Challenging the authenticity of an electronic document: what actually shifts the burden
Published August 26, 2026
A bare denial no longer defeats an electronic document. Challenging authenticity of electronic evidence now means explaining how and when the file could have been altered, because a record sealed and timestamped at its creation arrives with a presumption under the eIDAS Regulation or a certification under the US Federal Rules of Evidence, and both shift the practical burden onto whoever disputes it. The objection that still works identifies a specific failure in the acquisition; the one that no longer works simply refuses to accept the file.
This insight is part of our guide: digital evidence and the burden of proof in civil proceedings
Two different things: contesting admissibility and contesting authenticity
Most weak challenges attack the wrong target. Admissibility asks whether the item can reach the finder of fact at all, while authenticity asks whether it is what the party offering it says it is. The two do not distribute the burden in the same way.
What a presumption of authenticity actually does under eIDAS
Under the eIDAS Regulation (EU) 910/2014 the presumption attaches to specific qualified services, not to electronic form in general. Article 41 gives a qualified electronic timestamp the presumption of the accuracy of the date and time it indicates and of the integrity of the data linked to it, and Article 35 gives a qualified electronic seal the presumption of integrity of the data and of correctness of its origin. The presumption is rebuttable, but only with evidence about the data or the service that generated it.
Seal and signature are not interchangeable. A digital signature (QES) expresses the will of a person who signs a document, whereas an electronic seal attests that a body of data, a photograph, a video, an email, a web page, is intact and comes from the source it claims. Article 32 sets out how a QES is validated, and verification against those requirements produces the evidentiary effect.
Self-authenticating records under FRE 902(13) and 902(14)
US practice arrives at a comparable place differently. Rule 901(a) requires the proponent to produce evidence sufficient to support a finding that the item is what the proponent claims it is, a low bar about admissibility rather than weight. Rule 902, amended in 2017, went further: under 902(13) a record generated by an electronic process or system that produces an accurate result is self-authenticating when certified by a qualified person, with advance notice to the opponent, and 902(14) treats data copied from a device, storage medium or file the same way when identified by hash comparison.
What those subsections buy is posture: no foundation witness is needed, and the burden of going forward falls on the opponent, who must raise a real doubt within the notice period. Admissibility is not conclusiveness, so weight can still be attacked before the finder of fact.
| Dimension | eIDAS Regulation (EU) 910/2014 | US Federal Rules of Evidence |
|---|---|---|
| What is challenged | Integrity, origin, date and time indicated | Whether the item is what its proponent claims |
| Governing rule | Articles 35 and 41, validation under Article 32 | Rule 901(a), Rules 902(13) and 902(14) |
| Effect on the record | Rebuttable presumption of integrity, origin, time | Self-authenticating, no foundation witness |
| Who carries the burden | The party disputing the seal or timestamp | The opponent, once notice is served |
| What the challenger must produce | Evidence about the data or the qualified service | A concrete ground of doubt within the notice period |
What changes when the record was sealed at capture
Sealing at capture changes the subject of the dispute. When acquisition, hashing and qualified timestamping happen inside one operation, the state of the file is fixed at a known instant, so the argument has to move onto the process that produced the record.
Qualified timestamps, hashes and the integrity question
A cryptographic hash is a fixed-length value computed from a file’s content: change one byte and the value changes, so comparing today’s hash against the one recorded at capture shows that the file has not been modified since. A qualified timestamp binds that value to a moment attributable to a qualified trust service provider rather than to a device clock.
The distinction that decides most challenges is between integrity and accuracy. A hash proves that nothing changed after the seal, and says nothing about whether what was captured was true. A challenger who grasps the difference stops alleging tampering and argues instead about what the capture shows; one who misses it attacks a property anyone can verify in seconds.
Why a generic objection fails and a specific one survives
A generic objection says that electronic documents can be manipulated, which is true of everything electronic and therefore says nothing about this one. A specific objection names the moment and the mechanism: the interval between the event and the acquisition, an access that could have altered the source, a defect in how the process was documented, an inconsistency with metadata. Where the seal is applied at capture, the alleged tampering has to be located before the seal, and that window is often minutes wide.
The certification route and the expert route
Two routes lead to the same result at very different cost. The certification route relies on a document produced by a qualified person describing the process, served in advance, as Rules 902(13) and 902(14) contemplate. The expert route calls a technical witness, necessary when the process was not documented at the time or the opponent has raised a substantiated doubt.
Where the case is really decided
The outcome is usually settled before anything is filed, by the way the evidence was collected. As set out in our guide on how digital documents are weighed in civil proceedings, whoever controls the moment of acquisition controls the terms of the later dispute.
Building the record so the challenge stays generic
Three habits keep an opponent stuck at the generic level. Capture at the source instead of reproducing material later, since a screenshot taken and certified at the time survives scrutiny that a file saved to a desktop months later does not. Document the process while it happens, so that the chain of custody is a record and not a reconstruction. Disclose hash and timestamp early, following the wider court-ready digital evidence requirements.
How TrueScreen certifies data at the moment of capture
TrueScreen is the Data Authenticity Platform. It applies a forensic methodology at the point where the data is created: acquisition at the source, verification of integrity and authenticity, certification with a qualified timestamp and an electronic seal issued through integrated qualified trust service providers. TrueScreen is not itself a QTSP or a certificate authority, and integrates a third-party qualified QTSP’s seal by API.
When a photograph, a video, a screen recording or a web page is certified at capture, its integrity is verifiable by anyone holding the file, and whoever disputes it has to explain how the alteration would have happened.
FAQ: Challenging the authenticity of an electronic document
Is an electronic document automatically valid as evidence?
What does a qualified electronic timestamp actually prove?
What makes an electronic record self-authenticating in US federal courts?
Does a hash prove that the content of a file is true?
How can a party successfully contest a sealed and timestamped record?
Certify records before they can be contested
TrueScreen captures and seals documents, communications and acquisitions at the moment they are created, with a qualified timestamp issued by an integrated QTSP.

