Skip to main content

Part 3 - How Digital Evidence Is Processed and the Key Developments of Digital Evidence

Site: OpenLearn Create
Course: Digital Detectives: Understanding Communication in Digital Forensic Evidence
Book: Part 3 - How Digital Evidence Is Processed and the Key Developments of Digital Evidence
Printed by: Guest user
Date: Thursday, 10 September 2026, 9:10 PM

1. How Digital Evidence Is Processed​

Digital evidence is processed and handled slightly differently across Europe depending on each country's own systems, but the basic steps are the following:

Forensic's laying down evidence tag number

Detective thinking

Key Learning Point

It is important to remember that digital evidence is powerful, but not neutral. 

At multiple stages:

  • Choices are made about what to collect
  • Decisions are made about what to analyse
  • Interpretation depends on context

Large data volumes mean investigators must prioritise.

Understanding these human elements helps explain why digital evidence can be powerful, but also complex.

 

Move to the next page by clicking the arrow on the top right to move to the next page in this section.

2. Key Developments in Digital Evidence

Early Court Use

From the late 1970s and early 1980s, courts began admitting computer-generated records as evidence.
These early cases focused on questions of authenticity and reliability.
One of the earliest widely cited cases is R v. Wood (England, 1982), which addressed the admissibility of computer records. Similar questions were being considered in courts across Europe and North America around the same period, as computers entered workplaces and public administration.
While this case arose in a national context, it reflects a broader European shift toward recognising digital records as evidential material, provided their reliability could be demonstrated.

Expansion of the Internet

As internet use expanded in the 1990s, digital evidence moved beyond isolated computer systems to include:

  • Emails and online communications
  • Early web activity records
  • Network and server logs

This period marked a transition from digital evidence being relatively rare to becoming a routine part of investigations.
The rise of personal computers and later mobile phones significantly increased both the volume and variety of digital evidence.

Computer data on screen and mobile phone

Cyber-Dependent and Cyber-Enabled Crime

As digital technologies became embedded in daily life, crime also increasingly involved digital systems. Cybercrime includes offences that:

  • Target digital systems directly, such as hacking or malware
  • Use digital technologies to enable traditional crimes, such as fraud or exploitation

Digital evidence is central to investigating these crimes, often forming the primary source of information.
Europol reports consistently show year-on-year growth in cyber-enabled crime across Europe, increasing reliance on digital evidence in both investigation and prosecution.

Move to the next page by clicking the arrow on the top right to move to the next page in this section.

3. Key Developments Continued...

Increasing relevance since the 2000s

Digital evidence has also become critical in terrorism-related investigations. Online activity, encrypted communications, digital propaganda, and the use of social media platforms all generate digital traces that may be relevant to understanding radicalisation, planning, and coordination.
These investigations highlight both the importance and complexity of digital evidence, particularly where data may be distributed across platforms, jurisdictions, and devices.

An Ever-Changing Landscape of Digital Evidence

Digital evidence continues to evolve due to:

  • New technologies such as cloud computing and artificial intelligence
  • Increasing use of encrypted services
  • Growth of connected and sensor-based devices
  • Cross-border data storage and access challenges

As a result, methods for collecting, analysing, and interpreting digital evidence must constantly adapt. 

Smart watch

Move to the next page by clicking the arrow on the top right to move to the next page in this section.

 

4. Next steps

Take the quiz for Module A Part 4 to complete this section of learning.

In the next modules, you will explore in more detail:

  • The complexity of communicating digital evidence across borders
  • The difference in the communication styles across Europe
  • How terminology shapes understanding
  • And learning about the tools built to mitigate misunderstanding and aid in better forensic practice communication.

 

This is the end of Part 3. From the drop-down menu on the left of the screen, select Module A Part 4.