RANCHI ED | DIGITAL EVIDENCE | MOBILE PHONES | WHATSAPP | EMAIL | TALLY & ACCOUNTING RECORDS
Digital Evidence in Ranchi ED Cases: Phones, WhatsApp, Email and Accounting Data — Search, Seizure, Admissibility and Defence
Detailed legal research by Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts
Researched and legally updated: 5 August 2026
Direct Answer: What Is the Importance of Digital Evidence in a Ranchi ED Case?
Mobile phones, WhatsApp chats, emails, cloud records and accounting data can become central evidence in a Ranchi-linked PMLA investigation because they may be used to reconstruct communication, control, instructions, transaction timing, beneficial ownership, document preparation and the alleged movement or use of funds.
A seized electronic record is not automatically conclusive merely because it was recovered from a phone, laptop or office server. Its legal value depends upon:
- the lawful authority under which it was collected;
- the person from whose possession or control it was obtained;
- the manner in which the data was extracted;
- whether the original source was preserved;
- whether hash values or integrity records were generated;
- whether the complete record or only selected material was examined;
- whether the relevant user can be identified;
- whether the timestamps and time zone are reliable;
- whether the electronic-record requirements are satisfied;
- whether the material is connected with a scheduled offence;
- whether it establishes a proceeds-of-crime transaction; and
- whether it proves the individual role alleged against the person concerned.
A phone owner is not automatically the author of every message stored on the phone. A recipient of an email is not automatically part of the transaction discussed in the email. An accountant who entered a voucher is not automatically the beneficiary or decision-maker. Each conclusion requires a separate evidentiary foundation.
Ranchi Zonal Office and Local Case Preparation
The Directorate of Enforcement officially lists the Ranchi Zonal Office at:
Plot No. 1502/B,Airport Road,
Hinoo,
Ranchi, Jharkhand – 834002.
The investigating office should nevertheless be verified from the actual summons, search record, seizure memo, freezing order, provisional attachment order or prosecution complaint.
A person should not assume that every matter concerning Jharkhand is necessarily being investigated by the Ranchi Zonal Office, or that every electronic record requested by an officer has the same relevance.
Official 2026 Ranchi Digital-Evidence Illustration
In an official press release dated 30 March 2026, the Ranchi Zonal Office stated that digital forensic analysis of a mobile phone seized during search operations revealed WhatsApp communications relied upon in its investigation.
The same press release referred to financial records, bank statements, share certificates, corporate records and digital devices recovered during the investigation.
This is an illustration of the type of material that may be examined. The statements in an ED press release represent the agency’s investigative case and should not be treated as a substitute for final judicial findings.
Contents
- Meaning and categories of digital evidence
- ED powers under PMLA
- Mobile phones and laptops
- WhatsApp and messaging records
- Email and cloud evidence
- Tally, ERP and accounting data
- Evidence-to-transaction correlation
- Forensic integrity and hash values
- Electronic-record admissibility
- Section 22 PMLA presumptions
- What to do during an ED search
- Steps after seizure of devices
- Role-specific defence preparation
- Adaptable digital-evidence formats
- Frequently asked questions
Important Legal Verification Notice
The evidentiary law applicable to an electronic record may depend on the date of the proceeding, the form in which the record is produced, whether the original source is available, and the applicable transitional law.
Sections 61 to 63 of the Bharatiya Sakshya Adhiniyam, 2023 presently govern the proof of electronic and digital records in proceedings to which that statute applies. Older judgments applying Sections 65A and 65B of the Indian Evidence Act remain relevant only after examining the present statutory wording and transition.
This article does not advise any person to conceal, destroy, reset, remotely wipe, overwrite, alter or fabricate a device or digital record. Destruction or manipulation may create serious evidentiary and legal consequences.
What Constitutes Digital Evidence in an ED Investigation?
Digital evidence includes information stored, generated, communicated, processed or preserved through a computer, communication device, server, storage medium, application, cloud account or electronic system.
| Evidence category | Possible material | Principal legal question |
|---|---|---|
| Mobile phone | Messages, calls, contacts, application data, media, location artefacts and documents | Who used the device and created the relevant material? |
| WhatsApp or messaging | Chats, groups, attachments, voice notes, calls and backups | Is the conversation complete, authentic and correctly attributed? |
| Message body, full headers, attachments, routing information and mailbox logs | Who sent the email, who controlled the account and was it altered or forwarded? | |
| Accounting software | Ledgers, vouchers, journal entries, user logs, audit trail and backups | Does the entry reflect a real transaction and who authorised it? |
| Spreadsheet | Calculations, hidden sheets, formulas, macros, comments and revision metadata | Was it an official record, a working paper or an unimplemented proposal? |
| ERP and server | Vendor master, purchase orders, approvals, inventory and login history | Which user performed the action and was the system record complete? |
| Cloud account | Synced files, access logs, shared folders, backups and account history | Who controlled the cloud account and what provider-side records exist? |
| Financial platform | Online banking, payment-gateway, exchange and wallet records | Does the electronic instruction correspond with an actual money transfer? |
ED Powers Concerning Digital Records Under PMLA
Section 17: Search and Seizure
Section 17 permits an authorised officer, subject to the statutory conditions and recorded reasons, to search premises where records, proceeds of crime or property connected with the investigation are believed to be kept.
The search may involve:
- mobile phones;
- laptops and desktop computers;
- hard drives and storage devices;
- servers;
- email and cloud-access records;
- accounting backups;
- digital invoices;
- spreadsheets;
- company records; and
- other records considered relevant to the investigation.
Where seizure is impracticable, the statute also contains a freezing mechanism. The exact action should be identified from the search record and written order.
Where records or property are seized or frozen under Section 17, the authority is required to approach the Adjudicating Authority within the statutory period for retention or continuation.
Section 21: Retention of Records
Section 21 provides for retention of seized or frozen records for a period not exceeding 180 days, subject to the statutory process.
Continued retention beyond that period requires permission from the Adjudicating Authority upon satisfaction that the records are required for adjudication.
The person from whom records were seized or frozen is entitled to obtain copies. A written request should identify:
- the search date;
- the panchnama or seizure record;
- the device or storage medium;
- the business records required;
- the reason copies are necessary; and
- the preferred secure format.
Section 22: Presumption as to Records
Section 22 creates statutory presumptions concerning records or property found in a person’s possession or control, or otherwise produced, resumed, seized or frozen under the applicable legal framework.
The provision may support presumptions concerning:
- ownership or belonging;
- truth of the contents; and
- handwriting, signature, execution or attestation.
These presumptions make digital-record preparation particularly important. A person disputing a record should not rely upon a general statement that electronic material can be manipulated. The response should identify the specific defect, alternative user, missing context, technical limitation or inconsistent external record.
Section 50: Summons and Production of Records
Section 50 empowers specified PMLA authorities to summon a person, require attendance, compel production of records and receive evidence.
A summons may seek:
- mobile-device details;
- email exports;
- WhatsApp chats;
- accounting ledgers;
- Tally or ERP backups;
- bank reconciliation;
- digital invoices;
- vendor data;
- company access logs; or
- explanations concerning particular electronic entries.
The reply should follow the exact summons. Unrequested bulk data should not be supplied without understanding relevance, confidentiality, privilege, third-party rights and the scope of the investigation.
Mobile Phones and Laptops in Ranchi ED Cases
A mobile phone may contain evidence extending far beyond visible messages. Depending on the device, application, operating system, encryption, backup and lawful extraction method, an examination may involve:
- device identifiers;
- SIM and account details;
- contacts;
- call records stored on the device;
- messaging databases;
- photographs and videos;
- documents and downloaded files;
- browser history;
- application data;
- location artefacts;
- Wi-Fi connections;
- cloud synchronisation;
- deleted artefacts, where technically available;
- creation and modification timestamps; and
- links with other devices or accounts.
Device Ownership Is Not the Same as User Attribution
A phone registered or seized from one person may have been:
- shared with an employee or family member;
- used by an authorised assistant;
- connected to a shared business account;
- operated through remote-access software;
- temporarily possessed by another person;
- restored from an earlier device backup;
- linked to multiple web sessions; or
- compromised.
Attribution should therefore examine:
- device possession at the relevant time;
- screen-lock and biometric access;
- SIM and account registration;
- typing and language patterns;
- corresponding messages on another device;
- call and location evidence;
- independent witness evidence;
- business role; and
- transaction records.
Forensic Extraction Types
Depending on the device and available method, data may be collected through:
- logical extraction;
- file-system extraction;
- physical or storage-level acquisition;
- cloud acquisition;
- application-specific export; or
- manual documentation of visible content.
Different extraction methods may produce different datasets. A report should disclose what method was used and what could not be extracted.
WhatsApp and Messaging Evidence
WhatsApp evidence may include:
- one-to-one conversations;
- group conversations;
- group-administrator information;
- attachments;
- voice notes;
- call history;
- contact cards;
- shared locations;
- payment references;
- forwarded messages;
- linked-device sessions;
- application databases;
- local or cloud backups; and
- deleted-message artefacts, where available.
A Screenshot Is Not the Complete Chat
A screenshot may omit:
- earlier and later messages;
- group-member changes;
- message replies;
- forwarded-message status;
- attachments;
- deleted messages;
- contact-number changes;
- date and time settings;
- editing or cropping; and
- the original application database.
Where a serious allegation depends on a selected screenshot, the defence may seek examination of the complete conversation and surrounding digital material.
Questions to Ask About a WhatsApp Message
- From which device was the message extracted?
- Was it recovered from the sender, recipient or a third party?
- Is the complete chat available?
- What phone number was associated with the account?
- Who controlled that number and device at the relevant time?
- Was the message forwarded?
- Does it contain an attachment?
- Was the attachment opened, created or merely received?
- What was the surrounding conversation?
- Does an independent transaction correspond with the message?
- Is the timestamp normalised to the correct time zone?
- Was the extraction method recorded?
Messages May Show Discussion, Not Completion
A message discussing money, property, a company or a proposed transfer does not automatically prove that the transaction occurred.
The communication should be correlated with:
- bank statements;
- cash records;
- registration documents;
- invoices;
- ledger entries;
- company resolutions;
- possession records;
- travel or meeting evidence; and
- statements of the persons involved.
Email and Cloud Evidence
An email displayed on a screen or printed on paper may not reveal its full technical and factual history.
Important Email Components
- sender address;
- recipient and copied recipients;
- full email headers;
- Message-ID;
- routing path;
- server timestamps;
- authentication results;
- reply and forwarding chain;
- attachments;
- mailbox folder;
- alias or shared-mailbox information;
- login and access logs; and
- retention or deletion history.
Receipt Is Not Approval
A person copied on an email does not automatically approve or adopt its contents. The evidence should show whether the person:
- opened the message;
- responded;
- issued an instruction;
- implemented the proposal;
- had authority over the transaction; or
- received a benefit.
Shared and Departmental Mailboxes
Corporate accounts may be accessed by multiple employees. Where an email comes from a shared mailbox, investigators and the defence should examine:
- individual login records;
- delegated access;
- device or IP information;
- account permissions;
- mailbox audit logs;
- password-sharing practices; and
- the employee responsible at the relevant time.
Cloud Records
A file visible on a seized laptop may have been synchronised automatically from:
- a corporate drive;
- a shared cloud folder;
- another employee’s account;
- a backup;
- a messaging attachment; or
- an automated system.
File presence should therefore be distinguished from conscious creation, approval, use or knowledge.
Tally, ERP, Spreadsheets and Accounting Data
Accounting data can be especially important in a PMLA investigation because it may be used to test the relationship between recorded business transactions and the alleged proceeds of crime.
Relevant material may include:
- Tally backups and exports;
- ERP databases;
- general ledgers;
- party ledgers;
- cash books;
- bank books;
- journal vouchers;
- payment and receipt vouchers;
- contra entries;
- purchase and sales registers;
- credit and debit notes;
- vendor and customer master data;
- inventory and stock records;
- user-access logs;
- audit trails;
- alteration and deletion records;
- backup history;
- GST returns;
- e-invoices;
- e-way bills;
- spreadsheets;
- management-information reports; and
- bank reconciliations.
An Accounting Entry Is Not Automatically a Real Payment
A ledger entry may represent:
- an actual payment;
- an accrual;
- a provision;
- an adjustment;
- a reversal;
- an opening balance;
- a contra entry;
- a suspense entry;
- a proposed transaction;
- an erroneous entry;
- a back-dated entry; or
- a fictitious transaction.
Its true character should be determined from the underlying records.
Accounting-Entry Verification Matrix
| Accounting record | Corroborating record | Question to answer |
|---|---|---|
| Payment voucher | Bank debit, cheque or cash record | Was money actually paid? |
| Purchase invoice | Purchase order, delivery and stock receipt | Were goods or services actually received? |
| Sales invoice | Dispatch, e-way bill and customer payment | Was the transaction genuine? |
| Journal entry | Approval note and supporting calculation | Why was a non-cash adjustment made? |
| Cash-book entry | Cash availability and recipient evidence | Did the business have sufficient cash? |
| Loan entry | Agreement, lender capacity and banking trail | Was it a genuine loan or accommodation entry? |
| Share capital | Subscriber records, bank trail and allotment | Who supplied the actual consideration? |
| Vendor balance | Vendor confirmation and transaction history | Is the liability genuine and outstanding? |
Who Created the Entry?
An accounting system may record:
- user ID;
- entry date;
- effective voucher date;
- creation timestamp;
- modification timestamp;
- approver;
- terminal or device;
- backup version; and
- alteration history.
The person who typed an entry may not be the person who authorised, funded or benefited from the transaction.
Spreadsheets and Informal Calculations
A spreadsheet may be:
- an official book of account;
- a personal working paper;
- a provisional calculation;
- a budget;
- a comparison;
- a list supplied by another person;
- a draft proposal; or
- an unverified compilation.
The evidentiary conclusion should be based upon its creator, purpose, source data, revision history and correlation with actual transactions.
Digital Evidence Must Be Connected With the Alleged Money Trail
Money laundering under PMLA requires more than the existence of suspicious digital material. The investigation must still identify the scheduled offence, the property alleged to constitute proceeds of crime and the process or activity attributed to the person concerned.
Recommended Correlation Sequence
- Identify the exact message, email or accounting entry.
- Identify the device or system from which it came.
- Identify the person who created or controlled it.
- Identify the date and time.
- Identify the alleged transaction.
- Identify the bank account, cash movement, property or asset involved.
- Identify the scheduled-offence allegation.
- Identify the alleged proceeds-of-crime amount.
- Identify the person’s actual role.
- Test the conclusion against independent records.
Illustrative Correlation Table
| Digital material | Required independent check |
|---|---|
| WhatsApp message saying “payment done” | Bank debit, cash record, recipient confirmation and transaction date |
| Email approving a vendor | Authority matrix, purchase order, delivery, invoice and payment |
| Tally cash entry | Available cash, supporting voucher and recipient evidence |
| Spreadsheet showing profit distribution | Creator, source data, actual transfer and recipient accounts |
| Phone contact with an accused person | Call content, purpose, timing, business relationship and subsequent conduct |
| Property document saved on device | Ownership, acquisition, payment, possession and reason for file presence |
Forensic Integrity, Hash Values and Chain of Custody
Original Device and Working Copy
A forensic examination should ordinarily preserve the original source and perform analysis on an acquired or working copy where technically appropriate.
Directly browsing or altering the original device without proper documentation may affect later verification.
Hash Values
A hash value is a cryptographic fingerprint calculated from electronic data. Matching hash values may help show that the relevant image or output has not changed after the hashes were calculated.
A matching hash value does not independently prove:
- who created the file;
- whether its contents are true;
- whether the correct device was acquired;
- whether the extraction was complete;
- whether the user acted knowingly; or
- whether the record proves money laundering.
Chain of Custody
A chain-of-custody record should identify:
- the device or media;
- the person from whom it was obtained;
- the date, time and location;
- the officer collecting it;
- seal or packaging details;
- each transfer;
- the laboratory or examiner;
- the extraction date;
- the hash values;
- the working copy; and
- return, retention or resealing details.
Forensic Report Checklist
- Examiner’s name and qualification.
- Authority and scope of examination.
- Device identifiers.
- Condition of device when received.
- Extraction method.
- Tool and version.
- Hash algorithm and values.
- Time zone applied.
- Applications examined.
- Encrypted or inaccessible data.
- Extraction errors.
- Deleted-data limitations.
- Findings and supporting artefacts.
- Distinction between fact and inference.
Admissibility Under the Bharatiya Sakshya Adhiniyam, 2023
Section 61
An electronic or digital record is not denied admissibility merely because it is electronic. Subject to the statutory requirements, it may have the same legal effect as another document.
Section 62
The contents of electronic records are to be proved in accordance with Section 63.
Section 63
Section 63 regulates the admissibility of specified computer outputs, including electronic information printed, stored, recorded or copied from a computer, communication device or electronic source.
Where reliance is placed upon a printout, exported chat, copied file, forensic image, spreadsheet export, email output or accounting backup, the following may become central:
- the source device or system;
- lawful control over the device;
- ordinary use of the system;
- regular feeding of information;
- proper operation of the device;
- accuracy of the output;
- device identifiers;
- hash values;
- the person producing the record; and
- the expert component of the statutory certificate.
Statutory Certificate Schedule
The certificate schedule linked with Section 63(4)(c) expressly contemplates:
- computer or storage media;
- DVR;
- mobile phone;
- flash drive;
- server;
- cloud source;
- make and model;
- serial number;
- IMEI, UID, MAC or cloud identifier;
- hash algorithm;
- hash value;
- hash report; and
- expert certification.
Presumption Concerning Electronic Messages
The Bharatiya Sakshya Adhiniyam permits a court to presume that an electronic message forwarded through an email server corresponds with the message fed into the system for transmission.
It does not create an automatic presumption concerning the person who actually sent the message. User attribution therefore remains a separate issue.
How Can Section 22 PMLA Be Rebutted?
A rebuttal should be specific, evidence-based and record-specific.
Possible Rebuttal Grounds
- The device was shared.
- The account belonged to the company, not the individual.
- The record was received but not created or adopted.
- The message was forwarded from another source.
- The screenshot omits material context.
- The file arrived through automatic synchronisation.
- The spreadsheet was a draft or working document.
- The accounting entry was reversed.
- The user lacked transaction authority.
- The timestamp is inconsistent with server or bank records.
- The device had been replaced or restored from backup.
- The extraction omitted surrounding records.
- The transaction never occurred.
- The independent bank trail contradicts the entry.
- The material concerns a legitimate business transaction.
The response should identify the exact record, page, device, account, date and alternative explanation. A blanket denial ordinarily carries less value than a documented forensic and commercial explanation.
Digital-Evidence Workflow in a Ranchi ED Case
Digital evidence should be identified, preserved, verified, correlated and legally tested before a conclusion is drawn.Plain-text alternative: Identify the device and actual user → document seizure and custody → acquire data and record hashes → extract communications and accounting data → test completeness and attribution → correlate with the financial trail → examine PMLA presumptions and electronic-record requirements → prepare a role-specific response.
What to Do During an ED Search Involving Digital Devices
- Do not destroy or reset anything: do not delete chats, wipe devices, uninstall applications or alter accounting data.
- Identify the authority and case reference: preserve the search authorisation details and every document supplied.
- Maintain a device list: record make, model, colour, serial number, IMEI and storage-media details.
- Check the inventory: ensure that the panchnama or seizure record accurately describes every device and storage medium taken.
- Record the user: identify the actual person using each phone, laptop, email account or software login.
- Identify business-critical data: note accounting systems, payroll, GST, vendor, banking and operational records required for continuing business.
- Preserve the search record: obtain and safely retain the panchnama, annexures, inventory and acknowledgments.
- Do not make speculative explanations: an immediate guess concerning an old message or ledger entry may later conflict with the underlying record.
- Record objections accurately: where a device belongs to an employee, family member or third party, that fact should be properly documented.
- Seek legal advice promptly: future Section 50 statements, retention proceedings and transaction explanations may depend on the search-day record.
Steps After ED Seizes a Phone, Laptop or Accounting Server
1. Prepare a Complete Seizure Chart
Record:
- device description;
- owner;
- actual user;
- purpose of device;
- accounts accessible through it;
- business records stored;
- date of seizure;
- seal or inventory reference; and
- whether any copy was supplied.
2. Request Copies of Essential Records
Where the seized device contains records necessary for:
- statutory filing;
- GST compliance;
- employee salary;
- court proceedings;
- banking;
- customer service;
- medical or operational activity; or
- business continuity,
a written application may be prepared seeking copies or controlled access, subject to the applicable procedure and investigative requirements.
3. Preserve Parallel Sources
Preserve lawful and existing copies from:
- company servers;
- backup systems;
- email providers;
- accounting backups;
- bank portals;
- GST systems;
- vendors and customers;
- cloud drives; and
- statutory filings.
Do not create, modify or back-date records after the search.
4. Prepare a Digital-Evidence Chronology
Match each relevant communication or entry with:
- its date;
- the alleged transaction;
- the persons involved;
- the financial record;
- the scheduled-offence allegation; and
- the available lawful explanation.
5. Review Retention Proceedings
Check whether ED has followed the statutory process concerning retention or continuation of freezing before the Adjudicating Authority.
Role-Specific Digital-Evidence Preparation
Director or Promoter
- Identify decision-making authority.
- Separate personal and company devices.
- Explain company approval systems.
- Reconcile instructions with board or business records.
- Identify delegated functions.
Accountant or Tally Operator
- Explain who supplied source documents.
- Identify who approved vouchers.
- Explain user IDs and access rights.
- Separate data entry from commercial decision-making.
- Identify reversals and corrections.
Chartered Accountant or External Adviser
- Define the scope of engagement.
- Identify records supplied by the client.
- Separate audit, compliance and management functions.
- Identify assumptions and qualifications.
- Preserve engagement and working-paper records.
Employee
- Identify designation and reporting line.
- Explain custody of company devices.
- Identify shared accounts.
- Distinguish receipt of instruction from authority to approve.
- Explain routine and automated communications.
Family Member or Third Party
- Identify ownership of the device.
- Explain why company material was present.
- Identify any shared cloud or email account.
- Separate personal transactions from investigated transactions.
- Preserve independent financial records.
Standard Adaptable Digital-Evidence Inventory
The following is a private case-preparation format. It is not an official ED, Adjudicating Authority, forensic-laboratory or court form.
DIGITAL-EVIDENCE INVENTORY — RANCHI ED / PMLA MATTER
A. CASE DETAILS
1. Summons / search / ECIR reference:
2. Investigating office:
3. Search date:
4. Premises searched:
5. Person from whom device was obtained:
6. Panchnama or seizure-document number:
B. DEVICE DETAILS
7. Evidence ID:
8. Device type:
9. Make and model:
10. Colour:
11. Serial number:
12. IMEI / MAC / other identifier:
13. Storage capacity:
14. SIM or account linked:
15. Registered owner:
16. Actual user:
17. Shared users:
18. Purpose of device:
19. Condition when seized:
20. Seal or packaging details:
C. DIGITAL ACCOUNTS
21. Email accounts:
22. Messaging accounts:
23. Cloud accounts:
24. Accounting-software accounts:
25. ERP user IDs:
26. Banking or payment accounts:
27. Shared or delegated access:
28. Linked devices:
D. FORENSIC ACQUISITION
29. Date of acquisition:
30. Examiner or laboratory:
31. Acquisition method:
32. Tool and version:
33. Original-device hash:
34. Acquired-image hash:
35. Hash algorithm:
36. Time zone:
37. Extraction errors:
38. Encrypted or unavailable data:
39. Working-copy details:
E. MATERIAL RELIED UPON
40. WhatsApp chat:
41. Email:
42. Attachment:
43. Call record:
44. Photograph or video:
45. Tally entry:
46. ERP record:
47. Spreadsheet:
48. Bank record:
49. Cloud file:
50. Other record:
F. ATTRIBUTION AND CONTEXT
51. Alleged author:
52. Basis of attribution:
53. Surrounding conversation:
54. Independent corroboration:
55. Contradictory evidence:
56. Alleged transaction:
57. Scheduled-offence link:
58. Proceeds-of-crime link:
59. Person’s actual role:
60. Defence explanation:
G. LEGAL REVIEW
61. Section 17 compliance:
62. Section 21 retention status:
63. Copy requested:
64. Section 22 presumption:
65. Section 63 certificate:
66. Hash report:
67. Expert report:
68. Chain-of-custody issue:
69. Relief or application required:
Digital-Evidence Preservation Notice
INTERNAL DIGITAL-EVIDENCE PRESERVATION NOTICE
All concerned persons are directed to preserve, without alteration,
deletion, resetting, overwriting or destruction:
1. Mobile phones and SIM cards.
2. Laptops and computers.
3. Email accounts and complete mailbox data.
4. WhatsApp and other messaging records.
5. Cloud-storage accounts.
6. Tally, ERP and accounting backups.
7. Audit-trail and user-access records.
8. Bank statements and transaction exports.
9. GST, e-invoice and e-way bill records.
10. Vendor and customer master data.
11. Spreadsheets and management reports.
12. Server and security logs.
13. Original documents corresponding with digital entries.
14. Backup media.
15. Device and account inventories.
No person shall:
• remotely wipe a device;
• delete a chat or email;
• alter an accounting entry;
• back-date a record;
• replace a file;
• fabricate a document; or
• destroy a backup.
The preservation direction applies until written legal clearance.
Date:
Issued by:
Scope:
Acknowledged by:
Common Mistakes in Digital-Evidence Cases
- Assuming every message on a phone was sent by the owner.
- Explaining an old message without checking the complete chat.
- Relying only on cropped screenshots.
- Ignoring group context and forwarded-message status.
- Failing to obtain full email headers.
- Confusing receipt of an email with approval.
- Treating every saved file as consciously created or used.
- Assuming a ledger entry proves actual payment.
- Failing to reconcile Tally data with bank and source documents.
- Ignoring deleted, reversed or altered vouchers.
- Failing to identify the accounting user and approver.
- Not preserving pre-search backups.
- Resetting or replacing devices after learning of an investigation.
- Giving inconsistent explanations to ED, police, tax and company authorities.
- Not requesting copies of business-critical seized records.
- Not checking the Section 21 retention process.
- Ignoring Section 22 presumptions.
- Failing to examine the Section 63 certificate and hash report.
- Challenging evidence through vague allegations of manipulation.
- Failing to connect the record with the scheduled offence and alleged proceeds.
How Can Digital Evidence Be Legally Challenged?
The correct challenge depends upon the proceeding and the precise defect.
Possible Grounds
- Search or seizure did not satisfy the statutory framework.
- The device was inaccurately identified.
- The inventory or chain of custody is incomplete.
- The original source was not preserved.
- The acquisition method is undisclosed.
- Hash values are missing or inconsistent.
- The extraction was partial.
- The complete conversation was withheld.
- The record was obtained from a third party without proper attribution.
- The user account was shared.
- The timestamp or time zone is unreliable.
- The accounting data was misunderstood.
- The entry was reversed or never implemented.
- The corresponding bank transaction does not exist.
- The Section 63 certificate is absent, incomplete or unrelated to the output.
- The expert report does not disclose methodology.
- The evidence does not establish a scheduled-offence or proceeds nexus.
- The material does not establish the person’s role or knowledge.
Possible Legal Routes
- Written response to a Section 50 summons.
- Representation seeking copies or access to records.
- Objection in retention or attachment adjudication.
- Section 8 reply concerning attached or retained records.
- Appeal before the PMLA Appellate Tribunal.
- Discharge application before the competent Special Court.
- Cross-examination of the relevant witness or expert.
- Application for production or inspection of complete electronic material.
- Appropriate writ or appellate remedy before the competent High Court.
The existence of the Jharkhand High Court at Ranchi does not mean every digital-evidence dispute should begin through a writ petition. The statutory remedy, procedural stage and urgency must first be identified.
Frequently Asked Questions
1. Can ED seize my phone during a Ranchi search?
ED may seize or freeze a device or record where the statutory requirements are satisfied. The authorisation, inventory, connection with the investigation and retention process should be examined.
2. Does seizure mean that the phone owner is accused?
No. A device may be seized from an accused, witness, employee, family member or third party. Legal status depends on the allegations and material.
3. Is every WhatsApp message admissible?
No automatic conclusion follows. Source, completeness, attribution, integrity, certificate requirements and context must be examined.
4. Can a screenshot prove a cash payment?
A screenshot may support an allegation, but an actual payment should ordinarily be tested against bank, cash, accounting, recipient and transaction records.
5. What if my employee used my phone?
Preserve evidence concerning shared use, access, timing, account control and the employee’s role. A general oral claim of shared use may be insufficient.
6. Can deleted WhatsApp messages be recovered?
Recovery may be possible in some cases depending on the device, application, encryption, backups, later use and extraction method. It cannot be assumed or guaranteed.
7. Does an email prove that I approved the proposal?
Receipt or copying does not automatically prove approval. Response, authority, subsequent conduct and implementation should be examined.
8. What is the importance of an email header?
Full headers may contain routing, Message-ID, server and authentication information relevant to source and transmission.
9. Does a Tally entry prove that money changed hands?
No. The entry should be reconciled with the bank, cash balance, voucher, invoice, contract, recipient and supporting commercial records.
10. Can an accountant be prosecuted merely for entering a voucher?
Data entry alone does not automatically establish knowledge, conspiracy or money laundering. The person’s authority, instructions, knowledge and benefit must be examined.
11. Can ED retain my accounting server indefinitely?
Section 21 contains a statutory re
