Introduction
In modern criminal trials, physical locks and wax seals are no longer sufficient to guarantee the integrity of evidence. As investigations increasingly rely on smartphones, hard drives, closed-circuit television (CCTV) DVRs, and cloud storage, the battleground for the prosecution has shifted entirely to the digital arena.
Under the Bharatiya Sakshya Adhiniyam (BSA), 2023, which has superseded the Indian Evidence Act (IEA), 1872, the rules governing digital evidence have become considerably more demanding. While the landmark provision Section 63 BSA serves as the gateway for admitting electronic records, a digital exhibit is legally dead on arrival if the Investigating Officer (IO) fails to protect it from remote tampering at the source or bungles the mandatory statutory certification.
The Dual Vulnerability: The Active Threat of Remote Alteration
Digital evidence is volatile, invisible, and uniquely fragile. Unlike a physical weapon, an electronic device remains dynamically tied to network architectures. If an investigator seizes a suspect’s smartphone and leaves it active on a standard cellular or Wi-Fi network, the exhibit remains vulnerable to external manipulation:
2.1. Remote Wiping
Remote Wiping: Using applications like “Find My Device” or corporate mobile device management (MDM) software, a suspect or their associate can remotely trigger a factory reset from halfway across the world, destroying every byte of evidentiary value before the phone ever reaches a laboratory.
2.2. Data Spoofing and Alteration
Data Spoofing and Alteration: Active cloud synchronization can automatically alter metadata, delete incoming WhatsApp chats, or modify files the moment the device connects to an open network tower.
To defeat these technical defenses, the preservation of the digital exhibit must begin the exact second it is discovered.
Procedural Protocol for First Responders at the Source
To ensure that a digital exhibit survives cross-examination, investigators must adhere to a strict, non-negotiable protocol at the scene of the crime or search location.
Immediate First Action
| Immediate First Action | Purpose / Action Required |
|---|---|
| 1. Isolate Immediately | Place the device in Airplane Mode or disconnect it from all networks by safely removing power (where appropriate) to prevent remote access or data alteration. |
| 2. Shield Signals | Place the device inside a Faraday Bag to block cellular, Wi-Fi, Bluetooth, GPS, and other wireless signals, thereby preserving digital evidence. |
| 3. Recover Hash Value | Generate a SHA-256 hash of the extracted digital data to verify its integrity and demonstrate that the evidence has not been altered. |
| 4. Dual Certification | Complete Parts A and B of the Schedule/Certificate to document the seizure and authenticate the digital evidence in accordance with legal requirements. |
3.1. Instant Network Isolation
If a mobile device is found unlocked, the investigator should immediately change its settings to Airplane Mode, disable Wi-Fi, Bluetooth, and Location Services, and extend the screen-timeout setting to prevent the device from locking during initial assessment. If the device is found turned off, leave it off. Attempting to power it up without a controlled environment can alter system logs and overwrite temporary files.
3.2. Physical Signal Shielding (The Faraday Principle)
Every electronic device seized must be placed immediately into a certified Faraday bag—a flexible, signal-isolating pouch lined with conductive metallic mesh that completely blocks radio frequency (RF) signals, cellular data, Wi-Fi, and satellite connections.
Field Practice Warning: If a commercial Faraday bag is unavailable, wrapping the device tightly in multiple layers of heavy-duty aluminium foil serves as an emergency alternative, though it must be transferred to a proper forensic enclosure at the earliest opportunity.
3.3. Immediate Integrity Locking via Cryptographic Hash Values
The moment the device is secured or its contents are imaged, the investigator or accompanying cyber expert must generate its cryptographic hash value utilizing algorithms like SHA-256. This hash value acts as an unalterable digital fingerprint. It must be written down on the spot in the seizure list and the Case Diary.
Mastering the Certification Landscape Under Section 63 BSA
Even if an IO preserves a device perfectly, the electronic record will be rejected by the Court unless it is introduced alongside a flawless statutory certificate. Section 63 BSA replaces the old Section 65B of the IEA, changing both the form and substance of compliance.
The most profound modification introduced by Section 63(4) BSA is the formal standardization of the certification process through The Schedule of the Act, which splits the responsibility into a structured, clear layout:
| Certificate Requirement | Target Responsibility | Key Disclosures Mandated |
|---|---|---|
| Part A: The Party | To be filled by the person producing the record (e.g., the Complainant, Bank official, or IO). | Device Make, Model, Serial Number, and unique identifiers (IMEI, MAC ID, Cloud ID). Affirmation of lawful control and normal operation of the device. Generation of the Hash Value with a explicitly stated algorithm (e.g., SHA-256). |
| Part B: The Expert | To be filled by a certified Cyber/Digital Forensic Expert accompanying the team or analyzing the medium. | Technical verification of the electronic record’s source. Independent calculation and cross-verification of the Hash Value to certify zero structural alteration. |
5. Crucial Courtroom Battlepoints: Defeating the Defense
Defense counsels frequently succeed in having electronic evidence thrown out by highlighting tiny procedural lapses. Investigators can seal these loopholes by focusing on three primary areas during cross-examination preparation:
The “Single Entity” Principle (Section 63(3) BSA)
The new law explicitly recognizes that if data flows across multiple computers, communication devices, or networks during regular business activities, the entire infrastructure is treated as a single unified device. The IO must explicitly mention the complete workflow in the certificate to prevent the defense from claiming that intermediary servers represent an uncertified break in the chain of custody.
Strict Timelines for Hash Matching
The defense will attempt to argue that the data was tampered with during the transit period between the spot seizure and the forensic laboratory analysis. By matching the SHA-256 hash value written on the spot in the Part A certificate with the laboratory’s intake hash value in Part B, the prosecution can mathematically prove that not a single bit of data was modified during transit.
Mandatory Nature of Certification
The law leaves zero room for judicial relaxation. As established in landmark rulings like Arjun Panditrao, a certificate is a sine qua non (an absolute prerequisite) for secondary electronic evidence. No amount of oral testimony by an investigator can cure a missing or defectively drafted Section 63 BSA certificate.
By prioritizing network isolation at the very inception of a raid and meticulously executing the dual-part certificate required by the new Schedule, investigating officers can successfully transform volatile digital exhibits into unassailable truths inside the courtroom.
Conclusion
In the digital era, the admissibility of electronic evidence hinges not only on its collection but on its meticulous preservation and certification. Devices must be isolated from networks, shielded against signals, and secured with cryptographic hash values the moment they are seized. Under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, dual certification by both the investigating officer and forensic expert is a non-negotiable prerequisite, ensuring authenticity and integrity. By rigorously following these protocols, investigators can transform fragile digital exhibits into courtroom-ready evidence that withstands defense challenges and secures justice in technology-driven trials.

