Recovery of deleted data.

Recovery of Deleted Data 

1. Meaning of Recovery of Deleted Data

Recovery of deleted data refers to the process of retrieving electronic information that has been deleted from a computer, mobile phone, server, cloud account, database, email system, storage device, or other digital medium.

Deletion does not necessarily mean that the information has been permanently destroyed. Depending upon the storage system and the manner of deletion, recoverable information may remain in:

  • Recycle Bin or Trash;
  • file-system metadata;
  • unallocated disk space;
  • temporary files;
  • backups;
  • cloud replicas;
  • server logs;
  • email archives;
  • database logs;
  • application caches;
  • mobile-device backups;
  • forensic images; and
  • other electronically stored information.

In employment disputes, deleted data may become important where the dispute concerns employee misconduct, data theft, fraud, trade secrets, workplace communications, harassment complaints, moonlighting, unauthorised access, or destruction of company information.

2. Legal Importance of Deleted Data

The principal legal issue is not merely whether deleted data can technically be recovered. The court must also consider:

  1. How was the data recovered?
  2. Who recovered it?
  3. Was the original device preserved?
  4. Was the evidence altered or contaminated?
  5. Can the recovered material be authenticated?
  6. Is the electronic record admissible under the applicable evidence law?
  7. Was the employee given an opportunity to challenge the material?
  8. Was the recovery consistent with privacy and procedural requirements?

Thus, technical recoverability and legal admissibility are separate questions.

3. Methods of Recovering Deleted Data

A. Recovery from Recycle Bin/Trash

The simplest form of recovery is restoration of files that have merely been moved to a system's Recycle Bin or Trash.

B. File-System Recovery

Forensic software can sometimes reconstruct deleted files from:

  • file-system metadata;
  • directory entries;
  • file allocation structures; and
  • unallocated space.

C. Recovery from Unallocated Space

When a file is deleted, the operating system may mark the relevant storage space as available without immediately overwriting the underlying information.

Forensic examination may therefore recover portions of the deleted file.

D. Recovery from Backups

Deleted information may survive in:

  • server backups;
  • cloud backups;
  • disaster-recovery systems;
  • email archives;
  • database backups; and
  • enterprise document-management systems.

E. Recovery from Mobile Devices

Deleted SMS messages, photographs, application databases, call records and other information may sometimes be recovered from a mobile device or its backup.

F. Recovery from Metadata

Even where the substantive document is unavailable, metadata may establish:

  • creation time;
  • modification time;
  • deletion;
  • access;
  • user account;
  • device;
  • file path; or
  • transmission information.

4. Recovery and Chain of Custody

A major legal requirement is preservation of the chain of custody.

A proper process generally involves:

Identification → Preservation → Acquisition → Hashing → Examination → Recovery → Documentation → Presentation

For example, if an employer takes possession of an employee's laptop:

  1. The device should be identified.
  2. Its condition should be documented.
  3. A forensic image should preferably be created.
  4. The original should be preserved.
  5. Examination should be conducted on a forensic copy.
  6. Hash values should be recorded where appropriate.
  7. Recovered files should be documented.
  8. The methodology should be capable of explanation before the court or enquiry officer.

This reduces allegations that the employer planted, modified, fabricated or selectively recovered evidence.

5. Indian Evidence Law

Electronic records are governed principally by the Bharatiya Sakshya Adhiniyam, 2023 (BSA) for proceedings to which it applies, replacing the Indian Evidence Act, 1872.

The older Supreme Court decisions under Section 65B of the Indian Evidence Act remain particularly important for understanding the principles surrounding electronic evidence, although the statutory framework must be applied according to the law governing the particular proceeding.

The central concepts include:

  • authenticity;
  • integrity;
  • identification of the electronic record;
  • reliability of the computer system;
  • proper certification where legally required; and
  • proof of the circumstances in which the electronic record was produced.

6. Recovery of Deleted Data in Internal Disciplinary Proceedings

Deleted electronic data can be particularly significant in departmental or internal enquiries.

For example, an employee may be accused of:

  • deleting confidential files;
  • forwarding company documents;
  • manipulating records;
  • deleting emails;
  • destroying evidence;
  • unauthorised access;
  • transferring customer data; or
  • concealing misconduct.

However, the mere fact that a file was recovered from an employee's computer does not automatically establish that the employee committed the alleged misconduct.

The employer should establish, where relevant:

  • ownership/control of the device;
  • employee access;
  • authenticity of the file;
  • timing;
  • relevant system logs;
  • connection between the employee and the activity;
  • forensic methodology; and
  • compliance with applicable disciplinary procedure.

7. Privacy Considerations

Recovery of deleted data can potentially involve substantial employee privacy interests.

An employer should distinguish between:

legitimate investigation of company systems and unrestricted examination of an employee's personal information.

Particular care may be necessary where a device is:

  • personally owned;
  • jointly used;
  • used for personal communications; or
  • containing unrelated private information.

The scope of investigation should therefore ordinarily be connected to the alleged misconduct.

8. Deleted Data and Adverse Inference

Sometimes a party deliberately destroys relevant evidence.

Courts may draw an adverse inference where a party intentionally destroys or suppresses evidence that was material to the dispute.

However, an adverse inference is not automatic merely because data has disappeared.

The court may examine:

  • whether the evidence actually existed;
  • whether the party controlled it;
  • whether its destruction was intentional;
  • whether there was a duty to preserve it;
  • whether the destruction prejudiced the opposing party; and
  • whether an innocent explanation exists.

9. Six Important Case Laws

1. Anvar P.V. v. P.K. Basheer

(2014) 10 SCC 473

This is one of the foundational Supreme Court decisions on electronic evidence.

The Supreme Court held that electronic records are subject to the statutory requirements governing their admissibility. The Court significantly clarified the importance of the certificate requirement under Section 65B of the Evidence Act for electronic records produced in the prescribed manner.

Relevance to deleted data

Where deleted data is recovered through forensic methods, the party relying on the recovered material must still address the applicable requirements for proving the electronic record.

Principle:
Technical recovery does not by itself eliminate the legal requirements concerning admissibility and proof of electronic evidence.

2. Shafhi Mohammad v. State of Himachal Pradesh

(2018) 2 SCC 801

The Supreme Court considered the requirement of certification for electronic evidence and recognised circumstances in which a party may not be in possession or control of the relevant device.

Relevance

In an employment dispute, an employee may not control the employer's server, backup system or forensic image. Conversely, an employer may not control a former employee's personal device.

The case illustrates the importance of considering control over the electronic source when determining how electronic evidence can be proved.

3. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal

(2020) 7 SCC 1

This decision is particularly important because the Supreme Court comprehensively considered the law concerning electronic records and clarified the principles relating to Section 65B.

The Court reaffirmed the significance of the statutory certificate where electronic evidence is produced through the relevant mechanism.

Relevance to deleted data

Where forensic investigators recover deleted material from a computer, mobile device or server, the evidentiary process must distinguish between:

  • the physical device;
  • the electronic record;
  • the forensic copy;
  • the method used for extraction; and
  • the legally required proof of the resulting electronic evidence.

4. Tomaso Bruno v. State of Uttar Pradesh

(2015) 7 SCC 178

The Supreme Court emphasised the importance of modern technological evidence, particularly where electronic evidence could assist in determining the truth.

The case concerned the failure to produce potentially relevant CCTV evidence.

Relevance

The decision demonstrates that electronically stored information can have substantial evidentiary significance.

In employment litigation, relevant material may include:

  • CCTV footage;
  • access-control logs;
  • emails;
  • server logs;
  • attendance records;
  • computer logs; and
  • recovered deleted files.

Where relevant electronic evidence was available but not preserved or produced, the circumstances surrounding its absence may become legally significant.

5. Sonu @ Amar v. State of Haryana

(2017) 8 SCC 570

The Supreme Court considered objections concerning electronic evidence and the stage at which objections to admissibility should be raised.

Relevance

The case illustrates an important procedural principle: parties should not ordinarily wait until an advanced stage of proceedings to raise objections that could have been addressed earlier.

For recovered deleted data, objections may concern:

  • authenticity;
  • source;
  • manner of acquisition;
  • certification;
  • integrity; and
  • admissibility.

These issues should be raised and determined at the appropriate procedural stage.

6. P. Gopalkrishnan @ Dileep v. State of Kerala

(2020) 9 SCC 161

The Supreme Court dealt with electronic material and issues surrounding access to digital evidence, including the distinction between the evidentiary material itself and the privacy/confidentiality interests associated with it.

Relevance

The case is useful for understanding that electronic evidence may contain highly sensitive information and that access to such material can require appropriate safeguards.

In employment investigations, recovery of deleted files should therefore be balanced against:

  • employee privacy;
  • confidentiality;
  • privilege;
  • personal information;
  • third-party information; and
  • legitimate investigative requirements.

10. Additional Important Principle: Shifting Technology

Digital-forensic methods change rapidly. Deleted data may be recoverable from one type of system but effectively unrecoverable from another.

For example, recovery can be affected by:

  • SSD technology;
  • TRIM;
  • encryption;
  • cloud architecture;
  • automatic deletion;
  • secure deletion tools;
  • overwritten storage blocks;
  • remote wiping; and
  • application-specific databases.

Therefore, a statement that "deleted data can always be recovered" is legally and technically incorrect.

The correct question is whether the particular data remained available and whether the recovery methodology can reliably establish what was recovered.

11. Recovery of Deleted Data in Employment Litigation

Consider an employee accused of transferring confidential customer information.

The employer discovers that several files were deleted shortly before the employee's resignation.

A proper investigation might involve:

  1. Preserving the laptop.
  2. Preventing further alteration of the device.
  3. Creating a forensic image.
  4. Calculating and documenting appropriate hash values.
  5. Recovering deleted files from the forensic copy.
  6. Examining file metadata.
  7. Comparing the files with server records.
  8. Examining email or cloud logs.
  9. Establishing the employee's access.
  10. Providing relevant material during the disciplinary process.
  11. Giving the employee an opportunity to respond.
  12. Producing admissible electronic evidence if litigation follows.

This creates a much stronger evidentiary foundation than simply presenting a screenshot of a "recovered" file.

12. Recovery Does Not Automatically Prove Authorship

One of the most important distinctions is:

Finding a file on a device is not necessarily proof that a particular person created, accessed, transmitted or deleted it.

For example, a company laptop may be:

  • shared;
  • accessible through another employee's credentials;
  • remotely administered;
  • infected by malware; or
  • synchronised automatically with cloud services.

Therefore, authorship or responsibility may require corroborating evidence such as:

  • login records;
  • authentication logs;
  • access timestamps;
  • email records;
  • network logs;
  • USB connection records;
  • CCTV;
  • witness testimony; and
  • system administrator evidence.

13. Recovery and Destruction of Evidence

If an employee intentionally deletes company records after receiving a legal notice or after becoming aware of an investigation, the conduct may become independently relevant.

Similarly, an employer that destroys potentially relevant employee records after litigation has commenced may face evidentiary consequences.

A sound document-retention policy should therefore specify:

  • ordinary retention periods;
  • legal-hold procedures;
  • investigation holds;
  • litigation holds;
  • deletion procedures;
  • access controls;
  • backup retention; and
  • responsibilities of IT and HR personnel.

14. Practical HR/Legal Checklist

Before relying on recovered deleted data, an organisation should ask:

Preservation

  • Was the device preserved promptly?
  • Was further deletion prevented?
  • Was the original retained?

Forensic integrity

  • Was a forensic image created?
  • Was the methodology documented?
  • Were appropriate integrity/hash records maintained?

Authentication

  • Who owned or controlled the device?
  • Who had access?
  • Can the recovered file be linked to the employee?

Timing

  • When was the file created?
  • When was it modified?
  • When was it deleted?
  • When was it recovered?

Procedural fairness

  • Was the employee given sufficient particulars?
  • Was relevant evidence disclosed?
  • Was the employee permitted to respond?

Admissibility

  • Does the electronic evidence satisfy the applicable statutory requirements?
  • Is certification required?
  • Can the person responsible for the system or forensic acquisition explain the evidence?

Privacy

  • Was the investigation appropriately limited?
  • Did investigators collect unrelated personal information?
  • Were confidential third-party materials exposed?

15. Key Legal Principles

IssueLegal principle
Deleted fileDeletion does not necessarily mean permanent destruction
RecoveryTechnical recovery must be reliable and documented
AuthenticityRecovered data must be capable of authentication
Chain of custodyIntegrity of the evidence should be demonstrable
Electronic evidenceApplicable statutory requirements must be satisfied
Employee misconductRecovery alone does not automatically establish culpability
PrivacyInvestigation should be appropriately limited
Intentional destructionMay have evidentiary consequences
BackupsMay provide an alternative source of deleted information
MetadataCan corroborate timing and system activity
Forensic copyExamination should preferably occur on a preserved forensic copy
Internal enquiryNatural justice and fair opportunity to respond remain important

Conclusion

Recovery of deleted data is both a technological and evidentiary issue. Deleted electronic information may sometimes be recovered from unallocated storage, backups, cloud systems, databases, application records or forensic images. However, the mere recovery of information does not establish its authenticity, authorship or legal admissibility.

The leading Indian authorities, particularly Anvar P.V., Shafhi Mohammad and Arjun Panditrao Khotkar, demonstrate the importance of statutory compliance in proving electronic records. Tomaso Bruno highlights the evidentiary importance of electronic material, while Sonu @ Amar and P. Gopalkrishnan provide additional guidance on procedural and privacy-related aspects.

For employment disputes, the safest legal approach is therefore to combine forensic preservation + documented recovery methodology + authentication + applicable electronic-evidence requirements + procedural fairness + privacy safeguards.

LEAVE A COMMENT