IT Forensics · Business

How can a company carry out an internal investigation if the private use of company IT was permitted?

Permitted or tolerated personal use may result in work-related and personal data being mixed together on the same device or account.

Enquire without obligation

Why this question is important for a business

In the case of internal incidents, commercial interests, the preservation of evidence and employees’ rights may all be affected simultaneously. A technically wide-ranging investigation is therefore not automatically a good one. What is crucial is a clearly defined question of evidence and a transparently limited scope of the investigation.

Technical investigative approach

We plan the investigation in such a way that the question at issue is answered, as far as possible, using official metadata, narrowly defined search parameters and appropriate filtering or exclusion mechanisms.

Where the limits of what can be said lie

Private content must not be made the subject of an investigation simply because it is stored on company hardware.

Why LanCologne?

Internal investigations involve a direct clash of several interests: the company must be able to protect its systems, data, trade secrets and commercial interests. At the same time, employee data protection, proportionality, co-determination and, where applicable, the protection of private data must be observed.

LanCologne therefore does not begin by collecting as much data as possible. The starting point is the specific technical question to be investigated. Only then is it determined which devices, accounts, time periods and types of data are actually required. This often allows an investigation to be carried out much more precisely than a blanket, comprehensive analysis would.

Technical availability and legal permissibility are deliberately kept separate. The fact that an administrator, MDM system or cloud tenant technically enables access to certain information does not in itself answer the question of whether that information may be processed for the specific purpose in question.

Key findings are validated against primary data where necessary. Automated reports and forensic software are tools; they do not replace the expert interpretation of the underlying artefacts. Alternative technical explanations are also examined.

Equally important: an internal investigation must take exonerating facts just as seriously as incriminating ones. If the analysis reveals that a suspicion cannot be technically confirmed, or that a notable incident can be explained by a standard system process, this must be explicitly stated in the findings.

How we work

1Define the specific circumstances and the technical issue to be established.
2Clarify the legal basis and internal responsibilities with the company or its legal advisers.
3Limit the systems, accounts, data types and time periods required.
4Prioritise the preservation of evidence and document variable data.
5Record device and data identity, as well as the security status, in a traceable manner.
6Separate raw data from reports and user interface interpretations.
7Do not confuse employee, device, account and session assignments.
8Check for standard system processes and alternative explanations.
9Document incriminating, exonerating and inconclusive findings equally.
10The scope of the investigation should only be extended where there are new, substantiated connecting facts.
11How to write a technical report that is clear and reproducible.
12Conclusions regarding labour law, data protection law, civil law and criminal law should be left to the relevant legal advisers.

No prejudgement of employees

An internal suspicion is not simply declared to be the outcome of the investigation. We examine which technical facts support it, which contradict it, and what alternative explanations exist. Even a finding that is unfavourable to the company or exonerates it is fully documented.

Comprehensible to senior management and the legal department – reproducible for forensic experts

The main body explains the key message without using unnecessary technical jargon. The technical section documents data sources, backup statuses, identifiers, integrity information, time references, artefact locations and validation steps. This ensures that the investigation remains traceable for subsequent technical cross-checking.

LanCologne: independent technical support for businesses

Where an internal incident requires technical investigation, LanCologne provides support in the form of an objective, unbiased and transparent IT forensic investigation. The focus is not on a desired outcome, but solely on what can actually be substantiated on the basis of the digital evidence within the permissible scope of the investigation.

Legal framework

In Germany, Section 26 of the Federal Data Protection Act (BDSG) must be observed in particular with regard to employees’ data. Personal data relating to employees may be processed for the purposes of the employment relationship if this is necessary for the purposes specified therein. Section 26(1) of the BDSG sets out specific conditions for the detection of criminal offences: There must be documented factual grounds justifying the suspicion that the data subject has committed a criminal offence in the course of their employment; the processing must be necessary for the detection of the offence, and the employee’s legitimate interests must not outweigh this. In particular, the nature and extent of the processing must not be disproportionate.

In addition, the general principles of the GDPR apply. Article 5 of the GDPR requires, amongst other things, lawfulness, purpose limitation and data minimisation. Article 6 of the GDPR requires a valid legal basis for processing. Consequently, the fact that an analysis is technically feasible does not automatically mean that it is legally permissible.

In the case of technical equipment, Section 87(1)(6) of the Works Constitution Act (BetrVG) may also be relevant. According to this provision, in the absence of any statutory or collective agreement provisions, the works council has the right to be consulted on the introduction and use of technical systems designed to monitor employees’ behaviour or performance. Depending on their design, this may be relevant, for example, in the case of MDM, EDR, DLP, logging or other monitoring systems.

Section 26(6) of the Federal Data Protection Act (BDSG) expressly clarifies that the participation rights of employees’ representative bodies remain unaffected. The specific admissibility of an investigative measure under labour law and works constitution law should therefore, where employees are concerned, be clarified with the relevant legal advisers and, where appropriate, the designated company bodies before it is carried out.

LanCologne does not replace this legal assessment. Our task is, once the permissible scope of the investigation has been defined, to examine the technical question of evidence in a transparent, proportionate and unbiased manner.

Frequently Asked Questions

How can a company carry out an internal investigation if the private use of company IT was permitted?
In the case of internal incidents, commercial interests, the preservation of evidence and employees’ rights may all be affected simultaneously. A technically wide-ranging investigation is therefore not automatically a good one. What is crucial is a clearly defined question of evidence and a transparently limited scope of the investigation.
How is such a technical investigation carried out in practice?
We plan the investigation in such a way that the question at issue is answered, as far as possible, using official metadata, narrowly defined search parameters and appropriate filtering or exclusion mechanisms.
Does the investigation always produce a clear-cut result, either for or against a person involved?
Private content must not be made the subject of an investigation simply because it is stored on company hardware.
Is there a legal basis for this?
In Germany, Section 26 of the Federal Data Protection Act (BDSG) must be observed in particular with regard to employees’ data. Personal data relating to employees may be processed for the purposes of the employment relationship if this is necessary for the purposes specified therein. Section 26(1) of the BDSG sets out specific conditions for the detection of criminal offences: There must be documented factual grounds justifying the suspicion that the data subject has committed a criminal offence in the course of their employment; the processing must be necessary for the detection of the offence, and the employee’s legitimate interests must not outweigh this. In particular, the nature and extent of the processing must not be disproportionate.
In addition, the general principles of the GDPR apply. Article 5 of the GDPR requires, amongst other things, lawfulness, purpose limitation and data minimisation. Article 6 of the GDPR requires a valid legal basis for processing. Consequently, the fact that an analysis is technically feasible does not automatically mean that it is legally permissible.
In the case of technical equipment, Section 87(1)(6) of the Works Constitution Act (BetrVG) may also be relevant. According to this provision, in the absence of any statutory or collective agreement provisions, the works council has the right to be consulted on the introduction and use of technical systems designed to monitor employees’ behaviour or performance. Depending on their design, this may be relevant, for example, in the case of MDM, EDR, DLP, logging or other monitoring systems.
Section 26(6) of the Federal Data Protection Act (BDSG) expressly clarifies that the participation rights of employees’ representative bodies remain unaffected. The specific admissibility of an investigative measure under labour law and works constitution law should therefore, where employees are concerned, be clarified with the relevant legal advisers and, where appropriate, the designated company bodies before it is carried out.
LanCologne does not replace this legal assessment. Our task is, once the permissible scope of the investigation has been defined, to examine the technical question of evidence in a transparent, proportionate and unbiased manner.

🔗 Related topics

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now