How to Preserve Digital Evidence Properly

How to Preserve Digital Evidence Properly

A deleted Teams message, an edited spreadsheet or a phone handed back to its owner can change the evidential position of an investigation within minutes. The question of how to preserve digital evidence is therefore not simply a technical one. It is a matter of procedural fairness, confidentiality and whether an organisation can demonstrate that the material presented to a decision-maker is complete, authentic and reliably handled.

For disciplinary, regulatory and workplace investigations, preservation should begin as soon as there is a credible prospect that relevant material exists. Waiting until witness interviews are complete or allegations have been fully defined creates avoidable risk. Digital evidence is easily altered, overwritten, duplicated or lost through ordinary business activity.

How to preserve digital evidence from the outset

Preservation starts with scope. Record the allegation, the relevant time period, likely custodians, devices, systems and communications channels. This does not require the investigating team to know every item that will matter. It requires a reasonable, documented basis for protecting material while the facts are established.

A preservation record should identify what has been identified, where it sits, who controls it and what immediate action was taken. For example, relevant material may include work email, Teams or Slack messages, documents held in SharePoint, access-control logs, CCTV, call recordings, social media content, text messages and data held on a managed mobile device.

The scope must be proportionate. A broad instruction to retain everything may be difficult to operate and may retain personal data without justification. A scope that is too narrow may miss material that challenges the initial account. Review it as the investigation develops, documenting why sources were added, excluded or no longer required.

Issue a clear preservation instruction

Where an organisation controls the relevant systems or devices, issue a written preservation instruction promptly. It should state the matter in general terms, identify the date range and sources concerned, prohibit deletion or alteration, and explain whom to contact if the recipient is uncertain about relevance.

The instruction should be directed to the right people: IT administrators who manage retention settings, line managers who hold local records, and individual custodians where they may possess relevant material. Keep a record of issue, acknowledgement and any follow-up. This is valuable evidence of the organisation’s response if a record later proves unavailable.

For personal devices, private accounts or third-party platforms, the position is more fact-specific. Investigators should not assume unrestricted access. Consider the organisation’s policies, the legal basis for processing, the relevance of the material, the individual’s expectations of privacy and any contractual or regulatory powers. Legal advice may be required where the proposed collection is intrusive or contested.

Preserve the original and record every copy

The strongest position is usually to preserve the original source while creating a controlled working copy for review. Screenshots alone are rarely sufficient where the underlying account, message thread, file properties or system logs remain available. A screenshot can omit context, timestamps, participants, edits and metadata.

Where practical, collect evidence using an export or acquisition method that retains the source format and relevant metadata. This might mean an administrator export from a corporate platform, a download with accompanying audit data, or a forensic capture of a device. The appropriate method depends on the source, the seriousness of the allegation and the likely challenge to the evidence.

Record the collection method in plain terms. The case file should show who collected the item, when they did so, from which system or device, the account or location involved, and whether the item was copied, exported or imaged. If a tool generated a hash value, retain it with the collection record. Hash values provide a practical way to demonstrate that a file has not changed after collection.

Not every case requires specialist forensic imaging. A routine HR matter involving a small number of corporate emails may be adequately handled through a documented administrator export. Allegations involving fraud, data theft, manipulation of records or deliberate deletion may justify a more forensic approach. The principle is consistent: use a method proportionate to the risk, then be able to explain it.

Maintain a chain of custody that can withstand scrutiny

Chain of custody is the documented history of an evidential item from collection to final outcome. It is not a ceremonial form. It answers straightforward but consequential questions: where did this come from, who had access to it, and can we show that it has not been altered?

For each significant item, create a unique reference and record its source, date and time of collection, collector, storage location, file name or description, integrity information where available, and every transfer or change of access. If an item is redacted, translated, converted to PDF or excerpted for a hearing bundle, preserve the original and identify the derivative version clearly.

A simple chain becomes unreliable when evidence is moved between inboxes, local drives and consumer file-sharing services. Those routes can obscure version history and extend access far beyond the investigation team. A single secure platform is preferable because it keeps material, permissions, actions and case notes within the same controlled environment.

Audit trails should capture meaningful activity, including upload, download, viewing, editing, sharing and deletion attempts where the system supports it. The aim is not to create administration for its own sake. It is to provide an accountable record if the evidence is challenged by a respondent, panel, regulator or tribunal.

Control access without obstructing the investigation

Preservation does not mean making every item available to every participant. Sensitive case material can contain special category data, legally privileged communications, safeguarding information, confidential commercial data or third-party personal data. Access should be based on role and necessity.

Set permissions for investigators, case administrators, legal advisers, panel members and external experts separately. Avoid shared accounts. Apply multi-factor authentication where available, and use encryption in transit and at rest. For high-sensitivity matters, consider whether downloads should be restricted, whether access should expire after a hearing, and whether certain material needs a separate restricted category.

This must be balanced against fairness. A respondent should receive the material they are entitled to see in sufficient time and in a usable form. The disclosure record should distinguish between material relied upon, material that may reasonably assist or undermine an account, and material withheld or redacted for a documented reason. Decisions about non-disclosure should not be left implicit in a folder structure.

Endaxi Brief supports this discipline by bringing evidence management, case activity and hearing preparation into one auditable workflow built for sensitive data from day one.

Protect metadata, context and version history

Digital evidence is more than the words displayed on screen. Metadata may show when a document was created or modified, who authored it, where it was stored and how it moved. Context may show that an apparently decisive message was part of a longer exchange, sent in a different time zone or amended after publication.

Retain surrounding material where it is needed to understand the item fairly. For communications, this may mean preserving the full thread, participant details and attachments. For documents, it may mean retaining earlier versions, tracked changes and access history. For CCTV, it may mean preserving footage before and after the incident rather than extracting only a short clip.

Be cautious when converting files. A PDF is useful for controlled review and bundling, but conversion can remove metadata, embedded comments, formulae or hidden sheets. Keep the original file alongside the review copy, label each version, and record why a conversion or redaction was made.

Apply retention and deletion controls deliberately

Digital evidence should not be retained indefinitely simply because it might be useful. UK GDPR and EU GDPR principles require organisations to retain personal data only for as long as necessary, subject to legal, regulatory and procedural obligations. The appropriate period depends on the type of case, appeal rights, limitation periods, sector rules and the possibility of related proceedings.

Define the retention decision at case closure, not years later when ownership is unclear. Record the basis for the retention period, any litigation or regulatory hold, and the authorised disposal date. When the period ends, dispose of evidence securely and record that disposal. A defensible deletion process is part of good evidence governance, not its opposite.

Prepare evidence for review and hearing

Evidence is most useful when decision-makers can follow it without reconstructing the case from disconnected folders. Build a clear chronology, identify disputed facts, relate key exhibits to witness accounts and maintain stable exhibit references. If a statement refers to an email, call log or image, the reader should be able to locate the underlying item quickly and see its source.

Quality assurance should take place before disclosure or bundle production. Check that files open, page numbering is stable, redactions are effective, duplicate items are identified and references match the chronology and statements. Confirm that the material presented is the approved version, particularly where bundles have been regenerated after late evidence or procedural directions.

A well-preserved record does not guarantee a particular finding. It does give the investigator and panel a sounder basis for reaching one. Treat each collection decision as though you may later need to explain it to an independent reviewer: what was preserved, why it was relevant, who could access it and how its integrity was protected. That discipline is often what turns a difficult digital record into evidence that can be relied upon.