IT Forensics · Courts
How reliable is digital location data as evidence in court?
Location data may be derived from GPS, WLAN, mobile networks, photos, apps, map history or synchronised account data. These sources vary in terms of accuracy and the logic behind how the data is generated. A robust investigation distinguishes between a device’s position, a stored location reference and a person’s actual presence.
What exactly does the expert need to clarify?
It is not the number of artefacts found that is decisive. What matters is whether the relevant digital traces support the fact in question, contradict it, or do not allow for any conclusive conclusion. To this end, findings are examined in their technical context and alternative hypotheses are explicitly considered.
Where the limits of what can be said lie
A location artefact may support a connection to a device or account, but does not automatically prove which person was there. The radius of accuracy, caching and synchronisation must also be taken into account.
How LanCologne tackles the question requiring proof
In the case of court-ordered assignments, our work begins with the question of evidence, not with an analysis programme. We determine which technical facts need to be clarified, which data sources are relevant to this, and which alternative explanations need to be examined.
The data set is clearly documented and, as far as technically possible, examined using verified forensic backups or working copies. Automated matches are not accepted without verification where they relate to matters relevant to the decision. The origin, the logic behind its creation and the context of an artefact are decisive. Where necessary, a finding is verified against the raw data or using an independent, second, technically appropriate method.
In the report, we distinguish between the findings of fact, the technical assessment and the conclusion. We also clearly state the limits of our findings: what has been proven, what is merely supported, what remains open to question, and what cannot be determined on the basis of the available data?
The main body of the report is written in a way that is accessible to judges and other non-forensic experts. Technical verifiability is ensured by a separate technical section. This section documents the data sources, integrity values, artefacts and investigative steps that are essential for an independent review.
How we work
Methodological classification
There is no statutory list of prescribed software products for forensic IT investigations. The BSI Basic Protection module DER.2.2 contains useful guiding principles on precautionary measures, evidence preservation and the presentation of findings in a manner appropriate to the target audience in the event of IT security incidents. However, it expressly states that the actual forensic analysis is not covered by the module and that it does not relate to IT forensic investigations in criminal cases. We therefore do not present it as a standard for criminal proceedings.
Legal framework
ZPO Sections 403, 404a, 407a, 411; Section 286 ZPO; in criminal matters, Sections 72 et seq. StPO.
The final assessment of the evidence remains the responsibility of the court. Our role as experts is limited to providing a technical response to the technical question of evidence within the scope of the terms of reference.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you require an independent IT forensic investigation in relation to a specific issue of evidence in court? LanCologne examines the available digital evidence with an open mind and documents key findings, counter-findings and technical limitations in a transparent manner.