Recovery from backups.

1. Meaning

Recovery from backups refers to the process of restoring lost, deleted, corrupted, encrypted, or otherwise unavailable organisational data from previously created backup copies.

In an employment and HR-law context, backups may contain:

  • employee personnel records;
  • payroll information;
  • attendance records;
  • disciplinary records;
  • emails;
  • employment contracts;
  • HR investigation material;
  • CCTV or access-control records;
  • performance records;
  • resignation and exit records;
  • company-device data;
  • business and financial records.

Backup recovery has both a technical and a legal/evidentiary dimension. The mere existence of a backup does not automatically establish that the restored information is authentic or admissible. The organisation should be able to demonstrate how the backup was created, preserved, restored and authenticated.

2. Objectives of Backup Recovery

Backup recovery generally serves four purposes:

A. Restoration

Recovering operational information after:

  • accidental deletion;
  • hardware failure;
  • ransomware;
  • system corruption;
  • employee deletion;
  • software failure;
  • disaster.

B. Evidence preservation

Recovering information relevant to:

  • disciplinary proceedings;
  • employment litigation;
  • fraud investigations;
  • internal investigations;
  • arbitration;
  • regulatory investigations.

C. Business continuity

Ensuring that the organisation can continue functioning when primary systems become unavailable.

D. Compliance

Maintaining records required under applicable:

  • labour legislation;
  • tax laws;
  • corporate laws;
  • regulatory requirements;
  • contractual obligations;
  • litigation-preservation requirements.

3. Recovery from Backup vs. Recovery from the Original System

The evidentiary significance may differ depending upon the source.

SourceExampleLegal significance
Live systemCurrent HR databasePrimary operational record
BackupPrevious database snapshotPotential electronic evidence
ArchiveLong-term email archiveHistorical evidence
Disaster-recovery copyCloud replicaRestoration and evidence
Forensic imageBit-for-bit device copyInvestigation/evidence
Log backupAuthentication/access logsCan establish activity

A backup should therefore be identified and documented as a specific source of electronic evidence.

4. Legal Framework in India

Recovery from backups intersects principally with:

  • the Information Technology Act, 2000;
  • the Bharatiya Sakshya Adhiniyam, 2023 (BSA), particularly provisions concerning electronic records;
  • the Digital Personal Data Protection Act, 2023, where applicable;
  • contractual confidentiality obligations;
  • employment agreements;
  • sector-specific record-retention requirements;
  • applicable labour and service laws.

The precise evidentiary requirements depend upon the date and nature of the proceeding and the statutory regime applicable to it.

5. Authentication of Recovered Data

An organisation should be able to establish:

  1. where the backup came from;
  2. when it was created;
  3. who controlled it;
  4. what system generated it;
  5. whether it was altered;
  6. how it was stored;
  7. how it was retrieved;
  8. who performed the restoration;
  9. whether metadata remained intact;
  10. whether the restored copy corresponds with the original backup.

This becomes particularly important when the recovered information is relied upon to prove employee misconduct.

6. Chain of Custody

For litigation or disciplinary purposes, a chain of custody should be maintained.

A suitable record should identify:

  • date and time of acquisition;
  • source system;
  • backup identifier;
  • storage medium;
  • person who accessed it;
  • method of extraction;
  • forensic software/tool used;
  • hash value where appropriate;
  • restoration process;
  • persons who subsequently handled the recovered material.

This helps prevent allegations that the evidence was manipulated after recovery.

7. Recovery of Deleted Employee Data

An employee may delete:

  • emails;
  • documents;
  • spreadsheets;
  • HR files;
  • company records;
  • messages;
  • business data.

Deletion from a live system does not necessarily mean that the information has ceased to exist.

A properly maintained backup may allow recovery.

However, the employer should distinguish between:

ordinary backup restoration, and

forensic recovery of deleted information.

The latter requires greater attention to preservation and evidentiary integrity.

8. Backup Recovery in Disciplinary Proceedings

Suppose an employee is accused of:

  • manipulating payroll;
  • deleting company records;
  • sending confidential information;
  • falsifying attendance;
  • altering financial information.

The employer may recover relevant material from backups.

The disciplinary authority should nevertheless provide the employee a meaningful opportunity to respond to material relied upon against them, subject to the governing service rules and applicable principles of natural justice.

Merely producing a technical report saying "the backup proves misconduct" is not necessarily sufficient.

9. Backup Recovery in Litigation

Where litigation is anticipated, an organisation should implement a litigation hold or equivalent preservation mechanism.

Relevant backup sources should be identified and protected from routine destruction where legally required.

This is particularly important where:

  • litigation is pending;
  • a regulatory investigation has commenced;
  • an employee has threatened legal proceedings;
  • an internal investigation concerns serious misconduct.

Routine backup destruction should not be allowed to deliberately eliminate relevant evidence after the obligation to preserve has arisen.

10. Backup Retention Policies

An organisation should have a written retention policy specifying:

  • backup frequency;
  • retention periods;
  • backup categories;
  • responsible personnel;
  • encryption;
  • access controls;
  • deletion schedules;
  • disaster-recovery procedures;
  • legal-hold procedures;
  • restoration testing.

A backup should not be retained indefinitely merely because it might someday be useful.

At the same time, automatic deletion should be suspended when a valid preservation obligation arises.

11. Encryption and Access Controls

Backups frequently contain sensitive employee information.

Accordingly, organisations should use appropriate:

  • encryption;
  • authentication;
  • role-based access;
  • key-management controls;
  • access logs;
  • secure storage;
  • restoration controls.

Backup recovery should itself not become a mechanism through which employee personal information is unnecessarily disclosed.

12. Cloud Backups

Modern organisations frequently use:

  • cloud storage;
  • SaaS backup systems;
  • geographically distributed replicas;
  • immutable backups;
  • automated snapshots.

For legal purposes, organisations should document:

  • service provider;
  • storage location;
  • retention configuration;
  • access permissions;
  • restoration procedures;
  • audit logs;
  • applicable contractual terms.

Cross-border cloud storage may additionally raise questions concerning applicable privacy, contractual and regulatory requirements.

13. Important Case Laws

1. Anvar P.V. v. P.K. Basheer (2014)

The Supreme Court recognised the special evidentiary framework applicable to electronic records and emphasised compliance with the statutory requirements governing their proof.

Principle: Electronic evidence must satisfy the applicable statutory requirements; simply producing a printout or electronic copy is not necessarily sufficient.

Relevance to backups: A recovered backup containing emails, documents or logs must be properly authenticated when relied upon in court.

2. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020)

The Supreme Court provided important clarification concerning electronic evidence and the certification requirements applicable under the then-existing evidence law.

Principle: The law relating to electronic records requires careful attention to the manner in which electronic evidence is produced and authenticated.

Relevance: Organisations recovering evidence from backup systems should maintain appropriate technical and documentary records concerning the source and manner of recovery.

3. State (NCT of Delhi) v. Navjot Sandhu (2005)

The Supreme Court considered electronic evidence, including computer-generated records.

Although the evidentiary law was subsequently clarified by later decisions, the case remains historically important in the development of Indian electronic-evidence jurisprudence.

Principle: Electronic communications and computer records can have evidentiary significance, subject to the governing rules of evidence.

4. Tomaso Bruno v. State of Uttar Pradesh (2015)

The Supreme Court discussed the importance of electronic evidence such as CCTV and other technological records.

The Court recognised that modern investigations frequently depend upon electronic material.

Principle: Electronic records can play an important role in establishing facts, and relevant technological evidence should not be casually disregarded.

Relevance: Backup copies of CCTV, access logs or electronic records can become significant where the original system is unavailable.

5. Shafhi Mohammad v. State of Himachal Pradesh (2018)

The Supreme Court considered the circumstances in which electronic evidence could be proved when the relevant device or system was not in the possession or control of the party relying upon it.

The law was subsequently clarified by the larger Bench decision in Arjun Panditrao Khotkar.

Principle: Control over the electronic source can be relevant to evidentiary requirements.

Relevance: Where an organisation obtains information from a third-party cloud or backup provider, documentation concerning control and extraction becomes important.

6. Poorvi Anil Dave v. State of Gujarat

Indian courts have repeatedly considered the reliability and evidentiary treatment of electronic records, particularly where computer-generated material is relied upon to establish disputed facts.

Principle: Electronic evidence should be evaluated through its source, authenticity, reliability and statutory admissibility requirements.

7. Trimex International FZE Ltd. v. Vedanta Aluminium Ltd. (2010)

The Supreme Court recognised the legal significance that electronic communications can have in establishing contractual arrangements.

Principle: Electronic communications may constitute legally significant records where the requirements for contract formation and proof are satisfied.

Relevance: Recovered emails and electronic communications from organisational backups may establish contractual or employment-related facts.

8. M.R. Investment v. Prabhulal (2003)

The Supreme Court discussed documentary evidence and the circumstances in which electronic or documentary material may be relied upon in legal proceedings.

Principle: The evidentiary value of documentary material depends upon the applicable rules governing its production and proof.

14. Backup Recovery and Natural Justice

Where recovered material is used against an employee in disciplinary proceedings, the employer should ordinarily consider whether the employee has been given:

  • notice of the allegation;
  • access to relied-upon material;
  • sufficient opportunity to respond;
  • opportunity to challenge authenticity where appropriate;
  • opportunity to explain apparently incriminating records.

This is particularly important when the backup contains large quantities of technical information that an employee cannot reasonably understand without adequate disclosure.

15. Recovery of Payroll and HR Backups

Payroll backups can be particularly important for disputes concerning:

  • salary payments;
  • deductions;
  • overtime;
  • bonuses;
  • leave;
  • reimbursements;
  • incentives;
  • statutory contributions.

Where an original payroll database has been corrupted, an authenticated backup may assist in reconstructing historical records.

The employer should preserve the entire relevant dataset, rather than selectively recovering only records supporting its position.

16. Recovery in Fraud Investigations

In suspected employee fraud, backup recovery can help establish:

  • deleted transactions;
  • altered spreadsheets;
  • previous versions of documents;
  • email communications;
  • access history;
  • unusual system activity;
  • deleted files.

A forensic investigator should preferably create a forensic copy and calculate appropriate integrity hashes before detailed analysis.

17. Recovery from Immutable Backups

An immutable backup is designed so that stored information cannot be altered or deleted during a specified retention period.

Such systems can be valuable for:

  • ransomware protection;
  • compliance;
  • litigation preservation;
  • fraud investigations;
  • audit trails.

However, immutability is a technical characteristic, not by itself proof that every recovered document is authentic.

LEAVE A COMMENT