IT Forensics · Business

How can a company check whether data has been sent via private email addresses?

Company files may have been sent to private email addresses as attachments or via sharing links.

Enquire without obligation

Why this question is important for a business

In the event of potential data leaks, significant economic assets, customer relationships, development know-how or competitive advantages are often at stake. A robust investigation must therefore precisely establish what data movements actually took place, without jumping to the conclusion that a legal infringement has occurred merely on the basis of a suspicion.

Technical investigative approach

We examine lawfully obtained corporate email, endpoint, proxy, browser and file data in a targeted manner with a view to the specific issue in question.

Where the limits of what can be said lie

Private communications are particularly sensitive. The investigation must be limited to the necessary data and a sound legal framework.

Why LanCologne?

Any suspicion of data theft or the loss of confidential company information can have significant financial and legal consequences. This is precisely why the investigation must not begin with the desired outcome in mind.

LanCologne first translates the facts of the case into specific technical questions of evidence: Which files or data sets are affected? Were they actually opened, copied, exported, archived or transferred? Which technical transmission route can be verified? When did this take place? Which device, account or session context can be substantiated?

In this context, we make a strict distinction between the possibility of access, actual access, the copying process and a successful transfer. In practice, these terms are often used interchangeably, even though they describe technically distinct phenomena.

Key findings are, as far as possible, verified against primary data and cross-referenced with independent sources. An automated alert, a tool report or an individual timestamp is not accepted as evidence without verification.

Similarly, standard alternative explanations are investigated. Handover processes, project archives, backups, synchronisation, software updates or authorised cloud usage can generate traces that appear suspicious without context. Only once such explanations have been narrowed down on the basis of the data is a robust technical assessment possible.

For LanCologne, even a finding that exonerates the suspect constitutes a complete investigation result. If an alleged data transfer cannot be confirmed, this is documented in the same way as a verifiable transfer.

How we work

1Document the grounds for suspicion and the specific technical issue to be established.
2Define the legal framework and responsibilities in consultation with the company or legal advisers.
3Narrow down the relevant data sets, devices, accounts and time periods.
4Obtain variable evidence data at an early stage.
5Document data sources, provenance and integrity information.
6Separate access, copying, exporting, archiving and transfer from one another from a technical perspective.
7Identify target media and transmission routes solely on the basis of specific evidence.
8Do not confuse device, account and user assignments.
9Also check standard work processes and other possible explanations.
10Document the technical measures taken to protect alleged trade secrets, where relevant.
11Present positive, negative and inconclusive findings on an equal footing.
12Make a clear distinction between technical findings and legal assessments.

A trade secret is a legal classification – data movement is a technical question of evidence

We can determine or narrow down which files were present, what technical protection measures were in place, and which acts of access, copying or transfer can be verified. Whether the information in question meets the criteria for a trade secret and whether an act was unauthorised or unlawful is assessed separately from a legal perspective.

No jumping to conclusions – not even when transfer patterns are conspicuous

Unusually high file access, a USB connection or a cloud login may give rise to further investigation, but do not in themselves constitute a conclusion. Alternative workflows are also examined. Where several explanations remain possible, this uncertainty is not replaced by an assumption.

Why LanCologne in the context of data portability and trade secrets?

LanCologne does not carry out investigations with the aim of confirming a pre-existing suspicion. We answer the specific technical question of evidence, document the underlying primary data and state just as clearly what cannot be proven. This provides the management and legal department with a factual basis that can also withstand subsequent technical cross-checking.

Legal framework

Where employees are concerned, Section 26 of the Federal Data Protection Act (BDSG) remains a key starting point. For the detection of criminal offences, Section 26(1) of the BDSG requires, amongst other things, documented factual grounds, necessity and proportionality; the employee’s legitimate interest must not outweigh these considerations. In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation.

The GeschGehG is central to trade secrets. Under Section 2(1) of the Trade Secrets Act, not all confidential information is sufficient: amongst other things, the information must have economic value because it is not generally known or readily accessible; it must be subject to confidentiality measures appropriate to the circumstances; and there must be a legitimate interest in maintaining its confidentiality.

Section 4 of the Trade Secrets Act (GeschGehG) prohibits, under certain conditions, amongst other things, unauthorised access to, unauthorised appropriation of, or unauthorised copying of electronic files that contain a trade secret or from which one can be derived. Use and disclosure may also be prohibited. It is not for the IT forensic expert to determine whether a technically verified incident fulfils the legal elements of an offence.

The Business Secrets Protection Act (GeschGehG) also contains exceptions. Section 5 specifically lists certain acts carried out to protect legitimate interests, including, subject to certain conditions, the disclosure of unlawful acts or professional or other misconduct. In addition, the Whistleblower Protection Act may be relevant. Section 6 of the HinSchG governs, under certain conditions, the disclosure or revelation of trade secrets in the context of protected reports. A suspected data leak must therefore not automatically be equated with an unlawful breach of confidentiality.

The GeschGehG provides for potential civil law claims in the event of established infringements, including rectification and injunctions (Section 6), further measures under Section 7, certain rights to information under Section 8, and compensation for damages under Section 10. Which claims apply in individual cases must be assessed from a legal perspective. IT forensics merely provides the technical factual basis for this.

Where technical equipment is used for the monitoring of staff, the works council’s rights of participation, in particular under Section 87(1)(6) of the Works Constitution Act (BetrVG), may also be relevant. The specific admissibility of such measures will be clarified by the relevant internal and legal bodies prior to the investigation.

Frequently Asked Questions

How can a company check whether data has been sent via private email addresses?
In the event of potential data leaks, significant economic assets, customer relationships, development know-how or competitive advantages are often at stake. A robust investigation must therefore precisely establish what data movements actually took place, without jumping to the conclusion that a legal infringement has occurred merely on the basis of a suspicion.
How is such a technical investigation carried out in practice?
We examine lawfully obtained corporate email, endpoint, proxy, browser and file data in a targeted manner with a view to the specific issue in question.
Does the investigation always produce a clear-cut result, either for or against a person involved?
Private communications are particularly sensitive. The investigation must be limited to the necessary data and a sound legal framework.
Is there a legal basis for this?
Where employees are concerned, Section 26 of the Federal Data Protection Act (BDSG) remains a key starting point. For the detection of criminal offences, Section 26(1) of the BDSG requires, amongst other things, documented factual grounds, necessity and proportionality; the employee’s legitimate interest must not outweigh these considerations. In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation.
The GeschGehG is central to trade secrets. Under Section 2(1) of the Trade Secrets Act, not all confidential information is sufficient: amongst other things, the information must have economic value because it is not generally known or readily accessible; it must be subject to confidentiality measures appropriate to the circumstances; and there must be a legitimate interest in maintaining its confidentiality.
Section 4 of the Trade Secrets Act (GeschGehG) prohibits, under certain conditions, amongst other things, unauthorised access to, unauthorised appropriation of, or unauthorised copying of electronic files that contain a trade secret or from which one can be derived. Use and disclosure may also be prohibited. It is not for the IT forensic expert to determine whether a technically verified incident fulfils the legal elements of an offence.
The Business Secrets Protection Act (GeschGehG) also contains exceptions. Section 5 specifically lists certain acts carried out to protect legitimate interests, including, subject to certain conditions, the disclosure of unlawful acts or professional or other misconduct. In addition, the Whistleblower Protection Act may be relevant. Section 6 of the HinSchG governs, under certain conditions, the disclosure or revelation of trade secrets in the context of protected reports. A suspected data leak must therefore not automatically be equated with an unlawful breach of confidentiality.
The GeschGehG provides for potential civil law claims in the event of established infringements, including rectification and injunctions (Section 6), further measures under Section 7, certain rights to information under Section 8, and compensation for damages under Section 10. Which claims apply in individual cases must be assessed from a legal perspective. IT forensics merely provides the technical factual basis for this.
Where technical equipment is used for the monitoring of staff, the works council’s rights of participation, in particular under Section 87(1)(6) of the Works Constitution Act (BetrVG), may also be relevant. The specific admissibility of such measures will be clarified by the relevant internal and legal bodies prior to the investigation.

🔗 Related topics

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now