Breaking

Site add
blog single post
Evidence

Preserving digital evidence for workplace investigations

Why digital evidence is more fragile than it looks

Almost every workplace investigation now turns on digital material. Emails, Teams or Slack messages, WhatsApp threads, shared drive documents, calendar entries, badge logs and CCTV footage often carry the story more reliably than anyone's recollection. The trouble is that this material is surprisingly easy to lose, and surprisingly easy to undermine.

Deletion policies run quietly in the background. Mailboxes are archived after ninety days. A departing employee hands back a wiped laptop. CCTV overwrites itself on a thirty-day cycle. And even when the data survives, it can be weakened by the way it is handled — a screenshot of a message proves very little, while a native file with intact metadata proves a great deal.

The guiding principle is straightforward: capture first, analyse later. Preservation is not the same as investigation, and it should happen long before you have decided what the evidence means.

Secure the material quickly and proportionately

Speed matters, but so does discipline. A few practical steps will carry you a long way:

  • Issue a written preservation notice to IT and any relevant managers, naming the individuals concerned and asking them to suspend routine deletion, mailbox archiving and device wiping.
  • Preserve whole containers where you reasonably can — a full mailbox export, a channel export, a folder — rather than cherry-picking individual items that suit a particular narrative.
  • Preserve CCTV and access control records before their retention window closes. Thirty days is a common limit, and sometimes it is seven.
  • Act before accounts are deprovisioned. Once a leaver's mailbox is closed and their device reissued, options narrow sharply.
  • For serious matters — suspected fraud, safeguarding concerns, likely tribunal claims — consider forensic imaging of devices rather than simple copying.

Before you collect anything, confirm you have policy cover. Your acceptable use, IT and monitoring policies, plus the employee's contract and staff handbook, should give you a clear basis to examine company systems. If they do not, take advice before you start rummaging.

Keep metadata intact

Metadata is the quiet backbone of digital evidence. It tells you who sent what, to whom, when, from which device, and whether a document was created, amended or merely opened. Lose it and you lose the ability to answer the obvious challenges.

  • Export in native format wherever possible: individual emails as .eml or .msg, mailboxes as PST or MBOX, documents as the original files rather than printed PDFs.
  • Copy, don't move. Work from a duplicate and leave the original untouched.
  • Avoid opening files unnecessarily — opening a document can alter its last-accessed date.
  • Record a cryptographic hash, such as SHA-256, for each item or container, and re-check it later to demonstrate nothing has changed.
  • Treat screenshots and printouts as supplements, never substitutes. They are the easiest evidence to challenge.
  • Store everything in an access-restricted location with audit logging, so you can show who viewed what and when.

Follow data protection rules from the start

In the UK, investigations sit within the UK GDPR and the Data Protection Act 2018. Getting this right protects both the investigation and the people caught up in it.

  • Identify your lawful basis. Internal investigations are usually covered by legitimate interests or a legal obligation. Special category data — health, ethnicity, trade union membership, sexual orientation — needs an additional condition under Article 9.
  • Apply data minimisation. Collect what the specific allegation requires. Trawling an entire mailbox in search of something incriminating is both unlawful and, in practice, a gift to the other side.
  • Restrict access on a need-to-know basis and keep a viewing log.
  • Handle personal devices and personal messaging apps with real care. Employees may have a reasonable expectation of privacy, particularly where work and personal content are mixed.
  • Consider a data protection impact assessment if monitoring is extensive or systematic.
  • Remember individual rights, including subject access. Exemptions exist for some investigation material, but they are narrow and fact-specific.
  • Set a retention period and delete securely once the matter, any appeal and the tribunal window have closed.

Document the chain of custody

Keep a simple, contemporaneous log. What was collected, from where, by whom, when, how, and where it has been stored since. Record hash values, transfers between people or systems, and the names of anyone who has accessed the material.

Also record your reasoning. Why did you preserve this mailbox and not that one? Why did you stop at a particular date range? Decisions that seem obvious today will look arbitrary in eighteen months' time unless they are written down. If a case reaches an employment tribunal, this log is often what separates evidence that is accepted from evidence that is picked apart.

Practical habits that keep cases on track

  • Act within twenty-four to forty-eight hours of an allegation wherever possible.
  • Give one named person overall ownership of preservation — usually someone in HR or legal, not the person conducting the technical work.
  • Involve IT early, but keep the circle small and brief them on confidentiality.
  • Separate preservation from analysis, so the people examining material are not the ones altering originals.
  • Tell managers not to discuss, forward, print or delete anything connected to the matter.
  • Bring in external forensic support for high-value, complex or criminal-adjacent cases.
  • Assume everything you do will one day be scrutinised by a tribunal, a regulator or an opposing solicitor.

None of this is glamorous work. It is filing, labelling and logging. But do it well in the first forty-eight hours and the rest of your investigation stands on solid ground — evidence you can rely on, decisions you can defend, and a process that treats everyone involved fairly.

Comments