Authentication of e-documents.

1. Meaning of Authentication of E-Documents

Authentication of e-documents means establishing that an electronic document is genuine, reliable, has not been improperly altered, and is connected with the person or system from which it is claimed to originate.

Examples include:

  • E-mails
  • WhatsApp messages
  • Digital contracts
  • PDF documents
  • Electronic invoices
  • Computer-generated records
  • CCTV footage
  • Call Detail Records (CDRs)
  • Bank transaction records
  • Digital photographs and videos
  • Electronic signatures
  • Documents stored on cloud servers

Authentication is especially important because electronic records can potentially be copied, modified, deleted or manipulated without obvious physical traces.

Under the present Indian evidence framework, the Bharatiya Sakshya Adhiniyam, 2023 (BSA) has replaced the Indian Evidence Act for proceedings under the new law. It came into force on 1 July 2024. The BSA specifically deals with electronic and digital records in Sections 61–63 and electronic signatures in Section 66.

2. Legal Framework for Authentication

A. Information Technology Act, 2000

The Information Technology Act, 2000 provides the basic legal framework for:

  • electronic records;
  • electronic signatures;
  • digital signatures;
  • authentication of electronic records;
  • certifying authorities; and
  • secure electronic records and signatures.

The fundamental principle is that an electronic document should not be denied legal recognition merely because it exists in electronic form.

3. Bharatiya Sakshya Adhiniyam, 2023

The BSA has significantly modernised the law relating to electronic evidence.

Important provisions include:

Section 61 — Electronic or Digital Record

An electronic or digital record cannot be denied admissibility merely because it is electronic or digital.

This establishes the basic principle of technological neutrality.

Section 62 — Special provisions relating to electronic records

Section 62 provides that the contents of electronic records are proved according to Section 63.

Section 63 — Admissibility of electronic records

This is one of the most important provisions concerning authentication.

Where electronic evidence is produced as qualifying secondary electronic evidence, the statutory requirements regarding its production and certification have to be satisfied.

The present framework requires a certificate containing prescribed information, including information concerning the electronic record and its hash value.

4. What is a Hash Value?

A hash value is essentially a digital fingerprint of an electronic file.

For example:

Original PDF → Hash calculation → Unique hash value

If even a small part of the PDF is changed, its hash value will ordinarily change.

Therefore, hash values can assist the court in determining whether an electronic record presented as evidence is the same record that was originally preserved.

The Supreme Court in 2026 recognised the importance of hash values for verifying the authenticity and integrity of electronic data.

5. Electronic Signature and Authentication

Section 66 of the BSA deals specifically with proof of an electronic signature.

Where an electronic signature is alleged to have been affixed by a subscriber, its attribution to that subscriber ordinarily has to be proved, except where the law gives the relevant presumption for a secure electronic signature.

Thus, authentication may involve establishing:

  1. Who created the document?
  2. Who signed it?
  3. Whether the signature belongs to that person?
  4. Whether the document was subsequently altered?
  5. Whether the electronic system was functioning properly?
  6. Whether the record was maintained in ordinary course?
  7. Whether the chain of custody is reliable?

6. Primary and Secondary Electronic Evidence

A major distinction must be made between primary electronic evidence and electronic evidence produced through copies/outputs.

The BSA expressly recognises electronic or digital records as primary evidence in several circumstances.

For example, where an electronic record is stored in multiple files or storage spaces, the statutory provisions can treat those stored records as primary evidence.

This distinction is important because the authentication requirements can differ depending upon how the electronic evidence is produced.

7. Authentication Through Metadata

Metadata means information about an electronic document.

For example, an e-mail may contain:

  • sender information;
  • recipient information;
  • date and time;
  • server information;
  • IP information;
  • message ID;
  • attachment information.

A photograph may contain:

  • creation date;
  • device information;
  • location information;
  • file modification information.

Metadata can therefore help establish the origin, creation, transmission and modification history of an electronic document.

However, metadata should not automatically be treated as conclusive proof. Its reliability must be assessed along with the other evidence.

8. Authentication Through Digital Forensics

Digital forensic examination may be used where authenticity is disputed.

An expert may examine:

  • computer systems;
  • mobile phones;
  • hard drives;
  • servers;
  • cloud storage;
  • CCTV systems;
  • e-mail servers;
  • messaging applications.

The expert may determine whether:

  • a file was modified;
  • deleted material can be recovered;
  • timestamps are consistent;
  • a device contains the relevant data;
  • the electronic record has been manipulated.

The BSA also recognises the relevance of the opinion of an Examiner of Electronic Evidence in appropriate cases.

9. Authentication Through Certificate

Under the earlier Indian Evidence Act, Section 65B was central to proving many forms of electronic evidence.

Under the current BSA, Section 63 performs the corresponding function.

The certificate mechanism is intended to establish matters such as:

  • identification of the electronic record;
  • manner in which it was produced;
  • relevant device/system;
  • reliability of the computer system;
  • integrity of the electronic record;
  • hash value;
  • required certification.

The Supreme Court in 2026 upheld the constitutional validity of the Section 63(4) certificate requirement and specifically recognised the importance of hash values and expert certification.

10. Chain of Custody

Authentication also depends upon chain of custody.

Chain of custody means maintaining a documented history of:

Who collected the electronic record → Who handled it → Where it was stored → Who examined it → How it was produced before the court

For example, if CCTV footage is relied upon:

  1. CCTV system is identified.
  2. Original recording is preserved.
  3. Recording is copied using an appropriate forensic process.
  4. Hash value is generated where appropriate.
  5. Storage device is sealed/preserved.
  6. Persons handling the evidence are recorded.
  7. Certificate and supporting documentation are prepared.
  8. Evidence is produced before the court.

A broken or unexplained chain of custody may create doubts about authenticity.

11. Authentication of E-Mail

Suppose an employee sends an e-mail containing confidential information.

To authenticate it, the court may consider:

  • e-mail address;
  • sender and recipient;
  • server records;
  • message headers;
  • timestamps;
  • contents;
  • attachments;
  • surrounding correspondence;
  • witness testimony;
  • electronic device;
  • forensic evidence.

Simply producing a printed copy of an alleged e-mail may not always be sufficient when its authenticity is specifically disputed.

12. Authentication of WhatsApp Messages

WhatsApp messages are increasingly used in litigation.

Authentication may involve:

  • mobile phone containing the conversation;
  • identity of the account holder;
  • phone number;
  • device information;
  • message history;
  • screenshots;
  • original electronic record;
  • relevant certificate requirements;
  • forensic examination where necessary.

A screenshot alone can be vulnerable to challenge because screenshots can potentially be edited or fabricated.

Therefore, where authenticity is seriously disputed, the original device or appropriate electronic record and supporting evidence become particularly important.

13. Authentication of CCTV Footage

CCTV footage can be authenticated by establishing:

  • identity of the CCTV system;
  • location of camera;
  • functioning of the equipment;
  • date and time settings;
  • original storage medium;
  • manner of extraction;
  • continuity of custody;
  • absence of unexplained editing;
  • certificate where legally required.

The Supreme Court has repeatedly emphasised the importance of safeguards because electronic evidence is susceptible to alteration and manipulation.

14. Authentication of Digital Contracts

Digital contracts can be authenticated through:

  • electronic signatures;
  • digital signatures;
  • authentication certificates;
  • audit logs;
  • e-mail correspondence;
  • IP/device information;
  • timestamps;
  • access logs;
  • identity verification;
  • certificate from the relevant electronic-signature service.

A properly authenticated electronic signature can provide considerably stronger evidence of execution than an ordinary scanned signature.

15. Presumption Regarding Electronic Signature Certificates

Section 87 of the BSA provides a presumption concerning information contained in an Electronic Signature Certificate, subject to the statutory conditions.

This illustrates an important evidentiary principle:

The law sometimes allows a court to presume authenticity rather than requiring every element to be independently proved from the beginning.

However, such presumptions are generally rebuttable.

16. Six Important Case Laws

1. State (NCT of Delhi) v. Navjot Sandhu @ Afsan Guru

(2005) 11 SCC 600

This was an important early Supreme Court decision concerning electronic evidence.

The Court considered electronic records including call records and held that electronic evidence could be proved under the existing evidentiary framework.

The judgment was subsequently reconsidered in light of the more specific interpretation of Section 65B.

Importance

It represents the early judicial approach to electronic records before the Supreme Court adopted a stricter approach in Anvar P.V.

17. Anvar P.V. v. P.K. Basheer

(2014) 10 SCC 473

This is one of the most important Indian cases concerning electronic evidence.

The Supreme Court held that secondary electronic evidence had to satisfy the special requirements of Section 65B of the Indian Evidence Act.

The Court emphasised that electronic records are particularly susceptible to:

  • alteration;
  • manipulation;
  • deletion;
  • transposition; and
  • other forms of tampering.

Therefore, statutory safeguards were important to establish the source and authenticity of electronic records.

Importance

This case established the foundation for the modern Indian law of electronic evidence.

18. Tomaso Bruno v. State of Uttar Pradesh

(2015) 7 SCC 178

The Supreme Court discussed the importance of electronic evidence and technological material such as CCTV.

The decision emphasised that modern investigative techniques and electronic evidence can be highly important in discovering the truth.

Importance

The case demonstrates that courts should not ignore technologically available evidence when it is relevant to determining the facts.

However, subsequent jurisprudence clarified the specific requirements governing admissibility of electronic evidence.

19. Sonu @ Amar v. State of Haryana

(2017) 8 SCC 570

The Supreme Court considered objections concerning the certificate requirement for electronic evidence.

The Court discussed the procedural character of the certificate requirement and the consequences of failing to object at the appropriate stage.

Importance

The case demonstrates that timing of objections can become important in electronic-evidence disputes.

20. Shafhi Mohammad v. State of Himachal Pradesh

(2018) 2 SCC 801

The Supreme Court considered situations where a party may not be in possession or control of the electronic device.

The Court adopted a relatively flexible approach regarding the certificate requirement.

However, this judgment was subsequently overruled on this point by the larger Bench in Arjun Panditrao Khotkar.

Importance

It is important historically because it illustrates the evolution of Indian electronic-evidence law.

21. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal

(2020) 7 SCC 1

This is a landmark three-Judge Bench decision.

The Supreme Court reaffirmed Anvar P.V. and clarified the law concerning Section 65B.

It held, among other things, that where electronic evidence is produced as secondary evidence through a computer system, the statutory certificate requirement applies.

The Court also clarified that where the original electronic record/device itself is produced in an appropriate case, the certificate requirement does not operate in the same manner as it does for secondary electronic evidence.

Importance

This became the leading authority on the admissibility and authentication of electronic evidence under the old Evidence Act.

22. Recent Supreme Court Position — 2026

A significant recent development concerns Section 63(4) of the Bharatiya Sakshya Adhiniyam, 2023.

In Pune Bar Association v. Union of India, the Supreme Court considered a constitutional challenge to the certificate requirement under Section 63(4).

The challenge concerned, among other things:

  • certificate requirements;
  • hash values;
  • expert certification; and
  • practical burdens on litigants.

The Supreme Court upheld the constitutional validity of Section 63(4). It recognised that the hash value functions as a form of electronic fingerprint and helps establish authenticity and integrity.

This is particularly important because it confirms that authentication under the current BSA framework is not merely about producing a printout; integrity and provenance of electronic records remain central concerns.

23. Important Principles Emerging from the Cases

The case law establishes several broad principles:

1. Electronic evidence is legally recognised

An electronic document can constitute legally relevant evidence.

2. Authenticity must be established

The court must be satisfied that the record is what it is claimed to be.

3. Source is important

The court may examine where the electronic record came from and how it was obtained.

4. Integrity is important

Evidence should be protected against alteration or manipulation.

5. Certificate requirements matter

Where the statutory conditions for secondary electronic evidence apply, the prescribed certificate is important.

6. Original electronic records receive different treatment

The distinction between the original electronic record/device and secondary copies is legally significant.

7. Hash values strengthen authentication

A hash can help demonstrate that an electronic record has remained unchanged.

8. Expert evidence may be relevant

Technical questions concerning electronic records can be supported by competent electronic-evidence experts.

24. Practical Authentication Checklist

Before relying upon an e-document in litigation, an organisation should ideally maintain:

RequirementPurpose
Original electronic recordEstablishes source
Device/server informationEstablishes origin
MetadataHelps establish creation/transmission
Hash valueHelps establish integrity
Electronic signatureEstablishes execution/authorship
Audit logsEstablishes activity history
Access logsEstablishes who accessed the record
Chain of custodyPrevents unexplained handling
CertificateSatisfies statutory evidentiary requirements where applicable
Expert examinationAddresses technical disputes
Backup copiesProtects against accidental loss

25. Authentication vs Admissibility

These concepts should not be confused.

Authentication

Question:

Is this electronic document genuine and what it purports to be?

Admissibility

Question:

Can the court legally receive and consider this electronic record as evidence?

Relevance

Question:

Does this electronic record actually relate to the issue before the court?

Therefore, an electronic document may be:

  • relevant but not properly authenticated;
  • authentic but legally inadmissible in a particular form;
  • admissible but of weak evidentiary value.

26. Example

Suppose an employer alleges that an employee approved a fraudulent transaction through an e-mail.

The employer produces a printed e-mail.

The employee says:

"I never sent this e-mail."

The court may need to consider:

  1. Was the e-mail account controlled by the employee?
  2. What do the original server records show?
  3. Are the headers genuine?
  4. Is there metadata?
  5. What device generated the e-mail?
  6. Are there corresponding audit logs?
  7. Was the electronic record preserved properly?
  8. Is the certificate required under Section 63?
  9. Does the certificate contain the required information?
  10. Is there evidence of alteration?
  11. Does the surrounding correspondence support the e-mail?
  12. Is expert evidence necessary?

Only after considering these matters can the court properly assess the authenticity and evidentiary value of the e-mail.

27. Conclusion

Authentication of e-documents is the process of establishing the identity, origin, integrity and reliability of an electronic record.

Indian law has evolved considerably—from the earlier framework under Sections 65A and 65B of the Indian Evidence Act to the present framework under the Bharatiya Sakshya Adhiniyam, 2023.

The most important principles are:

Identify the source → preserve the original → establish integrity → maintain chain of custody → satisfy statutory certification requirements → prove electronic signatures where applicable → use expert evidence when necessary.

The landmark decisions of Navjot Sandhu, Anvar P.V., Tomaso Bruno, Sonu, Shafhi Mohammad and Arjun Panditrao Khotkar, together with the recent Pune Bar Association decision, show the development of Indian jurisprudence from relatively flexible treatment of electronic evidence to a structured framework focused on authenticity, integrity and reliability.

LEAVE A COMMENT