Electronic Evidence Is Admitted. Now What? How Indian Courts Test Authenticity and Catch Tampering
Summary: Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 governs the admissibility of electronic records, but satisfying the statutory certificate requirement does not by itself establish their authenticity, integrity or evidentiary weight. The Supreme Court rulings in Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473, and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, establish the importance of statutory certification for admissibility of computer output, but admission does not automatically determine the weight ultimately given to the evidence. Its reliability may still be tested by examining when and how the record was extracted, whether a cryptographic hash value was generated contemporaneously, and whether an uninterrupted chain of custody can be demonstrated. A hash value can establish that a digital file remained unchanged between identified checkpoints, but cannot establish its origin or integrity before the first hash was recorded; therefore, a hash generated only after a dispute arises may leave an important evidentiary gap. Similarly, uncontrolled copying, access by multiple persons and undocumented transfers may provide grounds to question integrity even without direct proof of tampering. The device custodian and expert signing the Section 63(4) certificate may also be cross-examined regarding extraction methodology, forensic safeguards, hash generation and their firsthand knowledge. Businesses should therefore treat certification as only one component of electronic-evidence management and adopt contemporaneous hashing, forensic extraction, secure preservation and documented custody protocols so that digital evidence is not merely admissible but remains credible when its authenticity and reliability are tested at trial.
Introduction
A logistics company produces CCTV footage showing a warehouse fire started after hours, when only one contractor’s team was on site. The footage is admitted. A Section 63(4) certificate is on record, signed by the security manager and an independent expert. The opposing side does not challenge the certificate. Instead, at trial, their lawyer asks a different question: can you show me the hash value recorded at the moment this footage was extracted, and can you show me who had access to the storage device between the night of the fire and the day it reached the forensic lab?

The company has no answer. The footage is technically admissible. It is also, at that point, close to worthless.
This is a distinction that gets lost in most discussions of electronic evidence in India, including in the broader conversation around Section 63 of the Bharatiya Sakshya Adhiniyam, 2023. Admissibility and reliability are not the same question. A certificate gets a record through the door. What happens after that, whether the judge actually believes the record reflects what it claims to reflect, is a separate fight, and it is the fight that decides most disputes involving digital evidence.
Admissibility Gets You In the Door. It Does Not Win the Case
Section 63(1) of the Bharatiya Sakshya Adhiniyam, 2023 allows a computer output, such as a printout, a chat export, or a CCTV recording, to be treated as a document and admitted without producing the original device, provided the conditions in the section are met. Section 63(4) requires a certificate, now signed by both the person responsible for the device and an expert, to accompany that record.
Getting past this threshold answers one question: is the court allowed to look at this record at all. It does not answer a second, more consequential question: how much weight should the court give it once it has looked. The Supreme Court’s decisions in Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473, and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, settled that the certificate is mandatory for admissibility. Neither judgment says that a properly certified record is automatically believed. Admissibility is a gate. Reliability is what happens on the other side of it.
For businesses, this distinction matters more than the certificate itself. A company that treats the Section 63(4) certificate as the finish line often discovers, too late, that the opposing side’s real strategy was never to keep the evidence out. It was to let it in and then dismantle it.
What a Hash Value Actually Proves
A hash value is a fixed-length string generated by running a file through a cryptographic algorithm, commonly SHA-256 today. Change even a single character in the underlying file and the hash value changes completely. Two identical hash values, calculated at two different points in time, are strong evidence that the file has not been altered between those two points.
That is the entire function of a hash value. It proves integrity between two checkpoints. It does not prove where the file came from, who created it, or whether it was accurate in the first place. A tampered file, hashed correctly and consistently after the tampering, will still produce matching hash values for every check performed afterward. The hash only tells you that nothing changed after the point at which it was first recorded, which is precisely why the timing of that first recording matters so much.
This is the gap that catches businesses off guard. A hash value calculated three weeks after an incident, once litigation looked likely, proves the file has not changed in those three weeks. It says nothing about what happened in the gap between the original event and the moment someone finally thought to calculate a hash. Indian courts, including High Courts dealing with digital evidence, have increasingly treated a contemporaneous hash value, one recorded at or near the point of extraction, as far more persuasive than one calculated after the fact. A late hash value is not worthless, but it invites exactly the question a cross-examining lawyer wants to ask: why did nobody hash this earlier, and what happened before you did?
Chain of Custody: Where the Gaps Actually Appear
Chain of custody is simply the documented record of who held a piece of evidence, when, and what they did with it, from the moment it was created or seized to the moment it is placed before the court. For electronic evidence, this typically runs from the original device, through extraction, through storage, to the forensic lab, and finally into the certificate itself.
In practice, the break rarely happens where people expect. It is not usually a dramatic act of tampering. It is an unexplained gap.
- A device seized at one time but logged into evidence storage hours later, with no record of where it was in between.
- A copy made on an ordinary office computer rather than a forensically sound workstation, with no write-blocking software used.
- Multiple copies of the same file circulating internally before anyone thought to record a hash value or note who had access.
- A storage device handed between departments, or between a company and its outside counsel, without a signed log of the handover.
None of these gaps prove tampering. What they prove is opportunity. And under Indian evidentiary practice, an unexplained gap in custody is often enough for the opposing side to argue that the record cannot be relied upon, even where there is no direct proof that anything was actually altered. The burden then shifts to the party relying on the evidence to explain the gap, and a business that cannot produce a clean answer is in a considerably weaker position than one that simply admits it should have documented the handover better.
Cross-Examining the Certifying Expert
The dual certificate under Section 63(4), one from the device custodian and one from the expert, does more than satisfy a paperwork requirement. It also identifies two people who can be called and questioned about exactly how the record was handled.
Once a party relies on a Section 63(4) certificate, the certifying expert becomes, in effect, a witness whose evidence can be tested. Questions in cross-examination typically probe the extraction method used, whether a forensically sound copying process was followed, whether the hash value was recorded at the time of extraction or reconstructed afterward, and whether the expert had firsthand knowledge of the device’s condition or is simply repeating what someone else told them.
An expert who prepared the certificate carefully, with contemporaneous documentation and a clear record of each step, tends to hold up well under this kind of questioning. An expert who signed off on a certificate prepared largely by someone else, based on a hash value calculated weeks after the fact, is far more exposed. This is one reason engaging the forensic expert early, at the point of extraction rather than once litigation has already started, makes a material difference to how the evidence survives scrutiny later.
Common Mistakes That Undermine Otherwise Genuine Evidence
- Treating the Section 63(4) certificate as the end of the process rather than the beginning of a record that may still be challenged on reliability grounds.
- Calculating a hash value only after a dispute has already begun, rather than at the point of extraction.
- Allowing a device or storage medium to pass through multiple hands without a signed log of each handover.
- Using a general-purpose computer or untrained staff member to make a working copy of digital evidence, instead of a forensically sound process.
- Assuming that because a certificate was filed and accepted by the court, the record cannot be challenged further at trial.
Practical Steps for Businesses
- Build a standard evidence-handling protocol before a dispute arises, not after, covering seizure, storage, extraction and hash recording.
- Record the hash value the moment a record is extracted, and store that value separately from the file itself so it cannot be altered alongside it.
- Maintain a written custody log for any device or storage medium likely to become evidence, noting every person who accessed it and when.
- Engage a forensic expert at the point of extraction rather than waiting until litigation is underway, so the certificate reflects firsthand knowledge rather than a reconstruction.
- Treat the Section 63(4) certificate as one part of a larger evidentiary record, not a substitute for a documented chain of custody.
Conclusion
Getting electronic evidence admitted under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 is a procedural threshold, and a necessary one. But the certificate that gets a WhatsApp chat, an email, or a piece of CCTV footage into the courtroom does not decide whether the judge trusts what that record shows. That question turns on whether the hash value was recorded early enough to mean something, and whether the custody trail behind the record has no gaps a skilled opposing lawyer can turn into doubt. Businesses that build evidence-handling discipline into their everyday practice, long before any dispute is on the horizon, are the ones whose electronic records still carry weight by the time a judge is actually deciding whether to believe them.
******
Disclaimer: This article is intended for general legal awareness and should not be construed as legal advice. The reliability and evidentiary weight of electronic evidence depends on the facts of each case and the applicable law.





