IT Forensics · Solicitors & Criminal Defence Lawyers

How can the defence respond professionally and promptly following a single digital evidence collection?

Following the digital collection of evidence, it may be crucial not to allow technical misunderstandings to persist until the end of the trial.

Enquire without obligation

Why this question is important for a criminal defence

During the course of the taking of evidence, individual technical statements may be given considerable weight. To ensure a proper defence, it must remain clear whether a statement follows directly from primary data, is based on an automated interpretation, or requires additional assumptions.

Technical investigative approach

We prepare a concise, source-based summary for the defence, setting out which technical finding has just been raised, what primary data it is based on, and which limitations or contradictory findings are directly relevant.

Where the limits of what can be said lie

LanCologne does not make a statement at the hearing. Section 257 of the Code of Criminal Procedure grants the defence counsel the opportunity to make a statement upon request; the content and timing of the statement are determined by the defence.

Why LanCologne?

At this stage of the trial, it is particularly important not to consider individual technical findings in isolation. Digital evidence can only be properly contextualised if its origin, data status, the logic behind its creation and its limitations are known.

LanCologne therefore consistently works from the primary finding to the conclusion. Automated reports, screenshots or software views are used for illustrative purposes but are not equated with the actual source of evidence. In the case of crucial findings, we examine the underlying files, databases, logs, metadata or other artefacts, insofar as the data infrastructure permits.

Findings that are incriminating and those that are exculpatory are treated according to the same professional standard. A technically feasible alternative is not deemed to constitute counter-evidence as long as there is no concrete evidence. Conversely, no further identification of a specific individual is inferred from a software display that appears plausible if the necessary connecting facts are not present.

The report should be comprehensible to defence lawyers and the court, whilst at the same time containing sufficient technical detail to enable another qualified IT forensic expert to understand and verify the key findings.

How we work

1Identify the specific fact to be proved and the corresponding digital source.
2Unambiguously map primary data, exports, reports and visualisations.
3Document the data status and the date and time of the backup or data collection.
4Check the integrity, identity and, where applicable, any version differences.
5Trace parser, filter and search results back to their technical source.
6Assess the allocation of time, devices, accounts, sessions and individuals separately.
7Examine automated processes and technically specific alternative explanations.
8Compare new findings from the main hearing against the existing database.
9Document incriminating, exonerating and unresolved points according to a uniform standard.
10Summarise the key points and the limits of the argument in a way that the defence can understand.

Incriminating, exculpatory and inconclusive findings

Our investigation is open-ended. If an incriminating finding is confirmed, this is documented in the same way as a credible counter-finding. If a technical question cannot be resolved due to a lack of data, several equally plausible causes or methodological limitations, this uncertainty is specifically noted.

Understandable to the defence and the court – comprehensible to other forensic experts

The key message is explained in clear, accessible language. The technical section documents data sources, identifiers, time references, integrity information, relevant raw data and validation steps. This enables another qualified IT forensic expert to carry out a technical review of the key findings.

LanCologne as an independent source of technical support for the defence

If, during the main hearing, digital evidence, new technical statements or contradictory IT forensic findings need to be assessed, LanCologne provides support through an objective, transparent and unbiased examination. The sole determining factor is what the available data actually proves.

Legal framework

Section 244 of the Code of Criminal Procedure (StPO) remains central to the ongoing taking of evidence. Under paragraph 2, the court must, of its own motion, extend the taking of evidence to cover all facts and evidence relevant to the decision. The requirements for a motion to adduce evidence and the statutory grounds for rejection are set out in particular in Section 244(3) et seq. of the Code of Criminal Procedure. LanCologne can identify technical factual issues and suitable sources of data, but does not itself submit motions to adduce evidence under criminal procedure.

Under Section 246(1) of the Code of Criminal Procedure, a request to take evidence may not be refused solely on the grounds that the evidence or the fact to be proved was raised out of time. The other provisions of Section 246, in particular those concerning possible applications for a stay of proceedings in the event of late submission, are procedural matters for the parties to the proceedings and the court.

Section 249 of the Code of Criminal Procedure governs documentary evidence. Under Section 249(1), electronic documents are deemed to be documents provided they are legible. Paragraph 2 sets out the conditions for the self-reading procedure. The technical task may involve verifying the version, origin and integrity of an electronic document; the court decides on the form of evidence to be taken.

Under section 257(2) of the Code of Criminal Procedure, the defence counsel must also be given the opportunity, upon request, to comment on each individual piece of evidence after it has been taken. Under paragraph 3, this statement must not pre-empt the closing statement. LanCologne may prepare technical details for this purpose, but does not make any procedural statements on behalf of the defence counsel.

If, during the main hearing, the legal basis changes or, in the cases covered by section 265, the facts of the case change, section 265 of the Code of Criminal Procedure (StPO) contains provisions regarding notification and, under certain conditions, suspension. Whether this provision applies in a specific case must be assessed on legal grounds. We shall confine ourselves to determining whether and how the factual basis has changed.

Once the taking of evidence has concluded, closing submissions are made in accordance with section 258 of the Code of Criminal Procedure. The actual assessment of the evidence is a matter for the court: pursuant to section 261 of the Code of Criminal Procedure, the court decides on the outcome of the taking of evidence in accordance with its free conviction, drawn from the entirety of the proceedings. A digital forensics report may explain technical facts and limitations, but it does not replace either the closing submissions or the court’s assessment of the evidence.

Frequently Asked Questions

Can LanCologne prepare technical points for a statement by the defence counsel during the main hearing?+
Yes. We can analyse a digital report from a technical perspective and identify its data basis and limitations. The explanation of the process itself is a matter for the defence counsel.
Is a software view in itself already the actual digital evidence?+
Not necessarily. It is often an interpreted representation of primary data. In the case of key findings, it should be clear which data the display is based on.
Can new digital evidence still be relevant during the main hearing?+
Yes. However, its technical significance and origin must be examined. The procedural approach depends on the specific circumstances of the case.
Does LanCologne ultimately decide whether the defendant is guilty or should be acquitted?+
No. We answer technical factual questions. The legal assessment and the evaluation of evidence are the responsibility of the defence and the court respectively.

LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now