Move to the next page by clicking the arrow on the top right to move to the next page in this section.
| Site: | OpenLearn Create |
| Course: | Digital Detectives: Understanding Communication in Digital Forensic Evidence |
| Book: | Part 1 - What is Digital Evidence and Why does it Matter |
| Printed by: | Guest user |
| Date: | Thursday, 10 September 2026, 9:09 PM |
Before we explore what digital evidence is, imagine you are arriving at a crime scene.
Watch the short footage below and look carefully at the scene. What could potentially provide evidence?
Try to identify as many different sources as you can. Some may be obvious, while others may be easier to overlook.
One Object, Different Types of Evidence
You may have spotted several possible sources of evidence. But there is another important point to consider: one object can provide more than one type of evidence.
Take a mobile phone.
An investigator might be interested in the digital information it contains, such as messages, photographs, location information or call records. But the physical device itself may also hold other evidence.
For example, there could be fingermarks on the screen or case, or DNA on the device.
This means decisions about how an object is handled can matter. Someone may want to access or preserve its digital information, while another specialist may need to examine the physical device for other traces.
So, when does an everyday object become a source of digital evidence? And what exactly do we mean by "digital evidence"?
That's what we're going to explore next.
Move to the next page by clicking the arrow on the top right to move to the next page in this section.
Welcome to the Clarus Project.
Welcome to the course, which was created by the University of Dundee for the Clarus research project. Watch the above video to find out more about the Clarus Project and what this course explores.
Throughout this course, you can use the resources available from the Clarus project to support your learning. You will find these linked throughout the course and in the course resources box on the left-hand side of the page.
What we will cover in this course
Every interaction with a device, platform, or connected system generates data.
In many investigations and legal proceedings, that data can become digital evidence.
In this module, you will explore:
Digital evidence is information or data, stored or transmitted in digital form, that can be used to establish facts in criminal investigations or legal proceedings. It encompasses all forms of electronically stored information recovered from digital devices, systems, communications, and storage media.
It includes data from:
Digital evidence is not limited to visible files such as documents or photographs. It also includes background data such as logs, timestamps, and metadata that may not be directly visible to users.
Digital evidence is the data itself. Digital forensics refers to the processes used to:
These processes aim to ensure that digital evidence can be relied upon in investigative and judicial contexts.
Pause and consider your day so far. Have you:
Each of these actions may have generated digital records.
Digital evidence is embedded in ordinary daily life.
Move to the next page by clicking the arrow on the top right to move to the next page in this section.



Move to the next page by clicking the arrow on the top right to move to the next page in this section.
Digital Data Is Widespread
Everyday activities such as communication, travel, work, and leisure generate digital data.
As a result, digital evidence is relevant to a wide range of investigations, not only those involving technology-related crime.

Key Learning Takeaway