IT Forensics · Business

How can a company carry out an IT forensic investigation into a suspected breach of compliance without prejudging the outcome?

Ein Compliance-Hinweis kann eine interne Untersuchung erforderlich machen. Aus einem Hinweis folgt jedoch weder die Richtigkeit des Vorwurfs noch die Verantwortlichkeit einer bestimmten Person.

Enquire without obligation

Why this question is important for a business

Internal investigations can have significant financial, personnel and legal consequences. This is precisely why it must first be clarified which specific technical fact is to be proven or disproved. The sheer volume of data is not an indicator of quality; what is crucial is that the investigation is appropriate, limited in scope and transparent.

Technical investigative approach

Wir übersetzen den Sachverhalt in überprüfbare technische Teilfragen und untersuchen nur die hierfür erforderlichen Systeme, Accounts, Zeiträume und Datenarten.

Where the limits of what can be said lie

Die IT-Forensik stellt technische Tatsachen fest. Ob daraus ein arbeits-, zivil- oder strafrechtlicher Verstoß folgt, ist gesondert zu bewerten.

Why LanCologne?

Internal investigations are particularly sensitive because they may simultaneously involve the company’s commercial interests, employees’ personal rights, data protection, employee participation in company decision-making, and potential future legal proceedings.

LanCologne therefore does not begin with the most comprehensive search of the IT systems possible. The starting point is a clearly formulated technical question of evidence. From this, the necessary data sources, time periods and investigative steps are derived. Technical feasibility and legal admissibility are deliberately kept separate.

The investigation remains open-ended. A suspicion is not confirmed simply because it sounds plausible. Incriminating, exculpatory and contradictory evidence is examined according to the same professional standards. Where several technical explanations are possible, these are identified and, as far as possible, tested against one another.

Automated reports, EDR alerts, DLP hits or output from forensic software are not accepted as evidence without verification. Key findings are, as far as possible, validated against primary data and correlated with independent artefacts.

To facilitate a subsequent technical review, we document not only the result but also the reasoning behind it. The main body of the report, written in clear language, is aimed at senior management and the legal department; a technical appendix enables a qualified external forensic expert to verify the key findings.

How we work

1Determine the grounds for the investigation and the specific issue to be established.
2Clarify in advance the responsibilities, legal basis and, where applicable, rights of participation.
3Limit the scope of users, systems, accounts, time and data to what is strictly necessary.
4Preserve volatile data or data at risk of loss at an early stage.
5Take confidentiality and the ‘need-to-know’ principle into account from both an organisational and a technical perspective.
6Separate the original data from suitable backups of working copies.
7Document the integrity, origin and time of sealing in a way that allows for traceability.
8Validate product alerts and tool outputs against primary data.
9Do not confuse account, device, session and user mapping.
10Examine incriminating, exculpatory and alternative explanations on an equal footing.
11Distinguish between technical findings and legal conclusions.
12Ensure the main report is clear and the technical appendix is reproducible.

No prejudgement – even where suspicions have already been confirmed internally

A company may already have clear grounds for suspicion for organisational or legal reasons. However, the outcome of the technical investigation remains open. We also document any findings that contradict the suspicion and explicitly state when an alleged act cannot be proven on the basis of the data obtained.

Technical findings and legal assessment remain separate

IT forensics can, for example, establish that a particular account exported a file, that a device was connected at a specific time, or that a message was technically transmitted. This does not automatically reveal which individual was responsible, whether the action was authorised, or what the consequences might be under employment, civil or criminal law.

LanCologne as an independent technical support service for the legal department and senior management

LanCologne is not commissioned to technically confirm a desired outcome. We are commissioned to provide an objective answer to a specific question of evidence based on the available digital traces. The investigation must remain verifiable even if it is subsequently scrutinised by an opposing party, a court or another qualified IT forensic expert.

Legal framework

Section 26 of the Federal Data Protection Act (BDSG) is a key legal reference point for employees’ data. Section 26(1) of the BDSG permits the processing of personal data relating to employees for the purposes of the employment relationship, subject to the conditions set out therein. With regard to the detection of criminal offences, the provision requires, in particular, that there be documented factual indications, as well as that the processing be necessary and proportionate; the employee’s legitimate interest must not take precedence. Section 26(6) of the BDSG leaves the participation rights of employee representative bodies unaffected.

In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation under Article 5, as well as the requirement for a valid legal basis under Article 6. In the case of special categories of personal data, Article 9 of the GDPR and, where applicable, Section 26(3) of the BDSG must also be observed.

In the case of technical equipment intended to monitor the behaviour or performance of employees, Section 87(1)(6) of the Works Constitution Act (BetrVG) provides for a right of co-determination for the works council, insofar as there are no statutory or collective agreement provisions in place. For MDM, EDR, DLP, logging and similar systems, the specific design of each must therefore be taken into account.

In the case of reports made under the Whistleblower Protection Act, Section 8 of the HinSchG is particularly relevant. The duty of confidentiality protects not only the identity of the whistleblower, but also the persons who are the subject of a report and any other persons named in the report. Section 9 of the HinSchG sets out statutory exceptions to the duty of confidentiality. Section 36 of the HinSchG prohibits reprisals and, subject to the conditions set out therein, contains a rule on the burden of proof.

In the case of trade secrets, an internal investigation must not automatically treat a report as a breach of confidentiality. Section 5 of the Trade Secrets Act (GeschGehG) sets out exceptions to the prohibitions in Section 4, including, amongst other things, under certain conditions for the detection of unlawful acts or professional or other misconduct, as well as for necessary disclosures to employee representatives.

Should civil proceedings arise at a later stage, the Code of Civil Procedure (ZPO) provides, amongst other things, for evidence by inspection; Section 371(1) ZPO expressly governs the case where an electronic document forms the subject matter of the evidence. Sections 402 et seq. ZPO apply to expert evidence. In criminal proceedings, the court determines the scope of the taking of evidence in accordance with the Code of Criminal Procedure (StPO); in particular, Section 244 of the StPO governs the principle of investigation and applications for evidence. However, these procedural provisions do not automatically transform a privately commissioned IT forensic report into a court expert report.

LanCologne provides technical expert services and does not offer legal advice. The specific admissibility of an investigative measure, the consequences under employment law, procedural strategy and criminal law assessment remain the responsibility of the relevant legal advisers, authorities and courts.

Frequently Asked Questions

How can a company carry out an IT forensic investigation into a suspected breach of compliance without prejudging the outcome?+
Internal investigations can have significant financial, personnel and legal consequences. This is precisely why it must first be clarified which specific technical fact is to be proven or disproved. The sheer volume of data is not an indicator of quality; what is crucial is that the investigation is appropriate, limited in scope and transparent.
How is such a technical investigation carried out in practice?+
Wir übersetzen den Sachverhalt in überprüfbare technische Teilfragen und untersuchen nur die hierfür erforderlichen Systeme, Accounts, Zeiträume und Datenarten.
Does the investigation always produce a clear-cut result, either for or against a person involved?+
Die IT-Forensik stellt technische Tatsachen fest. Ob daraus ein arbeits-, zivil- oder strafrechtlicher Verstoß folgt, ist gesondert zu bewerten.
Is there a legal basis for this?+
Für Beschäftigtendaten ist § 26 BDSG ein wesentlicher gesetzlicher Bezugspunkt. § 26 Abs. 1 BDSG erlaubt die Verarbeitung personenbezogener Beschäftigtendaten für Zwecke des Beschäftigungsverhältnisses unter den dort genannten Voraussetzungen. Zur Aufdeckung von Straftaten verlangt die Vorschrift insbesondere zu dokumentierende tatsächliche Anhaltspunkte, Erforderlichkeit und Verhältnismäßigkeit; das schutzwürdige Interesse der beschäftigten Person darf nicht überwiegen. § 26 Abs. 6 BDSG lässt Beteiligungsrechte der Interessenvertretungen unberührt. Daneben gelten die Grundsätze der DSGVO, insbesondere Rechtmäßigkeit, Zweckbindung und Datenminimierung nach Art. 5 sowie das Erfordernis einer tragfähigen Rechtsgrundlage nach Art. 6. Bei besonderen Kategorien personenbezogener Daten sind zusätzlich Art. 9 DSGVO und gegebenenfalls § 26 Abs. 3 BDSG zu beachten. Bei technischen Einrichtungen, die dazu bestimmt sind, Verhalten oder Leistung von Arbeitnehmern zu überwachen, sieht § 87 Abs. 1 Nr. 6 BetrVG ein Mitbestimmungsrecht des Betriebsrats vor, soweit keine gesetzliche oder tarifliche Regelung besteht. Für MDM, EDR, DLP, Logging und vergleichbare Systeme muss daher jeweils die konkrete Ausgestaltung betrachtet werden. Bei Hinweisen nach dem Hinweisgeberschutzgesetz ist insbesondere § 8 HinSchG relevant. Das Vertraulichkeitsgebot schützt nicht nur die Identität der hinweisgebenden Person, sondern auch Personen, die Gegenstand einer Meldung sind, und sonstige in der Meldung genannte Personen. § 9 HinSchG enthält gesetzliche Ausnahmen vom Vertraulichkeitsgebot. § 36 HinSchG verbietet Repressalien und enthält unter den dort genannten Voraussetzungen eine Beweislastregel. Bei Geschäftsgeheimnissen darf eine interne Untersuchung eine Meldung nicht automatisch als Geheimnisverletzung behandeln. § 5 GeschGehG enthält Ausnahmen von den Verboten des § 4, unter anderem unter bestimmten Voraussetzungen zur Aufdeckung rechtswidriger Handlungen oder beruflichen beziehungsweise sonstigen Fehlverhaltens sowie für erforderliche Offenlegungen gegenüber Arbeitnehmervertretungen. Kommt es später zu einem Zivilprozess, kennt die ZPO unter anderem den Beweis durch Augenschein; § 371 Abs. 1 ZPO regelt ausdrücklich den Fall, dass ein elektronisches Dokument Gegenstand des Beweises ist. Für Sachverständigenbeweis gelten §§ 402 ff. ZPO. In einem Strafverfahren bestimmt das Gericht den Umfang der Beweisaufnahme nach der StPO; insbesondere § 244 StPO regelt den Untersuchungsgrundsatz und Beweisanträge. Diese prozessualen Vorschriften machen aus einem privat beauftragten IT-forensischen Bericht jedoch nicht automatisch ein gerichtliches Gutachten. LanCologne erbringt technische Sachverständigenarbeit und keine Rechtsberatung. Die konkrete Zulässigkeit einer Untersuchungsmaßnahme, arbeitsrechtliche Konsequenzen, prozessuale Strategie und strafrechtliche Bewertung bleiben der zuständigen Rechtsberatung, den Behörden und Gerichten vorbehalten.

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now