Challenging the authenticity of an electronic document: what actually shifts the burden

A bare denial no longer defeats an electronic document. Challenging authenticity of electronic evidence now means explaining how and when the file could have been altered, because a record sealed and timestamped at its creation arrives with a presumption under the eIDAS Regulation or a certification under the US Federal Rules of Evidence, and both shift the practical burden onto whoever disputes it. The objection that still works identifies a specific failure in the acquisition; the one that no longer works simply refuses to accept the file.

This insight is part of our guide: digital evidence and the burden of proof in civil proceedings

Two different things: contesting admissibility and contesting authenticity

Most weak challenges attack the wrong target. Admissibility asks whether the item can reach the finder of fact at all, while authenticity asks whether it is what the party offering it says it is. The two do not distribute the burden in the same way.

What a presumption of authenticity actually does under eIDAS

Under the eIDAS Regulation (EU) 910/2014 the presumption attaches to specific qualified services, not to electronic form in general. Article 41 gives a qualified electronic timestamp the presumption of the accuracy of the date and time it indicates and of the integrity of the data linked to it, and Article 35 gives a qualified electronic seal the presumption of integrity of the data and of correctness of its origin. The presumption is rebuttable, but only with evidence about the data or the service that generated it.

Seal and signature are not interchangeable. A digital signature (QES) expresses the will of a person who signs a document, whereas an electronic seal attests that a body of data, a photograph, a video, an email, a web page, is intact and comes from the source it claims. Article 32 sets out how a QES is validated, and verification against those requirements produces the evidentiary effect.

Self-authenticating records under FRE 902(13) and 902(14)

US practice arrives at a comparable place differently. Rule 901(a) requires the proponent to produce evidence sufficient to support a finding that the item is what the proponent claims it is, a low bar about admissibility rather than weight. Rule 902, amended in 2017, went further: under 902(13) a record generated by an electronic process or system that produces an accurate result is self-authenticating when certified by a qualified person, with advance notice to the opponent, and 902(14) treats data copied from a device, storage medium or file the same way when identified by hash comparison.

What those subsections buy is posture: no foundation witness is needed, and the burden of going forward falls on the opponent, who must raise a real doubt within the notice period. Admissibility is not conclusiveness, so weight can still be attacked before the finder of fact.

Dimension eIDAS Regulation (EU) 910/2014 US Federal Rules of Evidence
What is challenged Integrity, origin, date and time indicated Whether the item is what its proponent claims
Governing rule Articles 35 and 41, validation under Article 32 Rule 901(a), Rules 902(13) and 902(14)
Effect on the record Rebuttable presumption of integrity, origin, time Self-authenticating, no foundation witness
Who carries the burden The party disputing the seal or timestamp The opponent, once notice is served
What the challenger must produce Evidence about the data or the qualified service A concrete ground of doubt within the notice period

What changes when the record was sealed at capture

Sealing at capture changes the subject of the dispute. When acquisition, hashing and qualified timestamping happen inside one operation, the state of the file is fixed at a known instant, so the argument has to move onto the process that produced the record.

Qualified timestamps, hashes and the integrity question

A cryptographic hash is a fixed-length value computed from a file’s content: change one byte and the value changes, so comparing today’s hash against the one recorded at capture shows that the file has not been modified since. A qualified timestamp binds that value to a moment attributable to a qualified trust service provider rather than to a device clock.

The distinction that decides most challenges is between integrity and accuracy. A hash proves that nothing changed after the seal, and says nothing about whether what was captured was true. A challenger who grasps the difference stops alleging tampering and argues instead about what the capture shows; one who misses it attacks a property anyone can verify in seconds.

Why a generic objection fails and a specific one survives

A generic objection says that electronic documents can be manipulated, which is true of everything electronic and therefore says nothing about this one. A specific objection names the moment and the mechanism: the interval between the event and the acquisition, an access that could have altered the source, a defect in how the process was documented, an inconsistency with metadata. Where the seal is applied at capture, the alleged tampering has to be located before the seal, and that window is often minutes wide.

The certification route and the expert route

Two routes lead to the same result at very different cost. The certification route relies on a document produced by a qualified person describing the process, served in advance, as Rules 902(13) and 902(14) contemplate. The expert route calls a technical witness, necessary when the process was not documented at the time or the opponent has raised a substantiated doubt.

Where the case is really decided

The outcome is usually settled before anything is filed, by the way the evidence was collected. As set out in our guide on how digital documents are weighed in civil proceedings, whoever controls the moment of acquisition controls the terms of the later dispute.

Building the record so the challenge stays generic

Three habits keep an opponent stuck at the generic level. Capture at the source instead of reproducing material later, since a screenshot taken and certified at the time survives scrutiny that a file saved to a desktop months later does not. Document the process while it happens, so that the chain of custody is a record and not a reconstruction. Disclose hash and timestamp early, following the wider court-ready digital evidence requirements.

How TrueScreen certifies data at the moment of capture

TrueScreen is the Data Authenticity Platform. It applies a forensic methodology at the point where the data is created: acquisition at the source, verification of integrity and authenticity, certification with a qualified timestamp and an electronic seal issued through integrated qualified trust service providers. TrueScreen is not itself a QTSP or a certificate authority, and integrates a third-party qualified QTSP’s seal by API.

When a photograph, a video, a screen recording or a web page is certified at capture, its integrity is verifiable by anyone holding the file, and whoever disputes it has to explain how the alteration would have happened.

FAQ: Challenging the authenticity of an electronic document

Is an electronic document automatically valid as evidence?
Not automatically. Article 25(1) of the eIDAS Regulation prevents an electronic signature from being denied legal effect or admissibility solely because it is electronic, while Rule 901(a) of the US Federal Rules of Evidence requires evidence sufficient to support a finding that the item is what its proponent claims.
What does a qualified electronic timestamp actually prove?
Under Article 41 of the eIDAS Regulation, a qualified electronic timestamp enjoys the presumption of the accuracy of the date and time it indicates and of the integrity of the data linked to it. It fixes when the data existed in that state, not that the content was accurate.
What makes an electronic record self-authenticating in US federal courts?
Rules 902(13) and 902(14) of the Federal Rules of Evidence, added in 2017, admit records generated by an electronic system, and data copied from a device or file and identified by hash comparison, without a foundation witness, provided a qualified person certifies the process and notifies the opponent in advance.
Does a hash prove that the content of a file is true?
No. A hash proves integrity: the file has not changed since the value was computed. It says nothing about whether the content was accurate at capture. Challenges that confuse the two collapse quickly; those aimed at what the capture shows stay open.
How can a party successfully contest a sealed and timestamped record?
By attacking the acquisition rather than the file: the interval before the seal was applied, an access to the source in that window, a defect in the capture process, or an inconsistency with metadata. A general assertion that digital files can be edited carries no weight against a verifiable seal.

Certify records before they can be contested

TrueScreen captures and seals documents, communications and acquisitions at the moment they are created, with a qualified timestamp issued by an integrated QTSP.

Start now
Request a demo

TrueScreen