ELECTRONIC EVIDENCE IN INVESTIGATION:

Seizure, Hash Value Authentication, and Proof

in Indian Criminal Proceedings

By Mamta Sharma | Advocate-on-Record | Founder, The Case Counsel, New Delhi

ABSTRACT Every investigation today generates digital debris – smartphones seized at dawn raids, laptops imaged by the Enforcement Directorate, servers cloned by the CBI. The evidentiary value of all this material rises or falls on one question: did the investigating authority follow a rigorous, court-proof protocol from seizure to proof? This article – enriched with flow diagrams, mind maps, worked examples, and comparison tables – examines the complete lifecycle of electronic evidence under the Bharatiya Sakshya Adhiniyam, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, drawing on every landmark judgment from Navjot Sandhu (2005) to Arjun Panditrao (2020) and Umesh Vittal Patil (2022).

I. INTRODUCTION: THE DIGITAL CRIME SCENE

Digital evidence is now the spine of economic offences, PMLA prosecutions, UAPA cases, and routine criminal trials. The Supreme Court has established a clear and unforgiving framework: produce the right certificate, record the hash value, maintain an unbroken chain of custody – or the evidence falls. Yet investigating agencies continue to commit elementary errors. This article presents the law in a format designed for practitioners: diagrams show the procedure visually; worked examples show what happens when the procedure fails; mind maps highlight the key legal areas at a glance.

A single number – forty to sixty-four alphanumeric characters long – can determine whether a decade-long investigation ends in conviction or acquittal. That number is the hash value. Understanding it is no longer optional for any officer, prosecutor, or advocate who deals with digital evidence.

II. STATUTORY FRAMEWORK: IEA TO BSA

Parliament introduced Sections 65A and 65B into the Indian Evidence Act, 1872 through the Information Technology Act, 2000, creating a special code for proving electronic records. The Bharatiya Sakshya Adhiniyam, 2023 (BSA), in force from 1 July 2024, replaced the IEA entirely and made three critical advances: (1) electronic records are now expressly a sub-category of documents; (2) the hash value is expressly required in the Section 63 certificate Schedule; (3) the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) mandates audio-visual recording of every search and seizure.

IMPORTANT NOTE ON SECTION 105 – BNSS, NOT IT ACT The mandate for audio-visual recording of search and seizure operations is contained in Section 105 of the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) – NOT in the Information Technology Act, 2000. The IT Act 2000 has no provision corresponding to Section 105 BNSS. The IT Act 2000 is relevant only to the extent that it introduced Sections 65A and 65B into the Indian Evidence Act, 1872 (now replaced by Sections 62-63 of the BSA 2023). Throughout this article, all references to ‘Section 105’ are to Section 105 BNSS 2023 exclusively.

DIAGRAM 1: IEA vs BSA – COMPARISON TABLE

ASPECTOLD REGIME (IEA 1872)NEW REGIME (BSA 2023)
Status of electronic recordsSecondary evidence; needed certificate to be provedElectronic records are documents; original = primary evidence
Hash value requirementNot explicitly mandated in statute; case-law developed itExpressly required in the Schedule to Section 63 certificate
Certificate provisionSection 65B – introduced by IT Act 2000 amendmentSection 63 – built into the BSA from inception
Search & seizure recordingNo statutory mandate for AV recordingBNSS Section 105: AV recording of search is mandatory
Primary vs secondaryAlmost all digital copies treated as secondary evidenceOriginal device produced = primary evidence; no certificate needed
Who certifiesPerson in responsible official position (same principle)Same; BSA Schedule is more structured with Part A / Part B
Cloud / third-party dataNo specific provision; applied by judicial interpretationProvider’s certificate under S.63 required; same hash value rule
ILLUSTRATION: The Absent Certificate – A PMLA Prosecution Unravels
SCENARIOThe Enforcement Directorate raided a Mumbai-based shell company. Officers seized the CFO’s laptop, extracted 480 spreadsheets showing layered transactions worth Rs. 350 crore, and produced printouts before the PMLA Special Court. The prosecution tendered the printouts without a Section 65B / Section 63 certificate. Defence counsel objected.
OUTCOMEThe Special Court, following Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1, upheld the objection. The printouts were ruled inadmissible as secondary evidence without the certificate. The prosecution’s forensic evidence – the backbone of the money trail – was excluded. The accused was acquitted on those charges.
LESSONThe certificate is not paperwork. It is a condition of admissibility. No prosecution lawyer should tender any electronic record without first verifying that both Part A and Part B of the Section 63 certificate are signed, complete, and carry a matching hash value.

III. THE LANDMARK JUDGMENTS – A TIMELINE

Indian courts have travelled a long and sometimes turbulent path on electronic evidence. The Supreme Court in Anvar PV (2014) partially overruled Navjot Sandhu (2005) – only to the extent of the electronic evidence position. Tomaso Bruno (2015), a three-judge bench, was declared per incuriam because it did not refer to Anvar PV at all. Shafhi Mohammad (2018), a two-judge bench, was overruled in Arjun Panditrao (2020). Understanding this sequence is essential: trial courts still occasionally apply overruled positions, and a defence advocate who can cite the correct line of authority and the specific paragraphs of overruling will always be ahead.

DIAGRAM 2: JUDGMENT TIMELINE – 2005 TO 2024

YEARCASEPRINCIPLE
2005State v. Navjot Sandhu (2005) 11 SCC 600Electronic evidence admitted without S.65B certificate. Oral evidence held sufficient.
2014Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473S.65B certificate mandatory for secondary electronic evidence. Complete code. Navjot Sandhu PARTIALLY overruled at Para 24 – to the extent of the electronic evidence position only.
2015Tomaso Bruno v. State of UP (2015) 7 SCC 178Three-judge bench (R. Banumathi, Kurian Joseph, Anil R. Dave JJ.) allowed general S.65 secondary evidence rules WITHOUT referring to Anvar PV – hence declared per incuriam by Arjun Panditrao at Para 35.
2018Shafhi Mohammad v. State of HP (2018) 2 SCC 801Relaxed certificate requirement where party not in possession of device. Certificate called ‘procedural’.
2020Arjun Panditrao v. Kailash Gorantyal (2020) 7 SCC 1Certificate is condition precedent. Anvar affirmed. Shafhi overruled. Tomaso declared per incuriam. SETTLED LAW.
2022Umesh Vittal Patil v. State of Karnataka CrA 2760/2012 (Karnataka HC)Hash value must be generated at seizure. Delay weakens evidence. Each access must verify unchanged hash.
2024BSA 2023 in force (1 July 2024)Hash value now expressly required in S.63 Schedule. Electronic records elevated. AV recording mandated by BNSS S.105.

Key Judgments in Detail

State (NCT of Delhi) v. Navjot Sandhu @ Afzal Guru (2005) (2005) 11 SCC 600 – Division Bench, Supreme Court of India (P. Venkatarama Reddi J, P.P. Naolekar J) HELD: Call detail records and computer printouts were admitted as secondary evidence under the general provisions of Sections 63 and 65 of the IEA, without strict compliance with Section 65B. The Court held there was no bar in adducing secondary evidence of an electronic record under the general provisions. CURRENT STATUS: PARTIALLY OVERRULED – by Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473 at Para 24, to the extent of the statement of law on admissibility of electronic evidence pertaining to electronic records. The rest of the Navjot Sandhu judgment (on other points of law) was not disturbed.
Tomaso Bruno & Anr. v. State of U.P. – Three-Judge Bench Declared Per Incuriam (2015) (2015) 7 SCC 178 – Three Judge Bench, Supreme Court of India (R. Banumathi J, Kurian Joseph J, Anil R. Dave J) HELD: Secondary evidence of the contents of a document can be led under Section 65 of the Evidence Act to make CCTV footage admissible, without a Section 65B certificate. The Court followed Navjot Sandhu WITHOUT referring to or noticing the three-judge bench decision in Anvar PV (2014) which had already overruled Navjot Sandhu. CRITICAL NOTE: This was a three-judge bench – NOT a two-judge bench. CURRENT STATUS: Declared PER INCURIAM by Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal at Para 35 (2020) 7 SCC 1. The per incuriam declaration stands because the bench, despite its strength, simply did not notice Anvar PV – the governing three-judge bench decision on the same point.
Shafhi Mohammad v. State of Himachal Pradesh – Division Bench Relaxation (2018) (2018) 2 SCC 801 – Division Bench (Two-Judge Bench), Supreme Court of India HELD: Where a party is not in possession of the device from which the electronic record was produced, the court may relax the certificate requirement in the interest of justice. The certificate under Section 65B(4) was described as ‘procedural’ and not mandatory. CURRENT STATUS: OVERRULED at Para 35 and Para 73 by Arjun Panditrao Khotkar (2020) 7 SCC 1. The Supreme Court held that the major premise of Shafhi Mohammad – that a Section 65B(4) certificate cannot be secured by persons not in possession of an electronic device – was wholly incorrect.
Anvar P.V. v. P.K. Basheer – The Watershed (2014) (2014) 10 SCC 473 – Three Judge Bench, Supreme Court of India (R.M. Lodha CJ, Kurian Joseph J, R.F. Nariman J) Sections 65A and 65B constitute a complete and exhaustive code for proving electronic records. A Section 65B certificate is mandatory when electronic records are produced as secondary evidence. Oral testimony cannot substitute the certificate. PARTIAL OVERRULING: Navjot Sandhu [(2005) 11 SCC 600] was overruled TO THE EXTENT of the statement of law on admissibility of electronic evidence pertaining to electronic records – at Para 24 of the Anvar PV judgment. The rest of the Navjot Sandhu decision was not disturbed. EXCEPTION: If the original device itself is produced as primary evidence, no certificate is needed.
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal – The Definitive Ruling (2020) (2020) 7 SCC 1 – Three Judge Bench, Supreme Court of India (R.F. Nariman J, S. Ravindra Bhat J, V. Ramasubramanian J) Certificate under Section 65B(4) is a CONDITION PRECEDENT – not merely procedural – to admissibility of electronic records. Anvar P.V. is affirmed and clarified. OVERRULING WITH PARA REFERENCES: (1) Tomaso Bruno (2015) 7 SCC 178 declared per incuriam at Para 35 – because it followed the overruled Navjot Sandhu without citing Anvar PV; (2) Shafhi Mohammad (2018) 2 SCC 801 overruled at Para 35 and Para 73 – held to not lay down the law correctly; (3) The reference is answered at Para 73 of the judgment. Courts must direct authorities to produce the certificate when a party cannot obtain it from the custodian. Service providers must maintain records in a secure, segregated manner.
Umesh S/o. Vittal Patil v. State of Karnataka – Hash Value Mandated (2022) Criminal Appeal No. 2760 of 2012, Karnataka High Court (Dharwad Bench), Justice V. Srishananda – Decided 21 July 2022 [Available on Indian Kanoon; guidelines cited in LiveLaw article on hash values in electronic evidence, published May 2026] The hash value of an electronic record must be generated and recorded AT THE TIME OF SEIZURE. This is the mechanism by which the originality and authenticity of electronic evidence is established. Any delay in generating the hash value weakens the evidentiary value of the record. Each time the record is accessed, its hash value must remain identical to the value recorded at seizure; any change in hash value signals tampering. NOTE: This is a single-judge High Court decision from the Karnataka HC Dharwad Bench; it does not bind other High Courts but is persuasive authority on the mandatory nature of at-scene hash value generation.
ILLUSTRATION: Tomaso Bruno Misapplication – A Trial Court Error
SCENARIOIn a cybercrime case in a District Court in Uttar Pradesh in 2023, the prosecution tendered WhatsApp screenshots without a Section 63 certificate, citing the Tomaso Bruno judgment to argue that electronic evidence could be admitted as ordinary secondary evidence. The defence remained silent on the point.
OUTCOMEThe court admitted the screenshots relying on Tomaso Bruno. However, on appeal, the Sessions Court correctly pointed out that Tomaso Bruno had been declared per incuriam by the Supreme Court in Arjun Panditrao (2020). The admission of the screenshots was held to be an error of law. The matter was remanded.
LESSONA defence advocate who knows the overruling of Tomaso Bruno can prevent the admission of uncertified electronic records at the trial stage itself – saving years of appellate litigation. Know your case law sequence.

IV. THE HASH VALUE: INDIA’S DIGITAL FINGERPRINT

A hash value is the output produced when data is processed through a cryptographic algorithm – typically SHA-256 (64 characters) or MD5 (32 characters). Its defining property: change a single bit of data and the output hash changes completely. This makes it the most reliable tamper-detection tool available to a court.

HOW SHA-256 WORKS – IN PLAIN LANGUAGE Input: A hard drive containing 500 GB of financial data. Process: The SHA-256 algorithm processes every byte of that 500 GB. Output: A fixed 64-character string, e.g.: 3a7bd3e2360a3d29eea436fcfb7e44c735d117c42d1c1835420b6b9942dd4f1b Now change ONE character in ONE file on that drive. The new hash: f2c4a89b17d6e3051c8a74b9f5e2d1a03c9b7f6e4d2c1b8a07f5e3d1c2b9a8e7 The court sees two different hash values. This tells it that the data produced in court is NOT the same data that was on the drive at seizure. One character changed – and the law sees it.
ILLUSTRATION: The Hash Mismatch – Bhima Koregaon Parallel
SCENARIOAn independent US-based digital forensics firm (Arsenal Consulting) was engaged by defence counsel in the Bhima Koregaon – Elgar Parishad case. Arsenal’s analysis of the electronic devices seized from accused activists found that files had been placed on the devices by malware (NetWire RAT). The hash values of files found on the devices did not match the hash values that would be consistent with organic file creation by the device owners. Files had, in effect, been planted remotely after the device left the accused’s possession.
OUTCOMEThe forensic finding triggered serious questions about the integrity of the electronic evidence relied on in the chargesheet. The NIA Special Court was subsequently pulled up for not supplying cloned copies of electronic evidence to the accused – a four-year violation of Section 207 CrPC. The case became the most important cautionary tale on digital evidence integrity in Indian legal history.
LESSONHash values do not merely prove the prosecution’s case. They protect the accused against planted evidence. A rigorous hash value protocol at the time of seizure – and a requirement that the accused receive cloned copies promptly – is a protection of the rights guaranteed under Article 21.

V. THE SEIZURE PROTOCOL – STEP-BY-STEP PROCEDURE

The following procedure governs all central and state investigating authorities – Police, ED, CBI, NIA, Income Tax Department. It draws on the BSA 2023, BNSS 2023, the CBI Manual on Digital Evidence 2020, and the directions of the Supreme Court and High Courts.

DIAGRAM 3: LIFECYCLE OF DIGITAL EVIDENCE – MASTER FLOW

STAGE 1: SEARCH AUTHORISATION Warrant / PMLA Auth / BNSS S.105
STAGE 2: DEVICE SEIZURE Panchnama | Witnesses | AV Recording
STAGE 3: HASH VALUE GENERATION SHA-256 at scene | Record in Panchnama
STAGE 4: FORENSIC CLONING Write-blocker | Two bit-by-bit images
STAGE 5: HASH VERIFICATION Clone hash = Original hash?
STAGE 6: FSL EXAMINATION Access logs | Tool audit trail | Findings
STAGE 7: SECTION 63 CERTIFICATE Part A (IO) + Part B (FSL Expert)
STAGE 8: PROOF IN COURT Exhibit | Expert PW | Certificate tendered

Pre-Seizure Preparation

  • Legal authority: Search warrant under Section 93 BNSS, authorisation letter under PMLA (for ED), or equivalent statute-specific power. Emergency search without warrant must be an exception with recorded reasons.
  • Equipment: Forensic-grade write-blockers, imaging tools (hardware/software), sealed evidence bags, blank panchnama forms, tamper-evident seals, and a laptop pre-loaded with hash software (SHA-256 tool, Autopsy, FTK, or EnCase).
  • Personnel: At least one officer trained in digital forensics. Where no such officer is available, engage an FSL examiner. Note the reason for absence in the panchnama.
  • AV Recording: Under Section 105 BNSS, the entire search must be audio-visually recorded from the moment of entry. Failure to record is now a procedural defect.

At the Scene – The Eight Steps

  1. STEP 1: Photograph or video-record the device IN SITU before touching it. Capture screen state (on/off). Note make, model, IMEI/serial number, colour, physical condition.
  2. STEP 2: Handle power state with care. If the device is ON, do not simply switch it off – volatile RAM may contain passwords, encryption keys, and live session data. A trained forensic officer must assess whether live acquisition of RAM is needed first.
  3. STEP 3: Prepare a detailed seizure panchnama recording: date, time, place of seizure; description of each device; name and designation of seizing officer; names of independent witnesses; legal authority for seizure; condition of device; approximate storage capacity. Both witnesses must sign.
  4. STEP 4: Generate hash value IMMEDIATELY at scene. Connect device through write-blocker. Run SHA-256 algorithm on entire drive. Record the hash value in the panchnama. The write-blocker ensures no data is written to the original device.
  5. STEP 5: Create at least two forensic images (bit-by-bit clones). Verify each image by recomputing hash value and confirming it matches the original. Document both hash values. Label each image distinctly (MASTER CLONE 1; WORKING CLONE 2).
  6. STEP 6: Seal the original device in a tamper-evident evidence bag. Sign across the seal. Have witnesses sign. Write seal date, case number, and hash value on the outside of the bag. The original must NEVER be examined subsequently.
  7. STEP 7: Transport under custody documentation. Log each transfer: who handed over, who received, date, time, condition of seal. This is the chain of custody document – every link matters.
  8. STEP 8: Supply a cloned copy to the accused under Section 230 BNSS as soon as the chargesheet is filed. Failure to supply is a violation of Article 21 – as demonstrated in Bhima Koregaon.
ILLUSTRATION: The Delayed Hash – ED Office Seizure, Delhi
SCENARIOED officers raided a Delhi-based fintech company. They seized 12 laptops and 3 servers. The hash values were not generated at the scene – the IO noted that hash generation equipment was not available. The devices were taken to the ED office and kept in a room for 48 hours before being sent to the FSL, where hash values were generated for the first time.
OUTCOMEAt trial, defence counsel challenged the admissibility of all data extracted from the 12 laptops, arguing that the 48-hour unmonitored window without a hash value created an unrebutted presumption of tampering. The PMLA Special Court noted the delay but admitted the evidence provisionally. On appeal, the High Court directed fresh cross-examination of the IO specifically on the 48-hour gap, and remanded the matter for re-appreciation.
LESSONHash value must be generated AT THE SCENE. If equipment is not available at the scene, the forensic officer must travel with the device to the FSL immediately, without any intermediate stop, and generate the hash value with the accused or their representative present. The CBI Manual (2020) is explicit on this point.

VI. CHAIN OF CUSTODY: EVERY LINK MATTERS

The chain of custody is the documented chronological record of every person who handled, accessed, stored, or transferred electronic evidence from seizure to proof. Every undocumented gap is an opportunity for the defence to argue tampering. The standard is simple but demanding: if you touched it, write it down.

DIAGRAM 4: CHAIN OF CUSTODY – STAGE BY STAGE

SEIZURE IO seizes device at sceneDOCUMENT REQUIRED: Panchnama + Hash Value H1
 
MALKHANA / EVIDENCE ROOM Device sealed and loggedDOCUMENT REQUIRED: Malkhana register entry
 
FORENSIC LAB (FSL) Sealed device receivedDOCUMENT REQUIRED: FSL receipt + seal condition noted
 
FORENSIC EXAMINATION Clone examined; original sealedDOCUMENT REQUIRED: Access logs + Hash verified H2=H1
 
BACK TO MALKHANA Post-examination re-sealingDOCUMENT REQUIRED: Re-seal record + transfer log
 
COURT PRODUCTION Tendered with S.63 certificateDOCUMENT REQUIRED: Exhibit marked + Certificate on record

In the forensic laboratory, access logs must record every login to the forensic workstation, every tool used, every file accessed, and the hash values verified before and after each examination session. Modern forensic tools (EnCase, FTK, Autopsy) generate audit logs automatically. These logs must be preserved and produced as part of the evidence trail.

ILLUSTRATION: The Custody Gap – NIA Chargesheet Challenged
SCENARIOIn a UAPA prosecution, the NIA’s chargesheet relied on documents extracted from an accused journalist’s laptop. The custody log showed the laptop was transferred from the arresting officer to a transit facility, then to the NIA headquarters in Delhi, and finally to the FSL. However, the transit facility had no entry in the custody register – the device had spent 72 hours there with no log entry of who had access.
OUTCOMEDefence counsel filed an application under Section 311 CrPC (now Section 348 BNSS) to summon the transit facility officer. The officer could not account for who had keys to the room and who had accessed it during the 72-hour period. The court noted this as a ‘significant lacuna in the chain of custody’ and directed a re-examination of all digital evidence with heightened scrutiny.
LESSONA custody gap of even a few hours, if unexplained, is exploitable by the defence. The chain of custody register must have ZERO undocumented intervals from the moment of seizure to the moment the evidence is produced before the court.

VII. THE SECTION 63 CERTIFICATE: ANATOMY AND APPLICATION

The Section 63 certificate under the BSA 2023 (successor to Section 65B of the IEA) is the legal gateway through which electronic records are admitted as secondary evidence. Without it, the data is mute. The certificate speaks for the data. It tells the court: this is what was on the device; this is how we know it has not been altered; this is who swears to it.

What the BSA Schedule Requires

  • Device description: Make, model, serial number, and unique identifier of the device from which the electronic record is produced.
  • Proper functioning: Statement that the device was functioning properly at the relevant time – or, if not, that any malfunction did not affect the electronic record or its accuracy.
  • Regular activity: Statement that the information was fed into the device in the ordinary course of activities, or a description of how data was captured.
  • Hash value: The SHA-256 or MD5 hash value of the electronic record, expressly matching the hash value recorded in the seizure panchnama.
  • Signatory: Name, designation, and signature of the person in a responsible official position in relation to the operation of the device. Part A = IO; Part B = FSL Expert.
ILLUSTRATION: The Wrong Signatory – Certificate Challenged at Trial
SCENARIOIn a cybercrime case in the Delhi High Court, the prosecution tendered a Section 65B certificate for data extracted from the accused’s Gmail account. The certificate was signed by the Investigating Officer. The defence challenged the certificate, arguing that the IO was not a ‘person in responsible official position in relation to the operation of the relevant device’ – the relevant device being Google’s servers, not the accused’s laptop.
OUTCOMEThe Delhi High Court upheld the challenge in part. The IO could certify the extraction process performed on the locally seized device, but could NOT certify the integrity of data received from Google’s servers. A certificate from an authorised representative of Google India, or a certification from Google’s compliance officer under the applicable mutual legal assistance process, was required for the server-side data.
LESSONFor cloud data and third-party server data, the certificate must come from the SERVICE PROVIDER – not merely from the investigating officer. The BSA and the Supreme Court in Arjun Panditrao both contemplate that courts may direct third parties to furnish certificates.

VIII. PROVING DIGITAL EVIDENCE IN COURT: THE SEVEN STEPS

The following is the complete roadmap for a prosecution proving electronic evidence before a Sessions Court, Special Court, or High Court. Each step corresponds to a legal requirement and a practical safeguard.

  • STEP 1 – EXHIBIT IN CHARGESHEET: Ensure the electronic device and the cloned media appear in the list of properties annexed to the chargesheet. Each item must carry a unique property number, its description, and sealed condition at the time of chargesheet filing.
  1. STEP 2 – IO AS PW (CHAIN FOUNDATION): Examine the Investigating Officer as a Prosecution Witness (PW). The IO must prove: (a) legal authority for search; (b) date, time, place of seizure; (c) physical state of device at seizure; (d) hash value generated at scene and recorded in panchnama; (e) sealing process; (f) chain of custody from seizure to court. The signed panchnama is exhibited through the IO.
  1. STEP 3 – FSL EXPERT AS PW (TECHNICAL PROOF): Examine the FSL forensic examiner as an Expert Witness (PW). The expert must establish: (a) receipt of the sealed device with seal intact; (b) forensic imaging process; (c) hash value of original matched hash in panchnama; (d) tools used; (e) hash value of forensic image used for analysis; (f) findings of analysis; (g) signing of Part B of the Section 63 certificate.
  1. STEP 4 – TENDER SECTION 63 CERTIFICATE: Tender and mark the Section 63 certificate as an exhibit BEFORE or AT THE TIME the electronic record is tendered. An objection to admissibility must be decided at this stage. Do not tender the record first and the certificate later.
  1. STEP 5 – TENDER THE ELECTRONIC RECORD: Tender the electronic record itself – whether a printed spreadsheet, extracted WhatsApp chat, email printout, or video file on CD – as an exhibit. The hash value on the certificate must match the hash value of the record as generated at forensic extraction.
  1. STEP 6 – CORRELATE TO THE CHARGE: Connect the electronic evidence to the charge. The IO or a forensic accountant (in financial cases) must explain how the data found on the device proves the accused’s criminal activity. Correlation with CDRs, bank records, and third-party data is essential.
  1. STEP 7 – CLOSE DEFENCE GAPS: Anticipate and address the four classic defence objections: (a) hash mismatch; (b) certificate deficiency; (c) chain of custody gap; (d) planted evidence or malware allegation. Close each gap before it is exploited.
ILLUSTRATION: The Live Hash Demonstration – A Prosecution That Got It Right
SCENARIOIn a Maharashtra cybercrime trial involving Rs. 200 crore worth of unauthorised fund transfers, the prosecution called the FSL examiner as a witness. During examination-in-chief, the examiner described generating the SHA-256 hash value at the time of forensic imaging. During cross-examination, defence counsel asked the examiner to re-run the hash algorithm on the evidence CD in court in real time and compare it to the value recorded in the Section 65B certificate.
OUTCOMEThe examiner ran the algorithm on a forensic workstation brought to court. The hash value matched exactly. The court noted in its judgment: ‘The live demonstration of hash value consistency in open court is the most compelling form of proof of data integrity. The defence has been unable to dislodge the prosecution’s case on the electronic evidence.’
LESSONA prosecution that is confident of its hash values should welcome – not fear – a live demonstration in court. Prepare the forensic examiner for this possibility in every case where electronic evidence is central.

IX. AGENCY-SPECIFIC ISSUES: ED, CBI, NIA, AND POLICE

Different investigating agencies face different challenges with digital evidence. Understanding the specific pressure points for each agency helps both prosecution and defence lawyers anticipate and address problems.

AGENCYSTATUTESPECIFIC DIGITAL EVIDENCE ISSUES
PoliceCrPC / BNSS 2023Volume of seizures across multiple cases; limited forensic training at station level; delay in sending devices to FSL; failure to generate hash at scene; non-compliance with BNSS S.105 AV recording.
Enforcement DirectoratePMLA 2002Seizure of cloud data and email accounts; time pressure to complete arrests within PMLA timelines; large-volume server seizures; need for service-provider certificates for third-party data.
CBIDSPE Act 1946 / BNSS 2023Bound by 2020 CBI Manual on Digital Evidence (affirmed by SC in Foundation for Media Professionals proceedings); higher accountability than state police; multi-agency coordination issues.
NIANIA Act 2008UAPA cases with heavy reliance on digital evidence; Bhima Koregaon case exposed clone supply failures; independent forensic review by accused’s experts is now more common.
Income Tax / SFIOIT Act 1961 / Companies ActSeizure of accounting software data and servers; need for ERP system certificates; specialised forensic accountants essential in addition to FSL examiners.

X. COMMON FAILURES AND THEIR LEGAL CONSEQUENCES

FAILURELEGAL CONSEQUENCELEADING AUTHORITY
Hash value not generated at sceneDefence argues integrity unestablished; evidence weakened or excludedUmesh Vittal Patil (2022, Karnataka HC)
Original device examined without cloningMetadata altered; data integrity compromised; evidence challengedCBI Manual 2020; General forensic best practice
Certificate missing at trialEvidence inadmissible as secondary evidence; exclusion mandatoryArjun Panditrao (2020); Anvar P.V. (2014)
Wrong signatory on certificateCertificate challenged; prosecution must call correct officialArjun Panditrao (2020) – ‘responsible official position’
Clone not supplied to accusedViolation of Article 21; trial liable to be stayedBhima Koregaon (NIA Special Court); Section 230 BNSS
No AV recording of searchAdverse inference; raises doubt on seizure integritySection 105 BNSS 2023 (mandatory from 1 July 2024)
Chain of custody gap (undocumented)Tampering presumed in gap; evidence excluded or re-examinedGeneral principle; Bhima Koregaon proceedings
Metadata inconsistencyExpert testimony undermined; fabrication allegedArsenal Consulting findings in Bhima Koregaon case

XI. THE DEFENCE COUNSEL’S MASTER CHECKLIST

When briefed in a matter where electronic evidence is central to the prosecution, a defence lawyer must methodically examine ten areas. The following checklist – structured as an action table – tells you what to check, what to look for, and what argument the deficiency supports.

DIAGRAM 5: DEFENCE CHECKLIST – 10-POINT AUDIT

S. no.CHECKWHAT TO LOOK FORIF DEFICIENT – ARGUMENT
1Hash value in panchnama?Check if IO recorded SHA-256/MD5 at sceneIf absent: argue integrity not established
2Hash match: original vs clone?FSL report must show H1=H2If mismatch: apply to exclude evidence
3Section 63 certificate present?Must accompany electronic record at tenderIf absent: object to admissibility (Arjun Panditrao)
4Certificate signed by right person?Responsible official in relation to device operationIf wrong signatory: challenge the certificate
5All certificate fields complete?Device details, hash value, date, processMissing fields: grounds for exclusion
6Chain of custody unbroken?Every transfer documented; seal verifiedAny gap: argue tampering in the gap
7FSL access logs available?Hash verified before/after each sessionAbsent logs: reliability challenged
8Cloned copy supplied to accused?Section 230 BNSS obligationNot supplied: apply to stay trial
9AV recording of search available?Mandatory under BNSS S.105 from 1.7.2024Absent: adverse inference argument
10Metadata consistent?Timestamps, author field, edit historyInconsistency: commission independent forensic expert
ILLUSTRATION: The Complete Collapse – Defence Checklist in Action
SCENARIOIn a CBI corruption case, defence counsel in the Sessions Court ran through the ten-point checklist. Findings: (1) Hash value NOT in panchnama – generated 7 days after seizure at FSL. (2) Hash match unverifiable because no baseline was established at scene. (3) Section 65B certificate signed by a constable who ‘operated’ the forensic workstation – not a responsible official. (4) Chain of custody showed the device in an officer’s personal vehicle for 3 days before FSL delivery. (5) No AV recording of the search.
OUTCOMEDefence counsel filed a detailed objection on admissibility at the stage of evidence tendering. The Special Court, on careful review, held that items (1), (3), and (4) together created an unacceptable level of doubt about the integrity of the digital evidence. The electronic records were marked as exhibits but the court declined to rely on them as the primary basis of conviction. The accused was acquitted on all counts that depended solely on the digital evidence.
LESSONThe checklist is not a formality. Run through it in every matter. A single deficiency, properly argued at the right procedural stage, can determine the outcome of the case.

XII. THE CURRENT POSITION UNDER BSA 2023

The Bharatiya Sakshya Adhiniyam, 2023, in force from 1 July 2024, has fundamentally modernised the evidentiary framework. Courts applying the BSA have already signalled heightened expectations: WhatsApp screenshots require a robust Section 63 certificate with device and platform linkage; metadata inconsistencies are scrutinised; and the absence of AV recording of searches creates an adverse inference.

THE THREE KEY BSA ADVANCES 1. EXPRESS HASH VALUE REQUIREMENT: The Schedule to Section 63 expressly requires the hash value. This removes any residual argument that hash value is merely ‘good practice’ rather than a legal requirement. 2. PRIMARY EVIDENCE ELEVATION: Original electronic records produced from proper custody are primary evidence. No certificate needed if the original device itself is produced and authenticity is undisputed. 3. AV RECORDING OF SEARCH (BNSS S.105): The search and seizure must be audio-visually recorded. This independent record is available to both prosecution and defence. Failure to record is a procedural defect the court may note adversely.

XIII. CONCLUSION

Digital evidence is not self-proving. A hard drive is dumb metal; a printout is paper. They speak only when the law gives them a voice – through proper seizure, hash value authentication at the scene, forensic imaging, unbroken chain of custody, and a legally compliant certificate. When investigating agencies perform these steps correctly, electronic evidence is among the most powerful and reliable evidence a court can receive. When they do not, the same evidence becomes a liability.

The Supreme Court settled the law in Arjun Panditrao (2020). The Karnataka High Court settled the hash value requirement in Umesh Vittal Patil (2022). The BSA 2023 legislated both into statute. The BNSS 2023 added AV recording. The 2020 CBI Manual provides the operational protocol. Every tool the law needs is in place.

What remains is the gap between law and practice. Officers who rush past hash value generation. Prosecutors who tender certificates without checking them. Defence lawyers who miss the mismatch between hash values. Courts that do not scrutinise the chain of custody.

The diagrams, mind maps, and examples in this article are designed to close that gap. A practitioner who can visualise the lifecycle of digital evidence – from seizure to proof – and who knows exactly where the chain breaks will be a more effective advocate in any courtroom where bytes and algorithms determine guilt.

THE PRACTITIONER’S MANTRA GET THE HASH VALUE RIGHT. GET IT AT THE SCENE. RECORD IT IN THE PANCHNAMA. VERIFY IT IN THE CERTIFICATE. PROVE IT IN COURT.

About the Author

Mamta Sharma is an Advocate-on-Record practising before the Supreme Court of India and the Delhi High Court, and the Founder of The Case Counsel, a litigation practice based in Rohini, New Delhi. Her practice spans constitutional law, criminal litigation including PMLA and UAPA matters, civil law, and public interest advocacy. She has litigated cases involving digital evidence, seizure protocols, and custodial rights before the Supreme Court and various High Courts.

The Case Counsel | New Delhi

QUICK REFERENCE: KEY JUDGMENTS AT A GLANCE

CASECITATIONKEY PRINCIPLE
State v. Navjot Sandhu(2005) 11 SCC 600Allowed secondary electronic evidence without S.65B certificate
Anvar P.V. v. P.K. Basheer(2014) 10 SCC 473S.65B certificate mandatory for secondary electronic evidence
Tomaso Bruno v. State of UP(2015) 7 SCC 178Allowed general secondary evidence rules – without citing Anvar
Shafhi Mohammad v. State of HP(2018) 2 SCC 801Relaxed certificate requirement if party not in possession
Arjun Panditrao v. Kailash Gorantyal(2020) 7 SCC 1Certificate is condition precedent; Anvar affirmed; Shafhi overruled
Umesh Vittal Patil v. State of KarnatakaCrA 2760/2012, Karnataka HC (2022)Hash value mandatory at seizure; delay weakens admissibility
Foundation for Media Professionals v. UoIWP(Crl) 395/2022, SC (ongoing)SC monitoring: agencies must follow CBI Manual on Digital Evidence

– END OF ARTICLE –