Pune Bar Association v. Union of India & Ors.
Writ Petition (Civil) No. 599 of 2026
Most early commentary on Pune Bar Association v. Union of India will treat it as an evidence-law case. That is what it is, technically. But the more useful reading sits in a register the order itself never invokes, data protection. The Court’s reasoning has implications that travel beyond evidence law into compliance and enforcement practice under the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”). That second reading is the one worth lingering on.
In Pune Bar Association v. Union of India, the Supreme Court declined to entertain a challenge to Section 63(4) of the Bharatiya Sakshya Adhiniyam, 2023 (“BSA”), which governs the admissibility of electronic records and replaces the earlier Section 65B of the Indian Evidence Act, 1872.
Facts in brief:
The petitioner challenged the provision on the ground that it imposed an excessive burden on litigants by requiring a certificate containing the hash value of the electronic record and a declaration by an expert.
Observations of the Court and Bombay Juris’ Analysis:
In declining to entertain the challenge, the Court observed that electronic records are vulnerable to alteration, manipulation, and misuse, particularly in the age of Artificial Intelligence and deepfake technology. It held that the requirement of disclosing a hash value a unique digital fingerprint generated through a cryptographic process helps establish the authenticity and integrity of electronic data. A hash value embodies the concept of a digital fingerprint. It is a unique alphanumeric string generated through a mathematical algorithm known as a hash function and serves as a unique identifier for a particular piece of digital data. Even a minor alteration in a file results in a completely different hash value. Consequently, hash values authenticate integrity, support chain of custody. Earlier section 65B of the Evidence Act only relied upon certification for authentication but the new Section 63(4) of the BSA has moved beyond mere certification to scientific and tech-based authentication.
Similarly, expert certification provides an additional safeguard to ensure the reliability of electronic evidence. The Court concluded that Section 63(4) of BSA has a rational nexus with the objective of ensuring trustworthy electronic evidence and is neither arbitrary nor unreasonable. Therefore, from this ruling of the Apex Court it may be inferred that measures like hashing can be construed as “reasonable security safeguards” (under Rule 6 of the DPDP Rules) for data fiduciaries while dealing with personal data in electronic mode.
The Court also examined the relationship between Section 39(2) of the BSA and Section 79A of the Information Technology Act, 2000, which recognizes the opinion of an Examiner of Electronic Evidence as expert evidence. It indicated that certification under Section 63(4) is not restricted to experts notified under Section 79A. Reading Sections 39(1) and 39(2) BSA harmoniously, the Court observed, in addition to entities notified under Section 79A a person with special skill and expertise in computer science and cyber forensics may qualify as an expert, subject to the Court being satisfied, on the basis of unimpeachable material, as to such expertise.. The Court accordingly that the Madras High Court’s (R. v. B & Anr, 2024 SCC OnLine Mad 6084) view requiring certification exclusively by a Section 79A examiner is not to be treated as binding precedent. The Court, however, expressly kept the question of law open and disposed of the petition without issuing notice to the Union of India.
The convergence between the case and the data protection framework operates at the level of regulatory policy. Section 8(5) of the DPDPA requires every Data Fiduciaries to take reasonable security safeguards to prevent personal data breach. Rule 6(1) of the DPDP Rules specifies, at minimum, securing of personal data through encryption, obfuscation, masking or the use of virtual tokens; controls on access to computer resources; logs, monitoring and review to enable detection, investigation and remediation of unauthorised access; and reasonable measures for continued processing in the event of confidentiality, integrity or availability of personal data being compromised. The Court’s reasoning, while not directed at these provisions, accepts the same premise that animates Rule 6 of the DPDP Rules: that digital information is vulnerable to alteration, and that cryptographic verification is an appropriate technical response. Paragraph 3 of the order expressly invokes artificial intelligence and deepfake risk as the policy concern, a concern that corresponds to the data protection objective of protecting personal data against unauthorised alteration.
The connection becomes operationally significant in enforcement. Proceedings before the Data Protection Board, appellate proceedings under the DPDPA, and civil claims arising from personal data breaches will typically rely on electronic records such as access logs, audit trails, forensic reports, incident-response documentation, and system-generated records. When tendered in evidence, each such record falls within Section 63(4) BSA and its certification requirements. Questions of authenticity and integrity will therefore arise as evidentiary questions, not merely as cybersecurity ones. A Data Fiduciary whose records carry verifiable hash values, and which is positioned to furnish a Schedule-compliant certificate under Section 63(4), is consequently better placed to defend its conduct in such proceedings, irrespective of the strength of its underlying security posture.
The connection between Pune Bar Association and the data protection framework is one of policy alignment, not doctrine. The two statutes do not cross-reference one another, and the Court did not refer to the DPDPA in its reasoning. The order is, in formal terms, a non-decision: the petition was disposed of without notice to the Union of India, and the question of law was expressly kept open. Within those limits, the order is nonetheless of relevance to practitioners advising Data Fiduciaries. It records the Supreme Court’s endorsement of hash-value verification as a sure way of identifying and verifying digital data, and it identifies the manipulability of digital information, including through artificial intelligence and deepfake technology, as the policy concern that justifies such verification. Both features are likely to be cited in enforcement proceedings and breach litigation under the DPDPA framework, notwithstanding that the order itself says nothing of that framework expressly.
Disclaimer: This note is meant for informational purposes only. For any queries or legal advice please feel free to get in touch with us.



