The Short Answer
To prove intellectual property (IP) theft, an employer must isolate the compromised device immediately and engage a forensic expert to extract the data using write-blockers. The resulting secondary electronic evidence is admissible only if accompanied by a dual-signatory certificate displaying cryptographic hash values, strictly mandated by Section 63(4) of the Bharatiya Sakshya Adhiniyam, 2023. Searching personal devices without explicit consent violates the DPDP Act, and presenting the forensic report in a domestic enquiry requires the expert to testify as a live witness to sustain the burden of proof.
The Legal Framework Governing Electronic Evidence
The Bharatiya Sakshya Adhiniyam, 2023 (BSA) and Section 63(4)
When an employee downloads proprietary source code or forwards client databases to a private server, the employer relies on server logs and hard drive artifacts as evidence. Under the Bharatiya Sakshya Adhiniyam, 2023 (BSA) which replaced the Indian Evidence Act on July 1, 2024; the rules for admitting this secondary electronic evidence are procedurally strict.
Section 63(4) of the BSA mandates a two-part certificate for secondary electronic records. The prescribed Schedule demands the cryptographic hash value (e.g., SHA-256 or MD5) of the record to act as a mathematical fingerprint against tampering.
- Part A (The Custodian): Under Section 63(4)(c), Part A must be signed by the person who manages or has lawful control of the device, not necessarily the formal corporate “owner.”
- Part B (The Expert): Part B requires the signature of an independent expert. In its 2026 judgment in Pune Bar Association v. Union of India, the Supreme Court upheld the constitutional validity of the Section 63(4) hash value requirement. The Court also clarified that the expert signing Part B does not strictly need to be a government-notified Section 79A Examiner of Electronic Evidence; an individual with established special skills in computer science and cyber forensics is legally competent to sign the certificate.
Without the exact Section 63(4) certificate, secondary electronic evidence is legally inadmissible.
Employee Privacy Limits Under the DPDP Act, 2023
Section 7(i) of the Digital Personal Data Protection Act, 2023 (DPDP Act) permits the processing of an employee’s personal data without explicit consent for the “purposes of employment” or to safeguard the employer from corporate loss (such as IP theft). However, this statutory exemption is highly restricted:
- Temporal Limit: Section 7(i) applies strictly during the active employment relationship. Once the employee resigns or is terminated, post-employment forensic data processing requires a separate legal basis or explicit, prior consent.
- Intrusive Surveillance: The exemption does not grant blanket authority for invasive monitoring. Executing location tracking, screen recording, or forensic imaging of a personal Bring Your Own Device (BYOD) laptop without explicitly documented prior consent directly violates the DPDP Act.
Concurrent Liability Under the IT Act, 2000
IP theft exposes the defaulting employee to simultaneous civil and criminal liabilities under the Information Technology Act, 2000. Section 43(b) provides for civil compensation awarded by an Adjudicating Officer for the unauthorized downloading or extraction of data. Concurrently, Section 66 imposes severe criminal penalties; imprisonment of up to three years, a fine of up to ₹5,00,000, or both; for executing the data extraction dishonestly or fraudulently. An employer may pursue both remedies simultaneously using the secured forensic report.
Procedural Integration: The Domestic Enquiry Under the 2026 Labour Codes
Following the implementation of the four Labour Codes on November 21, 2025, and the notification of Central Rules on May 8, 2026, disciplinary procedures for terminating a statutory “worker” under Section 2(zr) of the Industrial Relations Code remain strict. The employer must issue a formal charge sheet and conduct a domestic enquiry.
A forensic extraction report is not self-proving. Under established administrative law principles and Andhra Pradesh High Court precedent, the employer always bears the strict burden of proving the charges through oral and documentary evidence. Even if the accused employee absconds or refuses to participate in the enquiry, the employer cannot simply file the BSA certificate on record. The forensic expert must be presented as a management witness to authenticate the extraction methodology and submit to potential cross-examination, failing which the termination can be struck down as procedurally void.
Explicit Statutory Penalties for Non-Compliance
Mishandling an IP theft investigation exposes the employer to severe retaliatory liabilities:
- Void Termination and Back Wages: If a Labour Court rejects the electronic evidence due to a missing Section 63(4) BSA certificate or the failure to present the expert as a witness, the termination is rendered illegal. The court will order immediate reinstatement with full back wages.
- DPDP Act Fines: Extracting data from an employee’s personal device without explicit consent or processing data post-termination without a legal basis constitutes an unlawful data breach, attracting massive financial penalties from the Data Protection Board.
- Code on Wages Penalties: Employers frequently attempt to withhold the departing employee’s Full and Final (F&F) settlement as “compensation” for the stolen IP. Unilaterally deducting from earned wages without a civil court decree violates Section 17(2) of the Code on Wages, 2019. Paying less than the statutory amount due attracts a fine of up to ₹50,000 under Section 54(1)(a). If the employer ultimately pays the full amount but breaches the two-day statutory timeline, a penalty of up to ₹20,000 applies under Section 54(1)(c).
What Employers Must Do Now [FREE]
To legally preserve electronic evidence and secure a defensible termination or prosecution, corporate management and HR heads must execute the following protocol:
- Execute Immediate Device Isolation: Upon suspecting data theft, disconnect the target device from the network immediately to prevent remote wiping. Do not allow internal IT staff to boot the device manually, as normal booting alters metadata and destroys the evidentiary chain of custody.
- Engage Qualified Forensic Experts: Hire a third-party digital forensics expert to create a verifiable bit-by-bit clone of the hard drive using hardware write-blockers. Ensure the expert meets the competency standards clarified in the Pune Bar Association judgment.
- Prepare the Dual-Signatory Section 63(4) Certificate: Ensure the individual actually managing the device signs Part A, and the forensic expert signs Part B. Confirm the certificate explicitly lists the cryptographic hash values (SHA-256 or MD5) of the extracted logs.
- Update Acceptable Use and BYOD Policies: Amend employment contracts to explicitly state that corporate networks are monitored. Obtain distinct, written consent for forensic access to any personal devices used under a BYOD policy, clearly extending this consent to post-termination investigations regarding corporate data.
- Produce the Expert in the Enquiry: Do not rely on paper submissions. Mandate that the forensic expert appears physically or virtually as a witness during the domestic enquiry to prove the electronic record and satisfy the employer’s burden of proof.
Disclaimer: All articles, blogs, guides, and resources published on this website relate to Indian labour laws and compliance frameworks. The content is provided for general informational and educational purposes only and must not be construed as legal advice. Readers should consult our legal team or a qualified advocate for advice on specific workplace disputes or compliance audits.
