IT Forensics · Business
How can a company compile technical evidence for a potential criminal complaint without prejudging the criminal law assessment?
Where there is a suspicion of data theft, tampering, fraud or unauthorised access, the company may consider launching a criminal investigation.
Why this question is important for a business
Internal investigations can have significant financial, personnel and legal consequences. This is precisely why it must first be clarified which specific technical fact is to be proven or disproved. The sheer volume of data is not an indicator of quality; what is crucial is that the investigation is appropriate, limited in scope and transparent.
Technical investigative approach
We document specific technical actions, timestamps, systems, accounts, files and limits of inferability, and obtain the underlying evidence.
Where the limits of what can be said lie
We do not make any accusations. It is a matter for the law enforcement authorities and legal advisers to determine whether a criminal offence has been committed and against whom criminal suspicion is directed.
Why LanCologne?
Internal investigations are particularly sensitive because they may simultaneously involve the company’s commercial interests, employees’ personal rights, data protection, employee participation in company decision-making, and potential future legal proceedings.
LanCologne therefore does not begin with the most comprehensive search of the IT systems possible. The starting point is a clearly formulated technical question of evidence. From this, the necessary data sources, time periods and investigative steps are derived. Technical feasibility and legal admissibility are deliberately kept separate.
The investigation remains open-ended. A suspicion is not confirmed simply because it sounds plausible. Incriminating, exculpatory and contradictory evidence is examined according to the same professional standards. Where several technical explanations are possible, these are identified and, as far as possible, tested against one another.
Automated reports, EDR alerts, DLP hits or output from forensic software are not accepted as evidence without verification. Key findings are, as far as possible, validated against primary data and correlated with independent artefacts.
To facilitate a subsequent technical review, we document not only the result but also the reasoning behind it. The main body of the report, written in clear language, is aimed at senior management and the legal department; a technical appendix enables a qualified external forensic expert to verify the key findings.
How we work
No prejudgement – even where suspicions have already been confirmed internally
A company may already have clear grounds for suspicion for organisational or legal reasons. However, the outcome of the technical investigation remains open. We also document any findings that contradict the suspicion and explicitly state when an alleged act cannot be proven on the basis of the data obtained.
Technical findings and legal assessment remain separate
IT forensics can, for example, establish that a particular account exported a file, that a device was connected at a specific time, or that a message was technically transmitted. This does not automatically reveal which individual was responsible, whether the action was authorised, or what the consequences might be under employment, civil or criminal law.
LanCologne as an independent technical support service for the legal department and senior management
LanCologne is not commissioned to technically confirm a desired outcome. We are commissioned to provide an objective answer to a specific question of evidence based on the available digital traces. The investigation must remain verifiable even if it is subsequently scrutinised by an opposing party, a court or another qualified IT forensic expert.
Legal framework
Section 26 of the Federal Data Protection Act (BDSG) is a key legal reference point for employees’ data. Section 26(1) of the BDSG permits the processing of personal data relating to employees for the purposes of the employment relationship, subject to the conditions set out therein. With regard to the detection of criminal offences, the provision requires, in particular, that there be documented factual indications, as well as that the processing be necessary and proportionate; the employee’s legitimate interest must not take precedence. Section 26(6) of the BDSG leaves the participation rights of employee representative bodies unaffected.
In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation under Article 5, as well as the requirement for a valid legal basis under Article 6. In the case of special categories of personal data, Article 9 of the GDPR and, where applicable, Section 26(3) of the BDSG must also be observed.
In the case of technical equipment intended to monitor the behaviour or performance of employees, Section 87(1)(6) of the Works Constitution Act (BetrVG) provides for a right of co-determination for the works council, insofar as there are no statutory or collective agreement provisions in place. For MDM, EDR, DLP, logging and similar systems, the specific design of each must therefore be taken into account.
In the case of reports made under the Whistleblower Protection Act, Section 8 of the HinSchG is particularly relevant. The duty of confidentiality protects not only the identity of the whistleblower, but also the persons who are the subject of a report and any other persons named in the report. Section 9 of the HinSchG sets out statutory exceptions to the duty of confidentiality. Section 36 of the HinSchG prohibits reprisals and, subject to the conditions set out therein, contains a rule on the burden of proof.
In the case of trade secrets, an internal investigation must not automatically treat a report as a breach of confidentiality. Section 5 of the Trade Secrets Act (GeschGehG) sets out exceptions to the prohibitions in Section 4, including, amongst other things, under certain conditions for the detection of unlawful acts or professional or other misconduct, as well as for necessary disclosures to employee representatives.
Should civil proceedings arise at a later stage, the Code of Civil Procedure (ZPO) provides, amongst other things, for evidence by inspection; Section 371(1) ZPO expressly governs the case where an electronic document forms the subject matter of the evidence. Sections 402 et seq. ZPO apply to expert evidence. In criminal proceedings, the court determines the scope of the taking of evidence in accordance with the Code of Criminal Procedure (StPO); in particular, Section 244 of the StPO governs the principle of investigation and applications for evidence. However, these procedural provisions do not automatically transform a privately commissioned IT forensic report into a court expert report.
LanCologne provides technical expert services and does not offer legal advice. The specific admissibility of an investigative measure, the consequences under employment law, procedural strategy and criminal law assessment remain the responsibility of the relevant legal advisers, authorities and courts.
Frequently Asked Questions
How can a company compile technical evidence for a potential criminal complaint without prejudging the criminal law assessment?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation under Article 5, as well as the requirement for a valid legal basis under Article 6. In the case of special categories of personal data, Article 9 of the GDPR and, where applicable, Section 26(3) of the BDSG must also be observed.
In the case of technical equipment intended to monitor the behaviour or performance of employees, Section 87(1)(6) of the Works Constitution Act (BetrVG) provides for a right of co-determination for the works council, insofar as there are no statutory or collective agreement provisions in place. For MDM, EDR, DLP, logging and similar systems, the specific design of each must therefore be taken into account.
In the case of reports made under the Whistleblower Protection Act, Section 8 of the HinSchG is particularly relevant. The duty of confidentiality protects not only the identity of the whistleblower, but also the persons who are the subject of a report and any other persons named in the report. Section 9 of the HinSchG sets out statutory exceptions to the duty of confidentiality. Section 36 of the HinSchG prohibits reprisals and, subject to the conditions set out therein, contains a rule on the burden of proof.
In the case of trade secrets, an internal investigation must not automatically treat a report as a breach of confidentiality. Section 5 of the Trade Secrets Act (GeschGehG) sets out exceptions to the prohibitions in Section 4, including, amongst other things, under certain conditions for the detection of unlawful acts or professional or other misconduct, as well as for necessary disclosures to employee representatives.
Should civil proceedings arise at a later stage, the Code of Civil Procedure (ZPO) provides, amongst other things, for evidence by inspection; Section 371(1) ZPO expressly governs the case where an electronic document forms the subject matter of the evidence. Sections 402 et seq. ZPO apply to expert evidence. In criminal proceedings, the court determines the scope of the taking of evidence in accordance with the Code of Criminal Procedure (StPO); in particular, Section 244 of the StPO governs the principle of investigation and applications for evidence. However, these procedural provisions do not automatically transform a privately commissioned IT forensic report into a court expert report.
LanCologne provides technical expert services and does not offer legal advice. The specific admissibility of an investigative measure, the consequences under employment law, procedural strategy and criminal law assessment remain the responsibility of the relevant legal advisers, authorities and courts.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can a company ensure that a private IT forensic report is drawn up in such a way that it can be examined by a court-appointed expert at a later date?
- How can a company deal with conflicting findings from its internal IT department, external service providers and forensic experts?
- How can a company document the results of technical investigations in such a way that senior management and the legal department can understand them?
- Why should a company call in an independent IT forensic expert at an early stage when there is a suspected internal incident?