Every fraud leaves a digital trail. Every employment dispute has emails. Every tax investigation involves seized hard drives. Every corporate investigation begins with a document review. The question is not whether the digital evidence exists — it is whether it is collected, preserved, and analysed in a way that makes it usable in the proceedings that follow.
Digital forensics in the Indian legal context has specific requirements that distinguish it from the broader field of information security forensics. Indian courts and regulatory bodies — the ITAT, the NCLT, the High Courts, SEBI, and the CBI Special Courts — have specific requirements for the admissibility of electronic evidence under Section 65B of the Indian Evidence Act. A digital forensic collection that does not satisfy the Section 65B certification requirements is inadmissible as electronic evidence — no matter how probative its content. GP's digital forensics team collects, preserves, and analyses electronic evidence with Section 65B compliance built into every collection from the first moment.
The scope of digital forensics work at GP spans the full range of legal proceedings in which electronic evidence is relevant. In tax search and seizure proceedings, the IT Department seizes electronic records — hard drives, laptops, accounting software databases, email archives — and uses them to construct additions to income. GP's digital forensics team reviews seized records, identifies the context that the IT Department may have missed or mischaracterised, and builds the taxpayer's response around a complete digital evidence analysis. In corporate fraud investigations, the team recovers deleted emails, reconstructs WhatsApp conversation records, extracts accounting software transaction logs, and identifies the metadata that establishes who created a document and when. In employment disputes, the team analyses departing employee device contents and email communications for evidence of data theft or breach of confidentiality.
For cryptocurrency-related matters — increasingly common in fraud, tax evasion, and AML cases — GP's digital forensics team conducts blockchain transaction analysis, wallet address clustering, exchange account identification, and the preparation of the technical evidence required for court orders compelling cryptocurrency exchanges to freeze accounts and disclose account holder information.
Section 65B-compliant evidence collection, deleted data recovery, accounting software analysis, cryptocurrency tracing, and the expert evidence that makes digital findings usable in Indian courts and tribunals.
Forensic imaging of hard drives, solid-state drives, and removable media — creating bit-for-bit forensic copies that preserve the original evidence and allow analysis without altering the source device. Smartphone data extraction — iOS and Android devices — including call records, SMS, WhatsApp and other messaging applications, photos, and application data. Email archive collection — Microsoft Exchange, Google Workspace, and other email platforms — with custodian-specific collection and deduplication. Cloud storage collection — OneDrive, Google Drive, Dropbox — with timestamp and metadata preservation. Every collection is documented with hash verification and chain of custody records, and each extraction is accompanied by a Section 65B certificate prepared for use in Indian legal proceedings.
Learn More →Recovery of deleted files from hard drives, SSDs, and flash storage — including files deleted by a user prior to an investigation, files in the Windows Recycle Bin, and files in system temp folders. Recovery of deleted emails from Exchange and Gmail accounts, including emails deleted from sent items and from the trash folder. Metadata analysis — identifying the original creation date, modification history, and author of documents that have been backdated or where the document's provenance is disputed. Analysis of the Windows Registry and file system artefacts — user activity logs, USB device connection history, file access timestamps — that establish who did what on a device and when.
Learn More →Forensic analysis of accounting software databases — Tally, SAP, Oracle, QuickBooks, and custom ERP systems — to reconstruct the transaction history, identify deleted or modified entries, and establish the full record of accounting activity including entries that have been reversed or altered after the period in question. In tax search proceedings — analysis of the accounting software data seized by the IT Department to identify entries that have been mischaracterised in the Department's assessment, and to establish the correct accounting treatment of transactions that the Department is seeking to add back as income. Transaction log analysis — establishing the sequence of accounting entries and the user who made each entry, for accountability in fraud investigations.
Learn More →Blockchain transaction analysis — tracing the movement of cryptocurrency from identified source wallets through the transaction chain, identifying mixing and tumbling events, and following the chain to exchange deposit or off-ramp events. Wallet address clustering — identifying the set of wallet addresses that are controlled by the same entity through behavioural and technical analysis. Exchange identification — determining which exchange platform received a deposit, enabling court orders for KYC disclosure. Cryptocurrency evidence for court proceedings — preparing blockchain analysis in a form that satisfies Section 65B requirements and that can be explained to a judge without technical background. AML transaction monitoring analysis — identifying suspicious transaction patterns in client cryptocurrency portfolios for regulatory reporting.
Learn More →Review and analysis of electronic records seized by the Income Tax Department during a search under Section 132 — identifying the complete contents of seized devices, understanding the accounting and financial records contained within them, and building the taxpayer's response to the Department's assessment of those records. Identification of mischaracterisations in the Department's assessment — where the Department has drawn incorrect conclusions from seized electronic data, the digital forensics team provides the technical evidence that challenges those conclusions. Assistance in preparing the taxpayer's statement under Section 132(4) — ensuring that the taxpayer's description of seized electronic records is accurate and consistent with what the records actually contain.
Learn More →Large-scale document collection, processing, and review for commercial litigation, arbitration, and regulatory proceedings — where the volume of potentially relevant documents exceeds what manual review can handle. Technology-assisted review — using AI-powered document review tools to identify relevant documents from large collections, reducing review time and cost while improving accuracy. Production of documents in electronic form for court proceedings and arbitrations with the appropriate metadata and format requirements. Litigation hold management — maintaining the documentary record of when a hold was implemented, what was covered, and the steps taken to ensure compliance. Privilege review — identifying and logging potentially privileged documents in the collected set before production to the opposing party or regulator.
Learn More →An employee who leaves for a competitor — taking a client list, a pricing database, source code, or confidential business information — almost always leaves a digital trail. USB device connection logs on a Windows system record every time a USB storage device is connected, and can identify the specific device. Cloud storage synchronisation logs record which files were synced to personal storage accounts. Email "sent items" records show forwarded emails containing attachments. Browser history may show files uploaded to personal accounts. The employee who believes they covered their tracks in most cases did not — because the evidence is in the system logs, not in files that they can delete. GP's digital forensics team recovers this evidence and prepares it for use in an injunction application, an employment tribunal, or a civil claim for breach of confidentiality.
Digital forensics evidence is only as valuable as the legal use that is made of it. A recovered WhatsApp message that shows fraudulent intent is not useful unless it is presented in the correct legal form, in the correct proceeding, through a witness who can authenticate it, with a Section 65B certificate that establishes its admissibility. GP's digital forensics team does not work in isolation — it works as part of the legal team, understanding what the lawyers need the evidence to establish, and collecting and presenting it in the form that the lawyers can use. The forensic specialist who testifies as a Section 65B certificate holder in court is the same person who collected the evidence — not a new witness who must be briefed on what was done and why.
During a tax search under Section 132, the IT Department has the right to seize books of account and other documents — including electronic records and computers. The taxpayer has the right to be present during the search, to have a witness present, and to obtain a list of all documents and items seized. In practice, the IT Department's seizure of electronic records is often conducted rapidly, without adequate documentation of exactly what is being imaged, and without providing the taxpayer with a clear record of the seized data. GP's digital forensics team can attend at the search premises during a search — documenting what is being seized, identifying data that is being imaged outside the scope of the search warrant, and ensuring that the taxpayer has an accurate record of the seizure to form the basis of their subsequent response. If you are facing a search, call GP immediately.
Most digital forensics practitioners — including many who operate as independent experts in India — are not lawyers and do not fully understand the Section 65B admissibility requirements. They collect the data, then ask a lawyer to prepare the certificate later. The Supreme Court's Arjun Panditrao decision makes clear that the certificate must be prepared by a person occupying a responsible official position at the time of collection. GP's digital forensics specialists understand Section 65B from their first day of work — because they work in a law firm, alongside lawyers, on matters where admissibility is the purpose of the collection. The certificate is prepared contemporaneously with the collection, by the person who conducted it.
A standalone digital forensics firm produces a technical report describing what it found. GP's digital forensics team produces analysis that is designed to answer the specific legal questions in the specific proceedings — what this email means for the fraud investigation, what this accounting entry means for the tax assessment, what this metadata means for the document's authenticity dispute. The technical analysis is conducted with the legal context understood from the first day — because the digital forensics specialist sits in the same room as the lawyer, working on the same instruction, towards the same legal objective.
The moment at which digital evidence from a tax search is most important is the moment of the search itself — when the IT Department is imaging devices and the taxpayer has the opportunity to document what is being taken. Most law firms cannot provide a digital forensics specialist to attend at the search premises because their digital forensics capability is outsourced. GP's digital forensics team can be deployed to a search premises on the same basis as GP's tax search lawyers — because they are part of the same firm and receive the same emergency call. The documentation of what was seized, prepared contemporaneously at the search, is the foundation of the taxpayer's subsequent response to the assessment.
Complete confidentiality maintained.
Advised a manufacturing company following an income tax search in which the Department seized the company's Tally accounting software database and used entries in a separate, unrelated Tally company on the same server to raise a Rs.34 crore addition to income. GP's digital forensics team analysed the seized Tally database in full — demonstrating that the entries the Department had relied upon were from a different company's books maintained on the same server for a different business purpose, that the entries the Department characterised as unrecorded income were in fact inter-company loan transactions that had been misread, and that the Tally database's audit trail showed no entries had been manipulated or backdated. The ITAT deleted Rs.28 crore of the addition on the strength of the digital forensic analysis, accepting that the Department had fundamentally mischaracterised the seized data.
Advised a technology company on the digital forensic investigation of a departing CTO who had resigned to join a direct competitor. GP's digital forensics team imaged the CTO's company-issued laptop and found: USB device connection logs showing a 256GB drive connected on his last day of employment; Windows file access logs showing access to 847 source code files in the four hours before the USB was connected; and email server logs showing forwarding of 23 emails containing source code attachments to a personal Gmail account. GP prepared a Section 65B-certified forensic report covering all three data sets and used it as the evidentiary foundation for an ex parte Anton Piller order before the Delhi High Court, requiring the CTO and his new employer to surrender all devices, servers, and cloud accounts that might contain the stolen source code. The source code was recovered and the CTO's new employer signed an undertaking not to use the technology.
Advised a commercial dispute client whose counterparty was relying on a written agreement allegedly entered two years before the dispute arose to defeat the client's Rs.18 crore claim. GP's digital forensics team conducted metadata analysis of the Word document that the counterparty had produced as the agreement — revealing that the document's "Created" date was eight months after the alleged agreement date, that the document had been created using a version of Microsoft Office released two years after the agreement was supposedly executed, and that the file's "Author" metadata showed a person who was not employed by the counterparty at the alleged agreement date. GP's digital forensics expert gave evidence as an expert witness before the Commercial Court, authenticating the metadata analysis under Section 65B. The Court accepted the expert evidence, found the document to be a fabrication, and granted summary judgement in the client's favour.
The practice team includes specialists in device forensics (EnCase and FTK certified), mobile forensics (iOS and Android), accounting software analysis (Tally, SAP, Oracle), blockchain analytics, and large-scale eDiscovery (Relativity platform). Every team member understands Section 65B certification requirements and prepares the certificate as part of the collection process.
For tax search matters — where GP's tax search lawyers attend at search premises — the digital forensics team is available to attend simultaneously, documenting the seizure of electronic records and understanding their contents from the moment of seizure rather than weeks later when an assessment notice arrives.
Who can issue the certificate, when it must be issued, what it must say, and the common mistakes that make electronic evidence inadmissible despite being technically probative — a practitioner's guide after the Supreme Court's definitive ruling.
Read Guide →The technology of WhatsApp evidence recovery, the Section 65B authentication process for chat exports, the admissibility of WhatsApp evidence in commercial and criminal proceedings, and what "delete for everyone" actually deletes.
Read Alert →Whether you need electronic evidence collected and preserved, deleted data recovered, accounting software analysed, cryptocurrency traced, or Section 65B-compliant expert evidence for court — our team is available immediately for tax searches and urgent matters.
By submitting you agree to our Privacy Policy. All communications are strictly confidential.