IT Forensics · Business
How can a company sensibly limit the scope of an internal investigation?
Investigations that are too broad do not automatically increase the strength of the evidence, but may give rise to data protection risks and unnecessary infringements of employees’ rights.
Why this question is important for a business
In the case of internal incidents, commercial interests, the preservation of evidence and employees’ rights may all be affected simultaneously. A technically wide-ranging investigation is therefore not automatically a good one. What is crucial is a clearly defined question of evidence and a transparently limited scope of the investigation.
Technical investigative approach
Before we begin, we define the relevant devices, accounts, types of data, time period and specific search objectives, and we only expand the scope if new, reliable connecting facts justify this from both a technical and legal perspective.
Where the limits of what can be said lie
The principle of data minimisation under Article 5 of the GDPR requires that personal data be limited to what is necessary for the purpose.
Why LanCologne?
Internal investigations involve a direct clash of several interests: the company must be able to protect its systems, data, trade secrets and commercial interests. At the same time, employee data protection, proportionality, co-determination and, where applicable, the protection of private data must be observed.
LanCologne therefore does not begin by collecting as much data as possible. The starting point is the specific technical question to be investigated. Only then is it determined which devices, accounts, time periods and types of data are actually required. This often allows an investigation to be carried out much more precisely than a blanket, comprehensive analysis would.
Technical availability and legal permissibility are deliberately kept separate. The fact that an administrator, MDM system or cloud tenant technically enables access to certain information does not in itself answer the question of whether that information may be processed for the specific purpose in question.
Key findings are validated against primary data where necessary. Automated reports and forensic software are tools; they do not replace the expert interpretation of the underlying artefacts. Alternative technical explanations are also examined.
Equally important: an internal investigation must take exonerating facts just as seriously as incriminating ones. If the analysis reveals that a suspicion cannot be technically confirmed, or that a notable incident can be explained by a standard system process, this must be explicitly stated in the findings.
How we work
No prejudgement of employees
An internal suspicion is not simply declared to be the outcome of the investigation. We examine which technical facts support it, which contradict it, and what alternative explanations exist. Even a finding that is unfavourable to the company or exonerates it is fully documented.
Comprehensible to senior management and the legal department – reproducible for forensic experts
The main body explains the key message without using unnecessary technical jargon. The technical section documents data sources, backup statuses, identifiers, integrity information, time references, artefact locations and validation steps. This ensures that the investigation remains traceable for subsequent technical cross-checking.
LanCologne: independent technical support for businesses
Where an internal incident requires technical investigation, LanCologne provides support in the form of an objective, unbiased and transparent IT forensic investigation. The focus is not on a desired outcome, but solely on what can actually be substantiated on the basis of the digital evidence within the permissible scope of the investigation.
Legal framework
In Germany, Section 26 of the Federal Data Protection Act (BDSG) must be observed in particular with regard to employees’ data. Personal data relating to employees may be processed for the purposes of the employment relationship if this is necessary for the purposes specified therein. Section 26(1) of the BDSG sets out specific conditions for the detection of criminal offences: There must be documented factual grounds justifying the suspicion that the data subject has committed a criminal offence in the course of their employment; the processing must be necessary for the detection of the offence, and the employee’s legitimate interests must not outweigh this. In particular, the nature and extent of the processing must not be disproportionate.
In addition, the general principles of the GDPR apply. Article 5 of the GDPR requires, amongst other things, lawfulness, purpose limitation and data minimisation. Article 6 of the GDPR requires a valid legal basis for processing. Consequently, the fact that an analysis is technically feasible does not automatically mean that it is legally permissible.
In the case of technical equipment, Section 87(1)(6) of the Works Constitution Act (BetrVG) may also be relevant. According to this provision, in the absence of any statutory or collective agreement provisions, the works council has the right to be consulted on the introduction and use of technical systems designed to monitor employees’ behaviour or performance. Depending on their design, this may be relevant, for example, in the case of MDM, EDR, DLP, logging or other monitoring systems.
Section 26(6) of the Federal Data Protection Act (BDSG) expressly clarifies that the participation rights of employees’ representative bodies remain unaffected. The specific admissibility of an investigative measure under labour law and works constitution law should therefore, where employees are concerned, be clarified with the relevant legal advisers and, where appropriate, the designated company bodies before it is carried out.
LanCologne does not replace this legal assessment. Our task is, once the permissible scope of the investigation has been defined, to examine the technical question of evidence in a transparent, proportionate and unbiased manner.
Frequently Asked Questions
How can a company sensibly limit the scope of an internal investigation?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
In addition, the general principles of the GDPR apply. Article 5 of the GDPR requires, amongst other things, lawfulness, purpose limitation and data minimisation. Article 6 of the GDPR requires a valid legal basis for processing. Consequently, the fact that an analysis is technically feasible does not automatically mean that it is legally permissible.
In the case of technical equipment, Section 87(1)(6) of the Works Constitution Act (BetrVG) may also be relevant. According to this provision, in the absence of any statutory or collective agreement provisions, the works council has the right to be consulted on the introduction and use of technical systems designed to monitor employees’ behaviour or performance. Depending on their design, this may be relevant, for example, in the case of MDM, EDR, DLP, logging or other monitoring systems.
Section 26(6) of the Federal Data Protection Act (BDSG) expressly clarifies that the participation rights of employees’ representative bodies remain unaffected. The specific admissibility of an investigative measure under labour law and works constitution law should therefore, where employees are concerned, be clarified with the relevant legal advisers and, where appropriate, the designated company bodies before it is carried out.
LanCologne does not replace this legal assessment. Our task is, once the permissible scope of the investigation has been defined, to examine the technical question of evidence in a transparent, proportionate and unbiased manner.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can a company arrange for a forensic examination of an employee’s work computer?
- How can a company have a work smartphone or tablet subjected to a forensic examination?
- What role can MDM play in an internal IT forensic investigation?
- How can a company make use of MDM reports without overestimating their significance?