Evidence Law: Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023 (BSA)

Cloud Stored Data as Evidence

Cloud-Stored Data as Evidence under the Bharatiya Sakshya Adhiniyam, 2023: Custody, the Certificate Problem and Jurisdiction

Most of what a person creates now lives somewhere he has never been, on equipment he does not own, operated by a company that may not be subject to Indian process. The Adhiniyam handles this without saying anything about it: a record in a cloud account is an electronic record like any other. The difficulties are practical and they converge on a single question — who is the person in charge of the computer, and can he be persuaded to sign a certificate?

1. What Cloud Storage Changes

Three features of cloud storage alter the ordinary analysis of documentary evidence.

The party does not hold the record. A person's email, documents, photographs and messages may be accessible to him without being in his possession in any meaningful sense. He has an account, not a device, and the record is on somebody else's equipment.

The record may be nowhere in particular. Data is replicated across data centres, may move between them, and may exist simultaneously in several jurisdictions. Asking where a document 'is' frequently has no useful answer.

Deletion is not deletion. Material removed by a user may persist in backups, in versioning systems and in retention stores for periods the user does not control and is not told about. Conversely, material the user believes is retained may have been purged by a provider following its own schedule.

⚠ Access is not possession

The distinction runs through this whole subject. A party who can log into an account can see and download the material; he does not hold the original, cannot say how the provider stores it, and cannot certify anything about the provider's systems. For most purposes what he produces is a copy he made from a display or a download — which is why the certificate question is so much harder here than with a device in his own hands.

2. Relevance and Primary Evidence

On relevance, nothing is special. A cloud-stored record is a document under Section 2(1)(d), and it is relevant on the ordinary heads — as an admission under Section 15, as a business record under Sections 26(b), 28 or 29, as conduct under Section 6(2), as showing a state of mind under Section 12, or because the words themselves are operative.

On proof, the Explanations to Section 57 are more helpful than is generally appreciated.

Explanation 3 — a record created or stored simultaneously or sequentially in multiple files is primary evidence in each. Cloud storage is replication by design: the record exists on the user's device, in a synchronisation cache, and on one or more servers. Each of these is a file storing the record, and each is primary evidence. A party producing the synchronised copy from his own device is producing primary evidence, not a copy of a server-held original.

Explanation 4 — a record produced from proper custody is primary evidence unless disputed. An account holder producing material from his own account is producing it from proper custody.

Explanation 6 — automated storage including temporary files is primary evidence, which covers cached and synchronised copies held locally.

Explanation 3 is the most robust of the three for cloud material, because it carries no qualification. Where a party can show that the record he produces is one of several files in which the record is stored, he is producing primary evidence whether or not the other side disputes it — and cloud storage makes that showing easy, since replication is the whole architecture.

3. The Certificate Problem

Where the record is not primary evidence, Section 63(4) requires a certificate signed by a person in charge of the computer or communication device or of the management of the relevant activities, and by an expert. This is where cloud material becomes difficult.

The computer on which the record sits belongs to the provider. The person in charge of it is an officer of that provider, frequently abroad, with no obligation to sign anything for a private litigant in India. Three routes exist and none is straightforward.

3.1 The account holder as the person in charge

Where the party is the account holder, an argument is available that he is the person in charge of the management of the relevant activities — the words the sub-section offers as an alternative to charge of the device. The activities are his own; the account is his; the data was fed in by him in the ordinary course of his affairs.

The four conditions in Section 63(2) can be addressed on that footing: the account was used regularly for his activities, information of that kind was fed in regularly in the ordinary course, the service operated properly so far as he knows, and the download reproduces what was fed in. Section 63(4) expressly permits statements to be made to the best of the knowledge and belief of the person making them, which is what makes this workable.

The weakness is obvious and should be acknowledged rather than hidden: the account holder cannot speak to the provider's systems. Where the integrity of the provider's storage is genuinely in issue, his certificate does not answer it.

3.2 The provider's certificate

Where the provider has a presence in India, a certificate may be obtainable, and where the record matters this should be attempted. The intermediary framework under the Information Technology Act, 2000 and the rules made under it requires significant intermediaries to appoint officers in India for compliance purposes, which provides a point of contact.

3.3 Compelling production

📖 Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1

Held: A three-Judge Bench restored and clarified Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473. The certificate is mandatory where secondary electronic evidence is relied upon, but is not required where the original device is itself produced by its owner. Where a party is unable to obtain the certificate because the device or the system is in the control of another, the court may compel its production, and the party is not to be left without a remedy by reason of an inability for which he is not responsible.

Ratio: A party who cannot obtain a certificate through no fault of his own has a remedy in an application to compel, and this is the principal answer to the cloud certificate problem.

An application under this principle should identify the provider, the account, the material sought, the period, and the officer or entity who can certify. A general application asking the court to dispense with the certificate will not succeed; an application seeking production from an identified custodian may.

4. Jurisdiction

Where the provider and the data are outside India, obtaining material engages a set of questions the Adhiniyam does not address.

The absence of an extent clause. Section 1 of the Adhiniyam contains no express extent provision of the kind found in Section 1 of the Indian Evidence Act. Commentators read this as removing a textual obstacle to receiving evidence originating outside India. Removing an obstacle to admissibility does nothing about obtaining the record, and the practical difficulty is unaffected.

Domestic process against a foreign entity. A summons to produce a document under Section 94 of the Bharatiya Nagarik Suraksha Sanhita, 2023, corresponding to Section 91 of the Code of Criminal Procedure, 1973, may be served on an entity with a presence in India. Whether it reaches data held abroad by a foreign parent is a question providers have contested, and the answer varies with the category of material sought.

Mutual legal assistance. For content held abroad by a provider that declines domestic process, a request through the established channels may be the only route. It is slow, and the single most useful thing a party can do is to begin early.

Preservation. Providers honour preservation requests, which freeze material pending the completion of the process required to obtain it. A preservation request costs little, can be made promptly, and stops the retention clock. It is the most important immediate step in any case involving cloud material and is frequently overlooked.

⚠ What providers furnish differs by category

Providers ordinarily distinguish between basic subscriber information — who registered the account, when, with what contact details; transactional and access records — when the account was accessed and from which internet addresses; and content — the documents, messages and media themselves. The first two are furnished more readily and on lesser process; content ordinarily requires the most formal route and, where the provider is foreign, frequently a mutual legal assistance request. A party should ask for what he needs in the category that will actually be supplied, rather than making a single request for everything.

5. What Cloud Systems Hold That Devices Do Not

Three classes of material exist only on the provider's side and are worth asking for by name.

Access logs. A record of when the account was accessed, from what internet addresses, on what devices and with what applications. This is frequently the most valuable material of all, because it is the principal answer to the defence that an account was compromised or operated by somebody else.

Version history. Collaborative document systems retain a history of revisions, showing who changed what and when. In a dispute about whether a document was altered, and by whom, the version history may be decisive and has no counterpart on paper.

Backups and retained deleted material. Material deleted by a user may persist in a backup or in a retention store for a period, and the provider may be able to produce what the user cannot.

Each of these is a business record generated automatically in the ordinary course of the provider's operations. Where it can be obtained, it satisfies the conditions in Section 63(2) with ease, and it comes from a third party with no interest in the litigation — which is what makes provider records the strongest form of electronic evidence available in any case where they can be had.

6. The Account Holder's Own Download

Most major services permit an account holder to download an archive of his own data — messages, documents, media, activity logs and account history — in a structured form.

This is the single most practical route to cloud material, and it is under-used. Its advantages are that it requires no process, no cooperation and no delay; that it comes from the provider's systems rather than from a rendering on a screen; that it carries identifiers, timestamps and structure; and that it can be hashed as a file at the moment of download.

Its limitations should be stated candidly. It contains what the provider chooses to include in an archive, which may be less than the provider holds. It is produced by the account holder, so it establishes nothing against him about custody. And it cannot answer a question about the provider's own systems.

For a party proving his own records, it is ordinarily sufficient, and it is far superior to screenshots. For a party seeking to prove the records of another, it is unavailable, and the routes in the preceding sections must be used.

7. Chain of Custody

The chain for cloud material begins differently from the chain for a seized device, because there is no seizure.

The links that must be established are: when the material was obtained and by whom; from what account, and how access was obtained; what was downloaded or captured, and by what method; the hash computed at that moment; and how the material has been held since.

Two additional matters arise that have no counterpart with a device.

Authorisation of access. Where the account is not the party's own, how access was obtained is a question of substance, not merely of procedure. Material obtained by unauthorised access to an account is admissible on the reasoning in Pooran Mal v. Director of Inspection (Investigation), (1974) 1 SCC 345, the test being relevancy rather than the manner of obtaining — but unauthorised access is an offence under the Information Technology Act, 2000, and the circumstances remain a legitimate subject of comment on weight.

The live account. Unlike a seized device, an account continues to operate after the material is obtained. Material may be added, altered or deleted afterwards, and a download taken on one date will not match one taken later. The date of the download is therefore part of what must be proved, and where the account remains under the control of a party with an interest, the point should be taken.

8. Privacy

A cloud account holds a person's correspondence, documents, photographs, location history and browsing activity in one place. Access to it is the most comprehensive intrusion into informational privacy that any single step in an investigation can achieve.

📖 K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1

Held: A nine-Judge Bench held that the right to privacy is a fundamental right, and that informational privacy is a facet of it. Any invasion must satisfy legality, necessity and proportionality — a rational nexus between the object and the means adopted, with no less intrusive alternative available.

Ratio: The extraction of an entire cloud account in an investigation concerned with a narrow matter invites the proportionality objection directly.

As elsewhere, the consequence is not exclusion but justification. A request confined to a defined period and a defined category of material is far easier to sustain than a request for the whole of an account, and the confinement should appear on the face of the requisition. The no less intrusive alternative limb has particular force here: where the material sought could be obtained from a device already seized, or from access logs rather than content, the wider request is harder to defend.

9. A Practical Checklist

  1. Send a preservation request immediately, before anything else. It costs little and stops the retention clock.
  2. Download the account archive where the material is the party's own, and hash it at the moment of download.
  3. Record the date and method of download, since the account remains live and a later download will differ.
  4. Rely on Explanation 3 to Section 57 where the record is replicated, since it carries no unless-disputed qualification.
  5. Ask for access logs and version history, not merely content, since these are the material with no counterpart on a device.
  6. Identify the custodian who can certify, and address any application to compel production to that person.
  7. Begin foreign process early, and expect it to take months.
  8. Confine the request to a defined period and category, and be ready to justify its scope under Puttaswamy.

10. The Position Stated Shortly

  1. A cloud-stored record is a document under Section 2(1)(d), and relevance is determined on the ordinary heads.
  2. Access is not possession, and a party with an account does not hold the record.
  3. Explanation 3 to Section 57 is the most useful provision, because replication is the architecture of cloud storage and each stored file is primary evidence.
  4. The certificate problem is the central difficulty, since the person in charge of the computer is an officer of the provider.
  5. The account holder may be able to certify as the person in charge of the relevant activities, to the best of his knowledge and belief, but he cannot speak to the provider's systems.
  6. Where the certificate cannot be obtained, the court may compel production — Arjun Panditrao.
  7. Access logs and version history are the material worth asking for, and have no counterpart on a device.
  8. Preservation requests should go out at once, and foreign process should be started early.

11. Related Topics and Provisions

Topic or provision

Connection

Mobile Phone Data as Evidence

Synchronised copies held locally, and backups

Social Media Posts as Evidence

Platform records, preservation requests and foreign process

Emails as Evidence

Mail held in provider accounts

Electronic or Digital Record as Primary Evidence

Explanations 3, 4 and 6 to Section 57

Section 63 Certificate — Complete Note

The requirement and who may sign it

Chain of Custody of Digital Evidence

The links where there is no seizure

GPS and Location Data as Evidence

Location history held in a provider account

Section 94, BNSS, 2023

Summons to produce, and its limits against foreign entities