IT Forensics · Solicitors & Criminal Defence Lawyers
How can location data be assessed as a potential means of reducing the burden?
Digital location data may be relevant in cases involving alibis or questions of presence, but must be assessed on a case-by-case basis depending on the source.
Why this question is important for a criminal defence
Particularly during the pre-trial investigation, technical findings can have a significant impact on the defence strategy going forward. The key is not to find as many supposedly favourable results as possible, but to establish at an early stage which digital evidence is reliable and which of the investigation’s assumptions may be based on an overly broad technical interpretation.
Technical investigative approach
We compare GPS, WLAN, mobile network, photo, app and cloud locations, taking into account accuracy, device-specific factors and synchronisation.
Where the limits of what can be said lie
A device’s location does not automatically correspond to the client’s whereabouts. Similarly, individual location points do not constitute a complete movement profile.
Why LanCologne?
LanCologne does not support the defence by specifying a desired outcome, but by carrying out an independent technical examination. This is particularly crucial for the defence: a robust counter-assessment must also be able to withstand subsequent scrutiny by the Crown Prosecution Service, another expert witness and the court.
The starting point is the specific defence issue. What facts are being attributed to the client? What digital trail actually supports this assumption? Does it relate to a device, an account or a session, or can it be reliably linked to a natural person? Are there technically plausible alternative explanations? What traces would one expect to find in the alleged sequence of events, and are they present?
Legitimately accessible data sets are secured in a traceable manner, as far as technically possible, and checked for working copies. Critical findings are not simply taken from automated reports. Their origin, the logic behind their creation, the database or file system context and, where applicable, the underlying raw data are examined.
The result may be favourable, unfavourable or inconclusive for the client. This uncertainty regarding the outcome is not a disadvantage, but rather a prerequisite for ensuring that a technical finding can be relied upon at a later date.
How we work
Incriminating, exculpatory and inconclusive findings
The defence does not benefit from an expert report drawn up as a favour. If the data supports the allegation, this is stated just as clearly as any exculpatory findings. If several explanations remain technically possible or if the data set is insufficient, the remaining uncertainty is explicitly documented. It is precisely this distinction that makes a finding technically robust when presented later to the Crown Prosecution Service, other experts and the court.
Understandable to the defence lawyer – verifiable from a technical perspective by other forensic experts
The main section is worded in such a way that the defence counsel can grasp the technical significance for their defence strategy. A separate technical section documents the data sources, integrity information, time references, artefacts and investigative steps relevant to a review. This ensures that the methodology remains reproducible for another IT forensic expert.
LanCologne as an independent source of technical support for the defence
If a criminal defence lawyer wishes to have a digital factual issue independently examined as early as the pre-trial investigation stage, LanCologne provides support in the form of a transparent and unbiased IT forensic investigation. The aim is to establish a factually sound basis – regardless of whether the findings confirm, qualify or technically contradict the allegations.
Legal framework
The defence may begin its work as early as the pre-trial investigation stage. Under Section 137(1) of the Code of Criminal Procedure, the accused may engage a defence lawyer at any stage of the proceedings. Section 136(1) of the Code of Criminal Procedure stipulates, amongst other things, that during the questioning of the accused, the accused must be informed that applications may be made for the taking of evidence to exonerate them.
Section 160(2) of the Code of Criminal Procedure (StPO) is particularly important for establishing the facts of the case: the Public Prosecutor’s Office must investigate both incriminating and exonerating circumstances and ensure that evidence is secured where there is a risk of its loss. Under Section 163a(2) of the Code of Criminal Procedure, evidence which the accused requests to be taken in his or her defence must be taken if it is relevant. Section 166 of the Code of Criminal Procedure (StPO), on the other hand, specifically concerns requests for evidence made by the accused during a judicial examination and sets out stricter conditions; these situations are not treated as equivalent.
The defence counsel’s right to inspect files and examine evidence is governed by section 147 of the Code of Criminal Procedure. Prior to the conclusion of the investigation, restrictions may apply in accordance with paragraph 2. However, under paragraph 3, the defence counsel must not be denied access to expert reports at any stage of the proceedings. This right is vested in the defence counsel, not LanCologne. A technical examination by LanCologne therefore requires that the defence be able to lawfully provide the relevant documents or data.
The mere fact that an IT forensic expert has been privately engaged by the defence does not in itself make them a formally appointed expert witness under sections 72 et seq. of the Code of Criminal Procedure. The provisions of the Code of Criminal Procedure relating to expert witnesses are therefore only to be applied as such if the relevant procedural status actually exists.
The protection of professional secrecy and cooperation with external experts must also be considered on a case-by-case basis. Section 53a of the Code of Criminal Procedure (StPO) extends the right to refuse to give evidence to persons assisting in proceedings, subject to the conditions set out therein; Section 97 of the Code of Criminal Procedure (StPO) contains a related provision on protection against seizure, which is, however, subject to specific conditions and exceptions. Section 160a of the Code of Criminal Procedure (StPO) contains protective provisions for investigative measures involving persons bound by professional secrecy and persons assisting in the proceedings. Under Section 203(3) and (4) of the German Criminal Code (StGB), solicitors may disclose necessary confidential information to other cooperating persons; at the same time, these persons are subject to confidentiality obligations enforceable by criminal penalties. This does not imply blanket protection for every file held by an external IT forensic expert; the conditions must be assessed on a case-by-case basis.
If the investigations do not provide sufficient grounds for bringing a public prosecution, the Public Prosecutor’s Office will discontinue the proceedings in accordance with section 170(2) of the Code of Criminal Procedure. An IT forensic report does not guarantee such a decision; it can merely provide a technically sound element of the factual basis.
Frequently Asked Questions
LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can backups reveal previous states to the benefit of the defence?
- How is deleted data assessed from a criminal defence perspective?
- Why might independent IT forensic support be useful for a criminal defence, from the preliminary investigation right through to the end of the trial?
- When can the absence of a digital artefact exonerate the client?