IT Forensics · Private Individuals

How can I document a GPS tracker or locator I have found in a way that stands up to legal scrutiny?

A tracker found at the scene may be of both technical and, subsequently, forensic significance.

Enquire without obligation

Why this question is important for private individuals

Digital reconstruction can have a profound impact on a person’s everyday life. At the same time, joint accounts, old shared files or routine technical procedures can have a similar effect. An independent investigation should therefore neither downplay the issue nor confirm a suspicion prematurely.

Technical investigative approach

We document the context in which the item was found and any visible identifying features, and avoid making any unnecessary alterations; where a criminal offence may have been committed, it may be advisable to liaise with the police at an early stage.

Where the limits of what can be said lie

Tampering with or dismantling the device yourself may alter the evidence. An IT forensic investigation is no substitute for the police’s forensic evidence collection.

Why LanCologne?

Where cyberstalking or digital surveillance is suspected, the situation is often emotionally distressing for those affected. It is precisely for this reason that a professional investigation must draw a clear distinction between mere observation, technical capability and an incident that has actually been proven to have taken place.

LanCologne does not start from the assumption that a specific person is monitoring the device. We formulate specific technical questions: Is there an unknown device pairing? Is location sharing active? Has an account been used from an unauthorised session? Are there any traces of a monitoring app? Is there any traceable remote access? What other plausible technical explanations might there be?

We only examine devices, accounts and data that have been lawfully provided to us. The technical analysis is not intended to gain unauthorised access to another person’s accounts or devices.

Tool reports and scanner results are not accepted as evidence without verification. Key findings are validated, as far as possible, against primary artefacts, account information and independent evidence.

Even a negative finding is a result. If the available data does not confirm an alleged instance of surveillance, this is documented just as clearly as positive evidence. Where the available data does not allow for a definitive conclusion, this uncertainty is not replaced by speculation.

How we work

1Record specific observations and periods of suspicion.
2Prioritise acute personal safety risks over forensic considerations.
3Formulate technical questions of evidence rather than assumptions about the perpetrator.
4Keep relevant communications and account details as unchanged as possible.
5Examine the device, account, sharing and location levels separately.
6Pay particular attention to joint accounts or accounts that were previously held jointly.
7Test hypotheses relating to spyware, stalkerware and remote access using specific artefacts.
8Document tracker alerts and physical trackers, including the context in which they were found.
9Do not equate an IP address, an account, a device and a natural person.
10Give equal weight to findings that are incriminating and those that are exonerating.
11Explicitly identify data gaps and questions that cannot be answered by technical means.
12Document the findings in a way that is clear and comprehensible to lawyers, the police or other experts.

Personal safety takes precedence over the full preservation of evidence

Where there is a specific threat, the desire to obtain as complete a set of digital evidence as possible must not delay the necessary protective measures. The Police Crime Prevention Service recommends dialling the police emergency number in the event of an immediate threat. Forensic evidence collection and protective measures must therefore be appropriately coordinated on a case-by-case basis.

Suspicion, the ability to gain access and actual access are three different things

A previously known password, an active family sharing arrangement or installed remote maintenance software may provide a means of access. Only further evidence can reveal whether this means of access was actually used. Additional evidence may be required to attribute such use to a specific individual.

Why LanCologne in the context of cyberstalking and digital surveillance?

LanCologne is not commissioned to provide technical confirmation of a suspect who has already been identified. We examine the available digital evidence with an open mind. The report should be comprehensible to the person concerned whilst remaining sufficiently transparent to enable a solicitor, investigating authority or another qualified IT forensic expert to understand the key technical findings.

Legal framework

Section 238 of the German Criminal Code (StGB) governs stalking. The provision covers, subject to its conditions, repeated unauthorised stalking which is likely to significantly disrupt the affected person’s way of life. Examples include attempts to make contact via telecommunications or other means of communication, the misuse of personal data, and offences under Sections 202a to 202c of the German Criminal Code (StGB) committed against the affected person or persons close to them. Section 238(2) of the German Criminal Code (StGB) also cites, as a typical example of a particularly serious case, the use of a computer programme for digital spying in connection with such an offence.

Sections 202a et seq. of the German Criminal Code (StGB) may be relevant in cases of unauthorised access to specially secured data or certain forms of interception or preparation for such acts. It cannot be automatically concluded from a single technical artefact whether all the elements of the offence have been fulfilled.

The Protection Against Violence Act provides for court-ordered protective measures, subject to certain conditions. Section 1 of the Protection Against Violence Act (GewSchG), for example, prohibits making contact with the victim, including via means of remote communication. Under certain conditions, the provision also covers repeated stalking or harassment via means of remote communication. Legal advisers and the court will assess which protective measure is possible in a specific case.

The Police Crime Prevention Service advises victims of cyberstalking to keep any existing evidence – such as emails, messaging histories, digital photos or videos – as complete and unaltered as possible until they first contact the police. In the event of an immediate threat, personal safety takes priority.

LanCologne does not make any criminal attributions of guilt or liability, nor does it rule on protection orders. Our role is to establish the technical facts based on data lawfully provided to us and to document these findings in a transparent manner.

Frequently Asked Questions

How can I document a GPS tracker or locator I have found in a way that stands up to legal scrutiny?
Digital reconstruction can have a profound impact on a person’s everyday life. At the same time, joint accounts, old shared files or routine technical procedures can have a similar effect. An independent investigation should therefore neither downplay the issue nor confirm a suspicion prematurely.
How is such a technical investigation carried out in practice?
We document the context in which the item was found and any visible identifying features, and avoid making any unnecessary alterations; where a criminal offence may have been committed, it may be advisable to liaise with the police at an early stage.
Can such an investigation always produce a clear result?
Tampering with or dismantling the device yourself may alter the evidence. An IT forensic investigation is no substitute for the police’s forensic evidence collection.
Is there a legal basis for this?
Section 238 of the German Criminal Code (StGB) governs stalking. The provision covers, amongst other things, repeated unauthorised stalking which is likely to significantly disrupt the affected person’s way of life. Examples include attempts to make contact via telecommunications or other means of communication, the misuse of personal data, and offences under Sections 202a to 202c of the German Criminal Code (StGB) committed against the affected person or persons close to them. Section 238(2) of the StGB also cites, as a typical example of a particularly serious case, the use of a computer programme for digital spying in connection with such an offence. Sections 202a et seq. of the German Criminal Code (StGB) may be relevant in cases of unauthorised access to particularly secure data or certain forms of interception or preparation of such acts. It cannot be automatically concluded from a single technical artefact whether all the statutory elements of the offence are fulfilled. The Protection Against Violence Act allows for court-ordered protective measures subject to its conditions. Section 1 of the Protection Against Violence Act, for example, prohibits establishing contact with the victim, including through the use of remote means of communication. Under certain conditions, the provision also covers repeated stalking or harassment via remote means of communication. Legal advice and the courts assess which protective measure is possible in a specific case. The Police Crime Prevention Service recommends that victims of cyberstalking preserve existing data, such as emails, messaging histories, digital photos or videos, as completely and unchanged as possible until they first contact the police. In the event of an immediate threat, personal safety takes priority. LanCologne does not make any criminal attributions of guilt or blame, nor does it decide on protection orders. Our role is to establish the technical facts based on lawfully provided data and to document them in a traceable manner.

LanCologne – IT Forensics for Private Individuals

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now