Cyber Offences and Electronic Evidence Under India’s New Criminal Codes

This article is written by Divyanshu Tyagi, VivekaNanda Institute of Professional Studies, GGSIPU.

The transition from the Indian Penal Code, 1860 (IPC), the Code of Criminal Procedure, 1973 (CrPC), and the Indian Evidence Act, 1872 (IEA) to the Bharatiya Nyaya Sanhita, 2023 (BNS), the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), and the Bharatiya Sakshya Adhiniyam, 2023 (BSA) all operative from July 1, 2024 represents the most comprehensive revision of India’s criminal law architecture in over a century. The transition was long overdue in its digital dimensions. Courts had spent two decades straining the IPC’s definitions of “property,” “document,” and “cheating” to accommodate phishing syndicates and ransomware operators. The IEA’s Section 65B had generated three incompatible Supreme Court readings in Anvar P.V. v. P.K. Basheer (2014), Shafhi Mohammad v. State of Himachal Pradesh (2018), and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) within six years, leaving trial lawyers and judges without stable ground on the foundational question of how electronic records are proved.

The new codes respond to these difficulties with a philosophy of technological neutrality: instead of creating a separate cybercrime chapter, digital means of commission are integrated into general penal categories. This approach has both merit and cost. It avoids the brittleness of technology-specific drafting, but it simultaneously generates new overlaps with the Information Technology Act, 2000 (IT Act), which the BNS does not repeal and leaves several questions of constitutional significance unaddressed. This article examines the substantive provisions on cybercrime, the procedural framework for digital investigations, and the evidentiary architecture for electronic records, with attention to the gaps that judicial interpretation will be required to fill. 

Keywords: Bharatiya Nyaya Sanhita 2023, Bharatiya Sakshya Adhiniyam 2023, electronic evidence admissibility, Section 63 BSA certificate, IT Act and BNS overlap

I. The Substantive Framework: Cybercrime Under the BNS

General Offences Extended to Electronic Means

The BNS does not create a dedicated cybercrime chapter. Instead, established offences are explicitly extended to electronic modes of commission. Section 318 addresses cheating through electronic communications, including fraudulent UPI payment links, fake shopping portals, and cryptocurrency investment scams, with Section 318(4) providing an aggravated form carrying imprisonment of up to seven years. Section 319 covers cheating by personation, expressly encompassing identity spoofing through fake social media profiles and impersonation via messaging platforms. Sections 335 and 336 extend the law of forgery to “false electronic records,” a clarification previously absent from the IPC’s forgery provisions, which courts had been forced to apply by analogy. Section 78 defines stalking to include repeated monitoring of a woman’s internet, email, or electronic communications, providing a statutory basis for cyberstalking prosecution that was absent from the IPC’s Section 354D.

Organised Cybercrime: Section 111

Section 111 of the BNS is the most consequential provision for large-scale digital crime. It classifies cybercrime committed through an organised syndicate defined as a group acting in concert to obtain financial or material benefit through coercion, violence, or unlawful means alongside offences such as kidnapping, extortion, and contract killing. The consequences are severe. Depending on the nature and gravity of the organised crime involved, punishment may range from imprisonment for a term not less than five years to imprisonment for life, and in exceptional cases where death results from organised criminal activity, may extend to the death penalty. The applicability of these punishments to organised cybercrime remains a matter of statutory interpretation and judicial scrutiny. 

Critically, Section 111 does not define what conduct constitutes a “cyber-crime” for its purposes. The provision mentions cybercrime as a category of organised criminal activity without supplying an enumeration equivalent to the specific offences listed in Sections 43 and 66 of the IT Act. This omission is not merely a drafting imperfection. The practical consequence is that the boundary between an ordinary digital fraud properly prosecuted under the bailable provisions of the IT Act or the general cheating provisions of the BNS and the non-bailable, highly punitive Section 111 framework is undefined. Whether a multi-state phishing operation crosses the threshold will depend on prosecutorial characterisation and eventual judicial construction, neither of which currently rests on settled authority.

Deepfakes: No Dedicated Provision and a Fragmented Legal Position

The article previously stated that Section 197(d) of the BNS specifically criminalises deepfakes. This requires correction. Section 197(1)(d) penalises “assertions prejudicial to national integration” through false imputations provisions addressing communal disharmony and threats to national unity, not synthetic media as such. Section 353 of the BNS separately penalises the making, publishing, or circulating of false statements or rumours, including through electronic means, likely to cause public mischief, and carries imprisonment of up to three years. The Government has indicated in parliamentary responses that deepfake content causing public mischief may be prosecutable under Section 353 BNS, depending on the facts of the case. However, neither the BNS nor the IT Act currently contains a dedicated offence specifically addressing deepfakes as a distinct category of harm. 

However, neither provision constitutes a dedicated deepfake offence. India currently lacks a standalone statutory framework explicitly addressing deepfakes as a distinct category of harm. Depending on the nature of the deepfake, prosecution may be possible under Section 66C or 66D of the IT Act (identity theft and cheating by personation using a computer resource), Section 67A of the IT Act (sexually explicit electronic content), Section 319 of the BNS (cheating by personation), or Section 356 of the BNS (defamation). The Digital Personal Data Protection Act, 2023 may additionally be engaged where personal data is processed without consent. This fragmented position spread across multiple statutes, none of which directly addresses the synthetic manufacture of a person’s likeness or voice is a recognised gap in the existing legal framework.

The IT Act Overlap: An Unsettled Conflict

The BNS does not repeal the IT Act, and both statutes now operate concurrently over substantially overlapping territory. The clearest example is cheating by personation using a computer resource, which falls within both Section 319 of the BNS and Section 66D of the IT Act. The penalty and bail consequences differ: the IT Act offence is bailable, while BNS provisions, particularly when an aggravated or organised crime characterisation is applied, are not.

The governing principle for resolving conflicts between the IT Act and the IPC was established in Sharat Babu Digumarti v. Government (NCT of Delhi) (2017) 2 SCC 18, where the Supreme Court held that the IT Act, as a special law governing electronic offences and containing a non-obstante clause under Section 81, prevails over the IPC’s general provisions where the conduct falls within the IT Act’s scheme. The court quashed proceedings under Section 292 IPC against an accused who had been discharged under Section 67 of the IT Act for the same transaction.

Whether this principle governs the BNS-IT Act relationship is not yet settled. Sharat Babu arose in the context of the IPC and the IT Act; the BNS is a new enactment, and no authoritative ruling has applied the lex specialis principle as between the BNS and the IT Act. As of mid-2026, the question remains open, and courts have begun to raise it without resolving it definitively. There is also a distinct double jeopardy question whether an accused acquitted under an IT Act provision could be re-prosecuted under a BNS provision for the same transaction that neither statute addresses and that Article 20(2) and Section 300 BNSS leave open in this specific inter-statute context.

It should be noted that legal commentators and practitioners have raised concerns that the availability of non-bailable BNS provisions for conduct that would ordinarily be bailable under the IT Act creates the structural possibility of prosecutorial forum selection. Whether this concern reflects actual investigative practice is, as of the date of writing, not supported by documented statistical evidence and should be treated as an analytical concern rather than a confirmed pattern.

II. Procedural Accountability: Section 105 BNSS

The Recording Mandate

Section 105 of the BNSS mandates end-to-end audio-video recording of every search and seizure, preferably via mobile phone, covering entry onto premises, recovery of physical and digital assets, preparation of the panchnama, and attestation by independent witnesses. Warrantless searches under Section 185 carry the same obligation. Suspect and witness statements, and confessions recorded before a Magistrate, are similarly to be video-documented, with the recordings forwarded to the competent Magistrate without delay. The provision directly addresses the well-documented problem of manufactured panchnamas and allegations of planted evidence in Indian criminal investigations.

Section 105 also expands the power to attach property as proceeds of crime, moving beyond the more limited framework of Section 102 of the CrPC. Early implementation produced instances of arbitrary account freezes without a documented nexus to any specific offence. Concerns have been raised regarding arbitrary freezing of bank accounts and digital assets during investigations. Courts have increasingly emphasised the need for a demonstrable nexus between the property attached and the alleged offence, as well as adherence to principles of proportionality and procedural fairness. In State of West Bengal v. Anil Kumar Dey (2025 INSC 1413), the Supreme Court held that a bank’s prior secured interest cannot be displaced by a subsequent state forfeiture under Section 105, and that Ratan Babulal Lath v. State of Karnataka, which had sought to restrict parallel freezing under general law, had been decided sub silentio and did not constitute binding precedent under Article 141.

Implementation Difficulties and the Admissibility Question

Recording a forensic disk image or mobile extraction on camera risks exposing investigative methodology — extraction tools, authentication credentials, and potentially informant-linked data — in material that becomes available to the defence. Battery life, storage capacity, and connectivity failures are documented field realities. The BNSS contains no explicit provision specifying the consequence of an incomplete or technically interrupted recording, and courts have handled the admissibility question inconsistently on a case-by-case basis. Judicial guidance from the Supreme Court or High Courts clarifying the effect of a Section 105 recording failure on admissibility is urgently needed.

The Compelled Password Disclosure Question

Section 94 of the BNSS empowers courts to summon “any document or thing.” Enforcement agencies have sought to read this power as extending to device passwords, biometric keys, and encryption credentials. This interpretation engages a constitutional question that the BNSS does not resolve.

In Selvi v. State of Karnataka (2010) 7 SCC 263, a constitutional bench of the Supreme Court held that the involuntary administration of techniques that compel an accused to share information residing within their “mental privacy” violates the right against self-incrimination under Article 20(3). The court’s reasoning extended Article 20(3)’s protection beyond direct oral statements to any form of testimonial compulsion that draws on personal knowledge held by the accused. Whether compelled disclosure of a device password which similarly requires the accused to communicate information within their exclusive mental knowledge falls within this protection remains res integra at the level of the Supreme Court. The Karnataka High Court and a Delhi CBI Special Court have taken divergent positions on whether compelling password disclosure violates Article 20(3), with no binding appellate resolution. The BNSS offers no guidance, and this is an area where early Supreme Court clarification would have direct practical consequence for digital investigations.

III. The Evidentiary Architecture Under the BSA

The Three Leading Precedents and Their Legislative Legacy

Any analysis of the BSA’s electronic evidence provisions must begin with the three Supreme Court decisions that the legislation was designed to supersede. In Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473, a three-judge bench held that electronic records are governed exclusively by Sections 65A and 65B of the IEA, that a Section 65B certificate is mandatory for secondary electronic evidence, and that the general secondary evidence provisions under Sections 63 and 65 of the IEA have no application to electronic records. The court overruled State (NCT of Delhi) v. Navjot Sandhu (2005) 11 SCC 600, which had permitted oral testimony in lieu of a certificate.

In Shafhi Mohammad v. State of Himachal Pradesh (2018) 2 SCC 801, a two-judge bench introduced a relaxation, holding that the certificate requirement could be dispensed with where the electronic record was not within the control of the party seeking to produce it. This departure from Anvar P.V. was widely criticised as introducing uncertainty and was squarely addressed in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1, in which a three-judge bench restored the mandatory certification requirement and expressly overruled Shafhi Mohammad. The court held that a Section 65B(4) certificate is mandatory for the admission of electronic records as secondary evidence, that the certificate must be provided at the time of filing or before trial commences, and that courts retain power to compel production of the certificate from the relevant custodian. These three cases together represent the foundational judicial treatment of electronic evidence admissibility in India and provide the interpretive baseline against which the BSA’s new provisions must be measured.

The BSA’s Definitional and Primary Evidence Provisions

Section 2(1)(d) of the BSA defines “document” to encompass any matter expressed through any means, explicitly including electronic records. This brings WhatsApp messages, server logs, GPS coordinates, EXIF metadata, cell-tower records, and automated system logs within the category of documents for evidentiary purposes as a matter of statutory text, without requiring courts to stretch nineteenth-century definitions.

Section 57 of the BSA and its explanations address primary evidence. Explanation 4 provides that each copy of an electronic record stored simultaneously in multiple locations, local device memory, flash storage, and cloud backup is to be treated as an original. Explanation 6 extends this treatment to video recordings simultaneously stored and transmitted. Explanation 7 covers automated duplicates generated across networked servers. The practical result of these provisions, read together with Arjun Panditrao‘s framework, is that cloud-backed data may enter as primary evidence without requiring a secondary evidence certificate — a significant procedural simplification compared to the pre-BSA regime.

Explanation 5 and the Proper Custody Presumption

Explanation 5 of Section 57 provides that a digital record produced from “proper custody” is sufficient to prove its contents as primary evidence unless the record is actively disputed. This provision has generated scholarly debate, and the competing positions merit examination.

One position holds that custody-based presumptions well established for physical documents can reasonably be extended to electronic records, with metadata, access logs, and system records providing an adequate substitute for the physical integrity of a sealed document. The other view holds that the analogy between physical and digital custody is structurally unsound: a digital file can be modified, injected with fabricated content, or partially overwritten while remaining continuously in the physical possession of the same custodian, without any external evidence of interference. The physical seal remains unbroken; the file’s integrity may not.

The constitutional dimension of this debate arises primarily at the pre-trial stage. If a digital record in official custody is admitted on a prima facie basis at a bail hearing here courts apply a lower threshold than at trial an accused may face extended pre-trial detention on the basis of a record whose integrity has not been independently verified. Whether this engages the right to liberty under Article 21 in conjunction with the right to a fair trial is a question that courts will need to address as the provision operates in practice. The statutory text of Explanation 5 does not resolve it, and no judicial authority as of the date of this article has done so under the BSA.

Section 63: Dual Certification and the Schedule Inconsistency

For secondary electronic evidence printouts, screenshots, and manually exported data Section 63(4) of the BSA requires a certificate signed by both the person in lawful charge of the relevant device or system and an independent forensic expert or technical analyst. Part A of the prescribed Schedule requires identification of the record, device specifications, operating system details, and cloud identifiers. Part B requires the expert’s certification of hash values (SHA-256, SHA-1, or MD5), hash generation methodology, data extraction tools, and encryption integrity.

There is a direct inconsistency between the text of Section 63(4) and the prescribed Schedule form. Section 63(4) itself directs the certificate to be signed by the technical custodian of the system an IT administrator, database manager, or CCTV operator who has knowledge of the device’s proper functioning and operational regularity. The Schedule form, however, is directed at the litigating party producing the evidence. A private litigant producing records from a third-party cloud platform, a telecom billing server, or an email service provider does not have access to the information required to certify that system’s maintenance history, software version integrity, or operational regularity. The litigant can certify the chain of custody from the moment of extraction; the internal technical state of the originating system is beyond their knowledge. This inconsistency is not a matter of interpretive difficulty it is a direct conflict between the certification obligation imposed by the statutory text and the party designated to discharge it in the prescribed form.

This drafting error has produced a practical problem in trial courts, where admissibility challenges arising from the mismatch between Section 63(4)’s text and the Schedule form have generated inconsistent rulings. The Delhi High Court’s 2026 protocols, which require telecom CDRs to be certified by the service provider’s Nodal Officer in Part B format and mandate explicit encryption integrity statements for end-to-end encrypted communications, represent a sound partial remedy. However, these are practice directions of one High Court, not a nationally binding resolution. A statutory amendment formally recognising distinct certificate formats one for the technical system custodian and one for the litigating party is necessary to produce uniformity.

IV. Critical Evaluation

The reforms enacted through the BNS, BNSS, and BSA address recognised deficiencies in India’s pre-2024 criminal law. The extension of general offences to electronic means provides a more durable framework than technology-specific drafting. The mandatory recording requirement under Section 105 BNSS responds to a systemic problem of evidentiary fabrication. The BSA’s reconceptualisation of electronic records as primary evidence removes procedural formalism that had enabled guilty parties to escape liability on certification technicalities.

Several issues, however, require attention. First, the absence of a definition of “cyber-crime” within Section 111 of the BNS creates uncertainty at precisely the point where the stakes non-bailable status, minimum five-year imprisonment, and asset forfeiture are highest. A definitional annex or a reference to specified IT Act offences would address this. Second, the BNS-IT Act overlap presents unresolved questions about the governing principle for concurrent prosecutions, double jeopardy, and the applicability of Sharat Babu Digumarti to the new statutory framework. These require either legislative coordination or early Supreme Court guidance. Third, the position on deepfakes illustrates a broader pattern: the BNS’s provisions are general enough to capture many harmful digital behaviours, but they do not constitute a coherent regulatory response to synthetic media, and the gap is acknowledged even in government statements. Fourth, the Section 63(4) inconsistency and the Explanation 5 custody presumption are specific, tractable problems that produce practical difficulties in courts today and that legislative drafting could resolve.

Conclusion

The BNS, BNSS, and BSA represent a serious legislative engagement with India’s digital criminal justice needs. They are, however, better understood as a foundation than as a completed edifice. The provisions on cybercrime are broadly drafted and technologically neutral; the procedural mandates on recording promote accountability; the evidentiary provisions simplify the admission of digital records in most cases. What remains is a set of structural issues: the IT Act overlap, the undefined scope of organised cybercrime, the fragmented position on deepfakes, the certification inconsistency, and the unresolved constitutional questions around custodial presumptions and compelled disclosure that judicial interpretation and targeted legislative amendment will need to address before the promise of these reforms is reliably translated into practice.

Beyond questions of statutory interpretation, the new criminal codes raise broader constitutional concerns. Issues relating to compelled disclosure of passwords, large-scale digital surveillance, automated data collection, and the admissibility of electronically generated evidence engage Articles 14, 20(3), and 21 of the Constitution. The extent to which the new framework accommodates privacy, due process, and protection against self-incrimination will likely become a significant area of constitutional litigation in the coming years. 

References

1. National Crime Records Bureau, Crime in India 2023 – https://ncrb.gov.in/crime-in-india-year-wise.html

2. Parliamentary Standing Committee on Home Affairs, 363rd Report on the BNSS, 2023 – https://sansad.in/getFile/annex/261/AS43.pdf

3. Bureau of Police Research & Development, SOP for Videographic Search and Seizure Protocols (2024) – https://bprd.nic.in

4. Ministry of Home Affairs, Enforcement Notification, July 1, 2024 – https://mha.gov.in/sites/default/files/250883_english_01042024.pdf

5. Ministry of Information & Broadcasting, Parliament Q&A on Deepfakes, PIB (August 2025) – https://www.pib.gov.in/PressReleasePage.aspx?PRID=2154268

6. SCC Online Blog, “Right of Self-Incrimination in Digital Age: Compelled Disclosure of Password/Biometrics” (March 2023) – https://www.scconline.com/blog/post/2023/03/18/right-of-self-incrimination-in-digital-age-whether-compelled-disclosure-of-password-biometrics-is-unconstitutional/

7. SCC Online Blog, “Navigating Deepfakes in Indian Criminal Law” (November 2025) – https://www.scconline.com/blog/post/2025/11/08/deepfake-regulation-rights/

8. Journal of the Indian Law Institute, “The Proper Custody Controversy: Section 57 Explanation 5 BSA” (2025) – https://jili.in

9. Delhi High Court, E-True Copy Rules, 2024, Notification No. 142/Rules/DHC – https://delhihighcourt.nic.in