Madhya Pradesh has carefully built the digital "plumbing" for handling electronic evidence. But three choices in the design - an imbalance that favours the police, a fee rule that can quietly discourage genuine challenges, and a storage system that still depends on borrowed infrastructure will decide whether that plumbing actually delivers a fair trial.
On 25 June 2026, the Madhya Pradesh Home Department notified the Madhya Pradesh Electronic Records Rules, 2026. These Rules apply to every district and subordinate court in the state. This makes Madhya Pradesh one of the first states to turn the BNSS and BSA's general mentions of electronic evidence into an actual, working court process spelling out how something like a pen drive is logged, hashed, numbered, and stored once it reaches the filing counter.
This is a real achievement, and one that was overdue. The BSA had already replaced the old Evidence Act's basic treatment of electronic records with a more modern system built around hash values and certificates. But it's important to understand what these new Rules actually do: they don't decide whether an electronic record is admissible or trustworthy as evidence.
Instead, they only deal with what happens to a record after the court has already accepted it for filing that is, how it is looked after, or its "custody." Keeping that limit in mind, three choices made in the Rules deserve a closer look.
A TWO-TRACK SYSTEM FOR THE SAME EVIDENCE
The Rules set up two different paths for getting electronic evidence into the court system, one for ordinary people, and a different, easier one for the police.
Under Rules 4 and 6, an ordinary litigant or an accused person has to physically submit a device, or upload the record through a lawyer or authorised staff, at a special "authorised centre" set up by the High Court. Government agencies, including the police, don't have to do this. Under Rule 4(2), they can simply send records straight to the designated secure repository "through a secured network." Even more notably, Rule 3(2) says that the repository of the state's existing e-sakshya system, the very same portal the police already use while investigating cases automatically counts as an official secure repository. No separate approval or notification is needed for it.
In practice, this means that evidence collected by the police can move smoothly and directly from the crime scene all the way into the court's official system, fully under the investigating agency's control. Meanwhile, evidence submitted by the defence has to go through a counter, be sealed in an envelope, and pass through an authorised centre before it enters the same system.
There's nothing wrong with this difference on its own - police handling of digital evidence has always followed separate rules, including forensic procedures under the BNSS. The real problem is that the Rules don't give the defence any equally automatic right to check or verify the police's entries in the repository before cross-examining the forensic witness. Rule 18 only allows a party to ask for a copy, or for access for expert examination, by filing an application and only after paying for the cost of preparing that copy. So while both sides may look like they're being treated equally on paper, in reality one side's evidence enters pre-verified through a privileged channel, while the other side has to apply, pay, and wait before it can even test whether the hash value is correct.
A COSTS RULE THAT CAN CHILL GENUINE CONTESTATION
Rule 13 lets a court impose "exemplary costs" on anyone who dumps irrelevant data onto the secure repository or portal, and order it removed. That's a sensible safeguard against clutter. But Rule 18's cost rule works in the opposite direction, if an accused person genuinely doubts whether a hash value is correct, or wants a forensic expert to check whether a digital copy (a"mirror image") was made properly, they must pay for that examination themselves, even before the court has decided whether their doubt was reasonable in the first place.
This matters a great deal. The whole point of the hash-value system under Section 63(4) of the BSA is that anyone should be able to independently verify a record's integrity, a hash value only proves anything if someone can recalculate it and compare it to the original. But if only a party who can afford to hire an expert can actually do that check, then this safeguard becomes meaningless for poor accused persons, exactly the people who are most likely to need legal aid and least likely to be able to pay for a forensic review of the prosecution's digital evidence. The Rules don't provide any fee waiver for Rule 18 applications, even though other parts of the same chapter are otherwise careful about access.
INFRASTRUCTURE FOR AN INDIGENOUS PROMISE
Rule 24(2) is refreshingly honest about a weakness that many similar rules elsewhere tend to hide: until the High Court builds its own dedicated secure repository, it can simply recognise any other secure repository that follows the Information Technology Rules, 2018. In other words, the entire system this new law creates hashing records on receipt under Rule 7, giving them unique ID numbers under Rule 9, and preserving them under Rule 22 is, for now, running on infrastructure that the High Court doesn't actually own or fully control. It merely accepts that infrastructure as good enough under a 2018 central framework that was built for protected systems in general, not specifically for judicial evidence.
This is probably a reasonable, temporary arrangement, given how expensive it would be to build dedicated judicial data infrastructure from scratch. But it also means that, for now, the reliability of a certificate issued under Rule 21, which records the hash value and is digitally signed by an official who is then treated as being "in custody" of the record depends on security guarantees that the Rules themselves don't check or clearly define. It would help if the High Court used its power under Rule 24(1) to regularly publish clear, public information about exactly which repository is currently being used and on what terms, instead of keeping that information buried in internal notifications.
WHAT THE RULES GET RIGHT
Two features of the Rules genuinely deserve praise. First, Rule 15(2) completely bans the presentation, through the ordinary Rule 4 process, of any electronic record that would reveal the identity of a person against whom a sexual offence under Sections 64 to 71 of the Bharatiya Nyaya Sanita, 2023, is alleged or has occurred. Combined with Rule 15(1), which allows other sensitive material to be shown directly to the court with permission, instead of through the normal portal.
Second, Rule 20 is a small but important piece of careful drafting: it states that nothing in the Rules should be read as removing the need to prove an electronic record in accordance with law. It makes clear that having a unique ID number or a recorded hash value is only a fact about custody, it is not a substitute for actually satisfying Section 63 of the BSA on admissibility, or for meeting the ordinary burden of proving who created the record and that it hasn't been tampered with, at trial. Courts using these Rules should resist the temptation understandable, given how neat and orderly the system looks on paper to treat a Rule 9 ID number as automatically settling a Section 63 objection. The two questions remain separate, and Rule 20 says so clearly.
THE ROAD AHEAD
As other High Courts watch how this experiment plays out, three practical fixes would make it stronger. First, the fee requirement under Rule 18 should include a discretion to waive fees for applicants who have legal aid or who can show they are genuinely poor, so that the right to check a hash value's integrity doesn't end up depending on how much money someone has.
Second, the automatic "repository" status given to the police's e-sakshya system under Rule 3(2) should come with a clearly defined, simple procedure for the defence to inspect that repository's records rather than forcing them to use the same general Rule 18 process meant for any ordinary record. Third, the High Court should use its power under Rule 24(1) to regularly publish plain information about which repository is currently recognised under the temporary arrangement in Rule 24(2), so that this provisional status is visible to lawyers generally, not just to court staff.
None of this takes away from the real value of what has been notified. For years, Indian trial courts have handled pen drives and hard disks with no fixed procedure, relying instead on ad-hoc instructions from individual judges. A written, published, state-wide procedure for receiving, hashing, numbering, and preserving digital evidence is a genuine step forward, both for predictability and for allowing appellate courts to later review how digital evidence was actually handled at trial.
The only caution is this: building good custody systems and ensuring a fair trial are not the same thing, and the Rules' own Rule 20 rightly says so. What Madhya Pradesh has built, so far, is the plumbing. Whether the water flowing through it is shared fairly between the prosecution and the defence will depend on the corrections made in the next round.
References:
1. Madhya Pradesh Electronic Records (Reception, Storage, Retrieval, Access Management and Preservation in Courts) Rules, 2026, notified by the Madhya Pradesh Home Department, F.No.-1326823/3/3/4/0007/2026-B-1-02(HOME), Madhya Pradesh Gazette (Extraordinary), 25 June 2026.
2. Bharatiya Sakshya Adhiniyam, 2023, Sections 61, 62 and 63.
3. Bharatiya Nyaya Sanhita, 2023, Sections 64-71.
4. Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018.
Author is an Advocate practicing at Madhya Pradesh High Court and a Digital Evidence Specialist. Views are personal.