Evidence Law: Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023 (BSA)
Screenshots as Electronic Evidence
Screenshots as Electronic Evidence under the Bharatiya Sakshya Adhiniyam, 2023: What They Are, What They Prove and Why They Fail
The screenshot is the most frequently tendered and least frequently examined form of electronic evidence in Indian courts. It is treated as though it were a copy of the record it shows. It is not. A screenshot is a photograph of a screen, and the analytical consequences of that simple fact โ for whether it is primary or secondary evidence, for whether it falls within any enumerated kind of secondary evidence at all, and for what it can prove โ are considerable and are almost never worked through.
1. What a Screenshot Actually Is
A screenshot is an image file created by the operating system, capturing what was being displayed on the screen at the moment it was taken. It is a new document, created at the moment of capture, by the person who captured it.
This is the whole of the difficulty. A screenshot showing a message is not the message. It is an image of a rendering of the message, produced by an application which chose how to display it, on a device belonging to somebody, at a moment of that person's choosing. Two documents are therefore in play, and they must be kept apart.
The screenshot | The underlying record | |
|---|---|---|
What it is | An image file created at the moment of capture | The message, post or entry stored in the application's data |
Who created it | The person who took it | The system that recorded the communication |
When | At the moment of capture, which may be long afterwards | When the communication occurred |
What it holds | Pixels representing what was displayed | The content, identifiers, timestamps and metadata |
What it can prove | What was on that screen at that moment | That the communication occurred and what it said |
โ Two documents, two questions A party tendering a screenshot is tendering one document in order to prove the contents of another. The screenshot has its own provenance, its own custody and its own hash. The underlying record has all of these separately, and none of them is established by producing the image. Every difficulty with screenshot evidence traces back to the conflation of the two. |
2. Is a Screenshot Primary Evidence?
The question has to be asked twice, and the answers differ.
2.1 Of itself
A screenshot stored on a device is an electronic record, and the Explanations to Section 57 apply to it. Under Explanation 6, a record stored in multiple storage spaces in a computer resource, including temporary files, is primary evidence. Under Explanation 4, a record produced from proper custody is primary evidence unless disputed.
So the screenshot is primary evidence of itself โ of the fact that an image of that appearance exists on that device. That is a true statement and an almost useless one, because nobody disputes that the image exists.
2.2 Of the underlying record
This is the question that matters, and the answer is no. The screenshot was not created by the system that holds the message; it was created by the person with the camera, so to speak. It is a copy of a display of the record, made outside the system, and it is at best secondary evidence of the record's contents.
The point can be tested against Explanation 2 to Section 57, which provides that where a number of documents are made by one uniform process each is primary evidence of the contents of the rest, but where they are all copies of a common original they are not primary evidence of the contents of the original. A screenshot is a derivative of the record as displayed; it is not the record.
3. Is a Screenshot Even Secondary Evidence?
If a screenshot is secondary evidence of the underlying record, it must fall within one of the eight kinds enumerated in Section 58. This is worth working through, because the fit is uncomfortable.
Section 58, BSA โ the relevant clauses Secondary evidence means and includes โ (ii) copies made from the original by mechanical processes which in themselves ensure the accuracy of the copy, and copies compared with such copies; (iii) copies made from or compared with the original; (v) oral accounts of the contents of a document given by some person who has himself seen it. |
Clause (ii) requires a copy made from the original by a mechanical process ensuring accuracy. A screenshot is produced mechanically, and the capture is accurate in the sense that it records what was on the screen. But it is made from the display, not from the original record, and a display is itself a rendering produced by an application which may abbreviate, reformat, translate or omit. The fit is arguable rather than obvious.
Clause (iii) requires a copy made from or compared with the original. The same objection arises, unless the person who took the screenshot also compared it with the underlying record โ which is not what happens.
Clause (v) is an uncomfortable but instructive comparison. An oral account by a person who has seen a document is secondary evidence of its contents, and its weakness is that it depends entirely on what that person perceived and reports. A screenshot is, in substance, a mechanised version of the same thing โ a record of what one person saw on one screen at one moment, more accurate than memory but sharing its essential character.
โ The words means and includes Section 58 defines secondary evidence as what it 'means and includes', which leaves the list open at the edges, and no Indian court has held that a screenshot falls outside it. The practical position is that screenshots are received. But the analysis matters, because it explains why they are weak: a screenshot sits at the far end of the secondary-evidence spectrum, nearer to an oral account than to a certified copy, and it should be treated accordingly. |
4. What a Screenshot Loses
A record held in an application's data carries a great deal that never reaches the screen, and none of it survives capture.
- Message and post identifiers, by which the record can be located and verified in the system.
- Precise timestamps, as opposed to the abbreviated display time โ which frequently shows only a time of day, or a relative expression such as yesterday.
- Delivery and edit history, including whether a message was edited after sending.
- Sender identifiers as recorded by the system, as opposed to a display name drawn from the capturing device's own contact list.
- Whatever preceded and followed the captured portion.
- Any verification data by which the record could be checked against the source.
The display-name point deserves emphasis because it is not widely appreciated. In most messaging applications, the name shown against a message is taken from the recipient's contact list, not from anything the sender supplied. A screenshot showing a message from a named person shows what the capturing device's owner had saved that number as. It is not evidence of who the sender was.
5. Fabrication
A screenshot is an image, and images are edited without difficulty and without detectable trace. Beyond ordinary editing, a convincing screenshot can be produced without editing at all โ by altering a contact name before capture, by using a browser's developer tools to change displayed text on a page before capturing it, or by using applications designed to generate mock conversations.
The consequence is not that screenshots are never believed. It is that a screenshot, standing alone, cannot answer an allegation of fabrication. There is nothing in it to examine: no metadata connecting it to the source, no identifiers, no hash of anything but the image itself.
Where fabrication is alleged, the answer must come from outside the screenshot โ the underlying record produced from the device or the platform, the corresponding record on the other party's device, the operator's or platform's own records, or an admission. A party who has only a screenshot and faces a denial is in serious difficulty, and no amount of argument about Section 63 will help.
6. The Section 63 Position
Where a screenshot is tendered to prove the contents of an underlying record, the certificate under Section 63(4) is required, and a difficulty arises about what it should say.
The four conditions in Section 63(2) are framed around the system that produced the output โ regular use, regular feeding of information, proper operation, and derivation of the output from what was fed in. Applied to a screenshot, the questions become awkward: the device on which the screenshot was taken is not the system in which the message was created, and the output does not reproduce or derive from information fed into that device in the ordinary course of its activities. It derives from a display.
The practical answer is that a certificate covering a screenshot should be clear about what it certifies. It can properly certify that the image is an unaltered capture taken on a stated device at a stated time, with the hash of the image file. It cannot honestly certify that the image reproduces or derives from information fed into that device in the ordinary course, if what is meant is the underlying message.
Where the underlying record can be produced โ by export, by forensic extraction, or from the platform โ it should be, and the certificate should cover that. The screenshot then becomes what it is best suited to be: an aid to reading, tendered alongside the record it illustrates.
7. Completeness
A screenshot is inherently selective. A screen holds a few messages; a conversation holds thousands. What is captured is what the capturer chose to capture, and Section 33 applies squarely.
Section 33, BSA When any statement of which evidence is given forms part of a longer statement, or of a conversation, or part of an isolated document, or is contained in part of an electronic record, evidence shall be given of so much and no more as the Court considers necessary in that particular case to the full understanding of the nature and effect of the statement, and of the circumstances under which it was made. |
The second limb โ the circumstances in which the statement was made โ is what a screenshot systematically withholds. A message that appears to be an admission may be a repetition of what the other person just alleged; an apparent threat may be a quotation; an apparent agreement may be withdrawn in the next message that did not fit on the screen.
Where a party produces screenshots and resists production of the whole exchange, the court may require it under Section 33, and may presume under Illustration (g) to Section 119 that what is withheld would have been unfavourable. A party who has the device and produces only fragments of what is on it invites that inference directly.
8. When a Screenshot Is Adequate
None of this means screenshots are useless. There are situations in which a screenshot is perfectly sufficient, and it is worth identifying them so that effort is spent where it is needed.
Where the record is admitted. If the other side accepts that the message was sent and says only that it meant something different, the screenshot is unobjectionable and the argument is about construction rather than proof.
Where the screenshot is the best available evidence of a transient display. Some material exists only as a display and is never stored as a retrievable record โ an application's ephemeral notification, a page that has since been taken down, a message set to disappear. A capture made at the time may be the only record there ever was, and its weakness is then a limitation to be acknowledged rather than a defect to be cured.
As an aid to reading a record that has been properly proved. Where the underlying record is produced by export or extraction, a screenshot showing how it appeared is a useful illustration, and nothing turns on its evidentiary status.
In interlocutory proceedings, where the standard is prima facie and the material will be properly proved later if the matter proceeds.
9. Improving a Screenshot
Where a screenshot is all that can be had, several steps materially improve it, and they cost nothing.
- Hash the image at the moment of capture and record the digest contemporaneously, so that the image produced in court can be shown to be the image taken.
- Capture the full context โ scroll and capture the whole exchange rather than the passage relied upon, so that Section 33 is answered in advance.
- Include the identifying surroundings โ the contact header, the number rather than a saved name where the application shows it, the page address in the case of a web page, and the device's own clock display.
- Have the capture made by a disinterested person where possible, who can depose to having made it and be cross-examined about it.
- Preserve the device on which the capture was made, so that the image can be traced to it and the underlying record recovered later if needed.
- Obtain the underlying record as well, by export or extraction, at the earliest opportunity โ the screenshot then supports the record rather than standing in its place.
โ A screenshot shared through a messaging application is worth less still Where a screenshot has itself been forwarded through a chat before reaching the party who tenders it, it has been re-encoded and stripped of whatever metadata it carried, and its own provenance is now uncertain โ it is a copy of a copy of a display. The original image file from the device that made the capture should be obtained wherever possible. |
10. The Position Stated Shortly
- A screenshot is a new document created at the moment of capture, not a copy of the record it displays.
- Two documents are in play, and the provenance, custody and hash of each are separate.
- It is primary evidence of itself and at best secondary evidence of the underlying record.
- Its fit within the enumerated kinds in Section 58 is arguable, because it is a copy of a display rather than a copy made from the original.
- It loses identifiers, precise timestamps, edit history and system-recorded sender information, and the name it displays is drawn from the capturing device's own contact list.
- It cannot answer an allegation of fabrication, because there is nothing in it to examine.
- Section 33 bites hard, because a screenshot is inherently selective and withholds exactly the context the section requires.
- It is adequate where the record is admitted, where the display was transient, as an aid to a proved record, and at the interlocutory stage โ and inadequate almost everywhere else.
11. Related Topics and Provisions
Topic or provision | Connection |
|---|---|
WhatsApp Chats and Messages as Evidence | Export and forensic extraction as the alternatives to screenshots |
Social Media Posts as Evidence | Platform downloads and records as the alternatives |
Kinds of Secondary Evidence | The eight categories in Section 58 and where a screenshot sits among them |
Electronic or Digital Record as Primary Evidence | The Explanations to Section 57 |
Section 63 Certificate โ Complete Note | What the certificate can and cannot properly certify |
Hash Value and Integrity of Electronic Evidence | Hashing the image at the moment of capture |
Section 33, BSA | Completeness, and the context a screenshot withholds |
Section 119, Illustration (g), BSA | The adverse inference from producing fragments |