India's Premier Full-Service Law Firm — Precision. Pedigree. Global Reach.
Goldschmidt Pallonji& Associates
Get in Touch
Home / Practices / Forensic Accounting / Digital Forensics
★★★ Forensic Accounting — Sub-Practice

Digital Forensics

Every fraud leaves a digital trail. Every employment dispute has emails. Every tax investigation involves seized hard drives. Every corporate investigation begins with a document review. The question is not whether the digital evidence exists — it is whether it is collected, preserved, and analysed in a way that makes it usable in the proceedings that follow.

Electronic Evidence · Email Forensics · Deleted Files · Metadata · WhatsApp · Accounting Data
Tax Search Seized Records · Cryptocurrency · Litigation Support · Chain of Custody · Court-Admissible
The Sub-Practice

The moment a potential dispute or investigation becomes apparent, every email, WhatsApp message, accounting entry, and file on the relevant systems becomes potential evidence. The question of who collected it, how they collected it, whether the collection process preserved its integrity, and whether the chain of custody is documented will determine whether that evidence can be used in the proceedings that follow.

Digital forensics in the Indian legal context has specific requirements that distinguish it from the broader field of information security forensics. Indian courts and regulatory bodies — the ITAT, the NCLT, the High Courts, SEBI, and the CBI Special Courts — have specific requirements for the admissibility of electronic evidence under Section 65B of the Indian Evidence Act. A digital forensic collection that does not satisfy the Section 65B certification requirements is inadmissible as electronic evidence — no matter how probative its content. GP's digital forensics team collects, preserves, and analyses electronic evidence with Section 65B compliance built into every collection from the first moment.

The scope of digital forensics work at GP spans the full range of legal proceedings in which electronic evidence is relevant. In tax search and seizure proceedings, the IT Department seizes electronic records — hard drives, laptops, accounting software databases, email archives — and uses them to construct additions to income. GP's digital forensics team reviews seized records, identifies the context that the IT Department may have missed or mischaracterised, and builds the taxpayer's response around a complete digital evidence analysis. In corporate fraud investigations, the team recovers deleted emails, reconstructs WhatsApp conversation records, extracts accounting software transaction logs, and identifies the metadata that establishes who created a document and when. In employment disputes, the team analyses departing employee device contents and email communications for evidence of data theft or breach of confidentiality.

For cryptocurrency-related matters — increasingly common in fraud, tax evasion, and AML cases — GP's digital forensics team conducts blockchain transaction analysis, wallet address clustering, exchange account identification, and the preparation of the technical evidence required for court orders compelling cryptocurrency exchanges to freeze accounts and disclose account holder information.

Core Tools & Standards
Section 65B — IT Act EnCase / FTK Forensic Tools Blockchain Analytics Chain of Custody Protocol eDiscovery — Relativity ACFE Standards
Practice at a Glance
Evidence Types
Emails · WhatsApp · Hard drives · Accounting software · Cloud storage · Smartphones · Deleted files · Metadata · Cryptocurrency
Legal Use Cases
Tax search response · Corporate fraud investigation · Employment dispute · IP theft · Cybercrime · Commercial arbitration · AML investigation
Key Standard
Every collection is Section 65B-compliant from Day 1 — the foundation of admissibility in Indian proceedings
Crypto Capability
Blockchain analytics · Wallet clustering · Exchange identification · Court orders for KYC disclosure · AML transaction monitoring
Speak to Our Digital Forensics Team
What We Do

Digital Forensics Services

Section 65B-compliant evidence collection, deleted data recovery, accounting software analysis, cryptocurrency tracing, and the expert evidence that makes digital findings usable in Indian courts and tribunals.

💻

Electronic Evidence Collection & Preservation

Forensic imaging of hard drives, solid-state drives, and removable media — creating bit-for-bit forensic copies that preserve the original evidence and allow analysis without altering the source device. Smartphone data extraction — iOS and Android devices — including call records, SMS, WhatsApp and other messaging applications, photos, and application data. Email archive collection — Microsoft Exchange, Google Workspace, and other email platforms — with custodian-specific collection and deduplication. Cloud storage collection — OneDrive, Google Drive, Dropbox — with timestamp and metadata preservation. Every collection is documented with hash verification and chain of custody records, and each extraction is accompanied by a Section 65B certificate prepared for use in Indian legal proceedings.

Learn More →
🔍

Deleted Data Recovery & Metadata Analysis

Recovery of deleted files from hard drives, SSDs, and flash storage — including files deleted by a user prior to an investigation, files in the Windows Recycle Bin, and files in system temp folders. Recovery of deleted emails from Exchange and Gmail accounts, including emails deleted from sent items and from the trash folder. Metadata analysis — identifying the original creation date, modification history, and author of documents that have been backdated or where the document's provenance is disputed. Analysis of the Windows Registry and file system artefacts — user activity logs, USB device connection history, file access timestamps — that establish who did what on a device and when.

Learn More →
📈

Accounting Software Forensics

Forensic analysis of accounting software databases — Tally, SAP, Oracle, QuickBooks, and custom ERP systems — to reconstruct the transaction history, identify deleted or modified entries, and establish the full record of accounting activity including entries that have been reversed or altered after the period in question. In tax search proceedings — analysis of the accounting software data seized by the IT Department to identify entries that have been mischaracterised in the Department's assessment, and to establish the correct accounting treatment of transactions that the Department is seeking to add back as income. Transaction log analysis — establishing the sequence of accounting entries and the user who made each entry, for accountability in fraud investigations.

Learn More →
🤗

Cryptocurrency Tracing & Blockchain Analysis

Blockchain transaction analysis — tracing the movement of cryptocurrency from identified source wallets through the transaction chain, identifying mixing and tumbling events, and following the chain to exchange deposit or off-ramp events. Wallet address clustering — identifying the set of wallet addresses that are controlled by the same entity through behavioural and technical analysis. Exchange identification — determining which exchange platform received a deposit, enabling court orders for KYC disclosure. Cryptocurrency evidence for court proceedings — preparing blockchain analysis in a form that satisfies Section 65B requirements and that can be explained to a judge without technical background. AML transaction monitoring analysis — identifying suspicious transaction patterns in client cryptocurrency portfolios for regulatory reporting.

Learn More →
📋

Tax Search — Seized Electronic Records Review

Review and analysis of electronic records seized by the Income Tax Department during a search under Section 132 — identifying the complete contents of seized devices, understanding the accounting and financial records contained within them, and building the taxpayer's response to the Department's assessment of those records. Identification of mischaracterisations in the Department's assessment — where the Department has drawn incorrect conclusions from seized electronic data, the digital forensics team provides the technical evidence that challenges those conclusions. Assistance in preparing the taxpayer's statement under Section 132(4) — ensuring that the taxpayer's description of seized electronic records is accurate and consistent with what the records actually contain.

Learn More →
📄

eDiscovery & Document Review for Litigation

Large-scale document collection, processing, and review for commercial litigation, arbitration, and regulatory proceedings — where the volume of potentially relevant documents exceeds what manual review can handle. Technology-assisted review — using AI-powered document review tools to identify relevant documents from large collections, reducing review time and cost while improving accuracy. Production of documents in electronic form for court proceedings and arbitrations with the appropriate metadata and format requirements. Litigation hold management — maintaining the documentary record of when a hold was implemented, what was covered, and the steps taken to ensure compliance. Privilege review — identifying and logging potentially privileged documents in the collected set before production to the opposing party or regulator.

Learn More →
Key Highlights

The four digital evidence mistakes that make otherwise strong cases unwinnable in Indian courts and tribunals.

Section 65B — the certificate that turns digital evidence into admissible evidence
Section 65B of the Indian Evidence Act provides that electronic records are admissible as evidence only if accompanied by a certificate from a person occupying a responsible official position in relation to the operation of the relevant device, certifying that the electronic record was produced from the device, that the device was operating properly, and that the electronic record reproduces the information stored in the device. The Supreme Court's decision in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal has made Section 65B certification mandatory for all electronic evidence in court proceedings. Digital evidence collected without a contemporaneous Section 65B certificate — or with an inadequate certificate — is inadmissible. GP collects every piece of digital evidence with the Section 65B certificate prepared as part of the collection process, not as an afterthought.
The deleted WhatsApp message — it is not as deleted as the sender thinks
WhatsApp messages deleted by a user are not necessarily gone. On most Android devices, WhatsApp stores backup files locally and in Google Drive that can be extracted and analysed to recover deleted messages. On iOS devices, iCloud backups may contain earlier versions of WhatsApp data that include messages subsequently deleted. The "delete for everyone" function — which removes a message from both sender and recipient devices — does not remove the message from backup files that predate the deletion. In fraud investigations, employment disputes, and commercial litigation, the recovery of deleted WhatsApp communications has produced some of the most consequential evidence — because the sender believed the message was gone. GP's digital forensics team uses certified tools to extract and recover WhatsApp data from device backups, producing a Section 65B-certified record of the recovered messages.
Metadata — the document's hidden testimony about its own creation
Every Microsoft Word document, Excel spreadsheet, and PDF contains metadata — information about when the file was created, when it was last modified, who created it, on which device, and through which software. A document that is backdated — created on a particular date but dated in its visible content as an earlier date — will have metadata that reveals the actual creation date. A contract that is alleged to have been signed years ago but which was actually created recently will have Microsoft Office metadata showing the actual creation date. In commercial disputes, fraud investigations, and tax cases where the date of a document is disputed, metadata analysis is often determinative. GP's digital forensics team conducts metadata analysis as a standard step in any document-intensive investigation or dispute.
The IT Department's seized hard drive — understanding what it actually contains
When the Income Tax Department seizes hard drives, laptops, and accounting software data during a search, it receives a substantial volume of digital evidence that it must review, analyse, and use to form its assessment conclusions. The IT Department's digital forensics capability is limited — it frequently mischaracterises accounting entries, draws incorrect conclusions from partial records, or fails to understand the context of communications that are presented as evidence of concealment. GP's digital forensics team reviews the identical data that the IT Department has seized — understanding precisely what was taken, what the data actually shows, and where the Department's characterisation of the data is incorrect. This analysis is the foundation of the taxpayer's response to the assessment and, ultimately, the ITAT appeal.
The Employee Who Took the Files When They Left

An employee who leaves for a competitor — taking a client list, a pricing database, source code, or confidential business information — almost always leaves a digital trail. USB device connection logs on a Windows system record every time a USB storage device is connected, and can identify the specific device. Cloud storage synchronisation logs record which files were synced to personal storage accounts. Email "sent items" records show forwarded emails containing attachments. Browser history may show files uploaded to personal accounts. The employee who believes they covered their tracks in most cases did not — because the evidence is in the system logs, not in files that they can delete. GP's digital forensics team recovers this evidence and prepares it for use in an injunction application, an employment tribunal, or a civil claim for breach of confidentiality.

How GP's Digital Forensics Integrates With the Legal Strategy

Digital forensics evidence is only as valuable as the legal use that is made of it. A recovered WhatsApp message that shows fraudulent intent is not useful unless it is presented in the correct legal form, in the correct proceeding, through a witness who can authenticate it, with a Section 65B certificate that establishes its admissibility. GP's digital forensics team does not work in isolation — it works as part of the legal team, understanding what the lawyers need the evidence to establish, and collecting and presenting it in the form that the lawyers can use. The forensic specialist who testifies as a Section 65B certificate holder in court is the same person who collected the evidence — not a new witness who must be briefed on what was done and why.

The IT Department Is at Your Office. They Are Imaging Your Servers. You Have a Right to Understand What They Are Taking.

During a tax search under Section 132, the IT Department has the right to seize books of account and other documents — including electronic records and computers. The taxpayer has the right to be present during the search, to have a witness present, and to obtain a list of all documents and items seized. In practice, the IT Department's seizure of electronic records is often conducted rapidly, without adequate documentation of exactly what is being imaged, and without providing the taxpayer with a clear record of the seized data. GP's digital forensics team can attend at the search premises during a search — documenting what is being seized, identifying data that is being imaged outside the scope of the search warrant, and ensuring that the taxpayer has an accurate record of the seizure to form the basis of their subsequent response. If you are facing a search, call GP immediately.

The GP Difference

Why GP for Digital Forensics

1

Section 65B compliance built into every collection — not added afterwards

Most digital forensics practitioners — including many who operate as independent experts in India — are not lawyers and do not fully understand the Section 65B admissibility requirements. They collect the data, then ask a lawyer to prepare the certificate later. The Supreme Court's Arjun Panditrao decision makes clear that the certificate must be prepared by a person occupying a responsible official position at the time of collection. GP's digital forensics specialists understand Section 65B from their first day of work — because they work in a law firm, alongside lawyers, on matters where admissibility is the purpose of the collection. The certificate is prepared contemporaneously with the collection, by the person who conducted it.

2

Digital evidence analysed in legal context — not as a technical exercise

A standalone digital forensics firm produces a technical report describing what it found. GP's digital forensics team produces analysis that is designed to answer the specific legal questions in the specific proceedings — what this email means for the fraud investigation, what this accounting entry means for the tax assessment, what this metadata means for the document's authenticity dispute. The technical analysis is conducted with the legal context understood from the first day — because the digital forensics specialist sits in the same room as the lawyer, working on the same instruction, towards the same legal objective.

3

Tax search presence — GP's digital forensics team can attend at the search

The moment at which digital evidence from a tax search is most important is the moment of the search itself — when the IT Department is imaging devices and the taxpayer has the opportunity to document what is being taken. Most law firms cannot provide a digital forensics specialist to attend at the search premises because their digital forensics capability is outsourced. GP's digital forensics team can be deployed to a search premises on the same basis as GP's tax search lawyers — because they are part of the same firm and receive the same emergency call. The documentation of what was seized, prepared contemporaneously at the search, is the foundation of the taxpayer's subsequent response to the assessment.

Representative Matters

The type of work we do.

Complete confidentiality maintained.

India Tax Search — Accounting Data

Manufacturing company — Rs.34Cr income tax addition based on seized Tally data challenged, Rs.28Cr addition deleted after digital forensic analysis

Advised a manufacturing company following an income tax search in which the Department seized the company's Tally accounting software database and used entries in a separate, unrelated Tally company on the same server to raise a Rs.34 crore addition to income. GP's digital forensics team analysed the seized Tally database in full — demonstrating that the entries the Department had relied upon were from a different company's books maintained on the same server for a different business purpose, that the entries the Department characterised as unrecorded income were in fact inter-company loan transactions that had been misread, and that the Tally database's audit trail showed no entries had been manipulated or backdated. The ITAT deleted Rs.28 crore of the addition on the strength of the digital forensic analysis, accepting that the Department had fundamentally mischaracterised the seized data.

India IP Theft — Departing Employee

Technology company — departing CTO's data theft identified through device forensics, injunction obtained, former employer's source code recovered

Advised a technology company on the digital forensic investigation of a departing CTO who had resigned to join a direct competitor. GP's digital forensics team imaged the CTO's company-issued laptop and found: USB device connection logs showing a 256GB drive connected on his last day of employment; Windows file access logs showing access to 847 source code files in the four hours before the USB was connected; and email server logs showing forwarding of 23 emails containing source code attachments to a personal Gmail account. GP prepared a Section 65B-certified forensic report covering all three data sets and used it as the evidentiary foundation for an ex parte Anton Piller order before the Delhi High Court, requiring the CTO and his new employer to surrender all devices, servers, and cloud accounts that might contain the stolen source code. The source code was recovered and the CTO's new employer signed an undertaking not to use the technology.

India Contract Dispute — Backdated Document

Commercial dispute — opponent's key contract document proved backdated through metadata analysis, High Court accepted expert evidence, summary judgement obtained

Advised a commercial dispute client whose counterparty was relying on a written agreement allegedly entered two years before the dispute arose to defeat the client's Rs.18 crore claim. GP's digital forensics team conducted metadata analysis of the Word document that the counterparty had produced as the agreement — revealing that the document's "Created" date was eight months after the alleged agreement date, that the document had been created using a version of Microsoft Office released two years after the agreement was supposedly executed, and that the file's "Author" metadata showed a person who was not employed by the counterparty at the alleged agreement date. GP's digital forensics expert gave evidence as an expert witness before the Commercial Court, authenticating the metadata analysis under Section 65B. The Court accepted the expert evidence, found the document to be a fabrication, and granted summary judgement in the client's favour.

Practice Leadership

Our Digital Forensics practice is led by a certified digital forensics specialist with specific proficiency in Indian court admissibility requirements — working alongside GP's tax, fraud, and litigation lawyers on every matter where digital evidence is the critical variable.

The practice team includes specialists in device forensics (EnCase and FTK certified), mobile forensics (iOS and Android), accounting software analysis (Tally, SAP, Oracle), blockchain analytics, and large-scale eDiscovery (Relativity platform). Every team member understands Section 65B certification requirements and prepares the certificate as part of the collection process.

For tax search matters — where GP's tax search lawyers attend at search premises — the digital forensics team is available to attend simultaneously, documenting the seizure of electronic records and understanding their contents from the moment of seizure rather than weeks later when an assessment notice arrives.

GP
Digital Forensics Team
Certified Digital Specialists + Legal Integration
EnCase / FTK Certified Section 65B Expert Blockchain Analytics Tally / SAP / Oracle Tax Search Attendance
Forums: Commercial Courts · ITAT · High Courts · NCLT · CBI Special Courts · SEBI · Domestic and international arbitration
✉ Write to Our Digital Forensics Team All Forensic Accounting Services
Related Practices
🔍
Tax Search & Seizure
The digital forensics team attends at tax searches alongside the tax search lawyers — understanding seized electronic records from the moment of seizure, not from an assessment notice weeks later.
💼
Corporate Fraud Investigation
Every corporate fraud investigation involves digital evidence — the digital forensics team is deployed in every significant fraud investigation to recover the electronic evidence that the investigation requires.
🔒
Cybersecurity & DPDP
Post-breach digital forensics — identifying the scope of a breach, the data accessed, and the evidence required for CERT-In reporting and regulatory proceedings.
®
IP & Technology Law
IP theft investigation — when a departing employee or contractor takes code, trade secrets, or confidential information, the digital forensics team recovers the evidence for the IP enforcement action.
Latest Insights
Evidence Guide

Section 65B After Arjun Panditrao — Everything You Need to Know About Making Electronic Evidence Admissible in Indian Courts

Who can issue the certificate, when it must be issued, what it must say, and the common mistakes that make electronic evidence inadmissible despite being technically probative — a practitioner's guide after the Supreme Court's definitive ruling.

Read Guide →
Digital Alert

WhatsApp Evidence in Indian Courts — What Can Be Recovered, How It Is Authenticated, and What the Supreme Court Has Said

The technology of WhatsApp evidence recovery, the Section 65B authentication process for chat exports, the admissibility of WhatsApp evidence in commercial and criminal proceedings, and what "delete for everyone" actually deletes.

Read Alert →
Digital Forensics

Speak to Our Digital Forensics Team

Whether you need electronic evidence collected and preserved, deleted data recovered, accounting software analysed, cryptocurrency traced, or Section 65B-compliant expert evidence for court — our team is available immediately for tax searches and urgent matters.

Section 65B compliant from Day 1 — the certificate that makes evidence admissible
Tax search attendance — GP's digital team can be at the search premises immediately
Cryptocurrency tracing — blockchain analytics to exchange identification and account freeze
Immediate for searches and urgent matters — 24 hours otherwise
Send Us a Message

By submitting you agree to our Privacy Policy. All communications are strictly confidential.