and therefore does not oust sub-section (1), under which the opinion of any person with special skill in a relevant field (expressly including science) is a relevant fact:
"…if the Court is satisfied, on the basis of unimpeachable material, that any other person has special skill and expertise in computer science and cyber forensics, opinion of such person may be held relevant as an expert with regard to electronic/digital record and such person may sign Part B of the Schedule as an expert." - Pune Bar Association, para 7
The Court declined to treat the Madras High Court's contrary view as binding precedent, while formally keeping the larger question of law open. Position as of July 2026: a Section 79A-notified Examiner remains the gold standard, but a suitably qualified private cyber-forensics expert can sign Part B provided the court is satisfied of genuine, demonstrable expertise. Build that satisfaction into your record - CV, certifications (CCFP from NELIT, CHFI, GCFA, EnCE), tools used, and methodology - because the persuasive burden now sits with the party tendering the expert.
The High Courts in 2025–26: Screenshots Die, Metadata Reigns
Below the Supreme Court, a consistent doctrine is hardening:
Screenshots alone are routinely rejected. The Delhi High Court has emphasised that a bare screenshot, without a certificate carrying metadata and hash verification, is inadmissible. The evidentiary unit of account is now the native exported file plus its hash, not a picture of the screen.
The "own device" concession. The Andhra Pradesh High Court (May 2026) has taken the pragmatic view that where a party tenders messages from their own device, a self-certificate under Part A generally suffices - consistent with the Arjun Panditrao proviso.
Metadata is expected as standard. High Court practice in 2026 expects the full metadata envelope for every chat - timestamps, sender/recipient identifiers, and export provenance - not merely the message text.
The through-line: courts have shifted the inquiry from "can I read the message?" to "can I trust the container?" This is applied epistemology - evidence law as the "institutionalised regulation of the process of proof" (Ho Hock Lai, A Philosophy of Evidence Law, OUP 2008) - and in the digital age, the container is where trust lives or dies.
The New Frontier: Deepfakes and AI-Generated Evidence
Heraclitus warned that one cannot step twice into the same river; the modern evidentiary anxiety is subtler still - we can no longer be sure the river was ever there. A photorealistic video of an event that never happened is now producible on a consumer laptop.
The doctrinal starting point is reassuringly orthodox. Indian courts treat a deepfake as an electronic record like any other: not automatically inadmissible, but subject to the same Section 63 gate - certificate, hash, and chain of custody. The technology raises the stakes of authentication; it does not rewrite the rules.
The real battle is the burden of proof. Fabricating a deepfake is cheap; disproving one is expensive. Emerging Indian scholarship (e.g., Deepfake Evidence and the Indian Criminal Justice System, IJFMR 2025; AI-Generated Evidence in Indian Courts: Admissibility, Reliability and the Chain-of-Custody Challenge, IJIRL 2025) converges on three defensive pillars:
Provenance over appearance. Argue about where the file came from, not what it looks like. Original-source capture, device seizure, hash-at-source and an unbroken custody log defeat a deepfake allegation far more reliably than pixel-peeping.
Metadata and sensor forensics. C2PA content-provenance signatures, EXIF data, codec fingerprints, and physiological "tells" (blink rate, lighting inconsistency, PRNU sensor-noise mismatch) are the expert's toolkit.
Early forensic imaging. The moment authenticity is contested, image the device and preserve the hash. Delay is the deepfake's best friend.
Personality-rights litigation is the leading edge. While a settled standard for adjudicating deepfake authenticity is still developing, the civil injunctive response has matured rapidly. Through 2025–26 the Delhi and Bombay High Courts granted a wave of interim protections against unauthorised deepfakes and voice clones - for actors including NTR Jr., R. Madhavan and Shilpa Shetty (December 2025), entrepreneur Aman Gupta (Delhi HC, May 2026) and Ravi Kishan (July 2026) - anchoring the right in Article 21 and recognising that a person's image, voice and likeness are protected against AI misappropriation no less than against traditional forms. The gap that remains is the absence of dedicated legislation on AI evidence, leaving authentication standards to case-by-case judicial improvisation.
Chain of Custody: The Unglamorous Spine of the Whole Edifice
A certificate certifies a record; the chain of custody certifies the journey of that record from crime scene to courtroom. As the Supreme Court framed it in Pune Bar Association, electronic records are "a unique species of evidence which is liable to continuous mutation and modification affecting [their] authenticity, integrity and intrinsic evidentiary value" (para 3). Mutability is the enemy; documented custody is the answer.
A defensible 2026 protocol:
Identify and isolate - airplane mode / a Faraday bag before anything else; a single background sync can alter the record and break the hash.
Image, don't operate - take a forensic bit-stream image and work only on the copy. Never investigate on the original.
Hash at seizure - compute and record the SHA-256 of the source image at the moment of acquisition. This is the anchor for Part A.
Log every hand-off - who held it, when, why, and the hash checked at each transfer. A gap in the log is a gap the defence will drive a truck through.
Re-verify before tendering - recompute the hash immediately before filing and confirm it matches the seizure hash.
A pristine Part A over a contaminated chain is a signature on a lie.
The DPDP Overlay: Gathering Evidence Without Committing a Data Breach
New in 2026, and easy to miss: the Digital Personal Data Protection Rules, 2025 were notified by MeitY on 14 November 2025, operationalising the Digital Personal Data Protection Act, 2023. This changes the legality of collection, not the admissibility test - but a practitioner who ignores it can win the evidence and lose the client.
Collection discipline. Corporate internal investigations that harvest employee communications, CCTV, or device data now sit inside a consent-and-purpose-limitation regime. A documented chain of custody doubles as a DPDP defence: it demonstrates lawful, purpose-bound handling.
Litigation exemptions are real but narrow. The Act preserves processing necessary for legal claims and for compliance with court orders, but "I needed it for a case" is not a blanket licence. Prefer court-ordered production (Section 94 BSA / summons) over self-help data-grabs; the former both cleanses the collection and strengthens the custody narrative.
The philosophical tension is genuine: evidence law wants maximum truth-access (Bentham's anti-exclusionary instinct in the Rationale of Judicial Evidence), while data-protection law insists on minimum necessary intrusion. The mature practitioner in 2026 holds both - gathering only what the case needs, lawfully, and proving that it did.
Cross-Border and Cloud Evidence
The global nature of digital data continues to strain domestic procedure. Records now sit in servers across jurisdictions; the collection, admissibility and enforcement of such evidence turn on Mutual Legal Assistance Treaties (MLATs), letters rogatory, and the cooperation of intermediaries. The Section 63 certificate travels with the record regardless of where the server sits - but obtaining the record lawfully across borders remains one of the least-solved problems in the field, and one to watch as international frameworks evolve.
Conclusion: From Admissibility to Authenticity
The story of Indian electronic-evidence law is a slow migration of the central question. Under the IEA it was admissibility - may the record come in? (Anvar, Arjun Panditrao.) Under the BSA, and confirmed by Pune Bar Association in 2026, the question has become authenticity - should we believe it, and how do we know? The hash value, the two-part certificate, the qualified expert, and the unbroken chain of custody are the four load-bearing answers.
For the profession the message is bracing but fair. The romantic era of the persuasive screenshot is over. The new craft is quieter and more disciplined: preserve at source, hash early, certify properly, document the journey, and be ready to prove - against an adversary who may now manufacture reality - that your record is exactly what it claims to be.
As a cyber lawyer I read all this not as bureaucratic burden but as the law finally growing a spine of proportionate rigour equal to the technology it must judge. India's legal system has shown, once again, a proactive willingness to embrace technology while insisting on integrity. Justice in the digital age will belong to the meticulous.
Selected authorities and further reading
Case law
Pune Bar Association v. Union of India & Ors., Writ Petition (Civil) No. 599 of 2026, decided 22-05-2026 (SC).
R. v. B & Anr, 2024 SCC OnLine Mad 6084 (Madras HC) — held non-binding by the Supreme Court.
Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473.
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.
Shafhi Mohammad v. State of H.P., (2018) 2 SCC 801 (overruled).
Tomaso Bruno v. State of U.P., (2015) 7 SCC 178 (overruled).
State (NCT of Delhi) v. Navjot Sandhu, (2005) 11 SCC 600 (overruled by Anvar).
Manu Sharma v. State (NCT of Delhi), (2010) 6 SCC 1.
Sonu v. State of Haryana, (2017) 8 SCC 570 — timing of objection to the mode of proof.
Scholarship / references
Prashant Mali, Electronic Evidence Understanding through Case Laws Rostrum’s Law Review | ISSN: 2321-3787 Issue - RLR (2021) Volume VI Issue I
Ho Hock Lai, A Philosophy of Evidence Law: Justice in the Search for Truth (OUP 2008).
Stephen Mason & Daniel Seng (eds.), Electronic Evidence and Electronic Signatures (5th edn, IALS/Univ. of London, 2021).
William Twining, Rethinking Evidence (2nd edn, CUP 2006).
Jeremy Bentham, Rationale of Judicial Evidence (1827).
IJFMR, Deepfake Evidence and the Indian Criminal Justice System (2025); IJIRL, AI-Generated Evidence in Indian Courts (2025).
Authors other important Blogs and AI Book :
Cybersecurity Laws and Regulations in India - July 2026
AI Book Free Download : Seven AI Laws : The Future of Mankind
— Adv. (Dr.) Prashant Mali