Digital evidence in court: why a printout is not enough and how to build credibility that can be verified

Digital evidence in court: why a printout is not enough and how to build credibility that can be verified

Illustration generated by AI (GPT Image 2 model on the FOTOhub.app platform). Disclosed in accordance with art. 50 of the AI Act.

More and more criminal, civil, and disciplinary cases are decided not by a witness statement, but by a file: an email, a messaging-app screenshot, a recording, a system export, or server logs. The problem is that Polish procedure still tends to treat this material as though it were paper. But paper and digital data operate under entirely different rules.

In this article, I explain where the real problem lies, what the international standard for handling digital evidence looks like, what article 168a of the Polish code of criminal procedure actually means in light of Supreme Court case law, and why Poland needs a standard I call the Evidence Integrity Protocol.

A printout is not digital evidence. It is its shadow

Let us start with a distinction that is still too often ignored in courtroom practice. A printed chat message, a screenshot, or a PDF generated from correspondence is not digital evidence. It is a representation of content that requires separate verification of three things: source, history, and integrity.

Digital evidence is inherently fragile. A timestamp can be changed, a file can be overwritten without leaving an obvious trace, and careless preservation can permanently destroy volatile data. One interaction with a device, performed by someone without the right expertise, can erase metadata or RAM contents and compromise every stage of the analysis that follows.

Yet once a printout enters a case file, it can begin to take on a life of its own. That is where we reach a mechanism that poses a real threat to procedural fairness.

The "credibility amplification" mechanism

It does not take bad faith for material of uncertain origin to begin functioning in proceedings as if it had been verified. A sequence of routine procedural steps is enough:

  1. A party submits a printout of correspondence.
  2. The printout enters the case file and receives a page reference.
  3. A witness is questioned "regarding" the content of the printout and confirms it.
  4. Later filings begin referring to "the evidence in the file."
  5. The court refers in its reasoning to "the parties' correspondence."

At none of these stages has anyone answered the basic questions: where did the material come from, who collected it, is it complete, has it been altered, and who had access to it along the way? The material gains an aura of credibility simply by circulating through the procedural system. That is the difference between a document someone submitted and evidence someone can verify.

Five questions for every critical digital item

Question What must be established
Origin Which device, account, or system did the material come from?
Collection method Who secured it, when, by what method, and on what legal basis?
Integrity Is there cryptographic proof, a hash, showing the material has not changed since collection?
Completeness Is this the full record or correspondence, or only a selected fragment?
Access chain Who had contact with the material between collection and the hearing?

The absence of an answer to any one of these questions does not prove the material is false. It proves that its reliability cannot be assessed properly.

Admissibility is not reliability

At the center of this discussion is article 168a of Poland's code of criminal procedure. The provision states that evidence cannot be found inadmissible solely because it was obtained in breach of procedural rules or through a prohibited act, subject to narrow exceptions involving the most serious violations committed by a public official: murder, intentional bodily harm, or unlawful deprivation of liberty.

That provision must not be read to mean that every improperly obtained item of material should be accepted as reliable. Admissibility and reliability are two separate stages of evaluation. More importantly, Supreme Court case law has consistently narrowed the scope of the provision.

A key decision is the Supreme Court's ruling of October 24, 2023, V KK 178/23. The Court stated directly that article 168a does not establish a rule governing the admissibility of evidence, and that the prohibition on unlawful evidence follows from article 6 of the European convention on human rights, article 42 of the Polish constitution, and article 170 section 1 point 1 of the code of criminal procedure. Applying article 168a solely through a literal reading, the Court held, would "lead to the decomposition of the entire system of evidentiary prohibitions." Earlier, in its June 26, 2019 ruling in IV KK 328/18, the Supreme Court held that the provision cannot serve as a basis for taking evidence where doing so would make the proceedings unfair within the meaning of article 6 section 1 of the European convention on human rights.

It is also worth noting the legislative direction. Poland's criminal law codification commission has proposed restoring article 168a to its pre-2016 wording, returning to the principle that evidence obtained through a criminal act should not be used, and that proposal has been adopted by the Council of Ministers.

Two stages of evaluating evidence

Stage Question Core framework
1. Admissibility Can the material enter the proceedings at all? Article 168a, article 170 section 1 point 1, evidentiary prohibitions, and the article 6 ECHR standard
2. Reliability Can the material be trusted as a basis for factual findings? Article 7; integrity, origin, completeness, and auditability of data

The problem in Polish practice is that when the system shifts its focus toward the mere ability to place material into proceedings, it becomes even more necessary to have an independent standard for examining the quality of that material at the second stage.

The right to a fair trial is not about having a thick case file. It is about whether critical material can be independently challenged, re-examined, and assessed fairly.

The standard already exists: ISO/IEC 27037

A common argument is that "there is no way to regulate this because technology keeps changing." That is not true. An international standard for handling digital evidence has existed since 2012, and it has been adopted in the European Union as EN ISO/IEC 27037:2017. The standard provides guidance on identifying, collecting, acquiring, and preserving potential digital evidence so that the material can withstand scrutiny in court.

What matters is this: when digital evidence is challenged in court, opposing counsel rarely attacks the content first. The first line of attack is the collection method.

Four principles of digital-evidence quality

At the center of the standard are four principles that determine whether material can withstand challenge:

Principle What it means What happens without it
Auditability Every action performed on the material must be capable of reconstruction by an independent, qualified third party through logs, hashes, and records Data origin becomes unverifiable and the material is easily challenged
Repeatability The same procedure, performed by the same person using the same tools, produces the same result No internal quality control of the examination is possible
Reproducibility Another expert, using equivalent tools, can obtain a comparable result from a copy of the material The defense cannot verify the findings, undermining adversarial fairness
Justifiability Every technical decision, including any departure from procedure, such as live acquisition from a system that cannot be shut down, must be documented and justified Departures look arbitrary rather than methodologically justified

Four phases of evidence handling: the ICAP model

The standard organizes evidence handling into four phases: identification, collection, acquisition, and preservation.

Phase Objective Key output
Identification Map devices and data, assess volatility, and prioritize according to the order of volatility Scene record and systems inventory
Collection Move material into a controlled environment through seals, labels, and photographic documentation Collection record and the beginning of the chain of custody
Acquisition Create a bit-for-bit copy using write blockers and cryptographic validation Forensic image, SHA-256 hash, and report
Preservation Maintain integrity over time through physical, logical, and documentary controls such as hashes, seals, and timestamps Access register and periodic hash revalidation

The standard also defines two roles: the DEFR, or Digital Evidence First Responder, the first person to come into contact with the material, and the DES, or Digital Evidence Specialist, who handles complex systems such as RAID arrays, cloud environments, or volatile memory. The importance of that distinction is procedural: it requires documentation of who was authorized to perform which action. A lack of formal authority for the person securing evidence is one of the first challenges opposing counsel will raise.

The framework is supported by related standards: ISO/IEC 27041 on validating investigative methods, ISO/IEC 27042 on analysis and interpretation, ISO/IEC 27043 on incident-investigation process frameworks, and ISO/IEC 27050 on eDiscovery. A well-constructed expert opinion should draw on this wider family, making the methodological chain understandable to the court.

Hashes, timestamps, and seals: technology with legal consequences

Cryptography is not decoration here. It has a direct impact on the evidentiary value of the material.

The technical formula for a defensible chain of evidence

  • A SHA-256 hash of a forensic copy, calculated at the point of acquisition and entered into the record, protects the integrity of the content bit by bit. Changing a single bit produces a different hash result.
  • A qualified timestamp links the material to a specific moment in time. Under article 41 of the eIDAS regulation, EU 910/2014, it benefits from a presumption of accuracy of date and time and of data integrity, and it is effective against third parties throughout the European Union.
  • A qualified electronic seal identifies the organization responsible for securing the material and confirms the origin and integrity of the evidence package.
  • A chain-of-custody register records every subsequent access, transfer, and copy, together with the responsible person and time.
  • The loss of any one element does not automatically invalidate evidence, but it weakens the material's ability to withstand challenge by the opposing side.

A practical note on algorithms: forensic practice has adopted SHA-256 as the standard. SHA-1 has been deprecated since publicly documented collision attacks in 2017, while MD5 has been compromised by collisions since 2004 and 2008. An expert report that relies on MD5 as its only integrity control leaves the evidence exposed to an effective procedural challenge.

It is also worth noting that eIDAS 2.0, EU regulation 2024/1183, expands the framework for trust services, including the European digital identity wallet and qualified electronic archiving. That further strengthens the legal infrastructure for reliable electronic data.

The most common mistakes that undermine digital evidence

A recurring catalogue of failures appears across contested proceedings:

Error Why it weakens the material Remedy
A screenshot as the sole piece of evidence No metadata, hash, timestamp, or network context Forensic acquisition with metadata, DOM, headers, certificate data, and a seal
No hash or a deprecated algorithm Integrity cannot be verified over time SHA-256 at every acquisition stage, recorded in the evidence log
Broken or undocumented chain of custody The opposing side can reasonably argue that the material may have been altered Automated logs, seals, access controls, and periodic revalidation
No formal authority for the person securing the material One of the first challenges raised by opposing counsel Written roles and authorization policy aligned with ISO/IEC 27037
An email printout without the source file Headers, routing, and integrity cannot be examined Preserve the original file with a hash and timestamp, shifting the burden of challenge to the other side

A new front: synthetic content and the C2PA standard

The question "where did this material come from?" takes on a dramatically different meaning in the era of generative AI. Deepfakes mean that audio or video can no longer be treated as self-authenticating. One technological response is the C2PA standard, Coalition for Content Provenance and Authenticity, developed by organizations including Adobe, Microsoft, Intel, and news agencies.

C2PA defines Content Credentials: a cryptographically signed manifest embedded in a file that records which device created the content, which software processed it, what edits were made, and whether generative AI was involved. Every entry is digitally signed, and the manifest is linked to the content through a hash, meaning that any modification invalidates the credential.

The core idea behind this standard aligns with the central argument of this article: detecting forgery after the fact is an endless arms race against content generators. Provenance bypasses that race by establishing authenticity at the point where content is created, rather than trying to prove it only after distribution. C2PA does not decide whether content is "true." It confirms only that provenance information is accurate, unaltered, and signed by a trusted entity.

That is precisely the role an integrity layer should play for every form of digital evidence. C2PA will not cover legacy material or files stripped of metadata, however, which is why provenance-based methods and expert analysis must work together in evidentiary practice.

The standard Poland is missing: the Evidence Integrity Protocol

Since international standards already exist, the problem is not their absence. The problem is the lack of systematic enforcement in domestic practice. Poland needs a national standard for digital evidence with high procedural significance. Not another form, but a technical and procedural standard that separates supporting material from material capable of independently deciding a material factual issue.

Pillar 1. Evidence provenance record

Every digital item should receive an independent provenance record containing at least:

Pillar 2. Independent expertise as the standard for critical material

When the central evidence is an email, SMS, recording, device location, chat message, or online-account record, independent digital-forensics analysis should be the standard. It should not be a luxury available only when the defense has the time, money, and specialist capable of drafting a precise evidentiary motion.

The asymmetry here is structural. Law-enforcement bodies have extraction infrastructure, laboratories, and access to commercial-grade tools. The defense most often has a printout. Where central evidence is digital and only one side has the technical capacity to examine it, adversarial fairness stops being real and becomes a declaration.

Pillar 3. Equality of arms in access to data

The defense cannot receive only a PDF of a printout. Subject to privacy, legally protected secrecy, and procedural safeguards, it should have access to a verifiable copy of source material, metadata, hashes, the collection method, and the scope of analysis performed. Without that, adversarial process is performative: one side has access to infrastructure and expertise, while the other has an image of content without the history of how it came into existence.

The minimum evidence package for the defense in digital cases

  • A binary or logical copy of the source material, not a printout.
  • A list of hashes with the algorithm and time of calculation.
  • A collection record: who, when, with what, and on what basis.
  • A description of the extraction method and its scope: full physical copy, logical copy, or selective extraction.
  • A chain-of-access register from collection to disclosure.

A refusal to disclose any of these elements should be expressly justified, not automatic.

Poland's Supreme Court said it directly: screenshots require verification

Someone may argue that these proposals amount to academic maximalism. But Polish case law has already pointed in this direction.

In V KK 507/20, the Supreme Court set aside a ruling after criticizing the treatment of screenshots from a witness's mobile phone. The lower court had accepted them as credible without verifying that the messages were actually received, which phone number they came from, or the date and time they were sent.

The reasoning contains a principle that should become the reference point for every case based on digital communication: without procedural verification using telecommunications data, in that case through SMS history from the carrier, there was no basis for clearly and conclusively finding that the messages actually contained the attributed content, originated from a particular number, and were sent at the claimed time.

This is not a detail. It is the fundamental divide between an image and evidence.

A screenshot may show what was visible on a screen at the moment it was captured. It does not, by itself, prove:

The Supreme Court did not say screenshots are prohibited. It said something more mature: where their content matters to the factual findings, they must be verified. That verification cannot be replaced by the impression that a screen "looks credible."

Screenshot vs. verified evidence

Criterion Screenshot Verified material
Source Declared by the submitting party Confirmed by telecommunications data, provider records, or logs
Time Visible in the image and dependent on device settings Confirmed by a timestamp or infrastructure-side data
Integrity Not verifiable Hash calculated at collection and capable of repeat verification
Completeness Fragment selected by the submitting party Full conversational context available for examination
Authorship Assumed Verifiable in connection with control of the device and account

Securing a phone is only the beginning, not the end

Public debate around evidence from mobile devices often focuses on the most dramatic question: can the phone be unlocked? The real problem does not begin with the PIN. It begins after the device is secured.

Was the phone isolated from networks? Was its state preserved? Was a record made of the IMEI number, lock status, visible apps, and time of seizure? Was a proper forensic copy created? Was a hash calculated? Was later analysis performed on a copy rather than the original? Can the defense verify the extraction method and the scope of data?

If the answer to these questions is "we do not know," the material may still have operational value. It should not, however, thoughtlessly become the digital foundation of a judgment.

This distinction is crucial: operational usefulness and evidentiary value are two different categories. Material that led investigators toward a lead does not automatically become material capable of carrying a factual finding beyond a reasonable doubt.

How the mechanism works without bad faith: the anatomy of procedural illusion

It is worth tracing once more how unverified material acquires an appearance of strength. A page enters the file. A police officer describes its origin. A prosecutor attaches it to the indictment. The court sees a document, a report, and testimony. Each stage may unintentionally reinforce the impression that the material is reliable, even though no one has done the foundational technical work: no source file has been preserved, no metadata retained, no hashes calculated, no server logs checked, and no full chain of custody documented.

This does not have to be bad faith. It is often the result of a lack of a uniform standard, time pressure, limited resources, and uneven expertise. But the procedural effect remains the same: material of unverified origin can begin to function in the case file as if it had been verified.

In practice, two questions are too often dangerously merged: whether a document is in the case file, and whether the document's content corresponds to reality. The first is formal. The second is substantive. A system that answers yes to the first and treats that as an answer to the second produces factual findings on a fragile foundation.

De lege ferenda proposals

Here are specific proposals that translate the diagnosis into solutions:

  1. A mandatory preservation record with a hash for every digital item with evidentiary significance, covering the source, method, time, and person performing the action.
  2. A party's right to a copy of source material with metadata, not merely a printout or PDF, subject to necessary limits arising from privacy and legally protected secrecy.
  3. A minimum metadata standard for electronic correspondence: headers, identifiers, and infrastructure-side data from the carrier or service provider where available.
  4. Telecommunications and technical verification as the rule for critical material, consistent with the direction set in V KK 507/20: where communication content matters to factual findings, it must be verified rather than accepted on the basis of apparent credibility.
  5. Documentation of the chain of access from preservation through the hearing, with the ability for the opposing side to conduct an independent audit.

Conclusion: verifiability instead of assumed credibility

I am not arguing that every printout is false. I am making a more important point: by its nature, a printout is not standalone digital evidence. It is a representation of content whose source, history, and integrity must be independently verified.

A fair process in the digital age is not about having a large case file or a substantial volume of material. It is about whether the critical evidence can be independently examined, checked again, and fairly challenged. Technology gives us the tools: hashes, timestamps, binary copies, access registers, and content-provenance standards. Law gives us the framework: article 7 of the code of criminal procedure, the fair-trial standard, and Supreme Court case law which, in V KK 507/20, made clear that an image is not evidence until it has been verified.

One thing is missing: a systemic habit of asking about origin, integrity, and completeness every time, rather than only when a party happens to have an exceptionally thorough lawyer or a court sensitive to the specific nature of digital data. The Evidence Integrity Protocol is a proposal to turn that habit into a standard. In a dispute about facts, the advantage should belong to the side that is right, not the side that put the first piece of paper into the case file.

Do you have questions about preserving digital evidence or assessing material in a specific case? Write to me. In future articles, I will expand on qualified timestamps in procedural practice and analyze case law on evidence from encrypted messengers.

Topics: dowody cyfroweinformatyka śledczaart. 168a k.p.k.ISO/IEC 27037łańcuch dowodowySHA-256eIDASC2PAEvidence Integrity ProtocolSąd Najwyższy