Electronic Evidence in India: A Cyber Lawyer's Perspective on Case Laws under IEA and BSA in 2026

Updated July 2026 - incorporating the Supreme Court's landmark ruling in Pune Bar Association v. Union of India (2026).

The digital realm has permeated every facet of modern life, leaving an indelible mark on the legal landscape. Electronic evidence - emails, messages, social media posts, CCTV footage and digital documents - has become a cornerstone of legal proceedings. India's legal system, recognising this paradigm shift, has evolved from the Indian Evidence Act, 1872 (IEA) to the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which came into force on 1 July 2024.

This post traces the evolution of electronic-evidence jurisprudence in India through its landmark case law, and then brings the story fully up to date - through the BSA's Section 63 certificate regime, the Supreme Court's 2026 constitutional verdict on the hash value, the deepfake frontier, chain-of-custody discipline, and the new data-protection overlay.

The Genesis: Electronic Evidence under the IEA

The IEA, designed for a pre-digital era, received its first major digital amendment in 2000 with the introduction of Section 65B. That provision addressed the admissibility of electronic records, acknowledging their growing significance. But the absence of a prescribed format for the Section 65B certificate bred inconsistency and years of judicial back-and-forth.

Landmark case law under the IEA:

Embracing the Digital Age: The Bharatiya Sakshya Adhiniyam, 2023

The BSA repealed the IEA and re-engineered the law of electronic evidence for the digital age. The key advances:

The 2026 Watershed: Pune Bar Association v. Union of India and the Constitutional Blessing of the Hash Value

For a while, the profession quietly hoped that Section 63 would go the way of a New Year's resolution - solemnly enacted, cheerfully ignored. That hope died on 22 May 2026.

In Pune Bar Association v. Union of India & Ors., Writ Petition (Civil) No. 599 of 2026 (decided 22-05-2026), a three-Judge Bench - Surya Kant, CJI, Joymalya Bagchi and Vipul M. Pancholi, JJ. - rejected a frontal constitutional challenge to Section 63(4) BSA read with the Schedule. The petitioner argued that requiring an ordinary litigant to (a) disclose the hash value in Part A, and (b) obtain an expert's signature in Part B, was so onerous as to be manifestly arbitrary under Article 14. The Court was unmoved:

"Hash value of an electronic data is synonymous with an electronic fingerprint and provides a sure way of identifying and verifying digital data. The necessity of incorporating the hash value of the electronic record in the certificate is thus to ensure its authenticity and integrity, and cannot be said to lack a rational nexus with the object of the Act. Similarly, certification by an expert in Part B provides an additional layer of authenticity to the secondary electronic evidence." - Pune Bar Association, para 4

Three practitioner takeaways flow from this:

Deconstructing the Section 63 Certificate: Part A, Part B, and the Hash Value

Part A - the party/custodian's declaration. Completed by the person lawfully in charge of the device or computer resource. It captures the identification of the record, how it was produced, the details and operating condition of the device, and — the headline addition — the hash value with the algorithm used (SHA-1, SHA-256 or SHA-512). Practitioners should default to SHA-256, now the courtroom lingua franca.

Part B - the expert's declaration. An independent, second authentication by a person with technical expertise.

A worked example. Your client, a small exporter, receives a forged payment-diversion email — a classic Business Email Compromise. To prove it:

Contrast the failure mode: a WhatsApp screenshot pasted into a Word file - no export, no hash, no metadata. In 2026 that is not weak evidence; it is, increasingly, no evidence.

Who Is the "Expert"? The BSA's Biggest Gap - Now Answered

The BSA's silence on the meaning of "expert" in Part B was, for two years, its most litigable weakness. Two developments filled it - in opposite directions - before the Supreme Court settled the matter.

The Madras High Court's restrictive view. In R. v. B & Anr, 2024 SCC OnLine Mad 6084, the High Court read Part B narrowly: the expert must be an Examiner of Electronic Evidence notified under Section 79A of the Information Technology Act, 2000. The difficulty is arithmetic — barely a handful of laboratories are so notified. If every WhatsApp chat in every cheque-bounce and matrimonial matter had to queue behind that bottleneck, the right to lead electronic evidence would become, in the petitioner's word, illusory.

The Supreme Court's harmonious correction. In Pune Bar Association (paras 6–7), the Court read Section 39 BSA as a whole. Sub-section (2) deems the opinion of a Section 79A Examiner to be expert opinion - but, crucially, it is not prefaced by a non-obstante clause and therefore does not oust sub-section (1), under which the opinion of any person with special skill in a relevant field (expressly including science) is a relevant fact:

"…if the Court is satisfied, on the basis of unimpeachable material, that any other person has special skill and expertise in computer science and cyber forensics, opinion of such person may be held relevant as an expert with regard to electronic/digital record and such person may sign Part B of the Schedule as an expert." - Pune Bar Association, para 7

The Court declined to treat the Madras High Court's contrary view as binding precedent, while formally keeping the larger question of law open. Position as of July 2026: a Section 79A-notified Examiner remains the gold standard, but a suitably qualified private cyber-forensics expert can sign Part B provided the court is satisfied of genuine, demonstrable expertise. Build that satisfaction into your record - CV, certifications (CCFP from NELIT, CHFI, GCFA, EnCE), tools used, and methodology - because the persuasive burden now sits with the party tendering the expert.

The High Courts in 2025–26: Screenshots Die, Metadata Reigns

Below the Supreme Court, a consistent doctrine is hardening:

The through-line: courts have shifted the inquiry from "can I read the message?" to "can I trust the container?" This is applied epistemology - evidence law as the "institutionalised regulation of the process of proof" (Ho Hock Lai, A Philosophy of Evidence Law, OUP 2008) - and in the digital age, the container is where trust lives or dies.

The New Frontier: Deepfakes and AI-Generated Evidence

Heraclitus warned that one cannot step twice into the same river; the modern evidentiary anxiety is subtler still - we can no longer be sure the river was ever there. A photorealistic video of an event that never happened is now producible on a consumer laptop.

The doctrinal starting point is reassuringly orthodox. Indian courts treat a deepfake as an electronic record like any other: not automatically inadmissible, but subject to the same Section 63 gate - certificate, hash, and chain of custody. The technology raises the stakes of authentication; it does not rewrite the rules.

The real battle is the burden of proof. Fabricating a deepfake is cheap; disproving one is expensive. Emerging Indian scholarship (e.g., Deepfake Evidence and the Indian Criminal Justice System, IJFMR 2025; AI-Generated Evidence in Indian Courts: Admissibility, Reliability and the Chain-of-Custody Challenge, IJIRL 2025) converges on three defensive pillars:

Personality-rights litigation is the leading edge. While a settled standard for adjudicating deepfake authenticity is still developing, the civil injunctive response has matured rapidly. Through 2025–26 the Delhi and Bombay High Courts granted a wave of interim protections against unauthorised deepfakes and voice clones - for actors including NTR Jr., R. Madhavan and Shilpa Shetty (December 2025), entrepreneur Aman Gupta (Delhi HC, May 2026) and Ravi Kishan (July 2026) - anchoring the right in Article 21 and recognising that a person's image, voice and likeness are protected against AI misappropriation no less than against traditional forms. The gap that remains is the absence of dedicated legislation on AI evidence, leaving authentication standards to case-by-case judicial improvisation.

Chain of Custody: The Unglamorous Spine of the Whole Edifice

A certificate certifies a record; the chain of custody certifies the journey of that record from crime scene to courtroom. As the Supreme Court framed it in Pune Bar Association, electronic records are "a unique species of evidence which is liable to continuous mutation and modification affecting [their] authenticity, integrity and intrinsic evidentiary value" (para 3). Mutability is the enemy; documented custody is the answer.

A defensible 2026 protocol:

A pristine Part A over a contaminated chain is a signature on a lie.

The DPDP Overlay: Gathering Evidence Without Committing a Data Breach

New in 2026, and easy to miss: the Digital Personal Data Protection Rules, 2025 were notified by MeitY on 14 November 2025, operationalising the Digital Personal Data Protection Act, 2023. This changes the legality of collection, not the admissibility test - but a practitioner who ignores it can win the evidence and lose the client.

The philosophical tension is genuine: evidence law wants maximum truth-access (Bentham's anti-exclusionary instinct in the Rationale of Judicial Evidence), while data-protection law insists on minimum necessary intrusion. The mature practitioner in 2026 holds both - gathering only what the case needs, lawfully, and proving that it did.

Cross-Border and Cloud Evidence

The global nature of digital data continues to strain domestic procedure. Records now sit in servers across jurisdictions; the collection, admissibility and enforcement of such evidence turn on Mutual Legal Assistance Treaties (MLATs), letters rogatory, and the cooperation of intermediaries. The Section 63 certificate travels with the record regardless of where the server sits - but obtaining the record lawfully across borders remains one of the least-solved problems in the field, and one to watch as international frameworks evolve.

Conclusion: From Admissibility to Authenticity

The story of Indian electronic-evidence law is a slow migration of the central question. Under the IEA it was admissibility - may the record come in? (Anvar, Arjun Panditrao.) Under the BSA, and confirmed by Pune Bar Association in 2026, the question has become authenticity - should we believe it, and how do we know? The hash value, the two-part certificate, the qualified expert, and the unbroken chain of custody are the four load-bearing answers.

For the profession the message is bracing but fair. The romantic era of the persuasive screenshot is over. The new craft is quieter and more disciplined: preserve at source, hash early, certify properly, document the journey, and be ready to prove - against an adversary who may now manufacture reality - that your record is exactly what it claims to be.

As a cyber lawyer I read all this not as bureaucratic burden but as the law finally growing a spine of proportionate rigour equal to the technology it must judge. India's legal system has shown, once again, a proactive willingness to embrace technology while insisting on integrity. Justice in the digital age will belong to the meticulous.

Selected authorities and further reading

Case law

Scholarship / references

Authors other important Blogs and AI Book :

Cybersecurity Laws and Regulations in India - July 2026 

AI Laws and Regulations in India as of 2026: A Comprehensive Overview for Practitioners, Businesses, and Policymakers

AI Book Free Download : Seven AI Laws : The Future of Mankind

— Adv. (Dr.) Prashant Mali