Introduction
The advent of the Bharatiya Sakshya Adhiniyam, 2023 (“BSA”), which came into force on 1 July 2024 in substitution of the Indian Evidence Act, 1872, has reconfigured the statutory architecture governing the proof of electronic and digital records in Indian courts.[1]
Electronic evidence today permeates virtually every category of litigation, criminal and civil alike, ranging from WhatsApp chats and emails to CCTV footage, call detail records, server logs, and cloud-stored documents. Given the sheer pervasiveness of digital communication in commercial and personal life, courts are routinely called upon to determine not merely the probative value of such material but its threshold admissibility. Section 61 BSA, together with the interlinked provisions of Sections 62 and 63, forms the statutory gateway through which electronic records enter the evidentiary record.
This paper undertakes a focused examination of Section 61 BSA and its operative relationship with Section 63, addressing three principal themes: first, the requirements of statutory certificate compliance that condition the reception of secondary electronic evidence; second, the forensic imaging standards that undergird the authenticity and integrity of digital material tendered before court; and third, the doctrine of chain of custody as it has been judicially developed and as it now finds implicit statutory recognition. The analysis proceeds from the plain text of the provision, through its legislative lineage traceable to Section 65B of the erstwhile Evidence Act, to the evolving body of case law that continues to shape its practical application.
Statutory Framework: Sections 61 to 63 of the BSA
Section 61 BSA constitutes a threshold, non-obstante style declaration. It provides that nothing in the Adhiniyam shall be applied to deny the admissibility of an electronic or digital record merely on the ground that it is electronic or digital in nature, and that such a record shall have the same legal effect, validity and enforceability as any other document, subject to the requirements of Section 63.[2]
This is a materially new provision; no equivalent formulation existed in the Indian Evidence Act, 1872, even after its amendment by the Information Technology Act, 2000. Its function is chiefly declaratory: it forecloses any residual argument that electronic records are inherently inadmissible or of a lesser evidentiary species than paper documents. Commentators have observed that Section 61 operates as a legislative corrective to the excessively rigid reading that certain judicial pronouncements had earlier given to the certification requirement, ensuring that electronic material is not shut out at the threshold irrespective of the mode by which its contents are ultimately proved.[3]
Section 62 supplies the operative link, stipulating that the contents of an electronic record may be proved in accordance with Section 63. Section 63, in turn, is the direct successor to Section 65A and Section 65B of the 1872 Act and prescribes the special mode of proof for secondary electronic evidence, that is, computer output, printouts, and copies stored on optical, magnetic or semiconductor media. Sub-section (1) opens with a non-obstante clause and permits such material to be treated as a document, without further proof of the original, subject to satisfaction of the conditions that follow.
A structurally significant refinement introduced by Section 63 is the requirement of dual certification under sub-section (4): a certificate must ordinarily be furnished both by a person occupying a responsible official position in relation to the operation of the relevant device, and, in specified circumstances, by an expert. This dual-certificate structure departs from the singular certifying-official model under the erstwhile Section 65B and reflects a legislative intent to introduce an additional layer of technical scrutiny into the certification process.
Statutory Certificate Compliance under Section 63
The certificate contemplated under Section 63(4) is not a mere formality; it is the evidentiary hinge upon which the admissibility of secondary electronic evidence turns. The Schedule appended to the BSA prescribes the specific particulars that the certificate must contain, including identification of the electronic record, a description of the manner in which it was produced, particulars of the device or devices involved in its generation and storage, any modifications made to the record after its creation, and the measures taken to preserve its integrity.
Who May Certify
The certificate must be signed by a person who was, at the relevant time, in lawful control of or responsible for the operation of the computer or communication device from which the record originates. Courts have consistently emphasised that this cannot be discharged by an employee possessing no genuine operational responsibility over the device in question; the certifying person must be one who can meaningfully vouch for the reliability of the system and the manner of its functioning.
Where the reliability of the underlying process is contested, or where the record has passed through forensic examination, an additional certificate from a qualified expert is required under Section 63(4). This expert component is intended to certify matters that a mere custodian of the device cannot competently attest to, such as the integrity of the extraction methodology and the correctness of hash computation.
Consequences of Non-Compliance
The jurisprudence developed under the predecessor provision remains highly persuasive in construing Section 63. In Anvar P.V. v. P.K. Basheer, the Supreme Court held that secondary electronic evidence is inadmissible in the absence of the statutorily mandated certificate, and that the special provision governing electronic records excludes the application of the general secondary-evidence provisions applicable to other documents.[4]
The Supreme Court subsequently reaffirmed and clarified this position in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, holding that the requirement of a certificate is mandatory wherever a party seeks to rely on electronic evidence by way of a computer output without producing the original electronic device itself, and that this requirement cannot be dispensed with; however, the Court also recognised limited situational relaxations, including scenarios where the requesting party is unable to obtain such a certificate despite best efforts, in which event the court retains a residual discretion to order the production of the requisite certificate by the relevant authority.[5]
Section 61 BSA must now be read against this jurisprudential backdrop. Rather than displacing the certificate requirement, the better view is that Section 61 prevents an electronic record from being denied admissibility outright merely because it is electronic; the mode of proof, including the necessity of a Section 63 certificate for computer output tendered without the maker or custodian being examined as a witness, continues to apply. Where a witness with direct, first-hand knowledge of the record is produced and examined, courts have increasingly accepted that oral testimony may substitute for a certificate, since the underlying rationale of certification, namely reliability, is independently satisfied through viva voce evidence.
Judicial scrutiny of certificate quality has also sharpened in recent decisions. Courts have declined to treat a screenshot or an uncertified printout, whether of a WhatsApp conversation, an email chain, or a social media post, as self-proving; absent proper Section 63 certification and a documented process of generation, such material remains vulnerable to exclusion irrespective of its apparent relevance.[6]
A recurring evidentiary controversy concerns whether the certificate must record the hash value of the original source data or that of the copy produced before the court. The dominant judicial approach requires that the hash value be computed and recorded at, or as close as possible to, the point of extraction from the original device, so that the resulting digital fingerprint can meaningfully demonstrate that the copy tendered in court is an unaltered replica of the source.
Forensic Imaging Standards
The reliability contemplated by Section 63 cannot be assessed in the abstract; it necessarily depends on the technical rigour with which the electronic record was acquired, preserved and reproduced. Forensic imaging, meaning the creation of an exact bit-for-bit copy of a storage medium, is the accepted mechanism by which investigators and forensic examiners avoid altering the original evidence while enabling detailed examination of its contents.
Bit-Stream Imaging and Write-Blocking
Standard forensic practice requires that any device suspected to contain evidentiary data first be isolated from further use, following which a forensic image is created using a write-blocker, a hardware or software mechanism that permits data to be read from the source medium without permitting any write operation that could alter it. This bit-stream image captures not merely the visible file structure but also unallocated space, slack space and metadata, all of which may carry evidentiary significance.
Once the image is created, the original device is ordinarily sealed and returned to secure custody, and all subsequent forensic analysis is conducted exclusively upon the image or a verified working copy thereof, never upon the original medium. This practice is directed precisely at preserving the integrity of the source evidence for any future re-examination or challenge.
Hash Verification
Cryptographic hashing is the principal technical safeguard against undetected alteration. A cryptographic hash function such as SHA-256 generates a fixed-length alphanumeric value that functions as a unique digital fingerprint of the underlying data; even a single-bit change to the source file produces an entirely different hash output.[7]
Best practice requires the hash value to be computed immediately upon acquisition of the forensic image and again independently at the point the evidence is examined or tendered in court, so that any discrepancy between the two values immediately signals possible tampering or corruption. The Section 63(4) certificate is expected to record this hash value, together with the algorithm employed, enabling independent verification by the opposing party or the court’s own technical expert.
Extraction Environment and Documentation
Beyond hashing, sound forensic practice requires comprehensive documentation of the extraction environment: the make, model and configuration of the forensic workstation and software used, the version of the forensic tool employed, the date-independent sequence of steps followed, and the credentials of the examiner. Reliance on a properly accredited Forensic Science Laboratory, or an examiner notified for the purpose, lends additional credibility to the process, though commentators have noted that the limited capacity of India’s forensic laboratories poses a practical constraint on the consistent availability of such expert certification.[8]
Where the forensic process itself is contested, courts may examine whether recognised standards, whether drawn from Indian forensic manuals or international frameworks such as those published by the Association of Chiefs of Police or forensic readiness guidelines, were substantially adhered to, treating material deviation as a factor going to weight or, in serious cases, to admissibility itself.
Establishing Chain of Custody
Chain of custody refers to the unbroken, documented history of an item of evidence from the moment of its seizure or acquisition to its ultimate production before the court, recording every person who handled it, every place it was stored, and every action performed upon it. Although the BSA does not use the expression “chain of custody” verbatim, the concept is embedded within the certification and reliability requirements of Section 63 and has been extensively developed through case law.
Elements of a Sound Chain of Custody
A defensible chain of custody typically requires: a contemporaneous seizure memo prepared at the point of collection, identifying the device or medium, its serial or unique identifiers, and the circumstances of seizure; sealing of the item in the presence of independent witnesses; a documented log of every subsequent transfer of custody, including the identity of each recipient and the purpose of transfer; secure storage conditions that prevent unauthorised access; and a forensic extraction and hashing record that ties the final courtroom exhibit back to the originally seized item through an unbroken evidentiary thread.
Failure at any link in this chain creates an opportunity for the opposing party to challenge the reliability of the evidence, even where a facially compliant Section 63 certificate has been furnished. Courts have observed that mere awareness on the part of an investigating officer that a certificate is required does not cure an actual lapse in obtaining it or in maintaining a coherent custody trail; the substantive requirement must in fact be satisfied, not merely acknowledged.[9]
Judicial Treatment of Custody Gaps
Indian courts, drawing on a long line of authority developed in the context of both physical and electronic evidence, have generally distinguished between minor procedural irregularities, which affect weight but not admissibility, and substantive breaks in custody that raise a genuine possibility of tampering, which may warrant exclusion or, at minimum, a sharply diminished evidentiary value. Where CCTV footage, DVR recordings or mobile device data is seized by investigating agencies, courts increasingly expect a documented seizure memo, an extraction memo recording how and when the data was copied, identification of the storage medium used for the copy, and a hash report generated at the earliest practicable stage.
In cases involving cloud-stored data or records that pass through the servers of intermediaries such as telecom operators or social media platforms, establishing chain of custody becomes considerably more complex, since custody necessarily passes through third parties before reaching either the investigating agency or the party seeking to rely upon the record. In such situations, courts have looked to certifications and records maintained by the intermediary itself, alongside hash verification at the point the record is received by the party relying upon it, to reconstruct a defensible custody trail notwithstanding the involvement of external custodians.
Practitioners are well advised to treat the chain of custody not as a standalone procedural checklist but as the factual substratum that gives the Section 63 certificate its credibility. A certificate unsupported by a coherent custody record risks being treated as a bare assertion, particularly where the opposing party raises a timely and specific objection to the mode of proof, which, consistent with settled practice, should ordinarily be raised at the earliest stage of the trial rather than reserved for appeal.
Challenges and Emerging Issues
Several practical difficulties continue to attend the operation of Sections 61 to 63. First, the dual-certification requirement under Section 63(4) presupposes ready access to a qualified expert, yet the capacity of government forensic laboratories remains limited relative to the volume of digital evidence generated in contemporary litigation, creating delays that can compromise both timely investigation and the fairness of trial.
Second, uncertainty persists regarding whether the hash value referenced in the certificate must pertain to the original source medium or to the copy tendered in court, a distinction with real evidentiary consequences where the original device is no longer available for independent verification. Third, the treatment of data that passes through multiple intermediaries before reaching the party relying upon it, for instance a document converted from one format to another in the course of cloud storage or transmission, raises fresh questions as to how evidentiary integrity is to be demonstrated across each stage of that chain.
Fourth, the relationship between Section 61 and Section 63 continues to generate interpretive debate: whether Section 61 merely reaffirms in principle that electronic records are not inadmissible per se, leaving the special mode of proof under Section 63 fully intact for computer output tendered without a witness, or whether it works a more substantial liberalisation permitting proof of electronic records by any mode recognised for documents generally, including oral testimony of a person with direct knowledge, without invariable recourse to a Section 63 certificate. The latter reading finds support in the proposition that Section 63(4) certification is a facilitative, optional mode of proof rather than the exclusive gateway, available to a party who wishes to avoid producing a witness, but not a mandatory precondition where direct oral evidence is instead adduced.
Until this question receives authoritative resolution from the higher judiciary under the BSA regime itself, prudent practice counsels compliance with both limbs wherever feasible: securing a properly executed Section 63 certificate supported by rigorous forensic imaging and hash verification, while also preserving the availability of a competent witness who can speak to the creation and custody of the record, so that the evidence remains resilient whichever interpretive approach a given court ultimately adopts.
Conclusion
Section 61 of the Bharatiya Sakshya Adhiniyam, 2023 marks a deliberate legislative affirmation that electronic and digital records are not evidentiary outsiders; they stand on the same footing as any other document, subject always to the specific mode of proof prescribed by Section 63. The provision should be understood not as displacing the certification regime but as removing any residual doubt that electronic material can, in principle, ground a finding of fact in the same manner as conventional documentary evidence.
In practical terms, the admissibility of electronic evidence continues to rest on three interdependent pillars examined in this paper: rigorous compliance with the statutory certificate requirements under Section 63(4), including accurate identification of the certifying official and, where necessary, an independent expert; adherence to sound forensic imaging standards, particularly write-blocked bit-stream acquisition and contemporaneous cryptographic hash verification; and the maintenance of a coherent, documented chain of custody linking the original source to the evidence ultimately placed before the court.
As digital evidence becomes increasingly central to Indian litigation, the challenge facing courts, investigating agencies and practitioners alike is no longer whether such evidence should be admitted, but how its reliability can be consistently assured within the practical constraints of forensic infrastructure presently available in India. A disciplined, well-documented approach to certification, imaging and custody remains the surest safeguard against both wrongful exclusion of genuine evidence and the wrongful admission of material whose integrity cannot be trusted.
[1]The Bharatiya Sakshya Adhiniyam, 2023 (Act 47 of 2023) received Presidential assent on 25 December 2023 and was brought into force with effect from 1 July 2024 along with the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023.
[2]Bharatiya Sakshya Adhiniyam, 2023, s. 61, Chapter V, Part III (“Of Documentary Evidence”).
[3]See analyses of Section 61 as a legislative response intended to restore flexibility in the proof of electronic records following the strict interpretive approach previously adopted by the Supreme Court.
[4]Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473.
[5]Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.
[6]See, e.g., Dell International Services India Private Limited v. Adeel Feroze, where the Delhi High Court declined to treat uncertified WhatsApp printouts as admissible electronic evidence in the absence of a Section 63 BSA certificate.
[7]SHA-256, part of the SHA-2 family of cryptographic hash functions, produces a 256-bit (64-character hexadecimal) digest and is the algorithm most commonly recommended in Indian forensic and certification practice, alongside MD5, which remains in limited use though considered less collision-resistant.
[8]Commentary has flagged the insufficiency of Forensic Science Laboratory capacity across India as a structural constraint on the consistent, timely availability of expert-certified electronic evidence under Section 63(4).
[9]See judicial observations, including in Chandrabhan Sudam Sanap v. State of Maharashtra, where deficiencies in the investigating officer’s compliance with certification requirements were treated as legally significant despite the officer’s awareness of the requirement.