Digital Evidence from Cloud Collaboration Platforms: Authentication, Admissibility and the Cross-Border Conundrum
Introduction : Commercial disputes are increasingly being decided by the messages exchanged on collaboration tools, the version histories of shared documents, the access logs recording who viewed or edited a file, and the audit trails of the platforms recording each administrative action. Yet the very attributes that lend these evidence value in disputes – their volume, dispersion and potential storage on servers in any jurisdiction – also render them legally precarious. This blog addresses two questions. The first concerns authentication and admissibility of such evidence stored outside India – what steps must a corporate legal team take to authenticate such evidence in an Indian court? The second question, for the same type of evidence, pertains to preservation – what must a corporate legal team do, to preserve such evidence in a form admissible to a court? This blog examines each of these in detail, including the relevant statutes, case law, the cross-border dimension, and the practical preservation, metadata, retention and forensic certification toolkit required by a corporate legal team, concluding with a litigation hold template.Legal Provisions.
A. The Bharatiya Sakshya Adhiniyam, 2023 (India)
The Indian Evidence Act, 1872 was repealed and replaced by the new Bharatiya Sakshya Adhiniyam, 2023 (“BSA”), which commenced on 1 July 2024. Section 61 of the BSA confirms the admissibility of electronic and digital records as evidence. The contents of electronic records may be proved in accordance with Section 62 and Section 63 which govern admissibility. In particular, Section 63(1) BSA stipulates that information contained in an electronic record produced by a computer or any communication device is deemed to be a document and shall be admissible as such without proof or production of the original, unless the requirements of Section 63(2) are not met. Further, under Section 63(4), a certificate identifying the computer or communication device, dealing with the matters specified in Section 63(2) and signed by a person in charge of the computer or communication device or the management of the activities concerned is required to be attached to the electronic record at the time of its admission. The certificate’s particulars are set out in the Schedule to the BSA which specifically contemplates computer, storage device, mobile phones, flash drives, servers, and cloud services.
B. The Information Technology Act, 2000 (India)
The Information Technology Act, 2000 (“IT Act”) contains the definitions of “electronic form” and “electronic record” which are found in Section 2(r) and Section 2(t) respectively. The 2008 amendment to the IT Act introduced Section 79A which provides that the Central Government may appoint an Examiner of Electronic Evidence who shall give expert opinion on matters concerning electronic form evidence to any court or other authority. The IT Act also provides the legal framework for digital signatures, intermediaries, and other aspects of cyber law which touch upon the authenticity of cloud-stored records.
C. The Cross-border Framework
For cloud data stored outside India, the following three international instruments are relevant. The Clarifying Lawful Overseas Use of Data Act, 2018 (“CLOUD Act”) of the U.S. was enacted in response to the Microsoft Corp. v. United States, 138 S. Ct. 1186, 2018 case and allows the U.S. government to compel U.S.-based companies to hand over data irrespective of where it is stored, while executive agreements enable other countries to obtain data from U.S.-based companies. The Hague Evidence Convention, 1970 allows for letters of request to be sent to another country for obtaining evidence, and Mutual Legal Assistance Treaties (“MLATs”) provide a similar regime for criminal investigations. In India, the transfer of personal data outside India is governed by Section 16 of the Digital Personal Data Protection Act, 2023, while data localization requirements are imposed by sector-specific laws such as the Reserve Bank of India directions on payment system data.
Legal Analysis
A. The Authentication and Admissibility Framework
Indian law on electronic evidence has a history of three distinct phases. First, in State (NCT of Delhi) v. Navjot Sandhu @ Afsan Guru, (2005) 11 SCC 600, the Supreme Court took a liberal view of the admissibility of electronic records and allowed them into evidence without the certificate. This was reversed in Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473, wherein a three-judge bench ruled that Section 65B of the Indian Evidence Act, which was later re-enacted as Section 63 of the BSA, is a “complete code” which mandates production of the certificate under Section 65B(4) of the Indian Evidence Act for admissibility of secondary evidence of contents of an electronic record. A two-judge bench in Shafhi Mohammad v. State of Himachal Pradesh, (2018) 2 SCC 801 took a contrary view and held that the certificate was not necessary in all cases, but this was overruled by a three-judge bench in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 which ruled that the certificate is mandatory in all cases where original production is not possible, and that the inconvenience in cases of large volumes of data was not a sufficient reason to depart from the explicit wording of Section 65B of the Indian Evidence Act, now Section 63 of the BSA. These principles have been retained in the BSA which specifies the requirements for certificate under Section 63(4).
The relevance of this three-judge bench ruling in Arjun Panditrao Khotkar is that the certificate must be signed by “a person in charge of the computer or communication device or the management of the activities concerned.” In a cloud computing context, this would mean either the cloud provider’s administrator or the customer’s platform administrator who has oversight over the tenant environment and has legal authority to bind the customer in signing the certificate. It does not refer to an individual employee who sent or received the email or made changes to the record. This has significant implications for collection of evidence from cloud services. Consequently, corporate counsel should be mindful of who can sign the certificate at the time of collection, because it is required at the time of tendering of evidence.
B. Evidence Stored Outside India: The Cross-Border Conundrum
The location of cloud data raises a threshold issue – where is an electronic record located for the purposes of production and authentication? The foremost authority is the US Supreme Court decision in Microsoft Corp. v. United States, 138 S. Ct. 1186 (2018), which ruled on a Stored Communications Act, 1986 warrant for the production of emails stored on servers in Ireland. The issue was rendered moot by the passage of the CLOUD Act, which clarified that US providers must comply with warrants for data anywhere in the world, while executive agreements may be entered into with other states for reciprocal access. The case reaffirms the principle that while cloud service providers operate on a global scale, process and execution of legal process remain territorial.
With respect to commercial disputes in India, evidence located outside India is available, but through the appropriate channel. If the data is in the custody of a party to the dispute, that party may be ordered to produce it and the certificate may be issued by the administrator. If the data is in the custody of a foreign third party, not a party to the dispute, the requesting party may need to look to the Hague Evidence Convention, or an Mutual Legal Assistance Treaty (MLAT) for criminal matters, or, if the dispute is in the US and the data is in the custody of a US provider, 28 U.S.C. Section 1782 discovery. Indian courts cannot issue orders for the production of evidence by a foreign cloud provider, which makes the preservation and early identification of the custodian imperative.
C. Preservation, Litigation Holds and Employee Access
Once a dispute is reasonably foreseeable, preservation obligations attach. A litigation hold is the mechanism by which an organization puts an end to its regular data management practices, including deleting and retaining procedures, and directs custodians to take steps to preserve data. In relation to cloud data, this includes collaboration data, version history, access logs, and audit trails – data which may be subject to automatic deletion or other policies. The hold should be issued in writing and should identify the custodians and data to be preserved, and should be renewed on a regular basis. Employee access raises two issues in this context. Firstly, departing or dissident employees may take action to delete or alter data, and so their access to systems should be revoked as soon as possible after the institution of a litigation hold. Secondly, communication on company platforms may be subject to privilege, and so the organization needs to have policies in place to deal with possible assertions of privilege, including taking steps deliberately to assert or waive privilege.
D. Metadata and Retention Policies
Metadata often forms the most important part of the evidence chain in relation to cloud data. With respect to cloud data, this includes version history, access logs, and audit trails – each of which may provide critical evidence as to what occurred and when. Under the BSA framework, each of these items of metadata is part of the electronic record and must be preserved and produced as such. With respect to retention, policies relating to the automatic deletion of data can cut both ways. On the one hand, a properly constructed retention policy followed consistently and applied uniformly is perfectly admissible in evidence. However, the same policy, if triggered at the wrong time, can constitute an obstruction of justice and lead to adverse procedural consequences, including an adverse inference being drawn as to the existence of evidence – and so corporate counsel should ensure that such policies are in place and are not suspended inappropriately once preservation obligations attach.
E. Forensic Certification and Chain of Custody
In cases where the authenticity of cloud data is in issue, certification by a forensic auditor is critically important. The Examiner of Electronic Evidence under Section 79A of the IT Act may provide such certification. Forensic examination requires identification of the source of the data, imaging or other extraction of the data, generation of hash values, and documentation of the chain of custody, culminating in the production of a Section 63(4) certificate. The BSA statutory certificate specifically refers to cloud systems as a source of evidence, and so a forensic certificate should be in a position to cover such systems and identify how the data has been extracted therefrom. A forensic audit report in relation to access to the data, control of the system, and absence of alterations or other data integrity failures will assist considerably in establishing the authentication of cloud data.
Practical Implications
For corporate lawyers, most lessons of this article boil down to action items. First, to map the data ecosystem: collaboration tools, data location, data ownership within each tenant. Second, to determine who the certificate signatory would be for the issue of BSA Section 63(4) certificate. Third, to formulate a retention policy that shall also be the litigation hold suspension and its forensic authentication. Fourth, to impose hold on access, particularly on the exiting employees. Further, to involve the forensic experts on the matters pertaining to authenticity of the evidence. Last, to identify the channel for cross-border production of data, if any, on the litigation hold.
Litigation Hold Template
LITIGATION HOLD
[Company Name] | [Date]
To: [List of custodians / All employees]
Re: Preservation of Data and Documents Pending [Description of Dispute / Anticipated Litigation / Regulatory Inquiry]
1. This notice is issued by the Company, recalling its obligation to preserve evidence in connection with [describe dispute, matter name/number or anticipated proceeding] (“the Matter”).
2. You are hereby directed to preserve, and to take no action to delete, alter or destroy, all data and documents, including but not limited to the following categories of information, that may pertain to the Matter:
(a) email, calendar;
(b) communication on collaboration platforms, including Microsoft Teams, Slack, WhatsApp Business, Google Chat;
(c) documents, spreadsheet, presentation, and other files including all versions and version history;
(d) access logs, audit trail, and administrative logs;
(e) metadata, including all of the foregoing;
(f) all other data and documents reasonably likely to contain evidence relevant to the Matter.
1. You must not alter, delete or disable any automatic deletion, retention or archive setting that may apply to the information described above. [Where applicable: The Company has suspended automatic deletion of the relevant records for the accounts identified below:]
2. You must not access or use personal devices/personal accounts for work-related communications, including for the Matter, or for the transfer of data pertaining to the Matter.
3. You must retain all information described above even if you cease to be employed by the Company and you must not delete or alter any such information upon leaving the Company.
4. This litigation hold shall supersede any other retention or deletion policy of the Company, to the extent of any conflict, and shall remain in force until revoked by the Company.
5. If you have any questions about this litigation hold or if you need assistance in connection with it, please contact [Name, Designation, Email, Phone] as soon as possible.
6. Failure to comply with this litigation hold may result in disciplinary action against you and may adversely affect the Company’s position in the Matter.
Signed: [Name, Designation]
Conclusion
The use of cloud collaboration platforms has enriched and complicated the documentary trail and evidentiary value of the data collected from them, in equal measure. Indian law, through BSA 2023 and the long judicial lineage of Anvar and Arjun Panditrao Khotkar, has imposed strict obligations for the authentication of electronic records. Add to it the complication of the jurisdiction in which the cloud data is stored, which may be resolved only partially through the CLOUD Act and the Hague Convention, and the corporate counsel has enough reason to prepare a detailed litigation hold. It is necessary to know the location of the data, have the signatory for issue of BSA section 63(4) certificate, have a preservation policy to be suspended as litigation hold, and involve electronic discovery experts to prove authenticity of the data and records. A litigation hold at the right moment can be the difference between what can be said and what may be forever lost.
Author: Kirti in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at Khurana & Khurana, Advocates and IP Attorney
Bharatiya Sakshya Adhiniyam, 2023, s. 61 (India).
Bharatiya Sakshya Adhiniyam, 2023, s. 62 (India).
Bharatiya Sakshya Adhiniyam, 2023, s. 63 (India).
Bharatiya Sakshya Adhiniyam, 2023, s. 63(4) and Schedule (India).
Information Technology Act, 2000, s. 2(r), 2(t) (India).
Information Technology Act, 2000, s. 79A (India).
Digital Personal Data Protection Act, 2023, s. 16 (India).
State (NCT of Delhi) v. Navjot Sandhu @ Afsan Guru, (2005) 11 SCC 600 (India).
Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473 (India).
Shafhi Mohammad v. State of Himachal Pradesh, (2018) 2 SCC 801 (India).
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 (India).
Tomaso Bruno v. State of Uttar Pradesh, (2015) 7 SCC 178 (India).
Sonu @ Amar v. State of Haryana, (2017) 8 SCC 570 (India).
State of Karnataka v. M.R. Hiremath, (2019) 7 SCC 515 (India).
Vijay v. State of Maharashtra, (2016) 12 SCC 386 (India).
Vikram Singh v. State of Punjab, (2017) 8 SCC 518 (India).
P. Gopalkrishnan @ Dileep v. State of Kerala, (2020) 9 SCC 161 (India).
Microsoft Corp. v. United States, 138 S. Ct. 1186 (2018) (United States).
Clarifying Lawful Overseas Use of Data Act (CLOUD Act), Pub. L. No. 115-141 (2018) (United States).
Stored Communications Act, 18 U.S.C. Section 2703 (United States).
Convention on the Taking of Evidence Abroad in Civil or Commercial Matters, 1970 (Hague Evidence Convention).
Tavishee Dubey, Digital Evidence and Electronic Record Management and Criminal Trials, (2026) 14(8) International Journal of Creative Research Thoughts.
The Decision in Arjun Panditrao: Admissibility of Electronic Evidence in India Continues to Face Hurdles, SCC Times Blog (7 June 2021).




Comments